Data enhancement encryption method, system and equipment based on AES (Advanced Encryption Standard) and medium
By combining strong key derivation, random salt value and message authentication code AES encryption solution, the problem of insufficient data integrity in existing encryption technologies is solved, and high security and flexible data encryption is achieved, which is suitable for the encryption needs of financial, medical and other institutions.
Patent Information
- Application Number
- CN202510748093.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-06
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2045-06-06
AI Technical Summary
Existing encryption solutions such as AES, RSA and SHA have problems such as insufficient data integrity verification function, high computational complexity, and high key management costs in actual applications, which cannot effectively guarantee the security and integrity of the data.
By introducing strong key derivation, random salt values, initialization vectors and message authentication codes, combined with AES encryption mode, HMAC verification values are generated to form encrypted data packets to ensure the security and integrity of the data.
Enhanced data security and integrity, improve brute-force cracking capabilities, prevent replay attacks and data tampering, and customize encryption solutions that meet different needs.
Smart Images

Figure CN120281571A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of data security, and more specifically, relates to a data enhanced encryption method, system, device and medium based on AES. Background Art
[0002] With the rapid development of information technology, network security issues have become increasingly prominent. In recent years, attack means such as data leakage, phishing, and malware have emerged in an endless stream, bringing huge losses to enterprises and individuals. To address these challenges, information security technologies are also constantly evolving, and among them, encryption technology is one of the important means to ensure data security.
[0003] Traditional encryption schemes usually rely on symmetric encryption algorithms (such as AES), asymmetric encryption algorithms (such as RSA), and hash functions (such as SHA). Although these algorithms perform well in their respective fields, they still face some challenges in practical applications: AES Encryption: AES is a currently widely used symmetric encryption standard with powerful encryption capabilities. However, AES itself does not provide a data integrity verification function. Therefore, in practical applications, it is usually necessary to combine with HMAC or other message authentication codes to ensure the integrity and authenticity of the data.
[0004] RSA Encryption: RSA is an asymmetric encryption algorithm commonly used in digital signatures and key exchanges. Although RSA provides relatively high security, due to its high computational complexity, its performance is poor in large-scale data encryption. In addition, the key length of RSA is relatively long, resulting in an increase in key management and transmission costs.
[0005] SHA Hash Function: SHA is a commonly used hash function for generating a message digest of a fixed length. However, SHA can only ensure the integrity of the data and cannot provide an encryption function. Therefore, in practical applications, it is usually necessary to be combined with other encryption algorithms. Summary of the Invention
[0006] Aiming at the above problems, the purpose of the present invention is to provide a data enhanced encryption method, system, device and medium based on AES, which further improves the security and integrity of the data by introducing a series of enhancement mechanisms such as strong key derivation, random salt values, message authentication codes, and initialization vectors.
[0007] The present invention achieves the above purpose through the following technical solutions: In the first aspect, an embodiment of the present application provides a data enhanced encryption method based on AES, including: Receiving the plaintext data to be encrypted and the password provided by the user; Derive a first key and a second key from the password and a randomly generated salt value using a key derivation function; the first key is the master key, and the second key is the HMAC key for integrity verification; Randomly generate an initialization vector, and encrypt the plaintext data with the first key using the AES encryption mode to obtain the encrypted ciphertext data; Perform a message authentication code calculation on the ciphertext data, the initialization vector, and the salt value with the second key to generate an HMAC verification value; Combine the salt value, the initialization vector, the ciphertext data, and the HMAC verification value into the finally output encrypted data packet.
[0008] In an optional implementation manner, the receiving the plaintext data to be encrypted and the password provided by the user includes: Obtain the plaintext data to be encrypted based on the text or file to be encrypted; Receive the password string input by the user for generating the encryption key.
[0009] In an optional implementation manner, the deriving a first key and a second key from the password and a randomly generated salt value using a key derivation function includes: Use the PBKDF2 function or the Argon2 function, with the password and the randomly generated salt value as inputs, and repeatedly execute the hash algorithm under the specified number of iterations to derive the first key and the second key.
[0010] In an optional implementation manner, the randomly generating an initialization vector, and encrypting the plaintext data with the first key using the AES encryption mode to obtain the encrypted ciphertext data includes: Start the encryption operation and randomly generate an initialization vector; Encrypt the plaintext data with the first key using the CBC encryption mode or the GCM encryption mode to obtain the encrypted ciphertext data.
[0011] In an optional implementation manner, the performing a message authentication code calculation on the ciphertext data, the initialization vector, and the salt value with the second key to generate an HMAC verification value includes: Concatenate the ciphertext data, the initialization vector, and the salt value to generate concatenated data; Use the second key as the authentication key, and perform a hash operation on the concatenated data using the SHA-256 hash algorithm to generate an HMAC verification value.
[0012] In an optional implementation manner, the combining the salt value, the initialization vector, the ciphertext data, and the HMAC verification value into the finally output encrypted data packet includes: Combine the salt value, initialization vector, ciphertext data, and HMAC check value to generate an encrypted data packet in the following format: [Salt||IV||Ciphertext||HMAC]; where Salt is the salt value, IV is the initialization vector, Ciphertext is the ciphertext data, and HMAC is the HMAC check value.
[0013] In an optional embodiment, the specified number of iterations is not less than 100,000 times; the salt value and the initialization vector are generated by a secure random number generator, and both have a length of 16 bytes.
[0014] In a second aspect, an embodiment of the present application further provides a data enhanced encryption system based on AES, including: A data receiving module, configured to receive the plaintext data to be encrypted and the password provided by the user; A key generation module, configured to derive a first key and a second key from the password and the randomly generated salt value by using a key derivation function; the first key is the main key, and the second key is the HMAC key for integrity check; A data encryption module, configured to randomly generate an initialization vector, and encrypt the plaintext data by using the AES encryption mode with the first key to obtain the encrypted ciphertext data; A check value calculation module, configured to perform a message authentication code calculation on the ciphertext data, the initialization vector, and the salt value by using the second key to generate an HMAC check value; A data combination output module, configured to combine the salt value, the initialization vector, the ciphertext data, and the HMAC check value into a final output encrypted data packet.
[0015] In a third aspect, an embodiment of the present application further provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, and when the processor executes the program, the steps of the data enhanced encryption method based on AES as described in any one of the above are implemented.
[0016] In a fourth aspect, an embodiment of the present application further provides a storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the data enhanced encryption method based on AES as described in any one of the above are implemented.
[0017] From the above technical solutions, it can be seen that the present invention has the following advantages: In the AES-based data enhanced encryption method provided by this application, the master key and HMAC key are derived from the user password and random salt value by using a key derivation function. The plaintext data is encrypted by combining a random initialization vector and an AES encryption mode, and an HMAC check value is generated for integrity verification. Finally, the salt value, initialization vector, ciphertext data, and HMAC check value are combined into an encrypted data packet for output, effectively enhancing the security and integrity of data encryption. Through a high number of iterations, secure random number generation, and specific encryption and hashing algorithms, the ability to resist brute force attacks and tampering is improved.
[0018] This application uses key derivation functions such as PBKDF2 or Argon2 to generate high-strength encryption keys from the passwords provided by users. Compared with directly using passwords as keys, this approach significantly increases the difficulty of brute force attacks.
[0019] Each encryption operation in this application generates a new random IV and salt value, effectively preventing replay attacks. Even the same plaintext and password will produce different ciphertexts, thus avoiding the risk of pattern leakage.
[0020] This application integrates HMAC verification to ensure that the data has not been tampered with during transmission and can verify the authenticity of the data source. By calculating the HMAC check value after encryption, the receiving party can verify the integrity and authenticity of the data before decryption.
[0021] This application provides a flexible and easy-to-implement framework that can adjust details such as encryption modes and key derivation parameters according to specific requirements. Whether it is a financial institution, a medical institution, or other professional institutions, they can customize appropriate encryption solutions according to their own needs. Brief Description of the Drawings
[0022] In order to more clearly illustrate the technical solutions of the present invention, the drawings required for description will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0023] Figure 1 It is a schematic flowchart of the AES-based data enhanced encryption method provided by this application.
[0024] Figure 2 It is a schematic structural diagram of the AES-based data enhanced encryption system provided by this application.
[0025] Figure 3 It is a schematic structural diagram of the electronic device provided by this application. Detailed Embodiments
[0026] In the following detailed description of the specific steps of the AES-based data enhancement encryption method, various embodiments of the present disclosure will be more comprehensively described. The present disclosure may have various embodiments, and adjustments and changes can be made therein. However, it should be understood that there is no intention to limit the various embodiments of the present disclosure to the specific embodiments disclosed herein, but the present disclosure should be understood to cover all adjustments, equivalents, and / or alternative solutions that fall within the spirit and scope of the various embodiments of the present disclosure.
[0027] To facilitate a clear description of the technical solutions of the embodiments of the present application, the following briefly introduces some terms and technologies involved in the embodiments of the present application: PBKDF2 (Password-Based Key Derivation Function 2): PBKDF2 is a password-based key derivation function that generates a fixed-length key by repeatedly hashing the input password and salt value. It is commonly used to generate high-strength encryption keys, especially in situations where high security is required.
[0028] Argon2: Argon2 is another widely recognized key derivation function, especially suitable for application scenarios that require high memory consumption. Compared with PBKDF2, Argon2 introduces a memory-hard property in the calculation process, making hardware acceleration attacks such as those using GPUs and ASICs more difficult.
[0029] HMAC (Hash-based Message Authentication Code): HMAC is a hash-based message authentication code used to verify the integrity and authenticity of data. By appending the HMAC check value after encrypting the data, it can effectively prevent man-in-the-middle attacks and data tampering.
[0030] AES-GCM (Galois / Counter Mode): AES-GCM is an encryption mode that provides both encryption and authentication functions. It has higher efficiency compared to the CBC mode, especially when hardware support is available. It can significantly improve the speed of encryption and decryption while ensuring the integrity and authenticity of the data.
[0031] ECB (Electronic Codebook) mode vs. CBC (Cipher Block Chaining) mode: The ECB mode is a simple encryption mode, but it has obvious security risks. The same plaintext block will generate the same ciphertext block, which is prone to mode leakage. In contrast, the CBC mode effectively avoids the risk of mode leakage by introducing an initialization vector (IV).
[0032] In the following, the term "comprising" or "may comprise" that can be used in various embodiments of the present disclosure indicates the presence of the disclosed functions, operations, or elements, and does not limit the addition of one or more functions, operations, or elements. Further, as used in various embodiments of the present disclosure, the terms "comprising", "having" and their cognates are only intended to indicate a specific feature, number, step, operation, element, component, or combination of the foregoing items, and should not be construed as precluding the existence or addition of one or more other features, numbers, steps, operations, elements, components, or combinations of the foregoing items.
[0033] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0034] Please refer to Figure 1 The following is a flowchart of a method for data enhancement encryption based on AES in a specific embodiment. The method includes: S1: Receive the plaintext data to be encrypted and the password provided by the user.
[0035] In a specific implementation, the plaintext data to be encrypted is obtained based on the text or file to be encrypted; at the same time, a password string input by the user is received for generating an encryption key. Among them, the password input undergoes preprocessing, including removing spaces, converting the case uniformly, or performing hash preprocessing.
[0036] Exemplarily, in this step, the following data is first obtained: The plaintext to be encrypted, plaintext: can be any form of data, such as text, file, etc.
[0037] The password provided by the user, password: the password string input by the user for generating an encryption key.
[0038] S2: Derive a first key and a second key from the password and a randomly generated salt value by using a key derivation function; the first key is the main key, and the second key is the HMAC key for integrity verification.
[0039] In the specific implementation, the PBKDF2 function or the Argon2 function is used. With the password and the randomly generated salt value as inputs, by repeatedly executing the hashing algorithm at the specified number of iterations, the first key and the second key are derived. Among them, the specified number of iterations is not less than 100,000 times; the salt value is generated by a secure random number generator and has a length of 16 bytes.
[0040] Exemplarily, two keys are derived from the password and the randomly generated salt value using PBKDF2 or Argon2: Encryption key: used for AES encryption.
[0041] HMAC key: used for generating a message authentication code.
[0042] Among them, PBKDF2 is a password-based key derivation function that generates a fixed-length key by repeatedly hashing the input password and salt value. Its main parameters include: a) Number of iterations: Increasing the number of iterations can significantly increase the difficulty of brute-force cracking.
[0043] b) Salt value: Random data used each time a key is generated, ensuring that different keys are generated even for the same password.
[0044] c) Hashing algorithm: Usually, the SHA-256 or a higher-strength hashing algorithm is used.
[0045] In this step, at least 100,000 iterations are used, combined with a randomly generated 16-byte salt value. This not only increases the computational complexity but also makes rainbow table attacks almost impossible.
[0046] In addition, Argon2 is another widely recognized key derivation function, especially suitable for application scenarios that require high memory consumption. Compared with PBKDF2, Argon2 introduces a memory-hard characteristic in the calculation process, making hardware acceleration attacks such as those using GPUs and ASICs more difficult.
[0047] In this method, PBKDF2 or Argon2 can be selected according to specific performance requirements. For resource-constrained environments (such as mobile devices or embedded systems), PBKDF2 may be a better choice; while for server-side or high-performance applications, Argon2 provides higher security.
[0048] It should be noted that in this method, the main function of the salt value is to prevent rainbow table attacks and ensure that different ciphertexts are generated even for the same plaintext and password. Each encryption operation generates a new random salt value, which is not only used for key derivation but also stored as part of the metadata in the final encrypted data. In this way, the key can be regenerated by extracting the salt value during decryption.
[0049] The process of generating a random salt value is very simple but crucial. The following is a sample code snippet showing how to generate a 16-byte random salt value using the os.urandom() function in Python: import os def generate_random_salt(): return os.urandom(16) # Generate a 16-byte random salt value In practical applications, it is necessary to ensure the randomness and uniqueness of the salt value. Any behavior of reusing the salt value may lead to security vulnerabilities, so it is recommended to generate a new salt value for each encryption operation.
[0050] S3: Randomly generate an initialization vector and encrypt the plaintext data with the first key using the AES encryption mode to obtain the encrypted ciphertext data.
[0051] In the specific implementation, first start the encryption operation and generate an initialization vector of 16 bytes in length through a secure random number generator. Then, encrypt the plaintext data with the first key using the CBC encryption mode or the GCM encryption mode to obtain the encrypted ciphertext data.
[0052] It should be noted that in this method, the initialization vector (IV) is an important part of the AES encryption mode, especially in the CBC (Cipher Block Chaining) mode. The main function of the IV is to ensure that different ciphertexts are generated even for the same plaintext and key combination, thus preventing pattern leakage and replay attacks.
[0053] In this method, a new random IV is generated for each encryption operation. This IV is not only used in the encryption process but also stored as part of the metadata in the final encrypted data. In this way, the data can be correctly decrypted by extracting the IV during decryption.
[0054] The process of generating a random IV is similar to that of generating a salt value. The following is a sample code snippet showing how to generate a 16-byte random IV using the os.urandom() function in Python: def generate_random_iv(): return os.urandom(16) # Generate a 16-byte random IV It should be noted that the IV must be kept random and unique. Any behavior of reusing the IV may lead to serious security issues. Therefore, it is recommended to generate a new IV for each encryption operation.
[0055] S4: Perform message authentication code calculation on the ciphertext data, initialization vector, and salt value using the second key to generate an HMAC check value.
[0056] In the specific implementation, first concatenate the ciphertext data, initialization vector, and salt value to generate concatenated data; then use the second key as the authentication key and perform a hashing operation on the concatenated data using the SHA-256 hashing algorithm to generate an HMAC check value.
[0057] Exemplarily, the message authentication code (HMAC) is an important mechanism in this method to ensure data integrity and authenticity. By adding an HMAC check value after encrypting the data, it can effectively prevent man-in-the-middle attacks and data tampering.
[0058] In this step, the calculation process of HMAC is as follows: Use a key derivation function to generate two keys: an encryption key and an HMAC key.
[0059] Perform a hashing operation on the encrypted data, IV, and salt value to generate an HMAC check value.
[0060] Store the HMAC check value as part of the metadata in the final encrypted data.
[0061] S5: Combine the salt value, initialization vector, ciphertext data, and HMAC check value into the final output encrypted data packet.
[0062] In the specific implementation, the format of the encrypted data packet is as follows: [Salt (16 bytes) || IV (16 bytes) || Ciphertext (n bytes) || HMAC (32 bytes)]; Where Salt is a randomly generated salt value, IV is the initialization vector, Ciphertext is the ciphertext after AES encryption, and HMAC is the HMAC-SHA256 check value.
[0063] Exemplarily, the output format design of this step aims to ensure that all necessary metadata is properly saved so that the original data can be correctly restored during decryption. The output format should contain the following information: Salt value: Random data used for key derivation.
[0064] Initialization Vector (IV): Random data used in the encryption process.
[0065] Encrypted data: The ciphertext after AES encryption.
[0066] HMAC check value: The check value used to verify data integrity and authenticity.
[0067] The following is an example output format: encrypted_data = salt || iv || ciphertext || hmac_value This format is not only concise and clear but also easy to parse and process. To further optimize the output format, compression or encoding of each part can be considered to reduce the overhead of transmission and storage.
[0068] In addition, it should be particularly noted that based on the above data-enhanced encryption method, the present invention also discloses a data decryption process.
[0069] The decryption process includes the following steps: a) Extract Salt, IV, Ciphertext, and HMAC from the encrypted data packet; b) Derive the master key and HMAC key again using the same password and Salt; c) Recalculate the HMAC for the extracted Ciphertext, IV, and Salt and compare it with the original HMAC; d) If the HMAC check passes, decrypt the Ciphertext using the master key and IV to obtain the original plaintext; e) Otherwise, throw an exception and terminate the decryption operation.
[0070] In this embodiment, by deriving the key from the user password and random salt value, randomly generating the initialization vector, encrypting the plaintext data using AES, generating the HMAC check value in combination with the message authentication code, and combining the salt value, initialization vector, ciphertext data, and HMAC check value into an encrypted data packet, the security of key derivation can be enhanced, the confidentiality of encrypted data can be guaranteed, the data integrity can be ensured, and the security and reliability of the overall encryption scheme can be improved by specifying the number of iterations, secure random number generator, etc.
[0071] As Figure 2 shown, the following is an embodiment of the AES-based data-enhanced encryption system provided by the present disclosure. This system belongs to the same inventive concept as the AES-based data-enhanced encryption methods of the above embodiments. For the details not described in detail in the embodiment of the AES-based data-enhanced encryption system, reference can be made to the embodiments of the above AES-based data-enhanced encryption methods.
[0072] A data enhancement encryption system based on AES, comprising: a data receiving module, a key generation module, a data encryption module, a check value calculation module, and a data combination output module.
[0073] The data receiving module is used to receive the plaintext data to be encrypted and the password provided by the user.
[0074] The key generation module is used to derive a first key and a second key from the password and a randomly generated salt value by using a key derivation function; the first key is the main key, and the second key is the HMAC key for integrity verification.
[0075] The data encryption module is used to randomly generate an initialization vector and encrypt the plaintext data with the first key by using the AES encryption mode to obtain the encrypted ciphertext data.
[0076] The check value calculation module is used to perform a message authentication code calculation on the ciphertext data, the initialization vector, and the salt value by using the second key to generate an HMAC check value.
[0077] The data combination output module is used to combine the salt value, the initialization vector, the ciphertext data, and the HMAC check value into an encrypted data packet for final output.
[0078] The data enhancement encryption system based on AES provided in this embodiment derives keys from the user password and a random salt value, encrypts the plaintext data by using the AES encryption mode, calculates the check value for the ciphertext data, the initialization vector, and the salt value by using the HMAC key, and finally combines them into an encrypted data packet. This system enhances the security and integrity of data encryption, effectively resists brute force cracking through the random salt value and multiple iterations of key derivation, the HMAC check value ensures that the data has not been tampered with, and at the same time supports multiple encryption modes and hash algorithms, improving the flexibility and reliability of encryption.
[0079] Figure 3 A schematic diagram of the hardware structure of an electronic device for implementing various embodiments of the present invention.
[0080] The data enhancement and encryption method based on AES provided by the embodiments of this application can be applied to electronic devices. Those skilled in the art can understand that the structure of the electronic devices involved in the embodiments of the present invention does not constitute a limitation on the electronic devices. The electronic devices may include more or fewer components than those shown in the figures, or combine certain components, or have different component arrangements. In the embodiments of the present invention, the electronic devices include, but are not limited to, laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic devices can also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the embodiments of this application described herein and / or claimed.
[0081] The electronic device may include a processor, an external memory interface, an internal memory, a universal serial bus (USB) interface, a charging management module, a power management module, a battery, a wireless communication module, an audio module, a speaker, a microphone, a sensor module, keys, a camera, a display screen, and a SIM card interface, etc.
[0082] The processor may include one or more processing units. For example, the processor may include a central processing unit (CPU), etc., an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a memory, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Among them, different processing units may be independent devices or integrated in one or more processors.
[0083] Among them, the processor may be the nerve center and command center of the electronic device. The controller may generate operation control signals according to the instruction operation code and timing signals to complete the control of fetching instructions and executing instructions.
[0084] A memory can also be set in the processor for storing instructions and data. In some embodiments, the memory in the processor is a cache memory. This memory can save the instructions or data that the processor has just used or recycled. If the processor needs to use the instruction or data again, it can directly call it from this memory. This avoids repeated accesses, reduces the waiting time of the processor, and thus improves the system efficiency.
[0085] The external memory interface can be used to connect an external memory card, such as a MicroSD card, to implement the storage capacity expansion of the electronic device. The external memory card communicates with the processor through the external memory interface to implement the data storage function. For example, files such as music and videos are saved in the external memory card.
[0086] The internal memory can be used to store computer-executable program codes, and the computer-executable program codes include instructions. The processor executes various functional applications and data processing of the electronic device by running the instructions stored in the internal memory. The internal memory can include a program storage area and a data storage area. The internal memory can include a high-speed random access memory and can also include a non-volatile memory, such as at least one magnetic disk storage device, a flash memory device, a universal flash storage (UFS), etc.
[0087] The wireless communication function of the electronic device can be implemented through an antenna, a wireless communication module, a modulation and demodulation processor, a baseband processor, etc.
[0088] The wireless communication module can provide wireless communication solutions applied to the electronic device, including wireless local area networks (WLANs) (such as wireless fidelity (Wi-Fi) networks), Bluetooth (BT), global navigation satellite systems (GNSSs), frequency modulation (FM), near field communication (NFC), infrared technology (IR), etc.
[0089] The electronic device can implement audio functions, etc. through an audio module, a speaker, a receiver, a microphone, a headphone interface, an application processor, etc.
[0090] The electronic device can implement a shooting function through an ISP, a camera, a video codec, a GPU, a display screen, an application processor, etc.
[0091] An electronic device can implement a display function through a GPU, a display screen, an application processor, etc.
[0092] The GPU is a microprocessor for image processing, connecting the display screen and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. The processor may include one or more GPUs, which execute program instructions to generate or change display information.
[0093] The display screen is used to display images, videos, etc. The display screen includes a display panel.
[0094] The above-mentioned electronic device implements the AES-based data enhancement encryption method of the present application by deriving a master key and an HMAC key for integrity verification from the password provided by the user and a randomly generated salt value, randomly generating an initialization vector, encrypting the plaintext data using the AES encryption mode, performing a message authentication code calculation on the ciphertext data, the initialization vector, and the salt value through the HMAC key to generate a verification value, and finally combining this information into an encrypted data packet, achieving the beneficial effects of enhancing the security of the encryption process, protecting the confidentiality of the encrypted data, and ensuring the integrity of the data.
[0095] In the storage medium provided by the present application, there is a program product capable of implementing the AES-based data enhancement encryption method.
[0096] The AES-based data enhancement encryption method includes: Receiving the plaintext data to be encrypted and the password provided by the user; Deriving a first key and a second key from the password and the randomly generated salt value by using a key derivation function; the first key is the master key, and the second key is the HMAC key for integrity verification; Randomly generating an initialization vector, and encrypting the plaintext data through the first key using the AES encryption mode to obtain the encrypted ciphertext data; Performing a message authentication code calculation on the ciphertext data, the initialization vector, and the salt value through the second key to generate an HMAC verification value; Combining the salt value, the initialization vector, the ciphertext data, and the HMAC verification value into the finally output encrypted data packet. In some possible implementation manners, the AES-based data enhancement encryption method of the present disclosure may be implemented in the form of a program product, which includes program code. When the program product runs on a terminal device, the program code is used to cause the terminal device to execute the steps according to various exemplary embodiments of the present disclosure described in the "Exemplary Method" section of this specification.
[0097] The storage medium of the present disclosure may adopt any combination of one or more readable media. The readable media may be a readable signal medium or a readable storage medium. The readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (non-exhaustive list) of the readable storage medium include: an electrical connection having one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.
[0098] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present invention. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but rather to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A data enhancement encryption method based on AES, characterized in that It includes: Receiving the plaintext data to be encrypted and the password provided by the user; Deriving a first key and a second key from the password and a randomly generated salt value by using a key derivation function; The first key is the main key, and the second key is the HMAC key for integrity verification; Randomly generating an initialization vector, and encrypting the plaintext data with the first key using the AES encryption mode to obtain the encrypted ciphertext data; Performing a message authentication code calculation on the ciphertext data, the initialization vector, and the salt value with the second key to generate an HMAC verification value; Combining the salt value, the initialization vector, the ciphertext data, and the HMAC verification value into the finally output encrypted data packet.
2. The data enhancement encryption method based on AES according to claim 1, wherein The receiving the plaintext data to be encrypted and the password provided by the user includes: Obtaining the plaintext data to be encrypted based on the text or file to be encrypted; Receiving the password string input by the user for generating the encryption key.
3. The data enhancement encryption method based on AES according to claim 1, characterized in that, The deriving a first key and a second key from the password and a randomly generated salt value by using a key derivation function includes: Using the PBKDF2 function or the Argon2 function, taking the password and the randomly generated salt value as inputs, and deriving the first key and the second key by repeatedly executing the hash algorithm under the specified number of iterations.
4. The data enhancement encryption method based on AES according to claim 3, characterized in that The randomly generating an initialization vector, and encrypting the plaintext data with the first key using the AES encryption mode to obtain the encrypted ciphertext data includes: Starting the encryption operation and randomly generating an initialization vector; Encrypting the plaintext data with the first key using the CBC encryption mode or the GCM encryption mode to obtain the encrypted ciphertext data.
5. The data enhancement encryption method based on AES according to claim 4, wherein The performing a message authentication code calculation on the ciphertext data, the initialization vector, and the salt value with the second key to generate an HMAC verification value includes: Concatenating the ciphertext data, the initialization vector, and the salt value to generate concatenated data; Using the second key as the authentication key and performing a hash operation on the concatenated data with the SHA-256 hash algorithm to generate the HMAC verification value.
6. The data enhancement encryption method based on AES according to claim 5, characterized in that, The combining the salt value, the initialization vector, the ciphertext data, and the HMAC verification value into the finally output encrypted data packet includes: Combining the salt value, the initialization vector, the ciphertext data, and the HMAC verification value to generate an encrypted data packet in the following format: [Salt||IV||Ciphertext||HMAC]; where, Salt is the salt value, IV is the initialization vector, Ciphertext is the ciphertext data, and HMAC is the HMAC verification value.
7. The data enhancement encryption method based on AES according to claim 3, wherein The specified number of iterations is not less than 100,000 times; the salt value and the initialization vector are generated by a secure random number generator and both have a length of 16 bytes.
8. A data enhancement and encryption system based on AES, characterized in that, The system adopts the AES-based data enhancement encryption method as described in any one of claims 1 to 7; The system includes: A data receiving module for receiving the plaintext data to be encrypted and the password provided by the user; A key generation module for deriving a first key and a second key from the password and a randomly generated salt value by using a key derivation function; the first key is the main key, and the second key is the HMAC key for integrity verification; A data encryption module, configured to randomly generate an initialization vector and encrypt plaintext data with a first key using an AES encryption mode to obtain encrypted ciphertext data; A check value calculation module, configured to perform a message authentication code calculation on the ciphertext data, the initialization vector, and a salt value with a second key to generate an HMAC check value; A data combination output module, configured to combine the salt value, the initialization vector, the ciphertext data, and the HMAC check value into an encrypted data packet for final output.
9. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the steps of the AES-based data enhanced encryption method according to any one of claims 1 to 7.
10. A storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the AES-based data enhanced encryption method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Password protecting method and device
CN106656476A
Method of performing cryptographic operation, corresponding processing device and computer program product
CN115603892A
System and method for implementing cryptography in a storage system
US20180137293A1
User password management method and server
WO2018024056A1
Cited By
Communication data encryption method for automobile information security
CN120896753A
Communication data encryption method for automotive information security
CN120896753B