Sensitive data security storage method based on image information hiding

By combining hierarchical linear secret sharing and image information hiding technology, the encryption key EK is decomposed into the primary secret share and the secondary secret share, which solves the problem of key management and realizes high security of sensitive data and convenient operation of sensitive data.

CN120387177APending Publication Date: 2025-07-29FUJIAN NORCA TECH +1
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510464228.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-14
Publication Date
2025-07-29

AI Technical Summary

Technical Problem

In the prior art, the key management of sensitive data has the problem that the key cannot be recovered during device replacement or server attack, resulting in limited application scenarios and insufficient security.

Method used

The hierarchical linear secret sharing technology is combined with image information hiding technology to decompose the encryption key EK into the main secret share and multiple secondary secret shares. The main secret share is hidden in the image, and the secondary secret share is stored in the user equipment in the system. The password generation key kk is generated based on the password password entered by the user, and the user can extract information from the image.

Benefits of technology

Improves the security and operational convenience of sensitive data storage. Users do not need to rely on specific devices. They only need to enter the correct password to recover the key, expanding the application scenario and ensuring that the encryption key cannot be obtained even if all users conspire.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120387177A_ABST
    Figure CN120387177A_ABST
Patent Text Reader

Abstract

The invention discloses a sensitive data security storage method based on image information hiding, which comprises the following steps: encrypting information M to be hidden by using a key K to obtain a ciphertext C; encrypting the key K to obtain an encryption key EK, decomposing the encryption key EK into a master secret share and a recombined secret share, and decomposing the recombined secret share into n-1 secondary secret shares; hiding the master secret share, the ciphertext C and a randomly generated random value R in the image; and respectively storing the n-1 second-level secret shares and the key expiration time T at n-1 users in the system. According to the method, the hierarchical linear secret sharing technology and the image information hiding technology are combined, the security of sensitive data storage can be improved, a user can extract information from the image only by using a password, the method is not limited by certain specific equipment, and the operation convenience is high.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of data security, and particularly relates to a method for securely storing sensitive data based on image information hiding. Background Art

[0002] In this era of rapid development of information technology, the risk of data leakage is everywhere, and there is also a potential threat of being deeply analyzed by big data. In many cases, it is necessary to securely store some sensitive information involved in work and extract it when needed. However, the existing technical solutions have problems in key management, resulting in limited application scenarios and unable to meet actual needs. Specifically: when the key is stored locally, the key cannot be restored after resetting or replacing the device, resulting in inability to decrypt; when the key is stored on the server, there is a security risk. Once the server is attacked, the key will be completely decrypted. Summary of the Invention

[0003] The purpose of the present invention is to provide a method for securely storing sensitive data based on image information hiding, which improves the security of sensitive data storage, and users only need to use a password to extract information from the image, without being limited to a specific device, and has high operation convenience.

[0004] To achieve the above object, the solution of the present invention is:

[0005] A method for securely storing sensitive data based on image information hiding, including,

[0006] Using a key K to encrypt the information M to be hidden to obtain a ciphertext C;

[0007] Encrypting the key K to obtain an encrypted key EK, decomposing the encrypted key EK into 1 main secret share and 1 reconstruction secret share, and decomposing the reconstruction secret share into n - 1 secondary secret shares;

[0008] Hiding the main secret share, the ciphertext C and a randomly generated random value R in the image; storing the n - 1 secondary secret shares and the key expiration time T at n - 1 users in the system respectively.

[0009] Wherein, using a key K to encrypt the information M to be hidden to obtain a ciphertext C includes,

[0010] Randomly generating a 256 - bit key K;

[0011] Using the key K to encrypt the information M to be hidden to obtain a ciphertext C, and the length of the ciphertext C is c bits.

[0012] Wherein, encrypting the key K to obtain an encrypted key EK includes,

[0013] Use the password to generate the key kk, encrypt the key K with kk to obtain the encrypted key EK; among them, the password generation key kk is generated by the random value R and the binary form P of the password entered by the user, kk = H 256 (P||R), H 256 is the SM3 hashing algorithm with an output of 256 bits.

[0014] Among them, decompose the encrypted key EK into 1 main secret share and 1 recombination secret share, and decompose the recombination secret share into n - 1 secondary secret shares, including,

[0015] Convert the binary form of the encrypted key EK to a numerical form;

[0016] Arbitrarily take a random number a1, let a0 = EK, construct the polynomial f(x) = a0 + a1x, arbitrarily take 2 numbers x1, x2 ∈ Z p , where p is a large prime number, substitute them into the polynomial to calculate f(x1), f(x2) respectively, and obtain 2 first-level secret shares, namely the main secret share EK1 = (x1, f(x1)) and the recombination secret share EK2 = (x2, f(x2));

[0017] Arbitrarily take random numbers v1, v2,..., v t-2 ∈Z p , let v0 = f(x2), construct the polynomial g(x) = v0 + v1x + v2x 2 +...+ v t-2 x t-2 , arbitrarily take n - 1 numbers y1, y2,..., y n-1 ∈Z p Substitute them into the polynomial to calculate g(y1), g(y2),..., g(y n-1 ), and obtain n - 1 secondary secret shares EK 2,1 =(y1, g(y1)),..., EK 2,n-1 =(y n-1 , g(y n-1 ));

[0018] Convert the main secret share EK1 = (x1, f(x1)) to the 256-bit binary form x1||f(x1), where x1 and f(x1) each occupy 128 bits, to obtain the binary form of the main secret share.

[0019] Among them, hide the main secret share, the ciphertext C, and the randomly generated random value R in the image, including,

[0020] Concatenate the ciphertext C, the randomly generated random value R, and the binary form x1||f(x1) of the master secret share to obtain x1||f(x1)||C||R, and sequentially divide it into units of 16 bits to convert it into a series of 16-dimensional binary column vectors cr to be hidden. i , where c is the length of the ciphertext C;

[0021] Loop through the order of the sub-blocks to hide the column vectors cr to be hidden i in different sub-blocks of the image to be hidden; including,

[0022] Entropy decode the image to be hidden to obtain a sequence of normalized quantization coefficients in the 8×8 sub-block DCT domain. Select the least significant bits of the first 16 low-frequency quantization coefficients from the i-th sub-block and arrange them in the original order to obtain a 16-dimensional binary host data column vector α to be embedded. i ;

[0023] Define an 8th-order matrix

[0024] Calculate a 16-dimensional binary column vector where the matrix multiplication is defined as A is an 8*16-dimensional matrix, β is a 16-dimensional column vector, a i is the i-th column of matrix A, and β i is the element of the i-th row of column vector β;

[0025] According to the characteristics of the matrix, obtain a 16-dimensional binary column vector x i , such that the binary column vector d i = Ux i ; Calculate the embedded 16-dimensional host information column vector

[0026] After directly replacing the least significant bit of the corresponding quantization coefficient with the modified host information, perform entropy coding on the 8×8 DCT domain quantization coefficients containing the hidden information to obtain the embedded image.

[0027] Among them, save the n - 1 secondary secret shares and the key expiration time T in the system at n - 1 users respectively. It also includes,

[0028] The n - 1 users in the system respectively save the received secondary secret shares and the key expiration time locally;

[0029] If the current time exceeds the key expiration time, or a secret share deletion request from the hidden information owner is received, other user devices will delete the local secondary secret shares.

[0030] Among them, it also includes extracting the information M to be hidden from the image; including,

[0031] extracting the main secret share, ciphertext C, and random value R from the image; obtaining t - 1 secondary secret shares from any t - 1 users in the system; where t = [0.8v], [0.8v] is the ceiling function, and v is the average monthly daily active user;

[0032] recovering the reconstructed secret share based on the t - 1 secondary secret shares, and recovering the encryption key EK using the main secret share and the reconstructed secret share;

[0033] decrypting the encryption key EK to obtain the key K;

[0034] using the key K to decrypt the ciphertext C to obtain the hidden information M.

[0035] Among them, decrypting the encryption key EK to obtain the key K includes,

[0036] using the password - generated key kk to decrypt the encryption key EK to obtain the key K; where the password - generated key kk = H 256 (P||R), H 256 is the SM3 hashing algorithm with an output of 256 bits.

[0037] Among them, obtaining t - 1 secondary secret shares from any t - 1 users in the system also includes,

[0038] obtaining t - 1 secondary secret shares from any t - 1 users in the system. If the secondary secret share reaches the key expiration time T on other user devices and t - 1 secondary secret shares cannot be obtained, the key recovery fails.

[0039] Among them, it also includes that after extracting the hidden information M, if the information no longer needs to be securely stored, a secret share deletion request is sent to other users in the system, and the secondary secret share used to recover the current message decryption key is immediately deleted.

[0040] After adopting the above - mentioned scheme, the present invention combines the hierarchical linear secret sharing technology with the image information hiding technology to securely store sensitive data during work. The beneficial effects of the present invention are reflected in:

[0041] (1) The present invention divides the encryption key according to the number of users in the system, hides the master secret share in an image, and each user obtains a different secondary secret share. Only by obtaining the master secret share and a certain number of secondary secret shares can the encryption key be correctly restored. Since the master secret share is hidden in the image, even if all users collude, they cannot obtain the encryption key using the secondary secret shares stored by themselves, ensuring the security of sensitive information storage.

[0042] (2) The password generation key in the present invention is generated based on the password entered by the user. Therefore, as long as the user has the correct password, the key can be restored from the encryption key without relying on the key information stored on the device, which is convenient to operate and expands the application scenarios. Description of the Drawings

[0043] Figure 1 is the flowchart of the data storage and key distribution process in the embodiment of the present invention;

[0044] Figure 2 is the flowchart of the key restoration and data extraction process in the embodiment of the present invention;

[0045] Figure 3 is the flowchart of hiding the vector to be hidden in a picture in the embodiment of the present invention. Detailed Embodiments

[0046] The technical solutions and beneficial effects of the present invention will be described in detail below in conjunction with the drawings and specific embodiments.

[0047] The embodiment of the present invention provides a method for secure storage of sensitive data based on image information hiding, including the following processes:

[0048] I. Data storage and key distribution process, which can be referred to Figure 1 ;

[0049] 1. The user device randomly generates a 256-bit key K and a random value R.

[0050] 2. The user device uses the random value R and the binary form P of the password entered by the user to generate a password generation key kk = H 256 (P||R), where H 256 is the SM3 hashing algorithm with an output result of 256 bits.

[0051] 3. The user device uses the key K to perform SM4 encryption on the information M to be hidden, obtains a ciphertext C of c bits, and pads the ciphertext length c to a multiple of 16.

[0052] 4. The user device determines the number of shares t = [0.8v] required for recovery according to the monthly average daily active user value v provided by the server, where [0.8v] is the ceiling function, that is, the integer not less than 0.8v.

[0053] 5. The user device uses the password to generate the key kk to perform SM4 encryption on the key K to obtain the encrypted key EK. The user device converts the binary form of the encrypted key EK into a numerical form and splits it into n shares through hierarchical linear secret sharing, where n is the total number of users in the system minus one. Specifically:

[0054] (1) Arbitrarily take a random number a1, let a0 = EK, construct the polynomial f(x) = a0 + a1x, and arbitrarily take two numbers x1, x2 ∈ Z p , where p is a large prime number, and substitute them into the polynomial to calculate f(x1) and f(x2) respectively to obtain two first-level secret shares, namely the master secret share EK1 = (x1, f(x1)) and the reconstructed secret share EK2 = (x2, f(x2)). (2) Arbitrarily take random numbers v1, v2,..., v t-2 ∈Z p , let v0 = f(x2), construct the polynomial g(x) = v0 + v1x + v2x 2 +...+ v t-2 x t-2 , arbitrarily take n - 1 numbers y1, y2,..., y n-1 ∈Z p and substitute them into the polynomial to calculate g(y1), g(y2),..., g(y n-1 ), to obtain n - 1 second-level secret shares EK 2,1 = (y1, g(y1)),..., EK 2,n-1 = (y n-1 , g(y n-1 ))).

[0055] 6. The user sets the key expiration time T. The user device sends the second-level secret share and the key expiration time (EK 2,i , T), i ∈ [1, n - 1] to n - 1 other users in the system. Each user obtains a different second-level secret share and the same key expiration time T.

[0056] 7. The user device converts the master secret share EK1 = (x1, f(x1)) into a 256-bit binary form x1||f(x1), where x1 and f(x1) each occupy 128 bits, and determines whether the embeddable data volume of the picture is greater than or equal to c + 256 * 2 bits. Otherwise, it prompts the user that the current content cannot be hidden in this picture and a new picture needs to be replaced.

[0057] 8. The user device concatenates the ciphertext C, the random value R, and the binary form x1||f(x1) of the master secret share as x1||f(x1)||C||R, and sequentially divides it into units of 16 bits to convert it into a series of 16-dimensional binary column vectors cr to be hidden. i , where c is the length of the ciphertext C.

[0058] 9. The user device sequentially and circularly hides the vector cr to be hidden i in different sub-blocks of the picture. Cooperate with Figure 3 as shown, specifically:

[0059] (1) The user device entropy decodes the image to be hidden to obtain a sequence of normalized quantization coefficients in the 8×8 sub-block DCT domain, selects the least significant bits of the first 16 mid-low frequency quantization coefficients from the i-th sub-block, and arranges them in the original order to obtain a 16-dimensional binary column vector α of host data to be embedded. i .

[0060] (2) Define an 8th-order matrix

[0061] (3) Calculate a 16-dimensional binary column vector where the matrix multiplication is defined as A is an 8*16-dimensional matrix, β is a 16-dimensional column vector, a i is the i-th column of matrix A, and β i is the element of the i-th row of column vector β.

[0062] (4) According to the characteristics of the matrix, a 16-dimensional binary column vector x i can be found such that the binary column vector d i = Ux i .

[0063] (5) Calculate the 16-dimensional host information column vector after embedding

[0064] (6) After directly replacing the least significant bits of the corresponding quantization coefficients with the modified host information, entropy encode the quantization coefficients in the 8×8 DCT domain containing the hidden information to obtain the embedded image.

[0065] 10. Other user devices save their respective received secondary secret shares and expiration times (EK 2,i , T) locally.

[0066] 11. If the current time exceeds the expiration time of the secret key, or a secret share deletion request from the secret information owner is received, other user devices will delete the local secondary secret share EK 2,i .

[0067] II. For the key recovery and data extraction process, please refer to Figure 2 ;

[0068] 1. The user device recovers the hidden vector cr from the image i , Specifically:

[0069] (1) The user device decodes the hidden image entropy and obtains the 16-dimensional binary embedded post-host data column vector r i .

[0070] (2) Calculate

[0071] 2. From the binary vector cr i , The concatenation of the ciphertext, random value, and primary secret share x1||f(x1)||C||R is recovered, so as to obtain the ciphertext C, random value R, and primary secret share EK1=(x1,f(x1)).

[0072] 3. The user device obtains the secondary secret shares EK 2,1 ,...,EK 2,t-1 from any t-1 users. If the secondary secret share reaches the expiration time T on other user devices and t-1 secondary secret shares cannot be obtained, the key recovery fails.

[0073] 4. The user device recovers the encryption key EK with the secret share. Specifically:

[0074] (1) According to the secondary secret shares EK 2,1 =(y1,g(y1)),...,EK 2,t-1 =(y t-1 ,g(y t-1 )) to construct the matrix and the vector Recover the vector Obtain the recombined secret share EK2=(x2,v0).

[0075] (2) According to the primary secret shares EK1, EK2, construct the matrix and the vector Recover the vector Obtain the encryption key EK = a0.

[0076] 5. The user device uses the random value R and the binary form P of the password entered by the user to generate the password generation key kk = H256 (P||R).

[0077] 6. The user equipment uses the password-generated key kk to perform SM4 decryption on the encryption key EK to obtain the key K.

[0078] 7. The user equipment uses the key K to perform SM4 decryption on the ciphertext C to obtain the hidden information M.

[0079] 8. After the hidden information M is extracted, if the information no longer needs to be securely stored, the user can actively initiate a secret share deletion request to other users in the system to immediately delete the secondary secret share used to recover the current message key.

[0080] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code. The solutions in the embodiments of the present invention can be implemented in various computer languages. For example, object-oriented programming languages such as Java and interpreted scripting languages such as JavaScript.

[0081] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processors of general-purpose computers, special-purpose computers, embedded processors, or other programmable data processing devices to generate a machine, such that the instructions executed by the processors of the computer or other programmable data processing devices generate means for implementing the specified functions in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0082] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including instruction means that implement the specified functions in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0083] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus, so that a series of operation steps are executed on the computer or other programmable apparatus to produce a computer-implemented process, and thus the instructions executed on the computer or other programmable apparatus provide steps for implementing the functions specified in one process or a plurality of processes and / or blocks Figure 1 one process or a plurality of processes and / or blocks Figure 1 steps for implementing the functions specified in one block or a plurality of blocks.

[0084] Although the preferred embodiments of the present invention have been described, additional changes and modifications can be made by those skilled in the art once they learn the basic creative concept. Therefore, the appended claims are intended to be construed to cover the preferred embodiments as well as all changes and modifications falling within the scope of the present invention.

[0085] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these modifications and variations.

Claims

1. A sensitive data security storage method based on image information hiding, characterized in that: including encrypting the information M to be hidden using the key K to obtain the ciphertext C; encrypting the key K to obtain the encrypted key EK, decomposing the encrypted key EK into 1 primary secret share and 1 reconstruction secret share, and decomposing the reconstruction secret share into n - 1 secondary secret shares; hiding the primary secret share, the ciphertext C and the randomly generated random value R in the image; saving the n - 1 secondary secret shares and the key expiration time T at n - 1 users in the system respectively.

2. The method according to claim 1, wherein: encrypting the information M to be hidden using the key K to obtain the ciphertext C, including randomly generating a 256 - bit key K; encrypting the information M to be hidden using the key K to obtain the ciphertext C, where the length of the ciphertext C is c bits.

3. The method according to claim 1, characterized in that: encrypting the key K to obtain the encrypted key EK, including encrypting the key K using the password - generated key kk to obtain the encrypted key EK; Among them, the password generation key kk is generated from the random value R and the binary form P of the password entered by the user, kk = H 256 (P || R), where H 256 is the SM3 hashing algorithm with an output result of 256 bits.

4. The method according to claim 1, characterized in that: decomposing the encrypted key EK into 1 primary secret share and 1 reconstruction secret share, and decomposing the reconstruction secret share into n - 1 secondary secret shares, including converting the binary form of the encrypted key EK into a numerical form; Randomly select a random number \(a_1\), let \(a_0 = EK\), construct the polynomial \(f(x)=a_0 + a_1x\), and randomly select two numbers \(x_1,x_2\in Z\) p , where \(p\) is a large prime number, substitute them into the polynomial to calculate \(f(x_1)\) and \(f(x_2)\) respectively, and obtain two first-level secret shares, namely the main secret share \(EK_1=(x_1,f(x_1))\) and the reconstructed secret share \(EK_2=(x_2,f(x_2))\); Randomly select random numbers \(v_1, v_2, \ldots, v\) t-2 \(\in \mathbb{Z}\) p , let \(v_0 = f(x_2)\), and construct the polynomial \(g(x)=v_0 + v_1x + v_2x\) 2 +\cdots + v t- ^2x t-2 , randomly select \(n - 1\) numbers \(y_1, y_2, \ldots, y\) n-1 \(\in \mathbb{Z}\) p Substitute them into the polynomial to calculate \(g(y_1), g(y_2), \ldots, g(y\) n-1 \)), and obtain \(n - 1\) second-level secret shares \(EK\) 2,1 =(y_1, g(y_1)), \ldots, EK 2,n-1 =(y n-1 , g(y n-1 )); converting the primary secret share EK1=(x1,f(x1)) into the binary form x1||f(x1) of 256 bits, where x1 and f(x1) each occupy 128 bits, to obtain the binary form of the primary secret share.

5. The method according to claim 1, characterized in that: hiding the primary secret share, the ciphertext C and the randomly generated random value R in the image, including Concatenate the ciphertext C, the randomly generated random value R, and the binary form x1||f(x1) of the master secret share to obtain x1||f(x1)||C||R, and sequentially segment it in units of 16 bits to convert it into a series of 16-dimensional binary column vectors cr to be hidden i , where c is the length of the ciphertext C; Cyclically hide the column vector cr to be hidden according to the order of sub-blocks i in different sub-blocks of the image to be hidden; including Entropy decode the image to be hidden to obtain a sequence of normalized quantization coefficients in the 8×8 sub-block DCT domain. Select the least significant bits of the first 16 mid-low frequency quantization coefficients from the i-th sub-block, and arrange them in the original order to obtain a 16-dimensional binary host data column vector α to be embedded i ; Define order 8 matrix Calculate a 16-dimensional binary column vector The matrix multiplication is defined as A is an 8 * 16 matrix, β is a 16-dimensional column vector, a i is the i-th column of matrix A, β i is the element of the i-th row of column vector β; Obtain a 16-dimensional binary column vector x according to the characteristics of the I / I matrix i , such that the binary column vector d i = Ux i ; Calculate the 16-dimensional host information column vector after embedding after directly replacing the least significant bit of the corresponding quantization coefficient with the modified host information, performing entropy coding on the 8×8 DCT - domain quantization coefficients containing the hidden information to obtain the embedded image.

6. The method according to claim 1, characterized in that: saving the n - 1 secondary secret shares and the key expiration time T at n - 1 users in the system respectively, further including the n - 1 users in the system respectively save the received secondary secret shares and the key expiration time locally; if the current time exceeds the key expiration time, or a secret share deletion request from the hidden information owner is received, other user devices will delete the local secondary secret shares.

7. The method according to claim 1, wherein: further including extracting the information M to be hidden from the image; including extracting the primary secret share, the ciphertext C and the random value R from the image; obtaining t - 1 secondary secret shares from any t - 1 users in the system; where t = [0.8v], [0.8v] is the ceiling function and v is the monthly average number of daily active users; recovering the reconstruction secret share based on the t - 1 secondary secret shares, and recovering the encrypted key EK using the primary secret share and the reconstruction secret share; decrypting the encrypted key EK to obtain the key K; decrypting the ciphertext C using the key K to obtain the hidden information M.

8. The method according to claim 7, wherein: decrypting the encrypted key EK to obtain the key K, including Use the password generation key kk to decrypt the encryption key EK to obtain the key K; among them, use the random value R and the binary form P of the password entered by the user to generate the password generation key kk = H 256 (P||R), where H 256 is the SM3 hashing algorithm with an output result of 256 bits.

9. The method according to claim 7, wherein: obtaining t - 1 secondary secret shares from any t - 1 users in the system, further including obtaining t - 1 secondary secret shares from any t - 1 users in the system. If the secondary secret shares reach the key expiration time T at other user devices and t - 1 secondary secret shares cannot be obtained, the key recovery fails.

10. The method according to claim 7, characterized in that: It further includes that, after the hidden information M is extracted, if the information no longer needs to be securely stored, a secret share deletion request is sent to other users in the system to immediately delete the secondary secret share used to recover the current message decryption key.

Citation Information

Cited By

  • Electronic film management method and system based on multi-cloud collaboration and national secret security

    CN121098874A