Data encryption and decryption method and related equipment
By generating models based on encryption strategies and using environmentally-aware data-driven intelligent encryption and decryption methods, the problem of traditional encryption and decryption algorithms struggling to balance security and efficiency in the Internet of Things, the Internet of Vehicles, and cloud storage is solved. This approach dynamically responds to modern threats and improves data security and encryption efficiency.
Patent Information
- Application Number
- CN202511162971.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-19
- Publication Date
- 2025-11-04
AI Technical Summary
Traditional encryption and decryption algorithms struggle to balance data security and encryption efficiency in IoT, vehicle-to-everything (V2X) and cloud storage scenarios, and are unable to dynamically respond to modern advanced threats such as quantum computing and automated real-time attacks.
The encryption strategy generation model is trained through reinforcement learning and generative adversarial networks to dynamically determine the encryption algorithm, key information, and key distribution path. Combined with environmental awareness data and anomaly detection, it realizes an intelligent encryption and decryption process.
It enables dynamic encryption and decryption in different scenarios and situations, improving data security and encryption efficiency, and adapting to modern advanced threats.
Smart Images

Figure CN120896756A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of artificial intelligence technology, and in particular to a data encryption and decryption method and related equipment. Background Technology
[0002] In scenarios such as the Internet of Things (IoT), the Internet of Vehicles (IoV), and cloud storage, data encryption and decryption are core technologies for ensuring information security. Traditional encryption and decryption algorithms mainly include symmetric encryption and decryption algorithms (AES, ChaCha20, etc.), asymmetric encryption and decryption algorithms (such as RSA, ECC, etc.), and hybrid encryption and decryption algorithms (such as TLS / SSL, etc.).
[0003] Currently, these traditional encryption and decryption algorithms are widely used in scenarios such as the Internet of Things (IoT), connected vehicles, and cloud storage. However, in these scenarios, encryption and decryption algorithms are often selected manually, and the same algorithm is used for different situations, making it difficult to balance data security and encryption efficiency. Furthermore, traditional encryption and decryption algorithms suffer from static keys and fixed key update strategies, making them ill-equipped to deal with modern advanced threats (such as quantum computing and automated real-time attacks). For example, the key length of symmetric encryption and decryption algorithms is fixed after initialization and cannot be dynamically adjusted according to real-time threats; asymmetric encryption and decryption algorithms typically keep their public and private key pairs unchanged for a long time after generation unless manually changed or changed at a fixed period, making it impossible to flexibly adjust according to real-time threats and resulting in lagging protection.
[0004] Therefore, how to provide a data encryption and decryption scheme that can adapt to the data encryption and decryption needs in different scenarios and situations has become a technical problem that urgently needs to be solved by those skilled in the art. Summary of the Invention
[0005] In view of the above problems, this application provides a data encryption and decryption method and related equipment to meet the data encryption and decryption needs in different scenarios and situations. The specific solution is as follows:
[0006] The first aspect of this application provides a data encryption method, comprising:
[0007] Determine the original plaintext data to be encrypted;
[0008] Acquire encrypted environment-aware data;
[0009] The encryption agent is invoked to input the original plaintext data and the encryption environment awareness data into the encryption strategy generation model. The encryption strategy generation model outputs an encryption strategy, which includes the encryption algorithm selection result, key information, and key distribution path.
[0010] The original plaintext data is encrypted using the encryption strategy to obtain ciphertext data.
[0011] In one possible implementation, the encryption policy generation model is trained using reinforcement learning.
[0012] In the reinforcement learning process of the encryption strategy generation model, the training samples are original plaintext data samples, the state space is the environmental perception data corresponding to the original plaintext data samples, the action space is the encryption algorithm selection result label, key information label and key distribution path label corresponding to the original plaintext data samples, and the reward function is determined based on a weighted balance between encryption security and resource consumption.
[0013] In one possible implementation, encrypting the original plaintext data using the encryption strategy includes:
[0014] The encryption agent is invoked to input the encryption algorithm selection result and key information into the key generation model, and the key generation model generates a key.
[0015] The cryptographic agent is invoked to distribute the key based on the key distribution path;
[0016] The original plaintext data is encrypted using the key distributed by the encryption agent.
[0017] In one possible implementation, the key generation model is based on training a generative adversarial network;
[0018] In the process of training the key generation model based on generative adversarial networks, the generator is used to generate keys, and the discriminator is used to simulate attacker cracking behavior. The resistance to cracking of the keys generated by the generator is improved through adversarial optimization.
[0019] In one possible implementation, after the invoking cryptographic agent inputs the original plaintext data and the cryptographic environment-aware data into the cryptographic policy generation model, and the cryptographic policy generation model outputs the cryptographic policy, the method further includes:
[0020] Call upon the security management intelligent agent to perform anomaly detection;
[0021] Obtain the anomaly detection results of the security management intelligent agent;
[0022] The anomaly detection result is provided to the cryptographic agent, so that the cryptographic agent inputs the anomaly detection result into the cryptographic policy generation model, and the cryptographic policy generation model updates the cryptographic policy based on the anomaly detection result.
[0023] A second aspect of this application provides a data decryption method, comprising:
[0024] Obtain the decryption request and the ciphertext data to be decrypted;
[0025] The decryption request is verified, and the verification result is obtained;
[0026] Obtain decrypted environment awareness data;
[0027] The decryption environment perception data is input into the risk assessment model to conduct a decryption environment risk assessment and obtain the decryption environment risk assessment result.
[0028] If the verification result indicates that the verification is successful and the decryption environment risk assessment result indicates that there is no risk, then the encrypted data is decrypted.
[0029] In one possible implementation, decrypting the ciphertext data includes:
[0030] Perform lightweight signature verification on the encrypted data;
[0031] After the lightweight signature verification is successful, the encrypted data is decrypted using white-box key protection technology.
[0032] A third aspect of this application provides a data encryption device, comprising:
[0033] The original plaintext data determination unit is used to determine the original plaintext data to be encrypted.
[0034] Encrypted environment awareness data acquisition unit, acquires encrypted environment awareness data;
[0035] An encryption strategy generation unit is used to call an encryption agent to input the original plaintext data and the encryption environment awareness data into an encryption strategy generation model. The encryption strategy generation model outputs an encryption strategy, which includes the encryption algorithm selection result, key information, and key distribution path.
[0036] An encryption unit is used to encrypt the original plaintext data using the encryption strategy to obtain ciphertext data.
[0037] In one possible implementation, the encryption policy generation model is trained using reinforcement learning.
[0038] In the reinforcement learning process of the encryption strategy generation model, the training samples are original plaintext data samples, the state space is the environmental perception data corresponding to the original plaintext data samples, the action space is the encryption algorithm selection result label, key information label and key distribution path label corresponding to the original plaintext data samples, and the reward function is determined based on a weighted balance between encryption security and resource consumption.
[0039] In one possible implementation, the encryption unit includes:
[0040] A key generation unit is used to call the encryption agent to input the encryption algorithm selection result and key information into the key generation model, and the key generation model generates a key.
[0041] A key distribution unit is used to invoke the cryptographic agent to distribute the key based on the key distribution path;
[0042] An encryption processing unit is used to encrypt the original plaintext data using a key distributed by the encryption agent.
[0043] In one possible implementation, the key generation model is based on training a generative adversarial network;
[0044] In the process of training the key generation model based on generative adversarial networks, the generator is used to generate keys, and the discriminator is used to simulate attacker cracking behavior. The resistance to cracking of the keys generated by the generator is improved through adversarial optimization.
[0045] In one possible implementation, the device further includes:
[0046] Encryption policy update unit;
[0047] The encryption policy update unit is configured to, after the encryption agent inputs the original plaintext data and the encryption environment awareness data into the encryption policy generation model, and the encryption policy generation model outputs the encryption policy, call the security management agent to perform anomaly detection; obtain the anomaly detection result of the security management agent; and provide the anomaly detection result to the encryption agent, so that the encryption agent inputs the anomaly detection result into the encryption policy generation model, and the encryption policy generation model updates the encryption policy based on the anomaly detection result.
[0048] A fourth aspect of this application provides a data decryption apparatus, comprising:
[0049] The decryption information acquisition unit is used to acquire the decryption request and the ciphertext data to be decrypted;
[0050] A decryption request verification unit is used to verify the decryption request and obtain a verification result;
[0051] The environmental perception data acquisition unit is used to acquire and decrypt environmental perception data.
[0052] The risk assessment unit is used to input the decryption environment perception data into the risk assessment model, perform a decryption environment risk assessment, and obtain the decryption environment risk assessment result.
[0053] The decryption unit is used to decrypt the encrypted data if the verification result indicates that the verification is successful and the decryption environment risk assessment result indicates that there is no risk.
[0054] In one possible implementation, the decryption unit is specifically used for:
[0055] Perform lightweight signature verification on the encrypted data;
[0056] After the lightweight signature verification is successful, the encrypted data is decrypted using white-box key protection technology.
[0057] The fifth aspect of this application provides a computer program product including computer-readable instructions that, when executed on an electronic device, cause the electronic device to implement the data encryption method of the first aspect or any implementation thereof, and / or the data decryption method of the second aspect or any implementation thereof.
[0058] A sixth aspect of this application provides an electronic device, comprising at least one processor and a memory connected to the processor, wherein:
[0059] The memory is used to store computer programs;
[0060] The processor is used to execute the computer program to enable the electronic device to implement the data encryption method of the first aspect or any implementation thereof, and / or the data decryption method of the second aspect or any implementation thereof.
[0061] A seventh aspect of this application provides a computer-readable storage medium carrying one or more computer programs that, when executed by an electronic device, enable the electronic device to perform the data encryption method of the first aspect or any implementation thereof, and / or the data decryption method of the second aspect or any implementation thereof.
[0062] By employing the above technical solution, this application provides a data encryption and decryption method and related equipment. In the encryption method of this solution, after determining the original plaintext data to be encrypted, encryption environment awareness data is first acquired; the original plaintext data and encryption environment awareness data are input into an encryption policy generation model by invoking an encryption agent; the encryption policy generation model outputs an encryption algorithm selection result, key information, and key distribution path that match the current original plaintext data and encryption environment; finally, the encryption policy is used to encrypt the original plaintext data to obtain ciphertext data. Based on this solution, the encryption algorithm, key information, and key distribution path can be dynamically determined. Combined with a corresponding decryption scheme, this solution can adapt to data encryption and decryption needs in different scenarios and situations. Attached Figure Description
[0063] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent from the accompanying drawings and the following detailed description. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and the originals and elements are not necessarily drawn to scale.
[0064] Figure 1 A flowchart illustrating a data encryption method provided in an embodiment of this application;
[0065] Figure 2 A flowchart illustrating a data decryption method provided in an embodiment of this application;
[0066] Figure 3 This is a schematic diagram of the structure of a data encryption device provided in an embodiment of this application;
[0067] Figure 4 This is a schematic diagram of the structure of a data decryption device provided in an embodiment of this application;
[0068] Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0069] The embodiments of this application are described below with reference to the accompanying drawings. The terminology used in the implementation section of this application is for explaining specific embodiments only and is not intended to limit the scope of this application.
[0070] The embodiments of this application will now be described with reference to the accompanying drawings. Those skilled in the art will recognize that, with technological advancements and the emergence of new scenarios, the technical solutions provided in the embodiments of this application are equally applicable to similar technical problems.
[0071] The terms "first," "second," etc., used in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such terms are interchangeable where appropriate; this is merely a way of distinguishing objects with the same attributes in the embodiments of this application. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion, so that a process, method, system, product, or apparatus that comprises a series of elements is not necessarily limited to those elements, but may include other elements not explicitly listed or inherent to those processes, methods, products, or apparatuses.
[0072] In scenarios such as the Internet of Things (IoT), the Internet of Vehicles (IoV), and cloud storage, data encryption and decryption are core technologies for ensuring information security. Traditional encryption and decryption algorithms mainly include symmetric encryption and decryption algorithms (AES, ChaCha20, etc.), asymmetric encryption and decryption algorithms (such as RSA, ECC, etc.), and hybrid encryption and decryption algorithms (such as TLS / SSL, etc.).
[0073] The core characteristic of symmetric encryption and decryption algorithms is that encryption and decryption use the same key. The key length determines security, and the key must be securely transmitted; otherwise, it is easily stolen. The encryption process involves the sender generating ciphertext from plaintext using an encryption algorithm and the key. The decryption process involves the receiver using the key and the decryption algorithm to decrypt the ciphertext and recover the plaintext. The core characteristic of asymmetric encryption and decryption algorithms is the use of a public key for encryption and a private key for decryption. The public key is publicly transmitted, while the private key is strictly kept secret. The encryption process involves the sender encrypting plaintext using the receiver's public key to generate ciphertext. The decryption process involves the receiver using their own private key to decrypt the ciphertext and recover the plaintext. The core characteristic of hybrid encryption and decryption algorithms is the secure transmission of the symmetric encryption key using an asymmetric encryption algorithm, while using a symmetric encryption algorithm to encrypt the actual data.
[0074] Currently, these traditional encryption and decryption algorithms are widely used in scenarios such as the Internet of Things (IoT), connected vehicles, and cloud storage. However, in these scenarios, encryption and decryption algorithms are often selected manually, and the same algorithm is used for different situations, making it difficult to balance data security and encryption efficiency. Furthermore, traditional encryption and decryption algorithms suffer from static keys and fixed key update strategies, making them ill-equipped to deal with modern advanced threats (such as quantum computing and automated real-time attacks). For example, the key length of symmetric encryption and decryption algorithms is fixed after initialization and cannot be dynamically adjusted according to real-time threats; asymmetric encryption and decryption algorithms typically keep their public and private key pairs unchanged for a long time after generation unless manually changed or changed at a fixed period, making it impossible to flexibly adjust according to real-time threats and resulting in lagging protection.
[0075] To address the aforementioned problems, this application provides a data encryption method. The method is implemented by the data encryption requester. The data encryption method of this application embodiment will be described in detail below with reference to the accompanying drawings.
[0076] Reference Figure 1 , Figure 1 This is a flowchart illustrating a data encryption method provided in an embodiment of this application, as shown below. Figure 1 As shown in the figure, the data encryption method provided in this application embodiment may include the following steps, which are described in detail below.
[0077] S101: Determine the original plaintext data to be encrypted;
[0078] In this application, the original plaintext data to be encrypted is not limited to any data type, including but not limited to text, images, and videos.
[0079] S102: Obtain encrypted environment awareness data;
[0080] In this application, encrypted environment awareness data is used to characterize encrypted environment information. In one possible implementation, the encrypted environment awareness data includes at least one of network status data, device performance data, user behavior data, and external threat intelligence data.
[0081] In this application, network status data includes, but is not limited to, network bandwidth data, network latency data, and packet loss rate data. Network bandwidth data can be obtained through TCP (Transmission Control Protocol) throughput measurement, network latency data can be obtained through ICMP (Internet Control Message Protocol) / UDP (User Datagram Protocol) probes, and packet loss rate data can be obtained through ping tests.
[0082] Device performance data includes, but is not limited to, CPU (Central Processing Unit) utilization data, memory usage data, and battery power data. CPU utilization data can be obtained through the " / proc / stat" file, memory usage data can be obtained through the " / meminfo" file, and battery power data is specific to the battery power of a particular device, such as an IoT device.
[0083] User behavior data includes, but is not limited to, operation habit data (e.g., preference for encrypted file types) and geographic location data, including but not limited to GPS (Global Positioning System) location data or IP (Internet Protocol) location data.
[0084] External threat intelligence data includes, but is not limited to, blacklisted IPs and new attack signature databases (such as MITRE ATT&CK). In this application, external threat intelligence data can be obtained by accessing STIX / TAXII standard threat intelligence platforms (such as FireEye and CrowdStrike).
[0085] In this application, the environmental perception data can be the raw data obtained using the methods described above, or data after preprocessing the raw data. Preprocessing methods include, but are not limited to, standardization and feature extraction. Standardization includes normalizing heterogeneous data (e.g., bandwidth in Mbps, latency in ms). Feature extraction includes dimensionality reduction using PCA (Principal Components Analysis) to retain 95% of the key features with variance.
[0086] S103: Call the encryption agent to input the original plaintext data and the encryption environment awareness data into the encryption strategy generation model. The encryption strategy generation model outputs an encryption strategy, which includes the encryption algorithm selection result, key information and key distribution path.
[0087] In this application, an encryption agent can be configured, and the data encryption requester can input the original plaintext data and the encryption environment awareness data into the encryption strategy generation model by calling the encryption agent.
[0088] In this application, a pre-defined encryption algorithm library can be established, integrating various encryption algorithms, including but not limited to symmetric encryption (AES / ChaCha20), asymmetric encryption (RSA / ECC), block AES encryption, and post-quantum encryption (CRYSTALS-Kyber). The encryption strategy generation model, based on the type of the original plaintext data (e.g., text, image, video) and scenario requirements (e.g., transmission speed, storage capacity), as well as the encryption environment awareness data, matches the optimal encryption algorithm from the encryption algorithm library as the encryption algorithm selection result. For example, lightweight symmetric encryption (e.g., ChaCha20) is selected for low-latency scenarios (e.g., real-time voice); quantum key distribution (QKD) or post-quantum encryption algorithms (e.g., CRYSTALS-Kyber) are enabled for highly sensitive data (e.g., financial information). To address the limitations of IoT devices, a segmented encryption strategy (e.g., block AES encryption) is adopted to reduce memory usage.
[0089] In this application, the key information includes, but is not limited to, key length information and key update frequency information. The encryption policy generation model can dynamically adjust the key length information and key update frequency information to determine the optimal key length information and key update frequency information that match the original plaintext data and the encryption environment-aware data, based on the type of the original plaintext data (e.g., text, image, video) and scenario requirements (e.g., transmission speed, storage capacity), as well as the encryption environment-aware data. For example, in some cases, AES-256 may be upgraded to AES-512. When there is an external threat risk, the key update frequency may be increased.
[0090] In this application, the key distribution path can be determined based on the Quantum Key Distribution (QKD) algorithm. In one possible implementation, quantum random numbers can be generated based on the BB84 protocol, and key distribution can be managed via blockchain. This blockchain-managed key distribution process includes key sharding, reassembly verification, and on-chain auditing. During key sharding, the master key is split into N pieces (such as the Shamir threshold key) and distributed across different nodes. During reassembly verification, only nodes verified through smart contracts (such as device fingerprint matching or behavior score > threshold) are allowed to obtain reassembly permissions. During on-chain auditing, all key operations are recorded on a consortium blockchain (such as Hyperledger Fabric), supporting post-event traceability.
[0091] S104: Encrypt the original plaintext data using the encryption strategy to obtain ciphertext data.
[0092] This embodiment provides a data encryption method. In this encryption method, after determining the original plaintext data to be encrypted, encryption environment awareness data is first acquired. Then, by invoking an encryption agent, the original plaintext data and the encryption environment awareness data are input into an encryption policy generation model. The encryption policy generation model outputs an encryption algorithm selection result, key information, and key distribution path that match the current original plaintext data and encryption environment. Finally, the encryption policy is used to encrypt the original plaintext data to obtain ciphertext data. Based on this scheme, the encryption algorithm, key information, and key distribution path can be dynamically determined, thus adapting to data encryption and decryption needs in different scenarios and situations.
[0093] In one possible implementation, the encryption policy generation model is trained using reinforcement learning. During the reinforcement learning process, the training samples are original plaintext data samples, the state space is the environmental perception data corresponding to the original plaintext data samples, the action space is the encryption algorithm selection result label, key information label, and key distribution path label corresponding to the original plaintext data samples, and the reward function is determined based on a weighted balance between encryption security and resource consumption.
[0094] In this application, the base of the encryption policy generation model can be DQN (Deep Q-Network), and the reinforcement learning method can be the PPO (Proximal Policy Optimization) algorithm. The environmental awareness data corresponding to the original plaintext data sample includes at least one of network status data, device performance data, user behavior data, and external threat intelligence data; wherein the environmental awareness data corresponding to the original plaintext data sample can be obtained through a simulation environment, such as constructing a virtual network environment (e.g., Mininet) to simulate different attack scenarios (e.g., DDoS, man-in-the-middle attacks).
[0095] In this application, encryption security can be represented in various forms, such as the difficulty of key cracking. Resource consumption can also be represented in various forms, such as CPU / memory usage. For ease of understanding, this application provides an example of a reward function, as follows: Encryption security (e.g., difficulty of key cracking) × 0.7 + Resource consumption (e.g., CPU / memory usage) × 0.3.
[0096] It is important to note that when training the encryption policy generation model using reinforcement learning, a federated learning approach can be adopted, where each node trains the policy model locally and only shares gradients rather than the original data, thus avoiding privacy leaks.
[0097] In one possible implementation, encrypting the original plaintext data using the encryption strategy includes:
[0098] S201: The encryption agent is invoked to input the encryption algorithm selection result and key information into the key generation model, and the key generation model generates a key;
[0099] S202: Invoke the cryptographic agent to distribute the key based on the key distribution path;
[0100] S203: Encrypt the original plaintext data using the key distributed by the encryption agent.
[0101] In this application, an encryption agent can be configured. The data encryption requester provides the encryption strategy to the key generation model by calling the encryption agent. The key generation model generates a key based on the encryption strategy. The data encryption requester can also distribute the key to the data encryption requester using the key distribution path by calling the encryption agent, so that the data encryption requester can use the key to encrypt the original plaintext data.
[0102] In one possible implementation, the key generation model is based on training a generative adversarial network (GAN). During the training process, the generator generates keys, and the discriminator is used to improve the anti-cracking resistance of the keys generated by the generator based on simulated attacker cracking behavior.
[0103] In this application, the simulated attacker's cracking behavior includes, but is not limited to, brute-force attacks and side-channel attacks. In this application, simulated attacker cracking behavior can be obtained by generating fake encryption tasks (such as forging low-sensitivity data) to attract attackers to expose their attack behavior (such as brute-force attempts), and then capturing the attacker's attack behavior (such as cracking tool fingerprints or API call sequences).
[0104] In one possible implementation, after the invoking cryptographic agent inputs the original plaintext data and the cryptographic environment-aware data into the cryptographic policy generation model, and the cryptographic policy generation model outputs the cryptographic policy, the method further includes:
[0105] S301: Call the security management intelligent agent to perform anomaly detection;
[0106] S302: Obtain the anomaly detection results of the security management intelligent agent;
[0107] S303: The anomaly detection result is provided to the encryption agent, so that the encryption agent inputs the anomaly detection result into the encryption policy generation model, and the encryption policy generation model updates the encryption policy based on the anomaly detection result.
[0108] In this application, a security management agent can be configured, and the data encryption requester can call the security management agent to perform anomaly detection; obtain the anomaly detection result of the security management agent, and provide the anomaly detection result to the encryption agent, so that the encryption agent inputs the anomaly detection result into the encryption policy generation model, and the encryption policy generation model updates the encryption policy based on the anomaly detection result.
[0109] It should be noted that the security management agent can aggregate encryption / decryption events through a distributed log collection system (such as ElasticSearch), identify abnormal patterns (such as frequent key requests, cracking attempts), and thus obtain anomaly detection results. For example, the Isolation Forest algorithm can be used to identify abnormal encryption behavior (such as a sudden increase in key requests). When the encryption policy generation model updates the encryption policy based on the anomaly detection results, it can dynamically adjust the encryption policy based on the PPO (Proximity Policy Optimization) algorithm to balance security and resource consumption.
[0110] The above describes a data encryption method provided by an embodiment of this application. The following describes a data decryption method corresponding to the above-described data encryption method. The subject executing this method can be a decryption intelligent agent. The data decryption method of this application embodiment will be described in detail below with reference to the accompanying drawings.
[0111] Reference Figure 2 , Figure 2 This is a flowchart illustrating a data decryption method provided in an embodiment of this application, as shown below. Figure 2 As shown in the figure, the data decryption method provided in this application embodiment may include the following steps, which are described in detail below.
[0112] S401: Obtain the decryption request and the ciphertext data to be decrypted;
[0113] In this application, the decryption request and the ciphertext data to be decrypted can be obtained from the data decryption requester.
[0114] S402: Verify the decryption request and obtain the verification result;
[0115] In this application, the verification of the decryption request includes contextual validity verification and user behavior consistency check. Contextual validity verification refers to verifying the decryption request through multi-factor authentication (such as device fingerprint, user behavior profile, timestamp). For example, device fingerprint matching (based on hardware feature hashing). User behavior consistency check refers to secondary verification triggered by some special behaviors (such as operation frequency, sudden changes in geographical location, etc.) to verify the consistency of user behavior.
[0116] S403: Obtain and decrypt environmental awareness data;
[0117] In this application, the decryption environment awareness data is used to characterize decryption environment information. In one possible implementation, the decryption environment awareness data includes at least one of device historical behavior, network anomaly events, and decryption request frequency.
[0118] S404: Input the decryption environment perception data into the risk assessment model to perform a decryption environment risk assessment and obtain the decryption environment risk assessment result;
[0119] In this application, a risk assessment model can be obtained by training based on XGBoost.
[0120] S405: If the verification result indicates that the verification is successful and the decryption environment risk assessment result indicates that there is no risk, then the encrypted data is decrypted.
[0121] In this application, if the verification result indicates that the verification failed, and / or the decryption environment risk assessment result indicates that there is a risk, then the encrypted data will not be decrypted.
[0122] In one possible implementation, decrypting the ciphertext data includes:
[0123] Perform lightweight signature verification on the encrypted data;
[0124] After the lightweight signature verification is successful, the encrypted data is decrypted using white-box key protection technology.
[0125] In this application, the lightweight signature verification method can be a fast verification method such as ECDSA, and the white-box key protection technology can be TFA (Tiny Fuzzy Automaton) technology to distribute and store the key to prevent memory dump attacks.
[0126] The above describes a data encryption method and a data decryption method provided by embodiments of this application. The following will describe the apparatus for performing the above data encryption method and the apparatus for performing the above data decryption method.
[0127] Please see Figure 3 , Figure 3 This is a schematic diagram of a data encryption device provided in an embodiment of this application. Figure 3 As shown, the data encryption device includes:
[0128] The original plaintext data determination unit 11 is used to determine the original plaintext data to be encrypted;
[0129] Encrypted environment awareness data acquisition unit 12 acquires encrypted environment awareness data;
[0130] The encryption strategy generation unit 13 is used to call the encryption agent to input the original plaintext data and the encryption environment perception data into the encryption strategy generation model. The encryption strategy generation model outputs an encryption strategy, which includes the encryption algorithm selection result, key information and key distribution path.
[0131] The encryption unit 14 is used to encrypt the original plaintext data using the encryption strategy to obtain ciphertext data.
[0132] In one possible implementation, the encryption policy generation model is trained using reinforcement learning.
[0133] In the reinforcement learning process of the encryption strategy generation model, the training samples are original plaintext data samples, the state space is the environmental perception data corresponding to the original plaintext data samples, the action space is the encryption algorithm selection result label, key information label and key distribution path label corresponding to the original plaintext data samples, and the reward function is determined based on a weighted balance between encryption security and resource consumption.
[0134] In one possible implementation, the encryption unit includes:
[0135] A key generation unit is used to call the encryption agent to input the encryption algorithm selection result and key information into the key generation model, and the key generation model generates a key.
[0136] A key distribution unit is used to invoke the cryptographic agent to distribute the key based on the key distribution path;
[0137] An encryption processing unit is used to encrypt the original plaintext data using a key distributed by the encryption agent.
[0138] In one possible implementation, the key generation model is based on training a generative adversarial network;
[0139] In the process of training the key generation model based on generative adversarial networks, the generator is used to generate keys, and the discriminator is used to simulate attacker cracking behavior. The resistance to cracking of the keys generated by the generator is improved through adversarial optimization.
[0140] In one possible implementation, the device further includes:
[0141] Encryption policy update unit;
[0142] The encryption policy update unit is configured to, after the encryption agent inputs the original plaintext data and the encryption environment awareness data into the encryption policy generation model, and the encryption policy generation model outputs the encryption policy, call the security management agent to perform anomaly detection; obtain the anomaly detection result of the security management agent; and provide the anomaly detection result to the encryption agent, so that the encryption agent inputs the anomaly detection result into the encryption policy generation model, and the encryption policy generation model updates the encryption policy based on the anomaly detection result.
[0143] Please see Figure 4 , Figure 4 This is a schematic diagram of a data decryption device provided in an embodiment of this application. Figure 4 As shown, the data decryption device includes:
[0144] The decryption information acquisition unit 21 is used to acquire the decryption request and the ciphertext data to be decrypted;
[0145] The decryption request verification unit 22 is used to verify the decryption request and obtain a verification result;
[0146] The environmental perception data acquisition unit 23 is used to acquire and decrypt environmental perception data.
[0147] Risk assessment unit 24 is used to input the decryption environment perception data into the risk assessment model, perform decryption environment risk assessment, and obtain decryption environment risk assessment results;
[0148] The decryption unit 25 is used to decrypt the encrypted data if the verification result indicates that the verification is successful and the decryption environment risk assessment result indicates that there is no risk.
[0149] In one possible implementation, the decryption unit is specifically used for:
[0150] Perform lightweight signature verification on the encrypted data;
[0151] After the lightweight signature verification is successful, the encrypted data is decrypted using white-box key protection technology.
[0152] Each unit in the aforementioned data encryption and decryption devices can be implemented entirely or partially through software, hardware, or a combination thereof. These units can be embedded in or independent of the processor in a computer device, or stored in the computer device's memory as software, so that the processor can invoke and execute the corresponding operations of each unit.
[0153] This application also provides an electronic device in its embodiments. (See reference...) Figure 5 The diagram illustrates a structural schematic suitable for implementing the electronic device in the embodiments of this application. The electronic device in the embodiments of this application may include, but is not limited to, fixed terminals such as mobile phones, laptops, PDAs (personal digital assistants), PADs (tablet computers), desktop computers, etc. Figure 5 The electronic device shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments of this application.
[0154] like Figure 5 As shown, the electronic device may include a processing unit (e.g., a central processing unit, a graphics processing unit, etc.) 601, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 602 or a program loaded from a storage device 608 into a random access memory (RAM) 603. When the electronic device is powered on, the RAM 603 also stores various programs and data required for the operation of the electronic device. The processing unit 601, ROM 602, and RAM 603 are interconnected via a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.
[0155] Typically, the following devices can be connected to I / O interface 605: input devices 606 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 607 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices 608 including, for example, memory cards, hard drives, etc.; and communication devices 609. Communication device 609 allows electronic devices to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 5 Electronic devices with various devices are shown, but it should be understood that it is not required to implement or have all of the devices shown. More or fewer devices may be implemented or have alternatively.
[0156] This application also provides a computer program product including computer-readable instructions, which, when executed on an electronic device, cause the electronic device to implement any of the data encryption methods and / or data decryption methods provided in this application.
[0157] This application also provides a computer-readable storage medium that carries one or more computer programs. When the one or more computer programs are executed by an electronic device, the electronic device can implement any of the data encryption methods and / or data decryption methods provided in this application.
[0158] It should also be noted that the device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. In addition, in the device embodiment drawings provided in this application, the connection relationship between modules indicates that they have a communication connection, which can be implemented as one or more communication buses or signal lines.
[0159] Through the above description of the embodiments, those skilled in the art can clearly understand that this application can be implemented by means of software plus necessary general-purpose hardware, or it can be implemented by special-purpose hardware including application-specific integrated circuits, special-purpose CPUs, special-purpose memory, special-purpose components, etc. Generally, any function performed by a computer program can be easily implemented by corresponding hardware, and the specific hardware structure used to implement the same function can also be diverse, such as analog circuits, digital circuits, or special-purpose circuits. However, for this application, software program implementation is more often the preferred implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a readable storage medium, such as a computer floppy disk, USB flash drive, mobile hard disk, ROM, RAM, magnetic disk, or optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, training equipment, or network device, etc.) to execute the methods described in the various embodiments of this application.
[0160] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product.
[0161] The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, training device, or data center to another website, computer, training device, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium may be any available medium that a computer can store or a data storage device such as a training device or data center that integrates one or more available media. The available media may be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media (e.g., solid-state drives (SSDs)).
Claims
1. A data encryption method, characterized in that, include: Determine the original plaintext data to be encrypted; Acquire encrypted environment-aware data; The encryption agent is invoked to input the original plaintext data and the encryption environment awareness data into the encryption strategy generation model. The encryption strategy generation model outputs an encryption strategy, which includes the encryption algorithm selection result, key information, and key distribution path. The original plaintext data is encrypted using the encryption strategy to obtain ciphertext data.
2. The method according to claim 1, characterized in that, The encryption strategy generation model is trained using reinforcement learning. In the reinforcement learning process of the encryption strategy generation model, the training samples are original plaintext data samples, the state space is the environmental perception data corresponding to the original plaintext data samples, the action space is the encryption algorithm selection result label, key information label and key distribution path label corresponding to the original plaintext data samples, and the reward function is determined based on a weighted balance between encryption security and resource consumption.
3. The method according to claim 1, characterized in that, The encryption of the original plaintext data using the encryption strategy includes: The encryption agent is invoked to input the encryption algorithm selection result and key information into the key generation model, and the key generation model generates a key. The cryptographic agent is invoked to distribute the key based on the key distribution path; The original plaintext data is encrypted using the key distributed by the encryption agent.
4. The method according to claim 3, characterized in that, The key generation model is obtained based on training a generative adversarial network. In the process of training the key generation model based on generative adversarial networks, the generator is used to generate keys, and the discriminator is used to simulate attacker cracking behavior. The resistance to cracking of the keys generated by the generator is improved through adversarial optimization.
5. The method according to claim 1, characterized in that, After the cryptographic agent inputs the original plaintext data and the cryptographic environment-aware data into the cryptographic policy generation model, and the cryptographic policy generation model outputs the cryptographic policy, the method further includes: Call upon the security management intelligent agent to perform anomaly detection; Obtain the anomaly detection results of the security management intelligent agent; The anomaly detection result is provided to the cryptographic agent, so that the cryptographic agent inputs the anomaly detection result into the cryptographic policy generation model, and the cryptographic policy generation model updates the cryptographic policy based on the anomaly detection result.
6. A data decryption method, characterized in that, include: Obtain the decryption request and the ciphertext data to be decrypted; The decryption request is verified, and the verification result is obtained; Obtain decrypted environment awareness data; The decryption environment perception data is input into the risk assessment model to conduct a decryption environment risk assessment and obtain the decryption environment risk assessment result. If the verification result indicates that the verification is successful and the decryption environment risk assessment result indicates that there is no risk, then the encrypted data is decrypted.
7. The method according to claim 6, characterized in that, The decryption of the ciphertext data includes: Perform lightweight signature verification on the encrypted data; After the lightweight signature verification is successful, the encrypted data is decrypted using white-box key protection technology.
8. A computer program product, characterized in that, It includes computer-readable instructions that, when executed on an electronic device, cause the electronic device to implement the data encryption method as described in any one of claims 1 to 5, and / or the data decryption method as described in any one of claims 6 to 7.
9. An electronic device, characterized in that, It includes at least one processor and a memory connected to the processor, wherein: The memory is used to store computer programs; The processor is configured to execute the computer program to enable the electronic device to implement the data encryption method as described in any one of claims 1 to 5, and / or the data decryption method as described in any one of claims 6 to 7.
10. A computer-readable storage medium, characterized in that, The storage medium carries one or more computer programs that, when executed by an electronic device, enable the electronic device to implement the data encryption method as described in any one of claims 1 to 5, and / or the data decryption method as described in any one of claims 6 to 7.
Citation Information
Cited By
Database encryption method, device and system based on large-model multi-agent cooperation
CN121435261A
Database encryption methods, devices, and systems based on large-scale multi-agent collaboration
CN121435261B