A Method and System for Encrypting and Decrypting User Privacy Data

A hybrid DES-RSA encryption method using strong prime numbers addresses the speed and security trade-off in RSA, enhancing encryption efficiency and security for user privacy data.

CN114422108BActive Publication Date: 2025-07-15AEROSPACE SCI & ENG NETWORK INFORMATION DEV CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111644286.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-29
Publication Date
2025-07-15
Estimated Expiration
2041-12-29

AI Technical Summary

Technical Problem

In the prior art, the encryption speed and security of the RSA algorithm are difficult to meet at the same time, and there are problems with the key management of the DES algorithm, resulting in insufficient efficiency and security of the encryption process of user privacy data.

Method used

The DES algorithm is used to encrypt user privacy data, and the DES algorithm's key is encrypted using a public key generated based on strong prime numbers. The improved RSA algorithm is used to decrypt the key of the DES algorithm. Through the mixed use of the DES algorithm and the RSA algorithm, the encryption defect complementation is achieved.

Benefits of technology

It improves the encryption speed and security of user privacy data, enhances the security of the data set, has a higher success rate against attacks, and achieves effective complementarity of encryption efficiency and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114422108B_ABST
    Figure CN114422108B_ABST
Patent Text Reader

Abstract

The present invention discloses a method and system for encrypting and decrypting user privacy data. The method for encrypting and decrypting user privacy data encrypts plaintext data by using the DES algorithm, which can improve the encryption speed. In order to further improve the encryption effectiveness, the present invention uses the RSA encryption algorithm to encrypt the key used in the encryption process of the DES algorithm, thereby realizing the complementary encryption defects of the DES algorithm and the RSA algorithm, so as to solve the problem that the encryption speed and encryption security in the prior art cannot be satisfied simultaneously.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data encryption and decryption, and particularly to a method and system for encrypting and decrypting user privacy data. Background Art

[0002] In the context of the rapid development of computer technology and network technology, the degree of information digitization is also continuously increasing, and the amount of big data shows a sharp growth trend. This includes a large amount of user privacy data. Privacy data refers to data with strong privacy, high security protection level, and high sensitivity. Data is most vulnerable to attack and theft during the storage and retrieval processing. Therefore, the security protection of data privacy has become an urgent problem to be solved in maintaining data security and stable operation, and is an important topic in the field of information security.

[0003] The RSA system is one of the public key cryptosystems that have been applied and popularized in many fields. The RSA operation is essentially a modular exponentiation operation. The modular exponentiation operation of large number factorization in the RSA algorithm is a time-consuming task, which has always restricted the development of the RSA algorithm. The security level of this algorithm depends on factoring a large integer in a short time. In response to this problem, many scholars have proposed different optimization algorithms. Among them, the Chinese Remainder Theorem (CRT) is obvious for the effectiveness of decryption. It has been proved that considering the computational cost of the Chinese Remainder Theorem, the operation speed of the dual prime CRT-RSA is 3.32 times (1024-bit modulus) and 3.47 times (model 2048-bit) of the original algorithm respectively. Although the speed is satisfactory, there are security problems. Summary of the Invention

[0004] To solve the above problems existing in the prior art, the present invention provides a method and system for encrypting and decrypting user privacy data.

[0005] To achieve the above object, the present invention provides the following solution:

[0006] A method for encrypting and decrypting user privacy data, comprising:

[0007] Encrypting user privacy data using the DES algorithm to obtain encrypted data;

[0008] Encrypting the key used in the DES algorithm using a public key to obtain an encrypted key; the public key includes: a first key and a second key; the first key is generated based on a first strong prime number and a second strong prime number;

[0009] Decrypting the encrypted key using a private key to obtain the decrypted key of the DES algorithm; the private key is determined according to the first key and the second key;

[0010] Decrypt the encrypted data with the key based on the decrypted DES algorithm key to obtain the decrypted user privacy data.

[0011] Preferably, the generation process of the first strong prime number or the second strong prime number includes:

[0012] Randomly select a prime number from the prime number array and randomly generate a first integer; the first integer belongs to the set [1, 9];

[0013] Perform step-by-step calculations with the randomly selected prime number as the base with the first integer until the calculated result is a prime number to obtain a first result value;

[0014] Randomly generate a second integer, and perform step-by-step calculations with the first result value as the base with the second integer until the calculated result is a prime number to obtain a second result value; the second integer belongs to the set [1, 9];

[0015] Determine whether the difference between the multiple value of the second result value and 1 is a prime number. If the difference between the multiple value of the second result value and 1 is a prime number, determine the difference between the multiple value of the second result value and 1 as the first strong prime number or the second strong prime number;

[0016] If the difference between the multiple value of the second result value and 1 is a non-prime number, use the difference between the multiple value of the second result value and 1 as the first result value, and return "Randomly generate a second integer, and perform step-by-step calculations with the first result value as the base with the second integer until the calculated result is a prime number to obtain a second result value" until the difference between the multiple value of the second result value and 1 is a prime number.

[0017] Preferably, the prime number array consists of prime numbers less than 500.

[0018] Preferably, the first key is the product of the first strong prime number and the second strong prime number.

[0019] Preferably, the second key is a prime number less than the first key.

[0020] According to the specific embodiments provided by the present invention, the present invention discloses the following technical effects:

[0021] The user privacy data encryption and decryption method provided by the present invention can improve the encryption speed by encrypting the plaintext data using the DES algorithm. And in order to further improve the encryption effectiveness, the present invention uses the RSA encryption algorithm to encrypt the key used in the encryption process of the DES algorithm, thereby realizing the complementary encryption defects of the DES algorithm and the RSA algorithm to solve the problem that the encryption speed and encryption security in the prior art cannot be satisfied simultaneously.

[0022] Corresponding to the user privacy data encryption and decryption method provided above, the present invention provides two user privacy data encryption and decryption systems, specifically as follows:

[0023] One of the user privacy data encryption and decryption systems includes: a data sending end and a data receiving end;

[0024] The data sending end and the data receiving end perform data interaction;

[0025] The data sending end is used to encrypt user privacy data using the DES algorithm to obtain encrypted data, and is used to encrypt the key used in the DES algorithm using a public key to obtain an encrypted key, and is further used to send the encrypted data and the encrypted key to the receiving end; the public key includes: a first key and a second key; the first key is generated based on a first strong prime number and a second strong prime number;

[0026] The data receiving end is used to receive the encrypted data and the encrypted key, and is used to decrypt the encrypted key using a private key to obtain the decrypted key of the DES algorithm, and is further used to decrypt the encrypted data based on the decrypted key of the DES algorithm to obtain the decrypted user privacy data; the private key is determined according to the first key and the second key.

[0027] Preferably, the data sending end includes a strong prime number generation module, a public key generation module, and a private key generation module connected in sequence;

[0028] The strong prime number generation module is used to generate the first strong prime number and the second strong prime number; the public key generation module is used to generate a public key according to the first strong prime number and the second strong prime number; the private key generation module is used to generate a private key according to the public key.

[0029] Preferably, the strong prime number generation module includes: a random number generation unit, a first calculation unit, a second calculation unit, a judgment unit, a strong prime number determination unit, and a loop execution unit;

[0030] The random number generation unit is connected to the first calculation unit; the first calculation unit is connected to the second calculation unit; the second calculation unit is connected to the judgment unit; the judgment unit is respectively connected to the strong prime number determination unit and the loop execution unit; the loop execution unit is connected to the second calculation unit;

[0031] The random number generation unit is used to randomly select a prime number from a prime number array and randomly generate a first integer; the first integer belongs to the set [1, 9];

[0032] The first calculation unit is configured to perform step-by-step calculations based on a randomly selected prime number with the first integer as the base until a prime number is obtained as the calculation result, and then obtain the first result value;

[0033] The second calculation unit is configured to randomly generate a second integer, and perform step-by-step calculations based on the first result value with the second integer as the base until a prime number is obtained as the calculation result, and then obtain the second result value; the second integer belongs to the set [1, 9];

[0034] The judgment unit is configured to judge whether the difference between the multiple value of the second result value and 1 is a prime number;

[0035] The strong prime number determination unit is configured to, when the difference between the multiple value of the second result value and 1 is a prime number, determine that the difference between the multiple value of the second result value and 1 is the first strong prime number or the second strong prime number;

[0036] The loop execution unit is configured to, when the difference between the multiple value of the second result value and 1 is a non-prime number, use the difference between the multiple value of the second result value and 1 as the first result value, and return to execute "randomly generate a second integer, and perform step-by-step calculations based on the first result value with the second integer as the base until a prime number is obtained as the calculation result, and then obtain the second result value", until the difference between the multiple value of the second result value and 1 is a prime number.

[0037] Another user privacy data encryption and decryption system includes:

[0038] A data encryption module, configured to encrypt user privacy data using the DES algorithm to obtain encrypted data;

[0039] A key encryption module, configured to encrypt the key used in the DES algorithm using a public key to obtain an encrypted key; the public key includes: a first key and a second key; the first key is generated based on a first strong prime number and a second strong prime number;

[0040] A key decryption module, configured to decrypt the encrypted key using a private key to obtain the decrypted key of the DES algorithm; the private key is determined according to the first key and the second key;

[0041] A data decryption module, configured to decrypt the encrypted data based on the decrypted key of the DES algorithm to obtain the decrypted user privacy data.

[0042] Since the technical effects achieved by the two user privacy data encryption and decryption systems provided by the present invention are the same as those achieved by the above-provided user privacy data encryption and decryption method, they will not be elaborated here.

[0043] The above general description and the following description are only exemplary and explanatory, and are not used to limit this application. Description of the Drawings

[0044] One or more embodiments are exemplarily illustrated by corresponding drawings. These exemplary illustrations and the drawings do not constitute limitations on the embodiments. Elements with the same reference numerals in the drawings are shown as similar elements. The drawings do not constitute a scale limitation, and among them:

[0045] Figure 1 is a flowchart of the user privacy data encryption and decryption method provided by the present invention;

[0046] Figure 2 is a framework implementation diagram of the user privacy data encryption and decryption method provided by the present invention;

[0047] Figure 3 is a schematic structural diagram of a user privacy data encryption and decryption system provided by the present invention;

[0048] Figure 4 is a schematic structural diagram of another user privacy data encryption and decryption system provided by the present invention. Detailed Description of the Embodiments

[0049] In order to be able to understand the features and technical content of the embodiments of the present disclosure in more detail, the implementation of the embodiments of the present disclosure will be described in detail below in conjunction with the drawings. The attached drawings are only for reference and explanation, and are not used to limit the embodiments of the present disclosure. In the following technical description, for the sake of explanation, multiple details are provided to provide a full understanding of the disclosed embodiments. However, one or more embodiments can still be implemented without these details. In other cases, well-known structures and devices can be shown in a simplified manner.

[0050] As Figure 1 shown, a user privacy data encryption and decryption method provided by the present invention includes:

[0051] Step 100: Encrypt the user privacy data using the DES algorithm to obtain encrypted data.

[0052] Step 101: Encrypt the key used in the DES algorithm using the public key to obtain an encrypted key. The public key includes: a first key and a second key. The first key is generated based on a first strong prime number and a second strong prime number. The first key is the product of the first strong prime number and the second strong prime number. The second key is a prime number less than the first key.

[0053] Step 102: Decrypt the encrypted key using the private key to obtain the decrypted key of the DES algorithm. The private key is determined according to the first key and the second key.

[0054] Step 103: Decrypt the encrypted data based on the decrypted DES algorithm key to obtain the decrypted user privacy data.

[0055] The following is an inferential explanation of the design concept of the user privacy data encryption and decryption method provided above in the present invention based on the encryption process of the conventional RSA algorithm.

[0056] The encryption and decryption processes of the conventional RSA algorithm are as follows:

[0057] Step 1: Select two large prime numbers a and b, and a ≠ b, f = a × b, φ(f) = (a - 1) × (b - 1).

[0058] Step 2: Select a prime number g such that 1 < g < f.

[0059] Step 3: Use (g, f) as the public key to perform an encryption operation on the plaintext.

[0060] Step 4: Calculate the private key Perform a decryption operation on the ciphertext.

[0061] In the steps of the encryption and decryption processes of the conventional RSA algorithm, both g and f are public, but φ(f) is the key and needs to be kept secret. Once φ(f) is obtained, the security of the RSA algorithm will be greatly weakened. The security of the RSA algorithm is directly related to the lengths of a and b. The longer the lengths of a and b, the higher the security. Therefore, in the process of encrypting using the conventional RSA algorithm, it is necessary to ensure that the lengths of a and b are greater than or equal to 512 bits.

[0062] Moreover, the RSA algorithm is the first encryption algorithm that relies on factorization for system security. If f is very easily factorized, the security of the RSA algorithm will be greatly reduced. In summary, it can be considered that the security of the RSA algorithm is equivalent to factorization. That is: in the process of running the RSA algorithm, the selection of the public key is very important.

[0063] Based on this, the selection principle of the first key f in the public key is: the value of f should be large enough, which is the most fundamental principle to ensure the security performance of the RSA algorithm. To ensure the security of the algorithm, the lengths of the generated large prime numbers are all at least 100 - bit decimal numbers, and at this time, f can be more than 200 bits.

[0064] From the implementation process of the existing RSA algorithm, it can be seen that the randomly generated prime number is the key to the entire algorithm. To address the problem of reduced security caused by the randomly generated prime number value being possibly too small, the present invention introduces the concept of strong prime numbers to replace traditional prime numbers, increasing the difficulty of obtaining the correct prime factors by factorization, making the improved RSA encryption algorithm more secure.

[0065] Based on the idea of strong primes, a strong prime can be defined as follows:

[0066] Condition 1: There are large prime numbers a1 and a2 such that a1|(a - 1) and a2|(a + 1).

[0067] Condition 2: There are strong primes r1, r2, s1, and s2 such that r1|(a1 - 1), s1|(a1 + 1), r2|(a2 - 1), and s2|(a2 + 1).

[0068] Condition 3: The difference between a and b should be large, and the greatest common divisor of a - 1 and b - 1 should be small enough. Assuming the difference between a and b is small, then holds, and the values of a and b can be calculated.

[0069] Based on the above definition of strong primes, the selection principle of the second key g is as follows: During the operation of the RSA algorithm, g only needs to satisfy gcd(g, φ(f)) = 1, which means g can be randomly selected. According to the basic principle of encryption, the smaller the value of g, the less time is required for encryption. Therefore, the smaller g is, the better the algorithm runs. However, practice shows that a small g value will trigger security problems. In summary, in actual operation, the conditions that the parameter g needs to follow are as follows:

[0070] Condition 1: g should not be too small. Considering the efficiency and security of data encryption, it is best to select a prime number with a length of 16.

[0071] Condition 2: During the selection of the parameter g, the one with the largest order modulo φ(f) should be selected, that is, the smallest i in g i = 1 mod φ(f) should be ((a - 1)(b - 1)) / 2.

[0072] The selection principle of h: h, as a key, should be greater than f 1 / 4 , and in the actual application process, it is hoped to improve the decryption or signature efficiency according to the small - digit h. After g is determined, h can be obtained based on the Euclidean algorithm. In summary, assuming the length of h is less than f 1 / 4 , then only through mathematical algorithms can the parameter h be obtained efficiently.

[0073] Based on the above content, regarding when a prime number P can be defined as a strong prime, the following four points need to be satisfied:

[0074] 1) P must be a very large prime number.

[0075] 2) P - 1 has very large prime factors. That is, for any integer a1 and large prime number R, P = a1R + 1.

[0076] 3) R has a large prime factor. That is, for any integer a2 and large prime number S, it satisfies R = a2S + 1.

[0077] 4) P + 1 has a large prime factor. That is, for any integer a3 and large prime number T, it satisfies P = a3T - 1.

[0078] In specific applications, additional conditions can also be added according to the user's needs, such as assigning additional values to a1 and a2.

[0079] Based on the above design concept, in order to further improve the encryption speed, the present invention provides a method for generating strong prime numbers to generate a first strong prime number or a second strong prime number, specifically as follows:

[0080] Randomly select a prime number h1 from the prime number array and randomly generate a first integer x. The first integer belongs to the set [1, 9]. For example, the prime number array selected in the present invention can be a data set composed of prime numbers less than 500.

[0081] Perform step-by-step calculations based on the randomly selected prime number with the first integer x as the base until the calculation result is a prime number to obtain the first result value h2.

[0082] Randomly generate a second integer b and perform step-by-step calculations based on the first result value h2 with the second integer b as the base until the calculation result is a prime number to obtain the second result value h3. The second integer belongs to the set [1, 9].

[0083] Judge whether the difference between the multiple value of the second result value h3 and 1 is a prime number. If the difference between the multiple value of the second result value h3 and 1 is a prime number, then determine that the difference between the multiple value of the second result value h3 and 1 is the first strong prime number or the second strong prime number.

[0084] If the difference between the multiple value of the second result value h3 and 1 is a non-prime number, then use the difference between the multiple value of the second result value h3 and 1 as the first result value and return "Randomly generate a second integer b and perform step-by-step calculations based on the first result value h2 with the second integer b as the base until the calculation result is a prime number to obtain the second result value h3" until the difference between the multiple value of the second result value h3 and 1 is a prime number.

[0085] Based on the above determination process of strong prime numbers, the present invention provides a specific embodiment for determining strong prime numbers, as follows:

[0086] 1) In the present invention, prime numbers within 500 are used as the initial prime number array, and a prime number h1 is randomly selected from the prime number array.

[0087] 2) Randomly generate an integer x from 1 to 9. Combine it with the prime number h1 obtained in the first step to calculate 2ah1 + 1. Let a start from x and gradually increase by one. Use the prime number judgment function to obtain the first prime number that appears, denoted as h2.

[0088] 3) Randomly generate an integer y from 1 to 9. Calculate 2bh2 + 1. Let b start from y and gradually increase by one. Use the prime number judgment function to obtain the first prime number that appears, denoted as h3.

[0089] 4) Let P = 2h3 - 1. Use the prime number judgment function to determine whether P is a prime number. If P is not a prime number, execute (3); otherwise, execute (5).

[0090] 5) Output P. P is the generated strong prime number.

[0091] Based on the above-determined strong prime numbers, the existing RSA algorithm can be improved. However, although the improved RSA algorithm has enhanced effectiveness, its encryption speed needs to be improved. Therefore, the present invention introduces the DES algorithm to encrypt privacy data (see step 100). The DES algorithm has a fast encryption speed, but there are certain problems in key management. Therefore, by combining the improved RSA algorithm and the DES algorithm, effective complementarity can be achieved. The specific implementation process is as Figure 2 shown, including:

[0092] Step 1: Define the DES algorithm as: F DES = P' -1 ×T 16 ×T 15 ×…×T1×P'(MING)

[0093] In the formula: P’ is the initial transformation, and P' -1 is the inverse transformation of P'. The two satisfy IP'×IP' -1 = 1. T is the number of encoding operation rounds.

[0094] Step 2: DES iteration.

[0095] Step 3: During the sub-key generation process, reorder the original key, divide it into two parts, then obtain the two parts of the sub-key through circular shifting, and finally synthesize and reorder them to form the sub-key. The decryption process after hybrid encryption is similar to the encryption steps. In the decryption process, just reverse the order of the 16-round iteration self-keys. During the operation of the hybrid algorithm, encrypt the plaintext data set through the DES algorithm and encrypt the key used by the DES algorithm with RSA. Transmit the packaged ciphertext and the encrypted key to the receiving end. After the receiving end obtains the data packet, decrypt the key ciphertext to obtain the key used during DES algorithm encryption. The keys used for DES algorithm encryption and decryption are the same. After obtaining the key, the ciphertext can be decrypted.

[0096] On the basis of implementing the hybrid encryption of the privacy dataset, through homomorphic operations, the encryption of the privacy dataset is realized. Homomorphic operation is an encryption process designed for ciphertext. According to the operation result of the ciphertext, the corresponding plaintext result can be obtained. The process is as follows:

[0097] 1) Generate a key using the input prime number.

[0098] 2) Encrypt the plaintext using the key and return the ciphertext.

[0099] 3) Decrypt the ciphertext using the key and return the plaintext.

[0100] 4) Assume that C represents an operation set in the plaintext space, denoted as C{+}. For the input data c n (n = 1, 2, 3...) First, encrypt the data c n and convert it to the ciphertext space to obtain the ciphertext operation result. Use to represent the additive homomorphic processing, then and so on. By calculating the ciphertext and decrypting the result, the corresponding plaintext calculation result can be obtained.

[0101] In summary, the technical solution provided by the present invention has a high encryption efficiency. This method has strong encryption performance, stronger practicability. Compared with the single algorithm, the hybrid algorithm has a higher success rate in resisting attacks and can better guarantee the security of the dataset. The comprehensive performance of this method after applying the hybrid algorithm is more excellent, which well makes up for the defects of the DES algorithm and the RSA algorithm. It not only improves the encryption efficiency of the dataset but also enhances the security of the dataset. And an additive homomorphic calculation is designed to realize the encryption of the privacy dataset. The experimental results prove that this method has strong encryption performance and stronger practicability. It is found in the research that: in the improved RSA algorithm, the security of the RSA algorithm is related to factorization. When selecting the public key prime number, the smaller the prime number value, the less time required for the encryption process. Therefore, the fewer prime numbers, the higher the running efficiency of the algorithm. By selecting strong prime number values and increasing the difficulty of obtaining the correct prime factors by factorization, the improved RSA encryption algorithm has higher security and better application scenarios for the RSA encryption algorithm.

[0102] In addition, corresponding to the above-provided user privacy data encryption and decryption method, the present invention provides two user privacy data encryption and decryption systems, specifically as follows:

[0103] One of the user privacy data encryption and decryption systems, as Figure 3 shown, includes: a data sending end 300 and a data receiving end 301.

[0104] The data sender 300 interacts with the data receiver 301 for data.

[0105] The data sender 300 is used to encrypt the user privacy data using the DES algorithm to obtain encrypted data, and is used to encrypt the key used in the DES algorithm using the public key to obtain an encrypted key, and is also used to send the encrypted data and the encrypted key to the receiver. The public key includes: a first key and a second key. The first key is generated based on a first strong prime number and a second strong prime number.

[0106] The data receiver 301 is used to receive the encrypted data and the encrypted key, and is used to decrypt the encrypted key using the private key to obtain the decrypted key of the DES algorithm, and is also used to decrypt the encrypted data based on the decrypted key of the DES algorithm to obtain the decrypted user privacy data. The private key is determined according to the first key and the second key.

[0107] To improve the encryption speed, the existing RSA algorithm can be improved. Therefore, the data sender 300 used above may further include a strong prime number generation module, a public key generation module, and a private key generation module that are connected in sequence.

[0108] The strong prime number generation module is used to generate a first strong prime number and a second strong prime number. The public key generation module is used to generate a public key according to the first strong prime number and the second strong prime number. The private key generation module is used to generate a private key according to the public key.

[0109] To further improve the encryption speed, the strong prime number generation module used above includes: a random number generation unit, a first calculation unit, a second calculation unit, a judgment unit, a strong prime number determination unit, and a loop execution unit.

[0110] The random number generation unit is connected to the first calculation unit. The first calculation unit is connected to the second calculation unit. The second calculation unit is connected to the judgment unit. The judgment unit is respectively connected to the strong prime number determination unit and the loop execution unit. The loop execution unit is connected to the second calculation unit.

[0111] The random number generation unit is used to randomly select a prime number from the prime number array and randomly generate a first integer. The first integer belongs to the set [1, 9];

[0112] The first calculation unit is used to perform step-by-step calculations based on the randomly selected prime number with the first integer as the base until the calculation result is a prime number to obtain a first result value.

[0113] The second calculation unit is used to randomly generate a second integer and perform step-by-step calculations based on the first result value with the second integer as the base until the calculation result is a prime number to obtain a second result value. The second integer belongs to the set [1, 9].

[0114] The determination unit is used to determine whether the difference between the multiple value of the second result value and 1 is a prime number.

[0115] The strong prime number determination unit is used to determine that the difference between the multiple value of the second result value and 1 is the first strong prime number or the second strong prime number when the difference between the multiple value of the second result value and 1 is a prime number.

[0116] The loop execution unit is used to, when the difference between the multiple value of the second result value and 1 is a non-prime number, use the difference between the multiple value of the second result value and 1 as the first result value, and return to execute "randomly generate a second integer, and perform step-by-step calculations based on the first result value with the second integer as the base until the calculated result is a prime number to obtain the second result value", until the difference between the multiple value of the second result value and 1 is a prime number.

[0117] Another user privacy data encryption and decryption system, as Figure 4 shown, includes: a data encryption module 400, a key encryption module 401, a key decryption module 402, and a data decryption module 403.

[0118] Among them, the data encryption module 400 is used to encrypt the user privacy data by using the DES algorithm to obtain encrypted data.

[0119] The key encryption module 401 is used to encrypt the key used in the DES algorithm by using the public key to obtain an encrypted key. The public key includes: a first key and a second key. The first key is generated based on the first strong prime number and the second strong prime number.

[0120] The key decryption module 402 is used to decrypt the encrypted key by using the private key to obtain the decrypted key of the DES algorithm. The private key is determined according to the first key and the second key.

[0121] The data decryption module 403 is used to decrypt the encrypted data based on the decrypted key of the DES algorithm to obtain the decrypted user privacy data.

[0122] The above description and the accompanying drawings fully illustrate the embodiments of the present disclosure, enabling those skilled in the art to practice them. Other embodiments may include structural, logical, electrical, process, and other changes. Embodiments merely represent possible variations. Unless explicitly required, individual components and functions are optional, and the order of operations may vary. Parts and features of some embodiments may be included in or replace parts and features of other embodiments. The scope of the embodiments of the present disclosure includes the entire scope of the claims and all available equivalents of the claims. When used in this application, although terms such as "first", "second", etc. may be used in this application to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, without changing the meaning of the description, the first element may be called the second element, and similarly, the second element may be called the first element, as long as all occurrences of the "first element" are consistently renamed and all occurrences of the "second element" are consistently renamed. The first element and the second element are both elements, but they may not be the same element. Moreover, the terms used in this application are only used to describe the embodiments and are not used to limit the claims. As used in the description of the embodiments and the claims, unless the context clearly indicates otherwise, the singular forms "a", "an", and "the" are intended to also include the plural forms. Similarly, as used in this application, the term "and / or" refers to any and all possible combinations including one or more of the associated listed items. Additionally, when used in this application, the term "comprise" and its variants "comprises" and / or "comprising", etc. mean the presence of the stated features, wholes, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or groups thereof. Without further limitation, an element defined by the statement "comprising one..." does not exclude the presence of additional identical elements in the process, method, or device comprising the element. In this document, each embodiment may focus on the differences from other embodiments, and the same or similar parts among the embodiments may be referred to each other. For the methods, products, etc. disclosed in the embodiments, if they correspond to the method part disclosed in the embodiments, the relevant parts may refer to the description of the method part.

[0123] Those skilled in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner may depend on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of the embodiments of the present disclosure. Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.

[0124] In the embodiments disclosed herein, the disclosed methods, products (including but not limited to devices, equipment, etc.) can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of units can be merely a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of devices or units can be in electrical, mechanical, or other forms. The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place, or distributed to multiple network units. Some or all of the units can be selected according to actual needs to implement this embodiment. In addition, the functional units in the embodiments of the present disclosure can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit.

[0125] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a part of code, which contains one or more executable instructions for implementing a specified logical function. In some alternative implementations, the functions noted in the blocks may occur in an order different from that noted in the accompanying drawings. For example, two consecutive blocks may, in fact, be executed substantially in parallel, or they may sometimes be executed in the reverse order, depending on the functions involved. In the descriptions corresponding to the flowcharts and block diagrams in the accompanying drawings, the operations or steps corresponding to different blocks may also occur in an order different from that disclosed in the description, and sometimes there is no specific order between different operations or steps. For example, two consecutive operations or steps may, in fact, be executed substantially in parallel, or they may sometimes be executed in the reverse order, depending on the functions involved. Each block in the block diagram and / or flowchart, and combinations of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based system that performs the specified functions or actions, or may be implemented by a combination of dedicated hardware and computer instructions.

Claims

1. A method for encrypting and decrypting user privacy data, characterized in that, Including: Encrypting user privacy data using the DES algorithm to obtain encrypted data; Encrypting the key used in the DES algorithm using a public key to obtain an encrypted key; the public key includes: a first key and a second key; the first key is generated based on a first strong prime number and a second strong prime number; Decrypting the encrypted key using a private key to obtain the decrypted key of the DES algorithm; the private key is determined according to the first key and the second key; Decrypting the encrypted data based on the decrypted key of the DES algorithm to obtain the decrypted user privacy data; The generation process of the first strong prime number or the second strong prime number includes: Randomly selecting a prime number from a prime number array and randomly generating a first integer; the first integer belongs to the set [1, 9]; Performing step-by-step calculations based on the randomly selected prime number with the first integer as the base until the calculation result is a prime number to obtain a first result value; Randomly generating a second integer and performing step-by-step calculations based on the first result value with the second integer as the base until the calculation result is a prime number to obtain a second result value; the second integer belongs to the set [1, 9]; Determining whether the difference between the multiple value of the second result value and 1 is a prime number. If the difference between the multiple value of the second result value and 1 is a prime number, then determining the difference between the multiple value of the second result value and 1 as the first strong prime number or the second strong prime number; If the difference between the multiple value of the second result value and 1 is a non-prime number, then taking the difference between the multiple value of the second result value and 1 as the first result value and returning "Randomly generating a second integer and performing step-by-step calculations based on the first result value with the second integer as the base until the calculation result is a prime number to obtain a second result value" until the difference between the multiple value of the second result value and 1 is a prime number; 2. The user privacy data encryption and decryption method according to claim 1, wherein The prime number array consists of prime numbers less than 500.

3. The user privacy data encryption and decryption method according to claim 1, characterized in that, The first key is the product of the first strong prime number and the second strong prime number.

4. The user privacy data encryption and decryption method according to claim 1, characterized in that The second key is a prime number less than the first key.

5. A user privacy data encryption and decryption system, characterized in that, Including: A data sending end and a data receiving end; The data sending end and the data receiving end perform data interaction; The data sending end is used to encrypt user privacy data using the DES algorithm to obtain encrypted data, and is used to encrypt the key used in the DES algorithm using a public key to obtain an encrypted key, and is also used to send the encrypted data and the encrypted key to the receiving end; the public key includes: a first key and a second key; the first key is generated based on a first strong prime number and a second strong prime number; The data receiving end is used to receive the encrypted data and the encrypted key, and is used to decrypt the encrypted key using a private key to obtain the decrypted key of the DES algorithm, and is also used to decrypt the encrypted data based on the decrypted key of the DES algorithm to obtain the decrypted user privacy data; the private key is determined according to the first key and the second key; The data sending end includes a strong prime number generation module, a public key generation module, and a private key generation module connected in sequence; The strong prime number generation module is used to generate the first strong prime number and the second strong prime number; the public key generation module is used to generate a public key according to the first strong prime number and the second strong prime number; the private key generation module is used to generate a private key according to the public key; The strong prime number generation module includes: a random number generation unit, a first calculation unit, a second calculation unit, a judgment unit, a strong prime number determination unit, and a loop execution unit; The random number generation unit is connected to the first calculation unit; the first calculation unit is connected to the second calculation unit; the second calculation unit is connected to the judgment unit; the judgment unit is respectively connected to the strong prime number determination unit and the loop execution unit; the loop execution unit is connected to the second calculation unit; The random number generation unit is used to randomly select a prime number from a prime number array and randomly generate a first integer; the first integer belongs to the set [1, 9]; The first calculation unit is used to perform step-by-step calculations based on the randomly selected prime number with the first integer as the base until the calculation result is a prime number to obtain a first result value; The second calculation unit is used to randomly generate a second integer and perform step-by-step calculations based on the first result value with the second integer as the base until the calculation result is a prime number to obtain a second result value; the second integer belongs to the set [1, 9]; The judgment unit is used to judge whether the difference between the multiple value of the second result value and 1 is a prime number; The strong prime number determination unit is used to determine that the difference between the multiple value of the second result value and 1 is the first strong prime number or the second strong prime number when the difference between the multiple value of the second result value and 1 is a prime number; The loop execution unit is used to, when the difference between the multiple value of the second result value and 1 is a non-prime number, use the difference between the multiple value of the second result value and 1 as the first result value and return to execute "randomly generate a second integer and perform step-by-step calculations based on the first result value with the second integer as the base until the calculation result is a prime number to obtain a second result value" until the difference between the multiple value of the second result value and 1 is a prime number; 6. A user privacy data encryption and decryption system, characterized in that, Including: A data encryption module, which is used to encrypt user privacy data using the DES algorithm to obtain encrypted data; A key encryption module, which is used to encrypt the key used in the DES algorithm using the public key to obtain an encrypted key; the public key includes: a first key and a second key; the first key is generated based on the first strong prime number and the second strong prime number; A key decryption module, which is used to decrypt the encrypted key using the private key to obtain the decrypted key of the DES algorithm; the private key is determined according to the first key and the second key; A data decryption module, which is used to decrypt the encrypted data based on the decrypted key of the DES algorithm to obtain the decrypted user privacy data; the generation process of the first strong prime number or the second strong prime number includes: Randomly select a prime number from a prime number array and randomly generate a first integer; the first integer belongs to the set [1, 9]; Perform step-by-step calculations with the first integer as the base according to randomly selected prime numbers until the calculated result is a prime number, and then obtain the first result value; Randomly generate a second integer, and perform step-by-step calculations with the first result value as the base according to the second integer until the calculated result is a prime number, and then obtain the second result value; the second integer belongs to the set [1, 9]; Determine whether the difference between the multiple value of the second result value and 1 is a prime number. If the difference between the multiple value of the second result value and 1 is a prime number, then determine that the difference between the multiple value of the second result value and 1 is the first strong prime number or the second strong prime number; If the difference between the multiple value of the second result value and 1 is a non-prime number, then use the difference between the multiple value of the second result value and 1 as the first result value, and return "Randomly generate a second integer, and perform step-by-step calculations with the first result value as the base according to the second integer until the calculated result is a prime number, and then obtain the second result value" until the difference between the multiple value of the second result value and 1 is a prime number.

Citation Information

Patent Citations

  • Data encryption transmission method and system

    CN102333093A