Data processing method and device
The method of mixing multi-bit random numbers with data using spread functions and encryption algorithms addresses data integrity verification challenges, ensuring rapid and secure verification for both encrypted and unencrypted data.
Patent Information
- Application Number
- CN202210120289.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-02-07
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2042-02-07
AI Technical Summary
The prior art is difficult to effectively protect data integrity in data storage, especially when facing attacks, especially when anti-forgery and replay attacks, and the existing methods rely on complex data computing logic, making it difficult to be applied to both encrypted and non-encrypted data scenarios.
By mixing multi-bit random numbers of specific distributions in the data, using diffusion functions or encryption algorithms to generate and store data, and extracting the random number distribution through inverse diffusion functions or decryption algorithms for verification, the integrity of the data is judged.
It realizes rapid judgment of data integrity, is suitable for encrypted and non-encrypted data scenarios, enhances data protection, and does not rely on complex computing logic for the data itself.
Smart Images

Figure CN114462102B_ABST
Abstract
Description
Technical Field
[0001] This specification relates to the field of data processing, and particularly to data storage and verification. Background Art
[0002] With the development of Internet technology, the attack methods and security threats to storage systems are increasing day by day. Once an attacker successfully damages the stored data, it may not only lead to the leakage of user sensitive information, but also cause problems such as program operation failures.
[0003] To ensure data integrity, data verification is mainly performed by performing simple operations on the stored data itself or more complex hash operations such as parity check codes and message authentication codes. More complex operations may require more complex program logic to implement.
[0004] Based on this, there is still a desire to provide improved systems and methods for verifying data integrity. Summary of the Invention
[0005] There is a desire to provide improved methods and devices for verifying data integrity that do not rely on the calculation logic for the data itself, can be applied to both encrypted data and non-encrypted data scenarios, and have security features such as anti-forgery and anti-replay attack capabilities.
[0006] According to one aspect, a data storage method is provided, including receiving data to be stored;
[0007] receiving a multi-bit random number with a specific distribution; mixing the multi-bit random number and the data to be stored based on a diffusion function and / or an encryption algorithm to generate stored data, wherein the diffusion function and the encryption algorithm are respectively configured such that a change in any bit of the input data causes a change in a predetermined bit of its output data; and outputting the stored data for storage.
[0008] According to another aspect, a data verification method is provided, including receiving the stored data output by the data storage method based on an encryption algorithm; extracting the multi-bit random number from the stored data based on a decryption algorithm; determining the distribution of the extracted multi-bit random number; comparing the determined distribution with the specific distribution; and determining whether the stored data is trustworthy based on the comparison result.
[0009] According to another aspect, a data verification method is provided, including receiving the stored data output by the data storage method based on a diffusion function; extracting the multi-bit random number from the stored data based on an inverse diffusion function; determining the distribution of the extracted multi-bit random number; comparing the determined distribution with the specific distribution; and determining whether the stored data is trustworthy based on the comparison result.
[0010] According to another aspect, a data processing device is provided, including a receiving unit that receives data to be stored and a multi-bit random number having a specific distribution; a combining unit that mixes the multi-bit random number and the data to be stored based on a diffusion function and / or an encryption algorithm to generate stored data, wherein the diffusion function and the encryption algorithm are respectively configured such that a change in any bit of the input data causes a change in a predetermined bit of its output data; and an output unit that outputs the stored data for storage.
[0011] According to another aspect, a data processing device is provided, including a receiving unit that receives the stored data output by a data processing device based on an encryption algorithm; an extraction unit that extracts the multi-bit random number from the stored data based on a decryption algorithm; and a determination unit that determines the distribution of the extracted multi-bit random number, compares the determined distribution with the specific distribution, and determines whether the stored data is trustworthy based on the comparison result.
[0012] According to another aspect, a data processing device is provided, including a receiving unit that receives the stored data output by a data processing device based on a diffusion function; an extraction unit that extracts the multi-bit random number from the stored data based on an inverse diffusion function; and a determination unit that determines the distribution of the extracted multi-bit random number, compares the determined distribution with the specific distribution, and determines whether the stored data is trustworthy based on the comparison result.
[0013] According to another aspect, a data protection device is provided, including a memory; and the data processing device according to various embodiments of the present specification.
[0014] According to various aspects of the present specification, a data protection method based on the distribution characteristics of random numbers is disclosed. Through this distribution, the integrity of in-memory data can be quickly judged. Thus, without relying on the calculation logic for the data itself, it can be applicable to both encrypted data and unencrypted data scenarios. Furthermore, the data protection solution of the present specification can also be used together with a data protection method that depends on the calculation of the stored data itself, thereby strengthening the data protection intensity. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] Figure 1 A flowchart showing a data storage method according to an embodiment is shown;
[0016] Figure 2 A flowchart showing a data verification method according to an embodiment is shown;
[0017] Figure 3 A block diagram showing a data processing device according to an embodiment is shown;
[0018] Figure 4 FIG. 1 shows a block diagram of a data processing device according to an embodiment;
[0019] Figure 5 FIG. 2 shows a block diagram of an electronic device 800 as a data protection device according to an embodiment.
[0020] The various aspects and features of this specification are described with reference to the above-mentioned drawings. Generally, the same or similar reference numerals are used to denote the same components. The above-mentioned drawings are merely schematic and not restrictive. Without departing from the gist of this specification, the dimensions, shapes, reference numerals, or appearances of the various elements in the above-mentioned drawings may change and are not limited to those shown in the drawings of the specification only. DETAILED DESCRIPTION
[0021] The embodiments according to the various aspects of this specification relate to data storage and verification, particularly to the storage and verification of memory data. The following will be described with reference to memory data, but this is not restrictive, and the solutions of the embodiments according to the various aspects of this specification are applicable to any type and purpose of data.
[0022] Figure 1 FIG. 3 shows a flowchart of a data storage method 100 according to an embodiment. Specifically, the method 100 involves adding a random number to the data to be stored before storing the data for subsequent data verification to prevent the use of corrupted data.
[0023] According to the method 100, the memory data to be stored and the random number are received in steps 110 and 120 respectively. The received memory data can be any type of data to be stored. The received random number has multiple bits and has a specific distribution. The distribution characteristics of the random number with multiple bits can be determined in advance and the specific distribution can be recorded.
[0024] In one embodiment, the random number can be generated by a hardware random number generation device, such as a hardware random number module used in the current computer system and chip module. Such a hardware-generated random number has relatively stable and unique distribution characteristics and can be used as a trustworthy protection reference. Thereafter, the distribution of the random number can be determined and recorded. Generally, the multi-bit random number output by the hardware random number module has a relatively stable randomness distribution.
[0025] In step 130, the random number with multiple bits is mixed with the memory data to be stored. In one embodiment, the random number can be added to specific positions in the memory data respectively to change the memory data to be stored. Specifically, the random number can be added to the memory data at any predetermined granularity, such as in units of pages or in-page offsets.
[0026] When the data to be stored does not need to be encrypted, a predetermined diffusion function can be used to diffuse this change to the in-memory data to be stored by adding a random number, so that the change to the in-memory data by the random number is more evenly distributed, realizing the full mixing of the random number and the in-memory data. It should be understood that the full mixing of the random number and the in-memory data is necessary. Only when the random number is fully mixed and distributed into the in-memory data, will the random number be changed simultaneously when an attacker tampers with or destroys the in-memory data.
[0027] The diffusion function has input data and output data. In this embodiment, the input data of the diffusion function can be a pre-combined random number and in-memory data, and the output data is the stored data in which multiple bits of the random number and the in-memory data are fully mixed. However, it is also expected that the input of the diffusion function is both the random number and the in-memory data to be stored. The diffusion function is configured such that a change in any one bit of the input data causes a change in a predetermined number of bits in its output data. For example, when one bit of the input data changes relative to the original data, a predetermined number or percentage of bits in the output data change relative to the original data. In one embodiment, the diffusion function is configured to satisfy the avalanche effect, that is, a change in any one bit of the input data causes an average of half of the bits in its output data to change.
[0028] When the data to be stored needs to be encrypted, the diffusion function may not be used. This is because the inventors recognize that common encryption algorithms (such as corresponding encryption algorithms) have performance similar to that of a diffusion function, which can make the random number and the in-memory data mix more evenly. In this embodiment, after adding the random number to the in-memory data to be stored, an encryption algorithm can be performed on the in-memory data to mix the random number and the in-memory data. The encryption algorithm is also configured such that a change in any one bit of the input data causes a change in a predetermined number of bits in its output data. And, in one embodiment, the encryption algorithm is configured to satisfy the avalanche effect.
[0029] In step 140, the stored data is obtained through the mixing in step 130. In step 150, the stored data is output and stored in the memory for later use.
[0030] The data storage method according to the embodiments of the present specification has been described above for the cases where the data to be stored does not need and needs to be encrypted respectively. It can be understood that this is not restrictive. For those skilled in the art, it can be envisaged that when the data to be stored needs to be encrypted, the diffusion function can also be used. For example, the diffusion function can be used first to promote the mixing of the random number and the in-memory data, and then the encryption algorithm can be performed.
[0031] Figure 2 A flowchart of a data verification method 200 according to an embodiment is shown. Specifically, the method 200 relates toFigure 1 Verify the stored data generated by the method 100 shown, especially verify the data integrity.
[0032] According to this method 200, in step 210, receive the stored data stored according to the above method 100. In step 220, in one embodiment, when a diffusion function is used in method 100, that is, when encryption is not performed, input the stored data into the inverse diffusion function, so as to extract the multi-bit random number added before from the stored data. Thus, in steps 230 and 240, the memory data and the multi-bit random number are obtained respectively. In another embodiment, when an encryption algorithm is used in method 100, that is, when encryption is performed, perform a decryption algorithm on the stored data. Thus, in steps 230 and 240, the memory data and the multi-bit random number are obtained respectively. In another embodiment, when both a diffusion function and an encryption algorithm are used in method 100, in step 220, use both the inverse diffusion function and the decryption algorithm. Here, the inverse diffusion function and the decryption algorithm are respectively the inverse operations of the previously mentioned diffusion function and encryption algorithm, and their purpose is to extract the multi-bit random number mixed with the memory data during the previous storage process, so as to facilitate subsequent verification of whether its distribution has changed due to being attacked or damaged.
[0033] In step 240, also determine the distribution of the extracted multi-bit random data. In step 250, receive the specific distribution of the multi-bit random number received in step 120 of method 100 before. In step 260, compare the distribution determined in step 240 with the specific distribution received in step 250 to determine whether the two are the same. If they are the same, then in step 270, determine that the stored data is not damaged and is trustworthy. In particular, the memory data obtained in step 230 is trustworthy and further processing can be performed based on this memory data. If they are not the same, then in step 280, determine that the stored data has been damaged and is untrustworthy. In particular, the memory data obtained in step 230 is untrustworthy and this memory data cannot be used for subsequent processing. An appropriate alarm can also be generated in step 280.
[0034] The above reference Figure 1 and Figure 2 respectively describe the data storage and verification methods according to this specification. It can be understood that each step therein can be appropriately modified and adjusted to achieve the corresponding effects.
[0035] Figure 3 Shows a block diagram of a data processing device 10 according to an embodiment. This data processing device 10 is used to execute the data storage method as shown above Figure 1 to fully mix the random number with the memory data to generate stored data. The stored data generated in this way can be used as a reference when it is damagedFigure 2 The described method is verified to ensure data integrity.
[0036] The data processing device 10 includes a receiving unit 11, a combining unit 12, and an output unit 13. The receiving unit receives memory data to be stored and a multi-bit random number with a specific distribution. In the case where encryption is not required, the combining unit 12 inputs the memory data and the random number into a diffusion function to mix the memory data and the random number. In the case where encryption is required, the combining unit 12 adds the random number to the memory data and then executes an encryption algorithm, thereby mixing the memory data and the random number. The stored data obtained through mixing is output via the output unit 13.
[0037] Figure 4 The block diagram of a data processing device 20 according to an embodiment is shown. The data processing device 20 is used to execute the data verification method as described above Figure 2 shown.
[0038] The data processing device 20 includes a receiving unit 21, an extraction unit 22, and a determination unit 23. The receiving unit 21 receives the stored data output according to the data storage method described in this specification. When the stored data is encrypted, the extraction unit 22 extracts a multi-bit random number from the stored data based on a decryption algorithm. When the stored data is not encrypted but diffused by a diffusion function, the extraction unit 22 extracts a multi-bit random number based on an inverse diffusion function. The extraction unit 22 can also extract the memory data at the same time.
[0039] The determination unit 23 receives the extracted random number, determines the distribution of the extracted random number, compares the determined distribution with the received specific distribution, and determines whether the stored data (memory data) is trustworthy based on the comparison result. In one embodiment, when the stored data is determined to be trustworthy, the memory data can be output for subsequent processing. When the stored data is determined to be untrustworthy, an alarm can be output.
[0040] Although the data processing devices 10 and 20 that execute the data storage method and the data verification method are described with reference to Figure 3 and Figure 4 respectively, it can be understood that the functions of these two data processing devices can be implemented in the same processing device, and different units can be divided as needed to execute the corresponding functions.
[0041] It can be understood that the functions of each unit in the devices of the various embodiments of this specification and the corresponding method processes can be implemented by computer programs / software. These software can be loaded into the corresponding devices to execute the corresponding functions, especially when running to execute the methods according to the various embodiments of this specification.
[0042] Figure 5FIG. 0 shows a block diagram of an electronic device 800 as a data protection device according to an embodiment.
[0043] As Figure 5 shown, the electronic device 800 may include at least one processor 810, a memory (e.g., non-volatile memory) 820, a memory 830, and a communication interface 840, and the at least one processor 810, the memory 820, the memory 830, and the communication interface 840 are connected together via a bus 850. The at least one processor 810 executes at least one computer-readable instruction stored or encoded in the memory (i.e., the above-mentioned elements implemented in software form).
[0044] In one embodiment, computer-executable instructions are stored in the memory, which when executed cause the at least one processor 810 to execute the methods according to various embodiments of this specification. The data storage method and the data verification method according to the embodiments of this specification can be executed by the at least one processor 810 as data protection methods.
[0045] It can be understood that the data processing device according to various embodiments of this specification can also be implemented by software, for example, implemented as a computer program stored on a computer-readable medium.
[0046] It must be noted that the embodiments of this specification are described with reference to different topics. In particular, some embodiments are described with reference to method-type claims, while other embodiments are described with reference to device-type claims. However, those skilled in the art will learn from the above and the following descriptions that, unless otherwise specified, any combination between features related to different topics is also considered to be disclosed by this application in addition to any combination of features belonging to one type of topic. And, all features can be combined to provide a synergistic effect greater than the simple addition of the features.
[0047] The above describes this specification with reference to specific embodiments. Those skilled in the art should understand that, without departing from the spirit and basic features of this specification, the technical solutions of this specification can be implemented in various ways. The specific embodiments are merely illustrative and not restrictive. In addition, these embodiments can be arbitrarily combined to achieve the purpose of this specification. The protection scope of this specification is defined by the appended claims.
[0048] In some cases, the actions or steps recited in the claims can be executed in a different order than in the embodiments and still achieve the desired result. Additionally, the processes depicted in the figures do not necessarily require the particular order or sequential order shown to achieve the desired result. In certain implementations, multitasking and parallel processing are also possible or may be advantageous.
[0049] The word "comprising" in the description and claims does not exclude the presence of other elements or steps. The functions of the individual elements described in the description or recited in the claims may also be split or combined and implemented by a corresponding plurality of elements or a single element.
Claims
1. A data verification method, comprising: Receiving stored data stored according to the following data storage method: Receiving data to be stored; Receiving a multi-bit random number with a specific distribution; Mixing the multi-bit random number and the data to be stored based on an encryption algorithm to generate stored data, wherein the encryption algorithm is configured such that a change in any bit of the input data causes a change in a predetermined bit of its output data; and Outputting the stored data for storage; Extracting the multi-bit random number from the stored data based on a decryption algorithm; Determining the distribution of the extracted multi-bit random number; Comparing the determined distribution with the specific distribution; and Determining whether the stored data is trustworthy based on the comparison result.
2. The data verification method according to claim 1, wherein The encryption algorithm is configured such that a change in any bit of the input data causes a change in an average of half of the bits of its output data.
3. A data verification method, comprising Receiving stored data stored according to the following data storage method: Receiving data to be stored; Receiving a multi-bit random number with a specific distribution; Mixing the multi-bit random number and the data to be stored based on a diffusion function to generate stored data, wherein, The diffusion function is configured such that a change in any bit of the input data causes a change in a predetermined bit of its output data; and Outputting the stored data for storage; Extracting the multi-bit random number from the stored data based on an inverse diffusion function; Determining the distribution of the extracted multi-bit random number; Comparing the determined distribution with the specific distribution; and Determining whether the stored data is trustworthy based on the comparison result.
4. The data verification method according to claim 3, wherein The diffusion function is configured such that a change in any bit of the input data causes a change in an average of half of the bits of its output data.
5. A data processing device, comprising: A receiving unit that receives stored data stored according to the following data storage method; Receiving data to be stored; Receiving a multi-bit random number with a specific distribution; Mixing the multi-bit random number and the data to be stored based on an encryption algorithm to generate stored data, wherein the encryption algorithm is configured such that a change in any bit of the input data causes a change in a predetermined bit of its output data; and Outputting the stored data for storage; An extraction unit that extracts the multi-bit random number from the stored data based on a decryption algorithm; and A determination unit that determines the distribution of the extracted multi-bit random number, compares the determined distribution with the specific distribution, and determines whether the stored data is trustworthy based on the comparison result.
6. The data processing device according to claim 5, wherein The encryption algorithm is configured such that a change in any bit of the input data causes a change in an average of half of the bits of its output data.
7. A data processing device, comprising A receiving unit that receives stored data stored according to the following data storage method: Receiving data to be stored; Receiving a multi-bit random number with a specific distribution; Mixing the multi-bit random number and the data to be stored based on a diffusion function to generate stored data, wherein the diffusion function is configured such that a change in any bit of the input data causes a change in a predetermined bit of its output data; and Outputting the stored data for storage; An extraction unit that extracts the multi-bit random number from the stored data based on an inverse diffusion function; and A determination unit that determines the distribution of the extracted multi-bit random number, compares the determined distribution with the specific distribution, and determines whether the stored data is credible based on the comparison result.
8. The data processing device according to claim 7, wherein The diffusion function is configured such that a change in any bit of the input data causes a change in an average of half of the bits of its output data.
9. A data protection device, comprising A memory; and The data processing device according to any one of claims 5-8.
10. The data protection device according to claim 9, further comprising A hardware random number generation device that generates a multi-bit random number having the specific distribution.
Citation Information
Patent Citations
Memory integrity
CN109582604A
Method and Apparatus to Encrypt Plaintext Data
US20150006905A1