Data processing method, device, equipment and medium based on encryption algorithm

The insertion position of the identification string is determined by the national secret encryption model and prediction model, which solves the risk of data being decrypted by database collision during transmission and realizes high-security encryption processing of data.

CN114528574BActive Publication Date: 2025-10-03CHINA PING AN LIFE INSURANCE CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202210149025.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-02-18
Publication Date
2025-10-03
Estimated Expiration
2042-02-18

AI Technical Summary

Technical Problem

In the existing technology, although sensitive information is transmitted after at least one layer of encryption, there is still a risk that the data will be intercepted or leaked and then decrypted by database collision, resulting in reduced data security.

Method used

After the encrypted data is initially encrypted using the national secret encryption model, the target sub-segment and the number of insertion bits of the identification string are determined through the prediction model, and the identification string is inserted into the corresponding position to form the final encrypted data.

Benefits of technology

It improves the security of data and makes it difficult to crack the final encrypted data without informing the related parties of the specific encryption and processing rules, greatly improving the security of data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114528574B_ABST
    Figure CN114528574B_ABST
Patent Text Reader

Abstract

The present invention relates to information security and provides a data processing method, apparatus, device, and medium based on an encryption algorithm. The method first encrypts data to be encrypted based on a national secret encryption model to obtain initial encrypted data. An identification string corresponding to a third-party name and a prediction model are then obtained. The identification string is input into the prediction model to obtain a prediction result. The target subsegment to which the identification string belongs and the target number of insertion bits are determined based on the prediction result. Finally, the identification string is inserted into the corresponding position of the target subsegment based on the target number of insertion bits to update the initial encrypted data to obtain final encrypted data. This method implements the insertion of the identification string after the data is encrypted using the national secret encryption model. If the specific data encryption and processing rules are not disclosed to the related parties, the final encrypted data is difficult to crack, greatly improving data security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of cryptographic technology for information security, and in particular to a data processing method, device, computer equipment, and storage medium based on an encryption algorithm. Background Art

[0002] In the age of the Internet of Everything, data is exploding, and sensitive user information requires extreme care in its handling. Specifically, when sensitive information is transferred within an enterprise, it should be encrypted before transmission to minimize data leakage. While various encryption algorithms are available, data cannot be intercepted or leaked, and then decrypted using database collision techniques, posing a certain risk of data leakage. Summary of the Invention

[0003] The embodiments of the present invention provide a data processing method, apparatus, computer equipment and storage medium based on an encryption algorithm, aiming to solve the problem in the prior art that sensitive information is transmitted after at least one layer of encryption, which inevitably leads to data being intercepted or leaked and then decrypted using database collision and collision, resulting in reduced data security.

[0004] In a first aspect, an embodiment of the present invention provides a data processing method based on an encryption algorithm, comprising:

[0005] In response to a data encryption instruction, obtaining data to be encrypted corresponding to the data encryption instruction;

[0006] Encrypting the data to be encrypted according to the obtained national secret encryption model to obtain initial encrypted data;

[0007] The character string corresponding to the initial encrypted data is segmented according to a preset segmentation strategy to obtain a segmentation result; wherein the segmentation result includes a plurality of sub-segments;

[0008] Obtaining an identification string corresponding to a third-party name, obtaining a prediction model, and inputting the identification string into the prediction model to obtain a prediction result;

[0009] Determining the target subsegment to which the identification character string belongs and the target number of insertion bits according to the prediction result; and

[0010] The identification character string is inserted into the corresponding position of the target sub-segment according to the target insertion bit number to update the initial encrypted data to obtain the final encrypted data.

[0011] In a second aspect, an embodiment of the present invention provides a data processing device based on an encryption algorithm, comprising:

[0012] a data to be encrypted acquiring unit, configured to acquire the data to be encrypted corresponding to the data encryption instruction in response to the data encryption instruction;

[0013] An initial encryption unit, configured to encrypt the data to be encrypted according to the obtained national secret encryption model to obtain initial encrypted data;

[0014] a string segmentation unit, configured to segment the string corresponding to the initial encrypted data according to a preset segmentation strategy to obtain a segmentation result; wherein the segmentation result includes a plurality of sub-segments;

[0015] A prediction unit, configured to obtain an identification string corresponding to a third-party name, obtain a prediction model, and input the identification string into the prediction model to obtain a prediction result;

[0016] an insertion information acquisition unit, configured to determine a target subsegment to which the identification character string belongs and a target number of insertion bits according to the prediction result; and

[0017] The final encryption unit is used to insert the identification character string into the corresponding position of the target sub-segment according to the target insertion bit number to update the initial encrypted data to obtain the final encrypted data.

[0018] In a third aspect, an embodiment of the present invention further provides a computer device, which includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the data processing method based on the encryption algorithm described in the first aspect above is implemented.

[0019] In a fourth aspect, an embodiment of the present invention further provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the processor executes the data processing method based on the encryption algorithm described in the first aspect above.

[0020] The embodiments of the present invention provide a data processing method, apparatus, computer equipment, and storage medium based on an encryption algorithm. The method first encrypts the data to be encrypted based on a national secret encryption model to obtain initial encrypted data. Then, an identification string corresponding to the third-party name is obtained and a prediction model is obtained. The identification string is input into the prediction model to obtain a prediction result. The target subsegment to which the identification string belongs and the target number of insertion bits are determined based on the prediction result. Finally, the identification string is inserted into the corresponding position of the target subsegment based on the target number of insertion bits to update the initial encrypted data to obtain the final encrypted data. This method implements the insertion of the identification string after the data to be encrypted using the national secret encryption model. If the related parties are not informed of the specific data encryption and processing rules, the final encrypted data is not easily cracked, greatly improving data security. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0022] Figure 1 A schematic diagram of an application scenario of the data processing method based on the encryption algorithm provided in an embodiment of the present invention;

[0023] Figure 2 A schematic diagram of a data processing method based on an encryption algorithm provided in an embodiment of the present invention;

[0024] Figure 3 A schematic block diagram of a data processing device based on an encryption algorithm provided by an embodiment of the present invention;

[0025] Figure 4 A schematic block diagram of a computer device provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0026] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0027] It will be understood that when used in this specification and the appended claims, the terms “comprises” and “comprising” indicate the presence of described features, integers, steps, operations, elements and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or groups thereof.

[0028] It should also be understood that the terminology used in this specification is for the purpose of describing particular embodiments only and is not intended to limit the present invention. As used in the specification and appended claims, the singular forms "a," "an," and "the" are intended to include the plural forms unless the context clearly indicates otherwise.

[0029] It should be further understood that the term "and / or" used in the present description and the appended claims refers to and includes any and all possible combinations of one or more of the associated listed items.

[0030] See also Figure 1 and Figure 2 , Figure 1 A schematic diagram of an application scenario of the data processing method based on the encryption algorithm provided in an embodiment of the present invention; Figure 2 A flow chart of a data processing method based on an encryption algorithm provided in an embodiment of the present invention is provided. The data processing method based on the encryption algorithm is applied in a server and is executed by application software installed in the server.

[0031] like Figure 2 As shown, the method includes steps S101 to S106.

[0032] S101. In response to a data encryption instruction, obtain data to be encrypted corresponding to the data encryption instruction.

[0033] In this embodiment, the execution can be performed by either the user end or the server. When a user performs an operation on the user end or the server (the execution entities corresponding to the user end or the server are collectively referred to as the sending end in this application) and needs to send a certain data to be encrypted to the receiving end, it is necessary to encrypt it on the sending end before sending it, thereby improving data security. Among them, the data to be encrypted can be instant messaging data, user behavior data, user basic data and other types of data during specific implementation, and the data to be encrypted is legally obtained data. At this time, it is necessary to detect in real time on the sending end whether the user operation triggers the generation of a data encryption instruction. If the user selects data and operates to send it, it will trigger the generation of a data encryption instruction. At this time, the corresponding data to be encrypted is first obtained to perform subsequent encryption operations.

[0034] S102: Encrypt the data to be encrypted according to the obtained national secret encryption model to obtain initial encrypted data.

[0035] In this embodiment, after the sender obtains the data to be encrypted, it first obtains the locally pre-stored national secret encryption model to perform initial encryption on the data to be encrypted. For example, in this application, the national secret SM3 encryption algorithm is used to perform initial encryption on the data to obtain the initial encrypted data. By encrypting the data, data security can be effectively improved.

[0036] In one embodiment, the national secret encryption model is the national secret SM3 encryption algorithm, and step S102 includes:

[0037] Performing binary conversion on the data to be encrypted to obtain first converted data;

[0038] Segmenting the first converted data according to a preset first value to obtain a first segmentation result including a plurality of sub-segments;

[0039] If it is determined that the total number of characters in a subsegment is less than the first value, obtaining the corresponding subsegment as a target subsegment, adding one preset first character and k preset second characters to the end of the target subsegment to obtain a first adjusted subsegment, and obtaining file length information of the first converted data to concatenate the data with the first adjusted subsegment to obtain a second adjusted subsegment; wherein the total number of characters in the target subsegment plus 1 and k equals a preset third value;

[0040] updating the corresponding sub-segment in the first segmentation result to obtain second converted data;

[0041] Grouping the second converted data according to a preset second value to obtain a first grouping result including a plurality of subgroups;

[0042] The sub-groups in the first grouping result are sequentially input into the compression function of the national secret SM3 encryption algorithm for iterative compression to obtain an iterative compression result, and the iterative compression result is used as the initial encrypted data.

[0043] In this embodiment, when encrypting data to be encrypted using the national secret SM3 encryption algorithm, the following operations are specifically performed:

[0044] 1) first performing binary conversion on the data to be encrypted to obtain first converted data;

[0045] 2) Assuming that the length of the first conversion data m is l bits, first divide it by the preset first value (the first value is set to 512 in the specific implementation). If l can divide 512 evenly, it means that there is no need to add 1 1 and multiple 0s at the end; if l cannot divide 512 evenly, it is necessary to first add the bit "1" (that is, the preset first character) to the end of m, and then add k "0"s (that is, the preset second character), where k is the smallest non-negative integer that satisfies l+1+k≡448mod512 (wherein the third value is set to 448). Then add a 64-bit bit string, which is the binary representation of the length l (that is, the file length information of the first conversion data). The bit length of the padded second conversion data m' is a multiple of 512;

[0046] 3) The second converted data m′ is divided into blocks according to a preset second value (in a specific implementation, the second value is equal to the first value, both being 512) to obtain a first grouping result including n subgroups, where each subgroup is a data block of 512 bits in length, and n = (1 + 65 + k) / 512. The block division is performed sequentially according to the bit arrangement order of the second converted data m′. For example, bits 1-512 of the second converted data m′ are divided into the first subgroup, bits 513-1024 are divided into the second subgroup, and so on until all subgroups are completed.

[0047] 4) If the n subgroups of the first grouping result are recorded as the 1st data block B0 to the nth data block B n-1 At this time, the first data block B0 is first compressed based on the compression function CF in the national secret SM3 encryption algorithm to obtain the first compression result V1; then; the compression function is expressed as V i+1 =CF(V i , B i ), and V0=7380166f4914b2b9172442d7da8a0600a96f30bc163138aae38dee4db0fb0e4e; then the first compression result V1 and the second data block B1 are input into the compression function CF for the second compression to obtain the second compression result V2; and so on, until the n-1th compression result V n-1 and the nth data block B n-1 Input to the compression function CF for the nth compression to obtain the nth compression result V n ;

[0048] 5) The obtained n-th compression is performed to obtain the n-th compression result V n As the initial encryption result.

[0049] It can be seen that the above method can realize the rapid encryption of the data to be encrypted through the national encryption SM3 model, and improve the data security through initial encryption.

[0050] In one embodiment, the step of sequentially inputting the subgroups in the first grouping result into a compression function in the national SM3 encryption algorithm for iterative compression to obtain an iterative compression result, and using the iterative compression result as the initial encrypted data includes:

[0051] Get the jth data block B in the first grouping result j-1 , the jth data block B j-1 Divided into 16 message words and the 16 message words are respectively denoted as W j,0 To W j,15; Wherein, the initial value of j is 1 and the value range of j is [1,n], where n represents the total number of subgroups in the first grouping result;

[0052] The jth data block B j-1 The corresponding message word W j,0 To W j,15 According to the preset first message word expansion strategy, 52 first extended message words are obtained and are denoted as W j,16 To W j,67 ;

[0053] The jth data block B j-1 The corresponding message word W j,0 To W j,63 According to the preset second message word expansion strategy, 64 second extended message words are obtained and are respectively recorded as W' j,0 To W' j,63 ;

[0054] By the jth data block B j-1 The corresponding message word W j,0 To W j,63 And the second extended message word W' j,0 To W' j,63 Composing the jth data block B j-1 The corresponding extended message character set;

[0055] Get the jth data block B j-1 The corresponding j-1th compression result V j-1 , compress the j-1th result V j-1 Store to word register; where V0 = 7380166f4914b2b9172442d7da8a0600a96f30bc163138aae38dee4db0fb0e4e;

[0056] The j-1th compression result V j-1 According to the preset iteration strategy and the preset number of iterations of the extended message word set, the same compression result V as the j-1th compression result is obtained. j-1 The corresponding j-th compression result V j ;

[0057] Increment j by 1 to update the value of j;

[0058] If it is determined that j does not exceed n, return to execute to obtain the jth data block B in the first grouping result j-1 , the jth data block B j-1 Divided into 16 message words and the 16 message words are respectively denoted as W j0 To W j15 Steps;

[0059] If it is determined that j exceeds n, obtain the nth compression result V n As the initial encrypted data.

[0060] In this embodiment, since the data to be encrypted has previously been binary-converted to obtain first converted data, and the first converted data has also been divided into a first grouping result comprising n subgroups, each group consisting of 512 bits, the data block corresponding to each subgroup can now be compressed using an iterative compression algorithm to obtain initial encrypted data. The following describes the detailed process of obtaining the first compression result V1 based on the first data block B0 and the initial compression result V0:

[0061] 11) Since the first data block B0 is 512 bits, which is equivalent to 64 characters (because every 8 bits in binary represent one character), and a message word is 32 bits, the first data block B0 can be divided into 16 message words and the 16 message words are respectively denoted as W 1,0 To W 1,15 ;

[0062] 12) The default first message word expansion strategy is:

[0063] W j,l ←P1(W j,l-16 ⊕W j,l-9 ⊕(W j,l-3 <<<15))⊕(W j,l-13 <<<7)⊕W j,l-6 ;

[0064] Where, P1(X)=X⊕(X<<<15)⊕(X<<<23), and the value range of l is [16,67];

[0065] Based on the 16 message words W divided by the first data block B0 1,0 To W 1,15 With the above-mentioned first message word expansion strategy, 52 first extended message words can be obtained and are respectively recorded as W 1,16 To W 1,67 ;

[0066] 13) The preset second message word expansion strategy is: W′ j,m ←W j,m ⊕W j,m+4, The value range of m is [0,63]; based on the 16 message words W divided by the first data block B0 1,0 To W 1,15 , 52 first extended message words W 1,16 To W 1,67 The above second message word expansion strategy can be expanded to obtain 64 second extended message words and are respectively recorded as W' 1,0To W' 1,63 ;

[0067] 14) consists of 16 message words W 1,0 To W 1,15 , 52 first extended message words W 1,16 To W 1,67 and 64 second extended message words W' 1,0 To W' 1,63 The extended message character set corresponding to the first data block B0;

[0068] 15) Obtain the 0th compression result V0 corresponding to the 1st data block B0. Since V0 is a 64-bit hexadecimal number, each bit can be represented by a 4-bit binary number, so V0 corresponds to 256 bits. At this time, V0 is stored in the 8 word registers ABCDEFGH, and each word register can store 32 bits to achieve the initial storage of the 0th compression result V0.

[0069] 16) After the initial assignment of the eight word registers ABCDEFGH, 64 rounds of iteration are performed. Each round of iteration refers to the following iteration strategy:

[0070] SS1←((A<<<12)+E+(T j,L << <L))<<7;

[0071] SS2←SS1⊕(A<<<12);

[0072] TT1←FF j,m (A,B,C)+D+SS2+W' j,m ;

[0073] TT2←GG j,L (E,F,G)+H+SS1+W j,L ;

[0074] D←C;

[0075] C←B<<<9;

[0076] B←A;

[0077] A←TT1;

[0078] H←G;

[0079] G←F<<<19;

[0080] F←E;

[0081] E←P0(TT2);

[0082] Among them, T j,L When L is in the range [0,15], T j,L=79cc4519, and T j,L When L is between [16,63], T j,L =7a879d8a;

[0083] FF j,m (X, Y, Z) FF when the value of m is in [0, 15] j,m (X,Y,Z)=X⊕Y⊕Z, and FF j,m (X, Y, Z) FF when m is in [16, 63] j,m (X,Y,Z)=(X∧Y)∨(X∧Y)∨(Y∧Z);

[0084] GG j,L (X, Y, Z) GG when L is in [0, 15] j,L (X,Y,Z)=X⊕Y⊕Z, and GG j,L (X,Y,Z) when the value of L is [16,63] Among them, X, Y, and Z are words, ∧ is the AND operation, and ∨ is the OR operation. is a negation operation, ⊕ is an exclusive OR operation; where X, Y, and Z are words, ∧ is an AND operation, and ∨ is an OR operation. is a negation operation, ⊕ is an exclusive-or operation;

[0085] P0(X)=X⊕(X<<<9)⊕(X<<<17);

[0086] After the initial assignment of the eight word registers ABCDEFGH based on V0 and 64 rounds of iteration referring to the above iterative strategy, the first compression result V1 can be obtained. After that, the other sub-groups of the first grouping result can also be sequentially input into the compression function and expressed as V i+1 =CF(V i , B i ) performs compression operation. The specific compression operation process refers to the process of obtaining the first compression result V1 from the first data block B0 and the initial compression result V0. It can be seen that this encryption method can effectively improve data security.

[0087] S103 , segmenting the character string corresponding to the initial encrypted data according to a preset segmentation strategy to obtain a segmentation result; wherein the segmentation result includes multiple sub-segments.

[0088] In this embodiment, after obtaining the initial encrypted data (where the initial encrypted data is 256 bits long), it can be converted into a string consisting of 32 characters. This is because every 8 bits can be converted into a character. In order to accurately obtain the specific insertion position of the identification string in the subsequent steps, the string can be segmented according to a pre-set segmentation strategy to obtain segmentation results.

[0089] In one embodiment, the segmentation strategy is used to evenly divide the character string according to a preset number of first segments to obtain segmentation results. Step S103 includes:

[0090] The first number of segments corresponding to the division strategy is obtained, and the character string corresponding to the initial encrypted data is evenly divided according to the first number of segments to obtain a segmentation result.

[0091] In this embodiment, taking the preset number of first segments as 2 as an example, the first 16 characters of the 32-bit string can be divided into the first sub-segment, and the last 16 characters can be divided into the second sub-segment, thereby achieving fast and even division of the string, so that the identification string to be inserted subsequently can be inserted at any position in any of the above sub-segments.

[0092] S104: Obtain an identification string corresponding to the third-party name, obtain a prediction model, and input the identification string into the prediction model to obtain a prediction result.

[0093] In this embodiment, because the data to be encrypted is encrypted at the sending end so that the data can be sent to the receiving end more securely, the third-party name of the receiving end can also be obtained first, for example, the third-party name is a company name, department name, etc.; then the third-party name is converted into an identification string, for example, the third-party name in Chinese is directly converted into the company's English abbreviation as the identification string; then the identification string is used as the input of the prediction model (wherein the prediction model uses a neural network model such as a convolutional neural network and a recurrent neural network) to perform a prediction operation to obtain a prediction result. In this case, an insertion position in the segmented result is not randomly selected to insert the identification string, but the prediction operation obtains its corresponding prediction result and then the identification character is correspondingly inserted into the corresponding position in the segmented result.

[0094] In one embodiment, step S104 includes:

[0095] An input vector corresponding to the identification character string is obtained, and the input vector is input into the prediction model for calculation to obtain a prediction result.

[0096] In this embodiment, the general identification string is an English string and cannot be directly input into the prediction model for calculation. It needs to be converted into an input vector first. More specifically, the Word2Vec model can be used to convert the word corresponding to the English string into an input vector, and then the input vector is input into the prediction model for calculation to output a prediction result. The general prediction result is an output vector, which represents the probability that the identification string belongs to each of the preset multiple categories. For example, there are 5 preset categories (such as predicted category 1-predicted category 5), and the corresponding probabilities of the identification string belonging to predicted category 1-predicted category 5 are 0.3, 0.25, 0.2, 0.15 and 0.1 respectively. At this time, it can be seen that the probability value of the identification string belonging to predicted category 1 is the maximum value. At this time, the prediction result corresponding to the identification string is determined to be that it belongs to predicted category 1. Through the prediction model, the prediction result corresponding to the identification string can be quickly determined, thereby serving as a parameter to assist in the subsequent determination of the insertion position of the identification string.

[0097] S105 : Determine the target subsegment to which the identification character string belongs and the target number of insertion bits according to the prediction result.

[0098] In this embodiment, after obtaining the prediction result, the category number corresponding to the prediction result can be used as the sequence number of the target sub-segment to which the identification string belongs, thereby quickly determining the insertion position of the identification string. For example, referring to the above example, if the prediction result indicates that the identification string belongs to prediction category 1, and category number 1 of prediction category 1 can be used to select the first sub-segment in the segmentation result as the target sub-segment, then the identification string can be directly added to the end of the first sub-segment, thereby achieving a rapid update of the first sub-segment.

[0099] In one embodiment, step S105 includes:

[0100] Obtaining the category serial number corresponding to the prediction result, and obtaining the total number of segments of the sub-segments included in the segmentation result;

[0101] Calculating the remainder of the category serial number with respect to the total number of the segments to obtain a remainder result, and using the remainder result as the target segment serial number of the sub-segment to which the identification character string belongs;

[0102] According to the target segment sequence number, a corresponding sub-segment is obtained from the segmentation result as a target sub-segment;

[0103] The total number of target characters in the target sub-segment is obtained, and the target number of insertion bits is obtained by adding 1 to the total number of target characters.

[0104] More specifically, in this embodiment, after obtaining the prediction result, the remainder obtained by calculating the remainder between the category number (i.e., category number) corresponding to the prediction result and the total number of sub-segments included in the segmentation result can be used as the target segment number of the sub-segment to which the identification string belongs, thereby quickly determining the target segment to be inserted into. Furthermore, when determining the target number of characters to be inserted into the first sub-segment, the total number of characters in the first sub-segment is first obtained, and then the total number of characters plus one is used as the target number of characters to be inserted into the first character of the identification string. After the identification string is inserted into the end of the first sub-segment, the insertion of the identification string is completed.

[0105] S106: Insert the identification character string into the corresponding position of the target sub-segment according to the target insertion bit number to update the initial encrypted data to obtain the final encrypted data.

[0106] In this embodiment, by inserting the identification string into the corresponding position of the target subsegment according to the target insertion bit number, the initial encrypted data is updated, which is equivalent to performing a secondary encryption operation, thereby improving data security. The final encrypted data obtained at the transmitting end can then be sent to the receiving end. Upon receiving the final encrypted data, the receiving end can decrypt it by referring to the reverse encryption process to obtain the restored encrypted data.

[0107] In one embodiment, after step S106, the method further includes:

[0108] The final encrypted data is sent to a receiving end corresponding to the third-party name, and the target number of insertion bits is sent to the receiving end.

[0109] In this embodiment, after receiving the final encrypted data, the receiving end can only decrypt and restore the original encrypted data for viewing based on the national encryption SM3 decryption model after the insertion position of the known identification string and the correct string of the known identification string are removed.

[0110] The embodiments of the present application can acquire and process relevant data in the server based on artificial intelligence technology. Artificial Intelligence (AI) is the theory, method, technology, and application system that uses digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use knowledge to achieve optimal results.

[0111] Fundamental AI technologies generally include sensors, dedicated AI chips, cloud computing, distributed storage, big data processing, operating / interaction systems, and mechatronics. AI software technologies primarily encompass computer vision, robotics, biometrics, speech processing, natural language processing, and machine learning / deep learning.

[0112] This method realizes the insertion of an identification string into the data encrypted by the national secret encryption model. If the related parties are not informed of the specific data encryption and processing rules, the final encrypted data is not easy to be cracked, which greatly improves the security of the data.

[0113] The embodiment of the present invention further provides a data processing device based on an encryption algorithm, which is used to execute any embodiment of the aforementioned data processing method based on an encryption algorithm. Figure 3 , Figure 3 It is a schematic block diagram of a data processing device 100 based on an encryption algorithm provided in an embodiment of the present invention.

[0114] Among them, such as Figure 3 As shown, the data processing device 100 based on the encryption algorithm includes a to-be-encrypted data acquisition unit 101 , an initial encryption unit 102 , a character string segmentation unit 103 , a prediction unit 104 , an insertion information acquisition unit 105 and a final encryption unit 106 .

[0115] The to-be-encrypted data acquiring unit 101 is configured to, in response to a data encryption instruction, acquire the to-be-encrypted data corresponding to the data encryption instruction.

[0116] In this embodiment, the execution can be performed by either the user end or the server. When a user performs an operation on the user end or the server (the execution entities corresponding to the user end or the server are collectively referred to as the sending end in this application) and needs to send a certain data to be encrypted to the receiving end, it is necessary to encrypt it on the sending end before sending it, thereby improving data security. Among them, the data to be encrypted can be instant messaging data, user behavior data, user basic data and other types of data during specific implementation, and the data to be encrypted is legally obtained data. At this time, it is necessary to detect in real time on the sending end whether the user operation triggers the generation of a data encryption instruction. If the user selects data and operates to send it, it will trigger the generation of a data encryption instruction. At this time, the corresponding data to be encrypted is first obtained to perform subsequent encryption operations.

[0117] The initial encryption unit 102 is used to encrypt the data to be encrypted according to the obtained national secret encryption model to obtain initial encrypted data.

[0118] In this embodiment, after the sender obtains the data to be encrypted, it first obtains the locally pre-stored national secret encryption model to perform initial encryption on the data to be encrypted. For example, in this application, the national secret SM3 encryption algorithm is used to perform initial encryption on the data to obtain the initial encrypted data. By encrypting the data, data security can be effectively improved.

[0119] In one embodiment, the national secret encryption model is the national secret SM3 encryption algorithm, and the initial encryption unit 102 is specifically used to:

[0120] Performing binary conversion on the data to be encrypted to obtain first converted data;

[0121] Segmenting the first converted data according to a preset first value to obtain a first segmentation result including a plurality of sub-segments;

[0122] If it is determined that the total number of characters in a subsegment is less than the first value, obtaining the corresponding subsegment as a target subsegment, adding one preset first character and k preset second characters to the end of the target subsegment to obtain a first adjusted subsegment, and obtaining file length information of the first converted data to concatenate the data with the first adjusted subsegment to obtain a second adjusted subsegment; wherein the total number of characters in the target subsegment plus 1 and k equals a preset third value;

[0123] updating the corresponding sub-segment in the first segmentation result to obtain second converted data;

[0124] Grouping the second converted data according to a preset second value to obtain a first grouping result including a plurality of subgroups;

[0125] The sub-groups in the first grouping result are sequentially input into the compression function of the national secret SM3 encryption algorithm for iterative compression to obtain an iterative compression result, and the iterative compression result is used as the initial encrypted data.

[0126] In this embodiment, when encrypting data to be encrypted using the national secret SM3 encryption algorithm, the following operations are specifically performed:

[0127] 1) first performing binary conversion on the data to be encrypted to obtain first converted data;

[0128] 2) Assuming that the length of the first conversion data m is l bits, first divide it by the preset first value (the first value is set to 512 in the specific implementation). If l can divide 512 evenly, it means that there is no need to add 1 1 and multiple 0s at the end; if l cannot divide 512 evenly, it is necessary to first add the bit "1" (that is, the preset first character) to the end of m, and then add k "0"s (that is, the preset second character), where k is the smallest non-negative integer that satisfies l+1+k≡448mod512 (wherein the third value is set to 448). Then add a 64-bit bit string, which is the binary representation of the length l (that is, the file length information of the first conversion data). The bit length of the padded second conversion data m' is a multiple of 512;

[0129] 3) The second converted data m′ is divided into blocks according to a preset second value (in a specific implementation, the second value is equal to the first value, both being 512) to obtain a first grouping result including n subgroups, where each subgroup is a data block of 512 bits in length, and n = (1 + 65 + k) / 512. The block division is performed sequentially according to the bit arrangement order of the second converted data m′. For example, bits 1-512 of the second converted data m′ are divided into the first subgroup, bits 513-1024 are divided into the second subgroup, and so on until all subgroups are completed.

[0130] 4) If the n subgroups of the first grouping result are recorded as the 1st data block B0 to the nth data block B n-1 At this time, the first data block B0 is first compressed based on the compression function CF in the national secret SM3 encryption algorithm to obtain the first compression result V1; then; the compression function is expressed as V i+1 =CF(V i , B i ), and V0=7380166f4914b2b9172442d7da8a0600a96f30bc163138aae38dee4db0fb0e4e; then the first compression result V1 and the second data block B1 are input into the compression function CF for the second compression to obtain the second compression result V2; and so on, until the n-1th compression result V n-1 and the nth data block B n-1 Input to the compression function CF for the nth compression to obtain the nth compression result V n ;

[0131] 5) The obtained n-th compression is performed to obtain the n-th compression result V n As the initial encryption result.

[0132] It can be seen that the above method can realize the rapid encryption of the data to be encrypted through the national encryption SM3 model, and improve the data security through initial encryption.

[0133] In one embodiment, the step of sequentially inputting the subgroups in the first grouping result into a compression function in the national SM3 encryption algorithm for iterative compression to obtain an iterative compression result, and using the iterative compression result as the initial encrypted data includes:

[0134] Get the jth data block B in the first grouping result j-1 , the jth data block B j-1 Divided into 16 message words and the 16 message words are respectively denoted as W j,0 To W j,15 ; Wherein, the initial value of j is 1 and the value range of j is [1,n], where n represents the total number of subgroups in the first grouping result;

[0135] The jth data block B j-1 The corresponding message word W j,0 To W j,15 According to the preset first message word expansion strategy, 52 first extended message words are obtained and are denoted as W j,16 To W j,67 ;

[0136] The jth data block B j-1 The corresponding message word W j,0 To W j,63 According to the preset second message word expansion strategy, 64 second extended message words are obtained and are respectively recorded as W' j,0 To W' j,63 ;

[0137] By the jth data block B j-1 The corresponding message word W j,0 To W j,63 And the second extended message word W' j,0 To W' j,63 Composing the jth data block B j-1 The corresponding extended message character set;

[0138] Get the jth data block B j-1 The corresponding j-1th compression result V j-1 , compress the j-1th result V j-1 Store to word register; where V0 = 7380166f4914b2b9172442d7da8a0600a96f30bc163138aae38dee4db0fb0e4e;

[0139] The j-1th compression result V j-1According to the preset iteration strategy and the preset number of iterations of the extended message word set, the same compression result V as the j-1th compression result is obtained. j-1 The corresponding j-th compression result V j ;

[0140] Increment j by 1 to update the value of j;

[0141] If it is determined that j does not exceed n, return to execute to obtain the jth data block B in the first grouping result j-1 , the jth data block B j-1 Divided into 16 message words and the 16 message words are respectively denoted as W j0 To W j15 Steps;

[0142] If it is determined that j exceeds n, obtain the nth compression result V n As the initial encrypted data.

[0143] In this embodiment, since the data to be encrypted has previously been binary-converted to obtain first converted data, and the first converted data has also been divided into a first grouping result comprising n subgroups, each group consisting of 512 bits, the data block corresponding to each subgroup can now be compressed using an iterative compression algorithm to obtain initial encrypted data. The following describes the detailed process of obtaining the first compression result V1 based on the first data block B0 and the initial compression result V0:

[0144] 11) Since the first data block B0 is 512 bits, which is equivalent to 64 characters (because every 8 bits in binary represent one character), and a message word is 32 bits, the first data block B0 can be divided into 16 message words and the 16 message words are respectively denoted as W 1,0 To W 1,15 ;

[0145] 12) The default first message word expansion strategy is:

[0146] W j,l ←P1(W j,l-16 ⊕W j,l-9 ⊕(W j,l-3 <<<15))⊕(W j,l-13 <<<7)⊕W j,l-6 ;

[0147] Where, P1(X)=X⊕(X<<<15)⊕(X<<<23), and the value range of l is [16,67];

[0148] Based on the 16 message words W divided by the first data block B0 1,0 To W 1,15With the above-mentioned first message word expansion strategy, 52 first extended message words can be obtained and are respectively recorded as W 1,16 To W 1,67 ;

[0149] 13) The preset second message word expansion strategy is: W′ j,m ←W j,m ⊕W j,m+4, The value range of m is [0,63]; based on the 16 message words W divided by the first data block B0 1,0 To W 1,15 , 52 first extended message words W 1,16 To W 1,67 The above second message word expansion strategy can be expanded to obtain 64 second extended message words and are respectively recorded as W' 1,0 To W' 1,63 ;

[0150] 14) consists of 16 message words W 1,0 To W 1,15 , 52 first extended message words W 1,16 To W 1,67 and 64 second extended message words W' 1,0 To W' 1,63 The extended message character set corresponding to the first data block B0;

[0151] 15) Obtain the 0th compression result V0 corresponding to the 1st data block B0. Since V0 is a 64-bit hexadecimal number, each bit can be represented by a 4-bit binary number, so V0 corresponds to 256 bits. At this time, V0 is stored in the 8 word registers ABCDEFGH, and each word register can store 32 bits to achieve the initial storage of the 0th compression result V0.

[0152] 16) After the initial assignment of the eight word registers ABCDEFGH, 64 rounds of iteration are performed. Each round of iteration refers to the following iteration strategy:

[0153] SS1←((A<<<12)+E+(T j,L << <L))<<7;

[0154] SS2←SS1⊕(A<<<12);

[0155] TT1←FF j,m (A,B,C)+D+SS2+W' j,m ;

[0156] TT2←GG j,L (E,F,G)+H+SS1+W j,L ;

[0157] D←C;

[0158] C←B<<<9;

[0159] B←A;

[0160] A←TT1;

[0161] H←G;

[0162] G←F<<<19;

[0163] F←E;

[0164] E←P0(TT2);

[0165] Among them, T j,L When L is in the range [0,15], T j,L =79cc4519, and T j,L When L is between [16,63], T j,L =7a879d8a;

[0166] FF j,m (X, Y, Z) FF when the value of m is in [0, 15] j,m (X,Y,Z)=X⊕Y⊕Z, and FF j,m (X, Y, Z) FF when m is in [16, 63] j,m (X,Y,Z)=(X∧Y)∨(X∧Y)∨(Y∧Z);

[0167] GG j,L (X, Y, Z) GG when L is in [0, 15] j,L (X,Y,Z)=X⊕Y⊕Z, and GG j,L (X,Y,Z) when the value of L is [16,63] Among them, X, Y, and Z are words, ∧ is the AND operation, and ∨ is the OR operation. is a negation operation, ⊕ is an exclusive OR operation; where X, Y, and Z are words, ∧ is an AND operation, and ∨ is an OR operation. is a negation operation, ⊕ is an exclusive-or operation;

[0168] P0(X)=X⊕(X<<<9)⊕(X<<<17);

[0169] After the initial assignment of the eight word registers ABCDEFGH based on V0 and 64 rounds of iteration referring to the above iterative strategy, the first compression result V1 can be obtained. After that, the other sub-groups of the first grouping result can also be sequentially input into the compression function and expressed as V i+1 =CF(V i , B i) performs compression operation. The specific compression operation process refers to the process of obtaining the first compression result V1 from the first data block B0 and the initial compression result V0. It can be seen that this encryption method can effectively improve data security.

[0170] The string segmentation unit 103 is configured to segment the string corresponding to the initial encrypted data according to a preset segmentation strategy to obtain a segmentation result, wherein the segmentation result includes a plurality of sub-segments.

[0171] In this embodiment, after obtaining the initial encrypted data (where the initial encrypted data is 256 bits long), it can be converted into a string consisting of 32 characters. This is because every 8 bits can be converted into a character. In order to accurately obtain the specific insertion position of the identification string in the subsequent steps, the string can be segmented according to a pre-set segmentation strategy to obtain segmentation results.

[0172] In one embodiment, the segmentation strategy is used to evenly divide the character string according to a preset first number of segments to obtain segmentation results. The character string segmentation unit 103 is specifically used to:

[0173] The first number of segments corresponding to the division strategy is obtained, and the character string corresponding to the initial encrypted data is evenly divided according to the first number of segments to obtain a segmentation result.

[0174] In this embodiment, taking the preset number of first segments as 2 as an example, the first 16 characters of the 32-bit string can be divided into the first sub-segment, and the last 16 characters can be divided into the second sub-segment, thereby achieving fast and even division of the string, so that the identification string to be inserted subsequently can be inserted at any position in any of the above sub-segments.

[0175] The prediction unit 104 is configured to obtain an identification string corresponding to the third-party name, obtain a prediction model, and input the identification string into the prediction model to obtain a prediction result.

[0176] In this embodiment, because the data to be encrypted is encrypted at the sending end so that the data can be sent to the receiving end more securely, the third-party name of the receiving end can also be obtained first, for example, the third-party name is a company name, department name, etc.; then the third-party name is converted into an identification string, for example, the third-party name in Chinese is directly converted into the company's English abbreviation as the identification string; then the identification string is used as the input of the prediction model (wherein the prediction model uses a neural network model such as a convolutional neural network and a recurrent neural network) to perform a prediction operation to obtain a prediction result. In this case, an insertion position in the segmented result is not randomly selected to insert the identification string, but the prediction operation obtains its corresponding prediction result and then the identification character is correspondingly inserted into the corresponding position in the segmented result.

[0177] In one embodiment, the prediction unit 104 is specifically configured to:

[0178] An input vector corresponding to the identification character string is obtained, and the input vector is input into the prediction model for calculation to obtain a prediction result.

[0179] In this embodiment, the general identification string is an English string and cannot be directly input into the prediction model for calculation. It needs to be converted into an input vector first. More specifically, the Word2Vec model can be used to convert the word corresponding to the English string into an input vector, and then the input vector is input into the prediction model for calculation to output a prediction result. The general prediction result is an output vector, which represents the probability that the identification string belongs to each of the preset multiple categories. For example, there are 5 preset categories (such as predicted category 1-predicted category 5), and the corresponding probabilities of the identification string belonging to predicted category 1-predicted category 5 are 0.3, 0.25, 0.2, 0.15 and 0.1 respectively. At this time, it can be seen that the probability value of the identification string belonging to predicted category 1 is the maximum value. At this time, the prediction result corresponding to the identification string is determined to be that it belongs to predicted category 1. Through the prediction model, the prediction result corresponding to the identification string can be quickly determined, thereby serving as a parameter to assist in the subsequent determination of the insertion position of the identification string.

[0180] The insertion information acquisition unit 105 is configured to determine the target subsegment to which the identification character string belongs and the target number of insertion bits according to the prediction result.

[0181] In this embodiment, after obtaining the prediction result, the category number corresponding to the prediction result can be used as the sequence number of the target sub-segment to which the identification string belongs, thereby quickly determining the insertion position of the identification string. For example, referring to the above example, if the prediction result indicates that the identification string belongs to prediction category 1, and category number 1 of prediction category 1 can be used to select the first sub-segment in the segmentation result as the target sub-segment, then the identification string can be directly added to the end of the first sub-segment, thereby achieving a rapid update of the first sub-segment.

[0182] In one embodiment, the insertion information obtaining unit 105 is specifically configured to:

[0183] Obtaining the category serial number corresponding to the prediction result, and obtaining the total number of segments of the sub-segments included in the segmentation result;

[0184] Calculating the remainder of the category serial number with respect to the total number of the segments to obtain a remainder result, and using the remainder result as the target segment serial number of the sub-segment to which the identification character string belongs;

[0185] According to the target segment sequence number, a corresponding sub-segment is obtained from the segmentation result as a target sub-segment;

[0186] The total number of target characters in the target sub-segment is obtained, and the target number of insertion bits is obtained by adding 1 to the total number of target characters.

[0187] More specifically, in this embodiment, after obtaining the prediction result, the remainder obtained by calculating the remainder between the category number (i.e., category number) corresponding to the prediction result and the total number of sub-segments included in the segmentation result can be used as the target segment number of the sub-segment to which the identification string belongs, thereby quickly determining the target segment to be inserted into. Furthermore, when determining the target number of characters to be inserted into the first sub-segment, the total number of characters in the first sub-segment is first obtained, and then the total number of characters plus one is used as the target number of characters to be inserted into the first character of the identification string. After the identification string is inserted into the end of the first sub-segment, the insertion of the identification string is completed.

[0188] The final encryption unit 106 is configured to insert the identification character string into a corresponding position of the target sub-segment according to the target insertion bit number, so as to update the initial encrypted data and obtain the final encrypted data.

[0189] In this embodiment, by inserting the identification string into the corresponding position of the target subsegment according to the target insertion bit number, the initial encrypted data is updated, which is equivalent to performing a secondary encryption operation, thereby improving data security. The final encrypted data obtained at the transmitting end can then be sent to the receiving end. Upon receiving the final encrypted data, the receiving end can decrypt it by referring to the reverse encryption process to obtain the restored encrypted data.

[0190] In one embodiment, the data processing device 100 based on the encryption algorithm further includes:

[0191] The encrypted data sending unit is used to send the final encrypted data to the receiving end corresponding to the third-party name, and send the target insertion bit number to the receiving end.

[0192] In this embodiment, after receiving the final encrypted data, the receiving end can only decrypt and restore the original encrypted data for viewing based on the national encryption SM3 decryption model after the insertion position of the known identification string and the correct string of the known identification string are removed.

[0193] The device realizes the insertion of identification strings into the data encrypted by the national secret encryption model. If the related parties are not informed of the specific data encryption and processing rules, the final encrypted data is not easy to be cracked, which greatly improves the security of the data.

[0194] The data processing device based on the encryption algorithm can be implemented in the form of a computer program. Figure 4 Runs on the computer device shown.

[0195] See also Figure 4 , Figure 4 1 is a schematic block diagram of a computer device provided in an embodiment of the present invention. The computer device 500 is a server or a server cluster. The server can be a standalone server or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms.

[0196] See Figure 4 The computer device 500 includes a processor 502 , a memory, and a network interface 505 connected via a device bus 501 , wherein the memory may include a storage medium 503 and an internal memory 504 .

[0197] The storage medium 503 can store an operating device 5031 and a computer program 5032. When the computer program 5032 is executed, the processor 502 can execute a data processing method based on an encryption algorithm.

[0198] The processor 502 is used to provide computing and control capabilities to support the operation of the entire computer device 500.

[0199] The internal memory 504 provides an environment for the operation of the computer program 5032 in the storage medium 503. When the computer program 5032 is executed by the processor 502, the processor 502 can execute a data processing method based on an encryption algorithm.

[0200] The network interface 505 is used for network communication, such as providing data information transmission. Those skilled in the art will understand that Figure 4 The structure shown in the figure is merely a block diagram of a portion of the structure related to the solution of the present invention and does not constitute a limitation on the computer device 500 to which the solution of the present invention is applied. The specific computer device 500 may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.

[0201] The processor 502 is configured to run a computer program 5032 stored in the memory to implement the data processing method based on the encryption algorithm disclosed in the embodiment of the present invention.

[0202] Those skilled in the art will understand that Figure 4 The embodiment of the computer device shown in the figure does not constitute a limitation on the specific composition of the computer device. In other embodiments, the computer device may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently. For example, in some embodiments, the computer device may only include a memory and a processor. In such an embodiment, the structure and function of the memory and processor are the same as those in the figure. Figure 4 The embodiments shown are consistent and will not be described again here.

[0203] It should be understood that in the embodiment of the present invention, the processor 502 may be a central processing unit (CPU), and the processor 502 may also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc.

[0204] In another embodiment of the present invention, a computer-readable storage medium is provided. The computer-readable storage medium may be a non-volatile computer-readable storage medium or a volatile computer-readable storage medium. The computer-readable storage medium stores a computer program, wherein when the computer program is executed by a processor, the data processing method based on the encryption algorithm disclosed in the embodiment of the present invention is implemented.

[0205] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described equipment, devices and units can refer to the corresponding processes in the aforementioned method embodiments, and will not be repeated here. Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented with electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in terms of function in the above description. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.

[0206] In the several embodiments provided by the present invention, it should be understood that the disclosed devices, apparatuses and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, or units with the same function may be combined into one unit. For example, multiple units or components may be combined or integrated into another device, or some features may be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection through some interfaces, devices or units, or may be an electrical, mechanical or other form of connection.

[0207] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected according to actual needs to achieve the objectives of the embodiments of the present invention.

[0208] In addition, the functional units in the various embodiments of the present invention may be integrated into a single processing unit, each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0209] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a storage medium. Based on this understanding, the technical solution of the present invention is essentially or the part that contributes to the existing technology, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a backend server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a magnetic disk, or an optical disk.

[0210] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in the present invention, and such modifications or substitutions are intended to be within the scope of protection of the present invention. Therefore, the scope of protection of the present invention shall be subject to the scope of protection of the claims.

Claims

1. A data processing method based on an encryption algorithm, characterized in that: include: In response to a data encryption instruction, obtaining data to be encrypted corresponding to the data encryption instruction; Encrypting the data to be encrypted according to the obtained national secret encryption model to obtain initial encrypted data; Divide the character string corresponding to the initial encrypted data into segments according to a preset segmentation strategy to obtain a first segmentation result; wherein the first segmentation result includes multiple sub-segments; Obtaining an identification string corresponding to a third-party name, obtaining a prediction model, and inputting the identification string into the prediction model to obtain a prediction result; Determining the target subsegment to which the identification character string belongs and the target number of insertion bits according to the prediction result; and Inserting the identification string into the corresponding position of the target sub-segment according to the target insertion bit number to update the initial encrypted data to obtain the final encrypted data; The obtaining of an identification string corresponding to the third-party name, obtaining a prediction model, and inputting the identification string into the prediction model to obtain a prediction result includes: Obtaining an input vector corresponding to the identification string, and inputting the input vector into the prediction model for calculation to obtain a prediction result; wherein the input vector is obtained by converting the identification string using a Word2Vec model; and the prediction model is a neural network model; Determining the target subsegment to which the identification character string belongs and the target number of insertion bits according to the prediction result includes: Obtaining a category serial number corresponding to the prediction result, and obtaining a total number of sub-segments included in the first segmentation result; Calculating the remainder of the category serial number with respect to the total number of the segments to obtain a remainder result, and using the remainder result as the target segment serial number of the sub-segment to which the identification character string belongs; According to the target segment sequence number, a corresponding sub-segment is obtained from the first segmentation result as a target sub-segment; The total number of target characters in the target sub-segment is obtained, and the target number of insertion bits is obtained by adding 1 to the total number of target characters.

2. The data processing method based on encryption algorithm according to claim 1, characterized in that: The national secret encryption model is the national secret SM3 encryption algorithm; Encrypting the data to be encrypted according to the obtained national secret encryption model to obtain initial encrypted data includes: Performing binary conversion on the data to be encrypted to obtain first converted data; Segmenting the first converted data according to a preset first value to obtain a second segmentation result including a plurality of sub-segments; If it is determined that the total number of characters in a subsegment is less than the first value, obtaining the corresponding subsegment as a target subsegment, adding one preset first character and k preset second characters to the end of the target subsegment to obtain a first adjusted subsegment, and obtaining file length information of the first converted data to concatenate the data with the first adjusted subsegment to obtain a second adjusted subsegment; wherein the total number of characters in the target subsegment plus 1 and k equals a preset third value; updating the corresponding sub-segment in the second segmentation result to obtain second converted data; Grouping the second converted data according to a preset second value to obtain a first grouping result including a plurality of subgroups; The sub-groups in the first grouping result are sequentially input into the compression function of the national secret SM3 encryption algorithm for iterative compression to obtain an iterative compression result, and the iterative compression result is used as the initial encrypted data.

3. The data processing method based on encryption algorithm according to claim 2, characterized in that: The step of sequentially inputting the subgroups in the first grouping result into a compression function in the national secret SM3 encryption algorithm for iterative compression to obtain an iterative compression result, and using the iterative compression result as the initial encrypted data includes: Get the jth data block B in the first grouping result j-1 , the jth data block B j-1 Divided into 16 message words and the 16 message words are respectively denoted as W j,0 To W j,15 ; Wherein, the initial value of j is 1 and the value range of j is [1,n], where n represents the total number of subgroups in the first grouping result; The jth data block B j-1 The corresponding message word W j,0 To W j,15 According to the preset first message word expansion strategy, 52 first extended message words are obtained and are denoted as W j,16 To W j,67 ; The jth data block B j-1 The corresponding message word W j,0 To W j,63 According to the preset second message word expansion strategy, 64 second extended message words are obtained and are respectively recorded as W' j,0 To W' j,63 ; By the jth data block B j-1 The corresponding message word W j,0 To W j,63 And the second extended message word W' j,0 To W' j,63 Composing the jth data block B j-1 The corresponding extended message character set; Get the jth data block B j-1 The corresponding j-1th compression result V j-1 , compress the j-1th result V j-1 Store to word register; where V0 = 7380166f4914b2b9172442d7da8a0600a96f30bc163138aae38dee4db0fb0e4e; The j-1th compression result V j-1 According to the preset iteration strategy and the preset number of iterations of the extended message word set, the same compression result V as the j-1th compression result is obtained. j-1 The corresponding j-th compression result V j ; Increment j by 1 to update the value of j; If it is determined that j does not exceed n, return to execute to obtain the jth data block B in the first grouping result j-1 , the jth data block B j-1 Divided into 16 message words and the 16 message words are respectively denoted as W j0 To W j15 Steps; If it is determined that j exceeds n, obtain the nth compression result V n As the initial encrypted data.

4. The data processing method based on encryption algorithm according to claim 1, characterized in that: The division strategy is used to evenly divide the string according to a preset first number of segments to obtain a first segmentation result, and the character string corresponding to the initial encrypted data is divided into segments according to the preset division strategy to obtain the first segmentation result includes: The first number of segments corresponding to the division strategy is obtained, and the character string corresponding to the initial encrypted data is evenly divided according to the first number of segments to obtain a first segmentation result.

5. The data processing method based on encryption algorithm according to claim 1, characterized in that: After inserting the identification string into the corresponding position of the target sub-segment according to the target number of insertion bits to update the initial encrypted data and obtain the final encrypted data, the method further includes: The final encrypted data is sent to a receiving end corresponding to the third-party name, and the target number of insertion bits is sent to the receiving end.

6. A data processing device based on an encryption algorithm, characterized in that: include: a data to be encrypted acquiring unit, configured to acquire the data to be encrypted corresponding to the data encryption instruction in response to the data encryption instruction; An initial encryption unit, configured to encrypt the data to be encrypted according to the obtained national secret encryption model to obtain initial encrypted data; a string segmentation unit, configured to segment the string corresponding to the initial encrypted data according to a preset segmentation strategy to obtain a first segmentation result; wherein the first segmentation result includes a plurality of sub-segments; A prediction unit, configured to obtain an identification string corresponding to a third-party name, obtain a prediction model, and input the identification string into the prediction model to obtain a prediction result; an insertion information acquisition unit, configured to determine a target subsegment to which the identification character string belongs and a target number of insertion bits according to the prediction result; and a final encryption unit, configured to insert the identification character string into a corresponding position of the target sub-segment according to the target number of insertion bits, so as to update the initial encrypted data and obtain final encrypted data; The prediction unit is specifically configured to: Obtaining an input vector corresponding to the identification string, and inputting the input vector into the prediction model for calculation to obtain a prediction result; wherein the input vector is obtained by converting the identification string using a Word2Vec model; and the prediction model is a neural network model; The insertion information acquisition unit is specifically used for: Obtaining a category serial number corresponding to the prediction result, and obtaining a total number of sub-segments included in the first segmentation result; Calculating the remainder of the category serial number with respect to the total number of segments to obtain a remainder result, and using the remainder result as the target segment serial number of the sub-segment to which the identification character string belongs; According to the target segment sequence number, a corresponding sub-segment is obtained from the first segmentation result as a target sub-segment; The total number of target characters in the target sub-segment is obtained, and the target number of insertion bits is obtained by adding 1 to the total number of target characters.

7. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the data processing method based on the encryption algorithm according to any one of claims 1 to 5 is implemented.

8. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, which, when executed by a processor, causes the processor to perform the encryption algorithm-based data processing method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Data encryption processing method and device, computer equipment and storage medium

    CN113364760A

  • Digital copyright protection platform based on block chain and national secret SM2 / 3

    CN113486310A

  • Data processing method and device

    CN113761547A