Encryption method, device and electronic equipment

By setting up a user private area in the software encryption medium and recording private encryption information, the problem of software and related data requiring multiple encryption media is solved, unified encryption is achieved, encryption complexity is reduced and convenience is improved.

CN114676394BActive Publication Date: 2025-09-23HANGZHOU HIKROBOT TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202210280533.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-03-21
Publication Date
2025-09-23
Estimated Expiration
2042-03-21

AI Technical Summary

Technical Problem

In the prior art, each software requires multiple independent encryption media to protect itself and its associated data, which makes the encryption process cumbersome and inconvenient.

Method used

A user private area is set in the encryption medium of the target software to record private encryption information, and the private area is used to encrypt the associated data to achieve unified encryption of the associated data and the software.

Benefits of technology

By unifying the encryption medium, the complexity of encryption is reduced and the convenience and efficiency of encryption are improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114676394B_ABST
    Figure CN114676394B_ABST
Patent Text Reader

Abstract

This application provides an encryption method, apparatus, and electronic device. In this application, by setting a user private area in the encryption medium equipped with target software, recording private encryption information in the user private area, and encrypting the associated data associated with the target software using the private encryption information, the target software and the associated data associated with the target software are encrypted using the same encryption medium, thereby reducing encryption complexity and improving encryption convenience.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to data security technology, and in particular to encryption methods, devices and electronic devices. Background Art

[0002] Currently, each piece of software is equipped with its own encryption medium specifically designed to encrypt it. Software, in this context, generally refers to programs that implement at least one function (organize computer data and instructions in a specific sequence). Encryption media, in this context, is used to restrict and protect user access to software through parameters (usually encryption parameters) such as passwords, system keys, or hardware keys.

[0003] In existing applications, the encryption medium associated with each piece of software is limited to encrypting the software itself and cannot encrypt the associated data associated with the software. Examples of such associated data include software configuration information to be loaded when the software is used, the results generated after the software is run, newly added functions, and so on. That is, although these associated data are associated with the software, their encryption is independent of the software's own encryption. The encryption of different pieces of associated data depends on the corresponding encryption medium. For example, if the software relies on encryption medium a for encryption, then the software configuration information to be loaded when the software is used is encrypted by encryption medium b, the results generated after the software is run are encrypted by encryption medium c, and the newly added functions are encrypted by encryption medium d. Therefore, when the software loads these software configuration information, results information, and newly added functions, encryption medium a must be integrated with encryption medium b, encryption medium c, and encryption medium d, requiring four encryption media simultaneously, making encryption very cumbersome. Summary of the Invention

[0004] The present application provides an encryption method, apparatus, and electronic device to implement encryption of software and other software independent of the software using the same encryption medium.

[0005] This embodiment of the present application provides an encryption method, which includes:

[0006] A user private area is set in the currently deployed encryption medium for encrypting and protecting the target software, and private encryption information is recorded in the user private area; the encryption medium also records target software encryption information specifically used for encrypting and protecting the target software;

[0007] When an encryption trigger for encrypting associated data associated with the target software is detected, encrypting the associated data according to private encryption information corresponding to the associated data recorded in the user private area of ​​the encryption medium;

[0008] In which, the encryption of the associated data is independent of the encryption of the target software, and the associated data includes at least one of the following: software configuration information of the target software, result information generated after the target software has been run, custom function software, software configuration information of the custom function software, result information generated after the custom function software has been run; the custom function software is implemented by adding a new program for implementing the custom function to the target software.

[0009] An embodiment of the present application provides an encryption device, which includes:

[0010] A deployment unit is configured to set a user private area in a currently deployed encryption medium for encrypting and protecting target software, and record private encryption information in the user private area; the encryption medium also records target software encryption information specifically used for encrypting and protecting the target software;

[0011] a processing unit, configured to, upon detecting an encryption trigger for encrypting associated data associated with the target software, encrypt the associated data according to private encryption information corresponding to the associated data recorded in the user private area of ​​the encryption medium;

[0012] In which, the encryption of the associated data is independent of the encryption of the target software, and the associated data includes at least one of the following: software configuration information of the target software, result information generated after the target software has been run, custom function software, software configuration information of the custom function software, result information generated after the custom function software has been run; the custom function software is implemented by adding a new program for implementing the custom function to the target software.

[0013] An embodiment of the present application further provides an electronic device. The electronic device includes: a processor and a machine-readable storage medium;

[0014] The machine-readable storage medium stores machine-executable instructions that can be executed by the processor;

[0015] The processor is used to execute machine-executable instructions to implement the steps of the above-disclosed method.

[0016] It can be seen from the above technical solution that in this application, by setting a user private area in the encryption medium equipped with the target software, recording private encryption information in the user private area, and encrypting the associated data associated with the target software through the private encryption information, the target software and the associated data associated with the target software are encrypted using the same encryption medium, thereby reducing the encryption complexity and improving the encryption convenience. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present disclosure and, together with the description, serve to explain the principles of the present disclosure.

[0018] Figure 1 An example diagram of an encryption medium provided in an embodiment of the present application;

[0019] Figure 2 A flow chart of the method provided in the embodiment of the present application;

[0020] Figure 3 Another example diagram of the encryption medium provided in the embodiment of the present application;

[0021] Figure 4a This is an example diagram of a user's private area recording private encrypted information provided by an embodiment of the present application;

[0022] Figure 4b Another example diagram of recording private encrypted information in a user private area provided by an embodiment of the present application;

[0023] Figure 5a A schematic diagram of decryption-related data provided in an embodiment of the present application;

[0024] Figure 5b Another schematic diagram of decrypting associated data provided by an embodiment of the present application;

[0025] Figure 6 A diagram of the structure of the device provided in the embodiment of the present application;

[0026] Figure 7 This is a structural diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0027] Exemplary embodiments are described in detail herein, with examples illustrated in the accompanying drawings. When the following description refers to the drawings, identical numerals in different figures represent identical or similar elements unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatuses and methods consistent with certain aspects of the present application.

[0028] The terms used in this application are for the purpose of describing particular embodiments only and are not intended to limit this application. The singular forms "a", "the" and "the" used in this application are also intended to include plural forms, unless the context clearly indicates otherwise.

[0029] In order to enable those skilled in the art to better understand the technical solutions provided by the embodiments of the present application, the encryption medium involved in the embodiments of the present application is described below:

[0030] In applications, such as Figure 1 As shown, the encrypted medium includes but is not limited to the following areas:

[0031] 1) Proprietary read / write area: This area is authorized only to the original developer, allowing them to write and read data. In applications, the proprietary read / write area records encryption information (also known as software encryption information) used to encrypt the software that matches the encryption medium.

[0032] 2) Public Read-Only Area: This area is authorized for writing and reading data by the original developer, and is authorized for reading data by users. This area is typically used to record information provided by the original developer, allowing users to access information the developer intended, such as basic information about the most common encryption media (model, developer, etc.).

[0033] Based on the encryption media described above, in applications, each piece of software can be encrypted based on the software encryption information, such as keys and passwords, recorded in the dedicated read-write area of ​​the encryption media that comes with it, thereby protecting the software itself. However, as described in the background art, although the associated data associated with the software is associated with the software, its encryption is independent of the software's own encryption. The encryption of different pieces of associated data depends on the different encryption media used to encrypt them. For example, the software described in the background art relies on encryption medium a for encryption, while the software configuration information to be loaded when the software is used relies on encryption medium b for encryption, the result information generated by the software after execution relies on encryption medium c for encryption, and the newly added functionality to the software relies on encryption medium d for encryption.

[0034] Based on this, when the software loads its associated data, the encryption medium equipped with the software needs to be integrated with the encryption medium equipped with the associated data. For example, when the above software integrates the above software configuration information, result information, and newly added functions of the software, encryption medium a is required to integrate encryption medium b, encryption medium c, and encryption medium d, that is, 4 encryption media are required at the same time. The encryption is very cumbersome and will cause great inconvenience.

[0035] To solve the above technical problems, this embodiment provides an encryption method that can solve the above technical problems. Figure 2 The encryption method provided in the embodiment of the present application is illustrated by way of example:

[0036] See also Figure 2 , Figure 2 Flowchart of the method provided in the embodiment of the present application. Optionally, in this embodiment, the method can be applied to an electronic device. Here, the electronic device can be a device for managing or controlling software, which is not specifically limited in this embodiment.

[0037] like Figure 2 As shown, the process may include the following steps:

[0038] Step 201: Set a user private area in the currently deployed encryption medium for encrypting and protecting target software, and record private encryption information in the user private area.

[0039] Here, target software can refer to any software.

[0040] Optionally, in this embodiment, in order to solve the above technical problem, the following improvement may be made to the encryption medium equipped with the target software: a user private area is set in the encryption medium. Figure 3 Shown in Figure 1 Optionally, in this embodiment, the specific location of the user private area in the encrypted medium is not limited, as long as it does not conflict with existing areas in the encrypted medium, such as a dedicated read-write area, a public read-only area, etc.

[0041] In this embodiment, the user private area is authorized to record private encrypted information.

[0042] In order to realize recording of private encrypted information in the above user private area, as an embodiment, a corresponding external interface can be added to the above target software to realize recording of private encrypted information in the user private area through the external interface. Figure 4a As shown, recording the private encrypted information in the user private area may include: receiving the private encrypted information written externally into the user private area through the newly set external interface corresponding to the above-mentioned target software, thereby realizing recording the private encrypted information in the user private area.

[0043] As another embodiment, the software interaction interface corresponding to the target software can also be used to record private encrypted information in the user's private area. Figure 4b As shown, recording the private encrypted information in the user private area may include: receiving the private encrypted information to be written to the user private area from an external input through a software interaction interface corresponding to the target software, and writing the private encrypted information into the user private area. This ultimately achieves recording the private encrypted information in the user private area.

[0044] It should be noted that, in this embodiment, the private encryption information recorded in the user private area can be dynamically modified, deleted, etc. based on actual needs.

[0045] Step 202 : When an encryption trigger for encrypting associated data associated with the target software is detected, step 203 is executed.

[0046] In this embodiment, the above-mentioned associated data is associated with the target software, but the encryption of the associated data is independent of the encryption of the target software. Optionally, in this embodiment, the associated data includes at least one of the following: software configuration information of the target software, result information generated after the target software is run, custom function software, software configuration information of the custom function software, result information generated after the custom function software has been run. It should be noted that, in this embodiment, the above-mentioned associated data associated with the target software can be defined according to actual needs. For example, the above-mentioned associated data may not cover the custom function software, but only cover the software configuration information of the custom function software, result information generated after the custom function software has been run, etc. This embodiment does not limit them one by one.

[0047] In this embodiment, the custom function software is implemented by adding a new program for implementing the custom function to the target software, such as adding a user-defined tool or user-defined information to the target software. The newly added user-defined tool or user-defined information can be collectively referred to as custom function software.

[0048] According to existing encryption methods, each piece of software-associated data must be encrypted with a corresponding encryption medium. However, in this embodiment, no corresponding encryption medium is assigned to each piece of software-associated data. Instead, encryption of the associated data is achieved by extending a user-private area within the encryption medium assigned to the software. This is described in detail in step 203. This will not be further described here.

[0049] In this embodiment, the electronic device provides an external interface, which can be an interactive interface for the target software or a management interface for managing the target software (different from the interactive interface of the target software). Regardless of which interface is used, in this embodiment, an encryption trigger for encrypting associated data associated with the target software is promptly detected, and a trigger indicator (such as a button) associated with the associated data is set on the interface, so that when the trigger indicator is detected to be triggered, the corresponding associated data is promptly notified that encryption is to be performed.

[0050] Step 203: Encrypt the associated data according to the private encryption information corresponding to the associated data recorded in the user private area in the encryption medium.

[0051] As an embodiment, the user private area may record a private encryption information. The private encryption information may be used to encrypt all associated data associated with the target software. In this case, the private encryption information recorded in the user private area may be considered to correspond to all associated data of the target software.

[0052] As an embodiment, the above-mentioned user private area can record more than two private encryption information to achieve at least two different associated data corresponding to different private encryption information. For example, the above-mentioned user private area can record the following three private encryption information: key a1, key a2, key a3. The software configuration information of the target software corresponds to the key a1 recorded in the above-mentioned user private area, the result information generated by the target software after being run corresponds to the key a2, and the custom function software corresponds to the key a3. When encrypting the associated data associated with the target software, first identify what the associated data is specifically. For example, if the associated data is software configuration information, the software configuration information is encrypted based on the key a1 recorded in the above-mentioned user private area. For example, if the associated data is the above-mentioned result information, the result information is encrypted based on the key a2 recorded in the above-mentioned user private area, and so on.

[0053] It should be noted that in this embodiment, the software configuration information of the custom function software and the private encrypted information corresponding to the result information generated after the custom function software has been executed can be the same, for example, both can be the private encrypted information corresponding to the custom function software. Of course, the software configuration information of the custom function software and the private encrypted information corresponding to the result information generated after the custom function software has been executed can also be different. For example, the user private area described above defines two types of private encrypted information, one type being the private encrypted information corresponding to the custom function software, and the other type being the private encrypted information corresponding to the result information generated after the custom function software has been executed, etc. This embodiment does not limit these to one-to-one.

[0054] Finally, through the above step 203, this embodiment realizes encrypting the associated data associated with the software through the encryption medium equipped with the software.

[0055] So far, completed Figure 2 The process shown.

[0056] pass Figure 2 As can be seen from the illustrated process, in this embodiment, a user private area is set in the encryption medium equipped with the target software, private encryption information is recorded in the user private area, and the associated data associated with the target software is encrypted using the private encryption information. This enables the target software and the associated data associated with the target software to be encrypted using the same encryption medium, thereby reducing encryption complexity and improving encryption convenience.

[0057] Optionally, in this embodiment, if the associated data includes at least one of the following: software configuration information of the target software when it is running, result information generated after the target software has been run, software configuration information of the custom function software, and result information generated after the custom function software has been run, then after the associated data is encrypted in the above step 203 according to the private encryption information corresponding to the associated data recorded in the user private area of ​​the encryption medium, the method further includes: upon receiving a loading trigger to load the above encrypted associated data onto the target software for execution, the encrypted associated data is decrypted according to the decryption method corresponding to the overlapping encryption. Specifically, Figure 5a shown.

[0058] like Figure 5a As shown, when the encrypted associated data is decrypted according to the decryption method corresponding to the overlapping encryption, the target software encryption information and the private encryption information corresponding to the above-mentioned encrypted associated data are read from the encryption medium equipped with the above-mentioned target software, and the read target software encryption information and private encryption information are verified respectively. If the verification is passed, the encrypted associated data is decrypted and loaded into the target software for operation; otherwise, the loading failure is displayed.

[0059] Optionally, in this embodiment, when the associated data is encrypted in step 203 according to the private encryption information corresponding to the associated data recorded in the user private area of ​​the encryption medium, the currently used private encryption information and the currently recorded target software encryption information are recorded. Based on this, the verification of the read target software encryption information and the private encryption information may include: checking whether the currently read target software encryption information is the target software encryption information previously recorded when the associated data was encrypted in step 203, and checking whether the currently read private encryption information is the private encryption information previously recorded when the associated data was encrypted in step 203. If so, the verification is determined to have passed; otherwise, the verification fails.

[0060] As can be seen, in this embodiment, if the associated data includes at least one of the following: software configuration information of the target software when it is running, result information generated by the target software after it has been run, software configuration information of the custom function software, and result information generated by the custom function software after it has been run, then although the associated data is encrypted using private encryption information in step 203, this implies overlapping encryption of the associated data. Correspondingly, once the associated data needs to be loaded, the encrypted associated data must be decrypted using the decryption method corresponding to the overlapping encryption, as described above.

[0061] In this embodiment, if the associated data includes at least: custom function software; then after encrypting the associated data according to the private encryption information corresponding to the associated data recorded in the user private area of ​​the encryption medium in the above step 203, the method further includes: upon receiving a trigger for using a function provided by the target software, providing the function according to the decryption corresponding to the distributed encryption. Specifically, Figure 5b shown.

[0062] like Figure 5b As shown, when a trigger is received for using a custom function provided by a newly developed custom function software based on the target software, the private encryption information corresponding to the encrypted custom function software is read from the encryption medium, and the read private encryption information is verified. If the verification passes, the custom function software is decrypted and the custom function provided by the custom function software is allowed to be used. Otherwise, the use of the custom function provided by the custom function software is prohibited. When a trigger is received for using an original function provided by the target software, the target software encryption information is read from the encryption medium, and the read target software encryption information is verified. If the verification passes, the use of the original function provided by the target software is allowed. Otherwise, the use of the original function provided by the target software is prohibited. Here, the verification of the read private encryption information and the verification of the read target software encryption information are as described above and will not be repeated here.

[0063] In this embodiment, even if private encryption information is recorded in the user private area, the private encryption information recorded in the user private area does not remain unchanged and may be updated or deleted.

[0064] As an example, in this embodiment, when an externally input update message for updating the private encrypted information in the user private area is received through the external interface corresponding to the newly set target software, or when an externally input update message for updating the private encrypted information in the user private area is received through the software interaction interface corresponding to the target software, the private encrypted information already recorded in the user private area is updated according to the update message; for example, the private encrypted information already recorded in the user private area is updated with the private encrypted information carried in the update message. Thus, the private encrypted information in the user private area is updated.

[0065] As an example, in this embodiment, when a deletion instruction is received via the newly set external interface corresponding to the target software or via the software interaction interface corresponding to the target software, the private encrypted information recorded in the user private area is deleted according to the deletion instruction. This achieves deletion of the private encrypted information in the user private area.

[0066] The above describes the method provided in the embodiment of the present application. The following describes the device provided in the embodiment of the present application:

[0067] See also Figure 6 , Figure 6 This is a structural diagram of the encryption device provided in the embodiment of the present application. Figure 6 As shown, the device may include:

[0068] A deployment unit is configured to set a user private area in a currently deployed encryption medium for encrypting and protecting target software, and record private encryption information in the user private area; the encryption medium also records target software encryption information specifically used for encrypting and protecting the target software;

[0069] a processing unit, configured to, upon detecting an encryption trigger for encrypting associated data associated with the target software, encrypt the associated data according to private encryption information corresponding to the associated data recorded in the user private area of ​​the encryption medium;

[0070] In which, the encryption of the associated data is independent of the encryption of the target software, and the associated data includes at least one of the following: software configuration information of the target software, result information generated after the target software has been run, custom function software, software configuration information of the custom function software, result information generated after the custom function software has been run; the custom function software is implemented by adding a new program for implementing the custom function to the target software.

[0071] Optionally, the deploying unit recording the private encryption information in the user private area includes:

[0072] receiving the private encryption information written externally into the user private area through the newly set external interface corresponding to the target software; or

[0073] The private encrypted information to be written into the user private area is received from an external input through a software interaction interface corresponding to the target software, and the private encrypted information is written into the user private area.

[0074] Optionally, if the associated data includes at least one of the following: software configuration information of the target software when it is being run, result information generated after the target software has been run, software configuration information of the custom function software, and result information generated after the custom function software has been run, then the processing unit encrypts the associated data according to the private encryption information corresponding to the associated data recorded in the user private area in the encryption medium, and then, upon receiving a loading trigger to load the encrypted associated data onto the target software for execution, reads the target software encryption information and the private encryption information corresponding to the encrypted associated data from the encryption medium, and verifies the read target software encryption information and the private encryption information respectively; if the verification passes, decrypts the encrypted associated data and loads it onto the target software for execution; otherwise, displays a loading failure;

[0075] If the associated data at least includes the custom function software, the processing unit, after encrypting the associated data according to the private encryption information corresponding to the associated data recorded in the user private area in the encryption medium, further reads the encrypted private encryption information corresponding to the custom function software from the encryption medium upon receiving a trigger for using a custom function provided by the custom function software, verifies the read private encryption information, decrypts the custom function software and allows use of the custom function provided by the custom function software if the verification passes, otherwise prohibits use of the custom function provided by the custom function software; and

[0076] When a trigger to use the original function provided by the target software is received, the target software encryption information is read from the encryption medium and the target software encryption information is verified. If the verification passes, the original function provided by the target software is allowed to be used; otherwise, the use of the original function provided by the target software is prohibited.

[0077] Optionally, after recording the private encryption information in the user private area, the deployment unit further receives an external input update message for updating the private encryption information in the user private area through the newly set external interface corresponding to the target software, or receives an external input update message for updating the private encryption information in the user private area through the software interaction interface corresponding to the target software; updates the private encryption information recorded in the user private area according to the update message; or,

[0078] A deletion instruction is received through the newly set external interface corresponding to the target software, or through the software interaction interface corresponding to the target software, and the private encrypted information recorded in the user private area is deleted according to the deletion instruction.

[0079] So far, completed Figure 6 Structural description of the device shown.

[0080] The present application also provides Figure 6 The hardware structure of the device shown. Figure 7 , Figure 7 This is a structural diagram of an electronic device provided in an embodiment of the present application. Figure 7 As shown, the hardware structure may include: a processor and a machine-readable storage medium, the machine-readable storage medium storing machine-executable instructions that can be executed by the processor; the processor is used to execute the machine-executable instructions to implement the method disclosed in the above example of this application.

[0081] Based on the same application concept as the above method, an embodiment of the present application also provides a machine-readable storage medium, on which a number of computer instructions are stored. When the computer instructions are executed by a processor, the method disclosed in the above example of the present application can be implemented.

[0082] Exemplarily, the machine-readable storage medium may be any electronic, magnetic, optical, or other physical storage device that may contain or store information, such as executable instructions, data, and the like. For example, the machine-readable storage medium may be: RAM (Random Access Memory), volatile memory, non-volatile memory, flash memory, a storage drive (such as a hard disk drive), a solid-state drive, any type of storage disk (such as a CD, DVD, etc.), or similar storage media, or a combination thereof.

[0083] The systems, devices, modules, or units described in the above embodiments may be implemented by computer chips or entities, or by products having certain functions. A typical implementation device is a computer, which may be in the form of a personal computer, laptop computer, cellular phone, camera phone, smartphone, personal digital assistant, media player, navigation device, email transceiver, game console, tablet computer, wearable device, or any combination of these devices.

[0084] For the convenience of description, the above devices are described as being divided into various units according to their functions. Of course, when implementing this application, the functions of each unit can be implemented in the same or multiple software and / or hardware.

[0085] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the embodiments of the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0086] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0087] Furthermore, these computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0088] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable device to implement the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0089] The foregoing is merely an embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should all be included within the scope of the claims of the present application.

Claims

1. An encryption method, characterized in that: The method includes: A user private area is provided in an encryption medium currently deployed for encrypting and protecting target software, and private encryption information is recorded in the user private area; the encryption medium also records target software encryption information specifically used for encrypting and protecting the target software; the user private area and an area of ​​the encryption medium containing the target software encryption information are isolated from each other, and the private encryption information recorded in the user private area is specifically used to encrypt and decrypt associated data associated with the target software; When an encryption trigger for encrypting associated data associated with the target software is detected, encrypting the associated data according to private encryption information corresponding to the associated data recorded in the user private area of ​​the encryption medium; In which, the encryption of the associated data is independent of the encryption of the target software, and the associated data includes at least one of the following: software configuration information of the target software, result information generated after the target software has been run, custom function software, software configuration information of the custom function software, result information generated after the custom function software has been run; the custom function software is implemented by adding a new program for implementing the custom function to the target software.

2. The method according to claim 1, characterized in that Said recording of private encryption information in said user private area comprises: receiving the private encryption information written externally into the user private area through the newly set external interface corresponding to the target software; or The private encrypted information to be written into the user private area is received from an external input through a software interaction interface corresponding to the target software, and the private encrypted information is written into the user private area.

3. The method according to claim 1, characterized in that If the associated data includes at least one of the following: software configuration information of the target software when it is being run, result information generated after the target software has been run, software configuration information of the custom function software, and result information generated after the custom function software has been run, then after encrypting the associated data based on the private encryption information corresponding to the associated data recorded in the user private area of ​​the encryption medium, the method further includes: When a loading trigger is received to load the encrypted associated data onto the target software for execution, the target software encryption information and the private encryption information corresponding to the encrypted associated data are read from the encryption medium, and the read target software encryption information and the private encryption information are verified respectively. If the verification passes, the encrypted associated data is decrypted and loaded onto the target software for execution; otherwise, a loading failure is displayed.

4. The method according to claim 1, wherein If the associated data at least includes the custom function software, after encrypting the associated data according to the private encryption information corresponding to the associated data recorded in the user private area of ​​the encryption medium, the method further includes: Upon receiving a trigger for using a custom function provided by the custom function software, reading the encrypted private encryption information corresponding to the custom function software from the encryption medium, verifying the read private encryption information, and if the verification passes, decrypting the custom function software and allowing the use of the custom function provided by the custom function software; otherwise, prohibiting the use of the custom function provided by the custom function software; When a trigger to use the original function provided by the target software is received, the target software encryption information is read from the encryption medium and the target software encryption information is verified. If the verification passes, the target software is decrypted and the original function provided by the target software is allowed to be used. Otherwise, the use of the original function provided by the target software is prohibited.

5. The method according to any one of claims 1 to 4, characterized in that: After recording the private encryption information in the user private area, the method further comprises: Receiving, via the newly set external interface corresponding to the target software, an externally input update message for updating the private encrypted information in the user private area, or receiving, via the software interaction interface corresponding to the target software, an externally input update message for updating the private encrypted information in the user private area; and updating the private encrypted information recorded in the user private area according to the update message; or, A deletion instruction is received through the newly set external interface corresponding to the target software, or through the software interaction interface corresponding to the target software, and the private encrypted information recorded in the user private area is deleted according to the deletion instruction.

6. An encryption device, characterized in that: The device includes: A deployment unit is configured to set a user private area in a currently deployed encryption medium for encrypting and protecting target software, and record private encryption information in the user private area; the encryption medium further records target software encryption information specifically used for encrypting and protecting the target software; the user private area and an area of ​​the encryption medium containing the target software encryption information are mutually isolated, and the private encryption information recorded in the user private area is specifically used to encrypt and decrypt associated data associated with the target software; a processing unit, configured to, upon detecting an encryption trigger for encrypting associated data associated with the target software, encrypt the associated data according to private encryption information corresponding to the associated data recorded in the user private area of ​​the encryption medium; In which, the encryption of the associated data is independent of the encryption of the target software, and the associated data includes at least one of the following: software configuration information of the target software, result information generated after the target software has been run, custom function software, software configuration information of the custom function software, result information generated after the custom function software has been run; the custom function software is implemented by adding a new program for implementing the custom function to the target software.

7. The encryption device according to claim 6, characterized in that The deploying unit recording the private encryption information in the user private area includes: receiving the private encryption information written externally into the user private area through the newly set external interface corresponding to the target software; or The private encrypted information to be written into the user private area is received from an external input through a software interaction interface corresponding to the target software, and the private encrypted information is written into the user private area.

8. The encryption device according to claim 6, wherein: If the associated data includes at least one of the following: software configuration information of the target software when it is being run, result information generated after the target software has been run, software configuration information of the custom function software, and result information generated after the custom function software has been run, then the processing unit encrypts the associated data according to the private encryption information corresponding to the associated data recorded in the user private area in the encryption medium, and then, upon receiving a loading trigger for loading the encrypted associated data onto the target software for execution, reads the target software encryption information and the private encryption information corresponding to the encrypted associated data from the encryption medium, and verifies the read target software encryption information and the private encryption information respectively; if the verification passes, decrypts the encrypted associated data and loads it onto the target software for execution; otherwise, displays a loading failure; If the associated data at least includes the custom function software, the processing unit, after encrypting the associated data according to the private encryption information corresponding to the associated data recorded in the user private area in the encryption medium, further reads the encrypted private encryption information corresponding to the custom function software from the encryption medium upon receiving a trigger for using a custom function provided by the custom function software, verifies the read private encryption information, decrypts the custom function software and allows use of the custom function provided by the custom function software if the verification passes, otherwise prohibits use of the custom function provided by the custom function software; and When a trigger to use the original function provided by the target software is received, the target software encryption information is read from the encryption medium and the target software encryption information is verified. If the verification passes, the original function provided by the target software is allowed to be used; otherwise, the use of the original function provided by the target software is prohibited.

9. The encryption device according to any one of claims 6 to 8, characterized in that: After recording the private encrypted information in the user private area, the deployment unit further receives an externally input update message for updating the private encrypted information in the user private area through the newly set external interface corresponding to the target software, or receives an externally input update message for updating the private encrypted information in the user private area through the software interaction interface corresponding to the target software; updating the private encryption information recorded in the user private area according to the update message; or, A deletion instruction is received through the newly set external interface corresponding to the target software, or through the software interaction interface corresponding to the target software, and the private encrypted information recorded in the user private area is deleted according to the deletion instruction.

10. An electronic device, characterized in that: The electronic device includes: a processor and a machine-readable storage medium; The machine-readable storage medium stores machine-executable instructions that can be executed by the processor; The processor is configured to execute machine-executable instructions to implement the method steps of any one of claims 1-5.

Citation Information

Patent Citations

  • Storage device and storage method, and information-processing device and information-processing method

    CN101118773A

  • Information processing apparatus, information processing method and program

    CN103117073A

  • Device and method for managing an encrypted software application

    CN112214758A

  • Software storage medium, software reader, and software management system

    JP1993298085A