Data encryption method and device, storage medium and electronic device
By generating device-specific storage and transmission keys and leveraging the uniqueness of device hardware information, the security of data across different devices is solved, ensuring that data cannot be cracked on other devices after it has been stolen.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- QINGDAO HAIER TECH
- Filing Date
- 2022-03-28
- Publication Date
- 2026-05-01
AI Technical Summary
The data in the existing devices is not associated with the devices, which makes it easy for the data to be stolen and run on other devices, resulting in low data security.
By obtaining the target device's hardware information and a preset root key, a target storage key is generated to encrypt the data before storage. A real-time transmission key is generated during transmission, and the uniqueness of the device's hardware information is used to prevent the data from being cracked on other devices.
It effectively ensures that data cannot be cracked on other devices after it has been stolen, thus improving data security and solving the problem of data security across different devices.
Smart Images

Figure CN114861199B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of smart home technology, and more specifically, to a data encryption method and apparatus, storage medium and electronic device. Background Technology
[0002] With the rapid development of society, the market is flooded with products. Protecting user data security has become paramount. Currently, most devices encrypt data using traditional algorithms and store it on the device itself. However, the data stored on the device is not linked to the device itself, making it easy for the data to be cloned and run on other devices, resulting in low data security.
[0003] Regarding the relevant technologies, the data in existing devices is not associated with the device itself. As a result, if the data is stolen, it can be easily cracked and run on other devices, leading to low data security. Currently, no effective solution has been proposed.
[0004] Therefore, it is necessary to improve the relevant technology to overcome the aforementioned defects. Summary of the Invention
[0005] This invention provides a data encryption method and apparatus, storage medium and electronic device to at least solve the problem that data in existing devices is not associated with the device, and therefore, after the data is stolen, it is easy to crack and run on other devices, resulting in low data security.
[0006] According to one aspect of the present invention, a data encryption method is provided, comprising: when the processor of a target device is started, obtaining hardware information in the target device through the boot program of the processor; when it is determined that a security module is built into the processor or the security module is externally connected to the processor, obtaining a preset root key in the security module; generating a target storage key according to the hardware information and the root key, wherein the target storage key is used to encrypt data to be stored in the target device before storage; reading first data to be processed in the target device through the security module, and when the read first data is data to be stored in the target device, encrypting the first data according to the target storage key to obtain first encrypted data, and storing the first encrypted data in the target device.
[0007] Furthermore, if the first data read is data to be transmitted, a first transmission key is generated based on the hardware information, the root key, and the first random number; the first data read is then encrypted using the first transmission key to obtain second encrypted data.
[0008] Furthermore, when the first data read is data to be transmitted, generating a first transmission key based on the hardware information, the root key, and the first random number includes: when the first data read is data to be transmitted in a first session, obtaining the first random number corresponding to the first session; and generating a first transmission key based on the hardware information, the root key, and the first random number.
[0009] Furthermore, the method further includes: reading the second data to be processed in the target device through the security module; if the read second data is data to be transmitted in the second session, generating a second transmission key according to the hardware information, the root key and the second random number, wherein the first data is data to be transmitted in the first session, and the first session and the second session are different sessions; encrypting the read second data according to the second transmission key to obtain third encrypted data.
[0010] Furthermore, the method further includes: reading third data to be processed in the target device through the security module, wherein the first data is data to be transmitted in the first session; and encrypting the read third data according to the first transmission key when the read third data is data to be transmitted in the first session to obtain fourth encrypted data.
[0011] Furthermore, the step of generating the target storage key based on the hardware information and the root key includes: obtaining the current date, performing a hash operation on the current date, the hardware information, and the root key to obtain the target storage key.
[0012] Furthermore, the hardware information in the target device is obtained through the processor's bootloader, including obtaining at least one of the following through the processor's bootloader: the Media Access Control (MAC) address of the target device, the processor's identifier, and the memory chip's identifier.
[0013] According to another aspect of the present invention, a data encryption device is also provided, comprising: a first acquisition module, configured to acquire hardware information in the target device through the boot program of the processor when the processor of the target device is started; a second acquisition module, configured to acquire a preset root key in the security module when it is determined that the security module is built into the processor or the security module is externally connected to the processor; a generation module, configured to generate a target storage key according to the hardware information and the root key, wherein the target storage key is used to encrypt data to be stored in the target device before storage; and an encryption module, configured to read first data to be processed in the target device through the security module, and if the read first data is data to be stored in the target device, encrypt the first data according to the target storage key to obtain first encrypted data, and store the first encrypted data in the target device.
[0014] According to another aspect of the present invention, a computer-readable storage medium is also provided, wherein a computer program is stored in the computer program, and the computer program is configured to execute the above-described data encryption method at runtime.
[0015] According to another aspect of the present invention, an electronic device is also provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the data encryption method described above through the computer program.
[0016] This invention generates a target key using the device's hardware information and encrypts the data using the target key. This ensures that even if the data is stolen and used on other devices, the data cannot be cracked because the hardware information of the other devices differs from that of the original device. This solves the problem that data in existing devices is not associated with the device, making it easy for the stolen data to be cracked and used on other devices, resulting in low data security. Attached Figure Description
[0017] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0018] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0019] Figure 1This is a schematic diagram of the hardware environment for a data encryption method according to an embodiment of this application;
[0020] Figure 2 This is a flowchart (I) of a data encryption method according to an embodiment of the present invention;
[0021] Figure 3 This is a flowchart (II) of a data encryption method according to an embodiment of the present invention;
[0022] Figure 4 This is a structural block diagram (a) of a data encryption device according to an embodiment of the present invention;
[0023] Figure 5 This is a structural block diagram (II) of a data encryption device according to an embodiment of the present invention. Detailed Implementation
[0024] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.
[0025] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0026] According to one aspect of the embodiments of this application, a data encryption method is provided. This data encryption method is widely used in whole-house intelligent digital control application scenarios such as smart homes, smart home ecosystems, and intelligencehouse ecosystems. Optionally, in this embodiment, the above-mentioned data encryption method can be applied to, for example... Figure 1 The hardware environment shown consists of terminal device 102 and server 104. For example... Figure 1As shown, server 104 is connected to terminal device 102 via a network and can be used to provide services (such as application services) to the terminal or clients installed on the terminal. A database can be set up on the server or independently of the server to provide data storage services for server 104. Cloud computing and / or edge computing services can be configured on the server or independently of the server to provide data processing services for server 104.
[0027] The aforementioned network may include, but is not limited to, at least one of the following: wired network, wireless network. The aforementioned wired network may include, but is not limited to, at least one of the following: wide area network, metropolitan area network, local area network. The aforementioned wireless network may include, but is not limited to, at least one of the following: Wi-Fi (Wireless Fidelity), Bluetooth. The terminal device 102 may not be limited to PC, mobile phone, tablet computer, smart air conditioner, smart range hood, smart refrigerator, smart oven, smart stove, smart washing machine, smart water heater, smart washing equipment, smart dishwasher, smart projector, smart TV, smart clothes rack, smart curtains, smart audio-visual equipment, smart socket, smart speaker, smart speaker box, smart fresh air equipment, smart kitchen and bathroom equipment, smart bathroom equipment, smart robot vacuum cleaner, smart window cleaning robot, smart mopping robot, smart air purifier, smart steam oven, smart microwave oven, smart water heater, smart air purifier, smart water dispenser, smart door lock, etc.
[0028] To solve the above problems, Figure 2 This is a flowchart (I) of a data encryption method according to an embodiment of the present invention, which includes the following steps:
[0029] Step S202: When the processor of the target device is started, obtain the hardware information in the target device through the boot program of the processor;
[0030] In one exemplary embodiment, at least one of the following can be obtained through the processor's bootloader: the Media Access Control (MAC) address of the target device, the processor's identifier, and the memory chip's identifier. It should be noted that the processor's identifier uniquely identifies the processor; that is, each processor has a corresponding identifier, and different processors have different identifiers. Similarly, the memory chip's identifier also uniquely identifies the memory chip.
[0031] It should be noted that the bootloader can obtain the target device's MAC address, processor identifier, and storage chip identifier in the same or different ways.
[0032] In other words, the obtained hardware information includes at least one of the following: the target device's Media Access Control (MAC) address, the processor's identifier, and the memory chip's identifier.
[0033] Step S204: If it is determined that the processor has a built-in security module or the processor has an external security module, obtain the preset root key in the security module;
[0034] It should be noted that after the processor's bootloader starts, it can determine whether the processor has a security module. Specifically, this could be a built-in TrustZone or an external security chip. Then, if it is determined that the processor has a built-in or external security module, the root key preset in that security module will be used.
[0035] Step S206: Generate a target storage key based on the hardware information and the root key, wherein the target storage key is used to encrypt the data to be stored in the target device before storage;
[0036] It should be noted that there are multiple ways to generate the target storage key based on the hardware information and the root key. In one exemplary embodiment, the current date can be obtained, and the current date, the hardware information, and the root key can be hashed to obtain the target storage key.
[0037] Understandably, to further ensure key security, the current date can be used during key generation, and then encrypted using the current date, so that the key is different for each day. Even if the key is stolen, the stolen key cannot decrypt all the data, thus ensuring data security.
[0038] It should be noted that after the target storage key is generated, it will be stored in the security module corresponding to the processor.
[0039] Step S208: Read the first data to be processed in the target device through the security module, and if the first data read is the data to be stored in the target device, encrypt the first data according to the target storage key to obtain the first encrypted data, and store the first encrypted data in the target device.
[0040] Through the above steps, a target key is generated using the device's hardware information, and the data is encrypted using the target key. This ensures that even if the data is stolen and used on other devices, the hardware information of those other devices differs from that of the original device, making it impossible to crack the data. This solves the problem that data in existing devices is not associated with the device itself, making it easy for the stolen data to be cracked and used on other devices, resulting in low data security.
[0041] It should be noted that, in an exemplary embodiment, when the first data read is data to be transmitted, a first transmission key is generated based on the hardware information, the root key, and the first random number; the first data read is then encrypted using the first transmission key to obtain second encrypted data.
[0042] In this embodiment, if the target device sends data to the cloud server, a key is used to encrypt the data to be transmitted to ensure data security. This requires generating a transmission key. However, since data transmission is real-time, the generated key also needs to be real-time. Therefore, the target device can agree on a random number with the cloud server, and generate the transmission key using the agreed random number, obtained hardware information, and the key. The generated transmission key is then used to encrypt the data to be transmitted. It should be noted that the cloud server can generate the transmission key using the same algorithm, and then use the generated transmission key to decrypt the data sent by the target device.
[0043] In an exemplary embodiment, if the first data read is data to be transmitted, or if the first data read is data to be transmitted in a first session, the first random number corresponding to the first session is obtained, and then a first transmission key is generated based on the hardware information, the root key, and the first random number.
[0044] In other words, the random number required to generate the transmission key is associated with the session. When transmitting data in the session, it is necessary to obtain the random number corresponding to the session and use the random number corresponding to the session to generate the transmission key, and then transmit the data through the generated transmission key.
[0045] In an exemplary embodiment, the security module can also read the second data to be processed in the target device; if the read second data is data to be transmitted in the second session, a second transmission key is generated according to the hardware information, the root key and the second random number, wherein the first data is data to be transmitted in the first session, and the first session and the second session are different sessions; the read second data is encrypted according to the second transmission key to obtain third encrypted data.
[0046] It should be noted that the second random number is associated with the second session. After the target device generates the first transmission key to transmit data in the first session, if the second session contains second data that needs to be transmitted, it needs to regenerate the second transmission key using the same algorithm based on the second random number corresponding to the second session. This second transmission key is then used to encrypt the second data. By employing this upload technology, different transmission keys are used to encrypt data transmitted in different sessions. This prevents the data in another session from being compromised even if the transmission key for one session is stolen, further protecting data security.
[0047] In an exemplary embodiment, the security module can also read third data to be processed in the target device, wherein the first data is data to be transmitted in the first session; if the read third data is data to be transmitted in the first session, the read third data is encrypted according to the first transmission key to obtain fourth encrypted data.
[0048] In other words, the same transmission key can be used for the same session, and there is no need to generate a new transmission key every time data is transmitted, thereby reducing the computing power of the target device.
[0049] It should be noted that, in one exemplary embodiment, if it is determined that the processor has no built-in security module and no external security module, a preset root key in the processor's non-security module is obtained. Then, a corresponding storage key is generated based on the preset root key in the non-security module and the hardware information of the target device.
[0050] It should be noted that the method for generating the storage key corresponding to the insecure module is the same as the method for generating the storage key for the secure module. After generating the storage key corresponding to the insecure module, the storage key corresponding to the insecure module needs to be stored in the insecure module of the processor.
[0051] Similarly, when a non-secure module detects data to be stored, it encrypts the data before storage using the storage key corresponding to the non-secure module. When a non-secure module detects data to be transmitted, it generates a corresponding transmission key using the same method as the secure module, and then encrypts the data to be transmitted before transmission using the generated transmission key.
[0052] It should be noted that after the target storage key is generated, it will be stored in the security module corresponding to the processor.
[0053] Obviously, the embodiments described above are merely some embodiments of the present invention, and not all embodiments. To better understand the above data encryption method, the process is described below with reference to embodiments, but this is not intended to limit the technical solutions of the embodiments of the present invention. Specifically:
[0054] In an optional embodiment, Figure 3 This is a flowchart (II) of a data encryption method according to an embodiment of the present invention, which includes the following steps:
[0055] Step S302: CPU program startup (equivalent to the processor bootloader in the above embodiment) starts;
[0056] Step S304: Obtain the device MAC address, the identification number of the storage chip, and the identification number of the CPU;
[0057] Step S306: Determine whether the CPU has a security module. If it does, proceed to step S308; otherwise, proceed to step S312.
[0058] Step S308: Obtain the root key stored in the security module;
[0059] Step S310: Generate a storage key and a transmission key based on the root key of the security module, the device MAC address, the identifier of the storage chip, and the identifier of the CPU;
[0060] Step S312: Obtain the root key for the insecure module;
[0061] Step S314: Generate a storage key and a transmission key based on the root key of the non-secure module, the device MAC address, the identifier of the storage chip, and the identifier of the CPU.
[0062] To better understand, the following is a detailed explanation: After the target device's system boots up (which may include Secure Boot), the processor bootloader reads the hardware information of each target device and determines whether the processor has a TrustZone or a security chip. If so, it reads the rootkey (equivalent to the root key of the security module in the above embodiment) within the security system and generates a sessionkey (equivalent to the transmission key in the above embodiment) based on the readable hardware information and the rootkey. This sessionkey is used for communication between the user device and the cloud server. A storage key (equivalent to the storage key in the above embodiment) is generated using another algorithm for encrypted data storage. Otherwise, the rootkey is read externally, and the same algorithm is used to generate the sessionkey and storage key.
[0063] In this embodiment, the software can also read the FLASHID, MAC address, and cpuID (only found in high-security chips), and use an encryption algorithm to calculate a userkey from these or one of these hardware information items. If the chip has a secure area, it can also combine this with the root key written into the secure area to generate a new session key. This userkey is used to encrypt user data and stored on local flash memory. If someone clones the entire flash memory to a monitored flash memory to obtain user information, the user data cannot be decrypted due to incompatibility with the new flash memory or MAC address, indirectly protecting the user's privacy.
[0064] Furthermore, the technical solutions described above in this embodiment of the invention fully utilize the uniqueness and diversity of hardware to bind user data to multiple hardware devices, achieving the goal of high-security data protection. This can be implemented using existing equipment, solving the cost problem, and preventing the acquisition of user privacy data through hardware copying and other technical means. In addition, the technical solutions of this embodiment are also universal and applicable to various types of devices.
[0065] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods of the various embodiments of the present invention.
[0066] This embodiment also provides a data encryption device for implementing the above embodiments and preferred embodiments; details already described will not be repeated. As used below, the term "module" can refer to a combination of software and / or hardware that performs a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, hardware implementations, or a combination of software and hardware, are also possible and contemplated.
[0067] Figure 4 This is a structural block diagram (I) of a data encryption device according to an embodiment of the present invention, the device comprising:
[0068] The first acquisition module 42 is used to acquire hardware information in the target device through the boot program of the processor when the processor of the target device is started.
[0069] The second acquisition module 44 is used to acquire the preset root key in the security module when it is determined that the security module is built into the processor or the security module is externally connected to the processor.
[0070] The generation module 46 is used to generate a target storage key based on the hardware information and the root key, wherein the target storage key is used to encrypt the data to be stored in the target device before storage;
[0071] The encryption module 48 is used to read the first data to be processed in the target device through the security module, and when the first data read is data to be stored in the target device, to encrypt the first data according to the target storage key to obtain the first encrypted data, and to store the first encrypted data in the target device.
[0072] The aforementioned device generates a target key based on the device's hardware information and encrypts the data using the target key. This ensures that even if the data is stolen and used on other devices, the data cannot be cracked because the hardware information of those other devices differs from that of the original device. This guarantees data security and solves the problem that data in existing devices is not associated with the device itself, making it easy for the stolen data to be cracked and used on other devices, resulting in low data security.
[0073] Figure 5 This is a structural block diagram (II) of a data encryption device according to an embodiment of the present invention, which includes a processing module 52.
[0074] In an exemplary embodiment, the processing module 52 is configured to, when the first data read is data to be transmitted, generate a first transmission key based on the hardware information, the root key, and a first random number; and encrypt the first data read based on the first transmission key to obtain second encrypted data.
[0075] In this embodiment, if the target device sends data to the cloud server, a key is used to encrypt the data to be transmitted to ensure data security. This requires generating a transmission key. However, since data transmission is real-time, the generated key also needs to be real-time. Therefore, the target device can agree on a random number with the cloud server, and generate the transmission key using the agreed random number, obtained hardware information, and the key. The generated transmission key is then used to encrypt the data to be transmitted. It should be noted that the cloud server can generate the transmission key using the same algorithm, and then use the generated transmission key to decrypt the data sent by the target device.
[0076] In an exemplary embodiment, the processing module 52 is further configured to, when the first data read is data to be transmitted in the first session, obtain the first random number corresponding to the first session; and generate a first transmission key based on the hardware information, the root key, and the first random number.
[0077] In an exemplary embodiment, the processing module 52 is further configured to read second data to be processed in the target device through the security module; if the read second data is data to be transmitted in a second session, generate a second transmission key according to the hardware information, the root key and the second random number, wherein the first data is data to be transmitted in a first session, and the first session and the second session are different sessions; encrypt the read second data according to the second transmission key to obtain third encrypted data.
[0078] It should be noted that the second random number is associated with the second session. After the target device generates the first transmission key to transmit data in the first session, if the second session contains second data that needs to be transmitted, it needs to regenerate the second transmission key using the same algorithm based on the second random number corresponding to the second session. This second transmission key is then used to encrypt the second data. By employing this upload technology, different transmission keys are used to encrypt data transmitted in different sessions. This prevents the data in another session from being compromised even if the transmission key for one session is stolen, further protecting data security.
[0079] In an exemplary embodiment, the processing module 52 is further configured to read third data to be processed in the target device through the security module, wherein the first data is data to be transmitted in the first session; if the read third data is data to be transmitted in the first session, the read third data is encrypted according to the first transmission key to obtain fourth encrypted data.
[0080] In an exemplary embodiment, the generation module is further configured to obtain the current date; and perform a hash operation on the current date, the hardware information, and the root key to obtain the target storage key.
[0081] In an exemplary embodiment, the first acquisition module is further configured to acquire at least one of the following through the processor's bootloader: the Media Access Control (MAC) address of the target device, the identifier of the processor, and the identifier of the memory chip.
[0082] Embodiments of the present invention also provide a computer-readable storage medium storing a computer program, wherein the computer program is configured to perform the steps in any of the above method embodiments when executed.
[0083] Optionally, in this embodiment, the storage medium may be configured to store a computer program for performing the following steps:
[0084] S1, when the processor of the target device is started, the hardware information in the target device is obtained through the boot program of the processor;
[0085] S2, if it is determined that the processor has a built-in security module or the processor has an external security module, obtain the preset root key in the security module;
[0086] S3, Generate a target storage key based on the hardware information and the root key, wherein the target storage key is used to encrypt the data to be stored in the target device before storage;
[0087] S4, the security module reads the first data to be processed in the target device, and if the first data read is the data to be stored in the target device, the first data is encrypted according to the target storage key to obtain the first encrypted data, and the first encrypted data is stored in the target device.
[0088] In one exemplary embodiment, the aforementioned computer-readable storage medium may include, but is not limited to, various media capable of storing computer programs, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard disk, magnetic disk, or optical disk.
[0089] Specific examples in this embodiment can be found in the examples described in the above embodiments and exemplary implementations, and will not be repeated here.
[0090] Embodiments of the present invention also provide an electronic device including a memory and a processor, the memory storing a computer program and the processor being configured to run the computer program to perform the steps in any of the above method embodiments.
[0091] Optionally, in this embodiment, the processor can be configured to perform the following steps via a computer program:
[0092] S1, when the processor of the target device is started, the hardware information in the target device is obtained through the boot program of the processor;
[0093] S2, if it is determined that the processor has a built-in security module or the processor has an external security module, obtain the preset root key in the security module;
[0094] S3, Generate a target storage key based on the hardware information and the root key, wherein the target storage key is used to encrypt the data to be stored in the target device before storage;
[0095] S4, the security module reads the first data to be processed in the target device, and if the first data read is the data to be stored in the target device, the first data is encrypted according to the target storage key to obtain the first encrypted data, and the first encrypted data is stored in the target device.
[0096] In one exemplary embodiment, the electronic device may further include a transmission device and an input / output device, wherein the transmission device is connected to the processor and the input / output device is connected to the processor.
[0097] Specific examples in this embodiment can be found in the examples described in the above embodiments and exemplary implementations, and will not be repeated here.
[0098] It is obvious to those skilled in the art that the modules or steps of the present invention described above can be implemented using general-purpose computing devices. They can be centralized on a single computing device or distributed across a network of multiple computing devices. They can be implemented using computer-executable program code, and thus can be stored in a storage device for execution by a computing device. In some cases, the steps shown or described can be performed in a different order than those described herein, or they can be fabricated as separate integrated circuit modules, or multiple modules or steps can be fabricated as a single integrated circuit module. Thus, the present invention is not limited to any particular combination of hardware and software.
[0099] The above description is only a preferred embodiment of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications should also be considered within the scope of protection of this application.
Claims
1. A data encryption method, characterized in that, include: When the processor of the target device is started, the hardware information in the target device is obtained through the boot program of the processor; If it is determined that the processor has a built-in security module or the processor has an external security module, the root key preset in the security module is obtained; A target storage key is generated based on the hardware information and the root key, wherein the target storage key is used to encrypt the data to be stored in the target device before storage; The security module reads the first data to be processed from the target device, and if the first data read is data to be stored in the target device, the first data is encrypted according to the target storage key to obtain the first encrypted data, and the first encrypted data is stored in the target device. The method further includes: when the first data read is data to be transmitted in a first session, obtaining a first random number corresponding to the first session; generating a first transmission key based on the hardware information, the root key, and the first random number; and encrypting the first data read based on the first transmission key to obtain second encrypted data. The step of generating a target storage key based on the hardware information and the root key includes: obtaining the current date and performing a hash operation on the current date, the hardware information, and the root key to obtain the target storage key; The method further includes: reading second data to be processed from the target device through the security module; if the read second data is data to be transmitted in a second session, generating a second transmission key based on the hardware information, the root key, and a second random number, wherein the first data is data to be transmitted in a first session, and the first session and the second session are different sessions; encrypting the read second data according to the second transmission key to obtain third encrypted data, wherein the second random number is a random number corresponding to the second session; Specifically, if it is determined that the processor has no built-in security module and the processor also has no external security module, the root key preset in the processor's non-security module is obtained; and a corresponding storage key is generated based on the root key preset in the non-security module and the hardware information of the target device.
2. The method according to claim 1, characterized in that, The method further includes: The security module reads the third data to be processed from the target device, wherein the first data is the data to be transmitted in the first session; If the third data read is data to be transmitted in the first session, the third data read is encrypted according to the first transmission key to obtain fourth encrypted data.
3. The method according to any one of claims 1 to 2, characterized in that, Obtaining hardware information from the target device through the processor's bootloader includes: The processor's bootloader obtains at least one of the following: the Media Access Control (MAC) address of the target device, the processor's identifier, and the memory chip's identifier.
4. A data encryption device, characterized in that, include: The first acquisition module is used to acquire hardware information in the target device through the boot program of the processor when the processor of the target device is started. The second acquisition module is used to acquire the preset root key in the security module when it is determined that the security module is built into the processor or the security module is externally connected to the processor. A generation module is used to generate a target storage key based on the hardware information and the root key, wherein the target storage key is used to encrypt the data to be stored in the target device before storage; An encryption module is used to read first data to be processed in the target device through the security module, and when the first data read is data to be stored in the target device, to encrypt the first data according to the target storage key to obtain first encrypted data, and to store the first encrypted data in the target device. The device further includes: a processing module, configured to: obtain a first random number corresponding to the first session when the first data read is data to be transmitted in the first session; generate a first transmission key based on the hardware information, the root key and the first random number; and encrypt the first data read based on the first transmission key to obtain second encrypted data; The generation module is further configured to obtain the current date and perform a hash operation on the current date, the hardware information, and the root key to obtain the target storage key; The processing module is further configured to read second data to be processed from the target device through the security module; if the read second data is data to be transmitted in a second session, generate a second transmission key based on the hardware information, the root key, and a second random number, wherein the first data is data to be transmitted in a first session, and the first session and the second session are different sessions; encrypt the read second data according to the second transmission key to obtain third encrypted data, wherein the second random number is a random number corresponding to the second session; The device is further configured to, when it is determined that the processor has no built-in security module and the processor has no external security module, obtain a preset root key in the non-security module of the processor; and generate a corresponding storage key based on the preset root key in the non-security module and the hardware information of the target device.
5. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored program, wherein the program, when executed, performs the method of any one of claims 1 to 3.
6. An electronic device comprising a memory and a processor, characterized in that, The memory stores a computer program, and the processor is configured to execute the method of any one of claims 1 to 3 through the computer program.
Citation Information
Patent Citations
Key encryption method and decryption method, and, data encryption method and decryption method
WO2021114891A1