A method, device, electronic device and storage medium for virtual OTP decryption
By obtaining the virtual OTP key ciphertext and hardware OTP key, combined with hardware and software decryption rules, the problem of limiting the number of OTP areas is solved, and the decryption of data from different sources is achieved, with good scalability and compatibility.
Patent Information
- Application Number
- CN202210723737.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-23
- Publication Date
- 2025-08-01
- Estimated Expiration
- 2042-06-23
AI Technical Summary
In the prior art, the limit on the number of OTP regions makes it impossible to achieve the encryption and decryption requirements of data from different sources, and the existing encryption scheme cannot meet the decryption requirements of data from different sources.
By obtaining the virtual OTP key ciphertext and preset hardware OTP key corresponding to the data to be decrypted, decryption is performed using the preset hardware OTP key and preset software decryption rules, and combining the differences between hardware and software decryption rules to achieve decryption of data from different sources.
It realizes the decryption requirements for data from different sources, meets the encryption and decryption requirements for data from different sources, has good scalability and strong compatibility.
Smart Images

Figure CN115150074B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer security technology, and particularly to a method, apparatus, electronic device and storage medium for virtual OTP decryption. Background Art
[0002] OTP (One Time Programable) is a type of one-time programmable memory. After the program or data is burned into this memory, it cannot be changed or cleared again. The OTP area of the system-on-chip is generally used to store keys. The keys stored in this area can only be used and cannot be obtained by software, thus ensuring the security of the keys. The currently common encryption scheme is to encrypt and transmit the key and write the key into the OTP area, and decrypt it through the OTP during the decryption process. This scheme is limited by the number of OTP areas and cannot meet the requirements of encrypting and decrypting data from different sources. Summary of the Invention
[0003] The embodiments of the present invention aim to provide a method, apparatus, electronic device and storage medium for virtual OTP decryption, which can meet the requirements of encrypting and decrypting data from different sources. The specific technical solutions are as follows:
[0004] According to the first aspect of the embodiments of the present invention, a method for virtual OTP decryption is provided. The method includes:
[0005] When decrypting the data to be decrypted, obtaining the first virtual OTP key ciphertext corresponding to the data to be decrypted, and obtaining a preset hardware OTP key;
[0006] Using the preset hardware OTP key and the preset software decryption rule to decrypt the first virtual OTP key ciphertext to obtain the virtual OTP key plaintext, wherein the software decryption rules for the data to be decrypted from different sources are different;
[0007] Using the virtual OTP key plaintext to decrypt the data to be decrypted to obtain the decrypted data.
[0008] Optionally, when decrypting the data to be decrypted, obtaining the first virtual OTP key ciphertext corresponding to the data to be decrypted, and obtaining a preset hardware OTP key includes:
[0009] When decrypting the data to be decrypted, obtaining the virtual OTP key ciphertext corresponding to the data to be decrypted in a preset key file to obtain the first virtual OTP key ciphertext, wherein the virtual OTP key ciphertexts corresponding to the data to be decrypted from different sources are different;
[0010] Obtaining a preset hardware OTP key in a preset hardware OTP storage area.
[0011] Optionally, the decrypting the first virtual OTP key ciphertext by using a preset hardware OTP key and a preset software decryption rule to obtain a virtual OTP key plaintext includes:
[0012] Decrypting the first virtual OTP key ciphertext by using the preset hardware OTP key to obtain a once-decrypted virtual OTP key;
[0013] Decrypting the once-decrypted virtual OTP key by using the preset software encryption rule to obtain the virtual OTP key plaintext.
[0014] Optionally, the decrypting the first virtual OTP key ciphertext by using a preset hardware OTP key and a preset software decryption rule to obtain a virtual OTP key plaintext includes:
[0015] Decrypting the first virtual OTP key ciphertext by using the preset software encryption rule to obtain a once-decrypted virtual OTP key;
[0016] Decrypting the once-decrypted virtual OTP key by using the preset hardware OTP key to obtain the virtual OTP key plaintext.
[0017] According to the second aspect of the embodiments of the present invention, a method for generating a virtual OTP key ciphertext is provided, and the method includes:
[0018] Obtaining a virtual OTP key plaintext;
[0019] Encrypting the virtual OTP key plaintext by using a preset software encryption rule and a preset hardware OTP key to obtain a virtual OTP key ciphertext, wherein the software encryption rules for virtual OTP key plaintexts from different sources are different.
[0020] Optionally, the encrypting the virtual OTP key plaintext by using a preset software encryption rule and a preset hardware OTP key to obtain a virtual OTP key ciphertext includes:
[0021] Encrypting the virtual OTP key plaintext by using the preset software encryption rule to obtain a once-encrypted virtual OTP key;
[0022] Encrypting the once-encrypted virtual OTP key by using the preset hardware OTP key to obtain the virtual OTP key ciphertext.
[0023] Optionally, the encrypting the virtual OTP key plaintext by using a preset software encryption rule and a preset hardware OTP key to obtain a virtual OTP key ciphertext includes:
[0024] Encrypt the virtual OTP key plaintext using a preset hardware OTP key to obtain a once-encrypted virtual OTP key;
[0025] Encrypt the once-encrypted virtual OTP key using a preset software encryption rule to obtain a virtual OTP key ciphertext.
[0026] According to the third aspect of the embodiments of the present invention, there is provided a virtual OTP decryption device, the device includes:
[0027] An acquisition module, configured to obtain the first virtual OTP key ciphertext corresponding to the data to be decrypted and obtain a preset hardware OTP key when decrypting the data to be decrypted;
[0028] A key decryption module, configured to decrypt the first virtual OTP key ciphertext using a preset hardware OTP key and a preset software decryption rule to obtain a virtual OTP key plaintext, where the software decryption rules for data to be decrypted from different sources are different;
[0029] A decryption module, configured to decrypt the data to be decrypted using the virtual OTP key plaintext to obtain decrypted data.
[0030] Optionally, the acquisition module includes:
[0031] A key ciphertext acquisition module, configured to obtain the virtual OTP key ciphertext corresponding to the data to be decrypted in a preset key file to obtain a first virtual OTP key ciphertext when decrypting the data to be decrypted, where the virtual OTP key ciphertexts corresponding to data to be decrypted from different sources are different;
[0032] A hardware key acquisition module, configured to obtain a preset hardware OTP key in a preset hardware OTP storage area.
[0033] Optionally, the key decryption module includes:
[0034] A hardware decryption module, configured to decrypt the first virtual OTP key ciphertext using a preset hardware OTP key to obtain a once-decrypted virtual OTP key;
[0035] A software decryption module, configured to decrypt the once-decrypted virtual OTP key using a preset software encryption rule to obtain a virtual OTP key plaintext.
[0036] Optionally, the key decryption module includes:
[0037] A software decryption module, configured to decrypt the first virtual OTP key ciphertext using a preset software encryption rule to obtain a once-decrypted virtual OTP key;
[0038] A hardware decryption module, configured to decrypt the once-decrypted virtual OTP key by using a preset hardware OTP key to obtain the plaintext of the virtual OTP key.
[0039] According to a fourth aspect of the embodiments of the present invention, there is provided a virtual OTP key ciphertext generation device, including:
[0040] An acquisition module, configured to acquire the plaintext of the virtual OTP key;
[0041] An encryption module, configured to encrypt the plaintext of the virtual OTP key by using a preset software encryption rule and a preset hardware OTP key to obtain a virtual OTP key ciphertext, wherein the software encryption rules for the plaintext of the virtual OTP keys from different sources are different.
[0042] Optionally, the encryption module includes:
[0043] A software encryption module, configured to encrypt the plaintext of the virtual OTP key by using a preset software encryption rule to obtain a once-encrypted virtual OTP key;
[0044] A hardware encryption module, configured to encrypt the once-encrypted virtual OTP key by using a preset hardware OTP key to obtain a virtual OTP key ciphertext.
[0045] Optionally, the encryption module includes:
[0046] A hardware encryption module, configured to encrypt the plaintext of the virtual OTP key by using a preset hardware OTP key to obtain a once-encrypted virtual OTP key;
[0047] A software encryption module, configured to encrypt the once-encrypted virtual OTP key by using a preset software encryption rule to obtain a virtual OTP key ciphertext.
[0048] According to a fifth aspect of the embodiments of the present invention, there is provided an electronic device, including a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory complete mutual communication through the communication bus;
[0049] The memory is used to store a computer program;
[0050] When the processor is configured to execute the program stored in the memory, the method steps described in any one of the first aspect are implemented.
[0051] According to a sixth aspect of the embodiments of the present invention, there is provided another electronic device, including a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory complete mutual communication through the communication bus;
[0052] A memory for storing a computer program;
[0053] A processor for implementing the method steps described in any one of the second aspects when executing the program stored in the memory.
[0054] According to a seventh aspect of an embodiment of the present invention, there is provided a computer-readable storage medium storing a computer program therein, and when the computer program is executed by a processor, the method steps described in any one of the first aspect and the second aspect are implemented.
[0055] Advantageous effects of the embodiments of the present invention:
[0056] A method, apparatus, electronic device, and storage medium for virtual OTP decryption provided by an embodiment of the present invention, when decrypting data to be decrypted, by obtaining a first virtual OTP key ciphertext corresponding to the data to be decrypted, and obtaining a preset hardware OTP key, using the preset hardware OTP key and a preset software decryption rule to decrypt the first virtual OTP key ciphertext to obtain a virtual OTP key plaintext. Since the software decryption rules for data to be decrypted from different sources are different, the data to be decrypted from different sources will be decrypted according to different virtual OTP key plaintexts to obtain decrypted data, meeting the requirement of decrypting data to be decrypted from different sources.
[0057] Of course, when implementing any product or method of the present invention, it is not necessarily required to achieve all the above advantages simultaneously. BRIEF DESCRIPTION OF THE DRAWINGS
[0058] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention, and those of ordinary skill in the art can also obtain other embodiments based on these drawings.
[0059] Figure 1a is the first flowchart of the virtual OTP decryption method provided by an embodiment of the present invention;
[0060] Figure 1b is the second flowchart of the virtual OTP decryption method provided by an embodiment of the present invention;
[0061] Figure 1c is the third flowchart of the virtual OTP decryption method provided by an embodiment of the present invention;
[0062] Figure 1d is the fourth flowchart of the virtual OTP decryption method provided by an embodiment of the present invention;
[0063] Figure 2a It is a flowchart of a method for generating virtual OTP key ciphertext provided by an embodiment of the present invention;
[0064] Figure 2b It is another flowchart of a method for generating virtual OTP key ciphertext provided by an embodiment of the present invention;
[0065] Figure 2c It is yet another flowchart of a method for generating virtual OTP key ciphertext provided by an embodiment of the present invention;
[0066] Figure 2d It is a schematic diagram of a decryption process for decryption using a method of virtual OTP decryption provided by an embodiment of the present invention;
[0067] Figure 3 It is a schematic diagram of the structure of a virtual OTP decryption device provided by an embodiment of the present invention;
[0068] Figure 4 It is a schematic diagram of the structure of a virtual OTP key ciphertext generation device provided by an embodiment of the present invention;
[0069] Figure 5 It is a schematic diagram of the structure of an electronic device provided by an embodiment of the present invention;
[0070] Figure 6 It is a schematic diagram of the structure of another electronic device provided by an embodiment of the present invention. Detailed implementation manners
[0071] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art based on this application belong to the scope of protection of the present invention.
[0072] To meet the requirement of encrypting and decrypting data from different sources, an embodiment of the present invention provides a method, device, electronic device, and storage medium for virtual OTP decryption, which will be described in detail below:
[0073] The method for virtual OTP decryption provided by an embodiment of the present invention can be implemented through an electronic device. For example, the electronic device can be a smart phone, a smart camera, a hard disk video recorder, or a personal computer, etc.
[0074] See Figure 1a , Figure 1a It is the first flowchart of the virtual OTP decryption method provided by an embodiment of the present invention, and the method may include:
[0075] Step S101, when decrypting the data to be decrypted, obtain the first virtual OTP key ciphertext corresponding to the data to be decrypted, and obtain a preset hardware OTP key;
[0076] Step S102, use the preset hardware OTP key and the preset software decryption rule to decrypt the first virtual OTP key ciphertext to obtain the virtual OTP key plaintext, where the software decryption rules for the data to be decrypted from different sources are different;
[0077] Step S103, use the virtual OTP key plaintext to decrypt the data to be decrypted to obtain the decrypted data.
[0078] From Figure 1a the above embodiments, it can be seen that when decrypting the data to be decrypted, by obtaining the first virtual OTP key ciphertext corresponding to the data to be decrypted, and obtaining a preset hardware OTP key, using the preset hardware OTP key and the preset software decryption rule to decrypt the first virtual OTP key ciphertext to obtain the virtual OTP key plaintext. Since the software decryption rules for the data to be decrypted from different sources are different, the data to be decrypted from different sources will be decrypted according to different virtual OTP key plaintexts to obtain the decrypted data, meeting the requirement of decrypting the data to be decrypted from different sources.
[0079] In the embodiments of the present invention, the above data to be decrypted can be obtained by encrypting business data or programs that need to be encrypted. For example, at the encryption end, the corresponding virtual OTP key plaintext can be used to encrypt the business data or programs to obtain the data to be decrypted.
[0080] In a possible implementation manner, refer to Figure 1b , Figure 1b which is the second flowchart of the virtual OTP decryption method provided by the embodiments of the present invention; based on Figure 1a , Figure 1b the above step S101 is refined as Figure 1b described, step S101 may specifically include:
[0081] Step S1011, when decrypting the data to be decrypted, obtain the virtual OTP key ciphertext corresponding to the data to be decrypted in a preset key file to obtain the first virtual OTP key ciphertext, where the virtual OTP key ciphertexts corresponding to the data to be decrypted from different sources are different.
[0082] In the embodiments of the present invention, the above preset key file stores the first virtual OTP key ciphertext, and different data to be decrypted from different sources will correspond to different preset key files.
[0083] Step S1012, obtain a preset hardware OTP key in a preset hardware OTP storage area.
[0084] Only one preset hardware OTP key can be stored in the electronic device, and this preset hardware OTP key is stored in the hardware OTP storage area. However, multiple preset key files can be stored in the electronic device. Different preset key files correspond to different data sources, and the virtual OTP key ciphertext is recorded in the preset key files. The virtual OTP key ciphertexts corresponding to the to-be-decrypted data from different sources are different.
[0085] In a possible implementation manner, refer to Figure 1c , Figure 1c which is the third flowchart of the virtual OTP decryption method provided by the embodiments of the present invention; based on Figure 1a , Figure 1c the above step S102 is refined as shown in Figure 1c . The using the preset hardware OTP key and the preset software decryption rule to decrypt the first virtual OTP key ciphertext to obtain the virtual OTP key plaintext includes:
[0086] Step S1031, use the preset hardware OTP key to decrypt the first virtual OTP key ciphertext to obtain the once-decrypted virtual OTP key;
[0087] Step S1032, use the preset software encryption rule to decrypt the once-decrypted virtual OTP key to obtain the virtual OTP key plaintext;
[0088] In a possible implementation manner, refer to Figure 1d , Figure 1d which is the fourth flowchart of the virtual OTP decryption method provided by the embodiments of the present invention; based on Figure 1a , Figure 1d the above step S102 is refined as shown in Figure 1d . The using the preset hardware OTP key and the preset software decryption rule to decrypt the first virtual OTP key ciphertext to obtain the virtual OTP key plaintext includes:
[0089] Step S1033, use the preset software encryption rule to decrypt the first virtual OTP key ciphertext to obtain the once-decrypted virtual OTP key;
[0090] Step S1034, use the preset hardware OTP key to decrypt the once-decrypted virtual OTP key to obtain the virtual OTP key plaintext.
[0091] From Figure 1c and Figure 1dAs can be seen from the illustrated embodiments, when decrypting the first virtual OTP key ciphertext, two decryption methods can be included. Which decryption method to adopt is related to the encryption method of the first virtual OTP key ciphertext. For example, in the process of obtaining the first virtual OTP key ciphertext, first encrypt it using a preset software encryption rule, and then encrypt it using a preset hardware OTP key. Then, when decrypting the first virtual OTP key ciphertext, it is necessary to first decrypt it using the preset hardware OTP key, and then decrypt it using the preset software encryption rule; for example, in the process of obtaining the first virtual OTP key ciphertext, first encrypt it using the preset hardware OTP key, and then encrypt it using the preset software encryption rule. Then, when decrypting the first virtual OTP key ciphertext, it is necessary to first decrypt it using the preset software encryption rule, and then decrypt it using the preset hardware OTP key to obtain the virtual OTP key plaintext.
[0092] Hereinafter, the encryption process of the virtual OTP key ciphertext will be described. An embodiment of the present invention also provides a method for generating a virtual OTP key ciphertext. Figure 2a is a flowchart of a method for generating a virtual OTP key ciphertext provided by an embodiment of the present invention. As Figure 2a shown, the method may include:
[0093] Step S201, obtain the virtual OTP key plaintext.
[0094] In an embodiment of the present invention, the virtual OTP key plaintext is the key used for encrypting the data to be encrypted. The above virtual OTP key plaintext may be provided by the source party of the data to be encrypted, or may be generated according to actual needs. For example, the virtual OTP key plaintext may be obtained according to the platform code or other rules, and no specific limitation is made here. In one example, the virtual OTP key plaintexts used for data to be encrypted from different sources are different.
[0095] Step S202, encrypt the virtual OTP key plaintext using a preset software encryption rule and a preset hardware OTP key to obtain a virtual OTP key ciphertext, where the software encryption rules for virtual OTP key plaintexts from different sources are different.
[0096] In an embodiment of the present invention, the above virtual OTP key ciphertext may be stored in a preset key file. For data from different sources, there are corresponding different preset key files, that is, corresponding different virtual OTP key ciphertexts.
[0097] In the embodiments of the present invention, the above-mentioned preset hardware OTP key is stored in the hardware OTP storage area. There can be one such storage area or multiple ones. If there is only one hardware OTP storage area, the software encryption rules for the virtual OTP key plaintexts from different sources are different, and it can also meet the requirement of encrypting multiple data from different sources. Theoretically, there is no upper limit on the number of encryption keys, which has scalability.
[0098] From Figure 2a It can be seen from the above-described embodiments that by obtaining the virtual OTP key plaintext and using the preset software encryption rule and the preset hardware OTP key to encrypt the virtual OTP key plaintext, a virtual OTP key ciphertext is obtained. Since the software encryption rules for the virtual OTP key plaintexts from different sources are different, the generated virtual OTP key ciphertexts will be different according to different software encryption rules, meeting the requirement of generating different virtual OTP key ciphertexts corresponding to the data from different sources and realizing the encryption requirement for the data from different sources.
[0099] See Figure 2b And Figure 2c , based on Figure 2a , Figure 2b And Figure 2c In [references] and [references], the above-mentioned step S202 is refined. After obtaining the virtual OTP key plaintext, there are two ways to encrypt the virtual OTP key plaintext. The first way is shown in Figure 2b , and specifically it can include:
[0100] Step S2021: Use the preset software encryption rule to encrypt the virtual OTP key plaintext to obtain a once-encrypted virtual OTP key;
[0101] Step S2022: Use the preset hardware OTP key to encrypt the once-encrypted virtual OTP key to obtain a virtual OTP key ciphertext;
[0102] The second way is shown in Figure 2c , and specifically it can include:
[0103] Step S2023: Use the preset hardware OTP key to encrypt the virtual OTP key plaintext to obtain a once-encrypted virtual OTP key;
[0104] Step S2024: Use the preset software encryption rule to encrypt the once-encrypted virtual OTP key to obtain a virtual OTP key ciphertext.
[0105] From Figure 2b And Figure 2cAs can be seen from the described embodiments, after obtaining the virtual OTP key plaintext, there are two ways to encrypt the virtual OTP key plaintext. One can first encrypt the virtual OTP key plaintext using a preset software encryption rule, or first encrypt the virtual OTP key plaintext using a preset hardware OTP key, so as to obtain the once-encrypted virtual OTP key. The encryption order of the virtual OTP key plaintext is not required, which is convenient for encrypting the virtual OTP key plaintext.
[0106] In the embodiments of the present invention, a virtual OTP encryption method is formed by combining hardware OTP encryption and software encryption. It achieves better scalability while having the same encryption security as hardware OTP encryption. Also, since the encryption order of the virtual OTP key plaintext is not limited, it realizes stronger flexibility and has better compatibility for the encryption of keys from multiple different sources.
[0107] Next, through a specific embodiment, verify whether the decrypted data obtained by decrypting the data to be decrypted using the virtual OTP decryption method provided by the embodiments of the present invention with the virtual OTP key ciphertext obtained by the virtual OTP key ciphertext generation method provided by the embodiments of the present invention is consistent with the data before encryption, thereby determining whether the virtual OTP key ciphertext can successfully decrypt the data to be decrypted. Figure 2c It is a schematic diagram of a decryption process of decrypting the data to be decrypted using the virtual OTP decryption method provided by the embodiments of the present invention with the virtual OTP key ciphertext obtained by the virtual OTP key ciphertext generation method provided by the embodiments of the present invention, as Figure 2d shown.
[0108] (1) Generate a virtual OTP key plaintext according to a preset rule, denoted as A; the preset rule is determined according to requirements and is not limited.
[0109] (2) The plaintext of the data to be encrypted, denoted as B.
[0110] (3) Encrypt the plaintext B using the virtual OTP key A according to a preset encryption method to obtain the encrypted ciphertext, denoted as C; the preset encryption method is not limited.
[0111] (4) According to the virtual OTP key ciphertext in the preset key file and the preset hardware OTP key, decrypt using the virtual OTP decryption method provided by the embodiments of the present invention to obtain the original key, denoted as E; the virtual OTP key ciphertext obtained by encrypting the virtual OTP key plaintext A through the virtual OTP key ciphertext generation method provided by the embodiments of the present invention is stored in the preset key file.
[0112] (5) Use the original key E to perform a decryption method corresponding to the encryption method in step (3) on the encrypted ciphertext C in step (3) to obtain the decrypted plaintext, denoted as F;
[0113] (6) Compare whether the plaintext B and the decrypted plaintext F are the same. If they are the same, it is considered that the decryption is successful; if they are different, the decryption fails.
[0114] From the above process, it can be verified whether the virtual OTP key ciphertext obtained by the virtual OTP key ciphertext generation method provided in the embodiments of the present invention can successfully decrypt the data to be decrypted according to the virtual OTP decryption method provided in the embodiments of the present invention.
[0115] Based on the same inventive concept as the virtual OTP decryption method, the embodiments of the present invention correspondingly provide a virtual OTP decryption device. Figure 3 It is a schematic structural diagram of the virtual OTP decryption device provided in the embodiments of the present invention, as Figure 3 shown, the device may include:
[0116] An acquisition module 301, which can be used to acquire the first virtual OTP key ciphertext corresponding to the data to be decrypted and acquire a preset hardware OTP key when decrypting the data to be decrypted;
[0117] A key decryption module 302, which can be used to decrypt the first virtual OTP key ciphertext by using the preset hardware OTP key and a preset software decryption rule to obtain the virtual OTP key plaintext, wherein the software decryption rules for the data to be decrypted from different sources are different;
[0118] A decryption module 303, which can be used to decrypt the data to be decrypted by using the virtual OTP key plaintext to obtain the decrypted data.
[0119] From Figure 3 the above-mentioned embodiments, it can be seen that the acquisition module 301 can acquire the first virtual OTP key ciphertext corresponding to the data to be decrypted and acquire a preset hardware OTP key, and then the key decryption module 302 can decrypt the first virtual OTP key ciphertext by using the preset hardware OTP key and a preset software decryption rule to obtain the virtual OTP key plaintext, wherein the software decryption rules for the data to be decrypted from different sources are different, and finally the decryption module 303 can decrypt the data to be decrypted by using the virtual OTP key plaintext to obtain the decrypted data. Since the software decryption rules for the data to be decrypted from different sources are different, it is possible to decrypt the data to be decrypted from different sources according to the corresponding different software decryption rules.
[0120] As a specific implementation manner of the embodiments of the present invention, the acquisition module 301 may include:
[0121] The key ciphertext acquisition module can be used to obtain the virtual OTP key ciphertext corresponding to the data to be decrypted in a preset key file when decrypting the data to be decrypted, so as to obtain the first virtual OTP key ciphertext. Among them, the data to be decrypted from different sources corresponds to different virtual OTP key ciphertexts;
[0122] The hardware key acquisition module can be used to obtain a preset hardware OTP key in a preset hardware OTP storage area.
[0123] As a specific implementation manner of an embodiment of the present invention, the key decryption module 302 may include:
[0124] The hardware decryption module can be used to decrypt the first virtual OTP key ciphertext by using a preset hardware OTP key to obtain a once-decrypted virtual OTP key;
[0125] The software decryption module can be used to decrypt the once-decrypted virtual OTP key by using a preset software encryption rule to obtain the virtual OTP key plaintext.
[0126] As a specific implementation manner of an embodiment of the present invention, the key decryption module 302 may include:
[0127] The software decryption module can be used to decrypt the first virtual OTP key ciphertext by using a preset software encryption rule to obtain a once-decrypted virtual OTP key;
[0128] The hardware decryption module can be used to decrypt the once-decrypted virtual OTP key by using a preset hardware OTP key to obtain the virtual OTP key plaintext.
[0129] Regarding the device in the above embodiments, the specific manner in which each module performs operations has been described in detail in the embodiments related to the method, and will not be elaborated here.
[0130] Based on the same inventive concept as the virtual OTP key ciphertext generation method, an embodiment of the present invention correspondingly provides a virtual OTP key ciphertext generation device. Figure 4 The structural schematic diagram of the virtual OTP key ciphertext generation device provided by an embodiment of the present invention is as Figure 4 shown, and the device may include:
[0131] The acquisition module 401 can be used to acquire the virtual OTP key plaintext;
[0132] The encryption module 402 can be used to encrypt the plaintext of the virtual OTP key by using a preset software encryption rule and a preset hardware OTP key to obtain the ciphertext of the virtual OTP key. Among them, the software encryption rules for the plaintext of the virtual OTP key from different sources are different.
[0133] From Figure 4 As can be seen from the above embodiments, the virtual OTP key plaintext can be obtained through the acquisition module 401, and then through the encryption module 402, the plaintext of the virtual OTP key is encrypted by using a preset software encryption rule and a preset hardware OTP key to obtain the ciphertext of the virtual OTP key. Among them, the software encryption rules for the plaintext of the virtual OTP key from different sources are different, so as to encrypt different plaintexts of the virtual OTP key to generate different ciphertexts of the virtual OTP key.
[0134] As a specific implementation manner of the embodiment of the present invention, the encryption module 402 may include:
[0135] The software encryption module can be used to encrypt the plaintext of the virtual OTP key by using a preset software encryption rule to obtain the once-encrypted virtual OTP key;
[0136] The hardware encryption module can be used to encrypt the once-encrypted virtual OTP key by using a preset hardware OTP key to obtain the ciphertext of the virtual OTP key.
[0137] As a specific implementation manner of the embodiment of the present invention, the encryption module 402 may include:
[0138] The hardware encryption module can be used to encrypt the plaintext of the virtual OTP key by using a preset hardware OTP key to obtain the once-encrypted virtual OTP key;
[0139] The software encryption module can be used to encrypt the once-encrypted virtual OTP key by using a preset software encryption rule to obtain the ciphertext of the virtual OTP key.
[0140] Regarding the device in the above embodiments, the specific manners in which each module performs operations have been described in detail in the embodiments related to the method, and will not be elaborated here.
[0141] The embodiment of the present invention also provides an electronic device, Figure 5 is a schematic structural diagram of an electronic device provided by the embodiment of the present invention. As Figure 5 shown, it may include: a processor 501, a communication interface 502, a memory 503, and a communication bus 504. Among them, the processor 501, the communication interface 502, and the memory 503 communicate with each other through the communication bus 504;
[0142] A memory 503 that can be used to store computer programs;
[0143] A processor 501 that can be used to execute the programs stored in the memory to implement any of the above virtual OTP decryption methods.
[0144] An embodiment of the present invention also provides another electronic device. Figure 6 It is a schematic structural diagram of another electronic device provided by an embodiment of the present invention. As Figure 6 shown, it may include: a processor 601, a communication interface 602, a memory 603, and a communication bus 604. Among them, the processor 601, the communication interface 602, and the memory 603 communicate with each other through the communication bus 604;
[0145] A memory 603 that can be used to store computer programs;
[0146] A processor 601 that can be used to execute the programs stored in the memory to implement any of the above virtual OTP key ciphertext generation methods.
[0147] The communication bus mentioned in the above electronic device may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, only a thick line is used in the figure, but it does not mean that there is only one bus or one type of bus.
[0148] The communication interface can be used for communication between the above electronic device and other devices.
[0149] The memory may include a Random Access Memory (RAM), or may also include a Non-Volatile Memory (NVM), such as at least one disk memory. Optionally, the memory may also be at least one storage device located far from the aforementioned processor.
[0150] The above-mentioned processor may be a general-purpose processor, which may include a Central Processing Unit (CPU), a Network Processor (NP), etc.; it may also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.
[0151] In another embodiment provided by the present invention, there is also provided a computer-readable storage medium, in which a computer program is stored, and when the computer program is executed by a processor, the method for decrypting any of the above virtual OTPs is implemented.
[0152] In another embodiment provided by the present invention, there is also provided a computer-readable storage medium, in which a computer program is stored, and when the computer program is executed by a processor, the method for generating the ciphertext of any of the above virtual OTP keys is implemented.
[0153] In another embodiment provided by the present invention, there is also provided a computer program product containing instructions, which when running on a computer, causes the computer to execute the method for decrypting any of the virtual OTPs in the above embodiments.
[0154] In another embodiment provided by the present invention, there is also provided a computer program product containing instructions, which when running on a computer, causes the computer to execute the method for generating the ciphertext of any of the virtual OTP keys in the above embodiments.
[0155] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product may include one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present invention are generated in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.). The computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more integrated available media. The available medium may be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid state disk (SSD)).
[0156] It should be noted that, in this document, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "may include", "include", or any other variant thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or device that may include a series of elements may not only include those elements, but also include other elements not expressly listed, or may also include elements inherent to such process, method, article, or device. Without further limitation, an element defined by the statement "may include a..." does not exclude the existence of additional identical elements in the process, method, article, or device that may include the element.
[0157] Each embodiment in this specification is described in a related manner. For the same or similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the embodiments of the apparatus, electronic device, and storage medium, since they are basically similar to the method embodiments, the description is relatively simple, and reference can be made to the partial description of the method embodiments for the relevant parts.
[0158] The above are only the preferred embodiments of the present invention and are not intended to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention are all included in the protection scope of the present invention.
Claims
1. A method for decrypting virtual OTP, characterized in that, Applied to an electronic device, the electronic device includes a hardware OTP storage area, and a preset hardware OTP key is stored in the hardware OTP storage area. The method includes: When decrypting the data to be decrypted, obtain the first virtual OTP key ciphertext corresponding to the data to be decrypted, and obtain the preset hardware OTP key; different virtual OTP key ciphertexts correspond to data to be decrypted from different sources; Use the preset hardware OTP key and the preset software decryption rule to decrypt the first virtual OTP key ciphertext to obtain the virtual OTP key plaintext, where the software decryption rules for data to be decrypted from different sources are different; Use the virtual OTP key plaintext to decrypt the data to be decrypted to obtain the decrypted data.
2. The method according to claim 1, wherein The step of, when decrypting the data to be decrypted, obtaining the first virtual OTP key ciphertext corresponding to the data to be decrypted, and obtaining the preset hardware OTP key, includes: When decrypting the data to be decrypted, obtain the virtual OTP key ciphertext corresponding to the data to be decrypted in a preset key file to obtain the first virtual OTP key ciphertext, where different virtual OTP key ciphertexts correspond to data to be decrypted from different sources; Obtain the preset hardware OTP key in the preset hardware OTP storage area.
3. The method according to claim 1, characterized in that, The step of using the preset hardware OTP key and the preset software decryption rule to decrypt the first virtual OTP key ciphertext to obtain the virtual OTP key plaintext includes: Use the preset hardware OTP key to decrypt the first virtual OTP key ciphertext to obtain the once-decrypted virtual OTP key; Use the preset software decryption rule to decrypt the once-decrypted virtual OTP key to obtain the virtual OTP key plaintext.
4. The method according to claim 1, wherein The step of using the preset hardware OTP key and the preset software decryption rule to decrypt the first virtual OTP key ciphertext to obtain the virtual OTP key plaintext includes: Use the preset software decryption rule to decrypt the first virtual OTP key ciphertext to obtain the once-decrypted virtual OTP key; Use the preset hardware OTP key to decrypt the once-decrypted virtual OTP key to obtain the virtual OTP key plaintext.
5. A method for generating a virtual OTP key ciphertext, characterized in that, Applied to an electronic device, the electronic device includes a hardware OTP storage area, and a preset hardware OTP key is stored in the hardware OTP storage area. The method includes: Obtain the virtual OTP key plaintext; Use the preset software encryption rule and the preset hardware OTP key to encrypt the virtual OTP key plaintext to obtain the virtual OTP key ciphertext, where the software encryption rules for virtual OTP key plaintexts from different sources are different, and different virtual OTP key ciphertexts correspond to data to be decrypted from different sources.
6. The method according to claim 5, wherein The step of using the preset software encryption rule and the preset hardware OTP key to encrypt the virtual OTP key plaintext to obtain the virtual OTP key ciphertext includes: Use the preset software encryption rule to encrypt the virtual OTP key plaintext to obtain the once-encrypted virtual OTP key; Encrypt the once-encrypted virtual OTP key using a preset hardware OTP key to obtain a ciphertext of the virtual OTP key.
7. The method according to claim 5, characterized in that, The encrypting the plaintext of the virtual OTP key using a preset software encryption rule and a preset hardware OTP key to obtain a ciphertext of the virtual OTP key includes: Encrypt the plaintext of the virtual OTP key using a preset hardware OTP key to obtain a once-encrypted virtual OTP key; Encrypt the once-encrypted virtual OTP key using a preset software encryption rule to obtain a ciphertext of the virtual OTP key.
8. A device for virtual OTP decryption, characterized in that, Applied to an electronic device, the electronic device includes a hardware OTP storage area, and the preset hardware OTP key is stored in the hardware OTP storage area. The device includes: An acquisition module, configured to, when decrypting data to be decrypted, acquire a first ciphertext of the virtual OTP key corresponding to the data to be decrypted, and acquire the preset hardware OTP key; different ciphertexts of the virtual OTP key correspond to data to be decrypted from different sources; A key decryption module, configured to decrypt the first ciphertext of the virtual OTP key using the preset hardware OTP key and a preset software decryption rule to obtain the plaintext of the virtual OTP key, where the software decryption rules for data to be decrypted from different sources are different; A decryption module, configured to decrypt the data to be decrypted using the plaintext of the virtual OTP key to obtain the decrypted data.
9. The device according to claim 8, characterized in that, The acquisition module includes: A ciphertext acquisition module, configured to, when decrypting data to be decrypted, acquire the ciphertext of the virtual OTP key corresponding to the data to be decrypted in a preset key file to obtain a first ciphertext of the virtual OTP key, where different ciphertexts of the virtual OTP key correspond to data to be decrypted from different sources; A hardware key acquisition module, configured to acquire the preset hardware OTP key in the preset hardware OTP storage area.
10. The device according to claim 8, characterized in that, The key decryption module includes: A hardware decryption module, configured to decrypt the first ciphertext of the virtual OTP key using the preset hardware OTP key to obtain a once-decrypted virtual OTP key; A software decryption module, configured to decrypt the once-decrypted virtual OTP key using the preset software decryption rule to obtain the plaintext of the virtual OTP key.
11. The device according to claim 8, characterized in that, The key decryption module includes: A software decryption module, configured to decrypt the first ciphertext of the virtual OTP key using the preset software decryption rule to obtain a once-decrypted virtual OTP key; A hardware decryption module, configured to decrypt the once-decrypted virtual OTP key using the preset hardware OTP key to obtain the plaintext of the virtual OTP key.
12. A virtual OTP key ciphertext generation device, characterized in that, Applied to an electronic device, the electronic device includes a hardware OTP storage area, and the preset hardware OTP key is stored in the hardware OTP storage area. The device includes: An acquisition module, configured to acquire the plaintext of the virtual OTP key; An encryption module, which is used to encrypt the plaintext of the virtual OTP key by using a preset software encryption rule and a preset hardware OTP key to obtain the ciphertext of the virtual OTP key. Among them, the software encryption rules for the plaintext of the virtual OTP key from different sources are different, and different ciphertexts of the virtual OTP key correspond to the data to be decrypted from different sources.
13. The device according to claim 12, wherein The encryption module includes: A software encryption module, which is used to encrypt the plaintext of the virtual OTP key by using a preset software encryption rule to obtain the virtual OTP key after the first encryption; A hardware encryption module, which is used to encrypt the virtual OTP key after the first encryption by using a preset hardware OTP key to obtain the ciphertext of the virtual OTP key.
14. The device according to claim 12, characterized in that, The encryption module includes: A hardware encryption module, which is used to encrypt the plaintext of the virtual OTP key by using a preset hardware OTP key to obtain the virtual OTP key after the first encryption; A software encryption module, which is used to encrypt the virtual OTP key after the first encryption by using a preset software encryption rule to obtain the ciphertext of the virtual OTP key.
15. An electronic device, characterized in that, It includes a processor, a communication interface, a memory, and a communication bus. Among them, the processor, the communication interface, and the memory complete communication with each other through the communication bus; The memory is used to store computer programs; The processor, when executing the program stored on the memory, implements the method steps described in any one of claims 1-7.
16. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, and when the computer program is executed by the processor, it implements the method steps described in any one of claims 1-7.
Citation Information
Patent Citations
Virtual magnetic disk file protecting method, device and equipment and readable storage medium
CN108133144A
Data decryption method
CN113452654A