Information encryption method, device, storage medium and computer equipment
By encrypting the encrypted information with a preset encryption algorithm, the first ciphertext and timestamp are encrypted again, and sent to the server to generate the second secret key. The client finally uses the second secret key to encrypt the first ciphertext, solving the problem of low encryption efficiency caused by the long secret key of the international general cipher algorithm, and improving the efficiency and security of information encryption.
Patent Information
- Application Number
- CN202210974598.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-15
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2042-08-15
AI Technical Summary
In the prior art, the 1024-bit international general cryptographic algorithm has the risk of being attacked. The long secret key leads to slow transmission speed, which leads to low encryption efficiency.
By obtaining the information to be encrypted and its corresponding timestamp, encrypting the information to be encrypted using the first secret key in the preset encryption algorithm, obtaining the first ciphertext, and encrypting the first ciphertext and the timestamp to obtain the second ciphertext and the third ciphertext. The second ciphertext and the third ciphertext are sent to the server, the server generates the second key and returns to the client. The client uses the second key to encrypt the first ciphertext and obtains the fourth ciphertext.
It avoids the problem of slow transmission speed caused by excessive secret keys in international general encryption algorithms, improves the efficiency of information encryption, and ensures the security of information through multiple encryption methods, avoids the risk of leakage of information to be encrypted during transmission.
Smart Images

Figure CN115314313B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information technology, and in particular to an information encryption method, device, storage medium and computer equipment. Background Art
[0002] Among different types of personal privacy information, the protection of account identification information is particularly important. For example, once the website or APP login password is cracked, sensitive information in the account such as name, email address, ID number, biometric information, etc. will be leaked. Even more sensitive is the personal payment account password. Once leaked, lost or unauthorized, it will seriously endanger the property safety of the account holder. Therefore, the protection of personal passwords is the top priority of personal information protection.
[0003] At present, international general cryptographic algorithms are usually used to encrypt information. However, the current 1024-bit international general cryptographic algorithm has been proven to be at risk of being attacked, and must be upgraded to 2048 bits to ensure algorithm security. The 2048-bit international general cryptographic algorithm has a longer key, which results in a slower transmission speed of the key when using the algorithm for encryption, which in turn leads to lower encryption efficiency for information. Summary of the invention
[0004] The present invention provides an information encryption method, device, storage medium and computer equipment, which are mainly capable of improving the encryption efficiency of information.
[0005] According to a first aspect of the present invention, there is provided an information encryption method, comprising:
[0006] Obtain the information to be encrypted and its corresponding timestamp;
[0007] Encrypting the information to be encrypted using a first secret key in a preset encryption algorithm to obtain a first ciphertext corresponding to the information to be encrypted;
[0008] Encrypting the first ciphertext and the timestamp to obtain a second ciphertext and a third ciphertext corresponding to the information to be encrypted;
[0009] Sending the second ciphertext and the third ciphertext to the server, and obtaining a second secret key corresponding to the information to be encrypted, generated by the server based on the second ciphertext and the third ciphertext;
[0010] The first ciphertext is encrypted using the second secret key to obtain a fourth ciphertext corresponding to the information to be encrypted as an encryption result corresponding to the information to be encrypted.
[0011] According to a second aspect of the present invention, another information encryption method is provided, comprising:
[0012] Receive the second ciphertext and the third ciphertext sent by the client;
[0013] Decrypting the second ciphertext and the third ciphertext to obtain a first ciphertext and a timestamp corresponding to the information to be encrypted;
[0014] Based on the first ciphertext and the timestamp, a second key corresponding to the information to be encrypted is generated, and the second key is sent to the client, so that the client uses the second key to encrypt the first ciphertext corresponding to the information to be encrypted to obtain a fourth ciphertext corresponding to the information to be encrypted.
[0015] According to a third aspect of the present invention, there is provided an information encryption device, comprising:
[0016] An acquisition unit, used for acquiring information to be encrypted and its corresponding timestamp;
[0017] A first encryption unit, used to encrypt the information to be encrypted using a first secret key in a preset encryption algorithm to obtain a first ciphertext corresponding to the information to be encrypted;
[0018] A second encryption unit is used to encrypt the first ciphertext and the timestamp to obtain a second ciphertext and a third ciphertext corresponding to the information to be encrypted;
[0019] A sending unit, configured to send the second ciphertext and the third ciphertext to a server, and obtain a second secret key corresponding to the information to be encrypted, generated by the server based on the second ciphertext and the third ciphertext;
[0020] The third encryption unit is used to encrypt the first ciphertext by using the second secret key to obtain a fourth ciphertext corresponding to the information to be encrypted as an encryption result corresponding to the information to be encrypted.
[0021] According to a fourth aspect of the present invention, another information encryption device is provided, comprising:
[0022] A receiving unit, used for receiving a second ciphertext and a third ciphertext sent by a client;
[0023] A decryption unit, configured to decrypt the second ciphertext and the third ciphertext to obtain a first ciphertext and a timestamp corresponding to the information to be encrypted;
[0024] A generating unit is used to generate a second key corresponding to the information to be encrypted based on the first ciphertext and the timestamp, and send the second key to the client, so that the client uses the second key to encrypt the first ciphertext corresponding to the information to be encrypted to obtain a fourth ciphertext corresponding to the information to be encrypted.
[0025] According to a fifth aspect of the present invention, there is provided a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the following steps:
[0026] Obtain the information to be encrypted and its corresponding timestamp;
[0027] Encrypting the information to be encrypted using a first secret key in a preset encryption algorithm to obtain a first ciphertext corresponding to the information to be encrypted;
[0028] Encrypting the first ciphertext and the timestamp to obtain a second ciphertext and a third ciphertext corresponding to the information to be encrypted;
[0029] Sending the second ciphertext and the third ciphertext to the server, and obtaining a second secret key corresponding to the information to be encrypted, generated by the server based on the second ciphertext and the third ciphertext;
[0030] The first ciphertext is encrypted using the second secret key to obtain a fourth ciphertext corresponding to the information to be encrypted as an encryption result corresponding to the information to be encrypted.
[0031] According to a sixth aspect of the present invention, there is provided a computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the following steps are implemented:
[0032] Obtain the information to be encrypted and its corresponding timestamp;
[0033] Encrypting the information to be encrypted using a first secret key in a preset encryption algorithm to obtain a first ciphertext corresponding to the information to be encrypted;
[0034] Encrypting the first ciphertext and the timestamp to obtain a second ciphertext and a third ciphertext corresponding to the information to be encrypted;
[0035] Sending the second ciphertext and the third ciphertext to the server, and obtaining a second secret key corresponding to the information to be encrypted, generated by the server based on the second ciphertext and the third ciphertext;
[0036] The first ciphertext is encrypted using the second secret key to obtain a fourth ciphertext corresponding to the information to be encrypted as an encryption result corresponding to the information to be encrypted.
[0037] According to a seventh aspect of the present invention, another computer-readable storage medium is provided, on which a computer program is stored, and when the program is executed by a processor, the following steps are implemented:
[0038] Receive the second ciphertext and the third ciphertext sent by the client;
[0039] Decrypting the second ciphertext and the third ciphertext to obtain a first ciphertext and a timestamp;
[0040] Based on the first ciphertext and the timestamp, a second key corresponding to the information to be encrypted is generated, and the second key is sent to the client, so that the client uses the second key to encrypt the first ciphertext corresponding to the information to be encrypted to obtain a fourth ciphertext corresponding to the information to be encrypted.
[0041] According to an eighth aspect of the present invention, another computer device is provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the following steps are implemented:
[0042] Receive the second ciphertext and the third ciphertext sent by the client;
[0043] Decrypting the second ciphertext and the third ciphertext to obtain a first ciphertext and a timestamp;
[0044] Based on the first ciphertext and the timestamp, a second key corresponding to the information to be encrypted is generated, and the second key is sent to the client, so that the client uses the second key to encrypt the first ciphertext corresponding to the information to be encrypted to obtain a fourth ciphertext corresponding to the information to be encrypted.
[0045] According to an information encryption method, device, storage medium and computer equipment provided by the present invention, compared with the method of encrypting and protecting information using an international general cryptographic algorithm, the present invention obtains information to be encrypted and its corresponding timestamp; and uses a first secret key in a preset encryption algorithm to encrypt the information to be encrypted to obtain a first ciphertext corresponding to the information to be encrypted; at the same time, the first ciphertext and the timestamp are encrypted to obtain a second ciphertext and a third ciphertext corresponding to the information to be encrypted; then the second ciphertext and the third ciphertext are sent to a server, and a second secret key corresponding to the information to be encrypted generated by the server based on the second ciphertext and the third ciphertext is obtained; finally, the first ciphertext is encrypted using the second secret key to obtain a fourth ciphertext corresponding to the information to be encrypted, which is used as the encryption result corresponding to the information to be encrypted The result is that the first secret key in the preset encryption algorithm is used to encrypt the information to be encrypted to obtain the first ciphertext, and the first ciphertext and the timestamp are encrypted again to obtain the second ciphertext and the third ciphertext, and the second ciphertext and the third ciphertext are transmitted to the server, so that the server generates a second secret key based on the second ciphertext and the third ciphertext. Finally, the client uses the second secret key to encrypt the first ciphertext to obtain the fourth ciphertext as the final encryption result. Encrypting the information to be encrypted by the preset encryption algorithm can avoid the problem of slow transmission caused by the long secret key in the international general encryption algorithm, thereby improving the efficiency of information encryption. At the same time, by performing multiple encryptions on the encrypted information and transmitting it from the client to the server in multiple ciphertexts, the risk of leakage of the encrypted information in the process of transmitting it from the client to the server is avoided, thereby ensuring the security of the information. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of this application. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:
[0047] Figure 1 A flow chart of an information encryption method provided by an embodiment of the present invention is shown;
[0048] Figure 2 A schematic diagram of the structure of an information encryption device provided by an embodiment of the present invention is shown;
[0049] Figure 3 A schematic diagram showing the structure of another information encryption device provided by an embodiment of the present invention is shown;
[0050] Figure 4 A schematic diagram of the physical structure of a computer device provided by an embodiment of the present invention is shown;
[0051] Figure 5A schematic diagram of the physical structure of another computer device provided by an embodiment of the present invention is shown. DETAILED DESCRIPTION
[0052] The present invention will be described in detail below with reference to the accompanying drawings and in combination with embodiments. It should be noted that the embodiments and features in the embodiments of the present application can be combined with each other without conflict.
[0053] At present, the method of encrypting and protecting information using internationally accepted cryptographic algorithms has a low encryption efficiency due to the slow transmission speed of the secret key when encrypting using this algorithm.
[0054] In order to solve the above problems, the embodiment of the present invention provides an information encryption method, such as Figure 1 As shown, the method includes:
[0055] 101. Obtain information to be encrypted and its corresponding timestamp.
[0056] The information to be encrypted may be password information or information in the medical field, such as personal health record information or medical insurance information, and the timestamp is the time when the encryption instruction starts.
[0057] For the embodiment of the present invention, in order to overcome the problem of low efficiency of information encryption in the prior art, the embodiment of the present invention encrypts the information to be encrypted by using the first key in the preset encryption algorithm to obtain the first ciphertext. At the same time, in order to avoid the risk of information leakage caused by the first ciphertext during transmission, it is also necessary to encrypt the first ciphertext and the timestamp to obtain the second ciphertext and the third ciphertext, and transmit the second ciphertext and the third ciphertext to the server, so that the server generates a second key based on the second ciphertext and the third ciphertext, and transmits the second key to the client. The client encrypts the first ciphertext with the second key to obtain a fourth ciphertext as the final encryption result. The embodiment of the present invention uses the preset encryption algorithm to encrypt the information to be encrypted, which can avoid the problem of too long keys in the international general encryption algorithm, resulting in slow key transmission, thereby improving the efficiency of information encryption. At the same time, the embodiment of the present invention encrypts the first ciphertext again to avoid the risk of leakage in the process of transmitting the first ciphertext from the client to the server, thereby ensuring the security of the information. The embodiments of the present invention are mainly applied to the scenario of encrypting information. The execution subject of the embodiments of the present invention is a device or equipment capable of encrypting information, which can be specifically set on the client side or the server side.
[0058] Specifically, if the information to be encrypted is password information, then when the user enters the account number and password in the client, the information to be encrypted can be obtained, and at the same time, the identification information corresponding to the information to be encrypted can be obtained. The identification information can be the account number corresponding to the password, which is used to store corresponding to the encrypted information. At the same time, the password input time is determined as the time recorded in the timestamp, and then the information to be encrypted is encrypted using the first secret key to obtain the first ciphertext.
[0059] For example, if the information to be encrypted is medical insurance information, the medical insurance information is obtained from the hospital's database, and the medical insurance information is transmitted to the encryption software, and the encryption instruction in the encryption software is triggered. At this time, the timestamp corresponding to the information to be encrypted can be obtained, wherein the time recorded in the timestamp is the time when the encryption instruction is triggered. After that, the client automatically generates a first secret key and uses the first secret key to encrypt the medical insurance information.
[0060] 102. Encrypt the information to be encrypted using a first secret key in a preset encryption algorithm to obtain a first ciphertext corresponding to the information to be encrypted.
[0061] Among them, the preset encryption algorithm can specifically be a domestic commercial encryption algorithm, wherein the domestic commercial encryption algorithm includes a national secret symmetric encryption algorithm SM4, an asymmetric encryption algorithm SM2, and a digest calculation algorithm SM3. The secret key in the domestic commercial encryption algorithm is shorter, and thus the transmission speed in the encryption process is faster, thereby improving the efficiency of information encryption. For the embodiment of the present invention, a security password control is pre-installed in the client, and the security password plug-in can be a plug-in certified by a domestic commercial encryption product. After the client obtains the information to be encrypted, the client adopts a security password control certified by a domestic commercial encryption product, and uses the national secret SM generated by a hardware encryption and decryption device (HSM) 2 The public key pub1 in the asymmetric key pair, i.e., the first secret key, is used to encrypt the personal password information in plain text to obtain password1, i.e., the first ciphertext, and the first ciphertext and the timestamp are encrypted again to obtain the second ciphertext and the third ciphertext, and the information to be encrypted and the timestamp are transmitted to the server in the form of the second ciphertext and the third ciphertext to obtain the second secret key, and finally the first ciphertext is encrypted with the second secret key to obtain the fourth ciphertext, avoiding the risk of information leakage in the process of transmitting the first ciphertext to the server, thereby ensuring the security of information transmission, and then ensuring the security of the information to be encrypted. At the same time, the use of domestic encryption algorithms can improve the efficiency of information encryption.
[0062] 103. Encrypt the first ciphertext and the timestamp to obtain a second ciphertext and a third ciphertext corresponding to the information to be encrypted.
[0063] For the embodiment of the present invention, in order to ensure the security of the first ciphertext and timestamp during transmission, before transmitting the first ciphertext and timestamp to the server, the first ciphertext and timestamp need to be encrypted again to obtain a second ciphertext and a third ciphertext. Based on this, step 103 specifically includes: randomly generating a third key, an initialization vector and a fourth key based on the first ciphertext and the timestamp, and sending the private key corresponding to the fourth key to the server; concatenating the first ciphertext and the timestamp to obtain a first data string; encrypting the first data string using the third key and the initialization vector to obtain a second ciphertext corresponding to the information to be encrypted; encrypting the third key and the initialization vector using the fourth key to obtain a third ciphertext. The fourth key can be a key generated by negotiation between the client and the server, or a key randomly generated by the client based on the first ciphertext and the timestamp. The timestamp exists in the form of a character string.
[0064] Among them, the third secret key and the initialization vector are strings of length 32, wherein the initialization vector is used to participate in the calculation as a salt value component in the SM4-CBC algorithm, which can improve the security of data encryption. Specifically, the client uses the standard random number generation function that comes with the js or java code library to randomly generate two strings of length 32, which can be used as the third secret key key and the initialization vector iv. At the same time, the client and the server negotiate to generate a fourth secret key, wherein the fourth secret key can be the public key pub2 in the national secret SM2 asymmetric key pair. After that, the first ciphertext and the timestamp are concatenated to obtain a first data string. In order to improve the security of information transmission, the first data string needs to be encrypted using the third secret key and the initialization vector to obtain a second ciphertext. Based on this, the method includes: concatenating the initialization vector with the first data string to obtain a second data string; encrypting the second data string using the third secret key to obtain a second ciphertext corresponding to the information to be encrypted.
[0065] Specifically, the embodiment of the present invention can use the standard SM4-CBC algorithm. The SM4-CBC algorithm is implemented by the Android client code by referencing the bcprov general jar package. key is used as the third key, iv is used as the input initialization amount, the input initialization vector and the first data string are concatenated to obtain the second data string, and the second data string is encrypted using the third key to obtain the second ciphertext corresponding to the information to be encrypted, and then the third key and the initialization vector are encrypted using the fourth key negotiated with the server. Specifically, the public key pub2 in another pair of national secret SM2 asymmetric key pair can be used as the fourth key, and the fourth key is used to encrypt the initialization vector and the third key. The second ciphertext and the third ciphertext are concatenated to obtain a third data string, and the third data string is transmitted to the server. The server decrypts the second ciphertext and the third ciphertext in the third data string respectively to obtain the first ciphertext and the timestamp, and randomly generates a second key based on the first ciphertext and the timestamp, and transmits the second key to the client. The client finally encrypts the first ciphertext with the second key to obtain a fourth ciphertext, and then transmits the fourth ciphertext to the server for storage. Therefore, before the information to be encrypted is transmitted to the server for storage, the security of the information to be encrypted during transmission can be ensured by performing multiple encryption processes in different ways on the information to be encrypted.
[0066] 104. Send the second ciphertext and the third ciphertext to the server.
[0067] For the embodiment of the present invention, after the client encrypts the information to be encrypted to obtain the first ciphertext, it is also necessary to use the secret key randomly generated by the client to encrypt the first ciphertext and the timestamp to obtain the second ciphertext and the third ciphertext, and send the second ciphertext and the third ciphertext to the server. The timestamp is used by the server to verify the timeout period. If the verification is successful, the server generates a second secret key corresponding to the information to be encrypted, and returns the second secret key to the client. The client uses the second secret key to encrypt the first ciphertext to obtain the second ciphertext, thereby encrypting the information to be encrypted for the first time at the client to obtain the first ciphertext. In order to avoid the first ciphertext and the timestamp being encrypted at the server, There is a risk of leakage during the transmission process, and the first ciphertext and timestamp need to be encrypted again to obtain the second ciphertext and the third ciphertext, and finally the first ciphertext is transmitted to the server in the form of the second ciphertext and the third ciphertext. After the server obtains the second ciphertext and the third ciphertext, it decrypts them to obtain the first ciphertext and the timestamp, and generates a second key corresponding to the information to be encrypted based on the first ciphertext and the timestamp, and transmits the second key to the client. The client uses the second key to encrypt the first ciphertext to obtain the fourth ciphertext. Finally, the client transmits the fourth ciphertext to the server for storage. By double encrypting the information to be encrypted, the security of the information can be improved.
[0068] 105. Receive the second ciphertext and the third ciphertext sent by the client.
[0069] Specifically, the client transmits the second ciphertext and the third ciphertext corresponding to the information to be encrypted and the timestamp to the server. At the same time, the client also transmits the private key corresponding to the fourth key to the server, so that the server can decrypt the second ciphertext and the third ciphertext. At this time, the server can receive the second ciphertext and the third ciphertext corresponding to the information to be encrypted and the timestamp sent by the client and the private key corresponding to the fourth key.
[0070] 106. Decrypt the second ciphertext and the third ciphertext to obtain a first ciphertext and a timestamp corresponding to the information to be encrypted.
[0071] For the embodiment of the present invention, after receiving the second ciphertext and the third ciphertext, the server needs to decrypt the second ciphertext and the third ciphertext. Based on this, step 202 specifically includes: receiving the private key corresponding to the fourth key sent by the client, and using the private key to decrypt the third ciphertext to obtain the third key and the initialization vector; using the third key and the initialization vector to decrypt the second ciphertext to obtain a first data string spliced by the first ciphertext and the timestamp, and splitting the first ciphertext and the timestamp in the first data string.
[0072] Specifically, the server uses the private key corresponding to the fourth key sent by the client to decrypt the third ciphertext to obtain the third key and the initialization vector, and then uses the third key and the initialization vector to symmetrically decrypt the second ciphertext to obtain the first data string, and splits out the timestamp timestamp and the first ciphertext password1 in the first data string, and uses the timestamp to verify the timeout time. If the verification passes, the server automatically generates a second key corresponding to the first ciphertext, and sends the second key to the client, so that the client uses the second key to encrypt the first ciphertext to obtain the fourth ciphertext, which is the final encryption result of the information to be encrypted.
[0073] 107. Generate a second secret key corresponding to the information to be encrypted based on the first ciphertext and the timestamp.
[0074] For the embodiment of the present invention, the timestamp is used to verify the timeout time, and the specific verification method is: determine whether the time difference between the current system time and the time in the timestamp is less than the preset time difference; if the time difference is less than the preset time difference, then based on the first ciphertext, generate a second secret key corresponding to the information to be encrypted; if the time difference is greater than or equal to the preset time difference, then generate an alarm message prohibiting encryption, and send the alarm message to the client.
[0075] Among them, the current system time is the time displayed in the current server, and the preset time difference is determined according to the previous encryption time. Specifically, the time recorded in the timestamp is obtained, and the current system time is subtracted from the time recorded in the timestamp to obtain the time difference, and it is determined whether the time difference is less than the preset time difference. If the time difference is less than the preset time difference, it is determined that the time of information encryption is within the specified range. At this time, the server automatically generates the second key corresponding to the information to be encrypted, and sends the second key to the client, so that the client uses the second key to encrypt the first ciphertext to obtain the final encryption result. If the time difference between the current system time and the time recorded in the timestamp is greater than or equal to the preset time difference, it is determined that the encryption time exceeds the preset time, and the generation of the second key corresponding to the information to be encrypted is prohibited, and an alarm message is generated, and the alarm message is sent to the client. After receiving the alarm message, the client performs identity recognition on the user of the client. If the recognition is passed, the information is encrypted again.
[0076] 108. Send the second secret key to the client.
[0077] 109. Use the second secret key to encrypt the first ciphertext to obtain a fourth ciphertext corresponding to the information to be encrypted as an encryption result corresponding to the information to be encrypted.
[0078] For the embodiment of the present invention, after the client double-encrypts the information to be encrypted and obtains the second ciphertext and the third ciphertext, the client transmits the second ciphertext and the third ciphertext together to the server. The server decrypts the first ciphertext and the timestamp from the second ciphertext and the third ciphertext. The timestamp is used to verify the timeout period to prevent the ciphertext from being attacked by long-term replay. If the verification is successful, the server calls the hardware encryption and decryption device (HSM) to generate the symmetric key ZPK of SM4 inside the encryption machine, that is, the second key, and transmits the second key to the client. Finally, the client uses the second key sent by the server to encrypt the first ciphertext to obtain the fourth key as the final encryption result of the encrypted information. After the client encrypts the encrypted information to obtain the fourth ciphertext, it can transmit the fourth ciphertext to the server for storage. Thus, the first ciphertext is obtained by encrypting the information to be encrypted with the first key, and the first ciphertext and the timestamp are encrypted again to obtain the second ciphertext and the third ciphertext, and the second ciphertext and the third ciphertext are transmitted to the server, so that the server generates the second key based on the second ciphertext and the third ciphertext, and transmits the second key to the client, and the client encrypts the first ciphertext with the second key to obtain the fourth ciphertext as the final encryption result, thereby avoiding the risk of leakage of the first ciphertext and the timestamp in the process of being transmitted from the client to the server, thereby ensuring the security of the information. At the same time, the embodiment of the present invention realizes the encryption of private information at the front end and the transmission of the full ciphertext of the intermediate system to the back end through the matching use of the client security password control and the hardware encryption and decryption device (HSM), thereby ensuring that no private information appears in plain text in the entire link within the entire application system, thereby improving the security of the private information. At the same time, the embodiment of the present invention uses the domestic encryption algorithm to improve the efficiency of information encryption.
[0079] According to an information encryption method provided by the present invention, compared with the current method of transmitting plain text from the client to the server for encryption, the embodiment of the present invention obtains the information to be encrypted and its corresponding timestamp; and uses the first secret key in the preset encryption algorithm to encrypt the information to be encrypted to obtain the first ciphertext corresponding to the information to be encrypted; at the same time, the first ciphertext and the timestamp are encrypted to obtain the second ciphertext and the third ciphertext corresponding to the information to be encrypted; then the second ciphertext and the third ciphertext are sent to the server, and the second secret key corresponding to the information to be encrypted generated by the server based on the second ciphertext and the third ciphertext is obtained; finally, the first ciphertext is encrypted with the second secret key to obtain the fourth ciphertext corresponding to the information to be encrypted as the encryption result corresponding to the information to be encrypted, thereby The first ciphertext is obtained by encrypting the information to be encrypted with the first key in the preset encryption algorithm, and the first ciphertext and the timestamp are encrypted again to obtain the second ciphertext and the third ciphertext, and the second ciphertext and the third ciphertext are transmitted to the server, so that the server generates a second key based on the second ciphertext and the third ciphertext. Finally, the client encrypts the first ciphertext with the second key to obtain the fourth ciphertext as the final encryption result. Encrypting the information to be encrypted with the preset encryption algorithm can avoid the problem of slow transmission caused by the long key in the international general encryption algorithm, thereby improving the efficiency of information encryption. At the same time, by performing multiple encryption on the encrypted information and transmitting it from the client to the server in ciphertext, the risk of leakage of the encrypted information in the process of transmitting the encrypted information from the client to the server is avoided, thereby ensuring the security of the information.
[0080] Further, as Figure 1 The specific implementation of the present invention provides an information encryption device, such as Figure 2 As shown, the device includes: an acquisition unit 31, a first encryption unit 32, a second encryption unit 33, a sending unit 34 and a third encryption unit 35.
[0081] The acquisition unit 31 may be used to acquire the information to be encrypted and its corresponding timestamp.
[0082] The first encryption unit 32 may be configured to encrypt the information to be encrypted using a first secret key in a preset encryption algorithm to obtain a first ciphertext corresponding to the information to be encrypted.
[0083] The second encryption unit 33 may be configured to encrypt the first ciphertext and the timestamp to obtain a second ciphertext and a third ciphertext corresponding to the information to be encrypted.
[0084] The sending unit 34 may be configured to send the second ciphertext and the third ciphertext to the server, and obtain a second secret key corresponding to the information to be encrypted, which is generated by the server based on the second ciphertext and the third ciphertext.
[0085] The third encryption unit 35 may be configured to encrypt the first ciphertext using the second secret key to obtain a second ciphertext corresponding to the information to be encrypted as an encryption result corresponding to the information to be encrypted.
[0086] In a specific application scenario, in order to encrypt the first ciphertext and the timestamp, the second encryption unit 33 includes a generation module 331 , a splicing module 332 , and an encryption module 333 .
[0087] The generation module 331 can be used to randomly generate a third key, an initialization vector and a fourth key based on the first ciphertext and the timestamp, and send the private key corresponding to the fourth key to the server.
[0088] The concatenation module 332 may be used to concatenate the first ciphertext and the timestamp to obtain a first data string.
[0089] The encryption module 333 may be configured to encrypt the first data string using the third secret key and the initialization vector to obtain a second ciphertext corresponding to the information to be encrypted.
[0090] The encryption module 333 may also be configured to encrypt the third key and the initialization vector using a fourth key to obtain a third ciphertext.
[0091] In a specific application scenario, in order to determine the second ciphertext corresponding to the information to be encrypted, the encryption module 333 includes a splicing submodule and an encryption submodule.
[0092] The concatenation submodule may be used to concatenate the initialization vector with the first data string to obtain a second data string.
[0093] The encryption submodule can be used to encrypt the second data string using the third secret key to obtain a second ciphertext corresponding to the information to be encrypted.
[0094] It should be noted that for other corresponding descriptions of the functional modules involved in the information encryption device provided in the embodiment of the present invention, reference can be made to Figure 1 The corresponding description of the method shown will not be repeated here.
[0095] Based on the above Figure 1The method shown, accordingly, an embodiment of the present invention also provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, the following steps are implemented: obtaining information to be encrypted and its corresponding timestamp; encrypting the information to be encrypted using a first secret key in a preset encryption algorithm to obtain a first ciphertext corresponding to the information to be encrypted; encrypting the first ciphertext and the timestamp to obtain a second ciphertext and a third ciphertext corresponding to the information to be encrypted; sending the second ciphertext and the third ciphertext to a server, and obtaining a second secret key corresponding to the information to be encrypted generated by the server based on the second ciphertext and the third ciphertext; encrypting the first ciphertext using the second secret key to obtain a fourth ciphertext corresponding to the information to be encrypted as the encryption result corresponding to the information to be encrypted.
[0096] Based on the above Figure 1 The method shown and Figure 2 The embodiment of the device shown in the figure, the embodiment of the present invention also provides a physical structure diagram of a computer device, such as Figure 4 As shown, the computer device includes: a processor 41, a memory 42, and a computer program stored in the memory 42 and executable on the processor, wherein the memory 42 and the processor 41 are both arranged on a bus 43, and the processor 41 implements the following steps when executing the program: obtaining information to be encrypted and its corresponding timestamp; encrypting the information to be encrypted using a first key in a preset encryption algorithm to obtain a first ciphertext corresponding to the information to be encrypted; encrypting the first ciphertext and the timestamp to obtain a second ciphertext and a third ciphertext corresponding to the information to be encrypted; sending the second ciphertext and the third ciphertext to a server, and obtaining a second key corresponding to the information to be encrypted generated by the server based on the second ciphertext and the third ciphertext; encrypting the first ciphertext using the second key to obtain a fourth ciphertext corresponding to the information to be encrypted as an encryption result corresponding to the information to be encrypted.
[0097] Further, as Figure 1 The specific implementation of the present invention provides another information encryption device, such as Figure 3 As shown, the device includes: a receiving unit 51, a decryption unit 52 and a generating unit 53.
[0098] The receiving unit 51 may be configured to receive the second ciphertext and the third ciphertext sent by the client.
[0099] The decryption unit 52 may be used to decrypt the second ciphertext and the third ciphertext to obtain a first ciphertext and a timestamp.
[0100] The generating unit 53 can be used to generate a second key corresponding to the information to be encrypted based on the first ciphertext and the timestamp, and send the second key to the client, so that the client uses the second key to encrypt the first ciphertext corresponding to the information to be encrypted to obtain a fourth ciphertext corresponding to the information to be encrypted.
[0101] In a specific application scenario, in order to decrypt the second ciphertext and the third ciphertext to obtain the first ciphertext and the timestamp, the decryption unit 52 includes a decryption module 521 and a splitting module 522 .
[0102] The decryption module 521 may be configured to receive a private key corresponding to a fourth key sent by a client, and use the private key to decrypt the third ciphertext to obtain a third key and an initialization vector.
[0103] The splitting module 522 can be used to decrypt the second ciphertext using the third secret key and the initialization vector to obtain a first data string composed of the first ciphertext and the timestamp, and split the first ciphertext and the timestamp in the first data string.
[0104] In a specific application scenario, in order to generate the second secret key corresponding to the information to be encrypted based on the first ciphertext and the timestamp in the first data string, the generating unit 53 includes a determining module 531 and a generating module 532 .
[0105] The determination module 531 may be used to determine whether the time difference between the current system time and the time in the timestamp is less than a preset time difference.
[0106] The generating module 532 may be configured to generate a second secret key corresponding to the information to be encrypted based on the first ciphertext if the time difference is less than the preset time difference.
[0107] The generating module 532 may also be configured to generate an encryption-prohibiting warning message if the time difference is greater than or equal to the preset time difference, and send the warning message to the client.
[0108] It should be noted that for other corresponding descriptions of various functional modules involved in a server provided in an embodiment of the present invention, reference can be made to Figure 1 The corresponding description of the method shown will not be repeated here.
[0109] Based on the above Figure 1The method shown, accordingly, an embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, the following steps are implemented: receiving a second ciphertext and a third ciphertext sent by a client; decrypting the second ciphertext and the third ciphertext to obtain a first ciphertext and a timestamp corresponding to the information to be encrypted; based on the first ciphertext and the timestamp, generating a second secret key corresponding to the information to be encrypted, and sending the second secret key to the client, so that the client uses the second secret key to encrypt the first ciphertext corresponding to the information to be encrypted, and obtains a fourth ciphertext corresponding to the information to be encrypted.
[0110] Based on the above Figure 1 The method shown and Figure 3 The embodiment of the device shown in the figure, the embodiment of the present invention also provides a physical structure diagram of a computer device, such as Figure 5 As shown, the computer device includes: a processor 61, a memory 62, and a computer program stored in the memory 62 and executable on the processor, wherein the memory 62 and the processor 61 are both arranged on a bus 63, and when the processor 61 executes the program, the following steps are implemented: receiving a second ciphertext and a third ciphertext sent by a client; decrypting the second ciphertext and the third ciphertext to obtain a first ciphertext and a timestamp corresponding to the information to be encrypted; generating a second secret key corresponding to the information to be encrypted based on the first ciphertext and the timestamp, and sending the second secret key to the client, so that the client uses the second secret key to encrypt the first ciphertext corresponding to the information to be encrypted, and obtains a fourth ciphertext corresponding to the information to be encrypted.
[0111] According to the technical solution of the present invention, the present invention obtains information to be encrypted and its corresponding identification information and timestamp; encrypts the information to be encrypted using a first key in a preset encryption algorithm to obtain a first ciphertext corresponding to the information to be encrypted; and encrypts the first ciphertext and the timestamp to obtain a second ciphertext and a third ciphertext, and sends the second ciphertext and the third ciphertext to a server. When the server receives the second ciphertext and the third ciphertext, it decrypts the second ciphertext and the third ciphertext to obtain a first ciphertext and a timestamp, and based on the first ciphertext and the timestamp, generates a second key corresponding to the information to be encrypted, and sends the second key to a client. The client encrypts the first ciphertext using the second key to obtain a fourth ciphertext, which is the final encryption result of the information to be encrypted. Thus, the information to be encrypted is encrypted by a preset encryption algorithm, which can avoid the problem of slow transmission caused by too long a key in an international general encryption algorithm, thereby improving the efficiency of information encryption. At the same time, by performing multiple encryption on the information to be encrypted and transmitting it from the client to the server in a ciphertext manner, the risk of leakage of the information to be encrypted from the client to the server is avoided, thereby ensuring the security of the information.
[0112] Obviously, those skilled in the art should understand that the above modules or steps of the present invention can be implemented by a general computing device, they can be concentrated on a single computing device, or distributed on a network composed of multiple computing devices, and optionally, they can be implemented by a program code executable by a computing device, so that they can be stored in a storage device and executed by the computing device, and in some cases, the steps shown or described can be executed in a different order than here, or they can be made into individual integrated circuit modules, or multiple modules or steps therein can be made into a single integrated circuit module for implementation. Thus, the present invention is not limited to any specific combination of hardware and software.
[0113] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. For those skilled in the art, the present invention may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A method for encrypting information, It is characterized in that Applied to the client, including: Obtain the information to be encrypted and its corresponding timestamp; Encrypting the information to be encrypted using a first secret key in a preset encryption algorithm to obtain a first ciphertext corresponding to the information to be encrypted; Randomly generate a third secret key and an initialization vector, concatenate the first ciphertext and the timestamp into a first data string, encrypt the first data string to obtain a second ciphertext, and encrypt the third secret key and the initialization vector to obtain a third ciphertext; Sending the second ciphertext and the third ciphertext to the server, and obtaining a second secret key corresponding to the information to be encrypted, generated by the server based on the second ciphertext and the third ciphertext; The first ciphertext is encrypted using the second secret key to obtain a fourth ciphertext corresponding to the information to be encrypted as an encryption result corresponding to the information to be encrypted.
2. The method according to claim 1, It is characterized in that The randomly generated third secret key and initialization vector, concatenating the first ciphertext and the timestamp into a first data string, encrypting the first data string to obtain a second ciphertext, and encrypting the third secret key and initialization vector to obtain a third ciphertext, includes: Based on the first ciphertext and the timestamp, randomly generate a third key, an initialization vector, and a fourth key, and send a private key corresponding to the fourth key to the server; Encrypting the first data string using the third secret key and the initialization vector to obtain a second ciphertext corresponding to the information to be encrypted; The third secret key and the initialization vector are encrypted using the fourth secret key to obtain a third ciphertext.
3. The method according to claim 2, It is characterized in that The step of encrypting the first data string by using the third secret key and the initialization vector to obtain a second ciphertext corresponding to the information to be encrypted includes: Concatenate the initialization vector and the first data string to obtain a second data string; The second data string is encrypted using the third secret key to obtain a second ciphertext corresponding to the information to be encrypted.
4. A method for encrypting information, It is characterized in that Applied to the server, including: Receive a second ciphertext and a third ciphertext sent by the client, wherein the second ciphertext is obtained by encrypting a first data string formed by concatenating the first ciphertext and a timestamp by the client, and the third ciphertext is obtained by encrypting a third secret key and an initialization vector randomly generated by the client; Decrypting the second ciphertext and the third ciphertext to obtain a first ciphertext and a timestamp corresponding to the information to be encrypted; Based on the first ciphertext and the timestamp, a second key corresponding to the information to be encrypted is generated, and the second key is sent to the client, so that the client uses the second key to encrypt the first ciphertext corresponding to the information to be encrypted to obtain a fourth ciphertext corresponding to the information to be encrypted.
5. The method according to claim 4, It is characterized in that The decrypting the second ciphertext and the third ciphertext to obtain the first ciphertext and the timestamp includes: Receive a private key corresponding to the fourth key sent by the client, and use the private key to decrypt the third ciphertext to obtain a third key and an initialization vector; The second ciphertext is decrypted using the third secret key and the initialization vector to obtain a first data string composed of the first ciphertext and the timestamp, and the first ciphertext and the timestamp are separated from the first data string.
6. The method according to claim 4, It is characterized in that The generating, based on the first ciphertext and the timestamp, a second secret key corresponding to the information to be encrypted includes: Determine whether the time difference between the current system time and the time in the timestamp is less than a preset time difference; If the time difference is less than the preset time difference, generating a second secret key corresponding to the information to be encrypted based on the first ciphertext; If the time difference is greater than or equal to the preset time difference, an alarm message prohibiting encryption is generated and sent to the client.
7. An information encryption device, It is characterized in that Applied to the client, including: An acquisition unit, used for acquiring information to be encrypted and its corresponding timestamp; A first encryption unit, used to encrypt the information to be encrypted using a first secret key in a preset encryption algorithm to obtain a first ciphertext corresponding to the information to be encrypted; a second encryption unit, configured to randomly generate a third secret key and an initialization vector, concatenate the first ciphertext and the timestamp into a first data string, encrypt the first data string to obtain a second ciphertext, and encrypt the third secret key and the initialization vector to obtain a third ciphertext; A sending unit, configured to send the second ciphertext and the third ciphertext to a server, and obtain a second secret key corresponding to the information to be encrypted, generated by the server based on the second ciphertext and the third ciphertext; The third encryption unit is used to encrypt the first ciphertext by using the second secret key to obtain a fourth ciphertext corresponding to the information to be encrypted as an encryption result corresponding to the information to be encrypted.
8. An information encryption device, It is characterized in that Applied to the server, including: A receiving unit, configured to receive a second ciphertext and a third ciphertext sent by a client, wherein the second ciphertext is obtained by encrypting a first data string concatenated with the first ciphertext and a timestamp by the client, and the third ciphertext is obtained by encrypting a third secret key and an initialization vector randomly generated by the client; A decryption unit, configured to decrypt the second ciphertext and the third ciphertext to obtain a first ciphertext and a timestamp corresponding to the information to be encrypted; A generating unit is used to generate a second key corresponding to the information to be encrypted based on the first ciphertext and the timestamp, and send the second key to the client, so that the client uses the second key to encrypt the first ciphertext corresponding to the information to be encrypted to obtain a fourth ciphertext corresponding to the information to be encrypted.
9. A computer-readable storage medium having a computer program stored thereon, It is characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.
10. A computer device comprising a memory, a processor and a computer program stored in the memory and executable on the processor, It is characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
Method and system for symmetric encryption based on timestamp
CN108259407A
Data processing method and device, electronic equipment and storage medium
CN112637836A