A data encryption and decryption method, apparatus, terminal device, and storage medium
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-01
- Publication Date
- 2026-08-14
AI Technical Summary
[0027]本申请实施例与现有技术相比存在的有益效果是:本申请利用第一密钥对待加密数据进行加密,得到第一加密数据;对第一加密数据进行切分,得到至少两个第一加密数据块,并记录每一个第一加密数据块的切分顺序标识,得到对应的第一辅助数据,其中,切分顺序标识用于表示第一加密数据块在第一加密数据中的位置;获取每一第一加密数据块对应的第二密钥,利用第二密钥对对应的第一加密数据块进行加密,得到第二加密数据块,并在第一辅助数据中记录第二密钥对应的颜色标识,得到第二加密数据块对应的第二辅助数据,第二辅助数据用于对第二加密数据块进行解密。本申请对待加密数据进行两次加密,增大了破解难度,可以更好地保障数据安全;此外,本申请还可以得到第二辅助数据,在对第二加密数据块进行解密时可以根据第二辅助数据中包含的颜色标识确定第二加密数据块对应的第二密钥。
Smart Images

Figure CN115982753B_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of data security technology, and in particular relates to a data encryption and decryption method, apparatus, terminal equipment and storage medium. Background Technology
[0002] With the development of computer technology and the continuous advancement of digitalization, users generate a large amount of data every day, including some confidential data such as work emails, chat logs, design drafts, and core code. Therefore, how to reduce the risk of data leakage and how to prevent data from being directly stolen or misused are urgent technical problems that need to be solved. Summary of the Invention
[0003] This application provides a data encryption and decryption method, apparatus, terminal device, and storage medium, which can prevent data from being directly stolen or misused.
[0004] In a first aspect, embodiments of this application provide a data encryption method, the method comprising:
[0005] The data to be encrypted is encrypted using the first key to obtain the first encrypted data;
[0006] The first encrypted data is divided into at least two first encrypted data blocks; each first encrypted data block corresponds to first auxiliary data, and the first auxiliary data contains the division order identifier of the corresponding first encrypted data block, the division order identifier being used to indicate the position of the first encrypted data block in the first encrypted data;
[0007] Obtain the second key corresponding to each of the first encrypted data blocks; encrypt the corresponding first encrypted data block using the second key to obtain the second encrypted data block, and record the color identifier corresponding to the second key in the first auxiliary data to obtain the second auxiliary data corresponding to the second encrypted data block. The second auxiliary data is used to decrypt the second encrypted data block.
[0008] Secondly, embodiments of this application provide a data decryption method, the method comprising:
[0009] Obtain a second encrypted data block, which is an encrypted data block obtained after encrypting the first encrypted data block. The second encrypted data block has corresponding second auxiliary data, which includes the segmentation order identifier of the second encrypted data block and the color identifier of the second key used to encrypt the first encrypted data block.
[0010] Based on the color identifiers contained in the second auxiliary data, the second key corresponding to the second encrypted data block is determined;
[0011] Using the second key, the second encrypted data block is decrypted to obtain the first encrypted data block;
[0012] After obtaining all of the first encrypted data blocks, the first encrypted data blocks are concatenated based on the segmentation order identifier contained in the second auxiliary data to obtain the first encrypted data.
[0013] The first encrypted data is decrypted using the first key to obtain the data to be encrypted.
[0014] Thirdly, embodiments of this application provide a data encryption device, which includes:
[0015] The first encryption module is used to encrypt the data to be encrypted using the first key to obtain the first encrypted data.
[0016] The segmentation module is used to segment the first encrypted data to obtain at least two first encrypted data blocks; each first encrypted data block corresponds to first auxiliary data, and the first auxiliary data contains the segmentation order identifier of the corresponding first encrypted data block, the segmentation order identifier being used to indicate the position of the first encrypted data block in the first encrypted data;
[0017] The second encryption module is used to obtain the second key corresponding to each of the first encrypted data blocks; to encrypt the corresponding first encrypted data block using the second key to obtain the second encrypted data block; and to record the color identifier corresponding to the second key in the first auxiliary data to obtain the second auxiliary data corresponding to the second encrypted data block. The second auxiliary data is used to decrypt the second encrypted data block.
[0018] Fourthly, embodiments of this application provide a data decryption apparatus, the apparatus comprising:
[0019] The data acquisition module is used to acquire a second encrypted data block, which is an encrypted data block obtained by encrypting the first encrypted data block. The second encrypted data block has corresponding second auxiliary data, which includes the segmentation order identifier of the second encrypted data block and the color identifier of the second key used to encrypt the first encrypted data block.
[0020] The key determination module is used to determine the second key corresponding to the second encrypted data block based on the color identifier contained in the second auxiliary data;
[0021] The first decryption module is used to decrypt the second encrypted data block using the second key to obtain the first encrypted data block;
[0022] The splicing module is used to splice the first encrypted data blocks based on the segmentation order identifier contained in the second auxiliary data after obtaining all the first encrypted data blocks, so as to obtain the first encrypted data.
[0023] The second decryption module is used to decrypt the first encrypted data using the first key to obtain the data to be encrypted.
[0024] Fifthly, embodiments of this application provide a terminal device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements a data encryption method described in the first aspect and a data decryption method described in the second aspect.
[0025] In a sixth aspect, embodiments of this application provide a computer-readable storage medium storing a computer program that, when executed by a processor, implements a data encryption method as described in the first aspect and a data decryption method as described in the second aspect.
[0026] In a seventh aspect, embodiments of this application provide a computer program product that, when run on a terminal device, causes the terminal device to execute a data encryption method described in the first aspect and a data decryption method described in the second aspect.
[0027] The beneficial effects of this application embodiment compared with the prior art are as follows: This application uses a first key to encrypt the data to be encrypted, obtaining first encrypted data; the first encrypted data is divided into at least two first encrypted data blocks, and the division order identifier of each first encrypted data block is recorded to obtain corresponding first auxiliary data, wherein the division order identifier is used to indicate the position of the first encrypted data block in the first encrypted data; a second key corresponding to each first encrypted data block is obtained, and the corresponding first encrypted data block is encrypted using the second key to obtain a second encrypted data block, and the color identifier corresponding to the second key is recorded in the first auxiliary data to obtain second auxiliary data corresponding to the second encrypted data block, which is used to decrypt the second encrypted data block. This application encrypts the data to be encrypted twice, increasing the difficulty of cracking and better ensuring data security; in addition, this application can also obtain second auxiliary data, and when decrypting the second encrypted data block, the second key corresponding to the second encrypted data block can be determined according to the color identifier contained in the second auxiliary data. Attached Figure Description
[0028] To more clearly illustrate the technical solutions in the embodiments of this application, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0029] Figure 1 This is a schematic flowchart of a data encryption method provided in an embodiment of this application;
[0030] Figure 2 This is a flowchart illustrating a data encryption method provided in another embodiment of this application;
[0031] Figure 3 This is a schematic diagram of the pointer pointing relationship provided in an embodiment of this application;
[0032] Figure 4 This is a schematic flowchart of a data decryption method provided in an embodiment of this application;
[0033] Figure 5 This is a flowchart illustrating a data decryption method provided in another embodiment of this application;
[0034] Figure 6 This is a schematic structural block diagram of a data encryption device provided in an embodiment of this application;
[0035] Figure 7 This is a schematic structural block diagram of a data decryption device provided in another embodiment of this application;
[0036] Figure 8 This is a schematic diagram of the structure of a terminal device provided in an embodiment of this application. Detailed Implementation
[0037] In the following description, specific details such as particular system architectures and techniques are set forth for illustrative purposes and not for limitation, in order to provide a thorough understanding of the embodiments of this application. However, those skilled in the art will understand that this application may also be implemented in other embodiments without these specific details. In other instances, detailed descriptions of well-known systems, apparatuses, circuits, and methods have been omitted so as not to obscure the description of this application with unnecessary detail.
[0038] It should be understood that, when used in this application specification and the appended claims, the term "comprising" indicates the presence of the described features, integrals, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or a collection thereof.
[0039] It should also be understood that the term “and / or” as used in this application specification and the appended claims means any combination of one or more of the associated listed items and all possible combinations, and includes such combinations.
[0040] As used in this application specification and the appended claims, the term "if" may be interpreted, depending on the context, as "when," "once," "in response to determination," or "in response to detection." Similarly, the phrase "if determined" or "if detected [the described condition or event]" may be interpreted, depending on the context, as meaning "once determined," "in response to determination," "once detected [the described condition or event]," or "in response to detection [the described condition or event]."
[0041] Furthermore, in the description of this application and the appended claims, the terms "first," "second," "third," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.
[0042] References to "one embodiment" or "some embodiments" as described in this specification mean that one or more embodiments of this application include a specific feature, structure, or characteristic described in connection with that embodiment. Therefore, the phrases "in one embodiment," "in some embodiments," "in other embodiments," "in still other embodiments," etc., appearing in different parts of this specification do not necessarily refer to the same embodiment, but rather mean "one or more, but not all, embodiments," unless otherwise specifically emphasized. The terms "comprising," "including," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.
[0043] Example 1:
[0044] Please see Figure 1 , Figure 1 A schematic flow diagram of a data encryption method provided in this application is shown.
[0045] Step 101: Encrypt the data to be encrypted using the first key to obtain the first encrypted data.
[0046] Alternatively, the data to be encrypted can be a string of data, such as a password, or a file, such as a thesis.
[0047] Optionally, the first key can be provided by the user or generated randomly.
[0048] Encrypting the data to be encrypted using the first key is the initial encryption of the data, which can prevent the data to be encrypted from being directly stolen or misused, thus ensuring data security.
[0049] Step 102: Divide the first encrypted data into at least two first encrypted data blocks; each first encrypted data block corresponds to first auxiliary data, and the first auxiliary data contains the division order identifier of the corresponding first encrypted data block. The division order identifier is used to indicate the position of the first encrypted data block in the first encrypted data.
[0050] Optionally, the first encrypted data can be divided evenly, i.e., each first encrypted data block has the same length, or the first encrypted data can be divided randomly, i.e., each first encrypted data block may have the same length or different lengths.
[0051] Optionally, after segmenting the first encrypted data, the resulting first encrypted data blocks can be numbered to obtain a segmentation order identifier corresponding to each first encrypted data block. As an example and not a limitation, Arabic numerals, Roman numerals, or English letters can be used to number the first encrypted data blocks.
[0052] Step 103: Obtain the second key corresponding to each first encrypted data block; use the second key to encrypt the corresponding first encrypted data block to obtain the second encrypted data block, and record the color identifier corresponding to the second key in the first auxiliary data to obtain the second auxiliary data corresponding to the second encrypted data block. The second auxiliary data is used to decrypt the second encrypted data block.
[0053] Optionally, the second key can be provided by the user or randomly generated. The second key can be the same as or different from the first key.
[0054] Optionally, the second key may have a corresponding color identifier; different second keys correspond to different color identifiers. For example, if there are three second keys A, B, and C, then the color identifiers corresponding to the three second keys can be red, yellow, and blue, respectively.
[0055] Optionally, at least two first encrypted data blocks may have the same second key, meaning that at least two first encrypted data blocks can be encrypted using the same second key. For example, if there are three first encrypted data blocks X1, X2, and X3, their corresponding second keys can be A, A, and C, respectively.
[0056] Optionally, after recording the color identifier corresponding to the second key in the first auxiliary data corresponding to the first encrypted data block, the second key used to encrypt the first encrypted data block can be determined based on the color identifier during decryption.
[0057] Optionally, after encrypting the corresponding first encrypted data block using the second key to obtain the second encrypted data block, the method further includes:
[0058] Based on the first key, the second key, and all the second encrypted data blocks, a target data sequence is determined. Each target data in the target data sequence has a corresponding storage location. The target data is any data in the first key, the second key, and the second encrypted data block.
[0059] For each target data in the target data sequence, a first storage location is recorded in the corresponding target auxiliary data; the first storage location is the storage location of other target data adjacent to the target data in the target data sequence, and is used to obtain other target data based on the first storage location when the target data of the target data is obtained.
[0060] For each key data in the target data sequence, a second storage location is recorded in the corresponding key auxiliary data. The key data is either the first key or the second key. The second storage location is the storage location of other key data adjacent to the key data in the target data sequence, and is used to identify the key data in the target data sequence.
[0061] Assume K is the first key, Y1, Y2, and Y3 are the second encrypted data blocks, and A, B, and C are three second keys.
[0062] If the target data sequence obtained after random permutation is [Y1, B, Y3, K, A, C, Y2], then the process of recording the first storage position in the target auxiliary data and the second storage position in the key auxiliary data will be explained using the example of recording the first storage position in the target auxiliary data and the second storage position in the key auxiliary data. The first storage position is the storage location of another target data adjacent to and to the right of the target data in the target data sequence.
[0063] For target data Y1, record the storage location of B in its target auxiliary data; for target data B, record the storage location of Y3 in its target auxiliary data; for target data Y3, record the storage location of K in its target auxiliary data; for target data K, record the storage location of A in its target auxiliary data; for target data A, record the storage location of C in its target auxiliary data; for target data C, record the storage location of Y2 in its target auxiliary data; for target data Y2, record the storage location of Y1 in its target auxiliary data.
[0064] For key data B, record the storage location of K in its key auxiliary data; for key data K, record the storage location of A in its key auxiliary data; for key data A, record the storage location of C in its key auxiliary data; for key data C, record the storage location of B in its key auxiliary data.
[0065] After encrypting the first encrypted data block using the second key, this application stores the first key, the second key, and the second encrypted data block in different locations, which can prevent all data from being directly stolen or misused.
[0066] Optionally, this application can store the second encrypted data blocks separately, that is, the target data sequence can be determined based on all the second encrypted data blocks.
[0067] This application encrypts the data to be encrypted using a first key to obtain first encrypted data; it then divides the first encrypted data into at least two first encrypted data blocks, recording the division order identifier for each block to obtain corresponding first auxiliary data, where the division order identifier indicates the position of the first encrypted data block within the first encrypted data; finally, it obtains a second key corresponding to each first encrypted data block, encrypts the corresponding first encrypted data block using the second key to obtain a second encrypted data block, and records the color identifier corresponding to the second key in the first auxiliary data to obtain second auxiliary data corresponding to the second encrypted data block. This second auxiliary data is used to decrypt the second encrypted data block. This application encrypts the data to be encrypted twice, increasing the difficulty of cracking and better ensuring data security. Furthermore, this application can obtain second auxiliary data, and when decrypting the second encrypted data block, the second key corresponding to the second encrypted data block can be determined based on the color identifier contained in the second auxiliary data.
[0068] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0069] Example 2:
[0070] Please see Figure 2 , Figure 2 A schematic flow diagram of a data encryption method provided in this application is shown.
[0071] Step 201: Encrypt the data to be encrypted using the first key to obtain the first encrypted data.
[0072] The first key corresponds to first key auxiliary data, which contains color identifiers that match the first key.
[0073] The color identifier corresponding to the first key can be determined by the user or randomly assigned. As an example and not a limitation, the color identifier corresponding to the first key can be black, white, green, or other colors.
[0074] Step 202: Divide the first encrypted data into at least two blocks of first encrypted data.
[0075] The relevant content in step 202 can be found in the relevant description in step 102, and will not be repeated here.
[0076] Step 203: Obtain the second key corresponding to each first encrypted data block; based on the second key corresponding to each first encrypted data block, obtain the second key set.
[0077] Optionally, obtaining the second key corresponding to each first encrypted data block includes: obtaining the second key corresponding to each first encrypted data block from at least two candidate keys, wherein the color identifier corresponding to each candidate key is different from the color identifier corresponding to the first key, and the second key corresponds to second key auxiliary data, wherein the second key auxiliary data contains a color identifier that matches the second key.
[0078] Candidate keys can be provided by the user or randomly generated. The number of candidate keys can be greater than or equal to the number of the first encrypted data blocks, or less than the number of the first encrypted data blocks. When the number of candidate keys is greater than or equal to the number of the first encrypted data blocks, to increase the difficulty of cracking, a candidate key can be set to be selected only once. When the number of candidate keys is less than the number of the first encrypted data blocks, to ensure that each first encrypted data block corresponds to a second key, a candidate key can be set to be selected multiple times.
[0079] Optionally, obtaining the second key corresponding to each first encrypted data block from at least two candidate keys includes: sequentially or randomly selecting the second key corresponding to each first encrypted data block from at least two candidate keys.
[0080] It should be noted that, in order to determine the corresponding unique key based on the color code during decryption, the color code corresponding to the first key and the color code corresponding to each second key must be different.
[0081] Step 204: After encrypting the corresponding first encrypted data block using the second key to obtain the second encrypted data block, determine the first target key corresponding to the second key based on the first key and the unencrypted key. The unencrypted key is the unencrypted key in the second key set that has a different color identifier than the second key.
[0082] Optionally, a first target key corresponding to a second key can be randomly selected from the first key and the unencrypted key.
[0083] The first key is not encrypted. Therefore, to increase the difficulty of cracking, the first key can be set to be selected only once.
[0084] For the second key, its corresponding unencrypted key can also be understood as any unencrypted key in the second key set other than the second key. Therefore, the unencrypted key corresponding to each second key is different.
[0085] Step 205: Encrypt the second key using the first target key to obtain key encryption data, and record the color identifier corresponding to the first target key in the corresponding second key auxiliary data to obtain the third key auxiliary data corresponding to the key encryption data. The third key auxiliary data is used to decrypt the key encryption data.
[0086] The purpose of obtaining the third key auxiliary data is to determine the first target key based on the color identifier of the first target key contained in the third key auxiliary data when decrypting the key encrypted data, and then use the first target key to decrypt the key encrypted data to obtain the corresponding second key.
[0087] The following example illustrates the process of determining the first target key corresponding to the second key and the encryption process of the second key, assuming that the first key can only be selected once:
[0088] Suppose that K is the first key, and A, B, and C are three second keys.
[0089] For the second key A, its corresponding unencrypted keys are B and C. Then, the first target key corresponding to A can be selected from K, B, and C. Assuming that B is selected as the first target key corresponding to A, A is encrypted using B to obtain the key encrypted data A'.
[0090] For the second key B, A has already been encrypted, and its corresponding unencrypted key is C. Then, the first target key corresponding to B can be selected from K and C. Assuming that C is selected as the first target key corresponding to B, B is encrypted using C to obtain the key encrypted data B'.
[0091] For the second key C, A and B have already been encrypted. There are no unencrypted keys in the second key set except for C. Therefore, C does not have a corresponding unencrypted key. K can be selected as the first target key corresponding to C. C is encrypted using K to obtain the key encrypted data C'.
[0092] At this point, the second keys A, B, and C have all been encrypted.
[0093] This application encrypts the corresponding first encrypted data block using a second key to obtain a second encrypted data block. Based on the first key and the unencrypted key, it determines the first target key corresponding to the second key. The second key is then encrypted using the first target key to obtain encrypted key data. A color identifier corresponding to the first target key is recorded in the corresponding second key auxiliary data to obtain third key auxiliary data corresponding to the encrypted key data. This application encrypts the second key, further increasing the difficulty of cracking. Furthermore, this application can obtain third key auxiliary data, and when decrypting the encrypted key data, the first target key corresponding to the encrypted key data can be determined based on the color identifier contained in the third key auxiliary data.
[0094] In an optional implementation, after encrypting the corresponding first encrypted data block using the second key to obtain the second encrypted data block, the method further includes:
[0095] The second key is split to obtain at least two first key blocks. Each first key block corresponds to a fourth key auxiliary data, which includes a color identifier and a splitting order identifier for the first key block. Based on the first key and the unencrypted key, a second target key is determined for each first key block. The first key block is encrypted using the second target key to obtain encrypted key block data. The color identifier corresponding to the second target key is recorded in the corresponding fourth key auxiliary data to obtain fifth key auxiliary data for the encrypted key block data. The fifth key auxiliary data is used to decrypt the encrypted key block data.
[0096] Optionally, the second key can be divided evenly or randomly.
[0097] The following example, assuming the second key is evenly divided, illustrates the process of determining the second target key corresponding to the first key block and the encryption process of the first key block:
[0098] Suppose that K is the first key, and A, B, and C are three second keys. Divide the three second keys into three first key blocks respectively, resulting in nine first key blocks: A1, A2, A3, B1, B2, B3, C1, C2, and C3.
[0099] For the first key block A1, whose corresponding unencrypted keys are B and C, the second target key corresponding to A1 can be selected from K, B, and C. Assuming B is selected as the second target key corresponding to A1, A1 is encrypted using B to obtain the key block encrypted data A1'. For the first key block A2, whose corresponding unencrypted keys are B and C, the second target key corresponding to A2 can be selected from K, B, and C. Assuming C is selected as the second target key corresponding to A2, A2 is encrypted using C to obtain the key block encrypted data A2'. For the first key block A3, whose corresponding unencrypted keys are B and C, the second target key corresponding to A3 can be selected from K, B, and C. Assuming C is selected as the second target key corresponding to A3, A3 is encrypted using C to obtain the key block encrypted data A3'.
[0100] For the first key block B1, A has already been encrypted, and its corresponding unencrypted key is C. The second target key corresponding to B1 can be selected from K and C. Assuming C is selected as the second target key for B1, B1 is encrypted using C to obtain the encrypted key block data B1'. For the first key block B2, its corresponding unencrypted key is C. The second target key corresponding to B2 can be selected from K and C. Assuming C is selected as the second target key for B2, B2 is encrypted using C to obtain the encrypted key block data B2'. For the first key block B3, its corresponding unencrypted key is C. The second target key corresponding to B3 can be selected from K and C. Assuming K is selected as the second target key for B3, B3 is encrypted using K to obtain the encrypted key block data B3'.
[0101] For the first key blocks C1, C2, and C3, A and B have already been encrypted. In the second key set, there are no unencrypted keys except for C. Therefore, C1, C2, and C3 do not have corresponding unencrypted keys. K can be selected as the second target key corresponding to C1, C2, and C3. K is used to encrypt C1, C2, and C3 respectively to obtain the encrypted key block data C1', C2', and C3'.
[0102] At this point, the first key blocks A1, A2, A3, B1, B2, B3, C1, C2, and C3 have all been encrypted.
[0103] This implementation divides the second key into a first key block and encrypts the first key block, which can further increase the difficulty of cracking and improve data security.
[0104] In another optional implementation, determining the second target key corresponding to the first key block based on the first key and the unencrypted key includes: splitting the first key to obtain at least two second key blocks; and selecting the second target key from the at least two second key blocks and the unencrypted first key block corresponding to the unencrypted key.
[0105] Record the color identifier corresponding to the second target key in the corresponding fourth key auxiliary data to obtain the fifth key auxiliary data corresponding to the key block encryption data, including: recording the color identifier and the segmentation order identifier corresponding to the second target key in the corresponding fourth key auxiliary data to obtain the fifth key auxiliary data.
[0106] The following example, assuming that the first and second keys are evenly divided, illustrates another process for determining the second target key corresponding to the first key block and the encryption process of the first key block:
[0107] Suppose that K is the first key, and A, B, and C are three second keys. Divide the three second keys into three first key blocks respectively, resulting in nine first key blocks: A1, A2, A3, B1, B2, B3, C1, C2, and C3. Divide the first key K into three second key blocks: K1, K2, and K3.
[0108] For the first key block A1, whose corresponding unencrypted keys are B and C, the second target key corresponding to A1 can be selected from the key blocks corresponding to K, B, and C. Assuming B1 is selected as the second target key corresponding to A1, A1 is encrypted using B1 to obtain the key block encrypted data A1”. For the first key block A2, whose corresponding unencrypted keys are B and C, the second target key corresponding to A2 can be selected from the key blocks corresponding to K, B, and C. Assuming C2 is selected as the second target key corresponding to A2, A2 is encrypted using C2 to obtain the key block encrypted data A2”. For the first key block A3, whose corresponding unencrypted keys are B and C, the second target key corresponding to A3 can be selected from the key blocks corresponding to K, B, and C. Assuming C3 is selected as the second target key corresponding to A3, A3 is encrypted using C3 to obtain the key block encrypted data A3.
[0109] For the first key block B1, A has been encrypted, and its corresponding unencrypted key is C. Therefore, the second target key corresponding to B1 can be selected from the key blocks corresponding to K and C. Assuming C1 is selected as the second target key corresponding to B1, B1 is encrypted using C1 to obtain the encrypted key block data B1”. For the first key block B2, its corresponding unencrypted key is C. Therefore, the second target key corresponding to B2 can be selected from the key blocks corresponding to K and C. Assuming C2 is selected as the second target key corresponding to B2, B2 is encrypted using C2 to obtain the encrypted key block data B2”. For the first key block B3, its corresponding unencrypted key is C. Therefore, the second target key corresponding to B3 can be selected from the key blocks corresponding to K and C. Assuming K2 is selected as the second target key corresponding to B3, B3 is encrypted using K2 to obtain the encrypted key block data B3.
[0110] For the first key blocks C1, C2, and C3, A and B have already been encrypted. In the second key set, there are no unencrypted keys except for C. Therefore, C1, C2, and C3 do not have corresponding unencrypted keys. The key block corresponding to K can be selected as the second target key corresponding to C1, C2, and C3. For example, using K2 to encrypt C1, we get the key block encrypted data C1”; using K3 to encrypt C2, we get the key block encrypted data C2”; and using K1 to encrypt C3, we get the key block encrypted data C3”.
[0111] At this point, the first key blocks A1, A2, A3, B1, B2, B3, C1, C2, and C3 have all been encrypted.
[0112] This implementation divides the first key and the second key into key blocks, selects a second target key from the key blocks, and uses the second target key to encrypt the first key block. This makes it impossible to obtain the correct decryption result by directly using the unencrypted first key during decryption, thereby improving the concealment of the decryption key, further increasing the difficulty of cracking, and improving the security of the data.
[0113] It should be noted that the auxiliary data mentioned above can be header data, which includes a first segmentation order identifier (BlockNum1) field, a self-color identifier (SelfColor) field, and a decryption color identifier (DecryptColor) field. Specifically, the BlockNum1 field records the segmentation order identifier of the segmented data; the SelfColor field records the color identifier corresponding to the data itself; and the DecryptColor field records the color identifier corresponding to the key used to encrypt the data.
[0114] The data to be encrypted has a corresponding header data, and the above three fields in the header data are empty (NULL).
[0115] After encrypting the data to be encrypted using the first key to obtain the first encrypted data, the header data is not split when the first encrypted data is segmented, and each segmented first encrypted data block has its own header data. After numbering the obtained first encrypted data blocks to obtain the segmentation order identifier corresponding to each first encrypted data block, the obtained segmentation order identifier can be written into the BlockNum1 field in the corresponding header data to obtain the first auxiliary data corresponding to each first encrypted data block.
[0116] After encrypting the corresponding first encrypted data block using the second key to obtain the second encrypted data block, the color identifier corresponding to the second key can be written into the DecryptColor field of the header data corresponding to the first encrypted data block to obtain the second auxiliary data. Note that when encrypting the first encrypted data block using the second key, the header data corresponding to the first encrypted data block does not need to be encrypted.
[0117] The first key and the second key have corresponding header data; in the header data of the first key, the BlockNum1 field and the DecryptColor field are NULL, and the SelfColor field records the color identifier corresponding to the first key, thus obtaining the auxiliary data of the first key; in the header data of the second key, the BlockNum1 field and the DecryptColor field are NULL, and the SelfColor field records the color identifier corresponding to the second key, thus obtaining the auxiliary data of the second key.
[0118] After encrypting the second key using the first target key to obtain the key encryption data, the color identifier corresponding to the first target key can be written into the DecryptColor field of the header data corresponding to the second key to obtain the third key auxiliary data.
[0119] Optionally, after encrypting the corresponding first encrypted data block using the second key to obtain the second encrypted data block, and then splitting the second key to obtain at least two first key blocks, each first key block has corresponding header data. The splitting order identifier of the first key block can be written in the BlockNum1 field of the header data of the first key block, and the color identifier corresponding to the first key block can be written in the SelfColor field of the header data to obtain the fourth key auxiliary data. After encrypting the first key block using the second target key to obtain the key block encrypted data, the color identifier corresponding to the second target key can be written in the DecryptColor field of the header data to obtain the fifth key auxiliary data.
[0120] Optionally, when a second target key is selected from the key block, the header data also includes a second segmentation order identifier (BlockNum2) field, which is used to record the segmentation order identifier corresponding to the second target key used when encrypting the data.
[0121] After splitting the first key to obtain at least two second key blocks, the splitting order identifier of the second key block can be written in the BlockNum1 field of the header data of the second key block.
[0122] After selecting the second target key from the key block and encrypting the corresponding first encrypted data block using the second key, the segmentation order identifier of the second target key can be written into the BlockNum2 field of the header data of the first key block based on the segmentation order identifier under the BlockNum1 field in the header data of the second target key, thus obtaining the fifth key auxiliary data.
[0123] It should be noted that the BlockNum2 field in the header data corresponding to the data to be encrypted is NULL.
[0124] After encrypting the data, users can store or transmit the encrypted data and the key.
[0125] In an optional implementation, after encrypting the second key using the first target key to obtain key-encrypted data, the method further includes:
[0126] Based on the first key, all of the second encrypted data blocks, and all of the key encrypted data, a target data sequence is determined. Each target data in the target data sequence has a corresponding storage location. The target data is any data in the first key, the second encrypted data block, and the key encrypted data.
[0127] For each target data in the target data sequence, a first storage location is recorded in the corresponding target auxiliary data; the first storage location is the storage location of other target data adjacent to the target data in the target data sequence, and is used to obtain other target data based on the first storage location when the target data of the target is obtained.
[0128] For each key data in the target data sequence, a second storage location is recorded in the corresponding key auxiliary data. The key data is either the first key or key encryption data. The second storage location is the storage location of other key data adjacent to the key data in the target data sequence, and is used to identify the key data in the target data sequence.
[0129] Specifically, if the target data is the first key, then the target auxiliary data is the first key auxiliary data; if the target data is the second encrypted data block, then the target auxiliary data is the second auxiliary data; if the target data is key encrypted data, then the target auxiliary data is the third key auxiliary data.
[0130] Optionally, determining the target data sequence based on the first key, all the second encrypted data blocks, and all the key encrypted data includes: randomly arranging the first key, all the second encrypted data blocks, and all the key encrypted data to obtain the target data sequence.
[0131] Optionally, the first storage location can be the storage location of one other target data adjacent to the target data in the target data sequence, or it can be the storage location of two other target data adjacent to the target data in the target data sequence. The second storage location can be the storage location of one other key data adjacent to the key data in the target data sequence, or it can be the storage location of two other key data adjacent to the key data in the target data sequence.
[0132] It should be noted that when the first storage location is the storage location of another target data adjacent to the target data in the target data sequence, the other target data adjacent to the target data can refer to other target data adjacent to the target data and located to the left of the target data, or it can refer to other target data adjacent to the target data and located to the right of the target data. Similarly, when the second storage location is the storage location of another key data adjacent to the key data in the target data sequence, the storage location of this other key data adjacent to the key data can refer to other key data adjacent to the key data and located to the left of the key data, or it can refer to other key data located to the right of the key data.
[0133] Optionally, the header data may also include a first pointer (Front) field and a second pointer (Next) field. The first pointer field records a first storage location, and the second pointer field records a second storage location. Specifically, the first pointer field may include a first forward pointer (Front1) field and / or a first backward pointer (Next1) field; the second pointer field may include a second forward pointer (Front2) field and / or a second backward pointer (Next2) field. The first forward pointer field and the first backward pointer field can each be used to record the storage locations of two other target data adjacent to the target data, and the second forward pointer field and the second backward pointer field can each be used to record the storage locations of two other key data adjacent to the key data.
[0134] Assume that K is the first key, Y1, Y2, and Y3 are the second encrypted data blocks, and A', B', and C' are the encrypted data with three keys.
[0135] If the target data sequence obtained after random permutation is [Y1, B', Y3, K, A', C', Y2], then the process of recording the first storage position in the target auxiliary data and the second storage position in the key auxiliary data is explained by taking the first storage position as the storage position of the two other target data adjacent to the target data in the target data sequence and the second storage position as the storage position of the two other key data adjacent to the key data in the target data sequence as an example:
[0136] For target data Y1, record the storage locations of Y2 and B' in its target auxiliary data; for target data B', record the storage locations of Y1 and Y3 in its target auxiliary data; for target data Y3, record the storage locations of B' and K in its target auxiliary data; for target data K, record the storage locations of Y3 and A' in its target auxiliary data; for target data A', record the storage locations of K and C' in its target auxiliary data; for target data C', record the storage locations of A' and Y2 in its target auxiliary data; for target data Y2, record the storage locations of C' and Y1 in its target auxiliary data.
[0137] For key data B', the storage locations of C' and K are recorded in its key auxiliary data; for key data K, the storage locations of B' and A' are recorded in its key auxiliary data; for key data A', the storage locations of K and C' are recorded in its key auxiliary data; for key data C', the storage locations of A' and B' are recorded in its key auxiliary data.
[0138] Optionally, you may refer to Figure 3 , Figure 3 This is a diagram illustrating the pointer relationships. Based on Figure 3 As can be seen, this application uses Front1 and Next1 pointers to perform a double-chain linking of the target data, and then uses Front2 and Next2 pointers to perform a double-chain linking of the key data, forming a four-chain structure, which improves the concealment of the data and can further ensure data security.
[0139] Optionally, when the second key is divided into a first key block and the first key block is encrypted, this application can also store the encrypted key block data separately, that is, the target data sequence can be determined based on the encrypted key block data; or, this application can also store the first key, the second encrypted data block and the encrypted key block data separately, that is, the target data sequence can be determined based on the first key, the second encrypted data block and the encrypted key block data.
[0140] This application encrypts the corresponding first encrypted data block using a second key to obtain a second encrypted data block. Based on the first key and the unencrypted key, it determines a first target key corresponding to the second key. The second key is then encrypted using the first target key to obtain encrypted key data. A color identifier corresponding to the first target key is recorded in the corresponding second key auxiliary data to obtain third key auxiliary data. This third key auxiliary data is used to decrypt the encrypted key data. Since this application encrypts the second key after encrypting the first encrypted data block, it is necessary to crack the encrypted key data to obtain the second key before obtaining the first encrypted data block, increasing the difficulty of cracking and further ensuring data security.
[0141] Example 3:
[0142] Please see Figure 4 , Figure 4 The illustration shows a schematic flow of a data decryption method provided in this application.
[0143] Step 401: Obtain the second encrypted data block. The second encrypted data block is the encrypted data block obtained after encrypting the first encrypted data block. The second encrypted data block has corresponding second auxiliary data. The second auxiliary data includes the segmentation order identifier of the second encrypted data block and the color identifier of the second key used to encrypt the first encrypted data block.
[0144] Optionally, the second auxiliary data corresponding to the second encrypted data block is unencrypted data. The user can obtain the segmentation order identifier of the second encrypted data block and the color identifier of the second key used to encrypt the first encrypted data block based on the second auxiliary data.
[0145] Step 402: Determine the second key corresponding to the second encrypted data block based on the color identifier contained in the second auxiliary data.
[0146] Optionally, before determining the second key corresponding to the second encrypted data block, the method further includes: obtaining all the second keys used when encrypting the first encrypted data block. In a data storage scenario, the second keys can be stored in a first predetermined storage location, from which the user can obtain all the second keys; in a data transmission scenario, the second keys can be received along with the second encrypted data block, or all the second keys can be obtained from a server.
[0147] Each second key has a different color identifier, therefore, the second key corresponding to each second encrypted data block can be determined based on the color identifier contained in the second auxiliary data.
[0148] Step 403: Use the second key to decrypt the second encrypted data block to obtain the first encrypted data block.
[0149] Each second encrypted data block corresponds to a second key. By decrypting the corresponding second encrypted data block based on each second key, the entire first encrypted data block can be obtained.
[0150] Step 404: After obtaining all the first encrypted data blocks, the first encrypted data blocks are concatenated based on the segmentation order identifier contained in the second auxiliary data to obtain the first encrypted data.
[0151] The segmentation order identifier can indicate the position of the first encrypted data block in the first encrypted data. The first encrypted data can be obtained by sorting and splicing the first encrypted data block according to the segmentation order identifier.
[0152] Step 405: Decrypt the first encrypted data using the first key to obtain the data to be encrypted.
[0153] Optionally, before decrypting the first encrypted data using the first key, the method further includes: obtaining the first key. In a data storage scenario, the first key can be stored in a second designated storage location, and the user can obtain all the second keys from the second designated storage location; in a data transmission scenario, the first key can be received along with the second encrypted data block, or the first key can be obtained from a server.
[0154] Optionally, after decrypting the first encrypted data using the first key, the data to be encrypted can be obtained. The data to be encrypted can be unencrypted data, i.e., plaintext.
[0155] Before obtaining the second encrypted data block, the method further includes: obtaining target data, where the target data is any data contained in the target data sequence, the target data corresponds to target auxiliary data, the target auxiliary data records a first storage location, the first storage location is the storage location of other target data adjacent to the target data in the target data sequence, the target data sequence contains a first key, a second key and all the second encrypted data blocks; obtaining other target data based on the storage locations of other target data; obtaining adjacent target data adjacent to other target data based on the first storage location recorded in the target auxiliary data corresponding to other target data, determining the adjacent target data as other target data, returning to execute the step of obtaining adjacent target data adjacent to other target data based on the first storage location recorded in the target auxiliary data corresponding to other target data, until the target data sequence is obtained.
[0156] Assume K is the first key, Y1, Y2, and Y3 are the second encrypted data blocks, and A, B, and C are three second keys.
[0157] Taking the first storage location recorded in the target auxiliary data as the storage location of other target data adjacent to and located to the right of the target data in the target data sequence as an example, the process of obtaining the target data sequence is explained:
[0158] If the acquired target data is K, assuming that based on the first storage position recorded in the corresponding target auxiliary data, the adjacent target data A can be obtained; based on the first storage position recorded in the target auxiliary data corresponding to target data A, the adjacent target data C can be obtained; based on the first storage position recorded in the target auxiliary data corresponding to target data C, the adjacent target data Y2 can be obtained; based on the first storage position recorded in the target auxiliary data corresponding to target data Y2, the adjacent target data Y1 can be obtained; based on the first storage position recorded in the target auxiliary data corresponding to target data Y1, the adjacent target data B can be obtained; based on the first storage position recorded in the target auxiliary data corresponding to target data B, the adjacent target data Y3 can be obtained; based on the first storage position recorded in the target auxiliary data corresponding to target data Y3, the adjacent target data K can be obtained. Thus, it can be determined that all target data has been acquired, and the target data sequence can be obtained based on all the acquired target data.
[0159] After obtaining the target data sequence, the first key, the second key, and all the second encrypted data blocks can be obtained based on the target data sequence.
[0160] This application obtains a second encrypted data block, determines a second key corresponding to the second encrypted data block based on color identifiers contained in the second auxiliary data corresponding to the second encrypted data block, decrypts the second encrypted data block using the second key to obtain a first encrypted data block, and after obtaining all the first encrypted data blocks, concatenates the first encrypted data blocks based on the segmentation order identifiers contained in the second auxiliary data to obtain first encrypted data, and decrypts the first encrypted data using the first key to obtain the data to be encrypted. This application determines the second key corresponding to the second encrypted data block based on color identifiers contained in the second auxiliary data. If other users want to decrypt the second encrypted data block, without understanding the encryption rules of this application, even if they obtain the second key, they will not know the correspondence between the second key and the second encrypted data block. Therefore, this application increases the difficulty for other users to decrypt the second encrypted data block, thus preventing data theft.
[0161] Example 4:
[0162] Please see Figure 5 , Figure 5 The illustration shows a schematic flow of a data decryption method provided in this application.
[0163] Step 501: Obtain all the key-encrypted data.
[0164] The key encryption data is the encrypted data obtained after encrypting the second key. The key encryption data corresponds to the third key auxiliary data, which contains the color identifier corresponding to the second key and the color identifier corresponding to the first target key. The first target key is the key used to encrypt the second key.
[0165] If the encryption process encrypts the second key, then the decryption process requires first decrypting the encrypted data of the second key, that is, decrypting the key-encrypted data.
[0166] Optionally, each key encryption data corresponds to a third key auxiliary data, which includes the color identifier of the key used to encrypt the second key, that is, the color identifier corresponding to the first target key.
[0167] Step 502: Based on the color identifier corresponding to the decryption key, locate the target key encrypted data; the decryption key is either the first key or the already decrypted second key.
[0168] The color identifier of the first target key corresponding to the target key encryption data is the same as the color identifier of the decryption key; the first key corresponds to first key auxiliary data, which contains a color identifier that matches the first key.
[0169] Optionally, the first key can be an unencrypted key. Therefore, when searching for target key encrypted data based on the color identifier corresponding to the decryption key, the target key encrypted data can be searched first based on the color identifier of the first key. That is, the third key auxiliary data whose color identifier is the same as the color identifier of the first target key is determined as the target key auxiliary data, and the key encrypted data corresponding to the target key auxiliary data is the target key encrypted data.
[0170] Optionally, if the second key is obtained, the target key encryption data can be found based on the color identifier of the second key. That is, the third key auxiliary data whose color identifier is the same as that of the first target key and the second key is determined as the target key auxiliary data, and the key encryption data corresponding to the target key auxiliary data is the target key encryption data.
[0171] Step 503: Decrypt the target key encrypted data using the decryption key to obtain the corresponding second key.
[0172] Optionally, if the decryption key is the first key, the target key encrypted data can be decrypted using the first key; if the decryption key is the second key, the target key encrypted data can be decrypted using the second key.
[0173] Step 504: Determine the second key as the decryption key.
[0174] Return to the previous step and search for the target key encrypted data based on the color identifier corresponding to the decryption key, until all the second keys are obtained.
[0175] The following example, using the encrypted data A', B', and C' corresponding to the three secondary keys A, B, and C, illustrates the decryption process of the secondary keys:
[0176] Assume that in the third key auxiliary data corresponding to A', the color identifier for the second key A is white, and the color identifier for the first target key is red; in the third key auxiliary data corresponding to B', the color identifier for the second key B is red, and the color identifier for the first target key is green; in the third key auxiliary data corresponding to C', the color identifier for the second key C is green, and the color identifier for the first target key is blue; and the color identifier for the first key K is blue.
[0177] Optionally, based on the color identifier corresponding to the first key, if the target key encrypted data is C', then the first key K is used to decrypt C' to obtain the second key C;
[0178] Based on the color identifier corresponding to the second key C, the target key encrypted data is B'. Then, the second key C is used to decrypt B' to obtain the second key B.
[0179] Based on the color identifier corresponding to the second key B, the target key encrypted data is found to be A'. Then, A' is decrypted using the first key B to obtain the second key A.
[0180] Step 505: Obtain the second encrypted data block.
[0181] Step 506: Determine the second key corresponding to the second encrypted data block based on the color identifier contained in the second auxiliary data.
[0182] Step 507: Use the second key to decrypt the second encrypted data block to obtain the first encrypted data block.
[0183] Step 508: After obtaining all the first encrypted data blocks, the first encrypted data blocks are spliced together based on the segmentation order identifier contained in the second auxiliary data to obtain the first encrypted data.
[0184] Step 509: Decrypt the first encrypted data using the first key to obtain the data to be encrypted.
[0185] The relevant content in steps 505-509 can be found in the relevant descriptions in steps 401-405.
[0186] In an optional embodiment, if the encryption process of the second key involves dividing each second key into at least two first key blocks and encrypting each first key block, then the decryption process of the second key corresponding to this encryption process is as follows:
[0187] Retrieve all key block encrypted data. Key block encrypted data is the encrypted data obtained after encrypting the first key block. The first key block is the key block obtained after splitting the second key. Key block encrypted data corresponds to fifth key auxiliary data, which includes the color identifier corresponding to the first key block, the splitting order identifier, and the color identifier of the second target key. The second target key is the key used to encrypt the first key block. Based on the color identifier corresponding to the decryption key, find the target key block encrypted data. The color identifier of the second target key corresponding to the target key block encrypted data is the same as the color identifier corresponding to the decryption key. Decrypt the target key block encrypted data using the decryption key to obtain the corresponding first key block. According to the splitting order identifier, concatenate the first key blocks with the same color identifier to obtain the second key. Determine the second key as the decryption key, and return to execute the step of finding the target key block encrypted data based on the color identifier corresponding to the decryption key, until all second keys are obtained.
[0188] Assume the encryption process of the second key is as follows: the three second keys A, B, and C are each divided into three first key blocks, resulting in nine first key blocks: A1, A2, A3, B1, B2, B3, C1, C2, and C3. A is represented by white, B by red, C by green, and the first key K by blue. The following example, using the encrypted data A1', A2', A3', B1', B2', B3', C1', C2', and C3' from the obtained key blocks, illustrates the decryption process of the second key:
[0189] In the fifth key auxiliary data corresponding to A1', the color identifier for the first key block A1 is white, the segmentation order identifier is 1, and the color identifier for the second target key is red; in the fifth key auxiliary data corresponding to A2', the color identifier for the first key block A2 is white, the segmentation order identifier is 2, and the color identifier for the second target key is green; in the fifth key auxiliary data corresponding to A3', the color identifier for the first key block A3 is white, the segmentation order identifier is 3, and the color identifier for the second target key is blue;
[0190] In the fifth key auxiliary data corresponding to B1', the color identifier for the first key block B1 is red, the segmentation order identifier is 1, and the color identifier for the second target key is green; in the fifth key auxiliary data corresponding to B2', the color identifier for the first key block B2 is red, the segmentation order identifier is 2, and the color identifier for the second target key is green; in the fifth key auxiliary data corresponding to B3', the color identifier for the first key block B3 is red, the segmentation order identifier is 3, and the color identifier for the second target key is blue;
[0191] In the fifth key auxiliary data corresponding to C1', the color identifier for the first key block C1 is green, the segmentation order identifier is 1, and the color identifier for the second target key is blue; in the fifth key auxiliary data corresponding to C2', the color identifier for the first key block C2 is green, the segmentation order identifier is 2, and the color identifier for the second target key is blue; in the fifth key auxiliary data corresponding to C3', the color identifier for the first key block C3 is green, the segmentation order identifier is 3, and the color identifier for the second target key is blue.
[0192] Optionally, based on the color identifier corresponding to the first key, the target key encrypted data found is A3', B3', C1', C2', C3'. Then, the first key K is used to decrypt A3', B3', C1', C2', C3' respectively to obtain the first key block A3, B3, C1, C2, C3.
[0193] Based on the segmentation order identifier, the first key blocks C1, C2, and C3 are sorted and concatenated to obtain the second key C.
[0194] Based on the color identifier corresponding to the second key C, the target key encrypted data found is A2', B1', B2'. Then, the second key C is used to decrypt A2', B1', B2' to obtain the first key block A2, B1, B2.
[0195] Based on the segmentation order identifier, the first key blocks B1, B2, and B3 are sorted and concatenated to obtain the second key B.
[0196] Based on the color identifier corresponding to the second key B, the target key encrypted data is found to be A1'. Then, the second key C is used to decrypt A1' to obtain the first key block A1.
[0197] Based on the segmentation order identifier, the first key blocks A1, A2, and A3 are sorted and concatenated to obtain the second key A.
[0198] In another optional embodiment, if during the encryption process of the second key, after each second key is divided into at least two first key blocks, each first key block is encrypted using a second target key, where the second target key is either a second key block obtained after dividing the first key or a first key block obtained after dividing the second key, then the fifth key auxiliary data includes the division order identifier of the second target key. The decryption process of the second key corresponding to this encryption process is as follows:
[0199] Based on the color identifier and segmentation order identifier corresponding to the decryption key block, locate the encrypted data of the target key block. The color identifier of the second target key corresponding to the encrypted data of the target key block is the same as the color identifier of the decryption key block, and the segmentation order identifier of the second target key is the same as the segmentation order identifier of the decryption key block. The decryption key block is either the second key block or the already decrypted first key block. Decrypt the encrypted data of the target key block using the decryption key block to obtain the corresponding first key block. Identify the first key block as the decryption key block and return to execute the step of locating the encrypted data of the target key block based on the color identifier and segmentation order identifier corresponding to the decryption key block until all first key blocks are obtained. According to the segmentation order identifier, concatenate the first key blocks with the same color identifier to obtain the corresponding second key.
[0200] Assuming the first key K is divided into three second key blocks K1, K2, and K3, the following example, using the encrypted data A1”, A2”, A3”, B1”, B2”, B3”, C1”, C2”, and C3” obtained from the key blocks, illustrates the decryption process of the second key:
[0201] In the fifth key auxiliary data corresponding to "A1", the color identifier for the first key block A1 is white and the segmentation order identifier is 1, and the color identifier for the second target key is red and the segmentation order identifier is 2; in the fifth key auxiliary data corresponding to "A2", the color identifier for the first key block A2 is white and the segmentation order identifier is 2, and the color identifier for the second target key is green and the segmentation order identifier is 3; in the fifth key auxiliary data corresponding to "A3", the color identifier for the first key block A3 is white and the segmentation order identifier is 3, and the color identifier for the second target key is blue and the segmentation order identifier is 1;
[0202] In the fifth key auxiliary data corresponding to "B1", the color identifier for the first key block B1 is red and the segmentation order identifier is 1, and the color identifier for the second target key is green and the segmentation order identifier is 1; in the fifth key auxiliary data corresponding to "B2", the color identifier for the first key block B2 is red and the segmentation order identifier is 2, and the color identifier for the second target key is green and the segmentation order identifier is 3; in the fifth key auxiliary data corresponding to "B3", the color identifier for the first key block B3 is red and the segmentation order identifier is 3, and the color identifier for the second target key is blue and the segmentation order identifier is 2;
[0203] In the fifth key auxiliary data corresponding to "C1", the color identifier for the first key block C1 is green and the segmentation order identifier is 1, and the color identifier for the second target key is blue and the segmentation order identifier is 3; in the fifth key auxiliary data corresponding to "C2", the color identifier for the first key block C2 is green and the segmentation order identifier is 2, and the color identifier for the second target key is blue and the segmentation order identifier is 1; in the fifth key auxiliary data corresponding to "C3", the color identifier for the first key block C3 is green and the segmentation order identifier is 3, and the color identifier for the second target key is blue and the segmentation order identifier is 2.
[0204] Optionally, based on the color identifier corresponding to the second key block K1 with segmentation order identifier 1, if the found target key encrypted data is A3” and C2”, then the second key block K1 is used to decrypt A3” and C2” respectively to obtain the first key block A3 and C2; based on the color identifier corresponding to the second key block K2 with segmentation order identifier 2, if the found target key encrypted data is B3” and C3”, then the second key block K2 is used to decrypt B3” and C3” respectively to obtain the first key block B3 and C3; based on the color identifier corresponding to the second key block K3 with segmentation order identifier 3, if the found target key encrypted data is C1”, then the second key block K3 is used to decrypt C1” to obtain the first key block C1.
[0205] Based on the segmentation order identifier of the first key block, the first key blocks C1, C2, and C3 are sorted and concatenated to obtain the second key C.
[0206] Based on the color identifier corresponding to the second key block C1 with segmentation order identifier 1, the target key encrypted data found is B1”. Then, the second key block C1 is used to decrypt B1” to obtain the first key block B1. Based on the color identifier corresponding to the second key block C2 with segmentation order identifier 2, no target key encrypted data was found. Based on the color identifier corresponding to the second key block C3 with segmentation order identifier 3, the target key encrypted data found are A2” and B2”. Then, the second key block K2 is used to decrypt A2” and B2” respectively to obtain the first key blocks A2 and B2.
[0207] Based on the segmentation order identifier of the first key block, the first key blocks B1, B2, and B3 are sorted and concatenated to obtain the second key B.
[0208] Based on the color identifier corresponding to the second key block B1 with segmentation order identifier 1, no target key encrypted data was found; based on the color identifier corresponding to the second key block B2 with segmentation order identifier 2, the target key encrypted data found is A1”, then A1” is decrypted using the second key block B2 to obtain the first key block A1; based on the color identifier corresponding to the second key block B3 with segmentation order identifier 3, no target key encrypted data was found.
[0209] Based on the segmentation order identifier of the first key block, the first key blocks A1, A2, and A3 are sorted and concatenated to obtain the second key A.
[0210] In an optional embodiment, if the first key, all of the second encrypted data blocks, and all of the key encryption data are stored in different locations, the method further includes the following steps before obtaining all of the key encryption data:
[0211] Obtain target data, which is any data contained in the target data sequence. The target data corresponds to target auxiliary data, which records a first storage location. The first storage location is the storage location of other target data adjacent to the target data in the target data sequence. The target data sequence contains a first key, all second encrypted data blocks, and all key encrypted data. Based on the storage locations of other target data, obtain other target data. Based on the first storage location recorded in the target auxiliary data corresponding to other target data, obtain two adjacent target data adjacent to other target data, determine the adjacent target data as other target data, and return to execute the step of obtaining adjacent target data adjacent to other target data based on the first storage location recorded in the target auxiliary data corresponding to other target data, until the target data sequence is obtained.
[0212] Assume that K is the first key, Y1, Y2, and Y3 are the second encrypted data blocks, and A', B', and C' are the encrypted data with three keys.
[0213] Taking the first storage location recorded in the target auxiliary data as the storage location of other target data adjacent to and located to the right of the target data in the target data sequence as an example, the process of obtaining the target data sequence is explained:
[0214] If the acquired target data is K, assuming that based on the first storage position recorded in the corresponding target auxiliary data, the adjacent target data can be obtained as A'; based on the first storage position recorded in the target auxiliary data corresponding to target data A', the adjacent target data can be obtained as C'; based on the first storage position recorded in the target auxiliary data corresponding to target data C', the adjacent target data can be obtained as Y2; based on the first storage position recorded in the target auxiliary data corresponding to target data Y2, the adjacent target data can be obtained as Y1; based on the first storage position recorded in the target auxiliary data corresponding to target data Y1, the adjacent target data can be obtained as B'; based on the first storage position recorded in the target auxiliary data corresponding to target data B', the adjacent target data can be obtained as Y3; based on the first storage position recorded in the target auxiliary data corresponding to target data Y3, the adjacent target data can be obtained as K. Thus, it can be determined that all target data has been acquired, and the target data sequence can be obtained based on all the acquired target data.
[0215] After obtaining the target data sequence, the second encrypted data block can be determined from the target data sequence based on whether the Front2 field and / or Next2 field have values; the first key and key encrypted data can also be distinguished from the data in the target data sequence other than the second encrypted data block based on whether the DecryptColor field has a value, thereby obtaining all the key encrypted data.
[0216] This application obtains all key-encrypted data, locates target key-encrypted data based on the color identifier corresponding to the decryption key, and the decryption key is either a first key or a decrypted second key. It then uses the decryption key to decrypt the target key-encrypted data to obtain the corresponding second key. The second key is then used as the decryption key, and the process of locating the target key-encrypted data based on the color identifier corresponding to the decryption key is repeated until all second keys are obtained. The second key is then used to decrypt the second encrypted data block to obtain the first encrypted data block. After obtaining all the first encrypted data blocks, the first encrypted data blocks are concatenated based on the segmentation order identifier contained in the second auxiliary data to obtain the first encrypted data. The first encrypted data is then decrypted using the first key to obtain the data to be encrypted. This application requires decrypting the key-encrypted data before decrypting the second encrypted data block, making the decryption process more complex and further increasing the difficulty of cracking, thus ensuring data security.
[0217] Example 5:
[0218] Please see Figure 6 , Figure 6 A schematic structure of a data encryption device provided in this application is shown. For ease of explanation, only the parts relevant to the embodiments of this application are shown in the figure.
[0219] Reference Figure 6 The device includes a first encryption module 61, a segmentation module 62, and a second encryption module 63; the specific functions of each module are as follows:
[0220] The first encryption module 61 is used to encrypt the data to be encrypted using the first key to obtain the first encrypted data.
[0221] The segmentation module 62 is used to segment the first encrypted data to obtain at least two first encrypted data blocks; each first encrypted data block corresponds to first auxiliary data, and the first auxiliary data contains the segmentation order identifier of the corresponding first encrypted data block, which is used to indicate the position of the first encrypted data block in the first encrypted data;
[0222] The second encryption module 63 is used to obtain the second key corresponding to each first encrypted data block; to encrypt the corresponding first encrypted data block using the second key to obtain the second encrypted data block; and to record the color identifier corresponding to the second key in the first auxiliary data to obtain the second auxiliary data corresponding to the second encrypted data block. The second auxiliary data is used to decrypt the second encrypted data block.
[0223] The first key corresponds to first key auxiliary data, which includes a color identifier that matches the first key. Optionally, the second encryption module 63 is specifically used to: obtain a second key corresponding to each first encrypted data block from at least two candidate keys, wherein the color identifier corresponding to each candidate key is different from the color identifier corresponding to the first key, and the second key corresponds to second key auxiliary data, which includes a color identifier that matches the second key.
[0224] The device also includes a third encryption module, which is used for:
[0225] After obtaining the second key corresponding to each first encrypted data block, a second key set is obtained based on the second key corresponding to each first encrypted data block;
[0226] Furthermore, after encrypting the corresponding first encrypted data block using the second key to obtain the second encrypted data block, a first target key corresponding to the second key is determined based on the first key and the unencrypted key. The unencrypted key is an unencrypted key in the second key set that has a different color identifier than the second key. The second key is then encrypted using the first target key to obtain key encrypted data. The color identifier corresponding to the first target key is recorded in the corresponding second key auxiliary data to obtain third key auxiliary data corresponding to the key encrypted data. The third key auxiliary data is used to decrypt the key encrypted data.
[0227] Optionally, the device further includes a fourth encryption module, which is used for:
[0228] After encrypting the corresponding first encrypted data block using the second key to obtain the second encrypted data block, the second key is split to obtain at least two first key blocks. Each first key block corresponds to a fourth key auxiliary data, which includes the color identifier and splitting order identifier corresponding to the first key block.
[0229] Based on the first key and the unencrypted key, determine the second target key corresponding to the first key block;
[0230] The first key block is encrypted using the second target key to obtain encrypted key block data. The color identifier corresponding to the second target key is recorded in the corresponding fourth key auxiliary data to obtain the fifth key auxiliary data corresponding to the encrypted key block data. The fifth key auxiliary data is used to decrypt the encrypted key block data.
[0231] Optionally, determining the second target key corresponding to the first key block based on the first key and the unencrypted key includes: splitting the first key to obtain at least two second key blocks; selecting the second target key from the at least two second key blocks and the unencrypted first key block corresponding to the unencrypted key; and recording the color identifier corresponding to the second target key in the corresponding fourth key auxiliary data to obtain the fifth key auxiliary data corresponding to the key block encrypted data, including: recording the color identifier and the splitting order identifier corresponding to the second target key in the corresponding fourth key auxiliary data to obtain the fifth key auxiliary data.
[0232] Optionally, the device further includes a location recording module, which is used for:
[0233] Based on the first key, the second key, and all the second encrypted data blocks, a target data sequence is determined. Each target data in the target data sequence has a corresponding storage location. The target data is any data in the first key, the second key, and the second encrypted data block.
[0234] For each target data in the target data sequence, a first storage location is recorded in the corresponding target auxiliary data; the first storage location is the storage location of other target data adjacent to the target data in the target data sequence, and is used to obtain other target data based on the first storage location when the target data of the target data is obtained.
[0235] For each key data in the target data sequence, a second storage location is recorded in the corresponding key auxiliary data. The key data is either the first key or the second key. The second storage location is the storage location of other key data adjacent to the key data in the target data sequence, and is used to identify the key data in the target data sequence.
[0236] The data encryption device provided in this application embodiment can be applied in the aforementioned method embodiment one and embodiment two. For details, please refer to the description of the aforementioned method embodiment one and embodiment two, which will not be repeated here.
[0237] Example 6:
[0238] Please see Figure 7 , Figure 7 The figure illustrates a schematic structure of a data decryption apparatus provided in this application. For ease of explanation, only the parts relevant to the embodiments of this application are shown in the figure.
[0239] Reference Figure 7 The device includes a data acquisition module 71, a key determination module 72, a first decryption module 73, a splicing module 74, and a second decryption module 75; the specific functions of each module are as follows:
[0240] The data acquisition module 71 is used to acquire a second encrypted data block, which is an encrypted data block obtained by encrypting the first encrypted data block. The second encrypted data block has corresponding second auxiliary data, which includes the segmentation order identifier of the second encrypted data block and the color identifier of the second key used to encrypt the first encrypted data block.
[0241] The key determination module 71 is used to determine the second key corresponding to the second encrypted data block based on the color identifier contained in the second auxiliary data;
[0242] The first decryption module 73 is used to decrypt the second encrypted data block using the second key to obtain the first encrypted data block;
[0243] The splicing module 74 is used to splice the first encrypted data blocks based on the segmentation order identifier contained in the second auxiliary data after obtaining all the first encrypted data blocks, so as to obtain the first encrypted data.
[0244] The second decryption module 75 is used to decrypt the first encrypted data using the first key to obtain the data to be encrypted.
[0245] Optionally, the device further includes a first key acquisition module, which is used for:
[0246] Before determining the second key corresponding to the second encrypted data block based on the color identifier contained in the second auxiliary data, all key encryption data is obtained. The key encryption data is the encrypted data obtained after encrypting the second key. The key encryption data corresponds to third key auxiliary data. The third key auxiliary data contains the color identifier corresponding to the second key and the color identifier corresponding to the first target key. The first target key is the key used to encrypt the second key.
[0247] Based on the color identifier corresponding to the decryption key, the target key encrypted data is searched. The color identifier of the first target key corresponding to the target key encrypted data is the same as the color identifier corresponding to the decryption key. The decryption key is the first key or the decrypted second key. The first key corresponds to first key auxiliary data, which contains a color identifier that matches the first key.
[0248] The target key encrypted data is decrypted using the decryption key to obtain the corresponding second key;
[0249] The second key is determined as the decryption key, and the process returns to the step of searching for the target key encrypted data based on the color identifier corresponding to the decryption key, until all the second keys are obtained.
[0250] Optionally, the device further includes a second key acquisition module, which is used for:
[0251] Before determining the second key corresponding to the second encrypted data block based on the color identifier contained in the second auxiliary data, all key block encrypted data is obtained. The key block encrypted data is the encrypted data obtained after encrypting the first key block. The first key block is the key block obtained after splitting the second key. The key block encrypted data corresponds to the fifth key auxiliary data. The fifth key auxiliary data includes the color identifier corresponding to the first key block, the splitting order identifier, and the color identifier of the second target key. The second target key is the key used to encrypt the first key block.
[0252] Based on the color identifier corresponding to the decryption key, the target key block encrypted data is located. The color identifier of the second target key corresponding to the target key block encrypted data is the same as the color identifier corresponding to the decryption key.
[0253] The encrypted data of the target key block is decrypted using the decryption key to obtain the corresponding first key block;
[0254] Based on the segmentation order identifier, the first key blocks with the same color identifier are concatenated to obtain the second key;
[0255] The second key is determined as the decryption key, and the process returns to the step of searching for the target key block encrypted data based on the color identifier corresponding to the decryption key, until all the second keys are obtained.
[0256] If the fifth key auxiliary data includes a segmentation order identifier for the second target key, and the second target key is either a second key block obtained by segmenting the first key or a first key block obtained by segmenting the second key, optionally, the device further includes a third key acquisition module, which is used for:
[0257] After obtaining all the encrypted data of the key blocks, based on the color identifier and segmentation order identifier corresponding to the decryption key block, the encrypted data of the target key block is found. The color identifier of the second target key corresponding to the encrypted data of the target key block is the same as the color identifier corresponding to the decryption key block, and the segmentation order identifier of the second target key is the same as the segmentation order identifier corresponding to the decryption key block. The decryption key block is either the second key block or the decrypted first key block.
[0258] The encrypted data of the target key block is decrypted using the decryption key block to obtain the corresponding first key block;
[0259] The first key block is identified as the decryption key block, and the process returns to the step of searching for the encrypted data of the target key block based on the color identifier and segmentation order identifier corresponding to the decryption key block, until all the first key blocks are obtained;
[0260] Based on the segmentation order identifier, the first key blocks with the same color identifier are concatenated to obtain the corresponding second key.
[0261] Optionally, the device further includes a data sequence acquisition module, which is used for:
[0262] Before obtaining the second encrypted data block, target data is obtained. Target data is any data contained in the target data sequence. Target data corresponds to target auxiliary data. The target auxiliary data records a first storage location. The first storage location is the storage location of other target data adjacent to the target data in the target data sequence. The target data sequence contains a first key, a second key, and all of the second encrypted data blocks.
[0263] Retrieve other target data based on their storage locations;
[0264] Based on the first storage location recorded in the target auxiliary data corresponding to other target data, obtain the neighboring target data that is adjacent to the other target data.
[0265] If adjacent target data is identified as other target data, return to the first storage location recorded in the target auxiliary data corresponding to the other target data, and obtain the adjacent target data adjacent to the other target data, until the target data sequence is obtained.
[0266] The data decryption device provided in this application embodiment can be applied in the aforementioned method embodiments three and four. For details, please refer to the description of the aforementioned method embodiments three and four, which will not be repeated here.
[0267] Example 7:
[0268] Please see Figure 8 , Figure 8 The schematic structure of a terminal device according to an embodiment of this application is shown. The terminal device 8 of this embodiment includes: at least one processor 80 ( Figure 8 The above describes a data encryption method (only one is shown in the image), a memory 81, and a computer program 82 stored in the memory 81 and executable on the at least one processor 80. When the processor 80 executes the computer program 82, it implements the steps of a data encryption method in Embodiments 1 and 2 or the steps of a data decryption method in Embodiments 3 and 4.
[0269] The terminal device 8 can be a desktop computer, laptop, handheld computer, cloud server, or other computing device. The terminal device 8 may include, but is not limited to, a processor 80 and a memory 81. Those skilled in the art will understand that... Figure 8 This is merely an example of terminal device 8 and does not constitute a limitation on terminal device 8. It may include more or fewer components than shown in the figure, or combine certain components, or different components, such as input / output devices, network access devices, etc.
[0270] The processor 80 may be a Central Processing Unit (CPU), or it may be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor.
[0271] In some embodiments, the memory 81 may be an internal storage unit of the terminal device 8, such as a hard disk or memory of the terminal device 8. In other embodiments, the memory 81 may be an external storage device of the terminal device 8, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, etc., equipped on the terminal device 8. Furthermore, the memory 81 may include both internal and external storage units of the terminal device 8. The memory 81 is used to store the operating system, applications, bootloader, data, and other programs, such as the program code of the computer program. The memory 81 can also be used to temporarily store data that has been output or will be output.
[0272] It should be noted that the information interaction and execution process between the above-mentioned devices / units are based on the same concept as the method embodiments of this application. For details on their specific functions and technical effects, please refer to the method embodiments section, and they will not be repeated here.
[0273] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is merely an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiments can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit. Furthermore, the specific names of the functional units and modules are only for easy differentiation and are not intended to limit the scope of protection of this application. The specific working process of the units and modules in the above system can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0274] This application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps described in the various method embodiments above.
[0275] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments of this application can be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include at least: any entity or device capable of carrying computer program code to a terminal device, a recording medium, a computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media. Examples include USB flash drives, portable hard drives, magnetic disks, or optical disks. In some jurisdictions, according to legislation and patent practice, computer-readable media cannot be electrical carrier signals or telecommunication signals.
[0276] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0277] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0278] In the embodiments provided in this application, it should be understood that the disclosed devices / terminal equipment and methods can be implemented in other ways. For example, the device / terminal equipment embodiments described above are merely illustrative. For instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling or direct coupling or communication connection may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.
[0279] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0280] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included within the protection scope of this application.
Claims
1. A data encryption method, characterized in that, The method includes: The data to be encrypted is encrypted using the first key to obtain the first encrypted data; The first encrypted data is divided into at least two first encrypted data blocks; each first encrypted data block corresponds to first auxiliary data, and the first auxiliary data contains the division order identifier of the corresponding first encrypted data block, the division order identifier being used to indicate the position of the first encrypted data block in the first encrypted data; Obtain the second key corresponding to each of the first encrypted data blocks; encrypt the corresponding first encrypted data block using the second key to obtain the second encrypted data block, and record the color identifier corresponding to the second key in the first auxiliary data to obtain the second auxiliary data corresponding to the second encrypted data block. The second auxiliary data is used to decrypt the second encrypted data block. After encrypting the corresponding first encrypted data block using the second key to obtain the second encrypted data block, the method further includes: Based on the first key and the unencrypted key, a first target key corresponding to the second key is determined; the unencrypted key has a different color code than the second key. The second key is encrypted using the first target key to obtain encrypted key data; The color identifier of the first target key is recorded in the second key auxiliary data corresponding to the second key, and the third key auxiliary data corresponding to the key encryption data is obtained. The third key auxiliary data is used to decrypt the key encryption data.
2. The method as described in claim 1, characterized in that, The first key corresponds to first key auxiliary data, which includes a color identifier that matches the first key. Obtaining the second key corresponding to each of the first encrypted data blocks includes: From at least two candidate keys, obtain the second key corresponding to each of the first encrypted data blocks, wherein the color identifier corresponding to each candidate key is different from the color identifier corresponding to the first key, and the second key auxiliary data contains a color identifier that matches the second key; After obtaining the second key corresponding to each of the first encrypted data blocks, the method further includes: A second key set is obtained based on the second key corresponding to each of the first encrypted data blocks; The unencrypted key is a key in the second key set that has a different color identifier than the second key and is not encrypted.
3. The method as described in claim 2, characterized in that, After encrypting the corresponding first encrypted data block using the second key to obtain the second encrypted data block, the method further includes: The second key is divided to obtain at least two first key blocks. Each first key block corresponds to fourth key auxiliary data. The fourth key auxiliary data includes the color identifier and the division order identifier corresponding to the first key block. Based on the first key and the unencrypted key, determine the second target key corresponding to the first key block; The first key block is encrypted using the second target key to obtain encrypted key block data. The color identifier corresponding to the second target key is recorded in the corresponding fourth key auxiliary data to obtain the fifth key auxiliary data corresponding to the encrypted key block data. The fifth key auxiliary data is used to decrypt the encrypted key block data.
4. The method as described in claim 3, characterized in that, The step of determining the second target key corresponding to the first key block based on the first key and the unencrypted key includes: The first key is split to obtain at least two second key blocks; The second target key is selected from at least two second key blocks and the unencrypted first key block corresponding to the unencrypted key; The step of recording the color identifier corresponding to the second target key in the corresponding fourth key auxiliary data to obtain the fifth key auxiliary data corresponding to the key block encryption data includes: The color identifier and segmentation order identifier corresponding to the second target key are recorded in the corresponding fourth key auxiliary data to obtain the fifth key auxiliary data.
5. The method as described in claim 1, characterized in that, The method further includes: Based on the first key, the second key, and all of the second encrypted data blocks, a target data sequence is determined. Each target data in the target data sequence corresponds to a storage location. The target data is any data in the first key, the second key, and the second encrypted data block. For each target data in the target data sequence, a first storage location is recorded in the corresponding target auxiliary data; the first storage location is the storage location of other target data adjacent to the target data in the target data sequence, and is used to obtain the other target data based on the first storage location when the target data of the corresponding target data is obtained. For each key data in the target data sequence, a second storage location is recorded in the corresponding key auxiliary data, wherein the key data is either the first key or the second key; the second storage location is the storage location of other key data adjacent to the key data in the target data sequence, used to identify the key data in the target data sequence.
6. A data decryption method, characterized in that, It is used to decrypt data encrypted by the encryption method according to any one of claims 1-5; the method includes: Obtain a second encrypted data block, which is an encrypted data block obtained after encrypting the first encrypted data block. The second encrypted data block has corresponding second auxiliary data, which includes the segmentation order identifier of the second encrypted data block and the color identifier of the second key used to encrypt the first encrypted data block. Based on the color identifiers contained in the second auxiliary data, the second key corresponding to the second encrypted data block is determined; Using the second key, the second encrypted data block is decrypted to obtain the first encrypted data block; After obtaining all of the first encrypted data blocks, the first encrypted data blocks are concatenated based on the segmentation order identifier contained in the second auxiliary data to obtain the first encrypted data. The first encrypted data is decrypted using the first key to obtain the data to be encrypted.
7. The method as described in claim 6, characterized in that, The first key corresponds to first key auxiliary data, which includes a color identifier that matches the first key. Before determining the second key corresponding to the second encrypted data block based on the color identifier contained in the second auxiliary data, the process includes: Obtain all key encryption data, wherein the key encryption data is the encrypted data obtained after encrypting the second key, and the key encryption data corresponds to third key auxiliary data, wherein the third key auxiliary data includes the color identifier corresponding to the second key and the color identifier corresponding to the first target key, and the first target key is the key used to encrypt the second key; Based on the color identifier corresponding to the decryption key, the target key encrypted data is located. The color identifier of the first target key corresponding to the target key encrypted data is the same as the color identifier corresponding to the decryption key. The decryption key is the first key or the decrypted second key. The target key encrypted data is decrypted using the decryption key to obtain the corresponding second key; The second key is determined as the decryption key, and the process returns to the step of searching for the target key encrypted data based on the color identifier corresponding to the decryption key, until all of the second key is obtained.
8. The method as described in claim 7, characterized in that, Before determining the second key corresponding to the second encrypted data block based on the color identifier contained in the second auxiliary data, the method further includes: Obtain all key block encrypted data. The key block encrypted data is the encrypted data obtained after encrypting the first key block. The first key block is the key block obtained after splitting the second key. The key block encrypted data corresponds to fifth key auxiliary data. The fifth key auxiliary data includes the color identifier, splitting order identifier and color identifier of the second target key corresponding to the first key block. The second target key is the key used to encrypt the first key block. Based on the color identifier corresponding to the decryption key, the target key block encrypted data is located, and the color identifier of the second target key corresponding to the target key block encrypted data is the same as the color identifier corresponding to the decryption key. The encrypted data of the target key block is decrypted using the decryption key to obtain the corresponding first key block; Based on the segmentation order identifier, the first key blocks with the same color identifier are concatenated to obtain the second key; The second key is determined as the decryption key, and the process returns to the step of finding the target key block encrypted data based on the color identifier corresponding to the decryption key, until all the second keys are obtained.
9. The method as described in claim 8, characterized in that, If the fifth key auxiliary data includes a segmentation order identifier of the second target key, and the second target key is either a second key block obtained by segmenting the first key or a first key block obtained by segmenting the second key, then after obtaining all the key block encryption data, the method further includes: Based on the color identifier and segmentation order identifier corresponding to the decryption key block, the encrypted data of the target key block is found. The color identifier of the second target key corresponding to the encrypted data of the target key block is the same as the color identifier corresponding to the decryption key block, and the segmentation order identifier of the second target key is the same as the segmentation order identifier corresponding to the decryption key block. The decryption key block is either the second key block or the decrypted first key block. The encrypted data of the target key block is decrypted using the decryption key block to obtain the corresponding first key block; The first key block is identified as the decryption key block, and the process returns to the step of searching for the target key block encrypted data based on the color identifier and segmentation order identifier corresponding to the decryption key block, until all the first key blocks are obtained; Based on the segmentation order identifier, the first key blocks with the same color identifier are concatenated to obtain the corresponding second key.
10. The method as described in claim 6, characterized in that, Before obtaining the second encrypted data block, the process includes: Obtain target data, wherein the target data is any data contained in the target data sequence, the target data corresponds to target auxiliary data, the target auxiliary data records a first storage location, the first storage location is the storage location of other target data adjacent to the target data in the target data sequence, and the target data sequence contains a first key, a second key and all of the second encrypted data blocks; Based on the storage location of the other target data, obtain the other target data; Based on the first storage location recorded in the target auxiliary data corresponding to the other target data, obtain the adjacent target data that is adjacent to the other target data. The adjacent target data is identified as the other target data, and the process returns to the step of obtaining the adjacent target data adjacent to the other target data based on the first storage location recorded in the target auxiliary data corresponding to the other target data, until the target data sequence is obtained.
11. A data encryption device, characterized in that, The device includes: The first encryption module is used to encrypt the data to be encrypted using the first key to obtain the first encrypted data. The segmentation module is used to segment the first encrypted data to obtain at least two first encrypted data blocks; each first encrypted data block corresponds to first auxiliary data, and the first auxiliary data contains the segmentation order identifier of the corresponding first encrypted data block, the segmentation order identifier being used to indicate the position of the first encrypted data block in the first encrypted data; The second encryption module is used to obtain the second key corresponding to each of the first encrypted data blocks; to encrypt the corresponding first encrypted data block using the second key to obtain the second encrypted data block; and to record the color identifier corresponding to the second key in the first auxiliary data to obtain the second auxiliary data corresponding to the second encrypted data block. The second auxiliary data is used to decrypt the second encrypted data block. The data encryption device further includes a third encryption module, which is used to determine a first target key corresponding to the second key based on the first key and the unencrypted key; the unencrypted key has a different color identifier than the second key. The second key is encrypted using the first target key to obtain encrypted key data; The color identifier of the first target key is recorded in the second key auxiliary data corresponding to the second key, and the third key auxiliary data corresponding to the key encryption data is obtained. The third key auxiliary data is used to decrypt the key encryption data.
12. A data decryption device, characterized in that, It is used to decrypt data encrypted by the encryption method according to any one of claims 1-5; the apparatus includes: The data acquisition module is used to acquire a second encrypted data block, which is an encrypted data block obtained by encrypting the first encrypted data block. The second encrypted data block has corresponding second auxiliary data, which includes the segmentation order identifier of the second encrypted data block and the color identifier of the second key used to encrypt the first encrypted data block. The key determination module is used to determine the second key corresponding to the second encrypted data block based on the color identifier contained in the second auxiliary data; The first decryption module is used to decrypt the second encrypted data block using the second key to obtain the first encrypted data block; The splicing module is used to splice the first encrypted data blocks based on the segmentation order identifier contained in the second auxiliary data after obtaining all the first encrypted data blocks, so as to obtain the first encrypted data. The second decryption module is used to decrypt the first encrypted data using the first key to obtain the data to be encrypted.
13. A terminal device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the method as described in any one of claims 1 to 10.
14. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the method as described in any one of claims 1 to 10.
Citation Information
Patent Citations
Information processing system and method, information processing device and method, and program
CN1993975A