Ciphertext transmission method and device based on information hiding
By generating and processing certificates containing preset natural numbers, the encrypted information is hidden in the host data and extracted, which solves the problems of insufficient information hiding capacity and high leakage risk in the existing technology and realizes high-capacity, low-risk information transmission.
Patent Information
- Application Number
- CN202310520342.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-05-09
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2043-05-09
AI Technical Summary
Existing information hiding technologies have limited capacity, poor deceptiveness, and high risk of information leakage in multimedia information transmission, and cannot meet the needs of big data hidden transmission.
A certificate including a preset number of consecutive natural numbers is generated by a certificate authority. The sender and receiver servers unpack the certificate and divide it into multiple sub-matrices. A first reference matrix, multiple first sub-matrices, and a second reference matrix are used to hide the ciphertext information in the host data, and the ciphertext information is extracted from the host data through these matrices.
It improves the capacity of information hiding, reduces the risk of information leakage, and increases the confusingness and concealment of information hiding.
Smart Images

Figure CN116366368B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular to a ciphertext transmission method and device based on information hiding. Background Art
[0002] This section is intended to provide a background or context to the embodiments of the invention that are recited in the claims. No statement herein is admitted to be prior art by virtue of its inclusion in this section.
[0003] Information hiding is a new technology to ensure information security. The system embeds specific information into a digital host data stream (such as text, digital sound, image, video signal, etc.) to ensure that the hidden information does not attract the attention of hackers and other monitors as much as possible.
[0004] Since the introduction of the least significant bit (LSB) algorithm, various related improved algorithms have emerged. For example, the EMD algorithm was proposed, which hides a (2n+1)-base digital information by modifying the original pixel value of at most one of n image pixels. This algorithm can hide an average of 1.5 bits of information per pixel. Subsequently, this EMD algorithm has been improved, and the improved EMD algorithm (i.e., EMD-2 algorithm) has a hiding capacity of 1.585 bits per pixel. However, with the development of the multimedia era, the amount of multimedia information transmitted over the network has become increasingly large, while the hiding capacity of existing algorithms is limited and cannot meet the requirements of today's big data hiding and transmission. Furthermore, with the rapid development of information transmission technology, existing information hiding technologies have poor obfuscation capabilities and a high risk of information leakage. Summary of the Invention
[0005] An embodiment of the present invention provides a ciphertext transmission method based on information hiding, which is applied to a sending server to reduce the risk of information leakage, increase the obfuscation and confidentiality of information hiding, and improve the information hiding capacity. The method includes:
[0006] Sending a certificate acquisition request to an authentication group server to which a certificate issuing authority belongs, so that the authentication group server: after verifying and recording the sender user information and the recipient user information according to the certificate acquisition request, generates a certificate, and sends the certificate to the sender server and the recipient server; the certificate includes a plurality of preset consecutive natural numbers;
[0007] Receive the certificate sent by the authentication group server;
[0008] Unpacking the certificate to obtain a first reference matrix; any element in the first reference matrix is one of a plurality of preset consecutive natural numbers;
[0009] Dividing the first reference matrix into a plurality of first sub-matrices according to a first preset length and width threshold; wherein any two elements in the first sub-matrices are different;
[0010] Take the central elements of all first sub-matrices to generate a second reference matrix;
[0011] Obtaining host data used to hide ciphertext information and the ciphertext information to be hidden;
[0012] Hiding the ciphertext information in the host data using a first reference matrix, a plurality of first sub-matrices, and a second reference matrix to obtain the host data hiding the ciphertext information;
[0013] Send the host data with hidden ciphertext information to the receiving server.
[0014] An embodiment of the present invention provides a ciphertext transmission method based on information hiding, which is applied to a receiving server to reduce the risk of information leakage, increase the obfuscation and confidentiality of information hiding, and improve the information hiding capacity. The method includes:
[0015] Receive a certificate sent by an authentication group server to which a certificate issuing authority belongs; the certificate is generated by the authentication group server after verifying and recording the sender user information and the receiver user information according to the certificate acquisition request sent by the sender server; the certificate includes a plurality of preset consecutive natural numbers;
[0016] Unpacking the certificate to obtain a first reference matrix; any element in the first reference matrix is one of a plurality of preset consecutive natural numbers;
[0017] Dividing the first reference matrix into a plurality of first sub-matrices according to a first preset length and width threshold; wherein any two elements in the first sub-matrices are different;
[0018] Receiving host data with hidden ciphertext information sent by a sending server; the ciphertext information is hidden in the host data through a first reference matrix, a plurality of first sub-matrices, and a second reference matrix;
[0019] Ciphertext information is extracted from host data using the first reference matrix, the plurality of first sub-matrices, and the second reference matrix.
[0020] An embodiment of the present invention provides a ciphertext transmission device based on information hiding, which is applied to a sending server to reduce the risk of information leakage, increase the obfuscation and confidentiality of information hiding, and improve the information hiding capacity. The device includes:
[0021] A certificate acquisition module is configured to send a certificate acquisition request to an authentication group server to which a certificate issuing authority belongs, so that the authentication group server: after verifying and recording the sender user information and the receiver user information according to the certificate acquisition request, generates a certificate and sends the certificate to the sender server and the receiver server; the certificate includes a plurality of preset consecutive natural numbers;
[0022] A first certificate receiving module, configured to receive a certificate sent by an authentication group server;
[0023] a first certificate processing module configured to unpack the certificate to obtain a first reference matrix; wherein any element in the first reference matrix is one of a plurality of preset consecutive natural numbers; divide the first reference matrix into a plurality of first sub-matrices according to a first preset length and width threshold; wherein any two elements in the first sub-matrices are different; and take the central elements of all the first sub-matrices to generate a second reference matrix;
[0024] A ciphertext and host acquisition module, used to obtain host data used to hide ciphertext information and ciphertext information to be hidden;
[0025] An information hiding module, configured to hide the ciphertext information in the host data using a first reference matrix, a plurality of first sub-matrices, and a second reference matrix, to obtain the host data hiding the ciphertext information;
[0026] The ciphertext sending module is used to send the host data with hidden ciphertext information to the receiving server.
[0027] An embodiment of the present invention provides a ciphertext transmission device based on information hiding, which is applied to a receiving server to reduce the risk of information leakage, increase the obfuscation and confidentiality of information hiding, and improve the information hiding capacity. The device includes:
[0028] A second certificate receiving module is configured to receive a certificate sent by an authentication group server to which a certificate issuing authority belongs; the certificate is generated by the authentication group server after verifying and recording the sender user information and the receiver user information according to a certificate acquisition request sent by the sender server; the certificate includes a plurality of preset consecutive natural numbers;
[0029] a second certificate processing module configured to unpack the certificate to obtain a first reference matrix; wherein any element in the first reference matrix is one of a plurality of preset consecutive natural numbers; divide the first reference matrix into a plurality of first sub-matrices according to a first preset length and width threshold; wherein any two elements in the first sub-matrices are different; and take the central elements of all the first sub-matrices to generate a second reference matrix;
[0030] A ciphertext receiving module, configured to receive host data containing hidden ciphertext information sent by a sending server; the ciphertext information is hidden in the host data using a first reference matrix, a plurality of first sub-matrices, and a second reference matrix;
[0031] The ciphertext decryption module is used to extract ciphertext information from the host data using the first reference matrix, the plurality of first sub-matrices and the second reference matrix.
[0032] An embodiment of the present invention further provides a computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the above-mentioned ciphertext transmission method based on information hiding when executing the computer program.
[0033] An embodiment of the present invention further provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the computer program implements the above-mentioned ciphertext transmission method based on information hiding.
[0034] An embodiment of the present invention further provides a computer program product, which includes a computer program. When the computer program is executed by a processor, the computer program implements the above-mentioned ciphertext transmission method based on information hiding.
[0035] In an embodiment of the present invention, a certificate is generated by an authentication group server to which a certificate issuing authority belongs. The certificate includes a preset plurality of consecutive natural numbers. After the sending server receives the certificate, it unpacks the certificate to obtain a first reference matrix, wherein any element in the first reference matrix is one of the preset plurality of consecutive natural numbers. The first reference matrix is used to obtain a plurality of first sub-matrices and a second reference matrix, and the first reference matrix, the plurality of first sub-matrices, and the second reference matrix are used to hide all ciphertext information in the host data. In this example, the first reference matrix is divided into a plurality of first sub-matrices according to a first preset length and width threshold, and any two elements in the first sub-matrices are different, which can increase the information hiding capacity. The first reference matrix, the plurality of first sub-matrices, and the second reference matrix are used to hide all ciphertext information in the host data, thereby reducing the risk of information leakage and increasing the obfuscation and confidentiality of the information hiding.
[0036] In an embodiment of the present invention, a certificate is generated by an authentication group server to which a certificate issuing authority belongs. The certificate includes a plurality of preset consecutive natural numbers. After receiving the certificate, a receiving server unpacks the certificate to obtain a first reference matrix, wherein any element in the first reference matrix is one of the plurality of preset consecutive natural numbers. The first reference matrix is used to obtain a plurality of first sub-matrices and a second reference matrix. Host data containing hidden ciphertext information is received from a sending server. The ciphertext information is hidden within the host data using the first reference matrix, the plurality of first sub-matrices, and the second reference matrix. The ciphertext information is extracted from the host data using the first reference matrix, the plurality of first sub-matrices, and the second reference matrix. In this example, the first reference matrix is divided into a plurality of first sub-matrices according to a first preset length and width threshold, and any two elements in the first sub-matrices are different, thereby increasing the information hiding capacity. Furthermore, the first reference matrix, the plurality of first sub-matrices, and the second reference matrix are used to completely hide the ciphertext information within the host data, thereby reducing the risk of information leakage and increasing the obfuscation and confidentiality of the information hiding. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative work. In the drawings:
[0038] Figure 1 1. A schematic diagram of a flow chart of a ciphertext transmission method based on information hiding in an embodiment of the present invention, applied to a sending server;
[0039] Figure 2 4 is a structural diagram of a ciphertext transmission system based on information hiding in an embodiment of the present invention;
[0040] Figure 3 1 is a structural diagram of a Web service node in a ciphertext transmission system based on information hiding in an embodiment of the present invention;
[0041] Figure 4 2 is a structural diagram of an authentication group server in a ciphertext transmission system based on information hiding in an embodiment of the present invention;
[0042] Figure 5 is a schematic diagram of a first reference matrix in an embodiment of the present invention;
[0043] Figure 6 1 is a flow chart of a ciphertext transmission method based on information hiding according to an embodiment of the present invention, applied to a receiving server;
[0044] Figure 7This is a specific embodiment of the ciphertext transmission method based on information hiding in an embodiment of the present invention;
[0045] Figure 8 This is a schematic structural diagram of a ciphertext transmission device based on information hiding according to an embodiment of the present invention, applied to a sending server;
[0046] Figure 9 The figure is a schematic structural diagram of a ciphertext transmission device based on information hiding in an embodiment of the present invention, applied to a receiving server. DETAILED DESCRIPTION
[0047] To make the purpose, technical solutions and advantages of the embodiments of the present invention more clear, the embodiments of the present invention are further described in detail below with reference to the accompanying drawings. Here, the exemplary embodiments of the present invention and their descriptions are used to explain the present invention, but are not intended to limit the present invention.
[0048] The applicant discovered that with the development of the multimedia era, the amount of multimedia information transmitted over the network is becoming increasingly large, while the existing algorithms have limited hiding capacity and cannot meet the requirements of today's society for hiding and transmitting big data. Furthermore, with the rapid development of information transmission technology, existing information hiding technologies have poor obfuscation capabilities and a high risk of information leakage. Therefore, the applicant proposed a ciphertext transmission method based on information hiding.
[0049] It should be noted that the acquisition, storage, use, and processing of data in the technical solution of this application comply with the relevant provisions of national laws and regulations.
[0050] Figure 1 FIG. 1 is a flow chart of a ciphertext transmission method based on information hiding in an embodiment of the present invention, applied to a sending server. Figure 1 As shown, the method includes:
[0051] Step 101: Send a certificate acquisition request to an authentication group server to which a certificate issuing authority belongs, so that the authentication group server: after verifying and recording the sender user information and the receiver user information according to the certificate acquisition request, generates a certificate, and sends the certificate to the sender server and the receiver server; the certificate includes a plurality of preset consecutive natural numbers;
[0052] Step 102: Receive the certificate sent by the authentication group server;
[0053] Step 103: Unpack the certificate to obtain a first reference matrix; any element in the first reference matrix is one of a plurality of preset consecutive natural numbers;
[0054] Step 104: Divide the first reference matrix into a plurality of first sub-matrices according to a first preset length and width threshold; wherein any two elements in the first sub-matrices are different;
[0055] Step 105, taking the center elements of all the first sub-matrices to generate a second reference matrix;
[0056] Step 106, obtaining host data for hiding the ciphertext information and the ciphertext information to be hidden;
[0057] Step 107, hiding the ciphertext information into the host data by using the first reference matrix, the plurality of first sub-matrices and the second reference matrix to obtain the host data hiding the ciphertext information;
[0058] Step 108, sending the host data hiding the ciphertext information to the receiving server.
[0059] From Figure 1 As shown in the flowchart, in the embodiment of the present application, the certificate is generated by the authentication group server to which the certificate authority belongs, and the certificate includes a preset plurality of consecutive natural numbers. After the sender server receives the certificate, the first reference matrix is obtained by unpacking the certificate, any element in the first reference matrix is one of the preset plurality of consecutive natural numbers, the plurality of first sub-matrices and the second reference matrix are obtained by using the first reference matrix, and the ciphertext information is hidden into the host data by using the first reference matrix, the plurality of first sub-matrices and the second reference matrix. In this example, the first reference matrix is divided into a plurality of first sub-matrices according to the first preset length-width threshold, and any two elements in the first sub-matrix are different, which can improve the information hiding capacity, and the ciphertext information is hidden into the host data by using the first reference matrix, the plurality of first sub-matrices and the second reference matrix, which reduces the risk of information leakage and increases the information hiding confusion and concealment.
[0060] The information hiding-based ciphertext transmission method in the embodiment of the present application will be explained in detail below.
[0061] Firstly, the present application provides an information hiding-based ciphertext transmission system, Figure 2 The structure diagram of the information hiding-based ciphertext transmission system in the embodiment of the present application is shown in Figure 2 The system includes a Web client 1, a Web service node 1, a Web client 2, a Web service node 2 and an authentication group.
[0062] Among them, the Web client 1 and the Web client 2 are the sender and the receiver of the ciphertext transmission respectively, the Web service node 1 and the Web service node 2 are the sender server and the receiver server of the corresponding ciphertext transmission respectively, and are responsible for processing the business logic of the respective clients and running the information hiding algorithm. When the information hiding algorithm runs, both servers need to initiate an authentication request to the business server of the authentication group and obtain a certificate, and then encrypt, decrypt and transmit the ciphertext.
[0063] An authentication group is a server cluster consisting of one or more business servers and database servers. The business servers are responsible for executing certificate packaging, authentication, and sending and receiving logic, while the database servers are responsible for storing information about authorized users on both sides of the communication. Upon receiving an authentication request from a service node that requires communication using an information hiding algorithm, the business server interacts with the database server to register or verify the authentication information and decide whether to send the certificate to both service nodes.
[0064] Figure 3 FIG is a structural diagram of a Web service node in a ciphertext transmission system based on information hiding in an embodiment of the present invention. Figure 3 As shown, the Web service node includes a registration and authentication module 31, a business processing module 32, an information encryption module 33, an information decryption module 34, and a network communication module 35; wherein,
[0065] The registration and authentication module 31 is primarily responsible for interacting with the authentication group. When the Web service node is started and the information hiding function is determined to be used, the registration and authentication module 31 sends the user's own authentication information to the network communication module 35, which then submits it to the authentication group through a special encrypted channel and waits for the authentication group's response. Upon receiving the certificate from the authentication group through the network communication module 35, the module immediately transmits the certificate to the information encryption module 33 and the information decryption module 34, and notifies the business processing module 32 that the information hiding certificate has been obtained.
[0066] The business processing module 32 is mainly responsible for business processing of the Web client. The Web service node generates the ciphertext information to be transmitted through the business processing module 32. When the module receives the signal transmitted by the registration and authentication module 31, it can send all the ciphertext information to be transmitted to the information encryption module 33. When the module receives the decrypted ciphertext information transmitted from the information decryption module 34, it selects and executes the corresponding business logic based on the information content and transmits the result to the network communication module 35.
[0067] The information encryption module 33 is mainly responsible for executing the information hiding algorithm to hide the information in a multimedia message. This module will select a multimedia message from the database of the Web service node as the host for hiding the ciphertext information, including but not limited to pictures, videos, audio, etc. When this module receives the information to be processed from the business processing module 32 and the certificate transmitted by the registration and authentication module 31, it starts to execute the ciphertext information hiding algorithm;
[0068] The information extraction module 34 is mainly responsible for extracting ciphertext information and reconstructing multimedia information. After receiving the ciphertext information transmitted by the network communication module 35 and the certificate transmitted by the registration and authentication module 31, the module starts to execute the ciphertext information extraction algorithm to extract the relevant ciphertext information;
[0069] The network communication module 35 is the information entry and exit of the entire Web service node. It is mainly responsible for the communication between the Web service node and the Web client, the authentication group, and other Web service nodes. This module contains a special encrypted communication channel, which is responsible for interacting with the authentication group. At the same time, it interacts with the Web client and other Web service nodes through conventional communication channels.
[0070] Figure 4 FIG. 1 is a structural diagram of an authentication group server in a ciphertext transmission system based on information hiding in an embodiment of the present invention. Figure 4 As shown, the authentication group includes an authorization management module 41, an information storage module 42, a certificate generation module 43, and a network communication module 44; wherein,
[0071] The authorization management module 41 is mainly responsible for interacting with the information storage module 42 to record, analyze and verify the information of both users requesting encrypted communication and determine whether to grant certificates to both parties;
[0072] The information storage module 42 is mainly responsible for interacting with the authorization management module 41 to implement functions such as adding, deleting, modifying, and querying database information in the database server, and providing data support for the authorization management module 41 to execute certificate authentication logic;
[0073] The certificate generation module 43 is mainly responsible for designing and packaging the certificate. After the authorization management module 41 confirms that both users have been authorized, the certificate generation module starts designing and packaging the certificate and passes the packaged certificate to the network communication module 44.
[0074] The network communication module 44 is mainly responsible for receiving user information and sending certificates. In order to ensure the security of certificate transmission, this module can interact with each Web service node through a special encryption channel.
[0075] During the specific implementation of the embodiment of the present invention, in step 101, Web service node 1, i.e., the sender server, first sends a certificate acquisition request to the authentication group server to which the certificate issuing authority belongs; the authentication group server receives the certificate acquisition request, analyzes and verifies the sender user information and the receiver user information, and after the verification is passed, determines to grant certificates to both parties, records the information of both parties, and then sends the certificates to the sender server and the receiver server.
[0076] In the certificate generation module 43 of the authentication group server, the certificate is generated as follows:
[0077] 1. Authority confirmation: After confirming receipt of the authorization authentication consent information transmitted by the authorization management module 41 of the authentication group server, prepare to execute the certificate generation logic;
[0078] 2. Generate a base reference matrix: Generate a matrix based on a preset number of consecutive natural numbers, which is recorded as the base reference matrix. Each element in the base reference matrix is unique.
[0079] For example, the preset multiple consecutive natural numbers are 0 to 8, and the nine numbers 0 to 8 are randomly filled into the matrix (each number cannot be repeated), and finally the base reference matrix MatrixA is formed.
[0080] MatrixA schematic:
[0081] 3. Matrix expansion: Using each element in the base reference matrix as the center value, multiple sub-matrices are generated according to the first preset length and width thresholds. Each element in the sub-matrix is also taken from a preset number of consecutive natural numbers, and it is ensured that any two elements in the sub-matrix are different.
[0082] For example, for the above-mentioned base reference matrix MatrixA:
[0083] 3.1) Generate nine 3×3 sub-matrices box with each element of MatrixA as the center value, and the center element of box is denoted as box(1, 1);
[0084] 3.2) For each submatrix box, from the nine numbers 0-8, delete the values that match the central element box (1, 1) of the submatrix. Randomly fill the remaining eight numbers into the matrix (no numbers are repeated), and rearrange all the numbers according to the original position relationship of the central element box (1, 1) to obtain a 9×9 matrix box;
[0085] Box diagram:
[0086] 3.3) Duplicate the matrix Box 85 times horizontally and vertically to obtain a 258×258 matrix. Delete the two outer rows and two columns to form a 256×256 matrix Matrix, which is recorded as the first reference matrix.
[0087] In step 102, the sending server receives the certificate sent by the authentication group server. In steps 103, 104, and 105, the certificate is unsealed. Contrary to the certificate generation process in the authentication group server, the sending server unseales the certificate to obtain a first reference matrix; any element in the first reference matrix is one of a plurality of preset consecutive natural numbers; the first reference matrix is divided into a plurality of first sub-matrices according to a first preset length and width threshold; any two elements in the first sub-matrices are not the same; the central elements of all first sub-matrices are taken to generate a second reference matrix.
[0088] For example, for the first reference matrix Matrix generated by MatrixA in the authentication group server:
[0089] Step 1: The receiving server receives the certificate, unpacks it, and obtains a 256×256 first reference matrix Matrix, such as the one shown in the attached figure. Figure 5 As shown, Figure 5 is a schematic diagram of a first reference matrix in an embodiment of the present invention;
[0090] Step 2: Starting from the first element of Matrix, divide Matrix into multiple 3×3 small matrices, recorded as the first sub-matrix MatrixBox, and each element in MatrixBox is recorded as MatrixBox(i, j);
[0091] Step 3. Take the central elements of all MatrixBoxes and arrange them according to the positional relationship of the MatrixBoxes to which they belong to obtain a new matrix, which is recorded as the second reference matrix MatrixB. Each element in MatrixB is recorded as MatrixB(i, j).
[0092] Then, in step 106, the host data used to hide the ciphertext information and the ciphertext information to be hidden are obtained. For example, the ciphertext information to be hidden is obtained through the user's settings on the client, and a piece of host data, such as video, audio, or picture, is obtained from the database of the sending server.
[0093] Finally, the ciphertext information is hidden in the host data using the first reference matrix, multiple first sub-matrices and the second reference matrix to obtain the host data with hidden ciphertext information; and the host data with hidden ciphertext information is sent to the receiving server.
[0094] Taking a 512×512 image as an example, if all pixels are used, a maximum of 830,996 binary digits can be hidden using the information hiding method of an embodiment of the present invention. The hiding capacity is calculated according to the following formula, and the hiding capacity can reach 3.17 bpp, which can greatly improve the information hiding capacity.
[0095]
[0096] Where M is the number of bits of ciphertext information that the image can carry, and H and W are the sizes of the image.
[0097] In one embodiment, using a first reference matrix, a plurality of first sub-matrices, and a second reference matrix to hide the ciphertext information in the host data to obtain the host data hiding the ciphertext information may include:
[0098] Convert host data into host data stream P i , i is an integer;
[0099] Convert the ciphertext information into ciphertext data stream d according to the preset format rules i , i is an integer;
[0100] Repeat the following steps until the host data stream P i According to the entire ciphertext data stream d i , is replaced by the values of the horizontal and vertical coordinates of the first reference matrix, and the host data stream P with hidden ciphertext information is obtained. i ′:
[0101] From the host data stream P i Take the continuous data pairs at the preset position (P i ,P i+1 );
[0102] Take the ciphertext data stream d in order i The continuous data pairs (d i ,d i+1 );
[0103] (P i ,P i+1 ) are horizontal and vertical coordinates, and a first element is determined in the first reference matrix;
[0104] Determine the center element of the first submatrix mapped by the first element;
[0105] Determine a second element of a second reference matrix to which the central element of the first submatrix is mapped;
[0106] Taking the second element as the center element in the second reference matrix, dividing the matrix according to the first preset length and width threshold to obtain a second sub-matrix;
[0107] Find the same value as d in the second submatrix i Equal third element;
[0108] determining a first sub-matrix mapped by the third element in the first reference matrix;
[0109] In the first submatrix mapped by the third element in the first reference matrix, find the value that matches d i+1 The fourth element is equal to the first reference matrix, and the horizontal and vertical coordinates of the fourth element are determined;
[0110] The host data stream P i The continuous data pairs (P i ,P i+1 ), replaced by the values of the fourth element in the horizontal and vertical coordinates of the first reference matrix;
[0111] Let i=i+2;
[0112] Sending the host data with hidden ciphertext information to the receiving server may include:
[0113] The host data stream P that hides the ciphertext information i ’ is sent to the receiving server.
[0114] For example, continuing with the first reference matrix Matrix generated by MatrixA in the authentication group server, after obtaining the first reference matrix Matrix, a plurality of first sub-matrices MatrixBox, and the second reference matrix MatrixB:
[0115] Step 4: Convert the host data into a host data stream P i , i is an integer. No matter the host is a picture or other format such as video, the host data is converted into a host data stream to form a host matrix. In this example, a picture is used as an example;
[0116] Step 5: Convert the ciphertext information into ciphertext data stream d according to the preset format rules i , i is an integer; for example, the obtained ciphertext information is first converted into a binary data stream, and then converted into a non-ary data stream. If the number of digits after the conversion to non-ary is an odd number, it is stipulated that 1 is added to the last digit;
[0117] Step 6: Get the ciphertext data stream d in order i The continuous data pairs (d i ,d i+1 ), take two consecutive pixel pairs (P i ,P i+1 );
[0118] Step 7, with P i As the horizontal axis, P i+1 As the vertical coordinate, a unique element can be determined in the first reference matrix Matrix, which is recorded as Matrix(P i , P i+1 ), and Matrix(P i , P i+1) can be mapped to the MatrixBox to which it belongs, and then the coordinates of the center element MatrixBox (mbi, mbj) in the Matrix can be determined:
[0119]
[0120]
[0121] Step 8. According to MatrixBox (mbi, mbj), it can be uniquely mapped to a second element in MatrixB. The horizontal and vertical coordinates of the second element can be calculated according to the following formula, which is recorded as MatrixB (bi, bj):
[0122]
[0123]
[0124] Step 9: Divide MatrixB into a nine-square grid with MatrixB(bi,bj) as the central element. In the nine-square grid, there must be a unique element with d i The same value, that is, the third element, takes its coordinates as (flagi, flagj), that is, d i =MatrixB(flagi,flagj).
[0125] Step 10. According to the relationship between Matrix and MatrixB, MatrixB(flagi, flagj) can be uniquely mapped to a MatrixBox in Matrix and is equal to its center element. The coordinates of the center element are Matrix(mbi2, mbj2). The horizontal and vertical coordinate values can be obtained by the following formula:
[0126] mbi2=3flagi+1
[0127] mbj2=3flagj+1
[0128] In the MatrixBox with Matrix(mbi2,mbj2) as the center element, find the element with the same value as d i+1 The fourth element is equal to the first reference matrix Matrix, and the horizontal and vertical coordinates of the fourth element are determined;
[0129] Step 11: Host data stream P i The number of consecutive pixel pairs (P i ,P i+1 ), replaced by the value of the horizontal and vertical coordinates of the fourth element in the first reference matrix Matrix; at this time, the data pair (d i ,d i+1)Hidden;
[0130] Step 12: Let i = i + 2, and continue to execute steps 6 to 11 until all the ciphertext data streams d i It is hidden in the host image, and a host image with pixels replaced and hidden ciphertext information is obtained.
[0131] Since in the transformation process, the replaced pixel pairs (P i ,P i+1 ) is mapped in the first reference matrix, near the position where the fourth pixel is mapped in the first reference matrix, the host image P that hides the ciphertext information i ′ and the original host image P i It looks pretty similar and has good concealment.
[0132] In one embodiment, the horizontal and vertical width values of the first reference matrix cannot be divided evenly by the first preset length and width threshold;
[0133] After dividing the first reference matrix into a plurality of first sub-matrices according to the first preset length and width threshold, the method may further include:
[0134] A plurality of rows or columns at the boundary that cannot be assigned to the first sub-matrix remain in the first reference matrix;
[0135] For example, when the horizontal and vertical width values of the first reference matrix are 256×256 and the first preset length and width threshold is 3, if the submatrix is divided starting from the elements in the first row and first column of the first reference matrix, there will be one row and one column left that cannot be divided into the first submatrix.
[0136] Then (P i ,P i+1 ) are horizontal and vertical coordinates, determining a first element in the first reference matrix may include:
[0137] If the first element is located in a row or column at the boundary of the first reference matrix that cannot be assigned to the first sub-matrix, P i ,P i+1 Subtract the first threshold value respectively to subtract the data pair (P i ,P i+1 ) are the horizontal and vertical coordinates, and the first element is re-determined in the first reference matrix.
[0138] For example, when the horizontal and vertical width values of the first reference matrix are 256×256 and the first preset length and width threshold is 3, if the first element is located in the last row or the last column of the first reference matrix, that is, P i =255 or P i+1 =255, P i ,P i+1The value equal to 255 is subtracted by 1, which is equal to 254, and the first element is redetermined in the first reference matrix.
[0139] In one embodiment, taking the second element as the center element in the second reference matrix and dividing it according to the first preset length and width threshold to obtain the second sub-matrix may include:
[0140] If the second element is located in one of the first row, first column, last row, and last column of the second reference matrix, the second reference matrix is divided according to the first preset length and width threshold to obtain a third submatrix, wherein the second element is located in one of the first row, first column, last row, and last column of the third submatrix, or any combination thereof.
[0141] During implementation, when the second element is located in one of the first row, first column, last row, and last column of the second reference matrix, and it is impossible to draw a nine-square grid with it as the center element, for example, a unique square with d can be found in the nine-square grid where the second element is located. i The same value as the third element.
[0142] In one embodiment, the certificate has a validity period;
[0143] After receiving the certificate sent by the authentication group server, the following may also be included:
[0144] Validity period of the verification certificate;
[0145] If the certificate validity period has expired, resend the certificate acquisition request to the authentication group server;
[0146] Receive the certificate resent by the authentication group server.
[0147] For example, the authentication group server sets a time control module. After the certificate generation module 43 of the authentication group server generates a certificate, it sets a validity period for the certificate. The sending server verifies the validity period of the certificate. When the validity period expires, the time control module of the authentication group server interacts with the authorization management module 41, requesting the authorization management module 41 to recheck the user's authorization authentication status. Upon receiving the certificate acquisition request sent by the sending server, the certificate is regenerated. In this embodiment of the present invention, users are allowed to transmit ciphertext an unlimited number of times within the validity period of the certificate. Once the validity period of the certificate expires, the ciphertext transmission is terminated, thereby improving the security of the ciphertext transmission.
[0148] The embodiment of the present invention also provides a ciphertext transmission method based on information hiding using a receiver server. Figure 6 FIG. 1 is a flow chart of a ciphertext transmission method based on information hiding in an embodiment of the present invention, applied to a receiving server. Figure 6 As shown, the method includes:
[0149] Step 601, receiving a certificate sent by an authentication group server to which a certificate authority belongs; the certificate is generated by the authentication group server after verifying and recording a sender user information and a receiver user information according to a certificate acquisition request sent by a sender server; the certificate includes a plurality of preset consecutive natural numbers;
[0150] Step 602, performing a disassembling process on the certificate to obtain a first reference matrix; any element in the first reference matrix is one of the plurality of preset consecutive natural numbers;
[0151] Step 603, dividing the first reference matrix into a plurality of first sub-matrices according to a first preset length-width threshold; any two elements in the first sub-matrices are different
[0152] Step 604, taking center elements of all the first sub-matrices to generate a second reference matrix;
[0153] Step 605, receiving host data in which hidden ciphertext information is sent by a sender server; the ciphertext information is hidden into the host data by the first reference matrix, the plurality of first sub-matrices and the second reference matrix;
[0154] Step 606, extracting the ciphertext information from the host data by using the first reference matrix, the plurality of first sub-matrices and the second reference matrix.
[0155] From Figure 6 As shown in the flowchart, in the embodiment of the present application, a certificate is generated by an authentication group server to which a certificate authority belongs, the certificate includes a plurality of preset consecutive natural numbers, after a receiver server receives the certificate, a first reference matrix is obtained by disassembling the certificate, any element in the first reference matrix is one of the plurality of preset consecutive natural numbers, a plurality of first sub-matrices and a second reference matrix are obtained by using the first reference matrix; host data in which hidden ciphertext information is sent by a sender server is received; the ciphertext information is hidden into the host data by the first reference matrix, the plurality of first sub-matrices and the second reference matrix; the ciphertext information is extracted from the host data by using the first reference matrix, the plurality of first sub-matrices and the second reference matrix. In this example, the first reference matrix is divided into a plurality of first sub-matrices according to a first preset length-width threshold, any two elements in the first sub-matrices are different, which can improve the information hiding capacity, and the ciphertext information is hidden into the host data by using the first reference matrix, the plurality of first sub-matrices and the second reference matrix, which reduces the risk of information leakage and increases the information hiding confusion and concealment.
[0156] In this implementation, the receiving server receives the certificate from the authentication group server and the host data containing the hidden ciphertext information from the sending server. First, the receiving server processes the certificate in the same way as the sending server, obtaining a first reference matrix Matrix, multiple first sub-matrices MatrixBox, and a second reference matrix Matrix. Then, the receiving server uses the first reference matrix Matrix, multiple first sub-matrices MatrixBox, and second reference matrix Matrix to extract the ciphertext information from the host data.
[0157] In one embodiment, extracting ciphertext information from host data using the first reference matrix, the plurality of first sub-matrices, and the second reference matrix may include:
[0158] Convert host data into host data stream P i ′, i is an integer;
[0159] For host data stream P i 'Execute the following loop operation:
[0160] From the host data stream P i ' takes a continuous data pair at the preset position (P i ′,P i ' +1 );
[0161] (P i ′,P i ' +1 ) are horizontal and vertical coordinates, and a fourth element d is determined in the first reference matrix. i+1 , i is an integer;
[0162] According to the fourth element d in the first reference matrix i+1 , determine the central element d of the first submatrix of its mapping i , d i with d i+1 adjacent;
[0163] Let i=i+2, until all host data streams P are obtained i The ciphertext data stream d hidden in ′ i , end the loop operation;
[0164] The ciphertext data stream d i Convert to ciphertext information according to preset format rules.
[0165] Let me give you an example:
[0166] Step 1: The host data of the received hidden ciphertext information can be various carriers such as pictures, videos or audios. The host data is converted into a host data stream to form a host matrix. In this example, pictures are used as an example.
[0167] Step 2: Two consecutive pixel pairs (P i ′,P i ' +1 ), with P i ′ is the horizontal axis, with P i ' +1 As the vertical coordinate, a unique element can be determined in the first reference matrix Matrix, which is recorded as the ciphertext information d i+1 ;
[0168] Step 3: In the first reference matrix Matrix, d i+1 A first sub-matrix must be mapped, and the central element of the first sub-matrix is the ciphertext information d i ,
[0169] Step 4: Let i = i + 2, and repeat steps 1 to 3 until all host data streams P are obtained. i The ciphertext data stream d hidden in ′ i ;
[0170] Step 5: Convert the ciphertext data stream d i Convert it into a binary data stream and obtain the ciphertext information based on the binary data stream.
[0171] When extracting ciphertext information, it is also possible to encounter ciphertext hidden when the first element in the receiving server is located in a row or column that cannot be assigned to the first sub-matrix, or is at the boundary of the first reference matrix, or when the second element is located in one of the first row, first column, last row, or last column of the second reference matrix. In one embodiment, the horizontal and vertical width values of the first reference matrix cannot be divided evenly by the first preset length and width threshold;
[0172] After dividing the first reference matrix into a plurality of first sub-matrices according to the first preset length and width threshold, the method may further include:
[0173] A plurality of rows or columns at the boundary that cannot be assigned to the first sub-matrix remain in the first reference matrix;
[0174] (P i ′,P i ' +1 ) are horizontal and vertical coordinates, and a fourth element d is determined in the first reference matrix. i+1 ,include:
[0175] If the fourth element d i+1 Adjacent to the rows or columns that cannot be assigned to the first submatrix and are at the boundary, P i ′,P i ' +1 The first threshold is added respectively to the data pair (P i′,P i ' +1 ) is the horizontal and vertical coordinates, and a fourth element d is re-determined in the first reference matrix i+1 .
[0176] For example, the horizontal and vertical values of the first reference matrix are 256×256, and the first preset length and width threshold is 3. i ′,P i ' +1 ) appears in the image, and in the next pixel pair to be processed, the value corresponding to 254 becomes 255, which means that situation 1 has been encountered. When processing the next pixel pair, it can still be processed as if the value is 254.
[0177] If the second element is located in one of the first row, first column, last row, and last column of the second reference matrix, due to the inherent mechanism of the algorithm of the embodiment of the present invention, this situation will not affect the execution accuracy of the ciphertext extraction algorithm, so it can be directly executed according to the original information extraction algorithm.
[0178] In one embodiment, the certificate has a validity period;
[0179] After receiving the certificate sent by the authentication group server to which the certificate authority belongs, the following may also be included:
[0180] Validity period of the verification certificate;
[0181] If the validity period of the certificate has expired, a message that the validity period of the certificate has expired is sent to the sending server, so that the sending server: resends a certificate acquisition request to the authentication group server and receives the certificate resent by the authentication group server.
[0182] For example, the authentication group server sets a time control module. After the certificate generation module 43 of the authentication group server generates a certificate, it sets a validity period for the certificate. The receiving server verifies the validity period of the certificate. When the validity period expires, it sends a message to the sending server that the validity period of the certificate has expired. At the same time, the time control module of the authentication group server interacts with the authorization management module 41, requiring the authorization management module 41 to recheck the user's authorization authentication status. When it receives the certificate acquisition request sent by the sending server, it regenerates the certificate. In this embodiment of the present invention, users are supported to transmit ciphertext an unlimited number of times within the validity period of the certificate. Once the validity period of the certificate expires, the ciphertext transmission is terminated, thereby improving the security of the ciphertext transmission.
[0183] Figure 7 This is a specific embodiment of the ciphertext transmission method based on information hiding in an embodiment of the present invention, such as Figure 7 As shown:
[0184] Step 701: First, the Web service nodes of both communicating parties apply for a certificate from the authentication group through the registration authentication module 31 and the network communication module 35;
[0185] Step 702: The network communication module 44 of the authentication group constantly monitors messages. After receiving requests from both parties, it confirms, records, and verifies the user information of both parties through the authorization management module 41 and the information storage module 42.
[0186] Step 703: After the authority is confirmed, the authentication group starts the certificate generation module 43, sets the certificate validity period field to zero, generates, packages, and issues a certificate according to the certificate generation method in the embodiment of the present invention, and transmits the certificate to the Web service nodes of both parties through the special encrypted communication channel of the network communication module 44;
[0187] Step 704: The authentication group sets the time control module 44 to monitor the certificate validity period. When the validity period expires, the module proceeds to step S702 to continue monitoring. The Web service node receives the certificate and monitors messages through the network communication module 35. When a client subsequently sends a request or receives network information, the information encryption module 33 or the information extraction module 34 is activated.
[0188] Step 705: After receiving the message and certificate sent by client A, web service node A performs base-based conversion on the message sent by client A, selects multimedia data such as images and videos, and executes a ciphertext encryption algorithm, i.e., the ciphertext transmission algorithm applied to the sending server in the embodiment of the present invention, to obtain a ciphertext image concealing the ciphertext information, and transmits the ciphertext image to web service node B.
[0189] Step 706: After receiving the certificate and the ciphertext image, the Web service node B executes the ciphertext decryption algorithm, i.e., the ciphertext transmission algorithm applied to the receiving server in the embodiment of the present invention, to obtain the ciphertext data stream d i , the ciphertext data stream d in base nine i Convert it into a binary data stream to get the ciphertext information.
[0190] In summary, the embodiments of the present invention have the following advantages:
[0191] 1. The present invention introduces an information hiding algorithm, which is more deceptive than normal ciphertext transmission. When the message is intercepted by an intruder, it can effectively reduce the probability of the ciphertext being noticed by the intruder due to its high concealment, thereby playing the role of anti-interception and anti-intrusion.
[0192] 2. The information hiding algorithm used in the implementation of the present invention has a larger storage value, which can reach 3.17bpp, under the premise of the same information carrier. The storage value of traditional algorithms ranges from 1.58bpp to 2.32bpp. In comparison, the method implemented in the implementation of the present invention is more suitable for the requirements of modern multimedia big data transmission.
[0193] The present invention also provides an apparatus for transmitting encrypted text based on information hiding, as described in the following embodiments. Since the principles of the apparatus for solving problems are similar to those of the method for transmitting encrypted text based on information hiding, the implementation of the apparatus can be referenced to the implementation of the method for transmitting encrypted text based on information hiding, and any repetitions will not be repeated.
[0194] Figure 8 FIG. 1 is a schematic diagram of a ciphertext transmission device based on information hiding in an embodiment of the present invention, applied to a sending server. Figure 8 As shown, the device includes:
[0195] The certificate acquisition module 801 is configured to send a certificate acquisition request to an authentication group server to which a certificate issuing authority belongs, so that the authentication group server: after verifying and recording the sender user information and the recipient user information according to the certificate acquisition request, generates a certificate and sends the certificate to the sender server and the recipient server; the certificate includes a plurality of preset consecutive natural numbers;
[0196] A first certificate receiving module 802 is configured to receive a certificate sent by an authentication group server;
[0197] The first certificate processing module 803 is configured to unpack the certificate to obtain a first reference matrix; any element in the first reference matrix is one of a plurality of preset consecutive natural numbers; the first reference matrix is divided into a plurality of first sub-matrices according to a first preset length and width threshold; any two elements in the first sub-matrices are different; and the center elements of all the first sub-matrices are taken to generate a second reference matrix;
[0198] The ciphertext and host acquisition module 804 is used to obtain host data used to hide ciphertext information and the ciphertext information to be hidden;
[0199] An information hiding module 805 is configured to hide the ciphertext information in the host data using a first reference matrix, a plurality of first sub-matrices, and a second reference matrix to obtain the host data in which the ciphertext information is hidden;
[0200] The ciphertext sending module 806 is used to send the host data containing the hidden ciphertext information to the receiving server.
[0201] In one embodiment, the information hiding module 805 is specifically configured to:
[0202] Convert host data into host data stream P i , i is an integer;
[0203] Convert the ciphertext information into ciphertext data stream d according to the preset format rules i , i is an integer;
[0204] Repeat the following steps until the host data stream P i According to the entire ciphertext data stream d i , is replaced by the values of the horizontal and vertical coordinates of the first reference matrix, and the host data stream P with hidden ciphertext information is obtained. i ′:
[0205] From the host data stream P i Take the continuous data pairs at the preset position (P i ,P i+1 );
[0206] Take the ciphertext data stream d in order i The continuous data pairs (d i ,d i+1 );
[0207] (P i ,P i+1 ) are horizontal and vertical coordinates, and a first element is determined in the first reference matrix;
[0208] Determine the center element of the first submatrix mapped by the first element;
[0209] Determine a second element of a second reference matrix to which the central element of the first submatrix is mapped;
[0210] Taking the second element as the center element in the second reference matrix, dividing the matrix according to the first preset length and width threshold to obtain a second sub-matrix;
[0211] Find the same value as d in the second submatrix i Equal third element;
[0212] determining a first sub-matrix mapped by the third element in the first reference matrix;
[0213] In the first submatrix mapped by the third element in the first reference matrix, find the value that matches d i+1 The fourth element is equal to the first reference matrix, and the horizontal and vertical coordinates of the fourth element are determined;
[0214] The host data stream P i The continuous data pairs (P i ,P i+1 ), replaced by the values of the fourth element in the horizontal and vertical coordinates of the first reference matrix;
[0215] Let i=i+2;
[0216] The ciphertext sending module 806 is specifically used for:
[0217] The host data stream P that hides the ciphertext information i ’ is sent to the receiving server.
[0218] In one embodiment, the horizontal and vertical width values of the first reference matrix cannot be divided evenly by the first preset length and width threshold;
[0219] The device also includes:
[0220] After the first certificate processing module 803 divides the first reference matrix into a plurality of first sub-matrices according to the first preset length and width threshold, a plurality of rows or columns at the boundary that cannot be assigned to the first sub-matrices remain in the first reference matrix; the information hiding module 805 is specifically configured to:
[0221] If the first element is located in a row or column at the boundary of the first reference matrix that cannot be assigned to the first sub-matrix, P i ,P i+1 Subtract the first threshold value respectively to subtract the data pair (P i ,P i+1 ) are the horizontal and vertical coordinates, and the first element is re-determined in the first reference matrix.
[0222] In one embodiment, the information hiding module 805 is specifically configured to:
[0223] If the second element is located in one of the first row, first column, last row, and last column of the second reference matrix, the second reference matrix is divided according to the first preset length and width threshold to obtain a third submatrix, wherein the second element is located in one of the first row, first column, last row, and last column of the third submatrix, or any combination thereof.
[0224] In one embodiment, the certificate has a validity period;
[0225] The device also includes:
[0226] A first certificate verification module, configured to verify the validity period of the certificate after the first certificate receiving module 802 receives the certificate sent by the authentication group server;
[0227] If the certificate validity period has expired, resend the certificate acquisition request to the authentication group server;
[0228] Receive the certificate resent by the authentication group server.
[0229] Figure 9 This is a schematic diagram of the structure of a ciphertext transmission device based on information hiding in an embodiment of the present invention, applied to a receiving server. The device includes:
[0230] The second certificate receiving module 901 is configured to receive a certificate sent by an authentication group server to which the certificate authority belongs; the certificate is generated by the authentication group server after verifying and recording sender user information and receiver user information according to a certificate acquisition request sent by a sender server; and the certificate includes a plurality of preset consecutive natural numbers.
[0231] The second certificate processing module 902 is configured to perform a disassembly process on the certificate to obtain a first reference matrix; any element in the first reference matrix is one of the plurality of preset consecutive natural numbers; the first reference matrix is divided into a plurality of first sub-matrices according to a first preset length-width threshold; any two elements in the first sub-matrix are different; and a second reference matrix is generated by taking center elements of all the first sub-matrices.
[0232] The ciphertext receiving module 903 is configured to receive host data in which ciphertext information sent by the sender server is hidden; the ciphertext information is hidden in the host data by the first reference matrix, the plurality of first sub-matrices, and the second reference matrix.
[0233] The ciphertext decryption module 904 is configured to extract the ciphertext information from the host data by using the first reference matrix, the plurality of first sub-matrices, and the second reference matrix.
[0234] In one embodiment, the ciphertext decryption module 904 is specifically configured to:
[0235] convert the host data into a host data stream P i ′, i is an integer;
[0236] perform the following loop operation on the host data stream P i ′:
[0237] take consecutive data pairs (P i ′, P i ′ +1 ) from a preset position in the host data stream P i ′;
[0238] determine a fourth element d i+1 in the first reference matrix with (P i ′, P i ′ +1 ) as horizontal and vertical coordinates, i is an integer;
[0239] determine a center element d i of a first sub-matrix mapped according to the fourth element d i+1 in the first reference matrix, d i is adjacent to d i ; and i+1
[0240] Let i=i+2, until all host data streams P are obtained i The ciphertext data stream d hidden in ′ i , end the loop operation;
[0241] The ciphertext data stream d i Convert to ciphertext information according to preset format rules.
[0242] In one embodiment, the horizontal and vertical width values of the first reference matrix cannot be divided evenly by the first preset length and width threshold;
[0243] The device also includes:
[0244] After the second certificate processing module 902 divides the first reference matrix into a plurality of first sub-matrices according to the first preset length and width threshold, a plurality of rows or columns at the boundary that cannot be assigned to the first sub-matrices remain in the first reference matrix;
[0245] The ciphertext decryption module 904 is specifically used for:
[0246] If the fourth element d i+1 Adjacent to the rows or columns that cannot be assigned to the first submatrix and are at the boundary, P i ′,P i ' +1 The first threshold is added respectively to the data pair (P i ′,P i ' +1 ) is the horizontal and vertical coordinates, and a fourth element d is re-determined in the first reference matrix i+1 .
[0247] In one embodiment, the certificate has a validity period;
[0248] The device also includes:
[0249] A second certificate verification module is used to verify the validity period of the certificate after receiving the certificate sent by the authentication group server to which the certificate issuing authority belongs;
[0250] If the validity period of the certificate has expired, a message that the validity period of the certificate has expired is sent to the sending server, so that the sending server: resends a certificate acquisition request to the authentication group server and receives the certificate resent by the authentication group server.
[0251] An embodiment of the present invention further provides a computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the above-mentioned ciphertext transmission method based on information hiding when executing the computer program.
[0252] The embodiment of the present application also provides a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to realize the information hiding based ciphertext transmission method.
[0253] The embodiment of the present application also provides a computer program product, which comprises a computer program, and the computer program is executed by a processor to realize the information hiding based ciphertext transmission method.
[0254] In the embodiment of the present application, the certificate is generated by the authentication group server to which the certificate authority belongs, the certificate comprises preset continuous natural numbers, after the sender server receives the certificate, the first reference matrix is obtained by unpacking the certificate, any element in the first reference matrix is one of the preset continuous natural numbers, a plurality of first sub-matrices and a second reference matrix are obtained by using the first reference matrix, and the ciphertext information is completely hidden in the host data by using the first reference matrix, the plurality of first sub-matrices and the second reference matrix. In this example, the first reference matrix is divided into a plurality of first sub-matrices according to the first preset length-width threshold, any two elements in the first sub-matrix are different, the information hiding capacity can be improved, and the ciphertext information is completely hidden in the host data by using the first reference matrix, the plurality of first sub-matrices and the second reference matrix, the information leakage risk is reduced, and the information hiding confusion and concealment are increased.
[0255] In the embodiment of the present application, the certificate is generated by the authentication group server to which the certificate authority belongs, the certificate comprises preset continuous natural numbers, after the receiver server receives the certificate, the first reference matrix is obtained by unpacking the certificate, any element in the first reference matrix is one of the preset continuous natural numbers, a plurality of first sub-matrices and a second reference matrix are obtained by using the first reference matrix, the host data hiding the ciphertext information sent by the sender server is received, the ciphertext information is hidden in the host data by using the first reference matrix, the plurality of first sub-matrices and the second reference matrix, and the ciphertext information is extracted from the host data by using the first reference matrix, the plurality of first sub-matrices and the second reference matrix. In this example, the first reference matrix is divided into a plurality of first sub-matrices according to the first preset length-width threshold, any two elements in the first sub-matrix are different, the information hiding capacity can be improved, and the ciphertext information is completely hidden in the host data by using the first reference matrix, the plurality of first sub-matrices and the second reference matrix, the information leakage risk is reduced, and the information hiding confusion and concealment are increased.
[0256] It will be understood by those skilled in the art that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0257] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0258] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0259] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 The steps for the function specified in one or more boxes.
[0260] The specific embodiments described above further illustrate the objectives, technical solutions and beneficial effects of the present invention in detail. It should be understood that the above description is only a specific embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. A ciphertext transmission method based on information hiding, characterized in that: Applied to the sending server, including: Sending a certificate acquisition request to an authentication group server to which a certificate issuing authority belongs, so that the authentication group server: after verifying and recording the sender user information and the recipient user information according to the certificate acquisition request, generates a certificate, and sends the certificate to the sender server and the recipient server; the certificate includes a plurality of preset consecutive natural numbers; Receive the certificate sent by the authentication group server; Unpacking the certificate to obtain a first reference matrix; any element in the first reference matrix is one of a plurality of preset consecutive natural numbers; Dividing the first reference matrix into a plurality of first sub-matrices according to a first preset length and width threshold; wherein any two elements in the first sub-matrices are different; Take the central elements of all first sub-matrices to generate a second reference matrix; Obtaining host data used to hide ciphertext information and the ciphertext information to be hidden; Hiding the ciphertext information in the host data using a first reference matrix, a plurality of first sub-matrices, and a second reference matrix to obtain the host data hiding the ciphertext information; Send the host data with hidden ciphertext information to the receiving server; The method of hiding the ciphertext information in the host data by using the first reference matrix, the plurality of first sub-matrices, and the second reference matrix to obtain the host data with the hidden ciphertext information includes: Convert host data to host data stream , is an integer; Convert ciphertext information into ciphertext data stream according to preset format rules , is an integer; Repeat the following steps until the host data flow According to the entire ciphertext data flow , is replaced by the values of the horizontal and vertical coordinates of the first reference matrix, and the host data stream of the hidden ciphertext information is obtained : Data stream from the host Take continuous data pairs at preset positions ; Get the ciphertext data stream in order Continuous data pairs ; by As horizontal and vertical coordinates, a first element is determined in the first reference matrix; Determine the center element of the first submatrix mapped by the first element; Determine a second element of a second reference matrix to which the central element of the first submatrix is mapped; Taking the second element as the center element in the second reference matrix, dividing the matrix according to the first preset length and width threshold to obtain a second sub-matrix; Find the same in the second submatrix Equal third element; determining a first sub-matrix mapped by the third element in the first reference matrix; In the first submatrix mapped by the third element in the first reference matrix, find the The fourth element is equal to the first reference matrix, and the horizontal and vertical coordinates of the fourth element are determined; Host data flow Continuous data pairs , replaced by the values of the fourth element in the horizontal and vertical coordinates of the first reference matrix; make ; Send the host data containing the hidden ciphertext information to the receiving server, including: The host data stream that hides the ciphertext information Sent to the receiving server.
2. The method according to claim 1, wherein The horizontal, vertical and width values of the first reference matrix cannot be divided evenly by the first preset length and width threshold; After dividing the first reference matrix into a plurality of first sub-matrices according to the first preset length and width threshold, the method further includes: In the first reference matrix, there are a plurality of rows or columns at the boundary that cannot be assigned to the first sub-matrix; As horizontal and vertical coordinates, a first element is determined in the first reference matrix, including: If the first element is located in a row or column at the boundary of the first reference matrix that cannot be assigned to the first sub-matrix, Subtract the first threshold value respectively to subtract the data pair of the first threshold value For the horizontal and vertical coordinates, redefine the first element in the first reference matrix.
3. The method according to claim 2, wherein The second reference matrix is divided into a second submatrix with the second element as the center element according to the first preset length and width threshold, including: If the second element is located in one of the first row, first column, last row, and last column of the second reference matrix, the second reference matrix is divided according to the first preset length and width threshold to obtain a third submatrix, wherein the second element is located in one of the first row, first column, last row, and last column of the third submatrix, or any combination thereof.
4. The method according to claim 1, wherein The certificate has a validity period; After receiving the certificate sent by the authentication group server, it also includes: Validity period of the verification certificate; If the certificate validity period has expired, resend the certificate acquisition request to the authentication group server; Receive the certificate resent by the authentication group server.
5. A ciphertext transmission method based on information hiding, characterized in that: Applied to the receiving server, including: Receive a certificate sent by an authentication group server to which a certificate issuing authority belongs; the certificate is generated by the authentication group server after verifying and recording the sender user information and the receiver user information according to the certificate acquisition request sent by the sender server; the certificate includes a plurality of preset consecutive natural numbers; Unpacking the certificate to obtain a first reference matrix; any element in the first reference matrix is one of a plurality of preset consecutive natural numbers; Dividing the first reference matrix into a plurality of first sub-matrices according to a first preset length and width threshold; wherein any two elements in the first sub-matrices are different; Take the central elements of all first sub-matrices to generate a second reference matrix; Receiving host data with hidden ciphertext information sent by a sending server; the ciphertext information is hidden in the host data through a first reference matrix, a plurality of first sub-matrices, and a second reference matrix; Extracting ciphertext information from host data using the first reference matrix, the plurality of first sub-matrices, and the second reference matrix; The encrypted information is hidden in the host data by the sending server in the following manner: Convert host data to host data stream , is an integer; Convert ciphertext information into ciphertext data stream according to preset format rules , is an integer; Repeat the following steps until the host data flow According to the entire ciphertext data flow , is replaced by the values of the horizontal and vertical coordinates of the first reference matrix, and the host data stream of the hidden ciphertext information is obtained : Data stream from the host Take continuous data pairs at preset positions ; Get the ciphertext data stream in order Continuous data pairs ; by As horizontal and vertical coordinates, a first element is determined in the first reference matrix; Determine the center element of the first submatrix mapped by the first element; Determine a second element of a second reference matrix to which the central element of the first submatrix is mapped; Taking the second element as the center element in the second reference matrix, dividing the matrix according to the first preset length and width threshold to obtain a second sub-matrix; Find the same in the second submatrix Equal third element; determining a first sub-matrix mapped by the third element in the first reference matrix; In the first submatrix mapped by the third element in the first reference matrix, find the The fourth element is equal to the first reference matrix, and the horizontal and vertical coordinates of the fourth element are determined; Host data flow Continuous data pairs , replaced by the values of the fourth element in the horizontal and vertical coordinates of the first reference matrix; make ; The host data receiving the hidden ciphertext information sent by the sending server includes: Receive the host data stream of the hidden ciphertext information sent by the sending server .
6. The method according to claim 5, wherein Extracting ciphertext information from host data using the first reference matrix, the plurality of first sub-matrices, and the second reference matrix includes: Convert host data to host data stream , is an integer; Host data flow Perform the following loop operations: Data stream from the host Take continuous data pairs at preset positions ; by As the horizontal and vertical coordinates, determine a fourth element in the first reference matrix , is an integer; According to the fourth element in the first reference matrix , determine the central element of the first submatrix of its mapping , and adjacent; make , until all host data streams are obtained The ciphertext data stream hidden in , end the loop operation; Ciphertext data stream Convert to ciphertext information according to preset format rules.
7. The method according to claim 6, wherein The horizontal, vertical and width values of the first reference matrix cannot be divided evenly by the first preset length and width threshold; After dividing the first reference matrix into a plurality of first sub-matrices according to the first preset length and width threshold, the method further includes: A plurality of rows or columns at the boundary that cannot be assigned to the first sub-matrix remain in the first reference matrix; by As the horizontal and vertical coordinates, determine a fourth element in the first reference matrix ,include: If the fourth element The rows or columns at the border that cannot be assigned to the first submatrix will be Add the first threshold value to the data pair with the first threshold value. As the horizontal and vertical coordinates, redefine the fourth element in the first reference matrix .
8. The method according to claim 5, wherein The certificate has a validity period; After receiving the certificate from the authentication group server to which the certificate authority belongs, it also includes: Validity period of the verification certificate; If the validity period of the certificate has expired, a message that the validity period of the certificate has expired is sent to the sending server, so that the sending server: resends a certificate acquisition request to the authentication group server and receives the certificate resent by the authentication group server.
9. A ciphertext transmission device based on information hiding, characterized in that: Applied to the sending server, including: A certificate acquisition module is configured to send a certificate acquisition request to an authentication group server to which a certificate issuing authority belongs, so that the authentication group server: after verifying and recording the sender user information and the receiver user information according to the certificate acquisition request, generates a certificate and sends the certificate to the sender server and the receiver server; the certificate includes a plurality of preset consecutive natural numbers; A first certificate receiving module, configured to receive a certificate sent by an authentication group server; a first certificate processing module configured to unpack the certificate to obtain a first reference matrix; wherein any element in the first reference matrix is one of a plurality of preset consecutive natural numbers; divide the first reference matrix into a plurality of first sub-matrices according to a first preset length and width threshold; wherein any two elements in the first sub-matrices are different; and take the central elements of all the first sub-matrices to generate a second reference matrix; A ciphertext and host acquisition module, used to obtain host data used to hide ciphertext information and ciphertext information to be hidden; an information hiding module, configured to hide the ciphertext information in the host data using a first reference matrix, a plurality of first sub-matrices, and a second reference matrix, to obtain the host data hiding the ciphertext information; The ciphertext sending module is used to send the host data with hidden ciphertext information to the receiving server; The information hiding module is specifically used for: Convert host data to host data stream , is an integer; Convert ciphertext information into ciphertext data stream according to preset format rules , is an integer; Repeat the following steps until the host data flow According to the entire ciphertext data flow , is replaced by the values of the horizontal and vertical coordinates of the first reference matrix, and the host data stream of the hidden ciphertext information is obtained : Data stream from the host Take continuous data pairs at preset positions ; Get the ciphertext data stream in order Continuous data pairs ; by As horizontal and vertical coordinates, a first element is determined in the first reference matrix; Determine the center element of the first submatrix mapped by the first element; Determine a second element of a second reference matrix to which the central element of the first submatrix is mapped; Taking the second element as the center element in the second reference matrix, dividing the matrix according to the first preset length and width threshold to obtain a second sub-matrix; Find the same in the second submatrix Equal third element; determining a first sub-matrix mapped by the third element in the first reference matrix; In the first submatrix mapped by the third element in the first reference matrix, find the The fourth element is equal to the first reference matrix, and the horizontal and vertical coordinates of the fourth element are determined; Host data flow Continuous data pairs , replaced by the values of the fourth element in the horizontal and vertical coordinates of the first reference matrix; make ; The ciphertext sending module is specifically used for: The host data stream that hides the ciphertext information Sent to the receiving server.
10. The device according to claim 9, wherein The horizontal, vertical and width values of the first reference matrix cannot be divided evenly by the first preset length and width threshold; Also includes: After the first certificate processing module divides the first reference matrix into a plurality of first sub-matrices according to the first preset length and width threshold, a plurality of rows or columns at the boundary that cannot be assigned to the first sub-matrices remain in the first reference matrix; the information hiding module is specifically configured to: If the first element is located in a row or column at the boundary of the first reference matrix that cannot be assigned to the first sub-matrix, Subtract the first threshold value respectively to subtract the data pair of the first threshold value For the horizontal and vertical coordinates, redefine the first element in the first reference matrix.
11. The device according to claim 10, wherein The information hiding module is specifically used for: If the second element is located in one of the first row, first column, last row, and last column of the second reference matrix, the second reference matrix is divided according to the first preset length and width threshold to obtain a third submatrix, wherein the second element is located in one of the first row, first column, last row, and last column of the third submatrix, or any combination thereof.
12. The device according to claim 9, wherein The certificate has a validity period; Also includes: A first certificate verification module is configured to verify the validity period of the certificate after the first certificate receiving module receives the certificate sent by the authentication group server; If the certificate validity period has expired, resend the certificate acquisition request to the authentication group server; Receive the certificate resent by the authentication group server.
13. A ciphertext transmission device based on information hiding, characterized in that: Applied to the receiving server, including: A second certificate receiving module is configured to receive a certificate sent by an authentication group server to which a certificate issuing authority belongs; the certificate is generated by the authentication group server after verifying and recording the sender user information and the receiver user information according to a certificate acquisition request sent by the sender server; the certificate includes a plurality of preset consecutive natural numbers; a second certificate processing module configured to unpack the certificate to obtain a first reference matrix; wherein any element in the first reference matrix is one of a plurality of preset consecutive natural numbers; divide the first reference matrix into a plurality of first sub-matrices according to a first preset length and width threshold; wherein any two elements in the first sub-matrices are different; and take the central elements of all the first sub-matrices to generate a second reference matrix; A ciphertext receiving module, configured to receive host data containing hidden ciphertext information sent by a sending server; the ciphertext information is hidden in the host data using a first reference matrix, a plurality of first sub-matrices, and a second reference matrix; a ciphertext decryption module, configured to extract ciphertext information from host data using the first reference matrix, the plurality of first sub-matrices, and the second reference matrix; The encrypted information is hidden in the host data by the sending server in the following manner: Convert host data to host data stream , is an integer; Convert ciphertext information into ciphertext data stream according to preset format rules , is an integer; Repeat the following steps until the host data flow According to the entire ciphertext data flow , is replaced by the values of the horizontal and vertical coordinates of the first reference matrix, and the host data stream of the hidden ciphertext information is obtained : Data stream from the host Take continuous data pairs at preset positions ; Get the ciphertext data stream in order Continuous data pairs ; by As horizontal and vertical coordinates, a first element is determined in the first reference matrix; Determine the center element of the first submatrix mapped by the first element; Determine a second element of a second reference matrix to which the central element of the first submatrix is mapped; Taking the second element as the center element in the second reference matrix, dividing the matrix according to the first preset length and width threshold to obtain a second sub-matrix; Find the same in the second submatrix Equal third element; determining a first sub-matrix mapped by the third element in the first reference matrix; In the first submatrix mapped by the third element in the first reference matrix, find the The fourth element is equal to the first reference matrix, and the horizontal and vertical coordinates of the fourth element are determined; Host data flow Continuous data pairs , replaced by the values of the fourth element in the horizontal and vertical coordinates of the first reference matrix; make ; The ciphertext receiving module is specifically used to: Receive the host data stream of the hidden ciphertext information sent by the sending server .
14. The device according to claim 13, wherein The ciphertext decryption module is specifically used for: Convert host data to host data stream , is an integer; Host data flow Perform the following loop operations: Data stream from the host Take continuous data pairs at preset positions ; by As the horizontal and vertical coordinates, determine a fourth element in the first reference matrix , is an integer; According to the fourth element in the first reference matrix , determine the central element of the first submatrix of its mapping , and adjacent; make , until all host data streams are obtained The ciphertext data stream hidden in , end the loop operation; Ciphertext data stream Convert to ciphertext information according to preset format rules.
15. The device according to claim 14, wherein The horizontal, vertical and width values of the first reference matrix cannot be divided evenly by the first preset length and width threshold; Also includes: After the second certificate processing module divides the first reference matrix into a plurality of first sub-matrices according to the first preset length and width threshold, a plurality of rows or columns at the boundary that cannot be assigned to the first sub-matrices remain in the first reference matrix; The ciphertext decryption module is specifically used for: If the fourth element The rows or columns at the border that cannot be assigned to the first submatrix will be Add the first threshold value to the data pair with the first threshold value. As the horizontal and vertical coordinates, redefine the fourth element in the first reference matrix .
16. The device according to claim 13, wherein The certificate has a validity period; Also includes: A second certificate verification module is used to verify the validity period of the certificate after receiving the certificate sent by the authentication group server to which the certificate issuing authority belongs; If the validity period of the certificate has expired, a message that the validity period of the certificate has expired is sent to the sending server, so that the sending server: resends a certificate acquisition request to the authentication group server and receives the certificate resent by the authentication group server.
17. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the method according to any one of claims 1 to 8 is implemented.
18. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 8 is implemented.
19. A computer program product, characterized in that The computer program product comprises a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 8 is implemented.
Citation Information
Patent Citations
JPEG image information hiding based private information communication method and system
CN105426709A
Master key management method and device
CN111431708A