A sensitive information random encryption method, system and device and readable storage medium

CN117094017BActive Publication Date: 2026-09-29INSPUR SUZHOU INTELLIGENT TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311099010.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-08-29
Publication Date
2026-09-29
Estimated Expiration
2043-08-29

AI Technical Summary

Technical Problem

虽然一些厂商针对这一块进行了基于Base64的加密处理,但是方式简单,只是把原始数据基于Base64算法转换一遍而已

Benefits of technology

[0061]对比现有技术,本发明有益效果在于:本发明公开了一种敏感信息随机加密方法、系统、装置及可读存储介质,通过BMC新增一个加密算法管理线程用于每隔预设时长随机生成一个新的加密规则。当BMC的web端输入敏感信息需要加密时,依据自行设计的加密算法和代码随机生成的加密规则对敏感信息进行一次加密,再结合Base64编码算法对加密的数据进行二次加密处理。同时提供IPMI命令接口设置是否启用该加密通道。本发明可以降低web端敏感信息泄露的风险,利用随机的加密规则使得加密转码出的密文也具有随机性和多变性,进一步提高了信息传输过程中的稳定性和安全性,从而保证服务器的安全稳定运行,降低了用户数据泄露风险,保护了用户隐私,保障了数据安全。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117094017B_ABST
    Figure CN117094017B_ABST
Patent Text Reader

Abstract

The application provides a sensitive information random encryption method, system and device and a readable storage medium. The method comprises the following steps: starting an encryption algorithm management thread to generate a plurality of encryption random numbers and writing the encryption random numbers into an encryption rule file; obtaining sensitive information input in a webpage interface of a baseboard management controller; reading the encryption rule file to obtain the encryption random numbers; performing character conversion and character addition on the sensitive information by using the encryption random numbers to generate an encryption string of the sensitive information; performing code conversion on the encryption string of the sensitive information by using a base64 encoding to generate a password of the sensitive information; and transmitting the password of the sensitive information to a backend interface. The sensitive information is encrypted and transmitted by combining the encryption algorithm and the code random encryption rule and the base64 encoding algorithm, so that the stability and security in the information transmission process are further improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data encryption technology, and more specifically to a method, system, apparatus, and readable storage medium for the random encryption of sensitive information. Background Technology

[0002] The Baseboard Management Controller (BMC) is a server-specific, independent system with monitoring, control, and management functions. Even when the server is powered off, it can still monitor equipment, perform firmware upgrades and downgrades, and other operations. The BMC monitors the temperature, voltage, status, and fan speed of critical server components to ensure the server's normal operation. It also records component information and fault logs to facilitate subsequent fault analysis and root cause identification. BMC development is moving towards a more user-friendly interface, with the enrichment of BMC web interface functionality being a prime example. The BMC web page provides a clearer view of monitored content, recorded logs, alarm information, and server control options. The improved graphical interface of the BMC web page offers greater clarity and understanding of the monitored content, making its use increasingly popular.

[0003] As BMC's functionality expands, its web interface is evolving towards greater user-friendliness and visualization. This trend towards a better human-computer interaction interface has encouraged more server administrators to operate, manage, and monitor the entire server's operation through the BMC web interface. However, traditional BMC web pages transmit sensitive information in plaintext, posing a risk of data leakage. While some vendors have implemented Base64-based encryption, the methods are simplistic, merely converting the original data using the Base64 algorithm. This encryption method produces a fixed amount of encrypted data for the same data, making it easily detectable. Summary of the Invention

[0004] To address the above problems, the present invention aims to provide a method, system, device, and readable storage medium for the random encryption of sensitive information. By combining encryption algorithms and randomly generated encryption rules with Base64 encoding algorithms, sensitive information is encrypted and transmitted, thereby further improving the stability and security of information transmission.

[0005] To achieve the above objectives, the present invention employs the following technical solution:

[0006] In a first aspect, the present invention discloses a method for randomly encrypting sensitive information, comprising:

[0007] The encryption algorithm management thread is started to generate multiple encrypted random numbers and write them to the encryption rule file;

[0008] Obtain sensitive information entered in the web interface of the baseboard management controller;

[0009] By reading the encryption rules file, an encrypted random number can be obtained;

[0010] The sensitive information is converted and characters are added using encrypted random numbers to generate an encrypted string of the sensitive information.

[0011] The encrypted string of sensitive information is transcoded using base64 encoding to generate a password for the sensitive information.

[0012] The password for sensitive information is transmitted to the backend interface.

[0013] Furthermore, the step of starting the encryption algorithm management thread generates multiple encrypted random numbers and writes them into the encryption rule file, including:

[0014] Enable sensitive information encryption by sending an IPMI command to the baseboard controller;

[0015] Upon receiving an IPMI command, an encryption algorithm management thread is created via the baseboard controller;

[0016] Run an encryption algorithm management thread that generates three random encrypted numbers m, n, and k every five minutes and stores them in an encryption rule file;

[0017] The encrypted random number is a random number between 0 and 9.

[0018] Furthermore, the acquisition of sensitive information input from the web interface of the substrate management controller includes:

[0019] Log in to the web interface of the baseboard management controller;

[0020] Retrieve sensitive input data through the Uniform Resource Locator (URL) interface.

[0021] Furthermore, the step of using encrypted random numbers to perform character conversion and string addition on sensitive information to generate an encrypted string of sensitive information includes:

[0022] Convert sensitive information into a string;

[0023] The string is converted using an encrypted random number m, and random strings are added to the string using encrypted random numbers n and k to generate an encrypted string containing sensitive information.

[0024] Furthermore, the step of using encrypted random number m to perform character conversion on the string, and using encrypted random numbers n and k to add random strings to the string to generate an encrypted string containing sensitive information includes:

[0025] Reverse the first m characters of the string based on the encrypted random number m;

[0026] Store the reversed string, and denote it as the first string;

[0027] Generate n random characters based on the encrypted random number n;

[0028] Concatenate n random characters sequentially;

[0029] Store the concatenated string and denote it as the first appended string;

[0030] Based on the encrypted random number k, generate k random characters.

[0031] Concatenate k random characters sequentially;

[0032] Store the concatenated string and denote it as the second appended string;

[0033] The first appended string is added to the beginning of the first string to generate the second string;

[0034] Add a second appended string to the end of the second string to generate an encrypted string containing sensitive information;

[0035] The random characters can be numerals, uppercase English characters, or lowercase English characters.

[0036] Furthermore, before obtaining the encrypted random number by reading the encryption rule file, the process also includes:

[0037] Determine whether sensitive data obtained through the Uniform Resource Locator (URL) interface needs to be encrypted;

[0038] If encryption is not required, transmit sensitive data directly to the backend interface;

[0039] If encryption is required, the encryption algorithm management thread is obtained through the baseboard controller;

[0040] If the acquisition fails, it means that the encryption algorithm management thread has not been created, and the sensitive data is directly transmitted to the backend interface.

[0041] When the acquisition is successful, it means that the encryption algorithm management thread has been created successfully, and the encrypted random number stored in the encryption rule file is obtained by reading the encryption rule file.

[0042] Furthermore, after transmitting the password for sensitive information to the backend interface, the process also includes:

[0043] By reading the encryption rule file, the encrypted random numbers m, n, and k can be obtained;

[0044] The password for sensitive information is decoded using base64 encoding to generate the first encoding;

[0045] Based on the encrypted random numbers n and k, delete the first n characters and the last k characters of the first code to generate the second code;

[0046] Based on the encrypted random number m, the first m characters of the second encoding are reversed to generate sensitive information.

[0047] Secondly, the present invention also discloses a random encryption system for sensitive information, comprising:

[0048] The encryption function startup unit is configured to start the encryption algorithm management thread to generate multiple encrypted random numbers and write them to the encryption rule file;

[0049] Information acquisition unit, configured to acquire sensitive information input from the web interface of the baseboard management controller;

[0050] An encryption rule acquisition unit is configured to obtain encrypted random numbers by reading an encryption rule file;

[0051] The first encryption unit is configured to use encrypted random numbers to perform character conversion and character addition on sensitive information to generate an encrypted string of sensitive information.

[0052] The second encryption unit is configured to use base64 encoding to transcode the encrypted string of sensitive information and generate a password for the sensitive information.

[0053] The transmission unit is configured to transmit passwords containing sensitive information to the backend interface.

[0054] Furthermore, the encryption function activation unit is specifically used to: enable the sensitive information encryption function by sending an IPMI command to the baseboard controller; in response to receiving the IPMI command, create an encryption algorithm management thread through the baseboard controller; run the encryption algorithm management thread to randomly generate three encryption random numbers m, n, and k at a preset time interval and store them in the encryption rule file.

[0055] Furthermore, the information acquisition unit is specifically used for: logging into the web interface of the baseboard management controller; and acquiring the input sensitive data through the Uniform Resource Locator (URL) interface.

[0056] Furthermore, the first encryption unit is specifically used for: converting sensitive information into a string; reversing the first m characters of the string according to the encrypted random number m to generate a first string; randomly generating a first appended string according to the encrypted random number n, the first appended string including n random characters; randomly generating a second appended string according to the encrypted random number k, the second appended string including k random characters; adding the first appended string to the front of the first string to generate a second string; and adding the second appended string to the back of the second string to generate an encrypted string of sensitive information.

[0057] Thirdly, the present invention also discloses a device for randomly encrypting sensitive information, comprising:

[0058] Memory, used to store random encryption programs for sensitive information;

[0059] A processor, configured to implement the steps of the sensitive information random encryption method as described above when executing the sensitive information random encryption program.

[0060] Fourthly, the present invention also discloses a readable storage medium storing a sensitive information random encryption program, wherein when the sensitive information random encryption program is executed by a processor, it implements the steps of the sensitive information random encryption method described in any of the above descriptions.

[0061] Compared with existing technologies, the advantages of this invention are as follows: This invention discloses a method, system, device, and readable storage medium for random encryption of sensitive information. It adds an encryption algorithm management thread to the BMC (Browser Management Console) to randomly generate a new encryption rule every preset time interval. When sensitive information is input into the BMC's web interface and requires encryption, the sensitive information is encrypted once according to a self-designed encryption algorithm and a randomly generated encryption rule, and then further encrypted using Base64 encoding. An IPMI command interface is also provided to set whether to enable this encryption channel. This invention can reduce the risk of sensitive information leakage on the web interface. By using random encryption rules, the encrypted and transcoded ciphertext also possesses randomness and variability, further improving the stability and security of information transmission, thereby ensuring the secure and stable operation of the server, reducing the risk of user data leakage, protecting user privacy, and ensuring data security.

[0062] Therefore, it is evident that the present invention has outstanding substantive features and significant progress compared with the prior art, and the beneficial effects of its implementation are also obvious. Attached Figure Description

[0063] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0064] Figure 1 This is a flowchart of a method for randomly encrypting sensitive information according to a specific embodiment of the present invention.

[0065] Figure 2 This is a flowchart illustrating the decryption process of a random encryption method for sensitive information in a specific embodiment of the present invention.

[0066] Figure 3 This is a system structure diagram of a sensitive information random encryption system according to a specific embodiment of the present invention.

[0067] Figure 4 This is a schematic diagram of the structure of a sensitive information random encryption device according to a specific embodiment of the present invention.

[0068] In the diagram, 1 is the encryption function activation unit; 2 is the information acquisition unit; 3 is the encryption rule acquisition unit; 4 is the first encryption unit; 5 is the second encryption unit; 6 is the transmission unit; 101 is the processor; 102 is the memory; 103 is the input interface; 104 is the output interface; 105 is the communication unit; 106 is the keyboard; 107 is the display; and 108 is the mouse. Detailed Implementation

[0069] The core of this invention is to provide a method for randomly encrypting sensitive information. In related technologies, sensitive information is transmitted in plaintext in its original format during the transmission of BMC web pages, posing a risk of leakage. Although some manufacturers have implemented Base64-based encryption, the method is simple, merely converting the original data using the Base64 algorithm. This encryption method produces a fixed amount of encrypted data for the same data, making it easily detectable.

[0070] The sensitive information random encryption method provided by this invention first starts by activating an encryption algorithm management thread to generate multiple encrypted random numbers and writes them into an encryption rule file. Then, it retrieves the sensitive information input from the web interface of the baseboard management controller. At this point, the encrypted random numbers are used to perform character conversion and character addition on the sensitive information to generate an encrypted string; then, base64 encoding is used to transcode the encrypted string to generate a password for the sensitive information. Finally, the password is transmitted to the backend interface. Therefore, this invention, by combining an encryption algorithm and randomly generated encryption rules with Base64 encoding, further improves the stability and security of information transmission.

[0071] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains. The terminology used herein in the description of the invention is for the purpose of describing particular embodiments only and is not intended to be limiting of the invention.

[0072] The key terms used in this invention will be explained below.

[0073] IPMI, short for Intelligent Platform Management Interface, is a set of interface specifications for out-of-band management of computers. Out-of-band access means that the computer system can be accessed without being located in the same room as the system's physical assets. IPMI supports remote monitoring without requiring a license from the computer's operating system. Users can use IPMI to remotely access the BMC (Browser Management Console) to monitor the physical health characteristics of the server, such as temperature, voltage, fan status, and power status. They can also develop their own IPMI commands to control and configure other device modules on the server, providing convenience and versatility for server monitoring and management tasks.

[0074] Base64 is one of the most common encoding methods used on the internet for transmitting 8-bit byte code. It's a method of representing binary data based on 64 printable characters. These 64 printable characters are the lowercase letters 'az', uppercase letters 'AZ', numbers 0-9, and the symbols "+" and " / " from the ASCII table. During network transmission, only printable characters can be transmitted, and these are also transmitted in binary form. Base64 re-divides the transmitted binary data into groups of 6 bits each. If there are fewer than 6 bits, the lower bits are padded with 0s. Each 6 bits form a new byte, with the higher bits padded with 0s, creating a new binary sequence. Finally, the corresponding character is found using the value in the Base64 index table. In other words, any printable symbol can be converted into a character in the Base64 index table; this conversion process is called Base64 encoding.

[0075] To enable those skilled in the art to better understand the present invention, the invention will be further described in detail below with reference to the accompanying drawings and specific embodiments. Obviously, the described embodiments are merely some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0076] See Figure 1 As shown, this embodiment provides a method for randomly encrypting sensitive information, including the following steps:

[0077] S101: Start the encryption algorithm management thread to generate multiple encrypted random numbers and write them to the encryption rules file.

[0078] In a specific implementation, the sensitive information encryption function is first enabled by sending an IPMI command to the BMC. After receiving the IPMI command, the BMC creates an encryption algorithm management thread. At this time, the encryption algorithm management thread runs and randomly generates three encrypted random numbers m, n, and k every five minutes, and stores them in the encryption rule file.

[0079] S102: Obtain sensitive information entered in the BMC web interface.

[0080] In a specific implementation, the user first logs into the BMC web interface and then obtains the sensitive data entered through the URL (Uniform Resource Locator) interface.

[0081] S103: Determine encryption requirements and confirm encryption functionality.

[0082] In a specific implementation, it is determined whether the sensitive data obtained through the URL interface needs to be encrypted; if it does not need to be encrypted, the sensitive data is directly transmitted to the backend interface, that is, the sensitive data is transmitted to the backend interface in its original form without any processing.

[0083] If encryption is required, the encryption algorithm management thread is obtained through BMC to confirm whether the encryption function is enabled. If the acquisition fails, it means that the encryption algorithm management thread has not been created, and the sensitive data is directly transmitted to the backend interface. If the acquisition is successful, it means that the encryption algorithm management thread has been created successfully, and the next step is executed directly.

[0084] S104: Obtain encrypted random numbers by reading the encryption rules file.

[0085] It should be noted that the three encrypted random numbers m, n, and k stored in the encryption rule file are updated every five minutes. In this step, the encrypted random numbers m, n, and k currently stored in the encryption rule file are read in real time.

[0086] S105: Use encrypted random numbers to perform character conversion and character addition on sensitive information to generate an encrypted string of sensitive information.

[0087] In a specific implementation, firstly, the first m characters of the string are reversed based on the encrypted random number m to generate a first string. Then, a first appended string is randomly generated based on the encrypted random number n, consisting of n random characters; a second appended string is randomly generated based on the encrypted random number k, consisting of k random characters. The first appended string is then added to the beginning of the first string to generate a second string; finally, the second appended string is added to the end of the second string to generate an encrypted string containing sensitive information.

[0088] The purpose of this step is to encrypt sensitive data using a self-designed encryption algorithm and randomly generated encryption rules from the code. To more accurately illustrate the encryption process, let's take the sensitive data as the string "admin" as an example. The specific encryption process is as follows:

[0089] Assume the current encrypted random numbers m, n, and k are 3, 2, and 5 respectively. These three random numbers are saved to...

[0090] The file is located in / var / web_encrypt.

[0091] After reading the encrypted random numbers m, n, and k from the file / var / web_encrypt, the system first reverses the first three characters of "admin" (m=3) to convert it to mdain. Then, using the random number seed (n=2 and k=5), it generates two printable strings, "6f" and "qaz1d". These strings are then appended to the beginning and end of "mdain", respectively. At this point, the original string is converted to 6fmdainqaz1d.

[0092] S106: Use base64 encoding to transcode the encrypted string of sensitive information to generate a password for the sensitive information.

[0093] In a specific implementation, the string 6fmdainqaz1d generated in step S5 is converted using base64 encoding to generate the password NmZtZGFpbnFhejFk for sensitive information.

[0094] S107: Transmit the password for sensitive information to the backend interface.

[0095] Therefore, the sensitive information random encryption method provided by this invention can randomly generate encryption algorithms to encrypt and decrypt sensitive information after the encryption function is enabled, ensuring that the encrypted data has high complexity and increasing data security. After the encryption function is enabled, BMC creates a new thread specifically for generating encryption algorithms, and updates a new algorithm randomly every five minutes. The random encryption algorithm provided by this method generates three random numbers between 0 and 9 every five minutes and writes them to a file for front-end encryption. The three generated random numbers are m, n, and k. m represents reversing the order of data before the m-th data in the encrypted data; n represents adding n random characters to the beginning of the original data; and k represents adding k random characters to the end of the data to be encrypted. The resulting new data is then transmitted via Base64 encoding. Simultaneously, the BMC internal interface receives the encrypted data and decrypts it in the same way for subsequent internal data verification.

[0096] Accordingly, based on the aforementioned method for randomly encrypting sensitive information, once the password for the sensitive information is transmitted to the backend interface, it needs to be decrypted, such as... Figure 2 As shown, the decryption process specifically includes the following steps:

[0097] S201: Obtain encrypted random numbers m, n, and k by reading the encryption rule file.

[0098] In a specific implementation, the current encrypted random numbers m, n, and k are determined to be 3, 2, and 5 respectively by reading the / var / web_encrypt file.

[0099] S202: Use base64 encoding to decode the password of sensitive information and generate the first encoding.

[0100] In the specific real-time method, the password NmZtZGFpbnFhejFk of the obtained sensitive information is decoded using base64 to generate the first encoding 6fmdainqaz1d.

[0101] S203: Based on the encrypted random numbers n and k, delete the first n characters and the last k characters of the first code to generate the second code.

[0102] In a specific implementation, based on the obtained encrypted random numbers n=2 and k=5, the first two characters and the last five characters of the first code 6fmdainqaz1d are deleted to generate the second code mdain.

[0103] S204: Based on the encrypted random number m, reverse the first m characters of the second encoding to generate sensitive information.

[0104] In a specific implementation, based on the encrypted random number m=3, the first three characters of the second encoding mdain are reversed to obtain the sensitive information admin.

[0105] The above discloses the random encryption and decryption process for sensitive information. It can be seen that the random encryption method for sensitive information disclosed in this invention can reduce the risk of leakage of sensitive information on the web. This method uses random encryption rules to make the encrypted and encoded ciphertext also random and variable, further improving the stability and security of information transmission, thereby ensuring the safe and stable operation of the server, reducing the risk of user data leakage, protecting user privacy, and ensuring data security.

[0106] See Figure 3 As shown, the present invention also discloses a sensitive information random encryption system, including: an encryption function activation unit 1, an information acquisition unit 2, an encryption rule acquisition unit 3, a first encryption unit 4, a second encryption unit 5, and a transmission unit 6.

[0107] Encryption function startup unit 1 is configured to start the encryption algorithm management thread to generate multiple encrypted random numbers and write them into the encryption rule file.

[0108] In a specific implementation, the encryption function activation unit 1 is specifically used to: enable the sensitive information encryption function by sending an IPMI command to the BMC; in response to receiving the IPMI command, create an encryption algorithm management thread through the BMC; run the encryption algorithm management thread, randomly generate three encryption random numbers m, n, and k every five minutes, and store them in the encryption rule file.

[0109] Information acquisition unit 2 is configured to acquire sensitive information input from the web interface of the baseboard management controller.

[0110] In a specific implementation, the information acquisition unit 2 is specifically used for: logging into the web interface of BMC; and acquiring the input sensitive data through the URL interface.

[0111] Encryption rule acquisition unit 3 is configured to obtain encrypted random numbers by reading an encryption rule file.

[0112] The first encryption unit 4 is configured to use encrypted random numbers to perform character conversion and character addition on sensitive information to generate an encrypted string of sensitive information.

[0113] In a specific implementation, the first encryption unit 4 is specifically used to: convert sensitive information into a string; reverse the first m characters of the string according to the encrypted random number m to generate a first string; randomly generate a first appended string according to the encrypted random number n, the first appended string including n random characters; randomly generate a second appended string according to the encrypted random number k, the second appended string including k random characters; add the first appended string to the front of the first string to generate a second string; and add the second appended string to the back of the second string to generate an encrypted string of sensitive information.

[0114] The second encryption unit 5 is configured to use base64 encoding to transcode the encrypted string of sensitive information to generate a password for the sensitive information.

[0115] Transmission unit 6 is configured to transmit passwords containing sensitive information to the backend interface.

[0116] Therefore, this invention provides a sensitive information random encryption system that can add an encryption algorithm management thread to the BMC to randomly generate a new encryption rule every preset time interval. When sensitive information needs to be encrypted when entered into the BMC web interface, the sensitive information can be encrypted once according to the self-designed encryption algorithm and the encryption rule randomly generated by the code, and then the encrypted data can be further encrypted using the Base64 encoding algorithm, thereby further improving the stability and security of information transmission.

[0117] See Figure 4 As shown, the present invention also discloses a sensitive information random encryption device, including a processor 101 and a memory 102; wherein, when the processor 101 executes the sensitive information random encryption program stored in the memory, it performs the following steps:

[0118] 1. Start the encryption algorithm management thread to generate multiple encrypted random numbers and write them into the encryption rule file.

[0119] 2. Obtain sensitive information entered in the BMC web interface.

[0120] 3. Determine the encryption requirements and confirm the encryption function.

[0121] 4. Obtain encrypted random numbers by reading the encryption rules file.

[0122] 5. Use encrypted random numbers to convert and add characters to sensitive information to generate an encrypted string of sensitive information.

[0123] 6. Use base64 encoding to transcode the encrypted string of sensitive information to generate a password for the sensitive information.

[0124] 7. Transmit the password for sensitive information to the backend interface.

[0125] The sensitive information random encryption device provided in this embodiment may include, but is not limited to, smartphones, tablets, laptops, or desktop computers.

[0126] The processor 101 may include one or more processing cores, such as a quad-core processor or an octa-core processor. The processor 101 may be implemented using at least one hardware form selected from Digital Signal Processor (DSP), Field-Programmable Gate Array (FPGA), and Programmable Logic Array (PLA). The processor 101 may also include a main processor and a coprocessor. The main processor, also known as the Central Processing Unit (CPU), is used to process data in the wake-up state; the coprocessor is a low-power processor used to process data in the standby state. In some embodiments, the processor 101 may integrate a Graphics Processing Unit (GPU), which is responsible for rendering and drawing the content to be displayed on the screen. In some embodiments, the processor 101 may also include an Artificial Intelligence (AI) processor, which handles computational operations related to machine learning.

[0127] The memory 102 may include one or more computer-readable storage media, which may be non-transitory. The memory 102 may also include high-speed random access memory and non-volatile memory, such as one or more disk storage devices or flash memory devices. In this embodiment, the memory 102 is used to store at least the following computer program, which, after being loaded and executed by the processor 101, is capable of implementing the relevant steps of the sensitive information random encryption method disclosed in any of the foregoing embodiments. In addition, the resources stored in the memory 102 may also include an operating system and data, and the storage method may be temporary or permanent storage. The operating system may include Windows, Unix, Linux, etc. The data may include, but is not limited to, the data involved in the aforementioned sensitive information random encryption method.

[0128] In a specific implementation, when the processor 101 executes the computer program stored in the memory 102, it can specifically implement the following steps: enable the sensitive information encryption function by sending an IPMI command to the baseboard controller; in response to receiving the IPMI command, create an encryption algorithm management thread through the baseboard controller; run the encryption algorithm management thread to randomly generate three encrypted random numbers m, n, and k at a preset time interval and store them in the encryption rule file.

[0129] In a specific implementation, when the processor 101 executes the computer program stored in the memory 102, it can specifically implement the following steps: logging into the web interface of BMC; obtaining sensitive input data through the URL interface.

[0130] In a specific implementation, when the processor 101 executes the computer program stored in the memory 102, it can specifically implement the following steps: converting sensitive information into a string; reversing the first m characters of the string according to the encrypted random number m to generate a first string; randomly generating a first appended string according to the encrypted random number n, the first appended string including n random characters; randomly generating a second appended string according to the encrypted random number k, the second appended string including k random characters; adding the first appended string to the beginning of the first string to generate a second string; adding the second appended string to the end of the second string to generate an encrypted string of sensitive information.

[0131] In a specific implementation, when the processor 101 executes the computer program stored in the memory 102, it can specifically implement the following steps: determine whether the sensitive data obtained through the URL interface needs to be encrypted; if encryption is not required, directly transmit the sensitive data to the backend interface; if encryption is required, obtain the encryption algorithm management thread through the baseboard controller; if the acquisition fails, it indicates that the encryption algorithm management thread has not been created, and directly transmit the sensitive data to the backend interface; if the acquisition is successful, it indicates that the encryption algorithm management thread has been successfully created, and obtain the encrypted random number stored in the encryption rule file by reading the encryption rule file.

[0132] Furthermore, the sensitive information random encryption device in this embodiment may also include:

[0133] Input interface 103 is used to acquire a random encryption program for sensitive information imported from the outside and save the acquired random encryption program for sensitive information to the memory 102. It can also be used to acquire various instructions and parameters transmitted by external terminal devices and transmit them to the processor 101 so that the processor 101 can perform corresponding processing using the aforementioned instructions and parameters. In this embodiment, the input interface 103 may specifically include, but is not limited to, a USB interface, a serial interface, a voice input interface, a fingerprint input interface, a hard disk read interface, etc.

[0134] The output interface 104 is used to output various data generated by the processor 101 to a connected terminal device, so that other terminal devices connected to the output interface can obtain the various data generated by the processor 101. In this embodiment, the output interface 104 may specifically include, but is not limited to, a USB interface, a serial interface, etc.

[0135] The communication unit 105 is used to establish a remote communication connection between the server-running business optimization configuration device and the external server, so that the sensitive information random encryption device can mount the image file to the external server. In this embodiment, the communication unit 105 may specifically include, but is not limited to, a remote communication unit based on wireless communication technology or wired communication technology.

[0136] Keyboard 106 is used to acquire various parameter data or commands input by the user through real-time keystrokes.

[0137] Display 107 is used to display relevant information in real time about the random encryption process of sensitive information.

[0138] Mouse 108 can be used to assist users in inputting data and simplify user operations.

[0139] This invention also discloses a readable storage medium, which includes random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable hard disk, CD-ROM, or any other form of storage medium known in the art. The readable storage medium stores a random encryption program for sensitive information, which, when executed by a processor, performs the following steps:

[0140] 1. Start the encryption algorithm management thread to generate multiple encrypted random numbers and write them into the encryption rule file.

[0141] 2. Obtain sensitive information entered in the BMC web interface.

[0142] 3. Determine the encryption requirements and confirm the encryption function.

[0143] 4. Obtain encrypted random numbers by reading the encryption rules file.

[0144] 5. Use encrypted random numbers to convert and add characters to sensitive information to generate an encrypted string of sensitive information.

[0145] 6. Use base64 encoding to transcode the encrypted string of sensitive information to generate a password for the sensitive information.

[0146] 7. Transmit the password for sensitive information to the backend interface.

[0147] In summary, this invention uses encryption algorithms and randomly generated encryption rules in code, combined with Base64 encoding, to encrypt and transmit sensitive information, thereby further improving the stability and security of information transmission.

[0148] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. The methods disclosed in the embodiments are described simply because they correspond to the systems disclosed in the embodiments; relevant details can be found in the method section.

[0149] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.

[0150] In the embodiments provided by this invention, it should be understood that the disclosed systems, methods, and approaches can be implemented in other ways. For example, the system embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between systems or units may be electrical, mechanical, or other forms.

[0151] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0152] In addition, the functional modules in the various embodiments of the present invention can be integrated into one processing unit, or each module can exist physically separately, or two or more modules can be integrated into one unit.

[0153] Similarly, in the various embodiments of the present invention, each processing unit can be integrated into a functional module, or each processing unit can exist physically, or two or more processing units can be integrated into a functional module.

[0154] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software module executed by a processor, or a combination of both. The software module can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.

[0155] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0156] The above provides a detailed description of the method, system, apparatus, and readable storage medium for random encryption of sensitive information provided by this invention. Specific examples have been used to illustrate the principles and implementation methods of this invention. The descriptions of the embodiments above are merely for the purpose of helping to understand the method and core ideas of this invention. It should be noted that those skilled in the art can make various improvements and modifications to this invention without departing from its principles, and these improvements and modifications also fall within the protection scope of the claims of this invention.

Claims

1. A method for randomly encrypting sensitive information, characterized in that, include: The encryption algorithm management thread is started to generate three encrypted random numbers m, n, and k, and written to the encryption rule file; Obtain sensitive information entered in the web interface of the baseboard management controller; By reading the encryption rules file, an encrypted random number can be obtained; The sensitive information is converted and characters are added using encrypted random numbers to generate an encrypted string of the sensitive information. The encrypted string of sensitive information is transcoded using base64 encoding to generate a password for the sensitive information. Transmit the password containing sensitive information to the backend interface; The process of using encrypted random numbers m to perform character conversion on the string, and using encrypted random numbers n and k to add random strings to the string to generate an encrypted string containing sensitive information includes: Reverse the first m characters of the string based on the encrypted random number m; Store the reversed string, and denote it as the first string; Generate n random characters based on the encrypted random number n; Concatenate n random characters sequentially; Store the concatenated string and denote it as the first appended string; Based on the encrypted random number k, generate k random characters. Concatenate k random characters sequentially; Store the concatenated string and denote it as the second appended string; The first appended string is added to the beginning of the first string to generate the second string; Add a second appended string to the end of the second string to generate an encrypted string containing sensitive information; The random characters can be numerals, uppercase English characters, or lowercase English characters.

2. The method for randomly encrypting sensitive information according to claim 1, characterized in that, The encryption algorithm management thread generates multiple encrypted random numbers and writes them into the encryption rule file, including: Enable sensitive information encryption by sending an IPMI command to the baseboard controller; Upon receiving an IPMI command, an encryption algorithm management thread is created via the baseboard controller; Run an encryption algorithm management thread that generates three random encrypted numbers m, n, and k every five minutes and stores them in an encryption rule file; The encrypted random number is a random number between 0 and 9.

3. The method for randomly encrypting sensitive information according to claim 1, characterized in that, The sensitive information entered in the web interface of the substrate management controller includes: Log in to the web interface of the baseboard management controller; Retrieve sensitive input data through the Uniform Resource Locator (URL) interface.

4. The method for randomly encrypting sensitive information according to claim 1, characterized in that, Before obtaining the encrypted random number by reading the encryption rule file, the process also includes: Determine whether sensitive data obtained through the Uniform Resource Locator (URL) interface needs to be encrypted; If encryption is not required, transmit sensitive data directly to the backend interface; If encryption is required, the encryption algorithm management thread is obtained through the baseboard controller; If the acquisition fails, it means that the encryption algorithm management thread has not been created, and the sensitive data is directly transmitted to the backend interface. When the acquisition is successful, it means that the encryption algorithm management thread has been created successfully, and the encrypted random number stored in the encryption rule file is obtained by reading the encryption rule file.

5. The method for randomly encrypting sensitive information according to claim 2, characterized in that, After transmitting the password containing sensitive information to the backend interface, the process also includes: By reading the encryption rule file, the encrypted random numbers m, n, and k can be obtained; The password for sensitive information is decoded using base64 encoding to generate the first encoding; Based on the encrypted random numbers n and k, delete the first n characters and the last k characters of the first code to generate the second code; Based on the encrypted random number m, the first m characters of the second encoding are reversed to generate sensitive information.

6. A system for randomly encrypting sensitive information, characterized in that, include: The encryption function startup unit is configured to start the encryption algorithm management thread to generate three encrypted random numbers m, n, and k, and write them into the encryption rule file; Information acquisition unit, configured to acquire sensitive information input from the web interface of the baseboard management controller; An encryption rule acquisition unit is configured to obtain encrypted random numbers by reading an encryption rule file; The first encryption unit is configured to use encrypted random numbers to perform character conversion and character addition on sensitive information to generate an encrypted string of sensitive information. The second encryption unit is configured to use base64 encoding to transcode the encrypted string of sensitive information and generate a password for the sensitive information. A transmission unit configured to transmit passwords containing sensitive information to a backend interface; The process of using encrypted random numbers m to perform character conversion on the string, and using encrypted random numbers n and k to add random strings to the string to generate an encrypted string containing sensitive information includes: Reverse the first m characters of the string based on the encrypted random number m; Store the reversed string, and denote it as the first string; Generate n random characters based on the encrypted random number n; Concatenate n random characters sequentially; Store the concatenated string and denote it as the first appended string; Based on the encrypted random number k, generate k random characters. Concatenate k random characters sequentially; Store the concatenated string and denote it as the second appended string; The first appended string is added to the beginning of the first string to generate the second string; Add a second appended string to the end of the second string to generate an encrypted string containing sensitive information; The random characters can be numerals, uppercase English characters, or lowercase English characters.

7. A device for randomly encrypting sensitive information, characterized in that, include: Memory, used to store random encryption programs for sensitive information; A processor, configured to implement the steps of the sensitive information random encryption method as described in any one of claims 1 to 5 when executing the sensitive information random encryption program.

8. A readable storage medium, characterized in that: The readable storage medium stores a sensitive information random encryption program, which, when executed by a processor, implements the steps of the sensitive information random encryption method as described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Encryption method and device and storage medium

    CN110048835A

  • Database Obfuscation System and Method

    US20100131518A1