Laboratory data processing method, apparatus, system, device, and medium
By encrypting the original laboratory data and processing the equipment identification information, a randomly arranged ciphertext of auxiliary data is generated, which solves the problem of data being easily cracked in existing technologies and improves data security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SHANDONG NUCLEAR POWER CO LTD
- Filing Date
- 2023-10-30
- Publication Date
- 2026-07-24
AI Technical Summary
In existing technologies, storage devices encrypt the original data and send it completely to the server device, which is easily cracked, resulting in poor data security.
The original laboratory data is encrypted to generate original data ciphertext. The device identification information of the storage device is also encrypted to generate device identification ciphertext. The original data ciphertext is split into sub-ciphertexts and randomly arranged to generate auxiliary data ciphertext. The length information and ciphertext order information of the device identification ciphertext are inserted to form the target data ciphertext. The service device decrypts the data to obtain the original laboratory data.
This improves the security of encrypted data, making it impossible to obtain the original data even through brute-force attacks, thus enhancing data security.
Smart Images

Figure CN117421752B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data processing technology, and in particular to a laboratory data processing method, apparatus, system, equipment, and medium. Background Technology
[0002] In the process of data generation, transmission, and use, it is often necessary to ensure the credibility of the data, such as session maintenance in information systems and data transfer between two systems.
[0003] In existing technologies, storage devices encrypt the original data and send it completely to the server device for decryption. This method is easily cracked and has poor data security. Summary of the Invention
[0004] This invention provides a laboratory data processing method, apparatus, equipment, and medium to improve the security of raw data.
[0005] In a first aspect, the present invention provides a laboratory data processing method, executed by a storage device, the method comprising:
[0006] The original laboratory data is encrypted to obtain the original ciphertext data.
[0007] Encrypt the device identification information of the storage device to obtain the device identification ciphertext;
[0008] Based on the length of the device identifier ciphertext, the original data ciphertext is split into at least one sub-original data ciphertext, and the original order of each sub-original data ciphertext in the original data ciphertext is determined.
[0009] The original data ciphertext and device identifier ciphertext are randomly arranged to obtain auxiliary data ciphertext;
[0010] Based on the original order of each sub-original data ciphertext and the preset order of the device identifier ciphertext, as well as the auxiliary order of each sub-original data ciphertext in the auxiliary data ciphertext and the auxiliary order of the device identifier ciphertext in the auxiliary data ciphertext, ciphertext order information is generated.
[0011] The length and order information of the device identifier ciphertext are inserted into the auxiliary data ciphertext to obtain the target data ciphertext;
[0012] Send the target data ciphertext to the service device so that the service device can decrypt the target data ciphertext and obtain the original laboratory data.
[0013] Secondly, the present invention provides a laboratory data processing method, executed by a service device, the method comprising:
[0014] The target data ciphertext is received from the storage device. The target data ciphertext is generated as follows: the original laboratory data is encrypted to obtain the original data ciphertext; the device identification information of the storage device is encrypted to obtain the device identification ciphertext; based on the length of the device identification ciphertext, the original data ciphertext is split into at least one sub-original data ciphertext, and the original order of each sub-original data ciphertext within the original data ciphertext is determined; the sub-original data ciphertexts and the device identification ciphertext are randomly arranged to obtain auxiliary data ciphertext; based on the original order of each sub-original data ciphertext, the preset order of the device identification ciphertext, and the auxiliary order of each sub-original data ciphertext and the auxiliary order of the device identification ciphertext within the auxiliary data ciphertext, ciphertext order information is generated; the length information and ciphertext order information of the device identification ciphertext are inserted into the auxiliary data ciphertext to obtain the target data ciphertext.
[0015] The target data ciphertext is split to obtain the length information of the device identification ciphertext, the ciphertext order information, and the auxiliary data ciphertext;
[0016] Based on the length and order of the device identification ciphertext, the auxiliary data ciphertext is split into the device identification ciphertext and the original data ciphertext.
[0017] Decrypt the encrypted device identification information to obtain the device identification information;
[0018] Query device identification information from the configurable set of device identification information;
[0019] If the query result is not empty, the original encrypted data is decrypted to obtain the original laboratory data.
[0020] Thirdly, the present invention also provides a laboratory data processing apparatus, configured in a storage device, comprising:
[0021] The original data encryption module is used to encrypt the original laboratory data to obtain the original data ciphertext;
[0022] The identification information encryption module is used to encrypt the device identification information of the storage device to obtain the device identification ciphertext;
[0023] The original ciphertext splitting module is used to split the original data ciphertext into at least one sub-original data ciphertext according to the length of the device identifier ciphertext, and determine the original order of each sub-original data ciphertext in the original data ciphertext.
[0024] The auxiliary ciphertext generation module is used to randomly arrange the original sub-data ciphertexts and device identifier ciphertexts to obtain auxiliary data ciphertexts.
[0025] The ciphertext order determination module is used to generate ciphertext order information based on the original order of each sub-original data ciphertext, the preset order of the device identifier ciphertext, the auxiliary order of each sub-original data ciphertext in the auxiliary data ciphertext, and the auxiliary order of the device identifier ciphertext in the auxiliary data ciphertext.
[0026] The target ciphertext generation module is used to insert the length information and ciphertext order information of the device identifier ciphertext into the auxiliary data ciphertext to obtain the target data ciphertext.
[0027] The target ciphertext sending module is used to send target data ciphertext to the service device so that the service device can decrypt the target data ciphertext to obtain the original laboratory data.
[0028] Fourthly, the present invention also provides a laboratory data processing apparatus, configured in a service device, comprising:
[0029] The target ciphertext receiving module is used to receive target data ciphertext from the storage device. The target data ciphertext is generated as follows: The original laboratory data is encrypted to obtain original data ciphertext; the device identification information of the storage device is encrypted to obtain device identification ciphertext; based on the length of the device identification ciphertext, the original data ciphertext is split into at least one sub-original data ciphertext, and the original order of each sub-original data ciphertext within the original data ciphertext is determined; the sub-original data ciphertexts and the device identification ciphertext are randomly arranged to obtain auxiliary data ciphertext; based on the original order of each sub-original data ciphertext, the preset order of the device identification ciphertext, and the auxiliary order of each sub-original data ciphertext and the auxiliary order of the device identification ciphertext within the auxiliary data ciphertext, ciphertext order information is generated; the length information and ciphertext order information of the device identification ciphertext are inserted into the auxiliary data ciphertext to obtain the target data ciphertext.
[0030] The target ciphertext splitting module is used to split the target data ciphertext to obtain the length information of the device identifier ciphertext, the ciphertext order information, and the auxiliary data ciphertext.
[0031] The auxiliary ciphertext splitting module is used to split the auxiliary data ciphertext into device identifier ciphertext and original data ciphertext based on the length information and ciphertext order information of the device identifier ciphertext.
[0032] The ciphertext decryption module is used to decrypt the device identifier ciphertext to obtain the device identifier information;
[0033] The identification information query module is used to query device identification information from a configurable set of device identification information;
[0034] The original ciphertext decryption module is used to decrypt the original data ciphertext to obtain the original laboratory data if the query result is not empty.
[0035] Fifthly, embodiments of the present invention also provide an electronic device, comprising:
[0036] At least one processor; and
[0037] A memory that is communicatively connected to at least one processor; wherein
[0038] The memory stores instructions that can be executed by at least one processor to enable the at least one processor to perform the laboratory data processing method provided in any embodiment of the present invention.
[0039] In a sixth aspect, embodiments of the present invention also provide a computer-readable storage medium storing computer instructions that, when executed by a processor, implement the laboratory data processing method of any embodiment of the present invention.
[0040] The technical solution of this invention involves encrypting the original laboratory data to obtain ciphertext; encrypting the device identification information of the storage device to obtain device identification ciphertext; dividing the original ciphertext into at least one sub-original ciphertext based on the length of the device identification ciphertext, and determining the original order of each sub-original ciphertext within the original ciphertext; randomly arranging each sub-original ciphertext and the device identification ciphertext to obtain auxiliary ciphertext; generating ciphertext order information based on the original order of each sub-original ciphertext, the preset order of the device identification ciphertext, and the auxiliary order of each sub-original ciphertext and the auxiliary order of the device identification ciphertext within the auxiliary ciphertext; inserting the length information and ciphertext order information of the device identification ciphertext into the auxiliary ciphertext to obtain the target ciphertext; and sending the target ciphertext to the service device so that the service device can decrypt the target ciphertext to obtain the original laboratory data. The technical solution of this invention splits the original data ciphertext into at least one sub-original data ciphertext, and randomly arranges each sub-original data ciphertext and the device identifier ciphertext. Compared with the prior art, which sends the complete ciphertext, this invention adds the device identifier ciphertext to the data ciphertext and changes the composition structure of the ciphertext. Even if the ciphertext is brute-forced, the original data text cannot be obtained, thus improving the security of the data ciphertext.
[0041] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description
[0042] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0043] Figure 1 This is a flowchart illustrating a laboratory data processing method according to an embodiment of the present invention;
[0044] Figure 2 This is a flowchart illustrating a laboratory data processing method according to Embodiment 2 of the present invention;
[0045] Figure 3 This is a schematic diagram of the structure of a laboratory data processing device according to Embodiment 3 of the present invention;
[0046] Figure 4 This is a schematic diagram of the structure of a laboratory data processing device according to Embodiment 4 of the present invention;
[0047] Figure 5 This is a schematic diagram of the structure of an electronic device that implements the laboratory data processing method of this invention. Detailed Implementation
[0048] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0049] It should be noted that the terms "first" and "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0050] The acquisition, storage, and application of original laboratory data in the technical solutions of this invention comply with relevant laws and regulations and do not violate public order and good morals.
[0051] Example 1
[0052] Figure 1 This is a flowchart of a laboratory data processing method provided in Embodiment 1 of the present invention. This embodiment is applicable to the situation of encrypting and decrypting data. The method can be executed by a laboratory data processing device, which can be implemented in hardware and / or software and specifically configured in an electronic device, such as a storage device.
[0053] See Figure 1 The laboratory data processing method shown is executed by a storage device and includes:
[0054] S101. Encrypt the original laboratory data to obtain the original encrypted data.
[0055] In this embodiment, the storage device can be a device that stores data. The original laboratory data can be raw laboratory data collected from the laboratory, such as laboratory temperature, laboratory humidity, and measurement data of experimental equipment. The encrypted original data can be the encrypted version of the original laboratory data. Specifically, a certain algorithm is used to encrypt the original laboratory data to obtain the encrypted original data.
[0056] Optionally, encrypting the original laboratory data to obtain the original ciphertext includes: receiving a data request message from the service device, parsing the data request message to obtain the data request time; and encrypting the original laboratory data according to the data request time to obtain the original ciphertext.
[0057] In this context, a service device can be a device that provides services to users, and the data such as images, videos, audio, and text in the service can be stored in a storage device. The service device and the storage device are communicatively connected. A data request message can be a message used to instruct the storage device to send data to the receiving device. The data request time can be the moment when the service device receives the user's data access request.
[0058] Specifically, the service device receives a user's data access request, determines the time of receipt of the data request, generates a data request message based on the data request time, and sends the data request message to the storage device. The storage device receives the data request message from the service device, parses it to obtain the data request time, converts the data request time into a string, uses the string format of the data request time as an encryption key, and encrypts the auxiliary data plaintext using a preset encryption algorithm and encryption key to obtain the original ciphertext data.
[0059] It should be noted that the present invention does not limit the method of generating the data request message, as long as the data request message can contain the data request time; the present invention does not limit the method of parsing the data request message, as long as the data request time can be parsed from the data request message.
[0060] It is understandable that by adopting the above technical solution, the original laboratory data is encrypted using a key generated at the time of data request. Compared with the method of encrypting with a fixed key in the prior art, the key in the embodiment of the present invention changes at the time of data reception, and there is no risk of the ciphertext being cracked due to the leakage of a fixed key, thus improving the security of the original data.
[0061] In an optional embodiment, before encrypting the original laboratory data to obtain the original data ciphertext according to the data request, the method further includes: for each data field name in the original laboratory data, selecting a candidate field name that matches the data field name from the candidate field names, and replacing the data field name with the candidate field name; updating the original laboratory data to the original laboratory data in which the data field names have been replaced with the candidate field names.
[0062] The alternative field names can be set independently by technical personnel based on actual needs or practical experience.
[0063] For each data field name in the original laboratory data text, determine the similarity between the data field name and each candidate field name; identify the candidate field name with the lowest similarity as the candidate field name that matches the data field name, and replace the data field name with the matching candidate field name; update the original laboratory data text with the replaced data field name.
[0064] Understandably, by adopting the above technical solution, the data field names of the original laboratory data can be replaced with alternative field names, which can prevent the leakage of data field names, protect the data storage structure of the storage device, prevent external attacks on the storage device based on the data field names, and improve the security of the storage device.
[0065] S102. Encrypt the device identification information of the storage device to obtain the device identification ciphertext.
[0066] In this embodiment, the device identification information can be used to uniquely identify the storage device. The encrypted device identification information can be the encrypted device identification information. Specifically, a preset encryption algorithm is used to encrypt the device identification information of the storage device according to the encryption key to obtain the encrypted device identification information.
[0067] S103. Based on the length of the device identifier ciphertext, split the original data ciphertext into at least one sub-original data ciphertext, and determine the original order of each sub-original data ciphertext in the original data ciphertext.
[0068] In this embodiment, the sub-original data ciphertext can be the data ciphertext obtained by splitting the original data ciphertext. The original order can be the order of the data ciphertexts within the original data ciphertext.
[0069] Specifically, the original encrypted data is used as the encrypted data to be split; the length of the encrypted data to be split is checked to see if it is less than or equal to the length of the device identifier encrypted data; if the length of the encrypted data to be split is less than or equal to the length of the device identifier encrypted data, the length difference between the length of the encrypted data to be split and the length of the device identifier encrypted data is determined; the number of special identifier characters corresponding to the length difference are merged with the encrypted data to be split to obtain a sub-original encrypted data of the same length as the device identifier encrypted data, thus completing the splitting of the original encrypted data; if the length of the encrypted data to be split is greater than the length of the device identifier encrypted data, then starting from the beginning of the encrypted data to be split, a portion of the length of the device identifier encrypted data is extracted as the sub-original encrypted data, and the encrypted data to be split is updated to the remaining encrypted data to be split after the sub-original encrypted data is extracted; the process of checking if the length of the encrypted data to be split is greater than or equal to the length of the device identifier encrypted data is repeated until the splitting of the original encrypted data is complete; the special identifier characters are different from the characters in the original encrypted data. Determine the total number of ciphertexts between each sub-original data ciphertext and the identifier data ciphertext; determine the number of bits in the original order of the sub-original data ciphertexts based on the total number of ciphertext bits; determine the original order of each sub-original data ciphertext based on the number of bits in the original order of the sub-original data ciphertexts.
[0070] For example, if the original ciphertext is “&U%8I93T!91@37U12”, the length of the identifier ciphertext is 2, and the special identifier character is “θ”, then splitting the original ciphertext yields sub-original ciphertexts including “&U”, “%8”, “I9”, “3T”, “!9”, “1@”, “37”, “U1”, and “2θ”. The number of sub-original ciphertexts is 9, so the total number of ciphertexts is 10. The number of bits used to determine the original order is 2, so the original order of the sub-original ciphertext “&U” is 01, the original order of the sub-original ciphertext “%8” is 02, the original order of the sub-original ciphertext “I9” is 03, and so on. This will not be elaborated further here.
[0071] S104. Randomly arrange the original data ciphertext and device identifier ciphertext to obtain auxiliary data ciphertext.
[0072] In this embodiment, the auxiliary data ciphertext can be a data ciphertext obtained by randomly arranging each sub-original data ciphertext and the device identifier ciphertext. It should be noted that any random arrangement method in the prior art can be used to randomly arrange each sub-original data ciphertext and the device identifier ciphertext, and the present invention does not limit this.
[0073] S105. Generate ciphertext order information based on the original order of each sub-original data ciphertext, the preset order of the device identifier ciphertext, the auxiliary order of each sub-original data ciphertext in the auxiliary data ciphertext, and the auxiliary order of the device identifier ciphertext in the auxiliary data ciphertext.
[0074] In this embodiment, the preset order of the device identifier ciphertext has the same number of bits as the original order of the sub-original data ciphertexts; the preset order of the device identifier ciphertext can be less than the original order of each sub-original data ciphertext, or the preset order of the device identifier ciphertext can be greater than the original order of each original data ciphertext. The auxiliary order can be the auxiliary order of the data ciphertext within the auxiliary data ciphertext. Ciphertext order information can be used to characterize the auxiliary order of each sub-original data ciphertext within the auxiliary data ciphertext, and the auxiliary order of the device identifier ciphertext within the auxiliary data ciphertext.
[0075] Specifically, a certain algorithm is used to generate ciphertext order information based on the original order of each sub-original data ciphertext, the preset order of the device identifier ciphertext, the auxiliary order of each sub-original data ciphertext in the auxiliary data ciphertext, and the auxiliary order of the device identifier ciphertext in the auxiliary data ciphertext.
[0076] Optionally, based on the original order of each sub-original data ciphertext and the preset order of the device identifier ciphertext, as well as the auxiliary order of each sub-original data ciphertext in the auxiliary data ciphertext and the auxiliary order of the device identifier ciphertext in the auxiliary data ciphertext, ciphertext order information is generated, including: concatenating the original order of each sub-original data ciphertext and the preset order of the device identifier ciphertext according to the auxiliary order of each sub-original data ciphertext in the auxiliary data ciphertext and the auxiliary order of the device identifier ciphertext in the auxiliary data ciphertext to obtain ciphertext order information.
[0077] For example, if the auxiliary data ciphertext is “I9B62θ37!9%83T&U1@U1”, the device identifier ciphertext “B6” has a preset order of “00”, the auxiliary order of the sub-original data ciphertext “I9” is 01, the auxiliary order of the device identifier ciphertext “B6” is 02, the auxiliary order of the sub-original data ciphertext “2θ” is 03, ..., and the auxiliary order of the sub-original data ciphertext “U1” is 10; according to the auxiliary order of each sub-original data ciphertext in the auxiliary data ciphertext and the auxiliary order of the device identifier ciphertext in the auxiliary data ciphertext, the original order of each sub-original data ciphertext and the preset order of the device identifier ciphertext are concatenated to obtain the ciphertext order information “03000907050204010608”.
[0078] Understandably, by adopting the above technical solution, the complexity of the ciphertext order information determination process is reduced, the generation efficiency of ciphertext order information is improved, and thus the generation efficiency of the original laboratory data is improved.
[0079] In an optional embodiment, a preset encryption algorithm and encryption key can be used to encrypt the ciphertext order information, and the ciphertext order information can be updated to the encrypted ciphertext order information.
[0080] S106. Insert the length information and ciphertext order information of the device identification ciphertext into the auxiliary data ciphertext to obtain the target data ciphertext.
[0081] In this embodiment, the length information of the device identifier ciphertext can be used to characterize the length of the device identifier ciphertext. The target data ciphertext is the auxiliary data ciphertext into which the length information and ciphertext order information of the device identifier ciphertext are inserted. Specifically, the length information of the device identifier ciphertext is expanded using preset expansion characters so that the length of the expanded device identifier ciphertext is the preset length; and the ciphertext order information is expanded using preset expansion characters so that the length of the expanded ciphertext order information is the preset length; the expanded length information ciphertext is inserted into the first position in the auxiliary data ciphertext; and the order information ciphertext is inserted into the second position in the auxiliary data ciphertext to obtain the target data ciphertext; wherein, the first position and the second position are different, for example, the first position can be the start position and the second position can be the end position. The preset expansion characters are different from the characters in the original data ciphertext.
[0082] In one optional embodiment, a preset fixed-length encryption algorithm is used to encrypt the length information of the device identifier ciphertext to obtain length information ciphertext, and to encrypt the ciphertext order information to obtain order information ciphertext; the length information ciphertext is inserted into a first position in the auxiliary data ciphertext; the order information ciphertext is inserted into a second position in the auxiliary data ciphertext to obtain the target data ciphertext; the preset fixed-length encryption algorithm can be a preset encryption algorithm with a fixed ciphertext length; the length of the length information ciphertext and the length of the order information ciphertext are both preset lengths.
[0083] S107. Send the target data ciphertext to the service device so that the service device can decrypt the target data ciphertext and obtain the original laboratory data.
[0084] In a specific implementation scenario, the service device can be a laboratory information display device to provide laboratory information display services to users. The storage device can be a laboratory information storage device. The original laboratory data can be experimental data such as liquid scintillation spectrometer measurement data, thermoluminescence measurement data, and total emission measurement data. The laboratory information storage device can adopt IoT-based environmental information acquisition technology to collect data from the laboratory as the original laboratory data and store it; it can also send the target data encrypted text to the service device, enabling the service device to decrypt the target data encrypted text to obtain the original laboratory data and display it.
[0085] The technical solution of this invention involves encrypting the original laboratory data to obtain ciphertext; encrypting the device identification information of the storage device to obtain device identification ciphertext; dividing the original ciphertext into at least one sub-original ciphertext based on the length of the device identification ciphertext, and determining the original order of each sub-original ciphertext within the original ciphertext; randomly arranging each sub-original ciphertext and the device identification ciphertext to obtain auxiliary ciphertext; generating ciphertext order information based on the original order of each sub-original ciphertext, the preset order of the device identification ciphertext, and the auxiliary order of each sub-original ciphertext and the auxiliary order of the device identification ciphertext within the auxiliary ciphertext; inserting the length information and ciphertext order information of the device identification ciphertext into the auxiliary ciphertext to obtain the target ciphertext; and sending the target ciphertext to the service device so that the service device can decrypt the target ciphertext to obtain the original laboratory data. The technical solution of this invention splits the original data ciphertext into at least one sub-original data ciphertext, and randomly arranges each sub-original data ciphertext and the device identifier ciphertext. Compared with the prior art, which sends the complete ciphertext, this invention adds the device identifier ciphertext to the data ciphertext and changes the composition structure of the ciphertext. Even if the ciphertext is brute-forced, the original data text cannot be obtained, thus improving the security of the data ciphertext.
[0086] Example 2
[0087] Figure 2 This is a flowchart of a laboratory data processing method provided in Embodiment 2 of the present invention. This embodiment is applicable to the situation of encrypting and decrypting data. The method can be executed by a laboratory data processing device, which can be implemented in hardware and / or software and specifically configured in an electronic device, such as a service device.
[0088] See Figure 2 The laboratory data processing method shown is performed by the service equipment and includes:
[0089] S201. Receive target data ciphertext from the storage device; wherein the target data ciphertext is generated as follows: encrypt the original laboratory data to obtain original data ciphertext; encrypt the device identification information of the storage device to obtain device identification ciphertext; according to the length of the device identification ciphertext, split the original data ciphertext into at least one sub-original data ciphertext, and determine the original order of each sub-original data ciphertext in the original data ciphertext; randomly arrange each sub-original data ciphertext and the device identification ciphertext to obtain auxiliary data ciphertext; generate ciphertext order information according to the original order of each sub-original data ciphertext, the preset order of the device identification ciphertext, the auxiliary order of each sub-original data ciphertext in the auxiliary data ciphertext, and the auxiliary order of the device identification ciphertext in the auxiliary data ciphertext; insert the length information of the device identification ciphertext and the ciphertext order information into the auxiliary data ciphertext to obtain the target data ciphertext.
[0090] In this embodiment, the storage device can be a device that stores data. The service device can be a device that provides services to users, and data such as images, videos, audio, and text in the service can be stored in the storage device. The service device is communicatively connected to the storage device. The original laboratory data can be raw laboratory data collected from the laboratory, such as laboratory temperature, laboratory humidity, and measurement data of experimental equipment. The original data ciphertext can be ciphertext obtained by encrypting the original laboratory data. Device identification information can be used to uniquely identify the storage device. Device identification ciphertext can be encrypted device identification information. The sub-original data ciphertext can be data ciphertext obtained by splitting the original data ciphertext. The original order can be the order of the data ciphertext within the original data ciphertext. The auxiliary data ciphertext can be data ciphertext obtained by randomly arranging each sub-original data ciphertext and the device identification ciphertext. The preset order of the device identification ciphertext has the same number of bits as the original order of the sub-original data ciphertext; the preset order of the device identification ciphertext can be less than the original order of each sub-original data ciphertext, or the preset order of the device identification ciphertext can be greater than the original order of each original data ciphertext. The auxiliary order can be the order of the ciphertext within the auxiliary ciphertext. Ciphertext order information can be used to characterize the auxiliary order of each sub-original ciphertext within the auxiliary ciphertext, as well as the auxiliary order of the device identifier ciphertext within the auxiliary ciphertext. The target ciphertext is the auxiliary ciphertext with the length information and ciphertext order information of the device identifier ciphertext inserted.
[0091] Specifically, the target data ciphertext is generated as follows: the original laboratory data is encrypted using a certain algorithm to obtain the original data ciphertext. Using a preset encryption algorithm, the device identification information of the storage device is encrypted according to the encryption key to obtain the device identification ciphertext; the original data ciphertext is used as the ciphertext to be split; the length of the ciphertext to be split is checked to see if it is less than or equal to the length of the device identification ciphertext; if the length of the ciphertext to be split is less than or equal to the length of the device identification ciphertext, the length difference between the length of the ciphertext to be split and the length of the device identification ciphertext is determined; the number of special identifier characters corresponding to the length difference are merged with the ciphertext to be split to obtain a sub-original data ciphertext with the same length as the device identification ciphertext, thus completing the splitting of the original data ciphertext; if the length of the ciphertext to be split is greater than the length of the device identification ciphertext, then starting from the beginning of the ciphertext to be split, a ciphertext of the length of the device identification ciphertext is extracted as the sub-original data ciphertext, and the ciphertext to be split is updated to the remaining ciphertext to be split after the sub-original data ciphertext extraction; the process of checking if the length of the ciphertext to be split is greater than or equal to the length of the device identification ciphertext is returned, until the splitting of the original data ciphertext is completed; the special identifier characters are different from the characters in the original data ciphertext. Determine the total number of ciphertexts between each sub-original data ciphertext and the identifier data ciphertext; determine the number of bits in the original order of the sub-original data ciphertexts based on the total number of ciphertext bits; determine the original order of each sub-original data ciphertext based on the number of bits in the original order of the sub-original data ciphertexts; using a certain algorithm, generate ciphertext order information based on the original order of each sub-original data ciphertext, the preset order of the device identifier ciphertext, and the auxiliary order of each sub-original data ciphertext in the auxiliary data ciphertext and the auxiliary order of the device identifier ciphertext in the auxiliary data ciphertext; specifically, use preset expansion characters... The system expands the length of the device identification ciphertext to a preset length; it also expands the ciphertext order information using a preset expansion character to a preset length; the expanded ciphertext order information is then inserted into the first position of the auxiliary data ciphertext; and the order information ciphertext is inserted into the second position of the auxiliary data ciphertext to obtain the target data ciphertext. The first and second positions are different; for example, the first position could be the start position, and the second position could be the end position. The preset expansion character is different from the special identification character and also different from the characters in the original data ciphertext.
[0092] Optionally, before receiving the target encrypted data from the storage device, the method further includes: receiving a user's data access request and determining the time of receiving the data access request; generating a data request message based on the data request time; and sending the data request message to the storage device so that the storage device can parse the data request message to obtain and return the target encrypted data to the service device.
[0093] Specifically, a data access request can be used to instruct a service device to provide the user with the original laboratory data. The data request time can be the moment when the service device receives the user's data access request. The data request message can be a message used to instruct a storage device to send data to a receiving device.
[0094] Specifically, upon receiving a user's data access request, the moment the request is received is determined as the data request moment. A specific algorithm is used to generate a data request message based on the data request moment. This message is then sent to a storage device, which parses it to obtain the data request moment. The original laboratory data is then encrypted using this moment to obtain the original ciphertext. The target ciphertext is then derived from the device identifier ciphertext and the original ciphertext, and finally fed back to the service device. It should be noted that this invention does not limit the method for generating the data request message, as long as the message includes the data request moment.
[0095] It is understood that by adopting the above technical solution, the data request can be sent to the storage device at the moment of data request, so that the storage device can encrypt the original laboratory data using the key generated at the moment of data request. Compared with the method of encryption using a fixed key in the prior art, the key in the embodiment of the present invention changes at the moment of data reception, so there is no risk of the ciphertext being cracked due to the leakage of a fixed key, thus improving the security of the original data.
[0096] S202. The target data ciphertext is split to obtain the length information of the device identification ciphertext, the ciphertext order information, and the auxiliary data ciphertext.
[0097] Specifically, a preset length of ciphertext is extracted from the first position of the target data ciphertext as the length information of the device identification ciphertext; a preset length of ciphertext is extracted from the second position of the target data ciphertext as the ciphertext order information; and the target data ciphertext after extracting the length information of the device identification ciphertext and the ciphertext order information is used as auxiliary data ciphertext.
[0098] In one optional embodiment, a preset length of ciphertext is extracted from a first position of the target data ciphertext as length information ciphertext; a preset length of ciphertext is extracted from a second position of the target data ciphertext as sequence information ciphertext; the target data ciphertext after extracting the length information and sequence information of the device identifier ciphertext is used as auxiliary data ciphertext; the length information ciphertext is decrypted using a preset fixed-length encryption algorithm corresponding to a fixed-length decryption algorithm to obtain the length information of the device identifier ciphertext; and the sequence information ciphertext is decrypted using a fixed-length decryption algorithm to obtain the ciphertext sequence information.
[0099] S203. Based on the length information and ciphertext order information of the device identification ciphertext, the auxiliary data ciphertext is split into device identification ciphertext and original data ciphertext.
[0100] Specifically, using a certain algorithm, the auxiliary data ciphertext is split into device identifier ciphertext and original data ciphertext based on the length and order of the device identifier ciphertext.
[0101] Optionally, based on the length information and ciphertext order information of the device identifier ciphertext, the auxiliary data ciphertext is split into device identifier ciphertext and original data ciphertext, including: splitting the auxiliary data ciphertext into at least one sub-auxiliary data ciphertext based on the length information of the device identifier ciphertext, and determining the auxiliary order of each sub-auxiliary data ciphertext in the auxiliary data ciphertext; determining the device identifier ciphertext from each sub-auxiliary data ciphertext based on the ciphertext order information, the preset order of the device identifier ciphertext, and the auxiliary order of each sub-auxiliary data ciphertext in the auxiliary data ciphertext, and determining the original order of the sub-auxiliary data ciphertexts other than the device identifier ciphertext in the original data ciphertext; and concatenating the sub-auxiliary data ciphertexts other than the device identifier ciphertext according to the original order of the sub-auxiliary data ciphertexts in the original data ciphertext to obtain the original data ciphertext.
[0102] Among them, the sub-auxiliary data ciphertext can be the data ciphertext obtained after splitting the auxiliary data ciphertext.
[0103] Specifically, the total number of ciphertexts in the sub-auxiliary data ciphertexts is determined; based on the total number of ciphertexts, the number of ciphertexts in the auxiliary order of the sub-auxiliary data ciphertexts within the auxiliary data ciphertexts is determined; based on the number of ciphertexts in the auxiliary order of the sub-auxiliary data ciphertexts, the auxiliary order of each sub-auxiliary data ciphertext is determined; based on the total number of ciphertexts, the ciphertext order information is split to obtain sub-order information with the same number as the total number of ciphertexts; wherein, the sub-order information includes the original order in the original data ciphertext and the preset order of the device identifier ciphertext; according to the auxiliary order of each sub-auxiliary data ciphertext and the sub-order information in... The order of the ciphertext order information is used to associate the sub-auxiliary data ciphertexts with the sub-order information. The sub-auxiliary data ciphertexts associated with the device identifier ciphertext in the preset order are determined as the device identifier ciphertexts. For each sub-auxiliary data ciphertext other than the device identifier ciphertext, the original order associated with that sub-auxiliary data ciphertext is determined as the original order of that sub-auxiliary data ciphertext in the original data ciphertext. According to the original order of the sub-auxiliary data ciphertexts in the original data ciphertext, the sub-auxiliary data ciphertexts other than the device identifier ciphertext are concatenated to obtain the original data ciphertext.
[0104] Understandably, by adopting the above technical solution, the complexity of the original data ciphertext determination process is reduced, the efficiency of determining the original data ciphertext is improved, and thus the efficiency of determining the original laboratory data is improved.
[0105] S204. Decrypt the encrypted device identification information to obtain the device identification information.
[0106] Specifically, the data request time is converted into a string format, and the string format of the data request time is used as the encryption key. A preset decryption algorithm is used to decrypt the device identification information of the storage device according to the encryption key to obtain the device identification ciphertext.
[0107] S205. Query the device identification information from the configurable set of device identification information.
[0108] In this embodiment, the configurable device identification information set can be a set of identification information of devices with the authority to send data to the service device. This configurable device identification information set can be configured independently by technical personnel based on actual needs or practical experience. Specifically, the device identification information of the storage device is queried from the configurable device identification information set, and the query result for the storage device's device identification information is determined.
[0109] S206. If the query result is not empty, the original data ciphertext is decrypted to obtain the original laboratory data.
[0110] Specifically, the auxiliary data original is decrypted using a preset encryption algorithm and encryption key to obtain the original laboratory data. In an optional embodiment, if the query result is empty, the original encrypted data is discarded and the decryption process stops.
[0111] The technical solution of this invention involves receiving target data ciphertext from a storage device. The target data ciphertext is generated as follows: encrypting the original laboratory data to obtain original data ciphertext; encrypting the device identification information of the storage device to obtain device identification ciphertext; dividing the original data ciphertext into at least one sub-original data ciphertext based on the length of the device identification ciphertext, and determining the original order of each sub-original data ciphertext within the original data ciphertext; randomly arranging each sub-original data ciphertext and the device identification ciphertext to obtain auxiliary data ciphertext; and determining the original order of each sub-original data ciphertext and the preset order of the device identification ciphertext, as well as the auxiliary order of each sub-original data ciphertext within the auxiliary data ciphertext. The order and device identifier ciphertext are used to generate ciphertext order information within the auxiliary data ciphertext. The length and order information of the device identifier ciphertext are then inserted into the auxiliary data ciphertext to obtain the target data ciphertext. The target data ciphertext is then split to obtain the length and order information of the device identifier ciphertext and the auxiliary data ciphertext. Based on the length and order information of the device identifier ciphertext, the auxiliary data ciphertext is split into device identifier ciphertext and the original data ciphertext. The device identifier ciphertext is decrypted to obtain the device identifier information. The device identifier information is then queried from the configurable set of device identifier information. If the query result is not empty, the original data ciphertext is decrypted to obtain the original laboratory data. The technical solution of this invention splits the original data ciphertext into at least one sub-original data ciphertext, and randomly arranges each sub-original data ciphertext and the device identifier ciphertext. Compared with the prior art, which sends the complete ciphertext, this invention adds the device identifier ciphertext to the data ciphertext and changes the composition structure of the ciphertext. Even if the ciphertext is brute-forced, the original data text cannot be obtained, thus improving the security of the data ciphertext.
[0112] Example 3
[0113] Figure 3 This is a schematic diagram of a laboratory data processing device according to Embodiment 3 of the present invention. This embodiment of the invention is applicable to situations involving data encryption and decryption. The device can execute laboratory data processing methods and can be implemented in hardware and / or software. The device can be configured in an electronic device, such as a storage device.
[0114] See Figure 3 The laboratory data processing device shown includes: a raw text encryption module 301, an identification information encryption module 302, a raw ciphertext splitting module 303, an auxiliary ciphertext generation module 304, a ciphertext order determination module 305, a target ciphertext generation module 306, and a target ciphertext transmission module 307, wherein...
[0115] The original data encryption module 301 is used to encrypt the original laboratory data to obtain the original data ciphertext;
[0116] The identification information encryption module 302 is used to encrypt the device identification information of the storage device to obtain the device identification ciphertext;
[0117] The original ciphertext splitting module 303 is used to split the original data ciphertext into at least one sub-original data ciphertext according to the length of the device identifier ciphertext, and determine the original order of each sub-original data ciphertext in the original data ciphertext.
[0118] The auxiliary ciphertext generation module 304 is used to randomly arrange the original sub-data ciphertexts and device identifier ciphertexts to obtain auxiliary data ciphertexts.
[0119] The ciphertext order determination module 305 is used to generate ciphertext order information based on the original order of each sub-original data ciphertext, the preset order of the device identifier ciphertext, the auxiliary order of each sub-original data ciphertext in the auxiliary data ciphertext, and the auxiliary order of the device identifier ciphertext in the auxiliary data ciphertext.
[0120] The target ciphertext generation module 306 is used to insert the length information and ciphertext order information of the device identifier ciphertext into the auxiliary data ciphertext to obtain the target data ciphertext.
[0121] The target ciphertext sending module 307 is used to send the target data ciphertext to the service device so that the service device can decrypt the target data ciphertext to obtain the original laboratory data.
[0122] This invention embodiment encrypts the original laboratory data using a plaintext encryption module to obtain ciphertext; it then encrypts the device identification information of the storage device using an identification information encryption module to obtain device identification ciphertext; a plaintext splitting module splits the plaintext into at least one sub-plaintext based on the length of the device identification ciphertext, and determines the original order of each sub-plaintext within the plaintext; an auxiliary ciphertext generation module randomly arranges the sub-plaintexts and the device identification ciphertext to obtain auxiliary ciphertext; and finally, the ciphertext is used to generate auxiliary ciphertext. The order determination module generates ciphertext order information based on the original order of each sub-original data ciphertext, the preset order of the device identifier ciphertext, and the auxiliary order of each sub-original data ciphertext and the auxiliary order of the device identifier ciphertext in the auxiliary data ciphertext. The target ciphertext generation module inserts the length information and ciphertext order information of the device identifier ciphertext into the auxiliary data ciphertext to obtain the target data ciphertext. The target ciphertext sending module sends the target data ciphertext to the service device, enabling the service device to decrypt the target data ciphertext and obtain the original laboratory data. This embodiment of the invention splits the original data ciphertext into at least one sub-original data ciphertext and randomly arranges each sub-original data ciphertext and the device identifier ciphertext. Compared to the prior art, which sends the entire ciphertext, this embodiment adds the device identifier ciphertext to the data ciphertext and changes the composition structure of the ciphertext. Even if the ciphertext is brute-forced, the original data cannot be obtained, thus improving the security of the data ciphertext.
[0123] Optionally, the ciphertext order determination module 305 includes:
[0124] The ciphertext order determination unit is used to concatenate the original order of each sub-original data ciphertext and the preset order of the device identifier ciphertext according to the auxiliary order of each sub-original data ciphertext in the auxiliary data ciphertext and the auxiliary order of the device identifier ciphertext in the auxiliary data ciphertext to obtain ciphertext order information.
[0125] Optionally, the original text encryption module 301 includes:
[0126] The message parsing unit is used to receive data request messages from the service device, parse the data request messages, and obtain the data request time.
[0127] The original encryption unit is used to encrypt the original laboratory data to obtain the original ciphertext data according to the data request time.
[0128] The laboratory data processing device provided in the embodiments of the present invention can execute the laboratory data processing method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects for executing the laboratory data processing method.
[0129] Example 4
[0130] Figure 4 This is a schematic diagram of a laboratory data processing device according to Embodiment 4 of the present invention. This embodiment of the invention is applicable to situations involving data encryption and decryption. The device can execute laboratory data processing methods and can be implemented in hardware and / or software. The device can be configured in electronic devices, such as service devices.
[0131] See Figure 4 The laboratory data processing device shown includes: a target ciphertext receiving module 401, a target ciphertext splitting module 402, an auxiliary ciphertext splitting module 403, an identifier ciphertext decryption module 404, an identifier information query module 405, and an original ciphertext decryption module 406, wherein...
[0132] The target ciphertext receiving module 401 is used to receive target data ciphertext from the storage device. The target data ciphertext is generated as follows: The original laboratory data is encrypted to obtain original data ciphertext; the device identification information of the storage device is encrypted to obtain device identification ciphertext; based on the length of the device identification ciphertext, the original data ciphertext is split into at least one sub-original data ciphertext, and the original order of each sub-original data ciphertext within the original data ciphertext is determined; each sub-original data ciphertext and the device identification ciphertext are randomly arranged to obtain auxiliary data ciphertext; based on the original order of each sub-original data ciphertext, the preset order of the device identification ciphertext, and the auxiliary order of each sub-original data ciphertext and the auxiliary order of the device identification ciphertext within the auxiliary data ciphertext, ciphertext order information is generated; the length information and ciphertext order information of the device identification ciphertext are inserted into the auxiliary data ciphertext to obtain the target data ciphertext.
[0133] The target ciphertext splitting module 402 is used to split the target data ciphertext to obtain the length information of the device identifier ciphertext, the ciphertext order information, and the auxiliary data ciphertext.
[0134] The auxiliary ciphertext splitting module 403 is used to split the auxiliary data ciphertext into device identifier ciphertext and original data ciphertext according to the length information and ciphertext order information of the device identifier ciphertext.
[0135] The ciphertext decryption module 404 is used to decrypt the device ciphertext to obtain the device ciphertext.
[0136] The identification information query module 405 is used to query device identification information from a configurable set of device identification information;
[0137] The original ciphertext decryption module 406 is used to decrypt the original data ciphertext to obtain the original laboratory data if the query result is not empty.
[0138] This invention embodiment receives target data ciphertext from a storage device via a target ciphertext receiving module. The target data ciphertext is generated as follows: The original laboratory data is encrypted to obtain original data ciphertext; the device identification information of the storage device is encrypted to obtain device identification ciphertext; based on the length of the device identification ciphertext, the original data ciphertext is split into at least one sub-original data ciphertext, and the original order of each sub-original data ciphertext within the original data ciphertext is determined; the sub-original data ciphertexts and the device identification ciphertext are randomly arranged to obtain auxiliary data ciphertext; based on the original order of each sub-original data ciphertext, the preset order of the device identification ciphertext, and the auxiliary order of each sub-original data ciphertext within the auxiliary data ciphertext, and the auxiliary order of the device identification ciphertext within the auxiliary data ciphertext... The process involves several steps: First, generating ciphertext order information. Then, inserting the length and order information of the device identifier ciphertext into the auxiliary data ciphertext to obtain the target data ciphertext. Next, a target ciphertext splitting module splits the target data ciphertext to obtain the length and order information of the device identifier ciphertext and the auxiliary data ciphertext. Finally, an auxiliary ciphertext splitting module splits the auxiliary data ciphertext into device identifier ciphertext and original data ciphertext based on the length and order information of the device identifier ciphertext. A ciphertext decryption module decrypts the device identifier ciphertext to obtain the device identifier information. An identifier information query module queries the device identifier information from a configurable set of device identifier information. Finally, an original ciphertext decryption module decrypts the original data ciphertext if the query result is not empty to obtain the original laboratory data. The technical solution of this invention splits the original data ciphertext into at least one sub-original data ciphertext, and randomly arranges each sub-original data ciphertext and the device identifier ciphertext. Compared with the prior art, which sends the complete ciphertext, this invention adds the device identifier ciphertext to the data ciphertext and changes the composition structure of the ciphertext. Even if the ciphertext is brute-forced, the original data text cannot be obtained, thus improving the security of the data ciphertext.
[0139] Optional, the auxiliary ciphertext splitting module 403 includes:
[0140] The auxiliary ciphertext splitting unit is used to split the auxiliary data ciphertext into at least one sub-auxiliary data ciphertext according to the length information of the device identifier ciphertext, and determine the auxiliary order of each sub-auxiliary data ciphertext in the auxiliary data ciphertext.
[0141] The identifier ciphertext determination unit is used to determine the device identifier ciphertext from each sub-auxiliary data ciphertext based on the ciphertext order information, the preset order of the device identifier ciphertext, and the auxiliary order of each sub-auxiliary data ciphertext in the auxiliary data ciphertext, and to determine the original order of the sub-auxiliary data ciphertexts other than the device identifier ciphertext in the original data ciphertext.
[0142] The original ciphertext determination unit is used to concatenate the sub-auxiliary data ciphertexts (excluding the device identifier ciphertext) according to their original order in the original data ciphertext to obtain the original data ciphertext.
[0143] Optionally, the laboratory data processing apparatus may also include:
[0144] The timing determination unit is used to determine the timing of receiving a user's data access request.
[0145] The message generation unit is used to generate a data request message according to the data request time.
[0146] The message sending unit is used to send a data request message to the storage device, so that the storage device can parse the data request message to obtain and return the target data ciphertext to the service device.
[0147] The laboratory data processing device provided in the embodiments of the present invention can execute the laboratory data processing method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects for executing the laboratory data processing method.
[0148] Example 5
[0149] Figure 5 A schematic diagram of an electronic device 500 that can be used to implement embodiments of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.
[0150] like Figure 5As shown, the electronic device 500 includes at least one processor 501 and a memory, such as a read-only memory (ROM) 502 or a random access memory (RAM) 503, communicatively connected to the at least one processor 501. The memory stores computer programs executable by the at least one processor. The processor 501 can perform various appropriate actions and processes based on the computer program stored in the ROM 502 or loaded into the RAM 503 from storage unit 508. The RAM 503 can also store various programs and data required for the operation of the electronic device 500. The processor 501, ROM 502, and RAM 503 are interconnected via a bus 504. An input / output (I / O) interface 505 is also connected to the bus 504.
[0151] Multiple components in electronic device 500 are connected to I / O interface 505, including: input unit 506, such as keyboard, mouse, etc.; output unit 507, such as various types of monitors, speakers, etc.; storage unit 508, such as disk, optical disk, etc.; and communication unit 509, such as network card, modem, wireless transceiver, etc. Communication unit 509 allows electronic device 500 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0152] Processor 501 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 501 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 501 performs the various methods and processes described above, such as laboratory data processing methods.
[0153] In some embodiments, the laboratory data processing method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 508. In some embodiments, part or all of the computer program may be loaded and / or mounted on electronic device 500 via ROM 502 and / or communication unit 509. When the computer program is loaded into RAM 503 and executed by processor 501, one or more steps of the laboratory data processing method described above may be performed. Alternatively, in other embodiments, processor 501 may be configured to perform the laboratory data processing method by any other suitable means (e.g., by means of firmware).
[0154] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0155] Computer programs used to implement the methods of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to the processor of a general-purpose computer, a special-purpose computer, or other programmable laboratory data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The computer programs can be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0156] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0157] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0158] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.
[0159] A computing system can include clients and servers. Clients and servers are generally geographically separated and typically interact via communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system. It addresses the shortcomings of traditional physical hosts and VPS (Virtual Private Server) services, such as high management difficulty and weak business scalability.
[0160] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.
[0161] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.
Claims
1. A laboratory data processing method, characterized in that, Performed by a storage device, the method includes: The original laboratory data is encrypted to obtain the original ciphertext data. The device identification information of the storage device is encrypted to obtain the device identification ciphertext; Based on the length of the device identifier ciphertext, the original data ciphertext is split into at least one sub-original data ciphertext, and the original order of each sub-original data ciphertext in the original data ciphertext is determined. The original data ciphertexts and the device identifier ciphertexts are randomly arranged to obtain auxiliary data ciphertexts; Ciphertext order information is generated based on the original order of each sub-original data ciphertext, the preset order of the device identifier ciphertext, the auxiliary order of each sub-original data ciphertext in the auxiliary data ciphertext, and the auxiliary order of the device identifier ciphertext in the auxiliary data ciphertext. The preset order of the device identifier ciphertext is less than the original order of each sub-original data ciphertext, or the preset order of the device identifier ciphertext is greater than the original order of each original data ciphertext. The ciphertext order information is used to characterize the auxiliary order of each sub-original data ciphertext in the auxiliary data ciphertext, and the auxiliary order of the device identifier ciphertext in the auxiliary data ciphertext. The length information of the device identifier ciphertext and the ciphertext order information are inserted into the auxiliary data ciphertext to obtain the target data ciphertext; The target data ciphertext is sent to the service device so that the service device can decrypt the target data ciphertext to obtain the original laboratory data.
2. The method according to claim 1, characterized in that, The step of generating ciphertext order information based on the original order of each sub-original data ciphertext and the preset order of the device identifier ciphertext, as well as the auxiliary order of each sub-original data ciphertext in the auxiliary data ciphertext and the auxiliary order of the device identifier ciphertext in the auxiliary data ciphertext, includes: According to the auxiliary order of each sub-original data ciphertext in the auxiliary data ciphertext and the auxiliary order of the device identifier ciphertext in the auxiliary data ciphertext, the original order of each sub-original data ciphertext and the preset order of the device identifier ciphertext are concatenated to obtain the ciphertext order information.
3. The method according to any one of claims 1-2, characterized in that, The encryption of the original laboratory data to obtain the original ciphertext includes: Upon receiving a data request message from the service device, the data request message is parsed to obtain the data request time; Based on the data request time, the original laboratory data is encrypted to obtain the original ciphertext.
4. A laboratory data processing method, characterized in that, Performed by the service device, the method includes: Receive target data ciphertext from storage device; wherein the target data ciphertext is generated as follows: encrypt the original laboratory data to obtain original data ciphertext; encrypt the device identification information of the storage device to obtain device identification ciphertext; according to the length of the device identification ciphertext, split the original data ciphertext into at least one sub-original data ciphertext, and determine the original order of each sub-original data ciphertext in the original data ciphertext; randomly arrange each sub-original data ciphertext and the device identification ciphertext to obtain auxiliary data ciphertext; according to the original order of each sub-original data ciphertext and the preset order of the device identification ciphertext, ... The auxiliary order of each sub-original data ciphertext in the auxiliary data ciphertext and the auxiliary order of the device identifier ciphertext in the auxiliary data ciphertext are used to generate ciphertext order information; the preset order of the device identifier ciphertext is less than the original order of each sub-original data ciphertext, or the preset order of the device identifier ciphertext is greater than the original order of each original data ciphertext; the ciphertext order information is used to characterize the auxiliary order of each sub-original data ciphertext in the auxiliary data ciphertext, and the auxiliary order of the device identifier ciphertext in the auxiliary data ciphertext; the length information of the device identifier ciphertext and the ciphertext order information are inserted into the auxiliary data ciphertext to obtain the target data ciphertext; The target data ciphertext is split to obtain the length information of the device identifier ciphertext, the ciphertext order information, and the auxiliary data ciphertext; Based on the length information of the device identifier ciphertext and the ciphertext order information, the auxiliary data ciphertext is split into the device identifier ciphertext and the original data ciphertext; Decrypt the encrypted device identifier to obtain the device identifier information; Query the device identification information from the configurable set of device identification information; If the query result is not empty, the original encrypted data is decrypted to obtain the original laboratory data.
5. The method according to claim 4, characterized in that, The step of splitting the auxiliary data ciphertext into the device identifier ciphertext and the original data ciphertext based on the length information and the ciphertext order information includes: Based on the length information of the device identifier ciphertext, the auxiliary data ciphertext is split into at least one sub-auxiliary data ciphertext, and the auxiliary order of each sub-auxiliary data ciphertext in the auxiliary data ciphertext is determined. Based on the ciphertext order information, the preset order of the device identifier ciphertext, and the auxiliary order of each sub-auxiliary data ciphertext in the auxiliary data ciphertext, the device identifier ciphertext is determined from each sub-auxiliary data ciphertext, and the original order of the sub-auxiliary data ciphertexts other than the device identifier ciphertext in the original data ciphertext is determined. The original data ciphertext is obtained by concatenating the sub-auxiliary data ciphertexts (excluding the device identifier ciphertext) according to their original order in the original data ciphertext.
6. The method according to any one of claims 4-5, characterized in that, Before receiving the target data ciphertext from the storage device, the following is also included: Upon receiving a user's data access request, determine the time when the data access request was received; Generate a data request message based on the data request time; The data request message is sent to the storage device so that the storage device can parse the data request message to obtain and return the target data ciphertext to the service device.
7. A laboratory data processing device, characterized in that, Configured in a storage device, the means includes: The original data encryption module is used to encrypt the original laboratory data to obtain the original data ciphertext; The identification information encryption module is used to encrypt the device identification information of the storage device to obtain device identification ciphertext; The original ciphertext splitting module is used to split the original data ciphertext into at least one sub-original data ciphertext according to the length of the device identifier ciphertext, and determine the original order of each sub-original data ciphertext in the original data ciphertext. An auxiliary ciphertext generation module is used to randomly arrange each sub-original data ciphertext and the device identifier ciphertext to obtain auxiliary data ciphertext. The ciphertext order determination module is used to generate ciphertext order information based on the original order of each sub-original data ciphertext and the preset order of the device identifier ciphertext, as well as the auxiliary order of each sub-original data ciphertext in the auxiliary data ciphertext and the auxiliary order of the device identifier ciphertext in the auxiliary data ciphertext; the preset order of the device identifier ciphertext is less than the original order of each sub-original data ciphertext, or the preset order of the device identifier ciphertext is greater than the original order of each original data ciphertext; the ciphertext order information is used to characterize the auxiliary order of each sub-original data ciphertext in the auxiliary data ciphertext and the auxiliary order of the device identifier ciphertext in the auxiliary data ciphertext. The target ciphertext generation module is used to insert the length information of the device identifier ciphertext and the ciphertext order information into the auxiliary data ciphertext to obtain the target data ciphertext. The target ciphertext sending module is used to send the target data ciphertext to the service device so that the service device can decrypt the target data ciphertext to obtain the original laboratory data.
8. A laboratory data processing device, characterized in that, Configured in a service device, the means includes: A target ciphertext receiving module is used to receive target data ciphertext from a storage device; wherein the target data ciphertext is generated in the following manner: encrypting the original laboratory data to obtain original data ciphertext; encrypting the device identification information of the storage device to obtain device identification ciphertext; splitting the original data ciphertext into at least one sub-original data ciphertext according to the length of the device identification ciphertext, and determining the original order of each sub-original data ciphertext in the original data ciphertext; randomly arranging each sub-original data ciphertext and the device identification ciphertext to obtain auxiliary data ciphertext; and according to the original order of each sub-original data ciphertext and the pre-order of the device identification ciphertext... Given an order, and the auxiliary order of each sub-original data ciphertext in the auxiliary data ciphertext, and the auxiliary order of the device identifier ciphertext in the auxiliary data ciphertext, ciphertext order information is generated. The preset order of the device identifier ciphertext is either less than or greater than the original order of each sub-original data ciphertext. The ciphertext order information is used to characterize the auxiliary order of each sub-original data ciphertext in the auxiliary data ciphertext, and the auxiliary order of the device identifier ciphertext in the auxiliary data ciphertext. The length information of the device identifier ciphertext and the ciphertext order information are inserted into the auxiliary data ciphertext to obtain the target data ciphertext. The target ciphertext splitting module is used to split the target data ciphertext to obtain the length information of the device identifier ciphertext, the ciphertext order information, and the auxiliary data ciphertext; An auxiliary ciphertext splitting module is used to split the auxiliary data ciphertext into the device identifier ciphertext and the original data ciphertext based on the length information of the device identifier ciphertext and the ciphertext order information. The ciphertext decryption module is used to decrypt the device identifier ciphertext to obtain the device identifier information; The identification information query module is used to query the device identification information from a configurable set of device identification information; The original ciphertext decryption module is used to decrypt the original data ciphertext to obtain the original laboratory data text if the query result is not empty.
9. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to implement the laboratory data processing method of any one of claims 1-3, and / or implement the laboratory data processing method of any one of claims 4-6.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that cause a processor to execute and implement the laboratory data processing method of any one of claims 1-3, and / or the laboratory data processing method of any one of claims 4-6.