Data encryption method, device, electronic device and storage medium

By processing and encrypting the transmitted data, the problem of low data transmission security in the prior art is solved, and high confidentiality and security in the data transmission process is achieved.

CN118199992BActive Publication Date: 2025-05-06北京卫达信息技术有限公司
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202410367419.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-03-28
Publication Date
2025-05-06
Estimated Expiration
2044-03-28

AI Technical Summary

Technical Problem

The existing data encryption methods are relatively low in security during transmission and cannot meet data transmission with high confidentiality requirements.

Method used

By performing the key sequence number processing on the first data to be transmitted, the first key sequence number is obtained, the first key is obtained from the preset key table, the first data to be transmitted is encrypted, the first ciphertext is obtained, and the encrypted data is transmitted to improve the security of data transmission.

Benefits of technology

This method can effectively prevent data from being tampered with during transmission, improve data transmission security, and ensure the confidentiality and security of data during transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118199992B_ABST
    Figure CN118199992B_ABST
Patent Text Reader

Abstract

A method, device, electronic device and storage medium for data encryption relate to the technical field of data encryption. In the method, first data to be transmitted is received, and the first data to be transmitted is data sent to a user device; the first data to be transmitted is processed to obtain a first key serial number; the first key corresponding to the first key serial number is obtained from a preset key table; the first data to be transmitted is encrypted using the first key to obtain a first ciphertext; the second data to be transmitted is sent to the user device so that the user device processes the second data to be transmitted, and the second data to be transmitted includes the first ciphertext. By implementing the technical solution provided in the present application, by encrypting the first data to be transmitted and then transmitting the encrypted second data to be transmitted, tampering during the data transmission process can be prevented, thereby improving the security of data transmission.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of data encryption, and in particular to a method, device, electronic device and storage medium for data encryption. Background Art

[0002] With the rapid development of network technology, network communication has become the main way for people to communicate. However, when the transmitted data contains personal sensitive information, the anonymity and confidentiality of the data are particularly important. Therefore, implementing data encryption is a key measure to ensure the security of data during cross-device transmission, which can effectively prevent data leakage or tampering.

[0003] At present, the confidentiality and integrity of data during transmission can be ensured by introducing encryption mechanisms. In traditional data encryption methods, the sender only encrypts the first data to be transmitted based on the key and then sends it, and the receiver uses the same key or other keys to decrypt it to restore the original data. When transmitting data with high confidentiality requirements, this encryption method cannot meet the encryption requirements, resulting in low security during data transmission.

[0004] Therefore, there is an urgent need for a data encryption method, device, electronic device and storage medium that can solve the above technical problems. Summary of the invention

[0005] The present application provides a method, device, electronic device and storage medium for data encryption. The method performs key serial number processing on first data to be transmitted to obtain a first key serial number, then obtains a first key corresponding to the first key serial number from a preset key table, encrypts the first data to be transmitted using the first key to obtain a first ciphertext, and then sends the second data to be transmitted to a user device. By encrypting the first data to be transmitted and then transmitting the encrypted second data to be transmitted, tampering during data transmission can be prevented, thereby improving the security of data transmission.

[0006] In a first aspect, the present application provides a method for data encryption, the method comprising: receiving first data to be transmitted, the first data to be transmitted being data sent to a user device; performing key serial number processing on the first data to be transmitted to obtain a first key serial number, the key serial number processing comprising digest calculation; obtaining a first key corresponding to the first key serial number from a preset key table; encrypting the first data to be transmitted using the first key to obtain a first ciphertext; sending second data to be transmitted to the user device so that the user device decrypts the second data to be transmitted, the second data to be transmitted comprising the first ciphertext.

[0007] By adopting the above technical solution, the first data to be transmitted is processed to obtain the first key serial number. By encrypting the data, the risk of exposing the data is reduced. Then, the first key corresponding to the first key serial number is obtained from the preset key table to reduce the risk of key leakage. Then, the first key is used to encrypt the first data to be transmitted to obtain the first ciphertext. By encrypting the data, the data can be prevented from being tampered with during the transmission process. Then, the second data to be transmitted is sent to the user device, which can effectively solve the problem of low data transmission security and ensure the confidentiality and security of the data during the transmission process.

[0008] Optionally, the first data to be transmitted is processed with a key serial number to obtain a first key serial number; specifically including: performing a digest calculation on the first data to be transmitted to obtain a first hash value; converting the first hash value according to a preset conversion rule to obtain a first numerical value; performing a decimal conversion on the first numerical value to obtain a second numerical value; obtaining the number of keys in a preset key table; calculating the second numerical value and the number of keys to obtain the first key serial number.

[0009] By adopting the above technical solution, a summary calculation is performed on the first data to be transmitted to obtain a first hash value, which can ensure the integrity of the data. The first hash value and a preset conversion rule are used to convert the first hash value to obtain a first numerical value. The first numerical value is converted into a decimal value to obtain a second numerical value. The first key serial number is determined based on the second numerical value and the number of keys. The corresponding first key is searched based on the first key serial number, thereby avoiding the need to transmit the key during the communication process and reducing the risk of key leakage.

[0010] Optionally, after using the first key to encrypt the first data to be transmitted to obtain the first ciphertext, the method also includes: obtaining a second key, where the second key is a pre-set key; using the second key to encrypt the first hash value to obtain a second ciphertext; and sending the second data to be transmitted to the user device, where the second data to be transmitted also includes the second ciphertext.

[0011] By adopting the above technical solution, the first hash value is calculated using the second key to obtain the second ciphertext, and then the second data to be transmitted is sent to the user device. The second data to be transmitted includes the first ciphertext and the second ciphertext, so that subsequent user devices can decrypt the second data to be transmitted in turn, thereby improving the security of data transmission.

[0012] Optionally, the first hash value is converted according to a preset conversion rule to obtain a first numerical value; specifically including: obtaining a target character, the target character being any character corresponding to the first hash value; querying a binary number corresponding to the target character in a preset binary table; obtaining the binary number corresponding to each target character in turn, and sorting each binary number according to the first hash value to obtain the first numerical value.

[0013] By adopting the above technical solution, the target character is obtained, and the binary number corresponding to the target character in the preset binary table is queried to realize the conversion of the first hash value, and then the binary numbers corresponding to each target character in the first hash value are obtained in turn, and the first numerical value is obtained by sorting them according to the first hash value, so as to facilitate the subsequent calculation of the first key serial number according to the first numerical value, enhance the security of the generation of the first key serial number, adapt to first hash values ​​of different lengths, and improve the efficiency of the generation of the first key serial number.

[0014] Optionally, after sending the second data to be transmitted to the user device so that the user device can decrypt the second data to be transmitted, the method also includes: the user device receives the second data to be transmitted, the second data to be transmitted including the first ciphertext and the second ciphertext; obtains the second key; uses the second key to decrypt the second ciphertext to obtain a second hash value; processes the second hash value to obtain a second key serial number; obtains a third key corresponding to the second key serial number from a preset key table; uses the third key to decrypt the first ciphertext to obtain the first data to be transmitted.

[0015] By adopting the above technical solution, the user device uses the second key to decrypt the second ciphertext to obtain a second hash value, then processes the second hash value to obtain a second key serial number, then obtains the third key corresponding to the second key serial number from the preset key table, and then uses the third key to decrypt the first ciphertext to obtain the first data to be transmitted. The second key serial number is dynamically generated according to the second hash value, reducing the risk of the third key being cracked and ensuring the security of data transmission.

[0016] Optionally, the second hash value is processed to obtain a second key serial number; specifically including: converting the second hash value according to a preset conversion rule to obtain a third numerical value; performing a decimal conversion on the third numerical value to obtain a fourth numerical value; obtaining the number of keys in a preset key table; calculating the fourth numerical value and the number of keys to obtain the second key serial number.

[0017] By adopting the above technical solution, the second hash value is converted according to the preset conversion rule to obtain the third value, the third value is further converted into a decimal value to obtain a fourth value, and then the fourth value is calculated with the number of keys in the preset key table to obtain the second key serial number. By converting and calculating the second hash value to obtain the second key serial number, a simplified third key management process is implemented, the uniqueness and security of the second key serial number are ensured, and the efficiency of data transmission and processing is improved.

[0018] Optionally, after obtaining the second key, which is a pre-set key, the method also includes: obtaining a target usage count, which is the total number of times the second key is used for encryption; determining whether the target usage count is less than or equal to a preset usage threshold; when the target usage count is greater than the preset usage threshold, confirming that a prompt message is sent to the server and the user device, the prompt message is used to prompt the user to change the second key.

[0019] By adopting the above technical solution, the number of times the second key is used is monitored, the target number of times used is obtained, and then it is determined whether the target number of times used is less than or equal to the preset usage threshold. When the target number of times used is greater than the preset usage threshold, a prompt message is sent. The prompt message is used to prompt the user to replace the second key, which can help the user to promptly discover and respond to potential security risks and prevent data leakage due to leakage or abuse of the second key.

[0020] In a second aspect of the present application, a data encryption device is provided, the device comprising a receiving unit, a processing unit and a sending unit; the receiving unit receives first data to be transmitted, the first data to be transmitted is data sent to a user device; the processing unit performs key number processing on the first data to be transmitted to obtain a first key number, the key number processing includes digest calculation; obtains a first key corresponding to the first key number from a preset key table; uses the first key to encrypt the first data to be transmitted to obtain a first ciphertext; the sending unit sends second data to be transmitted to the user device, so that the user device decrypts the second data to be transmitted, the second data to be transmitted includes the first ciphertext.

[0021] Optionally, the processing unit is used to perform a digest calculation on the first data to be transmitted to obtain a first hash value; convert the first hash value according to a preset conversion rule to obtain a first numerical value; perform a decimal conversion on the first numerical value to obtain a second numerical value; the receiving unit is used to obtain the number of keys in a preset key table; the processing unit is used to calculate the second numerical value and the number of keys to obtain a first key serial number.

[0022] Optionally, the receiving unit is used to obtain a second key, which is a pre-set key; the processing unit is used to encrypt the first hash value using the second key to obtain a second ciphertext; the sending unit is used to send the second data to be transmitted to the user device, and the second data to be transmitted also includes a second ciphertext.

[0023] Optionally, the receiving unit is used to obtain a target character, where the target character is any character corresponding to the first hash value; the processing unit is used to query the binary number corresponding to the target character in a preset binary table; obtain the binary number corresponding to each target character in turn, sort each binary number according to the first hash value, and obtain a first numerical value.

[0024] Optionally, the receiving unit is used for the user device to receive second data to be transmitted, the second data to be transmitted including a first ciphertext and a second ciphertext; obtain a second key; the processing unit is used to decrypt the second ciphertext using the second key to obtain a second hash value; process the second hash value to obtain a second key serial number; obtain a third key corresponding to the second key serial number from a preset key table; and use the third key to decrypt the first ciphertext to obtain the first data to be transmitted.

[0025] Optionally, the processing unit is used to convert the second hash value according to a preset conversion rule to obtain a third value; perform decimal conversion on the third value to obtain a fourth value; the receiving unit is used to obtain the number of keys in a preset key table; the processing unit is used to calculate the fourth value and the number of keys to obtain a second key serial number.

[0026] Optionally, the receiving unit is used to obtain a target usage count, which is the total number of times the second key is used for encryption; the processing unit is used to determine whether the target usage count is less than or equal to a preset usage threshold; and the sending unit is used to confirm that a prompt message is sent to the server and the user device when the target usage count is greater than the preset usage threshold, and the prompt message is used to prompt the user to change the second key.

[0027] In a third aspect of the present application, an electronic device is provided, which includes a processor, a memory, a user interface and a network interface, the memory is used to store instructions, the user interface and the network interface are used to communicate with other devices, and the processor is used to execute the instructions stored in the memory, so that an electronic device executes any one of the methods described above in the present application.

[0028] In a fourth aspect of the present application, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores instructions, and when the instructions are executed, any one of the above methods of the present application is executed.

[0029] In summary, one or more technical solutions provided in the embodiments of the present application have at least the following technical effects or advantages:

[0030] 1. Process the first data to be transmitted to obtain a first key serial number, encrypt the data to reduce the risk of exposing the data, obtain the first key corresponding to the first key serial number from the preset key table to reduce the risk of key leakage, and then use the first key to encrypt the first data to be transmitted to obtain a first ciphertext. By encrypting the data, the data can be prevented from being tampered with during transmission. Then, the second data to be transmitted is sent to the user device, which can effectively solve the problem of low data transmission security and ensure the confidentiality and security of the data during transmission.

[0031] 2. Perform a summary calculation on the first data to be transmitted to obtain a first hash value to ensure the integrity of the data, then use the first hash value and a preset conversion rule to convert the first hash value to obtain a first numerical value, perform a decimal conversion on the first numerical value to obtain a second numerical value, and then determine the first key serial number based on the second numerical value and the number of keys, and search for the corresponding first key based on the first key serial number to avoid the need to transmit the key during the communication process and reduce the risk of key leakage.

[0032] 3. The user device uses the second key to decrypt the second ciphertext to obtain a second hash value, then processes the second hash value to obtain a second key serial number, then obtains the third key corresponding to the second key serial number from the preset key table, and then uses the third key to decrypt the first ciphertext to obtain the first data to be transmitted. The second key serial number is dynamically generated according to the second hash value, reducing the risk of the third key being cracked and ensuring the security of data transmission.

[0033] 4. Monitor the number of times the second key is used, obtain the target number of times used, and then determine whether the target number of times used is less than or equal to the preset usage threshold. When the target number of times used is greater than the preset usage threshold, send a prompt message. The prompt message is used to prompt the user to replace the second key, which can help the user promptly discover and respond to potential security risks and prevent data leakage due to leakage or abuse of the second key. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] Figure 1 It is a flowchart of a data encryption method provided in an embodiment of the present application;

[0035] Figure 2 It is a structural schematic diagram of a data encryption device provided in an embodiment of the present application;

[0036] Figure 3 It is a structural schematic diagram of an electronic device disclosed in an embodiment of the present application.

[0037] Explanation of the reference numerals: 201, receiving unit; 202, processing unit; 203, sending unit; 300, electronic device; 301, processor; 302, communication bus; 303, user interface; 304, network interface; 305, memory. DETAILED DESCRIPTION

[0038] In order to enable technicians in this field to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below in conjunction with the drawings in the embodiments of this specification. Obviously, the described embodiments are only part of the embodiments of this application, not all of the embodiments.

[0039] In the description of the embodiments of the present application, words such as "for example" or "for example" are used to indicate examples, illustrations or explanations. Any embodiment or design described as "for example" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or more advantageous than other embodiments or designs. Specifically, the use of words such as "for example" or "for example" is intended to present related concepts in a specific way.

[0040] In the description of the embodiments of the present application, the meaning of the term "multiple" refers to two or more. For example, multiple systems refer to two or more systems, and multiple screen terminals refer to two or more screen terminals. In addition, the terms "first" and "second" are used for descriptive purposes only and cannot be understood as indicating or implying relative importance or implicitly indicating the indicated technical features. Thus, the features defined as "first" and "second" may explicitly or implicitly include one or more of the features. The terms "include", "comprise", "have" and their variations all mean "including but not limited to", unless otherwise specifically emphasized.

[0041] With the rapid development of network technology, network communication has become the main way for people to communicate. However, when the transmitted data contains personal sensitive information, the anonymity and confidentiality of the data are particularly important. Therefore, implementing data encryption is a key measure to ensure the security of data during cross-device transmission, which can effectively prevent data leakage or tampering.

[0042] At present, the confidentiality and integrity of data during transmission can be ensured by introducing encryption mechanisms. Data encryption methods include symmetric encryption and asymmetric encryption. In symmetric encryption, the sender and the receiver share the same key to encrypt and decrypt data. In asymmetric encryption, the sender encrypts the data by using the receiver's public key, and then sends the encrypted data to the receiver. The receiver then uses the private key to decrypt the encrypted data to restore the original data.

[0043] However, in the above data encryption method, the sender only encrypts the first data to be transmitted based on the key and then sends it, and the receiver uses the same key or other keys to decrypt it to restore the original data. When enterprises transmit important data, they have high requirements for the confidentiality of the transmitted data. The above encryption method has the problem of low security and cannot meet the data transmission with high confidentiality requirements.

[0044] Therefore, a new encryption method is urgently needed to encrypt data, and improving the security of data transmission is an urgent problem to be solved. A data encryption method provided in an embodiment of the present application is applied to a server. The server of the present application refers to a device for data transmission within an enterprise. Figure 1is a flow chart of a data encryption method provided in an embodiment of the present application, refer to Figure 1 The method includes the following steps S101-S105.

[0045] S101: Receive first data to be transmitted.

[0046] In the above S101, the server receives the first data to be transmitted through a specific data interface or network protocol. The first data to be transmitted refers to the data that the server needs to send to the user device. The first data to be transmitted includes text, images, videos, audio or other forms of digital information. After receiving the first data to be transmitted, the server needs to ensure the integrity and accuracy of the first data to be transmitted to avoid data loss during the subsequent transmission of the first data to be transmitted.

[0047] For example, in an enterprise, employee A needs to send contract data to customer B. The contract data is confidential data and needs to be encrypted to ensure data security. If the contract data is not encrypted and directly transmitted in plain text, it may be stolen by others during the transmission process. If the data is stolen, there will be a risk of information leakage. Therefore, the contract data is defined as the first data to be transmitted so that the first data to be transmitted can be processed later.

[0048] S102: Perform key serial number processing on the first data to be transmitted to obtain a first key serial number.

[0049] In the above S102, after receiving the first data to be transmitted, the server needs to perform key serial number processing on the first data to be transmitted to obtain the first key serial number, and the key serial number processing includes digest calculation. Performing key serial number processing on the first data to be transmitted to obtain the first key serial number specifically includes: performing digest calculation on the first data to be transmitted to obtain a first hash value; converting the first hash value according to a preset conversion rule to obtain a first numerical value; performing decimal conversion on the first numerical value to obtain a second numerical value; obtaining the number of keys in the preset key table; calculating the second numerical value and the number of keys to obtain the first key serial number.

[0050] Specifically, after obtaining the first data to be transmitted, a digest calculation is performed on the first data to be transmitted to obtain a first hash value. The digest calculation is usually used to generate a short, fixed-size first hash value of the data. The first hash value can uniquely identify the original data (the first data to be transmitted), that is, the probability that different data will generate the same hash value is extremely low and can be ignored. Digest algorithms include MD5, SHA-1, and SHA-256. According to different security requirements and the nature of the first data to be transmitted, a suitable digest algorithm can be selected to preprocess the first data to be transmitted, such as padding and formatting, to meet the requirements of the digest algorithm. Finally, the preprocessed first data to be transmitted is calculated using the selected digest algorithm to generate a fixed-length hash value as output, namely the first hash value.

[0051] Then, the first hash value is converted according to the pre-configured preset conversion rule to obtain the first numerical value. Since the first hash value is usually binary or other forms of encoding, the first hash value can be converted into the form of the first numerical value for subsequent calculation and processing. Converting the first hash value according to the preset conversion rule to obtain the first numerical value specifically includes: obtaining the target character, the target character is any character corresponding to the first hash value; querying the binary number corresponding to the target character in the preset binary table; obtaining the binary numbers corresponding to each target character in turn, and sorting each binary number according to the first hash value to obtain the first numerical value. Specifically, a character can be selected from the first hash value as the target character. Since the first hash value is usually a string, any character can be selected as the processing object, that is, the target character. The format of the first hash value can be determined in advance, including hexadecimal, binary or other forms, and then according to the format of the first hash value, the first character, the last character or a character in the middle is selected as the target character. In order to avoid missing a character in the first hash value, each character in the first hash value can be processed in order from left to right, or from right to left. The specific order can be selected based on the actual situation. Then extract the target character from the first hash value according to the above sequence. It is necessary to establish a preset binary table in advance, and the preset binary table can be set based on the characters appearing in the hash value, and then set a custom binary number for each character in turn, and then establish the correspondence between the single character and the binary number in turn, and store the correspondence in the preset binary table. After the preset binary table is constructed, the target character is input into the preset binary table for query to obtain the binary number corresponding to the target character. After determining the binary number corresponding to the target character, the other characters in the first hash value are obtained in turn, and the binary numbers corresponding to the other characters are queried in turn. That is, each character of the first hash value is obtained, and each character is input into the preset binary table in turn for query to obtain the binary numbers corresponding to multiple characters, and then the multiple binary numbers are sorted according to the order of the first hash value to obtain the first value. The first value can be understood as obtaining the binary numbers corresponding to all characters in the first hash value, and splicing the binary numbers corresponding to each character according to the order of the characters in the first hash value to form a continuous binary number sequence, and this sequence is the first value. Converting the first hash value into the first numerical value can facilitate subsequent encryption and transmission, thereby increasing the repeatability and security of encryption.

[0052] For example, if a summary calculation is performed on the first data to be transmitted to obtain a first hash value, the first hash value can be set to A381b, and each target character in the first hash value is obtained in turn, the target characters are A, 3, 8, 1 and b, and the target characters can be sequentially input into a preset binary table for query. If the binary number corresponding to A in the preset binary table is 10, the binary number corresponding to b is 11, the binary number corresponding to 1 is 01, the binary number corresponding to 3 is 0001, and the binary number corresponding to 8 is 00000001, multiple binary numbers are spliced ​​according to the order of each target character in the first hash value to obtain 100001000000010111, and the first value is 100001000000010111. The setting of the above binary numbers can be selected based on actual conditions, and this is just an example.

[0053] After obtaining the first value, which is a binary number sequence composed of multiple binary numbers, the first value is converted into a decimal number to obtain the second value. Since the first value is a binary number, the binary number is converted into a decimal number, and the converted value is the second value. Then the number of keys in the preset key table is obtained. At this time, the preset key table means that before data transmission, a common key table, i.e., a preset key table, needs to be configured for both parties of communication in advance. Multiple keys are stored in the preset key table so that the keys can be used to encrypt the first data to be transmitted later. The key is a specific string of characters or digital combinations. The key plays a vital role in the fields of cryptography and information security, and is mainly used to encrypt and decrypt data. The key can be set based on different scenarios. If the data transmission scenario is within the enterprise, the employee number plus the enterprise name can be used as the configuration option of the key. If the data transmission scenario is between enterprises, the name processing number of the employees in both enterprises can be used as the configuration option of the key, and different keys can be configured for different scenarios. After storing multiple keys in the preset key table, each key is sorted in turn, and then the sequence number is marked according to the sorting, so that the corresponding key can be found according to the key sequence number later. Then, the total number of keys stored in the preset key table is obtained, that is, the total number of keys stored, and the second value and the number of keys are used for calculation to obtain the first key serial number. A valid first key serial number is generated according to the first data to be transmitted, and then the corresponding key is retrieved from the preset key table for encryption operation, thereby improving the security and flexibility of key generation.

[0054] In the above example, the first value is 100001000000010111. The first value is converted to decimal, that is, starting from the rightmost of the first value, a weight is assigned to each bit, starting from 0 and increasing, the rightmost bit weight is 0, and then the weight of each bit to the left is added by 1. Multiply the digit (0 or 1) on each bit by the corresponding weight, and finally add all the products. The result is the decimal number corresponding to the binary number, that is, the second value. The first value is converted to a decimal number of 541063, that is, the second value is 541063. The specific calculation process is a conventional calculation process, which is not repeated here. Get the number of keys in the preset key table. If the number of keys is 1000, read them in sequence according to the sequence number in the preset key table to determine the key corresponding to the second value in the preset key table. If the preset key table is read repeatedly multiple times to determine the key corresponding to the second value in the preset key table, then get the sequence number corresponding to the key in the preset key table, that is, the first key sequence number. If the first key sequence number is 541.

[0055] S103: Obtain a first key corresponding to the first key sequence number from a preset key table.

[0056] In the above S103, after the first data to be transmitted is processed to obtain the first key serial number, the first key serial number is input into the preset key table for query to obtain the first key corresponding to the first key serial number.

[0057] In the above example, when the first key serial number is 541, the first key corresponding to the first key serial number is queried in the preset key table, if the first key is zly235684.

[0058] S104: Encrypt the first data to be transmitted using the first key to obtain a first ciphertext.

[0059] In the above S104, after obtaining the first key, the server can use the first key to perform an encryption operation on the first data to be transmitted, and can use a symmetric encryption algorithm to encrypt the first data to be transmitted. During the encryption process, the server converts the first data to be transmitted into a form that can only be interpreted by the recipient holding the same key, that is, the first ciphertext. The process of encrypting the first data to be transmitted ensures the confidentiality and security of the data during the transmission process.

[0060] In addition, after the server determines to use the first key to encrypt the first data to be transmitted and obtain the first ciphertext. The receiver needs to use the first key to decrypt the first ciphertext, but using the first key to encrypt the first data to be transmitted is to process the first data to be transmitted and obtain the first key. In order to ensure that the receiver can decrypt the first ciphertext and obtain the original data, that is, the first data to be transmitted. The receiver needs to determine the first key for encrypting the first ciphertext, and can encrypt the first hash value to obtain the second ciphertext, so that the receiver can process the first hash value to obtain the first key for encrypting the first ciphertext. Specifically including: obtaining the second key, the second key is a pre-set key; using the second key to encrypt the first hash value to obtain the second ciphertext; sending the second data to be transmitted to the user device, and the second data to be transmitted also includes the second ciphertext.

[0061] Specifically, a fixed key between the server and the user device, that is, a second key, is obtained. The second key can also be understood as a key that is pre-fixed and stored in both parties (server and user device). The storage location can be an encrypted file, a hardware security module, and an encrypted field in a database. In order to ensure the security of the second key, before obtaining the second key, the device that obtains the second key needs to be verified to verify whether the server has the authority to access the second key. After the server is verified, the server can obtain the second key. The second key is then used to encrypt the first hash value. A suitable encryption algorithm can be selected according to the requirements to encrypt the first hash value. The encryption algorithm includes symmetric encryption and asymmetric encryption. The specific encryption algorithm selected depends on the type of the second key. The first hash value is encrypted using the selected encryption algorithm and the second key to obtain an encrypted ciphertext, that is, a second ciphertext. After the encryption is completed, the server can verify the second ciphertext to verify whether the generated second ciphertext is complete. The verification includes checking the length or format of the ciphertext. Finally, the first ciphertext and the second ciphertext are packaged into a complete second data to be transmitted, and then the second data to be transmitted is sent to the user device according to the communication protocol between the server and the user device. When sending the second data to be transmitted, it is necessary to confirm that a network connection has been established between the server and the user device, and then send the second data to be transmitted. During the sending process, the security of communication transmission should be ensured, and TLS or SSL can be used to encrypt the communication channel to prevent the data from being intercepted during the transmission process.

[0062] S105: Sending second data to be transmitted to the user equipment so that the user equipment can decrypt the second data to be transmitted, where the second data to be transmitted includes the first ciphertext.

[0063] In the above S105, after using the first key to encrypt the first data to be transmitted to obtain the first ciphertext, the second key is also used to encrypt the first hash value to obtain the second ciphertext. Then the first ciphertext and the second ciphertext are packaged into a complete second data to be transmitted, and the server then sends the second data to be transmitted to the user device. At this time, the user device refers to the device that transmits data with the server. If the server is the sender, the user device represents the receiver. So that the user device can process the second data to be transmitted. Before sending the second data to be transmitted to the user device, the server needs to perform an integrity check on the second data to be transmitted to avoid loss during the transmission process. The second data to be transmitted includes the first ciphertext and the second ciphertext. The first ciphertext represents the important data of this transmission, and the second ciphertext represents the first key used to encrypt the first ciphertext, so that the user device can obtain the first key used to encrypt the first ciphertext by processing the second ciphertext, and then decrypt the first ciphertext according to the first key.

[0064] Further, after receiving the second data to be transmitted sent by the server, the user device needs to decrypt the second data to be transmitted to obtain the original data, that is, the first data to be transmitted. Specifically, it includes: the user device receives the second data to be transmitted, and the second data to be transmitted includes the first ciphertext and the second ciphertext; obtains the second key; uses the second key to decrypt the second ciphertext to obtain the second hash value; processes the second hash value to obtain the second key sequence number; obtains the third key corresponding to the second key sequence number from the preset key table; uses the third key to decrypt the first ciphertext to obtain the first data to be transmitted. Specifically, the user device receives the second data to be transmitted sent from the sender through a network connection, and the sender refers to the server at this time. After receiving the second data to be transmitted, the user device decompresses the second data to be transmitted to obtain the first ciphertext and the second ciphertext. The user device needs to obtain the second key for decrypting the second ciphertext, because the second key is pre-stored on the user device. The user device accesses the storage area storing the second key and searches for the pre-stored second key. Before obtaining the second key, the user device needs to verify the user device to ensure that only authorized devices can access and obtain the second key. After obtaining the second key, the second ciphertext is decrypted using the second key to restore the original first hash value, that is, the second hash value. When the second ciphertext is decrypted using the second key, the user device can select an appropriate decryption algorithm according to the encryption method of the second ciphertext and the type of the second key, and obtain the second hash value after decryption. The second hash value is then processed to obtain the second key serial number.

[0065] Further, the second hash value is processed to obtain the second key serial number; specifically including: converting the second hash value according to the preset conversion rule to obtain the third value; performing decimal conversion on the third value to obtain the fourth value; obtaining the number of keys in the preset key table; calculating the fourth value and the number of keys to obtain the second key serial number. Specifically, the second hash value is converted according to the preset conversion rule to obtain the third value, that is, obtaining the first character corresponding to the second hash value, the first character is any character corresponding to the second hash value, and then querying the binary number corresponding to the first character in the preset binary table, and finally obtaining the binary numbers corresponding to each first character in turn, and sorting each binary number according to the second hash value to obtain the third value. The conversion process of the third value is similar to the conversion process of the first value mentioned above, and will not be repeated here. Then, according to the current base of the third value, the third value is converted to decimal to obtain the fourth value, and the fourth value is the converted decimal value. Then obtain the number of keys in the preset key table, and the preset key table means that before data transmission, a common key table, that is, a preset key table, needs to be configured for both parties in advance. Multiple keys are stored in the preset key table, and the number of keys in the preset key table needs to be obtained. The number of keys can be obtained by accessing the header information of the preset key table. Then the number of keys and the fourth value are calculated to obtain the second key serial number. The calculation process of the second key serial number is similar to the calculation process of the first key serial number, and no further details are given here. The third key corresponding to the second key serial number is obtained from the preset key table. At this time, the third key is the key obtained by calculating the second hash value to encrypt the first data to be transmitted. The user device accesses the preset key table, uses the second key serial number as an index, searches for the corresponding third key in the preset key table, and then uses the third key to decrypt the first ciphertext to restore the original first data to be transmitted. In this application, if the processing process of the second hash value and the first hash value is consistent, the first key and the third key obtained are the same key. If the processing process of the second hash value and the first hash value is inconsistent, the first key and the third key will not be the same key, and when the first ciphertext is decrypted using the third key, the first ciphertext will display a key error, and the first ciphertext needs to be decrypted again. The user equipment successfully receives the second data to be transmitted, and then processes the second data to be transmitted to obtain the original first data to be transmitted. This process ensures the confidentiality and integrity of the data.

[0066] In a possible implementation, in order to effectively monitor the number of times the second key is used and to remind the user to replace the second key in time when necessary, thereby improving the security of the second key, it specifically includes: obtaining a target number of times used, which is the total number of times the second key is used for encryption; determining whether the target number of times used is less than or equal to a preset usage threshold; when the target number of times used is greater than the preset usage threshold, confirming to send a prompt message to the server and the user device, the prompt message is used to prompt the user to replace the second key.

[0067] Specifically, the server obtains the total number of times the second key is used for encryption operations, that is, the target number of times of use, which can be obtained based on the tracking and recording of the device. In the management system of the user device and the server, a usage timer can also be initialized for the second key, and the initial value is usually 0. Whenever the second key is used for encryption operations, whether it is for current data or batch data, the timer update will be triggered, and the timer value will be increased by 1 after each encryption. The target number of times of use can be obtained in sequence by obtaining the timer value. Then it is determined whether the target number of times of use is less than or equal to the preset usage threshold. The preset usage threshold is a preset value used to determine whether the second key should be replaced. The preset usage threshold can be determined based on security requirements and the sensitivity of encrypted data. When the target number of times of use is greater than the preset usage threshold, it is confirmed to send a prompt message to the server and the user device. When it is determined that the second key is to be replaced, a prompt message needs to be sent to both parties of this communication to notify the user to replace the second key in time. When sending the prompt message, a prompt message containing necessary information can be generated based on a preset template or rule. The prompt message includes the identifier of the second key, the current number of times of use, and the importance of changing the key. Then determine the target device that needs to receive the prompt information, and the target device includes the user device and the server. After the server and the user device receive the prompt information, they need to process the prompt information accordingly to ensure that the risk of key leakage will occur if the second key is used for a long time.

[0068] For example, if the second key is used 10 times, the preset usage threshold can be set to 8 times. If the target usage number is greater than the preset usage threshold, it is confirmed that a prompt message is sent to the user device and the server to replace the second key to avoid the risk of data leakage due to failure to replace the second key.

[0069] Further, when the target usage times is less than or equal to the preset usage threshold, it is confirmed that the usage times of the second key is still within the normal range, and there is no need to replace the second key, and the usage times of the second key continue to be monitored.

[0070] Using the above method, before transmitting data, the present application needs to first obtain the first data to be transmitted that needs to be transmitted this time, process the first data to be transmitted this time to obtain the first key for encrypting the first data to be transmitted, and then use the first key to encrypt the first data to be transmitted to obtain the first ciphertext. Since the first data to be transmitted is different each time, the first key for encryption is also different each time. In order to ensure that the recipient determines the key for encrypting the first ciphertext, the first hash value is encrypted using the second key to obtain the second ciphertext. The recipient can use the second key to decrypt the second ciphertext to obtain the second hash value, and process the second hash to obtain the third key. Subsequently, the first ciphertext is decrypted using the third key to obtain the first data to be transmitted, thereby realizing encryption and secure transmission of the first data to be transmitted, and ensuring the security of the data.

[0071] The present application also provides a data encryption device. Figure 2 is a schematic diagram of a data encryption device provided in an embodiment of the present application, with reference to Figure 2 The device includes a receiving unit 201, a processing unit 202 and a sending unit 203.

[0072] The receiving unit 201 receives first data to be transmitted, where the first data to be transmitted is data sent to a user equipment.

[0073] The processing unit 202 performs key serial number processing on the first data to be transmitted to obtain a first key serial number, where the key serial number processing includes digest calculation; obtains a first key corresponding to the first key serial number from a preset key table; and encrypts the first data to be transmitted using the first key to obtain a first ciphertext.

[0074] The sending unit 203 sends second data to be transmitted to the user equipment so that the user equipment can decrypt the second data to be transmitted, where the second data to be transmitted includes the first ciphertext.

[0075] In a possible implementation, the processing unit 202 is used to perform a summary calculation on the first data to be transmitted to obtain a first hash value; convert the first hash value according to a preset conversion rule to obtain a first numerical value; perform a decimal conversion on the first numerical value to obtain a second numerical value; the receiving unit 201 is used to obtain the number of keys in a preset key table; the processing unit 202 is used to calculate the second numerical value and the number of keys to obtain a first key serial number.

[0076] In a possible implementation, the receiving unit 201 is used to obtain a second key, which is a pre-set key; the processing unit 202 is used to encrypt the first hash value using the second key to obtain a second ciphertext; the sending unit 203 is used to send the second data to be transmitted to the user device, and the second data to be transmitted also includes a second ciphertext.

[0077] In a possible implementation, the receiving unit 201 is used to obtain a target character, where the target character is any character corresponding to a first hash value; the processing unit 202 is used to query a binary number corresponding to the target character in a preset binary table; the binary numbers corresponding to each target character are obtained in turn, and each binary number is sorted according to the first hash value to obtain a first numerical value.

[0078] In a possible implementation, the receiving unit 201 is used by a user device to receive second data to be transmitted, the second data to be transmitted including a first ciphertext and a second ciphertext; obtain a second key; the processing unit 202 is used to decrypt the second ciphertext using the second key to obtain a second hash value; process the second hash value to obtain a second key serial number; obtain a third key corresponding to the second key serial number from a preset key table; and use the third key to decrypt the first ciphertext to obtain the first data to be transmitted.

[0079] In a possible implementation, the processing unit 202 is used to convert the second hash value according to a preset conversion rule to obtain a third value; perform decimal conversion on the third value to obtain a fourth value; the receiving unit 201 is used to obtain the number of keys in a preset key table; and the processing unit is used to calculate the fourth value and the number of keys to obtain a second key serial number.

[0080] In one possible implementation, the receiving unit 201 is used to obtain a target usage count, which is the total number of times the second key is used for encryption; the processing unit 202 is used to determine whether the target usage count is less than or equal to a preset usage threshold; the sending unit 203 is used to confirm that a prompt message is sent to the server and the user device when the target usage count is greater than the preset usage threshold, and the prompt message is used to prompt the user to change the second key.

[0081] It should be noted that: when the device provided in the above embodiment realizes its function, only the division of the above functional modules is used as an example. In actual application, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. In addition, the device and method embodiments provided in the above embodiment belong to the same concept, and the specific implementation process is detailed in the method embodiment, which will not be repeated here.

[0082] The present application also discloses an electronic device. Figure 3 , Figure 3 The electronic device 300 may include: at least one processor 301 , at least one network interface 304 , a user interface 303 , a memory 305 , and at least one communication bus 302 .

[0083] The communication bus 302 is used to realize the connection and communication between these components.

[0084] The user interface 303 may include a display screen (Display) and a camera (Camera). Optionally, the user interface 303 may also include a standard wired interface and a wireless interface.

[0085] The network interface 304 may optionally include a standard wired interface or a wireless interface (such as a WI-FI interface).

[0086] Among them, the processor 301 may include one or more processing cores. The processor 301 uses various interfaces and lines to connect various parts in the entire server, and executes various functions of the server and processes data by running or executing instructions, programs, code sets or instruction sets stored in the memory 305, and calling data stored in the memory 305. Optionally, the processor 301 can be implemented in at least one hardware form of digital signal processing (Digital Signal Processing, DSP), field programmable gate array (Field-Programmable Gate Array, FPGA), and programmable logic array (Programmable Logic Array, PLA). The processor 301 can integrate one or a combination of a central processing unit (Central Processing Unit, CPU), a graphics processing unit (Graphics Processing Unit, GPU) and a modem. Among them, the CPU mainly processes the operating system, user interface and application requests; the GPU is responsible for rendering and drawing the content to be displayed on the display screen; the modem is used to process wireless communications. It can be understood that the above-mentioned modem may not be integrated into the processor 301, and it can be implemented separately through a chip.

[0087] Among them, the memory 305 may include a random access memory (RAM) or a read-only memory (Read-Only Memory). Optionally, the memory 305 includes a non-transitory computer-readable storage medium. The memory 305 can be used to store instructions, programs, codes, code sets or instruction sets. The memory 305 may include a program storage area and a data storage area, wherein the program storage area. Instructions for implementing an operating system, instructions for at least one function (such as a touch function, a sound playback function, an image playback function, etc.), instructions for implementing the above-mentioned various method embodiments, etc. can be stored; the data storage area can store data involved in the above-mentioned various method embodiments, etc. The memory 305 can also be optionally at least one storage device located away from the aforementioned processor 301.

[0088] like Figure 3 As shown, the memory 305 as a computer storage medium may include an operating system, a network communication module, a user interface module, and a data encryption application.

[0089] exist Figure 3 In the electronic device 300 shown, the user interface 303 is mainly used to provide an input interface for the user and obtain data input by the user; and the processor 301 can be used to call the application program for storing data encryption in the memory 305. When executed by one or more processors, the electronic device executes one or more methods described in the above embodiments.

[0090] It should be noted that, for the aforementioned method embodiments, for the sake of simplicity, they are all described as a series of action combinations, but those skilled in the art should be aware that the present application is not limited by the order of the actions described, because according to the present application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily required for the present application.

[0091] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0092] In the several embodiments provided in the present application, it should be understood that the disclosed devices can be implemented in other ways. For example, the device embodiments described above are only schematic, such as the division of the units, which is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some service interfaces, and the indirect coupling or communication connection of devices or units can be electrical or other forms.

[0093] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0094] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.

[0095] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable memory. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, which is stored in a memory and includes several instructions for a computer device (which can be a personal computer, server or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned memory includes: various media that can store program codes, such as USB flash drives, mobile hard drives, magnetic disks or optical disks.

[0096] The above is only an exemplary embodiment of the present disclosure and cannot be used to limit the scope of the present disclosure. That is, any equivalent changes and modifications made according to the teachings of the present disclosure are still within the scope of the present disclosure. After considering the disclosure of the specification and the truth of practice, it will be easy for those skilled in the art to think of other embodiments of the present disclosure. This application is intended to cover any variation, use or adaptive change of the present disclosure, which follows the general principles of the present disclosure and includes common knowledge or customary technical means in the technical field that are not recorded in the present disclosure.

Claims

1. A method for data encryption, characterized in that: The method comprises: receiving first data to be transmitted; Performing key serial number processing on the first data to be transmitted to obtain a first key serial number, wherein the key serial number processing includes digest calculation; performing key serial number processing on the first data to be transmitted to obtain a first key serial number; specifically comprising: performing the digest calculation on the first data to be transmitted to obtain a first Hash value; converting the first Hash value according to a preset conversion rule to obtain a first numerical value; performing decimal conversion on the first numerical value to obtain a second numerical value; obtaining the number of keys in a preset key table; calculating the second numerical value and the number of keys to obtain the first key serial number; converting the first Hash value according to a preset conversion rule to obtain a first numerical value; specifically comprising: obtaining a target character, wherein the target character is any character corresponding to the first Hash value; querying the binary number corresponding to the target character in a preset binary table; obtaining the binary numbers corresponding to each of the target characters in turn, and sorting each of the binary numbers according to the first Hash value to obtain the first numerical value; Obtaining a first key corresponding to the first key sequence number from a preset key table; The first data to be transmitted is encrypted using the first key to obtain a first ciphertext; and second data to be transmitted is sent to a user device so that the user device decrypts the second data to be transmitted, wherein the second data to be transmitted includes the first ciphertext.

2. The method according to claim 1, characterized in that: After encrypting the first data to be transmitted using the first key to obtain a first ciphertext, the method further includes: Obtaining a second key, where the second key is a preset key; Encrypt the first Hash value using the second key to obtain a second ciphertext; The second data to be transmitted is sent to the user equipment, where the second data to be transmitted also includes the second ciphertext.

3. The method according to claim 2, characterized in that After sending the second data to be transmitted to the user equipment so that the user equipment decrypts the second data to be transmitted, the method further includes: The user equipment receives the second data to be transmitted, where the second data to be transmitted includes the first ciphertext and the second ciphertext; obtaining the second key; Decrypt the second ciphertext using the second key to obtain a second Hash value; process the second Hash value to obtain a second key serial number; Acquire a third key corresponding to the second key sequence number from the preset key table; The first ciphertext is decrypted using the third key to obtain the first data to be transmitted.

4. The method according to claim 3, characterized in that The processing of the second hash value to obtain a second key serial number specifically includes: Convert the second Hash value according to the preset conversion rule to obtain a third value; perform the decimal conversion on the third value to obtain a fourth value; Obtain the number of keys in the preset key table; The fourth value and the number of keys are calculated to obtain the second key sequence number.

5. The method according to claim 2, characterized in that: After obtaining the second key, where the second key is a preset key, the method further includes: Obtaining a target usage count, where the target usage count is the total number of times the second key is used for encryption; Determining whether the target usage count is less than or equal to a preset usage threshold; When the target usage times is greater than the preset usage threshold, it is confirmed to send a prompt message to the server and the user equipment, where the prompt message is used to prompt the user to replace the second key.

6. A data encryption device, characterized in that: The device comprises a receiving unit (201), a processing unit (202) and a sending unit (203); The receiving unit (201) receives first data to be transmitted, where the first data to be transmitted is data sent to a user equipment; The processing unit (202) performs key serial number processing on the first data to be transmitted to obtain a first key serial number, wherein the key serial number processing includes digest calculation; the key serial number processing on the first data to be transmitted to obtain a first key serial number specifically includes: performing the digest calculation on the first data to be transmitted to obtain a first Hash value; converting the first Hash value according to a preset conversion rule to obtain a first numerical value; performing decimal conversion on the first numerical value to obtain a second numerical value; obtaining the number of keys in a preset key table; calculating the second numerical value and the number of keys to obtain the first key serial number; converting the first Hash value according to the preset conversion rule to obtain the first numerical value; specifically includes: obtaining a target character, wherein the target character is any character corresponding to the first Hash value; querying the binary number corresponding to the target character in a preset binary table; obtaining the binary number corresponding to each of the target characters in turn, and sorting each of the binary numbers according to the first Hash value to obtain the first numerical value; obtaining the first key corresponding to the first key serial number from the preset key table; encrypting the first data to be transmitted using the first key to obtain a first ciphertext; The sending unit (203) sends second data to be transmitted to the user equipment so that the user equipment can decrypt the second data to be transmitted, wherein the second data to be transmitted includes the first ciphertext.

7. An electronic device, characterized in that: The electronic device (300) comprises a processor (301), a memory (305), a user interface (303) and a network interface (304), wherein the memory (305) is used to store instructions, the user interface (303) and the network interface (304) are used to communicate with other devices, and the processor (301) is used to execute the instructions stored in the memory (305) so that the electronic device (300) executes the method according to any one of claims 1 to 5.

8. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores instructions, and when the instructions are executed, the method according to any one of claims 1 to 5 is performed.

Citation Information

Patent Citations

  • Method and device for safe data transmission

    CN111683081A