Data Encryption Method, System and Computer Program Product Applied to Machine Learning
By generating a unique set of encryption keys for each data element and generating a verification certificate, the problem of low security in the prior art is solved, and higher security and protection effects are achieved.
Patent Information
- Application Number
- CN202410847684.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-06-27
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2044-06-27
AI Technical Summary
In the prior art, enterprise data encryption methods are not very secure, and all encrypted data can be accessed after authentication, which increases the risk of data being cracked.
A neural network is used to generate a chaotic key sequence, generate a unique set of encryption keys for each element of the data to be encrypted, and generate a corresponding verification certificate. Only after passing the authentication can the encrypted data be accessed.
It improves the security of data encryption, reduces the probability of being brute-forced, avoids the database-based authentication problem in traditional technology, and enhances data protection capabilities.
Smart Images

Figure CN118643516B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of data encryption, and particularly relates to a data encryption method, system and computer program product applied to machine learning. Background Art
[0002] With the rapid development of Internet technology, society has entered the big data era. The overall changes brought about by big data have exposed users to the risk of privacy leakage. Among them, during the process of surfing the Internet, as long as users use smart phones, shop online or participate in social media interactions, they need to transfer the ownership of personal data to service providers. Thus, during the long-term data interaction process, service providers store a vast amount of user personal data; for enterprises, these user data are very precious resources because enterprises can obtain a large amount of valuable information from user data through data mining and machine learning, etc., so as to help them generate commercial value; however, once user data is leaked, it may bring serious adverse effects to users and enterprises. Therefore, encrypting the data stored by enterprises is the main protection measure to prevent user data leakage.
[0003] Currently, the commonly used encryption method by enterprises is to encrypt data using a unified key or cipher book. This method is easily cracked by brute force and has low security; at the same time, after the existing enterprises encrypt the data, they usually authenticate the accessing users in units of databases, that is, after authentication, all the encrypted data in the database can be accessed. Thus, when lawbreakers access the database through deception, they can access all the encrypted data in the database, which further increases the risk of encrypted data being accessed and cracked; based on this, how to provide a data encryption method with high security has become an urgent problem to be solved. Summary of the Invention
[0004] The purpose of the present invention is to provide a data encryption method, system and computer program product applied to machine learning, so as to solve the problem of low encryption security existing in the prior art.
[0005] To achieve the above purpose, the present invention adopts the following technical solutions:
[0006] In the first aspect, a data encryption method applied to machine learning is provided, including:
[0007] Obtain the data to be encrypted and a key generation model based on a neural network;
[0008] Use the key generation model to generate a number of chaotic key sequences;
[0009] Encode the data to be encrypted to obtain encoded data;
[0010] Determine the encryption key set for each element in the encoded data according to the plurality of chaotic key sequences, wherein the encryption key set for any element includes an encryption key, and the encryption keys for each element are different from each other;
[0011] Use the encryption key set for each element in the encoded data to perform encryption processing on each element in the encoded data, so that after the encryption processing, encrypted data is formed based on the encrypted elements;
[0012] Generate a verification certificate for the encrypted data according to the encrypted data and the encryption key set for each element; <--
[0013] Associate and store the encrypted data and the verification certificate, so that after the associated storage, the encryption processing of the data to be encrypted is completed, wherein the verification certificate is used to authenticate the user terminal requesting decryption during decryption, and after the authentication is passed, the user terminal is allowed to obtain the encrypted data and perform decryption processing.
[0014] Based on the above disclosed content, when the present invention performs encryption, first use a key generation model to generate a plurality of chaotic key sequences, and then encode the data to be encrypted to obtain encoded data, and determine the encryption key set for each element in the encoded data according to the generated plurality of chaotic key sequences. Then, the encryption key set for each element can be used to perform encryption processing on each element, thereby obtaining encrypted data; wherein, the encryption keys for each element generated by the present invention are different from each other. In this way, using different encryption keys to encrypt the data to be encrypted can reduce the probability of being brute-forced, thereby improving the security of encryption; at the same time, the present invention also uses the encryption key set for each element to generate a verification certificate for the encrypted data, and associates and stores the certificate with the encrypted data, so that the identity of the user accessing the encrypted data can be authenticated based on this certificate, and only after the authentication is passed, the user is allowed to access the encrypted data; thus, generating a verification certificate to authenticate the accessing user in units of data can avoid the problem in the traditional technology that all encrypted data can be accessed after the authentication is passed when authenticating in units of the database; based on this, the security of encryption is further improved.
[0015] Through the above design, the present invention encrypts the data to be encrypted by generating an encryption key set for each element in the corresponding encoded data of the data to be encrypted, and after the encryption process, uses the encryption key set of the data to be encrypted to generate a corresponding authentication certificate; in this way, different encryption keys are used for the encryption process of the data to be encrypted, which can reduce the probability of being brute-forced, thereby improving the security of encryption; at the same time, the present invention generates a corresponding verification certificate for each unit of the data to be encrypted to authenticate the accessing user, which can avoid the problem that all encrypted data can be accessed after authentication in the traditional technology with the database as the unit; thus, the security of encryption is further improved; based on this, the present invention can reduce the risk of data being cracked, thereby greatly improving the security of encryption, and therefore, it is very suitable for large-scale application and promotion.
[0016] In a possible design, four chaotic key sequences are generated by using a key generation model;
[0017] Among them, determining the encryption key set for each element in the encoded data according to the several chaotic key sequences includes:
[0018] According to the length of the encoded data, key truncation processing is performed on each chaotic key sequence to obtain four truncated key sequences, where the length of any truncated key sequence is the same as the length of the encoded data;
[0019] For the i-th element in the encoded data, the i-th element is XORed with the (i - 1)-th element, and the result of the XOR operation is added to 1 to obtain the key index value of the i-th element, where when i is 1, the (i - 1)-th element is the last element in the encoded data;
[0020] From the four truncated key sequences, the i-th key in the k-th truncated key sequence is used as the encryption key of the i-th element, and the i-th keys in the (k + 1)-th truncated key sequence and the (k + 2)-th truncated key sequence are sequentially used as the first scrambling key and the second scrambling key of the i-th element, where k is the key index value;
[0021] Using the encryption key, the first scrambling key, and the second scrambling key of the i-th element to form the encryption key set of the i-th element;
[0022] Increment i by 1, and re-XOR the i-th element with the (i - 1)-th element until i is equal to n, to obtain the encryption key set for each element in the encoded data, where the initial value of i is 1, and n is the length of the encoded data.
[0023] In a possible design, according to the length of the encoded data, key truncation processing is performed on each chaotic key sequence to obtain four truncated key sequences, including:
[0024] For any chaotic key sequence, starting from a preset bit in the any chaotic key sequence, a key of a target length is truncated to form an initial truncated key sequence of the any chaotic key sequence, where the target length is the length of the encoded data;
[0025] Each key in the initial truncated key sequence is expanded by a preset multiple and rounded to obtain a preprocessed truncated key sequence, where the preset multiple is a multiple of 10;
[0026] An absolute value processing is performed on the preprocessed truncated key sequence, and each key in the preprocessed truncated key sequence after taking the absolute value is subjected to a modulo operation with 256 to obtain a plurality of remainders;
[0027] Using the plurality of remainders, a truncated key sequence of the any chaotic key sequence is formed.
[0028] In a possible design, the encryption key set of any element includes the encryption key corresponding to the any element, a first scrambling key, and a second scrambling key;
[0029] Among them, using the encryption key set of each element in the encoded data, each element in the encoded data is encrypted, including:
[0030] For any element in the encoded data, based on the length of the encoded data and the first scrambling key and the second scrambling key in the encryption key set of the any element, the any element is scrambled to obtain a scrambled element;
[0031] Using the encryption key in the encryption key set of the any element, the scrambled element is encrypted to obtain the encrypted any element after encryption.
[0032] In a possible design, based on the length of the encoded data and the first scrambling key and the second scrambling key in the encryption key set of the any element, the any element is scrambled to obtain a scrambled element, including:
[0033] According to the following formula (1), the any element is scrambled to obtain a scrambled element;
[0034] (1)
[0035] In the above formula (1), represents the any element, Represents the scrambling element, Successively represents the first scrambling key and the second scrambling key in the encryption key set of any one of the elements, Represents the length of the encoded data, Represents the modulo operation;
[0036] Correspondingly, using the encryption key in the encryption key set of any one of the elements, encrypt the scrambling element, so that after encryption, the encrypted any one of the elements is obtained, including:
[0037] Perform an exclusive OR operation on the encryption key in the encryption key set of any one of the elements and the scrambling element, so that after the exclusive OR operation, the encrypted any one of the elements is obtained.
[0038] In a possible design, generating a verification certificate for the encrypted data according to the encrypted data and the encryption key set of each element includes:
[0039] Generate a digital signature for each element based on the encryption keys in the encryption data set of each element in the encoded data;
[0040] Judge whether the digital signatures of each element meet the preset conditions;
[0041] If so, use the digital signatures of each element to form a digital signature set, and use the encryption keys of each element to form a verification key set;
[0042] Generate the digest information of the encrypted data, and use the digital signature set, the verification key set, the digest information and the encrypted data to form the verification certificate.
[0043] In a possible design, generating a digital signature for each element based on the encryption keys in the encryption data set of each element in the encoded data includes:
[0044] For any one of the elements in the encoded data, generate a first signature pre-vector and a second signature pre-vector for the any one of the elements, where the first signature pre-vector and the second signature pre-vector are obtained by Gaussian discrete distribution sampling;
[0045] Generate a signature vector for the any one of the elements by using the first signature pre-vector and the second signature pre-vector;
[0046] Generate a digital signature for the any one of the elements based on the signature vector and the encryption key of the any one of the elements.
[0047] In a possible design, if the digital signature of any one of the elements does not meet the preset conditions, the method further includes:
[0048] Regenerate the first signature pre-vector and the second signature pre-vector for any of the elements, and use the first signature pre-vector and the second signature pre-vector to generate a signature vector for any of the elements, and generate a digital signature for any of the elements based on the signature vector of any of the elements and an encryption key, until the digital signature of any of the elements meets the preset conditions;
[0049] Correspondingly, using the first signature pre-vector and the second signature pre-vector to generate a signature vector for any of the elements, then includes:
[0050] Generate a random number for any of the elements, and multiply the random number by the first signature pre-vector to obtain an intermediate vector after the multiplication process;
[0051] Sum the intermediate vector with the second signature pre-vector to obtain the signature vector of any of the elements after the summation process.
[0052] In a second aspect, a data encryption system applied to machine learning is provided, including:
[0053] An acquisition unit for acquiring data to be encrypted and a key generation model based on a neural network;
[0054] A key generation unit for generating a plurality of chaotic key sequences by using the key generation model;
[0055] An encoding unit for encoding the data to be encrypted to obtain encoded data;
[0056] The key generation unit is further configured to determine an encryption key set for each element in the encoded data according to the plurality of chaotic key sequences, wherein the encryption key set of any element includes an encryption key, and the encryption keys of each element are different from each other;
[0057] An encryption unit for encrypting each element in the encoded data by using the encryption key set of each element in the encoded data, so as to form encrypted data based on the encrypted elements after the encryption process;
[0058] The encryption unit is configured to generate a verification certificate for the encrypted data according to the encrypted data and the encryption key set of each element;
[0059] A storage unit for associatively storing the encrypted data and the verification certificate, so as to complete the encryption process of the data to be encrypted after the associative storage, wherein the verification certificate is used to authenticate the user terminal requesting decryption during decryption, and after the authentication is passed, the user terminal is allowed to obtain the encrypted data and perform decryption processing.
[0060] In a third aspect, a data encryption device for machine learning is provided. Taking the device as an electronic device as an example, it includes a memory, a processor, and a transceiver that are communicatively connected in sequence. Among them, the memory is used to store computer programs, the transceiver is used to send and receive messages, and the processor is used to read the computer programs and execute the data encryption method for machine learning as described in the first aspect or any possible design in the first aspect.
[0061] In a fourth aspect, a storage medium is provided. Instructions are stored on the storage medium. When the instructions run on a computer, they execute the data encryption method for machine learning as described in the first aspect or any possible design in the first aspect.
[0062] In a fifth aspect, a computer program product containing instructions is provided. When the instructions run on a computer, the computer is caused to execute the data encryption method for machine learning as described in the first aspect or any possible design in the first aspect.
[0063] Advantageous effects:
[0064] (1) The present invention adopts a method of generating an encryption key set for each element in the corresponding encoded data of the data to be encrypted to perform the encryption process of the data to be encrypted. After the encryption process, the encryption key set of the data to be encrypted is used to generate a corresponding authentication certificate. In this way, different encryption keys are used for the encryption process of the data to be encrypted, which can reduce the probability of being brute-forced, thereby improving the security of encryption. At the same time, the present invention uses the data to be encrypted as a unit to generate a corresponding verification certificate to authenticate the accessing user, which can avoid the problem in the traditional technology of authenticating by taking the database as a unit that all encrypted data can be accessed after passing the verification. Therefore, the security of encryption is further improved. Based on this, the present invention can reduce the risk of data being cracked, thereby greatly improving the security of encryption. Therefore, it is very suitable for large-scale application and promotion. BRIEF DESCRIPTION OF THE DRAWINGS
[0065] Figure 1 It is a schematic flowchart of the steps of the data encryption method for machine learning provided by an embodiment of the present invention;
[0066] Figure 2 It is a schematic structural diagram of the data encryption system for machine learning provided by an embodiment of the present invention;
[0067] Figure 3 It is a schematic structural diagram of the electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0068] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the present invention will be briefly introduced below in combination with the accompanying drawings and the description of the embodiments or the prior art. Obviously, the following description of the structures of the accompanying drawings is only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts. It should be noted here that the description of these embodiments is used to help understand the present invention, but does not constitute a limitation to the present invention.
[0069] It should be understood that although terms such as first and second may be used herein to describe various units, these units should not be limited by these terms. These terms are only used to distinguish one unit from another. For example, the first unit may be called the second unit, and similarly, the second unit may be called the first unit, without departing from the scope of the exemplary embodiments of the present invention.
[0070] It should be understood that for the term "and / or" that may appear in this document, it is only a description of the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, B exists alone, and A and B exist simultaneously; for the term " / and" that may appear in this document, it is a description of another association object relationship, indicating that two relationships may exist. For example, A / and B may represent: A exists alone, and A and B exist alone; in addition, for the character " / " that may appear in this document, generally it means that the front and back associated objects are in an "or" relationship.
[0071] Embodiment:
[0072] See Figure 1As shown, for the data encryption method applied to machine learning provided in this embodiment, when encrypting a piece of data, different encryption keys will be generated to encrypt the elements in the data. After encryption, a corresponding verification certificate will be generated based on all the encryption keys of the data. Only after the user passes the identity verification of the verification certificate can the user be allowed to access the encrypted data. Through the above design, different encryption keys are used for data encryption processing, which can reduce the probability of being brute-forced, thereby improving the security of encryption. At the same time, this method generates corresponding verification certificates for identity verification of accessing users in units of data, which can avoid the problem that all encrypted data can be accessed after passing the verification in the traditional technology where the database is used as the unit for identity verification. In this way, the security of encryption can be further improved. Therefore, this method is very suitable for large-scale application and promotion in the field of data encryption. Among them, for example, this method can run on the data encryption side, but is not limited to this. Optionally, the data encryption side can be, but is not limited to, a personal computer (PC) or a server. It can be understood that the foregoing execution subject does not constitute a limitation on the embodiments of the present application. Correspondingly, the running steps of this method can be, but are not limited to, the following steps S1 to S7 as shown.
[0073] S1. Obtain the data to be encrypted and a key generation model based on a neural network. In this embodiment, the data to be encrypted can be, but is not limited to, the data in an enterprise's database. Specifically, it can be sensitive data in the database, such as personal identity information, enterprise business information, etc. Of course, with different usage scenarios, the types of sensitive data also vary, and are not limited to the foregoing examples. At the same time, this embodiment is based on a piece of data to elaborate on the encryption method provided in this embodiment. In this way, it is equivalent that each piece of data to be encrypted in the database will generate its own corresponding key generation model and obtain a corresponding chaotic key sequence. In this way, the security of encryption can be further improved.
[0074] In specific implementation, for example, the aforementioned key generation model can but is not limited to using a cellular neural network model. A cellular neural network is a locally interconnected, two-valued output signal non-linear analog processor, which has characteristics such as continuous real-time, high-speed parallel computing, and being suitable for implementation on very large scale integration (VLSI). It has been widely applied in many fields such as biomedicine, image processing, automatic control, pattern recognition, signal processing, and secure communication. At the same time, its dynamic characteristics are mainly manifested as chaos, periodicity, quasi-periodicity, and stability. Optionally, in this embodiment, a fourth-order cellular neural network model is adopted, that is, a cellular neural network model with four cell neurons is used to generate the chaotic key sequence of the data to be encrypted. Of course, the cellular neural network model is a commonly used model for generating keys in data encryption, and its principle will not be elaborated here.
[0075] Furthermore, this embodiment also provides an improved cellular neural network model, which increases the security of the keys output by the entire model by introducing additional functions. Among them, the improved cellular neural network model also has four cell neurons, and its corresponding model state equation can but is not limited to being shown as the following formula (2).
[0076] (2)
[0077] In the above formula (2), represents the state equation, 、 、 and represent the cell states (i.e., the cell states at different times) of the first cell neuron, the second cell neuron, the third cell neuron, and the fourth cell neuron in the key generation model (i.e., the improved cellular neural network model), represents the state variable of the third cell neuron, represents the state variable of the fourth cell neuron, represents the state variable of the second cell neuron, represents the state variable of the first cell neuron, represents the sign function, represents the output of the fourth cell neuron, represents the serial number of the cell neuron. Among them, when the value inside the parentheses of the sign function is greater than 0, the result of the function is 1; when it is less than 0, the result is -1; when it is equal to 0, the result is 0; and 。
[0078] In this way, through the state equation of the improved cellular neural network model, several chaotic key sequences can be generated, and the process can but is not limited to being shown as the following step S2.
[0079] S2. Use the key generation model to generate a number of chaotic key sequences. In specific applications, when the initial values of the state variables of each cellular neuron are input into the model, the model can output 4 chaotic key sequences. Optionally, taking the improved cellular neural network model mentioned above as an example, the initial values of four cellular neurons can be, but are not limited to, 0, 0, 0, e^(-10) in sequence. And it is exemplified that in the improved neural network model, the 4th-order Runge-Kutta discretization algorithm can be used, but is not limited to this, to solve the foregoing formula (2). In this way, 4 chaotic key sequences can be obtained. Among them, each chaotic key sequence contains multiple chaotic keys (i.e., multiple values).
[0080] After generating the chaotic key sequences for this encryption, the encryption process of the data to be encrypted can be carried out. Among them, in this embodiment, the data to be encrypted is first encoded, and then the encryption key set of each element in the encoded data is determined. Finally, according to the encryption key set of each element, each element is encrypted to obtain the encrypted data. Optionally, the foregoing encryption process can be, but is not limited to, as shown in the following steps S3 to S5.
[0081] S3. Perform encoding processing on the data to be encrypted to obtain encoded data. In this embodiment, the data to be encrypted can be converted into ASCII encoded data, binary encoded data, one-hot encoded data, etc. Of course, any one of the foregoing can be selected in this embodiment, and no specific limitation is made here.
[0082] After completing the encoding processing of the data to be encrypted, the encryption key set of each element in the encoded data can be determined from the foregoing number of chaotic key sequences. Among them, the determination process of the encryption key set can be, but is not limited to, as shown in the following step S4.
[0083] S4. Determine the encryption key set of each element in the encoded data according to the number of chaotic key sequences. Among them, the encryption key set of any element includes an encryption key, and the encryption keys of each element are different from each other. In specific implementation, for example, but not limited to, the following steps S41 to S45 can be used to generate the encryption key set of each element.
[0084] S41. According to the length of the encoded data, perform key truncation processing on each chaotic key sequence to obtain four truncated key sequences, where the length of any one truncated key sequence is the same as the length of the encoded data; in specific implementation, first truncate a key sequence with the same length as the encoded data from the chaotic key sequence, and then perform expansion, rounding, taking the absolute value, and taking the remainder processing on the truncated key sequence, so that after the foregoing processing, four truncated key sequences can be obtained; optionally, the following takes any one chaotic key sequence as an example to elaborate on the foregoing process, and the process can be but is not limited to the steps S41a to S41d shown below.
[0085] S41a. For any one chaotic key sequence, starting from a preset bit in the any one chaotic key sequence, truncate a key with a target length to form the initial truncated key sequence of the any one chaotic key sequence, where the target length is the length of the encoded data; in specific application, for example, it can be but is not limited to starting from the 3216th bit in the any one chaotic key sequence to truncate the key, so as to obtain the foregoing initial truncated key sequence; of course, the foregoing preset bit can be specifically set according to actual use, and is not limited to the foregoing example here.
[0086] After obtaining the initial truncated key sequence, key expansion and rounding processing can be performed, and the process can be but is not limited to the steps S41b shown below.
[0087] S41b. Expand each key in the initial truncated key sequence by a preset multiple and perform rounding processing to obtain a preprocessed truncated key sequence, where the preset multiple is a multiple of 10; in this embodiment, for example, it can be but is not limited to expanding each key by 100 times and then performing rounding processing. At this time, the preprocessed truncated key sequence can be obtained; then, remainder processing can be performed, and the process can be but is not limited to the steps S41c shown below.
[0088] S41c. Perform absolute value processing on the preprocessed truncated key sequence, and perform a remainder operation on each key in the preprocessed truncated key sequence after taking the absolute value with 256 to obtain a plurality of remainders; in this embodiment, it is equivalent to converting each key in the preprocessed truncated key sequence into a non-negative number, and then taking the remainder with 256 to obtain the remainder; finally, according to the remainder of each key with 256, the truncated key sequence of the any one chaotic key sequence can be constructed, and the process can be but is not limited to the steps S41d shown below.
[0089] S41d. Use a plurality of remainders to form the truncated key sequence of the any one chaotic key sequence; in this embodiment, the first number among the remainders of each key with 256 can be taken to form the foregoing truncated key sequence.
[0090] Through the foregoing steps S41a to S41d, the interception of each chaotic key sequence can be completed, thereby obtaining four intercepted key sequences. Then, based on the four intercepted key sequences, the encryption key set for each element in the encoded data can be determined, and the process can be but is not limited to the following steps S42 to S45.
[0091] S42. For the i-th element in the encoded data, perform an exclusive OR operation on the i-th element and the (i - 1)-th element, and add 1 to the result of the exclusive OR operation to obtain the key index value of the i-th element. When i is 1, the (i - 1)-th element is the last element in the encoded data. In this embodiment, it is equivalent to performing an exclusive OR operation on each element in the encoded data with the corresponding previous element, and then adding 1 to the result to obtain the key index value of each element. For example, if the result of the exclusive OR operation between the second element and the first element is 1, then the key index value of the second element is 2. Similarly, if the result of the exclusive OR operation between the second element and the first element is 0, then the key index value of the second element is 1. Thus, after obtaining the key index value of the i-th element based on the foregoing method, the encryption key, the first scrambling key, and the second scrambling key of the i-th element can be determined from the four intercepted key sequences, and the foregoing process can be but is not limited to the following step S43.
[0092] S43. From the four intercepted key sequences, take the i-th key in the k-th intercepted key sequence as the encryption key of the i-th element, and take the i-th keys in the (k + 1)-th intercepted key sequence and the (k + 2)-th intercepted key sequence as the first scrambling key and the second scrambling key of the i-th element in sequence, where k is the key index value. In this embodiment, an example is used to illustrate the foregoing step S43. Assume that the i-th element is the second element, and its corresponding key index value is 2. Then, take the second key in the second intercepted key sequence as the encryption key of the second element, take the second key in the third intercepted key sequence as the first scrambling key of the second element, and take the second key in the fourth intercepted key sequence as the second scrambling key of the second element. Of course, when k is other values, the determination process of the encryption key and the two scrambling keys of the i-th element is the same as the foregoing example, and will not be elaborated here.
[0093] After obtaining the encryption key and the two scrambling keys of the i-th element based on step S43, the encryption key set of the i-th element can be formed by using the foregoing three keys, and the process can be but is not limited to the following step S44.
[0094] S44. Using the encryption key, the first scrambling key, and the second scrambling key of the i-th element, form the encryption key set of the i-th element; after obtaining the encryption key set of the i-th element based on the foregoing steps S42 to S44, the same method can be used to determine the encryption key sets of the remaining elements in the encoded data. The loop process can be but is not limited to the following step S45.
[0095] S45. Increment i by 1, and re-perform the exclusive OR operation on the i-th element and the (i - 1)-th element until i is equal to n, obtaining the encryption key sets of each element in the encoded data, where the initial value of i is 1 and n is the length of the encoded data.
[0096] Thus, through the foregoing steps S41 to S45, the encryption key sets of each element in the encoded data can be determined. Since a cellular neural network model is used to generate chaotic key sequences, each chaotic key sequence generated based on the chaotic system is completely different; in this way, the encryption keys of each element obtained can also be completely different; thereby, using different encryption keys to encrypt each element can increase the complexity of encryption, thus enhancing the security of encryption.
[0097] After obtaining the encryption key sets of each element in the encoded data, the encryption process of the encoded data can be performed. The process can be but is not limited to the following step S5.
[0098] S5. Using the encryption key sets of each element in the encoded data, perform encryption processing on each element in the encoded data so that after the encryption processing, encrypted data is formed based on the encrypted elements; in specific implementation, taking any element in the encoded data as an example to elaborate the specific encryption process; among them, the encryption process of the foregoing any element can be but is not limited to the following steps S51 and S52.
[0099] S51. For any element in the encoded data, based on the length of the encoded data and the first scrambling key and the second scrambling key in the encryption key set of the any element, perform scrambling processing on the any element to obtain a scrambled element; in specific implementation, for example, the scrambling processing on the any element can be but is not limited to according to the following formula (1) to obtain the scrambled element.
[0100] (1)
[0101] In the above formula (1), represents the any element, represents the scrambled element, respectively represent the first scrambling key and the second scrambling key in the encryption key set of any one of the said elements, represents the length of the said encoded data, represents the modulo operation, that is, represents and the remainder between.
[0102] Thus, according to the aforementioned first scrambling key and second scrambling key, and using the above formula (1), after calculating the scrambled element, the encryption key of any one of the said elements can be used to encrypt the aforementioned scrambled element, thereby completing the encryption of any one of the said elements; wherein, the encryption process can be but is not limited to the following steps shown in S52.
[0103] S52. Use the encryption key in the encryption key set of any one of the said elements to encrypt the scrambled element, so as to obtain the encrypted any one of the said elements after encryption; in this embodiment, for example, it can be but is not limited to performing an exclusive OR operation on the encryption key in the encryption key set of any one of the said elements and the scrambled element, so as to obtain the encrypted any one of the said elements after the exclusive OR operation.
[0104] Thus, through the aforementioned steps S51 and S52, the encryption process of any one of the said encoded data can be completed. Then, with the same principle, the encryption process of the remaining each code in the encoded data can be completed. At this time, the encrypted data can be formed by using each encrypted element, thereby completing the encryption of the aforementioned data to be encrypted; based on this, in this embodiment, different encryption keys are used to encrypt each element in the data to be encrypted. Compared with the traditional encryption technology using the same key, the probability of being cracked can be reduced, thereby improving the security of encryption; at the same time, in this embodiment, scrambling processing is also performed before encryption. Thus, the complexity of encryption is increased again, thereby being able to further enhance the encryption security.
[0105] In specific applications, after the data encryption is completed in this embodiment, a verification certificate for identity verification is also generated for the encrypted data, so as to perform identity verification on the user when accessing the encrypted data; wherein, the generation process of the verification certificate can be but is not limited to the following steps shown in S6.
[0106] S6. Generate the verification certificate of the encrypted data according to the encrypted data and the encryption key set of each element; in specific applications, in this embodiment, the digital signature of each element in the encoded data is first generated; then, the verification certificate (i.e., digital certificate) of the encrypted data is generated by using the encryption key set of each element and the digest information of the encrypted data; optionally, the aforementioned process can be but is not limited to the following steps shown in S61~S64.
[0107] S61. Generate a digital signature for each element in the encrypted data set based on the encryption key within the encrypted data set. In specific implementation, still taking any element in the encoded data as an example, the following steps S61a to S61c can be used, but are not limited to, to generate the digital signature of the any element.
[0108] S61a. For any element in the encoded data, generate a first signature pre-vector and a second signature pre-vector for the any element, where the first signature pre-vector and the second signature pre-vector are obtained by Gaussian discrete distribution sampling; in specific implementation, it is equivalent to randomly selecting set elements in a preset discrete set, and when selecting elements, the statistical characteristics of the Gaussian distribution are also followed; thus, the elements obtained by Gaussian discrete distribution sampling can be used to construct a discrete vector, and in this embodiment, the discrete vectors obtained by two Gaussian discrete distribution samplings are used as the two signature pre-vectors of the any element.
[0109] After obtaining the signature pre-vector of the any element, the signature vector of the any element can be generated based on the two signature pre-vectors, and the process can be, but is not limited to, as shown in the following step S61b.
[0110] S61b. Use the first signature pre-vector and the second signature pre-vector to generate the signature vector of the any element; in specific implementation, it can be, but is not limited to, first generating a random number for the any element; then, multiplying the random number by the first signature pre-vector to obtain an intermediate vector after the multiplication process; finally, summing the intermediate vector with the second signature pre-vector to obtain the signature vector of the any element after the summation process.
[0111] After obtaining the signature vector of the any element, the digital signature of the any element can be generated based on its corresponding encryption key, and the process can be, but is not limited to, as shown in the following step S61c.
[0112] S61c. Generate the digital signature of the any element based on the signature vector and encryption key of the any element; in specific implementation, for example, the digital signature of the any element can be, but is not limited to, expressed as: , where represent the digital signature, signature vector, and encryption key of the any element in sequence.
[0113] Thus, through the foregoing steps S61a to S61c, digital signatures of all elements in the encoded data can be obtained. Then, it is necessary to determine whether the digital signatures of each element meet the preset conditions, so as to determine whether to enter the certificate generation process based on the judgment result in the subsequent steps. The verification process of the digital signature can be but is not limited to the following steps shown in S62.
[0114] S62. Determine whether the digital signatures of each element meet the preset conditions; in a specific implementation, still taking any one of the foregoing elements as an example to illustrate the verification process of the digital signature. Among them, for example, the following formula (3) can be used but is not limited to verify the digital signature of any one of the elements.
[0115] (3)
[0116] In the above formula (3), represents a set of elements that conform to the Gaussian discrete distribution, that is, a set composed of elements that conform to the Gaussian distribution randomly selected from the discrete set (hereinafter referred to as the Gaussian discrete distribution set); represents a check coefficient, represents the L1 norm. Thus, the meaning of the foregoing formula (3) is: if the result on the right side of the equation conforms to the Gaussian discrete distribution (that is, the result is an element in the Gaussian discrete distribution set), then it is determined that the digital signature meets the preset conditions; otherwise, it does not meet the preset conditions. Thus, based on the foregoing formula (3), the verification of the digital signatures of all elements can be completed. Then, the subsequent process can be carried out according to the verification result, and the process is as shown in the following step S63.
[0117] S63. If so, use the digital signatures of each element to form a digital signature set, and use the encryption keys of each element to form a verification key set. In this embodiment, if the digital signature of any one element does not meet the preset conditions, then it is necessary to regenerate the first signature pre-vector and the second signature pre-vector for the any one element, and use the first signature pre-vector and the second signature pre-vector to generate the signature vector of the any one element, and generate the digital signature of the any one element based on the signature vector and the encryption key of the any one element until the digital signature of the any one element meets the preset conditions.
[0118] After obtaining the digital signature set and the verification key set based on the foregoing steps S61 to S63, the digest information of the encrypted data can be generated, and combined with the foregoing data, the verification certificate of the encrypted data can be generated. The generation process of the verification certificate can be but is not limited to the following steps shown in S64.
[0119] S64. Generate a digest information of the encrypted data, and use the digital signature set, the verification key set, the digest information, and the encrypted data to form the verification certificate; in this embodiment, for example, the foregoing verification certificate can be but is not limited to being expressed as: , where represents the verification certificate, represents the verification key set, represents the digital signature set, represents the encrypted data, represents the foregoing digest information; meanwhile, for example, the foregoing digest information is a hash digest.
[0120] Thus, through the foregoing steps S61 to S64, a verification certificate of the encrypted data can be generated, and then, by associatively storing it with the encrypted data, this encryption process can be completed; among them, the key storage process can be but is not limited to the following step S7.
[0121] S7. Associatively store the encrypted data and the verification certificate, so as to complete the encryption process of the data to be encrypted after the associative storage, where the verification certificate is used to authenticate the user terminal requesting decryption during decryption, and after the authentication is passed, the user terminal is allowed to obtain the encrypted data and perform decryption processing.
[0122] In this embodiment, when the encryption storage of the data to be encrypted is completed, if the user terminal needs to access the encrypted data, then the verification certificate needs to be used for authentication; among them, when generating the verification certificate, the data encryption end will generate a corresponding verification key and send it to the legitimate user; at this time, the user terminal can use the received verification key for authentication, and the process is as follows: use the verification key to calculate the verification digest information of the verification certificate, if the calculated verification digest information is the same as the digest information in the certificate, at this time, it can be explained that the identity of the user terminal is trustworthy, and the user terminal is allowed to access the encrypted data (such as allowing the download of the encrypted data); then, the encrypted data can be decrypted to obtain the plaintext data to be encrypted.
[0123] Specifically, the decryption process is as follows: (1) Generate the same chaotic key sequence by the chaotic sequence receiver of the synchronous cellular neural network; (2) Perform the same key processing on the generated chaotic key sequence (i.e., perform truncation, expansion, rounding, taking the absolute value, and taking the remainder processing) to obtain four decryption truncation key sequences; (3) Obtain the key index value of each element in the encoded data (issued by the data encryption end); (4) Use the key index value of each element to determine the decryption key of each element, the first de-scrambling key, and the second de-scrambling key in the four decryption truncation key sequences (in the same process as determining the encryption key); (5) Perform exclusive OR processing on each element in the encrypted data with the decryption key to obtain intermediate data; (6) Use the first de-scrambling key and the second de-scrambling key of each element in the intermediate data to perform de-scrambling processing on each element, so as to obtain the data to be encrypted after the de-scrambling processing; thus, through the foregoing steps, the decryption of the encrypted data can be completed.
[0124] Thus, through the data encryption method applied to machine learning detailedly described in the foregoing steps S1 to S7, when the present invention encrypts a piece of data, different encryption keys will be generated to encrypt the elements in the data, and after encryption, a corresponding verification certificate will be generated based on all the encryption keys of the data, and only after the user passes the identity verification of the verification certificate, is the user allowed to access the encrypted data; thus, through the foregoing design, different encryption keys are used for data encryption processing, which can reduce the probability of being brute-forced, thereby improving the security of encryption; at the same time, the present invention generates a corresponding verification certificate to authenticate the accessing user in units of data, which can avoid the problem that all encrypted data can be accessed after passing the authentication in the traditional technology where the database is used as the unit for authentication. In this way, the security of encryption can be further improved; therefore, the present invention is very suitable for large-scale application and promotion in the field of data encryption.
[0125] As Figure 2 shown, the second aspect of this embodiment provides a hardware system for implementing the data encryption method applied to machine learning described in the first aspect of the embodiment, including:
[0126] An acquisition unit, configured to acquire the data to be encrypted and a key generation model based on a neural network.
[0127] A key generation unit, configured to use the key generation model to generate a plurality of chaotic key sequences.
[0128] An encoding unit, configured to perform encoding processing on the data to be encrypted to obtain encoded data.
[0129] A key generation unit is further configured to determine an encryption key set for each element in the encoded data according to the plurality of chaotic key sequences, where the encryption key set for any element includes an encryption key, and the encryption keys for each element are different from each other.
[0130] An encryption unit is configured to perform encryption processing on each element in the encoded data by using the encryption key set for each element in the encoded data, so that after the encryption processing, encrypted data is formed based on the encrypted elements.
[0131] An encryption unit is configured to generate a verification certificate for the encrypted data according to the encrypted data and the encryption key set for each element.
[0132] A storage unit is configured to associate and store the encrypted data and the verification certificate, so that after the association storage, the encryption processing of the data to be encrypted is completed, where the verification certificate is used to authenticate the user terminal requesting decryption during decryption, and after the authentication passes, the user terminal is allowed to obtain the encrypted data and perform decryption processing.
[0133] The working process, working details and technical effects of the system provided in this embodiment can be referred to the first aspect of the embodiment, and will not be elaborated here.
[0134] As Figure 3 shown, a data encryption device applied to machine learning is provided in the third aspect of this embodiment. Taking the device as an electronic device as an example, it includes: a memory, a processor and a transceiver that are communicatively connected in sequence, where the memory is used to store a computer program, the transceiver is used to send and receive messages, and the processor is used to read the computer program and execute the data encryption method applied to machine learning as described in the first aspect of the embodiment.
[0135] Specifically, the memory may include, but is not limited to, random access memory (RAM), read only memory (ROM), flash memory, first input first output (FIFO), and / or first in last out (FILO), etc.; specifically, the processor may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor may be implemented in at least one of the following hardware forms: DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), and PLA (Programmable Logic Array). At the same time, the processor may also include a main processor and a coprocessor. The main processor is a processor used to process data in the wake state, also known as the CPU (Central Processing Unit); the coprocessor is a low-power processor used to process data in the standby state.
[0136] In some embodiments, the processor may be integrated with a GPU (Graphics Processing Unit), which is responsible for rendering and drawing the content to be displayed on the display screen. For example, the processor may be, but is not limited to, a microprocessor of the STM32F105 series, a reduced instruction set computer (RISC) microprocessor, a processor with an X86 architecture, or a processor integrated with an embedded neural-network processing unit (NPU); the transceiver may be, but is not limited to, a Wi-Fi wireless transceiver, a Bluetooth wireless transceiver, a General Packet Radio Service (GPRS) wireless transceiver, a ZigBee (a low-power local area network protocol based on the IEEE 802.15.4 standard) wireless transceiver, a 3G transceiver, a 4G transceiver, and / or a 5G transceiver, etc. In addition, the device may also include, but is not limited to, a power module, a display screen, and other necessary components.
[0137] For the working process, working details, and technical effects of the electronic device provided in this embodiment, reference may be made to the first aspect of the embodiment, which will not be elaborated here.
[0138] The fourth aspect of this embodiment provides a storage medium storing instructions for the data encryption method applied to machine learning described in the first aspect of the embodiment, that is, instructions are stored on the storage medium, and when the instructions run on a computer, the data encryption method applied to machine learning described in the first aspect of the embodiment is executed.
[0139] Among them, the storage medium refers to a carrier for storing data, which may include, but is not limited to, floppy disks, optical discs, hard disks, flash memories, USB flash drives, and / or Memory Sticks, etc. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices.
[0140] For the working process, working details, and technical effects of the storage medium provided in this embodiment, reference may be made to the first aspect of the embodiment, which will not be elaborated herein.
[0141] The fifth aspect of this embodiment provides a computer program product containing instructions, which, when the instructions run on a computer, cause the computer to execute the data encryption method applied to machine learning described in the first aspect of the embodiment, where the computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices.
[0142] Finally, it should be noted that the above are only preferred embodiments of the present invention and are not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A data encryption method applied to machine learning, characterized in that, Including: Obtain the data to be encrypted and a neural network-based key generation model; Use the key generation model to generate four chaotic key sequences; Perform binary encoding processing on the data to be encrypted to obtain encoded data; According to the length of the encoded data, perform key truncation processing on each chaotic key sequence to obtain four truncated key sequences, where the length of any truncated key sequence is the same as the length of the encoded data; for the i-th element in the encoded data, perform an exclusive OR operation on the i-th element and the (i - 1)-th element, and add 1 to the result of the exclusive OR operation to obtain the key index value of the i-th element, where when i is 1, the (i - 1)-th element is the last element in the encoded data; from the four truncated key sequences, use the i-th key in the k-th truncated key sequence as the encryption key for the i-th element, and use the i-th keys in the (k + 1)-th truncated key sequence and the (k + 2)-th truncated key sequence as the first scrambling key and the second scrambling key for the i-th element in sequence, where k is the key index value; use the encryption key, the first scrambling key, and the second scrambling key of the i-th element to form the encryption key set of the i-th element, where the encryption keys of each element are different from each other; increment i by 1, and re-perform an exclusive OR operation on the i-th element and the (i - 1)-th element until i is equal to n, to obtain the encryption key sets of each element in the encoded data, where the initial value of i is 1 and n is the length of the encoded data; Use the encryption key sets of each element in the encoded data to perform encryption processing on each element in the encoded data, so that after the encryption processing, an encrypted data is formed based on the encrypted elements, where the encryption processing process includes: for any element in the encoded data, perform scrambling processing on the any element based on the length of the encoded data and the first scrambling key and the second scrambling key in the encryption key set of the any element to obtain a scrambled element; use the encryption key in the encryption key set of the any element to perform encryption processing on the scrambled element to obtain the encrypted any element after encryption; Generate a verification certificate for the encrypted data according to the encrypted data and the encryption key set of each element; When generating the verification certificate, also generate a corresponding verification key and send it to legitimate users; Associate and store the encrypted data and the verification certificate, so that after the association storage, the encryption processing of the data to be encrypted is completed, where the verification certificate is used to authenticate the identity of the user terminal requesting decryption during decryption, and after the identity authentication is passed, the user terminal is allowed to obtain the encrypted data and perform decryption processing; The process of the identity authentication is: the user terminal uses the verification key to calculate the verification digest information of the verification certificate, and if the calculated verification digest information is the same as the digest information in the certificate, it means that the identity of the user terminal is trustworthy.
2. The method according to claim 1, wherein According to the length of the coded data, each chaotic key sequence is subjected to key interception processing to obtain four intercepted key sequences, including: For any chaotic key sequence, taking a preset position in the any chaotic key sequence as a starting point, intercepting a key of a target length to form an initial intercepted key sequence of the any chaotic key sequence, wherein the target length is the length of the encoded data; Expanding each key in the initial intercepted key sequence by a preset multiple and performing rounding processing to obtain a preprocessed intercepted key sequence, wherein the preset multiple is a multiple of 10; performing an absolute value processing on the pre-processed intercepted key sequence, and performing a modulo operation on each key in the pre-processed intercepted key sequence after taking the absolute value thereof and 256 to obtain a plurality of remainders; A plurality of remainders are used to form an intercepted key sequence of any chaotic key sequence.
3. The method according to claim 1, characterized in that, The method comprises: performing a scrambling process on the any element based on the length of the encoded data and a first scrambling key and a second scrambling key in the encryption key set of the any element to obtain a scrambled element, comprising: According to the following formula (1), any of the elements is disturbed to obtain a disturbed element; p′=mod(p+r1+r2,n)+1 (1) In the above formula (1), p represents any one element, p′ represents the scrambling element, r1 and r2 represent the first scrambling key and the second scrambling key in the encryption key set of any one element, n represents the length of the encoded data, and mod() represents a modulo operation; Accordingly, encrypting the scrambled element using an encryption key in the encryption key set of the any element to obtain the encrypted any element after encryption includes: An encryption key in the encryption key set of the any element is subjected to an exclusive OR operation with the scrambled element, so as to obtain the encrypted any element after the exclusive OR operation.
4. A computer program product comprising instructions, characterized in that, When the instructions are executed on a computer, the computer is caused to execute the data encryption method applied to machine learning as described in any one of claims 1 to 3.
Citation Information
Patent Citations
Method and system for controlling life cycle and safe deletion of electronic file
CN104866779A
Encryption and decryption method of OFDM-PON system based on cell neural network
CN109672517A
Data encryption method, data decryption method, equipment and storage medium
CN115883052A
Sensitive information security protection method and device, equipment and storage medium
CN117394984A