Cloud Platform Data Security Processing Method and System Based on Cloud Computing
By randomly generating the call code mechanism of encryption keys and decryption functions in the cloud platform, the problem of insufficient key protection in the cloud platform is solved, and efficient and secure processing of cloud data is achieved.
Patent Information
- Application Number
- CN202410974169.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-19
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2044-07-19
AI Technical Summary
Existing data security processing technology has weak protection from keys in cloud platforms, resulting in others being able to easily read encrypted data after the key is leaked.
The encryption key is randomly generated during cloud data storage and the data is encrypted through this key. After the user registers, a decryption function is generated based on the encryption key and login password, and a call code is randomly generated for the function and sent to the user. After logging in, the user calls the decryption function through the call code to decrypt and read the data.
Through the randomly generated encryption key and the call code mechanism of the decryption function, the risk of decryption key leakage is eliminated, and the security of data in the cloud platform is improved.
Smart Images

Figure CN119011122B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data security processing, and particularly to a method and system for data security processing of a cloud platform based on cloud computing. Background Art
[0002] Data security processing technology refers to a series of technologies and methods for protecting and processing data in an information system, aiming to ensure the confidentiality, integrity, and availability of data, and prevent data from being leaked, tampered with, lost, or affected by unauthorized access.
[0003] Existing data security processing technologies usually ensure data security through authentication or data encryption. However, the protection of data is relatively weak in a single case of either of them. Moreover, the cloud platform fixedly has an authentication link, and after authentication, the data is encrypted again. However, the number of users of the cloud platform is huge, and it is difficult to unify the keys used for data encryption. But sending the decryption key to all users may lead to key leakage, and others can bypass the authentication and directly read the decryption program for decryption. For example, in a Chinese patent with the publication number CN112887427A, a cloud platform encryption system and method are disclosed. In this solution, only general encryption processing is performed on the data in the cloud platform, and the private key is not protected. If the private key is leaked, others can easily read the data in the cloud platform. Existing data security processing technologies also have the problem of weak protection of keys, and others can easily read encrypted data after leakage. Summary of the Invention
[0004] The present invention aims to at least solve one of the technical problems in the prior art to some extent. When cloud data is stored in the cloud platform, an encryption key is randomly generated, the cloud data is encrypted with the encryption key and stored in the cloud platform. After a user registers an account on the cloud platform, the user's login password is obtained. Based on the encryption key and the login password, a corresponding decryption function is generated, and then a call code is randomly generated for the decryption function, and the call code is sent to the user. After the user logs in to the cloud platform, the decryption function is called through the call code, and the encrypted data is decrypted and read, so as to solve the problem that existing data security processing technologies have weak protection of keys and others can easily read encrypted data after leakage.
[0005] To achieve the above object, in a first aspect, the present application provides a method for data security processing of a cloud platform based on cloud computing, including the following steps:
[0006] When cloud data is stored in the cloud platform, an encryption key is randomly generated, and the cloud data is encrypted with the encryption key and stored in the cloud platform;
[0007] After a user registers an account on the cloud platform, obtain the user's login password, and generate a corresponding decryption function based on the encryption key and the login password;
[0008] Randomly generate a call code for the decryption function;
[0009] Send the call code to the user. After the user logs in to the cloud platform, call the decryption function through the call code to decrypt the encrypted data and then read it.
[0010] Furthermore, when cloud data is stored in the cloud platform, randomly generate an encryption key, and encrypt the cloud data with the encryption key and store it in the cloud platform, including the following sub-steps:
[0011] When cloud data is stored in the cloud platform, randomly generate an encryption key;
[0012] Encrypt the cloud data with the encryption key to obtain encrypted data, and store the encrypted data in the cloud platform.
[0013] Furthermore, when cloud data is stored in the cloud platform, randomly generating an encryption key includes the following sub-steps:
[0014] Randomly generate an encryption key;
[0015] The number of digits of the encryption key is the first number;
[0016] The encryption key consists of at least one capital letter, lowercase letter, and number.
[0017] Furthermore, encrypting the cloud data with the encryption key to obtain encrypted data and storing the encrypted data in the cloud platform includes the following sub-steps:
[0018] Obtain the cloud data;
[0019] Randomly select an encryption technology from the encryption and decryption technology pool. The encryption and decryption technology pool includes AES encryption technology, DES encryption technology, RC4 encryption technology, Rabbit encryption technology, and TripleDes encryption technology; Mark the selected encryption technology as the target encryption technology, and mark the corresponding decryption technology as the target decryption technology;
[0020] Based on the target encryption technology, use the encryption key as the key in the target encryption process to encrypt the cloud data to obtain encrypted data;
[0021] Store the encrypted data in the cloud platform;
[0022] The generation of the encryption key and the selection of the target encryption technology are both re-performed after the first conversion cycle.
[0023] Further, after the user registers an account on the cloud platform, obtain the user's login password, and based on the encryption key and the login password, generate the corresponding decryption function, including the following sub-steps:
[0024] Based on the user's login password and the generated encryption key, calculate the decryption intermediate code;
[0025] Generate the decryption function based on the decryption intermediate code.
[0026] Further, based on the user's login password and the generated encryption key, calculating the decryption intermediate code includes the following sub-steps:
[0027] After the user registers an account on the cloud platform, obtain the user's login password, and at the same time obtain the encryption key;
[0028] Based on the ASCII encoding, convert the login password to a hexadecimal number, marked as the first encoding; based on the ASCII encoding, convert the encryption key to a hexadecimal number, marked as the second encoding;
[0029] Calculate the login password divided by the encryption key, and mark the integer of the calculation result as the budget number;
[0030] Multiply the second encoding by the budget number, and mark the calculation result as the third encoding;
[0031] Number the characters in the first encoding, represented by the symbol F n ; number the characters in the third encoding, represented by the symbol T n ; where n is a positive integer and n is the serial number of F and T, 1 ≤ T ≤ m, and m is the maximum number of digits;
[0032] Calculate F n -T n , and mark the calculation result as P n , if P n is less than 0, then increase P n , where f is a hexadecimal number; calculate all P n , and arrange and combine P n in ascending order of n to obtain the decryption intermediate code.
[0033] Further, generating the decryption function based on the decryption intermediate code includes the following sub-steps:
[0034] The decryption function carries the corresponding budget number and the decryption intermediate code;
[0035] Obtain the user's login password, convert the login password to a hexadecimal number based on the ASCII encoding, marked as the fourth encoding, and obtain the number of digits of the fourth encoding, marked as the first judgment digit;
[0036] Obtain the decryption intermediate code, mark it as the fifth code, obtain the number of digits of the fifth code, and mark it as the second judgment digit;
[0037] Compare the first judgment digit with the second judgment digit. If the first judgment digit is the same as the second judgment digit, output a signal indicating the same number of digits; otherwise, output a signal indicating different numbers of digits. If a signal indicating different numbers of digits is output, return an error message to the user;
[0038] If a signal indicating the same number of digits is output, number the characters in the fifth code, represented by Q i represent, number the characters in the fourth code, represented by the symbol L i represent, where i is a positive integer and i is the serial number of Q and L, and the maximum value of i is the first judgment digit;
[0039] Calculate Q i minus L i , mark the calculation result as K i , if K i is less than 0, then increase K i by f, and calculate all K i ;
[0040] Arrange and combine K i in ascending order of i to obtain the sixth code;
[0041] Calculate the sixth code divided by the budget number to obtain the decryption key.
[0042] Furthermore, randomly generating a call code for the decryption function includes the following sub-steps:
[0043] Obtain the number of users on the cloud platform;
[0044] For the decryption function, randomly select a number from 1 to the number of users as the initial code;
[0045] Pad the initial code to the second digit by adding zeros at the beginning, and mark it as the call code.
[0046] Furthermore, send the call code to the user. After the user logs in to the cloud platform, call the decryption function through the call code to decrypt and read the encrypted data, including the following sub-steps:
[0047] Each user has a corresponding decryption function and a corresponding call code based on the login password he set;
[0048] Send the call code to the user by sending a text message;
[0049] After the user logs in to the cloud platform, the login password of the user is obtained. When the user needs to read data, after entering the received call code, the decryption function corresponding to the call code is selected, and the login password is calculated based on the decryption function to obtain the decryption key;
[0050] Based on the decryption key, the encrypted data is decrypted through the target decryption technology to obtain the cloud data.
[0051] In a second aspect, the present application provides a cloud platform data security processing system based on cloud computing, including an encrypted storage module, a function generation module, a call code generation module, and a user interaction module; the encrypted storage module, the function generation module, and the call code generation module are respectively connected to the user interaction module for data connection;
[0052] The encrypted storage module is used to randomly generate an encryption key when the cloud data is stored in the cloud platform, encrypt the cloud data through the encryption key, and store it in the cloud platform;
[0053] The function generation module is used to obtain the login password of the user after the user registers an account on the cloud platform, and generate a corresponding decryption function based on the encryption key and the login password;
[0054] The call code generation module is used to randomly generate a call code for the decryption function;
[0055] The user interaction module is used to send the call code to the user. After the user logs in to the cloud platform, the decryption function is called through the call code, and the encrypted data is decrypted and then read.
[0056] Advantages of the present invention: When the cloud data is stored in the cloud platform, the present invention randomly generates an encryption key, encrypts the cloud data through the encryption key, and stores it in the cloud platform. After the user registers an account on the cloud platform, the login password of the user is obtained, and a corresponding decryption function is generated based on the encryption key and the login password. The advantage is that the encryption key is also the decryption key, and the decryption key only exists in the system of the cloud platform and needs to be calculated through the decryption function, eliminating the risk of decryption key leakage and improving the security of the data in the cloud platform;
[0057] The present invention randomly generates a call code for the decryption function, and then sends the call code to the user. After the user logs in to the cloud platform, the decryption function is called through the call code, and the encrypted data is decrypted and then read. The advantage is that there are several decryption functions in the cloud platform, and the user can obtain the decryption function only by using the decryption function corresponding to himself, so as to decrypt the encrypted data. This requires two conditions to be met at the same time. One is that the visitor is a legitimate user of the cloud platform, and the other is that the visitor needs to know the call code corresponding to his own account, greatly improving the security of the data in the cloud platform and the effectiveness of data security protection. Description of the Drawings
[0058] Figure 1 is the principle block diagram of the system of the present invention;
[0059] Figure 2 is the schematic diagram of the decryption function called by the call code of the present invention;
[0060] Figure 3 is the step flowchart of the method of the present invention;
[0061] Figure 4 is the structural schematic diagram of the electronic device of the present invention. Specific embodiments
[0062] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0063] Embodiment 1, please refer to Figure 1 As shown, the present application provides a cloud platform data security processing system based on cloud computing, including an encryption storage module, a function generation module, a call code generation module, and a user interaction module; the encryption storage module, the function generation module, and the call code generation module are respectively connected to the user interaction module for data connection;
[0064] The encryption storage module is used to randomly generate an encryption key when cloud data is stored in the cloud platform, encrypt the cloud data with the encryption key and store it in the cloud platform; the encryption storage module includes a key generation unit and a data encryption unit;
[0065] The key generation unit is used to randomly generate an encryption key when cloud data is stored in the cloud platform;
[0066] The key generation unit is configured with a key generation strategy, and the key generation strategy includes:
[0067] Randomly generate an encryption key;
[0068] The number of digits of the encryption key is the first number;
[0069] The encryption key consists of at least one capital letter, lowercase letter, and number;
[0070] In practical applications, the first number needs to be less than or equal to the minimum value of the number of digits of the password that can be set by the cloud platform user. The login password of the cloud platform is usually 6-18 digits. Therefore, the first number is set to 6; the randomly generated encryption key is "ABab12";
[0071] The data encryption unit is used to encrypt cloud data with an encryption key to obtain encrypted data, and store the encrypted data in the cloud platform;
[0072] The data encryption unit is configured with a data encryption policy, and the data encryption policy includes:
[0073] Obtain cloud data;
[0074] Randomly select an encryption technology from the encryption and decryption technology pool. The encryption and decryption technology pool includes AES encryption technology, DES encryption technology, RC4 encryption technology, Rabbit encryption technology, and TripleDes encryption technology; mark the selected encryption technology as the target encryption technology, and mark the corresponding decryption technology as the target decryption technology;
[0075] Based on the target encryption technology, use the encryption key as the key in the target encryption process to encrypt the cloud data to obtain encrypted data;
[0076] Store the encrypted data in the cloud platform;
[0077] The generation of the encryption key and the selection of the target encryption technology are both re-performed after the first conversion cycle;
[0078] In practical applications, the encryption of cloud data will be re-executed after the first conversion cycle, and the encryption technology used is also random. When re-executing, first decrypt the encrypted data with the previous encryption key to obtain the original cloud data, then randomly generate a new encryption key, and then encrypt it again through a random encryption technology. The subsequent decryption function and call code will also be reset to reduce the risk of data leakage by means of regular replacement; the obtained cloud data is the "Data Security Processing System for Cloud Platform Based on Cloud Computing", and the randomly selected target encryption technology is RC4 encryption technology. Then, the cloud data is encrypted through the RC4 encryption technology, and the encryption key is "ABab12". The encrypted data obtained is "U2FsdGVkX1+te4g9TheFvNIY9brO3L3XWCXL0LZuL+SihMVWSJr MgbygaxUPGskbD39RJ4vRPaorkfP8rvSYu2elgA==", and the encrypted data is stored in the cloud platform.
[0079] The function generation module is used to obtain the user's login password after the user registers an account on the cloud platform, and generate a corresponding decryption function based on the encryption key and the login password; the function generation module includes a transfer analysis unit and a function generation unit;
[0080] The transfer analysis unit is used to calculate a decryption transfer code based on the user's login password and the generated encryption key;
[0081] The transfer analysis unit is configured with a transfer analysis strategy, and the transfer analysis strategy includes:
[0082] After the user registers an account on the cloud platform, obtain the user's login password and at the same time obtain the encryption key;
[0083] Convert the login password to a hexadecimal number based on ASCII encoding, marked as the first encoding; convert the encryption key to a hexadecimal number based on ASCII encoding, marked as the second encoding;
[0084] Calculate the login password divided by the encryption key, and mark the integer of the calculation result as the budget number;
[0085] In actual application, when the login password is "password" and the encryption key is "ABab12", the first encoding obtained through conversion is "70 61 73 73 77 6F 72 64", and the second encoding is "4142 61 62 31 32". The spaces in the first encoding and the second encoding are only for facilitating the distinction of the hexadecimal numbers corresponding to each character after conversion. In the actual processing process, there are no spaces in the first encoding and the second encoding, that is, the first encoding is "70617373776F7264", and the second encoding is "414261623132"; based on hexadecimal arithmetic, calculate 70617373776F7264 / 414261623132 = 1B8D9, and retain the integer of the calculation result, that is, the budget number is 1B8D9. If the budget number is zero, change the budget number to 1;
[0086] Multiply the second encoding by the budget number, and mark the calculation result as the third encoding;
[0087] Number the characters in the first encoding, represented by the symbol F n ; number the characters in the third encoding, represented by the symbol T n ; where n is a positive integer and n is the serial number of F and T, 1 ≤ T ≤ m, and m is the maximum number of digits;
[0088] Calculate F n - T n , and mark the calculation result as P n , if P n is less than 0, then increase P n by f, where f is a hexadecimal number; calculate all P n , and arrange and combine P n in ascending order of n to obtain the decryption transfer code;
[0089] In practical applications, the maximum number of digits obtained is 16. The second code is multiplied by the budget number to obtain the third code "706168A550C9A362". In the actual application process, there may be a situation where the number of digits of the third code is one less than that of the first code, but the probability of this situation occurring is relatively small. And if the number of digits of the third code is one less than that of the first code, just add a zero at the beginning of the third code; obtain F through the number 1 is 7, F 2 is 0, F 3 is 6, F 4 is 1, F 5 is 7, F 6 is 3, F 7 is 7, F 8 is 3, F 9 is 7, F 10 is 7, F 11 is 6, F 12 is F, F 13 is 7, F 14 is 2, F 15 is 6, F 16 is 4; T 1 is 7, T 2 is 0, T 3 is 6, T 4 is 1, T 5 is 6, T 6 is 8, T 7 is A, T 8 is 5, T 9 is 5, T 10 is 0, T 11 is C, T 12 is 9, T 13 is A, T 14 is 3, T 15 is 6, T 16 is 2; Calculate to obtain P 1 to P 16 are 0, 0, 0, 0, 1, -5, -3, -2, 2, 7, -6, 6, -3, -1, 0, and 2 in sequence. Make all P less than 0 n increase by f, and combine to obtain the decryption intermediate code "00001ACD2796CE02";
[0090] The function generation unit is used to generate a decryption function based on the decryption intermediate code;
[0091] The function generation unit is configured with a function generation strategy, and the function generation strategy includes:
[0092] Please refer to Figure 2 as shown, the decryption function carries the corresponding budget number and the decryption intermediate code;
[0093] Obtain the user's login password, convert the login password into hexadecimal numbers based on ASCII encoding, mark it as the fourth encoding, obtain the number of digits of the fourth encoding, and mark it as the first judgment digit;
[0094] Obtain the decryption intermediate code, mark it as the fifth encoding, obtain the number of digits of the fifth encoding, and mark it as the second judgment digit;
[0095] Compare the first judgment digit with the second judgment digit. If the first judgment digit is the same as the second judgment digit, output a signal indicating the same number of digits; otherwise, output a signal indicating different numbers of digits. If a signal indicating different numbers of digits is output, return an error message to the user;
[0096] In practical applications, the decryption function is not a mathematical function in the conventional sense, but a function in programming work. The decryption function is stored in the function pool, and the corresponding decryption function is called from the function pool through a call code, such as Figure 2 As shown, the obtained login password is "password", the converted fourth encoding is "70617373776F7264", the obtained first judgment digit is 16, the decryption intermediate code is "00001ACD2796CE02", including the leading 0, the obtained second judgment digit is 16, and by comparison, the first judgment digit is the same as the second judgment digit, and a signal indicating the same number of digits is output;
[0097] If a signal indicating the same number of digits is output, number the characters in the fifth encoding. Represented by Q i Represented by, number the characters in the fourth encoding. Represented by the symbol L i where i is a positive integer and i is the serial number of Q and L, and the maximum value of i is the first judgment digit;
[0098] Calculate Q i minus L i and mark the calculation result as K i If K i is less than 0, then increase K i by f and calculate all K i ;
[0099] Arrange and combine K i in ascending order of i to obtain the sixth encoding;
[0100] Calculate the quotient of the sixth encoding divided by the budget number to obtain the decryption key;
[0101] In practical applications, the numbered L 1 is 7, L 2 is 0, L 3 is 6, L 4 is 1, L5 is 7, L 6 is 3, L 7 is 7, L 8 is 3, L 9 is 7, L 10 is 7, L 11 is 6, L 12 is F, L 13 is 7, L 14 is 2, L 15 is 6, T 16 is 4; Q 1 to Q 16 are 0, 0, 0, 0, 1, A, C, D, 2, 7, 9, 6, C, E, 0 and 2 in sequence, and subtracting them gives K 1 to K 16 are 7, 0, 6, 1, 6, -7, -5, -A, 5, 0, -3, -5, 3, -C, 6 and 2 in sequence. Increase those less than 0 by f and combine them. The sixth code obtained is 706168A550C9A362. Divide it by the budget number 1B8D9, and the decryption key calculated is 414261623132. Restoring it to characters based on ASCII encoding gives the decryption key as "ABab12".
[0102] The call code generation module is used to randomly generate a call code for the decryption function;
[0103] The call code generation module is configured with a call code generation strategy, and the call code generation strategy includes:
[0104] Obtain the number of users on the cloud platform;
[0105] For the decryption function, randomly select a number from 1 to the number of users as the initial code;
[0106] Pad the initial code to the second digit by adding zeros at the beginning, and mark it as the call code;
[0107] In practical applications, the number of users obtained on the cloud platform is 787621. For the decryption function calculated in this embodiment, the randomly generated initial code is 2568. The second digit is the number of digits of the number of users, which is 6. Pad the initial code to the second digit, and the call code obtained is 002568.
[0108] The user interaction module is used to send the call code to the user. After the user logs in to the cloud platform, the decryption function is called through the call code to decrypt and read the encrypted data;
[0109] The user interaction module is configured with a user interaction strategy, and the user interaction strategy includes:
[0110] Each user has a corresponding decryption function and a corresponding call code based on the login password he sets.
[0111] The call code is sent to the user by sending a mobile phone text message.
[0112] After the user logs in to the cloud platform, the login password of the user is obtained. When the user needs to read data, after entering the received call code, the decryption function corresponding to the call code is selected, and the login password is calculated based on the decryption function to obtain the decryption key.
[0113] Based on the decryption key, the encrypted data is decrypted through the target decryption technology to obtain the cloud data.
[0114] In practical applications, each user corresponds to a decryption function. After the user logs in, the correct decryption function needs to be called through the call code to obtain the correct decryption key, so as to decrypt the encrypted data. In this embodiment, after the user logs in to the cloud platform through the account name and the login password "password", when reading the cloud data, the last call code received by the mobile phone text message is submitted. The call code is 002568. After the call program calls out the decryption function through the call code, the calculated decryption key is ABab12. Then, through the RC4 decryption technology, the encrypted data "U2FsdGVkX1+te4g9TheFvNIY9brO3L3XWCXL0LZuL+SihMVWSJrMgbygaxUPGskbD39RJ4vRPaorkfP8rvSY u2elgA==" is decrypted to obtain the cloud data as "Cloud platform data security processing system based on cloud computing". Since the encryption technology and the encryption key will be randomly changed regularly, the user will receive his own call code regularly. The user only needs to enter the last received call code.
[0115] Embodiment 2, please refer to Figure 4 As shown, the present application provides a cloud platform data security processing method based on cloud computing, including the following steps:
[0116] Step S1, when the cloud data is stored in the cloud platform, an encryption key is randomly generated, and the cloud data is encrypted through the encryption key and stored in the cloud platform; Step S1 includes the following sub-steps:
[0117] Step S101, when the cloud data is stored in the cloud platform, an encryption key is randomly generated;
[0118] Step S101 includes the following sub-steps:
[0119] Step S1011, an encryption key is randomly generated;
[0120] Step S1012, the number of digits of the encryption key is the first number;
[0121] Step S1013, the encryption key consists of at least one uppercase letter, lowercase letter, and number;
[0122] Step S102, encrypt the cloud data with the encryption key to obtain encrypted data, and store the encrypted data in the cloud platform;
[0123] Step S102 includes the following sub-steps:
[0124] Step S1021, obtain the cloud data;
[0125] Step S1022, randomly select an encryption technology from the encryption and decryption technology pool. The encryption and decryption technology pool includes AES encryption technology, DES encryption technology, RC4 encryption technology, Rabbit encryption technology, and TripleDes encryption technology; mark the selected encryption technology as the target encryption technology, and mark the corresponding decryption technology as the target decryption technology;
[0126] Step S1023, based on the target encryption technology, use the encryption key as the key in the target encryption process to encrypt the cloud data to obtain encrypted data;
[0127] Step S1024, store the encrypted data in the cloud platform;
[0128] Step S1025, the generation of the encryption key and the selection of the target encryption technology are both re-performed after the first conversion period;
[0129] Step S2, after the user registers an account on the cloud platform, obtain the user's login password, and generate a corresponding decryption function based on the encryption key and the login password; Step S2 includes the following sub-steps:
[0130] Step S201, calculate the decryption intermediate code based on the user's login password and the generated encryption key;
[0131] Step S201 includes the following sub-steps:
[0132] Step S2011, after the user registers an account on the cloud platform, obtain the user's login password and, at the same time, obtain the encryption key;
[0133] Step S2012, convert the login password to a hexadecimal number based on the ASCII code, marked as the first code; convert the encryption key to a hexadecimal number based on the ASCII code, marked as the second code;
[0134] Step S2013, calculate the login password divided by the encryption key, and mark the integer of the calculation result as the budget number;
[0135] Step S2014: Multiply the second code by the budget number, and mark the calculation result as the third code;
[0136] Step S2015: Number the characters in the first code, represented by the symbol F n ; Number the characters in the third code, represented by the symbol T n , where n is a positive integer and n is the serial number of F and T, 1 ≤ T ≤ m, and m is the maximum number of digits;
[0137] Step S2016: Calculate F n - T n , and mark the calculation result as P n . If P n is less than 0, then increase P n by f, where f is a hexadecimal digit; Calculate all P n , and arrange and combine P n in ascending order of n to obtain the decryption intermediate code;
[0138] Step S202: Generate a decryption function based on the decryption intermediate code;
[0139] Step S202 includes the following sub-steps:
[0140] Step S2021: The decryption function carries the corresponding budget number and the decryption intermediate code;
[0141] Step S2022: Obtain the user's login password, convert the login password to a hexadecimal number based on the ASCII code, mark it as the fourth code, and obtain the number of digits of the fourth code, marked as the first judgment digit;
[0142] Step S2023: Obtain the decryption intermediate code, mark it as the fifth code, and obtain the number of digits of the fifth code, marked as the second judgment digit;
[0143] Step S2024: Compare the first judgment digit with the second judgment digit. If the first judgment digit is the same as the second judgment digit, then output a signal indicating the same number of digits; otherwise, output a signal indicating different numbers of digits; If a signal indicating different numbers of digits is output, then return an error message to the user;
[0144] Step S2025: If a signal indicating the same number of digits is output, then number the characters in the fifth code, represented by Q i ; Number the characters in the fourth code, represented by the symbol L i , where i is a positive integer and i is the serial number of Q and L, and i is at most the first judgment digit;
[0145] Step S2026: Calculate Q i minus Li Mark the calculation result as K i If K i is less than 0, then increase f of K i and calculate all K i ;
[0146] Step S2027: Arrange and combine K i in ascending order of i to obtain the sixth code;
[0147] Step S2028: Divide the sixth code by the budget number to obtain the decryption key;
[0148] Step S3: Randomly generate a call code for the decryption function; Step S3 includes the following sub-steps:
[0149] Step S301: Obtain the number of users on the cloud platform;
[0150] Step S302: For the decryption function, randomly select a number from 1 to the number of users as the initial code;
[0151] Step S303: Pad the initial code to the second digit by adding zeros at the beginning and mark it as the call code;
[0152] Step S4: Send the call code to the user. After the user logs in to the cloud platform, the decryption function is called through the call code, and the encrypted data is decrypted and then read; Step S4 includes the following sub-steps:
[0153] Step S401: Each user has a corresponding decryption function and a corresponding call code based on the login password he set;
[0154] Step S402: Send the call code to the user by sending a text message;
[0155] Step S403: After the user logs in to the cloud platform, obtain the user's login password. When the user needs to read data, after entering the received call code, select the decryption function corresponding to the call code, and calculate the decryption key based on the decryption function for the login password;
[0156] Step S404: Based on the decryption key, decrypt the encrypted data through the target decryption technology to obtain the cloud data.
[0157] Example 3, please refer to Figure 4 as shown Figure 4The structure schematic diagram of an electronic device is exemplified. The electronic device may include: a processor, a communication interface, a memory, and a communication bus. Among them, the processor, the communication interface, and the memory complete mutual communication through the communication bus. The memory stores computer-readable instructions. The processor can call the instructions in the memory. When the computer-readable instructions are executed by the processor, the steps in the cloud platform data security processing method based on cloud computing are run to achieve the following functions: when cloud data is stored in the cloud platform, an encryption key is randomly generated, and the cloud data is encrypted with the encryption key and stored in the cloud platform; after the user registers an account on the cloud platform, the user's login password is obtained, and a corresponding decryption function is generated based on the encryption key and the login password; a call code is randomly generated for the decryption function; the call code is sent to the user. After the user logs in to the cloud platform, the decryption function is called through the call code, and the encrypted data is decrypted and then read.
[0158] In addition, when the logical instructions in the above-mentioned memory are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.
[0159] Embodiment 4, the present application also provides a computer-readable storage medium. The present application provides a storage medium on which a computer program is stored. When the computer program is executed by a processor, the steps in the cloud platform data security processing method based on cloud computing described above are run to achieve the following functions: when cloud data is stored in the cloud platform, an encryption key is randomly generated, and the cloud data is encrypted with the encryption key and stored in the cloud platform; after the user registers an account on the cloud platform, the user's login password is obtained, and a corresponding decryption function is generated based on the encryption key and the login password; a call code is randomly generated for the decryption function; the call code is sent to the user. After the user logs in to the cloud platform, the decryption function is called through the call code, and the encrypted data is decrypted and then read.
[0160] Through the description of the above embodiments, the embodiments of the present invention can be provided as a method, a system or a computer program product. Based on such an understanding, the above technical solution, in essence, or the part that contributes to the prior art can be embodied in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., including several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0161] In the embodiments provided in the present application, it should be understood that the disclosed system or method can be implemented in other ways. The above-described embodiments are merely illustrative. For example, the division of modules or units is only a logical function division, and there may be other division methods in actual implementation. For another example, multiple modules or units can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some communication interfaces. The indirect coupling or communication connection of systems, modules, and units can be electrical, mechanical, or other forms.
[0162] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, and are not intended to limit them. Although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A cloud platform data security processing method based on cloud computing, characterized in that: The steps include: When cloud data is stored in the cloud platform, an encryption key is randomly generated, and the cloud data is encrypted using the encryption key and stored in the cloud platform; After the user registers an account on the cloud platform, the user's login password is obtained, and the corresponding decryption function is generated based on the encryption key and login password; Randomly generate a calling code for the decryption function; The calling code is sent to the user. After the user logs in to the cloud platform, the decryption function is called through the calling code to decrypt the encrypted data and then read it.
2. The cloud platform data security processing method based on cloud computing according to claim 1 is characterized in that: When cloud data is stored in the cloud platform, an encryption key is randomly generated, and the cloud data is encrypted using the encryption key and stored in the cloud platform, including the following sub-steps: When cloud data is stored in the cloud platform, encryption keys are randomly generated; The cloud data is encrypted by using an encryption key to obtain encrypted data, and the encrypted data is stored in the cloud platform.
3. The cloud platform data security processing method based on cloud computing according to claim 2 is characterized in that: When cloud data is stored in a cloud platform, randomly generating encryption keys includes the following sub-steps: Randomly generate encryption keys; The number of digits of the encryption key is the first digit; the first digit is less than or equal to the minimum number of digits of the password that can be set by the cloud platform user; The encryption key consists of at least one uppercase letter, lowercase letter and number.
4. The cloud platform data security processing method based on cloud computing according to claim 3 is characterized in that: Encrypting cloud data with an encryption key to obtain encrypted data, and storing the encrypted data in the cloud platform includes the following sub-steps: Get cloud data; Randomly select an encryption technology from an encryption and decryption technology pool, wherein the encryption and decryption technology pool includes AES encryption technology, DES encryption technology, RC4 encryption technology, Rabbit encryption technology, and TripleDes encryption technology; mark the selected encryption technology as a target encryption technology, and mark the corresponding decryption technology as a target decryption technology; Based on the target encryption technology, the encryption key is used as the key in the target encryption process to encrypt the cloud data and obtain encrypted data; Store encrypted data to the cloud platform; The generation of the encryption key and the selection of the target encryption technology are both performed again after the first conversion cycle.
5. The cloud platform data security processing method based on cloud computing according to claim 4 is characterized in that: After the user registers an account on the cloud platform, the user's login password is obtained. Based on the encryption key and login password, the corresponding decryption function is generated, including the following sub-steps: Based on the user's login password and the generated encryption key, the decryption transit code is calculated; Generate a decryption function based on the decryption transcode.
6. The cloud platform data security processing method based on cloud computing according to claim 5 is characterized in that: Based on the user's login password and the generated encryption key, the decryption transcode is calculated and includes the following sub-steps: After the user registers an account on the cloud platform, the user's login password is obtained, and the encryption key is obtained at the same time; The login password is converted into a hexadecimal number based on the ASCII code, which is marked as the first code; the encryption key is converted into a hexadecimal number based on the ASCII code, which is marked as the second code; Calculate the login password minus the encryption key, and mark the integer of the calculation result as the budget number; Multiply the second code by the budget number, and mark the result as the third code; Number the characters in the first code, using the symbol F n Indicates; number the characters in the third code, through the symbol T n Indicates, where n is a positive integer and n is the sequence number of F and T, 1≤T≤m, and m is the maximum number of digits; Calculate F n -T n , and mark the result as P n , if P n If it is less than 0, then P n Increase f, where f is a hexadecimal number; calculate all P n , according to the order of n from small to large, P n Perform permutations and combinations to obtain the decryption transit code.
7. The cloud platform data security processing method based on cloud computing according to claim 6 is characterized in that: Generating a decryption function based on the decryption transcode includes the following sub-steps: The decryption function contains a corresponding budget number and a decryption transcoding; Obtain the user's login password, convert the login password into a hexadecimal number based on the ASCII code, mark it as the fourth code, obtain the number of digits of the fourth code, and mark it as the first judgment digit; Obtain the decryption transfer code, mark it as the fifth code, obtain the number of digits of the fifth code, mark it as the second judgment digit; The first judgment digit is compared with the second judgment digit. If the first judgment digit is the same as the second judgment digit, a signal of the same digit is output; otherwise, a signal of different digits is output; if the signal of different digits is output, a call error message is returned to the user; If the output has the same number of bits, the characters in the fifth code are numbered and the Q i Indicates that the characters in the fourth code are numbered, through the symbol L i Indicates, where i is a positive integer and i is the sequence number of Q and L, and i is at most the first judgment digit; Calculate Q i Minus L i , and mark the result as K i , if K i If K is less than 0, i Increase f and calculate all K i ; According to the order of i from small to large, K i Perform permutations and combinations to obtain the sixth code; Calculate the sixth code and divide it by the budget number to obtain the decryption key.
8. The cloud platform data security processing method based on cloud computing according to claim 7 is characterized in that: Generating a random calling code for the decryption function includes the following sub-steps: Get the number of users on the cloud platform; For the decryption function, a number is randomly selected from 1 to the number of users as the initial code; The initial code is padded to the second digit by filling the first digit with zeros and marked as the calling code.
9. The cloud platform data security processing method based on cloud computing according to claim 8 is characterized in that: The calling code is sent to the user. After the user logs in to the cloud platform, the decryption function is called through the calling code. The encrypted data is decrypted and then read, including the following sub-steps: Each user has a corresponding decryption function based on the login password he sets, and also has a corresponding calling code; Send the calling code to the user by sending a text message; After the user logs in to the cloud platform, the user's login password is obtained. When the user needs to read data, after entering the received call code, the decryption function corresponding to the call code is selected, and the login password is calculated based on the decryption function to obtain the decryption key; Based on the decryption key, the encrypted data is decrypted through the target decryption technology to obtain the cloud data.
10. A cloud platform data security processing system based on cloud computing, used to implement the cloud platform data security processing method based on cloud computing according to any one of claims 1 to 9, characterized in that: It includes an encryption storage module, a function generation module, a call code generation module and a user interaction module; the encryption storage module, the function generation module and the call code generation module are respectively connected to the user interaction module data; The encryption storage module is used to randomly generate an encryption key when the cloud data is stored in the cloud platform, encrypt the cloud data with the encryption key and store it in the cloud platform; The function generation module is used to obtain the user's login password after the user registers an account on the cloud platform, and generate a corresponding decryption function based on the encryption key and the login password; The calling code generation module is used to randomly generate a calling code for the decryption function; The user interaction module is used to send the calling code to the user. After the user logs in to the cloud platform, the decryption function is called through the calling code to decrypt the encrypted data and then read it.
Citation Information
Patent Citations
Cloud platform encryption system and method
CN112887427A
Data encryption method based on digital watermarking and JAVA local calling, data decryption method based on digital watermarking and JAVA local calling and data encryption and decryption system based on digital watermarking and JAVA local calling
CN104091101A
Medical data management method, device and equipment suitable for beauty salon and medium
CN110688671A