A method, device, equipment and storage medium for encryption and decryption
By determining the target modulus and modulo inverse correction values based on prime numbers, the data is encrypted and decrypted, and the existing encryption and decryption methods in key management and efficiency are solved, and the data is safely calculated and efficiently decrypted in the encrypted state is realized.
Patent Information
- Application Number
- CN202411858461.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-17
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2044-12-17
AI Technical Summary
The existing encryption and decryption methods have difficulties in key management and efficiency, especially in large-scale systems, the key management of symmetric encryption methods is difficult, while the private key management and encryption and decryption efficiency of asymmetric encryption methods are low.
By determining the target modulus and the minimum common multiple based on the first prime number and the second prime number, the modulus inverse correction value is then determined, and the encrypted data is encrypted and decrypted, and the operation of sensitive data in the encrypted state is realized.
It improves data security and system operation efficiency, avoids the risk of sensitive data being calculated after decryption, and simplifies the key management process.
Smart Images

Figure CN119312373B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular, to an encryption and decryption method, device, equipment and storage medium. Background Art
[0002] With the development of the mobile Internet, people may encounter data privacy problems in daily office work. For example, when a certain bank system calculates the total encrypted balance of accounts, the common practice is to decrypt two amounts and then add the decrypted plaintexts to obtain the total balance. When the tax department conducts statistics and analysis on encrypted taxpayer data, the common method is to decrypt the tax amounts of taxpayers and then sum up the decrypted plaintexts to obtain the statistical results of taxpayers. In an electronic voting system, when calculating the number of votes, it is necessary to decrypt the original historical votes into plaintext, then accumulate them with the new votes, and finally encrypt and store the accumulated votes. To solve the above data security problems, the common technical routes adopted in the industry and the common implementation methods are as follows:
[0003] 1) Symmetric encryption method: Generate a symmetric key and use AES or SM4 to encrypt and protect sensitive data. However, both the encryption and decryption of the symmetric encryption method use the same key, and both parties need to securely share the key, which makes the key management difficult, especially in large-scale systems.
[0004] 2) Asymmetric encryption method: Generate an asymmetric key and use RSA or SM2 to encrypt and protect sensitive data. However, the private key management of RSA and SM2 in asymmetric encryption is difficult. In addition, the efficiency of asymmetric encryption and decryption is low.
[0005] 3) Hybrid encryption method: Generate a pair of symmetric keys and a pair of asymmetric keys, use AES or SM4 to encrypt and protect sensitive data, and encrypt and store the content of the symmetric key using the asymmetric public key. However, the hybrid encryption requires operations on the private keys of RSA and SM2, decrypt the symmetric key, and then perform symmetric decryption on the ciphertext. After decrypting the plaintext and performing operations in memory, the plaintext data is easily leaked due to memory snooping. Summary of the Invention
[0006] Based on this, it is necessary to provide an encryption and decryption method, device, equipment and storage medium for the above technical problems to solve at least one of the problems existing in the above technical problems.
[0007] The present invention provides an encryption and decryption method, including:
[0008] Determine a target modulus and a least common multiple based on a first prime number and a second prime number;
[0009] Determine a modular inverse correction value based on the least common multiple and the target modulus;
[0010] Obtain data to be encrypted, where the data to be encrypted includes first original data and second original data;
[0011] Based on the target modulus, encrypt the first original data and the second original data respectively to obtain a first ciphertext corresponding to the first original data and a second ciphertext corresponding to the second original data;
[0012] Determine a ciphertext operation result based on the first ciphertext and the second ciphertext;
[0013] Decrypt the ciphertext operation result based on the modular inverse correction value to obtain a target plaintext.
[0014] Optionally, according to an encryption and decryption method provided by the present invention, the determining a modular inverse correction value based on the least common multiple and the target modulus includes:
[0015] In the forward recursion process:
[0016] In the first recursion process, assign the target modulus to a first parameter in a preset formula, assign the least common multiple to a second parameter in the preset formula, and determine a result of the first recursion calculation in combination with a random number of the first recursion;
[0017] In each subsequent recursion process, assign the value of the second parameter in the previous recursion process to the first parameter, assign the result of the previous recursion calculation to the second parameter, and determine a result of the current recursion in combination with a random number of the current recursion process until the result of the current recursion is 1;
[0018] In the backward recursion process:
[0019] Determine a calculation formula for each recursion in the forward recursion process, where the calculation formula includes a value of the first parameter, a value of the second parameter, and a random number in the recursion process;
[0020] Start backward recursion from the calculation formula of the last recursion in the forward recursion process, and use the calculation formula of the last recursion as the current backward recursion calculation formula;
[0021] In a result of each recursion in the forward recursion calculation process, determine a result of the previous recursion corresponding to the current backward recursion;
[0022] Compare the value of the first parameter, the value of the second parameter, and the random number in the current backward recursion calculation formula with the result of the previous recursion respectively;
[0023] If there exists a value that is the same as the result of the previous recursion, then according to the calculation formula of the current reverse recursion and the calculation formula of the previous recursion, a target expansion formula is generated, and the target expansion formula is used as the new calculation formula of the current reverse recursion. Return to execute the step of determining the result of the previous recursion corresponding to the current reverse recursion among the results of each recursion in the forward recursion calculation process until the reverse recursion reaches the calculation formula of the first recursion in the forward recursion process;
[0024] Simplify the final target expansion formula to determine the modular inverse correction value according to the simplified formula.
[0025] Optionally, according to an encryption and decryption method provided by the present invention, encrypting the first original data and the second original data respectively based on the target modulus to obtain a first ciphertext corresponding to the first original data and a second ciphertext corresponding to the second original data includes:
[0026] Determine a first random factor and a second random factor;
[0027] Based on the target modulus, determine an encryption base;
[0028] Encrypt the first original data based on the target modulus, the encryption base, and the first random factor to obtain the first ciphertext;
[0029] Encrypt the second original data based on the target modulus, the encryption base, and the second random factor to obtain the second ciphertext.
[0030] Optionally, according to an encryption and decryption method provided by the present invention, determining the ciphertext operation result based on the first ciphertext and the second ciphertext includes:
[0031] Multiply the first ciphertext and the second ciphertext to obtain a target ciphertext;
[0032] Based on the target modulus and the target ciphertext calculation, determine the ciphertext operation result.
[0033] Optionally, according to an encryption and decryption method provided by the present invention, decrypting the ciphertext operation result based on the modular inverse correction value to obtain a target plaintext includes:
[0034] Perform a power modulo operation on the ciphertext operation result to obtain a modulo operation result;
[0035] Multiply the modulo operation result and the modular inverse correction value to obtain a multiplication operation result;
[0036] Based on the target modulus, perform a modulo operation on the multiplication operation result to obtain the target plaintext.
[0037] Optionally, according to an encryption and decryption method provided by the present invention, the performing a power modulo operation on the ciphertext operation result to obtain a modulo operation result includes:
[0038] Determining a first operation result based on the ciphertext operation result, the target modulus, and the least common multiple;
[0039] Determining the modulo operation result based on the first operation result and the target modulus.
[0040] Optionally, according to an encryption and decryption method provided by the present invention, the determining a target modulus based on a first prime number and a second prime number includes:
[0041] Taking the product between the first prime number and the second prime number as the target modulus.
[0042] The present invention also provides an encryption and decryption device, including:
[0043] A first determination module, configured to determine a target modulus and a least common multiple based on a first prime number and a second prime number;
[0044] A second determination module, configured to determine a modular inverse correction value based on the least common multiple and the target modulus;
[0045] An acquisition module, configured to acquire data to be encrypted, where the data to be encrypted includes first original data and second original data;
[0046] An encryption module, configured to encrypt the first original data and the second original data respectively based on the target modulus to obtain a first ciphertext corresponding to the first original data and a second ciphertext corresponding to the second original data;
[0047] An operation module, configured to determine a ciphertext operation result based on the first ciphertext and the second ciphertext;
[0048] A decryption module, configured to decrypt the ciphertext operation result based on the modular inverse correction value to obtain a target plaintext.
[0049] The present invention also provides a computer device, including a memory, a processor, and computer-readable instructions stored in the memory and executable on the processor, where when the processor executes the computer-readable instructions, the above encryption and decryption method is implemented.
[0050] The present invention also provides one or more readable storage media storing computer-readable instructions, where when the computer-readable instructions are executed by a processor, the above encryption and decryption method is implemented.
[0051] The above encryption and decryption method, apparatus, device, and storage medium include: determining a target modulus and a least common multiple based on a first prime number and a second prime number; determining a modular inverse correction value based on the least common multiple and the target modulus; obtaining data to be encrypted, where the data to be encrypted includes first original data and second original data; encrypting the first original data and the second original data respectively based on the target modulus to obtain a first ciphertext corresponding to the first original data and a second ciphertext corresponding to the second original data; determining a ciphertext operation result based on the first ciphertext and the second ciphertext; and decrypting the ciphertext operation result based on the modular inverse correction value to obtain a target plaintext. In the present invention, by determining a target modulus based on a first prime number and a second prime number, and encrypting original data according to the target modulus, and then performing operations on each ciphertext, that is, the sensitive data of the user is not operated after decryption, but is operated in an encrypted state, effectively improving the security of the data; and then decrypting the ciphertext operation result to obtain a target plaintext, and performing encryption and decryption processing on the data by combining mathematical formulas, improving the operation efficiency of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0052] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for the description of the embodiments of the present invention will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention, and those of ordinary skill in the art can also obtain other drawings without creative efforts based on these drawings.
[0053] Figure 1 is a flowchart of an encryption and decryption method in an embodiment of the present invention;
[0054] Figure 2 is a structural diagram of an encryption and decryption apparatus in an embodiment of the present invention;
[0055] Figure 3 is a schematic diagram of a computer device in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0056] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art without creative efforts based on the embodiments of the present invention belong to the scope of protection of the present invention.
[0057] The terms used in one or more embodiments of the present invention are for the purpose of describing specific embodiments only and are not intended to limit one or more embodiments of the present invention. The singular forms "a", "the", and "said" used in one or more embodiments of the present invention are also intended to include the plural forms unless the context clearly dictates otherwise. It should also be understood that the term "and / or" used in one or more embodiments of the present invention refers to and encompasses any and all possible combinations of one or more of the associated listed items.
[0058] In one embodiment, specifically, as Figure 1 shown, Figure 1 is a schematic flow diagram of an encryption and decryption method in an embodiment of the present invention. The embodiment of the present invention provides an encryption and decryption method, including the following steps:
[0059] Step S11, based on a first prime number and a second prime number, determine a target modulus and a least common multiple;
[0060] It should be noted that the first prime number and the second prime number refer to numbers in natural numbers greater than 1 that have no other positive factors except 1 and itself. For example, the first prime number prime_A is 7, and the second prime number prime_B is 11. The least common multiple refers to the smallest one among the common multiples of two or more integers.
[0061] Specifically, take the product of the first prime number and the second prime number as the target modulus. Combining the above example, the target modulus M = 7×11 = 77. And based on the first prime number and the second prime number, calculate the least common multiple. Optionally, the least common multiple is the least common multiple determined based on (prime_A - 1) and (prime_B - 1). Continuing with the above example, prime_A - 1 = 6; prime_B - 1 = 10, and the least common multiple LCF of 6 and 10 is 30.
[0062] Step S12, based on the least common multiple and the target modulus, determine a modular inverse correction value;
[0063] Specifically, in combination with the process of finding the modular inverse of the least common multiple with respect to the target modulus based on the least common multiple and the target modulus, obtain the modular inverse correction value. It can be understood that: define forward and backward recursive mathematical formulas: T 0 =Q 0 -K 0 ×P 0 ,..., T i =Q i -K i ×P i .
[0064] In the forward recursive process:
[0065] The first recursive process: Assign the target modulus to the first parameter in the preset formula, assign the least common multiple to the second parameter in the preset formula, and determine the result of the first recursive calculation in combination with the random number of the first recursion. Here, the preset formula represents the above-mentioned recursive mathematical formula. In the first recursion, the first parameter represents Q 0 , and the second parameter represents P 0 , and K 0 refers to the random number of the first recursion. That is, the calculation process of the first step of recursion: 17 = 77 - 2×30. Further, in each subsequent recursive process, assign the value of the second parameter in the previous recursive process to the first parameter, assign the result of the previous recursive calculation to the second parameter, and determine the result of the current recursion in combination with the random number in the current recursive process until the result of the current recursion is 1, and the forward recursive process ends. If the result of the continuous recursion is not 1, the program interrupts and jumps out, determining that the least common multiple and the target modulus do not meet the conditions, and parameters need to be reselected for calculation.
[0066] When the result of the current recursion is calculated to be 1, it proves that the parameter check is passed, and the reverse recursive process enters, which is specifically as follows:
[0067] Determine the calculation formula for each recursion in the forward recursive process. Here, the calculation formula includes the value of the first parameter, the value of the second parameter, and the random number in the recursive process. For example, the calculation formula for the first step of recursion: 17 = 77 - 2×30; further, start reverse recursion from the calculation formula of the last recursion in the forward recursive process, that is, use the calculation formula of the last recursion as the current reverse recursive calculation formula, and then determine the result of the previous recursion corresponding to the current reverse recursion in the result of each recursion in the forward recursive calculation process, that is, the result of the penultimate recursion in the forward recursive process; further, compare the values of the first parameter, the second parameter, and the random number in the current reverse recursive calculation formula with the result of the previous recursion respectively; if there is a value that is the same as the result of the previous recursion, generate a target expansion formula according to the current reverse recursive calculation formula and the previous recursive calculation formula, and use the target expansion formula as the new current reverse recursive calculation formula, and return to execute the step of determining the result of the previous recursion corresponding to the current reverse recursion in the result of each recursion in the forward recursive calculation process until the reverse recursion reaches the calculation formula of the first recursion in the forward recursive process to obtain the final target expansion formula; further, simplify the final target expansion formula to obtain a simplified formula, and then determine the modular inverse correction value according to the simplified formula.
[0068] Step S13, obtain the data to be encrypted, where the data to be encrypted includes the first original data and the second original data;
[0069] It should be noted that the data to be encrypted is determined according to the actual data statistical application scenario, and the data to be encrypted includes the first original data and the second original data. For example, in the scenario of calculating the total encrypted balance of accounts in a banking system, the data to be encrypted refers to the balance data of two deposits in an account; in the scenario of counting the data of taxpayers, the data to be encrypted refers to the tax amount data of each taxpayer; in an electronic voting system, the data to be encrypted refers to the original historical voting count and the current voting count. For example, set the first original data Original_A to 4 and the second original data Original_B to 3. It can be understood that when there is a ciphertext that has been encrypted stored in the statistical application scenario, only the other unencrypted data is encrypted, that is, the data to be encrypted only includes one unencrypted original data.
[0070] Step S14, based on the target modulus, encrypt the first original data and the second original data respectively to obtain the first ciphertext corresponding to the first original data and the second ciphertext corresponding to the second original data;
[0071] Specifically, determine the first random factor corresponding to the encryption of the first original data and the second random factor corresponding to the encryption of the second original data. Among them, the first random factor and the second random factor can be randomly generated, and the first random factor and the second random factor can be the same or different. Then, based on the target modulus and the first random factor, encrypt the first original data to obtain the first ciphertext; in addition, based on the target modulus and the second random factor, encrypt the second original data to obtain the second ciphertext. It should be noted that the encryption process of the original data is specifically described in the following embodiments and will not be elaborated here.
[0072] Step S15, based on the first ciphertext and the second ciphertext, determine the ciphertext operation result;
[0073] Specifically, multiply the first ciphertext and the second ciphertext to obtain the target ciphertext; then, in combination with the target modulus, perform a modulo operation on the target ciphertext to obtain the ciphertext operation result. The calculation formula of the ciphertext operation result is as follows: c_add_result = (Ciphertext_A × Ciphertext_B) mod M^2.
[0074] Among them, c_add_result is the ciphertext operation result, Ciphertext_A represents the first ciphertext, Ciphertext_B represents the second ciphertext, and M represents the target modulus. For example, assume Ciphertext_A is 2621, Ciphertext_B is 5354, and M is 77, c_add_result = (2621 × 5354) mod 77 2 = 4820.
[0075] Step S16, decrypt the ciphertext operation result based on the modular inverse correction value to obtain the target plaintext.
[0076] Specifically, perform a power modular operation on the ciphertext operation result based on the target modulus and the least common multiple to obtain the modular operation result; then decrypt the ciphertext operation result based on the modular inverse correction value to restore the target plaintext. The specific decryption process is described in detail in the following embodiments and will not be elaborated here. It can be understood that in the scenario of calculating the total balance of two accounts in a banking system, the target plaintext refers to the total deposit amount data of the account; in the scenario of counting the data of taxpayers, the target plaintext refers to the total tax amount corresponding to the taxpayers; in an electronic voting system, the target plaintext refers to the total number of votes.
[0077] The embodiment of the present invention adopts the above solution, including: determining the target modulus and the least common multiple based on the first prime number and the second prime number; determining the modular inverse correction value based on the least common multiple and the target modulus; obtaining the data to be encrypted, where the data to be encrypted includes the first original data and the second original data; encrypting the first original data and the second original data respectively based on the target modulus to obtain the first ciphertext corresponding to the first original data and the second ciphertext corresponding to the second original data; determining the ciphertext operation result based on the first ciphertext and the second ciphertext; decrypting the ciphertext operation result based on the modular inverse correction value to obtain the target plaintext. The embodiment of the present invention determines the target modulus based on the first prime number and the second prime number, so as to encrypt the original data according to the target modulus and perform operations on each ciphertext. That is, the sensitive data of the user is not operated after decryption during the operation process, but is operated in the encrypted state, effectively improving the security of the data; then decrypting the ciphertext operation result to obtain the target plaintext, and improving the operation efficiency of the system by performing encryption and decryption processing on the data in combination with mathematical formulas.
[0078] In an embodiment of the present invention, determining the modular inverse correction value based on the least common multiple and the target modulus includes:
[0079] In the forward recursion process:
[0080] In the first recursion process, assign the target modulus to the first parameter in the preset formula, assign the least common multiple to the second parameter in the preset formula, and determine the result of the first recursion calculation in combination with the random number of the first recursion; in each subsequent recursion process, assign the value of the second parameter in the previous recursion process to the first parameter, assign the result of the previous recursion calculation to the second parameter, and determine the result of the current recursion in combination with the random number in the current recursion process until the result of the current recursion is 1;
[0081] In the reverse recursion process:
[0082] Determine the calculation formula for each recursion in the forward recursion process, where the calculation formula includes the value of the first parameter, the value of the second parameter, and a random number in the recursion process; start backward recursion from the calculation formula of the last recursion in the forward recursion process, and use the calculation formula of the last recursion as the current backward recursion calculation formula; in the result of each recursion in the forward recursion calculation process, determine the result of the previous recursion corresponding to the current backward recursion; compare the value of the first parameter, the value of the second parameter, and the random number in the current backward recursion calculation formula with the result of the previous recursion respectively; if there is a value that is the same as the result of the previous recursion, generate a target expansion formula according to the current backward recursion calculation formula and the previous recursion calculation formula, and use the target expansion formula as the new current backward recursion calculation formula, and return to execute the step of determining the result of the previous recursion corresponding to the current backward recursion in the result of each recursion in the forward recursion calculation process until backward recursion reaches the calculation formula of the first recursion in the forward recursion process; simplify the final target expansion formula to determine the modular inverse correction value according to the simplified formula.
[0083] Specifically, it is necessary to check and verify the least common multiple and the target modulus, that is, in the forward recursion process: in the first recursion process, assign the target modulus to the first parameter in the preset formula, assign the least common multiple to the second parameter in the preset formula, and combine the random number of the first recursion to determine the result of the first recursion calculation.
[0084] For example: Example of forward recursion constraint: T 0 =Q 0 -K 0 ×P 0 . In the first recursion process, Q 0 =M, P 0 =LCF; in the calculation process: 17 = 77 - 2 × 30.
[0085] Furthermore, in each subsequent recursion process, assign the value of the second parameter in the previous recursion process to the first parameter, assign the result of the previous recursion calculation to the second parameter, and combine the random number in the current recursion process to determine the result of the current recursion until the result of the current recursion is 1, that is, when performing the Ti calculation:
[0086] Make Q i =P i-1 ; make P i =T i-1 ; until when the forward recursion reaches Ti = 1, stop the recursive operation.
[0087] The first recursion process: 17 = 77 - 2 × 30.
[0088] Second recursive process: 13 = 30 - 1 × 17.
[0089] Third recursive process: 4 = 17 - 1 × 13.
[0090] Fourth recursive process: 1 = 13 - 3 × 4.
[0091] The result obtained from the fourth recursive process is 1, which proves that the parameter check verification passes, and thus the forward recursive operation stops. In addition, if the result of continuous recursion is not 1, the program interrupts and exits, determining that the least common multiple and the target modulus do not meet the conditions, and it is necessary to reselect the first prime number and the second prime number for calculation.
[0092] In the reverse recursive process (modulo inverse correction process):
[0093] Determine the calculation formula for each recursion in the forward recursive process. Among them, the calculation formula includes the value of the first parameter, the value of the second parameter, and the random number in the recursive process; start reverse recursion from the calculation formula of the last recursion in the forward recursive process, and use the calculation formula of the last recursion as the current reverse recursive calculation formula. For example, continuing with the above example, start reverse recursion from the fourth recursive process in the forward recursive process: 1 = 13 - 3 × 4.
[0094] Furthermore, among the results of each recursion in the forward recursive calculation process, determine the result of the previous recursion corresponding to the current reverse recursion; for example, starting reverse recursion from the fourth recursive process in the forward recursive process, query and obtain that the result of the previous forward recursion is 4 (the result of the third recursive process). Then compare the value of the first parameter, the value of the second parameter, and the random number in the calculation formula of the current reverse recursion with the result of the previous recursion respectively. If there is a value in the previous reverse recursive calculation formula that is the same as the result of the previous recursion, then integrate the calculation formula of the previous recursion into the calculation formula of the current reverse recursion to generate the target expansion formula.
[0095] It can be understood that when calculating Ti in the reverse recursion:
[0096] If Q i == T i-1 , then assign the T i-1 formula to Q i .
[0097] If K i == T i-1 , then assign the T i-1 formula to K i .
[0098] If P i == T i-1 , then assign the T i-1 formula to Pi 。
[0099] Continuing with the above example, the current reverse recursive calculation formula: 1 = 13 - 3×4. The result of the third forward recursive process is 4, and the calculation formula for the third forward recursive process is: 4 = 17 - 1×13; Incorporate the calculation formula of the previous recursion into the current reverse recursive calculation formula: 1 = 13 - 3×(17 - 1×13).
[0100] Further, use the target expansion formula as the new current reverse recursive calculation formula, and return to execute the step of determining the result of the previous recursion corresponding to the current reverse recursion among the results of each recursion in the forward recursive calculation process until the reverse recursion reaches the calculation formula of the first recursion in the forward recursive process. Continuing with the above example, the complete calculation process of the reverse recursion is as follows:
[0101] Fourth step: 1 = 13 - 3×4.
[0102] Third step: 1 = 13 - 3×(17 - 1×13).
[0103] Second step: 1 = (30 - 1×17) - 3×(17 - 1×(30 - 1×17)).
[0104] First step: 1 = (30 - 1×(77 - 2×30)) - 3×((77 - 2×30) - 1×(30 - 1×(77 - 2×30))).
[0105] After the reverse recursive calculation is completed, the final target expansion formula is obtained. Further, simplify the final target expansion formula. Optionally, in this embodiment, the target simplification formula is set to 1 = LCF * U - M * K, where U is the required modular inverse correction value and K is a random parameter. That is, simplifying 1 = (30 - 1×(77 - 2×30)) - 3×((77 - 2×30) - 1×(30 - 1×(77 - 2×30))) into the form of 1 = LCF×U - M×K gives the following simplified formula: 1 = 30×18 - 7×77, and the modular inverse correction value U can be determined to be 18.
[0106] Through the above solution, the embodiment of the present invention combines the process of finding the least common multiple in the modular inverse correction process of the target modulus based on the least common multiple and the target modulus to obtain the modular inverse correction value. During the recursive process, it has functions of quality inspection, reverse inference, and self-verification, and has high data accuracy.
[0107] In an embodiment of the present invention, based on the target modulus, encrypt the first original data and the second original data respectively to obtain the first ciphertext corresponding to the first original data and the second ciphertext corresponding to the second original data, including:
[0108] Determine a first random factor and a second random factor; determine an encryption base number based on a target modulus; encrypt first original data based on the target modulus, the encryption base number, and the first random factor to obtain a first ciphertext; encrypt second original data based on the target modulus, the encryption base number, and the second random factor to obtain a second ciphertext.
[0109] Specifically, determine the first random factor and the second random factor. For example, the first random factor \(R_A = 5\) and the second random factor \(R_B = 6\). In addition, calculate the encryption base number based on the target modulus. For example, the encryption base number \(G=\) target modulus \(M + 1=77 + 1\). Further, encrypt the first original data based on the target modulus, the encryption base number, and the first random factor to obtain a first ciphertext; and encrypt the second original data based on the target modulus, the encryption base number, and the second random factor to obtain a second ciphertext. The encryption formulas are as follows: The first ciphertext \(Ciphertext_A=(G^{Original_A}\times R_A^M)\bmod M^2\). For example, the first original data \(Original_A = 4\) and the second original data \(Original_B = 3\). \(Ciphertext_A=(78 4 \times5 77 )\bmod 77 2 = 2621\). The second ciphertext \(Ciphertext_B=(G^{Original_B}\times R_B^M)\bmod M^2\). For example, \(Ciphertext_B=(78 3 \times6 77 )\bmod 77 2 = 5354\).
[0110] Through the above solution, the embodiment of the present invention combines the target modulus and the random factor, and uses a mathematical formula to encrypt the original data, improving the security of the data and the operation efficiency of the system.
[0111] In an embodiment of the present invention, decrypt the ciphertext operation result based on a modular inverse correction value to obtain a target plaintext, including:
[0112] Perform a power modulo operation on the ciphertext operation result to obtain a modulo operation result; multiply the modulo operation result and the modular inverse correction value to obtain a multiplication operation result; perform a modulo operation on the multiplication operation result based on the target modulus to obtain the target plaintext.
[0113] Specifically, determine a first operation result based on the ciphertext operation result, the target modulus, and the least common multiple. The calculation formula is as follows: The first operation result \(Powermod=(c\_add\_result^{LCF})\bmod M^2\). Continuing with the above example, assume \(c\_add\_result = 4820\), \(Powermod = 482030 mod77 2 = 4313. Further, based on the first operation result and the target modulus, determine the modular operation result. The modular operation result Powermod' = (Powermod - 1) / M. For example, Powermod' = (4313 - 1) / 77 = 56.
[0114] Furthermore, multiply the modular operation result by the modular inverse correction value to obtain the multiplication operation result. Then, based on the target modulus, perform a modulo operation on the multiplication operation result to obtain the target plaintext. The calculation formula for the target plaintext is as follows: (Powermod' × U) mod M, where U represents the modular inverse correction value. For example, continuing with the above example, the modular inverse correction value U is 18, and the target plaintext = (56 × 18) mod 77 = 7. It can be tested and verified that the original text after decryption, the first original data Original_A is 4, the second original data Original_B is 3, and the sum of the two is equal to 7, proving that the encryption and decryption results used in this embodiment are correct.
[0115] In the embodiment of the present invention, the sensitive data of the user is not operated after decryption during the operation process, but is operated in an encrypted state, which improves the security of the data. Then, decrypt the ciphertext operation result according to the mathematical formula, which improves the operation efficiency of the system.
[0116] It should be understood that the magnitudes of the sequence numbers of the steps in the above embodiments do not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present invention.
[0117] In one embodiment, a decryption device is provided, and this decryption device corresponds one-to-one with the decryption method in the above embodiment. As Figure 2 shown, Figure 2 is a schematic structural diagram of a decryption device in an embodiment of the present invention. The decryption device includes:
[0118] The first determination module 21 is used to determine the target modulus and the least common multiple based on the first prime number and the second prime number;
[0119] The second determination module 22 is used to determine the modular inverse correction value based on the least common multiple and the target modulus;
[0120] The acquisition module 23 is used to acquire the data to be encrypted, where the data to be encrypted includes the first original data and the second original data;
[0121] The encryption module 24 is used to encrypt the first original data and the second original data respectively based on the target modulus to obtain the first ciphertext corresponding to the first original data and the second ciphertext corresponding to the second original data;
[0122] An operation module 25, configured to determine a ciphertext operation result based on a first ciphertext and a second ciphertext;
[0123] A decryption module 26, configured to decrypt the ciphertext operation result based on a modular inverse correction value to obtain a target plaintext.
[0124] The second determination module 22 is further configured to:
[0125] During the forward recursion process:
[0126] During the first recursion process, assign the target modulus to the first parameter in the preset formula, assign the least common multiple to the second parameter in the preset formula, and determine the result of the first recursion calculation in combination with the random number of the first recursion;
[0127] During each subsequent recursion process, assign the value of the second parameter in the previous recursion process to the first parameter, assign the result of the previous recursion calculation to the second parameter, and determine the result of the current recursion in combination with the random number in the current recursion process until the result of the current recursion is 1;
[0128] During the backward recursion process:
[0129] Determine the calculation formula for each recursion during the forward recursion process, where the calculation formula includes the value of the first parameter, the value of the second parameter, and the random number during the recursion process;
[0130] Start backward recursion from the calculation formula of the last recursion during the forward recursion process, and use the calculation formula of the last recursion as the current backward recursion calculation formula;
[0131] Among the results of each recursion during the forward recursion calculation process, determine the result of the previous recursion corresponding to the current backward recursion;
[0132] Compare the value of the first parameter, the value of the second parameter, and the random number in the calculation formula of the current backward recursion with the result of the previous recursion respectively;
[0133] If there is a value that is the same as the result of the previous recursion, generate a target expansion formula according to the calculation formula of the current backward recursion and the calculation formula of the previous recursion, and use the target expansion formula as the new current backward recursion calculation formula, and return to execute the step of determining the result of the previous recursion corresponding to the current backward recursion among the results of each recursion during the forward recursion calculation process until backward recursion reaches the calculation formula of the first recursion during the forward recursion process;
[0134] Simplify the final target expansion formula to determine the modular inverse correction value according to the simplified formula.
[0135] The encryption module 24 is further configured to:
[0136] Determine a first random factor and a second random factor;
[0137] Based on the target modulus, determine an encryption base;
[0138] Based on the target modulus, the encryption base, and the first random factor, encrypt the first original data to obtain a first ciphertext;
[0139] Based on the target modulus, the encryption base, and the second random factor, encrypt the second original data to obtain a second ciphertext.
[0140] The operation module 25 is further configured to:
[0141] Multiply the first ciphertext and the second ciphertext to obtain a target ciphertext;
[0142] Based on the target modulus and the target ciphertext calculation, determine a ciphertext operation result.
[0143] The decryption module 26 is further configured to:
[0144] Perform a power modulo operation on the ciphertext operation result to obtain a modulo operation result;
[0145] Multiply the modulo operation result and the modulo inverse correction value to obtain a multiplication operation result;
[0146] Based on the target modulus, perform a modulo operation on the multiplication operation result to obtain a target plaintext.
[0147] The decryption module 26 is further configured to:
[0148] Based on the ciphertext operation result, the target modulus, and the least common multiple, determine a first operation result;
[0149] Based on the first operation result and the target modulus, determine a modulo operation result.
[0150] The first determination module 21 is further configured to:
[0151] Use the product between the first prime number and the second prime number as the target modulus.
[0152] For the specific limitations of the encryption and decryption device, reference can be made to the limitations on the encryption and decryption method in the foregoing text, which will not be elaborated here. Each module in the above encryption and decryption device can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in or independent of the processor in the computer device in the form of hardware, or stored in the memory of the computer device in the form of software, so that the processor can call and execute the operations corresponding to the above modules.
[0153] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be asFigure 3 As shown Figure 3 Figure 3 is a schematic diagram of a computer device in an embodiment of the present invention. The computer device includes a processor, a memory, a network interface, and a database connected through a device bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a readable storage medium and an internal memory. The readable storage medium stores an operating device, computer-readable instructions, and a database. The internal memory provides an environment for the operation of the operating device and computer-readable instructions in the readable storage medium. The database of the computer device is used to store data involved in the encryption and decryption method. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer-readable instructions are executed by the processor, an encryption and decryption method is implemented. The readable storage medium provided in this embodiment includes a non-volatile readable storage medium and a volatile readable storage medium.
[0154] In one embodiment, a computer device is provided. The computer device may be a terminal device, and its internal structure diagram may be as Figure 3 shown. The computer device includes a processor, a memory, and a network interface connected through a device bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a readable storage medium. The readable storage medium stores computer-readable instructions. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer-readable instructions are executed by the processor, an encryption and decryption method is implemented. The readable storage medium provided in this embodiment includes a non-volatile readable storage medium and a volatile readable storage medium.
[0155] In one embodiment, a computer device is provided, including a memory, a processor, and computer-readable instructions stored in the memory and executable on the processor. When the processor executes the computer-readable instructions, the steps of the encryption and decryption method as described above are implemented.
[0156] In one embodiment, a readable storage medium is provided. The readable storage medium stores computer-readable instructions, and when the computer-readable instructions are executed by a processor, the steps of the above encryption and decryption method are implemented. Those of ordinary skill in the art can understand that all or part of the processes in the above-described embodiment methods can be completed by instructing relevant hardware through computer-readable instructions. The computer-readable instructions can be stored in a non-volatile readable storage medium or a volatile readable storage medium. When the computer-readable instructions are executed, they can include the processes of the embodiments of the above various methods. Among them, any reference to a memory, storage, database, or other medium used in the various embodiments provided in this application can include non-volatile and / or volatile memories. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or an external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.
[0157] Those skilled in the art can clearly understand that for the convenience and brevity of description, only the above division of each functional unit and module is used as an example. In actual applications, the above functions can be allocated to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.
[0158] The above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments or perform equivalent replacements for some of the technical features. These modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention and should all be included in the protection scope of the present invention.
Claims
1. An encryption and decryption method, characterized in that: include: Based on the first prime number and the second prime number, determining a target modulus and a least common multiple; Determining a modulus inverse correction value based on the least common multiple and the target modulus; Acquire data to be encrypted, wherein the data to be encrypted includes first original data and second original data; Based on the target modulus, encrypt the first original data and the second original data respectively to obtain a first ciphertext corresponding to the first original data and a second ciphertext corresponding to the second original data; Determining a ciphertext operation result based on the first ciphertext and the second ciphertext; Decrypting the ciphertext operation result based on the module inverse correction value to obtain the target plaintext; The step of determining a modulus inverse correction value based on the least common multiple and the target modulus includes: Define the forward and reverse recursive mathematical formula: T0=Q0-K0×P0,...,T i =Q i -K i ×P i; In the forward recursion process: During the first recursion, the target modulus is assigned to the first parameter in the preset formula, the least common multiple is assigned to the second parameter in the preset formula, and the result of the first recursive calculation is determined in combination with the random number of the first recursion, wherein, during the first recursion, the first parameter represents Q0, the second parameter represents P0, and K0 refers to the random number of the first recursion; In each subsequent recursive process, the value of the second parameter in the previous recursive process is assigned to the first parameter, the result of the previous recursive calculation is assigned to the second parameter, and the result of the current recursive process is determined in combination with the random number in the current recursive process, until the result of the current recursive process is 1; During the reverse recursion: Determine a calculation formula for each recursion in the forward recursive process, wherein the calculation formula includes a value of a first parameter, a value of a second parameter and a random number in the recursive process; Start reverse recursion from the last recursive calculation formula in the forward recursive process, so as to use the last recursive calculation formula as the current reverse recursive calculation formula; In the result of each recursion during the forward recursive calculation process, determine the result of the previous recursion corresponding to the current reverse recursion; Compare the value of the first parameter, the value of the second parameter and the random number in the current reverse recursive calculation formula with the result of the previous recursion; If there is a value that is the same as the result of the previous recursion, a target expansion is generated according to the calculation formula of the current reverse recursion and the calculation formula of the previous recursion, and the target expansion is used as the new calculation formula of the current reverse recursion, and the step of determining the result of the previous recursion corresponding to the current reverse recursion is returned to the result of each recursion in the forward recursive calculation process, until the reverse recursion reaches the calculation formula of the first recursion in the forward recursive process; Simplifying the final target expansion to determine the modular inverse correction value according to the simplified formula; The decrypting the ciphertext operation result based on the module inverse correction value to obtain the target plaintext includes: Performing a power modular operation on the ciphertext operation result to obtain a modular operation result; Multiplying the modular operation result and the modular inverse correction value to obtain a multiplication operation result; Based on the target modulus, a modulus operation is performed on the multiplication result to obtain the target plaintext.
2. The encryption and decryption method according to claim 1, characterized in that: The encrypting the first original data and the second original data based on the target modulus to obtain a first ciphertext corresponding to the first original data and a second ciphertext corresponding to the second original data includes: Determine a first random factor and a second random factor; Based on the target modulus, determining an encryption base; Encrypting the first original data based on the target modulus, the encryption base, and the first random factor to obtain the first ciphertext; The second original data is encrypted based on the target modulus, the encryption base, and the second random factor to obtain the second ciphertext.
3. The encryption and decryption method according to claim 1, characterized in that: The determining a ciphertext operation result based on the first ciphertext and the second ciphertext includes: Multiplying the first ciphertext and the second ciphertext to obtain a target ciphertext; Based on the target modulus and the target ciphertext operation, the ciphertext operation result is determined.
4. The encryption and decryption method according to claim 1, characterized in that: The performing a power modular operation on the ciphertext operation result to obtain a modular operation result includes: Determine a first operation result based on the ciphertext operation result, the target modulus, and the least common multiple; The modulo operation result is determined based on the first operation result and the target modulus.
5. The encryption and decryption method according to claim 1, characterized in that: The method of determining a target modulus based on the first prime number and the second prime number comprises: The product of the first prime number and the second prime number is used as the target modulus.
6. An encryption and decryption device, characterized in that: include: A first determining module is used to determine a target modulus and a least common multiple based on a first prime number and a second prime number; A second determination module is used to determine a modulus inverse correction value based on the least common multiple and the target modulus; An acquisition module, used for acquiring data to be encrypted, wherein the data to be encrypted includes first original data and second original data; an encryption module, configured to encrypt the first original data and the second original data respectively based on the target modulus to obtain a first ciphertext corresponding to the first original data and a second ciphertext corresponding to the second original data; A calculation module, used for determining a ciphertext calculation result based on the first ciphertext and the second ciphertext; A decryption module, used to decrypt the ciphertext operation result based on the module inverse correction value to obtain the target plaintext; The step of determining a modulus inverse correction value based on the least common multiple and the target modulus includes: Define the forward and reverse recursive mathematical formula: T0=Q0-K0×P0,...,T i =Q i -K i ×P i; In the forward recursion process: During the first recursion, the target modulus is assigned to the first parameter in the preset formula, the least common multiple is assigned to the second parameter in the preset formula, and the result of the first recursive calculation is determined in combination with the random number of the first recursion, wherein, during the first recursion, the first parameter represents Q0, the second parameter represents P0, and K0 refers to the random number of the first recursion; In each subsequent recursive process, the value of the second parameter in the previous recursive process is assigned to the first parameter, the result of the previous recursive calculation is assigned to the second parameter, and the result of the current recursive process is determined in combination with the random number in the current recursive process, until the result of the current recursive process is 1; During the reverse recursion: Determine a calculation formula for each recursion in the forward recursive process, wherein the calculation formula includes a value of a first parameter, a value of a second parameter and a random number in the recursive process; Start reverse recursion from the last recursive calculation formula in the forward recursive process, so as to use the last recursive calculation formula as the current reverse recursive calculation formula; In the result of each recursion during the forward recursive calculation process, determine the result of the previous recursion corresponding to the current reverse recursion; Compare the value of the first parameter, the value of the second parameter and the random number in the current reverse recursive calculation formula with the result of the previous recursion; If there is a value that is the same as the result of the previous recursion, a target expansion is generated according to the calculation formula of the current reverse recursion and the calculation formula of the previous recursion, and the target expansion is used as the new calculation formula of the current reverse recursion, and the step of determining the result of the previous recursion corresponding to the current reverse recursion is returned to the result of each recursion in the forward recursive calculation process, until the reverse recursion reaches the calculation formula of the first recursion in the forward recursive process; Simplifying the final target expansion to determine the modular inverse correction value according to the simplified formula; The decrypting the ciphertext operation result based on the module inverse correction value to obtain the target plaintext includes: Performing a power modular operation on the ciphertext operation result to obtain a modular operation result; Multiplying the modular operation result and the modular inverse correction value to obtain a multiplication operation result; Based on the target modulus, a modulus operation is performed on the multiplication result to obtain the target plaintext.
7. A computer device comprising a memory, a processor, and computer-readable instructions stored in the memory and executed on the processor, characterized in that: When the processor executes the computer-readable instructions, the encryption and decryption method according to any one of claims 1 to 5 is implemented.
8. A readable storage medium having computer-readable instructions stored thereon, characterized in that: When the computer-readable instructions are executed by a processor, the encryption and decryption method according to any one of claims 1 to 5 is implemented.