An encryption method based on the RSA algorithm
By combining RC5 and RSA algorithms, multiple obfuscation processing and hashing operations are used to generate session keys, which solves the problem of insufficient security of RSA algorithm under hardware improvement and password analysis, and achieves efficient and secure data encryption.
Patent Information
- Application Number
- CN202411792973.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-08
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2044-12-08
AI Technical Summary
The existing RSA algorithm encryption methods are insecurity in the face of improved computer hardware performance and mature password analysis technology, and are prone to cracking, and a single algorithm cannot effectively resist ciphertext attacks.
The hybrid encryption method is adopted, combined with the symmetric encryption algorithm RC5 and the asymmetric encryption algorithm RSA, and the security is improved through multiple obfuscation processing. It includes steps such as data format conversion, hash operation to generate session keys, CBC mode encryption, pseudo-random number generator to generate exchange sequences, permutation and replacement operations, etc., to enhance the confusion and unpredictability of the data.
It improves the security of RSA algorithm encryption, enhances the randomness and unpredictability of session keys, increases the difficulty of cracking, adapts to the encryption needs of structured and unstructured data, and improves data processing efficiency.
Smart Images

Figure CN119449308B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data encryption technology, and particularly to an encryption method based on the RSA algorithm. Background Art
[0002] With the rapid development of information technology and the increasing popularity of network applications, data security has become the focus of attention in various fields. In industries such as government, finance, and healthcare that involve important privacy data, higher requirements are put forward for the confidentiality and integrity of data. However, existing data encryption technologies still have some deficiencies, resulting in encrypted data being easily cracked and the security of data being difficult to effectively guarantee. Among many encryption algorithms, the RSA algorithm is widely used in fields such as data encryption and digital signature due to the intractability of the large number factorization problem. The RSA algorithm uses a pair of public and private keys to encrypt and decrypt data. The public key is used for encryption, and the private key is used for decryption. Without knowing the private key, even if an attacker obtains the public key and ciphertext, it is difficult to crack the plaintext within a computationally feasible time, thus ensuring the confidentiality of data.
[0003] However, with the continuous improvement of computer hardware performance and the increasing maturity of cryptanalysis technology, the traditional RSA algorithm also faces some security challenges. An attacker can use methods such as known plaintext attack and chosen ciphertext attack, and through a large amount of data analysis and calculation attempts, infer the private key or restore the plaintext. In addition, the security of the RSA algorithm also depends on the selection of the key length. Insufficient key length or improper key management may lead to the leakage of encrypted data.
[0004] In related technologies, for example, Chinese Patent Document CN116506230B provides a data acquisition method, system, electronic device, and computer storage medium based on RSA asymmetric encryption. The acquisition method includes: obtaining data from the original data source, analyzing the data from the original data source to find problem data in the original data source; establishing strategies and rules for the data cleaning and processing model, and importing the problem data in the original data source into the data cleaning and processing model to obtain clean target data; performing format conversion on the target data, converting the key-value format of the target data into a set data format for output; performing RSA data encryption on the target data and forwarding it to the cloud server. This application can reduce the workload of cleaning and processing, improve the speed and efficiency of cleaning and processing; the target data is encrypted by RSA and forwarded to the cloud server, which can reduce the bandwidth between edge computing and the cloud server; at the same time, the data is encrypted and output, ensuring that the data transmission process is not leaked or tampered with. However, relying solely on the asymmetric encryption of the RSA single algorithm cannot effectively resist security threats such as ciphertext attacks, and the security is not high. Summary of the Invention
[0005] In view of the problem that encrypted data in the prior art is easily cracked, the present application provides an encryption method based on the RSA algorithm, which improves the security of RSA algorithm encryption through hybrid encryption and multiple obfuscation processes.
[0006] The object of the present application is achieved through the following technical solutions.
[0007] The present application provides an encryption method based on the RSA algorithm, including: In the data collection stage, collect structured data to be encrypted, such as database records, XML files, etc., and convert them into a unified structured format, such as JSON or binary format. Collect unstructured data to be encrypted, such as text, images, audio and video, etc., and convert them into a unified unstructured format, such as Base64 encoding. Splice the converted structured data and unstructured data according to predefined rules to form complete data to be encrypted.
[0008] In the session key generation stage, use a secure hash algorithm (such as SHA-256) to perform a hash operation on the data to be encrypted to obtain a hash value of a fixed length. Use the hash value as a seed and use a pseudo-random number generator (such as PRNG) to generate a random number sequence. According to the preset key length (such as 128 bits, 192 bits or 256 bits) and the number of encryption rounds (such as 12 rounds, 16 rounds or 20 rounds), divide the random number sequence into the required sub-keys. Use the RC5 symmetric block encryption algorithm, with the sub-key as the round key, to encrypt a fixed initial vector (such as a full 0 bit string) to generate a session key.
[0009] In the session key encryption stage, select a preset RSA public key, including the public key modulus and the public key exponent. Convert the session key into a large integer and encrypt it using the RSA encryption algorithm. Use the encrypted session key as the ciphertext and transmit or store it together with the data to be encrypted.
[0010] In the data encryption stage, divide the data to be encrypted into data blocks of a fixed size, such as 64 bits or 128 bits. Use the RC5 symmetric block encryption algorithm, with the session key as the round key, to encrypt each data block. Adopt the cipher block chaining (CBC) mode, perform an exclusive OR operation on the ciphertext of the previous data block and the current data block, and then perform RC5 encryption. Splice all the encrypted data blocks together to form preliminary encrypted data.
[0011] In the data obfuscation stage, the preliminary encrypted data is divided into several data blocks of a fixed size. Each data block is subjected to M rounds of obfuscation processing, where M is a preset positive integer. Each round of obfuscation processing includes: dividing the data block into several sub-blocks; performing a byte-level permutation operation on each sub-block, such as swapping the i-th byte with the (i + 1) mod n-th byte, where n is the number of bytes in the sub-block; performing a byte-level substitution operation on the permuted sub-block, such as swapping the high 4 bits and the low 4 bits of each byte; reassembling the processed sub-blocks into a complete data block; and concatenating all the obfuscated data blocks together to obtain the final encrypted data.
[0012] Furthermore, generating a session key includes: performing SHA256 hash calculation on the structured data to be encrypted, serializing the structured data to be encrypted according to a predefined data format and field order to obtain a byte sequence, and performing SHA256 cryptographic hash algorithm on the byte sequence to obtain a 256-bit (32-byte) structured data hash value; performing MD5 hash calculation on the unstructured data to be encrypted, encoding the unstructured data to be encrypted according to a predefined encoding format (such as Base64) to obtain a byte sequence, and performing MD5 cryptographic hash algorithm on the byte sequence to obtain a 128-bit (16-byte) unstructured data hash value; generating an initial vector, concatenating the obtained structured data hash value and the obtained unstructured data hash value in a preset order, first the structured hash value and then the unstructured hash value, to obtain a 384-bit (48-byte) concatenated hash value, and using the concatenated hash value as the initial vector of the RC5 encryption algorithm; setting the RC5 algorithm parameters, setting the key length of the RC5 algorithm to L bits, such as 128 bits, 192 bits, or 256 bits, and setting the number of encryption rounds of the RC5 algorithm to T, such as 12 rounds, 16 rounds, or 20 rounds; and performing SHA3-384 hash calculation on the initial vector, and performing SHA3-384 cryptographic hash algorithm on the obtained initial vector to obtain a 384-bit (48-byte) SHA3 hash value.
[0013] Preferably, the PBKDF2 algorithm is used to further process the SHA3 hash value to obtain a session key of the required length. The SHA3 hash value is used as the password; a randomly generated salt value with a length of not less than 128 bits; a preset number of iterations of not less than 1000 times; and the length of the output key is equal to the key length L.
[0014] Further, generating a session key further includes: generating sub-vectors, dividing the obtained SHA3 hash value into S sub-vectors with a length of L bits, denoted as V1 to VS, where S = 384 / L. Preferably, using the RC5 algorithm with an initial key of a preset L-bit length and a set number of encryption rounds T, generating T sub-keys with a length of L bits, denoted as K1 to KT; preferably, performing an exclusive OR operation on the initial key and the SHA3 hash value, and using the obtained exclusive OR result as the seed key for the RC5 key expansion algorithm; using the RC5 key expansion algorithm, with the seed key as the input, generating 2T sub-keys; the RC5 key expansion algorithm ensures the randomness and unpredictability of the sub-keys; dividing the generated 2T sub-keys into two groups, the first T sub-keys K1 to KT are used for encrypting the odd sub-vectors, and the last T sub-keys K(T + 1) to K2T are used for decrypting the even sub-vectors;
[0015] Generating sub-keys, select an initial key of a preset L-bit length (such as 128 bits) as the key input for the RC5 algorithm. Using the RC5 key expansion algorithm, with the initial key and a set number of encryption rounds T as the input, generating T sub-keys with a length of L bits, denoted as K1 to KT. Preferably, using Ki to perform RC5 encryption E(Vi) on the odd-numbered plaintext sub-vector Vi, and using the encryption result E(Vi) as the left half of Ci; using K(i + T) to perform RC5 decryption D(Vi) on the even-numbered plaintext sub-vector Vi, and using the decryption result D(Vi) as the right half of Ci; by encrypting the odd sub-vectors and decrypting the even sub-vectors, and then splicing to obtain Ci, introducing the asymmetry of alternating encryption and decryption, increasing the difficulty of cracking the session key; Encrypting sub-vectors, for the i-th sub-vector Vi among the obtained S sub-vectors, using the generated i-th sub-key Ki as the key, and using the RC5 encryption algorithm to encrypt Vi, obtaining an encrypted sub-vector Ci with a length of L bits, where i is an integer from 1 to S.
[0016] Further, in the CBC mode encryption stage of session key generation, an Initialization Vector (IV) is introduced. A predefined L-bit Initialization Vector (IV) is set for the initialization of the CBC mode. CBC mode encryption is performed. The first sub-vector V1 obtained is XORed bitwise with the Initialization Vector (IV), and the XOR result is used as the initial value of the feedback encryption sub-vector C'0. For each integer i from 1 to S, the following steps are performed: The i-th encrypted sub-vector Ci obtained is XORed bitwise with the feedback encryption sub-vector C'i-1 obtained in the previous iteration, resulting in an XOR result Ri of length L bits. Using the generated i-th sub-key Ki as the key, RC5 encryption is performed on Ri, resulting in an encrypted result Ei of length L bits. The encrypted result Ei is XORed bitwise with the i-th sub-vector Vi obtained, resulting in a feedback encryption sub-vector C'i of length L bits. The above iterative process is repeated until S feedback encryption sub-vectors C'1 to C'S are obtained. The final session key is generated by concatenating the S feedback encryption sub-vectors C'1 to C'S in sequence, resulting in a final session key of length 384 bits (48 bytes).
[0017] Preferably, rearrange the bits of the SHA3 hash value according to a preset permutation table. The input and output lengths of the permutation table are the same as the length of the SHA3 hash value. The generation of the permutation table is based on the key used in the session key derivation process. The permutation table is obtained by expanding and transforming the key, ensuring the unpredictability of the permutation operation. Group the bit sequence obtained after the permutation operation from left to right, with each group having L bits, and a total of S sub-vectors V1 to VS of length L are obtained. Use the RC5 algorithm with an initial key of a preset length of L bits and a set number of encryption rounds T to generate T sub-keys of length L bits, denoted as K1 to KT. The generation of the sub-keys includes: performing a bitwise XOR operation on the initial key and the SHA3 hash value, and using the XOR result as the seed key for the RC5 key expansion algorithm. Use the RC5 key expansion algorithm, with the seed key as the input, and generate T sub-keys K1 to KT of length L through operations such as circular shifting and XOR. The RC5 key expansion algorithm ensures the randomness and unpredictability of the sub-keys. (3) Interleave the S sub-vectors Vi and the T sub-keys Ki to obtain S interleaved sub-vectors Wi and T interleaved sub-keys Ji: XOR the sub-vectors V1, V3,... at odd positions with the sub-keys K1, K3,... at odd positions in sequence to obtain the interleaved sub-vectors W1, W3,... and the interleaved sub-keys J1, J3,... at odd positions; XOR the sub-vectors V2, V4,... at even positions with the sub-keys K2, K4,... at even positions in sequence to obtain the interleaved sub-vectors W2, W4,... and the interleaved sub-keys J2, J4,... at even positions; The interleaving process introduces the correlation between sub-vectors and sub-keys through exclusive-or operation, disrupts the statistical characteristics of the original data, and increases the difficulty of cracking; (4) Adopt the CBC mode, with S interleaved sub-vectors Wi as the input, T interleaved sub-keys Ji as the key, introduce an initial vector IV with a length of L, and perform iterative calculations to obtain S feedback encrypted sub-vectors C'i with a length of L; The iterative calculation includes: performing bitwise exclusive-or on the first interleaved sub-vector W1 and the initial vector IV to obtain the exclusive-or result X1 as the input for the first round of CBC encryption; using the i-th interleaved sub-key Ji to perform RC5 encryption on the input Xi of the i-th round to obtain an encrypted result Ei with a length of L; performing bitwise exclusive-or on the encrypted result Ei and the (i + 1)-th interleaved sub-vector W(i + 1) to obtain an exclusive-or result X(i + 1) with a length of L as the input for the next round of CBC encryption; repeating the above process until the last round, performing exclusive-or on the encrypted result ES and WS to obtain C'S with a length of L; By substituting the interleaved sub-vectors for the original sub-vectors and inputting them into the CBC iteration, a feedback mechanism is introduced to increase the diffusion and confusion of the ciphertext, further enhancing the strength of the feedback encryption; (5) Perform a permutation operation on the S feedback encrypted sub-vectors C'1 to C'S with a length of L, and then splice them in order to obtain a session key with a length of S * L; The permutation operation uses a different permutation table from that in step (1), further increasing the difficulty of cracking; The permutation table is also generated based on the key, ensuring the unpredictability of the permutation operation. By introducing multiple rounds of randomization measures in the process of converting the SHA3 hash value to the session key, including: the permutation operation based on the key disrupts the bit positions of the hash value, hiding the statistical characteristics of the original data; dynamically generating sub-keys related to the hash value for interleaving processing and RC5 encryption, providing the randomness of the key; interleaving the sub-vectors and sub-keys, introducing correlation, and increasing the difficulty of cracking; using the CBC mode to iteratively encrypt the interleaved result, introducing the initial vector, and increasing the diffusion and confusion of the ciphertext; finally, permuting the feedback encryption result again to further disrupt the data order and bit distribution. Multiple randomization steps are concatenated and combined to finally obtain a session key with high randomness, unpredictability, and anti-attack ability. This method makes full use of the bit-level confusion of the hash value, innovatively combines technical measures such as permutation, interleaving, and feedback encryption, forming a comprehensive and effective session key generation scheme, which can significantly improve the security strength of the session key.
[0018] Further, encrypted data is generated, including: encrypting the data to be encrypted using the symmetric block cipher algorithm RC5. The RC5 algorithm is a block cipher algorithm that divides the plaintext data into data blocks of a fixed size and encrypts each data block using a key. In this application, the generated session key is used as the encryption key for the RC5 algorithm to encrypt the data to be encrypted, obtaining the encrypted data. Next, the encrypted data is divided into N blocks, where N is an integer greater than 1. An appropriate value of N can be selected according to the size of the data and the requirements of block division. For example, the data can be divided into blocks of a fixed size, such as 128 bytes, 256 bytes, etc.; or different block division methods can be adopted according to the characteristics of the data, such as file format, data type, etc.
[0019] The divided encrypted data is stored in a buffer area, and the buffer area can be memory, disk, or other storage media. Each data block occupies a continuous storage space in the buffer area, and the data blocks are numbered from 1 to N. The Mersenne Twister algorithm is used to generate a pseudo-random swap sequence containing N swap indices. The Mersenne Twister algorithm is an efficient pseudo-random number generation algorithm that can generate a pseudo-random number sequence with uniform distribution, long period, and good statistical characteristics. According to the generated pseudo-random swap sequence, swap operations are performed on the data blocks in the buffer area to change the order of the data blocks, realizing the confusion and perturbation of the data. Obtain the first swap index from the pseudo-random swap sequence, and according to this index, read two corresponding data blocks from the buffer area, which are respectively marked as data block blockA and data block blockB. Swap the storage positions of data block blockA and data block blockB in the buffer area. Specifically, copy data block blockA to a temporary buffer, then copy data block blockB to the original position of data block blockA, and finally copy the data block blockA in the temporary buffer to the original position of data block blockB. In this way, the swap operation of two data blocks is completed. Continue to obtain the next swap index from the pseudo-random swap sequence, and repeat the steps of data block swapping until all N data blocks have been swapped. After the data block swapping is completed, read N data blocks from the buffer area in the swapped order and concatenate them into the complete encrypted data. This encrypted data is used as the final output result and can be stored, transmitted, or subjected to other subsequent processing.
[0020] Further, the Mersenne Twister algorithm is used to generate a pseudo-random permutation order, including: The internal state of the Mersenne Twister algorithm consists of two parts: a seed value and a state vector. The seed value is used to determine the starting point of the pseudo-random number sequence, and the state vector is used to store the intermediate results of generating pseudo-random numbers. To enhance the security of the pseudo-random permutation sequence, the present application uses a key derivation function based on a hash function, taking the generated session key as input to derive the seed value. Specifically, the session key is used as the input of the hash function to calculate the hash value, and a part of the hash value is used as the seed value. This can ensure a cryptographic association between the seed value and the session key, increasing the randomness and unpredictability of the seed value.
[0021] Preferably, using HKDF (HMAC-based Key Derivation Function), the session key, a random salt value, a timestamp, and a counter are received as input data, where the session key is a shared key negotiated by both communication parties, the random salt value is a randomly generated fixed-length value, the timestamp represents the current time, and the counter is an incrementing integer value; the session key, the random salt value, the timestamp, and the counter are concatenated into an input string as the input of the improved HKDF; a double hash chain operation is performed on the input string, using two different hash functions and initialization vectors to generate the outputs of two hash chains respectively, and the double hash chain operation enhances the security of the key derivation process; the outputs of the two hash chains are combined through an exclusive-or operation to generate a derived key, and the exclusive-or operation mixes the outputs of the two hash chains, improving the randomness of the derived key; the derived key is split into multiple sub-keys, the length of each sub-key is adjusted according to requirements, and then the sub-keys are mixed through a key mixing algorithm to generate the final seed key, and key splitting and key mixing increase the unpredictability of the derived key; it is judged whether the length of the seed key is the same as the length of the seed value required by the Mersenne Twister algorithm, if not, the seed key is truncated or extended to obtain a processed seed key with the same length as the seed value; the processed seed key is used as the seed value and set as the initial seed value of the Mersenne Twister algorithm to initialize the internal state of the Mersenne Twister algorithm. In the double hash chain operation, one hash chain uses the SHA-256 hash function, and the other hash chain uses the SHA-512 hash function, and the two hash functions have different security strengths and output lengths. The key mixing algorithm is selected from exclusive-or operation, HMAC operation or other secure key mixing algorithms to mix the sub-keys to generate the final seed key.
[0022] Set the derived seed value as the initial seed value of the Mersenne Twister algorithm for initializing the internal state of the algorithm. Meanwhile, initialize the state vector to a preset constant, such as a vector of all 0s or all 1s, to prepare for subsequent state updates. According to the internal state of the Mersenne Twister algorithm, a new state vector is generated using a linear feedback shift register (LFSR) and bitwise operations. First, use the LFSR to perform a shift operation on the current state vector. The LFSR cyclically shifts the bits of the state vector according to a predetermined shift pattern, moving the highest bit out and placing it in the lowest bit to form a new state vector. The number of bits to shift can be set according to the parameters of the algorithm, such as 32 bits or 64 bits. Then, perform an exclusive OR operation on the shifted state vector and a preset feedback polynomial to update the content of the state vector. The feedback polynomial is a fixed binary polynomial, and its coefficients determine the feedback positions of the LFSR. By performing an exclusive OR operation on specific bits of the state vector and the feedback polynomial, new randomness can be introduced to prevent the state vector from entering a short-period cycle.
[0023] Preferably, a quaternary distortion function is used to generate a new state vector, which receives the current internal state vector of the Mersenne Twister algorithm as input. The internal state vector consists of multiple binary bits. Apply a linear feedback shift register to the internal state vector, perform a shift operation on the current state vector, and perform an exclusive OR operation with a preset feedback polynomial to generate an updated state vector. The preset feedback polynomial is a fixed binary polynomial. Apply bit operations to the updated state vector to mix the bit positions of the state vector and generate a mixed state vector. The bit operations include exclusive OR operation, AND operation, OR operation, or a combination thereof. Divide the mixed state vector into multiple quaternaries, each quaternary containing four binary bits, as the input of the quaternary distortion function. Apply the quaternary distortion function to each quaternary, and calculate a binary bit as the output according to the value of the quaternary. The quaternary distortion function is a Boolean function that maps the input of four binary bits to the output of one binary bit. Concatenate the binary bits calculated by applying the quaternary distortion function to all quaternaries to form a new state vector, which is used as the new state for generating the pseudo-random number sequence. The quaternary distortion function satisfies the following conditions: for any two different quaternary inputs, the output binary bits are different, that is, it has perfect nonlinear characteristics; the algebraic degree of the quaternary distortion function is 3, that is, the degree of the highest-order term in the function expression is 3; the nonlinear order of the quaternary distortion function is 4, that is, the nonlinearity of the function reaches the maximum value. Before dividing the mixed state vector into quaternaries, perform a permutation operation on the mixed state vector to rearrange the bit positions of the state vector, disrupt the original position relationship, and increase the diffusion effect of state transfer. After applying the quaternary distortion function to the quaternary to calculate the binary bit, perform a permutation operation on the calculated binary bit to rearrange the output binary bit, further increasing the confusion and diffusion of state transfer.
[0024] Perform bitwise operations on the updated state vector to further mix the bits of the state vector. The bitwise operations can include operations such as bitwise AND, bitwise OR, and bitwise XOR. By combining and transforming the bits of the state vector, the complexity and unpredictability of the state vector are increased. After LFSR shifting, feedback XOR, and bitwise operations, a new state vector is obtained, which serves as the current internal state of the Mersenne Twister algorithm. Perform a modulo-N operation on the generated new state vector to obtain a random integer in the range from 1 to N, which serves as a candidate swap index in the pseudo-random swap sequence. The modulo-N operation can be obtained by taking the lower bits of the state vector and taking the modulo of N. The candidate swap index represents the position of the data block in the buffer and is used for subsequent data block swap operations. Since the swap index needs to be between 1 and N and non-repeating, further processing and judgment of the candidate swap index are required. Use a hash table to determine whether the generated candidate swap index is repeated with the previously generated swap index. Perform a hash operation using the candidate swap index as the key to obtain a hash value. Check whether there is a corresponding key-value pair in the hash table, that is, whether there is the same swap index.
[0025] If the same swap index is found in the hash table, it means that the current candidate swap index is repeated and a new candidate swap index needs to be generated. Regenerate a new state vector based on the current internal state and continue to execute the subsequent steps until a non-repeating candidate swap index is generated. If the same swap index is not found in the hash table, it means that the current candidate swap index is valid and can be used as the final swap index. Add the obtained valid swap index to the pseudo-random swap sequence as an element of the sequence. At the same time, insert the valid swap index as the key into the hash table to update the content of the hash table for subsequent repeatability judgment. To further enhance the security and unpredictability of the pseudo-random swap sequence, obtain the current timestamp and perform an XOR operation with the generated new state vector to obtain the final state vector. The timestamp can be obtained by getting the system time or network time, which introduces a time factor and increases the dynamicity and randomness of the state vector.
[0026] Use the XORed final state vector as the new internal state of the Mersenne Twister algorithm for the next generation of candidate swap indices. This ensures that each generated swap index is related to the previous internal state, increasing the complexity and unpredictability of the pseudo-random swap sequence. Determine whether the number of swap indices in the current pseudo-random swap sequence has reached the preset value of N. If the number of swap indices reaches N, it means that a sufficient number of swap indices have been generated, and the complete pseudo-random swap sequence can be output. Use the pseudo-random swap sequence containing N swap indices as the final output result for subsequent data block swap operations. If the number of swap indices has not reached N, more valid swap indices need to be generated. Return to repeat the steps of generating candidate swap indices, judging repeatability, updating the swap sequence, and internal state according to the current internal state until N valid swap indices are generated. Among them, the feedback polynomial of the linear feedback shift register (LFSR) can be expressed as: f(x) = x^n + c_{n-1}x^{n-1} + c_{n-2}x^{n-2} +... + c_1x + c_0, where: n represents the number of stages of the LFSR, that is, the bit length of the state vector; c_i ∈ {0, 1}, i = 0, 1,..., n - 1, represents the coefficients of the feedback polynomial, which determine the position of the feedback bits; x^i represents the i-th bit in the state vector, and x^n represents the highest bit.
[0027] Further, the hash table is constructed and updated using the following steps: Initialize a hash table of size N, with the hash function being modulo N remainder, and the method for resolving hash collisions being chaining. The specific implementation is as follows: Define the data structure of the hash table, including: an array of buckets of size N, where each bucket is a pointer to the head node of a linked list; the structure of the linked list node, which contains an integer key and a pointer to the next node. Implement the hash function to map the swap index to the corresponding bucket subscript: Define the hash function as hash(key) = key % N, where key is the swap index and N is the size of the hash table; the hash function takes the modulo of the swap index by the size of the hash table to obtain a bucket subscript in the range of 0 to N - 1. Insert key-value pairs into the hash table: Use the generated valid swap index as the key, calculate its hash value hash(key), and obtain the corresponding bucket subscript; insert a new node at the head of the linked list corresponding to the bucket subscript, with the key of the node being the swap index, and insert the new node at the head of the linked list using the head-insertion method; the head-insertion method can maintain the insertion order of the key-value pairs, and the newly inserted key-value pair is always at the head of the linked list.
[0028] Determine whether the candidate swap index is repeated: Use the candidate swap index as the key, calculate its hash value hash(key) to obtain the corresponding bucket subscript; traverse the linked list corresponding to the bucket subscript and compare whether the key of each node in the linked list is equal to the candidate swap index; if an equal key is found, it means that the candidate swap index already exists in the hash table, that is, a repetition has occurred; if no equal key is found after traversing the entire linked list, it means that the candidate swap index does not exist in the hash table, that is, it is not repeated. This implementation method based on the hash table and the chaining method can efficiently insert and search key-value pairs, with an average time complexity of O(1). At the same time, using the head insertion method can maintain the insertion order of key-value pairs, facilitating subsequent processing and access. By judging duplicates through the hash table, it is possible to effectively avoid duplicate swap indexes in the pseudo-random swap sequence, ensuring the validity and randomness of the sequence.
[0029] Furthermore, perform M rounds of confusion processing on the encrypted data to obtain the final encrypted data, including: an array of fixed size, where the elements in the array are integers between 0 and the size of the substitution box - 1, and each integer represents the new position to which the bit at the corresponding position will be permuted; the substitution box is also an array of fixed size, where the elements in the array are integers between 0 and the size of the substitution box - 1, and each integer represents the new value to which the bit at the corresponding position will be replaced; the substitution box and the replacement box can be generated randomly or based on a key, ensuring the security and unpredictability of the confusion operation; use the generated substitution box and replacement box as parameters for the confusion processing and use them in each round of confusion operation. The data is divided into sub-blocks: regard the encrypted data as consisting of N data blocks of fixed size, and the size of the data block can be determined according to the block size of the encryption algorithm; further divide each data block into multiple sub-blocks, and the size of the sub-block is the same as the size of the substitution box; the number of sub-blocks is equal to the size of the data block divided by the size of the substitution box, ensuring that each sub-block can correspond one-to-one with the substitution box.
[0030] Permutation operation of sub - blocks: For each sub - block, rearrange the bit positions within the sub - block according to the preset positions in the permutation box; the permutation operation exchanges the bit positions within the sub - block according to the specified positions in the permutation box, and the new positions of the bits are determined by the values at the corresponding positions in the permutation box; the permutation operation is a bit - level rearrangement that increases the confusion degree of the data by shuffling the order of the bits. Sub - block substitution operation: For each permuted sub - block, perform a non - linear substitution on the bit positions within the sub - block according to the preset values in the substitution box; the substitution operation replaces each bit position within the sub - block with the value at the corresponding position in the substitution box, and the replaced bits are determined by the values in the substitution box; the substitution operation is a non - linear transformation that replaces the bit values by looking up a table, introducing non - linear characteristics and enhancing the confusion effect of the data. Sub - block combination: Re - combine the sub - blocks after the permutation and substitution operations into a complete data block in the order before permutation; the combination operation concatenates all the sub - blocks together in the original order to obtain the encrypted data after permutation and substitution; the combination operation ensures that the confused data has the same structure and length as the original encrypted data. Iterative confusion processing: Repeat the confusion processing on the encrypted data for M rounds; the same permutation box and substitution box are used in each round of confusion processing, but the division and combination order of the sub - blocks can vary in each round; multiple rounds of confusion processing further enhance the confusion degree of the data, making the data more difficult to be cracked or restored. Output the final encrypted data: After M rounds of confusion processing, obtain the final encrypted data; the final encrypted data has the same data format and length as the original encrypted data, but has been confused by the permutation and substitution operations; the confused data has higher randomness and unpredictability, enhancing the security of encryption.
[0031] Furthermore, perform M rounds of confusion processing on the encrypted data to obtain the final encrypted data, where the substitution operation includes: Divide the encrypted data after permutation: Re - divide the encrypted data after the permutation operation into multiple sub - blocks; the size of the sub - blocks is the same as the input size of the substitution box, usually 1 byte (8 bits); the number of sub - blocks is equal to the length of the encrypted data after permutation divided by the input size of the substitution box. Construct a byte substitution table: Create an array of 256 bytes as the byte substitution table; the index range of the byte substitution table is from 0 to 255, corresponding to all possible values of a byte; each element in the byte substitution table is also a byte, used to store the replaced byte value; the byte substitution table can be generated based on a key or randomly, ensuring the security and unpredictability of the substitution operation. Substitute bytes within the sub - block: For each sub - block obtained by division, use each byte within the sub - block as the index of the byte substitution table; according to the value of each byte within the sub - block, look up the element at the corresponding index position in the byte substitution table; replace each byte within the sub - block with the corresponding replaced byte found in the byte substitution table; the substitution operation is implemented by looking up a table, mapping the original byte value to the replaced byte value.
[0032] Splicing of sub - blocks: Splice all the sub - blocks after the replacement operation together in the order before division; the splicing operation recombines all the replaced sub - blocks into the complete encrypted data; the encrypted data after splicing has the same data length and format as the encrypted data after permutation. Iterative confusion processing: Repeat the confusion processing of the encrypted data for M rounds; the same byte substitution table is used in each round of confusion processing, ensuring the consistency of the replacement operation; multiple rounds of confusion processing further enhance the degree of data confusion, making the data more difficult to be cracked or restored. Output the final encrypted data: After M rounds of confusion processing, the final encrypted data is obtained; the final encrypted data has been double - confused by the permutation operation and the replacement operation; the confused data has higher randomness and unpredictability, enhancing the security of encryption. Through the above steps, the replacement operation is introduced after the permutation operation, and the byte substitution table is used to perform non - linear replacement on the bytes within the sub - blocks. The replacement operation maps the original bytes to the replaced bytes through table look - up, introducing additional non - linear transformation and further enhancing the data confusion effect. The construction of the byte substitution table can be based on the key or randomly generated, ensuring the security and unpredictability of the replacement operation. By dividing the encrypted data after permutation into sub - blocks of the same size as the input of the substitution box, it is convenient to perform independent replacement operations on each byte. The replaced sub - blocks are spliced together in the original order to obtain the encrypted data after replacement. Multiple rounds of iterative confusion processing further improve the randomness and unpredictability of the data, enhancing the overall security of encryption.
[0033] Preferably, a 256-byte substitution table and a permutation box are generated according to the key. The substitution table serves as the storage structure of the substitution box, and the permutation box is used to permute the byte positions within the sub-block. The index range of the substitution table is from 0 to 255, and each element in the table is a byte, which is used to store the replaced byte value. The size of the permutation box is the same as the size of the sub-block and is used to store the permutation method of the byte positions. The substitution table and the permutation box are dynamically generated according to the key, ensuring that the substitution box and the permutation box used for each encryption are different, enhancing the non-linearity and unpredictability of the encryption. The encrypted data is divided into N sub-blocks according to the input size of the substitution table, and necessary padding bytes are added at the end of the data to ensure that the data length is an integer multiple of the input size. For each sub-block, the byte positions are permuted using the permutation box: a pseudo-random number is generated according to the content of the sub-block, and this pseudo-random number is used as the index of the permutation box. According to the index, the corresponding permutation method is selected from the permutation box to permute the byte positions within the sub-block. The permuted sub-block has higher randomness and uniform distribution characteristics. The permuted encrypted data is subjected to M rounds of substitution processing. Each round of substitution processing includes: dividing the encrypted data into N sub-blocks, where the size of each sub-block is the same as the input size of the substitution table; for each sub-block, multiple substitutions are performed using the substitution table corresponding to the current round and a non-linear transformation function: each byte within the sub-block is used as the index of the substitution table, and the replaced byte at the corresponding position is found from the substitution table according to the index; the replaced byte is used as the input of the non-linear transformation function, and the transformed byte value is obtained through the non-linear transformation function. The non-linear transformation function can be an S-box, an exclusive OR operation, a modular addition, etc.; each byte within the sub-block is replaced with the transformed byte value to obtain the replaced sub-block; the replacement operation is repeated K times, where K is the preset number of replacement times; the multiple substitutions combined with the non-linear transformation further enhance the confusion and non-linearity of the data; the replaced sub-blocks are concatenated in the original order to obtain the encrypted data after this round of substitution processing; according to the encrypted data after this round of substitution processing, the substitution table and the permutation box are updated: the updated encrypted data is subjected to an exclusive OR operation with the original substitution table and permutation box to obtain the updated substitution table and permutation box; the updated substitution table and permutation box are related to the encrypted data of this round, further enhancing the dynamicity and unpredictability of the encryption. After M rounds of substitution processing, the final encrypted data is obtained.
[0034] Furthermore, the encrypted data is subjected to M rounds of confusion processing to obtain the final encrypted data. Key scheduling scheme: Using the generated session key as input, M round keys are derived by means of the key scheduling scheme; the number of round keys is the same as the number of rounds M of the confusion processing, and each round key corresponds to one round of confusion processing; the length of each round key is the same as the length of the encrypted data after substitution, ensuring the feasibility of the bitwise XOR operation between the round key and the encrypted data; the key scheduling scheme can be implemented based on a cryptographically secure pseudorandom function (such as HMAC or KDF), ensuring the security and independence of the round keys.
[0035] XOR operation of round keys: For the i-th round of confusion processing (i is an integer from 1 to M), the encrypted data after substitution is subjected to a bitwise XOR operation with the i-th round key; the XOR operation is a simple and effective cryptographic operation that performs a bitwise XOR on two bit strings of equal length to obtain the XOR result; the XOR operation has the following property: for any bits a and b, (a XOR b) XOR b = a, that is, the result of the XOR operation is XORed with the same value again, and the original value can be restored; by performing the XOR operation on the encrypted data and the round key, the data can be further confused, increasing the difficulty of cracking.
[0036] Iterative confusion processing: The encrypted data after XOR is used as the input for the next round of confusion processing, and the M rounds of confusion processing are repeated; in each round of confusion processing, the corresponding round key is used to perform a bitwise XOR operation with the encrypted data of the current round to obtain the encrypted data after XOR; the encrypted data after XOR is used as the input for the next round of confusion processing, ensuring the dependency and continuity between the rounds of confusion processing; through multiple rounds of iterative confusion processing, the encrypted data can be continuously confused and diffused, enhancing the overall security of the encryption.
[0037] Final encrypted data: After M rounds of confusion processing, the final encrypted data is obtained; the final encrypted data has undergone multiple confusions such as permutation operation, substitution operation, and XOR operation with the round key; the confused data has a high degree of randomness and unpredictability. Even if part of the encrypted data is obtained, it is difficult to infer the original data or other parts of the encrypted data; the combination of multiple confusions comprehensively enhances the security of the encrypted data, greatly increasing the difficulty of cracking. Through the above steps, based on the permutation operation and substitution operation, the XOR operation between the round key and the encrypted data is introduced, further enhancing the confusion effect of the data.
[0038] The key scheduling scheme derives the same number of round keys as the number of confusion rounds from the session key, ensuring that each round of confusion processing uses an independent key and increasing the difficulty of cracking. The length of the round key is the same as the length of the encrypted data after substitution, facilitating the implementation of bitwise XOR operation. In each round of confusion processing, the encrypted data of the current round is subjected to a bitwise XOR operation with the corresponding round key to obtain the XORed encrypted data. The XOR operation has good cryptographic properties, can effectively confuse the data, and is reversible. The original data can be restored by XORing with the same round key again. Multiple rounds of iterative confusion processing continuously confuse and diffuse the encrypted data, making the randomness and unpredictability of the data continuously enhanced. The output of each round of confusion processing is used as the input of the next round, ensuring the accumulation and transmission of the confusion effect.
[0039] Preferably, using the generated session key as input, a key scheduling scheme is adopted, and through a secure key derivation function, M round keys and an initial vector (IV) are derived; during the iterative and confusion operations, a key confusion mechanism is introduced: in each iteration, the output of the previous round is confused with the sub-key of the current round, such as an exclusive OR (XOR) operation; the confused result is used as the input of the pseudo-random function of the current round to generate the round key of the current round; by introducing the key confusion mechanism, the key dependency relationship between different rounds is enhanced, making it difficult for an attacker to infer the values of other round keys from the known round keys, thereby improving the security of the encryption scheme; a counter mechanism is introduced during each iteration: the number of the current round is XORed with the session key and used as an additional input to the pseudo-random function; by introducing the counter mechanism, the independence and unpredictability of the round keys are enhanced; among the M round keys derived through the key scheduling scheme, the length of each round key is the same as the length of the encrypted data after substitution, ensuring a one-to-one correspondence between the round keys and the encrypted data; a cryptographically secure random number generator is used, such as a hardware-based true random number generator or a securely authenticated pseudo-random number generator; a random bit sequence with a length equal to the length of the encrypted data block is generated as the initial vector (IV); by using a secure random number generator, it is ensured that the generated initial vector has sufficient randomness and unpredictability, enhancing the security of the encryption scheme; for each data block, the initial vector (IV) is used for initialization as the starting input of the encryption process; the data block is divided into several sub-blocks, and the size of each sub-block is the same as the input size of the byte substitution table; each sub-block is subjected to multiple rounds of confusion processing, and each round of confusion processing includes: dynamically generating a byte substitution table and a permutation box according to the round key of the current round; using the byte substitution table to replace each byte in the sub-block with the corresponding replacement byte; using the permutation box to permute the replaced sub-block to change the positions of the bytes in the sub-block; performing a non-linear transformation on the permuted sub-block to introduce non-linear characteristics; XORing the transformed sub-block with the round key of the current round to obtain the encrypted sub-block; concatenating all the encrypted sub-blocks to obtain the encryption result of the current data block; using the encryption result of the current data block as the initial vector (IV) for the next data block for the encryption process of the next data block; concatenating all the encrypted data blocks to obtain the final encrypted data; outputting the encrypted data to complete the encryption process.
[0040] Compared with the prior art, the advantages of the present application are as follows:
[0041] This solution uses a combination of the symmetric encryption algorithm RC5 and the asymmetric encryption algorithm RSA to generate a session key pair to encrypt data. The generation process of the session key introduces multiple hash algorithms such as SHA256, MD5, and SHA3-384, and introduces a feedback mechanism through the CBC mode, enhancing the randomness and unpredictability of the key. Even if an attacker obtains part of the encrypted data, it is difficult to infer the complete session key, thus improving the security of data encryption.
[0042] After the data is encrypted in this solution, the Mersenne Twister algorithm is used to generate a pseudo-random permutation sequence to perform a permutation operation on the encrypted data block, scrambling the order of the data and increasing the confusion degree of the data. At the same time, substitution boxes and replacement boxes are introduced to perform permutation and non-linear substitution on the bit positions of the data block, and the round key is used for exclusive OR operation with the data, further enhancing the diffusion and differential resistance of the data. This multiple confusion processing increases the difficulty for attackers to analyze and crack the encrypted data, improving the anti-attack ability of the encrypted data.
[0043] This solution comprehensively considers the characteristics of structured and unstructured data, uses the SHA256 algorithm to perform hash calculation on structured data, and uses the MD5 algorithm to perform hash calculation on unstructured data to generate the initial vector. This differential processing for different data types can better adapt to the encryption requirements of structured and unstructured data, providing comprehensive data protection.
[0044] This solution selects the efficient symmetric encryption algorithm RC5 and the classic asymmetric encryption algorithm RSA. While ensuring data security, it also considers the performance of encryption and decryption. Using the session key to encrypt data avoids the overhead of frequently using public and private keys to encrypt and decrypt a large amount of data. At the same time, through the optimized confusion processing process and the support of parallel computing, the data processing efficiency is improved, which is suitable for application scenarios with requirements for encryption performance. Brief Description of the Drawings
[0045] This application will be further described in the form of exemplary embodiments, and these exemplary embodiments will be described in detail through the drawings. These embodiments are not restrictive. In these embodiments, the same numbers represent the same structures, where:
[0046] Figure 1 is an exemplary flowchart of an encryption method based on the RSA algorithm shown in some embodiments of this application;
[0047] Figure 2 is an exemplary flowchart of generating a session key shown in some embodiments of this application;
[0048] Figure 3An exemplary flowchart of generating encrypted data according to some embodiments of the present application;
[0049] Figure 4 An exemplary flowchart of generating a pseudo-random permutation sequence according to some embodiments of the present application;
[0050] Figure 5 An exemplary flowchart of generating the final encrypted data according to some embodiments of the present application. Detailed implementation manners
[0051] The methods and systems provided by the embodiments of the present application will be described in detail below with reference to the accompanying drawings.
[0052] Embodiment 1
[0053] Figure 1 An exemplary flowchart of an encryption method based on the RSA algorithm according to some embodiments of the present application, including: collecting data to be encrypted; wherein, the data to be encrypted includes structured data and unstructured data. Using the symmetric block encryption algorithm RC5, with a preset key length and number of encryption rounds, to generate a session key for the data to be encrypted; using a preset RSA public key to encrypt the generated session key; using the symmetric block encryption algorithm RC5 and the encrypted session key to encrypt the data to be encrypted to generate encrypted data; performing M rounds of confusion processing on the encrypted data to obtain the final encrypted data.
[0054] In the encryption method based on the RSA algorithm provided by the present application, it is first necessary to collect the data to be encrypted. The data to be encrypted includes structured data and unstructured data. Structured data is usually organized in a specific format and structure, such as database tables, CSV files, JSON-formatted data, etc. For the collection of structured data, the following methods can be used: Querying data from a relational database: Using SQL statements to query the required data from relational databases such as MySQL, Oracle, and PostgreSQL, and returning the query results in a structured form. Reading structured files: Reading data from structured files such as CSV files, JSON files, and XML files, and parsing the data content according to predefined formats and fields. Receiving structured data streams: Receiving structured data streams transmitted by external systems through network interfaces, message queues, etc., such as JSON-formatted data returned by REST API interfaces.
[0055] Unstructured data refers to data without a predefined format and structure, such as text files, images, audio, video, etc. For the collection of unstructured data, the following methods can be adopted: Reading unstructured files: Read the original binary data or text content from unstructured files such as text files, image files, audio files, video files, etc. Receiving unstructured data streams: Receive unstructured data transmitted by external systems through network interfaces, file uploads, etc., such as uploaded image files, audio files, etc. Collecting real-time unstructured data: Collect images, audio and other unstructured data in real time through devices such as cameras and microphones, and convert them into digital signals for processing. Store the collected structured data and unstructured data into appropriate data structures for subsequent encryption processing. Data structures such as arrays, lists, and dictionaries can be used to store structured data, and data structures such as byte arrays and strings can be used to store unstructured data.
[0056] Figure 2 It is an exemplary flowchart for generating a session key shown in some embodiments of the present application. The generation of the session key is a key step. The session key is used to encrypt the data to be encrypted using the symmetric encryption algorithm RC5. Perform hash calculations on structured data and unstructured data: For structured data to be encrypted, use the SHA256 algorithm for hash calculation. SHA256 is a secure one-way hash function that can map data of any length to a 256-bit hash value. By performing SHA256 hash calculation on the structured data, a 256-bit structured data hash value is obtained.
[0057] For unstructured data to be encrypted, use the MD5 algorithm for hash calculation. MD5 is another commonly used hash function that can map data of any length to a 128-bit hash value. By performing MD5 hash calculation on the unstructured data, a 128-bit unstructured data hash value is obtained.
[0058] Concatenate the hash values to generate an initial vector: Concatenate the structured data hash value and the unstructured data hash value in a preset order to form a 384-bit concatenated hash value. The preset order can be to place the structured data hash value in the front and the unstructured data hash value in the back, or concatenate them in other agreed-upon orders. The 384-bit hash value after concatenation is used as the initial vector for subsequent encryption operations.
[0059] Set the parameters of the RC5 algorithm: Set the key length of the RC5 algorithm to L bits, where L is a positive integer. The key length determines the security strength of the RC5 algorithm. Commonly, lengths such as 128 bits, 192 bits, or 256 bits can be selected. Set the number of encryption rounds of the RC5 algorithm to T, where T is a positive integer. The number of encryption rounds represents the number of iterations in the RC5 algorithm. Increasing the number of encryption rounds can improve the encryption security but also increase the computational overhead. Perform SHA3-384 hash calculation on the initial vector: Use the SHA3-384 algorithm to perform a hash calculation on the generated initial vector. SHA3-384 is a hash function in the SHA-3 family that can map data of any length to a 384-bit hash value. By performing the SHA3-384 hash calculation on the initial vector, a 384-bit SHA3 hash value is obtained. Split the SHA3 hash value into sub-vectors: Split the obtained 384-bit SHA3 hash value into S sub-vectors, denoted as V1 to VS. The splitting method can be to evenly split the SHA3 hash value into S parts, with each part having a length of 384 / S bits. For example, if S = 12, the SHA3 hash value is split into 12 sub-vectors with a length of 32 bits each.
[0060] Generate the sub-keys of the RC5 algorithm: Use the RC5 algorithm with a preset initial key of length L bits and the set number of encryption rounds T as parameters to generate T sub-keys of length L bits, denoted as K1 to KT. The key expansion process of the RC5 algorithm will generate a series of sub-keys based on the initial key and the number of encryption rounds for each round of encryption operation.
[0061] Perform RC5 encryption on the sub-vectors using the sub-keys: For the i-th sub-vector Vi among the obtained S sub-vectors, perform RC5 encryption using the generated i-th sub-key Ki. The RC5 encryption algorithm will perform a series of bit operations and circular shift operations on the sub-vector Vi and the sub-key Ki to obtain an encrypted sub-vector Ci of length L bits. Repeat this process to perform RC5 encryption on each sub-vector Vi using the corresponding sub-key Ki respectively, obtaining S encrypted sub-vectors C1 to CS.
[0062] Perform iterative calculation using the CBC mode: Use the cipher block chaining (CBC) mode with the obtained S encrypted sub-vectors C1 to CS as inputs for iterative calculation. In the CBC mode, each encrypted sub-vector will perform an exclusive OR operation with the result of the previous encrypted sub-vector and then perform the next round of encryption operation. Through iterative calculation, S feedback encrypted sub-vectors C'1 to C'S of length L bits are obtained.
[0063] Concatenate the feedback encryption sub-vectors to generate the session key: Concatenate the obtained S feedback encryption sub-vectors C'1 to C'S in sequence to obtain a session key with a length of 384 bits. The concatenation order is the same as the generation order of the feedback encryption sub-vectors to ensure the correctness of the session key. By encrypting the session key with RSA, the confidentiality and integrity of the session key can be ensured. Preset the RSA public and private key pair: Before the start of the encryption process, generate a pair of RSA public and private keys in advance. The RSA public key is used to encrypt the session key, and the corresponding RSA private key is used to decrypt the encrypted session key.
[0064] The generation of the RSA public and private keys can be achieved through the following steps: Select two large prime numbers p and q, and calculate their product n = p * q, where n is called the RSA modulus. Calculate the Euler's totient function value of n, φ(n) = (p - 1) * (q - 1). Select an integer e that is relatively prime to φ(n) as the public key exponent, usually 65537. Calculate the modular multiplicative inverse d of e with respect to φ(n) such that (e * d) mod φ(n) = 1, and d is used as the private key exponent. The RSA public key is (n, e), and the RSA private key is (n, d).
[0065] Encrypt the session key with the RSA public key: Use the generated 384-bit session key as the plaintext data to be encrypted. Encrypt the session key with the preset RSA public key (n, e) to obtain the encrypted session key. The specific process of RSA encryption is as follows: Represent the session key as an integer m less than the RSA modulus n. Calculate the encrypted session key c using the formula: c = m^e mod n, where ^ represents modular exponentiation. The obtained c is the encrypted session key, which is an integer of the same length as the RSA modulus n. Encode and format the encrypted session key: Since the encrypted session key is a large integer, for convenient transmission and storage, it needs to be encoded and formatted. Commonly used encoding methods include Base64 encoding, hexadecimal encoding, etc., which can convert the encrypted session key into a readable string format. The encoded encrypted session key can be stored or transmitted as a string for subsequent decryption and use.
[0066] Figure 3An exemplary flowchart of generating encrypted data according to some embodiments of the present application. Securely transmit the encrypted session key: The encrypted session key needs to be transmitted to the recipient through a secure communication channel so that the recipient can decrypt it using the corresponding RSA private key. Secure communication protocols such as SSL / TLS can be used to perform secondary encryption on the encrypted session key during the transmission process to ensure that it cannot be obtained by unauthorized third parties. Measures should also be taken during the transmission process to prevent tampering and replay attacks to ensure the integrity and authenticity of the encrypted session key. Use the symmetric block encryption algorithm RC5 and the encrypted session key to encrypt the data to be encrypted and generate encrypted data: Store the data in blocks: Divide the data to be encrypted into N blocks, where N is an integer greater than 1, representing the number of data blocks. Store the divided data in a buffer, which can be a continuous space in memory or other data structures suitable for storing data blocks. The size of each data block can be set according to actual needs and the requirements of the encryption algorithm, usually choosing a block size that matches the block size of the encryption algorithm.
[0067] Figure 4 An exemplary flowchart of generating a pseudo-random exchange sequence according to some embodiments of the present application. Use the Mersenne Twister algorithm to generate a pseudo-random exchange sequence. Initialize the internal state of the Mersenne Twister algorithm: The internal state includes two parts: a seed value and a state vector. The seed value is used to initialize the state vector, and the current timestamp, a random number, or other entropy sources can be used as the seed value. The state vector is an integer array with a length of 624 and is used to generate a pseudo-random number sequence. Pass the seed value to the Mersenne Twister algorithm and initialize the values of the state vector according to the seed value. Use a key derivation function based on a hash function to generate the seed value: Use the generated session key as input and calculate the hash value through a hash function (such as SHA-256). Use the calculated hash value as the initial seed value of the Mersenne Twister algorithm. Using a key derivation function can enhance the randomness and security of the seed value and prevent the seed value from being predicted or guessed.
[0068] Generate a new state vector according to the internal state: Use a linear feedback shift register (LFSR) to perform a shift operation on the current state vector. The LFSR generates a new state vector by performing an exclusive OR operation on certain bits of the state vector. The Mersenne Twister algorithm uses a specific LFSR structure called the Mersenne Prime LFSR. The feedback polynomial of the LFSR uses the characteristics of Mersenne primes and can generate a pseudo-random sequence with a long period. Perform bit operations such as bit shift and exclusive OR on the generated new state vector to further mix the bits of the state vector.
[0069] Generate a candidate swap index: Perform a modulo N operation on the newly generated state vector to obtain a random integer ranging from 1 to N. The modulo N operation ensures that the generated random integer falls within the legal swap index range. Use the generated random integer as the candidate swap index for subsequent duplicate checks. Determine if the candidate swap index is a duplicate: Use a hash table to determine if the candidate swap index is a duplicate of the previously generated swap indices. Look up the candidate swap index as the key in the hash table. If the same key exists in the hash table, it means the candidate swap index is a duplicate and a new candidate swap index needs to be generated. If the same key does not exist in the hash table, it means the candidate swap index is valid and can be used as the final swap index.
[0070] Update the pseudo-random swap sequence and the hash table: Add the valid swap index to the pseudo-random swap sequence as part of the sequence. At the same time, insert the valid swap index as the key into the hash table for subsequent duplicate checks. The hash table is updated using the head-insertion method, inserting the new key at the head of the linked list to improve the lookup efficiency.
[0071] Update the internal state of the Mersenne Twister algorithm: Obtain the current timestamp as an additional entropy source. Perform an exclusive OR operation on the current timestamp and the newly generated state vector to obtain the final state vector. Use the final state vector as the new internal state of the Mersenne Twister algorithm for the next generation of pseudo-random numbers. By introducing the timestamp, the unpredictability and randomness of the pseudo-random number sequence can be increased. Repeat until N valid swap indices are generated. Each time a new candidate swap index is generated, a duplicate check is performed to ensure that the generated swap index is not a duplicate. When the number of valid swap indices generated reaches N, stop the generation process to obtain the complete pseudo-random swap sequence. A pseudo-random swap sequence containing N swap indices is generated using the Mersenne Twister algorithm. The Mersenne Twister algorithm has good statistical properties and a long period, and can generate high-quality pseudo-random number sequences. By introducing the session key as the seed value and combining it with a hash function for key derivation, the randomness and security of the seed value are enhanced. At the same time, a hash table is used for duplicate checks to ensure that the generated swap indices are not duplicates, guaranteeing the validity of the pseudo-random swap sequence. Finally, by introducing the timestamp to update the internal state, the unpredictability of the pseudo-random number sequence is further increased.
[0072] The exchange of data blocks is guided by a pseudo-random exchange sequence, achieving the obfuscation and rearrangement of the positions of encrypted data. Obtain the first exchange index from the generated pseudo-random exchange sequence, which represents the positions of the first pair of data blocks to be exchanged. According to the exchange index, obtain two data blocks at the corresponding positions from the buffer storing the encrypted data blocks, and label them as data block blockA and data block blockB respectively. The buffer can be a continuous space in memory, and the data blocks are stored in the buffer in a continuous manner. The exchange index serves as the offset of the data block in the buffer, and through the offset, the corresponding data block can be quickly located and accessed. Save the obtained data blocks blockA and blockB in temporary variables for subsequent exchange operations. Exchange the storage positions of data block blockA and data block blockB in the buffer to achieve the position swap of the data blocks.
[0073] The exchange operation can be implemented in the following two ways: Pointer exchange: If the data block is accessed through a pointer or reference, the pointers pointing to the data block can be simply exchanged without moving the actual data. Data exchange: If the data block is directly stored in the buffer, the position exchange needs to be achieved by exchanging the content of the data block. A temporary variable can be used to store the content of one of the data blocks, then copy the content of the other data block to this position, and finally copy the content in the temporary variable to the position of the other data block. After the exchange operation is completed, the positions of data block blockA and data block blockB in the buffer are swapped, achieving the obfuscation of the positions. Obtain the next exchange index in the pseudo-random exchange sequence, and repeat the operation of exchanging the storage positions. According to the index order in the pseudo-random exchange sequence, exchange the data blocks at the corresponding positions in turn until all the data blocks are exchanged. The specific steps are as follows: Initialize a loop variable i, representing the current exchange index position, with an initial value of 0. Obtain the next exchange index index from the pseudo-random exchange sequence. According to the exchange index index, obtain two data blocks blockA and blockB at the corresponding positions from the buffer. Exchange the storage positions of blockA and blockB in the buffer, which can be achieved by pointer exchange or data exchange. Increment the loop variable i, indicating moving to the next exchange index position. Repeat until the loop variable i reaches the length N of the pseudo-random exchange sequence, that is, all the data blocks are exchanged. Through the repeated exchange process, according to the order of the pseudo-random exchange sequence, the positions of the encrypted data blocks are obfuscated and rearranged, increasing the randomness and unpredictability of the data. After all the data blocks are exchanged, output N encrypted data blocks from the buffer in the exchanged order as the generated encrypted data.
[0074] Figure 5It is an exemplary flowchart for generating final encrypted data as shown in some embodiments of the present application. During the process of performing M rounds of confusion processing on the encrypted data, by introducing substitution boxes, replacement boxes, and round keys, the encrypted data undergoes multiple rounds of permutation, replacement, and XOR operations, enhancing the randomness and unpredictability of the encrypted data to obtain the final encrypted data: Presetting substitution boxes and replacement boxes: A substitution box is an array of a fixed size used to perform permutation operations on the bit positions of a data block. The size of the substitution box is the same as the size of the data block, and each element represents the position of the bit after permutation. A replacement box is a lookup table of a fixed size used to perform non-linear replacement on the bit positions of a data block. The size of the replacement box is usually 256 bytes, and each element represents the byte value after replacement. The substitution box and the replacement box can be generated by random generation or key-derived methods to increase the randomness and security of the confusion processing.
[0075] Use the generated substitution box and replacement box as parameters for the confusion processing to guide the permutation and replacement operations of the data block.
[0076] When performing permutation operations on the encrypted data, it is necessary to divide the encrypted data into multiple sub-blocks and rearrange the bit positions within each sub-block according to the preset substitution box. Division of data blocks: Determine the size of the substitution box. Assume the size of the substitution box is n bits. Divide the encrypted data into multiple sub-blocks of size n bits. If the length of the encrypted data is not an integer multiple of n, padding can be performed at the end of the last sub-block. The padding bits can use fixed values or random values. The number of sub-blocks after division is the length of the encrypted data divided by n, rounded up. Rearrangement of bit positions within a sub-block: For each sub-block, rearrange the bit positions within the sub-block according to the positions preset in the substitution box. The specific steps are as follows: Initialize a temporary array of the same size as the sub-block to store the permuted sub-block. The size of the temporary array is n bits, which is the same as the size of the sub-block. Each element of the temporary array is initialized to 0. Traverse each bit position of the sub-block and place the bit at the corresponding position in the temporary array according to the value at the corresponding position in the substitution box. The substitution box is an array of size n, where each element represents the position of the bit after permutation. For the i-th bit position of the sub-block (starting from i = 0), find the value j at index i in the substitution box. Place the value of the i-th bit position of the sub-block at the j-th position in the temporary array. Combine the bit positions in the temporary array in the permuted order to obtain the permuted sub-block. The size of the permuted sub-block is the same as the size of the original sub-block, both being n bits. The order of the bit positions in the permuted sub-block is the same as the order of the bit positions in the temporary array.
[0077] Combination of the permuted sub - blocks: Combine the permuted sub - blocks in the order before permutation to obtain the permuted encrypted data. The combination process is to concatenate the permuted sub - blocks in sequence to form a complete encrypted data. The concatenation order is the same as the sub - block division order, that is, the first permuted sub - block corresponds to the first sub - block of the original encrypted data, and so on. The length of the permuted encrypted data is the same as the length of the original encrypted data. Through the above steps, a permutation operation is performed on the encrypted data. The encrypted data is divided into multiple sub - blocks, and the bit positions within each sub - block are rearranged according to a preset substitution box. Finally, the permuted encrypted data is obtained. The design of the substitution box needs to meet certain security requirements to avoid weak keys or predictable permutation patterns. The substitution box can be generated by random generation or key - derived methods to increase the randomness and security of the permutation operation. At the same time, during implementation, it is necessary to ensure that the size of the substitution box is consistent with the size of the sub - block to avoid security vulnerabilities caused by data truncation or padding.
[0078] When performing a substitution operation on the permuted encrypted data, the encrypted data needs to be divided into multiple sub - blocks, and a pre - constructed byte substitution table is used to substitute the bytes within each sub - block. The permuted encrypted data is divided into multiple sub - blocks, and the size of each sub - block is the same as the input size of the substitution box (usually 1 byte). If the length of the encrypted data is not an integer multiple of the input size of the substitution box, padding can be performed at the end of the last sub - block. The padding byte can be a fixed value or a random value. The number of divided sub - blocks is the ceiling of the length of the encrypted data divided by the input size of the substitution box.
[0079] Construction of the byte substitution table: Construct a 256 - byte byte substitution table as the storage structure of the substitution box. The index range of the byte substitution table is from 0 to 255, corresponding to all possible byte values. Each element in the table is a byte used to store the substituted byte value. The byte substitution table can be generated by random generation or key - derived methods to increase the randomness and security of the substitution operation. Substitution of bytes within a sub - block: For each divided sub - block, each byte within the sub - block is used as the index of the byte substitution table. The specific steps are as follows: Traverse each byte within the sub - block. Use the value of the current byte as the index of the byte substitution table. In the byte substitution table, find the element at the corresponding position according to the index value to obtain the substituted byte value. Replace the current byte within the sub - block with the corresponding substituted byte found in the byte substitution table. The size of the substituted sub - block is the same as the size of the original sub - block, both being the input size of the substitution box (usually 1 byte).
[0080] Concatenation of the replaced sub-blocks: Concatenate all the obtained replaced sub-blocks in the order before partitioning as the replaced encrypted data. The concatenation process is to sequentially connect the replaced sub-blocks to form a complete encrypted data. The concatenation order is the same as the sub-block partitioning order, that is, the first replaced sub-block corresponds to the first sub-block of the original encrypted data, and so on. The length of the replaced encrypted data is the same as the length of the permuted encrypted data. Through the above steps, a replacement operation is performed on the permuted encrypted data. The encrypted data is divided into multiple sub-blocks, and the bytes within each sub-block are replaced using a pre-constructed byte substitution table, finally obtaining the replaced encrypted data. The design of the byte substitution table needs to meet certain security requirements to avoid the emergence of weak keys or predictable substitution patterns. The byte substitution table can be generated by random generation or key-derived methods to increase the randomness and security of the replacement operation. At the same time, during implementation, it is necessary to ensure that the size of the byte substitution table is 256 bytes, covering all possible byte values, and the replaced byte values should be randomly distributed to enhance the non-linear characteristics of the replacement operation.
[0081] When performing confusion processing on the replaced encrypted data, multiple round keys need to be generated, and the encrypted data of each round is bitwise XORed with the corresponding round key. Generation of round keys: Adopt a key scheduling scheme, using the generated session key as input to derive M round keys. The length of each round key is the same as the length of the replaced encrypted data to ensure that it can be bitwise XORed with the encrypted data.
[0082] The key scheduling scheme can use the following methods: Hash function: Use the session key and round number as input, and generate the round key through a hash function (such as SHA-256). The session key and round number can be concatenated, and then the concatenated data is hashed to obtain a fixed-length hash value. Truncate or extend the hash value to the same length as the encrypted data as the round key for this round. Pseudo-random number generator (PRNG): Use the session key as the seed and generate a series of random numbers through the pseudo-random number generator. A secure pseudo-random number generation algorithm such as CTR-DRBG or HMAC-DRBG can be used. Truncate or extend the generated random numbers to the same length as the encrypted data as the round key. Other key derivation functions: Use specialized key derivation functions such as HKDF (HMAC-based Key Derivation Function) or PBKDF2 (Password-Based Key Derivation Function2). Use the session key as input and generate key material of the required length through the key derivation function. Divide the key material into M equal-length parts as the round keys.
[0083] XOR operation: For the i-th round of confusion processing, perform a bitwise XOR operation on the replaced encrypted data and the i-th round key to obtain the XORed encrypted data. The XOR operation can be achieved by performing XOR operations on the corresponding bit positions of the encrypted data and the round key. The specific steps are as follows: Align the replaced encrypted data and the i-th round key bit by bit; perform XOR operations on each corresponding bit position of the encrypted data and the round key. The result of the XOR operation is used as the output of this round of confusion processing, that is, the XORed encrypted data. The XOR operation has the following properties: The XOR operation is reversible, that is, performing the XOR operation again on the XORed result can restore the original data. The XOR operation can introduce randomness and confusion effects, making the encrypted data more difficult to predict and analyze. Multiple rounds of confusion processing: Use the XORed encrypted data as the input for the next round of confusion processing, and repeat the M rounds of confusion processing. In each round of confusion processing, use a different round key to perform the XOR operation with the encrypted data.
[0084] After M rounds of confusion processing, the final encrypted data is obtained. The XOR operation is a simple and effective way of confusion. By performing a bitwise XOR on the encrypted data and the round key, it introduces randomness and confusion effects, making it difficult for attackers to directly analyze and crack the encrypted data. The iterative process of multiple rounds of confusion processing further enhances the security of the encrypted data. Using different round keys for XOR operations in each round causes the encrypted data to change in each round, increasing the difficulty of cracking.
[0085] Example 2
[0086] For a certain privacy data encryption, collect the financial privacy data to be encrypted:
[0087] Structured customer information: Name "XXXX", ID number "XXXX", bank card number "XXXX"
[0088] Unstructured transaction record text: "XXXX paid 1,234.56 through bank card XXXX123456 at 21:30 on May 10, 2023"
[0089] Generate a session key: Perform SHA256 hashing on the structured customer information "XXXXXXXXXXXX123456" to obtain a 256-bit hash value:
[0090] a4b8c9d0e1f2g3h4i5j6k7l8m9n0opqrstuvwxyz0XXXXABCDEFGHIJKLM.
[0091] Perform MD5 hashing on the unstructured transaction record text to obtain a 128-bit hash value:
[0092] a1b2c3d4e5f6g7h8i9j0klmnopqrstu; Concatenate the hash values to obtain a 384-bit initial vector:
[0093] a4b8c9d0e1f2g3h4i5j6k7l8m9n0opqrstuvwxyz0XXXXABCDEFGHIJKLMa1b2c3d4e5f6g7h8i9j0klmnopqrstu. Assume the RC5 key length is 256 bits and encrypt for 12 rounds. Hash the above 384-bit initial vector using SHA3-384 to obtain:
[0094] ABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789abcdefghijklmnopqrstuvwxyz0011223344556677889900AABBCCDDEEFF. Divide the SHA3 hash value into 3 128-bit sub-vectors: V1: ABCDEFGHIJKLMNOPQRSTUVWXYZ01234567; V2:
[0095] 89abcdefghijklmnopqrstuvwxyz001122; V3: 3344556677889900AABBCCDDEEFF; Encrypt for 12 rounds using the 256-bit initial key K0 to generate 12 256-bit sub-keys K1 to K12; Perform RC5 encryption on V1, V2, and V3 using K1, K2, and K3 respectively to obtain: C1: a0a1a2a3a4a5a6a7a8a9aaabacadaeaf; C2: b0b1b2b3b4b5b6b7b8b9babbbcbdbebf; C3: c0c1c2c3c4c5c6c7c8c9cacbcccdcecf.
[0096] Link C1 to C3 using the CBC mode: Let the IV be a 256-bit initial vector of all 0s. XOR the IV with V1 to obtain C'0: ABCDEFGHIJKLMNOPQRSTUVWXYZ01234567. XOR C1 with C'0 to obtain R1: 0b0c0d0e0f0g0h0i0j0k0l0m0n0o0p0q. Encrypt R1 using K1 to obtain E1, and XOR E1 with V1 to obtain C'1:
[0097] 34343434343434343434343434343434. XOR C2 with C'1 to obtain R2:
[0098] bdbdbdbdbdbdbdbdbdbdbdbdbdbdbdbd, Encrypt R2 using K2 to obtain E2, and XOR E2 with V2 to obtain C'2:
[0099] 78787878787878787878787878787878. Exclusive OR of C3 and C'2 gives R3:
[0100] b8b9babbbcbdbebfb0b1b2b3b4b5b6b7, encrypt R3 with K3 to get E3, exclusive OR of E3 and V3 gives C'3: cdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcd.
[0101] Concatenate C'1, C'2, and C'3 to obtain a 384-bit session key:
[0102] 343434343434343434343434343434347878787878787878787878787878787878cdcdc dcdcdcdcdcdcdcdcdcdcdcdcdcd. Encrypt the session key with a 3072-bit RSA public key to obtain the encrypted session key, and perform RC5 block encryption on the financial privacy data: Plaintext data block: "XXXXXXXXXXXX12345678$1,234.562023-05-1021:30". Use the session key as the key and encrypt it in CBC mode with the RC5 algorithm to obtain the ciphertext data block:
[0103] a68qw9ertyu5iop34asdf2gh78jk12l3zx4cv6bn5m1qaz7ws8xedc9rfv4tgb65hy78uj90mki87ol6p54hy3jn21qw0ms9xd7cv4fr3gt6yh. Perform 3 rounds of confusion processing on the ciphertext data block: Block: The size of the ciphertext data block is 96 bytes, divided into 1 block B1. Initialize MT19937 with the session key seed to generate a pseudo-random exchange sequence {1}, without duplicate removal. Since there is only 1 data block, no exchange is required, and output B1 as the exchanged ciphertext; Rearrange the bit positions within B1 using a 128-byte permutation box P to obtain the permuted data block B1'; Replace each byte in B1' with a 256-byte substitution box S to obtain the substituted data block B1''; Derive 3 128-byte round keys RK1, RK2, and RK3 from the session key; Exclusive OR the round keys RK1, RK2, and RK3 with B1'' respectively to complete 3 rounds of confusion and obtain the final ciphertext.
[0104] k86rq0ertyu2iop31asdf5gh46jk80l7zx9cv1bn2m4qaz8ws0xedc3rfv7tgb12hy45uj67mki09ol3p21hy8jn54qw7ms6xd0cv9fr8gt1yh. Output the final ciphertext data after 3 rounds of confusion.
Claims
1. An encryption method based on the RSA algorithm, comprising: Collecting data to be encrypted; wherein the data to be encrypted includes structured data and unstructured data; Using the symmetric block encryption algorithm RC5 with a preset key length and number of encryption rounds to generate a session key for the data to be encrypted; Encrypting the generated session key using a preset RSA public key; Using the symmetric block encryption algorithm RC5 and the encrypted session key to encrypt the data to be encrypted, generating encrypted data; Performing M rounds of confusion processing on the encrypted data to obtain the final encrypted data; Generating encrypted data, including: using the MersenneTwister algorithm to generate a pseudo-random exchange sequence containing N exchange indices; wherein the exchange index is a positive integer between 1 and N, used to indicate the position of a data block in the buffer; using the MersenneTwister algorithm to generate a pseudo-random exchange sequence containing N exchange indices, including: Initializing the internal state of the MersenneTwister algorithm, where the internal state includes a seed value and a state vector; using a key derivation function based on a hash function, taking the generated session key as input, deriving a seed value, and setting the seed value as the initial seed value of the MersenneTwister algorithm; According to the internal state of the MersenneTwister algorithm, using a linear feedback shift register and bit operations to generate a new state vector; wherein the linear feedback shift register performs a shift operation on the current state vector and performs an exclusive OR operation with a preset feedback polynomial to update the state vector; the bit operations perform bit operations on the updated state vector to mix the bits of the state vector; Performing a modulo N operation on the generated new state vector to obtain a random integer in the range of 1 to N, which is used as a candidate exchange index in the pseudo-random exchange sequence; Using a hash table to determine whether the generated candidate exchange index is repeated with the previously generated exchange index; performing a hash operation with the candidate exchange index as the key, and looking up the corresponding key-value pair in the hash table. If found, it means the candidate exchange index is repeated, and return to regenerate the candidate exchange index. Otherwise, use the generated candidate exchange index as a valid exchange index; Adding the obtained valid exchange index to the pseudo-random exchange sequence, inserting the valid exchange index as the key into the hash table, and updating the content of the hash table; obtaining the current timestamp, performing an exclusive OR operation with the generated new state vector to obtain the final state vector, and using the final state vector as the new internal state of the MersenneTwister algorithm; Determining whether the number of exchange indices in the pseudo-random exchange sequence reaches N. If it reaches N, output the pseudo-random exchange sequence containing N exchange indices. Otherwise, repeat the step of generating valid exchange indices until N valid exchange indices are generated.
2. The encryption method based on the RSA algorithm according to claim 1, characterized in that: Generating a session key, including: Performing a hash calculation on the structured data to be encrypted using the SHA256 algorithm to obtain a 256-bit structured data hash value; The MD5 algorithm is used to perform a hash calculation on the unstructured data to be encrypted, obtaining an unstructured data hash value with a length of 128 bits; The structured data hash value and the unstructured data hash value are concatenated in a preset order to obtain a concatenated hash value with a length of 384 bits, which is used as the initial vector; Set the key length of the RC5 algorithm to L bits and the number of encryption rounds to T; where L and T are positive integers; The SHA3-384 algorithm is used to perform a hash calculation on the initial vector, obtaining a SHA3 hash value with a length of 384 bits.
3. The encryption method based on the RSA algorithm according to claim 2, wherein: Generating a session key further includes: Divide the SHA3 hash value into S sub-vectors, denoted as to ; For the i-th sub-vector among the obtained S sub-vectors , the i-th sub-key generated is used for RC5 encryption to obtain an encrypted sub-vector of length L bits ; where i is an integer from 1 to S; Using the Cipher Block Chaining (CBC) mode, with S encrypted sub-vectors to as inputs, perform iterative calculations to obtain S feedback encrypted sub-vectors of length L bits to ; Encrypt the obtained S feedback sub-vectors to perform concatenation to obtain a session key of 384 bits in length.
4. The encryption method based on the RSA algorithm according to claim 3, wherein: Using the CBC mode, S feedback encryption sub-vectors each of length L bits are obtained to , including: XOR the first sub-vector with a preset initial vector IV to obtain an XOR result as the initial value of the feedback encryption sub-vector ; where the length of the initial vector IV is L bits; The i-th encrypted sub-vector is bitwise XORed with the feedback encrypted sub-vector obtained in the previous iteration to obtain an XOR result of length L bits ; Use the generated i-th sub-key as the key to perform RC5 encryption operation on the obtained XOR result to obtain an encrypted result with a length of L bits ; The encrypted result is bitwise XORed with the i-th subvector Vi to obtain a feedback encrypted subvector of length L bits ; Repeat the above iterative process to obtain S feedback encrypted sub-vectors in sequence to .
5. The encryption method based on the RSA algorithm according to any one of claims 2 to 4, wherein: Generating encrypted data includes: The encrypted data obtained by encrypting the data to be encrypted using the symmetric block encryption algorithm RC5 and the encrypted session key is divided into N blocks and stored in a buffer, where N is an integer greater than 1; Obtain the first swap index in the generated pseudo-random swap sequence, and according to the first swap index, obtain two data blocks at the corresponding positions from the buffer storing the encrypted data blocks, and mark them as data block blockA and data block blockB respectively; Swap the storage positions of data block blockA and data block blockB in the buffer; Obtain the next swap index in the pseudo-random swap sequence, and repeat the operation of swapping the storage positions until all data blocks are completed; Output N blocks of encrypted data from the buffer in the swapped order as the generated encrypted data.
6. The encryption method based on the RSA algorithm according to claim 1, wherein: The hash table is constructed and updated using the following steps: Initialize a hash table with a size of N, and the hash function is taking the remainder modulo N; Use the generated valid swap index as the key and insert it into the corresponding bucket in the hash table. The key is added to the head of the linked list using the head interpolation method; When judging whether the candidate swap index is repeated, use the candidate swap index as the key, calculate the hash value, and check whether there is the same key in the linked list in the corresponding bucket. If it exists, it means it is repeated, otherwise it is not repeated.
7. The encryption method based on the RSA algorithm according to claim 1, wherein: Performing M rounds of confusion processing on the encrypted data to obtain the final encrypted data, including: Preset a set of substitution boxes and replacement boxes with a fixed size. The substitution boxes are used to perform permutation operations on the bit positions of the data blocks, and the replacement boxes are used to perform non-linear replacements on the bit positions of the data blocks; the generated substitution boxes and replacement boxes are used as parameters for the confusion processing; Use the generated encrypted data as the input. The encrypted data consists of N data blocks; the encrypted data is divided into multiple sub-blocks, and the size of each sub-block is the same as the size of the substitution box; For each sub-block, rearrange the bit positions within the sub-block according to the positions preset by the substitution box to obtain the permuted sub-block; Combine the replaced sub-blocks in the order before permutation to obtain the permuted encrypted data.
8. The encryption method based on the RSA algorithm according to claim 7, characterized in that: Performing M rounds of confusion processing on the encrypted data to obtain the final encrypted data, further comprising: Dividing the encrypted data after permutation into multiple sub-blocks, and the size of each sub-block is the same as the input size of the substitution box; Constructing a byte substitution table of 256 bytes as the storage structure of the substitution box, the index range of the byte substitution table is from 0 to 255, and each element in the table is a byte for storing the substituted byte value; For each sub-block obtained by division, using each byte in the sub-block as the index of the byte substitution table; In the byte substitution table, according to the value of each byte in the sub-block, looking up the element at the corresponding index position in the table to obtain the substituted byte value; Replacing each byte in the sub-block with the corresponding substituted byte found in the byte substitution table to obtain the substituted sub-block; Sequentially concatenating all the obtained substituted sub-blocks in the order before division as the encrypted data after substitution.
9. The encryption method based on the RSA algorithm according to claim 8, characterized in that: Performing M rounds of confusion processing on the encrypted data to obtain the final encrypted data, further comprising: Adopting a key scheduling scheme, using the generated session key as the input to derive M round keys, and the length of each round key is the same as the length of the encrypted data after substitution; For the i-th round of confusion processing, performing a bitwise exclusive OR operation on the encrypted data after substitution and the i-th round key to obtain the encrypted data after exclusive OR; where i is an integer from 1 to M; Using the encrypted data after exclusive OR as the input for the next round of confusion processing, and repeating the M rounds of confusion processing to obtain the final encrypted data.
Citation Information
Patent Citations
Data acquisition method and system based on RSA asymmetric encryption
CN116506230B
Hybrid encryption method and system, hybrid decryption method and system, equipment and storage medium
CN112989391A
Data processing method and device, server and medium
CN118827186A