Encryption Method and System Based on Symmetric Cryptography Algorithm
The symmetric cryptographic algorithm classifies and encrypts structured and unstructured sensitive data to generate high-security encryption keys, solving the problem of insufficient key security in the prior art and achieving effective protection of sensitive data.
Patent Information
- Application Number
- CN202510097390.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-22
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2045-01-22
AI Technical Summary
When processing structured sensitive data, existing data encryption technologies lack optimization for data characteristics, resulting in insufficient key security to effectively protect sensitive data.
The encryption method based on symmetric cryptography algorithm is adopted to classify structured sensitive data, select key numerical fields for Fermatophane properties to filter large prime numbers as basic key elements, and generate encryption keys based on preset key combination rules. The hash function is used for unstructured sensitive data to generate hash encryption keys, and simulated desensitized data is generated after integration.
By optimizing and processing based on the characteristics of structured and unstructured sensitive data, high-security encryption keys are generated to effectively protect sensitive data, and the security and privacy of data are improved.
Smart Images

Figure CN119538312B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data processing, and particularly relates to an encryption method and system based on a symmetric cryptography algorithm. Background Art
[0002] During the processes of data collection, storage, transmission, and processing, sensitive data faces the risk of leakage. In many industrial fields, a large amount of sensitive data is stored and processed, including customers' personal identity information, financial data, medical records, etc. Once the above data is leaked, it will not only seriously violate personal privacy but also may cause huge economic losses to enterprises.
[0003] Although existing data encryption technologies can protect data security to a certain extent, when traditional encryption algorithms process structured sensitive data, they often adopt a general key generation method, lacking optimization for data characteristics, resulting in insufficient security of the key. Summary of the Invention
[0004] The main objective of the present invention is to provide an encryption method and system based on a symmetric cryptography algorithm, aiming to overcome the defect that the generated key has insufficient security.
[0005] To achieve the above objective, the present invention provides an encryption method based on a symmetric cryptography algorithm, including the following steps:
[0006] Classify the obtained sensitive data to obtain structured sensitive data and unstructured sensitive data;
[0007] Select the key numerical fields in the structured sensitive data, input them into a preset Fermat primality test algorithm, screen out large prime numbers as basic key elements, and generate an encryption key by combining the basic key elements with a preset key combination rule; wherein, the preset Fermat primality test algorithm pre-optimizes the iteration times and screening range of prime number determination;
[0008] Adopt a symmetric cryptography algorithm to encrypt the structured sensitive data based on the encryption key to obtain encrypted structured data;
[0009] Encrypt the unstructured sensitive data to obtain encrypted unstructured data;
[0010] Integrate the encrypted structured data and the encrypted unstructured data to generate simulated desensitized data.
[0011] Further, after generating the simulated desensitized data, it includes:
[0012] Evaluate the simulated de - sensitized data against a preset de - sensitized data standard to obtain an evaluation result. If the evaluation result does not meet the requirements, re - optimize the iteration times and screening range of the Fermat primality test algorithm for prime number determination.
[0013] Further, encrypt the unstructured sensitive data to obtain encrypted unstructured data, including:
[0014] For the unstructured sensitive data, generate a hash encryption key using a hash function;
[0015] Use a symmetric cryptography algorithm to encrypt the unstructured sensitive data based on the hash encryption key to obtain encrypted unstructured data.
[0016] Further, select the key numerical fields in the structured sensitive data and input them into a preset Fermat primality test algorithm to screen out large prime numbers as basic key elements, including:
[0017] Perform data analysis on the structured sensitive data to extract numerical fields with key identifiers as the key numerical fields;
[0018] Divide the key numerical fields into multiple numerical sub - segments, and each numerical sub - segment participates in the Fermat primality test algorithm as an independent input;
[0019] For each numerical sub - segment, when performing the Fermat primality test, set an initial base value range, and use the modular exponentiation algorithm to perform Fermat primality test calculations by changing the base multiple times;
[0020] When the numerical sub - segment shows a preset prime number possibility in multiple Fermat primality tests, mark it as a large prime number candidate, calculate the relationship between the large prime number candidate and other known prime numbers, and determine the true large prime number according to the relationship, and exclude pseudo - prime numbers;
[0021] Store the true large prime numbers as basic key elements in a secure key buffer, and perform unique identification and indexing.
[0022] Further, the step of generating an encryption key by combining the basic key elements with a preset key combination rule includes:
[0023] Use an encryption transformation based on lattice cryptography theory to map each of the basic key elements to a high - dimensional vector in a high - dimensional lattice space;
[0024] Introduce the entanglement state characteristic of quantum bits to perform quantum state encoding on each of the high - dimensional vectors to obtain key element encodings;
[0025] Combine each of the key element encodings to obtain the encryption key.
[0026] Further, the step of generating an encryption key by combining the basic key elements with a preset key combination rule includes:
[0027] Performing a first fast hashing on each of the basic key elements based on a lightweight hash function to obtain a preliminary hash value; wherein, the hash seed is generated according to the current running state information of the system;
[0028] Performing a second hashing on the preliminary hash value based on the Blake2b hash function to obtain an element value after deep confusion;
[0029] Dynamically determining the bit rotation direction and number of steps according to the current system clock cycle, and rearranging the binary bits of the confused element value to obtain a rearranged element value;
[0030] Constructing a finite field multiplication operation based on a primitive polynomial, and expanding the rearranged element value within the finite field to obtain an expanded element value; wherein, the coefficients of the primitive polynomial are dynamically selected according to the sensitivity level of the data to be encrypted;
[0031] Combining the expanded element values in sequence to form the encryption key.
[0032] Further, for the unstructured sensitive data, generating a hash encryption key by using a hash function includes:
[0033] Performing a hash calculation on the unstructured sensitive data based on a hash function to obtain a hash value, and using each character in the hash value as a basic element of a matrix to construct a two-dimensional matrix;
[0034] Extracting the sentence structure feature vector, low-frequency feature vector, and feature vector of the key frequency band of the unstructured sensitive data; the unstructured sensitive data includes text, image, and audio data;
[0035] Mapping the sentence structure feature vector, low-frequency feature vector, and feature vector of the key frequency band into a three-dimensional space respectively, and constructing a triangular mesh surface through a triangulation algorithm according to the similarity and relevance between the feature vectors;
[0036] Generating the hash encryption key based on the triangular mesh surface and the two-dimensional matrix.
[0037] Further, generating the hash encryption key based on the triangular mesh surface and the two-dimensional matrix includes:
[0038] Quantifying the vertex coordinate values of each triangular face of the triangular mesh surface, and establishing a mapping relationship with the elements at preset positions in the two-dimensional matrix;
[0039] Based on the matrix element values mapped by the vertex coordinates of each triangular face, bilinear interpolation is used to calculate the corresponding values for any point within the triangular face, and a numerical matrix is combined to obtain a numerical matrix;
[0040] Perform singular value decomposition on the numerical matrix, extract the singular values therein, and recombine the singular values to obtain recombined singular values;
[0041] Perform a hash operation on the recombined singular values to generate the hash encryption key.
[0042] The present invention also provides an encryption system based on a symmetric cryptography algorithm, including:
[0043] A classification module for classifying the obtained sensitive data to obtain structured sensitive data and unstructured sensitive data;
[0044] A generation module for selecting key numerical fields from the structured sensitive data, inputting them into a preset Fermat primality test algorithm, screening out large prime numbers as basic key elements, and generating an encryption key by combining the basic key elements with a preset key combination rule; wherein, the preset Fermat primality test algorithm pre-optimizes the number of iterations and screening range for prime number determination;
[0045] A first encryption module for encrypting the structured sensitive data based on the encryption key using a symmetric cryptography algorithm to obtain encrypted structured data;
[0046] A second encryption module for encrypting the unstructured sensitive data to obtain encrypted unstructured data;
[0047] An integration module for integrating the encrypted structured data and the encrypted unstructured data to generate simulated desensitized data.
[0048] The present invention also provides a computer device, including a memory and a processor, wherein a computer program is stored in the memory, and when the processor executes the computer program, the steps of the method described in any one of the above are implemented.
[0049] The present invention also provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the method described in any one of the above are implemented.
[0050] The encryption method and system based on symmetric cryptography algorithms provided by the present invention include: classifying the obtained sensitive data to obtain structured sensitive data and unstructured sensitive data; selecting the key numerical fields in the structured sensitive data, inputting them into a preset Fermat primality test algorithm, screening out large prime numbers as basic key elements, and generating an encryption key by combining the basic key elements with a preset key combination rule; wherein, the preset Fermat primality test algorithm pre-optimizes the number of iterations and screening range for prime number determination; using a symmetric cryptography algorithm, encrypting the structured sensitive data based on the encryption key to obtain encrypted structured data; encrypting the unstructured sensitive data to obtain encrypted unstructured data; and integrating the encrypted structured data and the encrypted unstructured data to generate simulated desensitized data. In the present invention, by selecting the key numerical fields in the structured sensitive data, inputting them into a preset Fermat primality test algorithm, screening out large prime numbers as basic key elements, and generating an encryption key by combining the basic key elements with a preset key combination rule, it is possible to optimize the processing according to the characteristics of the structured sensitive data, thereby effectively protecting the security of sensitive data and overcoming the defect of insufficient security of the generated key. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] Figure 1 is a schematic diagram of the steps of an encryption method based on symmetric cryptography algorithms in an embodiment of the present invention;
[0052] Figure 2 is a block diagram of the structure of an encryption system based on symmetric cryptography algorithms in an embodiment of the present invention;
[0053] Figure 3 is a schematic block diagram of the structure of a computer device in an embodiment of the present invention.
[0054] The implementation, functional features and advantages of the present invention will be further described with reference to the embodiments and the accompanying drawings. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0055] In order to make the objectives, technical solutions and advantages of the present invention clearer and more understandable, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0056] Referring to Figure 1 , an encryption method based on symmetric cryptography algorithms is provided in an embodiment of the present invention, including the following steps:
[0057] Step S1, classifying the obtained sensitive data to obtain structured sensitive data and unstructured sensitive data;
[0058] Step S2: Select the key numerical fields from the structured sensitive data, input them into a preset Fermat primality test algorithm, filter out large prime numbers as basic key elements, and generate an encryption key by combining the basic key elements with a preset key combination rule; wherein, the preset Fermat primality test algorithm pre-optimizes the iteration times and screening range for prime number determination.
[0059] Step S3: Use a symmetric cryptography algorithm to encrypt the structured sensitive data based on the encryption key to obtain encrypted structured data.
[0060] Step S4: Encrypt the unstructured sensitive data to obtain encrypted unstructured data.
[0061] Step S5: Integrate the encrypted structured data and the encrypted unstructured data to generate simulation desensitized data.
[0062] In this embodiment, as described in the above step S1, the sensitive data sources are extensive and diverse in form. Classification can lay a foundation for subsequent targeted encryption processing measures. Different types of sensitive data have significant differences in terms of structural characteristics, storage methods, and processing requirements. Distinguishing them helps to more precisely protect data security and achieve effective simulation desensitization.
[0063] Distinguish the sensitive data according to the pre-set data structure determination rules. For structured sensitive data, such as table data in a database, which has clear field definitions, data types, and fixed row and column relationships, it can be determined by identifying whether the data conforms to a predefined relational database schema or whether there are clear structured markers (such as XML tags, etc., which are data forms used to mark the hierarchical structure). For unstructured sensitive data, such as text files, images, audio, etc., which lack a unified structure format and the data organization form is relatively free and irregular, it is defined by judging whether the data cannot be simply presented in a fixed field and record form.
[0064] As described in step S2 above, first, analyze the importance of each field in the structured sensitive data in terms of business logic, data sensitivity, and data relevance, etc., to determine the key numerical fields. For example, in financial transaction data, key numerical fields such as transaction amount and account balance often play a crucial role in data sensitivity and integrity, and these fields will be preferentially selected. The selected key numerical fields are input into a preset Fermat primality test algorithm. This algorithm is based on Fermat's little theorem to initially judge whether a number is a prime number. However, due to the existence of pseudo-prime numbers, relying solely on the original algorithm is not completely reliable. In this solution, it has been optimized in advance. By reasonably adjusting the iteration times of prime number determination, unnecessary repeated tests are avoided, and the efficiency is improved while ensuring accuracy; at the same time, the screening range is accurately determined. According to factors such as cryptographic security requirements and the magnitude of the data being processed, the appropriate value range of large prime numbers is clarified, so as to more efficiently screen out the truly required large prime numbers as the basic key elements.
[0065] After obtaining the basic key elements, further generate an encryption key according to the preset key combination rule. For example, use a hash function to scramble the basic key elements, use bit operations for element permutation and expansion, or combine and transform these elements according to a specific mathematical function relationship, and finally generate an encryption key that meets the encryption requirements and has sufficient complexity and randomness.
[0066] As described in step S3 above: common symmetric cryptography algorithms can be selected, such as the Advanced Encryption Standard (AES), etc. Taking AES as an example, divide the structured sensitive data according to its data block size (such as 128 bits, etc.), and then use the encryption key generated in step S2 to encrypt each data block in turn through multiple rounds of encryption operations such as byte substitution, row shift, column confusion, and round key addition, and finally obtain all the encrypted structured data, that is, the encrypted structured data. During the entire encryption process, the encryption key is the same at the sender and the receiver. When decrypting, use the same key to perform reverse operations according to the corresponding decryption algorithm process to restore the original structured sensitive data.
[0067] As described in the above step S4, for the characteristics of unstructured sensitive data, a suitable symmetric encryption algorithm is adopted for encryption. For example, for text-based unstructured sensitive data, the text can be first encoded and converted (such as UTF-8 encoding) to make it in binary data form, and then symmetric encryption algorithms such as DES (Data Encryption Standard), 3DES (Triple Data Encryption Standard), etc. are used, and the pre-generated encryption key applicable to unstructured data (the generation method may be based on other suitable mechanisms, such as generated by a hash function, etc.) is used to perform bit-by-bit encryption on the binary data, and finally the encrypted unstructured data is obtained, that is, the encrypted unstructured data. For unstructured sensitive data such as images and audio, corresponding digital processing (such as pixel value representation of images, sampling quantization of audio, etc.) needs to be carried out first, and then similar symmetric encryption algorithms and corresponding keys are used for encryption.
[0068] As described in the above step S5, according to the overall architecture and business association logic of the original sensitive data, the encrypted structured data and encrypted unstructured data are reorganized and spliced. For example, if the original sensitive data is a document containing customer information (structured data part, such as fields of name, contact information, etc.) and customer feedback pictures and text descriptions (unstructured data part), then during integration, in accordance with the original format order of the document, the encrypted structured data fields and the encrypted unstructured data part are arranged in sequence. At the same time, some conventional means such as padding and format adjustment can also be used to make the integrated simulated desensitized data similar in appearance and data structure to the original sensitive data, but the sensitive information in it has been encrypted to achieve the desensitization purpose and meet the data usage requirements in scenarios such as development and testing environments, without causing accidental leakage of sensitive information.
[0069] In one embodiment, after generating the simulated desensitized data, it includes:
[0070] The simulated desensitized data is evaluated against a preset desensitized data standard to obtain an evaluation result. If the evaluation result does not meet the requirements, the iteration times and screening range of the prime number determination of the Fermat primality test algorithm are re-optimized.
[0071] In this embodiment, a preset evaluation algorithm and tool are used to check the simulated desensitized data from different dimensions. For example, for data privacy, it can be judged by detecting whether there is a risk of reverse cracking in the encrypted sensitive fields and whether there are residual traces of sensitive information; for data availability, simulate using the simulated desensitized data in an actual business scenario (such as importing data into a data analysis software for routine analysis operations) to see if there are problems such as format incompatibility and data logic errors; and for data consistency, compare the matching degree of the simulated desensitized data with the original sensitive data in terms of data structure, key identifiers, etc. Based on these inspection situations, an overall evaluation result is obtained to clarify whether it meets the preset desensitized data standard.
[0072] When the evaluation result shows that the simulated desensitized data does not meet the expected standard, it indicates that there may be room for optimization in the entire encryption and desensitization process. Since the generation of the encryption key has a crucial impact on the security of data encryption and the final desensitization effect, and in the process of generating the encryption key, the Fermat primality test algorithm is an important link in screening the basic key elements, so re-optimizing the number of iterations and screening range of its prime number determination is expected to change the characteristics of the generated encryption key, thereby improving the quality of subsequent encrypted and desensitized data to meet the preset standard.
[0073] Based on the feedback information of the current evaluation result that does not meet the requirements, analyze the possible problems, such as whether the privacy is not up to standard due to insufficient encryption strength, or whether the key generation is unreasonable and affects the data consistency. Then, through means such as mathematical analysis and simulation testing, adjust the number of iterations of prime number determination in the Fermat primality test algorithm, which may increase or decrease the number of iterations, so that the selected large prime number is more accurate and reliable as the basic key element; at the same time, re-examine and adjust the screening range, and expand or narrow the selection interval of large prime numbers according to the new security requirements and data characteristics to ensure that the subsequent generated encryption key is better in terms of security, randomness, etc. Then re-execute a series of encryption, integration, and evaluation steps starting from key generation until the finally generated simulated desensitized data can meet the preset desensitized data standard.
[0074] In one embodiment, encrypting the unstructured sensitive data to obtain encrypted unstructured data includes:
[0075] For the unstructured sensitive data, a hash function is used to generate a hash encryption key;
[0076] A symmetric cryptography algorithm is used to encrypt the unstructured sensitive data based on the hash encryption key to obtain encrypted unstructured data.
[0077] In this embodiment, since unstructured sensitive data lacks a unified and fixed structural format (such as different types of data like text files, images, audio, etc.), a method that can adapt to its characteristics is required when generating encryption keys. Using a hash function to generate a hash encryption key mainly utilizes the characteristics of the hash function such as one-wayness and avalanche effect. Based on the content characteristics of the unstructured sensitive data itself, an encryption key with sufficient randomness, uniqueness, and difficulty in reverse derivation is generated, providing a basic guarantee for the subsequent secure and effective encryption of unstructured sensitive data.
[0078] Using the previously generated hash encryption key, the unstructured sensitive data is encrypted through a symmetric cryptography algorithm, converting the sensitive information in the original unstructured sensitive data into ciphertext form, ensuring that even if the data is illegally obtained during storage, transmission, etc., the attacker cannot interpret the content without the correct key, thus protecting the security and privacy of the data.
[0079] For different types of unstructured sensitive data, the specific encryption operation details will be slightly different, but the overall idea is the same. For example, for text data, the binary sequence after its encoding is encrypted in groups; for image data, the data composed of pixel values is encrypted in groups; for audio data, the integrated audio data information is encrypted in groups. After such encryption processing, the original unstructured sensitive data is all converted into encrypted unstructured data, existing in the form of ciphertext, realizing the encryption protection of unstructured sensitive data.
[0080] Through the close cooperation of the above two steps, first generating a hash encryption key adapted to unstructured sensitive data, and then using this key to perform encryption through a symmetric cryptography algorithm, it can effectively meet the encryption requirements of unstructured sensitive data, improve the overall data security protection level, and play an important role in protecting data privacy especially in scenarios involving sensitive data processing.
[0081] In one embodiment, the key numerical fields in the structured sensitive data are selected and input into a preset Fermat primality test algorithm to screen out large prime numbers as basic key elements, including:
[0082] Perform data analysis on the structured sensitive data, extract the numerical fields with key identifiers as the key numerical fields;
[0083] Divide the key numerical fields into multiple numerical sub-segments, and each numerical sub-segment participates in the Fermat primality test algorithm as an independent input;
[0084] For each numerical sub-segment, when performing the Fermat primality test, set the initial base value range, adopt the modular exponentiation algorithm, and perform Fermat primality test calculations by changing the base multiple times;
[0085] When the numerical sub - segments show a preset prime possibility in multiple Fermat primality tests, mark them as large - prime candidates, calculate the relationships between the large - prime candidates and other known prime numbers, determine the true large primes according to the relationships, and exclude pseudoprimes.
[0086] Store the true large primes as basic key elements in the secure key cache area, and perform unique identification and indexing.
[0087] In this embodiment, first, data analysis is performed on the structured sensitive data according to the preset analysis rules. The above - mentioned rules usually comprehensively consider various factors. For example, from the perspective of business logic, identify the data fields in the key links of the business process, such as the transaction amount, account balance, etc. in financial transaction records, which are crucial for the integrity and confidentiality of data; from the level of data sensitivity, key numerical values such as ID numbers and bank card numbers involving customer privacy information are often the key objects of attention.
[0088] In addition, key identifiers are also determined according to factors such as the usage scenario of the data and the correlation relationship between data. For example, in the data of the supply - chain management system, numerical fields related to goods cost, transportation price, etc. may be identified as having key identifiers because they involve business secrets. After screening and extracting through these rules, those qualified numerical fields are determined as key numerical fields, and subsequent encryption keys will be generated based on them.
[0089] Directly performing Fermat primality tests on the entire key numerical field faces problems such as high computational complexity, low efficiency, and affected result accuracy. Dividing it into multiple numerical sub - segments can reduce the computational amount of a single test, improve the overall test efficiency, and also help to analyze data characteristics more carefully, screen suitable large primes from different sub - segment perspectives, increase the possibility of generating high - quality basic key elements, and make the test process more flexible and controllable.
[0090] The key numerical field is segmented according to the preset segmentation strategy. The above - mentioned segmentation strategy can be determined based on the size range of the numerical values, the structural characteristics of the data, or the requirements of cryptographic security strength, etc. For example, the numerical field can be divided according to a fixed length (such as dividing into one sub - segment every 100 bits); or it can be divided according to the grouping situation of the data in the structured system (such as splitting a certain key field in each row record of the database table into several sub - segments) according to certain logic.
[0091] After the division is completed, each obtained numerical sub - segment will be regarded as an independent entity, and then will be successively input into the Fermat primality test algorithm for corresponding prime - number screening tests to ensure that each sub - segment can be fully and independently analyzed and judged.
[0092] Fermat primality test is a method based on Fermat's little theorem to speculate whether a number is prime. However, to ensure the effectiveness, accuracy, and computational efficiency of the test, it is necessary to reasonably set the range of base values and adopt appropriate arithmetic algorithms. Setting the range of base values can control the scope and precision of the test, avoiding unnecessary calculations and misjudgments; adopting the modular exponentiation algorithm can efficiently complete the calculations. By testing with multiple transformed bases, the prime number possibility of the numerical segment can be verified from multiple perspectives, improving the reliability of the judgment.
[0093] In this embodiment, the range of base values is determined in advance. The setting of this range usually comprehensively considers factors such as cryptographic security requirements and the numerical characteristics of the numerical segment itself. For example, under the condition of meeting certain cryptographic strength standards, according to the approximate magnitude, data type, etc. of the numerical segment, a suitable integer interval is selected as the range of base values. The bases within this interval can be some common numerical sets verified through cryptographic practices, or numerical ranges randomly generated by the system and conforming to specific rules.
[0094] Then, the modular exponentiation algorithm is used to perform the Fermat primality test calculation. The modular exponentiation algorithm can quickly calculate the result. It reduces the amount of calculation and improves the operation speed by using some mathematical techniques (such as repeated squaring to find the power, optimization of the modulo operation, etc.). During the calculation process, the base is changed multiple times, that is, different values within the set range of base values are selected as the base, and the above modular exponentiation is repeated. Based on the results obtained from each calculation, a comprehensive judgment is made on whether the numerical segment shows a high possibility of being prime, so as to more comprehensively and accurately screen for prime numbers.
[0095] Although the numerical segments showing the possibility of being prime after the Fermat primality test have a high probability of being prime, the Fermat primality test has certain misjudgment situations and will produce pseudoprimes. By further calculating the relationship between the large prime candidates and other known prime numbers, the true large prime numbers can be more accurately identified, and those pseudoprimes can be excluded, thus ensuring that the large prime numbers used as the basic key elements have extremely high accuracy and reliability, laying a solid foundation for generating high-quality encryption keys.
[0096] When a numerical sub - segment conforms to the prime number characteristics presented by Fermat's Little Theorem after multiple Fermat primality tests with different bases, it is first marked as a large prime candidate. Next, specific mathematical methods are used to calculate its relationship with other known prime numbers, such as using mathematical tools like the Extended Euclidean Algorithm and the Chinese Remainder Theorem. Through the Extended Euclidean Algorithm, relationship information such as the greatest common divisor between the large prime candidate and known prime numbers can be calculated, and based on these relationships, it is determined whether the candidate satisfies the properties of a true prime number; the Chinese Remainder Theorem can further assist in verifying the authenticity of the large prime candidate in the case of multiple congruence equations (constructing congruence relationships with other known prime numbers). If, after these relationship calculations and verifications, the numerical sub - segment indeed meets the determination criteria of a true prime number, then it is determined as a true large prime number; conversely, if it is found not to meet the corresponding relationship requirements, it is determined as a pseudoprime number and excluded to ensure that the finally selected large prime numbers are accurate and reliable.
[0097] The determined true large prime numbers serve as the basic key elements for generating subsequent encryption keys, and their security is of crucial importance. Storing them in a secure key buffer can prevent external illegal access and tampering, ensuring the integrity and confidentiality of these key elements; performing unique identification and indexing facilitates the accurate and rapid invocation and management of these basic key elements when generating encryption keys later, improving the efficiency and reliability of the entire key generation and encryption process.
[0098] When storing true large prime numbers, a unique identifier is assigned to each large prime number. This identifier can be determined based on the order of its generation, the associated characteristics with data, or by generating through a specific hash algorithm, etc., so that it can be uniquely distinguished within the buffer. At the same time, a corresponding indexing mechanism is established, such as using data structures like tree structures (such as binary search trees, etc.) or hash tables to record the correspondence between large prime numbers and their identifiers, facilitating quick search and positioning. In this way, when it is necessary to use these basic key elements to generate encryption keys according to the preset key combination rules later, the corresponding large prime numbers can be obtained efficiently and accurately, ensuring the smooth progress of the entire encryption process.
[0099] In one embodiment, the generating of the encryption key by combining the basic key elements with a preset key combination rule includes:
[0100] Adopting an encryption transformation based on lattice cryptography theory to map each of the basic key elements to high - dimensional vectors in a high - dimensional lattice space;
[0101] Introducing the entanglement state characteristics of quantum bits to perform quantum state encoding on each of the high - dimensional vectors to obtain key element encodings;
[0102] Combining each of the key element encodings to obtain the encryption key.
[0103] In this embodiment, the lattice cryptography theory has a unique security advantage. Encryption transformation based on it can utilize the complex mathematical structure of the lattice space to enhance the security and complexity of the basic key elements. By mapping the basic key elements to high-dimensional vectors in the high-dimensional lattice space, the originally relatively simple key elements can be integrated into the characteristics of the lattice space, providing a richer mathematical structure foundation for subsequent further encryption processing, and increasing the difficulty for attackers to crack.
[0104] First, the corresponding lattice structure is constructed based on the lattice cryptography theory. The lattice is usually generated by a set of linearly independent vectors (lattice basis), which defines the basic framework of the lattice space. In actual operation, the appropriate lattice basis vectors and lattice dimensions and other parameters are determined according to the cryptographic security strength requirements and the number and characteristics of the basic key elements. For example, a specific integer vector is selected as the lattice basis, and the element values, vector lengths, and linear relationships of these lattice basis vectors are carefully designed to meet the cryptographic trade-off between security and computational efficiency.
[0105] Then, each basic key element is used as input, and the pre-built lattice structure is used to convert it into a high-dimensional vector in the high-dimensional lattice space through a preset mathematical mapping relationship. This mapping process involves a series of complex linear transformations, coordinate conversions and other operations. For example, according to the linear combination operation of the lattice basis vector and the basic key element, the corresponding coordinate value in the high-dimensional lattice space is calculated according to the established rules, thereby determining its high-dimensional vector representation. These high-dimensional vectors not only contain the information of the original basic key element, but also incorporate the unique mathematical structure and security characteristics given by the lattice space.
[0106] The entangled state characteristics of quantum bits are a unique phenomenon in quantum mechanics, which makes a non-classical connection between multiple particles in a quantum system exist. This connection is highly complex and non-clonable. Introducing it into the processing of high-dimensional vectors can further enhance the security and uniqueness of key element encoding with the help of these special properties of quantum states. Through quantum state encoding, high-dimensional vectors are converted into a representation based on quantum states, so that key elements have quantum information protection, which is fundamentally different from traditional encoding methods and greatly increases the difficulty for attackers to obtain and crack key information.
[0107] For each high-dimensional vector, the information of each dimension is corresponding and associated with the state of qubits. Utilizing the entanglement state characteristics of qubits, through specific quantum gate operations (such as Hadamard gates, CNOT gates, etc., which can realize the change and control of qubit states), an entanglement state is constructed to generate complex correlation relationships between different qubits, thereby encoding the high-dimensional vector. For example, the value of a certain dimension in the high-dimensional vector can be represented by a specific superposition state of qubits, and multiple qubits form an overall quantum state through entanglement, and this quantum state serves as the key element encoding corresponding to the high-dimensional vector.
[0108] In the above process, the specific encoding rules, the order and parameters of quantum gate operations, etc. are all carefully designed according to cryptographic security requirements and quantum information theory to ensure that the generated key element encoding makes full use of the characteristics of qubit entanglement states, has high randomness, unpredictability, and anti-interference capabilities, and can effectively resist classical computing and even potential quantum computing attack means.
[0109] Integrate each key element encoding according to the preset combination rules. The above combination rules can be formulated based on mathematical logic, cryptographic algorithms, or specific business requirements, etc.
[0110] In one embodiment, the generating the encryption key by combining the basic key elements with the preset key combination rules includes:
[0111] Perform a first quick hashing on each of the basic key elements based on a lightweight hash function to obtain a preliminary hash value; wherein, the hash seed is generated according to the current running state information of the system;
[0112] Perform a second hashing on the preliminary hash value based on the Blake2b hash function to obtain a deeply scrambled element value;
[0113] Dynamically determine the bit rotation direction and number of steps according to the current system clock cycle, and rearrange the binary bits of the scrambled element value to obtain a rearranged element value;
[0114] Construct a finite field multiplication operation based on a primitive polynomial, and extend the rearranged element value within the finite field to obtain an extended element value; wherein, the coefficients of the primitive polynomial are dynamically selected according to the sensitivity level of the data to be encrypted;
[0115] Combine each of the extended element values in sequence to form the encryption key.
[0116] In this embodiment, the lightweight hash function (MurmurHash) is used for the first hash processing. The main purpose is to initially disrupt the original information structure of the basic key elements while ensuring a certain operation efficiency, and increase their randomness and unpredictability. By generating a hash seed based on the current running state information of the system, it can make each generated hash result associated with the specific state of the system at that moment. Even for the same basic key elements, different initial hash values will be obtained when performing hash operations at different times, further improving the dynamics and security in the key generation process and preventing attackers from inferring key information through a fixed pattern. For example, a suitable integer can be obtained as the hash seed by performing simple mathematical operations (such as addition, multiplication and then taking the modulus, etc.) on part of the numerical value of the timestamp and the CPU usage rate.
[0117] The basic key elements and the generated hash seed are input into the selected lightweight hash function together. The hash function calculates each basic key element according to its internal established operation logic (usually involving multiple iterative processes, bit operations, etc. on the input data) and outputs the corresponding initial hash value. Compared with the original basic key elements, the information of these initial hash values has been initially confused and transformed.
[0118] The Blake2b hash function has high security and strong confusion ability. After obtaining the initial hash value through the first fast hash, using it for the second hash can further strengthen the confusion degree of the key element information, making it more difficult to be reverse-derived and cracked.
[0119] The initial hash value obtained in the previous step is used as the input data and input into the Blake2b hash function. The Blake2b hash function has a rigorous structure and complex operation process inside. It will perform multiple rounds of operations such as compression, permutation, and expansion on the input initial hash value. For example, in each round of operation, non-linear function operations, bit mixing operations, etc. will be performed according to specific round constants, message words (here are the binary data blocks corresponding to the initial hash value), and state vectors. After multiple rounds of such processing, the deeply confused element values are output. These element values have a large difference from the original basic key elements at the information level, hiding the original key information and having higher confidentiality.
[0120] By using the dynamically changing factor of the system clock cycle to determine the bit rotation direction and number of steps, and rearranging the binary bits of the element values that have already been hashed and obfuscated, it is to introduce more dynamic randomness in the key generation process. This dynamically changing bit arrangement method makes it difficult for attackers to analyze and restore the original key information through a fixed pattern even if they obtain some of the obfuscated element values, greatly enhancing the anti-analysis ability and security of the key, and making it more meet the requirements of cryptography for key complexity and unpredictability.
[0121] First, obtain the current system clock cycle information, which can be obtained through the clock functions provided by the system or relevant time acquisition interfaces to get the clock cycle value accurate to a certain time granularity (such as milliseconds, microseconds, etc.). Then, according to the pre-set algorithm, determine the bit rotation direction (for example, if a certain bit of the clock cycle is even, it is set to rotate clockwise, if it is odd, it is set to rotate counterclockwise, etc.) and the number of steps (it can be an appropriate integer obtained after operations such as taking the modulus of the clock cycle value as the number of steps) based on this clock cycle value.
[0122] Next, for the binary bits of the obfuscated element values, perform bit rotation operations according to the determined rotation direction and number of steps, that is, move each binary bit within its corresponding byte or word according to the corresponding rules. For example, for an 8-bit byte data, if it is set to rotate clockwise by 3 steps, then the original binary bit at the lowest position will move to the 3rd position, and so on. After such rearrangement operations are completed for all the binary bits of the obfuscated element values, the rearranged element values are obtained.
[0123] Use the finite field multiplication operation based on the primitive polynomial to expand the rearranged element values. On the one hand, it is to increase the information content and complexity of the key elements, so that the generated encryption key can have richer cryptographic characteristics; on the other hand, dynamically selecting the coefficients of the primitive polynomial according to the sensitivity level of the data to be encrypted can achieve the adaptation of the key to the data sensitivity. For data with higher sensitivity, stronger and more complex encryption keys are generated, thus better ensuring the security of the data and achieving flexible and effective data encryption protection.
[0124] First, a finite field needs to be constructed, which requires determining an appropriate primitive polynomial. The primitive polynomial is a key element in the construction of the finite field, and the selection of its coefficients is based on the sensitivity level of the data to be encrypted. For example, for data with a high sensitivity level, a primitive polynomial with a higher power and a more complex coefficient distribution is selected, while for data with lower sensitivity, a relatively simpler one that still meets the cryptographic security requirements can be selected. These primitive polynomials can be pre-defined and stored according to different sensitivity levels and dynamically called according to the specific data sensitivity situation during actual key generation.
[0125] Then, regarding the rearranged element values as elements in a finite field, they are extended through finite field multiplication operations. Finite field multiplication operations have strict operation rules, which are different from ordinary multiplication operations and need to follow the characteristics of the finite field for calculation. Specifically, during the operation process, in combination with the selected primitive polynomial and the addition (usually implemented by exclusive OR operation) and multiplication rules of the finite field, multiple multiplication, addition, etc. operations are performed on the rearranged element values to expand them into extended element values containing more information. For example, by continuously performing multiplication operations with specific elements in the finite field (determined by the primitive polynomial and operation rules) and combining intermediate results for addition operations, etc., extended element values that meet the requirements are gradually generated, enabling them to have stronger cryptographic characteristics and richer information-bearing capabilities within the framework of the finite field.
[0126] After the previous series of processes, each basic key element has been transformed into extended element values with high security, complexity, and adaptability. Combining them in sequence is to form a complete encryption key. This encryption key synthesizes the cryptographic advantages given by the previous steps and can be used to encrypt sensitive data based on symmetric cryptography algorithms in subsequent operations, ensuring the confidentiality and integrity of data in various application scenarios.
[0127] Through the above steps, by using a variety of innovative technical means and a dynamic parameter selection mechanism, the basic key elements are gradually transformed into an encryption key with high security and adaptability, providing strong protection for the encryption of sensitive data based on symmetric cryptography algorithms.
[0128] In one embodiment, for the unstructured sensitive data, a hash encryption key is generated using a hash function, including:
[0129] Performing a hash calculation on the unstructured sensitive data based on the hash function to obtain a hash value, and using each character in the hash value as the basic element of a matrix to construct a two-dimensional matrix;
[0130] Extracting the sentence structure feature vector, low-frequency feature vector, and feature vector of the key frequency band of the unstructured sensitive data; the unstructured sensitive data includes text, image, and audio data;
[0131] Mapping the sentence structure feature vector, low-frequency feature vector, and feature vector of the key frequency band into three-dimensional space respectively, and constructing a triangular mesh surface through a triangulation algorithm according to the similarity and relevance between each feature vector;
[0132] Generating the hash encryption key based on the triangular mesh surface and the two-dimensional matrix.
[0133] In this embodiment, the hash function (SHA-256, SHA-512) is first used to process the unstructured sensitive data because the hash function has the characteristics of unidirectionality and avalanche effect, and can convert unstructured sensitive data of any length into a hash value of fixed length. This hash value can be regarded as a characteristic representation of the original data, while hiding the specific content of the original data to ensure a certain degree of confidentiality. The characters in the hash value are used as the basic elements of the matrix to construct a two-dimensional matrix, aiming to further convert the hash value into a data form with a certain structure, so as to facilitate the subsequent fusion processing with other features extracted from the data, so as to generate a more complex and secure hash encryption key.
[0134] Each character in the above hash value (usually a character represented in hexadecimal, etc.) is used as a basic element of the matrix, and a two-dimensional matrix is constructed according to a pre-set matrix construction rule. For example, these character elements can be allocated according to a fixed number of rows and columns, and the characters in the hash value are filled into the corresponding positions of the matrix in turn, thereby constructing a two-dimensional matrix structure. This matrix carries the characteristic information about the original unstructured sensitive data contained in the hash value, and has a structured form that is convenient for subsequent operations.
[0135] Different types of unstructured sensitive data (text, images, audio) contain their own unique intrinsic characteristics. By extracting these feature vectors of different dimensions, we can capture the essential information of the data more comprehensively and deeply, and provide rich materials for the subsequent generation of hash encryption keys that are closely related to the data and have high security. Sentence structure feature vectors help to grasp the grammatical and logical structure characteristics of text data; low-frequency feature vectors can mine relatively less significant but potentially unique features in image data; and feature vectors in key frequency bands focus on the characteristics of data within certain important frequency ranges. These features combined can better reflect the diversity and complexity of unstructured sensitive data.
[0136] Natural language processing technology can be used to extract sentence structure feature vectors from text data; image perception algorithms can be used to extract low-frequency feature vectors from image data; and audio recognition technology can be used to extract feature vectors of key frequency bands from audio data.
[0137] Mapping the feature vectors extracted from different dimensions into a three-dimensional space is to present these features in an intuitive way that facilitates the analysis of the relationships between them. Using the triangulation algorithm to construct a triangular mesh surface is to further integrate and visualize these features, making them form a continuous surface with geometric structure. This surface can comprehensively reflect the internal connections between the features of unstructured sensitive data in all aspects, laying a foundation for generating keys through fusion processing with the previously constructed two-dimensional matrix. At the same time, this geometric structure form also increases the complexity and uniqueness of the key generation process and enhances security.
[0138] First, the values of each dimension of the sentence structure feature vector, low-frequency feature vector, and feature vector of the key frequency band are respectively mapped to the coordinate axes of the three-dimensional space, so that each feature vector has a corresponding coordinate point representation in the three-dimensional space. Then, analyze the similarity and correlation between these coordinate points. Similarity can be measured by calculating the distance between vectors (such as metrics like Euclidean distance, cosine similarity, etc.), and correlation can be judged according to the logical relationship and mutual influence degree of the features represented by the feature vectors in the data.
[0139] Based on these similarities and correlations, use a triangulation algorithm (such as the Delaunay triangulation algorithm, etc.) to construct a triangular mesh surface. This algorithm will find appropriate combinations of points according to the distribution of the point set, so that the triangles formed by these points satisfy certain geometric rules (such as trying to ensure that the smallest interior angle of the triangle is the largest, etc.). By connecting these triangles to form a triangular mesh surface covering all points, this surface contains the complex relationship information between the feature vectors of unstructured sensitive data and is presented in a geometric form, providing a unique structural basis for subsequent key generation operations.
[0140] By fusing the multi-dimensional feature relationship information of unstructured sensitive data represented by the triangular mesh surface and the hash value feature information carried by the two-dimensional matrix, a hash encryption key is generated, enabling the key to fully combine various internal characteristics of unstructured sensitive data. It not only has the advantages of one-wayness and confidentiality based on the hash function but also incorporates rich feature information of the data itself, thus generating a hash encryption key with high security, closely related to the original data, and difficult to be cracked, which is used for subsequent encryption protection of unstructured sensitive data.
[0141] Multiple methods can be used to generate a fusion key. A possible operation is to first perform quantization processing on the triangular mesh surface. For example, geometric parameters such as the vertex coordinate values of the surface, the areas of the triangles, and the lengths of the edges are extracted, and these parameters are combined with the elements in the two-dimensional matrix according to certain rules. For instance, the geometric parameters of the triangular mesh surface and the elements in the two-dimensional matrix are alternately selected in a certain order to form a new one-dimensional data sequence. Then, some additional encryption processing means are applied to this new data sequence, such as performing re-hashing through a specific hash function (which can be a different hash function with higher security requirements than the previous one, such as Blake2b, etc.), or performing operations such as confusion and expansion on the data sequence based on bit operations (such as exclusive OR, shift, etc.), ultimately generating a hash encryption key that meets the requirements of cryptography.
[0142] In one embodiment, generating the hash encryption key based on the triangular mesh surface and the two-dimensional matrix includes:
[0143] Quantize the vertex coordinate values of each triangular face of the triangular mesh surface and establish a mapping relationship with the elements at preset positions in the two-dimensional matrix;
[0144] Based on the matrix element values mapped by the vertex coordinates of each triangular face, use bilinear interpolation to calculate the corresponding values of any point within the triangular face, and combine them to obtain a value matrix;
[0145] Perform singular value decomposition on the value matrix, extract the singular values, and recombine the singular values to obtain recombined singular values;
[0146] Perform a hash operation on the recombined singular values to generate the hash encryption key.
[0147] In this embodiment, the triangular mesh surface contains the correlation information between multi-dimensional features of unstructured sensitive data, and the vertex coordinate values of its triangular faces are key geometric feature data. Quantizing these coordinate values is to convert them into discrete numerical forms that are convenient for subsequent calculation and processing, enabling them to better fuse with the feature information based on hash values carried by the two-dimensional matrix. Establishing the mapping relationship aims to build a communication bridge between the two, allowing the geometric features of the surface and the element information of the matrix to be correlated and interact synergistically, providing richer and logically coherent materials for generating the hash encryption key.
[0148] First, for each triangular face of the triangular mesh surface, obtain the coordinate values of its vertices (coordinates in three-dimensional space, usually represented in real number form). During quantization, according to the preset precision requirements and quantization range, each dimension of the coordinate value is converted into a discrete integer value. For example, it can be stipulated that the value range of the coordinate value is equally divided into several intervals, each interval corresponding to a specific integer code, and the code corresponding to the interval where the coordinate value is located is used as its quantized value.
[0149] Then, determine the mapping relationship between the elements at the preset positions in the two-dimensional matrix and these quantized vertex coordinate values. The selection of the preset positions can be based on certain rules. For example, starting from the upper left corner of the matrix, select elements in a certain scanning order (such as row-first or column-first); or determine the positions corresponding to the vertex coordinate values according to certain attributes of the matrix elements (such as the parity or size order of the element values). For example, map the three vertex coordinate values of the first triangular face in the triangular mesh surface to the elements in the 1st row and 1st column, 2nd row and 3rd column, and 3rd row and 5th column of the two-dimensional matrix respectively, and so on. Establish the mapping between the vertex coordinates of each triangular face and the matrix elements, so that the geometric features of the surface can be associated with the element information of the matrix through this mapping.
[0150] Calculating the corresponding value for any point within the triangular face through bilinear interpolation is to make full use of the information of the matrix element values mapped by the vertices of the triangular face, extend it to the entire triangular face, further enrich and refine the data feature representation, and make the information integrated from the triangular mesh surface and the two-dimensional matrix more continuous and complete. Combining these values to form a numerical matrix is to organize these refined information into a structured form convenient for subsequent mathematical processing (such as singular value decomposition, etc.), so as to extract more cryptographically valuable features from it to generate a hash encryption key.
[0151] For each triangular face in the triangular mesh surface, the values of the two-dimensional matrix elements mapped by its three vertex coordinates are known. Arbitrarily take a point within the triangular face and use the bilinear interpolation formula to calculate the corresponding value of this point. The basic principle of bilinear interpolation is based on the extension of linear interpolation in two directions. First, perform linear interpolation on the two sides of the triangle respectively, and then perform another linear interpolation on the interpolated results.
[0152] Perform such bilinear interpolation calculations on multiple sampling points within the triangular surface (a sufficient number of points can be selected according to a preset sampling strategy, such as uniform sampling, etc.), obtaining a series of numerical values. Arrange and combine the numerical values calculated for all triangular surfaces in a certain order (such as according to the arrangement order of the triangular surfaces on the curved surface, or based on a logical order related to data characteristics), constructing a numerical matrix. This numerical matrix synthesizes the rich information after the fusion of the triangular mesh surface and the two-dimensional matrix and presents it in a structured form.
[0153] Singular value decomposition (SVD) is an important matrix analysis tool. Performing singular value decomposition on a numerical matrix can uncover the internal structure and main characteristic information of the matrix data. The extracted singular values represent the degree of importance of the matrix in different dimensions. By reorganizing these singular values, the original characteristic information structure can be further disrupted and transformed, increasing the complexity and randomness of the data, making it more suitable for generating highly secure hash encryption keys. At the same time, some potentially redundant or information that is not conducive to key security can be removed, and the key cryptographic features can be refined.
[0154] After extracting the singular values, operate on them according to the preset reorganization rules. The reorganization rules can be formulated according to cryptographic security requirements and the characteristics of the data itself. For example, they can be grouped according to the magnitude order of the singular values, and then the singular values of different groups are recombined in a cross-arrangement manner; or a new order of the singular values can be determined according to a certain random number sequence (this random number sequence can be generated by the system and is associated with the environmental information of the current data processing, such as generated in combination with the system timestamp, process ID, etc.), and they are rearranged and combined into reorganized singular values. Such reorganization operations make the characteristic information contained in the singular values undergo a reconfiguration and become more difficult to analyze and restore, laying a foundation for generating secure hash encryption keys subsequently.
[0155] After a series of previous processes, the reorganized singular values have synthesized the complex characteristic information of the unstructured sensitive data contained in the triangular mesh surface and the two-dimensional matrix. And through transformations such as quantization, interpolation, singular value decomposition, and reorganization, they have a certain degree of randomness and complexity. Performing a hash operation on them is to utilize the characteristics of the hash function such as one-wayness and avalanche effect to further transform this characteristic information into a fixed-length, highly confidential hash encryption key, making the finally generated key difficult to be reverse-derived and effectively ensuring the security of unstructured sensitive data during the encryption process.
[0156] After generating the hash encryption key, some necessary verification and validation operations can also be performed on it. For example, check whether the length of the key meets the requirements of cryptographic standards, evaluate its randomness by calculating the entropy value of the key (generally, a sufficiently high entropy value is desired, indicating that the key has good unpredictability), etc. If the corresponding requirements are not met, it may be necessary to go back to the previous steps, such as adjusting the rules for establishing the mapping relationship between the triangular mesh surface and the two-dimensional matrix, the sampling strategy of bilinear interpolation, or the rules for singular value recombination, etc., and re-execute the relevant operations until a hash encryption key that meets the cryptographic security standards is generated to ensure that it can be reliably applied to the encryption protection process of unstructured sensitive data.
[0157] In one embodiment, the step of generating a hash encryption key for the unstructured sensitive data by using a hash function includes:
[0158] Perform a preliminary hash calculation on the unstructured sensitive data using a fast hash algorithm (such as MurmurHash) to obtain a set of hash values, convert it into a two-dimensional array form, and thus construct a base matrix. The number of rows and columns of the base matrix is determined according to the size of the hash value set and specific cryptographic rules. For example, determine the prime number combination of the number of rows and columns according to the data sensitivity level;
[0159] For unstructured sensitive data, extract the term frequency-inverse document frequency feature vector for text data, extract the scale-invariant feature transform feature point set for image data, and extract the Mel frequency cepstral coefficient feature vector for audio data;
[0160] Construct a curve represented by a hidden Markov chain model (HMM) according to the extracted feature vectors. The number of states and transition probabilities of the HMM are determined by the dimension and distribution of the feature vectors. For example, the number of states is related to the number of principal components of the feature vector, and the transition probability is related to the strength of the feature correlation, so that the curve can reflect the internal structure of the unstructured sensitive data from the perspective of probability distribution;
[0161] Perform a fusion operation on the base matrix and the HMM curve; specifically, include: according to the state transition probability distribution of the HMM curve, perform selective weighted adjustment on the elements in the base matrix. For the matrix area corresponding to the state with a high transition probability, use a larger weight coefficient (this coefficient is determined by the requirements of the cryptographic security key space) for weighting. The weight coefficient is obtained by taking the modulus after performing a hash operation with the current system timestamp to ensure that the weight generated each time has randomness and unpredictability;
[0162] Perform a transformation operation based on singular value decomposition (SVD) on the weighted matrix. By performing SVD decomposition on the matrix, retain its main singular values and corresponding singular vectors. Determine the number of singular values to be retained according to the preset cryptographic security parameters, and reconstruct the matrix using the retained singular values and vectors to obtain a compressed and transformed matrix, enhancing the security and complexity of the data;
[0163] Perform serialization processing on the reconstructed matrix. Convert the matrix elements into a one-dimensional data sequence in row-major or column-major order, and then use a secure hash algorithm (such as SHA - 256) to perform a final hash operation on this sequence to generate a hash encryption key;
[0164] Perform key strength evaluation on the generated hash encryption key. By calculating the collision probability of the key and the key space size, and comparing with the preset cryptographic strength indicators. If the evaluation result does not meet the requirements, readjust the feature extraction method, matrix construction and transformation parameters, HMM curve construction rules, etc., and execute the above steps again until a hash encryption key that meets the strength requirements is generated.
[0165] Refer to Figure 2 In one embodiment of the present invention, an encryption system based on a symmetric cryptography algorithm is further provided, including:
[0166] A classification module for classifying the obtained sensitive data to obtain structured sensitive data and unstructured sensitive data;
[0167] A generation module for selecting key numerical fields from the structured sensitive data, inputting them into a preset Fermat primality test algorithm, screening out large prime numbers as basic key elements, and generating an encryption key by combining the basic key elements with a preset key combination rule; wherein, the preset Fermat primality test algorithm pre-optimizes the number of iterations and screening range for prime number determination;
[0168] A first encryption module for encrypting the structured sensitive data based on the encryption key using a symmetric cryptography algorithm to obtain encrypted structured data;
[0169] A second encryption module for encrypting the unstructured sensitive data to obtain encrypted unstructured data;
[0170] An integration module for integrating the encrypted structured data and the encrypted unstructured data to generate simulated desensitized data.
[0171] In this embodiment, for the specific implementation of each module in the above system embodiment, please refer to that described in the above method embodiment, and details will not be elaborated here.
[0172] Refer to Figure 3, embodiments of the present invention also provide a computer device, which can be a server, and its internal structure can be as Figure 3 shown. The computer device includes a processor, a memory, a display screen, an input device, a network interface, and a database connected by a system bus. Among them, the processor of the computer design is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store the corresponding data in this embodiment. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, the above method is implemented.
[0173] Those skilled in the art can understand that Figure 3 the structure shown in
[0174] is only a block diagram of a part of the structure related to the solution of the present invention, and does not constitute a limitation on the computer device to which the solution of the present invention is applied.
[0175] In summary, the present invention provides an encryption method and system based on a symmetric cryptography algorithm in embodiments, including: classifying the obtained sensitive data to obtain structured sensitive data and unstructured sensitive data; selecting key numerical fields in the structured sensitive data, inputting them into a preset Fermat primality test algorithm, screening out large prime numbers as basic key elements, and generating an encryption key by combining the basic key elements with a preset key combination rule; wherein, the preset Fermat primality test algorithm pre-optimizes the iteration times and screening range of prime number determination; using a symmetric cryptography algorithm, encrypting the structured sensitive data based on the encryption key to obtain encrypted structured data; encrypting the unstructured sensitive data to obtain encrypted unstructured data; integrating the encrypted structured data and the encrypted unstructured data to generate simulated desensitized data. In the present invention, by selecting key numerical fields in the structured sensitive data, inputting them into a preset Fermat primality test algorithm, screening out large prime numbers as basic key elements, and generating an encryption key by combining the basic key elements with a preset key combination rule; it is possible to optimize the processing according to the characteristics of the structured sensitive data, thereby effectively protecting the security of sensitive data and overcoming the defect that the generated key has insufficient security.
[0176] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium provided by the present invention and used in the embodiments can include non-volatile and / or volatile memories. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (SSRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM, etc.
[0177] It should be noted that in this article, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, apparatus, article or method including a series of elements not only includes those elements but also includes other elements not expressly listed, or also includes elements inherent in such process, apparatus, article or method. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of additional identical elements in the process, apparatus, article or method including that element.
[0178] The above are only the preferred embodiments of the present invention, and do not limit the patent scope of the present invention accordingly. Any equivalent structure or equivalent process transformation made by using the specification and drawings of the present invention, or directly or indirectly applied in other related technical fields, shall be equally included in the patent protection scope of the present invention.
Claims
1. An encryption method based on symmetric cryptography algorithms, characterized in that, It includes the following steps: Classify the obtained sensitivity-related data to obtain structured sensitive data and unstructured sensitive data; Select the key numerical fields in the structured sensitive data, input them into a preset Fermat primality test algorithm, filter out large prime numbers as basic key elements, and generate an encryption key by combining the basic key elements with a preset key combination rule; wherein, the preset Fermat primality test algorithm pre-optimizes the iteration times and screening range of prime number determination; Use a symmetric cryptography algorithm to encrypt the structured sensitive data based on the encryption key to obtain encrypted structured data; Encrypt the unstructured sensitive data to obtain encrypted unstructured data; Integrate the encrypted structured data and the encrypted unstructured data to generate simulation desensitized data; Encrypt the unstructured sensitive data to obtain encrypted unstructured data, including: For the unstructured sensitive data, generate a hash encryption key using a hash function; Use a symmetric cryptography algorithm to encrypt the unstructured sensitive data based on the hash encryption key to obtain encrypted unstructured data; For the unstructured sensitive data, generate a hash encryption key using a hash function, including: Perform a hash calculation on the unstructured sensitive data based on the hash function to obtain a hash value, use each character in the hash value as the basic element of a matrix, and construct a two-dimensional matrix; Extract the sentence structure feature vector, low-frequency feature vector, and feature vector of the key frequency band of the unstructured sensitive data; the unstructured sensitive data includes text, image, and audio data; Map the sentence structure feature vector, low-frequency feature vector, and feature vector of the key frequency band into three-dimensional space respectively, and construct a triangular mesh surface through a triangulation algorithm according to the similarity and relevance between the feature vectors; Generate the hash encryption key based on the triangular mesh surface and the two-dimensional matrix.
2. The encryption method based on the symmetric cryptography algorithm according to claim 1, wherein After generating the simulation desensitized data, it includes: Evaluate the simulation desensitized data against a preset desensitized data standard to obtain an evaluation result. If the evaluation result does not meet the requirements, re-optimize the iteration times and screening range of prime number determination in the Fermat primality test algorithm.
3. The encryption method based on the symmetric cryptography algorithm according to claim 1, wherein Select the key numerical fields in the structured sensitive data, input them into a preset Fermat primality test algorithm, and filter out large prime numbers as basic key elements, including: Perform data analysis on the structured sensitive data, extract the numerical fields with key identifiers as the key numerical fields; Divide the key numerical fields into multiple numerical sub-segments, and each numerical sub-segment participates in the Fermat primality test algorithm as an independent input; For each numerical sub-segment, when performing the Fermat primality test, set an initial base value range, use the modular exponentiation algorithm, and perform Fermat primality test calculations by changing the base multiple times; When the numerical sub-segment shows a preset prime number possibility in multiple Fermat primality tests, mark it as a large prime number candidate, calculate the relationship between the large prime number candidate and other known prime numbers, and determine the real large prime number according to the relationship, and exclude the pseudo-prime numbers; Store the real large prime number as a basic key element in a secure key buffer, and perform unique identification and indexing.
4. The encryption method based on the symmetric cryptography algorithm according to claim 1, wherein, The generation of the encryption key by combining the basic key elements with a preset key combination rule includes: Using an encryption transformation based on lattice cryptography theory, map each of the basic key elements to high-dimensional vectors in a high-dimensional lattice space; Introduce the entanglement state characteristics of quantum bits to perform quantum state encoding on each of the high-dimensional vectors to obtain key element encodings; Combine each of the key element encodings to obtain the encryption key.
5. The encryption method based on the symmetric cryptography algorithm according to claim 1, wherein The generation of the encryption key by combining the basic key elements with a preset key combination rule includes: Perform a first fast hashing on each of the basic key elements based on a lightweight hash function to obtain a preliminary hash value; wherein, the hash seed is generated according to the current operating state information of the system; Perform a second hashing on the preliminary hash value based on the Blake2b hash function to obtain a deeply confused element value; Dynamically determine the bit rotation direction and number of steps according to the current system clock cycle, and rearrange the binary bits of the confused element value to obtain a rearranged element value; Construct a finite field multiplication operation based on a primitive polynomial, and extend the rearranged element value within the finite field to obtain an extended element value; wherein, the coefficients of the primitive polynomial are dynamically selected according to the sensitivity level of the data to be encrypted; Combine each of the extended element values in sequence to form the encryption key.
6. The encryption method based on the symmetric cryptography algorithm according to claim 1, wherein, Generate the hash encryption key based on the triangular grid surface and the two-dimensional matrix, including: Quantize the vertex coordinate values of each triangular face of the triangular grid surface, and establish a mapping relationship with the elements at preset positions in the two-dimensional matrix; Based on the matrix element values mapped by the vertex coordinates of each triangular face, use bilinear interpolation to calculate the values corresponding to any point within the triangular face, and combine them to obtain a numerical matrix; Perform singular value decomposition on the numerical matrix, extract the singular values therein, and recombine the singular values to obtain recombined singular values; Perform a hash operation on the recombined singular values to generate the hash encryption key.
7. An encryption system based on a symmetric cryptography algorithm, characterized in that, Includes: A classification module for classifying the obtained sensitivity-related data to obtain structured sensitive data and unstructured sensitive data; A generation module for selecting key numerical fields from the structured sensitive data, inputting them into a preset Fermat primality test algorithm, screening out large prime numbers as basic key elements, and combining the basic key elements with a preset key combination rule to generate an encryption key; wherein, the preset Fermat primality test algorithm pre-optimizes the number of iterations and screening range for prime number determination; A first encryption module for encrypting the structured sensitive data based on the encryption key using a symmetric cryptography algorithm to obtain encrypted structured data; A second encryption module for encrypting the unstructured sensitive data to obtain encrypted unstructured data; An integration module for integrating the encrypted structured data and the encrypted unstructured data to generate simulation desensitized data; Encrypting the unstructured sensitive data to obtain encrypted unstructured data, including: For the unstructured sensitive data, a hash encryption key is generated by using a hash function; By using a symmetric cryptography algorithm, the unstructured sensitive data is encrypted based on the hash encryption key to obtain encrypted unstructured data; Generating a hash encryption key for the unstructured sensitive data by using a hash function includes: Performing a hash calculation on the unstructured sensitive data based on the hash function to obtain a hash value, and using each character in the hash value as a basic element of a matrix to construct a two-dimensional matrix; Extracting the sentence structure feature vector, low-frequency feature vector, and feature vector of a key frequency band of the unstructured sensitive data; the unstructured sensitive data includes text, image, and audio data; Mapping the sentence structure feature vector, low-frequency feature vector, and feature vector of the key frequency band into a three-dimensional space respectively, and constructing a triangular mesh surface through a triangulation algorithm according to the similarity and relevance between the feature vectors; Based on the triangular mesh surface and the two-dimensional matrix, the hash encryption key is generated.
8. A computer device, comprising a memory and a processor, wherein a computer program is stored in the memory, characterized in that, When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
Data processing method and device, server and medium
CN118827186A