Assessment report data encryption method, decryption method, computer equipment and readable storage medium based on national secrets

By adopting the hierarchical encryption method based on national secrets and secure tag signature technology in the data encryption of assessment report, the problem of insufficient security of existing encryption algorithms is solved, and efficient and secure assessment report data processing is achieved.

CN119892494BActive Publication Date: 2025-06-06SHENZHEN ZHONGHONG ONLINE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510353253.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-25
Publication Date
2025-06-06
Estimated Expiration
2045-03-25

AI Technical Summary

Technical Problem

Existing encryption algorithms have problems with insufficient security, especially when faced with advanced attacks, and there are problems with compatibility and stability.

Method used

The data encryption method of assessment report based on the National Secretariat is adopted. By obtaining the assessment report data, the data blocks to be encrypted at different levels are encrypted in a hierarchical manner, and a unique security mark is assigned to each encrypted data block, including metadata information. Then, the signed encrypted data block information is encrypted and sent through the first national secret algorithm and the encryption key configured by the system.

Benefits of technology

It improves data security and compatibility, prevents information from being tampered with, realizes the rapid generation of immutable assessment reports, and improves the stability and reliability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119892494B_ABST
    Figure CN119892494B_ABST
Patent Text Reader

Abstract

Assessment report data encryption method, decryption method, computer device and readable storage medium based on national secret. The embodiment of the present invention relates to the field of data security technology, and discloses an assessment report data encryption method based on national secret, the method comprising: obtaining assessment report information; hierarchically encrypting each different level of encrypted data block to obtain each first encrypted data block after encryption; assigning a security mark to each first encrypted data block, and associating the security mark with the first encrypted data block; signing the first encrypted data block according to the corresponding security mark, and obtaining the signed encrypted data block information; the signed encrypted data block information includes the first encrypted data block, the encryption summary corresponding to the first encrypted data block and the security mark; encrypting the signed encrypted data block information through the first national secret algorithm and the encryption key configured by the system, and sending it to the receiving end. The embodiment of the present invention can realize the rapid generation of immutable reports while improving the encryption security by using the security mark for digital signature.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention relate to the field of data security technology, and specifically to a method for encrypting assessment report data based on national secrets, a method for decrypting assessment report data based on national secrets, a computer device, and a computer-readable storage medium. Background Art

[0002] Currently, widely used encryption algorithms, such as AES, MD5, and SHA-1, have several significant technical flaws. First, some encryption algorithms have inherent security vulnerabilities in their design, which make the system vulnerable to cracking when facing advanced attacks, thereby threatening the integrity and confidentiality of information. Second, the implementation of some encryption algorithms depends on specific hardware or software environments. This dependence may cause compatibility and stability problems on different platforms. Furthermore, the security of encryption algorithms is often closely related to the frequency of their updates and maintenance, and some old or no longer supported encryption algorithms may face higher security risks due to the lack of timely updates. Summary of the invention

[0003] In view of the above problems, the embodiments of the present invention provide an assessment report data encryption method based on national secrets, an assessment report data decryption method based on national secrets, a computer device and a computer-readable storage medium, which are used to solve the problem of insufficient security of encryption algorithms in the prior art.

[0004] According to one aspect of an embodiment of the present invention, a method for encrypting assessment report data based on national encryption is provided, the method comprising:

[0005] Acquire assessment report data; the assessment report information includes assessment data and corresponding metadata information; the assessment data includes a plurality of data blocks to be encrypted classified according to different levels; the metadata information includes report information corresponding to each data block to be encrypted;

[0006] Performing hierarchical encryption on each of the different levels of the to-be-encrypted data blocks to obtain each first encrypted data block after encryption;

[0007] Allocate a unique security tag to each of the first encrypted data blocks, and associate each of the security tags with the first encrypted data block; the security tag includes metadata information corresponding to the first encrypted data block;

[0008] After signing the first encrypted data block according to the security mark, the signed encrypted data block information is obtained; the signed encrypted data block information includes the first encrypted data block, the encryption summary corresponding to the first encrypted data block and the security mark;

[0009] The signed encrypted data block information is encrypted using the first national secret algorithm and the encryption key configured by the system, and then sent to the receiving end.

[0010] In an optional manner, a unique security tag is assigned to each of the first encrypted data blocks, and each of the security tags is associated with the first encrypted data block; the security tag includes necessary metadata information corresponding to the first encrypted data block, including:

[0011] Encrypting metadata information corresponding to the first encrypted data block by using a third-country secret algorithm and an encryption key configured by the system to obtain encrypted metadata;

[0012] The encrypted metadata and the first public key are concatenated to obtain a concatenated encrypted string; wherein the first public key is generated by the receiving end using the fourth national encryption algorithm;

[0013] The concatenated encrypted string is shortened by base64 encoding to obtain a target encrypted string;

[0014] The target encrypted string is used as the security mark.

[0015] In an optional manner, after signing the first encrypted data block according to the security mark respectively, obtaining the signed encrypted data block information includes:

[0016] Encrypting the first encrypted data block using the fifth national encryption algorithm to obtain an initial summary;

[0017] The initial digest is encrypted using the first public key to obtain an encrypted digest.

[0018] In an optional manner, after using the target encrypted string as the security mark, the method further includes:

[0019] Determining the period of validity of the security mark;

[0020] When the preset usage period is exceeded, the safety mark is updated.

[0021] In an optional manner, the obtaining of assessment report data further includes:

[0022] Obtain data required for initial assessment report;

[0023] The data required for the initial assessment report is classified and pre-processed according to the importance of the data to obtain a plurality of data blocks to be encrypted at different levels.

[0024] In an optional manner, the different levels of data blocks to be encrypted include first-level data blocks to be encrypted, second-level data blocks to be encrypted, and third-level data blocks to be encrypted, which are ranked from high to low and whose group lengths are ranked from high to low; the step of performing hierarchical encryption on each of the different levels of data blocks to be encrypted to obtain each encrypted first encrypted data block includes:

[0025] Using the second national secret algorithm, the encryption key configured by the system and the first offset, the first level of the to-be-encrypted data block is encrypted to obtain a first encrypted data block corresponding to the first level of the to-be-encrypted data;

[0026] Using the second national secret encryption algorithm, the system configured encryption key and the second offset, encrypt the second level of the to-be-encrypted data block to obtain the first encrypted data block corresponding to the second level of the to-be-encrypted data;

[0027] The unencrypted data block to be encrypted at the third level is used as the first encrypted data block corresponding to the data block to be encrypted at the third level.

[0028] According to another aspect of an embodiment of the present invention, a method for decrypting assessment report data based on national encryption is provided, which is applied to a receiving end, and the method includes:

[0029] Receive data to be decrypted; the data to be decrypted is obtained by encrypting the signed encrypted data block information using the first national secret algorithm; the signed encrypted data block information includes the first encrypted data block, the encryption summary corresponding to the first encrypted data block and the security mark; the security mark includes the metadata information corresponding to the first encrypted data block; the encryption summary is obtained by signing the first encrypted data block according to the security mark; the first encrypted data block is obtained by hierarchically encrypting the data blocks to be encrypted; the data blocks to be encrypted are obtained by classifying the assessment data according to different levels;

[0030] After decrypting the decrypted data according to the system-configured encryption key corresponding to the first national secret algorithm, the first encrypted data block, the encryption summary and the security mark are obtained;

[0031] Performing data verification according to the security mark and the encryption summary;

[0032] When the verification passes, the first encrypted data block is decrypted in different levels to obtain decrypted data blocks of different levels;

[0033] Decrypting the security mark to obtain metadata information corresponding to each first encrypted data block;

[0034] The decrypted data blocks are combined according to the metadata information to obtain an immutable assessment report.

[0035] According to another aspect of an embodiment of the present invention, a device for encrypting assessment report data based on national encryption is provided, comprising:

[0036] An acquisition module, used to acquire assessment report information; the assessment report information includes assessment data and corresponding metadata information; the assessment data includes a plurality of data blocks to be encrypted classified according to different levels; the metadata information includes report information corresponding to each data block to be encrypted;

[0037] A hierarchical encryption module, used for hierarchically encrypting each to-be-encrypted data block of different levels to obtain each first encrypted data block after encryption;

[0038] A security tag module, configured to assign a unique security tag to each of the first encrypted data blocks, and associate each of the security tags with the first encrypted data block; the security tag includes metadata information corresponding to the first encrypted data block;

[0039] a signature module, configured to sign the first encrypted data block according to the security mark to obtain signed encrypted data block information; the signed encrypted data block information includes the first encrypted data block, an encrypted summary corresponding to the first encrypted data block and the security mark;

[0040] The sending module is used to encrypt the signed encrypted data block information using the first national secret algorithm and the encryption key configured by the system, and then send it to the receiving end.

[0041] According to another aspect of an embodiment of the present invention, there is provided a computer device, comprising: a processor, a memory, a communication interface and a communication bus, wherein the processor, the memory and the communication interface communicate with each other via the communication bus;

[0042] The memory is used to store at least one executable instruction, and the executable instruction enables the processor to execute the operation of the assessment report data encryption method based on national secrets or the assessment report data decryption method based on national secrets.

[0043] According to another aspect of an embodiment of the present invention, a computer-readable storage medium is provided, wherein the storage medium stores at least one executable instruction. When the executable instruction is executed on a computer device, the computer device executes the operation of the assessment report data encryption method based on national secrets or the assessment report data decryption method based on national secrets.

[0044] The embodiment of the present invention obtains the assessment report information, which includes the metadata information corresponding to the data block, performs hierarchical encryption on each different level of the to-be-encrypted data block, assigns a unique security tag to each encrypted data block, and associates each of the security tags with the encrypted data block. In addition, the metadata information corresponding to the encrypted data block is added to the security tag, and the first encrypted data block is signed according to the security tag to obtain the signed encrypted data block information, and the signed encrypted data block information is encrypted by the first national secret algorithm and the encryption key configured by the system and then sent to the receiving end. While being able to perform hierarchical encryption on the data, by adding the metadata element to the security tag, it is combined in the encryption process, so that the report information corresponding to each data block can be directly obtained after decryption, so that the data blocks can be quickly combined to generate a report according to the metadata information. Furthermore, by using the security tag to sign the encrypted block, the information is further prevented from being tampered with, and the security of the encryption is improved.

[0045] The above description is only an overview of the technical solution of the embodiment of the present invention. In order to more clearly understand the technical means of the embodiment of the present invention, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the embodiment of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are listed below. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] The accompanying drawings are only used to illustrate the embodiments and are not to be considered as limiting the present invention. In addition, the same reference symbols are used to represent the same components throughout the accompanying drawings. In the accompanying drawings:

[0047] Figure 1 A schematic diagram of the process of encrypting assessment report data based on national encryption provided by an embodiment of the present invention is shown;

[0048] Figure 2 A schematic diagram of the process of generating a security mark in the national encryption-based assessment report data encryption method provided in an embodiment of the present invention is shown;

[0049] Figure 3 A schematic diagram of the process of digital signature in the national encryption-based assessment report data encryption method provided in an embodiment of the present invention is shown;

[0050] Figure 4 A schematic diagram of a flow chart of a method for decrypting assessment report data based on national encryption provided by another embodiment of the present invention is shown;

[0051] Figure 5 The following is a schematic diagram showing the structure of a national encryption-based assessment report data encryption device provided by an embodiment of the present invention;

[0052] Figure 6A schematic diagram of the structure of a computer device provided by an embodiment of the present invention is shown. DETAILED DESCRIPTION

[0053] Exemplary embodiments of the present invention will be described in more detail below with reference to the accompanying drawings. Although exemplary embodiments of the present invention are shown in the drawings, it should be understood that the present invention can be implemented in various forms and should not be limited to the embodiments set forth herein.

[0054] At present, the pain points of the e-government assessment system mainly include system stability and security issues: the e-government assessment system needs to have a high degree of stability and security to ensure data security and the normal operation of the system. However, in actual applications, due to the influence of technology, network and other factors, the system may encounter some stability or security issues, such as data loss, system crash, etc. These problems may have a negative impact on the assessment results.

[0055] In order to solve these pain points, it is necessary to further strengthen the stability and security of the system and improve the transparency and other aspects. In response to the above pain points, the existing technical solutions are generally: most key technologies and core components rely on imports, such as Intel's CPU with X86 architecture, RedHat operating system, Oracle database, etc. At the same time, most application systems use encryption algorithms developed abroad, such as AES, MD5, SHA-1, etc.

[0056] However, the inventors of the present application have found that the currently widely used encryption algorithms have several significant technical defects. First, there are inherent security vulnerabilities in the design of some encryption algorithms, which make the system vulnerable to cracking when facing advanced attacks, thereby threatening the integrity and confidentiality of information. Secondly, the implementation of some encryption algorithms depends on specific hardware or software environments, and this dependence may cause compatibility and stability problems of the system on different platforms. Furthermore, the security of encryption algorithms is often closely related to the frequency of their updates and maintenance, and some old or no longer supported encryption algorithms may face higher security risks due to lack of timely updates. Although some encryption algorithms used in the assessment results may have been considered safe in the past, they have been found to have the above-mentioned technical defects over time. These defects may threaten the security of digital signatures, thereby affecting the security and reliability of the entire system.

[0057] Based on this, the embodiment of the present invention provides an assessment report data encryption method and decryption method based on national secrets. The method combines advanced cryptographic principles and efficient computing technology, can achieve rapid verification of signature data while ensuring data security, and improves the efficiency of assessment report generation. Through this method, the data integrity of the assessment results can be effectively checked and tampering can be prevented, providing a strong guarantee for the fairness and credibility of the electronic assessment system.

[0058] Figure 1 The flowchart of the assessment report data encryption method based on national encryption provided by an embodiment of the present invention is shown. The method is executed by a computer device as a sending end. The computer device can be a computer device, distributed device, intelligent terminal device, etc. that deploys a government affairs system and / or a government affairs assessment system, and the embodiment of the present invention does not make specific restrictions. Figure 1 As shown, the method comprises the following steps:

[0059] Step 110: Obtain assessment report information.

[0060] The assessment report information includes assessment data and corresponding metadata information. The assessment data includes multiple data blocks to be encrypted classified according to different levels; the metadata information includes report information corresponding to each data block to be encrypted, including the location and format information of the data block to be encrypted in the report, as well as the timestamp of the data to be encrypted, data source and other information.

[0061] The specific process of obtaining assessment report information includes:

[0062] Step 1102: Obtaining data required for the initial assessment report. According to the assessment report generation request, the corresponding time period and the data required for the initial assessment report are obtained from the government affairs system.

[0063] Step 1102: The data required for the initial assessment report is classified and preprocessed according to the importance of the data to obtain a plurality of different levels of data blocks to be encrypted. The different levels of data blocks to be encrypted include the first level of data blocks to be encrypted, the second level of data blocks to be encrypted, and the third level of data blocks to be encrypted, which are ranked from high to low and the packet length (data dimension) from high to low. Specifically, the embodiment of the present invention classifies the data required for the initial assessment report according to the importance. Generally, the assessment report information items include the assessment year, assessment department, person to be assessed, assessment items, and scores. The assessment report ledger information items will also include event titles, issuance time, scoring rules, etc. As shown in Table 1, the levels are divided from high to low into the first level of data blocks to be encrypted, the second level of data blocks to be encrypted, and the third level of data blocks to be encrypted; the first level of data blocks to be encrypted includes data corresponding to information items such as the assessment department, person to be assessed, event title, and issuance time; the second level of data blocks to be encrypted includes data corresponding to information items such as assessment items, scoring rules, and scores; the third level of data blocks to be encrypted includes data corresponding to the information item of the assessment year. It can be seen that the first level of data blocks to be encrypted has more data items than the second level of data blocks to be encrypted, and the second level of data blocks to be encrypted has more data items than the third level of data blocks to be encrypted, that is, the data dimension of the higher level is greater than the data dimension of the lower level.

[0064] Table 1:

[0065] Security Level Information Items First level Assessment department, person being assessed, event title, issuance time Second level Assessment items, scoring rules, and scores Third Level Assessment Year

[0066] Step 120: Perform hierarchical encryption on each of the different levels of the to-be-encrypted data blocks to obtain encrypted first encrypted data blocks.

[0067] In the embodiment of the present invention, in order to balance data security and data processing efficiency, different security protection measures are taken for data blocks to be encrypted at different security levels according to the data security classification to ensure the integrity and accuracy of the data.

[0068] In one embodiment of the present invention, the first-level data block to be encrypted is encrypted using the second national secret algorithm, the encryption key configured by the system, and the first offset to obtain the first encrypted data block corresponding to the first-level data to be encrypted. The second-level data block to be encrypted is encrypted using the second national secret encryption algorithm, the encryption key configured by the system, and the second offset to obtain the first encrypted data block corresponding to the second-level data to be encrypted. The unencrypted third-level data block to be encrypted is used as the first encrypted data block corresponding to the third-level data block to be encrypted. Due to the different data dimensions (i.e., packet lengths), when the second national secret algorithm is used to encrypt the first-level data block to be encrypted and the second-level data block to be encrypted, different offsets need to be made according to the packet length. As can be seen from Table 1, the data dimension of the first-level data block to be encrypted is greater than the data dimension of the second-level data block to be encrypted, so the two can be encrypted using the same national secret algorithm. Since the packet lengths of the two are different, although the same algorithm is used for encryption, the security of the first-level data block to be encrypted is still higher than the security of the second-level data block to be encrypted. The second national secret algorithm may be any one of the existing national secret algorithms. In the embodiment of the present invention, for example, it may be the national secret SM4 algorithm. The domestic SM4 encryption algorithm is a group symmetric encryption algorithm. The first offset is determined according to the packet length of the first-level data block to be encrypted, and the second offset is determined according to the packet length of the second-level data block to be encrypted. Since the encryption security requirements of the third-level data block to be encrypted are relatively low, the unencrypted third-level data block to be encrypted is used as the first encrypted data block corresponding to the third-level data block to be encrypted.

[0069] Step 130: Allocate a unique security tag to each of the first encrypted data blocks, and associate each of the security tags with the first encrypted data blocks.

[0070] The security tag includes metadata information corresponding to the first encrypted data block. A security tag is assigned to each encrypted data block, and the security tag is used to verify the integrity and source of the data to prevent the data from being tampered with.

[0071] Specifically, Figure 2 As shown, in one embodiment of the present invention, the specific process of generating a security mark includes:

[0072] Step 210: Encrypt the metadata information corresponding to the first encrypted data block using a third-country secret algorithm and an encryption key configured by the system to obtain encrypted metadata.

[0073] Among them, the third national secret algorithm is any one of the existing national secret algorithms. For example, in one embodiment of the present invention, it can be the SM1 algorithm (the SM1 algorithm is a group symmetric encryption algorithm, and the algorithm security and confidentiality strength is equivalent to AES, but the algorithm is not public) or the SM4 algorithm and the encryption key configured by the system to encrypt the metadata information corresponding to the first encrypted data block to obtain encrypted metadata.

[0074] Step 220: Concatenate the encrypted metadata and the first public key to obtain a concatenated encrypted string. The first public key is generated by the receiving end using the fourth national encryption algorithm in advance and the corresponding first private key, and the first public key is sent to the receiving end. The fourth national encryption algorithm is any one of the existing national encryption algorithms, for example, in one embodiment of the present invention, it can be the SM2 algorithm.

[0075] Among them, the system uses a pseudo-random number generator in cryptography to generate an encryption key configured by the system. The encryption key is the system identifier sent, which is used by the receiving end to confirm whether the data comes from the sending end. In an embodiment of the present invention, the encryption metadata, the first public key and the encryption key configured by the system are spliced ​​according to a preset splicing format to obtain a spliced ​​encrypted string. As a result, the security mark contains both the source information of the first encrypted data block (encryption metadata) and the mutual recognition of the system (encryption key configured by the system).

[0076] Step 240: shorten the concatenated encrypted string by base64 encoding to obtain a target encrypted string. Since the concatenated encrypted string is composed of multiple pieces of information, its string is relatively long. In order to simplify data and improve data transmission efficiency, the embodiment of the present invention also shortens the length of the concatenated encrypted string by base64 encoding to obtain the final target encrypted string.

[0077] Step 250: Use the target encrypted string as the security mark.

[0078] In order to improve the security of system encryption, the embodiment of the present invention also regularly determines the service life of the security mark; when the preset service life is exceeded, the security mark is updated. Specifically, the service life refers to the service life of the encryption key configured by the system. When the encryption key configured by the system exceeds the preset service life, a pseudo-random number generator in cryptography is used to regenerate a new encryption key configured by the system, thereby updating the security mark.

[0079] Step 140: After signing the first encrypted data block according to the security mark, the signed encrypted data block information is obtained.

[0080] The signed encrypted data block information includes the first encrypted data block, the encrypted summary corresponding to the first encrypted data block and the security mark.

[0081] In an embodiment of the present invention, a security mark is used to sign the first encrypted data block, and the signing process includes: encrypting the first encrypted data block through the fifth national secret algorithm to obtain an initial summary; encrypting the initial summary using the first public key to obtain an encrypted summary. The fifth national secret algorithm can be any one of the national secret algorithms. For example, in an embodiment of the present invention, it can be SM3 (one-way hash algorithm). Specifically, Figure 3 As shown, the specific process of signing the first encrypted data block according to the security mark is: the first encrypted data block is processed by a one-way hash function to obtain an initial summary of 256 bits. Among them, the first encrypted data block and the summary of the first encrypted data block have a strong correspondence. As long as the first encrypted data block is changed, the summary obtained after the one-way hash function processing will be different. The sending end uses the first public key sent in advance by the receiving end (that is, the first public key generated in the security mark process generated in the above steps) to encrypt the initial summary to obtain an encrypted summary. The sending end sends the first encrypted data block, the encrypted summary and the security mark to the receiving end together.

[0082] Step 150: Encrypt the signed encrypted data block information using the first national encryption algorithm and the encryption key configured by the system, and send it to the receiving end.

[0083] Among them, the first national secret algorithm can be an existing national secret algorithm, and in the embodiment of the present invention, it is an SM4 algorithm. The sending end encrypts the signed encrypted data block information through the first national secret algorithm and the encryption key configured by the system, and transmits the assessment data to the receiving end through a domestic security channel. The receiving end receives the encrypted assessment data, decrypts it using the national secret SM4 to obtain the signed encrypted data block information, verifies the signature by the security mark, and decrypts the first encrypted data block to obtain the decrypted assessment data. According to the decrypted assessment data and the metadata information in the security mark, determine the position and format of each assessment in the report, and generate an immutable assessment report. Specifically, the receiving end receives the format and decoding method information of the security mark of the sending end in advance. After the receiving end obtains the signed encrypted data block information, it decodes it according to the preset format and decoding method to obtain the first public key and metadata information.

[0084] The embodiment of the present invention obtains assessment report information, and the assessment data includes metadata information corresponding to the data block, hierarchically encrypts each different level of the to-be-encrypted data block, assigns a unique security tag to each encrypted data block, and associates each of the security tags with the encrypted data block. In addition, the metadata information corresponding to the encrypted data block is added to the security tag, and the first encrypted data block is signed according to the security tag to obtain the signed encrypted data block information, and the signed encrypted data block information is encrypted by the first national secret algorithm and the encryption key configured by the system and sent to the receiving end. While being able to perform hierarchical encryption on the data, by adding metadata elements to the security tag, it is combined in the encryption process, so that the report information corresponding to each data block can be directly obtained after decryption, so that the data blocks can be quickly combined to generate a report according to the metadata information. Furthermore, by using the security tag to sign the encrypted block, the information is further prevented from being tampered with, and the security of the encryption is improved.

[0085] Figure 4 The flowchart of the assessment report data decryption method based on national encryption provided by another embodiment of the present invention is shown. The method is executed by a computer device as a receiving end. The computer device can be a computer device, distributed device, intelligent terminal device, etc. deployed with a government affairs system and / or a government affairs assessment system, and the embodiment of the present invention does not make specific restrictions. Figure 4 As shown, the method comprises the following steps:

[0086] Step 410: Receive data to be decrypted.

[0087] Among them, the data to be decrypted is obtained by encrypting the signed encrypted data block information with the first national secret algorithm. The signed encrypted data block information includes the first encrypted data block, the encryption summary corresponding to the first encrypted data block and the security mark; the security mark includes the metadata information corresponding to the first encrypted data block; the encryption summary is obtained by signing the first encrypted data block according to the security mark. The first encrypted data block is obtained by hierarchical encryption of the encrypted data block; the encrypted data block is obtained by classifying the assessment data according to different levels. Among them, the data to be decrypted is implemented by the assessment report data encryption method based on national secrets of the aforementioned embodiment, so the assessment report data decryption method based on national secrets is the reverse operation of the aforementioned assessment report data encryption method based on national secrets.

[0088] Step 420: After decrypting the decrypted data according to the first national encryption algorithm, the first encrypted data block, the encryption summary and the security mark are obtained.

[0089] Wherein, when the signed encrypted data block information is encrypted by the first national secret algorithm, it is encrypted by the first national secret algorithm and the system configuration encryption key. Here, the decrypted data is decrypted by the first national secret algorithm and the system configuration encryption key to obtain the first encrypted data block, the encryption summary and the security mark. Wherein, the security mark includes the concatenated encrypted string obtained by concatenating the encrypted metadata and the first public key. Wherein, the receiving end pre-receives the format and decoding method information of the security mark of the sending end. After the receiving end obtains the signed encrypted data block information, the security mark is decoded according to the preset format and decoding method to obtain the first public key and the encrypted metadata.

[0090] Step 430: Perform data verification based on the security mark and the encryption summary.

[0091] The encrypted summary is decrypted according to the fourth national secret algorithm and the first private key corresponding to the first public key pre-generated by the aforementioned receiving end itself to obtain the initial summary.

[0092] Among them, the first encrypted data block is signed by the fifth national secret algorithm to obtain a verification signature. Determine whether the verification signature is consistent with the initial summary obtained after decrypting the encrypted summary. If they are consistent, it is determined that the data has not been tampered with. If they are inconsistent, it is determined that the data has been tampered with.

[0093] In the embodiment of the present invention, the receiving end also determines whether the data is sent by the sending end according to the received encryption key of the system configuration. Specifically, the receiving end compares the received encryption key of the system configuration with the encryption key of the receiving end stored in advance, and determines that the data is sent by the sending end when they are consistent.

[0094] Step 440: When the verification passes, the first encrypted data block is decrypted in a hierarchical manner to obtain decrypted data blocks of different levels.

[0095] When the verification is passed, each first encrypted data block is decrypted according to the inverse operation of the hierarchical encryption to obtain decrypted data blocks of different levels.

[0096] Step 450: Decrypt the security tag to obtain metadata information corresponding to each first encrypted data block.

[0097] The encrypted metadata is decrypted according to a third-country encryption algorithm to obtain metadata information corresponding to the first encrypted data block.

[0098] Step 460: Combine the decrypted data blocks according to the metadata information to obtain an immutable assessment report.

[0099] Among them, the receiving end determines the position and format of each assessment in the report according to the decrypted assessment data and metadata information in the security mark, and generates an immutable assessment report. In the embodiment of the present invention, when generating an immutable assessment report, an electronic signature will be generated according to the signature information, and the electronic signature will be displayed on the report page, so that the digital signature of the immutable assessment report is more intuitive and visually displayed to the user, which improves the fairness and credibility of the electronic assessment and effectively improves the user experience.

[0100] The embodiment of the present invention obtains assessment report information, and the assessment data includes metadata information corresponding to the data block, hierarchically encrypts each different level of the to-be-encrypted data block, assigns a unique security tag to each encrypted data block, and associates each of the security tags with the encrypted data block. In addition, the metadata information corresponding to the encrypted data block is added to the security tag, and the first encrypted data block is signed according to the security tag to obtain the signed encrypted data block information, and the signed encrypted data block information is encrypted by the first national secret algorithm and the encryption key configured by the system and sent to the receiving end. While being able to perform hierarchical encryption on the data, by adding metadata elements to the security tag, it is combined in the encryption process, so that the report information corresponding to each data block can be directly obtained after decryption, so that the data blocks can be quickly combined to generate a report according to the metadata information. Furthermore, by using the security tag to sign the encrypted block, the information is further prevented from being tampered with, and the security of the encryption is improved.

[0101] Figure 5 The schematic diagram of the structure of the assessment report data encryption device based on national encryption provided by the embodiment of the present invention is shown. Figure 5 As shown, the device 500 includes:

[0102] The acquisition module 510 is used to acquire the assessment report information; the assessment report information includes assessment data and corresponding metadata information; the assessment data includes a plurality of data blocks to be encrypted classified according to different levels; the metadata information includes report information corresponding to each data block to be encrypted;

[0103] A hierarchical encryption module 520 is used to hierarchically encrypt each of the different levels of the to-be-encrypted data blocks to obtain the encrypted first encrypted data blocks;

[0104] A security tag module 530 is used to assign a unique security tag to each of the first encrypted data blocks, and associate each of the security tags with the first encrypted data block; the security tag includes metadata information corresponding to the first encrypted data block;

[0105] The signing module 540 is used to sign the first encrypted data block according to the security mark to obtain the signed encrypted data block information; the signed encrypted data block information includes the first encrypted data block, the encryption summary corresponding to the first encrypted data block and the security mark;

[0106] The sending module 550 is used to encrypt the signed encrypted data block information using the first national encryption algorithm and the encryption key configured by the system, and then send it to the receiving end.

[0107] In an optional manner, a unique security tag is assigned to each of the first encrypted data blocks, and each of the security tags is associated with the first encrypted data block; the security tag includes necessary metadata information corresponding to the first encrypted data block, including:

[0108] Encrypting metadata information corresponding to the first encrypted data block by using a third-country secret algorithm and an encryption key configured by the system to obtain encrypted metadata;

[0109] The encrypted metadata and the first public key are concatenated to obtain a concatenated encrypted string; wherein the first public key is generated by the receiving end using the fourth national encryption algorithm;

[0110] The concatenated encrypted string is shortened by base64 encoding to obtain a target encrypted string;

[0111] The target encrypted string and the first private key are used as the security mark.

[0112] In an optional manner, after signing the first encrypted data block according to the security mark respectively, obtaining the signed encrypted data block information includes:

[0113] Encrypting the first encrypted data block using the fifth national encryption algorithm to obtain an initial summary;

[0114] The initial digest is encrypted using the first public key to obtain an encrypted digest.

[0115] In an optional manner, after using the target encrypted string and the first private key as the security mark, the device further includes:

[0116] A determination module, used to determine the useful life of the security mark;

[0117] The updating module is used to update the security mark when the preset usage period is exceeded.

[0118] In an optional manner, the obtaining of the assessment report information further includes:

[0119] Obtain data required for initial assessment report;

[0120] The data required for the initial assessment report is classified and pre-processed according to the importance of the data to obtain a plurality of data blocks to be encrypted at different levels.

[0121] In an optional manner, the different levels of data blocks to be encrypted include first-level data blocks to be encrypted, second-level data blocks to be encrypted, and third-level data blocks to be encrypted, which are ranked from high to low and whose group lengths are ranked from high to low; the step of performing hierarchical encryption on each of the different levels of data blocks to be encrypted to obtain each encrypted first encrypted data block includes:

[0122] Using the second national secret algorithm, the encryption key configured by the system and the first offset, the first level of the to-be-encrypted data block is encrypted to obtain a first encrypted data block corresponding to the first level of the to-be-encrypted data;

[0123] Using the second national secret encryption algorithm, the system configured encryption key and the second offset, encrypt the second level of the to-be-encrypted data block to obtain the first encrypted data block corresponding to the second level of the to-be-encrypted data;

[0124] The unencrypted data block to be encrypted at the third level is used as the first encrypted data block corresponding to the data block to be encrypted at the third level.

[0125] The specific working process of the device in the embodiment of the present invention is generally consistent with the specific steps of the assessment report data encryption method based on national secrets in the aforementioned embodiment, and will not be repeated here.

[0126] The embodiment of the present invention obtains assessment report information, and the assessment data includes metadata information corresponding to the data block, hierarchically encrypts each different level of the to-be-encrypted data block, assigns a unique security tag to each encrypted data block, and associates each of the security tags with the encrypted data block. In addition, the metadata information corresponding to the encrypted data block is added to the security tag, and the first encrypted data block is signed according to the security tag to obtain the signed encrypted data block information, and the signed encrypted data block information is encrypted by the first national secret algorithm and the encryption key configured by the system and sent to the receiving end. While being able to perform hierarchical encryption on the data, by adding metadata elements to the security tag, it is combined in the encryption process, so that the report information corresponding to each data block can be directly obtained after decryption, so that the data blocks can be quickly combined to generate a report according to the metadata information. Furthermore, by using the security tag to sign the encrypted block, the information is further prevented from being tampered with, and the security of the encryption is improved.

[0127] Figure 6The schematic diagram of the structure of the computer device provided by the embodiment of the present invention is shown. The specific embodiment of the present invention does not limit the specific implementation of the computer device.

[0128] like Figure 6 As shown, the computer device may include: a processor (processor) 602 , a communication interface (Communications Interface) 604 , a memory (memory) 606 , and a communication bus 608 .

[0129] Wherein: the processor 602, the communication interface 604, and the memory 606 communicate with each other through the communication bus 608. The communication interface 604 is used to communicate with other devices such as a client or a network element of another server. The processor 602 is used to execute the program 610, which can specifically execute the relevant steps in the above-mentioned method for encrypting assessment report data based on national secrets or the method for decrypting assessment report data based on national secrets.

[0130] Specifically, the program 610 may include program code including computer executable instructions.

[0131] The processor 602 may be a central processing unit (CPU), or an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiment of the present invention. The one or more processors included in the computer device may be processors of the same type, such as one or more CPUs; or processors of different types, such as one or more CPUs and one or more ASICs.

[0132] The memory 606 is used to store the program 610. The memory 606 may include a high-speed RAM memory, and may also include a non-volatile memory (non-volatile memory), such as at least one disk memory.

[0133] The program 610 may be specifically called by the processor 602 to enable the computer device to perform the following operations:

[0134] Acquire assessment report information; the assessment report information includes assessment data and corresponding metadata information; the assessment data includes a plurality of data blocks to be encrypted classified according to different levels; the metadata information includes report information corresponding to each data block to be encrypted;

[0135] Performing hierarchical encryption on each of the different levels of the to-be-encrypted data blocks to obtain each first encrypted data block after encryption;

[0136] Allocate a unique security tag to each of the first encrypted data blocks, and associate each of the security tags with the first encrypted data block; the security tag includes metadata information corresponding to the first encrypted data block;

[0137] After signing the first encrypted data block according to the security mark, the signed encrypted data block information is obtained; the signed encrypted data block information includes the first encrypted data block, the encryption summary corresponding to the first encrypted data block and the security mark;

[0138] The signed encrypted data block information is encrypted using the first national secret algorithm and the encryption key configured by the system, and then sent to the receiving end;

[0139] and / or,

[0140] Receive data to be decrypted; the data to be decrypted is obtained by encrypting the signed encrypted data block information using a first national secret algorithm; the signed encrypted data block information includes a first encrypted data block, an encrypted summary corresponding to the first encrypted data block, and a security mark; the security mark includes metadata information corresponding to the first encrypted data block; the encrypted summary is obtained by signing the first encrypted data block according to the security mark;

[0141] After decrypting the decrypted data according to the first national secret algorithm, the first encrypted data block, the encryption summary and the security mark are obtained;

[0142] Performing data verification according to the security mark and the encryption summary;

[0143] When the verification passes, the first encrypted data block is decrypted in different levels to obtain decrypted data blocks of different levels;

[0144] Decrypting the security mark to obtain metadata information corresponding to each first encrypted data block;

[0145] The decrypted data blocks are combined according to the metadata information to obtain an immutable assessment report.

[0146] In an optional manner, a unique security tag is assigned to each of the first encrypted data blocks, and each of the security tags is associated with the first encrypted data block; the security tag includes necessary metadata information corresponding to the first encrypted data block, including:

[0147] Encrypting metadata information corresponding to the first encrypted data block by using a third-country secret algorithm and an encryption key configured by the system to obtain encrypted metadata;

[0148] The encrypted metadata and the first public key are concatenated to obtain a concatenated encrypted string; wherein the first public key is generated by the receiving end using the fourth national encryption algorithm;

[0149] The concatenated encrypted string is shortened by base64 encoding to obtain a target encrypted string;

[0150] The target encrypted string and the first private key are used as the security mark.

[0151] In an optional manner, after signing the first encrypted data block according to the security mark respectively, obtaining the signed encrypted data block information includes:

[0152] Encrypting the first encrypted data block using the fifth national encryption algorithm to obtain an initial summary;

[0153] The initial digest is encrypted using the first public key to obtain an encrypted digest.

[0154] In an optional manner, after using the target encrypted string and the first private key as the security mark, the method further includes:

[0155] Determining the period of validity of the security mark;

[0156] When the preset usage period is exceeded, the safety mark is updated.

[0157] In an optional manner, the obtaining of the assessment report information further includes:

[0158] Obtain data required for initial assessment report;

[0159] The data required for the initial assessment report is classified and pre-processed according to the importance of the data to obtain a plurality of data blocks to be encrypted at different levels.

[0160] In an optional manner, the different levels of data blocks to be encrypted include first-level data blocks to be encrypted, second-level data blocks to be encrypted, and third-level data blocks to be encrypted, which are ranked from high to low and whose group lengths are ranked from high to low; the step of performing hierarchical encryption on each of the different levels of data blocks to be encrypted to obtain each encrypted first encrypted data block includes:

[0161] Using the second national secret algorithm, the encryption key configured by the system and the first offset, the first level of the to-be-encrypted data block is encrypted to obtain a first encrypted data block corresponding to the first level of the to-be-encrypted data;

[0162] Using the second national secret encryption algorithm, the system configured encryption key and the second offset, encrypt the second level of the to-be-encrypted data block to obtain the first encrypted data block corresponding to the second level of the to-be-encrypted data;

[0163] The unencrypted data block to be encrypted at the third level is used as the first encrypted data block corresponding to the data block to be encrypted at the third level.

[0164] According to another aspect of an embodiment of the present invention, a method for decrypting assessment report data based on national encryption is provided, which is applied to a receiving end, and the method includes:

[0165] Receive data to be decrypted; the data to be decrypted is obtained by encrypting the signed encrypted data block information using the first national secret algorithm; the signed encrypted data block information includes the first encrypted data block, the encryption summary corresponding to the first encrypted data block and the security mark; the security mark includes the metadata information corresponding to the first encrypted data block; the encryption summary is obtained by signing the first encrypted data block according to the security mark; the first encrypted data block is obtained by hierarchically encrypting the data blocks to be encrypted; the data blocks to be encrypted are obtained by classifying the assessment data according to different levels;

[0166] After decrypting the decrypted data according to the first national secret algorithm, the first encrypted data block, the encryption summary and the security mark are obtained;

[0167] Performing data verification according to the security mark and the encryption summary;

[0168] When the verification passes, the first encrypted data block is decrypted in different levels to obtain decrypted data blocks of different levels;

[0169] Decrypting the security mark to obtain metadata information corresponding to each first encrypted data block;

[0170] The decrypted data blocks are combined according to the metadata information to obtain an immutable assessment report.

[0171] The embodiment of the present invention obtains assessment report information, and the assessment data includes metadata information corresponding to the data block, hierarchically encrypts each different level of the to-be-encrypted data block, assigns a unique security tag to each encrypted data block, and associates each of the security tags with the encrypted data block. In addition, the metadata information corresponding to the encrypted data block is added to the security tag, and the first encrypted data block is signed according to the security tag to obtain the signed encrypted data block information, and the signed encrypted data block information is encrypted by the first national secret algorithm and the encryption key configured by the system and sent to the receiving end. While being able to perform hierarchical encryption on the data, by adding metadata elements to the security tag, it is combined in the encryption process, so that the report information corresponding to each data block can be directly obtained after decryption, so that the data blocks can be quickly combined to generate a report according to the metadata information. Furthermore, by using the security tag to sign the encrypted block, the information is further prevented from being tampered with, and the security of the encryption is improved.

[0172] An embodiment of the present invention provides a computer-readable storage medium, which stores at least one executable instruction. When the executable instruction is executed on a computer device, the computer device executes the assessment report data encryption method based on national secrets or the assessment report data decryption method based on national secrets in any of the above-mentioned method embodiments.

[0173] The executable instructions can be specifically used to cause the computer device to perform the following operations:

[0174] Acquire assessment report information; the assessment report information includes assessment data and corresponding metadata information; the assessment data includes a plurality of data blocks to be encrypted classified according to different levels; the metadata information includes report information corresponding to each data block to be encrypted;

[0175] Performing hierarchical encryption on each of the different levels of the to-be-encrypted data blocks to obtain each first encrypted data block after encryption;

[0176] Allocate a unique security tag to each of the first encrypted data blocks, and associate each of the security tags with the first encrypted data block; the security tag includes metadata information corresponding to the first encrypted data block;

[0177] After signing the first encrypted data block according to the security mark, the signed encrypted data block information is obtained; the signed encrypted data block information includes the first encrypted data block, the encryption summary corresponding to the first encrypted data block and the security mark;

[0178] The signed encrypted data block information is encrypted using the first national secret algorithm and the encryption key configured by the system, and then sent to the receiving end;

[0179] and / or,

[0180] Receive data to be decrypted; the data to be decrypted is obtained by encrypting the signed encrypted data block information using a first national secret algorithm; the signed encrypted data block information includes a first encrypted data block, an encrypted summary corresponding to the first encrypted data block, and a security mark; the security mark includes metadata information corresponding to the first encrypted data block; the encrypted summary is obtained by signing the first encrypted data block according to the security mark;

[0181] After decrypting the decrypted data according to the first national secret algorithm, the first encrypted data block, the encryption summary and the security mark are obtained;

[0182] Performing data verification according to the security mark and the encryption summary;

[0183] When the verification passes, the first encrypted data block is decrypted in different levels to obtain decrypted data blocks of different levels;

[0184] Decrypting the security mark to obtain metadata information corresponding to each first encrypted data block;

[0185] The decrypted data blocks are combined according to the metadata information to obtain an immutable assessment report.

[0186] In an optional manner, a unique security tag is assigned to each of the first encrypted data blocks, and each of the security tags is associated with the first encrypted data block; the security tag includes necessary metadata information corresponding to the first encrypted data block, including:

[0187] Encrypting metadata information corresponding to the first encrypted data block by using a third-country secret algorithm and an encryption key configured by the system to obtain encrypted metadata;

[0188] The encrypted metadata and the first public key are concatenated to obtain a concatenated encrypted string; wherein the first public key is generated by the receiving end using the fourth national encryption algorithm;

[0189] The concatenated encrypted string is shortened by base64 encoding to obtain a target encrypted string;

[0190] The target encrypted string and the first private key are used as the security mark.

[0191] In an optional manner, after signing the first encrypted data block according to the security mark respectively, obtaining the signed encrypted data block information includes:

[0192] Encrypting the first encrypted data block using the fifth national encryption algorithm to obtain an initial summary;

[0193] The initial digest is encrypted using the first public key to obtain an encrypted digest.

[0194] In an optional manner, after using the target encrypted string and the first private key as the security mark, the method further includes:

[0195] Determining the period of validity of the security mark;

[0196] When the preset usage period is exceeded, the safety mark is updated.

[0197] In an optional manner, the obtaining of the assessment report information further includes:

[0198] Obtain data required for initial assessment report;

[0199] The data required for the initial assessment report is classified and pre-processed according to the importance of the data to obtain a plurality of data blocks to be encrypted at different levels.

[0200] In an optional manner, the different levels of data blocks to be encrypted include first-level data blocks to be encrypted, second-level data blocks to be encrypted, and third-level data blocks to be encrypted, which are ranked from high to low and whose group lengths are ranked from high to low; the step of performing hierarchical encryption on each of the different levels of data blocks to be encrypted to obtain each encrypted first encrypted data block includes:

[0201] Using the second national secret algorithm, the encryption key configured by the system and the first offset, the first level of the to-be-encrypted data block is encrypted to obtain a first encrypted data block corresponding to the first level of the to-be-encrypted data;

[0202] Using the second national secret encryption algorithm, the system configured encryption key and the second offset, encrypt the second level of the to-be-encrypted data block to obtain the first encrypted data block corresponding to the second level of the to-be-encrypted data;

[0203] The unencrypted data block to be encrypted at the third level is used as the first encrypted data block corresponding to the data block to be encrypted at the third level.

[0204] According to another aspect of an embodiment of the present invention, a method for decrypting assessment report data based on national encryption is provided, which is applied to a receiving end, and the method includes:

[0205] Receive data to be decrypted; the data to be decrypted is obtained by encrypting the signed encrypted data block information using a first national secret algorithm; the signed encrypted data block information includes a first encrypted data block, an encrypted summary corresponding to the first encrypted data block, and a security mark; the security mark includes metadata information corresponding to the first encrypted data block; the encrypted summary is obtained by signing the first encrypted data block according to the security mark;

[0206] After decrypting the decrypted data according to the first national secret algorithm, the first encrypted data block, the encryption summary and the security mark are obtained;

[0207] Performing data verification according to the security mark and the encryption summary;

[0208] When the verification passes, the first encrypted data block is decrypted in different levels to obtain decrypted data blocks of different levels;

[0209] Decrypting the security mark to obtain metadata information corresponding to each first encrypted data block;

[0210] The decrypted data blocks are combined according to the metadata information to obtain an immutable assessment report.

[0211] The embodiment of the present invention obtains assessment report information, and the assessment data includes metadata information corresponding to the data block, hierarchically encrypts each different level of the to-be-encrypted data block, assigns a unique security tag to each encrypted data block, and associates each of the security tags with the encrypted data block. In addition, the metadata information corresponding to the encrypted data block is added to the security tag, and the first encrypted data block is signed according to the security tag to obtain the signed encrypted data block information, and the signed encrypted data block information is encrypted by the first national secret algorithm and the encryption key configured by the system and sent to the receiving end. While being able to perform hierarchical encryption on the data, by adding metadata elements to the security tag, it is combined in the encryption process, so that the report information corresponding to each data block can be directly obtained after decryption, so that the data blocks can be quickly combined to generate a report according to the metadata information. Furthermore, by using the security tag to sign the encrypted block, the information is further prevented from being tampered with, and the security of the encryption is improved.

[0212] An embodiment of the present invention provides an assessment report data encryption device based on national secrets, which is used to execute the above-mentioned assessment report data encryption method based on national secrets.

[0213] An embodiment of the present invention provides an assessment report data decryption device based on national encryption, which is used to execute the above-mentioned assessment report data decryption method based on national encryption.

[0214] An embodiment of the present invention provides a computer program, which can be called by a processor to enable a computer device to execute the assessment report data encryption method based on national secrets or the assessment report data decryption method based on national secrets in any of the above method embodiments.

[0215] An embodiment of the present invention provides a computer program product, which includes a computer program stored on a computer-readable storage medium, and the computer program includes program instructions. When the program instructions are run on a computer, the computer executes the assessment report data encryption method based on national secrets or the assessment report data decryption method based on national secrets in any of the above method embodiments.

[0216] The algorithm or display provided herein is not inherently related to any particular computer, virtual system or other equipment. Various general purpose systems can also be used together with the teachings based on this. According to the above description, it is obvious to construct the structure required for this type of system. In addition, the embodiment of the present invention is not directed to any specific programming language yet. It should be understood that various programming languages ​​can be utilized to realize the content of the present invention described herein, and the description made to specific languages ​​above is for disclosing the best mode of the present invention.

[0217] In the description provided herein, a large number of specific details are described. However, it is understood that embodiments of the present invention can be practiced without these specific details. In some instances, well-known methods, structures and techniques are not shown in detail so as not to obscure the understanding of this description.

[0218] Similarly, it should be understood that in order to streamline the present invention and aid in understanding one or more of the various inventive aspects, in the above description of exemplary embodiments of the present invention, various features of the embodiments of the present invention are sometimes grouped together into a single embodiment, figure, or description thereof. However, this method of disclosure should not be interpreted as reflecting an intention that the claimed invention requires more features than those expressly recited in each claim.

[0219] Those skilled in the art will appreciate that the modules in the devices in the embodiments may be adaptively changed and set in one or more devices different from the embodiments. The modules or units or components in the embodiments may be combined into one module or unit or component, and may be divided into multiple submodules or subunits or subcomponents. All features disclosed in this specification (including the accompanying claims, abstracts and drawings) and all processes or units of any method or device disclosed in this manner may be combined in any combination, except that at least some of such features and / or processes or units are mutually exclusive. Unless otherwise expressly stated, each feature disclosed in this specification (including the accompanying claims, abstracts and drawings) may be replaced by an alternative feature that provides the same, equivalent or similar purpose.

[0220] It should be noted that the above embodiments illustrate the present invention rather than limit it, and that those skilled in the art may devise alternative embodiments without departing from the scope of the appended claims. In the claims, any reference symbol between brackets shall not be construed as a limitation on the claims. The word "comprising" does not exclude the presence of elements or steps not listed in the claims. The word "one" or "an" preceding an element does not exclude the presence of a plurality of such elements. The present invention may be implemented by means of hardware comprising a number of different elements and by means of a suitably programmed computer. In a unit claim enumerating a number of devices, several of these devices may be embodied by the same hardware item. The use of the words first, second, and third, etc. does not indicate any order. These words may be interpreted as names. The steps in the above embodiments, unless otherwise specified, should not be understood as limitations on the order of execution.

Claims

1. A method for encrypting assessment report data based on national secrets, characterized in that: The method is applied to a transmitting end, and the method comprises: Acquire assessment report information; the assessment report information includes assessment data and corresponding metadata information; the assessment data includes a plurality of data blocks to be encrypted classified according to different levels; the metadata information is used to characterize the report information corresponding to each data block to be encrypted; Performing hierarchical encryption on each of the different levels of the to-be-encrypted data blocks to obtain each first encrypted data block after encryption; Allocating a unique security tag to each of the first encrypted data blocks, and associating each of the security tags with the first encrypted data blocks, including: encrypting metadata information corresponding to the first encrypted data block by using a third-country encryption algorithm and an encryption key configured by the system to obtain encrypted metadata; splicing the encrypted metadata and the first public key to obtain a spliced ​​encrypted string; wherein the first public key is generated by the receiving end using a fourth-country encryption algorithm; shortening the spliced ​​encrypted string by using base64 encoding to obtain a target encrypted string; and using the target encrypted string as the security tag; After signing the first encrypted data block according to the corresponding security mark, the signed encrypted data block information is obtained; the signed encrypted data block information includes the first encrypted data block, the encryption summary corresponding to the first encrypted data block and the security mark; The signed encrypted data block information is encrypted using the first national secret algorithm and the encryption key configured by the system, and then sent to the receiving end.

2. The method according to claim 1, characterized in that After signing the first encrypted data block according to the security mark respectively, obtaining the signed encrypted data block information includes: Encrypting the first encrypted data block using the fifth national encryption algorithm to obtain an initial summary; The initial digest is encrypted using the first public key to obtain an encrypted digest.

3. The method according to claim 1, characterized in that: After using the target encrypted string as the security mark, the method further includes: Determining the period of validity of the security mark; When the preset usage period is exceeded, the safety mark is updated.

4. The method according to any one of claims 1 to 3, characterized in that: The obtaining of the assessment report information also includes: Obtain data required for initial assessment report; The data required for the initial assessment report is classified and pre-processed according to the importance of the data to obtain a plurality of data blocks to be encrypted at different levels.

5. The method according to any one of claims 1 to 3, characterized in that: The data blocks to be encrypted at different levels include the first level of data blocks to be encrypted, the second level of data blocks to be encrypted and the third level of data blocks to be encrypted, which are arranged in descending order of level and group length; The step of performing hierarchical encryption on each of the different levels of the to-be-encrypted data blocks to obtain the encrypted first encrypted data blocks includes: Using the second national secret algorithm, the encryption key configured by the system and the first offset, the first level of the to-be-encrypted data block is encrypted to obtain a first encrypted data block corresponding to the first level of the to-be-encrypted data; Using the second national secret algorithm, the encryption key configured by the system and the second offset, the second level of the to-be-encrypted data block is encrypted to obtain a first encrypted data block corresponding to the second level of the to-be-encrypted data; The unencrypted data block to be encrypted at the third level is used as the first encrypted data block corresponding to the data block to be encrypted at the third level.

6. A method for decrypting assessment report data based on national secrets, characterized in that: Applied to the receiving end, the method comprises: Receive data to be decrypted; the data to be decrypted is obtained by encrypting the signed encrypted data block information with the first national secret algorithm; the signed encrypted data block information includes the first encrypted data block, the encrypted summary corresponding to the first encrypted data block and the security mark; wherein, the metadata information corresponding to the first encrypted data block is encrypted by the third national secret algorithm and the encryption key configured by the system to obtain the encrypted metadata; the encrypted metadata and the first public key are spliced ​​to obtain a spliced ​​encrypted string; wherein, the first public key is generated by the receiving end using the fourth national secret algorithm; the spliced ​​encrypted string is shortened by base64 encoding to obtain a target encrypted string; the target encrypted string is used as the security mark; the encrypted summary is obtained by signing the first encrypted data block according to the security mark; the first encrypted data block is obtained by hierarchical encryption of the data block to be encrypted; the data block to be encrypted is obtained by classifying the assessment data according to different levels; After decrypting the decrypted data according to the system-configured encryption key corresponding to the first national secret algorithm, the first encrypted data block, the encryption summary and the security mark are obtained; Performing data verification according to the security mark and the encryption summary; When the verification passes, the first encrypted data block is decrypted in different levels to obtain decrypted data blocks of different levels; Decrypting the security mark to obtain metadata information corresponding to each first encrypted data block; The decrypted data blocks are combined according to the metadata information to obtain an immutable assessment report.

7. A national secret-based assessment report data encryption device, characterized in that: The device comprises: An acquisition module, used to acquire assessment report information; the assessment report information includes assessment data and corresponding metadata information; the assessment data includes a plurality of data blocks to be encrypted classified according to different levels; the metadata information includes report information corresponding to each data block to be encrypted; A hierarchical encryption module, used for hierarchically encrypting each to-be-encrypted data block of different levels to obtain each first encrypted data block after encryption; A security tag module, used to assign a unique security tag to each of the first encrypted data blocks, and associate each of the security tags with the first encrypted data blocks, including: encrypting metadata information corresponding to the first encrypted data block by using a third-country encryption algorithm and a system-configured encryption key to obtain encrypted metadata; splicing the encrypted metadata and the first public key to obtain a spliced ​​encrypted string; wherein the first public key is generated by the receiving end using a fourth-country encryption algorithm; shortening the spliced ​​encrypted string by base64 encoding to obtain a target encrypted string; and using the target encrypted string as the security tag; a signature module, configured to sign the first encrypted data block according to the security mark to obtain signed encrypted data block information; the signed encrypted data block information includes the first encrypted data block, an encrypted summary corresponding to the first encrypted data block and the security mark; The sending module is used to encrypt the signed encrypted data block information using the first national secret algorithm and the encryption key configured by the system, and then send it to the receiving end.

8. A computer device, characterized in that: include: A processor, a memory, a communication interface and a communication bus, wherein the processor, the memory and the communication interface communicate with each other via the communication bus; The memory is used to store at least one executable instruction, and the executable instruction enables the processor to perform the operation of the assessment report data encryption method based on national secrets as described in any one of claims 1-5 or the assessment report data decryption method based on national secrets as described in claim 6.

9. A computer-readable storage medium, characterized in that: The storage medium stores at least one executable instruction. When the executable instruction is executed on a computer device, the computer device executes the operation of the assessment report data encryption method based on national secrets as described in any one of claims 1 to 5 or the assessment report data decryption method based on national secrets as described in claim 6.

Citation Information

Patent Citations

  • Data transmission method, data processing method and computer equipment

    CN117749909A

  • Json field data encryption method and device based on national cryptographic algorithm and storage medium

    CN118233098A