Data encryption method and device, related equipment and computer readable storage medium
By acquiring the device image of the access device and performing prime number matching and data combination transformation, generating encryption parameters for data encryption, the problem of inaccurate detection of the address changes of the attack device in the prior art is solved, and the security of data transmission is improved.
Patent Information
- Application Number
- CN202411998546.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-30
- Publication Date
- 2025-05-06
AI Technical Summary
In the prior art, by verifying whether the access device cannot accurately detect the address change of the attack device in the blacklist, the security of data transmission is reduced.
By acquiring the device image of the access device, determining the pixel coordinates of the access device in the device image, performing prime number matching and data combination transformation, and generating encryption parameters for data encryption.
Due to the uniqueness of the device image and the mathematical characteristics of prime numbers, it is difficult to be mathematically decomposed, which increases the difficulty of cracking encrypted data and enhances the security of data transmission.
Smart Images

Figure CN119939567A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data encryption technology, and in particular to a data encryption method, apparatus, related equipment and computer-readable storage medium. Background Art
[0002] With the development of Internet technology, more and more devices are communicating data and being remotely controlled through online connections. In order to ensure the security of online communication and operation authorization, it is often necessary to perform security verification on the access device after the access device sends an access request. Currently, the relevant technology often verifies whether the access device is in the blacklist. If the device is not in the blacklist, the verification is passed. Although this method can avoid some malicious attacks, when the address and other information of the attacking device changes, it is impossible to accurately perform security detection on the changed attacking device, which reduces the security of data transmission. Summary of the invention
[0003] In order to solve the technical problems existing in the related technologies, the embodiments of the present application provide a data encryption method, apparatus, related equipment and computer-readable storage medium.
[0004] To achieve the above purpose, the technical solution of the embodiment of the present application is implemented as follows:
[0005] On the one hand, an embodiment of the present application provides a data encryption method, the method comprising:
[0006] Acquire a device image including an access device;
[0007] Determine pixel coordinates of the access device in the device image;
[0008] Performing prime number matching on the pixel coordinates to obtain prime number coordinates in the pixel coordinates;
[0009] The prime number coordinates are subjected to data combination transformation to obtain encryption parameters, and the target plaintext is encrypted based on the encryption parameters to obtain encrypted data.
[0010] On the other hand, an embodiment of the present application provides a data encryption device, including:
[0011] An acquisition module, used to acquire device images including access devices;
[0012] A coordinate determination module, used to determine the pixel coordinates of each pixel point of the access device in the device image;
[0013] A prime number matching module is used to perform prime number matching on the pixel coordinates to obtain prime number coordinates in the pixel coordinates;
[0014] The data combination module is used to perform data combination transformation on the prime number coordinates to obtain encryption parameters, and encrypt the target plaintext based on the encryption parameters to obtain encrypted data.
[0015] On the other hand, an embodiment of the present application further provides an electronic device, comprising: a processor and a memory for storing a computer program that can be run on the processor, wherein the processor is used to execute the steps in the above method when running the computer program.
[0016] On the other hand, an embodiment of the present application further provides a computer storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above method are implemented.
[0017] On the other hand, an embodiment of the present application further provides a computer program product, including a computer program, which implements the steps in the above method when executed by a processor.
[0018] The data encryption method, apparatus, related equipment and computer-readable storage medium provided in the embodiments of the present application obtain a device image including an access device, verify the security of the access device based on the device image acquired by an image acquisition device, because the device image of the device is unique and the device image is difficult to acquire by other means, the security of the access device verification is improved, the pixel coordinates of the access device in the device image are determined, prime number matching is performed on the pixel coordinates to obtain prime number coordinates in the pixel coordinates, data combination transformation is performed on the prime number coordinates to obtain encryption parameters, encryption is performed using the acquired prime number coordinates as encryption parameters, due to the mathematical characteristics of prime numbers, it is difficult to be mathematically decomposed, the difficulty of cracking the encrypted data is increased, and thus the security of the data is improved, the target plaintext is encrypted based on the encryption parameters to obtain encrypted data, the encryption parameters are generated by the unique device image as described above, the difficulty of cracking the encrypted data is increased, and the security of data transmission is improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] Figure 1 A schematic diagram of a data encryption method according to an embodiment of the present application;
[0020] Figure 2 It is a schematic diagram of the architecture of data encryption provided by an embodiment of the present application;
[0021] Figure 3 It is a schematic diagram of the transmission process provided by the embodiment of the present application;
[0022] Figure 4 A schematic diagram of the structure of a data encryption device according to an embodiment of the present application;
[0023] Figure 5Schematic diagram of the hardware structure of the embodiment of the present application. DETAILED DESCRIPTION
[0024] The present application is further described in detail below in conjunction with the accompanying drawings and embodiments.
[0025] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art to which this application belongs. The terms used herein in the specification of this application are only for the purpose of describing specific embodiments and are not intended to limit this application.
[0026] For companies that provide public cloud services, a computer room with stable power supply plays a vital role. In order to prevent external attacks on the power supply system of the computer room, a monitoring system can be added to the power supply system, and an identity authentication mechanism can be established. The authentication mechanism is based on data transmission.
[0027] At present, there are two types of data communication methods for traditional power supply monitoring systems:
[0028] (1) Communication based on serial link (RS-232 / 485, etc.) or Ethernet. This method has fast response speed and can provide high-speed data transmission.
[0029] (2) Using satellite communication wireless packet switching technology for communication, this method can provide data transmission services at a rate of more than 100 kbit / s, with short connection time and low charges.
[0030] At the same time, in traditional power supply monitoring systems, when the device is directly connected to the server, a lot of time will be spent on setting up the environment at the device access layer and developing the application system, and the application system is difficult to be compatible in different monitoring systems.
[0031] Based on this, an embodiment of the present application proposes a data encryption method. In various embodiments of the present application, a device image including an access device is obtained, and the security of the access device is verified based on the device image acquired by the image acquisition device. Since the device image of the device is unique and the device image is difficult to acquire by other means, the security of the access device verification is improved, the pixel coordinates of the access device in the device image are determined, prime number matching is performed on the pixel coordinates to obtain the prime number coordinates in the pixel coordinates, data combination transformation is performed on the prime number coordinates to obtain encryption parameters, and encryption is performed using the acquired prime number coordinates as encryption parameters. Due to the mathematical characteristics of prime numbers, it is difficult to be mathematically decomposed, which increases the difficulty of cracking the encrypted data, thereby improving the security of the data, and encrypting the target plaintext based on the encryption parameters to obtain encrypted data. By generating encryption parameters from the unique device image as described above, the difficulty of cracking the encrypted data is improved, and the security of data transmission is improved.
[0032] The present application embodiment provides a data encryption method. Figure 1 The data encryption method of the present invention is shown in FIG. Figure 1 ;like Figure 1 As shown, the method includes:
[0033] Step 101: Acquire a device image including an access device.
[0034] As an example, the access device may be a device that initiates the access request, and the device image may be an image including the appearance of the access device.
[0035] In actual implementation, before obtaining the device image of the access device, the access device can also be preliminarily verified. The verification process can be to obtain the unique identifier of the access device, and compare the whitelist and blacklist recorded in the server. If the unique identifier of the access device is the unique identifier recorded in the whitelist, it is determined that the access device has passed the preliminary verification, and subsequent verification can be performed at this time; if the unique identifier of the access device is the unique identifier recorded in the blacklist, it is determined that the access device has not passed the preliminary verification. At this time, the access request of the access device can be rejected, and verification information of verification failure can be returned to the access device; if the unique identifier of the access device is not in the whitelist or the blacklist, the access device can be verified through network verification. Specifically, the server can send an identity authentication request to the access device, so that the access device uploads the identity information of the access device after receiving the identity authentication information, and then the server performs verification based on the identity information of the access device.
[0036] In actual implementation, the process of obtaining the device image of the access device can be that the access device actively uploads the device image of the access device, or the access device authorizes the image acquisition device deployed on the access device to be remotely controlled by the server, and the server controls the image acquisition device to acquire the device image of the access device.
[0037] Step 102: Determine the pixel coordinates of the connected device in the device image.
[0038] In some embodiments, determining the pixel coordinates of the connected device in the device image in step 102 can be implemented by the following technical solutions: determining the color value of each pixel point of the device image; based on the color value, filtering out the device pixel points belonging to the connected device from each pixel point of the device image; determining the original coordinates of the device pixel points in the device image; and performing a linear transformation on the original coordinates to obtain the pixel coordinates.
[0039] As an example, the color value of a pixel refers to the numerical value that represents the color of the pixel in a digital image. In digital image processing, the color value of a pixel is usually composed of the numerical values of the three color channels of red, green and blue. The value of each channel is usually between 0 and 255, representing the intensity of the red, green and blue channels respectively. For example, the color value of a pixel may be (R, G, B), such as (255, 0, 0) represents pure red, (0, 255, 0) represents pure green, (0, 0, 255) represents pure blue, (255, 255, 255) represents pure white, and (0, 0, 0) represents pure black.
[0040] In actual implementation, the color value of each pixel in the device image can be extracted to determine the position of the access device in the device image, and then the pixel points in the device image belonging to the access device can be determined, that is, the pixel points in the device image used to constitute the access device are the device pixel points belonging to the access device; then the original coordinates of these device pixel points in the device image can be determined separately, and the original coordinates can be linearly converted to obtain pixel coordinates.
[0041] In some embodiments, the color value includes the intensity value of three color channels. The above-mentioned determination of the device pixel points belonging to the access device in the device image based on the color value can be achieved through the following technical solution: perform the following processing for each pixel point of the device image: weighted sum the intensity values of the three color channels of each pixel point to obtain the original pixel value of each pixel point; respectively determine the first weight between the pixel point and each neighborhood pixel point, wherein the neighborhood pixel point is a pixel point within the area centered on the pixel point; based on the first weight, weighted fusion is performed on the original pixel values of each neighborhood pixel point to obtain the target pixel value of the pixel point; based on the target pixel value, filter out the device pixel points belonging to the access device from each pixel point of the device image.
[0042] In actual implementation, the original pixel value of a pixel point can be determined by the following formula (1):
[0043] Gray(i,j)=0.299*R(i,j)+0.587*G(i,j)+0.114B(i,j) (1)
[0044] In formula (1), R(i,j) represents the intensity value of the red channel of the pixel with coordinates (i,j) in the device image, G(i,j) represents the intensity value of the green channel of the pixel with coordinates (i,j) in the device image, B(i,j) represents the intensity value of the green channel of the pixel with coordinates (i,j) in the device image, Gray(i,j) represents the original pixel value of the pixel with coordinates (i,j) in the device image, and the values 0.299, 0.587, and 0.114 represent the weights of the three color channels, respectively.
[0045] In actual implementation, after determining the original pixel value of each pixel, the domain range of each pixel can be set. For example, the domain range of the pixel is set to 4x4, then the domain of each pixel is a domain centered on the pixel, with a length of four pixels and a width of four pixels, and each pixel in the domain is a pixel domain pixel of the pixel.
[0046] In actual implementation, the first weight between each pixel and each neighboring pixel can be set according to the distance between each domain pixel and the pixel, pixel similarity and other information, and then the domain pixels are weighted and fused by the first weight to obtain the target pixel value, and finally the original pixel value of the pixel is updated to the target pixel value. Since the target pixel value is determined based on each pixel and the pixels around the pixel, the target pixel value can better reflect the change trend of the pixel value of each pixel in the device image, so the area where the target pixel value changes dramatically in the device image can be used as the boundary area of the access device, and then the position of the access device in the device image is determined.
[0047] In actual implementation, the target pixel value can be determined by the following formula (2):
[0048]
[0049] In formula (2), f(i,j) is the target pixel value, is the first weight, and f(k,l) is the original pixel value.
[0050] Through the above manner, the position of the access device in the access image can be accurately determined, thereby improving the accuracy of determining the access device in the access image.
[0051] In some embodiments, the above-mentioned determination of the first weight between the pixel point and each neighborhood pixel point can be achieved by the following technical solution: performing the following processing for each neighborhood pixel point: determining the first coordinate of the neighborhood pixel point in the device image, and determining the second coordinate of the pixel point in the device image; determining the domain kernel of the neighborhood pixel point based on the first coordinate and the second coordinate; determining the range kernel of the neighborhood pixel point based on the original pixel value of the domain pixel and the original pixel value of the pixel point; fusing the domain kernel and the range kernel to obtain the first weight between the pixel point and each neighborhood pixel point.
[0052] In actual implementation, the following formulas (3) to (5) can be used:
[0053]
[0054] In formula (3), d(i,j,k,l) is the domain kernel, i is the horizontal coordinate in the first coordinate, j is the vertical coordinate in the first coordinate, j is the horizontal coordinate in the second coordinate, l is the vertical coordinate in the second coordinate, σ d is the grayscale filtering similarity factor.
[0055]
[0056] In formula (4), r(i,j,k,l) is the range kernel, i is the horizontal coordinate in the first coordinate, j is the vertical coordinate in the first coordinate, j is the horizontal coordinate in the second coordinate, l is the vertical coordinate in the second coordinate, σ r is the spatial filtering proximity factor.
[0057]
[0058] In formula (5), is the first weight, d(i,j,k,l) is the domain kernel, and r(i,j,k,l) is the range kernel.
[0059] In some embodiments, the above-mentioned screening out device pixel points belonging to the access device from each pixel point of the device image based on the target pixel value can be achieved through the following technical solution: performing the following processing for each pixel point: determining the pixel difference between the target pixel value of the pixel point and the target pixel value of the adjacent pixel point, wherein the adjacent pixel points are the pixel points adjacent to the pixel point; taking the adjacent pixel points whose pixel difference is greater than the difference threshold as the boundary pixel points, and connecting the boundary pixel points with adjacent relationship in the device image to obtain the device boundary line; determining the pixel points within the first area surrounded by the device boundary line as the device pixel points belonging to the access device.
[0060] In actual implementation, in order to determine the access device in the device image, the difference between the target pixels of two adjacent pixels can be compared. For example, if pixel A and pixel B are adjacent, where the target pixel value of pixel A is 10 and the target pixel value of pixel B is 70, then it can be determined that the pixel difference between pixel A and pixel B is 60. If the difference threshold is 50, pixel A and pixel B can be used as boundary pixels. By determining all the boundary pixels in the device image, these boundary pixels can be connected to obtain an area surrounded by boundary pixels, which is used as the area of the access device in the access image.
[0061] Step 103: Perform prime number matching on the pixel coordinates to obtain prime number coordinates of the pixel coordinates.
[0062] In some embodiments, the pixel coordinates are prime-number matched in step 103 to obtain the prime coordinates of the pixel coordinates. The prime coordinates of the pixel coordinates can be implemented by the following technical scheme: the abscissa in the pixel coordinates is prime-numbered to obtain the abscissa whose value is a prime number as the prime abscissa; the ordinate in the pixel coordinates is prime-numbered to obtain the ordinate whose value is a prime number as the prime ordinate; the prime abscissa and the prime ordinate are coordinate-combined to obtain the prime coordinates.
[0063] When actually implementing, the process of prime number retrieval to pixel coordinates can be for determining the prime number in pixel coordinates, for example, pixel coordinate A is (11, 46), pixel coordinate B is (12, 29), wherein, the horizontal coordinate 11 of pixel coordinate A is a prime number, then the horizontal coordinate 11 of pixel coordinate A can be used as the prime number horizontal coordinate, the ordinate 29 of pixel coordinate B is a prime number, then the ordinate of pixel coordinate B can be used as the prime number ordinate, so the prime number coordinate finally obtained can be (11, 29). It should be noted that the process of finding the prime number coordinate can be for sorting pixel coordinates according to the order of horizontal coordinate (or ordinate) from large to small (or from small to large), determining successively whether the horizontal coordinate and ordinate of each pixel coordinate are prime numbers, until determining the prime number horizontal coordinate and the prime number ordinate, the prime number ordinate and the prime number horizontal coordinate are combined to obtain the prime number coordinate.
[0064] Step 104: Perform data combination transformation on the prime number coordinates to obtain encryption parameters, and encrypt the target plaintext based on the encryption parameters to obtain encrypted data.
[0065] In actual implementation, plaintext can be the original data that has not been converted into ciphertext before the encryption operation. In cryptography, plaintext refers to all unencrypted information, which can be text, numbers, pictures, audio or any other form of data. When plaintext is converted through an encryption algorithm, it becomes ciphertext, so that even if it is intercepted, people without the correct key cannot easily understand its content.
[0066] In some embodiments, the prime number coordinates include a prime number horizontal coordinate and a prime number vertical coordinate. The data combination transformation of the prime number coordinates in step 104 to obtain the encryption parameter can be implemented by the following technical solution: multiplying the prime number horizontal coordinate and the prime number vertical coordinate to obtain a first product; determining the Euler function of the first product, and determining a public key parameter that is coprime with the Euler function; determining the modular inverse element of the public key parameter as a private key parameter; combining the first product and the public key parameter to obtain an encrypted public key, combining the first product and the private key parameter to obtain an encrypted private key, and using the encrypted public key and the encrypted private key as encryption parameters.
[0067] In actual implementation, the public key parameters and private key parameters can be determined by the following formulas (6) to (9):
[0068] n=p*q (6)
[0069] In formula (6), n is the first product, p is the prime number abscissa, and q is the prime number ordinate.
[0070]
[0071] In formula (7), is the Euler function, p is the prime number horizontal coordinate, and q is the prime number vertical coordinate.
[0072] Then, choose an integer e such that And e and Mutually prime. Take e as the public key parameter.
[0073]
[0074] In formula (8), d is the module inverse element (private key parameter), e is the public key parameter, is the Euler function.
[0075] Afterwards, the encrypted public key can be obtained by combining the first product and the public key parameter. Specifically, the first product and the public key parameter can be concatenated to obtain the encrypted public key. For example, if the first product is n and the public key parameter is e, the encrypted public key can be (n, e). Similarly, the first product and the private key parameter can be concatenated to obtain the encrypted private key. For example, if the first product is n and the private key parameter is d, the encrypted private key can be (n, d). Afterwards, the target plaintext can be encrypted. Specifically, the target plaintext can be encrypted using an asymmetric encryption algorithm.
[0076] In some embodiments, the following technical solutions can also be executed: in response to an access request from an access device, obtaining encrypted data carried in the access request; decrypting the encrypted data based on encryption parameters to obtain a first plaintext; comparing the first plaintext with the target plaintext, and determining an access result of the access request based on the comparison result.
[0077] In actual implementation, after the access device sends an access request, it can obtain the encrypted data carried in the access request, and then decrypt the encrypted data based on the private key stored in the server to obtain the first plaintext. The first plaintext obtained by decryption is compared with the above-mentioned target plaintext to determine whether they are the same. If the first plaintext is the same as the target plaintext, it is determined that the access device has passed the verification and the access device is allowed to execute subsequent processes. If the first plaintext is different from the target plaintext, it is determined that the access device has not passed the verification, and the access device is not allowed to access, and a notification of the access device is returned to the access device.
[0078] The present application is described below in conjunction with application examples.
[0079] The present invention proposes a method for authenticating network communication in a power supply monitoring system in a computer room, which is divided into two parts: device access authentication and interface call authentication. In the device access authentication stage, local verification and network verification are used to reduce network requests and improve access speed. Its security architecture is as follows: Figure 2 shown.
[0080] See also Figure 2 , Figure 2 It is a schematic diagram of the data encryption architecture provided in an embodiment of the present application.
[0081] exist Figure 2 In the example, the first device is an access device, which sends an access authentication to the IoT platform. After the IoT platform passes the access authentication of the first device, the access authentication of the first device is transmitted to the server. The server performs an interface call authentication on the access device to obtain the authentication structure of the interface call authentication. The server then returns the authentication result to the access device through the IoT platform.
[0082] Among them, the process of the IoT platform performing access authentication on the access request of the first device can be to set up a local blacklist and whitelist verification on the IoT platform. If it is a blacklist device, access is directly denied; if it is a whitelist device, the access authentication process is entered; if it is another type of device, it is determined whether it can access through network verification. After the access device completes the device access authentication with the platform, the power supply status is uploaded to the IoT platform through the narrowband Internet of Things (NB-IoT) communication method; after the server completes the interface call authentication, it requests or sends data to the IoT platform by calling the interface according to actual needs, obtains the status of the access device or controls the access device, thereby ensuring the safe operation of the entire system and preventing attackers from forging false data uploads or issuing malicious control operations.
[0083] Add a blacklist and whitelist check field (meta) to the open platform (IoT platform). The value of the check field is white, black, or other. When a terminal device (access device) is authenticated, its meta value is first detected. If the meta value is black, it is judged as a blacklist device and is directly denied access to the open platform. All publicly available malicious terminal devices on the market can be marked as black. If the meta value is white, it is judged as a whitelist device and enters the access authentication process. All terminal devices on the market that have passed authoritative security authentication can be marked as white. If the meta value is other, it is judged as other types of devices. Devices marked with this type need to connect to the network to determine whether they are safe, and then complete the blacklist and whitelist judgment. Generally, newly launched terminal devices can be marked as other.
[0084] Through the blacklist and whitelist verification process, the development platform can deny access to unsafe terminals with a meta value of black in advance, and allow access to safe terminals with a meta value of white. For terminal devices with a meta value of other, network queries can be used to make judgments. This not only reduces network requests, but also effectively improves the speed and security of terminal access. For the released terminal devices, token authentication is then performed.
[0085] The following describes the process of generating a token:
[0086] First, randomly take a photo of the appearance of the terminal device, transfer the picture to the computer, perform a series of image processing, and obtain two different prime numbers p and q (i.e. the prime number coordinates mentioned above) from the processing results as the basic parameters for generating subsequent tokens. Use the weighted average method to perform weighted average on the R, G, and B components (i.e. the intensity values of the three color channels mentioned above) of the color image (i.e. the device image mentioned above) with different weights. The calculation formula of this method is:
[0087] Gray(i,j)=0.299*R(i,j)+0.587*G(i,j)+0.114B(i,j) (9)
[0088] In formula (9), R(i,j) represents the intensity value of the red channel of the pixel with coordinates (i,j) in the device image, G(i,j) represents the intensity value of the green channel of the pixel with coordinates (i,j) in the device image, B(i,j) represents the intensity value of the green channel of the pixel with coordinates (i,j) in the device image, and Gray(i,j) represents the pixel value of the pixel with coordinates (i,j) in the device image.
[0089] Then use bilateral filtering to obtain the device outline in the image. Suppose the gray value of the central pixel of the image to be filtered is , and the gray value of its neighboring pixel is . Then the algorithm expression of bilateral filtering is:
[0090]
[0091] In formula (10), f(i,j) is the target pixel value, is the first weight, and f(k,l) is the original pixel value.
[0092] The first weight may be determined by referring to the following formulas (11) to (13).
[0093]
[0094] In formula (11), d(i,j,k,l) is the domain kernel, i is the horizontal coordinate in the first coordinate, j is the vertical coordinate in the first coordinate, j is the horizontal coordinate in the second coordinate, l is the vertical coordinate in the second coordinate, σ d is the grayscale filtering similarity factor.
[0095]
[0096] In formula (12), r(i,j,k,l) is the range kernel, i is the horizontal coordinate of the pixel, j is the vertical coordinate of the pixel, j is the horizontal coordinate of the second pixel, l is the vertical coordinate of the pixel, σ r is the spatial filtering proximity factor.
[0097]
[0098] In formula (13), is the first weight, d(i,j,k,l) is the domain kernel, and r(i,j,k,l) is the range kernel.
[0099] After determining the original coordinates of the device pixel in the device image, the image contrast can be enhanced using proportional linear transformation using the following formula (14) to obtain the pixel coordinates of the device image.
[0100] g(x,y)=kf(x,y)+b (14)
[0101] In formula (14), f(x, y) is the original coordinate, g(x, y) is the pixel coordinate, and k and b are transformation parameters. By setting different values of k and b, images expanded or compressed in different proportions can be obtained. After the above processing, a series of two-dimensional coordinate data based on the pictures of the terminal device are obtained. From these coordinate data, prime numbers are searched in sequence, where the data of the x coordinate is used as the prime number p, and the data of the y coordinate is used as the prime number q. If the x of the current coordinate is not a prime number and y is a prime number, then let q = y, and the value of p continues to search for the x coordinate of the next coordinate, so as to finally determine two prime numbers.
[0102] The IoT platform performs security authentication based on the authentication token, which is generated by a digital signature algorithm. When the authentication token carried by the visitor (device or application) passes the verification of the IoT platform, normal access can be achieved. The generation of the authentication token by the digital signature algorithm can be divided into the following steps:
[0103] According to the two different prime numbers p and q obtained, calculate their product to get n (i.e., the above-mentioned first product). Specifically, refer to the following formula:
[0104] n = p * q (15)
[0105] In formula (15), n is the first product, p is the prime number abscissa, and q is the prime number ordinate.
[0106] After that, calculate the Euler's totient function of n. Specifically, refer to the following formula (16):
[0107] φ(n) = (p - 1)(q - 1) (16)
[0108] In formula (16), φ(n) is the Euler's totient function, p is the prime number abscissa, and q is the prime number ordinate.
[0109] After that, select an integer e such that 1 < e < φ(n) and e is relatively prime to φ(n). e is part of the public key and is disclosed to the recipient of the data.
[0110] Calculate the modular multiplicative inverse d of e such that it satisfies the following formula (17):
[0111] d * e = mod(φ(n)) (17)
[0112] In formula (17), d is the modular multiplicative inverse, e is the public key parameter, and φ(n) is the Euler's totient function.
[0113] After the above processing, the public key (n, e) and the private key (n, d) can be obtained. Convert the plaintext M to be encrypted into an integer m such that 0 ≤ m < n. The encrypted ciphertext C is m e*(mod*n) .
[0114] The plaintext M can be freely composed of elements such as the terminal device version number, token expiration time, usage scenario, etc. It should be noted that both the encryption and decryption processes in the digital signature algorithm are based on modular exponentiation. During the calculation process, modular arithmetic is required to ensure that the result is within a certain range.
[0115] When the terminal device uploads data to the platform, it places the Token in the connection message for identity authentication. If the authentication is successful, the data is transmitted; otherwise, the platform rejects the uploaded information. The transmission process is as Figure 3 shown. Figure 3 It is a schematic diagram of the transmission process provided by an embodiment of the present application.
[0116] In step 301, the access device sends a connection request to the server.
[0117] In step 302, the server authenticates the access device.
[0118] The platform obtains the authentication information in the connection request message for authentication, that is, decrypts the token. When decrypting the token transmitted by the decrypting terminal (i.e., the above-mentioned access device), the received ciphertext C needs to be decrypted using its own private key (n, d), and the ciphertext C is converted into an integer c, satisfying 0 ≤ c < n. The obtained plaintext M is the result after decryption. If this value is the same as the value during encryption, the authentication passes; otherwise, the authentication fails and the connection is disconnected.
[0119] In step 303, the server returns the authentication result to the access device.
[0120] After the authentication passes, if the historical information in the connection request message is 0, the platform will load the saved device information. If the historical information in the connection request message is 1 and the device has no saved information on the platform, the device-related information will not be loaded.
[0121] To return the authentication result message, the device needs to receive the authentication result message from the platform before it can send subsequent data packets. The return code in the authentication result message describes the authentication result. If the value of the return code is 0, it represents successful authentication.
[0122] The application end (i.e., the above-mentioned access device) calls the call interface provided by the Internet of Things platform through the Internet protocol and sets the generated token as a field in the header parameter of the Internet protocol message for authentication. The header parameter is responsible for notifying the server about the request information of the application end, and the generation of the token changes following the elements that make up the plaintext.
[0123] After the server application passes the authentication, the calling interface returns the authentication data. In the returned data, the device ID is a unique ID assigned by the platform for each request to distinguish each request and ensure communication security. By obtaining the returned data, the development of the back-end business logic is completed, thereby achieving the purpose of calling the interface to obtain data or issue commands.
[0124] Through the above method, a security authentication solution combining local and network is adopted to filter out unsafe access devices, reduce network requests, and improve authentication efficiency; the Internet of Things platform is used to connect the terminal and the application end, which can quickly integrate platform resources and be compatible with a variety of terminal devices, reduce system development and management costs, and effectively avoid incompatibility and time-consuming problems caused by direct connection between devices; identity security authentication is performed on device data uploads and application server API calls, which can effectively prevent system access permission leakage and improve the security of the company's computer room power supply system.
[0125] In order to implement the data encryption method on the server side of the embodiment of the present application, the embodiment of the present application also provides a data encryption device, Figure 4 Schematic diagram of the structure of the data encryption device according to the embodiment of the present application. Figure 4 As shown, the data encryption device comprises:
[0126] An acquisition module 41 is used to acquire a device image including an access device;
[0127] A coordinate determination module 42, used to determine the pixel coordinates of the access device in the device image;
[0128] A prime number matching module 43 is used for performing prime number matching on the pixel coordinates to obtain prime number coordinates in the pixel coordinates;
[0129] The data combination module 44 is used to perform data combination transformation on the prime number coordinates to obtain encryption parameters, and encrypt the target plaintext based on the encryption parameters to obtain encrypted data.
[0130] In one embodiment, the coordinate determination module 42 is also used to determine the color value of each pixel point of the device image; based on the color value, filter out device pixel points belonging to the access device from each pixel point of the device image; determine the original coordinates of the device pixel point in the device image; and perform a linear transformation on the original coordinates to obtain the pixel coordinates.
[0131] In one embodiment, the coordinate determination module 42 is also used to perform the following processing on each pixel point of the device image: weighted sum of the intensity values of the three color channels of each pixel point to obtain the original pixel value of each pixel point; determine the first weight between the pixel point and each neighborhood pixel point, wherein the neighborhood pixel point is a pixel point within a region centered on the pixel point; based on the first weight, weighted fusion of the original pixel values of each neighborhood pixel point to obtain the target pixel value of the pixel point; based on the target pixel value, filter out device pixel points belonging to the access device from each pixel point of the device image.
[0132] In one embodiment, the coordinate determination module 42 is also used to perform the following processing for each neighborhood pixel point: determine the first coordinate of the neighborhood pixel point in the device image, and determine the second coordinate of the pixel point in the device image; determine the domain kernel of the neighborhood pixel point based on the first coordinate and the second coordinate; determine the range kernel of the neighborhood pixel point based on the original pixel value of the domain pixel and the original pixel value of the pixel point; and fuse the domain kernel and the range kernel to obtain a first weight between the pixel point and the neighborhood pixel point.
[0133] In one embodiment, the coordinate determination module 42 is also used to perform the following processing for each pixel point: determine the pixel difference between the target pixel value of the pixel point and the target pixel value of the adjacent pixel point, wherein the adjacent pixel point is the pixel point adjacent to the pixel point; use the adjacent pixel points whose pixel difference is greater than the difference threshold as boundary pixel points, and connect the boundary pixel points with adjacent relationship in the device image to obtain a device boundary line; determine the pixel points within the first area surrounded by the device boundary line as device pixel points belonging to the access device.
[0134] In one embodiment, the prime number matching module 43 is further used for performing a prime number search on the abscissa in the pixel coordinates to obtain a abscissa whose value is a prime number as the prime number abscissa; performing a prime number search on the ordinate in the pixel coordinates to obtain a ordinate whose value is a prime number as the prime number ordinate; and performing coordinate combination on the prime number abscissa and the prime number ordinate to obtain the prime number coordinates.
[0135] In one embodiment, the prime number matching module 43 is further used to perform product processing on the prime number horizontal coordinate and the prime number vertical coordinate to obtain a first product; determine the Euler function of the first product, and determine a public key parameter that is coprime with the Euler function; determine the modular inverse element of the public key parameter as a private key parameter; combine the first product and the public key parameter to obtain an encrypted public key, combine the first product and the private key parameter to obtain an encrypted private key, and use the encrypted public key and the encrypted private key as the encryption parameters.
[0136] In one embodiment, the data combination module 44 is also used to respond to the access request of the access device, obtain the encrypted data carried by the access request; decrypt the encrypted data based on the encryption parameters to obtain a first plaintext; compare the first plaintext with the target plaintext, and determine the access result of the access request based on the comparison result.
[0137] It should be noted that: when the data encryption device provided in the above embodiment performs data encryption, it only uses the division of the above-mentioned program modules as an example. In actual applications, the above-mentioned processing can be assigned to different program modules as needed, that is, the internal structure of the device is divided into different program modules to complete all or part of the processing described above.
[0138] It should be noted that: the data encryption device provided in the above embodiment only uses the division of the above program modules as an example when performing data encryption. In actual applications, the above processing can be assigned to different program modules as needed, that is, the internal structure of the device is divided into different program modules to complete all or part of the processing described above. In addition, the data encryption device provided in the above embodiment and the data encryption method embodiment on the second client side belong to the same concept. The specific implementation process is detailed in the data encryption method embodiment, which will not be repeated here.
[0139] Based on the hardware implementation of the above program modules, and in order to implement the data encryption method of the embodiment of the present application, the embodiment of the present application also provides a server, Figure 5 The hardware structure diagram of the embodiment of the present application is as follows: Figure 5 As shown, the server 50 includes:
[0140] A first communication interface 51, capable of exchanging information with other devices;
[0141] The first processor 52 is connected to the first communication interface 51 to implement information interaction with other devices and is used to execute the above-provided data encryption method when running a computer program, and the computer program is stored in the first memory 53.
[0142] Specifically, the first processor 52 is used to obtain a device image including an access device; determine the pixel coordinates of each pixel point of the access device in the device image; perform prime number matching on the pixel coordinates to obtain prime number coordinates in the pixel coordinates; perform data combination transformation on the prime number coordinates to obtain encryption parameters, and encrypt the target plaintext based on the encryption parameters to obtain encrypted data.
[0143] The first communication interface 51 is used to feed back the adjusted status of each storage node to the user.
[0144] In one embodiment, the first processor 52 is further used to determine the color value of each pixel of the device image; based on the color value, filter out device pixels belonging to the access device from each pixel of the device image; determine the original coordinates of the device pixel in the device image; and perform linear transformation on the original coordinates to obtain the pixel coordinates.
[0145] In one embodiment, the first processor 52 is further used to perform the following processing on each pixel of the device image: perform weighted summation of the intensity values of the three color channels of each pixel to obtain the original pixel value of each pixel; determine a first weight between the pixel and each neighborhood pixel, wherein the neighborhood pixel is a pixel within a region centered on the pixel; based on the first weight, perform weighted fusion of the original pixel values of each neighborhood pixel to obtain a target pixel value of the pixel; based on the target pixel value, filter out device pixels belonging to the access device from each pixel of the device image.
[0146] In one embodiment, the first processor 52 is further used to perform the following processing for each neighborhood pixel point: determine the first coordinate of the neighborhood pixel point in the device image, and determine the second coordinate of the pixel point in the device image; determine the domain kernel of the neighborhood pixel point based on the first coordinate and the second coordinate; determine the range kernel of the neighborhood pixel point based on the original pixel value of the domain pixel and the original pixel value of the pixel point; and fuse the domain kernel and the range kernel to obtain a first weight between the pixel point and the neighborhood pixel point.
[0147] In one embodiment, the first processor 52 is further used to perform the following processing for each pixel point: determine the pixel difference between the target pixel value of the pixel point and the target pixel value of an adjacent pixel point, wherein the adjacent pixel point is a pixel point adjacent to the pixel point; use the adjacent pixel points whose pixel difference is greater than a difference threshold as boundary pixel points, and connect the boundary pixel points with adjacent relationships in the device image to obtain a device boundary line; and determine the pixel points within the first area surrounded by the device boundary line as device pixel points belonging to the access device.
[0148] In one embodiment, the first processor 52 is further used to perform a prime number search on the abscissa in the pixel coordinates to obtain a abscissa whose value is a prime number as the prime number abscissa; perform a prime number search on the ordinate in the pixel coordinates to obtain a ordinate whose value is a prime number as the prime number ordinate; and perform coordinate combination on the prime number abscissa and the prime number ordinate to obtain the prime number coordinate.
[0149] In one embodiment, the first processor 52 is further used to perform product processing on the prime number horizontal coordinate and the prime number vertical coordinate to obtain a first product; determine the Euler function of the first product, and determine a public key parameter that is coprime with the Euler function; determine the modular inverse element of the public key parameter as a private key parameter; combine the first product and the public key parameter to obtain an encrypted public key, combine the first product and the private key parameter to obtain an encrypted private key, and use the encrypted public key and the encrypted private key as the encryption parameters.
[0150] In one embodiment, the first processor 52 is further used to respond to an access request from the access device, obtain the encrypted data carried in the access request; decrypt the encrypted data based on the encryption parameters to obtain a first plaintext; compare the first plaintext with the target plaintext, and determine an access result of the access request based on the comparison result.
[0151] It should be noted that the specific processing process of the first communication interface 51 and the first processor 52 can be understood by referring to the above data encryption method.
[0152] Of course, in actual application, the various components in the server 50 are coupled together through the first bus system 54. It is understandable that the first bus system 54 is used to realize the connection and communication between these components. In addition to the data bus, the first bus system 54 also includes a power bus, a control bus and a status signal bus. However, for the sake of clarity, Figure 5 In the figure, various buses are labeled as a first bus system 54 .
[0153] The first memory 53 in the embodiment of the present application is used to store various types of data to support the operation of the server 50. Examples of such data include: any computer program used to operate on the server 50.
[0154] The data encryption method disclosed in the above embodiment of the present application can be applied to the first processor 52, or implemented by the first processor 52. The first processor 52 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above data encryption method can be completed by the hardware integrated logic circuit or software instructions in the first processor 52. The above-mentioned first processor 52 may be a general-purpose processor, a digital signal processor (DSP, Digital Signal Processor), or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The first processor 52 can implement or execute the data encryption method, steps and logic block diagram disclosed in the embodiment of the present application. The general-purpose processor may be a microprocessor or any conventional processor, etc. In combination with the steps of the data encryption method disclosed in the embodiment of the present application, it can be directly embodied as a hardware decoding processor to execute, or it can be executed by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium, which is located in the first memory 53. The first processor 52 reads the information in the first memory 53 and completes the steps of the above data encryption method in combination with its hardware.
[0155] In an exemplary embodiment, the server 50 can be implemented by one or more application-specific integrated circuits (ASIC), DSP, programmable logic device (PLD), complex programmable logic device (CPLD), field-programmable gate array (FPGA), general-purpose processor, controller, microcontroller (MCU), microprocessor, or other electronic components to execute the aforementioned data encryption method.
[0156] In an exemplary embodiment, the embodiment of the present application further provides an electronic device, including a processor and a memory for storing a computer program that can be run on the processor, wherein the processor is used to execute the steps of any of the above methods when running the computer program.
[0157] The embodiment of the present application further provides a storage medium, namely a computer storage medium, specifically a computer-readable storage medium, for example, including a memory 603 storing a computer program, and the computer program can be executed by a processor 602 of an electronic device 600 to complete the steps of the aforementioned method. The computer-readable storage medium can be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface storage, optical disk, or CD-ROM.
[0158] An embodiment of the present application also provides a computer program product, including a computer program, which implements the steps of any of the above methods when executed by a processor.
[0159] It should be noted that: "first", "second", etc. are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. The term "and / or" herein is only a description of the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. In addition, the term "one or more" herein represents any combination of at least two of any one or more of a plurality of items. For example, including one or more of A, B, and C can represent including any one or at least two or more elements selected from the set consisting of A, B, and C.
[0160] In addition, the technical solutions described in the embodiments of the present application can be combined arbitrarily without conflict.
[0161] The above description is only a preferred embodiment of the present application and is not intended to limit the protection scope of the present application.
Claims
1. A data encryption method, characterized in that: The method comprises: Acquire a device image including an access device; Determine pixel coordinates of the access device in the device image; Performing prime number matching on the pixel coordinates to obtain prime number coordinates in the pixel coordinates; The prime number coordinates are subjected to data combination transformation to obtain encryption parameters, and the target plaintext is encrypted based on the encryption parameters to obtain encrypted data.
2. The method according to claim 1, characterized in that The determining pixel coordinates of each pixel point corresponding to the connected device in the device image includes: Determining the color value of each pixel of the device image; Based on the color value, filter out device pixels belonging to the access device from the pixels of the device image; Determine the original coordinates of the device pixel in the device image; The original coordinates are linearly transformed to obtain the pixel coordinates.
3. The method according to claim 2, characterized in that The color value includes intensity values of three color channels; The step of selecting device pixels belonging to the access device from the pixels in the device image based on the color value includes: The following processing is performed for each pixel of the device image: Performing weighted summation on the intensity values of the three color channels of each of the pixel points to obtain the original pixel value of each of the pixel points; Determine a first weight between the pixel point and each neighboring pixel point, wherein the neighboring pixel point is a pixel point within a region centered on the pixel point; Based on the first weight, weighted fusion is performed on the original pixel value of each of the neighborhood pixels to obtain a target pixel value of the pixel; Based on the target pixel value, device pixel points belonging to the access device are screened out from the pixel points of the device image.
4. The method according to claim 3, characterized in that The determining a first weight between the pixel point and each neighboring pixel point includes: The following processing is performed for each neighborhood pixel: Determine a first coordinate of the neighborhood pixel point in the device image, and determine a second coordinate of the pixel point in the device image; Determine a domain kernel of the neighborhood pixel points based on the first coordinate and the second coordinate; Determine a range kernel of the neighborhood pixel point based on the original pixel value of the domain pixel and the original pixel value of the pixel point; The domain kernel and the range kernel are fused to obtain a first weight between the pixel point and the neighboring pixel points.
5. The method according to claim 3, characterized in that: The step of screening out device pixels belonging to the access device from the pixels of the device image based on the target pixel value includes: The following processing is performed for each pixel: Determine a pixel difference between a target pixel value of the pixel point and a target pixel value of an adjacent pixel point, wherein the adjacent pixel point is a pixel point adjacent to the pixel point; Adjacent pixel points whose pixel differences are greater than a difference threshold are taken as boundary pixel points, and the boundary pixel points having an adjacent relationship in the device image are connected to obtain a device boundary line; Pixel points within a first area surrounded by the device boundary line are determined as device pixel points belonging to the access device.
6. The method according to claim 1, characterized in that The performing prime number matching on the pixel coordinates to obtain prime number coordinates in the pixel coordinates includes: Performing a prime number search on the abscissa in the pixel coordinates to obtain a abscissa whose value is a prime number as the prime number abscissa; Performing a prime number search on the ordinate in the pixel coordinates to obtain a ordinate whose value is a prime number as the prime number ordinate; The prime number abscissa and the prime number ordinate are combined to obtain the prime number coordinate.
7. The method according to claim 1, characterized in that The prime number coordinates include a prime number abscissa and a prime number ordinate; The step of performing data combination transformation on the prime number coordinates to obtain encryption parameters includes: Performing product processing on the prime number abscissa and the prime number ordinate to obtain a first product; Determine an Euler function of the first product, and determine a public key parameter that is coprime with the Euler function; Determine the modular inverse element of the public key parameter as the private key parameter; The first product and the public key parameter are combined to obtain an encrypted public key, and the first product and the private key parameter are combined to obtain an encrypted private key, and the encrypted public key and the encrypted private key are used as the encryption parameters.
8. The method according to claim 1, characterized in that After encrypting the target plaintext based on the encryption parameter to obtain encrypted data, the method further includes: In response to an access request from the access device, obtaining the encrypted data carried in the access request; Decrypting the encrypted data based on the encryption parameter to obtain a first plaintext; The first plaintext is compared with the target plaintext, and an access result of the access request is determined based on the comparison result.
9. A data encryption device, characterized in that: include: An acquisition module, used to acquire device images including access devices; A coordinate determination module, used to determine the pixel coordinates of the access device in the device image; A prime number matching module is used to perform prime number matching on the pixel coordinates to obtain prime number coordinates in the pixel coordinates; The data combination module is used to perform data combination transformation on the prime number coordinates to obtain encryption parameters, and encrypt the target plaintext based on the encryption parameters to obtain encrypted data.
10. An electronic device, characterized in that: include: A processor and a memory for storing a computer program that can be executed on the processor, wherein: The processor is used to execute the steps of the method according to any one of claims 1 to 8 when running a computer program.
11. A computer storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 8 are implemented.
12. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 8 are implemented.