Data decryption method, electronic device, storage medium and program product
By recording the initial summary value in page units in the database and using a preset summary algorithm to calculate the target summary value when the switching fails, the problem of inaccurate recording information when the hardware encryption device switches is failed, and the success rate and accuracy of data decryption are improved.
Patent Information
- Application Number
- CN202411978461.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-30
- Publication Date
- 2025-05-06
AI Technical Summary
When switching hardware encryption devices in the database, the time point of the switching failure is uncertain, resulting in inaccurate encryption device information recorded, thereby reducing the accuracy of decryption.
By recording a unique initial digest value in the unit of pages in the database, and when the switching fails, the page information, target encryption device information and initial digest value are obtained based on the page to be decrypted, the target digest value is calculated using a preset digest algorithm to determine whether it is the same as the initial digest value, thereby determining the identity of the target encryption device for decryption.
Improves the success rate and accuracy of data decryption, ensuring that data can be accurately decrypted when the hardware encryption device switches fail.
Smart Images

Figure CN119939624A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular to a data decryption method, electronic equipment, storage medium and program product. Background Art
[0002] The transparent storage encryption technology of the database can be adapted for use with a variety of hardware encryption devices, such as network cipher machines of different brands. When a new hardware encryption device is used and the hardware encryption device currently used by the database is switched, the switch may fail. This requires that the encrypted data in the database be decrypted when the switch fails so that the new hardware encryption device can be used to re-encrypt it.
[0003] Currently, decryption is generally performed by the database in advance when creating an encryption object. The database records the name of the hardware encryption device used and the algorithm name adopted by the device in units of data tables or data table spaces. Then, in response to a switching failure, the corresponding encrypted data is decrypted based on the recorded device name and algorithm name.
[0004] However, the time point of the switching failure is uncertain. In the same data table, part of the data may be encrypted by the hardware encryption device before the switch, and the other part may be encrypted by the hardware encryption device after the switch, resulting in inaccurate recorded content, which in turn leads to decryption failure and reduces the accuracy of decryption. Summary of the invention
[0005] The embodiments of the present application provide a data decryption method, an electronic device, a storage medium, and a program product to achieve the effect of improving the success rate and accuracy of data decryption.
[0006] In a first aspect, an embodiment of the present application provides a data decryption method, which is applied to a database device, and includes: in response to a failure in performing a switch operation on an encryption device currently used by the database device, determining a page to be decrypted, and acquiring page information, target encryption device information, and an initial digest value according to the page to be decrypted; the initial digest value is a unique digest value determined when the page to be decrypted is encrypted;
[0007] Using a preset digest algorithm to calculate the page information and the target encryption device information to obtain a target digest value;
[0008] It is determined whether the initial digest value is the same as the target digest value. If so, the identity of the target encryption device is determined according to the target encryption device information, and the data in the to-be-decrypted page is decrypted according to the identity.
[0009] In a possible implementation, obtaining page information, target encryption device information, and an initial summary value based on the page to be decrypted includes: obtaining basic information and page detail information of the page to be decrypted to obtain the page information; determining a data table to which the page to be decrypted belongs, and obtaining target encryption device information recorded when an encryption object is created for the data table to which it belongs; reading characters of a preset embedded field in the page to be decrypted, and determining and obtaining the characters as the initial summary value.
[0010] In a possible implementation, the target encryption device information includes a target encryption device identifier and an encryption algorithm; the use of a preset digest algorithm to calculate the page information and the target encryption device information to obtain a target digest value includes: combining the page information, the target encryption device identifier and the encryption algorithm into a target string, and obtaining key information stored in the target encryption device; combining the key information, and using the preset digest algorithm to calculate the target string to obtain a target digest value.
[0011] In a possible implementation, after combining the key information and using the preset digest algorithm to calculate the target string, the method further includes: obtaining a calculation result and a preconfigured number of iterations; and iteratively calculating the calculation result using the preset digest algorithm according to the preconfigured number of iterations to obtain a target digest value.
[0012] In a possible implementation, decrypting the data in the page to be decrypted according to the identity includes: when the identity is the encryption device before switching, calling the port corresponding to the encryption device before switching, and based on the port, using the encryption device before switching to decrypt the data in the page to be decrypted; or, when the identity is the encryption device after switching, calling the port corresponding to the encryption device after switching, and based on the port, using the encryption device after switching to decrypt the data in the page to be decrypted.
[0013] In a possible implementation, after determining whether the initial digest value is the same as the target digest value, the method further includes: if not, determining the identity of the target encryption device according to the target encryption device information; when the identity is the encryption device before switching, calculating the latest target digest value based on the information related to the encryption device after switching, and determining whether the latest target digest value is the same as the initial digest value, so that if they are the same, the encryption device after switching is used to decrypt the data in the page to be decrypted; or, when the identity is the encryption device after switching, calculating the latest target digest value based on the information related to the encryption device before switching, and determining whether the latest target digest value is the same as the initial digest value, so that if they are the same, the encryption device before switching is used to decrypt the data in the page to be decrypted.
[0014] In a possible implementation manner, after determining whether the latest target summary value is the same as the initial summary value, the method further includes: if they are different, generating target prompt information, and displaying the target prompt information on a corresponding operation interface.
[0015] In a second aspect, an embodiment of the present application provides a data decryption device, comprising: a processing module, for determining a page to be decrypted in response to a failure in performing a switching operation on an encryption device currently used by the database device, and obtaining page information, target encryption device information, and an initial digest value according to the page to be decrypted; the initial digest value is a unique digest value determined when the page to be decrypted is encrypted; the page information and the target encryption device information are calculated using a preset digest algorithm to obtain a target digest value; determining whether the initial digest value is the same as the target digest value, and if so, determining the identity of the target encryption device according to the target encryption device information;
[0016] The decryption module is used to decrypt the data in the to-be-decrypted page according to the identity.
[0017] In a possible implementation, the processing module, when obtaining page information, target encryption device information and initial summary value based on the page to be decrypted, is specifically used to: obtain basic information and page detail information of the page to be decrypted to obtain the page information; determine the data table to which the page to be decrypted belongs, and obtain the target encryption device information recorded when creating an encryption object for the data table to which it belongs; read the characters of a preset embedded field in the page to be decrypted, and determine the characters as the initial summary value and obtain it.
[0018] In a possible implementation manner, the target encryption device information includes a target encryption device identifier and an encryption algorithm;
[0019] The processing module, when using the preset digest algorithm to calculate the page information and the target encryption device information to obtain the target digest value, is specifically used to: combine the page information, the target encryption device identifier and the encryption algorithm into a target character string, and obtain the key information stored in the target encryption device; in combination with the key information, use the preset digest algorithm to calculate the target character string to obtain the target digest value.
[0020] In a possible implementation, the processing module is further used to obtain a calculation result and a preconfigured number of iterations after the target string is calculated using the preset digest algorithm in combination with the key information; and iteratively calculate the calculation result using the preset digest algorithm according to the preconfigured number of iterations to obtain a target digest value.
[0021] In a possible implementation, the decryption module, when decrypting the data in the page to be decrypted according to the identity, is specifically used to: when the identity is the encryption device before switching, call the port corresponding to the encryption device before switching, and based on the port, use the encryption device before switching to decrypt the data in the page to be decrypted; or, when the identity is the encryption device after switching, call the port corresponding to the encryption device after switching, and based on the port, use the encryption device after switching to decrypt the data in the page to be decrypted.
[0022] In a possible implementation manner, the processing module is further configured to, after determining whether the initial digest value is the same as the target digest value, determine the identity of the target encryption device according to the target encryption device information if not; when the identity is the encryption device before switching, calculate the latest target digest value based on the information related to the encryption device after switching, and determine whether the latest target digest value is the same as the initial digest value; and when they are the same, the decryption module is further configured to use the switched encryption device to decrypt the data in the to-be-decrypted page;
[0023] Alternatively, the processing module is further used to calculate the latest target digest value based on the relevant information of the encryption device before switching when the identity is the switched encryption device, and to determine whether the latest target digest value is the same as the initial digest value. The decryption module is further used to decrypt the data in the page to be decrypted using the encryption device before switching when they are the same.
[0024] In a possible implementation manner, the processing module is further configured to, after determining whether the latest target summary value is the same as the initial summary value, generate target prompt information if they are different, and display the target prompt information on a corresponding operation interface.
[0025] In a third aspect, an embodiment of the present application provides an electronic device, including: a memory, a processor;
[0026] The memory stores computer-executable instructions;
[0027] The processor executes the computer-executable instructions stored in the memory, so that the processor executes the above first aspect and / or various possible implementations of the first aspect.
[0028] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are executed by a processor, they are used to implement the first aspect above and / or various possible implementations of the first aspect.
[0029] In a fifth aspect, an embodiment of the present application provides a computer program product, including a computer program, which, when executed by a processor, implements the above first aspect and / or various possible implementation methods of the first aspect.
[0030] The data decryption method, electronic device, storage medium and program product provided by the embodiment of the present application, because when the currently used encryption device is used to encrypt the data in the database device, a unique initial summary value is recorded on each page, so in response to the failure of the switch operation for the encryption device currently used by the database device, by determining the page to be decrypted, and obtaining the page information, target encryption device information and initial summary value according to the page to be decrypted, the preset summary algorithm can be used to calculate the page information and the target encryption device information to obtain the target summary value, and by judging whether the initial summary value is the same as the target summary value, the identity of the target encryption device can be determined according to the target encryption device information when it is determined that they are the same, so as to decrypt the data in the page to be decrypted according to the identity. The success rate of decryption is improved, and the accuracy of decryption is improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0032] Figure 1 A schematic diagram of a scenario of the data decryption method provided in this application;
[0033] Figure 2 Schematic diagram of the data decryption method provided in this application Figure 1 ;
[0034] Figure 3 Schematic diagram of the data decryption method provided in this application Figure 2 ;
[0035] Figure 4 A schematic diagram of the structure of the data decryption device provided by this application;
[0036] Figure 5 A schematic diagram of the structure of the electronic device provided in this application.
[0037] The above drawings have shown clear embodiments of the present application, which will be described in more detail later. These drawings and text descriptions are not intended to limit the scope of the present application in any way, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION
[0038] Exemplary embodiments will be described in detail herein, examples of which are shown in the accompanying drawings. When the following description refers to the drawings, the same numbers in different drawings represent the same or similar elements unless otherwise indicated. The implementations described in the following exemplary embodiments do not represent all implementations consistent with the present application. Instead, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.
[0039] First, the terms involved in this application are explained:
[0040] Encryption device: refers to the hardware device responsible for encrypting and decrypting data in the database, such as a network cipher machine.
[0041] Digest algorithm: refers to a password-based hash function, which is an algorithm that converts data input of arbitrary length into an output of fixed length (usually called a hash value or digest).
[0042] At present, when decrypting, generally when the database creates an encryption object, it records the encryption device information corresponding to the encryption device used, such as the encryption device name and the algorithm used by the device, in units of data tables or data table spaces. Then, in response to the need to switch the hardware encryption device, when the switch fails, the corresponding encrypted data is decrypted according to the recorded encryption device information. However, the time point of the switch failure is uncertain. In the same data table, some data may be encrypted by the hardware encryption device before the switch, and the other part may be encrypted by the hardware encryption device after the switch, resulting in inaccurate recorded content, which in turn leads to decryption failure and reduces the accuracy of decryption.
[0043] The data decryption method provided by the present application, in order to improve the success rate of decryption and thus improve the accuracy of decryption, does not record the encryption device information used, such as the encryption device name and the algorithm adopted by the device, only in units of data tables or data table spaces, but on this basis, uses the smallest unit of encryption, i.e., page, as a unit, generates a unique summary value according to the specific information of the page and the recorded encryption device information, and records the summary value in the page, then subsequently responds to switching the encryption device currently used by the database device. If the switching fails, the page to be decrypted is determined, and another unique summary value is generated according to the specific information of the page to be decrypted and the recorded encryption device information, so that the two summary values are compared, and when the comparison result is consistent, the device corresponding to the recorded encryption device information is used to decrypt the data of the page to be decrypted, thereby improving the success rate of decryption and thus improving the accuracy of decryption.
[0044] Figure 1 A schematic diagram of a scenario of the data decryption method provided in this application, such as Figure 1 As shown, the system corresponding to the data decryption method provided in this embodiment includes: a database device 1, a password management device 2, and a user terminal 3. Among them, the database device 1 is a device for storing data, the password management device 2 is a device for managing password-related information, and the user terminal 3 is a terminal where the database administrator is located. Among them, the database device 1 is connected to the password management device 2 and the user terminal 3 for communication. First, based on the need to switch the decryption device currently used by the database device 1, the database administrator triggers a switching operation on the operation interface corresponding to the user terminal 3. Then, in response to the failure of the switching operation for the currently used encryption device, the database device 1 determines the page to be decrypted, and obtains the page information and the initial digest value according to the page to be decrypted, that is, the unique digest value determined when the page to be decrypted is encrypted, and obtains the target encryption device information based on the password management device 2, so as to calculate the page information and the target encryption device information using a preset digest algorithm to obtain the target digest value. Then, it is determined whether the initial digest value is the same as the target digest value. If so, the identity of the target encryption device is determined according to the target encryption device information, and the data in the page to be decrypted is decrypted according to the identity.
[0045] The technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems are described in detail below with specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.
[0046] Figure 2 Schematic diagram of the data decryption method provided in this application Figure 1 ,like Figure 2As shown, the execution subject is a data decryption device, which is located in an electronic device, specifically in a database device. The method includes:
[0047] S201. In response to a failure in executing a switch operation on an encryption device currently used by a database device, determine a page to be decrypted, and obtain page information, target encryption device information, and an initial digest value based on the page to be decrypted; the initial digest value is a unique digest value determined when encrypting the page to be decrypted.
[0048] The database device is a hardware and software system for storing, managing and processing data, and may be any storage device, such as a storage server, etc. This embodiment does not limit the specific database device.
[0049] The currently used encryption device is the encryption device used for the encrypted data in the database device before the switch is executed. The switch operation is an operation to switch the currently used encryption device based on a replacement requirement, such as a replacement requirement based on device aging, performance issues, security upgrades, or compliance requirements.
[0050] The page to be decrypted is an encrypted page waiting to be decrypted, and may include specific encrypted data.
[0051] In this embodiment, the relevant management personnel of the database device can connect the port of the encryption device to be replaced with the database device in advance based on the need to switch the currently used encryption device, and perform switching configuration on the corresponding client based on the connection result, thereby triggering the switching operation based on the configuration result. Based on this, the database device uses the currently used encryption device to gradually decrypt the data in the database according to the above switching configuration, and uses the encryption device to be replaced to gradually encrypt the above decrypted data based on the connection with the encryption device to be replaced. In response to the interruption of the above step-by-step decryption or encryption process, it is determined that the switching operation for the encryption device currently used by the database device has failed.
[0052] It is understandable that transparent storage encryption of a database is generally performed on a page basis, that is, a page is the smallest unit for performing encryption and decryption, and the execution process of the above-mentioned switching operation is a step-by-step execution process. Therefore, the location where the step-by-step decryption or encryption process is interrupted may be a page contained in a certain data table.
[0053] Based on this, in response to the failure of the switch operation for the encryption device currently used by the database device, the pages included in each data table in the database device, that is, the pages to be decrypted, are obtained in sequence according to the preset order, and the page information, the target encryption device information and the initial digest value are obtained according to the pages to be decrypted. The preset order is any pre-defined decryption order, for example, the alphabetical order of the data table identifier, or the order of the data size of the data table. This embodiment does not limit the specific preset order.
[0054] The page information is any information representing the page to be decrypted, and may specifically include information such as data and data type in the page to be decrypted. This embodiment does not limit the specific page information.
[0055] The target encryption device information is information related to the target encryption device recorded when creating an encryption object based on the data table to which the page to be decrypted belongs. The target encryption device is an encryption device determined to perform the encryption operation based on the data table to which the page to be decrypted belongs.
[0056] The initial digest value is a unique digest value recorded in the page to be decrypted when a specific encryption operation is performed on the page to be decrypted before the switching operation fails.
[0057] It can be understood that the execution scenario of this solution is a scenario of switching the currently used encryption device. Therefore, when the switching operation fails, some pages will be encrypted by the currently used encryption device, and the other pages will be encrypted by the encryption device to be replaced.
[0058] Based on this, when obtaining page information, target encryption device information and initial digest value according to the page to be decrypted, it can be specifically:
[0059] The page to be decrypted is read, and page information corresponding to the page to be decrypted is obtained according to the reading result.
[0060] And, an encryption object is created in advance based on the data table to which the page to be decrypted belongs, and the encryption device information used at this time is recorded. Subsequently, by obtaining the encryption device information recorded when the encryption object is created based on the data table, the target encryption device information corresponding to the page to be decrypted can be obtained. It can be understood that if the page to be decrypted is a page encrypted before the switching operation, the target encryption device information is the information corresponding to the encryption device currently used. If the page to be decrypted is a page that is re-encrypted during the switching operation, the target encryption device information is the information corresponding to the encryption device to be replaced.
[0061] And, pre-calculate the initial digest value corresponding to the page to be decrypted, and insert the corresponding initial digest value into the blank field reserved in the page to be decrypted. Then, by reading the above field, the initial digest value corresponding to the page to be decrypted can be obtained. It can be understood that if the page to be decrypted is a page encrypted before the switching operation, the initial digest value is the unique digest value recorded in the page to be decrypted when the encryption device currently used performs a specific encryption operation on the page to be decrypted. If the page to be decrypted is a page that is re-encrypted during the switching operation, the initial digest value is the unique digest value recorded in the page to be decrypted when the encryption device to be replaced performs a specific encryption operation on the page to be decrypted.
[0062] It is understandable that when recording the corresponding initial digest value in the page to be decrypted, it can be specifically stored in the page header of the page to be decrypted, or can be stored in other locations of the page to be decrypted. This embodiment does not limit the specific storage location.
[0063] S202: Calculate the page information and the target encryption device information using a preset digest algorithm to obtain a target digest value.
[0064] Among them, the preset digest algorithm is a pre-configured digest algorithm, for example, it can be a hash function algorithm such as SM3 algorithm, SHA-256, SHA-3, etc. This embodiment does not limit the specific preset digest algorithm used.
[0065] The target digest value is a digest value recalculated after the switching operation fails.
[0066] In this embodiment, after obtaining the page information corresponding to the page to be decrypted, the target encryption device information and the initial digest value, the corresponding target digest value is calculated according to the page information corresponding to the page to be decrypted and the target encryption device information.
[0067] Specifically, a preset digest algorithm can be defined in advance in the system configuration file or settings, and the preset digest algorithm can be loaded when the database device is started. Then, in response to calculating the corresponding target digest value according to the page information corresponding to the page to be decrypted and the target encryption device information, the pre-stored preset digest algorithm is obtained, and the preset digest algorithm is used to calculate the fields where the page information and the target encryption device information are located, and the calculation result is determined as the target digest value.
[0068] It should be noted that the calculation of the initial digest value corresponding to the page to be decrypted also adopts the above method, that is, if the page to be decrypted is a page encrypted before the switching operation, the page information of the page to be decrypted and the information corresponding to the currently used encryption device are calculated using the preset digest algorithm to obtain the initial digest value. If the page to be decrypted is a page that is re-encrypted during the switching operation, the page information of the page to be decrypted and the information corresponding to the encryption device to be replaced are calculated using the preset digest algorithm, and the digest value recorded before the switching operation is replaced with the calculated digest value to obtain the initial digest value.
[0069] S203: Determine whether the initial digest value is the same as the target digest value. If so, determine the identity of the target encryption device according to the target encryption device information, and decrypt the data in the to-be-decrypted page according to the identity.
[0070] In this embodiment, after obtaining the target digest value, the target digest value is compared with the initial digest value to determine whether the two values are the same. If so, it means that the target encryption device information recorded for the page to be decrypted is correct. The identity of the target encryption device is determined based on the target encryption device information, and when it is determined that the target encryption device is the currently used encryption device, the currently used encryption device is used to decrypt the data in the page to be decrypted. When it is determined that the target encryption device is the encryption device to be replaced, the encryption device to be replaced is used to decrypt the data in the page to be decrypted.
[0071] The data decryption method provided in this embodiment records a unique initial digest value on each page when the currently used encryption device is used to encrypt the data in the database device. Therefore, in response to the failure of the switch operation for the encryption device currently used by the database device, by determining the page to be decrypted, and obtaining the page information, target encryption device information and initial digest value according to the page to be decrypted, the page information and the target encryption device information can be calculated using a preset digest algorithm to obtain the target digest value, and by judging whether the initial digest value is the same as the target digest value, the identity of the target encryption device can be determined according to the target encryption device information when it is determined that they are the same, thereby decrypting the data in the page to be decrypted according to the identity. The success rate of decryption is improved, and the accuracy of decryption is improved.
[0072] As an optional embodiment, based on the above embodiment, this embodiment further refines the process of obtaining page information, target encryption device information and initial digest value according to the page to be decrypted. When obtaining page information, target encryption device information and initial digest value according to the page to be decrypted, this embodiment specifically includes the following steps:
[0073] Step a1: Obtain basic information and page details of the page to be decrypted to obtain page information.
[0074] The basic information is basic information that characterizes the identity of the page to be decrypted, and may include, for example, the database device name, the mode name of the page to be decrypted, the storage file name of the data table to which the page to be decrypted belongs, and the page block number of the page to be decrypted in the data table to which it belongs. The page detail information is the data detail information contained in the page to be decrypted.
[0075] In this embodiment, after determining the page to be decrypted, the content included in the page to be decrypted is read to obtain page detail information corresponding to the page to be decrypted, and the database device name, the data structure / format of the page to be decrypted, the storage file name of the data table to which the page to be decrypted belongs, and the page block number of the page to be decrypted in the data table to which it belongs are determined to obtain page detail information corresponding to the page to be decrypted, thereby obtaining page information.
[0076] Step a2: Determine the data table to which the to-be-decrypted page belongs, and obtain the target encryption device information recorded when the encryption object is created for the corresponding data table.
[0077] In this embodiment, based on the obtained page information, the target encryption device information of the page to be decrypted is obtained. Specifically, the data table to which the page to be decrypted belongs is determined, and the encryption device information recorded when the encryption object is created based on the above data table is obtained from the password management device, and the encryption device information is determined as the target encryption device information.
[0078] Step a3: Read the characters of the preset embedded field in the page to be decrypted, and determine the characters as the initial digest value and obtain it.
[0079] The preset embedded field is a field pre-set in the page to be decrypted and used to store the initial digest value.
[0080] It can be understood that, since the initial digest value is stored in advance in the page to be decrypted, by reading the characters of the preset embedded field in the page to be decrypted, the characters can be determined as the initial digest value and obtained.
[0081] For example, when the initial digest value is stored in the page to be decrypted, the field char pg_encinfo_digit[XX] may be inserted in advance at the following position of the page to be decrypted, that is:
[0082] typedef struct PageHdr
[0083] {
[0084] PageWlog pg_lsd;
[0085] char pg_encinfo_digit[XX];
[0086] Uinit16 pg_flags; ...
[0088] }
[0089] Then, by reading char pg_encinfo_digit[XX] in the page to be decrypted, the specific value represented by XX can be determined as the initial summary value and obtained.
[0090] Among them, PageWlog pg_lsd is used to store the log information of the page to be decrypted. char pg_encinfo_digit[XX] is a preset embedded field for recording summary values, which is used to store the summary value corresponding to the page to be decrypted. The size of XX is usually consistent with the output length of the preset summary algorithm used. Uinit16 pg_flags is used to store the flag bits of the page to be decrypted, such as page status, type and other information.
[0091] It should be understood that the above examples are only for illustrative purposes and should not constitute any limitation to the present application.
[0092] The data decryption method provided in this embodiment can obtain the page information by obtaining the basic information and page details of the page to be decrypted, and by determining the data table to which the page to be decrypted belongs, the target encryption device information recorded when the encryption object is created for the data table to which it belongs can be obtained, and by reading the characters of the preset embedded field in the page to be decrypted, the characters can be determined as the initial summary value and obtained. In this way, the page information, the target encryption device information and the initial summary value can be obtained smoothly, and the success rate of the acquisition is improved.
[0093] As an optional embodiment, based on the above embodiment, this embodiment further refines the content included in the target encryption device information, and uses a preset digest algorithm to calculate the page information and the target encryption device information to obtain a target digest value. In this embodiment, the target encryption device information includes a target encryption device identifier and an encryption algorithm; when the preset digest algorithm is used to calculate the page information and the target encryption device information to obtain the target digest value, the following steps are specifically included:
[0094] Step b1: combine the page information, the target encryption device identifier and the encryption algorithm into a target character string, and obtain the key information stored in the target encryption device.
[0095] In this embodiment, the target encryption device information includes a target encryption device identifier and an encryption algorithm. The target encryption device identifier is any identifier that characterizes the identity of the target encryption device, such as the name or number of the target encryption device. The specific form of the identifier is not limited in this embodiment. The encryption algorithm is the encryption algorithm used by the target encryption device when performing encryption.
[0096] The target string is a specific string for calculating the digest value.
[0097] The key information is the key information stored in the target encryption device and used during encryption.
[0098] It is understandable that the encryption algorithm and key information used by the same target encryption device may be the same or different, and this embodiment does not limit this.
[0099] Based on this, in response to using a preset digest algorithm to calculate the page information and the target encryption device information to obtain the target digest value, the page information, the target encryption device identifier, and the field where the encryption algorithm is located are first converted into byte representation, and the above bytes are combined into a target string, and then based on the password management device, the key information stored in the target encryption device is read.
[0100] Step b2: Combined with the key information, a preset digest algorithm is used to calculate the target character string to obtain a target digest value.
[0101] In this embodiment, after obtaining the target character string and key information, the target character string is padded according to the preset digest algorithm under the encryption of the key information so that its total length meets the requirements of the preset digest algorithm, and then the initial hash value corresponding to the preset digest algorithm is obtained, and the padded data is divided into corresponding blocks, and a compression operation is performed on each block. Each block is mixed with the initial hash value through operation to obtain a new hash value, and the final target digest value is output based on the new hash values corresponding to all blocks.
[0102] It is understandable that when calculating the initial digest value, the method of this embodiment may also be used for calculation, and the calculation method of the initial digest value should be consistent with the calculation method of the target digest value.
[0103] The data decryption method provided in this embodiment, since the algorithm and / or key information adopted by the same target encryption device may be the same or different, by combining the page information, the target encryption device identification and the encryption algorithm into a target character string, and obtaining the key information stored in the target encryption device, the target character string can be calculated using a preset summary algorithm in combination with the key information, and a target summary value that takes into account the identity of the target encryption device, the algorithm adopted by the target encryption device, and the key information adopted by the target encryption device can be obtained, thereby improving the accuracy and security of the determined summary value.
[0104] As an optional embodiment, based on the above embodiment, after calculating the target character string by using a preset digest algorithm in combination with the key information, this embodiment further includes the following steps:
[0105] Step c1: Get the calculation results and the preconfigured number of iterations.
[0106] The calculation result is the calculation result obtained by calculating the target string using a preset digest algorithm, and the number of iterations is the number of iterations performed on the calculation result.
[0107] In this embodiment, in order to further improve the accuracy of the determined digest value, iterative calculation can be performed on the calculation result. Specifically, the number of iterations can be pre-configured, and after the target string is calculated using a preset digest algorithm in combination with the key information, the calculation result is obtained, and the pre-configured number of iterations is obtained.
[0108] Step c2: Iterate the calculation result using a preset digest algorithm according to a preconfigured number of iterations to obtain a target digest value.
[0109] In this embodiment, based on the obtained calculation result and the preconfigured number of iterations, the calculation result is iteratively calculated multiple times using a preset digest algorithm according to the above number of iterations, and then in response to the actual number of iterations reaching the preconfigured number of iterations, the calculation result at this time is determined as the target digest value. It can be understood that the calculation method used in each iterative calculation is similar to the calculation method in step b2, which will not be repeated here.
[0110] The data decryption method provided in this embodiment has a pre-configured number of iterations. Therefore, by obtaining the calculation result and the pre-configured number of iterations, the calculation result can be iteratively calculated using a preset digest algorithm according to the pre-configured number of iterations to obtain a target digest value, thereby further improving the accuracy of the determined digest value.
[0111] As an optional embodiment, this embodiment further refines the decryption of data in the decryption page according to the identity based on any of the above embodiments. When decrypting data in the decryption page according to the identity, this embodiment specifically includes the following steps:
[0112] Step d1: When the identity is the encryption device before switching, call the port corresponding to the encryption device before switching, and based on the port, use the encryption device before switching to decrypt the data in the page to be decrypted.
[0113] In this embodiment, based on the result that the target digest value is the same as the initial digest value, the identity of the target encryption device is first determined according to one or more of the target encryption device identifier, the encryption algorithm, and the key information in the target encryption device information.
[0114] The encryption device before switching is the currently used encryption device, and the encryption device after switching is the encryption device to be replaced.
[0115] Exemplarily, when the encryption device before switching and the encryption device after switching are different, only the target encryption device identifier can be used to determine the identity of the target encryption device. When the encryption device before switching and the encryption device after switching are the same, but the encryption algorithm and key information are different, the encryption algorithm and / or key information can be used to determine the identity of the target encryption device. When the encryption device before switching and the encryption device after switching are the same and the encryption algorithms used by both are also the same, but the key information is different, the key information can be used to determine the identity of the target encryption device. When the encryption device before switching and the encryption device after switching are the same and the key information used by both are also the same, but the encryption algorithms are different, the encryption algorithm can be used to determine the identity of the target encryption device. This example is for example only and should not constitute any limitation to this application.
[0116] Based on this, when the identity is determined to be the encryption device before switching, the port corresponding to the encryption device before switching is called according to the connected encryption device, and based on the connection of the port, the encryption device before switching is used to perform a decryption operation on the data in the decryption page.
[0117] Alternatively, step d2: when the identity is the switched encryption device, the port corresponding to the switched encryption device is called, and based on the port, the switched encryption device is used to decrypt the data in the to-be-decrypted page.
[0118] In this embodiment, when the identity is determined to be a switched encryption device, the port corresponding to the switched encryption device is called according to the connected encryption device, and based on the connection of the port, the switched encryption device is used to perform a decryption operation on the data in the page to be decrypted.
[0119] The data decryption method provided in this embodiment connects the encryption device before switching and the encryption device after switching based on the corresponding ports during switching. Therefore, when the identity is the encryption device before switching, by calling the port corresponding to the encryption device before switching, the encryption device before switching can be used to decrypt the data in the page to be decrypted based on the port; or, when the identity is the encryption device after switching, by calling the port corresponding to the encryption device after switching, the encryption device after switching can be used to decrypt the data in the page to be decrypted based on the port, thereby smoothly performing decryption and further improving the success rate of decryption.
[0120] As an optional embodiment, based on any of the above embodiments, after determining whether the initial digest value is the same as the target digest value, this embodiment further includes the following steps:
[0121] Step e1: If not, determine the identity of the target encryption device according to the target encryption device information.
[0122] In this embodiment, after determining whether the initial digest value is the same as the target digest value, if not, it means that the recorded target encryption device information is inaccurate, so the identity of the target encryption device is first determined based on the target encryption device information. The specific determination method is similar to the method described in step d1 and will not be repeated here.
[0123] Step e2: When the identity is the encryption device before switching, calculate the latest target digest value based on the relevant information of the encryption device after switching, and determine whether the latest target digest value is the same as the initial digest value. If they are the same, use the encryption device after switching to decrypt the data in the decryption page.
[0124] In this embodiment, based on the two possible identities of the target encryption device, i.e., the encryption device before switching and the encryption device after switching, after determining the identity of the target encryption device, if the identity is the encryption device before switching, the latest target digest value is calculated according to the page information of the page to be decrypted and the related information of the encryption device after switching, and it is determined whether the latest target digest value is the same as the initial digest value, so that when they are the same, the encryption device after switching is used to decrypt the data in the page to be decrypted. The specific execution process is similar to steps S202-S203, and will not be repeated here.
[0125] Among them, the information related to the switched encryption device may specifically include the switched encryption device identification, algorithm information and key information. When calculating the latest target summary value based on the switched encryption device identification, algorithm information and key information, the calculation can be performed according to the method described in steps b1-b2, and will not be repeated here.
[0126] Alternatively, step e3: when the identity is the encryption device after switching, the latest target digest value is calculated based on the relevant information of the encryption device before switching, and it is determined whether the latest target digest value is the same as the initial digest value. If they are the same, the encryption device before switching is used to decrypt the data in the decryption page.
[0127] Similarly, after determining the identity of the target encryption device, if the identity is the switched encryption device, the latest target digest value is calculated according to the page information of the page to be decrypted and the relevant information of the encryption device before the switch, and it is determined whether the latest target digest value is the same as the initial digest value, so that if they are the same, the encryption device before the switch is used to decrypt the data in the page to be decrypted. The specific execution process is similar to steps S202-S203, and will not be repeated here.
[0128] Among them, the encryption device related information before switching may specifically include the encryption device identification, algorithm information and key information before switching. When calculating the latest target summary value based on the encryption device identification, algorithm information and key information before switching, the calculation can be performed according to the method described in steps b1-b2, and will not be repeated here.
[0129] The data decryption method provided by the present embodiment determines the identity of the target encryption device according to the target encryption device information when the target digest value corresponding to the page to be decrypted is inconsistent with the initial digest value. When the identity is determined to be the encryption device before switching, the latest target digest value can be calculated based on the relevant information of the encryption device after switching, and it can be further determined whether the latest target digest value is the same as the initial digest value. If they are the same, the encryption device after switching is used to decrypt the data in the page to be decrypted; or, when the identity is the encryption device after switching, the latest target digest value can be calculated based on the relevant information of the encryption device before switching, and it can be determined whether the latest target digest value is the same as the initial digest value. If they are the same, the encryption device before switching is used to decrypt the data in the page to be decrypted. In this way, when the recorded target encryption device information is inaccurate, the page to be decrypted can be successfully decrypted, thereby further improving the success rate of decryption.
[0130] As an optional embodiment, based on the above embodiment, after determining whether the latest target digest value is the same as the initial digest value, this embodiment further includes the following steps:
[0131] At different times, target prompt information is generated and displayed on the corresponding operation interface.
[0132] The target prompt information is to inform relevant management personnel that there is a fault in the data encryption and decryption settings.
[0133] In this embodiment, if the latest target digest value is still different from the initial digest value, it means that the data in the page to be decrypted may be garbled or have other faults. Based on the result of the fault, target prompt information is generated and displayed on the corresponding operation interface so that relevant managers can be informed of the result of the fault in a timely manner.
[0134] The data decryption method provided in this embodiment generates target prompt information when the latest target summary value is still different from the initial summary value, and displays the target prompt information on the corresponding operation interface, so that relevant managers can smoothly learn the results of the failure and improve the user experience.
[0135] Figure 3 Schematic diagram of the data decryption method provided in this application Figure 2 ,like Figure 3 As shown, this embodiment describes in detail the complete process of the data decryption method, which includes:
[0136] S301: In response to a failure in executing a switch operation on an encryption device currently used by a database device, determine a page to be decrypted.
[0137] S302: Obtain basic information and page details of the page to be decrypted to obtain page information.
[0138] S303, determining the data table to which the to-be-decrypted page belongs, and obtaining target encryption device information recorded when creating an encryption object for the data table; the target encryption device information includes a target encryption device identifier and an encryption algorithm.
[0139] S304, reading characters of a preset embedded field in the page to be decrypted, and determining and acquiring the characters as an initial digest value; the initial digest value is a unique digest value determined when the page to be decrypted is encrypted.
[0140] S305: Combine the page information, the target encryption device identifier, and the encryption algorithm into a target character string, and obtain the key information stored in the target encryption device.
[0141] S306: Calculate the target character string using a preset digest algorithm in combination with the key information.
[0142] S307: Obtain calculation results and a preconfigured number of iterations.
[0143] S308. Iteratively calculate the calculation result using a preset digest algorithm according to a preconfigured number of iterations to obtain a target digest value.
[0144] S309, judging whether the initial digest value is the same as the target digest value, and determining the identity of the target encryption device according to the target encryption device information, if so, executing S310 or S311, if not, executing S312 or S313.
[0145] S310: When the identity is the encryption device before switching, call the port corresponding to the encryption device before switching, and based on the port, use the encryption device before switching to decrypt the data in the page to be decrypted.
[0146] S311. When the identity is a switched encryption device, call a port corresponding to the switched encryption device, and based on the port, use the switched encryption device to decrypt data in the page to be decrypted.
[0147] S312. When the identity is the encryption device before switching, calculate the latest target digest value based on the information related to the encryption device after switching, and determine whether the latest target digest value is the same as the initial digest value. If so, execute S314; if not, execute S316.
[0148] S313. When the identity is the switched encryption device, calculate the latest target digest value based on the encryption device related information before the switch, and determine whether the latest target digest value is the same as the initial digest value. If so, execute S315; if not, execute S316.
[0149] S314, using the switched encryption device to decrypt the data in the page to be decrypted.
[0150] S315: Decrypt the data in the page to be decrypted using the encryption device before switching.
[0151] S316: Generate target prompt information, and display the target prompt information on the corresponding operation interface.
[0152] Figure 4 A schematic diagram of the structure of the data decryption device provided by this application, such as Figure 4 As shown, the data decryption device 40 may be located in an electronic device, specifically in a database device. The data decryption device 40 provided in this embodiment includes: a processing module 41 and a decryption module 42.
[0153] Among them, the processing module 41 is used to determine the page to be decrypted in response to the failure of the switching operation on the encryption device currently used by the database device, and obtain page information, target encryption device information and initial digest value according to the page to be decrypted; the initial digest value is a unique digest value determined when the page to be decrypted is encrypted; the page information and the target encryption device information are calculated using a preset digest algorithm to obtain a target digest value; it is determined whether the initial digest value is the same as the target digest value, and if so, the identity of the target encryption device is determined according to the target encryption device information; the decryption module 42 is used to decrypt the data in the page to be decrypted according to the identity.
[0154] Optionally, when the processing module 41 obtains page information, target encryption device information and an initial summary value based on the page to be decrypted, it is specifically used to: obtain basic information and page detail information of the page to be decrypted to obtain page information; determine the data table to which the page to be decrypted belongs, and obtain the target encryption device information recorded when creating an encryption object for the data table to which it belongs; read the characters of a preset embedded field in the page to be decrypted, and determine the characters as the initial summary value and obtain it.
[0155] Optionally, the target encryption device information includes a target encryption device identifier and an encryption algorithm;
[0156] Accordingly, when the processing module 41 uses a preset digest algorithm to calculate the page information and the target encryption device information to obtain a target digest value, it is specifically used to: combine the page information, the target encryption device identifier and the encryption algorithm into a target string, and obtain the key information stored in the target encryption device; in combination with the key information, use the preset digest algorithm to calculate the target string to obtain the target digest value.
[0157] Optionally, the processing module 41 is further used to obtain a calculation result and a preconfigured number of iterations after calculating the target string using a preset digest algorithm in combination with the key information; and iteratively calculate the calculation result using the preset digest algorithm according to the preconfigured number of iterations to obtain a target digest value.
[0158] Optionally, the decryption module 42, when decrypting data in a decryption page according to an identity, is specifically used to: when the identity is an encryption device before switching, call a port corresponding to the encryption device before switching, and based on the port, use the encryption device before switching to decrypt the data in the decryption page; or, when the identity is an encryption device after switching, call a port corresponding to the encryption device after switching, and based on the port, use the encryption device after switching to decrypt the data in the decryption page.
[0159] Optionally, the processing module 41 is further used to determine whether the initial digest value is the same as the target digest value, and if not, determine the identity of the target encryption device according to the target encryption device information; when the identity is the encryption device before switching, calculate the latest target digest value based on the information related to the encryption device after switching, and determine whether the latest target digest value is the same as the initial digest value, and the decryption module 42 is further used to use the switched encryption device to decrypt the data in the to-be-decrypted page if they are the same;
[0160] Alternatively, the processing module 41 is also used to calculate the latest target digest value based on the relevant information of the encryption device before switching when the identity is the switched encryption device, and to determine whether the latest target digest value is the same as the initial digest value. The decryption module 42 is also used to use the encryption device before switching to decrypt the data in the decryption page when they are the same.
[0161] Optionally, the processing module 41 is further configured to, after determining whether the latest target summary value is the same as the initial summary value, generate target prompt information if they are different, and display the target prompt information on a corresponding operation interface.
[0162] The data decryption device provided in this embodiment can execute the method provided in the above method embodiment. Its implementation principle and technical effect are similar, and this embodiment will not be described in detail here.
[0163] Figure 5 This is a schematic diagram of the structure of the electronic device provided in this application. Figure 5 As shown, the electronic device 50 provided in this embodiment includes: at least one processor 51 and a memory 52. Optionally, the device 50 also includes a communication component 53. The processor 51, the memory 52 and the communication component 53 are connected via a bus 54.
[0164] In a specific implementation process, at least one processor 51 executes the computer-executable instructions stored in the memory 52, so that at least one processor 51 executes the above method.
[0165] The specific implementation process of the processor 51 can be found in the above method embodiment, and its implementation principle and technical effect are similar, so this embodiment will not be repeated here.
[0166] In the above embodiments, it should be understood that the processor may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), etc. A general-purpose processor may be a microprocessor or any conventional processor. The steps of the method disclosed in the invention may be directly implemented as being executed by a hardware processor, or may be executed by a combination of hardware and software modules in the processor.
[0167] The memory may include a high-speed memory (Random Access Memory, RAM), and may also include a non-volatile memory (Non-volatile Memory, NVM), such as at least one disk memory.
[0168] The bus may be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. The bus may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, the bus in the drawings of the present application is not limited to only one bus or one type of bus.
[0169] The present application also provides a computer program product, including a computer program, which implements the above method when executed by a processor.
[0170] The present application also provides a computer-readable storage medium, in which computer-executable instructions are stored. When a processor executes the computer-executable instructions, the above method is implemented.
[0171] The above-mentioned readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk. The readable storage medium can be any available medium that can be accessed by a general or special-purpose computer.
[0172] An exemplary readable storage medium is coupled to a processor so that the processor can read information from the readable storage medium and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can be located in an application specific integrated circuit (Application Specific Integrated Circuits, referred to as: ASIC). Of course, the processor and the readable storage medium can also exist in the device as discrete components.
[0173] The division of units is only a logical function division, and there may be other divisions in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interface, device or unit, which can be electrical, mechanical or other forms.
[0174] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0175] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0176] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the methods of each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, etc. Various media that can store program codes.
[0177] Those skilled in the art can understand that all or part of the steps of implementing the above-mentioned method embodiments can be completed by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, the steps of the above-mentioned method embodiments are executed; and the aforementioned storage medium includes: ROM, RAM, disk or optical disk and other media that can store program codes.
[0178] Finally, it should be noted that those skilled in the art will readily conceive of other embodiments of the present invention after considering the specification and practicing the invention disclosed herein. The present invention is intended to cover any variations, uses or adaptations of the present invention, which follow the general principles of the present invention and include common knowledge or customary technical means in the art not disclosed by the present invention, are not limited to the precise structure described above and shown in the drawings, and may be modified and changed in various ways without departing from the scope thereof. The scope of the present invention is limited only by the appended claims.
Claims
1. A data decryption method, characterized in that: The method is applied to a database device, and the method comprises: In response to a failure in performing a switch operation on an encryption device currently used by the database device, determining a page to be decrypted, and acquiring page information, target encryption device information, and an initial digest value according to the page to be decrypted; the initial digest value is a unique digest value determined when encrypting the page to be decrypted; Using a preset digest algorithm to calculate the page information and the target encryption device information to obtain a target digest value; It is determined whether the initial digest value is the same as the target digest value. If so, the identity of the target encryption device is determined according to the target encryption device information, and the data in the to-be-decrypted page is decrypted according to the identity.
2. The method according to claim 1, characterized in that The acquiring page information, target encryption device information and initial digest value according to the to-be-decrypted page includes: Obtaining basic information and page detail information of the page to be decrypted to obtain the page information; Determine the data table to which the to-be-decrypted page belongs, and obtain target encryption device information recorded when creating an encryption object for the data table; The characters of the preset embedded field in the to-be-decrypted page are read, and the characters are determined as the initial digest value and obtained.
3. The method according to claim 2, characterized in that The target encryption device information includes a target encryption device identifier and an encryption algorithm; The using a preset digest algorithm to calculate the page information and the target encryption device information to obtain a target digest value includes: Combining the page information, the target encryption device identifier and the encryption algorithm into a target character string, and obtaining key information stored in the target encryption device; In combination with the key information, the preset digest algorithm is used to calculate the target character string to obtain a target digest value.
4. The method according to claim 3, characterized in that After the target character string is calculated by using the preset digest algorithm in combination with the key information, the method further includes: Get the calculation results and the preconfigured number of iterations; The calculation result is iteratively calculated using the preset digest algorithm according to the preconfigured number of iterations to obtain a target digest value.
5. The method according to any one of claims 1 to 4, characterized in that: Decrypting the data in the to-be-decrypted page according to the identity includes: When the identity is the encryption device before switching, calling the port corresponding to the encryption device before switching, and based on the port, using the encryption device before switching to decrypt the data in the page to be decrypted; Alternatively, when the identity is a switched encryption device, a port corresponding to the switched encryption device is called, and based on the port, the switched encryption device is used to decrypt the data in the page to be decrypted.
6. The method according to any one of claims 1 to 4, characterized in that: After determining whether the initial digest value is the same as the target digest value, the method further includes: If not, determining the identity of the target encryption device according to the target encryption device information; When the identity is the encryption device before switching, the latest target digest value is calculated based on the information related to the encryption device after switching, and it is determined whether the latest target digest value is the same as the initial digest value, so that when they are the same, the switched encryption device is used to decrypt the data in the page to be decrypted; Alternatively, when the identity is the encryption device after switching, the latest target digest value is calculated based on the relevant information of the encryption device before switching, and it is determined whether the latest target digest value is the same as the initial digest value, so that when they are the same, the encryption device before switching is used to decrypt the data in the page to be decrypted.
7. The method according to claim 6, characterized in that After determining whether the latest target digest value is the same as the initial digest value, the method further includes: At different times, target prompt information is generated and displayed on a corresponding operation interface.
8. An electronic device, characterized in that: include: Memory, processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory, so that the processor performs the method according to any one of claims 1 to 7.
9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions, which are used to implement the method according to any one of claims 1 to 7 when executed by a processor.
10. A computer program product, characterized in that The invention comprises a computer program, which implements the method according to any one of claims 1 to 7 when being executed by a processor.