Cigarette enterprise platform data encryption method, electronic equipment and program product
By randomly generating and multi-layer encryption keys in the tobacco data processing platform, the problems of insufficient security and singularity of traditional encryption methods in the tobacco data processing platform are solved, and higher data security is achieved.
Patent Information
- Application Number
- CN202411860760.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-17
- Publication Date
- 2025-05-13
AI Technical Summary
Traditional data encryption methods have problems such as insufficient security and single encryption methods in tobacco data processing platforms, which are easily intercepted and deciphered, resulting in the original data of the entire network platform being disclosed.
Multi-layer encryption is realized and security is improved by randomly generating a first key for encrypting the original data, and generating a second key and a third key for encrypting or decrypting the first key based on a preset encryption policy.
Through a multi-layer encryption policy, it is ensured that one of the keys is not affected when it is stolen, which improves the security of the traditional encryption methods and the problem of insufficient security and singularity.
Smart Images

Figure CN119989375A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data encryption, and in particular to a data encryption method, electronic equipment and program product for a cigarette enterprise platform. Background Art
[0002] With the development of the times, the recording and review of tobacco data are no longer limited to traditional paper documents. Data storage, calculation, and review through network platforms are the mainstream form of tobacco data processing.
[0003] At present, although tobacco data processing based on the network platform is convenient and fast, the original data recorded in the platform involves the company's commercial information (such as tobacco ingredients, quality indicators and other important data), so data security has become a top priority. Traditional data security protection usually randomly generates corresponding keys for the original data to encrypt and protect the original data.
[0004] However, the keys generated by the above encryption method are easy to be intercepted and deciphered, and once the encryption method is deciphered, the original data of the entire network platform will be fully disclosed, resulting in the problems of insufficient security and single encryption method. Summary of the invention
[0005] In view of this, the purpose of the embodiments of the present application is to provide a cigarette enterprise platform data encryption method, electronic device and program product, which can improve the problems of insufficient encryption security and single form in traditional original data encryption methods.
[0006] In order to achieve the above technical objectives, the technical solutions adopted in this application are as follows: In a first aspect, an embodiment of the present application provides a method for encrypting data on a cigarette enterprise platform, the method comprising: Obtain the original data to be encrypted in the cigarette enterprise platform; Randomly generate a first key for encrypting the original data; Based on a preset first encryption strategy, generate a second key for encrypting or decrypting the first key, and encrypt or decrypt the first key by using the second key; Based on a preset second encryption strategy, a third key for encrypting or decrypting the first key and the second key is generated, and the first key and the second key are encrypted or decrypted by using the third key.
[0007] In combination with the first aspect, in some optional implementations, the first key includes a PKG key, a PIN key, and a MAC key; Randomly generating a first key for encrypting the original data, comprising: Randomly generate a PKG key for encrypting the entire original data; Randomly generate a PIN key for encrypting the user password in the original data; A MAC key is randomly generated for verifying the authenticity of the original data.
[0008] In combination with the first aspect, in some optional implementations, based on a preset first encryption strategy, generating a second key for encrypting or decrypting the first key, and encrypting or decrypting the first key by using the second key includes: Randomly generate two large prime numbers; Determine the second key according to the two large prime numbers, where the second key includes a first public key parameter and a first private key parameter; Encrypting the first key according to the first public key parameter to obtain a first ciphertext corresponding to the first key; The first ciphertext is decrypted according to the first private key parameter to obtain a first plaintext corresponding to the first key.
[0009] In combination with the first aspect, in some optional implementations, determining a first public key parameter and a first private key parameter of the second key according to the two large prime numbers includes: According to the two large prime numbers, determine the product of the two large prime numbers a and b as the modulus n; According to the two large prime numbers and the modulus, the Euler function value corresponding to the modulus is determined: ; Determine any integer c that is coprime to the Euler function value as the first public key parameter; Determine that the first public key parameters satisfy The d in is used as the first private key parameter.
[0010] In combination with the first aspect, in some optional implementations, encrypting the first key according to the first public key parameter to obtain a first ciphertext corresponding to the first key includes: According to the first public key parameter, the first key is encrypted by the following formula to obtain the first ciphertext: E=m c (mod n); Wherein, E represents the first ciphertext, m represents the first key, c represents the first public key parameter, and n represents the modulus of two large prime numbers.
[0011] In combination with the first aspect, in some optional implementations, decrypting the first ciphertext according to the first private key parameter to obtain a first plaintext corresponding to the first key includes: According to the first private key parameter, the first ciphertext is decrypted by the following formula to obtain the first plaintext: m=E d (mod n); Wherein, m represents the first plaintext, E represents the first ciphertext, d represents the first private key parameter, and n represents the modulus of two large prime numbers.
[0012] In combination with the first aspect, in some optional implementations, based on a preset second encryption strategy, generating a third key for encrypting or decrypting the first key and the second key, and encrypting or decrypting the first key and the second key by using the third key includes: Get two custom large prime numbers; Determine the third key according to the two self-defined large prime numbers, wherein the third key includes a second public key parameter and a second private key parameter; Encrypting the first key and the second key according to the second public key parameter to obtain a second ciphertext corresponding to the first key and the second key; The second ciphertext is decrypted according to the second private key parameter to obtain a second plaintext corresponding to the first key and the second key.
[0013] In combination with the first aspect, in some optional implementations, the method further includes: The first key for encrypting the original data is repeatedly and randomly generated at a preset period, and based on the preset first encryption strategy, the second key for encrypting or decrypting the first key is generated, and the first key is encrypting or decrypting by the second key to update the first key and the second key.
[0014] In a second aspect, an embodiment of the present application further provides an electronic device, comprising a processor and a memory coupled to each other, wherein a computer program is stored in the memory, and when the computer program is executed by the processor, the electronic device executes the above method.
[0015] In a third aspect, an embodiment of the present application further provides a computer program product, including a computer program, which implements the above method when executed by a processor.
[0016] The invention adopting the above technical solution has the following advantages: In the technical solution provided in the present application, the original data to be encrypted in the cigarette enterprise platform is first obtained. Then a first key for encrypting the original data is randomly generated. Then based on a preset first encryption strategy, a second key for encrypting or decrypting the first key is generated. Finally, based on the preset second encryption strategy, a third key for encrypting or decrypting the first key and the second key is generated. In this way, the original data is initially encrypted by the randomly generated first key, then the first key is encrypted by the second key, and finally the first key and the second key are decentralized encrypted by the third key to ensure that when one of the keys is stolen, the security of other keys is not affected. Improve the problems of insufficient encryption security and single form in traditional original data encryption methods. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] The present application may be further described by the non-limiting embodiments given in the accompanying drawings. It should be understood that the following drawings only illustrate certain embodiments of the present application and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, other relevant drawings may be obtained based on these drawings without creative effort.
[0018] Figure 1 A structural block diagram of an electronic device provided in an embodiment of the present application.
[0019] Figure 2 A flow chart of the cigarette enterprise platform data encryption method provided in the embodiment of the present application.
[0020] Icon: 100 - electronic device; 101 - processor; 102 - memory. DETAILED DESCRIPTION
[0021] The present application will be described in detail below in conjunction with the accompanying drawings and specific embodiments. It should be noted that in the drawings or descriptions, similar or identical parts use the same figure numbers, and the implementation methods not shown or described in the drawings are forms known to ordinary technicians in the relevant technical field. In the description of this application, the terms "first", "second", etc. are only used to distinguish the description and cannot be understood as indicating or implying relative importance.
[0022] Please refer to Figure 1 , the embodiment of the present application provides an electronic device 100 which may include a processor 101 and a memory 102. The memory 102 stores a computer program, and when the computer program is executed by the processor 101, the electronic device 100 can execute the corresponding steps in the following cigarette enterprise platform data encryption method.
[0023] In this embodiment, the processor 101 may be an integrated circuit chip having signal processing capabilities. The processor 101 may be a general-purpose processor. For example, the processor 101 may be a central processing unit (CPU), a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, and may implement or execute the methods, steps and logic block diagrams disclosed in the embodiments of the present application.
[0024] The memory 102 may be, but is not limited to, a random access memory, a read-only memory, a programmable read-only memory, an erasable programmable read-only memory, an electrically erasable programmable read-only memory, etc. In this embodiment, the memory 102 may be used to store original data, a first key, a preset first encryption strategy, a second key, a preset second encryption strategy, a third key, etc. Of course, the memory 102 may also be used to store a program, and the processor 101 executes the program after receiving an execution instruction.
[0025] Understandably, Figure 1 The structure of the electronic device 100 shown in FIG. 1 is only a schematic diagram of the structure. The electronic device 100 may also include Figure 1 More components are shown. Figure 1 Each component shown in the figure can be implemented by hardware, software or a combination thereof.
[0026] In this embodiment, the electronic device 100 can be a personal computer, a cloud server, a laptop computer, etc. It is used to obtain the original data to be encrypted in the cigarette enterprise platform. Then a first key for encrypting the original data is randomly generated. Then based on the preset first encryption strategy, a second key for encrypting or decrypting the first key is generated, and the first key is encrypted or decrypted by the second key. Finally, based on the preset second encryption strategy, a third key for encrypting or decrypting the first key and the second key is generated, and the first key and the second key are encrypted or decrypted by the third key.
[0027] Please refer to Figure 2 The present application also provides a method for encrypting data on a cigarette enterprise platform, which can be applied to the electronic device 100, and each step in the method is executed or implemented by the electronic device 100. The method for encrypting data on a cigarette enterprise platform can include the following steps: Step 210, obtaining the original data to be encrypted in the cigarette enterprise platform; Step 220, randomly generating a first key for encrypting the original data; Step 230: Based on a preset first encryption strategy, generate a second key for encrypting or decrypting the first key, and encrypt or decrypt the first key by using the second key; Step 240: Based on a preset second encryption strategy, generate a third key for encrypting or decrypting the first key and the second key, and encrypt or decrypt the first key and the second key by using the third key.
[0028] In the above-mentioned implementation, the original data to be encrypted in the cigarette enterprise platform is first obtained. Then a first key for encrypting the original data is randomly generated. Then based on a preset first encryption strategy, a second key for encrypting or decrypting the first key is generated. Finally, based on a preset second encryption strategy, a third key for encrypting or decrypting the first key and the second key is generated. In this way, the original data is initially encrypted by the randomly generated first key, and then the first key is encrypted by the second key. Finally, the first key and the second key are decentralized encrypted by the third key to ensure that when one of the keys is stolen, the security of other keys is not affected. Improve the problems of insufficient encryption security and single form in the traditional original data encryption method.
[0029] The following will describe in detail the steps of the data encryption method of the cigarette enterprise platform, as follows: In step 210, the acquisition of the original data may be in the process of tobacco enterprise data processing, by the processor 101 of the electronic device 100 real-time calling the original data (which may be tobacco information, tobacco price, subject information, etc.) in the cigarette enterprise platform, and performing subsequent encryption processing; or, the acquisition of the original data may also be in the development and testing stage, by storing the pre-input original data in the memory 102 of the electronic device 100, and calling it through the processor 101 in the subsequent encryption process of the original data. The method of acquiring the original data is not specifically limited here.
[0030] In step 220, the first key may include a PKG key, a PIN key, and a MAC key; Randomly generating a first key for encrypting the original data may include: Randomly generate a PKG key for encrypting the entire original data; Randomly generate a PIN key for encrypting the user password in the original data; A MAC key is randomly generated for verifying the authenticity of the original data.
[0031] In this embodiment, the PKG (Private Key Generator) key is used to encrypt the data packet of the entire original data called by the user during the data call process. The effective period of the PKG key changes dynamically with the call process, that is, the effective period of the PKG key is the same as the duration of the user calling the original data. The PIN (Personal identification Number) key is used to encrypt the user password in the original data, and the MAC (Message Authentication Code) key is used to verify the authenticity of the original data. Among them, the MAC algorithm is a non-public algorithm that combines the data verification algorithm and the DES (Data Encryption Standard) algorithm. It is mainly used to determine the authenticity of the received data packet to prevent attackers from constructing false data packets (such as fake contracts) and transmitting them to different terminals to achieve the purpose of committing crimes. The MAC key is the key used to calculate the MAC value. In this embodiment, the PIN key and the MAC key can be dynamic, and the effective period can be flexibly set according to user needs, such as 1 day, 2 days, etc. This embodiment takes 1 day as an example.
[0032] It is understandable that the PIN key and MAC key are two dynamically changing keys. Before starting data processing every day, when the cigarette enterprise platform receives a data call request, it randomly generates a new PIN key and MAC key, and randomly generates a different PKG key for each data call operation in each data call / processing. It is understandable that in order to avoid key theft, the first key (that is, PKG key, PIN key and MAC key) cannot be transmitted in plain text during transmission. Therefore, the first key is encrypted by the second key to ensure the security of the first key during transmission.
[0033] Specifically, in step 230, based on a preset first encryption strategy, generating a second key for encrypting or decrypting the first key, and encrypting or decrypting the first key by using the second key may include: Randomly generate two large prime numbers; Determine the second key according to the two large prime numbers, where the second key includes a first public key parameter and a first private key parameter; Encrypting the first key according to the first public key parameter to obtain a first ciphertext corresponding to the first key; The first ciphertext is decrypted according to the first private key parameter to obtain a first plaintext corresponding to the first key.
[0034] In this embodiment, determining the first public key parameter and the first private key parameter of the second key according to the two large prime numbers may include: According to the two large prime numbers, determine the product of the two large prime numbers a and b as the modulus n; According to the two large prime numbers and the modulus, the Euler function value corresponding to the modulus is determined: ; Determine any integer c that is coprime to the Euler function value as the first public key parameter; Determine that the first public key parameters satisfy The d in is used as the first private key parameter.
[0035] In this embodiment, encrypting the first key according to the first public key parameter to obtain a first ciphertext corresponding to the first key may include: According to the first public key parameter, the first key is encrypted by the following formula to obtain the first ciphertext: E=m c (mod n); Wherein, E represents the first ciphertext, m represents the first key, c represents the first public key parameter, and n represents the modulus of two large prime numbers.
[0036] In this embodiment, decrypting the first ciphertext according to the first private key parameter to obtain the first plaintext corresponding to the first key may include: According to the first private key parameter, the first ciphertext is decrypted by the following formula to obtain the first plaintext: m=E d (mod n); Wherein, m represents the first plaintext, E represents the first ciphertext, d represents the first private key parameter, and n represents the modulus of two large prime numbers.
[0037] In this way, the second key is generated through the above-mentioned preset first encryption strategy, and the encryption or decryption of the first key is achieved through the second key.
[0038] In step 240, based on a preset second encryption strategy, generating a third key for encrypting or decrypting the first key and the second key, and encrypting or decrypting the first key and the second key by using the third key may include: Get two custom large prime numbers; Determine the third key according to the two self-defined large prime numbers, wherein the third key includes a second public key parameter and a second private key parameter; Encrypting the first key and the second key according to the second public key parameter to obtain a second ciphertext corresponding to the first key and the second key; The second ciphertext is decrypted according to the second private key parameter to obtain a second plaintext corresponding to the first key and the second key.
[0039] In this embodiment, the determination of the second public key parameter and the second private key parameter can refer to the determination method of the above-mentioned first public key parameter and the first private key parameter, the process of encrypting the first key and the second key respectively by the second public key parameter can refer to the above-mentioned process of encrypting the first key by the first public key parameter, and the process of decrypting the first key and the second key respectively by the second private key parameter can refer to the above-mentioned process of decrypting the first key by the first private key parameter. The only difference is that the two large prime numbers in step 240 are user-defined.
[0040] In this embodiment, the first key (including the PKG key, the PIN key and the MAC key) and the second key can be encrypted respectively by presetting the second encryption strategy, and each third key is customized. In this way, decentralized management of the keys is achieved, and when any key among the third keys (such as the third key used to encrypt the PKG key) is stolen, the key can be immediately disabled and changed, while ensuring the security of other keys.
[0041] As an optional implementation, the method may further include: The first key for encrypting the original data is repeatedly and randomly generated at a preset period, and based on the preset first encryption strategy, the second key for encrypting or decrypting the first key is generated, and the first key is encrypting or decrypting by the second key to update the first key and the second key.
[0042] In this embodiment, the preset period can be flexibly set according to user needs, such as once a day, once an hour, once a week, etc. In an optional implementation, the preset period can be the same as the validity period of each key in the above-mentioned first key (PKG key, PIN key and MAC key).
[0043] In this embodiment, after the first key and the second key are generated, in order to ensure the security and real-time performance of the first key and the second key, the first key and the second key are periodically updated based on the validity period of the first key (since the second key is a further encryption process of the first key, the validity period of the second key is usually the same as that of the first key, that is, the two keys are effective and invalid at the same time). In this way, the encryption protection of the original data is further strengthened.
[0044] It should be noted that those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the electronic device 100 described above can refer to the corresponding process of each step in the aforementioned method, and will not be elaborated herein.
[0045] The embodiment of the present application also provides a computer program product, including a computer program, which implements the above-mentioned cigarette enterprise platform data encryption method when executed by the processor 101.
[0046] Through the description of the above implementation methods, technical personnel in this field can clearly understand that the present application can be implemented by hardware, and can also be implemented by means of software plus a necessary general hardware platform. Based on such an understanding, the technical solution of the present application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.), including a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each implementation scenario of the present application.
[0047] In summary, the embodiments of the present application provide a data encryption method, electronic device and program product for a cigarette enterprise platform. In this technical solution, the original data to be encrypted in the cigarette enterprise platform is first obtained. Then a first key for encrypting the original data is randomly generated. Then, based on a preset first encryption strategy, a second key for encrypting or decrypting the first key is generated. Finally, based on the preset second encryption strategy, a third key for encrypting or decrypting the first key and the second key is generated. In this way, the original data is initially encrypted by the randomly generated first key, and then the first key is encrypted by the second key, and finally the first key and the second key are decentralized encrypted by the third key, ensuring that when one of the keys is stolen, the security of other keys is not affected. Improve the problems of insufficient encryption security and single form in the traditional original data encryption method.
[0048] In the embodiments provided by the present application, it should be understood that the disclosed method can also be implemented in other ways. The method embodiments described above are merely schematic, for example, the flow charts and block diagrams in the accompanying drawings show the possible architecture, functions and operations of the methods and computer program products according to the multiple embodiments of the present application. In this regard, each box in the flow chart or block diagram can represent a part of a module, a program segment or a code, and a part of the module, a program segment or a code includes one or more executable instructions for implementing the specified logical function. It should also be noted that each box in the block diagram and / or the flow chart, and the combination of the boxes in the block diagram and / or the flow chart can be implemented by a dedicated hardware-based system that performs the specified function or action, or can be implemented by a combination of dedicated hardware and computer instructions. In addition, each functional module in each embodiment of the present application can be integrated together to form an independent part, or each module can exist separately, or two or more modules can be integrated to form an independent part.
[0049] The above description is only an embodiment of the present application and is not intended to limit the protection scope of the present application. For those skilled in the art, the present application may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.
Claims
1. A cigarette enterprise platform data encryption method, characterized in that: The method comprises: Obtain the original data to be encrypted in the cigarette enterprise platform; Randomly generate a first key for encrypting the original data; Based on a preset first encryption strategy, generate a second key for encrypting or decrypting the first key, and encrypt or decrypt the first key by using the second key; Based on a preset second encryption strategy, a third key for encrypting or decrypting the first key and the second key is generated, and the first key and the second key are encrypted or decrypted by using the third key.
2. The method according to claim 1, characterized in that The first key includes a PKG key, a PIN key and a MAC key; Randomly generating a first key for encrypting the original data, comprising: Randomly generate a PKG key for encrypting the entire original data; Randomly generate a PIN key for encrypting the user password in the original data; A MAC key is randomly generated for verifying the authenticity of the original data.
3. The method according to claim 1, characterized in that Based on a preset first encryption strategy, generating a second key for encrypting or decrypting the first key, and encrypting or decrypting the first key by using the second key, including: Randomly generate two large prime numbers; Determine the second key according to the two large prime numbers, where the second key includes a first public key parameter and a first private key parameter; Encrypting the first key according to the first public key parameter to obtain a first ciphertext corresponding to the first key; The first ciphertext is decrypted according to the first private key parameter to obtain a first plaintext corresponding to the first key.
4. The method according to claim 3, characterized in that Determining a first public key parameter and a first private key parameter of the second key according to the two large prime numbers includes: According to the two large prime numbers, determine the product of the two large prime numbers a and b as the modulus n; According to the two large prime numbers and the modulus, the Euler function value corresponding to the modulus is determined: ; Determine any integer c that is coprime to the Euler function value as the first public key parameter; Determine that the first public key parameters satisfy The d in is used as the first private key parameter.
5. The method according to claim 3, characterized in that: Encrypting the first key according to the first public key parameter to obtain a first ciphertext corresponding to the first key includes: According to the first public key parameter, the first key is encrypted by the following formula to obtain the first ciphertext: E=m c (mod n); Wherein, E represents the first ciphertext, m represents the first key, c represents the first public key parameter, and n represents the modulus of two large prime numbers.
6. The method according to claim 3, characterized in that Decrypting the first ciphertext according to the first private key parameter to obtain a first plaintext corresponding to the first key includes: According to the first private key parameter, the first ciphertext is decrypted by the following formula to obtain the first plaintext: m=E d (mod n); Wherein, m represents the first plaintext, E represents the first ciphertext, d represents the first private key parameter, and n represents the modulus of two large prime numbers.
7. The method according to claim 1, characterized in that Based on a preset second encryption strategy, generating a third key for encrypting or decrypting the first key and the second key, and encrypting or decrypting the first key and the second key by using the third key, including: Get two custom large prime numbers; Determine the third key according to the two self-defined large prime numbers, wherein the third key includes a second public key parameter and a second private key parameter; Encrypting the first key and the second key according to the second public key parameter to obtain a second ciphertext corresponding to the first key and the second key; The second ciphertext is decrypted according to the second private key parameter to obtain a second plaintext corresponding to the first key and the second key.
8. The method according to claim 1, characterized in that: The method further comprises: The first key for encrypting the original data is repeatedly and randomly generated at a preset period, and based on the preset first encryption strategy, the second key for encrypting or decrypting the first key is generated, and the first key is encrypting or decrypting by the second key to update the first key and the second key.
9. An electronic device, characterized in that: The electronic device comprises a processor and a memory coupled to each other, wherein the memory stores a computer program. When the computer program is executed by the processor, the electronic device executes the method according to any one of claims 1 to 8.
10. A computer program product, characterized in that The invention comprises a computer program which, when executed by a processor, implements the method according to any one of claims 1 to 8.