Data encryption method and device, computer equipment and storage medium

By using the fingerprint information of the encrypted hardware and user authentication information to generate an encryption key, the data to be processed is encrypted, and data security risks in the face of attack methods in the prior art are solved, and high-performance and high-security data encryption is achieved.

CN119989386APending Publication Date: 2025-05-13CHINA SOUTHERN POWER GRID INTERNET SERVICE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510160619.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-13
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

When existing encryption technologies face attacks on side channel and reverse engineering, they have security risks of data loss or data tampering.

Method used

By acquiring the fingerprint information of the encryption hardware, generating an encryption key in combination with the user authentication information, and using the key to encrypt the data to be processed when an encryption event is detected.

Benefits of technology

Effectively prevent encryption keys from being copied and forged, improve the security of data encryption, prevent security risks such as data loss or data tampering, and meet the high-performance encryption needs in different application scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119989386A_ABST
    Figure CN119989386A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of information security, in particular to a data encryption method and device, computer equipment and a storage medium. The method comprises the steps of obtaining an encryption key corresponding to to-be-processed data under the condition that an encryption event for the to-be-processed data is detected; wherein the encryption key is determined according to fingerprint information corresponding to the encryption hardware; and encrypting the to-be-processed data according to the encryption key to obtain target data. The encryption key generated according to the fingerprint information can be effectively prevented from being copied and counterfeited; and furthermore, after the to-be-processed data is encrypted according to the encryption key, high-performance encryption requirements in different application scenes can be effectively met, smooth proceeding of a data encryption process is ensured, the security of data encryption is improved, and potential safety hazards such as data loss or data tampering are prevented.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of information security technology, and in particular to a data encryption method, device, computer equipment and storage medium. Background Art

[0002] With the rapid development of information technology, information security issues are becoming increasingly prominent. Traditional encryption technology mainly relies on key management and algorithm complexity to ensure data security.

[0003] However, the encryption methods in the prior art may cause security risks such as data loss or data tampering when they are vulnerable to certain attack methods (such as side channel attacks, reverse engineering, etc.). Summary of the invention

[0004] Based on this, it is necessary to provide a data encryption method, device, computer equipment and storage medium that can improve data security in response to the above technical problems.

[0005] In a first aspect, the present application provides a data encryption method. The method comprises:

[0006] In the case of detecting an encryption event for the data to be processed, obtaining an encryption key corresponding to the data to be processed; wherein the encryption key is determined according to fingerprint information corresponding to the encryption hardware;

[0007] The data to be processed is encrypted according to the encryption key to obtain target data.

[0008] In one embodiment, the encryption key generation process includes:

[0009] Obtaining fingerprint information corresponding to encryption hardware, wherein the fingerprint information is generated according to hardware characteristics of the encryption hardware;

[0010] Receive user authentication information input by the user;

[0011] The encryption key is generated according to the fingerprint information and the user authentication information.

[0012] In one embodiment, generating the encryption key according to the fingerprint information and the user authentication information includes:

[0013] A key is generated for the fingerprint information and the user authentication information based on a preset target encryption algorithm to obtain the encryption key.

[0014] In one of the embodiments, the target encryption algorithm includes at least one of a symmetric encryption algorithm, an asymmetric encryption algorithm, and a hash algorithm.

[0015] In one of the embodiments, the user authentication information includes at least one of a user password and biometric information.

[0016] In one embodiment, the method further comprises:

[0017] Performing anomaly detection on the encryption key;

[0018] When the abnormality detection result indicates that an abnormality exists, the encryption key is deleted and new fingerprint information corresponding to the encryption hardware is generated;

[0019] The encryption key is generated according to the new fingerprint information and user authentication information.

[0020] In a second aspect, the present application also provides a data encryption device. The device comprises:

[0021] A detection module, used to detect the encryption time of the data to be processed and generate an encryption key corresponding to the data to be processed; wherein the encryption key is determined according to the fingerprint information corresponding to the encryption hardware;

[0022] The processing module is used to encrypt the data to be processed according to the encryption key to obtain target data.

[0023] In a third aspect, the present application further provides a computer device. The computer device includes a memory and a processor, the memory stores a computer program, and the processor implements the following steps when executing the computer program:

[0024] In the case of detecting an encryption event for the data to be processed, obtaining an encryption key corresponding to the data to be processed; wherein the encryption key is determined according to fingerprint information corresponding to the encryption hardware;

[0025] The data to be processed is encrypted according to the encryption key to obtain target data.

[0026] In a fourth aspect, the present application further provides a computer-readable storage medium. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the following steps are implemented:

[0027] In the case of detecting an encryption event for the data to be processed, obtaining an encryption key corresponding to the data to be processed; wherein the encryption key is determined according to fingerprint information corresponding to the encryption hardware;

[0028] The data to be processed is encrypted according to the encryption key to obtain target data.

[0029] In a fifth aspect, the present application further provides a computer program product. The computer program product includes a computer program, and when the computer program is executed by a processor, the following steps are implemented:

[0030] In the case of detecting an encryption event for the data to be processed, obtaining an encryption key corresponding to the data to be processed; wherein the encryption key is determined according to fingerprint information corresponding to the encryption hardware;

[0031] The data to be processed is encrypted according to the encryption key to obtain target data.

[0032] The above-mentioned data encryption method, device, computer equipment and storage medium, when an encryption event for the data to be processed is detected, obtains the encryption key corresponding to the data to be processed; then, the data to be processed is encrypted according to the encryption key to obtain the target data; wherein the encryption key is determined according to the fingerprint information corresponding to the encryption hardware. According to the above content, it can be known that the present application generates an encryption key through the fingerprint information corresponding to the encryption hardware, and then, the data to be processed is encrypted according to the encryption key to obtain the target data; since the fingerprint information is the unique identifier corresponding to the encryption hardware, and has the characteristics of being non-clonable and unpredictable, the encryption key generated according to the fingerprint information can effectively prevent being copied and forged; then, after the data to be processed is encrypted according to the encryption key, it can effectively respond to the high-performance encryption requirements in different application scenarios, ensure the smooth progress of the data encryption process, improve the security of data encryption, and prevent security risks such as data loss or data tampering. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] Figure 1 An application environment diagram of a data encryption method provided in an embodiment of the present application;

[0034] Figure 2 A schematic diagram of a flow chart of a first data encryption method provided in an embodiment of the present application;

[0035] Figure 3 A schematic diagram of a flow chart of a second data encryption method provided in an embodiment of the present application;

[0036] Figure 4 A schematic diagram of a two-factor authentication flow chart provided in an embodiment of the present application;

[0037] Figure 5 A structural block diagram of a data encryption device provided in an embodiment of the present application;

[0038] Figure 6 FIG. 4 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION

[0039] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0040] It should be noted that PUF technology can be used to solve technical problems. As an emerging security mechanism, PUF technology generates unique identifiers by utilizing the physical properties of the hardware itself. It is non-clonable and unpredictable, and can effectively prevent copying and counterfeiting. However, using PUF technology alone may not meet the high-performance encryption requirements in certain application scenarios. Therefore, combining PUF technology with traditional encryption chips can give full play to the advantages of both and build a more secure and reliable encryption system.

[0041] The data encryption method provided in the embodiment of the present application can be applied to Figure 1 In the application environment shown. Among them, the terminal 102 communicates with the server 104 through the network. The data storage system can store the data that the server 104 needs to process. The data storage system can be integrated on the server 104, or it can be placed on the cloud or other network servers. In the case of detecting an encryption event for the data to be processed, the encryption key corresponding to the data to be processed is obtained; then, the data to be processed is encrypted according to the encryption key to obtain the target data; wherein the encryption key is determined according to the fingerprint information corresponding to the encryption hardware. Among them, the terminal 102 can be, but is not limited to, various personal computers, laptops, smart phones, tablets, Internet of Things devices and portable wearable devices. The Internet of Things devices can be smart speakers, smart TVs, smart air conditioners, smart car-mounted devices, etc. Portable wearable devices can be smart watches, smart bracelets, head-mounted devices, etc. The server 104 can be implemented with an independent server or a server cluster consisting of multiple servers.

[0042] In one embodiment, Figure 2 As shown, a data encryption method is provided, which is applied to Figure 1 Taking the server 104 in the example as an example, the following steps are included:

[0043] S201, when an encryption event for the data to be processed is detected, obtaining an encryption key corresponding to the data to be processed.

[0044] The encryption key is determined according to the fingerprint information corresponding to the encryption hardware.

[0045] It should be noted that in order to ensure that the generated encryption key can effectively encrypt the data to be processed in the future, an identifier with the characteristics of being unclonable and unpredictable can be combined in the process of generating the encryption key; therefore, the encryption key can be determined based on the fingerprint information corresponding to the encryption hardware.

[0046] In one embodiment of the present application, when it is necessary to obtain the encryption key corresponding to the data to be processed, the following contents may be included: if the encryption key corresponding to the data to be processed is pre-stored, the encryption key corresponding to the data to be processed is extracted from the storage location of the encryption key; to ensure the smooth progress of subsequent processes.

[0047] In another embodiment of the present application, when it is necessary to obtain the encryption key corresponding to the data to be processed, the following contents may be included: if the encryption key corresponding to the data to be processed is not stored in advance, the fingerprint information corresponding to the encryption hardware is pre-processed to obtain the initial key; the processing minutes are used as part of the encryption key or input parameters to generate the encryption key.

[0048] S202, encrypt the data to be processed according to the encryption key to obtain target data.

[0049] It should be noted that when it is necessary to encrypt the data to be processed according to the encryption key, the following may be specifically included: generating a key for the fingerprint information based on a preset encryption algorithm to obtain an encryption key.

[0050] In one embodiment of the present application, when the target encryption algorithm is a symmetric encryption algorithm, the encryption processing of the data to be processed may include the following: dividing the data to be processed into data blocks of a fixed size, using an encryption algorithm and an encryption key to encrypt each data block to generate an encrypted ciphertext block; combining all the encrypted ciphertext blocks to form the final target data (encrypted complete ciphertext).

[0051] Among them, common symmetric encryption algorithms include DES, 3DES, AES, etc. The characteristic of these algorithms is that the same key is used for encryption and decryption, so the secure transmission of the key is very important.

[0052] In one embodiment of the present application, when the target encryption algorithm is an asymmetric encryption algorithm, the encryption processing of the data to be processed may include the following: the encryption key includes a public key and a private key; the public key of the recipient is used to encrypt the data to be processed to generate an encrypted ciphertext. The encrypted ciphertext is sent to the recipient. After receiving the ciphertext, the recipient uses its own private key to perform decryption processing to restore the original data to be processed.

[0053] Among them, common asymmetric encryption algorithms include RSA, DSA, etc.

[0054] The above data encryption method, when an encryption event for the data to be processed is detected, obtains the encryption key corresponding to the data to be processed; then, the data to be processed is encrypted according to the encryption key to obtain the target data; wherein the encryption key is determined according to the fingerprint information corresponding to the encryption hardware. According to the above content, it can be known that the present application generates an encryption key through the fingerprint information corresponding to the encryption hardware, and then, the data to be processed is encrypted according to the encryption key to obtain the target data; since the fingerprint information is the unique identifier corresponding to the encryption hardware, and has the characteristics of being non-clonable and unpredictable, the encryption key generated according to the fingerprint information can effectively prevent being copied and forged; then, after the data to be processed is encrypted according to the encryption key, it can effectively respond to the high-performance encryption requirements in different application scenarios, ensure the smooth progress of the data encryption process, improve the security of data encryption, and prevent security risks such as data loss or data tampering.

[0055] In one embodiment, when an encryption key needs to be generated, the following may be specifically included:

[0056] S301, obtaining fingerprint information corresponding to encryption hardware.

[0057] The fingerprint information is generated according to the hardware characteristics of the encryption hardware.

[0058] S302, receiving user authentication information input by the user.

[0059] The user authentication information includes at least one of a user password and biometric information.

[0060] S303, generating an encryption key according to the fingerprint information and the user authentication information.

[0061] It should be noted that when it is necessary to generate an encryption key based on the fingerprint information and the user authentication information, the following may be specifically included: generating a key based on the fingerprint information and the user authentication information based on a preset target encryption algorithm to obtain an encryption key.

[0062] The target encryption algorithm includes at least one of a symmetric encryption algorithm, an asymmetric encryption algorithm and a hash algorithm.

[0063] Further explanation is that the encryption key can also be detected for anomalies; when the anomaly detection result is an anomaly, the encryption key is deleted and new fingerprint information corresponding to the encryption hardware is generated; the encryption key is generated based on the new fingerprint information and user authentication information.

[0064] In one embodiment of the present application, the validity period of the encryption key can be pre-defined. Therefore, when performing anomaly detection on the encryption key, it can be detected whether the usage time of the encryption key exceeds the validity period; if so, it is determined that the anomaly detection result is an anomaly, and the encryption key can be deleted, and new fingerprint information corresponding to the encryption hardware can be generated; based on the new fingerprint information and user authentication information, an encryption key is generated.

[0065] In one embodiment of the present application, when performing anomaly detection on the encryption key, it can be detected whether the fingerprint information has been tampered with. If tampering occurs, the anomaly detection result is determined to be an anomaly, and the fingerprint information is restored, or a backup key is generated based on the backup information to ensure the security and stability of the system.

[0066] In one embodiment of the present application, when performing anomaly detection on the encryption key, it can be detected whether the encryption key is successfully generated based on the fingerprint information and user authentication information; if not, it is determined that the anomaly detection result is an anomaly, and a backup key is generated based on the backup information to ensure the security and stability of the system.

[0067] To further illustrate, the application scenarios of the generated encryption keys may include, but are not limited to: Internet of Things (IoT) devices: provide secure authentication and data encryption for smart devices to prevent unauthorized access and data leakage. Financial payment system: protect users' transaction information and personal privacy, and ensure the security and reliability of the payment process. Cloud computing platform: establish a secure communication channel between cloud service providers and users to prevent data from being stolen or tampered with. Industrial control system: ensure the safe operation of critical infrastructure and prevent production interruptions or safety accidents caused by malicious attacks. Video encryption system: the completion of the video security trusted module can realize the secure transmission of video data in the power system. The research and development of the video security trusted module can ensure the security management capabilities of the power video terminal, avoid the leakage of power production safety videos, and trigger uncontrollable incidents such as public safety.

[0068] The above data encryption method, by generating an encryption key, ensures that the data to be processed can be encrypted smoothly, ensures the smooth progress of the data encryption process, improves the security of data encryption, and prevents security risks such as data loss or data tampering.

[0069] In one embodiment, a data encryption system may be preset, wherein the data encryption system includes a PUF module and an encryption chip module.

[0070] Among them, the PUF module generates unique fingerprint information based on the inherent physical properties of the hardware (such as transistor threshold voltage, delay time, etc.). This fingerprint information is used as the initial key or seed for subsequent encryption operations. The PUF module also has a self-test function to ensure the consistency and reliability of the fingerprint information generated at each startup; the encryption chip module uses symmetric encryption algorithms (such as AES), asymmetric encryption algorithms (such as RSA) or hash algorithms (such as SHA-256) to encrypt, decrypt and verify signatures for data. The encryption chip module has a built-in key management system that supports dynamic key generation, storage and update. The encryption chip module works in conjunction with the PUF module, using the fingerprint information generated by the PUF as part of the key or input parameter to enhance the security of the encryption algorithm.

[0071] The system supports multiple security protocols (such as TLS, SSH, IPsec) to ensure the integrity, confidentiality and availability of data during network transmission. It provides standardized API interfaces to facilitate third-party application integration and calls. It supports multi-layer protection mechanisms, including firewalls, intrusion detection systems (IDS) and anti-virus software, to further enhance the security of the system.

[0072] Further, such as Figure 4 As shown in the figure, two layers of security verification are incorporated into the system design, that is, two different types of hardware components, PUF chip and encryption chip module, are used to increase the security of the system. Specifically, the fingerprint information corresponding to the encryption hardware is generated based on the physical characteristics of the PUF chip. Each PUF chip has unique physical characteristics due to slight differences in its manufacturing process. These characteristics enable each PUF chip to generate a unique fingerprint information. This fingerprint information plays a vital role in the subsequent encryption process. After the unique fingerprint information is generated, the next step is to encrypt the data using the encryption chip and encryption key. The data to be processed is divided into multiple blocks (such as s1, s2, s3, etc.) in the form of program code for processing. Each block will be encrypted by the encryption chip, and the encryption key generated according to the fingerprint information will be used in the encryption process. In this way, even if the data is intercepted during transmission, the attacker cannot easily crack the content.

[0073] After the data is encrypted, signature verification is required to ensure the security of the data. Signature verification is an important step. It generates a signature by performing specific mathematical operations on the encrypted data. This signature can prove the integrity and authenticity of the data. At the data receiving end, by performing the same mathematical operation on the received data and comparing the generated signature with the signature provided by the sending end, it can be determined whether the data has been tampered with during the transmission process. Finally, if the signature verification passes, it means that the data has not been tampered with during the transmission process, and the program code can be loaded and run normally. This process is the last link in the two-factor authentication process and is also a key step to verify whether the entire process is successful. If the code encounters an exception or error during the loading and running process, it may mean that there is a problem in the data transmission or processing process, which requires further inspection and processing.

[0074] In the process of hash authentication for each program block, instead of using a fixed chip, it is randomly decided to use a PUF chip or an encryption chip for hash calculation and verification. No matter which chip is selected, a hash value will be calculated for the corresponding program block. This hash value is used to verify the integrity and authenticity of the program block to ensure that it has not been tampered with.

[0075] The system uses a two-factor authentication mechanism, combining the fingerprint information module generated by PUF and the password or biometric information provided by the user to generate the final encryption key. The key is generated locally and destroyed immediately after use to avoid the risks brought by long-term storage. It supports remote distribution and synchronization of keys to ensure secure communication between different devices.

[0076] The above-mentioned data encryption system, when detecting an encryption event for the data to be processed, obtains the encryption key corresponding to the data to be processed; then, encrypts the data to be processed according to the encryption key to obtain the target data; wherein the encryption key is determined according to the fingerprint information corresponding to the encryption hardware. According to the above content, it can be known that the present application generates an encryption key through the fingerprint information corresponding to the encryption hardware, and then, encrypts the data to be processed according to the encryption key to obtain the target data; since the fingerprint information is the unique identifier corresponding to the encryption hardware, and has the characteristics of being non-clonable and unpredictable, the encryption key generated according to the fingerprint information can effectively prevent being copied and forged; then, after encrypting the data to be processed according to the encryption key, it can effectively respond to the high-performance encryption requirements in different application scenarios, ensure the smooth progress of the data encryption process, improve the security of data encryption, and prevent security risks such as data loss or data tampering.

[0077] It should be understood that, although the steps in the flowcharts involved in the above embodiments are displayed in sequence according to the indication of the arrows, these steps are not necessarily executed in sequence according to the order indicated by the arrows. Unless there is a clear explanation in this article, the execution of these steps is not strictly limited in order, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above embodiments may include multiple steps or multiple stages, and these steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily carried out in sequence, but can be executed in turn or alternately with other steps or at least a part of the steps or stages in other steps.

[0078] Based on the same inventive concept, the embodiment of the present application also provides a data encryption device for implementing the data encryption method involved above. The implementation scheme for solving the problem provided by the device is similar to the implementation scheme recorded in the above method, so the specific limitations in one or more data encryption device embodiments provided below can refer to the limitations on the data encryption method above, and will not be repeated here.

[0079] In one embodiment, Figure 5 As shown, a data encryption device is provided, comprising: a detection module 10 and a processing module 20, wherein:

[0080] The detection module 10 is used to detect the encryption time of the data to be processed and generate an encryption key corresponding to the data to be processed; wherein the encryption key is determined according to the fingerprint information corresponding to the encryption hardware;

[0081] The processing module 20 is used to encrypt the data to be processed according to the encryption key to obtain the target data.

[0082] In one embodiment, fingerprint information corresponding to the encryption hardware is obtained, wherein the fingerprint information is generated according to hardware characteristics of the encryption hardware;

[0083] Receive user authentication information input by the user;

[0084] Generate an encryption key based on fingerprint information and user authentication information.

[0085] In one embodiment, a key is generated for the fingerprint information and the user authentication information based on a preset target encryption algorithm to obtain an encryption key.

[0086] In one embodiment, the target encryption algorithm includes at least one of a symmetric encryption algorithm, an asymmetric encryption algorithm, and a hash algorithm.

[0087] In one embodiment, the user authentication information includes at least one of a user password and biometric information.

[0088] In one embodiment, an anomaly detection is performed on the encryption key;

[0089] When the anomaly detection result indicates that an anomaly exists, the encryption key is deleted and new fingerprint information corresponding to the encryption hardware is generated;

[0090] Generate an encryption key based on the new fingerprint information and user authentication information.

[0091] The above-mentioned data encryption device, when detecting an encryption event for the data to be processed, obtains the encryption key corresponding to the data to be processed; then, encrypts the data to be processed according to the encryption key to obtain the target data; wherein the encryption key is determined according to the fingerprint information corresponding to the encryption hardware. According to the above content, it can be known that the present application generates an encryption key through the fingerprint information corresponding to the encryption hardware, and then, encrypts the data to be processed according to the encryption key to obtain the target data; since the fingerprint information is the unique identifier corresponding to the encryption hardware, and has the characteristics of being non-clonable and unpredictable, the encryption key generated according to the fingerprint information can effectively prevent being copied and forged; then, after encrypting the data to be processed according to the encryption key, it can effectively respond to the high-performance encryption requirements in different application scenarios, ensure the smooth progress of the data encryption process, improve the security of data encryption, and prevent security risks such as data loss or data tampering.

[0092] Each module in the above data encryption device can be implemented in whole or in part by software, hardware, or a combination thereof. Each module can be embedded in or independent of a processor in a computer device in the form of hardware, or can be stored in a memory in a computer device in the form of software, so that the processor can call and execute operations corresponding to each module.

[0093] In one embodiment, a computer device is provided. The computer device may be a terminal, and its internal structure diagram may be as follows: Figure 6As shown. The computer device includes a processor, a memory, an input / output interface, a communication interface, a display unit and an input device. Among them, the processor, the memory and the input / output interface are connected through a system bus, and the communication interface, the display unit and the input device are connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and the external device. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be implemented through WIFI, a mobile cellular network, NFC (near field communication) or other technologies. When the computer program is executed by the processor, a data encryption method is implemented. The display unit of the computer device is used to form a visually visible picture, which can be a display screen, a projection device or a virtual reality imaging device. The display screen can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer covering the display screen, or a button, trackball or touchpad set on the computer device shell, or an external keyboard, touchpad or mouse.

[0094] Those skilled in the art will understand that Figure 6 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.

[0095] In one embodiment, a computer device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and when the processor executes the computer program, the following steps are implemented:

[0096] When an encryption event for the data to be processed is detected, an encryption key corresponding to the data to be processed is obtained; wherein the encryption key is determined according to fingerprint information corresponding to the encryption hardware;

[0097] The data to be processed is encrypted according to the encryption key to obtain the target data.

[0098] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:

[0099] Obtaining fingerprint information corresponding to the encryption hardware, wherein the fingerprint information is generated according to hardware characteristics of the encryption hardware;

[0100] Receive user authentication information input by the user;

[0101] Generate an encryption key based on fingerprint information and user authentication information.

[0102] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:

[0103] Based on the preset target encryption algorithm, the fingerprint information and user authentication information are key generated to obtain the encryption key.

[0104] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:

[0105] The target encryption algorithm includes at least one of a symmetric encryption algorithm, an asymmetric encryption algorithm and a hash algorithm.

[0106] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:

[0107] The user authentication information includes at least one of a user password and biometric information.

[0108] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:

[0109] Anomaly detection of encryption keys;

[0110] When the anomaly detection result indicates that an anomaly exists, the encryption key is deleted and new fingerprint information corresponding to the encryption hardware is generated;

[0111] Generate an encryption key based on the new fingerprint information and user authentication information.

[0112] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored, and when the computer program is executed by a processor, the following steps are implemented:

[0113] When an encryption event for the data to be processed is detected, an encryption key corresponding to the data to be processed is obtained; wherein the encryption key is determined according to fingerprint information corresponding to the encryption hardware;

[0114] The data to be processed is encrypted according to the encryption key to obtain the target data.

[0115] In one embodiment, when the computer program is executed by a processor, the following steps are also implemented:

[0116] Obtaining fingerprint information corresponding to the encryption hardware, wherein the fingerprint information is generated according to hardware characteristics of the encryption hardware;

[0117] Receive user authentication information input by the user;

[0118] Generate an encryption key based on fingerprint information and user authentication information.

[0119] In one embodiment, when the computer program is executed by a processor, the following steps are also implemented:

[0120] Based on the preset target encryption algorithm, the fingerprint information and user authentication information are key generated to obtain the encryption key.

[0121] In one embodiment, when the computer program is executed by a processor, the following steps are also implemented:

[0122] The target encryption algorithm includes at least one of a symmetric encryption algorithm, an asymmetric encryption algorithm and a hash algorithm.

[0123] In one embodiment, when the computer program is executed by a processor, the following steps are also implemented:

[0124] The user authentication information includes at least one of a user password and biometric information.

[0125] In one embodiment, when the computer program is executed by a processor, the following steps are also implemented:

[0126] Anomaly detection of encryption keys;

[0127] When the anomaly detection result indicates that an anomaly exists, the encryption key is deleted and new fingerprint information corresponding to the encryption hardware is generated;

[0128] Generate an encryption key based on the new fingerprint information and user authentication information.

[0129] In one embodiment, a computer program product is provided, comprising a computer program, which, when executed by a processor, implements the following steps:

[0130] When an encryption event for the data to be processed is detected, an encryption key corresponding to the data to be processed is obtained; wherein the encryption key is determined according to fingerprint information corresponding to the encryption hardware;

[0131] The data to be processed is encrypted according to the encryption key to obtain the target data.

[0132] In one embodiment, when the computer program is executed by a processor, the following steps are also implemented:

[0133] Obtaining fingerprint information corresponding to the encryption hardware, wherein the fingerprint information is generated according to hardware characteristics of the encryption hardware;

[0134] Receive user authentication information input by the user;

[0135] Generate an encryption key based on fingerprint information and user authentication information.

[0136] In one embodiment, when the computer program is executed by a processor, the following steps are also implemented:

[0137] Based on the preset target encryption algorithm, the fingerprint information and user authentication information are key generated to obtain the encryption key.

[0138] In one embodiment, when the computer program is executed by a processor, the following steps are also implemented:

[0139] The target encryption algorithm includes at least one of a symmetric encryption algorithm, an asymmetric encryption algorithm, and a hash algorithm.

[0140] In one embodiment, when the computer program is executed by a processor, the following steps are also implemented:

[0141] The user authentication information includes at least one of a user password and biometric information.

[0142] In one embodiment, when the computer program is executed by a processor, the following steps are also implemented:

[0143] Anomaly detection of encryption keys;

[0144] When the anomaly detection result indicates that an anomaly exists, the encryption key is deleted and new fingerprint information corresponding to the encryption hardware is generated;

[0145] Generate an encryption key based on the new fingerprint information and user authentication information.

[0146] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant laws, regulations and standards of relevant countries and regions.

[0147] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to the memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in each embodiment provided in this application may include at least one of a relational database and a non-relational database. Non-relational databases may include distributed databases based on blockchains, etc., but are not limited to this. The processor involved in each embodiment provided in this application may be a general-purpose processor, a central processing unit, a graphics processor, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, etc., but are not limited to this.

[0148] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0149] The above embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the present application. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the attached claims.

Claims

1. A data encryption method, characterized in that: The method comprises: In the case of detecting an encryption event for the data to be processed, obtaining an encryption key corresponding to the data to be processed; wherein the encryption key is determined according to fingerprint information corresponding to the encryption hardware; The data to be processed is encrypted according to the encryption key to obtain target data.

2. The method according to claim 1, characterized in that: The encryption key generation process includes: Acquire fingerprint information corresponding to encryption hardware, wherein the fingerprint information is generated according to hardware characteristics of the encryption hardware; Receive user authentication information input by the user; The encryption key is generated according to the fingerprint information and the user authentication information.

3. The method according to claim 2, characterized in that The step of generating the encryption key according to the fingerprint information and the user authentication information includes: A key is generated for the fingerprint information and the user authentication information based on a preset target encryption algorithm to obtain the encryption key.

4. The method according to claim 3, characterized in that The target encryption algorithm includes at least one of a symmetric encryption algorithm, an asymmetric encryption algorithm and a hash algorithm.

5. The method according to claim 2, characterized in that: The user authentication information includes at least one of a user password and biometric information.

6. The method according to claim 1, characterized in that The method further comprises: Performing anomaly detection on the encryption key; When the abnormality detection result indicates that an abnormality exists, the encryption key is deleted and new fingerprint information corresponding to the encryption hardware is generated; The encryption key is generated according to the new fingerprint information and user authentication information.

7. A data encryption device, characterized in that: The device comprises: A detection module, used to detect the encryption time of the data to be processed and generate an encryption key corresponding to the data to be processed; wherein the encryption key is determined according to the fingerprint information corresponding to the encryption hardware; The processing module is used to encrypt the data to be processed according to the encryption key to obtain target data.

8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.

10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.