Data processing method, storage medium and electronic equipment

By using data processing methods using AES encryption and RSA digital signature technology between the encryption device and the decryption device, the problem that traditional software protection solutions are difficult to verify the hardware environment of the user equipment is solved, and the security of device verification is improved.

CN120012068APending Publication Date: 2025-05-16HEFEI ZHONGKE LEINAO INTELLIGENCE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510116004.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-24
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

Traditional software protection solutions are difficult to personalize the hardware environment of user equipment, resulting in low security of device verification.

Method used

Through the data processing method between the encryption device and the decryption device, AES encryption and RSA digital signature technology are used to ensure the security and legality of the input data, thereby achieving personalized verification of the target device.

Benefits of technology

Improves the security of device verification, ensures the security of key transmission and verification of data sources, and prevents data tampering and abuse.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120012068A_ABST
    Figure CN120012068A_ABST
Patent Text Reader

Abstract

The invention discloses a data processing method, a storage medium and electronic equipment, relates to the technical field of information security, is applied to encryption equipment, and comprises the following steps: acquiring input data of target equipment; encrypting the input data by using the first AES key information to generate a first ciphertext; encrypting the first AES key information by using the first public key to generate a second ciphertext, and generating a digital signature of the second ciphertext by using a private key corresponding to the first public key; and sending the first ciphertext, the second ciphertext and the digital signature to a decryption device, so that the decryption device verifies the legality of the digital signature based on a second public key and the second ciphertext which are the same as the first public key, if the digital signature is legality, decrypting the first ciphertext by adopting second AES key information which is the same as the first AES key information, and if the digital signature is legality, decrypting the digital signature by adopting the second AES key information which is the same as the first AES key information. And the input data are obtained, and the input data are verified, so that the security of equipment verification is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to a data processing method, a storage medium and an electronic device. Background Art

[0002] Traditional software protection solutions, such as serial number registration and software activation, all have the following problems: it is difficult to perform personalized verification on the user's device, such as verifying the hardware environment of the user's device. That is, a target device with any hardware can send a serial number or activation code to a device with specific functions or services to obtain these functions or services, but it is impossible to determine whether the target device is a device that is authorized to use the above functions or services, making the device verification less secure. Summary of the invention

[0003] The present invention aims to solve one of the technical problems in the related art at least to a certain extent. To this end, one object of the present invention is to provide a data processing method, a storage medium and an electronic device to improve the security of device authentication.

[0004] According to a first aspect of an embodiment of the present invention, there is provided a data processing method, which is applied to an encryption device, and the method includes:

[0005] Get input data from the target device;

[0006] Encrypting the input data using the first AES key information to generate a first ciphertext;

[0007] Encrypting the first AES key information using the first public key to generate a second ciphertext, and generating a digital signature of the second ciphertext using a private key corresponding to the first public key;

[0008] The first ciphertext, the second ciphertext and the digital signature are sent to a decryption device, so that the decryption device verifies the legitimacy of the digital signature based on a second public key that is the same as the first public key and the second ciphertext; if the digital signature is legitimate, the first ciphertext is decrypted using second AES key information that is the same as the first AES key information to obtain the input data, and the input data is verified.

[0009] According to a second aspect of an embodiment of the present invention, there is provided a data processing method, which is applied to a decryption device, and the method includes:

[0010] Obtaining a first ciphertext, a second ciphertext, and a digital signature generated for a target device and sent by an encryption device;

[0011] Verifying the legitimacy of the digital signature based on a second public key and the second ciphertext; wherein the second public key is the same as the first public key that generated the second ciphertext;

[0012] If the digital signature is legitimate, the first ciphertext is decrypted using the second AES key information to obtain input data of the target device, and the input data is verified; wherein the second AES key information is the same as the first AES key information used to generate the first ciphertext.

[0013] According to a third aspect of an embodiment of the present invention, there is provided a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, the data processing method described in any one of the above items is implemented.

[0014] According to a fourth aspect of an embodiment of the present invention, there is provided an electronic device, comprising: a memory and a processor; a computer program is stored in the memory, and when the computer program is executed by the processor, any of the data processing methods described above is implemented.

[0015] In the solution provided by the embodiment of the present invention, after the encryption device obtains the input data, it uses the first AES key information to encrypt the input data to generate the first ciphertext, and generates the digital signature of the first AES key information. Among them, AES encryption provides efficient data encryption and integrity verification functions, which can ensure the security of the input data. The content of the digital signature is the first AES key information encrypted using the RSA public key, which can also ensure the security of the key transmission, so that the input data is not easy to be cracked or abused. And by using the private key corresponding to the first public key to generate a digital signature, the source of the data can be verified and tampering can be prevented. In this way, the authenticity of the ciphertext can be verified by verifying the digital signature, so that when the digital signature is legitimate, the decryption device decrypts the first ciphertext to obtain the real input data of the target device, so that the information of the target device can be obtained through the input data, and the target device is personalized. Verification is performed to determine that the target device has been authorized to use the function of the decryption device, thereby improving the security of device verification.

[0016] Additional aspects and advantages of the present invention will be given in part in the following description and in part will be obvious from the following description, or will be learned through practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1 is a flowchart of a first data processing method provided by an embodiment of the present invention;

[0018] Figure 2 is a flow chart of a second data processing method provided by an embodiment of the present invention;

[0019] Figure 3 is a flowchart of a third data processing method provided by an embodiment of the present invention;

[0020] Figure 4 is a flowchart of a fourth data processing method provided by an embodiment of the present invention;

[0021] Figure 5 It is a structural schematic diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0022] Embodiments of the present invention are described in detail below, examples of which are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to be used to explain the present invention, and should not be construed as limiting the present invention.

[0023] The data processing method, storage medium and electronic device according to the embodiments of the present invention are described below with reference to the accompanying drawings.

[0024] In one embodiment of the present invention, see Figure 1 , provides a data processing method, applied to an encryption device, comprising the following steps S101-S104.

[0025] S101: Obtain input data of the target device;

[0026] S102: Encrypt input data using first AES key information to generate first ciphertext;

[0027] S103: using the first public key to encrypt the first AES key information to generate a second ciphertext, and using the private key corresponding to the first public key to generate a digital signature of the second ciphertext;

[0028] S104: Send the first ciphertext, the second ciphertext and the digital signature to the decryption device, so that the decryption device verifies the legitimacy of the digital signature based on the second public key that is the same as the first public key and the second ciphertext. If the digital signature is legitimate, the first ciphertext is decrypted using the second AES key information that is the same as the first AES key information to obtain input data, and the input data is verified.

[0029] In an implementation scenario of the solution provided in an embodiment of the present invention, there are two devices, an authorization center and a verification agent, wherein the authorization center is the encryption device mentioned above; and the verification agent is a decryption device, that is, a device that actually executes the verification of input data.

[0030] The authorization center can be an independent device that provides encryption functions and generates digital signatures, thereby realizing authorization based on digital signatures, that is, when the digital signature is legal, the target device can be authorized to use the services provided by the decryption device; in this scenario, the encryption device obtains input data from other target devices that need to interact with the decryption device for data.

[0031] In another scenario, the encryption device is the target device, that is, the authorization center that executes the above steps S101-S104 is installed as an application on the target device, so that the input data can be obtained from the encryption device itself.

[0032] The separation design of the authorization center and the verification agent can clarify functional responsibilities and ensure system scalability and ease of maintenance.

[0033] Legitimacy means that the digital signature can be verified as the digital signature of the target device. Since the digital signature is generated by a private key, it can be verified by the public key that matches the private key. In the above step S103, while sending the first ciphertext, the second ciphertext and the digital signature are also sent. In this way, the decryption device can verify in the following way, that is, since the digital signature is encrypted by the private key, it can be decrypted by the first public key. Since the second public key is the same as the first public key, it can be decrypted by the second public key to restore the second ciphertext.

[0034] In this way, the decryption device receives the digital signature, which is generated based on the second ciphertext, and the second ciphertext is obtained from the digital signature through the second public key; the decryption device also receives a second ciphertext sent by the target device, so that the two second ciphertexts can be compared to see if they are the same. If they are the same, it means that the digital signature is legitimate.

[0035] In one embodiment of the present invention, the input data includes information to be verified, for example, the input data includes:

[0036] Hardware information of the target device, function module number of the decryption device, date information, call count information, and version number information.

[0037] The hardware information may include a motherboard serial number, a processor ID, etc., which are used to bind the hardware and implement personalized verification of the hardware environment. The processor ID may be the ID (Identification) of the CPU (Central Processing Unit).

[0038] On the decryption device, different functional modules can be distinguished according to the number. After the decryption device decrypts the first ciphertext and obtains the input data, the functional module number can be obtained from the input data, and the functional module corresponding to the number can be called to provide services for the target device. Different functional modules can be used to provide different services, for example, functional module A is used to provide network connection function, functional module B is used to provide resource download function, etc. In this way, according to the verification result, the use permission of the corresponding functional module can be dynamically enabled or denied to ensure the accurate execution of the authorization rules.

[0039] The date information may record the expiration time of the target device's authority, the time when the target device first obtains the service authorization of the decryption device, etc. The call count information may include the number of times the target device calls the function of the decryption device, which may be the number of calls to a certain function module or the total number of calls to all function modules, etc.

[0040] The version number information may include the version number of the application program that provides the service that the target device needs to call.

[0041] In addition, the input data may also include pre-defined information to be verified, such as an activation code or a serial number.

[0042] The first AES (Advanced Encryption Standard) key information may include: an AES key and an initialization vector. When encrypting input data, the plaintext input data is divided into blocks, the first block of plaintext is firstly XORed with the initialization vector, the XOR result is encrypted with the AES key, and the first block of ciphertext is obtained. The ciphertext output this time is used as the initialization vector of the next block of data. In this way, the ciphertexts of all data blocks are obtained, and the sum of them is the first ciphertext.

[0043] Correspondingly, in step S104, the second AES key includes the same AES key and initialization vector. When decrypting the first ciphertext, the first ciphertext is divided into blocks, and the block size is consistent with the block size of the plaintext input data. The first block of ciphertext is decrypted with the same AES key, and then the result and the initialization vector are XORed to obtain the first block of plaintext. The ciphertext decrypted this time, that is, the first block of ciphertext, is used as the initialization vector for the next block of decrypted data. In this way, the plaintext of all the blocks of the first ciphertext is obtained, and the sum of them is the restored input data.

[0044] In step S104, the input data is verified, that is, the target device is verified through the input data to see whether it meets the conditions set by the encryption device for providing services, so that the encryption device provides services to the verified target device, such as providing data transmission or communication services, etc. The specific implementation method is referred to in the subsequent embodiments, which will not be described in detail here.

[0045] In one embodiment, after S101 obtains the input data, the decryption device converts various information in the input data into a unified format to ensure data consistency, accuracy and system compatibility.

[0046] As can be seen from the above, in the solution provided by the embodiment of the present invention, after the encryption device obtains the input data, it uses the first AES key information to encrypt the input data to generate the first ciphertext, and generates the digital signature of the first AES key information. Among them, AES encryption provides efficient data encryption and integrity verification functions, which can ensure the security of the input data. The content of the digital signature is the first AES key information encrypted using the RSA public key, which can also ensure the security of the key transmission, so that the input data is not easy to be cracked or abused. And by using the private key corresponding to the first public key to generate a digital signature, the source of the data can be verified and tampering can be prevented. In this way, the authenticity of the ciphertext can be verified by verifying the digital signature, so that when the digital signature is legitimate, the decryption device decrypts the first ciphertext to obtain the real input data of the target device, so that the information of the target device can be obtained through the input data, and the target device is personalized. Verification is performed to determine that the target device has been authorized to use the function of the decryption device, thereby improving the security of device verification.

[0047] In one embodiment of the present invention, the first ciphertext, the second ciphertext and the digital signature may be concatenated, and the concatenated data may be base64 encoded to obtain encoded data; the encoded data may be sent to a decryption device. The encrypted content may be standardized by base64 encoding, making the data easy to transmit and store, and facilitating the application of the authorization file in a variety of storage and transmission scenarios.

[0048] In one embodiment, before concatenating the first ciphertext, the second ciphertext, and the digital signature, the digital signature may be encrypted using the first AES key information to obtain a third ciphertext of the digital signature.

[0049] In this case, the digital signature received by the decryption device is also ciphertext, and the second key information can be used to decrypt the ciphertext digital signature to obtain the plaintext digital signature, and then verify the legitimacy of the digital signature according to the above embodiment. By encrypting the digital signature, security is further improved.

[0050] In one embodiment of the present invention, see Figure 2 , provides a data processing method applied to a decryption device, comprising steps S201-S203.

[0051] S201: Obtaining a first ciphertext, a second ciphertext, and a digital signature generated for a target device and sent by an encryption device;

[0052] S202: Verify the legitimacy of the digital signature based on the second public key and the second ciphertext; wherein the second public key is the same as the first public key used to generate the second ciphertext;

[0053] S203: If the digital signature is valid, the first ciphertext is decrypted using the second AES key information to obtain input data of the target device, and the input data is verified; wherein the second AES key information is the same as the first AES key information used to generate the first ciphertext.

[0054] The method of generating the first ciphertext, the second ciphertext and the digital signature in step S201 is the same as that in the aforementioned steps S101 to S104, and will not be described in detail here.

[0055] The way to obtain the public key is open, therefore, for the encryption device and the decryption device, the same public key from the same source can be obtained through a public network or a shared storage device, and the obtained public keys are the first public key and the second public key respectively.

[0056] As can be seen from the above, in the solution provided by the embodiment of the present invention, after the encryption device obtains the input data, it uses the first AES key information to encrypt the input data to generate the first ciphertext, and generates the digital signature of the first AES key information. Among them, AES encryption provides efficient data encryption and integrity verification functions, which can ensure the security of the input data. The content of the digital signature is the first AES key information encrypted using the RSA public key, which can also ensure the security of the key transmission, so that the input data is not easy to be cracked or abused. And by using the private key corresponding to the first public key to generate a digital signature, the source of the data can be verified and tampering can be prevented. In this way, the authenticity of the ciphertext can be verified by verifying the digital signature, so that when the digital signature is legitimate, the decryption device decrypts the first ciphertext to obtain the real input data of the target device, so that the information of the target device can be obtained through the input data, and the target device is personalized. Verification is performed to determine that the target device has been authorized to use the function of the decryption device, thereby improving the security of device verification.

[0057] In one embodiment of the present invention, when the input data includes hardware information of the target device, function module number of the decryption device, date information, call count information, and version number information, the input data is verified, including:

[0058] In the date information, call count information, version number information and hardware information, for the target information with preset restriction conditions, it is determined whether the target information meets the restriction conditions to obtain a verification result.

[0059] Target information refers to information with restrictions. For example, if the decryption device has restrictions on hardware information, then the hardware information is the target information. This is just an example. There can be more than one item of target information. For example, date information, call count information, version number information, and hardware information can all be target information.

[0060] For example, the restriction condition for hardware information is: compare the first motherboard serial number and the first processor identifier included in the hardware information with the pre-stored second motherboard serial number and the second processor identifier bound to the target device, and restrict the first motherboard serial number to be the same as the second motherboard serial number and the first processor identifier to be the same as the second processor identifier.

[0061] For more information about other restrictions, see the following Figure 4 The process of determining whether a restriction condition exists in the illustrated embodiment will not be described in detail here.

[0062] Each time the target device sends input data to the decryption device, the call count information and date information can change dynamically. For example, the call count information is incremented by 1 each time the decryption device provides services to the target device, and the date information can include the latest remaining time before the expiration date. In this way, the validity period, number of times, and other information of the software authorization can be dynamically managed.

[0063] In one embodiment of the present invention, if the verification result indicates that the target information meets the restriction condition, the decryption device calls the function module corresponding to the function module number to provide services for the target device. In this way, the function provided by the decryption device can be specified through the function module number of the target device, so that the authorization management of the function module can be accurate to a specific function or module, which improves the flexibility of authorization management and meets the needs of complex function call modes.

[0064] In one embodiment of the present invention, if the digital signature is a third ciphertext encrypted using the first AES key information, after obtaining the first ciphertext, the second ciphertext and the digital signature generated for the target device and sent by the encryption device, the method further includes:

[0065] The third ciphertext is decrypted using the second AES key information to obtain a digital signature in plain text.

[0066] Figure 3 The method flow chart shown is the data processing flow of the encryption device. Specifically, in the input part, the encryption device obtains the input data and verifies the validity of the input data. For example, the encryption device records part of the verification information of the target device in advance, compares it with the input data, and verifies that the input data is valid if the comparison is consistent.

[0067] For example, the target device can be pre-registered on the encryption device, so that the encryption device pre-records the motherboard serial number and processor ID of the target device, as well as the account password name of the target device, and compares them with the motherboard serial number and processor ID, and account password in the input data, and verifies that the input data is valid under the same circumstances.

[0068] In the case where the input data includes call information and date information, the encryption device may also record the number of calls and expiration time and compare them with the input data.

[0069] If invalid, an error code is sent to the target device.

[0070] When the input data is verified and determined to be valid, a data standardization operation is performed, that is, each piece of information in the input data is converted into a unified format. The input data is encrypted by AES to obtain a first ciphertext, and the first ciphertext can be base64 encoded.

[0071] Figure 3 The AES key and IV (Initialization Vector) are the first key information, and the public key is the first public key. The first key information is RSA encrypted using the public key, and RSA encryption refers to encryption using the RSA algorithm. The second ciphertext is generated.

[0072] And, use the private key to digitally sign the second ciphertext. The specific steps include:

[0073] (1) Hash processing: Hash the data to be signed to generate a hash value. Usually, hash algorithms such as SHA-256 are used;

[0074] (2) Signature: Use the private key to sign the hash value. In Java, you can use the Signature class to perform the signature operation.

[0075] like Figure 3 , the digital signature is concatenated with the first ciphertext, and finally, the second ciphertext is concatenated and output, that is, the first ciphertext, the second ciphertext and the digital signature are sent to the decryption device.

[0076] Figure 4 The method flow chart shown is the data processing flow of the decryption device. Specifically, the authorization file includes the above-mentioned first ciphertext, second ciphertext and digital signature, and reading the content is to obtain the first ciphertext, second ciphertext and digital signature. The authorization file is base64 decoded to obtain the original data. In the original data, the first ciphertext is decrypted by AES using the key to obtain the plaintext data. The key here is the key in the second key information, which is the same as the first key information. The decryption device and the encryption device can pre-agree on the same key and initialization vector.

[0077] After the content reading step, the branches in the figure indicate that you can first perform base64 decoding and AES decryption, or you can first perform signature verification.

[0078] Signature verification is to verify the legitimacy of the digital signature based on the second public key and the second ciphertext to ensure the integrity of the file and the reliability of the source. Figure 4 The public key in is the second public key, which is the same as the first public key. If it fails, an error code is output.

[0079] If the verification is successful, standard data parsing is performed, that is, the module number, expiration date, call count, version number and hardware binding information in the input data are extracted for subsequent verification of the input data. The expiration date is the content contained in the date information in the above embodiment.

[0080] After parsing is completed, determine the existing restrictions. Among them, you can determine whether the expiration date is restricted. If so, that is, this restriction exists, then perform expiration date verification to check whether the expiration date in the input data exceeds the current date. If it exceeds, output an error code;

[0081] If the expiration date does not exceed the current date, it can be determined whether the number of calls is limited. If so, the number of calls is verified to check whether the number of calls in the input data has reached the preset upper limit of the number of calls; if so, an error code is output;

[0082] If it is not reached, it can also be determined whether to restrict the hardware information. If so, the hardware information verification is performed to check whether the pre-stored hardware information of the target device is the same as the hardware information in the input data. If not, an error code is input.

[0083] In addition, if none of the restriction conditions exist, an error code can also be output as a prompt. The above error feedback mechanism enhances the convenience of user interaction.

[0084] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the data processing method described in any of the above embodiments is implemented.

[0085] In one embodiment, an electronic device is provided, comprising: a memory and a processor; a computer program is stored in the memory, and when the computer program is executed by the processor, the data processing method described in any of the above embodiments is implemented.

[0086] Figure 5 It is a structural block diagram of an electronic device according to an embodiment of the present invention.

[0087] like Figure 5As shown, the electronic device 500 includes: a processor 501 and a memory 503. The processor 501 and the memory 503 are connected, such as through a bus 502. Optionally, the electronic device 500 may also include a transceiver 504. It should be noted that in actual applications, the transceiver 504 is not limited to one, and the structure of the electronic device 500 does not constitute a limitation on the embodiments of the present invention.

[0088] Processor 501 may be a CPU (Central Processing Unit), a general purpose processor, a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array) or other programmable logic devices, transistor logic devices, hardware components or any combination thereof. It may implement or execute various exemplary logic blocks, modules and circuits described in conjunction with the disclosure of the present invention. Processor 501 may also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, etc.

[0089] The bus 502 may include a path to transmit information between the above components. The bus 502 may be a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus. The bus 502 may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 5 Only one thick line is used in the diagram, but this does not mean that there is only one bus or only one type of bus.

[0090] The memory 503 is used to store a computer program corresponding to the data processing method of the above embodiment of the present invention, and the computer program is controlled and executed by the processor 501. The processor 501 is used to execute the computer program stored in the memory 503 to implement the content shown in the above method embodiment.

[0091] Among them, the electronic device 500 includes but is not limited to: mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), vehicle-mounted terminals (such as vehicle-mounted navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 5The electronic device 500 shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present invention.

[0092] It should be noted that the logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be specifically implemented in any computer-readable medium for use by an instruction execution system, device or apparatus (such as a computer-based system, a system including a processor, or other system that can fetch instructions from an instruction execution system, device or apparatus and execute instructions), or in combination with these instruction execution systems, devices or apparatuses. For the purposes of this specification, "computer-readable medium" can be any device that can contain, store, communicate, propagate or transmit a program for use by an instruction execution system, device or apparatus, or in combination with these instruction execution systems, devices or apparatuses. More specific examples of computer-readable media (a non-exhaustive list) include the following: an electrical connection portion with one or more wirings (electronic device), a portable computer disk box (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disk read-only memory (CDROM). In addition, the computer-readable medium may even be paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium and then editing, interpreting or processing in other suitable ways if necessary, and then stored in a computer memory.

[0093] It should be understood that the various parts of the present invention can be implemented by hardware, software, firmware or a combination thereof. In the above-mentioned embodiments, a plurality of steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, it can be implemented by any one of the following technologies known in the art or their combination: a discrete logic circuit having a logic gate circuit for implementing a logic function for a data signal, a dedicated integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.

[0094] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "examples", "specific examples", or "some examples" means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representation of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner.

[0095] In the description of the present invention, it is to be understood that the terms “center”, “longitudinal”, “lateral”, “length”, “width”, “thickness”, “up”, “down”, “front”, “back”, “left”, “right”, “vertical”, “horizontal”, “top”, “bottom”, “inside”, “outside”, “clockwise”, “counterclockwise”, “axial”, “radial”, “circumferential”, etc., indicating orientations or positional relationships based on the orientations or positional relationships shown in the accompanying drawings, are only for the convenience of describing the present invention and simplifying the description, and do not indicate or imply that the referred device or element must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be understood as limiting the present invention.

[0096] In addition, the terms "first" and "second" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Therefore, the features defined as "first" and "second" may explicitly or implicitly include at least one of the features. In the description of the present invention, the meaning of "plurality" is at least two, such as two, three, etc., unless otherwise clearly and specifically defined.

[0097] In the present invention, unless otherwise clearly specified and limited, the terms "installed", "connected", "connected", "fixed" and the like should be understood in a broad sense, for example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection or an indirect connection through an intermediate medium, it can be the internal connection of two elements or the interaction relationship between two elements, unless otherwise clearly defined. For ordinary technicians in this field, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.

[0098] In the present invention, unless otherwise clearly specified and limited, a first feature being "above" or "below" a second feature may mean that the first and second features are in direct contact, or the first and second features are in indirect contact through an intermediate medium. Moreover, a first feature being "above", "above" or "above" a second feature may mean that the first feature is directly above or obliquely above the second feature, or simply means that the first feature is higher in level than the second feature. A first feature being "below", "below" or "below" a second feature may mean that the first feature is directly below or obliquely below the second feature, or simply means that the first feature is lower in level than the second feature.

[0099] Although the embodiments of the present invention have been shown and described above, it is to be understood that the above embodiments are exemplary and are not to be construed as limitations of the present invention. A person skilled in the art may change, modify, replace and vary the above embodiments within the scope of the present invention.

Claims

1. A data processing method, characterized in that: Applied to an encryption device, the method comprises: Get input data from the target device; Encrypting the input data using the first AES key information to generate a first ciphertext; Encrypting the first AES key information using the first public key to generate a second ciphertext, and generating a digital signature of the second ciphertext using a private key corresponding to the first public key; The first ciphertext, the second ciphertext and the digital signature are sent to a decryption device, so that the decryption device verifies the legitimacy of the digital signature based on a second public key that is the same as the first public key and the second ciphertext; if the digital signature is legitimate, the first ciphertext is decrypted using second AES key information that is the same as the first AES key information to obtain the input data, and the input data is verified.

2. The method according to claim 1, characterized in that The input data includes: The hardware information of the target device, the function module number, date information, call count information, and version number information of the decryption device.

3. The method according to claim 1, characterized in that The sending the first ciphertext, the second ciphertext and the digital signature to a decryption device comprises: Concatenate the first ciphertext, the second ciphertext, and the digital signature, and perform base64 encoding on the concatenated data to obtain encoded data; The encoded data is sent to a decryption device.

4. The method according to claim 1, characterized in that: Before concatenating the first ciphertext, the second ciphertext, and the digital signature, the method further includes: The digital signature is encrypted using the first AES key information to obtain a third ciphertext of the digital signature.

5. A data processing method, characterized in that: Applied to a decryption device, the method comprises: Obtaining a first ciphertext, a second ciphertext, and a digital signature generated for a target device and sent by an encryption device; Verifying the legitimacy of the digital signature based on a second public key and the second ciphertext; wherein the second public key is the same as the first public key that generated the second ciphertext; If the digital signature is legitimate, the first ciphertext is decrypted using the second AES key information to obtain input data of the target device, and the input data is verified; wherein the second AES key information is the same as the first AES key information used to generate the first ciphertext.

6. The method according to claim 5, characterized in that In the case where the input data includes the hardware information of the target device, the function module number, date information, call count information, and version number information of the decryption device, the verifying of the input data includes: In the date information, call count information, version number information and hardware information, for target information with preset restriction conditions, it is determined whether the target information meets the restriction conditions to obtain a verification result.

7. The method according to claim 6, characterized in that If the verification result indicates that the target information satisfies the restriction condition, the method further includes: The function module corresponding to the function module number is called to provide services for the target device.

8. The method according to claim 5, characterized in that If the digital signature is a third ciphertext encrypted by using the first AES key information, after obtaining the first ciphertext, the second ciphertext and the digital signature generated for the target device and sent by the encryption device, the method further includes: The third ciphertext is decrypted using the second AES key information to obtain a digital signature in plain text.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the data processing method according to any one of claims 1 to 8 is implemented.

10. An electronic device, characterized in that: include: Memory, processor; The memory stores a computer program, and when the computer program is executed by the processor, the data processing method according to any one of claims 1 to 8 is implemented.