Data encryption and decryption method and device, computer equipment and storage medium

By combining multiple asymmetric cryptographic algorithms in the cryptographic support layer of the DOIDOSI model to generate public key clusters and introducing a dynamic adjustment mechanism, the problem that traditional cryptographic algorithms are difficult to meet complex business scenarios and diversified security needs is solved, and the system's security and flexibility are unified.

CN120017338APending Publication Date: 2025-05-16黎鸿
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510100868.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-20
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

Traditional cryptographic algorithms are difficult to meet the increasingly complex business scenarios and diversified security needs, and it is urgent to explore new password integration methods to improve the security and flexibility of the system.

Method used

Multiple public key clusters are generated using a variety of asymmetric cryptographic algorithms (such as RSA and ECC). Combined with a dynamic adjustment mechanism, flexibly select and switch password policies according to business scenarios and security needs, and customize data interfaces through dynamic adjustment of angle domains.

Benefits of technology

It improves the security and flexibility of the system, can adapt to the needs of different business scenarios, and achieves a balance between security and performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017338A_ABST
    Figure CN120017338A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of artificial intelligence, and relates to a data encryption and decryption method and device, computer equipment and a storage medium, and the method comprises the steps: receiving a data encryption and decryption request which comprises a business type, a business scene and to-be-processed data; adjusting the initial angle threshold according to the service type and the service scene to obtain a target angle domain; calling an algorithm database, and obtaining a target resultant force cryptographic algorithm corresponding to the target angle domain from the algorithm database; generating a target public and private key pair according to a preset private key and a target resultant cryptographic algorithm; updating the initial configuration parameter according to the target public and private key pair to obtain a target configuration parameter; generating a target data interface according to the target public and private key pair and the target configuration parameter; and calling the target data interface, and encrypting and decrypting the to-be-processed data according to the target data interface to obtain target encrypted and decrypted data. The security and flexibility of the system can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of artificial intelligence technology, and in particular to a data encryption and decryption method, device, computer equipment and storage medium. Background Art

[0002] With the rapid development of information technology and the sharp increase in global data volume, digital identity management systems are facing unprecedented challenges. Traditional digital identity authentication and management frameworks have gradually exposed their shortcomings in scalability, interoperability, and security, making it difficult to meet the needs of modern society for efficient, secure, and flexible identity management. In order to meet these challenges, the Digital Omnipotent Identity and Open System Interconnect (DOIDOSI / DOSI) model came into being, hoping to become the representative of a new generation of digital identity management and authentication frameworks. The DOIDOSI model can solve the problems of fragmentation, poor interoperability, and insufficient security in traditional digital identity systems. By building a unified, open, and scalable identity management platform, DOIDOSI promotes seamless connection and collaboration between different systems, greatly improving the utilization efficiency and security of digital identity data. In addition, the elastic chain concept in the model provides an innovative solution for coping with large-scale dynamically changing environments, enabling digital identity systems to achieve flexible expansion and adaptability while ensuring high security.

[0003] The DOIDOSI model builds a multi-layered, modular architecture by integrating various existing identity management and authentication technologies. From the social subject layer to the block data layer, each layer carries specific functions and responsibilities, and together constitutes a complete digital identity ecosystem. Among them, the cryptographic support layer serves as a bridge between the upper-layer business applications and the lower-layer blockchain technology, and its security is directly related to the stable operation of the entire system. However, a single cryptographic algorithm can no longer meet the increasingly complex business scenarios and diverse security requirements, and it is urgent to explore new cryptographic integration methods to improve the security and flexibility of the system.

[0004] With the development of new technologies such as quantum computing, traditional cryptographic algorithms are at risk of being cracked. At the same time, different application scenarios have significantly different requirements for security, efficiency, compatibility, etc., which puts higher requirements on the cryptographic support layer. How to effectively integrate multiple advanced cryptographic technologies in the same system to achieve the unity of security and flexibility has become a key issue that needs to be solved urgently. Summary of the invention

[0005] The purpose of the embodiments of the present application is to propose a data encryption and decryption method, apparatus, computer equipment and storage medium to solve the problem of how to effectively integrate multiple advanced cryptographic technologies in the same system to achieve the unity of security and flexibility.

[0006] In order to solve the above technical problems, the present application embodiment provides a data encryption and decryption method, which adopts the following technical solution:

[0007] Receiving a data encryption and decryption request sent by a user terminal, wherein the data encryption and decryption request includes a service type and a service scenario and data to be processed;

[0008] Adjusting the initial angle threshold according to the service type and the service scenario to obtain a target angle domain;

[0009] Calling an algorithm database, and obtaining a target combined force cryptographic algorithm corresponding to the target angle domain in the algorithm database;

[0010] Generate a target public-private key pair according to a preset private key and the target combined cryptographic algorithm;

[0011] Performing an update operation on the initial configuration parameters according to the target public-private key pair to obtain target configuration parameters;

[0012] Generate a target data interface according to the target public-private key pair and the target configuration parameters;

[0013] The target data interface is called, and encryption and decryption processing is performed on the data to be processed according to the target data interface to obtain target encrypted and decrypted data.

[0014] Furthermore, the step of performing encryption and decryption processing on the data to be processed according to the target data interface to obtain target encrypted and decrypted data specifically includes the following steps:

[0015] Performing a vector conversion operation on the data to be processed according to the target public-private key pair to obtain an initial vector;

[0016] Performing a preprocessing operation on the data to be processed to obtain a preprocessed byte array;

[0017] The preprocessed byte array is processed in blocks to obtain N block byte arrays, where N is an integer greater than 0;

[0018] Calculate the angle value of each block byte array according to the initial vector;

[0019] Calculate the angle value of each block byte array according to the cosine function to obtain the cosine value of each block byte array;

[0020] Merge the cosine values ​​of all the block byte arrays to obtain a merged cosine value;

[0021] The combined cosine value is hashed according to the target hash function to obtain the target encryption and decryption data.

[0022] Furthermore, the step of performing a preprocessing operation on the data to be processed to obtain a preprocessed byte array specifically includes the following steps:

[0023] Performing a data conversion operation on the data to be processed to obtain a converted byte array;

[0024] Performing a filling operation on the converted byte array to obtain the preprocessed byte array.

[0025] Furthermore, the step of calculating the angle value of each block byte array according to the initial vector comprises the following steps:

[0026] Calculate the dot product of each block byte array and the initial vector respectively to obtain a real number of each block byte array;

[0027] A real number conversion operation is performed on the real numbers of each block byte array respectively to obtain the angle value of each block byte array.

[0028] Furthermore, after the step of calling the target data interface and performing encryption and decryption processing on the data to be processed according to the target data interface to obtain target encrypted and decrypted data, the following steps are also included:

[0029] Auditing and monitoring the target encrypted and decrypted data;

[0030] When the target encrypted and decrypted data completes the transaction processing, the target configuration parameters are restored to the initial configuration parameters.

[0031] In order to solve the above technical problems, the embodiment of the present application also provides a data encryption and decryption device, which adopts the following technical solution:

[0032] A request acquisition module, used to receive a data encryption and decryption request sent by a user terminal, wherein the data encryption and decryption request includes a service type and a service scenario and data to be processed;

[0033] An angle threshold adjustment module, used to adjust the initial angle threshold according to the service type and the service scenario to obtain a target angle domain;

[0034] A Heli cryptographic algorithm acquisition module, used for calling an algorithm database, and acquiring a target Heli cryptographic algorithm corresponding to the target angle domain in the algorithm database;

[0035] A public-private key pair generation module, used to generate a target public-private key pair according to a preset private key and the target combined cryptographic algorithm;

[0036] A configuration parameter updating module, used to update the initial configuration parameters according to the target public-private key pair to obtain the target configuration parameters;

[0037] A data interface generation module, used to generate a target data interface according to the target public-private key pair and the target configuration parameters;

[0038] The encryption and decryption processing module is used to call the target data interface and perform encryption and decryption processing on the data to be processed according to the target data interface to obtain target encrypted and decrypted data.

[0039] Furthermore, the encryption and decryption processing module includes:

[0040] A vector conversion submodule, used for performing a vector conversion operation on the data to be processed according to the target public-private key pair to obtain an initial vector;

[0041] A preprocessing submodule, used for performing a preprocessing operation on the data to be processed to obtain a preprocessed byte array;

[0042] A block submodule, used for performing block processing on the preprocessed byte array to obtain N block byte arrays, wherein N is an integer greater than 0;

[0043] An angle value calculation submodule, used to calculate the angle value of each block byte array according to the initial vector;

[0044] The cosine value calculation submodule is used to calculate the angle value of each block byte array according to the cosine function to obtain the cosine value of each block byte array;

[0045] The merging submodule is used to merge the cosine values ​​of all the block byte arrays to obtain a merged cosine value;

[0046] The hash processing submodule is used to perform hash processing on the combined cosine value according to the target hash function to obtain the target encryption and decryption data.

[0047] Furthermore, the preprocessing submodule includes:

[0048] A data conversion unit, used for performing a data conversion operation on the data to be processed to obtain a conversion byte array;

[0049] A filling unit is used to perform a filling operation on the converted byte array to obtain the preprocessed byte array.

[0050] In order to solve the above technical problems, the embodiment of the present application further provides a computer device, which adopts the following technical solution:

[0051] It comprises a memory and a processor, wherein the memory stores computer-readable instructions, and the processor implements the steps of the data encryption and decryption method as described above when executing the computer-readable instructions.

[0052] In order to solve the above technical problems, the embodiment of the present application further provides a computer-readable storage medium, which adopts the following technical solution:

[0053] The computer-readable storage medium stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, the steps of the data encryption and decryption method described above are implemented.

[0054] The present application provides a data encryption and decryption method, comprising: receiving a data encryption and decryption request sent by a user terminal, wherein the data encryption and decryption request includes a business type, a business scenario, and data to be processed; adjusting the initial angle threshold according to the business type and the business scenario to obtain a target angle domain; calling an algorithm database, and obtaining a target joint force cryptographic algorithm corresponding to the target angle domain in the algorithm database; generating a target public-private key pair according to a preset private key and the target joint force cryptographic algorithm; updating the initial configuration parameters according to the target public-private key pair to obtain the target configuration parameters; generating a target data interface according to the target public-private key pair and the target configuration parameters; calling the target data interface, and encrypting and decrypting the data to be processed according to the target data interface to obtain the target encryption and decryption data. Compared with the prior art, the present application makes full use of the advantages of multiple cryptographic technologies, and generates multiple corresponding public keys by combining different asymmetric cryptographic algorithms (such as RSA, ECC, etc.) to improve the security of the system; at the same time, a dynamic adjustment mechanism is introduced to flexibly select and switch cryptographic strategies according to different business scenarios or security requirements. BRIEF DESCRIPTION OF THE DRAWINGS

[0055] In order to more clearly illustrate the scheme in the present application, a brief introduction is given below to the drawings required for use in the description of the embodiments of the present application. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0056] Figure 1 is an exemplary system architecture diagram to which the present application may be applied;

[0057] Figure 2 It is a flow chart of the implementation of the data encryption and decryption method provided in the embodiment of the present application;

[0058] Figure 3 It is a structural diagram of a data encryption and decryption device provided in an embodiment of the present application;

[0059] Figure 4 It is a structural diagram of an embodiment of a computer device according to the present application. DETAILED DESCRIPTION

[0060] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by technicians in the technical field of the present application; the terms used in the specification of the application herein are only for the purpose of describing specific embodiments and are not intended to limit the present application; the terms "including" and "having" and any variations thereof in the specification and claims of the present application and the above-mentioned drawings are intended to cover non-exclusive inclusions. The terms "first", "second", etc. in the specification and claims of the present application or the above-mentioned drawings are used to distinguish different objects, not to describe a specific order.

[0061] Reference to "embodiments" herein means that a particular feature, structure, or characteristic described in conjunction with the embodiments may be included in at least one embodiment of the present application. The appearance of the phrase in various locations in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment that is mutually exclusive with other embodiments. It is explicitly and implicitly understood by those skilled in the art that the embodiments described herein may be combined with other embodiments.

[0062] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings.

[0063] like Figure 1 As shown, the system architecture 100 may include a terminal device 101, a network 102 and a server 103. The terminal device 101 may be a laptop 1011, a tablet computer 1012 or a mobile phone 1013. The network 102 is used to provide a medium for a communication link between the terminal device 101 and the server 103. The network 102 may include various connection types, such as wired, wireless communication links or optical fiber cables, etc.

[0064] The user can use the terminal device 101 to interact with the server 103 through the network 102 to receive or send messages, etc. Various communication client applications can be installed on the terminal device 101, such as web browser applications, shopping applications, search applications, instant messaging tools, email clients, social platform software, etc.

[0065] The terminal device 101 can be any electronic device with a display screen and supporting web browsing. In addition to the laptop computer 1011, tablet computer 1012 or mobile phone 1013, the terminal device 101 can also be an e-book reader, an MP3 player (Moving Picture Experts Group Audio Layer III), an MP4 (Moving Picture Experts Group Audio Layer IV), a laptop computer, a desktop computer, etc.

[0066] The server 103 may be a server that provides various services, such as a background server that provides support for a web page displayed on the terminal device 101 .

[0067] It should be noted that the data encryption and decryption method provided in the embodiment of the present application is generally executed by a server / terminal device, and accordingly, the data encryption and decryption device is generally set in the server / terminal device.

[0068] It should be understood that Figure 1 The number of terminal devices, networks and servers in the embodiment is only for illustration. Any number of terminal devices, networks and servers may be provided according to implementation requirements.

[0069] Continue to refer Figure 2 , shows a flow chart of an embodiment of a data encryption and decryption method according to the present application. The data encryption and decryption method comprises: step S201, step S202, step S203, step S204, step S205, step S206 and step S207.

[0070] In step S201, a data encryption and decryption request sent by a user terminal is received, wherein the data encryption and decryption request includes a service type and a service scenario and data to be processed;

[0071] In the embodiments of the present application, the present application is applicable to the Digital Omnipotent Identity and Open System Interconnect (DOIDOSI / DOSI) reference model, wherein the DOIDOSI / DOSI model is a comprehensive digital identity management framework, and its hierarchical structure is divided into ten layers from bottom to top, and each layer serves a specific functional area, specifically including:

[0072] (1) Social subject layer: Service (assistant, helper, avatar, clone) social subject is the entire function and role of the DOIDOSI model. The social subject layer is the model entrance based on social subjects, focusing on the registration, registration and management of various entities in the society (such as individuals, organizations, devices, etc.), ensuring that each entity has a unique identifier, unified regularity and the relevance of rights and obligations in the digital world;

[0073] (2) Subject ownership layer: manages the resources and permissions owned by each subject, involving the ownership and control of identity data, and safeguarding data sovereignty;

[0074] (3) Humanized identification layer: Confirm humanized identification and identification for each subject to facilitate identification, memory, and use, thereby enhancing the user experience;

[0075] (4) Name format layer: defines the naming rules and format standards of identity tags to ensure the consistency and readability of identity tags;

[0076] (5) Business set stratification: modularize different business logic and services to facilitate flexible combination and reuse, and support diverse application scenarios;

[0077] (6) Cryptographic support layer: responsible for generating, storing and managing cryptographic algorithms and keys, generating, storing and managing public key address tables and cryptographic algorithm data interfaces, and is the core link to ensure data confirmation, transmission and storage security;

[0078] (7) Relationship set hierarchy: describes the relationship network between different subjects and supports the implementation of trust transfer and access control policies;

[0079] (8) Blockchain consensus layer: blockchain technology is used to achieve decentralized consensus on data, ensuring the immutability and transparency of identity data;

[0080] (9) Blockchain network layer: building blockchain network infrastructure to promote efficient data transmission and sharing;

[0081] (10) Block data layer: As the final data storage layer, it uses distributed ledger technology to record all identity-related transactions.

[0082] In the embodiments of the present application, in the cryptographic support layer of the DOIDOSI model, the design of the cryptographic integration method follows the following core concepts: First, make full use of the advantages of multiple cryptographic technologies, and generate multiple corresponding public keys by combining different asymmetric cryptographic algorithms (such as RSA, ECC, etc.) to improve the security of the system; second, introduce a dynamic adjustment mechanism to flexibly select and switch cryptographic strategies according to different business scenarios or security requirements; third, ensure the universality and scalability of the method so that it can adapt to the development of future cryptographic technologies and the emergence of new business scenarios. The design goal is to build a secure and flexible cryptographic integration framework to provide solid technical support for the digital universal identity system.

[0083] In step S202, the initial angle threshold is adjusted according to the service type and service scenario to obtain a target angle range.

[0084] In the embodiment of the present application, the angle domain (θ) plays a vital role in the Heli cryptographic algorithm. The angle domain is defined as a set of specific business scenarios or security requirements, denoted as θ = {θ1, θ2, ..., θ n}, where each θ i Represents a unique business environment or security level. The main function of the angle domain is to dynamically determine the most appropriate encryption method and parameter configuration based on the current business needs or security situation. For example, when processing highly sensitive financial transactions, the system will choose a larger angle domain value (such as θ i = high security) to correspond to more complex and secure cryptographic algorithms; while for general information query services, a smaller angle domain value (such as θ i = Medium security) to balance security and processing efficiency.

[0085] In step S203, the algorithm database is called to obtain the target combined force cryptographic algorithm corresponding to the target angle domain in the algorithm database.

[0086] In the embodiments of the present application, the Heli cryptographic algorithm is an innovative encryption strategy that abandons the limitations of traditional single algorithms and generates multiple public keys by combining the same private key with multiple asymmetric cryptographic algorithms to form a powerful "public key cluster". This cluster not only inherits the advantages of each algorithm, but also significantly improves the overall anti-attack capability and flexibility through the complementarity between algorithms. For example, combining the efficient decryption of RSA with the compact key size of ECC, the most appropriate public key can be selected for encryption according to the actual communication environment, which not only ensures security but also optimizes transmission efficiency.

[0087] In step S204, a target public-private key pair is generated according to the preset private key and the target combined cryptographic algorithm.

[0088] In step S205, the initial configuration parameters are updated according to the target public-private key pair to obtain the target configuration parameters.

[0089] In step S206, a target data interface is generated according to the target public-private key pair and the target configuration parameters.

[0090] In an embodiment of the present application, the data interface mapping method is one of the key mechanisms to achieve the flexibility of the Heli cryptographic algorithm. This method realizes the customization of data interfaces in different business scenarios by dynamically adjusting the value of θ. Specifically, when the system detects that the business scenario has changed or the security requirements have been upgraded, it will automatically adjust the value of θ according to pre-set rules. This adjustment process involves multiple aspects such as switching of cryptographic algorithms, changes in key length, and selection of hash functions. In this way, the data interface mapping method ensures that the Heli cryptographic algorithm can always provide the best balance of security and performance to meet the needs of different application scenarios.

[0091] In the embodiment of the present application, the data interface mapping method is one of the key technologies to realize the angle domain concept. It drives the adaptive change of the parameters of the Heli cryptographic algorithm by dynamically adjusting the value of θ, thereby realizing the customization of the data interface. Specifically, the method includes the following steps:

[0092] (1) Requirements analysis: First, clarify the security and performance requirements of the current application scenario and determine the corresponding angle domain values;

[0093] (2) Algorithm selection: According to the angle domain value, select the most suitable asymmetric cryptographic algorithm combination from the preset algorithm library. For example, for high security requirements, the combination of RSA and ECC may be preferred; for performance-sensitive scenarios, only ECC may be used;

[0094] (3) Parameter configuration: For different algorithms, further refine and configure specific parameters, such as key length, hash function type, etc., to ensure optimal security and performance;

[0095] (4) Interface generation: Based on the selected algorithm and parameters, a data interface that adapts to the current scenario is dynamically generated for upper-level applications to call and implement data encryption and decryption.

[0096] In some optional implementations of the embodiments of the present application, the above-mentioned data interface mapping method may also include feedback optimization, specifically, continuously monitoring the effect of encryption operations, including security assessment and performance testing, and adjusting the angle domain value and related parameters in a timely manner according to the feedback results to form a closed-loop optimization mechanism.

[0097] In the embodiment of the present application, let θ be a point in the angle domain, representing a certain service type or application scenario. Then the service cryptographic algorithm A can be expressed as:

[0098] A n+1 =A n (θ)

[0099] This formula shows that the business cryptographic algorithm A is a function of θ. Specifically, for each different value of θ, there is a corresponding instance or result of the business cryptographic algorithm A. This representation emphasizes the key role of θ in determining the business cryptographic algorithm A, that is, different business types or application scenarios (represented by θ) will inevitably lead to different business cryptographic algorithm implementations.

[0100] In the embodiment of the present application, it is assumed that in a certain business scenario, the system needs to process a financial transaction with high security requirements. In the initial state, the angle domain is set to θ i = Standard security, the corresponding cryptographic algorithm is RSA-2048. As the business scenario changes, the system recognizes that the transaction belongs to the high-risk category and needs to be strengthened. At this time, the system automatically adjusts the angle domain value to θ i = High security, and trigger the switching process of the password algorithm. The specific steps are as follows:

[0101] (1) The system is based on the new angle domain value (θ i =High security), determine to use a stronger cryptographic algorithm, such as ECC-384;

[0102] (2) Generate a new public-private key pair using the existing private key and the selected cryptographic algorithm (ECC-384);

[0103] (3) Update the relevant configuration in the system to ensure that subsequent transaction requests use the new public-private key pair for encryption and decryption operations;

[0104] (4) Encrypt the current transaction and record relevant logs for subsequent auditing and monitoring;

[0105] (5) After completing the transaction processing, the system returns to the normal security monitoring state, waiting for the next change in business scenarios or adjustment of security requirements.

[0106] In step S207, the target data interface is called, and encryption and decryption processing is performed on the data to be processed according to the target data interface to obtain target encrypted and decrypted data.

[0107] In the embodiment of the present application, in order to achieve compatibility in different application scenarios, an angle domain is introduced to define the data interface. The angle domain can be regarded as a multidimensional space, and each dimension represents a business type or application scenario. By mapping the business cryptographic algorithm to the corresponding angle domain, isolation and collaboration between different businesses can be achieved.

[0108] Handle multiple different business needs within a unified framework while ensuring that each business can operate in the appropriate context. For example, in a financial system, there may be multiple business scenarios involved, such as payment, credit assessment, and risk management. By mapping these scenarios to different dimensions, it can be ensured that each business logic can operate independently without being affected by other businesses. In addition, when operations need to be performed across multiple dimensions (such as processing payments and credit assessments at the same time), efficient information sharing and interaction can be achieved through the collaborative mechanism between perspective domains.

[0109] In an embodiment of the present application, a data encryption and decryption method is provided, including: receiving a data encryption and decryption request sent by a user terminal, wherein the data encryption and decryption request includes a business type, a business scenario, and data to be processed; adjusting the initial angle threshold according to the business type and the business scenario to obtain a target angle domain; calling an algorithm database, and obtaining a target combined cryptographic algorithm corresponding to the target angle domain in the algorithm database; generating a target public-private key pair according to a preset private key and a target combined cryptographic algorithm; updating the initial configuration parameters according to the target public-private key pair to obtain the target configuration parameters; generating a target data interface according to the target public-private key pair and the target configuration parameters; calling the target data interface, and encrypting and decrypting the data to be processed according to the target data interface to obtain the target encryption and decryption data. Compared with the prior art, the present application makes full use of the advantages of multiple cryptographic technologies, and generates multiple corresponding public keys by combining different asymmetric cryptographic algorithms (such as RSA, ECC, etc.) to improve the security of the system; at the same time, a dynamic adjustment mechanism is introduced to flexibly select and switch cryptographic strategies according to different business scenarios or security requirements.

[0110] In some optional implementations of the embodiments of the present application, the above-mentioned step of encrypting and decrypting the data to be processed according to the target data interface to obtain the target encrypted and decrypted data specifically includes the following steps:

[0111] Perform vector conversion operation on the data to be processed according to the target public and private keys to obtain the initial vector;

[0112] Perform preprocessing operations on the data to be processed to obtain a preprocessing byte array;

[0113] The preprocessed byte array is divided into blocks to obtain N block byte arrays, where N is an integer greater than 0;

[0114] Calculate the angle value of each block byte array according to the initial vector;

[0115] Calculate the angle value of each block byte array according to the cosine function to obtain the cosine value of each block byte array;

[0116] Merge the cosine values ​​of all the block byte arrays to obtain a merged cosine value;

[0117] The combined cosine value is hashed according to the target hash function to obtain the target encrypted and decrypted data.

[0118] In the embodiment of the present application, encryption and decryption of the data to be processed according to the target data interface can be performed according to the following steps:

[0119] (1) Define basic concepts and parameters:

[0120] Input data: data to be encrypted or decrypted, which can be a string of any length;

[0121] Key: A fixed-length string or sequence of numbers used to mix with input data;

[0122] Hash function: Choose a standard hash function (such as SHA-256) to generate a fixed-length hash value;

[0123] Cosine function: Use the cosine function (cos) in mathematics, whose input is the angle (in radians);

[0124] (2) Preprocessing input data;

[0125] (3) Generate initial vector:

[0126] Generate an initialization vector (IV) using the input data and the key. This can be achieved through a simple XOR operation: IV = hash(input_data) key ;

[0127] (4) Block processing:

[0128] Divide the padded byte array into multiple fixed-size blocks, each block has the same size as the key length;

[0129] (5) Calculate the angle of each block;

[0130] (6) Apply the cosine function:

[0131] Apply the cosine function to the angle calculated for each block to get a new value;

[0132] Map this new value back into an integer range (e.g., via modulo operation);

[0133] (7)Combination results:

[0134] Combine the results of all blocks together to form the final cipher output;

[0135] (8) Return the hash value:

[0136] The final password output is hashed using a standard hash function to produce a fixed-length hash value.

[0137] In some optional implementations of the embodiments of the present application, the above step of performing a preprocessing operation on the data to be processed to obtain a preprocessed byte array specifically includes the following steps:

[0138] Perform data conversion operation on the data to be processed to obtain a converted byte array;

[0139] Perform padding operation on the converted byte array to obtain a preprocessed byte array.

[0140] In an embodiment of the present application, the preprocessing operation on the data to be processed may be: converting the input data into a byte array; padding the byte array so that its length meets specific requirements (for example, an integer multiple of the key length).

[0141] In some optional implementations of the embodiments of the present application, the above step of calculating the angle value of each block byte array according to the initial vector specifically includes the following steps:

[0142] Calculate the dot product of each block byte array and the initial vector respectively to obtain the real number of each block byte array;

[0143] The real numbers of each block byte array are respectively converted to real numbers to obtain the angle value of each block byte array.

[0144] In an embodiment of the present application, the angle value of each block byte array is calculated according to the initial vector by calculating the dot product of each block with the initial vector to obtain a real number; and converting this real number into an angle (radians) as the input of the cosine function.

[0145] In some optional implementations of the embodiments of the present application, after the step of calling the target data interface and performing encryption and decryption processing on the data to be processed according to the target data interface to obtain the target encrypted and decrypted data, the following steps are also included:

[0146] Audit and monitor the target encrypted and decrypted data;

[0147] When the target encrypted and decrypted data completes the transaction processing, the target configuration parameters are restored to the initial configuration parameters.

[0148] In the embodiment of the present application, as the value of θ increases, the system uses a more complex and secure cryptographic algorithm (such as transitioning from RSA-2048 to ECC-384), and its security is significantly improved. Specifically, the difficulty of cracking increases and the ability to resist common attacks is enhanced. However, this improvement in security is also accompanied by an increase in the consumption of computing resources and an increase in processing time. Therefore, it is necessary to weigh the balance between security and performance when selecting the value of θ.

[0149] In the embodiment of the present application, the data interface mapping method shows good adaptability in different business scenarios. Whether it is real-time transaction processing with high performance requirements or sensitive data transmission scenarios with high security requirements, the corresponding requirements can be met by dynamically adjusting the θ value. In addition, the method can also automatically optimize the encryption strategy according to the system load and network conditions to improve the overall performance.

[0150] In the embodiments of the present application, compared with a single cryptographic algorithm, the multi-algorithm integration method has obvious advantages in terms of security and flexibility. In terms of security, multi-algorithm integration improves the overall protection capability by combining the advantages of multiple cryptographic technologies; in terms of flexibility, it can dynamically adjust the encryption strategy according to different business scenarios to meet specific security requirements or performance requirements. However, this flexibility also brings certain complexity and increased management costs. Therefore, in practical applications, it is necessary to weigh the pros and cons and make reasonable choices according to the specific situation.

[0151] The embodiments of the present application can acquire and process relevant data based on artificial intelligence technology. Among them, artificial intelligence (AI) is the theory, method, technology and application system that uses digital computers or machines controlled by digital computers to simulate, extend and expand human intelligence, perceive the environment, acquire knowledge and use knowledge to obtain the best results.

[0152] AI basic technologies generally include sensors, dedicated AI chips, cloud computing, distributed storage, big data processing technology, operation / interaction systems, mechatronics, etc. AI software technologies mainly include computer vision technology, robotics technology, biometrics technology, speech processing technology, natural language processing technology, and machine learning / deep learning.

[0153] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through computer-readable instructions, and the computer-readable instructions can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, the aforementioned storage medium can be a non-volatile storage medium such as a disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM).

[0154] It should be understood that, although the steps in the flowchart of the accompanying drawings are displayed in sequence as indicated by the arrows, these steps are not necessarily executed in sequence in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least a part of the steps in the flowchart of the accompanying drawings may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily executed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be executed in turn or alternately with other steps or at least a part of the sub-steps or stages of other steps.

[0155] Further references Figure 3 , as a response to the above Figure 2 The present application provides an embodiment of a data encryption and decryption device, and the device embodiment is similar to Figure 2 Corresponding to the method embodiment shown, the device can be specifically applied to various electronic devices.

[0156] like Figure 3 As shown, the data encryption and decryption device 200 of the embodiment of the present application includes:

[0157] The request acquisition module 210 is used to receive a data encryption and decryption request sent by a user terminal, wherein the data encryption and decryption request includes a service type and a service scenario and data to be processed;

[0158] An angle threshold adjustment module 220, used to adjust the initial angle threshold according to the service type and service scenario to obtain a target angle domain;

[0159] The Heli cryptographic algorithm acquisition module 230 is used to call the algorithm database and obtain the target Heli cryptographic algorithm corresponding to the target angle domain in the algorithm database;

[0160] A public-private key pair generation module 240, for generating a target public-private key pair according to a preset private key and a target combined cryptographic algorithm;

[0161] The configuration parameter updating module 250 is used to update the initial configuration parameters according to the target public-private key pair to obtain the target configuration parameters;

[0162] The data interface generation module 260 is used to generate a target data interface according to a target public-private key pair and target configuration parameters;

[0163] The encryption and decryption processing module 270 is used to call the target data interface and perform encryption and decryption processing on the data to be processed according to the target data interface to obtain target encrypted and decrypted data.

[0164] In an embodiment of the present application, a data encryption and decryption device 200 is provided, including: a request acquisition module 210, which is used to receive a data encryption and decryption request sent by a user terminal, wherein the data encryption and decryption request includes a business type, a business scenario, and data to be processed; an angle threshold adjustment module 220, which is used to adjust the initial angle threshold according to the business type and the business scenario to obtain a target angle domain; a combined cryptographic algorithm acquisition module 230, which is used to call an algorithm database and obtain a target combined cryptographic algorithm corresponding to the target angle domain in the algorithm database; a public-private key pair generation module 240, which is used to generate a target public-private key pair according to a preset private key and a target combined cryptographic algorithm; a configuration parameter update module 250, which is used to update the initial configuration parameters according to the target public-private key pair to obtain the target configuration parameters; a data interface generation module 260, which is used to generate a target data interface according to the target public-private key pair and the target configuration parameters; an encryption and decryption processing module 270, which is used to call the target data interface, and encrypt and decrypt the data to be processed according to the target data interface to obtain the target encrypted and decrypted data. Compared with the existing technology, this application makes full use of the advantages of multiple cryptographic technologies and generates multiple corresponding public keys by combining different asymmetric cryptographic algorithms (such as RSA, ECC, etc.) to improve the security of the system; at the same time, it introduces a dynamic adjustment mechanism to flexibly select and switch cryptographic strategies according to different business scenarios or security requirements.

[0165] In some optional implementations of the embodiments of the present application, the encryption and decryption processing module includes:

[0166] The vector conversion submodule is used to perform a vector conversion operation on the data to be processed according to the target public and private keys to obtain an initial vector;

[0167] The preprocessing submodule is used to perform preprocessing operations on the data to be processed to obtain a preprocessed byte array;

[0168] A block submodule is used to perform block processing on the preprocessed byte array to obtain N block byte arrays, where N is an integer greater than 0;

[0169] An angle value calculation submodule, used to calculate the angle value of each block byte array according to the initial vector;

[0170] The cosine value calculation submodule is used to calculate the angle value of each block byte array according to the cosine function to obtain the cosine value of each block byte array;

[0171] The merging submodule is used to merge the cosine values ​​of all the block byte arrays to obtain a merged cosine value;

[0172] The hash processing submodule is used to perform hash processing on the combined cosine value according to the target hash function to obtain the target encryption and decryption data.

[0173] In some optional implementations of the embodiments of the present application, the preprocessing submodule includes:

[0174] A data conversion unit, used for performing a data conversion operation on the data to be processed to obtain a conversion byte array;

[0175] The padding unit is used to perform padding operation on the converted byte array to obtain a preprocessed byte array.

[0176] To solve the above technical problems, the present application also provides a computer device. Figure 4 , Figure 4 This is a basic structural block diagram of a computer device according to an embodiment of the present application.

[0177] The computer device 300 includes a memory 310, a processor 320, and a network interface 330 that are interconnected and communicated through a system bus. It should be noted that the figure only shows a computer device 300 having components 310-330, but it should be understood that it is not required to implement all the components shown, and more or fewer components can be implemented instead. Among them, those skilled in the art can understand that the computer device here is a device that can automatically perform numerical calculations and / or information processing according to pre-set or stored instructions, and its hardware includes but is not limited to microprocessors, application specific integrated circuits (Application Specific Integrated Circuit, ASIC), programmable gate arrays (Field-Programmable Gate Array, FPGA), digital processors (Digital Signal Processor, DSP), embedded devices, etc.

[0178] The computer device may be a computing device such as a desktop computer, a notebook, a PDA, a cloud server, etc. The computer device may interact with a user through a keyboard, a mouse, a remote controller, a touch pad, or a voice control device.

[0179] The memory 310 includes at least one type of readable storage medium, and the readable storage medium includes flash memory, hard disk, multimedia card, card-type memory (for example, SD or DX memory, etc.), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, magnetic disk, optical disk, etc. In some embodiments, the memory 310 can be an internal storage unit of the computer device 300, such as a hard disk or memory of the computer device 300. In other embodiments, the memory 310 can also be an external storage device of the computer device 300, such as a plug-in hard disk equipped on the computer device 300, a smart memory card (Smart Media Card, SMC), a secure digital (Secure Digital, SD) card, a flash card, etc. Of course, the memory 310 can also include both the internal storage unit of the computer device 300 and its external storage device. In the embodiment of the present application, the memory 310 is generally used to store the operating system and various application software installed on the computer device 300, such as computer-readable instructions of data encryption and decryption methods. In addition, the memory 310 can also be used to temporarily store various data that have been output or are to be output.

[0180] The processor 320 may be a central processing unit (CPU), a controller, a microcontroller, a microprocessor, or other data processing chip in some embodiments. The processor 320 is generally used to control the overall operation of the computer device 300. In the embodiment of the present application, the processor 320 is used to run the computer-readable instructions stored in the memory 310 or process data, such as computer-readable instructions for running the data encryption and decryption method.

[0181] The network interface 330 may include a wireless network interface or a wired network interface. The network interface 330 is generally used to establish a communication connection between the computer device 300 and other electronic devices.

[0182] The computer device provided in this application makes full use of the advantages of multiple cryptographic technologies and generates multiple corresponding public keys by combining different asymmetric cryptographic algorithms (such as RSA, ECC, etc.) to improve the security of the system; at the same time, it introduces a dynamic adjustment mechanism to flexibly select and switch cryptographic strategies according to different business scenarios or security requirements.

[0183] The present application also provides another implementation, namely, providing a computer-readable storage medium, wherein the computer-readable storage medium stores computer-readable instructions, and the computer-readable instructions can be executed by at least one processor to enable the at least one processor to perform the steps of the data encryption and decryption method as described above.

[0184] The computer-readable storage medium provided in this application makes full use of the advantages of multiple cryptographic technologies and generates multiple corresponding public keys by combining different asymmetric cryptographic algorithms (such as RSA, ECC, etc.) to improve the security of the system; at the same time, a dynamic adjustment mechanism is introduced to flexibly select and switch cryptographic strategies according to different business scenarios or security requirements.

[0185] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus a necessary general hardware platform, and of course by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a number of instructions for a terminal device (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in each embodiment of the present application.

[0186] Obviously, the embodiments described above are only some embodiments of the present application, rather than all embodiments. The preferred embodiments of the present application are given in the accompanying drawings, but they do not limit the patent scope of the present application. The present application can be implemented in many different forms. On the contrary, the purpose of providing these embodiments is to make the understanding of the disclosure of the present application more thorough and comprehensive. Although the present application is described in detail with reference to the aforementioned embodiments, for those skilled in the art, it is still possible to modify the technical solutions recorded in the aforementioned specific implementation methods, or to perform equivalent replacement of some of the technical features therein. Any equivalent structure made using the contents of the specification and drawings of this application, directly or indirectly used in other related technical fields, is similarly within the scope of patent protection of this application.

Claims

1. A data encryption and decryption method, characterized in that: The steps include: Receiving a data encryption and decryption request sent by a user terminal, wherein the data encryption and decryption request includes a service type and a service scenario and data to be processed; Adjusting the initial angle threshold according to the service type and the service scenario to obtain a target angle domain; Calling an algorithm database, and obtaining a target combined force cryptographic algorithm corresponding to the target angle domain in the algorithm database; Generate a target public-private key pair according to a preset private key and the target combined cryptographic algorithm; Performing an update operation on the initial configuration parameters according to the target public-private key pair to obtain target configuration parameters; Generate a target data interface according to the target public-private key pair and the target configuration parameters; The target data interface is called, and encryption and decryption processing is performed on the data to be processed according to the target data interface to obtain target encrypted and decrypted data.

2. The data encryption and decryption method according to claim 1, characterized in that: The step of performing encryption and decryption processing on the data to be processed according to the target data interface to obtain target encrypted and decrypted data specifically includes the following steps: Performing a vector conversion operation on the data to be processed according to the target public-private key pair to obtain an initial vector; Performing a preprocessing operation on the data to be processed to obtain a preprocessed byte array; The preprocessed byte array is processed in blocks to obtain N block byte arrays, where N is an integer greater than 0; Calculate the angle value of each block byte array according to the initial vector; Calculate the angle value of each block byte array according to the cosine function to obtain the cosine value of each block byte array; Merge the cosine values ​​of all the block byte arrays to obtain a merged cosine value; The combined cosine value is hashed according to the target hash function to obtain the target encryption and decryption data.

3. The data encryption and decryption method according to claim 2, characterized in that: The step of performing a preprocessing operation on the data to be processed to obtain a preprocessed byte array specifically includes the following steps: Performing a data conversion operation on the data to be processed to obtain a converted byte array; Performing a filling operation on the converted byte array to obtain the preprocessed byte array.

4. The data encryption and decryption method according to claim 2, characterized in that: The step of respectively calculating the angle value of each block byte array according to the initial vector specifically comprises the following steps: Calculate the dot product of each block byte array and the initial vector respectively to obtain a real number of each block byte array; A real number conversion operation is performed on the real numbers of each block byte array respectively to obtain the angle value of each block byte array.

5. The data encryption and decryption method according to claim 1, characterized in that: After the step of calling the target data interface and performing encryption and decryption processing on the data to be processed according to the target data interface to obtain target encrypted and decrypted data, the following steps are also included: Auditing and monitoring the target encrypted and decrypted data; When the target encrypted and decrypted data completes the transaction processing, the target configuration parameters are restored to the initial configuration parameters.

6. A data encryption and decryption device, characterized in that: include: A request acquisition module, used to receive a data encryption and decryption request sent by a user terminal, wherein the data encryption and decryption request includes a service type and a service scenario and data to be processed; An angle threshold adjustment module, used to adjust the initial angle threshold according to the service type and the service scenario to obtain a target angle domain; A Heli cryptographic algorithm acquisition module, used for calling an algorithm database, and acquiring a target Heli cryptographic algorithm corresponding to the target angle domain in the algorithm database; A public-private key pair generation module, used to generate a target public-private key pair according to a preset private key and the target combined cryptographic algorithm; A configuration parameter updating module, used to update the initial configuration parameters according to the target public-private key pair to obtain the target configuration parameters; A data interface generation module, used to generate a target data interface according to the target public-private key pair and the target configuration parameters; The encryption and decryption processing module is used to call the target data interface and perform encryption and decryption processing on the data to be processed according to the target data interface to obtain target encrypted and decrypted data.

7. The data encryption and decryption device according to claim 6, characterized in that: The encryption and decryption processing module includes: A vector conversion submodule, used for performing a vector conversion operation on the data to be processed according to the target public-private key pair to obtain an initial vector; A preprocessing submodule, used for performing a preprocessing operation on the data to be processed to obtain a preprocessed byte array; A block submodule, used for performing block processing on the preprocessed byte array to obtain N block byte arrays, wherein N is an integer greater than 0; An angle value calculation submodule, used to calculate the angle value of each block byte array according to the initial vector; The cosine value calculation submodule is used to calculate the angle value of each block byte array according to the cosine function to obtain the cosine value of each block byte array; The merging submodule is used to merge the cosine values ​​of all the block byte arrays to obtain a merged cosine value; The hash processing submodule is used to perform hash processing on the combined cosine value according to the target hash function to obtain the target encryption and decryption data.

8. The data encryption and decryption device according to claim 6, characterized in that: The preprocessing submodule includes: A data conversion unit, used for performing a data conversion operation on the data to be processed to obtain a conversion byte array; A filling unit is used to perform a filling operation on the converted byte array to obtain the preprocessed byte array.

9. A computer device comprising a memory and a processor, characterized in that: The memory stores computer-readable instructions, and when the processor executes the computer-readable instructions, the steps of the data encryption and decryption method according to any one of claims 1 to 6 are implemented.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-readable instructions, and when the computer-readable instructions are executed by a processor, the steps of the data encryption and decryption method according to any one of claims 1 to 6 are implemented.