Data encryption and decryption method and device based on address, storage medium and product
By adopting address-based data encryption and decryption methods in embedded devices and using address calculation keys for encryption and decryption, the efficiency and resource occupation of data encryption protection of embedded devices are solved, and efficient and secure data encryption and decryption are achieved.
Patent Information
- Application Number
- CN202510114933.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-23
- Publication Date
- 2025-05-27
AI Technical Summary
The data stored in the external Flash memory of embedded devices requires high efficiency, low resource usage and certain security encryption protection, and the prior art is difficult to meet these needs.
The address-based data encryption and decryption method is adopted to obtain the address of the plain text or cipher text of the data to be encrypted or decrypted, and the encryption or decryption calculation is performed to reduce the use of key resources and improve the efficiency of encryption and decryption calculation.
This method reduces the use of key resources in embedded devices, improves the efficiency of encryption and decryption calculations, and ensures the reversibility of the encryption and decryption process and reduces the use of computing resources by using the same set of addresses.
Smart Images

Figure CN120050069A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present invention relate to the technical field of data security, and particularly to a data encryption method, device, storage medium and product based on address. Background Art
[0002] Since the information generated during the use of an embedded device is generally stored in an external Flash memory, and the information contains some privacy information related to the user during the use of the embedded device and the security information of the device, it is necessary to protect the data stored in the entire Flash memory. However, an embedded device is a computer system designed for a specific function or application, and is usually embedded in other devices for use. For lower power consumption and smaller volume, the microcontroller unit (MCU) of the embedded device generally has poor performance, few resources, and high requirements for real-time performance. Therefore, an encryption algorithm with high efficiency, less resource occupation and certain security is required to protect the data stored in the external Flash memory of the embedded device. Summary of the Invention
[0003] The purpose of the embodiments of the present invention is to provide a data encryption and decryption method, device, storage medium and product based on address, so that encryption or decryption can be performed based on the address of the plaintext to be encrypted or the ciphertext to be decrypted, and the encryption or decryption key is calculated through the address, thereby reducing the occupation of key resources and improving the efficiency of encryption and decryption calculations.
[0004] To solve the above technical problems, the embodiments of the present invention provide a data encryption method based on address, including: obtaining the data plaintext of the data to be encrypted; obtaining the key for encrypting the data plaintext through the address of the data plaintext, and performing an encryption calculation according to the data plaintext and the key; storing the calculation result at the address of the data plaintext to obtain the target data ciphertext.
[0005] The embodiments of the present invention also provide a data decryption method based on address, including: obtaining the data ciphertext of the data to be decrypted; obtaining the key for decrypting the data ciphertext through the address of the data ciphertext, and performing a decryption calculation according to the data ciphertext and the key; storing the calculation result at the address of the data ciphertext to obtain the target data plaintext.
[0006] An embodiment of the present invention also provides an electronic device, including: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and when the instructions are executed by the at least one processor, the at least one processor is enabled to execute the above-mentioned data encryption method based on an address and the above-mentioned data decryption method based on an address.
[0007] An embodiment of the present invention also provides a computer-readable storage medium storing a computer program, including: when the computer program is executed by a processor, it implements the above-mentioned data encryption method based on an address and the above-mentioned data decryption method based on an address.
[0008] An embodiment of the present invention also provides a computer program product, including computer instructions, and when the computer instructions are executed by a processor, they implement the above-mentioned data encryption method based on an address and the above-mentioned data decryption method based on an address.
[0009] In an embodiment of the present invention, the plaintext of the data to be encrypted is obtained; a key for encrypting the plaintext of the data is obtained through the address of the plaintext of the data, and encryption calculation is performed according to the plaintext of the data and the key; since the key for encryption is obtained based on the address of the plaintext to be encrypted or the address of the ciphertext to be decrypted, in the process of encryption or decryption, the address is used as part of the key for calculation, and in subsequent calculation processes, the occupation of key resources is reduced, and the efficiency of encryption and decryption calculations is improved; moreover, the calculation result is stored at the address of the plaintext of the data to obtain the target data ciphertext, so that the same set of addresses is used for encryption calculation or decryption calculation of the plaintext and the ciphertext, and the encryption and decryption calculations are based on the same address, making the decryption process corresponding to encryption reversible, which is beneficial to reducing the occupation of computing resources of the embedded device.
[0010] In addition, before obtaining the plaintext of the data to be encrypted, it includes: obtaining a preset unit length, grouping the plaintext of the data according to the preset unit length to obtain grouped plaintexts, and each group of the grouped plaintexts occupies a grouped address; the step of obtaining the key for encrypting the plaintext of the data through the address of the plaintext of the data includes: calculating to obtain the key for encrypting the grouped plaintext according to the grouped address of the grouped plaintext, and calculating a calculation result according to the grouped plaintext and the key corresponding to the grouped plaintext, and the calculation result is the grouped ciphertext; the step of storing the calculation result at the address of the plaintext of the data includes: storing the grouped ciphertext at the grouped address of the grouped plaintext. In the embodiment of the present invention, the data to be encrypted is grouped by a preset unit length. Since the preset unit length can be flexibly adjusted, and the address based on which the encryption is performed is the address obtained after grouping according to the preset unit length, therefore, during the encryption process, grouping the plaintext of the data to be encrypted according to the preset unit length can also be used as a factor for one layer of encryption. The same plaintext of the data can be divided into different groups by different preset unit lengths and have different addresses, thereby improving the security of the encryption algorithm. In addition, the preset unit length can be flexibly adjusted according to the computing power of the actual embedded device. When the preset unit length is larger, the number of groups will be fewer, so the grouped data that needs to be encrypted will be reduced, simplifying the complexity of the calculation and improving the efficiency of the encryption operation.
[0011] In addition, the key includes an address key and a content key. The maximum value of the number of the address keys is the address key length value, and the maximum value of the number of the content keys is the content key length value; the step of calculating to obtain the key for encrypting the grouped plaintext according to the grouped address of the grouped plaintext includes: extracting the grouped address corresponding to the grouped plaintext, and calculating the target address key of the grouped plaintext according to the grouped address and the address key length value; calculating the target content key according to the grouped address and the target address key; the step of performing encryption calculation according to the plaintext of the data and the key includes: adding the grouped plaintext and the target content key to calculate the grouped ciphertext. In the embodiment of the present invention, the key is encrypted in two layers. The key is divided into an address key and a content key. The first layer of the address key is determined based on the grouped address and the address key length value, and the second layer of the content key for encrypting the data is further calculated based on the address of the first layer of the address key and the grouped plaintext, and encryption is performed according to the content key, so that the encryption process can only be performed after obtaining the key in two layers based on the address, thereby improving the security of the encryption of the data.
[0012] In addition, there is a preset first mapping relationship between the address key and the address key serial number; there is a preset second mapping relationship between the content key and the content key serial number; the obtaining of the target address key of the grouped plaintext according to the grouped address and the address key length value includes: performing a remainder operation on the grouped address according to the address key length value to obtain a target address key serial number; obtaining a target address key corresponding to the address key serial number according to the first mapping relationship and the target address key serial number; the obtaining of the target content key according to the grouped address and the target address key includes: performing a remainder operation on the grouped address according to the target address key to obtain the target content key serial number; obtaining a target content key corresponding to the target content key serial number according to the second mapping relationship and the target content key serial number. In the embodiment of the present invention, since the content key for encrypting data is obtained through two remainder operations based on the address, and finally the content key is added to the grouped plaintext to be encrypted, the entire encryption process can achieve data encryption only through two remainder operations and one addition operation, which is applicable to embedded devices with limited computing resources, greatly simplifies the encryption calculation work, is beneficial to reducing the resources occupied by the calculation during the calculation process, and improves the calculation efficiency.
[0013] In addition, the maximum value of the address key serial number is the same as the address key length value, and the maximum value of the content key serial number is the same as the content key length value; the address key length value is not greater than the content key length value. In the embodiment of the present invention, the address key length value is not greater than the content key length value, so that during the remainder operation of the content key, it is ensured that the content key can be obtained inevitably only through one remainder operation, thus simplifying the calculation process.
[0014] In addition, before obtaining the data ciphertext of the data to be encrypted, it includes: obtaining a preset unit length, grouping the data ciphertext according to the preset unit length to obtain grouped ciphertexts, and each grouped ciphertext occupies a grouped address; the obtaining of the key for decrypting the data ciphertext through the address of the data ciphertext includes: calculating a key for decrypting the grouped ciphertext according to the grouped address of the grouped ciphertext, and calculating a calculation result according to the grouped ciphertext and the key corresponding to the grouped ciphertext, and the calculation result is the grouped plaintext; the storing of the calculation result to the address of the data ciphertext includes: storing the grouped plaintext to the grouped address of the grouped ciphertext. Description of the Drawings
[0015] One or more embodiments are exemplarily illustrated by the pictures in the corresponding drawings. These exemplary illustrations do not constitute a limitation on the embodiments. Elements with the same reference numerals in the drawings are represented as similar elements, unless otherwise stated. The drawings in the figures do not constitute a scale limitation.
[0016] Figure 1 is the flowchart of a data encryption method based on address provided by an embodiment of the present application Figure 1 ;
[0017] Figure 2 is the schematic diagram of a preset unit length of a data encryption method based on address provided by an embodiment of the present application;
[0018] Figure 3 is the schematic diagram of grouped addresses of a data encryption method based on address provided by an embodiment of the present application;
[0019] Figure 4 is the flowchart of a data encryption method based on address provided by an embodiment of the present application Figure 2 ;
[0020] Figure 5 is the flowchart of a data encryption method based on address provided by an embodiment of the present application Figure 3 ;
[0021] Figure 6 is the flowchart of a data decryption method based on address provided by an embodiment of the present application;
[0022] Figure 7 is the schematic diagram of the internal structure of an electronic device provided by an embodiment of the present application. Detailed implementation manners
[0023] The microcontroller unit (MCU) of an embedded device usually has relatively poor performance, few resources, and high real-time requirements. Therefore, an encryption algorithm with high efficiency, few resource occupations, and certain security is required to protect the data stored in the external Flash memory of the embedded device.
[0024] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the embodiments of the present invention will be described in detail below with reference to the drawings. However, those of ordinary skill in the art can understand that in the embodiments of the present invention, many technical details are provided for readers to better understand the present application. However, even without these technical details and various changes and modifications based on the following embodiments, the technical solutions required to be protected by the present application can still be implemented. The following division of each embodiment is for convenience of description and should not constitute any limitation on the specific implementation manner of the present invention. Each embodiment can be combined and cross-referenced with each other on the premise of no contradiction.
[0025] One embodiment of the present invention relates to a data encryption method based on an address, which can be applied to an embedded device or an Internet of Things terminal. The data encryption method based on an address includes: obtaining the data plaintext of the data to be encrypted; obtaining a key for encrypting the data plaintext through the address of the data plaintext, and performing an encryption calculation according to the data plaintext and the key; storing the calculation result at the address of the data plaintext to obtain the target data ciphertext. In the embodiment of the present invention, the data plaintext of the data to be encrypted is obtained; a key for encrypting the data plaintext is obtained through the address of the data plaintext, and an encryption calculation is performed according to the data plaintext and the key; since the key for encryption is obtained based on the address of the plaintext to be encrypted or the address of the ciphertext to be decrypted, in the process of encryption or decryption, the address is used as a part of the key for calculation, and in the subsequent calculation process, the occupation of key resources is reduced, and the efficiency of encryption and decryption calculations is improved; moreover, the calculation result is stored at the address of the data plaintext to obtain the target data ciphertext, so that the same set of addresses is used for encryption calculation or decryption calculation of the plaintext and the ciphertext, and the encryption and decryption calculations are based on the same address, making the decryption process corresponding to the encryption reversible, which is beneficial to reducing the occupation of the computing resources of the embedded device. The implementation details of the data encryption method based on an address in the embodiment of the present invention will be specifically described below. The following content is only the implementation details provided for convenient understanding and is not necessary for implementing this solution.
[0026] As Figure 1 shown, in step 101, the data plaintext of the data to be encrypted is obtained.
[0027] In one embodiment, before obtaining the data plaintext of the data to be encrypted, it includes: obtaining a preset unit length, and grouping the data plaintext according to the preset unit length to obtain grouped plaintexts, and each group of the grouped plaintexts occupies a group address.
[0028] Among them, the preset unit length, that is, the alignment length of each group of data in the grouping process, the unit of the alignment length can be byte (Byte) or bit (Bit). For example, in the process of encrypting the data plaintext, the data is aligned in groups of 4 bytes, or the data is aligned in groups of 32 bits. Since the length of 1 byte is 8 bits, that is, when the preset unit length is 1 byte, the preset unit length is also 8 bits. When the user needs to encrypt 256-byte data plaintext, the value of the preset unit length can be defined as any value that can be divided evenly by 2048, such as 2 bits, 4 bits, 24 bits. By setting the preset unit length, the encryption algorithm in the embodiment of the present application has adaptability to data to be encrypted of any length, and the generalization ability of the encryption method is improved.
[0029] It should be noted that the preset unit length is also the calculation process during each encryption process. When processing data of a preset unit length, that is, the data plaintext is grouped by the preset unit length. Each time an encryption calculation is performed, a group of data is encrypted. Therefore, for the same data plaintext to be encrypted, when the set preset unit length value is larger, the number of groups obtained by grouping is smaller, the number of encryption calculations is also smaller, and the calculation efficiency is higher. For example, Figure 2 as shown, when the same data plaintext is encrypted, processing according to the first preset unit length will result in more groups and more calculation times than processing according to the second preset unit length. Therefore, the processing efficiency of the second preset unit length is higher.
[0030] Moreover, since for the same data plaintext to be encrypted, when the set preset unit length is different, the number of groups obtained by grouping is also different, and the grouping addresses corresponding to each group are also different. Therefore, the encryption results obtained are also different. For example, Figure 3 as shown, the data plaintext is 96 bits. According to Figure 3 the order from top to bottom are the first group of grouping, the second group of grouping, and the third group of grouping respectively; in the first group of grouping, the preset unit length is 8 bits, then the data plaintext is divided into 12 groups, and each group of grouped plaintext corresponds to the grouping addresses 0 to 11 in sequence; for the same group of data plaintext, in the second group of grouping, the preset unit length is 16 bits, then the data plaintext is divided into 6 groups, and each group of grouped plaintext corresponds to the grouping addresses 0 to 5 in sequence; similarly, in the third group of grouping, the preset unit length is 32 bits, then the data plaintext is divided into 3 groups, and each group of grouped plaintext corresponds to the grouping addresses 0 to 2 in sequence. Therefore, the embodiments of the present application can use the preset unit length as an intervention factor for one - layer encryption to improve the security of the encryption algorithm. It should be noted that the grouping address can be set according to user preset. The grouping address does not have to start from 0. At the same time, different data plaintexts also support using the same address, as long as it is ensured that the same address is used during the encryption and decryption processes of the data plaintext. The above description is only for illustrative purposes, and the present application does not limit the specific address of the grouping address here.
[0031] The data to be encrypted is grouped by a preset unit length. Since the preset unit length can be flexibly adjusted and the address for encryption is obtained based on the groups formed by the preset unit length, during the encryption process, grouping the plaintext of the data to be encrypted according to the preset unit length can also be regarded as a factor for encryption. The same plaintext data can be divided into different groups by different preset unit lengths and have different addresses, thus enhancing the security of the encryption algorithm. Additionally, the preset unit length can be flexibly adjusted according to the computing power of the actual embedded device. When the preset unit length is larger, the number of groups will be fewer, so the grouped data that needs to be encrypted will decrease, simplifying the computational complexity and improving the efficiency of the encryption operation.
[0032] In step 102, a key for encrypting the data plaintext is obtained through the address of the data plaintext, and encryption calculation is performed based on the data plaintext and the key.
[0033] In one embodiment, obtaining the key for encrypting the data plaintext through the address of the data plaintext includes: calculating a key for encrypting the grouped plaintext based on the grouped address of the grouped plaintext, and obtaining a calculation result through calculation based on the grouped plaintext and the key corresponding to the grouped plaintext, where the calculation result is the grouped ciphertext. In the embodiments of the present invention, the key is encrypted in two layers. The key is divided into an address key and a content key. The first-layer address key is determined based on the grouped address and the address key length value, and the second-layer content key for encrypting with the data is further calculated based on the first-layer address key and the address of the grouped plaintext, and encryption is performed according to the content key, such that the encryption process can only be carried out after obtaining two layers of keys based on the address, thereby enhancing the security of data encryption.
[0034] In one embodiment, the key includes an address key and a content key. The maximum value of the number of address keys is the address key length value, and the maximum value of the number of content keys is the content key length value. Specifically, the address key performs a modulo operation on the address corresponding to the grouped plaintext and the address key to confuse the mapping relationship between the address and the content, improving the security of data encryption. The length value of the address key, that is, the maximum number of address keys, can be any value, and the encryption security can be improved by increasing the length value of the address key; the content key is the key data found based on the address, and the original data is replaced after performing addition or subtraction calculations on the plaintext or ciphertext in a reversible manner. The data unit length of the content key is the same as the preset unit length to avoid the grouped plaintext or grouped ciphertext being unable to be added or subtracted with the content key. The length value of the content key, that is, the maximum number of content keys, can be any value, and the encryption security can be improved by increasing the length value of the content key. It should be noted that the address key length value is not greater than the content key length value. That is, the maximum number of address keys is less than the maximum number of content keys, so as to ensure that the content key can be obtained inevitably through only one modulo calculation during the modulo calculation of the content key, avoiding redundant modulo calculation processes and simplifying the complexity of the calculation process.
[0035] In one embodiment, calculating the key for encrypting the grouped plaintext according to the grouped address of the grouped plaintext includes: extracting the grouped address corresponding to the grouped plaintext, and calculating the target address key of the grouped plaintext according to the grouped address and the address key length value; calculating the target content key according to the grouped address and the target address key; the encrypting calculation according to the data plaintext and the key includes: adding the grouped plaintext and the target content key to calculate the grouped ciphertext.
[0036] In one embodiment, there is a preset first mapping relationship between the address key and the address key serial number; there is a preset second mapping relationship between the content key and the content key serial number. The maximum value of the address key serial number is the same as the address key length value, and the maximum value of the content key serial number is the same as the content key length value.
[0037] In one embodiment, calculating the target address key of the packet plaintext according to the packet address and the address key length value includes: performing a modulo operation on the packet address according to the address key length value to obtain a target address key serial number; obtaining the target address key corresponding to the address key serial number according to the first mapping relationship; calculating the target content key according to the packet address and the target address key includes: performing a modulo operation on the packet address according to the target address key to obtain the target content key serial number; obtaining the target content key corresponding to the target content key serial number according to the second mapping relationship. In the embodiment of the present invention, since the content key for encrypting data is obtained through two modulo operations based on the address, and finally the content key is added to the packet plaintext to be encrypted, the entire encryption process only requires two modulo operations and one addition operation to achieve data encryption, which is suitable for embedded devices with limited computing resources, greatly simplifies the encryption calculation work, is beneficial to reducing the resources occupied by the calculation during the calculation process, and improves the calculation efficiency.
[0038] In step 103, store the calculation result at the address of the data plaintext to obtain the target data ciphertext.
[0039] In one embodiment, storing the calculation result at the address of the data plaintext includes: storing the packet ciphertext at the packet address of the packet plaintext.
[0040] In a specific embodiment, the address key length value is n, and the content key length value is m; in the first modulo operation for encryption processing, the target address key serial number k is calculated through the packet address addr, and the calculation method is as follows:
[0041] k = addr % n
[0042] Where, % is the modulo operator.
[0043] Further, obtain the target address key key1[k] (k ≤ m) according to the target address key serial number k and the first mapping relationship, and further calculate the target content key data serial number q, and the calculation method is as follows:
[0044] q = addr % key1[k]
[0045] Finally, obtain the target content key key2[q] according to the target content key serial number q and the second mapping relationship, and further perform an addition operation with the packet plaintext data to obtain the target packet ciphertext data`:
[0046] data` = data + key2[q]
[0047] In addition, during the decryption process, after calculating the target address key sequence number k, the target address key key1[k], the target content key data sequence number q, and the target content key key2[q] in the same way, a subtraction calculation is further performed with the block ciphertext data` to obtain the target block plaintext data:
[0048] data = data` - key2[q]
[0049] In a specific embodiment, such as Figure 4 and Figure 5 shown, in step S1, relevant parameters of the encryption and decryption algorithm are initialized. The relevant parameters of the encryption and decryption algorithm include: a preset unit length, an address key length value, address key data, a first mapping relationship, a content key length value, content key data, and a second mapping relationship.
[0050] For example, the preset unit length is defined as 1 byte.
[0051] The length value of the address key key1 is defined as 8 bytes, and the specific address key data (sequence numbers 0 to 7) are successively: 0x02 0x03 0x07 0x0A 0x0C 0x02 0x04 0x09.
[0052] The length value of the content key key2 is defined as 16 bytes, and the specific content key data (sequence numbers 0 to 15) are successively: 0x01 0x02 0x03 0x04 0x05 0x06 0x07 0x08 0x11 0x12 0x13 0x14 0x15 0x16 0x17 0x18.
[0053] In step S2, the data plaintext is obtained. For example, the data length of the target data plaintext is 2 bytes, and the data in the target data plaintext is 0x5F 0x2E; the starting address of the target plaintext is 0x10.
[0054] In step S3, the data plaintext is grouped according to the preset unit length. For example, the first block plaintext is 0x5F, and the first block address is 0x10; the second block plaintext is 0x2E, and the second block address is 0x11.
[0055] In step S4, encryption processing is sequentially performed on each block plaintext.
[0056] Such as Figure 5 shown, in sub-step S41 of step S4, the target address key sequence number k corresponding to the block plaintext is calculated according to the block address of the block plaintext and the address key length value. For example, for the first block plaintext, k = 0x10 % 8; k = 0.
[0057] In sub-step S42 of step S4, the corresponding target address key key1[k] is found according to the target address key sequence number k. For example, for the first group of plaintext, the target address sequence number key1[0] = 0x02.
[0058] In sub-step S43 of step S4, the target content key sequence number q corresponding to the group of plaintext is calculated according to the group address of the group of plaintext and the target address key. For example, for the first group of plaintext, q = 0x10 % 0x02; q = 0.
[0059] In sub-step S44 of step S4, the corresponding target address key key2[q] is found according to the target address key sequence number q. For example, for the first group of plaintext, the target address sequence number key2[0] = 0x01.
[0060] In sub-step S45 of step S4, the target address key is added to the group of plaintext to obtain the group ciphertext. For example, for the first group of plaintext, the first group ciphertext data`[0] = data[0] + key2[q], data`[0] = 0x60. That is, the data of the encrypted result of the first group of plaintext, the first group ciphertext, is 0x60.
[0061] After the encryption process of each group of plaintext is completed, if there is still unencrypted plaintext in the back, the sub-steps in step S4 above are repeated for the next group of plaintext until there is no unencrypted plaintext. That is, after the first group of plaintext is encrypted, there is still unencrypted second group of plaintext. The second group of plaintext is encrypted through sub-steps S41 to S45 in step S4 to obtain the second group ciphertext 0x31.
[0062] As Figure 4 shown, in step S5, the encrypted group ciphertexts are sequentially corresponding to the addresses of the group of plaintexts to obtain the target ciphertext data.
[0063] According to the above step process, the target ciphertext data obtained by encrypting the target data plaintext data 0x5F 0x2E is 0x60 0x31.
[0064] It should be noted that since the same address is used for the plaintext and ciphertext during the encryption process, when decrypting the data, the decryption can also be achieved through the process of steps S1 to S5 above, only by replacing the ciphertext with the plaintext for processing. However, in sub-step S45 of step S4, it needs to be changed to: subtracting the target address key from the group ciphertext to obtain the group plaintext.
[0065] In an embodiment of the present invention, the plaintext of the data to be encrypted is obtained; a key for encrypting the plaintext of the data is obtained through the address of the plaintext of the data, and encryption calculation is performed according to the plaintext of the data and the key; since the key for encryption is obtained based on the address of the plaintext to be encrypted or the address of the ciphertext to be decrypted, in the process of encryption or decryption, the address is used as part of the key for calculation, and in subsequent calculation processes, the occupation of key resources is reduced, and the efficiency of encryption and decryption calculation is improved; moreover, the calculation result is stored at the address of the plaintext of the data to obtain the target data ciphertext, so that the same set of addresses is used for encryption calculation or decryption calculation of the plaintext and the ciphertext, and the encryption and decryption calculations are based on the same address, making the decryption process corresponding to encryption reversible, which is beneficial to reducing the occupation of computing resources of the embedded device.
[0066] The step division of the above method is only for clear description. When implemented, it can be combined into one step or some steps can be split into multiple steps. As long as the same logical relationship is included, it is within the protection scope of this patent; adding insignificant modifications to the algorithm or process or introducing insignificant designs, but without changing the core design of its algorithm and process, are within the protection scope of this patent.
[0067] In addition, the examples mentioned in the above embodiments can be freely combined, and any combination method can be understood as an embodiment. The "embodiment" or "example" mentioned at various positions in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art can understand that the embodiments described herein can be combined with other embodiments.
[0068] In summary, specific embodiments of the present subject matter have been described. Other embodiments are within the scope of the appended claims. In some cases, the actions recited in the claims can be performed in a different order and still achieve the desired result. Additionally, the processes depicted in the figures do not necessarily require the particular order or sequential order shown to achieve the desired result.
[0069] Another embodiment of the present invention relates to a data decryption method based on an address, which can be applied to an embedded device or an Internet of Things terminal. The data encryption method based on an address includes: obtaining a data ciphertext of data to be decrypted; obtaining a key for decrypting the data ciphertext through the address of the data ciphertext, and performing a decryption calculation according to the data ciphertext and the key; storing the calculation result to the address of the data ciphertext to obtain a target data plaintext. In the embodiment of the present invention, obtaining a data ciphertext of data to be decrypted; obtaining a key for decrypting the data plaintext through the address of the data ciphertext, and performing a decryption calculation according to the data ciphertext and the key; since the key for decryption is obtained based on the address of the ciphertext to be decrypted or the address of the plaintext to be encrypted, in the process of encryption or decryption, the address is used as part of the key for calculation, and in the subsequent calculation process, the occupation of key resources is reduced, and the efficiency of encryption and decryption calculations is improved; and, storing the calculation result to the address of the data ciphertext to obtain a target data plaintext, so that the same set of addresses is used for encryption calculation or decryption calculation of the plaintext and the ciphertext, and the encryption and decryption calculations are based on the same address, making the decryption process corresponding to encryption reversible, which is beneficial to reducing the occupation of computing resources of the embedded device. The implementation details of the data encryption method based on an address in the embodiments of the present invention will be specifically described below. The following content is only implementation details provided for convenience of understanding and is not necessary for implementing this solution.
[0070] As Figure 6 shown, in step 601, obtain the data ciphertext of the data to be decrypted.
[0071] In step 602, obtain the key for decrypting the data ciphertext through the address of the data ciphertext, and perform a decryption calculation according to the data ciphertext and the key.
[0072] In step 603, store the calculation result to the address of the data ciphertext to obtain the target data plaintext.
[0073] In one embodiment, obtain a preset unit length, group the data ciphertext according to the preset unit length to obtain grouped ciphertexts, and each grouped ciphertext occupies a grouped address; the obtaining the key for decrypting the data ciphertext through the address of the data ciphertext includes: calculating to obtain the key for decrypting the grouped ciphertext according to the grouped address of the grouped ciphertext, and performing a calculation according to the grouped ciphertext and the key corresponding to the grouped ciphertext to obtain a calculation result, where the calculation result is grouped plaintext; the storing the calculation result to the address of the data ciphertext includes: storing the grouped plaintext to the grouped address of the grouped ciphertext.
[0074] In an embodiment of the present invention, a data ciphertext of data to be decrypted is obtained; a key for decrypting the data plaintext is obtained through the address of the data ciphertext, and a decryption calculation is performed according to the data ciphertext and the key; since the key for decryption is obtained based on the address of the ciphertext to be decrypted or the address of the plaintext to be encrypted, in the process of encryption or decryption, the address is used as part of the key for calculation. In subsequent calculation processes, the occupation of key resources is reduced, and the efficiency of encryption and decryption calculations is improved; moreover, the calculation result is stored at the address of the data ciphertext to obtain the target data plaintext, so that the same set of addresses is used for encryption calculation or decryption calculation of the plaintext and the ciphertext. The encryption and decryption calculations are based on the same address, making the decryption process corresponding to encryption reversible, which is beneficial to reducing the occupation of computing resources of the embedded device.
[0075] The step division of the above method is only for clear description. When implemented, it can be combined into one step or some steps can be split into multiple steps. As long as the same logical relationship is included, it is within the protection scope of this patent; adding insignificant modifications or introducing insignificant designs to the algorithm or process, but without changing the core design of its algorithm and process, are all within the protection scope of this patent.
[0076] In addition, the examples mentioned in the above embodiments can be freely combined, and any combination method can be understood as an embodiment. The "embodiment" or "example" that appears at various positions in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art can understand that the embodiments described herein can be combined with other embodiments.
[0077] In summary, specific embodiments of the present subject matter have been described. Other embodiments are within the scope of the appended claims. In some cases, the actions recited in the claims can be performed in a different order and still achieve the desired result. Additionally, the processes depicted in the figures do not necessarily require the particular order or sequential order shown to achieve the desired result.
[0078] Another embodiment of the present invention relates to an electronic device, such as Figure 7 shown, including at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the above-mentioned address-based data encryption method and the above-mentioned address-based data decryption method.
[0079] Among them, the memory and the processor are connected in a bus manner. The bus may include any number of interconnected buses and bridges, and the bus connects various circuits of one or more processors and the memory together. The bus can also connect various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art, and thus will not be further described herein. The bus interface provides an interface between the bus and the transceiver. The transceiver can be a component or multiple components, such as multiple receivers and transmitters, and provides a unit for communicating with various other devices on the transmission medium. The data processed by the processor is transmitted on the wireless medium through the antenna. Further, the antenna also receives data and transmits the data to the processor.
[0080] The processor is responsible for managing the bus and general processing, and can also provide various functions, including timing, peripheral interface, voltage regulation, power management, and other control functions. The memory can be used to store the data used by the processor when executing operations.
[0081] Embodiments of the present invention also provide a computer-readable storage medium storing a computer program, including: when the computer program is executed by a processor, it implements the above-mentioned data encryption method based on an address and the above-mentioned data decryption method based on an address.
[0082] That is, those skilled in the art can understand that all or part of the steps in implementing the methods of the above embodiments can be completed by instructing relevant hardware through a program. This program is stored in a storage medium and includes several instructions to enable a device (which can be a single-chip microcomputer, a chip, etc.) or a processor to execute all or part of the steps of the methods described in various embodiments of the present application. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.
[0083] Embodiments of the present invention also provide a computer program product including computer instructions, which implement the above-mentioned data encryption method based on an address and the above-mentioned data decryption method based on an address when executed by a processor.
[0084] Those of ordinary skill in the art can understand that the above embodiments are specific embodiments for implementing the present invention, and in practical applications, various changes can be made in form and details without departing from the spirit and scope of the present invention.
Claims
1. A data encryption method based on address, characterized in that: include: Obtain the data plaintext of the data to be encrypted; Obtaining a key for encrypting the data plaintext through the address of the data plaintext, and performing encryption calculation according to the data plaintext and the key; The calculation result is stored in the address of the data plaintext to obtain the target data ciphertext.
2. The address-based data encryption method according to claim 1, characterized in that: Before obtaining the data plaintext of the data to be encrypted, it includes: obtaining a preset unit length, grouping the data plaintext according to the preset unit length to obtain grouped plaintexts, each group of the grouped plaintexts occupying one group address; The obtaining of the key for encrypting the data plaintext by the address of the data plaintext comprises: performing calculation according to the group address of the group plaintext to obtain the key for encrypting the group plaintext, performing calculation according to the group plaintext and the key corresponding to the group plaintext to obtain a calculation result, wherein the calculation result is the group ciphertext; The storing the calculation result to the address of the data plaintext includes: storing the group ciphertext to the group address of the group plaintext.
3. The address-based data encryption method according to claim 2, characterized in that: The keys include address keys and content keys, the maximum value of the number of address keys is the address key length value, and the maximum value of the number of content keys is the content key length value; The step of calculating according to the group address of the group plaintext to obtain a key for encrypting the group plaintext includes: Extracting the packet address corresponding to the packet plaintext, and calculating the target address key of the packet plaintext according to the packet address and the address key length value; Calculate a target content key according to the packet address and the target address key; The performing encryption calculation according to the data plaintext and the key includes: adding the group plaintext and the target content key to calculate the group ciphertext.
4. The address-based data encryption method according to claim 3, characterized in that: There is a preset first mapping relationship between the address key and the address key serial number; there is a preset second mapping relationship between the content key and the content key serial number; The step of calculating the target address key of the packet plaintext according to the packet address and the address key length value includes: Perform modulo calculation on the packet address according to the address key length value to obtain a target address key sequence number; According to the first mapping relationship and the target address key serial number, obtaining the target address key corresponding to the address key serial number; The step of calculating the target content key according to the group address and the target address key comprises: Performing modulo calculation on the group address according to the target address key to obtain the target content key sequence number; According to the second mapping relationship and the target content key serial number, a target content key corresponding to the target content key serial number is acquired.
5. The address-based data encryption method according to claim 4, characterized in that: The maximum value of the address key serial number is the same as the address key length value, and the maximum value of the content key serial number is the same as the content key length value; the address key length value is not greater than the content key length value.
6. A method for decrypting data based on an address, characterized in that: include: Obtain the data ciphertext of the data to be decrypted; Obtaining a key for decrypting the data ciphertext through the address of the data ciphertext, and performing a decryption calculation based on the data ciphertext and the key; The calculation result is stored in the address of the data ciphertext to obtain the target data plaintext.
7. The address-based data decryption method according to claim 6, characterized in that: Before obtaining the data ciphertext of the data to be encrypted, the following steps are included: Obtaining a preset unit length, and grouping the data ciphertext according to the preset unit length to obtain grouped ciphertexts, wherein each group of the grouped ciphertexts occupies one group address; The step of obtaining a key for decrypting the data ciphertext through the address of the data ciphertext comprises: Calculating according to the group address of the group ciphertext to obtain a key for decrypting the group ciphertext, and calculating according to the group ciphertext and the key corresponding to the group ciphertext to obtain a calculation result, wherein the calculation result is the group plaintext; The storing the calculation result to the address of the data ciphertext includes: storing the grouped plaintext to the grouped address of the grouped ciphertext.
8. An electronic device, characterized in that: include: at least one processor; as well as, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the address-based data encryption method as described in any one of claims 1 to 5, and to execute the address-based data decryption method as described in any one of claims 6 to 7.
9. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the address-based data encryption method according to any one of claims 1 to 5 is implemented, and the address-based data decryption method according to any one of claims 6 to 7 can be executed.
10. A computer program product, characterized in that The invention comprises computer instructions, which, when executed by a processor, implement the address-based data encryption method according to any one of claims 1 to 5, and can execute the address-based data decryption method according to any one of claims 6 to 7.