Flow encryption method and device based on packet hash chain, electronic equipment and storage medium

By introducing a stream encryption method based on packet hash chain in the counter mode encryption algorithm, the problem of inefficiency in traditional encryption methods when processing high-speed and large-scale data is solved, and more efficient and secure encryption processing is achieved.

CN120074804APending Publication Date: 2025-05-30STATE GRID HUNAN ELECTRIC POWER COMPANY LIMITED +2
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510132256.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-06
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

When traditional counter mode encryption algorithms process high-speed and large-scale data, the computing resource overhead is high and the processing delay is high, and cannot meet the needs of massive terminal secure communications.

Method used

The stream encryption method based on the packet hash chain is adopted to generate the initial Hash chain of a preset length through the Hash function, a chain secret information sequence is generated, and a chain key sequence is pre-generated through the encryption algorithm, and the encryption is carried out in combination with the pipeline processing method of concurrent execution.

Benefits of technology

Reduces processing delay and computing resource overhead of the encryption process, improves the efficiency and response speed of encryption operations, and ensures overall performance and security when processing high-speed and large-scale data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074804A_ABST
    Figure CN120074804A_ABST
Patent Text Reader

Abstract

The invention discloses a stream encryption method and device based on a packet Hash chain, electronic equipment and a storage medium, and the method comprises the steps: generating an initial Hash chain with a preset length through a Hash function, the initial Hash chain comprising a chain type secret information sequence; pre-generating a chain secret key sequence for each piece of chain secret information in the chain secret information sequence through an encryption algorithm; and when a data message needing to be encrypted arrives, segmenting the data message needing to be encrypted into data packets by adopting a concurrent execution pipeline processing mode, and then performing XOR operation on each data packet and a corresponding key in a pre-generated chained key sequence in parallel to generate a ciphertext. According to the method and the device, the parallelism and the efficiency of data processing are improved, the security communication requirements of massive terminals are met, the overall performance and the response speed during high-speed and large-scale data processing are ensured, and the overall efficiency and the security during high-speed and large-scale data encryption processing are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical fields of data encryption, data security, etc. In particular, it relates to a stream encryption method, device, equipment and storage medium based on a grouped hash chain. Background Art

[0002] With the rapid development of information technology, especially in the fields of distributed systems, cloud computing, Internet of Things and big data, the secure transmission and processing of data have become crucial. In these systems, data often needs to be securely transmitted between multiple nodes, which requires not only secure data transmission but also higher efficiency. However, in the traditional data encryption and decryption transmission process, there are problems such as large computational resource overhead and high processing delay, which cannot meet the secure communication requirements of a large number of terminals.

[0003] The counter mode (CTR) is a popular operating mode of symmetric encryption algorithms and is widely used in various secure communication systems. The core of this mode is to combine an incrementing counter with an encryption key to generate a unique encryption key for each data block, thus allowing independent encryption and decryption of data blocks. In theory, this design supports parallel processing of encrypted data blocks and can improve the efficiency of encryption operations. However, the CTR mode has obvious limitations when processing high-speed and large-scale data. For example, in a system that needs to process a large amount of data, the overhead and complexity of counter updates increase exponentially, which directly affects the overall performance and response speed of the system. In addition, each data block in the CTR mode requires an independent counter value, which increases the complexity of key generation and distribution, thus reducing the efficiency of the overall system. Summary of the Invention

[0004] One aspect of the present application provides a stream encryption method based on a grouped hash chain to solve the technical problem that the existing counter mode encryption algorithm has low overall efficiency due to low overall performance and slow response speed when processing high-speed and large-scale data.

[0005] The present application is implemented through the following solutions:

[0006] A stream encryption method based on a grouped hash chain, comprising the steps of:

[0007] Generating an initial hash chain of a preset length through a Hash function, the initial hash chain containing a chained secret information sequence;

[0008] Pre-generating a chained key sequence for each chained secret information in the chained secret information sequence through an encryption algorithm;

[0009] When the data packet to be encrypted arrives, a pipelining processing method with concurrent execution is adopted to split the data packet to be encrypted into data groups, and then each data group is XORed with the corresponding key in the pre-generated chained key sequence in parallel to generate ciphertext.

[0010] Further, generating an initial Hash chain with a preset length through a Hash function, where the initial Hash chain includes a chained secret information sequence, specifically includes the steps of:

[0011] The data owner generates an initial random value as a seed;

[0012] According to the initial random value and the requirements of the network, an initial Hash chain with a preset length is generated through a Hash function. The initial Hash chain includes a chained secret information sequence composed of the initial random value and hash values.

[0013] Further, before XORing each data group with the corresponding key in the pre-generated chained key sequence in parallel to generate ciphertext, it further includes the steps of:

[0014] When the data packet to be encrypted arrives, if the number of data groups in the data packet is greater than the number of keys in the chained key sequence, the initial Hash chain is dynamically extended according to the difference between the two and the Hash function. After pre-generating new chained keys for each newly added chained secret information in the extended chained secret information sequence through an encryption algorithm, they are combined with the chained key sequence obtained before dynamic extension to form the final chained key sequence.

[0015] Further, pre-generating a chained key sequence for each chained secret information in the chained secret information sequence through an encryption algorithm specifically includes the steps of:

[0016] Pre-generating the first key in the chained key sequence for the initial random value in the initial Hash chain through an encryption algorithm;

[0017] Sequentially pre-generating other keys in the chained key sequence for the chained secret information sequence in the initial Hash chain through the same encryption algorithm.

[0018] Further, pre-generating a chained key sequence for each chained secret information in the chained secret information sequence through an encryption algorithm specifically includes the steps of:

[0019] Sequentially pre-generating a chained key sequence for the chained secret information sequence in the initial Hash chain through an encryption algorithm.

[0020] Further, when pre - generating a chained key sequence for each chained secret information in the chained secret information sequence through an encryption algorithm, after each key in the chained key sequence is pre - generated, a security verification is performed, and the security verification includes checking the randomness of the key.

[0021] Further, the encryption algorithm is a block encryption algorithm.

[0022] On the other hand, this application also provides a stream encryption device based on a block hash chain, including:

[0023] An initial Hash chain generation module, configured to generate an initial Hash chain of a preset length through a Hash function, where the initial Hash chain contains a chained secret information sequence;

[0024] A chained key sequence generation module, configured to pre - generate a chained key sequence for each chained secret information in the chained secret information sequence through an encryption algorithm;

[0025] A parallel encryption module, configured to, when a data packet to be encrypted arrives, adopt a pipelined processing method with concurrent execution, split the data packet to be encrypted into data groups, and then perform an exclusive - OR operation on each data group in parallel with the corresponding key in the pre - generated chained key sequence to generate ciphertext.

[0026] Further, the initial Hash chain generation module specifically includes:

[0027] A seed generation module, configured to generate an initial random value as a seed by the data owner;

[0028] An initial Hash chain generation module, configured to generate an initial Hash chain of a preset length through a Hash function according to the initial random value and the requirements of the network, where the initial Hash chain includes a chained secret information sequence composed of the initial random value and hash values.

[0029] Further, before the parallel encryption module performs an exclusive - OR operation on each data group in parallel with the corresponding key in the pre - generated chained key sequence to generate ciphertext, it is also configured to:

[0030] When a data packet to be encrypted arrives, if the number of data groups of the data packet is greater than the number of keys contained in the chained key sequence, dynamically expand the initial Hash chain according to the difference between the two and the Hash function, pre - generate a new chained key for each newly added chained secret information in the expanded chained secret information sequence through an encryption algorithm, and combine the new chained key with the chained key sequence obtained before the dynamic expansion to form a final chained key sequence.

[0031] Further, the chained key sequence generation module specifically includes:

[0032] The first key pre-generation module is used to pre-generate the first key in the chained key sequence from the initial random value in the initial Hash chain through an encryption algorithm;

[0033] The other key pre-generation modules are used to sequentially pre-generate the other keys in the chained key sequence from the chained secret information sequence in the initial Hash chain through the same encryption algorithm.

[0034] Further, the chained key sequence generation module specifically includes:

[0035] The chained key sequence pre-generation module is used to sequentially pre-generate the chained key sequence from the chained secret information sequence in the initial Hash chain through an encryption algorithm.

[0036] Further, in the chained key sequence generation module, when pre-generating the keys in the chained key sequence from each chained secret information in the chained secret information sequence through an encryption algorithm, after each key in the chained key sequence is pre-generated, a security verification is performed, and the security verification includes checking the randomness of the key.

[0037] Further, in the chained key sequence generation module, the encryption algorithm is a block encryption algorithm.

[0038] On the other hand, the present application also provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the steps of the stream encryption method based on the block hash chain are implemented.

[0039] On the other hand, the present application also provides a storage medium. The storage medium includes a stored program. When the program runs, it controls the device where the storage medium is located to execute the steps of the stream encryption method based on the block hash chain.

[0040] Compared with the prior art, the present application has the following beneficial effects:

[0041] The present application provides a stream encryption method, apparatus, electronic device, and storage medium based on a grouped hash chain. Compared with the traditional counter mode, before the message to be encrypted arrives, the stream encryption method based on the grouped hash chain of the present application first generates a chained secret information sequence through a Hash function, solving the problems of large computational resource consumption, high processing delay, and security issues faced by traditional encryption methods such as the counter mode (CTR). And by encrypting each chained secret information in the chained secret information sequence based on an encryption algorithm, the pre-generation of keys is realized, reducing the processing delay of the encryption process and improving the response speed of the encryption process. At the same time, since the pre-generation of keys depends on the previous key or the initial random value, the privacy and security of the encryption process are ensured, effectively reducing the computational resource overhead in the data encryption and decryption transmission process; the present application uses a pipelined concurrent encryption method. After the data message to be encrypted is segmented into data packets, the reading, encryption processing, and ciphertext sending of the data message in plaintext form are realized in a pipelined scheduling manner, ensuring the uninterruptedness of the data message during the entire processing process, realizing the pipelined concurrent packet encryption of the message, making full use of the computational resources of the system hardware platform, improving the parallelism and efficiency of data processing, solving the problem of meeting the secure communication requirements of a large number of terminals, ensuring the overall performance and response speed when processing high-speed and large-scale data, improving the overall efficiency when encrypting and processing high-speed and large-scale data, and taking into account both efficiency and security.

[0042] In addition to the purposes, features, and advantages described above, the present application has other purposes, features, and advantages. The following will refer to the drawings for a further detailed description of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] The drawings constituting a part of the present application are used to provide a further understanding of the present application. The schematic embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation of the present application.

[0044] Figure 1 It is a schematic flowchart of the stream encryption method based on the grouped hash chain of the preferred embodiment of the present application.

[0045] Figure 2 It is a schematic flowchart of the sub-steps of step S1 in the preferred embodiment of the present application.

[0046] Figure 3 It is a flowchart of the generation of the Hash chain secret information sequence in the preferred embodiment of the present application.

[0047] Figure 4 It is a schematic flowchart of the sub-steps of step S2 in the preferred embodiment of the present application.

[0048] Figure 5 It is a schematic diagram of the generation process of the chained key sequence in the preferred embodiment of the present application.

[0049] Figure 6 It is a schematic diagram of the sub-step process of step S2 in another preferred embodiment of the present application.

[0050] Figure 7 It is a concurrent encryption timing diagram based on a pipeline in the preferred embodiment of the present application.

[0051] Figure 8 It is a schematic diagram of the module of a stream encryption device based on a grouped hash chain in the preferred embodiment of the present application.

[0052] Figure 9 It is a schematic block diagram of the entity of an electronic device in the preferred embodiment of the present application.

[0053] Figure 10 It is an internal structure diagram of a computer device in the preferred embodiment of the present application. Detailed implementation manners

[0054] The embodiments of the present application will be described in detail below with reference to the accompanying drawings. However, the present application can be implemented in many different ways defined and covered by the following.

[0055] As Figure 1 shown, the preferred embodiment of the present application provides a stream encryption method based on a grouped hash chain, including the steps of:

[0056] S1. Generate an initial Hash chain with a preset length through a Hash function, where the initial Hash chain contains a chained secret information sequence;

[0057] S2. Pre-generate a chained key sequence for each chained secret information in the chained secret information sequence through an encryption algorithm;

[0058] S3. When a data packet to be encrypted arrives, adopt a concurrent pipeline processing method to split the data packet to be encrypted into data groups, and then perform an exclusive OR operation on each data group in parallel with the corresponding key in the pre-generated chained key sequence to generate ciphertext.

[0059] This embodiment provides a stream encryption method based on a grouped hash chain. Compared with the traditional counter mode, before the message to be encrypted arrives, the stream encryption method based on a grouped hash chain in this embodiment first generates a chained secret information sequence through a Hash function, solving the problems of large computational resource consumption, high processing delay, and existing security issues faced by traditional encryption methods such as the counter mode (CTR). Encrypting each chained secret information in the chained secret information sequence based on an encryption algorithm to pre-generate keys reduces the processing delay of the encryption process and improves the response speed of the encryption process. At the same time, since the pre-generation of keys depends on the previous key or the initial random value, the privacy and security of the encryption process are ensured, effectively reducing the computational resource overhead during the data encryption and decryption transmission process. In this embodiment, through a pipelined concurrent encryption method, after the data message to be encrypted is segmented into data packets, the reading, encryption processing, and ciphertext sending of the data message in plaintext form are realized in a pipelined scheduling manner, ensuring the uninterruptedness of the data message during the entire processing process, realizing pipelined concurrent packet encryption of the message, making full use of the computational resources of the system hardware platform, improving the parallelism and efficiency of data processing, solving the problem of meeting the secure communication requirements of a large number of terminals, ensuring the overall performance and response speed when processing high-speed and large-scale data, improving the overall efficiency when encrypting and processing high-speed and large-scale data, and taking into account both efficiency and security.

[0060] As Figure 2 shown, in the preferred embodiment of the present application, step S1 specifically includes the steps:

[0061] S11. The data owner generates an initial random value as a seed;

[0062] S12. According to the initial random value and the requirements of the network, a preset-length initial Hash chain is generated through a Hash function. The initial Hash chain includes a chained secret information sequence composed of the initial random value and hash values.

[0063] As Figure 3 shown, when generating the initial Hash chain through a Hash function in this embodiment, the data owner first generates an initial random value S = S 1 0 used as the seed for generating the Hash chain, then performs hash calculation according to the initial random value and the requirements of the network to obtain the corresponding hash value, and finally obtains the preset-length initial Hash chain from the chained secret information sequence composed of the initial random value and hash values:

[0064]

[0065] This Hash chain is pre-allocated and iteratively generates a series of hash values, which will serve as the basis for future encryption tasks, thus optimizing the key generation process. At the same time, since the generation of keys depends on the previous secret information or the initial secret information, the privacy and security of the encryption process are ensured.

[0066] As Figure 4 shown, in another feasible and preferred embodiment of the present application, step S2 specifically includes the steps:

[0067] S21. Pre-generate the first key K in the chained key sequence for the initial random value in the initial Hash chain through an encryption algorithm 1 ;

[0068] S22. Sequentially pre-generate other keys in the chained key sequence for the chained secret information sequence in the initial Hash chain through the same encryption algorithm to obtain the chained key sequence.

[0069] Figure 5 describes the key generation process of the streaming architecture. Starting from the initial random value, the initial parameters and states of the block encryption algorithm (such as the SM4 algorithm) are set. Using the initial random value as the key input of the SM4 algorithm, the first round of encryption operation is performed to generate the first key K 1 , and this key will be directly used for data encryption.

[0070] Then, the other chained secret information sequences in the initial Hash chain (such as to ) are sequentially calculated through the block encryption algorithm (such as the SM4 algorithm) to obtain keys K 2 to key Thus, a chained key sequence composed of keys K 1 to key is obtained.

[0071] In this embodiment, the first key in the chained key sequence is pre-generated by the encryption algorithm for the initial random value in the initial Hash chain, while the others in the chained key sequence are pre-generated by the encryption algorithm for the chained secret information sequence in the initial Hash chain through the same encryption algorithm. At the same time, since the generation of keys depends on the previous secret information or the initial random value, the privacy and security of the encryption process are ensured.

[0072] As Figure 6 shown, in another feasible and preferred embodiment of the present application, step S2 specifically includes the steps:

[0073] S21. Sequentially pre-generate the chained key sequence for the chained secret information sequence in the initial Hash chain through the encryption algorithm.

[0074] Compared with the previous embodiment, this embodiment only uses the chained secret information sequence in the initial Hash chain (excluding the initial random value as the seed), and all the secret information used is a hash value. This embodiment adjusts the key generation strategy. Although the number of keys is reduced by one when pre-generating the chained key sequence, compared with the initial random value, the hash value has unique advantages in ensuring data integrity and authenticity. Therefore, this embodiment further ensures the integrity, privacy, and security of encryption by only using hash values and encryption algorithms to pre-generate the chained key sequence, thus adapting to different security requirements and operating environments.

[0075] In a preferred embodiment of the present application, when pre-generating the chained key sequence for each chained secret information in the chained secret information sequence through an encryption algorithm, after each key in the chained key sequence is pre-generated, a security verification is performed, and the security verification includes checking the randomness of the key.

[0076] In this embodiment, when pre-generating the chained key sequence for each chained secret information in the chained secret information sequence through an encryption algorithm, after each key in the chained key sequence is pre-generated, a security verification is performed, which further ensures that all the generated keys meet the security standards and guarantees the encryption security.

[0077] In another feasible preferred embodiment of the present application, in step S2, the encryption algorithm is not limited by the specific method of this patent and has high flexibility. Any known block encryption algorithm can be selected, such as 3DES, AES, SM4, etc., to adapt to different security requirements and application scenarios.

[0078] The technical solution of this embodiment supports multiple Hash functions, and the Hash functions adopted include but are not limited to MD5, SHA-1, SHA-256, SM3, etc., and have good adaptability. The applicable Hash algorithm can be flexibly selected according to the security requirements of specific application scenarios.

[0079] In the above embodiment, the timing diagram of concurrent encryption based on the pipeline is as Figure 7 shown, where t 1 (1) to t 1 (7) represent sequentially reading the plaintext blocks, and t 2 (1) to t 2 (4) represent encrypting the read plaintext data, and t 3 (1) to t 3 (4) represent sending the encrypted ciphertext to the target device. When the reading of t 1 has not been completed, the encryption of t 2 can be started in advance to utilize the idle resources of the pipeline. Similarly, when the encryption of t2 is processing subsequent blocks, t 3The ciphertext transmission can be carried out concurrently. When the data packet requiring encryption arrives, pipeline processing is performed concurrently. The packet is segmented and fed in parallel, and then the data packets are encrypted using the pre-generated chained key sequence. There, each data packet is XORed with its corresponding key to generate the ciphertext.

[0080] In another feasible and preferred embodiment of the present application, in step S3, before each data packet is XORed with the corresponding key in the pre-generated chained key sequence in parallel to generate the ciphertext, the following steps are further included:

[0081] When the data packet to be encrypted arrives, if the number of data packets in the data packet is greater than the number of keys in the chained key sequence, the initial Hash chain is dynamically extended according to the difference between the two and the Hash function. After pre-generating a new chained key for each newly added chained secret information in the extended chained secret information sequence through an encryption algorithm, it is combined with the chained key sequence obtained before the dynamic extension to form the final chained key sequence.

[0082] As the demand for encryption operations increases, if the initial Hash chain is insufficient to meet the continuous operation requirements, the Hash chain will be dynamically extended by introducing a new random seed (such as ) If the data volume of the data packet to be encrypted is large and the number of uses of the Hash chain exceeds, the initial Hash chain is insufficient to meet the continuous operation requirements, then the Hash chain needs to be extended. When the Hash chain is used, a new random seed can be selected and a new Hash chain can be generated.

[0083]

[0084] where n in 2 is the number of uses of the Hash chain in this round. If it exceeds n 2 , then a new random seed needs to be continuously introduced and so on until where the subscript m represents the number of introduced random seeds and the superscript n represents the number of generated chained secret information in this round.

[0085] If the number of uses of the initial Hash chain exceeds n 1 , then a new Hash chain needs to be redeployed. At this time, the data owner B will calculate the second-round random seed and the number of uses n of the Hash chain 2 , and then send them to the communication party R.

[0086]

[0087] where The initial random value used for the second-round Hash, which is used to generate the chained secret information. 2 represents the second round, and n 2 represents the number of chained secret information generated in this round, and ID B represents that the sender is B, and is used to verify the integrity and authenticity of the message, and K mac The setting of the key and the selection of the MAC algorithm are conventional designs and are not given in this patent.

[0088] After R receives the message, it uses the same key K mac to recalculate the MAC value of the message and compare it with the received MAC value to verify and receive the message. Pass Generate a new Hash chain,

[0089]

[0090] The number of Hash chains is n 2 , which is used to generate the chained key sequence of this round. If the number of data packets in the data packet of the data message is still greater than the number of keys contained in the chained key sequence of this round, a new random seed is introduced The method is similar to the above.

[0091] This embodiment can adjust the Hash chain generation strategy according to the actual application requirements, and then adjust the key generation strategy, so that the number of keys in the chained key sequence adaptively matches the length of the data message to be encrypted, meeting the encryption needs of data messages of different lengths. This flexibility enables the technical solution of this application to adapt to the security requirements and operating environments of data messages of different lengths.

[0092] As Figure 8 shown, another preferred embodiment of this application also provides a stream encryption device based on a grouped hash chain, including:

[0093] An initial Hash chain generation module, which is used to generate an initial Hash chain of a preset length through a Hash function, and the initial Hash chain contains a chained secret information sequence;

[0094] A chained key sequence generation module, which is used to pre-generate a chained key sequence for each chained secret information in the chained secret information sequence through an encryption algorithm;

[0095] A parallel encryption module, which is used when the data message to be encrypted arrives, adopts a concurrent execution pipeline processing method, cuts the data message to be encrypted into data packets, and then performs an exclusive OR operation on each data packet in parallel with the corresponding key in the pre-generated chained key sequence to generate ciphertext.

[0096] In another preferred embodiment of the present application, the initial Hash chain generation module specifically includes:

[0097] A seed generation module for the data owner to generate an initial random value as a seed;

[0098] An initial Hash chain generation module for generating an initial Hash chain of a preset length through a Hash function according to the initial random value and the requirements of the network, where the initial Hash chain includes a chained secret information sequence composed of the initial random value and hash values.

[0099] In another preferred embodiment of the present application, before the parallel encryption module performs an exclusive OR operation on each data packet in parallel with the corresponding key in the pre-generated chained key sequence to generate ciphertext, it is further used for:

[0100] When a data packet to be encrypted arrives, if the number of data packets of the data packet is greater than the number of keys contained in the chained key sequence, the initial Hash chain is dynamically extended according to the difference between the two and the Hash function. After pre-generating new chained keys for each newly added chained secret information in the extended chained secret information sequence through an encryption algorithm, they are combined with the chained key sequence obtained before the dynamic extension to form a final chained key sequence.

[0101] In another preferred embodiment of the present application, the chained key sequence generation module specifically includes:

[0102] A first key pre-generation module for pre-generating the first key in the chained key sequence through an encryption algorithm for the initial random value in the initial Hash chain;

[0103] An other key pre-generation module for sequentially pre-generating other keys in the chained key sequence through the same encryption algorithm for the chained secret information sequence in the initial Hash chain.

[0104] In another preferred embodiment of the present application, the chained key sequence generation module specifically includes:

[0105] A chained key sequence pre-generation module for sequentially pre-generating a chained key sequence through an encryption algorithm for the chained secret information sequence in the initial Hash chain.

[0106] In another preferred embodiment of the present application, in the chained key sequence generation module, when pre-generating a chained key sequence for each chained secret information in the chained secret information sequence through an encryption algorithm, after each key in the chained key sequence is pre-generated, a security verification is performed, and the security verification includes checking the randomness of the key.

[0107] In another preferred embodiment of the present application, in the chained key sequence generation module, the encryption algorithm is a block encryption algorithm.

[0108] As Figure 9 shown, a preferred embodiment of the present application further provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the stream encryption method based on the block hash chain in the above embodiments are implemented.

[0109] As Figure 10 shown, a preferred embodiment of the present application further provides a computer device, which may be a terminal or a living body detection server, and its internal structure diagram may be as Figure 10 shown. The computer device includes a processor, a memory, and a network interface connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with other external computer devices through a network connection. When the computer program is executed by the processor, the steps of the above-mentioned stream encryption method based on the block hash chain are implemented.

[0110] Those skilled in the art can understand that Figure 10 the structure shown in

[0111] is only a block diagram of some structures related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0112] In summary, the present invention proposes a novel stream encryption method based on a grouped hash chain, which significantly reduces the computational resource overhead and processing delay during data encryption and decryption transmission, and improves encryption security. Different from existing methods, the present invention uses grouped hashing to generate an initial random value to obtain secret information, optimizes the key generation process, and pre-generates a key sequence. Finally, a pipelined concurrent encryption strategy is adopted to improve the parallelism and efficiency of data processing. This method not only reduces the dependence on computational resources and processing delay, but also significantly ensures the security of encryption operations. It solves the problems of large computational resource consumption, high processing delay, and security issues faced by traditional encryption methods such as the counter mode (CTR). Through the grouped hash chain architecture and key pre-generation technology, it effectively solves the problems of large computational resource overhead and high processing delay during data encryption and decryption transmission, which cannot meet the security communication requirements of a large number of terminals.

[0113] It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.

[0114] If the functions described in the method of this embodiment are implemented in the form of software function units and sold or used as independent products, they can be stored in one or more computer-readable storage media that can be read by a computing device. Based on this understanding, the part of this application embodiment that contributes to the prior art or part of this technical solution can be embodied in the form of a software product. This software product is stored in a storage medium and includes several instructions to enable a computing device (which can be a personal computer, a server, a mobile computing device, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The aforementioned storage media include: USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs, etc., which can store program codes.

[0115] Those skilled in the art should understand that the embodiments of this application can be provided as a method, a system, or a computer program product. Therefore, this application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, this application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes. The solutions in the embodiments of this application can be implemented in various computer languages. For example, object-oriented programming languages such as Java and interpreted scripting languages such as JavaScript.

[0116] This application is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate a means for implementing the functions specified in one process Figure 1 one process or multiple processes and / or blocks Figure 1 or multiple blocks.

[0117] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including an instruction means that implements the functions specified in one process Figure 1 one process or multiple processes and / or blocks Figure 1 or multiple blocks.

[0118] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one process Figure 1 one process or multiple processes and / or blocks Figure 1 or multiple blocks.

[0119] Although the preferred embodiments of the present application have been described, those skilled in the art can make additional changes and modifications once they learn the basic creative concepts. Therefore, the appended claims are intended to be construed to include the preferred embodiments as well as all changes and modifications that fall within the scope of the present application.

[0120] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these changes and modifications.

Claims

1. A stream encryption method based on grouped hash chains, characterized in that: Includes steps: Generate an initial Hash chain of a preset length through a Hash function, wherein the initial Hash chain contains a chained secret information sequence; Pre-generating a chain key sequence for each chain secret information in the chain secret information sequence by using an encryption algorithm; When a data message to be encrypted arrives, a concurrent pipeline processing method is adopted to cut the data message to be encrypted into data packets, and then each data packet is XORed with the corresponding key in the pre-generated chain key sequence in parallel to generate a ciphertext.

2. The stream encryption method based on grouped hash chains according to claim 1, characterized in that: The step of generating an initial Hash chain of a preset length by using a Hash function, wherein the initial Hash chain includes a chained secret information sequence, specifically comprises the following steps: The data owner generates an initial random value as a seed; According to the initial random value and the requirements of the network, an initial Hash chain of a preset length is generated through a Hash function, and the initial Hash chain includes a chain secret information sequence consisting of an initial random value and a Hash value.

3. The stream encryption method based on grouped hash chains according to claim 2, characterized in that: Before performing XOR operation on each data group in parallel with the corresponding key in the pre-generated chain key sequence to generate ciphertext, the method further includes the steps of: When a data message to be encrypted arrives, if the number of data packets in the data message is greater than the number of keys contained in the chain key sequence, the initial hash chain is dynamically expanded according to the difference between the two and the hash function. After a new chain key is pre-generated through the encryption algorithm for each newly added chain secret information in the expanded chain secret information sequence, it is combined with the chain key sequence obtained before dynamic expansion to form the final chain key sequence.

4. The stream encryption method based on grouped hash chains according to claim 2, characterized in that: The method of pre-generating a chain key sequence by using an encryption algorithm for each chain secret information in the chain secret information sequence specifically comprises the following steps: Pre-generate the first key in the chain key sequence from the initial random value in the initial Hash chain through an encryption algorithm; The chained secret information sequence in the initial Hash chain is pre-generated in turn through the same encryption algorithm to generate other keys in the chained key sequence.

5. The stream encryption method based on grouped hash chains according to claim 1, characterized in that: The method of pre-generating a chain key sequence by using an encryption algorithm for each chain secret information in the chain secret information sequence specifically comprises the following steps: The chained secret information sequence in the initial Hash chain is pre-generated into a chained key sequence through an encryption algorithm.

6. The stream encryption method based on grouped hash chains according to claim 1, characterized in that: When a chain key sequence is pre-generated by an encryption algorithm for each chain secret information in the chain secret information sequence, security verification is performed after each key in the pre-generated chain key sequence, and the security verification includes checking the randomness of the key.

7. The stream encryption method based on grouped hash chains according to claim 1, characterized in that: The encryption algorithm is a block encryption algorithm.

8. A stream encryption device based on grouped hash chains, characterized in that: include: An initial Hash chain generation module, used to generate an initial Hash chain of a preset length through a Hash function, wherein the initial Hash chain includes a chain secret information sequence; A chain key sequence generation module, used for pre-generating a chain key sequence for each chain secret information in the chain secret information sequence by using an encryption algorithm; The parallel encryption module is used to divide the data message to be encrypted into data packets by adopting a concurrent execution pipeline processing method when the data message to be encrypted arrives, and then perform an XOR operation on each data packet in parallel with the corresponding key in the pre-generated chain key sequence to generate a ciphertext.

9. The stream encryption device based on grouped hash chains according to claim 8, characterized in that: The initial Hash chain generation module specifically includes: The seed generation module is used by the data owner to generate an initial random value as a seed; The initial Hash chain generation module is used to generate an initial Hash chain of preset length through a Hash function according to the initial random value and network requirements. The initial Hash chain includes a chain secret information sequence consisting of an initial random value and a Hash value.

10. The stream encryption device based on grouped hash chains according to claim 9, characterized in that: Before the parallel encryption module performs an XOR operation on each data group in parallel with a corresponding key in a pre-generated chained key sequence to generate a ciphertext, the parallel encryption module is further used to: When a data message to be encrypted arrives, if the number of data packets in the data message is greater than the number of keys contained in the chain key sequence, the initial hash chain is dynamically expanded according to the difference between the two and the hash function. After a new chain key is pre-generated through the encryption algorithm for each newly added chain secret information in the expanded chain secret information sequence, it is combined with the chain key sequence obtained before dynamic expansion to form the final chain key sequence.

11. The stream encryption device based on grouped hash chains according to claim 9, characterized in that: The chained key sequence generation module specifically includes: A first key pre-generation module, used to pre-generate the first key in the chain key sequence from the initial random value in the initial Hash chain through an encryption algorithm; Other key pre-generation modules are used to pre-generate other keys in the chain key sequence by using the same encryption algorithm for the chain secret information sequence in the initial Hash chain in sequence.

12. The stream encryption device based on grouped hash chains according to claim 8, characterized in that: The chained key sequence generation module specifically includes: The chain key sequence pre-generation module is used to pre-generate the chain key sequence for the chain secret information sequence in the initial Hash chain in sequence through an encryption algorithm.

13. The stream encryption device based on grouped hash chains according to claim 8, characterized in that: In the chain key sequence generation module, when a chain key sequence is pre-generated for each chain secret information in the chain secret information sequence through an encryption algorithm, security verification is performed after each key in the pre-generated chain key sequence, and the security verification includes checking the randomness of the key.

14. The stream encryption device based on grouped hash chains according to claim 8, characterized in that: In the chain key sequence generation module, the encryption algorithm is a block encryption algorithm.

15. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of the stream encryption method based on group hash chain as claimed in any one of claims 1 to 7 are implemented.

16. A storage medium, comprising a stored program, which controls a device where the storage medium is located to execute the steps of the stream encryption method based on group hash chain as claimed in any one of claims 1 to 7 when the program is executed.