Data encryption method, equipment and device
By using multiple encryption keys in the data encryption scheme for chain encryption and encrypting according to the encryption instruction information of the cryptographic device, the problem of data encryption security risks in the prior art is solved, and the security and randomness of data encryption are improved.
Patent Information
- Application Number
- CN202510282239.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-11
- Publication Date
- 2025-06-06
AI Technical Summary
In the existing data encryption scheme, the encryption method of encrypting data using a password service platform has a security risk, and it is impossible to effectively prevent data exposure caused by password cracking or leaking.
By acquiring multiple encryption keys, encrypting the encrypted data in a chain encryption method, and determining whether to use the password device to further encrypt the encrypted data based on the encryption instruction information of the password device, improving the randomness and security of data encryption.
It improves the randomness of data encryption methods, reduces the risk of overall key leakage, enhances the security of data encryption, and avoids the security risks when relying solely on the password service platform to encrypt.
Smart Images

Figure CN120110666A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data security technology, and in particular to a method, device and apparatus for data encryption. Background Art
[0002] With the rapid development of information technology, network information has brought convenience to people, but it has also led to the exposure of a large amount of sensitive information on the network. How to protect sensitive data has become an unavoidable problem in the development of this technology. Data security encryption technology is an important means to solve the problem of data security transmission. In order to avoid the leakage of sensitive data, data security encryption technology is usually used to encrypt data.
[0003] In the prior art, systems without encryption functions usually use a password service platform to encrypt data. However, the existing password service management platform can only provide a single encryption method when providing password capabilities. Once the password is cracked or leaked, all encrypted data will be exposed, posing a security risk.
[0004] Therefore, the existing data encryption scheme that uses a cryptographic service platform to encrypt data has data encryption security risks and needs to be improved. Summary of the invention
[0005] The present application provides a data encryption method, device and apparatus to improve the security of encrypted data.
[0006] In a first aspect, the present application provides a method for data encryption, the method comprising: obtaining multiple encryption keys, the multiple encryption keys are obtained based on a preset initial key and multiple random numbers, and the multiple encryption keys correspond one-to-one to the multiple random numbers; based on the multiple encryption keys, chain encrypting the encrypted data in sequence to obtain first ciphertext data; obtaining encryption indication information of a cryptographic device, the encryption indication information is used to indicate whether to use a cryptographic device for encryption; determining that the encryption indication information indicates to use a cryptographic device for encryption, and using the cryptographic device to encrypt the first ciphertext data to obtain second ciphertext data; and outputting the second ciphertext data.
[0007] According to the method, the chain encryption method is used to encrypt the data to be encrypted to obtain the first ciphertext data, and the first ciphertext data is encrypted by the cryptographic device based on the encryption indication information to obtain the second ciphertext data. The encryption indication information corresponding to different moments is different. Therefore, the method can improve the randomness of the data encryption method, solve the data encryption security risks of only using the cryptographic service platform to encrypt data, and thus improve the security of data encryption.
[0008] In one possible design, obtaining multiple encryption keys includes: obtaining the multiple encryption keys from storage locations of the multiple encryption keys, where the storage locations of the multiple encryption keys include system startup files, code business files, and packaging configuration files.
[0009] Based on this design, multiple encryption keys are distributed and stored on multiple independent and secure nodes, reducing the risk of overall key leakage and improving the security of data encryption.
[0010] In one possible design, the multiple encryption keys include a first key, a second key and a third key, and the chain encryption of the data to be encrypted based on the multiple encryption keys in sequence to obtain the first ciphertext data includes: encrypting the data to be encrypted based on the first key to obtain first-level ciphertext data; encrypting the first-level ciphertext data based on the second key to obtain second-level ciphertext data; encrypting the second-level ciphertext data based on the third key to obtain the first ciphertext data.
[0011] Based on this design, the use of chain encryption can further improve the security of data encryption.
[0012] In one possible design, the first-level ciphertext data is hashed to obtain a first-level label, and the label of the first-level key is used to verify the integrity of the first key; the first-level label is concatenated with the second-level ciphertext data, and the concatenated data is hashed to obtain a second-level label, and the second-level label is used to verify the integrity of the first key and the second key; the second-level label is concatenated with the first key data, and the concatenated data is hashed to obtain a third-level label, and the third-level label is used to verify the integrity of the first key, the second key and the third key.
[0013] Based on this design, the label of each link depends on the label of the output of the previous link, thus forming an irreversible chain structure that can detect potential tampering at any time and ensure the integrity and confidentiality of the data.
[0014] In one possible design, the encryption indication information of the cryptographic device is determined based on a current moment and multiple historical operating states of the cryptographic device.
[0015] Based on this design, the randomness of the encryption indication information can be increased, thereby improving the security of the encrypted data.
[0016] In one possible design, the use of the cryptographic device to encrypt the first ciphertext data to obtain second ciphertext data includes: decrypting the first ciphertext data in sequence based on multiple decryption keys to obtain the data to be encrypted, the multiple decryption keys corresponding one-to-one to the multiple encryption keys; and using the cryptographic device to encrypt the data to be encrypted to obtain second ciphertext data.
[0017] In a second aspect, an embodiment of the present application provides a data encryption device, the device comprising:
[0018] A communication module, used to obtain a plurality of encryption keys, wherein the plurality of encryption keys are obtained according to a preset initial key and a plurality of random numbers, and the plurality of encryption keys correspond to the plurality of random numbers one by one;
[0019] A processing module, configured to sequentially perform chain encryption on the data to be encrypted based on the multiple encryption keys to obtain first ciphertext data;
[0020] The processing module is further used to obtain encryption indication information of a cryptographic device, where the encryption indication information is used to indicate whether to use the cryptographic device for encryption;
[0021] The processing module is further configured to determine that the encryption indication information indicates that encryption is performed using a cryptographic device, and to use the cryptographic device to encrypt the first ciphertext data to obtain second ciphertext data;
[0022] The communication module is further used to output the second ciphertext data.
[0023] In one possible design, multiple encryption keys are obtained, and the communication module is specifically used to: obtain the multiple encryption keys from the storage locations of the multiple encryption keys, and the storage locations of the multiple encryption keys include system startup files, code business files, and packaging configuration files.
[0024] In one possible design, the multiple encryption keys include a first key, a second key and a third key, and the data to be encrypted is chain-encrypted in sequence based on the multiple encryption keys to obtain first ciphertext data. The processing module is specifically used to: encrypt the data to be encrypted based on the first key to obtain first-level ciphertext data; encrypt the first-level ciphertext data based on the second key to obtain second-level ciphertext data; and encrypt the second-level ciphertext data based on the third key to obtain the first ciphertext data.
[0025] In one possible design, the processing module is also used to: perform hash processing on the first-level ciphertext data to obtain a first-level label, and the label of the first-level key is used to verify the integrity of the first key; splice the first-level label with the second-level ciphertext data, and perform hash processing on the spliced data to obtain a second-level label, and the second-level label is used to verify the integrity of the first key and the second key; splice the second-level label with the first key data, and perform hash processing on the spliced data to obtain a third-level label, and the third-level label is used to verify the integrity of the first key, the second key and the third key.
[0026] In one possible design, the encryption indication information of the cryptographic device is determined based on a current moment and multiple historical operating states of the cryptographic device.
[0027] In one possible design, the cryptographic device is used to encrypt the first ciphertext data to obtain second ciphertext data, and the processing module is specifically used to: decrypt the first ciphertext data in sequence based on multiple decryption keys to obtain the data to be encrypted, and the multiple decryption keys correspond one-to-one to the multiple encryption keys; and use the cryptographic device to encrypt the data to be encrypted to obtain second ciphertext data.
[0028] In a third aspect, an embodiment of the present application provides an electronic device, comprising at least one processor and at least one memory, wherein the memory stores a computer program, and when the program is executed by the processor, the processor executes the steps of any method described in the first aspect above.
[0029] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium storing a computer program executable by a processor, wherein when the program runs on the processor, the processor executes the steps of any of the methods described in the first aspect.
[0030] In a fifth aspect, an embodiment of the present application provides a computer program product, comprising a computer program, wherein the computer program is stored in a computer-readable storage medium; when a processor of an electronic device reads the computer program from the computer-readable storage medium, the processor executes the computer program, so that the electronic device performs the steps of any method described in the first aspect.
[0031] The technical effects brought about by the second to fifth aspects and any one of their designs can refer to the technical effects brought about by the corresponding designs in the first aspect, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.
[0033] Figure 1 A schematic diagram of the structure of a data encryption system provided in an embodiment of the present application;
[0034] Figure 2 A flowchart of a data encryption method provided in an embodiment of the present application;
[0035] Figure 3 A schematic diagram of the structure of another data encryption system provided in an embodiment of the present application;
[0036] Figure 4 A schematic diagram of a data encryption method with multiple encryption modes provided in an embodiment of the present application;
[0037] Figure 5 A schematic diagram of a data encryption device provided in an embodiment of the present application;
[0038] Figure 6 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0039] In order to make the purpose, technical scheme and advantages of the embodiments of the present application clearer, the technical scheme in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Among them, the described embodiments are part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application.
[0040] Furthermore, in the description of the embodiments of the present application, unless otherwise specified, “and” means or. For example, A / B can mean A or B. The “and / or” in the text is merely a description of the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone.
[0041] In addition, the terms "first" and "second" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Thus, the features defined as "first" and "second" may explicitly or implicitly include one or more of the features. In the description of this application, the meaning of "plurality" is two or more, unless otherwise clearly and specifically defined.
[0042] In the description of this application, it should be noted that, unless otherwise clearly specified and limited, the term "connection" should be understood in a broad sense, for example, it can be directly connected, or indirectly connected through an intermediate medium, or it can be the internal connection of two devices. For ordinary technicians in this field, the specific meanings of the above terms in this application can be understood according to specific circumstances.
[0043] Before introducing a data encryption method provided by an embodiment of the present application, in order to facilitate understanding, the technical background of the embodiment of the present application is first introduced in detail below.
[0044] With the rapid development of network information technology, more and more privacy data leaks occur, and people are more and more aware of protecting privacy data. At present, in order to ensure the security of privacy data, data encryption is usually used to encrypt privacy data before transmitting it.
[0045] The password service platform is a platform for encrypting data. When the existing password service system is facing the transition stage from the password service platform being fully functional to the formal incorporation of password management equipment, since the password service platform has not yet been connected to the actual password hardware equipment, the system cannot directly rely on the hardware encryption equipment to provide password service capabilities. At the same time, the existing password service management platform can only provide a single encryption method when providing password capabilities. Once the password is cracked or leaked, all encrypted data will be exposed, posing a security risk.
[0046] Therefore, the existing data encryption scheme that uses a cryptographic service platform to encrypt data has data encryption security risks and needs to be improved.
[0047] In order to solve the above-mentioned defects, the embodiments of the present application provide a data encryption method, apparatus, device and medium for improving the security of encrypted data.
[0048] Figure 1 A schematic diagram of the structure of a data encryption system provided in an embodiment of the present application. Figure 1As shown, the data encryption system includes a key verification distributed operation module, an encryption mode switching module, a cryptographic device and a cryptographic device detection module. Among them, the key verification distributed operation module can be used to store the key in different storage locations through a chain segmentation method, thereby avoiding key leakage and key tampering. The encryption mode switching module can be used to switch the encrypted data in the national password encryption scenario to the cryptographic device encryption mode, and perform cryptographic device encryption on the national password encrypted data for cleaning, thereby further improving the security of the data. The cryptographic device detection module can be used to automatically switch whether the system uses a cryptographic device to encrypt data, avoid the risks brought by human operation, and improve the security of data encryption.
[0049] In the present application, the method adopted includes: the first device obtains multiple encryption keys. The multiple encryption keys are obtained according to a preset initial key and multiple random numbers, and the multiple encryption keys correspond to the multiple random numbers one by one. The first device sequentially performs chain encryption on the encrypted data based on the multiple encryption keys to obtain the first ciphertext data. The first device obtains encryption indication information of the cryptographic device. The encryption indication information is used to indicate whether to use the cryptographic device for encryption, and different encryption indication information corresponds to different times. The first device determines that the encryption indication information indicates to use the cryptographic device for encryption, and uses the cryptographic device to encrypt the first ciphertext data to obtain the second ciphertext data. The first device outputs the second ciphertext data.
[0050] According to the method, the chain encryption method is used to encrypt the data to be encrypted to obtain the first ciphertext data, and the first ciphertext data is encrypted by the cryptographic device based on the encryption indication information to obtain the second ciphertext data. The encryption indication information corresponding to different moments is different. Therefore, the method can improve the randomness of the data encryption method, solve the data encryption security risks of only using the cryptographic service platform to encrypt data, and thus improve the security of data encryption.
[0051] In addition, the subject used to execute the method described in the present application may be a server, or may be a processing device in a computer system used to execute the method described in the present application, such as a processor or a processing module, etc., which is not specifically limited in the present application.
[0052] In order to make the purpose, technical solution and beneficial effects of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0053] like Figure 2 As shown, a flow chart of a method for data encryption according to an embodiment of the present application is shown. Taking the first device as the execution subject, the flow may include the following specific steps:
[0054] S201, the first device obtains a plurality of encryption keys, wherein the plurality of encryption keys are obtained according to a preset initial key and a plurality of random numbers, and the plurality of encryption keys correspond to the plurality of random numbers one by one.
[0055] In one or more embodiments, the preset initial key may be a key generated based on the national cryptographic library. For example, the initial key may be a key randomly selected from the national cryptographic library when the encryption system is deployed. Alternatively, the initial key may be a key randomly selected from the national cryptographic library on a regular basis, that is, the initial key may be updated regularly, thereby increasing the randomness of the initial key and improving the security of data encryption. In addition, the initial key may also be generated in other ways, which are not specifically limited in this application.
[0056] Optionally, the encryption key may be obtained based on a preset initial key and a corresponding random number, wherein the random number may be generated by a random number generator, or the random number may be generated based on a national cryptographic library.
[0057] Exemplarily, the present application may also include a key management device, which may generate multiple random numbers based on the national cryptographic library, and process the initial key and the random number according to the key encryption method to obtain the corresponding encryption key. For example, the initial key may be expressed as rootkey, and the key encryption method may be SM4 encryption, then the encryption key, the initial key and the random number satisfy:
[0058] Encryption key = SM4 (rootkey, random number).
[0059] For example, Figure 3 A schematic diagram of the structure of a data encryption system provided in an embodiment of the present application. Figure 3 As shown, the root key can be represented as an initial key, and key 1, key 2, and key 3 can be represented as multiple encryption keys, respectively. Among them, key 1, key 2, and key 3 can be generated based on the national key library and the root key, respectively.
[0060] Optionally, in the present application, different encryption keys may be generated based on different encryption links. That is, multiple encryption keys correspond to multiple encryption links. For example, multiple encryption keys include system keys, configuration keys, and service keys.
[0061] In one or more embodiments, the generated multiple encryption keys can be stored in different storage locations, thereby improving the security of the encryption keys. The storage locations may include system startup files, code business files, and packaged configuration files. Different storage locations can store different encryption keys. For example, the system startup file can store system keys, the code business file can store service keys, and the packaged configuration file can store configuration keys. Accordingly, the first device can obtain the multiple encryption keys from the storage locations of the multiple encryption keys.
[0062] S202: The first device performs chain encryption on the data to be encrypted in sequence based on multiple encryption keys to obtain first ciphertext data.
[0063] Among them, chain encryption can refer to using the key of the current link to encrypt the ciphertext data of the previous link again until all encryption keys are used up.
[0064] In one or more embodiments, the multiple encryption keys may include a first key, a second key, and a third key. The first device sequentially performs chain encryption on the encrypted data based on the multiple encryption keys to obtain the first ciphertext data may refer to:
[0065] The first device uses the first key to encrypt the data to be encrypted to obtain a first-level ciphertext;
[0066] The first device uses the second key to encrypt the first-level ciphertext to obtain the second-level ciphertext;
[0067] The first device uses the third key to encrypt the second-level ciphertext to obtain the third-level ciphertext, that is, to obtain the first ciphertext data.
[0068] It is understandable that if the multiple encryption keys include more encryption keys, chain encryption can be continued. Alternatively, the user can pre-set the number of encryptions, and when the number of encryptions is less than the number of encryption keys, a corresponding number of encryption keys can be randomly selected from the multiple encryption keys.
[0069] For example, Figure 3 As shown, the encryption key includes key 1, key 2 and key 3. Key 1 is used to encrypt the data to be encrypted to obtain ciphertext 1. Ciphertext 1 is used as the data to be encrypted, and key 2 is used to encrypt ciphertext 1 to obtain ciphertext 2. Ciphertext 2 is used as the encrypted data, and key 3 is used to encrypt ciphertext 2 to obtain ciphertext 3, that is, the final ciphertext data.
[0070] In one or more embodiments, in order to prevent the encryption key from being tampered with, the first device may also generate a verification tag corresponding to the encryption key, wherein the verification tag may be used to verify the integrity of the encryption key.
[0071] Optionally, the first device may perform hash processing on the first-level ciphertext corresponding to the first key to obtain a corresponding first-level tag. The first-level tag may be used to verify the integrity of the first key. The first device may concatenate the first-level tag with the second-level ciphertext corresponding to the second key, and perform hash processing on the concatenated data to obtain a corresponding second-level tag. The second-level tag may be used to verify the integrity of the first key and the second key. The first device may concatenate the second-level tag with the first key data corresponding to the third key, and perform hash processing on the concatenated data to obtain a corresponding third-level tag. The third-level tag may be used to verify the integrity of the first key, the second key, and the third key. For example, Figure 3 As shown, the first device performs hash processing on ciphertext 1 to obtain label 1. The first device concatenates label 1 with ciphertext 2, and performs hash processing on the concatenated data to obtain label 2. The first device concatenates label 2 with ciphertext 3, and performs hash processing on the concatenated data to obtain label 3.
[0072] That is, the first device can concatenate the ciphertext of the current link with the verification tag of the previous link, and use the hash value of the concatenated data as the verification tag of the current link, thereby verifying the integrity of the encryption key of all links before the current link based on the verification tag to prevent the encryption key from being tampered with. For example, the verification tag of the i-th link can be expressed as Hash i , the ciphertext of the i-th link can be expressed as i , then the verification tag of the i-th link, the ciphertext of the i-th link, and the verification tag of the previous link satisfy:
[0073] Hash i =SM3(String(Hash i-1 +Ciphertext i ));
[0074] SM3 refers to the SM3 algorithm, and String(X+Y) indicates concatenating X and Y.
[0075] It is understandable that if the current link is the first link, the verification tag of the previous link can be ignored.
[0076] S203, the first device obtains encryption indication information of the cryptographic device. The encryption indication information can be used to indicate whether to use the cryptographic device for encryption. Different encryption indication information corresponds to different times.
[0077] In one or more embodiments, the encryption indication information may be determined based on the current moment and multiple historical operating states of the cryptographic device.
[0078] The operation status of the cryptographic device may include normal and abnormal. It is understandable that the cryptographic device may obtain the operation status of the device at regular intervals and store it. For example, the cryptographic device obtains the operation status of its own device every 10 seconds and stores the operation status. When multiple consecutive historical operation statuses of the cryptographic device are all normal, it indicates that the cryptographic device can be used to encrypt data.
[0079] Optionally, the encryption indication information of whether to use a cryptographic device for encryption may change with time according to a preset change rule, thereby achieving randomization of the encryption indication information and improving the security of data encryption.
[0080] It is understandable that the encryption instruction information may be determined by combining multiple historical operating states of the cryptographic device and the instruction information corresponding to the current moment. That is, when multiple historical operating states of the cryptographic device are normal, and the instruction information corresponding to the current moment is to use the cryptographic device for encryption, the encryption instruction information is to use the cryptographic device to encrypt the data. Otherwise, the encryption instruction information is not to use the cryptographic device to encrypt the data.
[0081] In one or more embodiments, the cryptographic device can send multiple historical operating states of itself to the first device, and the first device pre-stores the correspondence between time and encryption indication information. The first device can then determine the encryption indication information based on the indication information corresponding to the current time and the multiple operating states of the cryptographic device.
[0082] Alternatively, the present application may also include other devices, and the other devices may send encryption indication information to the first device. Figure 1 As shown, the other device may be a cryptographic device detection module, which may determine the encryption indication information and send the encryption indication information to the first device. Accordingly, the first device receives the encryption indication information from the cryptographic device.
[0083] In addition, the operating status of the cryptographic device may also include the status of the interface of the cryptographic device. Exemplarily, taking the cryptographic device detection module as the execution subject, the following contents may be included:
[0084] The cryptographic device detection module can obtain the operating status of the cryptographic device regularly through the simple network management protocol (SNMP). The operating status of the cryptographic device can be expressed as S<time,snmp,status> .
[0085] The cryptographic device detection module can obtain the status of the interface of the cryptographic device in real time through the hypertext transfer protocol (HTTP). The status of the interface of the cryptographic device can be represented by H<time,http,status> .
[0086] The cryptographic device detection module can obtain the operating status of multiple cryptographic devices and the status of the interfaces of the cryptographic devices according to time segments. For example, the time interval of the time segment can be 30 seconds.
[0087] The cryptographic device detection module can perform XOR processing on the operating state of the cryptographic device and the state of the interface of the cryptographic device respectively. The XOR result of the operating state of the cryptographic device can be expressed as L s (t), then the operating state of the cryptographic device satisfies:
[0088]
[0089] The XOR result of the state of the interface of the cryptographic device can be expressed as L H (t), then the state of the interface of the cryptographic device satisfies:
[0090]
[0091] The cryptographic device detection module may determine whether the cryptographic device is in an available state based on an exclusive OR result of an operating state of the cryptographic device and an exclusive OR result of a state of an interface of the cryptographic device.
[0092] When the XOR result of the running status of the cryptographic device and the XOR result of the status of the interface of the cryptographic device meet the following conditions:
[0093]
[0094] This means that the cryptographic device is in an available state, otherwise it is in an unavailable state. In other words, the cryptographic device is capable of providing encryption services only when the operation state and interface state of the cryptographic device are both normal. In addition, when multiple historical operation states of the cryptographic device are all normal, it means that the cryptographic device can stably provide encryption services, thereby ensuring the stability of encryption using the cryptographic device.
[0095] In one or more embodiments, the encryption indication information may also be determined only based on whether the cryptographic device is available. That is, when the cryptographic device is available, the encryption indication information is used to indicate that the cryptographic device is used to encrypt the data. When the cryptographic device is unavailable, the encryption indication information is used to indicate that the cryptographic device is not used to encrypt the data.
[0096] S204: The first device determines that the encryption indication information indicates that encryption is performed using a cryptographic device, and uses the cryptographic device to encrypt the first ciphertext data to obtain second ciphertext data.
[0097] In one or more embodiments, when the encryption indication information indicates that a cryptographic device is used to encrypt data, the first device may use the cryptographic device to encrypt the first ciphertext data to obtain the second ciphertext data.
[0098] Optionally, before using the cryptographic device to encrypt the first ciphertext data, the first device may parse the link corresponding to the first ciphertext data through a dynamic selector to determine a processing method corresponding to the link, wherein the processing method includes encryption and decryption.
[0099] When the processing method is encryption, the first device may use a cryptographic device to encrypt the first ciphertext data to obtain the second ciphertext data.
[0100] When the processing method is decryption, the first device can obtain multiple decryption keys from the system memory. Among them, the multiple decryption keys correspond one-to-one to the multiple encryption keys, and the decryption key and the encryption key can be a symmetric key pair. In addition, in order to ensure the security of the decryption key, the storage time of the decryption key can be pre-set. The first device can decrypt the first ciphertext data in sequence based on the multiple decryption keys to obtain the data to be encrypted. The first device can use the key device to encrypt the data to be encrypted to obtain the second ciphertext data. It can be understood that the process of the first device using the decryption key to decrypt the first ciphertext data is the reverse process of the encryption process, which will not be repeated here.
[0101] In one or more embodiments, the processing method may be determined according to business requirements. For example, when the business requirement is to perform secondary encryption on the encrypted data, the processing method may be encryption. When the business requirement is to perform primary encryption on the encrypted data, the processing method may be decryption.
[0102] For example, Figure 4 A schematic diagram of a data encryption method with multiple encryption modes provided in an embodiment of the present application. With the first device as the execution subject, the process may include the following steps:
[0103] S401: The first device determines whether the cryptographic device is in an available state.
[0104] When the password device is in an unavailable state, step S402 is executed. When the password device is in an available state, step S403 is executed.
[0105] S402, the first device encrypts and decrypts data using a national code encryption method.
[0106] S403: The first device processes the data using a cryptographic device.
[0107] The specific steps of the first device using the cryptographic device to process data may include steps S403.1 to S403.3.
[0108] S403.1, the first device uses a dynamic selector to parse the link of the data and determine a processing method corresponding to the link.
[0109] When the processing mode is encryption operation, step S403.2 is executed. When the processing mode is decryption operation, step S403.3 is executed.
[0110] S403.2, the first device uses a cryptographic device to encrypt the data to obtain corresponding ciphertext.
[0111] S403.3, the first device decrypts the data using the decryption key, and puts the decrypted data into a cache queue.
[0112] S404, the first device uses a cryptographic device to encrypt the data in the cache queue to obtain corresponding ciphertext.
[0113] S405, the data in the inventory list of the first device is decrypted by the national password and the decrypted data is encrypted using a cryptographic device to obtain a corresponding ciphertext.
[0114] Among them, the stock list is used to store ciphertext encrypted with national password.
[0115] S406: When there is no data in the cache queue and the stock list, the first device closes the dynamic selector.
[0116] Among them, when there is no data in the cache queue and the stock list, it means that all data are encrypted and decrypted using a cryptographic device. Therefore, the dynamic selector can be closed to end the data encryption and decryption operation processing.
[0117] S205, the first device outputs second ciphertext data.
[0118] In one or more embodiments, the first device may be a device for encrypting plaintext data, and the first device may encrypt the plaintext data based on steps S201 to S205 to obtain the second ciphertext data. The first device may send the second ciphertext data to the target device. Alternatively, the target device may retrieve the second ciphertext data in the first device.
[0119] Based on the above content and the same concept, the present application provides a data encryption device. Figure 5 As shown, the device includes a communication module 501 and a processing module 502 .
[0120] The communication module 501 is used to obtain multiple encryption keys, where the multiple encryption keys are obtained according to a preset initial key and multiple random numbers, and the multiple encryption keys correspond to the multiple random numbers one by one.
[0121] The processing module 502 is used to perform chain encryption on the data to be encrypted in sequence based on multiple encryption keys to obtain first ciphertext data.
[0122] The processing module 502 is further used to obtain encryption indication information of the cryptographic device, where the encryption indication information is used to indicate whether to use the cryptographic device for encryption, and different encryption indication information corresponds to different times.
[0123] The processing module 502 is further configured to determine that the encryption indication information indicates that encryption is performed using a cryptographic device, and to use the cryptographic device to encrypt the first ciphertext data to obtain second ciphertext data.
[0124] The communication module 501 is further used to output the second ciphertext data.
[0125] In one possible design, multiple encryption keys are obtained, and the communication module 501 is specifically used to: obtain multiple encryption keys from storage locations of multiple encryption keys, and the storage locations of the multiple encryption keys include system startup files, code business files, and packaging configuration files.
[0126] In a possible design, the multiple encryption keys include a first key, a second key, and a third key. The data to be encrypted is chain-encrypted in sequence based on the multiple encryption keys to obtain first ciphertext data. The processing module 502 is specifically used to: encrypt the data to be encrypted based on the first key to obtain first-level ciphertext data. Encrypt the first-level ciphertext data based on the second key to obtain second-level ciphertext data. Encrypt the second-level ciphertext data based on the third key to obtain the first ciphertext data.
[0127] In a possible design, the processing module 502 is further used to: perform hash processing on the first-level ciphertext data to obtain a first-level label, and the label of the first-level key is used to verify the integrity of the first key. The first-level label is spliced with the second-level ciphertext data, and the spliced data is hashed to obtain a second-level label, and the second-level label is used to verify the integrity of the first key and the second key. The second-level label is spliced with the first key data, and the spliced data is hashed to obtain a third-level label, and the third-level label is used to verify the integrity of the first key, the second key, and the third key.
[0128] In one possible design, encryption indication information of the cryptographic device is determined based on a current moment and multiple historical operating states of the cryptographic device.
[0129] In one possible design, a cryptographic device is used to encrypt the first ciphertext data to obtain the second ciphertext data, and the processing module 502 is specifically used to: decrypt the first ciphertext data in sequence based on multiple decryption keys to obtain the data to be encrypted, and the multiple decryption keys correspond to the multiple encryption keys one by one. The cryptographic device is used to encrypt the data to be encrypted to obtain the second ciphertext data.
[0130] Figure 6 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application is shown.
[0131] The electronic device in the embodiment of the present application may include a processor 601. The processor 601 is the control center of the device, and various interfaces and lines can be used to connect various parts of the device, by running or executing instructions stored in the memory 603 and calling data stored in the memory 603. Optionally, the processor 601 may include one or more processing units, and the processor 601 may integrate an application processor and a modem processor, wherein the application processor mainly processes operating systems and application programs, etc., and the modem processor mainly processes wireless communications. It is understandable that the above-mentioned modem processor may not be integrated into the processor 601. In some embodiments, the processor 601 and the memory 603 may be implemented on the same chip, and in some embodiments, they may also be implemented separately on independent chips.
[0132] Processor 601 can be a general-purpose processor, such as a central processing unit (CPU), a digital signal processor, an application-specific integrated circuit, a field programmable gate array or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component, and can implement or execute the various methods, steps and logic block diagrams disclosed in the embodiments of the present application. A general-purpose processor can be a microprocessor or any conventional processor, etc. The method steps disclosed in conjunction with the embodiments of the present application can be directly executed by a hardware processor, or can be executed by a combination of hardware and software modules in the processor.
[0133] In the embodiment of the present application, the memory 603 stores instructions that can be executed by at least one processor 601. The at least one processor 601 can be used to execute the method steps disclosed in the embodiment of the present application by executing the instructions stored in the memory 603.
[0134] Memory 603, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer executable programs and modules. Memory 603 may include at least one type of storage medium, such as flash memory, hard disk, multimedia card, card-type memory, random access memory (Random Access Memory, RAM), static random access memory (Static Random Access Memory, SRAM), programmable read-only memory (Programmable Read Only Memory, PROM), read-only memory (Read Only Memory, ROM), electrically erasable programmable read-only memory (Electrically Erasable Programmable Read-Only Memory, EEPROM), magnetic storage, disk, optical disk, etc. Memory 603 is any other medium that can be used to carry or store a desired program code in the form of an instruction or data structure and can be accessed by a computer, but is not limited thereto. The memory 603 in the embodiment of the present application can also be a circuit or any other device that can realize a storage function, for storing program instructions and / or data.
[0135] In the embodiment of the present application, the device may further include a communication interface 602 , through which the electronic device may transmit data.
[0136] Optional, can be Figure 6 The processor 601 (or the processor 601 and the communication interface 602) implements Figure 5 The processing module 502 and / or the communication module 501 shown, that is, the actions of the processing module 502 and / or the communication module 501 can be executed by the processor 601 (or the processor 601 and the communication interface 602).
[0137] Based on the same inventive concept, the embodiment of the present application also provides a computer-readable storage medium, which may store instructions. When the instructions are executed on a computer, the computer executes the operation steps provided in the above method embodiment. The computer-readable storage medium may be Figure 6 The memory 603 is shown.
[0138] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented in one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that include computer-usable program code.
[0139] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0140] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0141] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps of the functions specified in one or more boxes. Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is also intended to include these modifications and variations.
Claims
1. A method for data encryption, characterized in that: The method comprises: Acquire multiple encryption keys, where the multiple encryption keys are obtained according to a preset initial key and multiple random numbers, and the multiple encryption keys correspond one-to-one to the multiple random numbers; Performing chain encryption on the data to be encrypted in sequence based on the multiple encryption keys to obtain first ciphertext data; Obtaining encryption indication information of a cryptographic device, wherein the encryption indication information is used to indicate whether to use the cryptographic device for encryption; Determining that the encryption indication information indicates that encryption is performed using a cryptographic device, and using the cryptographic device to encrypt the first ciphertext data to obtain second ciphertext data; The second ciphertext data is output.
2. The method according to claim 1, characterized in that The obtaining of multiple encryption keys comprises: The multiple encryption keys are obtained from storage locations of the multiple encryption keys, where the storage locations of the multiple encryption keys include a system startup file, a code business file, and a packaging configuration file.
3. The method according to claim 1, characterized in that The multiple encryption keys include a first key, a second key, and a third key, and the chain encryption of the data to be encrypted based on the multiple encryption keys in sequence to obtain the first ciphertext data includes: Encrypting the data to be encrypted based on the first key to obtain primary ciphertext data; Encrypting the first-level ciphertext data based on the second key to obtain second-level ciphertext data; The second-level ciphertext data is encrypted based on the third key to obtain the first ciphertext data.
4. The method according to claim 3, characterized in that The method further comprises: Performing hash processing on the first-level ciphertext data to obtain a first-level label, wherein the label of the first-level key is used to verify the integrity of the first key; Concatenating the primary tag with the secondary ciphertext data, and performing hash processing on the concatenated data to obtain a secondary tag, wherein the secondary tag is used to verify the integrity of the first key and the second key; The secondary tag is concatenated with the first key data, and the concatenated data is hashed to obtain a tertiary tag, where the tertiary tag is used to verify the integrity of the first key, the second key, and the third key.
5. The method according to claim 1, characterized in that The encryption indication information of the cryptographic device is determined according to a current moment and a plurality of historical operating states of the cryptographic device.
6. The method according to claim 1, characterized in that The step of using the cryptographic device to encrypt the first ciphertext data to obtain second ciphertext data includes: Decrypting the first ciphertext data in sequence based on multiple decryption keys to obtain the data to be encrypted, wherein the multiple decryption keys correspond one to one to the multiple encryption keys; The cryptographic device is used to encrypt the data to be encrypted to obtain second ciphertext data.
7. A data encryption device, characterized in that: The device comprises: A communication module, used to obtain a plurality of encryption keys, wherein the plurality of encryption keys are obtained according to a preset initial key and a plurality of random numbers, and the plurality of encryption keys correspond to the plurality of random numbers one by one; A processing module, configured to sequentially perform chain encryption on the data to be encrypted based on the multiple encryption keys to obtain first ciphertext data; The processing module is further used to obtain encryption indication information of a cryptographic device, where the encryption indication information is used to indicate whether to use the cryptographic device for encryption; The processing module is further configured to determine that the encryption indication information indicates that encryption is performed using a cryptographic device, and to use the cryptographic device to encrypt the first ciphertext data to obtain second ciphertext data; The communication module is further used to output the second ciphertext data.
8. An electronic device, characterized in that: The method comprises at least one processor and at least one memory, wherein the memory stores a computer program, and when the program is executed by the processor, the processor executes the method according to any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that: It stores a computer program executable by a computer, and when the program is run on the computer, the computer is enabled to execute the method according to any one of claims 1 to 6.
10. A computer program product, characterized in that When the computer program product is called by a computer, the computer executes the method according to any one of claims 1 to 6.
Citation Information
Cited By
Data encryption method, data decryption method and related devices
CN121261916A