A Method for Decryption and Scheduling of Rainbow Tables Based on Multi-Layer Encryption Protection

By building a multi-level rainbow table and task scheduling mechanism, combined with hardware resources, the problem that rainbow tables in the existing technology cannot efficiently crack multi-level encryption algorithms, and an efficient and flexible password decryption process is achieved.

CN120145425BActive Publication Date: 2025-07-11JINAN LANJIANJUN NEW INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510621602.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-15
Publication Date
2025-07-11
Estimated Expiration
2045-05-15

AI Technical Summary

Technical Problem

The existing rainbow table technology cannot efficiently crack multi-level encryption algorithms, especially complex modern encryption algorithms and hashing algorithms that use salting mechanisms, making it difficult to meet the needs of efficient decryption.

Method used

A multi-level rainbow table is built, including a first-level rainbow table and a second-level rainbow table, which are used for common single-layer and complex single-layer encryption algorithms respectively. It adopts a hierarchical storage and task object recognition mechanism, and combines hardware resources such as multi-core CPU, GPU, and TPU for decryption task scheduling to achieve fast matching and efficient decryption.

Benefits of technology

Through multi-level rainbow tables and precise task scheduling, the password cracking speed is significantly improved, resource utilization is improved, and decryption tasks of different scales and complexities are adapted to decryption tasks, ensuring efficient decryption and scalability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120145425B_ABST
    Figure CN120145425B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of information security technology, and specifically to a method for decrypting and scheduling rainbow tables based on multi-layer encryption protection. Through the hierarchical storage of multi-level rainbow tables and storage modules, combined with an accurate task target recognition and matching mechanism, the present invention effectively accelerates the decryption process. By identifying the optimal subclass of rainbow tables based on information such as the encrypted hash value, length, and encryption algorithm of the password, the decryption algorithm for the target password can be quickly matched, greatly improving the speed of password cracking. The present invention adopts a task scheduling and allocation mechanism based on the degree of matching, which can reasonably allocate computing resources according to the priority of decryption tasks. Low-priority tasks preferentially use basic decryption units, while high-priority tasks use dedicated hardware acceleration modules, effectively improving the utilization rate of resources and ensuring that high-priority tasks are processed in a timely manner.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to a rainbow table decryption and scheduling method based on multi-layer encryption protection. Background Art

[0002] With the rapid development of information technology, data security and privacy protection have become important issues that need to be solved in modern society. Various encryption technologies are widely used in network security, financial transactions, communication transmission and other fields to ensure the security of sensitive information. However, although these encryption algorithms can effectively improve the security of data protection, they also bring technical challenges to cracking these encryptions.

[0003] As a common encryption method, hash encryption algorithm is widely used in scenarios such as password storage, data integrity verification, and digital signatures. The hash algorithm maps the input data (such as passwords) to a hash value of fixed length, making it almost impossible to reverse the original data. Common hash algorithms include MD5, SHA-1, SHA-256, etc. Although these algorithms guarantee data security to a certain extent, they also have the risk of being cracked, especially when simple salting or no salting is used.

[0004] Rainbow table is a technology that quickly cracks hash passwords by pre-calculating the correspondence between common passwords and their hash values. It speeds up the cracking process by reducing the amount of calculation and using time and space in exchange for time. However, the traditional rainbow table method can only crack a single encryption algorithm, and has limited effect on complex modern encryption algorithms (such as AES, RSA, etc.) or hash algorithms that use a salting mechanism.

[0005] With the continuous development of encryption technology, more and more encryption methods have adopted multi-level protection strategies. For example, a password may be encrypted multiple times or protected using different encryption algorithms. To address this problem, existing rainbow table technology usually cannot meet the needs of efficient decryption. Therefore, how to improve the efficiency of rainbow table cracking and be able to cope with the cracking of complex encryption algorithms has become an urgent problem to be solved in the field of cryptography.

[0006] In view of the above problems, it is necessary to propose a rainbow table decryption and scheduling method based on multi-layer encryption protection. Summary of the invention

[0007] The purpose of the present invention is to solve the problems existing in the background technology and to propose a rainbow table decryption and scheduling method based on multi-layer encryption protection.

[0008] The purpose of the present invention can be achieved through the following technical solutions:

[0009] A rainbow table decryption and scheduling method based on multi-layer encryption protection, specifically including the following steps:

[0010] Step 1: Rainbow table construction and hierarchical storage;

[0011] Construct multiple levels of rainbow tables according to different encryption algorithms, including:

[0012] First-level rainbow table: It includes first-level rainbow table subclasses for common single-layer encryption algorithms. Among them, the first-level rainbow table subclasses include rainbow tables for encryption algorithms including DES, MD5, and SHA-1;

[0013] The described first-level rainbow table is applicable to traditional single-layer hash encryption algorithms and is used to crack scenarios without salting or using simple encryption.

[0014] Second-level rainbow table: It includes second-level rainbow table subclasses for complex single-layer encryption algorithms. Among them, the second-level rainbow table subclasses include rainbow tables for algorithms such as SHA-256, AES, RSA, PBKDF2, Argon2, and bcrypt;

[0015] The described second-level rainbow table is applicable to modern encryption algorithms and hash algorithms using the salting mechanism.

[0016] As a preferred embodiment of the present invention, the first-level rainbow table and the second-level rainbow table are hierarchically stored. The first-level rainbow table is stored in the first storage module, and the second-level rainbow table is stored in the second storage module.

[0017] The described first storage module includes a solid-state drive SSD and memory to provide fast response.

[0018] The described second storage module includes a hard disk array and a cloud storage server array to meet the requirements of query scheduling allocation and expandable storage space. The first storage module and the second storage module establish indexes for the mapping relationship of each encryption algorithm and the second-level rainbow table.

[0019] Step 2: Task target identification and multi-level rainbow table matching;

[0020] Analyze the ciphertext format data of the input password based on the rainbow table matching algorithm, identify the encryption method, determine the target password to be decrypted and its corresponding encryption level, and match to the corresponding rainbow table subclass in the first-level rainbow table or the second-level rainbow table.

[0021] The described ciphertext format data includes: the encrypted hash value of the password, the password length, the encryption timestamp, and the public key length;

[0022] As a preferred embodiment of the present invention, through the rainbow table matching algorithm, the ciphertext format data of the same group of passwords is analyzed to infer its encryption method, and the specific first-level or second-level rainbow table subclass is matched through the mapping relationship index. The specific process is as follows:

[0023] Obtain the hash value sequence Ci = {C1, C2,..., Cn} of this group of passwords C; where C1, C2,..., Cn are the specific hash values of each password; where n is the total number of passwords included in this group of passwords, and through a preset formula Calculate each byte Distribution frequency ; where Is the total number of occurrences of byte In all passwords, where L(Ci) is the number of bytes included in Ci in the hash value sequence, Is the total byte length of all hash values included in this group of passwords.

[0024] As a preferred embodiment of the present invention, through a preset formula Calculate the matching degree f(C, A) between this group of passwords C and the first-level or second-level rainbow table subclass A, where A represents a specific first-level or second-level rainbow table subclass; where D(C, A) is the byte distribution deviation between this group of passwords and the first-level or second-level rainbow table subclass A, where Is the ideal byte distribution of byte In the preset first-level or second-level rainbow table subclass A, where H(C) is the ciphertext entropy of this group of passwords C, which is a measure of the uncertainty of this group of passwords and represents the randomness of this group of passwords. The higher the ciphertext entropy, the stronger the encryption algorithm. Simple encryption algorithms have lower ciphertext entropy values; where f(C, A) represents the matching degree between this group of passwords C and the first-level or second-level rainbow table subclass A; where λ1 and λ2 are preset weight factors and dimension unification factors, which respectively control the influence of byte distribution deviation and ciphertext entropy, and unify The computational dimensions of the two operators; where α and β are preset weight coefficients, which control the contribution of each feature to the matching degree; where Is the reference ciphertext entropy of the preset first-level or second-level rainbow table subclass A.

[0025] Obtain the matching degree f(C, A) between this group of passwords C and each first-level or second-level rainbow table subclass A. The higher the matching degree, the higher the probability that the group of passwords C is the encryption output of the encryption algorithm corresponding to the first-level or second-level rainbow table subclass A. Denote the first-level or second-level rainbow table subclass A with the largest matching degree f(C, A) as the optimal matching subclass A-best of this group of passwords; Denote the first-level or second-level rainbow table subclass A with the second largest matching degree f(C, A) as the sub-optimal matching subclass A-second of this group of passwords;

[0026] As a preferred embodiment of the present invention, the calculation of the matching degree f(C, A) traverses all target password groups to obtain the optimal matching subclass and the sub-optimal matching subclass of each group of passwords.

[0027] Step 3: Decryption task scheduling and allocation;

[0028] Collect the optimal matching subclass and the sub-optimal matching subclass of each target password group, as well as the matching degrees f(C, A-best) and f(C, A-second) with the optimal matching subclass and the sub-optimal matching subclass, and perform decryption task scheduling and allocation to arrange the decryption work, so as to improve the decryption efficiency and ensure the accuracy of the decryption rainbow table selection.

[0029] For the password groups where the matching degrees f(C, A-best) and f(C, A-second) of the optimal matching subclass and the sub-optimal matching subclass are both greater than the maximum preset threshold, it is determined that the probability of belonging to the optimal matching subclass and the sub-optimal matching subclass is relatively large. Decryption can be completed through a small number of comparisons, and less computing resources are required. Mark the decryption task of the password group as a low-priority decryption task.

[0030] For the password groups where the matching degrees f(C, A-best) and f(C, A-second) of the optimal matching subclass and the sub-optimal matching subclass are both less than the minimum preset threshold, it is determined that the probability of belonging to the optimal matching subclass and the sub-optimal matching subclass is relatively small. There is a deviation in the determination of the encryption method for such password groups. Decryption can only be completed through a large number of subsequent replacements and iterations of the optimal matching subclass and the sub-optimal matching subclass. It is difficult to directly infer the accurate encryption algorithm based on the existing matching degree, and it is also difficult to directly complete the decryption task through the rainbow table of the optimal matching subclass and the sub-optimal matching subclass. Therefore, for these password groups, it is determined that their decryption tasks require subsequent adjustment and iteration, and more computing resources are required. Mark the decryption task of the password group as a high-priority decryption task.

[0031] For other password groups, mark them as general-priority decryption tasks.

[0032] Step 4: Computing resource scheduling;

[0033] Perform computing resource scheduling for low-priority decryption tasks, high-priority decryption tasks, and general-priority decryption tasks.

[0034] Sort all decryption tasks according to the average of the matching degrees f(C, A - best) and f(C, A - second) of the optimal matching subclass and the sub - optimal matching subclass. Generate a task queue in the order of the average of the matching degrees f(C, A - best) and f(C, A - second) of the sub - optimal matching subclass from large to small. Mark the first U decryption tasks in the task queue as execution tasks and input them into the operation module. The operation module includes a basic decryption unit, a general decryption unit, a fast decryption unit, and an advanced decryption unit. Identify the proportion of each priority level among the decryption tasks marked as execution tasks in the task queue.

[0035] The described basic decryption unit includes: a multi - core CPU and a memory;

[0036] The described general decryption unit includes: a multi - core medium - frequency CPU, a GPU tensor processing unit, a memory, and an SSD high - speed solid - state drive;

[0037] The described fast decryption unit includes: a multi - core high - frequency CPU, a GPU tensor processing unit, a TPU dedicated acceleration hardware, and an SSD high - speed solid - state drive.

[0038] The described advanced decryption unit includes: a multi - core high - frequency CPU, a GPU tensor processing unit, a TPU dedicated acceleration hardware, an SSD high - speed solid - state drive, and an FPGA custom - programmed integrated circuit for decryption.

[0039] If the proportion of low - priority decryption tasks is greater than 1 / 3, initiate collaborative docking between the first storage module and the basic decryption unit, and initiate collaborative docking between the second storage module and the general decryption unit;

[0040] If the proportion of medium - priority decryption tasks is greater than 1 / 3, initiate collaborative docking between the first storage module and the general decryption unit, and initiate collaborative docking between the second storage module and the fast decryption unit.

[0041] If the proportion of high - priority decryption tasks is greater than 1 / 3, initiate collaborative docking between the first storage module and the fast decryption unit, and initiate collaborative docking between the second storage module and the advanced decryption unit.

[0042] The described collaborative docking is specifically a dedicated high - speed data transfer interface, a dedicated high - speed storage access protocol, and a task scheduling framework.

[0043] As a preferred embodiment of the present invention, use a performance monitoring tool to detect the usage data of CPU, GPU, memory, and storage resources in the basic decryption unit, general decryption unit, fast decryption unit, and advanced decryption unit.

[0044] Step Five: Decryption result verification and algorithm iteration;

[0045] After the decryption task is completed, the decryption results of low-priority decryption tasks, high-priority decryption tasks, and normal-priority decryption tasks are verified. First, the plaintext obtained by decryption is compared with the known plaintext in the password library for matching verification. If the decryption result matches the corresponding plaintext in the password library, the decryption is determined to be successful; if the corresponding password original text cannot be matched in the corresponding rainbow tables of the optimal matching subclass and the sub-optimal matching subclass, the task result is determined to be decryption failure, and iterative decryption is performed.

[0046] If the results of low-priority, normal-priority, and high-priority decryption tasks are decryption failures, they are marked as "tasks to be reprocessed", replacing the optimal matching subclass and the sub-optimal matching subclass, and returning to step four to re-execute the computing resource scheduling and password group decryption.

[0047] Compared with the prior art, the beneficial effects of the present invention are:

[0048] 1. Through the hierarchical storage of the multi-level rainbow table and the storage module, combined with the accurate task target recognition and matching mechanism, the present invention effectively speeds up the decryption process. By identifying the optimal rainbow table subclass according to information such as the encrypted hash value, length, and encryption algorithm of the password, the decryption algorithm of the target password can be quickly matched, greatly improving the speed of password cracking;

[0049] 2. The present invention adopts a task scheduling and allocation mechanism based on the matching degree, which can reasonably allocate computing resources according to the priority of the decryption task. Low-priority tasks preferentially use basic decryption units, while high-priority tasks use dedicated hardware acceleration modules (such as TPU and FPGA), effectively improving the resource utilization rate and ensuring that high-priority tasks are processed in a timely manner;

[0050] 3. The multi-storage module design of the present invention, including SSD, hard disk array, and cloud storage server, can be flexibly scheduled according to task requirements. Whether it is a small-scale single-layer encryption cracking or a complex multi-layer encryption cracking, the system can be dynamically allocated according to storage requirements and computing capabilities, with strong scalability, meeting decryption tasks of different scales and complexities. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] For the convenience of those skilled in the art to understand, the present invention will be further described below with reference to the accompanying drawings:

[0052] Figure 1 is the method flow chart of the present invention; DETAILED DESCRIPTION OF THE INVENTION

[0053] The technical solution of the present invention will be clearly and completely described below in conjunction with the embodiments. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the scope of protection of the present invention.

[0054] Please refer to Figure 1 As shown, a rainbow table decryption and scheduling method based on multi-layer encryption protection specifically includes the following steps:

[0055] Step 1: Rainbow table construction and hierarchical storage;

[0056] Construct multiple levels of rainbow tables according to different encryption algorithms, including:

[0057] Level 1 rainbow table: It includes subclasses of level 1 rainbow tables for common single-layer encryption algorithms. Among them, the subclasses of level 1 rainbow tables include rainbow tables for DES, MD5, and SHA-1 encryption algorithms;

[0058] The described level 1 rainbow table is applicable to traditional single-layer hash encryption algorithms and is used to crack scenarios without salting or with simple encryption.

[0059] It should be noted that the single-layer hash encryption algorithms corresponding to the level 1 rainbow table are based on the fact that these rainbow tables can quickly find and decrypt passwords under a single encryption algorithm by storing the corresponding relationship between the hash values of common passwords and plaintext passwords. The level 1 rainbow table occupies less space, has a simple storage structure, and is frequently queried, making it suitable for efficient query and fast decryption.

[0060] Level 2 rainbow table: It includes subclasses of level 2 rainbow tables for complex single-layer encryption algorithms. Among them, the subclasses of level 2 rainbow tables include rainbow tables for SHA-256, AES, RSA, PBKDF2, Argon2, and bcrypt algorithms;

[0061] It should be noted that different from the level 1 rainbow table, the level 2 rainbow table deals with more complex encryption methods, including SHA-256, AES, and other modern encryption algorithms. For these encryption algorithms, the stored hash values include not only simple password mappings but also information such as keys, salt values, and specific configurations of encryption algorithms. Therefore, the construction and storage structure of the level 2 rainbow table are more complex and the storage requirements are larger. However, for high-security encryption algorithms, it is still an effective acceleration tool, especially when combined with hardware acceleration based on GPU computing, which can significantly improve the cracking speed.

[0062] The described level 2 rainbow table is applicable to modern encryption algorithms and hash algorithms using the salting mechanism.

[0063] Further, the first-level rainbow table and the second-level rainbow table are stored in a hierarchical manner. The first-level rainbow table is stored in the first storage module, and the second-level rainbow table is stored in the second storage module.

[0064] The first storage module includes a solid-state drive (SSD) and memory to provide fast response.

[0065] The second storage module includes a hard disk array and a cloud storage server array to meet the requirements of query scheduling allocation and expandable storage space. The first storage module and the second storage module establish indexes for the mapping relationship of each encryption algorithm and the second-level rainbow table.

[0066] Step 2: Task objective recognition and multi-level rainbow table matching;

[0067] Based on the rainbow table matching algorithm, analyze the ciphertext format data of the input password, identify the encryption method, determine the target password to be decrypted and its corresponding encryption level, and match to the corresponding rainbow table subclass in the first-level rainbow table or the second-level rainbow table.

[0068] The ciphertext format data includes: the encrypted hash value of the password, the password length, the encryption timestamp, and the public key length;

[0069] It should be noted that among them, the encrypted hash value of the password is the final output of password encryption; the password length is the number of bytes of the final output password. Specifically, the correspondence between common encryption algorithms and password lengths is as follows: MD5: usually 32 bytes; SHA-1: usually 40 bytes; SHA-256: usually 64 bytes; AES: 16, 24, or 32 bytes according to the key length; RSA: the ciphertext length is usually half of the key length.

[0070] It should be further noted that passwords encrypted by the same encryption method can have different lengths, especially when the encryption algorithm uses variable-length inputs (such as salt values, initialization vectors) or multi-layer encryption. The length of the ciphertext usually depends on the length of the plaintext, the type and configuration of the encryption algorithm, and whether additional parameters are used. For example, for encryption modes (such as CBC, ECB), if the length of the plaintext is not an integer multiple of the block size, the algorithm will perform padding, so the length of the output ciphertext may vary. Especially when dealing with plaintexts of different lengths, the padding will vary according to the length of the plaintext. However, the length distribution of the ciphertext is closely related to the characteristics of the encryption method, the nature of the input data, and the encryption parameters, and has a certain statistical pattern, usually changing based on integer multiples of the block size. If the length of the input plaintext is relatively dispersed, the statistical distribution of the ciphertext length will show a certain statistical pattern. For example, the byte distribution of AES ciphertext is usually more uniform.

[0071] Further, through the described rainbow table matching algorithm, analyze the ciphertext format data of the same set of passwords, infer their encryption methods, and index and match to specific first-level or second-level rainbow table subclasses through the mapping relationship. The specific process is as follows:

[0072] Obtain the hash value sequence Ci = {C1, C2,..., Cn} of this set of passwords C; where C1, C2,..., Cn are the specific hash values of each password; where n is the total number of passwords included in this set of passwords, and calculate each byte through a preset formula distribution frequency ; where is the total number of occurrences of byte in all passwords, where L(Ci) is the number of bytes included in Ci in the hash value sequence, is the total byte length of all hash values included in this set of passwords;

[0073] Calculate the matching degree f(C, A) between this set of passwords C and the first-level or second-level rainbow table subclass A through a preset formula , where A represents a specific first-level or second-level rainbow table subclass; where D(C, A) is the byte distribution deviation between this set of passwords and the first-level or second-level rainbow table subclass A, where is the ideal byte distribution of byte in the preset first-level or second-level rainbow table subclass A, where H(C) is the ciphertext entropy of this set of passwords C, which is a measure of the uncertainty of this set of passwords and represents the randomness of this set of passwords. The higher the ciphertext entropy, the stronger the encryption algorithm. Simple encryption algorithms have lower ciphertext entropy values; where f(C, A) represents the matching degree between this set of passwords C and the first-level or second-level rainbow table subclass A; where λ1 and λ2 are preset weight factors and dimension unification factors, which respectively control the influence of byte distribution deviation and ciphertext entropy, and unify the computational dimensions of the two operators; where α and β are preset weight coefficients, which control the contribution of each feature to the matching degree; where is the reference ciphertext entropy of the preset first-level or second-level rainbow table subclass A.

[0074] Obtain the matching degree f(C, A) between this set of passwords C and each first-level or second-level rainbow table subclass A. The higher the matching degree, the higher the probability that the set of passwords C is the encrypted output of the encryption algorithm corresponding to the first-level or second-level rainbow table subclass A. Denote the first-level or second-level rainbow table subclass A with the largest matching degree f(C, A) as the optimal matching subclass A-best of this set of passwords; denote the first-level or second-level rainbow table subclass A with the second largest matching degree f(C, A) as the sub-optimal matching subclass A-second of this set of passwords;

[0075] Further, the calculation of the matching degree f(C, A) is traversed through all target password groups to obtain the optimal matching subclass and the sub-optimal matching subclass of each group of passwords.

[0076] Step 3: Decryption task scheduling and allocation;

[0077] Collect the optimal matching subclass and the sub-optimal matching subclass of each target password group, as well as the matching degrees f(C, A-best) and f(C, A-second) with the optimal matching subclass and the sub-optimal matching subclass, and perform decryption task scheduling and allocation to arrange the decryption work, so as to improve the decryption efficiency and ensure the accuracy of the selection of the decryption rainbow table.

[0078] For the password groups where the matching degrees f(C, A-best) and f(C, A-second) of the optimal matching subclass and the sub-optimal matching subclass are both greater than the maximum preset threshold, it is determined that the probability of belonging to the optimal matching subclass and the sub-optimal matching subclass is relatively large, and the decryption can be completed through a small number of comparisons, and less computing resources are called. Mark the decryption task of the password group as a low-priority decryption task.

[0079] For the password groups where the matching degrees f(C, A-best) and f(C, A-second) of the optimal matching subclass and the sub-optimal matching subclass are both less than the minimum preset threshold, it is determined that the probability of belonging to the optimal matching subclass and the sub-optimal matching subclass is relatively small. It is determined that there is a deviation in the encryption method of this type of password group, and the decryption can only be completed through a large number of subsequent replacements and iterations of the optimal matching subclass and the sub-optimal matching subclass. It is difficult to directly infer the accurate encryption algorithm based on the existing matching degree, and it is also difficult to directly complete the decryption task through the rainbow table of the optimal matching subclass and the sub-optimal matching subclass. Therefore, for these password groups, it is determined that their decryption tasks need subsequent adjustment and iteration, and more computing resources are called. Mark the decryption task of the password group as a high-priority decryption task.

[0080] For other password groups, mark them as general-priority decryption tasks.

[0081] Step 4: Computing resource scheduling;

[0082] Perform computing resource scheduling for low-priority decryption tasks, high-priority decryption tasks, and general-priority decryption tasks.

[0083] Sort all decryption tasks according to the average of the matching degrees f(C, A-best) and f(C, A-second) of the optimal matching subclass and the sub-optimal matching subclass, generate a task queue in the order from large to small of the average of the matching degrees f(C, A-best) and f(C, A-second) of the sub-optimal matching subclass, mark the first U decryption tasks in the task queue as execution tasks, and input them into the operation module. The operation module includes a basic decryption unit, a general decryption unit, a fast decryption unit, and an advanced decryption unit. Identify the proportion of each priority level among the decryption tasks marked as execution tasks in the task queue.

[0084] The described basic decryption unit includes: a multi-core CPU and a memory;

[0085] The described general decryption unit includes: a multi-core medium-frequency CPU, a GPU tensor processing unit, a memory, and an SSD high-speed solid-state drive;

[0086] The described fast decryption unit includes: a multi-core high-frequency CPU, a GPU tensor processing unit, a TPU dedicated acceleration hardware, and an SSD high-speed solid-state drive.

[0087] The described advanced decryption unit includes: a multi-core high-frequency CPU, a GPU tensor processing unit, a TPU dedicated acceleration hardware, an SSD high-speed solid-state drive, and an FPGA decryption dedicated custom programming integrated circuit.

[0088] It should be noted that TPU is a hardware accelerator specifically for machine learning and complex computing tasks, and is suitable for decryption tasks that require a large amount of matrix calculations and high-concurrency tasks. TPU acceleration is used for high-priority tasks, especially deep learning acceleration and complex multi-layer encryption and decryption operations.

[0089] If the proportion of low-priority decryption tasks is greater than 1 / 3, start collaborative docking between the first storage module and the basic decryption unit, and start collaborative docking between the second storage module and the general decryption unit;

[0090] If the proportion of medium-priority decryption tasks is greater than 1 / 3, start collaborative docking between the first storage module and the general decryption unit, and start collaborative docking between the second storage module and the fast decryption unit.

[0091] If the proportion of high-priority decryption tasks is greater than 1 / 3, start collaborative docking between the first storage module and the fast decryption unit, and start collaborative docking between the second storage module and the advanced decryption unit.

[0092] The described collaborative docking is specifically a dedicated high-speed data transmission interface, a dedicated high-speed storage access protocol, and a task scheduling framework.

[0093] Further, use a performance monitoring tool to detect the usage data of CPU, GPU, memory, and storage resources in the basic decryption unit, general decryption unit, fast decryption unit, and advanced decryption unit.

[0094] Step Five: Decryption Result Verification and Algorithm Iteration;

[0095] After the decryption task is completed, verify the decryption results of low-priority decryption tasks, high-priority decryption tasks, and general-priority decryption tasks. First, perform matching verification by comparing the plaintext obtained by decryption with the known plaintext in the password library. If the decryption result matches the corresponding plaintext in the password library, it is determined that the decryption is successful; if the corresponding ciphertext cannot be matched in the corresponding rainbow tables of the optimal matching subclass and the sub-optimal matching subclass, it is determined that the task result is decryption failure, and iterative decryption is performed.

[0096] If the results of low-priority, general-priority, and high-priority decryption tasks are decryption failures, mark them as "tasks to be reprocessed", replace the optimal matching subclass and the sub-optimal matching subclass, and return to Step Four to re-execute the computing resource scheduling and password group decryption.

[0097] It should be understood that the terms "including" and "comprising" used in the specification and claims of this disclosure indicate the presence of the described features, wholes, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or their combinations.

[0098] It should also be understood that the terms used in this disclosure specification are only for the purpose of describing specific embodiments and are not intended to limit this disclosure. As used in this disclosure specification and claims, unless the context clearly indicates otherwise, the singular forms "a", "an", and "the" are intended to include the plural forms. It should be further understood that the term "and / or" used in this disclosure specification and claims refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations;

[0099] The preferred embodiments of the present invention disclosed above are only used to help explain the present invention. The preferred embodiments do not elaborate on all details and do not limit the present invention to only the specific embodiments. Obviously, many modifications and variations can be made according to the content of this specification. The present specification selects and specifically describes these embodiments to better explain the principles and practical applications of the present invention, so that those skilled in the art can understand and utilize the present invention well. The present invention is only limited by the claims and their full scope and equivalents.

Claims

1. A rainbow table decryption and scheduling method based on multi-layer encryption protection, characterized in that, It includes the following steps: Step 1, Rainbow table construction and hierarchical storage; Construct multiple levels of rainbow tables according to different encryption algorithms, including a first-level rainbow table and a second-level rainbow table, and store them in different storage modules respectively. The first-level rainbow table is applicable to traditional single-layer hash encryption algorithms, and the second-level rainbow table is applicable to modern encryption algorithms and salted hash algorithms. The storage module is hierarchically classified according to storage requirements to provide efficient query and decryption support; Step 2, Task target identification and multi-level rainbow table matching; Analyze the input ciphertext format data, identify the encryption method and determine the decryption target, match the corresponding first-level or second-level rainbow table subclass, calculate the matching degree of the password through a preset formula, and select the optimal and sub-optimal matching subclasses; Step 3, Decryption task scheduling and allocation; Divide the decryption tasks of each target password group into priorities according to the matching degree, and perform decryption task scheduling and allocation to improve the decryption efficiency and ensure the selection of the correct rainbow table for decryption; Step 4, Computing resource scheduling; According to the priority of the task, schedule computing resources and reasonably allocate them to basic decryption units, general decryption units, fast decryption units and advanced decryption units to ensure efficient resource utilization and task execution; Step 5, Decryption result verification and algorithm iteration; Verify the decryption result. By matching the plaintext in the known password library, judge whether the decryption task is successful. If the decryption fails, process the iterative decryption task and return to the resource scheduling step for adjustment.

2. The rainbow table decryption and scheduling method based on multi-layer encryption protection according to claim 1, characterized in that, The specific first-level rainbow table and second-level rainbow table are as follows: First-level rainbow table: It includes first-level rainbow table subclasses for common single-layer encryption algorithms. Among them, the first-level rainbow table subclasses include rainbow tables for DES, MD5 and SHA-1 encryption algorithms; The first-level rainbow table is applicable to traditional single-layer hash encryption algorithms and is used to crack scenarios without salt or with simple encryption; Second-level rainbow table: It includes second-level rainbow table subclasses for complex single-layer encryption algorithms. Among them, the second-level rainbow table subclasses include rainbow tables for SHA-256, AES, RSA, PBKDF2, Argon2 and bcrypt algorithms; The second-level rainbow table is applicable to modern encryption algorithms and hash algorithms using the salt mechanism; Perform hierarchical storage on the first-level rainbow table and the second-level rainbow table, store the first-level rainbow table in the first storage module, and store the second-level rainbow table in the second storage module.

3. A rainbow table decryption and scheduling method based on multi-layer encryption protection according to claim 2, characterized in that, The first storage module and the second storage module include: The first storage module includes a solid-state drive SSD and memory to provide fast response; The second storage module includes a hard disk array and a cloud storage server array to meet the requirements of query scheduling allocation and expandable storage space; the first storage module and the second storage module establish indexes for the mapping relationship of each encryption algorithm and the second-level rainbow table.

4. A rainbow table decryption and scheduling method based on multi-layer encryption protection according to claim 1, characterized in that, The specific process of analyzing the input ciphertext format data is as follows: Through the rainbow table matching algorithm, analyze the ciphertext format data of the same group of passwords, infer its encryption method, and match the specific first-level or second-level rainbow table subclass through the mapping relationship index. The specific process is as follows: Obtain the hash value sequence Ci = {C1, C2,..., Cn} of the set of passwords C; where C1, C2,..., Cn are the specific hash values of each password; where n is the total number of passwords included in the set of passwords, through a preset formula Calculate each byte The distribution frequency of ; where Is the byte The total number of occurrences in all passwords, where L(Ci) is the number of bytes included in Ci in the hash value sequence, Is the total byte length of all hash values included in the set of passwords; Through a preset formula Calculate the matching degree f(C, A) between the password group C and the first-level or second-level rainbow table subclass A, where A represents a specific first-level or second-level rainbow table subclass; where D(C, A) is the byte distribution deviation between the password group and the first-level or second-level rainbow table subclass A, where is the ideal byte distribution of the byte in the preset first-level or second-level rainbow table subclass A, where H(C) is the ciphertext entropy of the password group C, which is a measure of the uncertainty of the password group and represents the randomness of the password group. The higher the ciphertext entropy, the stronger the encryption algorithm. A simple encryption algorithm has a lower ciphertext entropy value; where f(C, A) represents the matching degree between the password group C and the first-level or second-level rainbow table subclass A; where λ1 and λ2 are preset weight factors and dimension unification factors, which respectively control the influence of the byte distribution deviation and the ciphertext entropy, and unify the computational dimensions of the two operators; where α and β are preset weight coefficients, which control the contribution of each feature to the matching degree; where is the reference ciphertext entropy of the preset first-level or second-level rainbow table subclass A; Determine the optimal matching subclass and the sub-optimal matching subclass according to the matching degree.

5. A rainbow table decryption and scheduling method based on multi-layer encryption protection according to claim 1, characterized in that, The specific process of determining the optimal matching subclass and the sub-optimal matching subclass according to the matching degree is as follows: Obtain the matching degree f(C, A) between the group password C and each first-level or second-level rainbow table subclass A. The higher the matching degree, the higher the probability that the group password C is the encrypted output of the encryption algorithm corresponding to the first-level or second-level rainbow table subclass A. Denote the first-level or second-level rainbow table subclass A with the maximum matching degree f(C, A) as the optimal matching subclass A-best of the group password; denote the first-level or second-level rainbow table subclass A with the second-largest matching degree f(C, A) as the sub-optimal matching subclass A-second of the group password. Traverse all target password groups to calculate the matching degree f(C, A), and obtain the optimal matching subclass and sub-optimal matching subclass of each group of passwords.

6. A rainbow table decryption and scheduling method based on multi-layer encryption protection according to claim 1, characterized in that, The specific process of decrypting task scheduling and allocation is as follows: Collect the optimal matching subclass and sub-optimal matching subclass of each target password group, as well as the matching degrees f(C, A-best) and f(C, A-second) with the optimal matching subclass and sub-optimal matching subclass, and perform decrypting task scheduling and allocation to arrange the decrypting work, so as to improve the decrypting efficiency and ensure the accuracy of the selected decrypting rainbow table. For the password groups where the matching degrees f(C, A-best) and f(C, A-second) of the optimal matching subclass and sub-optimal matching subclass are both greater than the maximum preset threshold, mark the decrypting tasks of these password groups as low-priority decrypting tasks. For the password groups where the matching degrees f(C, A-best) and f(C, A-second) of the optimal matching subclass and sub-optimal matching subclass are both less than the minimum preset threshold, it is determined that there is a deviation in the encryption method determination of these password groups. Decryption can only be completed through a large number of subsequent replacements and iterations of the optimal matching subclass and sub-optimal matching subclass. It is difficult to directly infer the accurate encryption algorithm based on the existing matching degree, and it is also difficult to directly complete the decrypting task through the rainbow table of the optimal matching subclass and sub-optimal matching subclass. Therefore, for these password groups, it is determined that their decrypting tasks require subsequent adjustment and iteration, and mark the decrypting tasks of these password groups as high-priority decrypting tasks. For other password groups, mark them as normal-priority decrypting tasks. Perform computing resource scheduling for low-priority decrypting tasks, high-priority decrypting tasks, and normal-priority decrypting tasks.

7. A rainbow table decryption and scheduling method based on multi-layer encryption protection according to claim 1, characterized in that, The specific process of performing computing resource scheduling for low-priority decrypting tasks, high-priority decrypting tasks, and normal-priority decrypting tasks is as follows: Sort all decrypting tasks according to the average value of the matching degrees f(C, A-best) and f(C, A-second) of the optimal matching subclass and sub-optimal matching subclass. Generate a task queue in the order from large to small of the average value of the matching degrees f(C, A-best) and f(C, A-second) of the sub-optimal matching subclass. Mark the first U decrypting tasks in the task queue as execution tasks and input them into the operation module. The operation module includes a basic decrypting unit, a general decrypting unit, a fast decrypting unit, and an advanced decrypting unit; identify the proportion of each priority in the decrypting tasks marked as execution tasks in the task queue. Initiate cooperative docking according to the proportion of priority decrypting tasks.

8. A rainbow table decryption and scheduling method based on multi-layer encryption protection according to claim 7, characterized in that: The basic decryption unit includes: a multi-core CPU and a memory; The general decryption unit includes: a multi-core medium-frequency CPU, a GPU tensor processing unit, a memory, and an SSD high-speed solid-state drive; The fast decryption unit includes: a multi-core high-frequency CPU, a GPU tensor processing unit, a TPU dedicated acceleration hardware, and an SSD high-speed solid-state drive; The advanced decryption unit includes: a multi-core high-frequency CPU, a GPU tensor processing unit, a TPU dedicated acceleration hardware, an SSD high-speed solid-state drive, and an FPGA custom programming integrated circuit dedicated for decryption.

9. A rainbow table decryption and scheduling method based on multi-layer encryption protection according to claim 8, characterized in that, The specific process of starting cooperative docking according to the proportion of priority decryption tasks is as follows: If the proportion of low-priority decryption tasks is greater than 1 / 3, start cooperative docking between the first storage module and the basic decryption unit, and start cooperative docking between the second storage module and the general decryption unit; If the proportion of medium-priority decryption tasks is greater than 1 / 3, start cooperative docking between the first storage module and the general decryption unit, and start cooperative docking between the second storage module and the fast decryption unit; If the proportion of high-priority decryption tasks is greater than 1 / 3, start cooperative docking between the first storage module and the fast decryption unit, and start cooperative docking between the second storage module and the advanced decryption unit; The said cooperative docking is specifically a dedicated high-speed data transmission interface, a dedicated high-speed storage access protocol, and a task scheduling framework.

10. A rainbow table decryption and scheduling method based on multi-layer encryption protection according to claim 1, characterized in that, The specific process of decrypting result verification and algorithm iteration is as follows: After the decryption task is completed, decrypting result verification is performed on low-priority decryption tasks, high-priority decryption tasks, and medium-priority decryption tasks. First, match verification is performed by comparing the plaintext obtained by decryption with the known plaintext in the password library; If the decryption result matches the corresponding plaintext in the password library, it is determined that the decryption is successful; if the corresponding password original text cannot be matched in the corresponding rainbow tables of the optimal matching subclass and the sub-optimal matching subclass, it is determined that the task result is decryption failure, and iterative decryption is performed; If the results of low-priority, medium-priority, and high-priority decryption tasks are decryption failures, mark them as "tasks to be reprocessed", replace the optimal matching subclass and the sub-optimal matching subclass, and return to step four to re-execute the computing resource scheduling and password group decryption.

Citation Information

Patent Citations

  • Encryption and analysis system based on distributed GPU and rainbow table and method of encryption and analysis system

    CN103714300A

  • Excel ciphertext document recovery method, computer equipment and storage medium

    CN112287374A