A data security encryption method

By constructing an encryption key matrix for image channel value exchange and feature vectors, and generating perturbation sequences with hashing algorithms, high-security image encryption is achieved, and the problem of low encryption security in the prior art is solved.

CN120151454BActive Publication Date: 2025-08-01CHENGDU AERONAUTIC POLYTECHNIC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510630208.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-16
Publication Date
2025-08-01
Estimated Expiration
2045-05-16

AI Technical Summary

Technical Problem

The encryption security of existing image encryption technology is low, the key space is limited, and it is easy to be cracked by attackers.

Method used

The plain text image is divided into R, G, and B channels, and the channel values of adjacent rows and columns are exchanged, the eigenvalues of pixels are extracted to construct eigenvectors, the regions are divided to generate first and second encryption key matrices, and the hashing algorithm is used to generate perturbation sequences, and multiple encryption and fuse channel data.

Benefits of technology

It greatly expands the key space, improves the security of encryption, reduces the possibility of attackers cracking keys, and enhances the security of image data during transmission and storage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120151454B_ABST
    Figure CN120151454B_ABST
Patent Text Reader

Abstract

The present invention discloses a data security encryption method, belonging to the technical field of image encryption. First, the plaintext image is divided into R, G, and B channels, and the scrambled and inverse channels image is obtained by exchanging the channel values of adjacent rows and columns; then, the local and global feature values of each pixel point in the channel plaintext image and the scrambled and inverse channels image are extracted to construct a feature vector; next, the scrambled and inverse channels image is partitioned, and the first and second encryption key matrices of each region are obtained according to the feature vector; finally, each region is encrypted multiple times using the key matrix, and the three encrypted channels are fused to obtain a fused encrypted image, effectively improving the data encryption security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of image encryption technology, and particularly relates to a data security encryption method. Background Art

[0002] As an important carrier for information transmission, images have been deeply integrated into key fields such as telemedicine, video surveillance, and military reconnaissance. With the popularization of network transmission, images face multiple security threats such as interception, tampering, and forgery during the transmission process. Data leakage incidents occur frequently, seriously threatening information security. The current mainstream image encryption technologies have their own characteristics and limitations: The encryption algorithm based on the chaos theory uses the high sensitivity of the chaos system to the initial conditions to achieve encryption. However, its key space is limited. In the face of a known plaintext attack, the attacker may crack the key by analyzing a small number of plaintext-ciphertext pairs, resulting in the failure of encryption. Therefore, the prior art has the problem of low encryption security. Summary of the Invention

[0003] In view of the above deficiencies in the prior art, a data security encryption method provided by the present invention solves the problem of low encryption security existing in the prior art.

[0004] To achieve the above invention purpose, the technical solution adopted by the present invention is: A data security encryption method includes the following steps:

[0005] Divide the plaintext image into R, G, and B channels to obtain three-channel plaintext images;

[0006] Exchange the adjacent row channel values and adjacent column channel values of each channel plaintext image to obtain a scrambled and inverse channel image;

[0007] Extract the plaintext local feature value and the plaintext global feature value for each pixel point in the channel plaintext image, extract the scrambled local feature value and the scrambled global feature value for each pixel point in the scrambled and inverse channel image, and construct the feature vector of each pixel point;

[0008] Divide the scrambled and inverse channel image into multiple regions, and obtain the first encryption key matrix and the second encryption key matrix for each region according to the feature vectors of each pixel point in each region;

[0009] Perform multiple encryptions on each region according to the first encryption key matrix and the second encryption key matrix, and perform a fusion process on the encrypted three channels to obtain a fusion encrypted image.

[0010] Further, the process of obtaining the scrambled and inverse channel image includes:

[0011] Divide every two adjacent rows of the channel plaintext image into a group to obtain multiple row combinations;

[0012] In each row combination, swap the channel values of two rows to obtain the first scrambled image;

[0013] Divide each adjacent two columns in the first scrambled image into a group to obtain multiple column combinations;

[0014] In each column combination, swap the channel values of two columns to obtain the second scrambled image;

[0015] Take the bitwise inversion of the binary code corresponding to the channel value in the second scrambled image to obtain the scrambled inversion channel image.

[0016] Furthermore, the process of constructing the feature vector of each pixel point includes:

[0017] In the channel plaintext image, with each pixel point as the center, extract the channel values of the upper, lower, left, and right neighboring pixel points of the central pixel point to obtain the plaintext local feature value of this pixel point;

[0018] In the channel plaintext image, take the absolute value of the difference between the channel value of each pixel point and the average channel value of the channel plaintext image as the plaintext global feature value of this pixel point;

[0019] In the scrambled inversion channel image, with each pixel point as the center, extract the pixel values of the upper, lower, left, and right neighboring pixel points of the central pixel point to obtain the scrambled local feature value of this pixel point;

[0020] In the scrambled inversion channel image, take the absolute value of the difference between the channel value of each pixel point and the average channel value of the scrambled inversion channel image as the scrambled global feature value of this pixel point;

[0021] Take the plaintext local feature value, plaintext global feature value, scrambled local feature value, and scrambled global feature value at the same pixel point position as elements to form the feature vector of this pixel point.

[0022] Furthermore, the process of obtaining the plaintext local feature value includes: in the channel plaintext image, take the absolute value of the difference between the channel value of the upper neighboring pixel point and the channel value of the lower neighboring pixel point as the first difference, take the absolute value of the difference between the channel value of the left neighboring pixel point and the channel value of the right neighboring pixel point as the second difference, and add the first difference and the second difference to obtain the plaintext local feature value;

[0023] The process of obtaining the scrambled local feature value includes: in the scrambled inversion channel image, take the absolute value of the difference between the channel value of the upper neighboring pixel point and the channel value of the lower neighboring pixel point as the third difference, take the absolute value of the difference between the channel value of the left neighboring pixel point and the channel value of the right neighboring pixel point as the fourth difference, and add the third difference and the fourth difference to obtain the scrambled local feature value.

[0024] Further, the process of obtaining the first encryption key matrix and the second encryption key matrix includes:

[0025] Divide the scrambled inverse channel image into multiple regions;

[0026] Convert each element in the feature vector of each pixel point in the region into an 8-bit binary code, and perform bit scrambling on the 4 corresponding binary codes in the feature vector to obtain 4 8-bit scrambled sequences for each pixel point;

[0027] Input the pixel values of 4 pixel points in each region into the hash algorithm SHA-256, and based on 32 equally long 8-bit hash sequences, obtain the first half of 4 8-bit perturbation sequences and the second half of 4 8-bit perturbation sequences;

[0028] According to the 4 8-bit scrambled sequences of a pair of pixel points in each region, and the first half of 4 8-bit perturbation sequences, obtain the first encryption key matrix;

[0029] According to the 4 8-bit scrambled sequences of another pair of pixel points in each region, and the second half of 4 8-bit perturbation sequences, obtain the second encryption key matrix.

[0030] Further, the process of performing bit scrambling on the 4 corresponding binary codes in the feature vector includes:

[0031] Concatenate the same bits of the 4 corresponding binary codes to obtain 8 4-bit sequences;

[0032] Then concatenate the 8 4-bit sequences in pairs to obtain 4 8-bit scrambled sequences.

[0033] Further, the process of obtaining the first half of the 4 8-bit perturbation sequences and the second half of the 4 8-bit perturbation sequences includes:

[0034] Input the pixel values of 4 pixel points in each region into the hash algorithm SHA-256 to obtain 32 equally long 8-bit hash sequences, convert each 8-bit hash sequence to decimal to obtain 32 hash data;

[0035] Divide the 32 hash data into 2 segments;

[0036] Extract the first half of the 16 hash data, divide the 16 hash data into groups of 4 hash data, calculate the average value for each group to obtain 4 hash averages, and convert the hash averages to 8-bit binary codes to obtain the first half of the 4 8-bit perturbation sequences;

[0037] Extract the second half of the 16 hash data, divide the 16 hash data into groups of 4 hash data, calculate the average value for each group to obtain 4 hash averages, and convert the hash averages to 8-bit binary codes to obtain the second half of the 4 8-bit perturbation sequences.

[0038] Further, the processes of obtaining the first encryption key matrix and obtaining the second encryption key matrix both include:

[0039] Performing exclusive OR processing on the i-th 8-bit scrambling sequence of one pixel point and the i-th 8-bit scrambling sequence of another pixel point to obtain the i-th exclusive OR result sequence, where i is 1, 2, 3, and 4;

[0040] Performing exclusive OR processing on the i-th exclusive OR result sequence and the i-th 8-bit perturbation sequence to obtain the i-th encryption key sequence;

[0041] Filling the 4 encryption key sequences into the matrix of in sequence to obtain the encryption key matrix.

[0042] Further, the process of obtaining the fusion encrypted image includes:

[0043] Performing bitwise exclusive OR processing on each first encryption key matrix and the binary code of the channel value in the corresponding area to obtain the first encrypted image of the channel;

[0044] Performing row-column permutation on the first encrypted image of the channel to obtain the permuted channel encrypted image;

[0045] Performing exclusive OR processing on the corresponding area in the permuted channel encrypted image with each second encryption key matrix to obtain the second encrypted image of the channel;

[0046] Fusing the 3 second encrypted images of the channel to obtain the fusion encrypted image.

[0047] Further, the process of fusing the 3 second encrypted images of the channel includes: performing bitwise exclusive OR on the 3 encrypted binary codes of the channels belonging to the same pixel point position to obtain the fusion encrypted image.

[0048] The beneficial effects of the present invention are:

[0049] The present invention splits a plaintext image into R, G, and B channels, and exchanges the channel values of adjacent rows and adjacent columns for each channel. This scrambling and inverse operation breaks the original distribution law of the channel values in the image. Then, according to the characteristic values of each pixel point in the channel plaintext image and the scrambled and inverse channel image, a feature vector of each pixel point is constructed to fully exploit the local and global feature information of the image, enabling the encryption process to closely combine with the characteristics of the image itself. Next, the scrambled and inverse channel image is divided into multiple regions, and the corresponding first encryption key matrix and second encryption key matrix are obtained according to the feature vectors of the pixel points in each region, so that each region has an independent encryption key, greatly expanding the key space and reducing the possibility of an attacker cracking the key through known plaintext-ciphertext pairs. Finally, the encrypted data of the three channels are fused to further enhance the security of the encryption. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] Figure 1 is a flowchart of a data security encryption method;

[0051] Figure 2 is a channel value distribution diagram of the image region of;

[0052] Figure 3 is for Figure 2 a channel value distribution diagram after exchanging the channel values of two rows of;

[0053] Figure 4 is for Figure 3 a channel value distribution diagram after exchanging the channel values of two columns of;

[0054] Figure 5 is for Figure 4 a channel value distribution diagram after taking the inverse of; DETAILED DESCRIPTION OF THE EMBODIMENTS

[0055] The following describes the specific embodiments of the present invention to facilitate those skilled in the art of the present technology to understand the present invention. However, it should be clear that the present invention is not limited to the scope of the specific embodiments. For those of ordinary skill in the art of the present technology, as long as various changes are within the spirit and scope of the present invention defined and determined by the appended claims, these changes are obvious, and all inventions created using the concept of the present invention are within the scope of protection.

[0056] As Figure 1 shown, a data security encryption method includes the following steps:

[0057] Divide the plaintext image into R, G, and B channels to obtain three channel plaintext images;

[0058] Exchange the channel values of adjacent rows and adjacent columns for each channel plaintext image to obtain a scrambled and inverse channel image;

[0059] Extract the plaintext local feature value and the plaintext global feature value for each pixel point in the channel plaintext image, extract the scrambled local feature value and the scrambled global feature value for each pixel point in the scrambled inverse channel image, and construct the feature vector of each pixel point;

[0060] Divide the scrambled inverse channel image into multiple regions, and obtain the first encryption key matrix and the second encryption key matrix for each region according to the feature vectors of each pixel point in each region;

[0061] Perform encryption on each region multiple times according to the first encryption key matrix and the second encryption key matrix, and fuse the encrypted three channels to obtain the fused encrypted image.

[0062] In this embodiment, the process of obtaining the scrambled inverse channel image includes:

[0063] Divide every two adjacent rows of the channel plaintext image into a group to obtain multiple row combinations;

[0064] In each row combination, exchange the channel values of the two rows to obtain the first scrambled image;

[0065] Divide every two adjacent columns in the first scrambled image into a group to obtain multiple column combinations;

[0066] In each column combination, exchange the channel values of the two columns to obtain the second scrambled image;

[0067] Invert each bit of the binary code corresponding to the channel value in the second scrambled image to obtain the scrambled inverse channel image.

[0068] The present invention groups every two adjacent rows of the channel plaintext image and exchanges the channel values, breaking the arrangement rule of the channel values in the vertical direction of the image, making the originally ordered channel value distribution chaotic, effectively interfering with the attacker's recognition of the image structure features, and reducing the success rate of the attack based on the analysis of the vertical direction features of the image. Secondly, perform adjacent two-column grouping and channel value exchange on the first scrambled image to further disrupt the channel value layout in the horizontal direction, and perform a dual row-column scrambling mechanism, which greatly changes the channel value distribution pattern of the image from the two-dimensional space dimension. Finally, invert each bit of the binary code corresponding to the channel value of the second scrambled image to comprehensively change the channel value distribution, increase the cracking difficulty, and improve the encryption security.

[0069] Taking the region in the image as an example, as Figure 2 shown, the upper two rows are in a group, and the lower two rows are in a group. Exchange the channel values of the two rows in a group to obtain the channel value distribution as Figure 3 shown, and exchange the channel values of the two columns to obtain as Figure 4The channel value distribution shown is then subjected to bitwise inversion of the binary bits of the channel value to obtain the channel value distribution as shown in Figure 5 shown.

[0070] In this embodiment, the process of constructing the feature vector of each pixel includes:

[0071] In the channel plaintext image, taking each pixel as the center, extracting the channel values of the upper, lower, left, and right neighboring pixels of the central pixel to obtain the plaintext local feature value of this pixel;

[0072] In the channel plaintext image, taking the absolute value of the difference between the channel value of each pixel and the average channel value of the channel plaintext image as the plaintext global feature value of this pixel;

[0073] In the scrambled and inverted channel image, taking each pixel as the center, extracting the pixel values of the upper, lower, left, and right neighboring pixels of the central pixel to obtain the scrambled local feature value of this pixel;

[0074] In the scrambled and inverted channel image, taking the absolute value of the difference between the channel value of each pixel and the average channel value of the scrambled and inverted channel image as the scrambled global feature value of this pixel;

[0075] Taking the plaintext local feature value, plaintext global feature value, scrambled local feature value, and scrambled global feature value at the same pixel position as elements to form the feature vector of this pixel.

[0076] The present invention extracts the local feature value and global feature value of each pixel from the channel plaintext image and the scrambled and inverted channel image respectively, constructs an independent feature vector for each pixel, and further associates the encryption key with the position of the pixel.

[0077] In this embodiment, the process of obtaining the plaintext local feature value includes: in the channel plaintext image, taking the absolute value of the difference between the channel value of the upper neighboring pixel and the channel value of the lower neighboring pixel as the first difference, taking the absolute value of the difference between the channel value of the left neighboring pixel and the channel value of the right neighboring pixel as the second difference, and adding the first difference and the second difference to obtain the plaintext local feature value;

[0078] The process of obtaining the scrambled local feature value includes: in the scrambled and inverted channel image, taking the absolute value of the difference between the channel value of the upper neighboring pixel and the channel value of the lower neighboring pixel as the third difference, taking the absolute value of the difference between the channel value of the left neighboring pixel and the channel value of the right neighboring pixel as the fourth difference, and adding the third difference and the fourth difference to obtain the scrambled local feature value.

[0079] The present invention generates independent feature vectors for each pixel point, associating the encryption key with the pixel position. This means that the encryption methods for pixels at different positions are unique, greatly increasing the complexity of encryption and the key space. It is difficult for attackers to crack the entire encrypted image by analyzing some pixels, effectively resisting common attack means such as statistical analysis attacks and differential attacks, and significantly enhancing the security of image data during transmission and storage.

[0080] In this embodiment, the process of obtaining the first encryption key matrix and the second encryption key matrix includes:

[0081] Dividing the scrambled inverse channel image into multiple regions;

[0082] Converting each element in the feature vector of each pixel point in the region into an 8-bit binary code, and performing bit scrambling on the binary codes corresponding to 4 elements in the feature vector to obtain 4 8-bit scrambled sequences for each pixel point;

[0083] Inputting the pixel values of 4 pixel points in each region into the hash algorithm SHA-256, and obtaining the first half 4 8-bit perturbation sequences and the second half 4 8-bit perturbation sequences based on 32 equally long 8-bit hash sequences;

[0084] Obtaining the first encryption key matrix according to the 4 8-bit scrambled sequences of a pair of pixel points in each region and the first half 4 8-bit perturbation sequences;

[0085] Obtaining the second encryption key matrix according to the 4 8-bit scrambled sequences of another pair of pixel points in each region and the second half 4 8-bit perturbation sequences.

[0086] In the present invention, 4 pixel points in the region are arbitrarily paired in pairs, and an encryption key matrix is obtained according to the 4 8-bit scrambled sequences of a pair of pixel points and 4 8-bit perturbation sequences.

[0087] The present invention divides the scrambled inverse channel image into regions of size, and constructs two independent encryption key matrices based on the feature vectors of the pixel points within the regions. The bit scrambling in the present invention greatly increases the degree of chaos of the data by scrambling and reorganizing these binary code bits. Then, the SHA-256 hash algorithm is used to generate perturbation sequences, and the perturbation sequences are combined with the scrambled sequences to improve the complexity and security of the key, effectively resisting cryptographic analysis attacks.

[0088] In this embodiment, the process of performing bit scrambling on the binary codes corresponding to 4 elements in the feature vector includes:

[0089] Concatenating the same bit of the binary codes corresponding to 4 elements to obtain 8 4-bit sequences;

[0090] Then, the 8 four-bit sequences are spliced pairwise to obtain 4 eight-bit scrambled sequences.

[0091] In this embodiment, the process of bit scrambling is specifically as follows:

[0092] Splice the 4 elements corresponding to the 1st binary digit to obtain the 1st four-bit sequence; splice the 4 elements corresponding to the 2nd binary digit to obtain the 2nd four-bit sequence; splice the 4 elements corresponding to the 3rd binary digit to obtain the 3rd four-bit sequence; splice the 4 elements corresponding to the 4th binary digit to obtain the 4th four-bit sequence; splice the 4 elements corresponding to the 5th binary digit to obtain the 5th four-bit sequence; splice the 4 elements corresponding to the 6th binary digit to obtain the 6th four-bit sequence; splice the 4 elements corresponding to the 7th binary digit to obtain the 7th four-bit sequence; splice the 4 elements corresponding to the 8th binary digit to obtain the 8th four-bit sequence.

[0093] Splice the 1st four-bit sequence and the 2nd four-bit sequence to obtain the 1st eight-bit scrambled sequence; splice the 3rd four-bit sequence and the 4th four-bit sequence to obtain the 2nd eight-bit scrambled sequence; splice the 5th four-bit sequence and the 6th four-bit sequence to obtain the 3rd eight-bit scrambled sequence; splice the 7th four-bit sequence and the 8th four-bit sequence to obtain the 4th eight-bit scrambled sequence.

[0094] In this embodiment, the process of obtaining the first half of the 4 eight-bit perturbation sequences and the second half of the 4 eight-bit perturbation sequences includes:

[0095] Input the pixel values of 4 pixel points in each region into the hash algorithm SHA-256 to obtain 32 eight-bit hash sequences of equal length, convert each eight-bit hash sequence to decimal to obtain 32 hash data;

[0096] Divide the 32 hash data into 2 segments;

[0097] Extract the first half of the 16 hash data, divide the 16 hash data into groups of 4 hash data, calculate the average value for each group to obtain 4 hash averages, convert the hash averages to 8-bit binary codes to obtain the first half of the 4 eight-bit perturbation sequences;

[0098] Extract the second half of the 16 hash data, divide the 16 hash data into groups of 4 hash data, calculate the average value for each group to obtain 4 hash averages, convert the hash averages to 8-bit binary codes to obtain the second half of the 4 eight-bit perturbation sequences.

[0099] The present invention uses the hash algorithm SHA-256 to generate 256-bit binary codes, which are used to form the first half of the 4 eight-bit perturbation sequences and the second half of the 4 eight-bit perturbation sequences for the key construction process, increasing the security of the key.

[0100] In this embodiment, the processes of obtaining the first encryption key matrix and the second encryption key matrix both include:

[0101] Performing an exclusive OR operation on the i-th 8-bit scrambling sequence of one pixel point and the i-th 8-bit scrambling sequence of another pixel point to obtain the i-th exclusive OR result sequence, where i is 1, 2, 3, and 4;

[0102] Performing an exclusive OR operation on the i-th exclusive OR result sequence and the i-th 8-bit perturbation sequence to obtain the i-th encryption key sequence;

[0103] Filling the 4 encryption key sequences into the matrix of in sequence to obtain the encryption key matrix.

[0104] In the present invention, when constructing the encryption key sequence, the 8-bit scrambling sequences of two pixel points and the corresponding 8-bit perturbation sequences are subjected to bitwise exclusive OR.

[0105] The present invention combines the scrambling sequence and the perturbation sequence of pixel points to generate the encryption key matrix. The scrambling sequence disrupts the original feature vector information through bit scrambling, and the perturbation sequence is generated by a hash algorithm. The combination of the two makes the key generation process highly complex. It is difficult for an attacker to crack the key through a single sequence, increasing the cracking difficulty and effectively resisting various cryptographic analysis attacks.

[0106] In the present invention, each encryption key sequence is 8 bits. The first encryption key sequence is filled into the position (1, 1) of the matrix of , the second encryption key sequence is filled into the position (1, 2) of the matrix of , the third encryption key sequence is filled into the position (2, 1) of the matrix of , and the fourth encryption key sequence is filled into the position (2, 2) of the matrix of .

[0107] In this embodiment, the process of obtaining the fused encrypted image includes:

[0108] Performing a bitwise exclusive OR operation on each first encryption key matrix and the binary code of the channel value of the corresponding region to obtain the first encrypted channel image;

[0109] Performing row and column permutation on the first encrypted channel image to obtain the permuted encrypted channel image;

[0110] Performing an exclusive OR operation on the corresponding region of the permuted encrypted channel image using each second encryption key matrix to obtain the second encrypted channel image;

[0111] Fusing the 3 second encrypted channel images to obtain the fused encrypted image.

[0112] The present invention uses a first encryption key matrix for encryption. To improve the security of encryption, the first encrypted image of the channel is subjected to row-column permutation, which disrupts the spatial position relationship of the encrypted pixels of the image, and then a second encryption is performed, making it difficult for an attacker to restore the image by analyzing the pixel position relationship and increasing the cracking difficulty.

[0113] In this embodiment, the formula for row-column permutation of the first encrypted image of the channel is: , where P(i,j) is the channel value at the coordinate (i,j) in the permuted channel encrypted image, i is the row coordinate, j is the column coordinate, k is the row permutation parameter, l is the column permutation parameter, M is the number of rows of the first encrypted image of the channel, N is the number of columns of the first encrypted image of the channel, mod is the remainder operation, is the channel value at the position in the first encrypted image of the channel.

[0114] k is the row permutation parameter, which controls the movement of the original image in the vertical direction (row direction). If k is positive, the image will move downward; if k is negative, the image will move upward. l is the column permutation parameter, which controls the movement of the original image in the horizontal direction (column direction). If l is positive, the image will move to the right; if l is negative, the image will move to the left.

[0115] In the present invention, k and l are set according to experiments or experience. For example, k = 5 and l = 5, the image moves down 5 rows significantly in the vertical direction and 5 columns to the right in the horizontal direction. This will cause a large change in the position of the image channel values. Especially for larger-sized images, it can make the pixel distribution more dispersed, significantly change the image structure, enhance the confusion degree of the encrypted image, and make it more difficult for an attacker to infer the plaintext structure from the ciphertext.

[0116] In this embodiment, the process of fusing the second encrypted images of 3 channels includes: performing bitwise XOR on the 3-channel encrypted binary codes belonging to the same pixel position to obtain a fused encrypted image.

[0117] In this embodiment, another implementation manner of fusion is: weighting the 3-channel values belonging to the same pixel position to obtain a fused encrypted image.

[0118] The present invention generates two encryption key matrices for each region position in the scrambled inverse channel image. After obtaining the first encrypted image of the channel, the second encryption key matrix encrypts the corresponding region position of the first encrypted image of the channel.

[0119] The present invention splits a plaintext image into R, G, and B channels, and exchanges the channel values of adjacent rows and adjacent columns for each channel. This scrambling and inversion operation breaks the original distribution law of the channel values in the image. Then, according to the characteristic values of each pixel point in the channel plaintext image and the scrambled and inverted channel image, a feature vector of each pixel point is constructed to fully exploit the local and global feature information of the image, so that the encryption process can be closely combined with the characteristics of the image itself. Next, the scrambled and inverted channel image is divided into multiple regions, and the corresponding first encryption key matrix and second encryption key matrix are obtained according to the feature vectors of the pixel points in each region, so that each region has an independent encryption key, greatly expanding the key space and reducing the possibility for an attacker to crack the key through known plaintext-ciphertext pairs. Finally, the encrypted data of the three channels are fused to further enhance the security of encryption.

[0120] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A data security encryption method, characterized in that, It includes the following steps: Divide the plaintext image into R, G, and B channels to obtain three-channel plaintext images; Exchange the channel values of adjacent rows and adjacent columns for each channel plaintext image to obtain a scrambled and inverted channel image; Extract the plaintext local feature value and the plaintext global feature value for each pixel point in the channel plaintext image, extract the scrambled local feature value and the scrambled global feature value for each pixel point in the scrambled and inverted channel image, and construct the feature vector for each pixel point; Divide the scrambled and inverted channel image into multiple regions, and obtain the first encryption key matrix and the second encryption key matrix for each region according to the feature vectors of each pixel point in each region; Perform encryption on each region multiple times according to the first encryption key matrix and the second encryption key matrix, and perform fusion processing on the encrypted three channels to obtain a fusion encrypted image; The process of constructing the feature vector for each pixel point includes: Centered on each pixel point in the channel plaintext image, extract the channel values of the upper, lower, left, and right neighboring pixel points of the central pixel point to obtain the plaintext local feature value of this pixel point; Take the absolute value of the difference between the channel value of each pixel point and the average channel value of the channel plaintext image in the channel plaintext image as the plaintext global feature value of this pixel point; Centered on each pixel point in the scrambled and inverted channel image, extract the pixel values of the upper, lower, left, and right neighboring pixel points of the central pixel point to obtain the scrambled local feature value of this pixel point; Take the absolute value of the difference between the channel value of each pixel point and the average channel value of the scrambled and inverted channel image in the scrambled and inverted channel image as the scrambled global feature value of this pixel point; Use the plaintext local feature value, the plaintext global feature value, the scrambled local feature value, and the scrambled global feature value at the same pixel point position as elements to form the feature vector of this pixel point; The process of obtaining the first encryption key matrix and the second encryption key matrix includes: Divide the scrambled and inverted channel image into multiple regions; Convert each element in the feature vector of each pixel point in the region into an 8-bit binary code, and perform bit confusion on the 4 corresponding binary codes in the feature vector to obtain 4 8-bit confusion sequences for each pixel point; Input the pixel values of 4 pixel points in each region into the hash algorithm SHA-256, and obtain the first half of 4 8-bit perturbation sequences and the second half of 4 8-bit perturbation sequences based on 32 equally long 8-bit hash sequences; Obtain the first encryption key matrix according to the 4 8-bit confusion sequences of a pair of pixel points in each region and the first half of 4 8-bit perturbation sequences; Obtain the second encryption key matrix according to the 4 8-bit confusion sequences of another pair of pixel points in each region and the second half of 4 8-bit perturbation sequences.

2. The data security encryption method according to claim 1, characterized in that, The process of obtaining the scrambled and inverted channel image includes: Divide every two adjacent rows of the channel plaintext image into a group to obtain multiple row combinations; In each row combination, exchange the channel values of the two rows to obtain the first scrambled image; Divide every two adjacent columns in the first scrambled image into a group to obtain multiple column combinations; In each column combination, exchange the channel values of the two columns to obtain the second scrambled image; Take the bitwise inversion of the binary code corresponding to the channel value in the second scrambled image to obtain the scrambled and inverted channel image.

3. The data security encryption method according to claim 1, wherein The process of obtaining the plaintext local eigenvalue includes: in the channel plaintext image, taking the absolute value of the difference between the channel value of the upper neighborhood pixel point and the channel value of the lower neighborhood pixel point as the first gap, taking the absolute value of the difference between the channel value of the left neighborhood pixel point and the channel value of the right neighborhood pixel point as the second gap, and adding the first gap and the second gap to obtain the plaintext local eigenvalue; The process of obtaining the scrambled local eigenvalue includes: in the scrambled inverse channel image, taking the absolute value of the difference between the channel value of the upper neighborhood pixel point and the channel value of the lower neighborhood pixel point as the third gap, taking the absolute value of the difference between the channel value of the left neighborhood pixel point and the channel value of the right neighborhood pixel point as the fourth gap, and adding the third gap and the fourth gap to obtain the scrambled local eigenvalue.

4. The data security encryption method according to claim 1, wherein The process of bit scrambling the 4 - element corresponding binary codes in the feature vector includes: Concatenating the same bit of the 4 - element corresponding binary codes to obtain 8 four - bit sequences; Then concatenating the 8 four - bit sequences in pairs to obtain 4 eight - bit scrambled sequences.

5. The data security encryption method according to claim 1, wherein The process of obtaining the first half - segment 4 eight - bit perturbation sequences and the second half - segment 4 eight - bit perturbation sequences includes: Inputting the pixel values of 4 pixel points in each region into the hash algorithm SHA - 256 to obtain 32 equally - long eight - bit hash sequences, converting each eight - bit hash sequence to decimal to obtain 32 hash data; Dividing the 32 hash data into 2 segments; Extracting the first 16 hash data, dividing the 16 hash data into groups of 4 hash data, calculating the mean value for each group to obtain 4 hash means, converting the hash means to eight - bit binary codes to obtain the first half - segment 4 eight - bit perturbation sequences; Extracting the second 16 hash data, dividing the 16 hash data into groups of 4 hash data, calculating the mean value for each group to obtain 4 hash means, converting the hash means to eight - bit binary codes to obtain the second half - segment 4 eight - bit perturbation sequences.

6. The data security encryption method according to claim 1, wherein The processes of obtaining the first encryption key matrix and obtaining the second encryption key matrix both include: Performing exclusive - OR processing on the i - th eight - bit scrambled sequence of one pixel point and the i - th eight - bit scrambled sequence of another pixel point to obtain the i - th exclusive - OR result sequence, where i is 1, 2, 3, and 4; Performing exclusive - OR processing on the i - th exclusive - OR result sequence and the i - th eight - bit perturbation sequence to obtain the i - th encryption key sequence; Filling the 4 encryption key sequences into the matrix in sequence to obtain the encryption key matrix.

7. The data security encryption method according to claim 1, wherein The process of obtaining the fused encrypted image includes: Performing bit - by - bit exclusive - OR processing on each first encryption key matrix and the binary code of the channel value in the corresponding region to obtain the first - time encrypted channel image; Performing row - column permutation on the first - time encrypted channel image to obtain the permuted channel encrypted image; Performing exclusive - OR processing on the corresponding region of the permuted channel encrypted image using each second encryption key matrix to obtain the second - time encrypted channel image; Fusing the 3 second - time encrypted channel images to obtain the fused encrypted image.

8. The data security encryption method according to claim 7, wherein The process of fusing the 3 second - time encrypted channel images includes: performing bit - by - bit exclusive - OR on the 3 channel - encrypted binary codes belonging to the same pixel point position to obtain the fused encrypted image.

Citation Information

Patent Citations

  • Image encryption method based on block scrambling and state conversion

    CN112422268A

  • Image encryption method based on filling curve and adjacent pixel bit scrambling

    CN112714235A