Data encryption method and device, data decryption method and device and computer equipment

By dynamically generating and obfuscating the processing of initial keys in data transmission and multiple encryption of encrypted data, the risk of data leakage caused by key plaintext transmission in traditional technology is solved, and the security of data transmission is significantly improved.

CN120165846APending Publication Date: 2025-06-17KINGDEE DEEKING CLOUDCOMPUTING CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510265133.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-05
Publication Date
2025-06-17

AI Technical Summary

Technical Problem

In traditional technology, the keys for encrypted data are easily intercepted during transmission through plain text, which increases the risk of transmission data leakage and leads to lower data transmission security.

Method used

In response to the interface access request, the initial key is generated using a random number and obfuscated, and the first key is obtained. Then, the encrypted data is encrypted according to the first key to obtain the first ciphertext. Next, the initial key is encrypted according to the first ciphertext, and the second key is obtained, and encrypted to obtain the second ciphertext.

Benefits of technology

Dynamic changes and multiple encryption of the initial key are realized, which improves the encryption complexity of the first ciphertext and the risk of cracking the initial key, thereby improving the security of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120165846A_ABST
    Figure CN120165846A_ABST
Patent Text Reader

Abstract

The invention relates to a data encryption method and device, a data decryption method and device, computer equipment, a computer readable storage medium and a computer program product. The data encryption method comprises the following steps: in response to an interface access request, generating an initial key through a random number; performing confusion processing on the initial key to obtain a first key; acquiring to-be-encrypted data, and performing first encryption processing on the to-be-encrypted data according to the first key to obtain a first ciphertext; performing second encryption processing on the initial key according to the first ciphertext to obtain a second key; and encrypting the second key to obtain a second ciphertext. By adopting the method, the security of data transmission can be enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information security technology, and in particular, to a data encryption method, a data decryption method, a device, a computer device, a computer-readable storage medium, and a computer program product. Background Art

[0002] When applications interact with each other or between an application and a front-end interface, data on a server is often accessed and operated through an API (Application Programming Interface). To improve the security of the transmitted data, the transmitted data can be encrypted to ensure that the information is not illegally obtained or tampered with.

[0003] In traditional technologies, the key for encrypting data is transmitted in plaintext, which is easily intercepted during the transmission process, increasing the risk of transmitted data leakage and resulting in low data transmission security. Summary of the Invention

[0004] Based on this, in view of the above technical problems, it is necessary to provide a data encryption method, a data decryption method, a device, a computer device, a computer-readable storage medium, and a computer program product that can improve data transmission security.

[0005] In a first aspect, this application provides a data encryption method, including:

[0006] Responding to an interface access request, generating an initial key through a random number;

[0007] Performing a confusion process on the initial key to obtain a first key;

[0008] Obtaining data to be encrypted, and performing a first encryption process on the data to be encrypted according to the first key to obtain a first ciphertext;

[0009] Performing a second encryption process on the initial key according to the first ciphertext to obtain a second key;

[0010] Encrypting the second key to obtain a second ciphertext.

[0011] In one embodiment, the performing a first encryption process on the data to be encrypted according to the first key to obtain a first ciphertext includes:

[0012] Generating a target format file corresponding to the data to be encrypted;

[0013] Encrypting the target format file corresponding to the data to be encrypted through the first key to obtain an initial ciphertext;

[0014] Generating a target format file corresponding to the initial ciphertext;

[0015] Encrypt the target format file corresponding to the initial ciphertext to obtain a first ciphertext.

[0016] In one embodiment, the second encryption process on the initial key according to the first ciphertext to obtain a second key includes:

[0017] Perform a confusion process on the first ciphertext to obtain a confused first ciphertext;

[0018] Encrypt the initial key with the confused first ciphertext to obtain a second key.

[0019] In one embodiment, the encryption of the second key to obtain a second ciphertext includes:

[0020] Generate a target format file corresponding to the second key;

[0021] Encrypt the target format file corresponding to the second key to obtain a second ciphertext.

[0022] In one embodiment, the confusion process includes at least one of feature dimension confusion, spatial dimension confusion, entropy dimension confusion, encryption, encoding, or eigenvalue truncation.

[0023] In a second aspect, the present application provides a data decryption method, including:

[0024] Obtain a first ciphertext and a second ciphertext;

[0025] Decrypt the second ciphertext to obtain a second key;

[0026] Perform a first decryption process on the second key according to the first ciphertext to obtain an initial key;

[0027] Perform a confusion process on the initial key to obtain a first key;

[0028] Perform a second decryption process on the first ciphertext according to the first key to obtain decrypted data.

[0029] In one embodiment, the performing a first decryption process on the second key according to the first ciphertext to obtain an initial key includes:

[0030] Perform a confusion process on the first ciphertext to obtain a confused first ciphertext;

[0031] Decrypt the second key with the confused first ciphertext to obtain an initial key.

[0032] In one embodiment, performing a second decryption process on the first ciphertext according to the first key to obtain decryption data, including:

[0033] Decrypting the first ciphertext to obtain a target format file corresponding to the initial ciphertext, and extracting the initial ciphertext from the target format file corresponding to the initial ciphertext;

[0034] Decrypting the initial ciphertext with the first key to obtain a target format file corresponding to the decryption data;

[0035] Extracting the decryption data from the target format file corresponding to the decryption data.

[0036] In a third aspect, the present application further provides a data encryption device, including:

[0037] A key generation module, configured to generate an initial key by a random number in response to an interface access request;

[0038] A confusion processing module, configured to perform a confusion process on the initial key to obtain a first key;

[0039] A first encryption processing module, configured to obtain data to be encrypted, and perform a first encryption process on the data to be encrypted according to the first key to obtain a first ciphertext;

[0040] A second encryption processing module, configured to perform a second encryption process on the initial key according to the first ciphertext to obtain a second key;

[0041] A key encryption module, configured to encrypt the second key to obtain a second ciphertext.

[0042] In a fourth aspect, the present application provides a data decryption device, including:

[0043] A ciphertext acquisition module, configured to acquire a first ciphertext and a second ciphertext;

[0044] A ciphertext decryption module, configured to decrypt the second ciphertext to obtain a second key;

[0045] A first decryption processing module, configured to perform a first decryption process on the second key according to the first ciphertext to obtain an initial key;

[0046] A confusion processing module, configured to perform a confusion process on the initial key to obtain a first key;

[0047] A second decryption processing module, configured to perform a second decryption process on the first ciphertext according to the first key to obtain decryption data.

[0048] In a fifth aspect, the present application further provides a computer device, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the steps of the data encryption method provided in the first aspect or the steps of the data decryption method provided in the second aspect are implemented.

[0049] In a sixth aspect, the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the data encryption method provided in the first aspect or the steps of the data decryption method provided in the second aspect are implemented.

[0050] In a seventh aspect, the present application further provides a computer program product, including a computer program. When the computer program is executed by a processor, the steps of the data encryption method provided in the first aspect or the steps of the data decryption method provided in the second aspect are implemented.

[0051] For the above data encryption method, device, computer device, computer-readable storage medium, and computer program product, by responding to an interface access request, an initial key is generated through a random number, and the initial key is obfuscated to obtain a first key; the data to be encrypted is subjected to a first encryption process according to the first key to obtain a first ciphertext, the initial key is subjected to a second encryption process according to the first ciphertext to obtain a second key, and the second key is encrypted to obtain a second ciphertext, which can realize the dynamic change of the initial key. At the same time, after obfuscating the initial key and then encrypting the data to be encrypted, the encryption complexity of the obtained first ciphertext can be improved; in addition, by performing multiple encryptions on the initial key with the first ciphertext, the risk of cracking the initial key can be reduced, thereby improving the security of data transmission.

[0052] For the above data decryption method, device, computer device, computer-readable storage medium, and computer program product, by obtaining the first ciphertext and the second ciphertext, decrypting the second ciphertext to obtain a second key, performing a first decryption process on the second key according to the first ciphertext to obtain the initial key, obfuscating the initial key to obtain a first key, and performing a second decryption process on the first ciphertext according to the first key to obtain the decrypted data, it is possible to quickly decrypt the data encrypted multiple times, improving the data transmission efficiency while enhancing the security of the transmitted data. BRIEF DESCRIPTION OF THE DRAWINGS

[0053] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required for use in the description of the embodiments of the present application or related technologies. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other related drawings can be obtained without creative efforts based on these drawings.

[0054] Figure 1 It is an application environment diagram of the data encryption method in an embodiment;

[0055] Figure 2 It is a schematic flowchart of the data encryption method in an embodiment;

[0056] Figure 3 It is a schematic flowchart of the data decryption method in an embodiment;

[0057] Figure 4 It is a schematic flowchart of the data encryption method in another embodiment;

[0058] Figure 5 It is a schematic flowchart of the data decryption method in another embodiment;

[0059] Figure 6 It is a schematic flowchart of the processing flow of the confusion algorithm in an embodiment;

[0060] Figure 7 It is a structural block diagram of the data encryption device in an embodiment;

[0061] Figure 8 It is a structural block diagram of the data decryption device in an embodiment;

[0062] Figure 9 It is an internal structure diagram of a computer device in an embodiment.

[0063] Figure 10 It is an internal structure diagram of a computer device in another embodiment. Detailed implementation manners

[0064] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0065] The data encryption method or data decryption method provided by the embodiments of the present application can be applied to, for example Figure 1In the application environment shown. Among them, the terminal 102 communicates with the server 104 through the network. The data storage system can store the data that the server 104 needs to process. The data storage system can be integrated on the server 104, or placed on the cloud or other network servers. When the server 104 responds to the interface access request of the terminal 102, it generates an initial key through a random number, performs an obfuscation process on the initial key to obtain a first key, performs a first encryption process on the obtained data to be encrypted according to the first key to obtain a first ciphertext, performs a second encryption process on the initial key according to the first ciphertext to obtain a second key, and encrypts the second key to obtain a second ciphertext. The server 104 can send the first ciphertext and the second ciphertext to the terminal 102. The terminal 102 obtains the first ciphertext and the second ciphertext, decrypts the second ciphertext to obtain the second key, performs a first decryption process on the second key according to the first ciphertext to obtain the initial key, performs an obfuscation process on the initial key to obtain the first key, and performs a second decryption process on the first ciphertext according to the first key to obtain the decrypted data.

[0066] Among them, the terminal 102 can be, but is not limited to, various personal computers, laptop computers, smart phones, tablet computers, Internet of Things devices, and portable wearable devices. The Internet of Things devices can be smart speakers, smart TVs, smart air conditioners, smart in-vehicle devices, projection devices, etc. The portable wearable devices can be smart watches, smart bracelets, head-mounted devices, etc. The head-mounted devices can be virtual reality (VR) devices, augmented reality (AR) devices, smart glasses, etc. The server 104 can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud computing services. It should be noted that the data encryption method or data decryption method provided in the embodiments of the present application is not limited to the scenario where the server and the terminal interact, but also applicable to the application scenarios where the terminal interacts with the terminal, or the server interacts with the server.

[0067] In an exemplary embodiment, as Figure 2 shown, a data encryption method is provided. Taking the method applied to the Figure 1 server in as an example for description, it includes the following steps 202 to step 210. Among them:

[0068] Step 202, in response to the interface access request, generate an initial key through a random number.

[0069] Among them, an interface access request refers to an access request from a terminal to an interface. For example, through a Web interface, an application program on the terminal can be allowed to access and operate resources or functions on the server. A Web interface is also called a Web API. When the terminal application needs to obtain data on the server, a corresponding interface access request will be initiated.

[0070] Optionally, in response to the terminal's access request to the interface, the server generates a random number of a preset length and uses the random number of the preset length as the initial key. Exemplarily, a random number of a preset length can be generated by a random number generator, and then the random number of the preset length is used as the initial key. Among them, the preset length can be set according to the actual application scenario, such as 69 bits, 128 bits, or 256 bits, etc. In the actual application scenario, the initial key, user identifier, and key status can be bound and saved. Among them, the user identifier refers to the identifier of the user who initiates the interface access request, and the key status can include an effective status, an update status, and a disabled status.

[0071] Step 204: Perform an obfuscation process on the initial key to obtain a first key.

[0072] Among them, the obfuscation process refers to converting the code of a computer program into a form that is functionally equivalent but difficult to read and understand. The initial key can exist in the form of a string. Therefore, the initial key can be regarded as the code of a computer program for processing. For example, the initial key can be obfuscated through an obfuscation algorithm to obtain a first key, which can increase the complexity of the key.

[0073] Step 206: Obtain the data to be encrypted, and perform a first encryption process on the data to be encrypted according to the first key to obtain a first ciphertext.

[0074] Among them, the data to be encrypted refers to the data that needs to be encrypted. The data to be encrypted can be, for example, regular business data or a data key. A data key is a key used to encrypt business data. In the actual application scenario, the data to be encrypted can be the access data corresponding to the interface access request.

[0075] Optionally, the data to be encrypted can be converted into a target format file, and then the target format file of the data to be encrypted is encrypted with the first key to obtain a first ciphertext. It is easy to understand that the method of encrypting the target format file of the data to be encrypted with the first key is not specifically limited. For example, any encryption algorithm can be used for encryption. The target format file can be any data format file, such as JSON (JavaScript Object Notation), YAML (YAML Ain't Markup Language), TOML (Tom's Obvious, Minimal Language), XML (eXtensible Markup Language), Protocol Buffers, MessagePack, Properties (Java Properties Format) file, etc.

[0076] Optionally, the data to be encrypted can be converted into a target format file, and the target format file corresponding to the data to be encrypted is encrypted with the first key to obtain an initial ciphertext, and then the initial ciphertext is encrypted with an encryption algorithm to obtain a first ciphertext.

[0077] Optionally, the data to be encrypted can be obfuscated to obtain the obfuscated data to be encrypted, and the obfuscated data to be encrypted is bound to the user identifier and the data version number and saved.

[0078] Step 208, perform a second encryption process on the initial key according to the first ciphertext to obtain a second key.

[0079] In an actual application scenario, the first ciphertext can be obfuscated to obtain an obfuscated first ciphertext, and then the initial key is encrypted with the obfuscated first ciphertext to obtain a second key. Among them, obfuscation is a processing method that increases complexity, and the corresponding obfuscation algorithm can be selected according to the actual application scenario for obfuscation processing.

[0080] Step 210, encrypt the second key to obtain a second ciphertext.

[0081] The second key can be encrypted with an encryption algorithm to obtain a second ciphertext. Or, it can also be to encrypt the target format file corresponding to the second key to obtain a second ciphertext. Among them, the encryption algorithm can be at least one of AES256, base64, GCM, MD5, and SHA.

[0082] In an actual application scenario, the server may send the encrypted first ciphertext and the second ciphertext to the client of the terminal, and the client decrypts them to obtain corresponding decrypted data, thereby obtaining resource data required by the application.

[0083] In the above data encryption method, an initial key is generated by a random number, and the initial key is obfuscated to obtain a first key; the encrypted data is encrypted for a first time according to the first key to obtain a first ciphertext; the initial key is encrypted for a second time according to the first ciphertext to obtain a second key; the second key is encrypted to obtain a second ciphertext, which can realize dynamic changes of the initial key. At the same time, the initial key is obfuscated before the encrypted data is encrypted, which can increase the encryption complexity of the obtained first ciphertext and improve the transmission security of the first ciphertext. In addition, multiple encryption of the initial key through a more complex first ciphertext can further reduce the risk of cracking the initial key. Based on the multiple encryption of the first ciphertext and the encryption of the initial key, the security of data transmission can be greatly improved.

[0084] In some embodiments, step 206 of performing a first encryption process on the data to be encrypted according to the first key to obtain a first ciphertext includes:

[0085] Generate a target format file corresponding to the data to be encrypted; encrypt the target format file corresponding to the data to be encrypted using a first key to obtain an initial ciphertext; generate a target format file corresponding to the initial ciphertext; encrypt the target format file corresponding to the initial ciphertext to obtain a first ciphertext.

[0086] The target format file corresponding to the data to be encrypted refers to a target format file corresponding to the data to be encrypted, for example, a target format file corresponding to information such as the data to be encrypted, a user identifier, and a data version number. The user identifier refers to the identifier of the terminal user who initiates the interface access request, and the data version number refers to the version number of the data to be encrypted, which can uniquely identify the version information of the data to be encrypted.

[0087] Exemplarily, obtain the data to be encrypted, the user identification, and the data version number, construct a JSON file corresponding to the data to be encrypted, the user identification, and the data version number, that is, generate a target format file corresponding to the data to be encrypted, and based on the AES256 or GCM encryption algorithm, encrypt the target format file corresponding to the data to be encrypted with the first key to obtain the initial ciphertext. Obtain the expiration information corresponding to the initial ciphertext, construct a JSON file corresponding to the initial ciphertext and the expiration information, that is, generate a target format file corresponding to the initial ciphertext, and encrypt the JSON file to obtain the first ciphertext. It is easy to understand that the target format file is not limited to a JSON format file, and can also be other data format files. Correspondingly, the encryption algorithm is not limited to AES256 or GCM, and can also be other encryption algorithms.

[0088] In this embodiment, by generating a target format file corresponding to the data to be encrypted, encrypting the target format file corresponding to the data to be encrypted with the first key to obtain the initial ciphertext, generating a target format file corresponding to the initial ciphertext, and encrypting the target format file corresponding to the initial ciphertext to obtain the first ciphertext, it is possible to perform multiple transformations and encryptions on the data to be encrypted, improve the complexity of the encrypted ciphertext, and further improve the security of the transmitted data.

[0089] In an exemplary embodiment, step 208 of performing a second encryption process on the initial key according to the first ciphertext includes:

[0090] Perform a confusion process on the first ciphertext to obtain a confused first ciphertext; encrypt the initial key with the confused first ciphertext to obtain the second key.

[0091] It is possible to perform a confusion process on the first ciphertext to obtain a confused first ciphertext, and then use an encryption algorithm to encrypt the initial key with the confused first ciphertext to obtain the second key. It is equivalent to that the confused first ciphertext is the "key" for encrypting the initial key. Exemplarily, perform a confusion process on the first ciphertext through a confusion algorithm to obtain a confused first ciphertext, and use AES256 to encrypt the initial key with the confused first ciphertext to obtain the second key. The second key can be in the form of a string.

[0092] In this embodiment, by performing a confusion process on the first ciphertext to obtain a confused first ciphertext, and encrypting the initial key with the confused first ciphertext to obtain the second key, it is realized that after performing a confusion process on the ciphertext obtained by encrypting the data, the initial key is encrypted again. It is equivalent to that the confused first ciphertext is the encryption key of the initial key, which greatly increases the complexity of the encryption key of the initial key, thereby improving the encryption security of the initial key. Even if it is leaked, it is difficult to crack, reducing the cracking risk.

[0093] In some embodiments, step 210 of encrypting the second key to obtain the second ciphertext includes:

[0094] Generating a target format file corresponding to the second key; encrypting the target format file corresponding to the second key to obtain the second ciphertext.

[0095] After obtaining the second key, a target format file including the second key can be generated. For example, a target format file of the second key can be generated, or a target format file of the second key and information related to the second key can be generated to obtain the target format file corresponding to the second key. For example, generating a target format file of the second key and the expiration information of the second key as the target format file corresponding to the second key.

[0096] Exemplarily, obtain the second key and the expiration information of the second key, generate a target format file corresponding to the second key and the expiration information of the second key as the target format file corresponding to the second key, and encrypt the target format file corresponding to the second key based on base64 to obtain the second ciphertext.

[0097] In this embodiment, by generating a target format file corresponding to the second key and encrypting the target format file corresponding to the second key to obtain the second ciphertext, the security of the initial key can be further improved.

[0098] In an exemplary embodiment, the obfuscation process includes at least one of feature dimension obfuscation, spatial dimension obfuscation, entropy dimension obfuscation, encryption, encoding, or eigenvalue interception.

[0099] Among them, feature dimension obfuscation refers to the process of obfuscating data features. For example, first extract the data features, and then move the bytes corresponding to the data features, etc. Spatial dimension obfuscation refers to constructing a matrix corresponding to the data and then performing transformation processing on the matrix. Entropy dimension obfuscation refers to calculating the information entropy, calculating the obfuscation intensity according to the information entropy, and performing character transformation on the obfuscation intensity. Encryption refers to the encryption process through any encryption algorithm, such as SHA256 encryption. Eigenvalue interception refers to the method of extracting features through a preset rule, such as extracting a corresponding digital array through a regular expression.

[0100] Exemplarily, the obfuscation process includes feature dimension obfuscation, spatial dimension obfuscation, entropy dimension obfuscation, Secure Hash Algorithm SHA256 encryption, Base64 encoding for representing binary data based on 64 printable characters, and eigenvalue interception.

[0101] It should be noted that the specific processing methods corresponding to the confusion processing at different positions in this embodiment can be the same or different, and can be selected according to actual needs. However, it is easy to understand that the more processing methods are used, the higher the corresponding confusion degree.

[0102] By performing confusion processing on the data, the complexity of the data can be increased, the true meaning of the data can be reduced, and the encryption complexity can be improved, thereby improving the security of data transmission.

[0103] In one embodiment, as Figure 3 shown, a data decryption method is provided. Taking the case where this method is applied to Figure 1 the terminal as an example, it includes the following steps 302 to step 310. Among them:

[0104] Step 302, obtain the first ciphertext and the second ciphertext.

[0105] The first ciphertext and the second ciphertext can be obtained from the server, or the first ciphertext and the second ciphertext can be obtained from the storage medium. Among them, the first ciphertext includes the decryption data, and the second ciphertext includes the decryption key.

[0106] Step 304, decrypt the second ciphertext to obtain the second key.

[0107] Use the encrypted algorithm to perform corresponding decryption on the second ciphertext to obtain the second key. For example, if base64 is used to encode the second key during encryption to obtain the second ciphertext, then use base64 to decode the second ciphertext to obtain the second key.

[0108] Optionally, decrypt the second ciphertext to obtain the target format file corresponding to the second key, then the second key can be extracted from the target format file corresponding to the second key, and the validity of the second key can also be verified according to the corresponding expiration information in the target format file corresponding to the second key. If the validity verification passes, extract the second key from the target format file corresponding to the second key.

[0109] Step 306, perform a first decryption process on the second key according to the first ciphertext to obtain the initial key.

[0110] Optionally, the second key can be decrypted by the first ciphertext to obtain the initial key. Or, the first ciphertext can be subjected to confusion processing to obtain the confused first ciphertext, and then the second key can be decrypted by the confused first ciphertext to obtain the initial key.

[0111] Step 308, perform confusion processing on the initial key to obtain the first key.

[0112] Among them, the confusion processing may include at least one of feature dimension confusion, spatial dimension confusion, entropy dimension confusion, encryption, encoding, or eigenvalue interception. For the specific implementation manner of the confusion processing, reference may be made to the description of the above relevant embodiments, which will not be elaborated herein.

[0113] Step 310: Perform a second decryption process on the first ciphertext according to the first key to obtain decrypted data.

[0114] The first ciphertext can be decrypted by the first key to obtain decrypted data. Alternatively, the first ciphertext can be decrypted to obtain an initial ciphertext, and the initial ciphertext can be decrypted by the first key to obtain decrypted data. It is easy to understand that the decryption process may include multiple decryption processes, and the first decryption process and the second decryption process are different.

[0115] In the above data decryption method, by obtaining the first ciphertext and the second ciphertext, decrypting the second ciphertext to obtain the second key, performing a first decryption process on the second key according to the first ciphertext to obtain the initial key, performing a confusion process on the initial key to obtain the first key, and performing a second decryption process on the first ciphertext according to the first key to obtain decrypted data, it is possible to quickly decrypt the multiply encrypted data, improve the security of the transmitted data, and improve the data transmission efficiency at the same time.

[0116] In some embodiments, step 306 of performing a first decryption process on the second key according to the first ciphertext to obtain the initial key includes:

[0117] Perform a confusion process on the first ciphertext to obtain a confused first ciphertext; decrypt the second key by the confused first ciphertext to obtain the initial key.

[0118] The confusion algorithm used in encryption can be used to perform a confusion process on the first ciphertext to obtain a confused first ciphertext, and then the confused first ciphertext can be used as the key to decrypt the second key to obtain the initial key.

[0119] Exemplarily, the first ciphertext can be confused by a confusion algorithm to obtain a confused first ciphertext, and the second key can be decrypted by the confused first ciphertext using AES256 or GCM to obtain the initial key.

[0120] In this embodiment, by performing a confusion process on the first ciphertext to obtain a confused first ciphertext, and then decrypting the second key by the confused first ciphertext to obtain the initial key, the transmission security of the initial key can be improved, and the initial key can be quickly decrypted.

[0121] In an exemplary embodiment, step 310 of performing a second decryption process on the first ciphertext according to the first key to obtain decrypted data includes:

[0122] Decrypt the first ciphertext to obtain the target format file corresponding to the initial ciphertext, and extract the initial ciphertext from the target format file corresponding to the initial ciphertext; decrypt the initial ciphertext with the first key to obtain the target format file corresponding to the decryption data; extract the decryption data from the target format file corresponding to the decryption data.

[0123] In this embodiment, by using an algorithm corresponding to encryption, such as base64, decode the first ciphertext to obtain the target format file corresponding to the initial ciphertext. The initial ciphertext can be extracted from the target format file corresponding to the initial ciphertext. Decrypt the initial ciphertext with the first key, for example, use the AES256 or GCM decryption algorithm for decryption to obtain the target format file corresponding to the decryption data. The expiration date information can be extracted from the target format file corresponding to the decryption data. Verify the validity of the decryption data according to the expiration date information. When the validity verification passes, the decryption data and the version information of the decryption data can be extracted from the target format file corresponding to the decryption data.

[0124] In this embodiment, by decrypting the first ciphertext to obtain the target format file corresponding to the initial ciphertext, extracting the initial ciphertext from the target format file corresponding to the initial ciphertext, decrypting the initial ciphertext with the first key to obtain the target format file corresponding to the decryption data, and extracting the decryption data from the target format file corresponding to the decryption data, the decryption of the decryption data can be accurately achieved.

[0125] In an exemplary embodiment, the flowchart of the data encryption method is as Figure 4As shown, in response to an interface access request, the server generates an initial key MKEK of 256 bits in size through a random number, performs a confusion process on the initial key MKEK through a confusion algorithm to obtain a first key KEK, and can bind and store the first key KEK with the user identification and the key status. The data to be encrypted DEK is obtained, and the data to be encrypted DEK is bound and stored with the user identification and the data version number. The data to be encrypted DEK and the data version number are used to generate a corresponding JSON format file, that is, the target format file corresponding to the data to be encrypted DEK. Based on AES256 or GCM, the first key KEK is used to encrypt the JSON format file corresponding to the data to be encrypted DEK to obtain an initial ciphertext EDEK. The initial ciphertext EDEK and the expiration information are used to generate a JSON format file corresponding to the initial ciphertext EDEK. Based on base64 encoding, the JSON format file corresponding to the initial ciphertext EDEK is obtained to get a first ciphertext EEDEK. The first ciphertext EEDEK is processed through a confusion algorithm to obtain a confused first ciphertext MK. Based on AES256 or GCM, the confused first ciphertext MK is used to encrypt the initial key MKEK to obtain a second key EMKEK. The second key EMKEK and the expiration information are used to generate a JSON format file corresponding to the second key EMKEK. Based on base64, the JSON format file corresponding to the second key EMKEK is encrypted to obtain a second ciphertext EEKEK. The server returns the first ciphertext EEDEK and the second ciphertext EEKEK to the terminal.

[0126] and Figure 4 The schematic flowchart of the data decryption method corresponding to the data encryption method shown in Figure 5As shown in the figure, the terminal receives the first ciphertext EEDEK and the second ciphertext EEKEK sent by the server, decodes the second ciphertext EEKEK based on base64 to obtain the JSON format file corresponding to the second key EMKEK, extracts the expiration date from the JSON format file corresponding to the second key EMKEK, verifies the validity of the second key EMKEK, and extracts the second key EMKEK from the JSON format file corresponding to the second key EMKEK after the validity verification passes. The first ciphertext EEDEK is obfuscated through an obfuscation algorithm to obtain the obfuscated first ciphertext MK, and the second key EMKEK is decrypted using the obfuscated first ciphertext MK based on AES256 or GCM to obtain the initial key MKEK. The initial key MKEK is obfuscated through an obfuscation algorithm to obtain the first key KEK. The first ciphertext EEDEK is decoded based on base64 to obtain the JSON format file corresponding to the initial ciphertext, extracts the initial ciphertext EDEK from the JSON format file corresponding to the initial ciphertext EDEK, decodes the initial ciphertext EDEK using the first key KEK based on AES256 or GCM to obtain the JSON format file corresponding to the decrypted data, extracts the expiration date information from the JSON format file corresponding to the decrypted data DEK, verifies the validity of the decrypted data DEK based on the expiration date information, and extracts the decrypted data DEK and the version information of the decrypted data DEK from the JSON format file corresponding to the decrypted data DEK after the validity verification passes.

[0127] Among them, the obfuscation process can be implemented through a multi-dimensional obfuscation algorithm. The flow schematic diagram of the multi-dimensional obfuscation algorithm is as Figure 6 shown. The specific process includes:

[0128] (1) Input data:

[0129] - input_data: The string data to be obfuscated

[0130] (2) Feature dimension obfuscation:

[0131] - Calculate the feature factor:

[0132] * Calculate the MD5 value of the input string

[0133] * feature_factor = hexdec(substr(md5(input_data), 0, 8)) % 8

[0134] - Segment processing:

[0135] * segment_size = 8

[0136] * segments[] = Segment the input_data into 8-byte segments

[0137] - Circular shift:

[0138] * Perform a right shift on each segment: segment >> feature_factor

[0139] * Fill the left side with the shifted bits

[0140] * shifted_data = Combine all the shifted segments

[0141] (3) Spatial dimension scrambling:

[0142] - Calculate the group size:

[0143] * data_length = strlen(shifted_data) strlen

[0144] * group_size = ceil(sqrt(data_length))

[0145] - Build the matrix:

[0146] * Create a matrix of group_size * group_size and fill it with data

[0147] * Example: "abcdefghi" ->

[0148] [a b c]

[0149] [d e f]

[0150] [g h i]

[0151] - Matrix transpose:

[0152] * Swap rows and columns to get a new matrix

[0153] * After transpose example:

[0154] [a d g]

[0155] [b e h]

[0156] [c f i]

[0157] - Recombine the data:

[0158] * Read the transposed matrix in row-major order

[0159] * transposed_data = "adgbehcfi"

[0160] (4) Entropy Dimension Confusion:

[0161] - Calculate information entropy:

[0162] * Count the frequency of each character P(x)

[0163] * entropy = -∑(P(x) * log2(P(x)))

[0164] * Example: "aaabbc"

[0165] P(a)=0.5, P(b)=0.33, P(c)=0.17

[0166] entropy = -(0.5*log2(0.5) + 0.33*log2(0.33) + 0.17*log2(0.17))

[0167] - Determine the confusion strength:

[0168] * base_strength = 10

[0169] * strength = ceil(entropy * base_strength)

[0170] * Limit range: min=5, max=50

[0171] - Character transformation:

[0172] * Perform ASCII code transformation on each character:

[0173] new_ascii = (original_ascii + strength) % 256

[0174] * Convert back to characters after transformation

[0175] * mixed_data = Combine all transformed characters

[0176] (5) SHA256 Encryption:

[0177] - Encrypt the confusion result: hashed_data = SHA256(mixed_data)

[0178] (6) Base64 Encoding:

[0179] - Encoding process: encoded_data = Base64(hashed_data)

[0180] (7) Interception process (default interception is 32 bits):

[0181] 1) Feature value extraction:

[0182] - Digital features:

[0183] * Use the regular expression / [0-9] / g to extract all numbers

[0184] * numbers = array of extracted numbers

[0185] 2) Position calculation:

[0186] - Digital position:

[0187] * first_number = numbers[0] or 0

[0188] * last_number = numbers[length - 1] or 0

[0189] * number_pos = first_number + last_number

[0190] - Starting position:

[0191] * start_pos = number_pos

[0192] 3) Final output:

[0193] * Intercept 32 lengths starting from start_pos

[0194] * If the length is less than 32 bits, pad with the number 0 to 32 bits and return

[0195] In the above embodiments, the dynamic change of the key can be realized through random numbers, that is, the initial keys generated for each interface access request are different. Furthermore, the initial key is encrypted and transformed to obtain the first key, the data to be encrypted is encrypted based on the first key to obtain the first ciphertext, then the initial key is encrypted and transformed through the first ciphertext to obtain the second ciphertext corresponding to the initial key, and finally the first ciphertext and the second ciphertext are transmitted to the terminal, which can reduce the risk of key and data leakage and cracking risk, and can realize the secure transmission of keys and data, improving the security of data transmission.

[0196] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear indication in this document, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same moment, but can be executed at different moments, and the execution order of these steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.

[0197] Based on the same inventive concept, an embodiment of the present application also provides a data encryption device for implementing the above-mentioned data encryption method. The implementation solution provided by this device to solve the problem is similar to the implementation solution described in the above method. Therefore, the specific limitations in one or more embodiments of the following data encryption device can refer to the limitations on the data encryption method in the above text, and will not be repeated here.

[0198] In an exemplary embodiment, as Figure 7 shown, a data encryption device is provided, including: a key generation module 702, a confusion processing module 704, a first encryption processing module 706, a second encryption processing module 708, and a key encryption module 710, where:

[0199] The key generation module 702 is configured to generate an initial key by a random number in response to an interface access request;

[0200] The confusion processing module 704 is configured to perform confusion processing on the initial key to obtain a first key;

[0201] The first encryption processing module 706 is configured to obtain data to be encrypted, and perform first encryption processing on the data to be encrypted according to the first key to obtain a first ciphertext;

[0202] The second encryption processing module 708 is configured to perform second encryption processing on the initial key according to the first ciphertext to obtain a second key;

[0203] The key encryption module 710 is configured to encrypt the second key to obtain a second ciphertext.

[0204] In some embodiments, the first encryption processing module 706 is further configured to generate a target format file corresponding to the data to be encrypted; encrypt the target format file corresponding to the data to be encrypted with the first key to obtain an initial ciphertext; generate a target format file corresponding to the initial ciphertext; and encrypt the target format file corresponding to the initial ciphertext to obtain a first ciphertext.

[0205] In some embodiments, the second encryption processing module 708 is further configured to perform a confusion process on the first ciphertext to obtain a confused first ciphertext; and encrypt the initial key with the confused first ciphertext to obtain a second key.

[0206] In some embodiments, the key encryption module 710 is further configured to generate a target format file corresponding to the second key; and encrypt the target format file corresponding to the second key to obtain a second ciphertext.

[0207] Based on the same inventive concept, an embodiment of the present application further provides a data decryption device for implementing the data decryption method involved above. The implementation solution provided by this device for solving problems is similar to the implementation solution described in the above method. Therefore, the specific limitations in one or more embodiments of the data decryption device provided below can refer to the limitations on the data decryption method in the above text and will not be repeated here.

[0208] In an exemplary embodiment, as Figure 8 shown, a data decryption device is provided, including: a ciphertext acquisition module 802, a ciphertext decryption module 804, a first decryption processing module 806, a confusion processing module 808, and a second decryption processing module 810, where:

[0209] The ciphertext acquisition module 802 is configured to acquire a first ciphertext and a second ciphertext;

[0210] The ciphertext decryption module 804 is configured to decrypt the second ciphertext to obtain a second key;

[0211] The first decryption processing module 806 is configured to perform a first decryption process on the second key according to the first ciphertext to obtain an initial key;

[0212] The confusion processing module 808 is configured to perform a confusion process on the initial key to obtain a first key;

[0213] The second decryption processing module 810 is configured to perform a second decryption process on the first ciphertext according to the first key to obtain decrypted data.

[0214] In some embodiments, the first decryption processing module 806 is further configured to perform a confusion process on the first ciphertext to obtain a confused first ciphertext; decrypt the second key with the confused first ciphertext to obtain an initial key.

[0215] In some embodiments, the second decryption processing module 810 is further configured to decrypt the first ciphertext to obtain a target format file corresponding to the initial ciphertext, and extract the initial ciphertext from the target format file corresponding to the initial ciphertext; decrypt the initial ciphertext with the first key to obtain a target format file corresponding to the decryption data; extract the decryption data from the target format file corresponding to the decryption data.

[0216] Each module in the above data encryption device or data decryption device can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in or independent of the processor in the computer device in the form of hardware, or stored in the memory of the computer device in the form of software, so that the processor can call and execute the operations corresponding to the above modules.

[0217] In an exemplary embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as Figure 9 shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store key data. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, a data encryption method is implemented.

[0218] In an exemplary embodiment, a computer device is provided. The computer device may be a terminal, and its internal structure diagram may be as Figure 10As shown in the figure. The computer device includes a processor, a memory, an input / output interface, a communication interface, a display unit, and an input device. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface, the display unit, and the input device are connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals in a wired or wireless manner, and the wireless manner can be achieved through WIFI, a mobile cellular network, near field communication (NFC), or other technologies. When the computer program is executed by the processor, it implements a data decryption method. The display unit of the computer device is used to form a visually visible picture, which can be a display screen, a projection device, or a virtual reality imaging device. The display screen can be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device can be a touch layer covering the display screen, or a button, a trackball, or a touchpad provided on the outer shell of the computer device, or an external keyboard, touchpad, or mouse, etc.

[0219] Those skilled in the art can understand that Figure 9 or Figure 10 the structure shown in the figure is only a block diagram of some structures related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0220] In an exemplary embodiment, a computer device is provided, including a memory and a processor. A computer program is stored in the memory. When the processor executes the computer program, it implements the steps of the data encryption method or the data decryption method in the above embodiment.

[0221] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by the processor, it implements the steps of the data encryption method or the data decryption method in the above embodiment.

[0222] In one embodiment, a computer program product is provided, including a computer program. When the computer program is executed by the processor, it implements the steps of the data encryption method or the data decryption method in the above embodiment.

[0223] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant regulations.

[0224] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in this application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in this application can be general-purpose processors, central processors, graphics processors, digital signal processors, programmable logic devices, data processing logics based on quantum computing, artificial intelligence (AI) processors, etc., without limitation.

[0225] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this application.

[0226] The above-described embodiments merely represent several implementation manners of this application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation to the patent scope of this application. It should be noted that for those of ordinary skill in the art, without departing from the concept of this application, several modifications and improvements can still be made, and these all belong to the protection scope of this application. Therefore, the protection scope of this application shall be subject to the appended claims.

Claims

1. A data encryption method, characterized in that: The method comprises: In response to the interface access request, generating an initial key by a random number; Obfuscating the initial key to obtain a first key; Acquire data to be encrypted, and perform a first encryption process on the data to be encrypted according to the first key to obtain a first ciphertext; Performing a second encryption process on the initial key according to the first ciphertext to obtain a second key; The second key is encrypted to obtain a second ciphertext.

2. The method according to claim 1, characterized in that: The step of performing a first encryption process on the data to be encrypted according to the first key to obtain a first ciphertext includes: Generate a target format file corresponding to the data to be encrypted; Encrypting the target format file corresponding to the data to be encrypted by using the first key to obtain an initial ciphertext; Generate a target format file corresponding to the initial ciphertext; The target format file corresponding to the initial ciphertext is encrypted to obtain a first ciphertext.

3. The method according to claim 1, characterized in that The performing a second encryption process on the initial key according to the first ciphertext to obtain a second key includes: Performing obfuscation processing on the first ciphertext to obtain an obfuscated first ciphertext; The initial key is encrypted using the obfuscated first ciphertext to obtain a second key.

4. The method according to claim 1, characterized in that: The encrypting the second key to obtain a second ciphertext includes: Generate a target format file corresponding to the second key; The target format file corresponding to the second key is encrypted to obtain a second ciphertext.

5. The method according to any one of claims 1 to 4, characterized in that: The obfuscation process includes at least one of feature dimension obfuscation, space dimension obfuscation, entropy dimension obfuscation, encryption, encoding or feature value truncation.

6. A data decryption method, characterized in that: The method comprises: Obtain a first ciphertext and a second ciphertext; decrypting the second ciphertext to obtain a second key; Performing a first decryption process on the second key according to the first ciphertext to obtain an initial key; Obfuscating the initial key to obtain a first key; A second decryption process is performed on the first ciphertext according to the first key to obtain decrypted data.

7. The method according to claim 6, characterized in that The performing a first decryption process on the second key according to the first ciphertext to obtain an initial key includes: Performing obfuscation processing on the first ciphertext to obtain an obfuscated first ciphertext; The second key is decrypted using the obfuscated first ciphertext to obtain an initial key.

8. The method according to claim 6, characterized in that Performing a second decryption process on the first ciphertext according to the first key to obtain decrypted data includes: Decrypting the first ciphertext to obtain a target format file corresponding to the initial ciphertext, and extracting the initial ciphertext from the target format file corresponding to the initial ciphertext; Decrypting the initial ciphertext using the first key to obtain a target format file corresponding to the decrypted data; The decrypted data is extracted from a target format file corresponding to the decrypted data.

9. A data encryption device, characterized in that: The device comprises: A key generation module, used to generate an initial key by a random number in response to an interface access request; An obfuscation processing module, used to perform obfuscation processing on the initial key to obtain a first key; A first encryption processing module, used for obtaining data to be encrypted, and performing a first encryption process on the data to be encrypted according to the first key to obtain a first ciphertext; A second encryption processing module, used for performing a second encryption processing on the initial key according to the first ciphertext to obtain a second key; The key encryption module is used to encrypt the second key to obtain a second ciphertext.

10. A data decryption device, characterized in that: The device comprises: A ciphertext acquisition module, used to acquire a first ciphertext and a second ciphertext; A ciphertext decryption module, used to decrypt the second ciphertext to obtain a second key; A first decryption processing module, configured to perform a first decryption process on the second key according to the first ciphertext to obtain an initial key; An obfuscation processing module, used to perform obfuscation processing on the initial key to obtain a first key; The second decryption processing module is used to perform a second decryption process on the first ciphertext according to the first key to obtain decrypted data.

11. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 8 are implemented.

12. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 8 are implemented.

13. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 8 are implemented.