Data encryption method and device, computer equipment and storage medium

By dynamically switching the key pair between the first device and the second device, and updating the key pair according to the network environment and effective use time, the problem of low data security caused by key pair leakage in the prior art is solved, and higher data security and device performance are achieved.

CN120217399APending Publication Date: 2025-06-27WUHAN UNITED IMAGING HEALTHCARE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311847121.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-27
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

When the key pair is leaked, existing data encryption technology leads to low security of encrypted data, and it is difficult to dynamically manage the update frequency and effective duration of the key pair.

Method used

By dynamically switching the key pair between the first device and the second device, the key pair used for encryption is determined by using the comparison result of the first check value and the second check value, and the key pair is dynamically updated according to the network environment and the effective use duration.

Benefits of technology

Improves encrypted data security, reduces the risk of key pair leakage, and improves device performance, avoiding the need to frequently read key pairs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120217399A_ABST
    Figure CN120217399A_ABST
Patent Text Reader

Abstract

The invention relates to a data encryption method and device, computer equipment and a storage medium. The first device receives a first verification value and a first key pair sent by the second device at the current time; and determining a comparison result of the first verification value and the second verification value, and encrypting data of the first device according to the comparison result. Wherein the first verification value is a verification value determined according to a first key pair, and the second verification value is a verification value determined according to a second key pair received last time. In the embodiment of the invention, according to the comparison result of the first verification value and the second verification value, whether the first key pair sent by the second equipment changes relative to the second key pair sent last time is determined, and the corresponding key pair is dynamically switched to encrypt the data of the first equipment, so that the security of the encrypted data is improved; the first device does not need to read the key pair every time, and the performance of the first device is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technologies, and particularly to a data encryption method, apparatus, computer device, and storage medium. Background Art

[0002] A large amount of sensitive data of users is involved in medical information software. To ensure the security of the sensitive data of users, it is necessary to use a key pair to encrypt the sensitive data to obtain encrypted data, and store and transmit the encrypted data. Therefore, the security requirements for the key pair are very high.

[0003] Currently, data encryption adopts a method of presetting multiple groups of key pairs to isolate each environment or each application. However, for the same environment or the same application, only one group of key pairs can be used. If the key pair is leaked, the security of the encrypted data is relatively low. Summary of the Invention

[0004] Based on this, in view of the above technical problems, it is necessary to provide a data encryption method, apparatus, computer device, and storage medium that can improve the security of encrypted data.

[0005] In a first aspect, this application provides a data encryption method, including:

[0006] A first device receives a first verification value and a first key pair sent by a second device for the current time; the first verification value is a verification value determined according to the first key pair;

[0007] Determine the comparison result between the first verification value and a second verification value; the second verification value is a verification value determined according to the second key pair received last time;

[0008] Encrypt the data of the first device according to the comparison result.

[0009] In one embodiment, if the comparison result is that the first verification value is consistent with the second verification value, then encrypting the data of the first device according to the comparison result includes:

[0010] Encrypt the data of the first device according to the second key pair.

[0011] In one embodiment, if the comparison result is that the first verification value is inconsistent with the second verification value, then encrypting the data of the first device according to the comparison result includes:

[0012] Encrypt the data of the first device according to the first key pair.

[0013] In one embodiment, encrypting the data of the first device according to the first key pair includes:

[0014] Generate a third check value according to the first key pair;

[0015] When the first check value is consistent with the third check value, encrypt the data of the first device according to the first key pair.

[0016] In one embodiment, the first key pair and the second key pair include an effective usage duration.

[0017] In a second aspect, the present application further provides a data encryption method, including:

[0018] The second device sends the first check value and the first key pair of the current time to the first device, so that the first device determines the comparison result between the first check value and the second check value, and encrypts the data of the first device according to the comparison result; the first check value is the check value determined according to the first key pair, and the second check value is the check value determined according to the second key pair received last time.

[0019] In one embodiment, the method further includes:

[0020] Determine an update frequency according to the network environment of the second device, and generate the first key pair based on the update frequency, or

[0021] Generate the first key pair every preset duration.

[0022] In a third aspect, the present application further provides a data encryption device, including:

[0023] A receiving module, configured to receive, by the first device, the first check value and the first key pair sent by the second device for the current time; the first check value is the check value determined according to the first key pair;

[0024] A determining module, configured to determine the comparison result between the first check value and the second check value; the second check value is the check value determined according to the second key pair received last time;

[0025] An encryption module, configured to encrypt the data of the first device according to the comparison result.

[0026] In a fourth aspect, the present application further provides a data encryption device, including:

[0027] A sending module, configured to send, by a second device, a first verification value and a first key pair of the current time to a first device, so that the first device determines a comparison result between the first verification value and a second verification value, and encrypts data of the first device according to the comparison result; the first verification value is a verification value determined according to the first key pair, and the second verification value is a verification value determined according to a second key pair received last time.

[0028] In a fifth aspect, the present application further provides a computer device, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:

[0029] The first device receives the first verification value and the first key pair sent by the second device for the current time; the first verification value is a verification value determined according to the first key pair;

[0030] Determine a comparison result between the first verification value and the second verification value; the second verification value is a verification value determined according to a second key pair received last time;

[0031] Encrypt data of the first device according to the comparison result.

[0032] In a sixth aspect, the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:

[0033] The first device receives the first verification value and the first key pair sent by the second device for the current time; the first verification value is a verification value determined according to the first key pair;

[0034] Determine a comparison result between the first verification value and the second verification value; the second verification value is a verification value determined according to a second key pair received last time;

[0035] Encrypt data of the first device according to the comparison result.

[0036] In a seventh aspect, the present application further provides a computer program product, including a computer program. When the computer program is executed by a processor, the following steps are implemented:

[0037] The first device receives the first verification value and the first key pair sent by the second device for the current time; the first verification value is a verification value determined according to the first key pair;

[0038] Determine a comparison result between the first verification value and the second verification value; the second verification value is a verification value determined according to a second key pair received last time;

[0039] Encrypt data of the first device according to the comparison result.

[0040] In the above data encryption method, device, computer device and storage medium, the first device receives the first verification value and the first key pair sent by the second device for the current time; determines the comparison result between the first verification value and the second verification value, and encrypts the data of the first device according to the comparison result. Wherein, the first verification value is the verification value determined according to the first key pair, and the second verification value is the verification value determined according to the second key pair received last time. In the embodiments of the present application, according to the comparison result between the first verification value and the second verification value, it is determined whether the first key pair sent by the second device has changed relative to the second key pair sent last time, and the corresponding key pair is dynamically switched to encrypt the data of the first device, improving the security of the encrypted data. Moreover, the first device does not need to read the key pair every time, improving the performance of the first device. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required for the description of the embodiments or related technologies. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0042] Figure 1 It is an application environment diagram of the data encryption method in an embodiment;

[0043] Figure 2 It is a flowchart of the data encryption method in an embodiment;

[0044] Figure 3 It is a structural block diagram of the data encryption device in an embodiment;

[0045] Figure 4 It is an internal structure diagram of a computer device in an embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0046] In order to make the purpose, technical solutions and advantages of the present application clearer, the following further details the present application in conjunction with the drawings and embodiments. It should be understood that the specific embodiments described here are only used to explain the present application and are not used to limit the present application.

[0047] The data encryption method provided by the embodiments of the present application can be applied to, for example Figure 1In the application environment shown. Among them, the first device 102 communicates with the second device 104 through a network. The data storage system can store the data that the second device 104 needs to process. The data storage system can be integrated on the second device 104, or can be placed on the cloud or other network servers. Among them, the first device 102 can be, but is not limited to, various personal computers, laptop computers, smart phones, tablet computers, Internet of Things devices, and portable wearable devices. The Internet of Things devices can be smart speakers, smart TVs, smart air conditioners, smart in-vehicle devices, etc. The portable wearable devices can be smart watches, smart bracelets, head-mounted devices, etc. The second device 104 can be implemented by an independent server or a server cluster composed of multiple servers.

[0048] In an exemplary embodiment, as Figure 2 shown, a data encryption method is provided. Taking the method applied to Figure 1 the first device in as an example for description, it includes the following S202 to S203. Among them:

[0049] S201, the first device receives the first check value and the first key pair sent by the second device for the current time; the first check value is the check value determined according to the first key pair.

[0050] Optionally, the first key pair can be a symmetric encryption algorithm, for example, RC algorithm, BlowFish algorithm, and DESTripleDES algorithm, etc.; it can also be an asymmetric encryption algorithm, for example, RSA algorithm, DSA algorithm, ECC algorithm, and DH algorithm, etc.

[0051] In this embodiment, the second device generates the first key pair by means of external file mounting, and performs verification on the first key pair through verification methods such as checksum, exclusive-or verification, or CRC verification method, etc., to obtain the first check value. For example, the CRC32 algorithm is used to verify the first key pair to obtain the first check value. CRC32 = X 32 +X 26 +X 23 +X 22 +X 16 +X 12 +X 11 +X 10 +X 8 +X 7 +X 5 +X 4 +X 2 +X 1 +1, where X is the first key pair and CRC32 is the obtained first check value.

[0052] The second device can generate a first key pair at preset time intervals, generate a first verification value based on the first key pair, send the first key pair and the first verification value to the first device, and the first device receives the first key pair and the first verification value.

[0053] The second device can also set a deadline timestamp / valid duration for the key pair to mark the validity period. Each validity period is globally unique, and the validity period markings of each key pair can be the same or different. For example, the deadline timestamp set for the second key pair generated last time is xx year xx month xx day 13:00. The second device conducts real-time detection. If it detects that the second key pair is approaching the deadline timestamp, it generates the first key pair, sets a deadline timestamp / valid duration for the first key pair, and marks the validity period.

[0054] It is also possible to generate the first key pair when the IP address of the second device changes, generate a first verification value based on the first key pair, send the first key pair and the first verification value to the first device, and the first device receives the first key pair and the first verification value. For example, the original IP address of the second device is in Beijing, and the current IP address of the second device is in Tianjin. When the second device detects a change in its own address during startup, it triggers the second device to generate the first key pair, generates a first verification value based on the first key pair, and sends the first key pair and the first verification value to the first device.

[0055] Alternatively, generate the first key pair when the network environment of the second device changes. For example, when the second device is deployed from a European private cloud to a US private cloud, when the second device starts running and detects a change in its network environment, it automatically generates the first key pair according to the time zone where the second device is located to ensure data access isolation between private clouds.

[0056] Alternatively, determine the update frequency according to the network environment of the second device, generate the first key pair according to the update frequency, generate a first verification value based on the first key pair, send the first key pair and the first verification value to the first device, and the first device receives the first key pair and the first verification value. In each of the above methods, the second device can force the update of the key pair and urgently repair it when the key pair is leaked.

[0057] S202, determine the comparison result between the first verification value and the second verification value; the second verification value is the verification value determined according to the second key pair received last time.

[0058] Among them, the first verification value and the second verification value are unique, and there is a one-to-one correspondence between the verification value and the key pair. That is, when the key pair changes, the calculated verification value will also change.

[0059] If the second device sets a deadline timestamp / valid duration for the first key pair, when the first device uses it, it needs to compare whether the current key pair is within the valid period, which can reduce the risk of key pair leakage.

[0060] In this embodiment, the comparison result is whether the first check value and the second check value are the same. The first device can determine the comparison result of the first check value and the second check value by taking the difference. If the difference is 0, it proves that the first check value and the second check value are the same; it can also obtain the quotient value of the first check value and the second check value to determine the comparison result. If the quotient value is 1, it proves that the first check value and the second check value are the same; or it can determine the comparison result of the first check value and the second check value by comparing characters one by one.

[0061] S203, encrypt the data of the first device according to the comparison result.

[0062] In this embodiment, the first device determines whether the first key pair has changed relative to the second key pair received last time according to the comparison result. If the first key pair has changed, the first device switches to the first key pair and encrypts the data of the first device based on the first key pair. If the first key pair has not changed, the first device uses the second key pair received last time to encrypt the data of the first device.

[0063] In the above data encryption method, the first device receives the first check value and the first key pair sent by the second device currently; determines the comparison result of the first check value and the second check value, and encrypts the data of the first device according to the comparison result. Among them, the first check value is the check value determined according to the first key pair, and the second check value is the check value determined according to the second key pair received last time. In the embodiment of the present application, according to the comparison result of the first check value and the second check value, it is determined whether the first key pair sent by the second device has changed relative to the second key pair sent last time, and the corresponding key pair is dynamically switched to encrypt the data of the first device, improving the security of the encrypted data. Moreover, the first device does not need to read the key pair every time, improving the performance of the first device.

[0064] In one embodiment, encrypting the data of the first device according to the comparison result may include: when the comparison result is that the first check value is the same as the second check value, encrypt the data of the first device according to the second key pair; when the comparison result is that the first check value is different from the second check value, encrypt the data of the first device according to the first key pair.

[0065] In this embodiment, when the comparison result is that the first check value is the same as the second check value, that is, the first key pair sent by the second device is the same as the second key pair sent last time, the first device does not need to read the first key pair again and directly encrypts the data of the first device according to the second key pair.

[0066] In the case where the comparison result is that the first verification value is inconsistent with the second verification value, that is, the first key pair sent by the second device is inconsistent with the second key pair sent last time, the first device needs to read the first key pair and encrypt the data of the first device according to the first key pair.

[0067] In the embodiment of the present application, in the case where the comparison result is that the first verification value is consistent with the second verification value, the data of the first device is encrypted according to the second key pair; in the case where the comparison result is that the first verification value is inconsistent with the second verification value, the data of the first device is encrypted according to the first key pair. In this embodiment, according to the comparison result of the first verification value and the second verification value, it is determined whether to read the first key pair, and a dynamic switch is made between the first key pair and the second key pair. In the case where the comparison result is that the first verification value is consistent with the second verification value, the data of the first device is directly encrypted according to the second key pair, and there is no need to read the first key pair each time, improving the performance of the first device.

[0068] In one embodiment, encrypting the data of the first device according to the first key pair includes:

[0069] Generating a third verification value according to the first key pair; in the case where the first verification value is consistent with the third verification value, encrypting the data of the first device according to the first key pair.

[0070] In this embodiment, the first device receives the first verification value. In the case where the first verification value is inconsistent with the second verification value, the first device generates a third verification value based on the read first key pair by using the same verification method as the second device. In the case where the third verification value is consistent with the first verification value, the data of the first device is encrypted by using the first key pair.

[0071] In the embodiment of the present application, in the case where the first verification value is consistent with the third verification value, the data of the first device is encrypted according to the first key pair. The first device uses the third verification value to verify the received first key pair, preventing the first key pair sent by the second device from being tampered with and improving the reliability of the first key pair.

[0072] In one embodiment, a data encryption method is provided, and this method is applied to Figure 1 the second device in, and includes the following steps: The second device sends the current first verification value and the first key pair to the first device for the first device to determine the comparison result of the first verification value and the second verification value, and encrypt the data of the first device according to the comparison result; the first verification value is the verification value determined according to the first key pair, and the second verification value is the verification value determined according to the second key pair received last time.

[0073] For the specific implementation manner, reference may be made to the above Figure 2The embodiments shown.

[0074] In one embodiment, the above data encryption method further includes: determining an update frequency according to the network environment of the second device, and generating a first key pair based on the update frequency, or generating a first key pair every preset time period.

[0075] In this embodiment, the update frequency is determined according to the network environment of the second device. For example, if the network environment of the second device is all intranet, the update frequency of the key pair is determined to be 24 hours. If the network environment of the second device is all extranet, the update frequency of the key pair is determined to be 12 hours. The second device generates a first key pair based on the update frequency or every preset time period, and generates a first check value using the first key pair.

[0076] In this embodiment, two ways of generating the first key pair are provided. For different application scenarios, different generation methods can be selected, providing multiple choices for users, and moreover, the security of the first key pair can be improved.

[0077] In one embodiment, the first key pair and the second key pair include an effective usage duration.

[0078] In this embodiment, the first key pair and the second key pair include an effective usage duration. After exceeding the effective usage duration, the first device can no longer use the first key pair and / or the second key pair to encrypt the data of the first device, improving the security of the first key pair and / or the second key pair, and thus improving the security of the encrypted data.

[0079] It should be understood that although the steps in the flowcharts involved in the above embodiments are sequentially shown according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.

[0080] Based on the same inventive concept, an embodiment of the present application further provides a data encryption device for implementing the above-mentioned data encryption method. The implementation solutions provided by this device to solve problems are similar to the implementation solutions described in the above method. Therefore, the specific limitations in one or more embodiments of the following data encryption device can refer to the limitations on the data encryption method in the above text, and will not be repeated here.

[0081] In an exemplary embodiment, as Figure 3 shown, a data encryption device is provided, including: a receiving module 11, a determining module 12, and an encryption module 13, where:

[0082] The receiving module 11 is configured to receive, by a first device, a first check value and a first key pair sent by a second device for the current time; the first check value is a check value determined according to the first key pair;

[0083] The determining module 12 is configured to determine a comparison result between the first check value and a second check value; the second check value is a check value determined according to a second key pair received last time;

[0084] The encryption module 13 is configured to encrypt data of the first device according to the comparison result.

[0085] In one embodiment, the encryption module includes:

[0086] A first encryption unit configured to encrypt data of the first device according to the second key pair.

[0087] In one embodiment, the encryption module further includes:

[0088] A second encryption unit configured to encrypt data of the first device according to the first key pair.

[0089] In one embodiment, the second encryption unit is further configured to generate a third check value according to the first key pair; in the case where the first check value is consistent with the third check value, encrypt data of the first device according to the first key pair.

[0090] In one embodiment, the data encryption device further includes:

[0091] A sending module configured to send, by the second device, the first check value and the first key pair for the current time to the first device, so that the first device determines a comparison result between the first check value and the second check value, and encrypts data of the first device according to the comparison result; the first check value is a check value determined according to the first key pair, and the second check value is a check value determined according to a second key pair received last time.

[0092] In one embodiment, the data encryption device further includes:

[0093] A generating module configured to determine an update frequency according to the network environment of the second device, and generate a first key pair based on the update frequency; or generate a first key pair every preset time period.

[0094] In one embodiment, the first key pair and the second key pair include an effective usage duration.

[0095] Each module in the above data encryption device can be implemented in whole or in part by software, hardware, and their combination. Each of the above modules can be embedded in the processor of the computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to each of the above modules.

[0096] In an exemplary embodiment, a computer device is provided. The computer device can be a server, and its internal structure diagram can be as Figure 4 shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store data related to data encryption. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals through a network connection. When the computer program is executed by the processor, it implements a data encryption method.

[0097] Those skilled in the art can understand that Figure 4 the structure shown in

[0098] is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.

[0099] The first device receives the first check value and the first key pair sent by the second device for the current time; the first check value is the check value determined according to the first key pair;

[0100] Determine the comparison result between the first check value and the second check value; the second check value is the check value determined according to the second key pair received last time;

[0101] Encrypt the data of the first device according to the comparison result.

[0102] In an embodiment, when the processor executes the computer program, the following steps are also implemented:

[0103] Encrypt the data of the first device according to the second key.

[0104] In one embodiment, when the processor executes the computer program, the following steps are further implemented:

[0105] Encrypt the data of the first device according to the first key.

[0106] In one embodiment, when the processor executes the computer program, the following steps are further implemented:

[0107] Generate a third check value according to the first key;

[0108] When the first check value is consistent with the third check value, encrypt the data of the first device according to the first key.

[0109] In one embodiment, when the processor executes the computer program, the following steps are further implemented:

[0110] The second device sends the first check value and the first key pair of the current time to the first device for the first device to determine the comparison result of the first check value and the second check value, and encrypt the data of the first device according to the comparison result; the first check value is the check value determined according to the first key pair, and the second check value is the check value determined according to the second key pair received last time.

[0111] In one embodiment, when the processor executes the computer program, the following steps are further implemented:

[0112] Determine the update frequency according to the network environment of the second device, and generate the first key pair based on the update frequency; or,

[0113] Generate the first key pair every preset time period.

[0114] In one embodiment, the first key pair and the second key pair include an effective usage duration.

[0115] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:

[0116] The first device receives the first check value and the first key pair sent by the second device for the current time; the first check value is the check value determined according to the first key pair;

[0117] Determine the comparison result of the first check value and the second check value; the second check value is the check value determined according to the second key pair received last time;

[0118] Encrypt the data of the first device according to the comparison result.

[0119] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0120] Encrypt the data of the first device according to the second key.

[0121] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0122] Encrypt the data of the first device according to the first key.

[0123] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0124] Generate a third check value according to the first key;

[0125] When the first check value and the third check value are consistent, encrypt the data of the first device according to the first key.

[0126] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0127] The second device sends the first check value and the first key pair of the current time to the first device for the first device to determine the comparison result of the first check value and the second check value, and encrypt the data of the first device according to the comparison result; the first check value is the check value determined according to the first key pair, and the second check value is the check value determined according to the second key pair received last time.

[0128] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0129] Determine the update frequency according to the network environment of the second device, and generate the first key pair based on the update frequency; or,

[0130] Generate the first key pair every preset time period.

[0131] In one embodiment, the first key pair and the second key pair include an effective usage duration.

[0132] In one embodiment, a computer program product is provided, including a computer program, which when executed by a processor implements the following steps:

[0133] The first device receives the first check value and the first key pair sent by the second device for the current time; the first check value is the check value determined according to the first key pair;

[0134] Determine the comparison result of the first check value and the second check value; the second check value is the check value determined according to the second key pair received last time;

[0135] Encrypt the data of the first device according to the comparison result.

[0136] In one embodiment, when the processor executes the computer program, the following steps are further implemented:

[0137] Encrypt the data of the first device according to the second key.

[0138] In one embodiment, when the processor executes the computer program, the following steps are further implemented:

[0139] Encrypt the data of the first device according to the first key.

[0140] In one embodiment, when the processor executes the computer program, the following steps are further implemented:

[0141] Generate a third check value according to the first key;

[0142] When the first check value is consistent with the third check value, encrypt the data of the first device according to the first key.

[0143] In one embodiment, when the processor executes the computer program, the following steps are further implemented:

[0144] The second device sends the current first check value and the first key pair to the first device for the first device to determine the comparison result of the first check value and the second check value, and encrypt the data of the first device according to the comparison result; the first check value is the check value determined according to the first key pair, and the second check value is the check value determined according to the second key pair received last time.

[0145] In one embodiment, when the processor executes the computer program, the following steps are further implemented:

[0146] Determine the update frequency according to the network environment of the second device, and generate the first key pair based on the update frequency; or,

[0147] Generate the first key pair every preset time period.

[0148] In one embodiment, the first key pair and the second key pair include an effective usage duration.

[0149] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant regulations.

[0150] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memories can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memories can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., without limitation.

[0151] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.

[0152] The above-described embodiments merely represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.

Claims

1. A data encryption method, characterized in that, The method includes: A first device receives a first verification value and a first key pair sent by a second device in the current instance; the first verification value is a verification value determined according to the first key pair; Determine the comparison result between the first verification value and a second verification value; the second verification value is a verification value determined according to a second key pair received in the previous instance; Encrypt the data of the first device according to the comparison result.

2. The method according to claim 1, wherein If the comparison result is that the first verification value is consistent with the second verification value, then encrypting the data of the first device according to the comparison result includes: Encrypt the data of the first device according to the second key pair.

3. The method according to claim 1, characterized in that, If the comparison result is that the first verification value is inconsistent with the second verification value, then encrypting the data of the first device according to the comparison result includes: Encrypt the data of the first device according to the first key pair.

4. The method according to claim 3, wherein Encrypting the data of the first device according to the first key pair includes: Generate a third verification value according to the first key pair; When the first verification value is consistent with the third verification value, encrypt the data of the first device according to the first key pair.

5. The method according to any one of claims 1 to 4, characterized in that, The first key pair and the second key pair include an effective usage duration.

6. A data encryption method, characterized in that, The method includes: A second device sends a first verification value and a first key pair in the current instance to a first device for the first device to determine the comparison result between the first verification value and the second verification value and encrypt the data of the first device according to the comparison result; the first verification value is a verification value determined according to the first key pair, and the second verification value is a verification value determined according to a second key pair received in the previous instance.

7. The method according to claim 6, characterized in that, The method further includes: Determine an update frequency according to the network environment of the second device and generate the first key pair based on the update frequency; or, Generate the first key pair every preset duration.

8. A data encryption device, characterized in that, The apparatus includes: A receiving module, configured to receive, by a first device, a first verification value and a first key pair sent by a second device in the current instance; the first verification value is a verification value determined according to the first key pair; A determining module, configured to determine the comparison result between the first verification value and a second verification value; the second verification value is a verification value determined according to a second key pair received in the previous instance; An encryption module, configured to encrypt the data of the first device according to the comparison result.

9. A data encryption device, characterized in that, The apparatus includes: A sending module, configured to send, by a second device, a first verification value and a first key pair in the current instance to a first device for the first device to determine the comparison result between the first verification value and the second verification value and encrypt the data of the first device according to the comparison result; the first verification value is a verification value determined according to the first key pair, and the second verification value is a verification value determined according to a second key pair received in the previous instance.

10. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.

11. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

12. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.