Micro-service communication encryption method based on lightweight password PRESENT
By using the lightweight cryptographic algorithm PRESENT for encryption and decryption in the microservice architecture, the problems of high computing complexity and high resource consumption in high frequency and low latency communications are solved, and data transmission security and performance are achieved.
Patent Information
- Application Number
- CN202510369692.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-27
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2045-03-27
AI Technical Summary
In the microservice architecture, traditional encryption solutions have high computing complexity and high resource consumption, making it difficult to meet the communication needs of high frequency and low latency, which may cause problems such as service response delay and container resource contention.
The microservice communication encryption method based on the lightweight cryptographic algorithm PRESENT is adopted. Multiple iterations are performed through the round functions of the PRESENT algorithm for encryption and decryption, reducing computing overhead and memory consumption.
While ensuring data transmission security, it meets the performance and resource consumption requirements in the microservice architecture, improving service response speed and container resource utilization efficiency.
Smart Images

Figure CN120238286A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of microservice communication security, and in particular, to a microservice communication encryption method based on the lightweight cipher PRESENT. Background Art
[0002] With the rapid development of cloud computing and containerization technologies, the microservice architecture has become the mainstream mode for distributed system development due to its characteristics such as high cohesion, low coupling, and dynamic scalability. In the microservice architecture, each service module is usually deployed in the form of lightweight Docker containers, and resource isolation and rapid orchestration are achieved through virtualization technologies. However, the communication between microservices relies on network interface calls. In a containerized environment, communication links across nodes and clusters may be exposed to the internal network or public network, resulting in security risks such as eavesdropping, tampering, and replay attacks on sensitive data.
[0003] In the prior art, although traditional encryption schemes (such as AES, SM4, etc.) have relatively high security, their high computational complexity and large resource consumption make it difficult to meet the high-frequency and low-latency communication requirements in the microservice architecture, and may cause problems such as service response latency and container resource contention. Summary of the Invention
[0004] The purpose of the present invention is to provide a microservice communication encryption method based on the lightweight cipher PRESENT, which can ensure the security of data transmission while meeting the requirements for performance and resource consumption in the microservice architecture.
[0005] To achieve the above purpose, the present invention provides a microservice communication encryption method based on the lightweight cipher PRESENT, and the steps include:
[0006] S1. The client module receives the plaintext data input by the user (including text, file, or message content), forms the data to be encrypted or decrypted, and sends an encryption or decryption request to the message queue module, and the request information includes the plaintext or ciphertext data to be processed;
[0007] S2. The message queue module responds to the sent encryption or decryption request information and forwards the encryption or decryption request information to the Docker encryption microservice module or the Docker decryption microservice module;
[0008] S3. After the Docker encryption microservice module obtains the encryption request forwarded by the message queue module, it performs an encryption operation, executes multiple rounds of iteration using the round function of the PRESENT algorithm to obtain the corresponding ciphertext, and transmits the encrypted ciphertext to the message queue module;
[0009] S4. After the Docker decryption microservice module obtains the decryption request forwarded by the message queue module, it performs the decryption operation, restores the initial plaintext message through the PRESENT algorithm, and transmits the initial plaintext message to the message queue module;
[0010] S5. The result processing module receives the ciphertext or plaintext passed by the message queue module, and then returns it to the client module to complete the feedback of the result message and form a communication closed loop.
[0011] Preferably, the message queue module uses a dual-queue mechanism to implement task scheduling. The encryption request and the decryption request enter the instruction queue list for classification processing respectively. When an encryption request is detected, the plaintext data is forwarded to the Docker encryption microservice module, and an encryption data identifier is established and added to the data queue list; when the decryption request is triggered, the corresponding ciphertext data is automatically matched according to the data identifier and transmitted to the Docker decryption microservice module in a targeted manner.
[0012] Preferably, the encryption process of the Docker encryption microservice module specifically includes:
[0013] S31. The Docker encryption microservice module obtains the encryption request forwarded by the message queue module and reads the plaintext data;
[0014] S32. Generate a round key and perform multiple rounds of iteration on each plaintext data, and use the corresponding round key in each round;
[0015] S33. After all rounds are completed, perform a whitening key operation to obtain the final ciphertext;
[0016] S34. Return the ciphertext data to the message queue module.
[0017] Preferably, each round function in step S32 includes round key addition, S-box substitution, and P permutation, and is iterated 31 times in total. Specifically:
[0018] Round key addition: At the beginning of each round of encryption, the plaintext data state i is XORed with the round key K i of the current round. The formula is:
[0019]
[0020] S-box substitution: Use a 4-bit S-box. Let x and y be 4-bit binary numbers, x be the input, and y be the output. The S-box operation is expressed as:
[0021] y = S(x);
[0022] P permutation: After S-box substitution, perform P permutation to rearrange each bit of the data.
[0023] Preferably, in step S32, a round function corresponding to each round is generated. After the Docker encryption microservice module is started, an 80-bit master key K is read from the client module. This master key is generated by a random number generator. The master key K = [k 79 , k 78 , …, k0] is placed into a shift register, and multiple round keys K i are generated through a key expansion algorithm. Among them, the first 64 bits of the master key are taken in the first round, and each subsequent round key is generated based on the previous round key.
[0024] Preferably, the key expansion algorithm includes cyclic shift, S-box substitution, and round constant addition.
[0025] Preferably, the decryption process of the Docker decryption microservice module is opposite to the encryption process of the Docker encryption microservice module, including inverse P permutation, inverse S-box substitution, and round key addition. First, a round key addition operation is performed using the round key K 31 . Then, the ciphertext is restored in state using the corresponding round key in each round. After the iteration is completed, the initial plaintext is obtained. Finally, the initial plaintext is transmitted to the message queue module.
[0026] Therefore, the present invention adopts the above-mentioned microservice communication encryption method based on the lightweight cipher PRESENT, which can ensure the security of data transmission while meeting the requirements for performance and resource consumption in the microservice architecture. The core idea of this method is to use the PRESENT algorithm to encrypt the communication between microservices. The PRESENT algorithm has low computational overhead and memory consumption and is suitable for running in resource-constrained environments.
[0027] Next, through the accompanying drawings and embodiments, the technical solutions of the present invention will be further described in detail. Description of the Drawings
[0028] Figure 1 It is a flowchart of a microservice communication framework based on Docker according to an embodiment of the present invention;
[0029] Figure 2 It is a schematic diagram of the encryption process of the PRESENT algorithm according to an embodiment of the present invention;
[0030] Figure 3 It is a schematic diagram of key expansion according to an embodiment of the present invention;
[0031] Figure 4 It is a schematic diagram of the decryption process of the PRESENT algorithm according to an embodiment of the present invention. Detailed Embodiments
[0032] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Components of the embodiments of the present invention described and illustrated in the drawings here can be arranged and designed in various different configurations. In the description of the present invention, it should be noted that the orientation or positional relationship indicated by the terms "upper", "lower", "inner", "outer", etc. is based on the orientation or positional relationship shown in the drawings, or the orientation or positional relationship in which the product of this invention is customarily placed during use. It is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and thus should not be construed as a limitation of the present invention.
[0033] Embodiment
[0034] The present invention provides a microservice communication encryption model based on the lightweight cipher PRESENT, including a client module, a message queue module, a Docker encryption microservice module, a Docker decryption microservice module, and a result processing module. The specific content of each module is as follows:
[0035] Client module: It is involved in communication requests and result reception. The communication requests include encryption requests and decryption requests, and result reception is to receive the result messages transmitted by the result processing module. After receiving the user input information, the client module sends an encryption or decryption request message to the message queue module. The encryption or decryption request is sent to the message queue module, and the message queue module performs the next operation.
[0036] Message queue module: Responds to the sent encryption or decryption request, transmits data to the microservice according to the request, and passes the intermediate results. The encryption or decryption request is placed in the instruction queue list. After receiving the encryption request, the message queue module forwards it to the Docker encryption microservice module, and then puts the encrypted data into the data queue list. Similarly, after receiving the decryption request, the ciphertext to be decrypted is transmitted to the Docker decryption microservice module through the message queue, and the decrypted plaintext is returned to the result processing module. This part ensures the confidentiality of the sender's message during transmission and prevents it from being stolen or tampered with.
[0037] Docker encryption microservice module: Used for key generation and performing encryption operations to ensure the secure encryption of data. For the received initial plaintext, it is encrypted through the iterative PRESENT algorithm encryption round function to obtain the corresponding ciphertext.
[0038] Docker Decryption Microserver Module: It is used to gradually restore the plaintext through the inverse round function to ensure data integrity. For the received ciphertext, perform decryption operations and restore the initial plaintext message through the PRESENT algorithm. The decryption process is the reverse of the encryption process, and the initial plaintext is gradually restored by iteratively performing multiple rounds of decryption round functions.
[0039] Result Processing Module: As the exit of communication messages, it is responsible for result processing and return. After encryption and decryption are completed, the result processing module receives the encrypted ciphertext or decrypted plaintext. Finally, the communication closed-loop is completed through the result processing module, that is, it is returned to the client module through the result processing module to ensure the security and integrity of end-to-end communication.
[0040] As Figure 1 shown, the present invention provides a microservice communication encryption method based on the lightweight cipher PRESENT, and the steps include:
[0041] S1. The client module receives the plaintext data input by the user (including text, file, or message content), forms the encrypted or decrypted data, sends an encrypted or decrypted request to the message queue module through the interface, and at the same time associates and listens to the response channel to receive the subsequent processing results. Among them, the request information includes the plaintext or ciphertext data to be processed.
[0042] S2. The message queue module responds to the sent encrypted or decrypted request information and forwards the encrypted or decrypted request information to the Docker encryption microserver module or the Docker decryption microserver module.
[0043] In this embodiment, the message queue module uses a dual-queue mechanism to implement task scheduling. The encryption requests and decryption requests enter the instruction queue list respectively for classification processing to ensure the efficient execution of tasks and the consistency of data time sequence. When an encryption request is detected, the plaintext data is forwarded to the Docker encryption microserver module, and an encrypted data identifier is established and added to the data queue list; when a decryption request is triggered, the corresponding ciphertext data is automatically matched according to the data identifier and transmitted to the Docker decryption microserver module.
[0044] S3. After the Docker encryption microserver module obtains the encryption request forwarded by the message queue module, it performs encryption operations, uses the round function of the PRESENT algorithm to perform multiple rounds of iteration to obtain the corresponding ciphertext, and transmits the encrypted ciphertext to the message queue module.
[0045] In this embodiment, the encryption process of the Docker encryption microserver module specifically includes:
[0046] S31. The Docker encryption microserver module obtains the encryption request forwarded by the message queue module and reads the plaintext data.
[0047] S32. Generate round keys and perform 31 rounds of iteration on each plaintext data, using the corresponding round key in each round. Among them, as Figure 2 shown, each round function includes round key addition, S-box substitution, and P-permutation. Specifically:
[0048] Round key addition: At the beginning of each round of encryption, the plaintext data state i is XORed with the round key K i of the current round. The XOR operation combines the plaintext data and the key, increasing the complexity of encryption. That is:
[0049]
[0050] S-box substitution: Use a 4-bit S-box. Let x and y be 4-bit binary numbers, x be the input, and y be the output. The S-box operation is expressed as:
[0051] y = S(x);
[0052] The S-box substitution rules are as follows in the table.
[0053] Table 1 S-box substitution table of the PRESENT algorithm
[0054] x 0 1 2 3 4 5 6 7 8 9 A B C D E F S[x] C 5 6 B 9 0 A D 3 E F 8 4 7 1 2
[0055] P-permutation: After S-box substitution, perform P-permutation to rearrange each bit of the data. The essence of the permutation is shifting, and the P-permutation is shown in the following table.
[0056] Table 2 P-permutation table of the PRESENT encryption algorithm
[0057] i 0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 P(i) 0 16 32 48 1 17 33 49 2 18 34 50 3 19 35 51 i 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 P(i) 4 20 36 52 5 21 37 53 6 22 38 54 7 23 39 55 i 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 P(i) 8 24 40 56 9 25 41 57 10 26 42 58 11 27 43 59 i 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 P(i) 12 28 44 60 13 29 45 61 13 29 45 61 14 30 46 62
[0058] Since the corresponding round key is used in each round, a total of 31 round keys need to be generated.
[0059] Specifically:
[0060] After the Docker encryption microservice module starts, read an 80-bit master key K from the client module. This master key is generated by a random number generator. Put the master key K = [k 79 , k 78 , …, k0] into the shift register, and generate multiple round keys K i through 31 rounds of key expansion, generating a total of 31 round keys. Among them, take the first 64 bits of the master key in the first round, and each subsequent round key is generated based on the previous round key. As Figure 3 shown, the key expansion algorithm includes circular shift, S-box substitution, and round constant addition, specifically including:
[0061] Circular shift: Shift the round key K of the previous roundi Circular left shift by 61 bits:
[0062] [k 79 ,k 78 ,…,k0]=[k 18 ,k 17 ,…,k 19 .
[0063] S-box substitution: Each 4 bits is operated through Table 1 in Step S32. That is:
[0064] K[k 79 ,k 78 ,k 77 ,k 76 =S([k 79 ,k 78 ,k 77 ,k 76 ).
[0065] Round constant addition: The circularly shifted round key K i in k 19 k 18 k 17 k 16 k 15 is bitwise XORed with the 5-bit round constant round_constant, where the value of round_constant is the five-bit binary number of the round number i.
[0066]
[0067] Take the high 64 bits of the round key K i in the current shift register as the round key for the i-th round. That is:
[0068] K i =[k 63 ,k 62 ,…,k0]=[k 79 ,k 78 ,…,k 16 (i=0,1,...,31).
[0069] After 31 rounds of iteration in S33, a whitening key operation is performed to obtain the final ciphertext.
[0070] In S34, the ciphertext data is returned to the message queue module.
[0071] In S4, after the Docker decryption microservice module obtains the decryption request forwarded by the message queue module, it performs the decryption operation, restores the initial plaintext message through the PRESENT algorithm, and transmits the initial plaintext message to the message queue module.
[0072] In this embodiment, the decryption process of the Docker decryption microservice module is the reverse of the encryption process of the Docker encryption microservice module. As Figure 4 shown, it includes inverse P permutation, inverse S-box substitution, and round key addition. First, the round key K 31 is used for the round key addition operation, and then the corresponding round key is used in each round to restore the state of the ciphertext. After 31 rounds of iteration, the round key K0 is XORed with the output state of the 31st round to obtain the initial plaintext. Finally, the initial plaintext is transmitted to the message queue module.
[0073] The decryption round function includes inverse P permutation, inverse S-box substitution, and round key addition, specifically including:
[0074] Inverse P permutation: In the inverse permutation layer, bit shifting is performed on the intermediate state. The inverse P permutation is as follows in the table.
[0075] Table 3 Inverse P Permutation Table of PRESENT Encryption Algorithm
[0076] i 0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 P(i) 0 4 8 12 16 20 24 28 32 36 40 44 48 52 56 60 i 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 P(i) 1 5 9 13 17 21 25 29 33 37 41 45 49 53 57 61 i 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 P(i) 2 6 10 14 18 22 26 30 34 38 42 46 50 54 58 62 i 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 P(i) 3 7 11 15 19 23 27 31 35 39 43 47 51 55 59 63
[0077] Inverse S-box substitution: The inverse mapping of the S-box is used for the operation, which is similar to the S-box substitution in step S32. The inverse S-box operation can be expressed as:
[0078] y = Inv_S(x);
[0079] The rules of inverse S-box substitution are as follows in the table.
[0080] Table 4 Inverse S-box Substitution Table of PRESENT Encryption Algorithm
[0081] x 0 1 2 3 4 5 6 7 8 9 A B C D E F S[x] 5 E F 8 C 1 2 D B 4 6 3 0 7 9 A
[0082] Round key addition: The ciphertext is XORed with the round key of the K 31-i round.
[0083] S5. The result processing module receives the ciphertext or plaintext passed by the message queue module, and then returns it to the client module to complete the feedback of the result message and form a communication closed loop.
[0084] Therefore, the present invention adopts the above-mentioned microservice communication encryption method based on the lightweight cipher PRESENT. Based on the characteristics of the lightweight cipher algorithm PRESENT, such as the streamlined round function design (31-round encryption), low memory occupancy (64-bit block length), and hardware friendliness, it can ensure the security of data transmission while meeting the requirements for performance and resource consumption in the microservice architecture.
[0085] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions of the present invention or make equivalent replacements, and these modifications or equivalent replacements do not enable the modified technical solutions to deviate from the spirit and scope of the technical solutions of the present invention.
Claims
1. A microservice communication encryption method based on lightweight password PRESENT, characterized in that the steps include: S1. The client module receives the plaintext data input by the user, forms encrypted or decrypted data, and sends an encryption or decryption request to the message queue module, wherein the request information includes the plaintext or ciphertext data to be processed; S2. The message queue module responds to the sent encryption or decryption request information and forwards the encryption or decryption request information to the Docker encryption microserver module or the Docker decryption microserver module; S3, after the Docker encryption micro-server module obtains the encryption request forwarded by the message queue module, it performs encryption operations, uses the round function of the PRESENT algorithm to perform multiple rounds of iterations to obtain the corresponding ciphertext, and transmits the encrypted ciphertext to the message queue module; S4, after the Docker decryption micro-server module obtains the decryption request forwarded by the message queue module, it performs the decryption operation, restores the initial plaintext message through the PRESENT algorithm, and transmits the initial plaintext message to the message queue module; S5. The result processing module receives the ciphertext or plaintext transmitted by the message queue module, and then returns it to the client module to form a closed communication loop.
2. According to claim 1, a microservice communication encryption method based on lightweight password PRESENT is characterized in that: The message queue module adopts a dual-team mechanism to implement task scheduling. Encryption requests and decryption requests enter the instruction queue table for classification and processing respectively. When an encryption request is detected, the plaintext data is forwarded to the Docker encryption microserver module, and an encrypted data identifier is established and added to the data queue table; when a decryption request is triggered, the corresponding ciphertext data is automatically matched according to the data identifier and transmitted to the Docker decryption microserver module in a directed manner.
3. According to claim 1, a microservice communication encryption method based on lightweight password PRESENT is characterized in that: The encryption process of the Docker encrypted micro-server module specifically includes: S31, the Docker encryption micro-server module obtains the encryption request forwarded by the message queue module and reads the plaintext data; S32, generating round keys, performing multiple rounds of iterations on each plaintext data, and using the corresponding round keys in each round; S33, after all rounds are completed, a whitening key operation is performed to obtain the final ciphertext; S34. Return the encrypted data to the message queue module.
4. According to claim 3, a microservice communication encryption method based on lightweight password PRESENT is characterized in that: Step S32: Each round function includes round key addition, S box substitution and P substitution, which is iterated 31 times in total, specifically: Round key plus: At the beginning of each round of encryption, the plaintext data state i and the round key K of the current round i Perform XOR operation, the formula is: state i =state i ⊕K i ; S-box substitution: Using a 4-bit S-box, let x and y be 4-bit binary numbers, x is the input, y is the output, and the S-box operation is expressed as: y = S(x); P permutation: After S-box substitution, P permutation is performed to rearrange the bits of the data.
5. According to claim 4, a microservice communication encryption method based on lightweight password PRESENT is characterized in that: In step S32, a round key corresponding to each round is generated. After the Docker encryption microserver module is started, an 80-bit master key K is read from the client module. The master key K is generated by a random number generator, and the master key K is placed in a shift register. Multiple round keys K are generated by a key expansion algorithm. i , where the first round takes the first 64 bits of the master key, and each subsequent round of keys is generated based on the previous round of keys.
6. According to claim 5, a microservice communication encryption method based on lightweight password PRESENT is characterized in that: The key expansion algorithm includes cyclic shift, S-box substitution and round constant addition.
7. A microservice communication encryption method based on lightweight password PRESENT according to claim 6, characterized in that: The decryption process of the Docker decryption microserver module is the opposite of the encryption process of the Docker encryption microserver module, including inverse P substitution, inverse S box substitution and round key addition. First, the round key K is used. 31 Perform round key addition operation, and then use the corresponding round key to restore the ciphertext in each round. After the iteration is completed, the initial plaintext is obtained, and finally the initial plaintext is transmitted to the message queue module.
Citation Information
Patent Citations
Micro-service interface safety call device and encryption method thereof
CN108289102A
Method and device for sending and consuming MQ message, and storage medium
CN112235205A
Micro-service data transmission method and device, electronic equipment and storage medium
CN115865400A
Data acquisition system, method and equipment for k8s cluster application and medium
CN116700895A