Data encryption method and system based on confidential computer and storage medium
By logically analyzing and randomly filling the private data of confidential computers, and combining with multiple encryption algorithms to process, an explanation of pseudo-private data and private data substitutions is generated, the problem of data leakage caused by cracking encryption methods in the prior art is solved, and data security and integrity are improved.
Patent Information
- Application Number
- CN202510340173.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-21
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2045-03-21
AI Technical Summary
After the encryption method of existing confidential computer data is cracked, it will lead to all data leakage and property losses.
By logically analyzing the private data, a pseudo-private data fill table is generated, and randomly selected and filled is performed. The pseudo-private data and private data permutants are encrypted and processed to generate an explanation of the private data permutants.
Even if the encrypted data is cracked, the cracker cannot restore the data, which improves the security and integrity of the data.
Smart Images

Figure CN120296761A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data encryption, and specifically relates to a data encryption method, system and storage medium based on a classified computer. Background Art
[0002] A computer that processes secret information by using functions such as collection, processing, storage, transmission, and retrieval is usually called a classified computer.
[0003] The existing data encryption of classified computers only encrypts all data uniformly. When the encryption method is cracked, all the encrypted data will be leaked, resulting in a certain degree of property loss. Summary of the Invention
[0004] To solve the above technical problems, a data encryption method, system and storage medium based on a classified computer are provided. The technical solution solves the problem that the existing data encryption of classified computers only encrypts all data uniformly. When the encryption method is cracked, all the encrypted data will be leaked, resulting in a certain degree of property loss as mentioned in the above background art.
[0005] To achieve the above object, the technical solution adopted by the present invention is as follows: A data encryption method based on a classified computer, comprising: Obtaining relevant parameters of private data, wherein the relevant parameters of the private data include the location characteristics of the private data and the byte length characteristics of the private data. The location characteristics of the private data include the start position of the private data and the end position of the private data. The private data is obtained from the data to be encrypted; It can be understood that the private data is determined by performing a privacy analysis on the data to be encrypted through a private data reference table, that is, if the privacy degree of a certain segment of data reaches the standard of the private data reference table, it means that this segment of data is private data and needs to be encrypted; Based on a data encryption terminal, performing a logical analysis on the location characteristics of the private data and the data to be encrypted to determine a pseudo-private data filling table, and the pseudo-private data filling table is in a matrix structure; It can be understood that several groups of data similar to the private data are generated according to the content of the private data, and one of them is randomly selected and filled in the position where the private data is located. Even if the filled public data is leaked, the cracker cannot obtain the core information therein; Based on a data encryption terminal, randomly selecting from the pseudo-private data filling table to determine the filled pseudo-private data, the filling data at the start position of the private data, and the filling data at the end position of the private data; Based on the data encryption terminal, fill the starting point padding data of the private data and the ending point padding data of the private data into the starting point and the ending point of the private data to obtain the permuted private data, the first permutation position of the private data, and the second permutation position of the private data; Based on the data encryption terminal, perform a marking and sorting process on the first permutation position of the private data and the second permutation position of the private data to obtain the private data permutation symbol; It can be understood that the decryptor can restore the filled public data through the private data permutation symbol; Based on the data encryption terminal, fill the filled pseudo-private data into the public data.
[0006] Preferably, the data encryption terminal performs a logical analysis on the position characteristics of the private data and the data to be encrypted to determine the pseudo-private data filling table, which specifically includes the following steps: Based on the data encryption terminal, respectively use the starting point and the ending point of the private data as features to perform a position determination process on the data to be encrypted, and determine the ending point and the starting point of the public data. Among them, the public data is the data in the data to be encrypted that does not include the private data. The starting point of the public data corresponds to the ending point of the private data, and the ending point of the public data corresponds to the starting point of the private data; Based on the data encryption terminal, use the ending point and the starting point of the public data as features to perform a data reading process on the public data to obtain the starting point data of the public data and the ending point data of the public data; Based on the data encryption terminal, use the starting point and the ending point of the private data as features to perform a data reading process on the private data to obtain the starting point data of the private data and the ending point data of the private data; Based on the data encryption terminal, perform a logical analysis on the starting point data of the public data and the ending point data of the private data, and the ending point data of the public data and the starting point of the private data to determine the starting point logic of the pseudo-private data and the ending point logic of the pseudo-private data; It is understandable that data is stored on a classified computer in binary numbers. When the classified data is text, it is also stored in binary numbers on the classified computer. To construct a pseudo-private data filling table, several groups of similar data are generated based on the logical relationship between private data and public data. The starting bit of the private data has logic with the data before the starting bit of the private data (i.e., the ending bit data of the public data), otherwise the data is not readable. Similarly, the starting bit data of the public data and the ending bit data of the private data also conform to the above rules. Therefore, the logical analysis here has not yet converted the private data into binary numbers. After the logical analysis of the private data is completed, in order to store it, it is then converted into binary numbers because binary numbers can store the private data but cannot represent the logic of the data; Based on the data encryption terminal, using the starting bit logic of the pseudo-private data, the ending bit logic of the pseudo-private data, and the byte length characteristics of the private data as restrictive conditions, data imitation of the private data is performed to obtain a pseudo-private data filling table; It is understandable that when the logic of the pseudo-data to be filled (i.e., the starting bit logic of the pseudo-private data, the ending bit logic of the pseudo-private data) is determined, pseudo-private data with a certain logic with the public data can be generated according to the byte length characteristics of the private data.
[0007] Preferably, the steps for randomly selecting from the pseudo-private data filling table based on the data encryption terminal to determine the filled pseudo-private data, the filling data at the starting bit of the private data, and the filling data at the ending bit of the private data are specifically as follows: Based on a random number function, perform a random selection process on the pseudo-private data filling table to obtain the filled pseudo-private data, the row data of the filled pseudo-private data, and the column data of the filled pseudo-private data; It is understandable that several groups of generated pseudo-private data are stored in a matrix structure, and the row information and column information in the matrix represent the position characteristics of this pseudo-private data in the pseudo-private data filling table; Based on the data encryption terminal, perform binary conversion on the row data of the filled pseudo-private data and the column data of the filled pseudo-private data respectively to obtain the binary data corresponding to the row data and the binary data corresponding to the column data; Based on the data encryption terminal, set the binary data corresponding to the row data as the filling data at the starting bit of the private data, and set the binary data corresponding to the column data as the filling data at the ending bit of the private data; It is understandable that in order to restore the complete data to be encrypted subsequently, it is necessary to retain the private data. However, encrypting and storing only the private data has certain risks. Therefore, the private data is modified. But for the convenience and logic of subsequent restoration of the private data, the private data is modified by filling the row data of pseudo-private data and the column data of pseudo-private data.
[0008] Preferably, for the data encryption terminal, filling the data filled at the starting position of the private data and the data filled at the ending position of the private data to the starting position and the ending position of the private data, and obtaining the permuted private data, the first permutation position of the private data, and the second permutation position of the private data specifically includes the following steps: Based on the data encryption terminal, perform data extraction processing on the starting position and the ending position of the private data to obtain the blank starting position of the private data and the blank ending position of the private data; Based on the data encryption terminal, perform length analysis on the data filled at the starting position of the private data to determine the length of the data filled at the starting position of the private data; Based on the data encryption terminal, fill the data filled at the starting position of the private data and the data filled at the ending position of the private data to the blank starting position and the blank ending position of the private data respectively to obtain the permuted private data and the length of the permuted private data; Based on the data encryption terminal, set the last data position of the data filled at the starting position of the private data as the first permutation position of the private data; Based on the data encryption terminal, perform calculation processing on the length of the data filled at the starting position of the private data, the byte length feature of the private data, and the length of the permuted private data to determine the second permutation position of the private data.
[0009] Preferably, the specific calculation formula for determining the second permutation position of the private data is: ; In the formula, the is the second permutation position of the private data; is the length of the permuted private data; is the byte length feature of the private data; is the length of the data filled at the starting position of the private data; It is understandable that in order to determine the data change positions in the private data (the first permutation position and the second permutation position of the private data), by calculating the data length filled at the starting position of the private data, the byte length feature of the private data, and the permuted private data length, adding 1 to the above formula is because the data filled at the starting position of the private data and the data filled at the ending position of the private data are filled at the blank starting position and the blank ending position of the private data. Therefore, there is a situation where one data position is counted twice in the permuted private data length, that is, the starting position of the private data is counted twice. So, adding 1 is required to obtain the second permutation position of the private data.
[0010] Preferably, the method for performing a marking and sorting process on the first permutation position and the second permutation position of the private data by the data encryption terminal to obtain the private data replacement symbol specifically includes the following steps: Based on the data encryption terminal, perform a sequential analysis on the data to be encrypted to determine the position of each private data in the data to be encrypted; Based on the data encryption terminal, sort the positions of each private data in the data to be encrypted according to the read - write order of the data to be encrypted to obtain the number of each private data; It is understandable that there is more than one private data in the data to be encrypted. To make it more convenient for the decryptor to restore the data to be encrypted, number and sort the private data according to the read - write order of the data to be encrypted; Based on the data encryption terminal, perform information synthesis on the number of each private data, the first permutation position of each private data, the second permutation position of each private data, the starting - position data of each private data, and the ending - position data of each private data to obtain the private data replacement symbol.
[0011] Preferably, the specific manifestation form of the private data replacement symbol is , where the is the number of each private data, is the first permutation position of each private data, is the binary number corresponding to the starting - position data of each private data, is the second permutation position of each private data, is the binary number corresponding to the ending - position data of each private data, and i is the specific number of private data: It is understandable that the private data replacement symbol is for the decryptor to restore the filled public data according to a fixed restoration rule to ensure that the restored data to be encrypted is correct and to ensure the integrity of the data to be encrypted.
[0012] Preferably, the method for filling the pseudo - private data into the public data by the data encryption terminal specifically includes the following steps: Based on the data encryption terminal, the corresponding padded pseudo-private data is filled into the corresponding position of the public data according to the number of each private data; Based on the data encryption terminal, an explanatory manual for the private data replacement symbol is generated according to the composition rule of the private data replacement symbol; It can be understood that if only one private data replacement symbol is provided, the decryptor may not be able to understand how to use the private data replacement symbol to restore the padded public data. Therefore, an explanatory manual for the private data replacement symbol is generated according to the composition rule of the private data replacement symbol, and the decryptor can restore the data only according to the explanatory manual for the private data replacement symbol; Based on the encryption algorithm, the padded public data, the private data replacement symbol, and the explanatory manual for the private data replacement symbol are respectively encrypted, and the encrypted package and the decryption package are sent to the electronic device of the decryptor; It can be understood that the encryption algorithm can be a symmetric encryption algorithm, an asymmetric encryption algorithm, a hash algorithm, stream encryption and block encryption. In the present invention, multiple encryption algorithms are respectively used to encrypt the padded public data, the private data replacement symbol, and the explanatory manual for the private data replacement symbol separately, ensuring that when one encrypted package is cracked, the other two encrypted packages are also cracked in the same way.
[0013] Further, a data encryption system based on a classified computer is proposed, which is used to implement a data encryption method based on a classified computer as described above, including: A data encryption terminal, which is used to perform logical analysis on the private data in the data to be encrypted, randomly select padded pseudo-private data, data filling processing, and data encryption processing; A storage device, which is the storage module of the classified computer and is used to store the data to be encrypted; Among them, the following are integrated inside the data encryption terminal: A core controller, which is used to control data transmission and information interaction between each module; A data extraction module, which performs private data extraction processing on the data to be encrypted according to the private data reference table; A data logic analysis module, which is used to perform logical analysis on the position characteristics of the private data and the data to be encrypted to determine the pseudo-private data filling table; A filling data selection module, which randomly selects the pseudo-private data filling table according to the random number function to determine the padded pseudo-private data, and sets the row information and column information of the padded pseudo-private data as the starting point filling data and the ending point filling data of the private data respectively; A data replacement module, which fills the blank start position and the blank end position of the private data with the start position filled data and the end position filled data of the private data respectively, and analyzes and calculates the filled blank start position and the filled blank end position of the private data to determine the first replacement position and the second replacement position of the private data; A replacement symbol generation module, which is used to synthesize information from the number of each private data, the first replacement position of each private data, the second replacement position of each private data, the start position data of each private data, and the end position data of each private data to obtain a private data replacement symbol; A data encryption module, which encrypts the filled public data, the private data replacement symbol, and the explanatory instruction manual of the private data replacement symbol respectively through an encryption algorithm, and sends the encrypted package and the decryption package to the electronic device of the decryptor.
[0014] Furthermore, a storage medium is proposed, on which a computer program is stored. When the computer program is called and run, it executes a data encryption method based on a classified computer as described above.
[0015] Compared with the prior art, the present invention provides a data encryption method, system and storage medium based on a classified computer, and has the following beneficial effects: The present invention first conducts a logical analysis on the private data to generate a pseudo-private data filling table. Secondly, it randomly selects from the pseudo-private data filling table to determine the filled pseudo-private data. Then, it changes the private data according to the row information and column information of the filled pseudo-private data, and generates a corresponding private data replacement symbol. Finally, it encrypts the private data replacement symbol, the filled public data, and the explanatory instruction manual of the private data replacement symbol respectively through multiple encryption algorithms. In the above manner, even if the filled public data and the replaced private data are leaked, the cracker cannot restore them, ensuring the security of the data. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 It is a schematic flowchart of steps S100 - S600 in a data encryption method based on a classified computer proposed by the present invention; Figure 2 It is a schematic flowchart of steps S201 - S205 in a data encryption method based on a classified computer proposed by the present invention; Figure 3 It is a schematic flowchart of steps S301 - S303 in a data encryption method based on a classified computer proposed by the present invention; Figure 4Schematic diagram of steps S401 - S405 in a data encryption method based on a classified computer proposed by the present invention; Figure 5 Schematic diagram of steps S501 - S503 in a data encryption method based on a classified computer proposed by the present invention; Figure 6 Schematic diagram of steps S601 - S603 in a data encryption method based on a classified computer proposed by the present invention; Figure 7 Block diagram of the structure of a data encryption system based on a classified computer proposed by the present invention. Detailed implementation manners
[0017] The following description is used to disclose the present invention so that those skilled in the art can implement the present invention. The preferred embodiments in the following description are only examples, and those skilled in the art can think of other obvious variations.
[0018] Refer to Figure 1 As shown, a data encryption method based on a classified computer includes: S100. Obtain relevant parameters of the private data. Among them, the relevant parameters of the private data include the location characteristics of the private data and the byte length characteristics of the private data. The location characteristics of the private data include the starting position of the private data and the ending position of the private data. The private data is obtained from the data to be encrypted; S200. Based on the data encryption terminal, conduct a logical analysis on the location characteristics of the private data and the data to be encrypted to determine a pseudo - private data filling table, and the pseudo - private data filling table is in a matrix structure; S300. Based on the data encryption terminal, randomly select from the pseudo - private data filling table to determine the filled pseudo - private data, the filling data at the starting position of the private data, and the filling data at the ending position of the private data; S400. Based on the data encryption terminal, fill the filling data at the starting position of the private data and the filling data at the ending position of the private data into the starting position and the ending position of the private data to obtain the permuted private data, the first permutation position of the private data, and the second permutation position of the private data; S500. Based on the data encryption terminal, conduct a marking and sorting process on the first permutation position of the private data and the second permutation position of the private data to obtain the private data permutation symbol; S600. Based on the data encryption terminal, fill the filled pseudo - private data into the public data; Those skilled in the art can understand that when encrypting data to be encrypted using only one encryption algorithm, once the encryption algorithm is cracked by a cracker, the cracker will obtain all the data to be encrypted. When all the data to be encrypted is leaked, it will cause a certain degree of property loss. For example, the leakage of the demolition location will cause the housing prices in that area to soar, thereby increasing the demolition cost. Therefore, by extracting private data, filling pseudo-private data, and changing private data for the data to be encrypted, even if the cracker obtains the filled public data and the changed private data, they cannot restore them, improving the security of the data.
[0019] Referring to Figure 2 As shown, based on the data encryption terminal, the logical analysis of the position characteristics of the private data and the data to be encrypted is carried out to determine the specific steps of the pseudo-private data filling table as follows: S201. Based on the data encryption terminal, the position determination process is carried out on the data to be encrypted by taking the starting position of the private data and the ending position of the private data as features, and the ending position of the public data and the starting position of the public data are determined. Among them, the public data is the data in the data to be encrypted that does not include private data. The starting position of the public data corresponds to the ending position of the private data, and the ending position of the public data corresponds to the starting position of the private data; S202. Based on the data encryption terminal, the data reading process is carried out on the public data by taking the ending position of the public data and the starting position of the public data as features, and the starting position data of the public data and the ending position data of the public data are obtained; S203. Based on the data encryption terminal, the data reading process is carried out on the private data by taking the starting position of the private data and the ending position of the private data as features, and the starting position data of the private data and the ending position data of the private data are obtained; S204. Based on the data encryption terminal, the logical analysis of the starting position data of the public data and the ending position data of the private data, and the ending position data of the public data and the starting position of the private data is carried out to determine the starting position logic of the pseudo-private data and the ending position logic of the pseudo-private data; S205. Based on the data encryption terminal, the private data is data imitated by taking the starting position logic of the pseudo-private data, the ending position logic of the pseudo-private data, and the byte length characteristics of the private data as limiting conditions, and the pseudo-private data filling table is obtained; In this embodiment, in order to make the pseudo-filled data have a certain logic with the public data, through logical analysis of the starting bit data of the public data and the ending bit data of the private data, and the ending bit data of the public data and the starting bit of the private data, the starting bit logic of the pseudo-private data and the ending bit logic of the pseudo-private data are determined. Then, with the starting bit logic of the pseudo-private data, the ending bit logic of the pseudo-private data, and the byte length feature of the private data as limiting conditions, information imitation is performed on the content of the private data. It should be noted that the imitation of the data here is not carried out in binary numbers. Because the binary number is represented by a combination of "0" and "1" and cannot express the logic of its data, it is impossible to imitate based on the binary number of the private data.
[0020] Refer to Figure 3 As shown, based on the data encryption terminal, randomly select from the pseudo-private data filling table to determine the filled pseudo-private data, the starting bit filling data of the private data, and the ending bit filling data of the private data, which specifically includes the following steps: S301. Based on the random number function, perform random selection processing on the pseudo-private data filling table to obtain the filled pseudo-private data, the row data of the filled pseudo-private data, and the column data of the filled pseudo-private data; S302. Based on the data encryption terminal, perform binary conversion on the row data of the filled pseudo-private data and the column data of the filled pseudo-private data respectively to obtain the binary data corresponding to the row data and the binary data corresponding to the column data; S303. Based on the data encryption terminal, set the binary data corresponding to the row data as the starting bit filling data of the private data, and set the binary data corresponding to the column data as the ending bit filling data of the private data; In this embodiment, in order to make the change of the private data logical, the private data is changed by the row data of the filled pseudo-private data and the column data of the filled pseudo-private data. And when it is necessary to restore the filled public data, according to the row data of the filled pseudo-private data and the column data of the filled pseudo-private data of the changed private data, it can be determined which pseudo-filled data in the pseudo-private data filling table is used to fill the public data, and then the filling position is determined according to the pseudo-filled data. Then, the filling position is filled with the restored private data to obtain the complete data to be encrypted.
[0021] Refer to Figure 4 As shown, based on the data encryption terminal, fill the starting bit filling data of the private data and the ending bit filling data of the private data into the starting bit and the ending bit of the private data to obtain the permuted private data, the first permutation bit of the private data, and the second permutation bit of the private data, which specifically includes the following steps: S401. Based on the data encryption terminal, perform data extraction processing on the starting position and the ending position of the private data to obtain the blank starting position and the blank ending position of the private data; S402. Based on the data encryption terminal, perform length analysis on the data filled at the starting position of the private data to determine the length of the data filled at the starting position of the private data; S403. Based on the data encryption terminal, fill the data filled at the starting position of the private data and the data filled at the ending position of the private data into the blank starting position and the blank ending position of the private data respectively to obtain the permuted private data and the length of the permuted private data; S404. Based on the data encryption terminal, set the last data position of the data filled at the starting position of the private data as the first permutation position of the private data; S405. Based on the data encryption terminal, perform calculation processing on the length of the data filled at the starting position of the private data, the byte length feature of the private data, and the length of the permuted private data to determine the second permutation position of the private data; Among them, the specific calculation formula for determining the second permutation position of the private data is: ; In the formula, the is the second permutation position of the private data; is the length of the permuted private data; is the byte length feature of the private data; is the length of the data filled at the starting position of the private data; In this embodiment, when it is necessary to restore the filled public data, it is necessary to restore the changed private data, and the restoration of the private data includes two parts. One is to determine the data filling positions of the original private data (that is, the blank starting position and the blank ending position of the private data, which are also the first permutation position and the second permutation position of the private data), and the other is to fill the data extracted before into the blank starting position and the blank ending position of the private data (that is, the starting position data and the ending position data of the private data), and fill them into the first permutation position and the second permutation position of the private data. It can be understood that the representation forms of the private data here are all binary numbers.
[0022] Refer to Figure 5 As shown, based on the data encryption terminal, perform marker sorting processing on the first permutation position and the second permutation position of the private data to obtain the private data permutation symbol, which specifically includes the following steps: S501. Based on the data encryption terminal, perform sequential analysis on the data to be encrypted to determine the position of each private data in the data to be encrypted; S502. Based on the data encryption terminal, sort the positions of each private data in the data to be encrypted according to the read-write order of the data to be encrypted, and obtain the number of each private data; S503. Based on the data encryption terminal, synthesize the information of the number of each private data, the first replacement bit of each private data, the second replacement bit of each private data, the starting bit data of each private data, and the ending bit data of each private data to obtain a private data replacement symbol; Among them, the specific form of the private data replacement symbol is , where the is the number of each private data, is the first replacement bit of each private data, is the binary number corresponding to the starting bit data of each private data, is the second replacement bit of each private data, is the binary number corresponding to the ending bit data of each private data, and i is the specific number of private data; In this embodiment, in order for the decryptor to accurately restore the filled public data, a private data replacement symbol is constructed, and the private data replacement symbol contains the number of private data, the first replacement bit of each private data, the second replacement bit of each private data, the starting bit data of each private data, and the ending bit data of each private data. Then, according to the first replacement bit of each private data and the second replacement bit of each private data, determine the position of the replaced data in the replaced private data, and then fill the starting bit data and the ending bit data of the private data into the corresponding positions, and the restoration of the private data can be realized.
[0023] Referring to Figure 6 shown, based on the data encryption terminal, filling the filled pseudo-private data into the public data specifically includes the following steps: S601. Based on the data encryption terminal, fill the corresponding filled pseudo-private data into the corresponding position of the public data according to the number of each private data; Here, the corresponding position of the public data refers to the position of the private data, that is, the blank position left after the private data is extracted; S602. Based on the data encryption terminal, generate an explanatory manual for the private data replacement symbol according to the composition rule of the private data replacement symbol; S603. Based on the encryption algorithm, encrypt the filled public data, the private data replacement symbol, and the explanatory manual of the private data replacement symbol respectively, and send the encrypted package and the decryption package to the electronic device of the decryptor; In this embodiment, the encrypted packet is decrypted by using the filled public data, the private data replacement symbol, and the decryption packet of the explanatory instruction book of the private data replacement symbol to obtain the filled public data, the private data replacement symbol, and the explanatory instruction book of the private data replacement symbol. Then, the private data replacement symbol is decrypted according to the explanatory instruction book of the private data replacement symbol to obtain the filling positions for replacing the private data (the first replacement position of the private data and the second replacement position of the private data). Next, the start position data and the end position data of the private data are filled into the first replacement position and the second replacement position of the private data. Then, the replaced data is converted into binary to obtain the row data of the filled pseudo-private data and the column data of the filled pseudo-private data. Finally, the filled pseudo-private data table is retrieved according to the row data and the column data of the filled pseudo-private data to determine the used filled pseudo-private data. Then, the filled public data is matched with the filled pseudo-private data to determine the data filling position (the position feature of the private data). Finally, the restored private data is filled into the position feature of the private data to obtain the complete data to be encrypted.
[0024] Refer to Figure 7 As shown, a data encryption system based on a classified computer is used to implement a data encryption method based on a classified computer as described above, including: A data encryption terminal, which is used to perform logical analysis on the private data in the data to be encrypted, randomly select the filled pseudo-private data, perform data filling processing, and perform data encryption processing; A storage device, which is the storage module of the classified computer and is used to store the data to be encrypted; Among them, the following are integrated inside the data encryption terminal: A core controller, which is used to control data transmission and information interaction between each module; A data extraction module, which performs private data extraction processing on the data to be encrypted according to the private data reference table; A data logic analysis module, which is used to perform logical analysis on the position feature of the private data and the data to be encrypted to determine the filled pseudo-private data table; A filled data selection module, which randomly selects from the filled pseudo-private data table according to the random number function to determine the filled pseudo-private data, and sets the row information and column information of the filled pseudo-private data as the start position filling data of the private data and the end position filling data of the private data respectively; A data replacement module, which fills the blank start position and the blank end position of the private data with the start position filled data of the private data and the end position filled data of the private data respectively, and analyzes and calculates the filled blank start position and the filled blank end position of the private data to determine the first replacement position of the private data and the second replacement position of the private data; A replacement symbol generation module, which is used to synthesize information from the number of each private data, the first replacement position of each private data, the second replacement position of each private data, the start position data of each private data, and the end position data of each private data to obtain a private data replacement symbol; A data encryption module, which encrypts the filled public data, the private data replacement symbol, and the explanatory statement of the private data replacement symbol through encryption algorithms respectively, and sends the encrypted package and the decryption package to the electronic device of the decryptor.
[0025] The above shows and describes the basic principles, main features and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited by the above embodiments. What is described in the above embodiments and the specification is only the principle of the present invention. Without departing from the spirit and scope of the present invention, the present invention will have various changes and improvements, and these changes and improvements all fall within the scope of the present invention claimed. The scope of protection claimed by the present invention is defined by the appended claims and their equivalents.
Claims
1. A data encryption method based on a classified computer, characterized in that, Including: Obtaining relevant parameters of private data, where the relevant parameters of the private data include the position feature of the private data and the byte length feature of the private data. The position feature of the private data includes the start position and the end position of the private data. The private data is obtained from the data to be encrypted. Based on the data encryption terminal, logically analyzing the position feature of the private data and the data to be encrypted to determine a pseudo-private data filling table, where the pseudo-private data filling table is a matrix structure. Based on the data encryption terminal, randomly selecting from the pseudo-private data filling table to determine the filled pseudo-private data, the data for filling the start position of the private data, and the data for filling the end position of the private data. Based on the data encryption terminal, filling the data for filling the start position of the private data and the data for filling the end position of the private data into the start position and the end position of the private data to obtain the permuted private data, the first permutation position of the private data, and the second permutation position of the private data. Based on the data encryption terminal, performing a marking and sorting process on the first permutation position of the private data and the second permutation position of the private data to obtain the private data permutation symbol. Based on the data encryption terminal, filling the filled pseudo-private data into the public data.
2. The data encryption method based on a classified computer according to claim 1, characterized in that, The step of logically analyzing the position feature of the private data and the data to be encrypted based on the data encryption terminal to determine the pseudo-private data filling table specifically includes the following steps: Based on the data encryption terminal, respectively using the start position and the end position of the private data as features to perform a position determination process on the data to be encrypted to determine the end position and the start position of the public data. Here, the public data is the data in the data to be encrypted that does not include the private data. The start position of the public data corresponds to the end position of the private data, and the end position of the public data corresponds to the start position of the private data. Based on the data encryption terminal, using the end position and the start position of the public data as features to perform a data reading process on the public data to obtain the start position data and the end position data of the public data. Based on the data encryption terminal, using the start position and the end position of the private data as features to perform a data reading process on the private data to obtain the start position data and the end position data of the private data. Based on the data encryption terminal, logically analyzing the start position data of the public data and the end position data of the private data, and the end position data of the public data and the start position of the private data to determine the start position logic of the pseudo-private data and the end position logic of the pseudo-private data. Based on the data encryption terminal, using the start position logic of the pseudo-private data, the end position logic of the pseudo-private data, and the byte length feature of the private data as limiting conditions to perform data imitation on the private data to obtain the pseudo-private data filling table.
3. A data encryption method based on a classified computer according to claim 1, characterized in that, The step of randomly selecting from the pseudo-private data filling table based on the data encryption terminal to determine the filled pseudo-private data, the data for filling the start position of the private data, and the data for filling the end position of the private data specifically includes the following steps: Based on the random number function, performing a random selection process on the pseudo-private data filling table to obtain the filled pseudo-private data, the row data of the filled pseudo-private data, and the column data of the filled pseudo-private data. Based on the data encryption terminal, perform binary conversion on the row data filled with pseudo-private data and the column data filled with pseudo-private data respectively to obtain the binary data corresponding to the row data and the binary data corresponding to the column data; Based on the data encryption terminal, set the binary data corresponding to the row data as the filling data for the starting position of the private data, and set the binary data corresponding to the column data as the filling data for the ending position of the private data.
4. A data encryption method based on a classified computer according to claim 1, characterized in that, The above-mentioned based on the data encryption terminal, filling the filling data for the starting position of the private data and the filling data for the ending position of the private data into the starting position of the private data and the ending position of the private data, and obtaining the permuted private data, the first permutation position of the private data, and the second permutation position of the private data specifically includes the following steps: Based on the data encryption terminal, perform data extraction processing on the starting position of the private data and the ending position of the private data to obtain the blank starting position of the private data and the blank ending position of the private data; Based on the data encryption terminal, perform length analysis on the filling data for the starting position of the private data to determine the length of the filling data for the starting position of the private data; Based on the data encryption terminal, fill the filling data for the starting position of the private data and the filling data for the ending position of the private data into the blank starting position of the private data and the blank ending position of the private data respectively to obtain the permuted private data and the length of the permuted private data; Based on the data encryption terminal, set the position of the last bit of the filling data for the starting position of the private data as the first permutation position of the private data; Based on the data encryption terminal, perform calculation processing on the length of the filling data for the starting position of the private data, the byte length feature of the private data, and the length of the permuted private data to determine the second permutation position of the private data.
5. A data encryption method based on a classified computer according to claim 4, characterized in that The specific calculation formula for determining the second permutation position of the private data is: ; In the formula, the is the second transposition of the private data; is the length of the transposed private data; is the byte length feature of the private data; is the length of the data filled at the starting position of the private data.
6. A data encryption method based on a classified computer according to claim 1, characterized in that, The above-mentioned based on the data encryption terminal, performing marker sorting processing on the first permutation position of the private data and the second permutation position of the private data to obtain the private data permutation symbol specifically includes the following steps: Based on the data encryption terminal, perform sequential analysis on the data to be encrypted to determine the position of each private data in the data to be encrypted; Based on the data encryption terminal, sort the positions of each private data in the data to be encrypted according to the reading and writing order of the data to be encrypted to obtain the number of each private data; Based on the data encryption terminal, perform information synthesis on the number of each private data, the first permutation position of each private data, the second permutation position of each private data, the starting position data of each private data, and the ending position data of each private data to obtain the private data permutation symbol.
7. A data encryption method based on a classified computer according to claim 6, characterized in that, The specific manifestation form of the private data replacement symbol is , the is the number of each private data, is the first replacement position of each private data, is the binary number corresponding to the starting position data of each private data, is the second replacement position of each private data, is the binary number corresponding to the ending position data of each private data, and i is the specific quantity of the private data.
8. A data encryption method based on a classified computer according to claim 1, characterized in that The above-mentioned based on the data encryption terminal, filling the filled pseudo-private data into the public data specifically includes the following steps: Based on the data encryption terminal, fill the corresponding filled pseudo-private data into the corresponding position of the public data according to the number of each private data; Based on the data encryption terminal, generate an explanatory manual for the private data permutation symbol according to the composition rules of the private data permutation symbol; Based on the encryption algorithm, perform encryption processing on the filled public data, the private data permutation symbol, and the explanatory manual for the private data permutation symbol respectively, and send the encrypted package and the decryption package to the electronic device of the decrypter.
9. A data encryption system based on a classified computer, which is used to implement a data encryption method based on a classified computer as described in any one of claims 1-8, characterized in that, Including: A data encryption terminal, which is used to perform logical analysis on private data in the data to be encrypted, randomly select pseudo-private data for filling, data filling processing, and data encryption processing; A storage device, which is a storage module of a classified computer and is used to store the data to be encrypted; Among them, the following are integrated inside the data encryption terminal: A core controller, which is used to control data transmission and information interaction between each module; A data extraction module, which performs private data extraction processing on the data to be encrypted according to a private data reference table; A data logic analysis module, which is used to perform logical analysis on the position characteristics of private data and the data to be encrypted to determine a pseudo-private data filling table; A filling data selection module, which randomly selects from the pseudo-private data filling table according to a random number function to determine the filled pseudo-private data, and sets the row information and column information of the filled pseudo-private data as the starting point filling data of private data and the ending point filling data of private data respectively; A data replacement module, which fills the blank starting point of private data and the blank ending point of private data according to the starting point filling data of private data and the ending point filling data of private data respectively, and performs analysis and calculation on the blank starting point and the blank ending point of the filled private data to determine the first replacement position of private data and the second replacement position of private data; A replacement symbol generation module, which is used to synthesize information on the number of each private data, the first replacement position of each private data, the second replacement position of each private data, the starting point data of each private data, and the ending point data of each private data to obtain a private data replacement symbol; A data encryption module, which encrypts the filled public data, the private data replacement symbol, and the explanatory statement of the private data replacement symbol respectively through an encryption algorithm, and sends the encrypted package and the decryption package to the electronic device of the decryptor.
10. A storage medium, characterized in that, A computer program is stored thereon, and when the computer program is called and run, it executes a data encryption method based on a classified computer as described in any one of claims 1-8.
Citation Information
Patent Citations
Encryption method based on AES encryption algorithm
CN113206736A
Encryption method and system based on character segmentation, permutation and combination
CN117216784A
Private information retrieval method supporting multiple parties
WO2024239592A1