A data encryption method and system based on a secret computer and a storage medium
By performing logical analysis and pseudo-private data filling on classified computers, private data substitution symbols are generated, solving the problem of data leakage caused by the cracking of encryption methods in existing technologies, and achieving high-security encryption of data.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SHANDONG GUOXIN BLUE SHIELD ELECTRONIC TECH CO LTD
- Filing Date
- 2025-03-21
- Publication Date
- 2026-05-15
AI Technical Summary
Existing encryption methods for classified computer data can lead to data leakage and financial losses if the encryption is broken.
By performing logical analysis on the private data to generate a pseudo-private data filling table, randomly selecting pseudo-private data, and modifying the private data according to the row and column information of the pseudo-private data to generate a private data permutation symbol, the data is finally encrypted using multiple encryption algorithms.
Even if public and private data are leaked, hackers will not be able to recover the data, thus improving data security.
Smart Images

Figure CN120296761B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data encryption technology, specifically to a data encryption method, system, and storage medium based on a classified computer. Background Technology
[0002] Computers that use functions such as data collection, processing, storage, transmission, and retrieval to handle classified information are generally referred to as classified computers.
[0003] Existing data encryption for classified computers only encrypts all data uniformly. Once the encryption method is cracked, all encrypted data will be leaked, resulting in a certain degree of property loss. Summary of the Invention
[0004] To address the aforementioned technical problems, this paper provides a data encryption method, system, and storage medium for classified computers. This technical solution solves the problem mentioned in the background that existing data encryption methods for classified computers only encrypt all data uniformly. When the encryption method is cracked, all encrypted data will be leaked, resulting in a certain degree of property loss.
[0005] To achieve the above objectives, the technical solution adopted by the present invention is as follows:
[0006] A data encryption method based on a classified computer includes:
[0007] Obtain relevant parameters of private data, wherein the relevant parameters of private data include the location characteristics of private data and the byte length characteristics of private data. The location characteristics of private data include the start position and the end position of private data. The private data is obtained from the data to be encrypted.
[0008] Understandably, private data is determined by analyzing the privacy of the data to be encrypted using a private data reference table. That is, if the privacy of a certain piece of data reaches the standard of the private data reference table, it means that the piece of data is private data and needs to be encrypted.
[0009] Based on the data encryption terminal, the location characteristics of private data and the data to be encrypted are logically analyzed to determine the pseudo-private data filling table, which is a matrix structure.
[0010] Understandably, several sets of data similar to the private data are generated based on the content of the private data, and one of them is randomly selected to fill the location of the private data. Even if the public data after filling is leaked, the hacker will not be able to obtain the core information.
[0011] Based on the data encryption terminal, the pseudo-private data filling table is randomly selected to determine the filling of pseudo-private data, the filling of data at the starting position of private data, and the filling of data at the ending position of private data.
[0012] Based on the data encryption terminal, the starting point filling data and the ending point filling data of the private data are filled into the starting point and the ending point of the private data, and the permuted private data, the first permutation bit of the private data and the second permutation bit of the private data are obtained;
[0013] Based on the data encryption terminal, the first permutation bit and the second permutation bit of the private data are marked and sorted to obtain the private data permutation symbol;
[0014] Understandably, the person decrypting the data can use the private data substitution symbol to restore the public data after it has been filled in.
[0015] Based on the data encryption terminal, pseudo-private data is filled into public data.
[0016] Preferably, the step of performing logical analysis on the location characteristics of private data and the data to be encrypted based on the data encryption terminal to determine the pseudo-private data filling table specifically includes the following steps:
[0017] Based on the data encryption terminal, the starting point and ending point of the private data are used as features to determine the position of the data to be encrypted, and the ending point and starting point of the public data are determined. The public data is the data to be encrypted that does not include the private data. The starting point of the public data corresponds to the ending point of the private data, and the ending point of the public data corresponds to the starting point of the private data.
[0018] Based on the data encryption terminal, the public data is read and processed using the end point and the start point of the public data as features to obtain the start point data and the end point data of the public data.
[0019] Based on the data encryption terminal, the private data is read and processed using the starting point and ending point of the private data as features to obtain the starting point data and ending point data of the private data.
[0020] Based on the data encryption terminal, logical analysis is performed on the starting point data of public data and the ending point data of private data, as well as the ending point data of public data and the starting point of private data, to determine the starting point logic of pseudo-private data and the ending point logic of pseudo-private data.
[0021] Understandably, data is stored as binary numbers on classified computers. When classified data is text, it is also stored as binary numbers on classified computers. In order to construct pseudo-private data filling tables, several sets of similar data are generated by analyzing the logical relationship between private and public data. The starting point of the private data and the data preceding the starting point of the private data (i.e., the ending point of the public data) must be logically consistent; otherwise, the data would not be readable. Similarly, the starting point of the public data and the ending point of the private data must also conform to the above rules. Therefore, the logical analysis here has not yet converted the private data into binary numbers. After the logical analysis of the private data is completed, it will be converted into binary numbers again in order to store it, because binary numbers can store private data but cannot represent the logic of the data.
[0022] Based on the data encryption terminal, the private data is copied by using the starting point logic of the pseudo-private data, the ending point logic of the pseudo-private data, and the byte length characteristics of the private data as constraints, and the pseudo-private data filling table is obtained.
[0023] It is understandable that when the logic of the pseudo data to be filled is determined (i.e., the starting point logic of the pseudo private data and the ending point logic of the pseudo private data), pseudo private data with a certain logic with the public data can be generated based on the byte length characteristics of the private data.
[0024] Preferably, the step of randomly selecting data from the pseudo-private data filling table based on the data encryption terminal to determine the data to be filled with pseudo-private data, the data to be filled at the starting position of private data, and the data to be filled at the ending position of private data specifically includes the following steps:
[0025] Based on the random number function, the pseudo-private data filling table is randomly selected to obtain the pseudo-private data, the row data of the pseudo-private data, and the column data of the pseudo-private data.
[0026] It is understandable that the generated sets of pseudo-private data are stored in a matrix structure, and the row and column information in the matrix represent the position characteristics of this pseudo-private data in the pseudo-private data filling table.
[0027] Based on the data encryption terminal, the row data and column data filled with pseudo-private data are converted into binary data respectively to obtain the binary data corresponding to the row data and the binary data corresponding to the column data.
[0028] Based on the data encryption terminal, the binary data corresponding to the row data is set as the start position of the private data filling data, and the binary data corresponding to the column data is set as the end position of the private data filling data.
[0029] It is understandable that in order to restore the complete encrypted data later, it is necessary to retain the private data. However, encrypting and storing only the private data carries certain risks. Therefore, the private data is modified. However, for the convenience and logic of restoring the private data later, the private data is modified by filling in the row data and column data of the pseudo-private data.
[0030] Preferably, the step of filling the private data start position with private data and the private data end position with private data based on the data encryption terminal, and obtaining the permuted private data, the first permutation position of the private data, and the second permutation position of the private data specifically includes the following steps:
[0031] Based on the data encryption terminal, the starting point and ending point of the private data are extracted and processed to obtain the blank starting point and blank ending point of the private data.
[0032] Based on the data encryption terminal, the length of the padding data at the starting point of the private data is analyzed to determine the length of the padding data at the starting point of the private data.
[0033] Based on the data encryption terminal, the starting point padding data and the ending point padding data of the private data are respectively filled into the blank starting point and the blank ending point of the private data to obtain the replaced private data and the length of the replaced private data.
[0034] Based on the data encryption terminal, the last bit of the data filling data at the starting point of the private data is set as the first permutation bit of the private data;
[0035] Based on the data encryption terminal, the length of the data filled at the starting point of the private data, the byte length characteristics of the private data, and the length of the permuted private data are calculated and processed to determine the second permutation bit of the private data.
[0036] Preferably, the specific calculation formula for determining the second permutation bit of the private data is as follows:
[0037] ;
[0038] In the formula, the This is the second permutation bit for private data; To replace the length of private data; The byte length characteristic of private data; Fill the data length at the starting point of the private data;
[0039] Understandably, in order to determine the data change positions in the private data (the first permutation bit and the second permutation bit of the private data), the length of the padding data at the start position of the private data, the byte length characteristics of the private data, and the length of the permuted private data are calculated. The formula above adds 1 because the padding data at the start position and the padding data at the end position of the private data are filled in the blank start position and the blank end position of the private data. Therefore, there is a case where a data position is recorded twice in the permutation of the private data length, that is, the start position of the private data is measured twice. Therefore, it is necessary to add 1 to obtain the second permutation bit of the private data.
[0040] Preferably, the step of marking and sorting the first and second permutation bits of the private data based on the data encryption terminal to obtain the private data permutation symbol specifically includes the following steps:
[0041] Based on the data encryption terminal, sequential analysis is performed on the data to be encrypted to determine the position of each piece of private data in the data to be encrypted.
[0042] Based on the data encryption terminal, the position of each piece of private data in the data to be encrypted is sorted according to the read and write order of the data to be encrypted, and the number of each piece of private data is obtained.
[0043] It is understandable that there is more than one piece of private data in the data to be encrypted. In order to make it easier for the decryptor to restore the data to be encrypted, the private data is numbered and sorted according to the reading and writing order of the data to be encrypted.
[0044] Based on the data encryption terminal, information is synthesized from the number of each private data, the first permutation bit of each private data, the second permutation bit of each private data, the starting point data of each private data, and the ending point data of each private data to obtain the private data permutation symbol.
[0045] Preferably, the specific form of the private data permutation symbol is as follows: The Each piece of private data is assigned a unique identifier. The first permutation bit for each piece of private data. The binary number corresponding to the starting bit of each piece of private data. The second permutation bit for each piece of private data. The binary number corresponding to the endpoint bit of each piece of private data, where i is the specific number of pieces of private data:
[0046] Understandably, the private data substitution symbol is used by the decryptor to restore the public data after padding according to fixed restoration rules, ensuring that the restored data to be encrypted is correct and thus ensuring the integrity of the data to be encrypted.
[0047] Preferably, the step of filling public data with pseudo-private data based on the data encryption terminal specifically includes the following steps:
[0048] Based on the data encryption terminal, the corresponding pseudo-private data is filled into the corresponding position of the public data according to the number of each private data;
[0049] Based on the data encryption terminal, an explanation manual for private data substitution symbols is generated according to the rules for the composition of private data substitution symbols.
[0050] Understandably, if only a private data substitution symbol is provided, the decryptor may not understand how to use the private data substitution symbol to restore the public data after it has been filled in. Therefore, an explanation manual for the private data substitution symbol is generated according to the rules for its composition. The decryptor can restore the data simply by following the explanation manual for the private data substitution symbol.
[0051] Based on the encryption algorithm, the public data after padding, the private data substitution symbol, and the interpretation of the private data substitution symbol are encrypted respectively, and the encrypted packet and the decrypted packet are sent to the electronic device of the decryptor.
[0052] It is understood that the encryption algorithm can be a symmetric encryption algorithm, an asymmetric encryption algorithm, a hash algorithm, stream encryption, and block encryption. In this invention, multiple encryption algorithms are used to encrypt the public data after padding, the private data substitution symbol, and the explanation of the private data substitution symbol separately, ensuring that when one encryption packet is cracked, the other two encryption packets are also cracked in the same way.
[0053] Furthermore, a data encryption system based on a classified computer is proposed to implement the aforementioned data encryption method based on a classified computer, including:
[0054] A data encryption terminal is used to perform logical analysis of private data in the data to be encrypted, random selection of pseudo-private data for filling, data filling processing, and data encryption processing.
[0055] A storage device, wherein the storage device is a storage module of a classified computer, used to store data to be encrypted;
[0056] The data encryption terminal integrates the following:
[0057] The core controller is used to control the data transmission and information interaction between the various modules.
[0058] The data extraction module performs private data extraction processing on the data to be encrypted based on the private data reference table;
[0059] The data logic analysis module is used to perform logical analysis on the location characteristics of private data and the data to be encrypted to determine the pseudo-private data filling table.
[0060] The data selection module randomly selects pseudo-private data from the pseudo-private data filling table according to a random number function, determines the pseudo-private data to be filled, and sets the row information and column information of the pseudo-private data to be filled as the starting point data and the ending point data of the private data, respectively.
[0061] The data replacement module fills the blank starting position and blank ending position of the private data according to the filling data at the starting position and the filling data at the ending position of the private data, respectively, and analyzes and calculates the blank starting position and blank ending position of the private data after filling to determine the first replacement position and the second replacement position of the private data.
[0062] The permutation symbol generation module is used to synthesize information from the number of each private data, the first permutation bit of each private data, the second permutation bit of each private data, the starting point data of each private data, and the ending point data of each private data to obtain a private data permutation symbol.
[0063] The data encryption module encrypts the filled public data, private data permutation symbol, and private data permutation symbol interpretation specification respectively using an encryption algorithm, and sends the encryption package and decryption package to the decryptor's electronic device.
[0064] Furthermore, a storage medium is proposed that stores a computer program, which, when invoked and executed, performs a data encryption method based on a classified computer as described above.
[0065] Compared with the prior art, the present invention provides a data encryption method, system and storage medium based on a classified computer, which has the following beneficial effects:
[0066] This invention first performs logical analysis on the private data to generate a pseudo-private data filling table. Next, it randomly selects data from the pseudo-private data filling table to determine the pseudo-private data to be filled. Then, it modifies the private data based on the row and column information of the pseudo-private data and generates corresponding private data substitution symbols. Finally, it encrypts the private data substitution symbols, the filled public data, and the explanation of the private data substitution symbols using multiple encryption algorithms. This method ensures that even if the filled public data and the substitution private data are leaked, attackers cannot recover them, thus guaranteeing data security. Attached Figure Description
[0067] Figure 1 This is a flowchart illustrating steps S100-S600 in a data encryption method based on a classified computer proposed in this invention.
[0068] Figure 2 This is a flowchart illustrating steps S201-S205 of a data encryption method based on a classified computer proposed in this invention.
[0069] Figure 3 This is a flowchart illustrating steps S301-S303 of a data encryption method based on a classified computer proposed in this invention.
[0070] Figure 4 This is a flowchart illustrating steps S401-S405 of a data encryption method based on a classified computer proposed in this invention.
[0071] Figure 5 This is a flowchart illustrating steps S501-S503 of a data encryption method based on a classified computer proposed in this invention.
[0072] Figure 6 This is a flowchart illustrating steps S601-S603 of a data encryption method based on a classified computer proposed in this invention.
[0073] Figure 7 This is a structural block diagram of a data encryption system based on a classified computer proposed in this invention. Detailed Implementation
[0074] The following description is intended to disclose the invention and enable those skilled in the art to implement it. The preferred embodiments described below are merely examples, and other obvious variations will occur to those skilled in the art.
[0075] Reference Figure 1 As shown, a data encryption method based on a classified computer includes:
[0076] S100. Obtain relevant parameters of the private data, wherein the relevant parameters of the private data include the location characteristics of the private data and the byte length characteristics of the private data, the location characteristics of the private data include the start position of the private data and the end position of the private data, and the private data is obtained from the data to be encrypted;
[0077] S200. Based on the data encryption terminal, perform logical analysis on the location characteristics of the private data and the data to be encrypted to determine the pseudo-private data filling table, wherein the pseudo-private data filling table is a matrix structure.
[0078] S300: Based on the data encryption terminal, randomly select the pseudo-private data filling table to determine the filling of pseudo-private data, the filling of private data starting position data, and the filling of private data ending position data.
[0079] S400: Based on the data encryption terminal, fill the starting point of the private data and the ending point of the private data with the starting point and the ending point of the private data, and obtain the permuted private data, the first permutation point of the private data and the second permutation point of the private data;
[0080] S500: Based on the data encryption terminal, the first permutation bit and the second permutation bit of the private data are marked and sorted to obtain the private data permutation symbol;
[0081] S600: Based on the data encryption terminal, fill public data with pseudo-private data;
[0082] Those skilled in the art will understand that if only one encryption algorithm is used to encrypt the data to be encrypted, once a cracker cracks the encryption algorithm, the cracker will obtain all the data to be encrypted. When all the data to be encrypted is leaked, it will cause a certain degree of financial loss. Therefore, by extracting private data from the data to be encrypted, filling in pseudo-private data, and modifying private data, even if a cracker obtains the filled public data and the modified private data, they will not be able to restore it, thus improving data security.
[0083] Reference Figure 2 As shown, based on the data encryption terminal, the location characteristics of private data and the data to be encrypted are logically analyzed to determine the specific steps for filling the pseudo-private data table:
[0084] S201. Based on the data encryption terminal, the starting point and ending point of the private data are used as features to determine the position of the data to be encrypted, and the ending point and starting point of the public data are determined. The public data is the data to be encrypted that does not include the private data. The starting point of the public data corresponds to the ending point of the private data, and the ending point of the public data corresponds to the starting point of the private data.
[0085] S202. Based on the data encryption terminal, the public data is read and processed using the end point and the start point of the public data as features to obtain the start point data and the end point data of the public data.
[0086] S203. Based on the data encryption terminal, the private data is read and processed using the starting point and ending point of the private data as features to obtain the starting point data and ending point data of the private data.
[0087] S204. Based on the data encryption terminal, perform logical analysis on the starting point data of public data and the ending point data of private data, and the ending point data of public data and the starting point of private data, to determine the starting point logic of pseudo-private data and the ending point logic of pseudo-private data.
[0088] S205. Based on the data encryption terminal, the private data is copied using the starting point logic of the pseudo-private data, the ending point logic of the pseudo-private data, and the byte length characteristics of the private data as constraints, and the pseudo-private data filling table is obtained.
[0089] In this embodiment, to ensure a certain logical connection between the pseudo-filled data and the public data, logical analysis is performed on the starting point data of the public data and the ending point data of the private data, as well as the ending point data of the public data and the starting point of the private data. This determines the starting point logic and ending point logic of the pseudo-private data. Then, the content of the private data is copied using the starting point logic, the ending point logic, and the byte length characteristics of the private data as constraints. It is worth noting that the data copying here is not performed in binary form because binary numbers are represented by a combination of "0" and "1", which cannot express the logical connection of the data. Therefore, it is impossible to copy the data based on the binary number of the private data.
[0090] Reference Figure 3 As shown, based on the data encryption terminal, the random selection of the pseudo-private data filling table to determine the filling of pseudo-private data, the filling data at the starting position of private data, and the filling data at the ending position of private data specifically includes the following steps:
[0091] S301. Based on the random number function, randomly select data from the pseudo-private data filling table to obtain the pseudo-private data, the row data of the pseudo-private data, and the column data of the pseudo-private data.
[0092] S302. Based on the data encryption terminal, perform binary conversion on the row data and column data filled with pseudo-private data respectively to obtain the binary data corresponding to the row data and the binary data corresponding to the column data.
[0093] S303. Based on the data encryption terminal, the binary data corresponding to the row data is set as the start-point filling data of the private data, and the binary data corresponding to the column data is set as the end-point filling data of the private data.
[0094] In this embodiment, to ensure the logical nature of the changes to the private data, the private data is modified by filling in the row data and column data of the pseudo-private data. When it is necessary to restore the public data after the changes are made, the row data and column data of the pseudo-private data can be used to determine which pseudo-filling data is used to fill the public data in the pseudo-private data filling table. Then, the filling position is determined based on the pseudo-filling data. Finally, the complete data to be encrypted is obtained by filling the filling position with the restored private data.
[0095] Reference Figure 4 As shown, based on the data encryption terminal, the process of filling the starting and ending positions of the private data with padding data and filling the ending position of the private data, and obtaining the permuted private data, the first permutation position of the private data, and the second permutation position of the private data specifically includes the following steps:
[0096] S401. Based on the data encryption terminal, perform data extraction processing on the starting point and ending point of the private data to obtain the blank starting point and blank ending point of the private data.
[0097] S402. Based on the data encryption terminal, perform length analysis on the padding data at the starting point of the private data to determine the length of the padding data at the starting point of the private data.
[0098] S403. Based on the data encryption terminal, fill the starting point of the private data and the ending point of the private data with the filling data and the blank starting point and ending point of the private data respectively, and obtain the replaced private data and the length of the replaced private data.
[0099] S404. Based on the data encryption terminal, the last bit of the data filling data at the starting point of the private data is set as the first permutation bit of the private data.
[0100] S405. Based on the data encryption terminal, calculate and process the length of the data filled at the starting point of the private data, the byte length characteristics of the private data, and the length of the permuted private data to determine the second permutation bit of the private data;
[0101] The specific calculation formula for determining the second permutation bit of the private data is as follows:
[0102] ;
[0103] In the formula, the This is the second permutation bit for private data; To replace the length of private data; The byte length characteristic of private data; Fill the data length at the starting point of the private data;
[0104] In this embodiment, when it is necessary to restore the public data after filling, it is also necessary to restore the modified private data. The restoration of private data includes two parts: first, determining the data filling position of the original private data (i.e., the blank start position and blank end position of the private data, which are also the first and second permutation positions of the private data); second, filling the blank start position and blank end position of the private data with the previously extracted data (i.e., the start position data and end position data of the private data), and filling it into the first and second permutation positions of the private data. It can be understood that the private data here is represented in binary form.
[0105] Reference Figure 5 As shown, based on the data encryption terminal, the first and second permutation bits of the private data are marked and sorted to obtain the private data permutation symbol. The specific steps include:
[0106] S501. Based on the data encryption terminal, perform sequential analysis on the data to be encrypted to determine the position of each piece of private data in the data to be encrypted;
[0107] S502. Based on the data encryption terminal, sort the position of each private data in the data to be encrypted according to the read and write order of the data to be encrypted, and obtain the number of each private data.
[0108] S503. Based on the data encryption terminal, information is synthesized from the number of each private data, the first permutation bit of each private data, the second permutation bit of each private data, the starting point data of each private data, and the ending point data of each private data to obtain the private data permutation symbol.
[0109] The specific form of the private data substitution symbol is as follows: The Each piece of private data is assigned a unique identifier. The first permutation bit for each piece of private data. The binary number corresponding to the starting bit of each piece of private data. The second permutation bit for each piece of private data. The binary number corresponding to the endpoint bit data of each private data, where i is the specific number of private data;
[0110] In this embodiment, in order for the decryptor to accurately restore the public data after filling, a private data substitution symbol is constructed. The private data substitution symbol contains the private data number, the first substitution bit of each private data, the second substitution bit of each private data, the start bit data of each private data, and the end bit data of each private data. Then, the position of the substitution data in the private data is determined according to the first substitution bit and the second substitution bit of each private data. Finally, the start bit data and the end bit data of the private data are filled into the corresponding positions to realize the restoration of the private data.
[0111] Reference Figure 6 As shown, based on the data encryption terminal, the specific steps for filling public data with pseudo-private data include the following:
[0112] S601. Based on the data encryption terminal, fill the corresponding pseudo-private data into the corresponding position of the public data according to the number of each private data;
[0113] The corresponding location of the publicly available data here refers to the location of the private data, that is, the blank space left after the private data is extracted;
[0114] S602. Based on the data encryption terminal, generate an explanation manual for the private data substitution symbol according to the composition rules of the private data substitution symbol;
[0115] S603. Based on the encryption algorithm, the public data after padding, the private data substitution symbol, and the explanation of the private data substitution symbol are encrypted respectively, and the encrypted packet and the decrypted packet are sent to the electronic device of the decryptor.
[0116] In this embodiment, the encrypted package is decrypted using the decryption package containing the filled public data, the private data substitution symbol, and the explanation of the private data substitution symbol. This yields the filled public data, the private data substitution symbol, and the explanation of the private data substitution symbol. Then, the private data substitution symbol is decrypted according to the explanation of the private data substitution symbol to obtain the filling positions for the private data (the first and second substitution bits of the private data). The starting and ending points of the private data are then filled into the first and second substitution bits of the private data. The replaced data is then converted to binary to obtain the row and column data of the pseudo-private data. Finally, the pseudo-private data filling table is retrieved based on the row and column data of the pseudo-private data to determine the pseudo-private data to be used. The pseudo-private data is then used to match the filled public data to determine the data filling position (the positional characteristics of the private data). Finally, the restored private data is filled into the positional characteristics of the private data to obtain the complete data to be encrypted.
[0117] Reference Figure 7 As shown, a data encryption system based on a classified computer is used to implement the data encryption method based on a classified computer as described above, comprising:
[0118] A data encryption terminal is used to perform logical analysis of private data in the data to be encrypted, random selection of pseudo-private data for filling, data filling processing, and data encryption processing.
[0119] A storage device, wherein the storage device is a storage module of a classified computer, used to store data to be encrypted;
[0120] The data encryption terminal integrates the following:
[0121] The core controller is used to control the data transmission and information interaction between the various modules.
[0122] The data extraction module performs private data extraction processing on the data to be encrypted based on the private data reference table;
[0123] The data logic analysis module is used to perform logical analysis on the location characteristics of private data and the data to be encrypted to determine the pseudo-private data filling table.
[0124] The data selection module randomly selects pseudo-private data from the pseudo-private data filling table according to a random number function, determines the pseudo-private data to be filled, and sets the row information and column information of the pseudo-private data to be filled as the starting point data and the ending point data of the private data, respectively.
[0125] The data replacement module fills the blank starting position and blank ending position of the private data according to the filling data at the starting position and the filling data at the ending position of the private data, respectively, and analyzes and calculates the blank starting position and blank ending position of the private data after filling to determine the first replacement position and the second replacement position of the private data.
[0126] The permutation symbol generation module is used to synthesize information from the number of each private data, the first permutation bit of each private data, the second permutation bit of each private data, the starting point data of each private data, and the ending point data of each private data to obtain a private data permutation symbol.
[0127] The data encryption module encrypts the filled public data, private data permutation symbol, and private data permutation symbol interpretation specification respectively using an encryption algorithm, and sends the encryption package and decryption package to the decryptor's electronic device.
[0128] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely principles of the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the claimed invention. The scope of protection claimed by the appended claims and their equivalents is defined.
Claims
1. A data encryption method based on a classified computer, characterized in that, include: Obtain relevant parameters of private data, wherein the relevant parameters of private data include the location characteristics of private data and the byte length characteristics of private data. The location characteristics of private data include the start position and the end position of private data. The private data is obtained from the data to be encrypted. Based on the data encryption terminal, the location characteristics of private data and the data to be encrypted are logically analyzed to determine the pseudo-private data filling table, which is a matrix structure. Based on the data encryption terminal, the pseudo-private data filling table is randomly selected to determine the filling of pseudo-private data, the filling of data at the starting position of private data, and the filling of data at the ending position of private data. Based on the data encryption terminal, the starting point filling data and the ending point filling data of the private data are filled into the starting point and the ending point of the private data, and the permuted private data, the first permutation bit of the private data and the second permutation bit of the private data are obtained; Based on the data encryption terminal, the first permutation bit and the second permutation bit of the private data are marked and sorted to obtain the private data permutation symbol; Based on the data encryption terminal, pseudo-private data is filled into public data; The step of performing logical analysis on the location characteristics of private data and the data to be encrypted based on the data encryption terminal to determine the pseudo-private data filling table specifically includes the following steps: Based on the data encryption terminal, the starting point and ending point of the private data are used as features to determine the position of the data to be encrypted, and the ending point and starting point of the public data are determined. The public data is the data to be encrypted that does not include the private data. The starting point of the public data corresponds to the ending point of the private data, and the ending point of the public data corresponds to the starting point of the private data. Based on the data encryption terminal, the public data is read and processed using the end point and the start point of the public data as features to obtain the start point data and the end point data of the public data. Based on the data encryption terminal, the private data is read and processed using the starting point and ending point of the private data as features to obtain the starting point data and ending point data of the private data. Based on the data encryption terminal, logical analysis is performed on the starting point data of public data and the ending point data of private data, as well as the ending point data of public data and the starting point of private data, to determine the starting point logic of pseudo-private data and the ending point logic of pseudo-private data. Based on the data encryption terminal, the private data is replicated by using the starting point logic of the pseudo-private data, the ending point logic of the pseudo-private data, and the byte length characteristics of the private data as constraints, and the pseudo-private data filling table is obtained.
2. The data encryption method based on a classified computer according to claim 1, characterized in that, The process of randomly selecting pseudo-private data from the data encryption terminal to determine the pseudo-private data, the data to be filled at the start position of the private data, and the data to be filled at the end position of the private data specifically includes the following steps: Based on the random number function, the pseudo-private data filling table is randomly selected to obtain the pseudo-private data, the row data of the pseudo-private data, and the column data of the pseudo-private data. Based on the data encryption terminal, the row data and column data filled with pseudo-private data are converted into binary data respectively to obtain the binary data corresponding to the row data and the binary data corresponding to the column data. Based on the data encryption terminal, the binary data corresponding to the row data is set as the starting point of the private data filling data, and the binary data corresponding to the column data is set as the ending point of the private data filling data.
3. The data encryption method based on a classified computer according to claim 1, characterized in that, The process of filling the starting and ending positions of the private data with start and end data based on the data encryption terminal, and obtaining the permuted private data, the first permutation position, and the second permutation position of the private data, specifically includes the following steps: Based on the data encryption terminal, the starting point and ending point of the private data are extracted and processed to obtain the blank starting point and blank ending point of the private data. Based on the data encryption terminal, the length of the padding data at the starting point of the private data is analyzed to determine the length of the padding data at the starting point of the private data. Based on the data encryption terminal, the starting point padding data and the ending point padding data of the private data are respectively filled into the blank starting point and the blank ending point of the private data to obtain the replaced private data and the length of the replaced private data. Based on the data encryption terminal, the last bit of the data filling data at the starting point of the private data is set as the first permutation bit of the private data; Based on the data encryption terminal, the length of the data filled at the starting point of the private data, the byte length characteristics of the private data, and the length of the permuted private data are calculated and processed to determine the second permutation bit of the private data.
4. A data encryption method based on a classified computer according to claim 3, characterized in that, The specific calculation formula for determining the second permutation bit of the private data is as follows: ; In the formula, the This is the second permutation bit for private data; To replace the length of private data; The byte length characteristic of private data; Fill in the data length at the starting point of the private data.
5. A data encryption method based on a classified computer according to claim 1, characterized in that, The process of marking and sorting the first and second permutation bits of the private data based on the data encryption terminal to obtain the private data permutation symbol specifically includes the following steps: Based on the data encryption terminal, sequential analysis is performed on the data to be encrypted to determine the position of each piece of private data in the data to be encrypted. Based on the data encryption terminal, the position of each piece of private data in the data to be encrypted is sorted according to the read and write order of the data to be encrypted, and the number of each piece of private data is obtained. Based on the data encryption terminal, information is synthesized from the number of each private data, the first permutation bit of each private data, the second permutation bit of each private data, the starting point data of each private data, and the ending point data of each private data to obtain the private data permutation symbol.
6. A data encryption method based on a classified computer according to claim 5, characterized in that, The specific form of the private data substitution symbol is as follows: The Each piece of private data is assigned a unique identifier. The first permutation bit for each piece of private data. The binary number corresponding to the starting bit of each piece of private data. The second permutation bit for each piece of private data. Let i be the binary number corresponding to the endpoint bit of each piece of private data, where i is the specific number of pieces of private data.
7. A data encryption method based on a classified computer according to claim 1, characterized in that, The process of filling public data with pseudo-private data based on a data encryption terminal specifically includes the following steps: Based on the data encryption terminal, the corresponding pseudo-private data is filled into the corresponding position of the public data according to the number of each private data; Based on the data encryption terminal, an explanation manual for private data substitution symbols is generated according to the rules for the composition of private data substitution symbols. Based on the encryption algorithm, the public data after padding, the private data substitution symbol, and the explanation of the private data substitution symbol are encrypted respectively, and the encrypted packet and the decrypted packet are sent to the electronic device of the decryptor.
8. A data encryption system based on a classified computer, used to implement the data encryption method based on a classified computer as described in any one of claims 1-7, characterized in that, include: A data encryption terminal is used to perform logical analysis of private data in the data to be encrypted, random selection of pseudo-private data for filling, data filling processing, and data encryption processing. A storage device, wherein the storage device is a storage module of a classified computer, used to store data to be encrypted; The data encryption terminal integrates the following: The core controller is used to control the data transmission and information interaction between the various modules. The data extraction module performs private data extraction processing on the data to be encrypted based on the private data reference table; The data logic analysis module is used to perform logical analysis on the location characteristics of private data and the data to be encrypted to determine the pseudo-private data filling table. The data selection module randomly selects pseudo-private data from the pseudo-private data filling table according to a random number function, determines the pseudo-private data to be filled, and sets the row information and column information of the pseudo-private data to be filled as the starting point data and the ending point data of the private data, respectively. The data replacement module fills the blank starting position and blank ending position of the private data according to the filling data at the starting position and the filling data at the ending position of the private data, respectively, and analyzes and calculates the blank starting position and blank ending position of the private data after filling to determine the first replacement position and the second replacement position of the private data. The permutation symbol generation module is used to synthesize information from the number of each private data, the first permutation bit of each private data, the second permutation bit of each private data, the starting point data of each private data, and the ending point data of each private data to obtain a private data permutation symbol. The data encryption module encrypts the filled public data, private data permutation symbol, and private data permutation symbol interpretation specification respectively using an encryption algorithm, and sends the encryption package and decryption package to the decryptor's electronic device.
9. A storage medium, characterized in that, It stores a computer program, which, when invoked and executed, performs a data encryption method based on a classified computer as described in any one of claims 1-7.