Information data protection method and device, equipment and storage medium

By performing circular domain calculation and inverse operation on the information data, dynamically changing sub-data is generated, which solves the problem of low security caused by fixed storage of information data, and achieves higher security and attack resistance.

CN120296785APending Publication Date: 2025-07-11GUANGZHOU ZHONO ELECTRONICS TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510373578.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-27
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

In the prior art, information data is stored in memory in a fixed manner, and cannot effectively resist multiple attacks by attackers, and the security of information data is low.

Method used

By obtaining the first sub-data and the second sub-data corresponding to the information data to be protected, and the random number, the first sub-data and the random number are cyclically calculated, the first updated data is generated, and the stored first sub-data is replaced with the first updated data. At the same time, the random number is inversely operated, the inverse operation value is generated, and the second sub-data and the inverse operation value are cyclically calculated, and the second updated data is generated, so that the sub-data of the information data is dynamically changed.

Benefits of technology

The dynamic changes of sub-data of information data are realized, making it difficult for attackers to monitor and analyze, improving the security of information data and effectively resisting multiple attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120296785A_ABST
    Figure CN120296785A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides an information data protection method and device, equipment and a storage medium, and the method comprises the steps: obtaining first sub-data and second sub-data corresponding to to-be-protected information data, and a random number, carrying out the cyclic domain operation of the first sub-data and the random number, and obtaining first update data, replacing the first sub-data with first update data, generating the to-be-protected information data based on the first sub-data and the second sub-data, performing inverse operation on a number of cyclic domain operation on the random number to obtain an inverse operation value, and performing cyclic domain operation on the second sub-data and the inverse operation value to obtain second update data, and replacing the stored second sub-data with the second update data, wherein a result obtained by carrying out the cyclic domain operation on the first sub-data and the second sub-data is the same as a result obtained by carrying out the cyclic domain operation on the first update data and the second update data. According to the scheme, the sub-data for generating the information data dynamically changes through cyclic domain operation, so that an attacker is difficult to monitor and analyze the information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the technical field of information protection, and in particular, to an information data protection method, apparatus, device, and storage medium. Background Art

[0002] In the digital age, the protection of data information is of vital importance. Taking key information as an example, key information plays a crucial role in information security. It is the core element in the encryption and decryption processes, determining the strength of the encryption algorithm and the security level of the data. Once the key information is leaked or mismanaged, it may lead to illegal access or tampering of the data, thus triggering serious security problems. In order to ensure the security of data information, it is necessary to strengthen the management and protection of data information.

[0003] In related information data protection methods, usually a layer of custom algorithm is applied to the information, and the information is decomposed into the algorithm input of the custom algorithm, the algorithm key, and the custom algorithm itself. The algorithm input and algorithm key information are stored in the memory. Although this protection method splits the information into multiple sub-informations, the information is still fixedly stored in the memory, unable to prevent multiple attacks by attackers and information combination, and the security of the information is relatively low. Summary of the Invention

[0004] The embodiments of the present application provide an information data protection method, apparatus, device, and storage medium, which solve the problem in the related art that the information data to be protected is fixedly stored in the memory, unable to effectively resist multiple attacks by attackers, and the security of the information data is relatively low, making the sub-data for generating the information data change dynamically, achieving the purpose that it is difficult for attackers to monitor and analyze the information.

[0005] In a first aspect, the embodiments of the present application provide an information data protection method, including:

[0006] Obtain a first sub-data, a second sub-data, and a random number corresponding to the information data to be protected, perform a cyclic field operation on the first sub-data and the random number to obtain a first updated data, and replace the stored first sub-data with the first updated data, where the information data to be protected is generated based on the first sub-data and the second sub-data;

[0007] Perform an inverse operation on the number for which the cyclic field operation is performed on the random number to obtain an inverse operation value;

[0008] Perform a cyclic field operation on the second sub-data and the inverse operation value to obtain a second updated data, and replace the stored second sub-data with the second updated data, where the result of performing the cyclic field operation on the first sub-data and the second sub-data is the same as the result of performing the cyclic field operation on the first updated data and the second updated data.

[0009] Optionally, after replacing the second sub-data to be stored with the second updated data, the method further includes:

[0010] When the information data to be protected is called, performing the cyclic field operation on the first updated data and the second updated data to generate the information data to be protected.

[0011] Optionally, before obtaining the first sub-data, the second sub-data, and the random number corresponding to the information data to be protected, the method further includes:

[0012] Generating an iteration flag, where the iteration flag is generated based on a fixed program triggered when the chip is powered on, or based on an iteration instruction detected and transmitted externally.

[0013] Optionally, the cyclic field operation includes any one of exclusive OR operation, modular addition operation, modular multiplication operation, and mapping operation. The inverse operation of the number in the exclusive OR operation is the number itself. The inverse operation of the number in the modular addition operation is the additive inverse of the number in the modular addition operation with respect to the modulus. The inverse operation of the number in the modular multiplication operation is the multiplicative inverse of the number in the modular multiplication operation with respect to the modulus. The inverse operation of the number in the mapping operation is the inverse mapping.

[0014] Optionally, when the cyclic field operation is a modular multiplication operation, the performing the cyclic field operation on the first sub-data and the random number to obtain the first updated data includes:

[0015] Calculating a first product result of the random number and the first sub-data, and performing a modulo operation on the first product result with a preset modulus to obtain the first updated data;

[0016] Correspondingly, the performing the cyclic field operation on the second sub-data and the inverse operation value to obtain the second updated data includes:

[0017] Calculating a second product result of the inverse operation value and the second sub-data, and performing the modulo operation on the second product result with the preset modulus to obtain the second updated data.

[0018] Optionally, the information data to be protected includes key information data, the first sub-data includes a custom algorithm input, and the second sub-data includes a custom algorithm key.

[0019] Optionally, before obtaining the first sub-data, the second sub-data, and the random number corresponding to the information data to be protected, the method further includes:

[0020] Performing a program task corresponding to a first security program;

[0021] Correspondingly, before obtaining the inverse operation value through the inverse operation of the number obtained by performing the cyclic field operation on the random number, the method further includes:

[0022] Performing the program tasks corresponding to the second security program;

[0023] Correspondingly, after generating the information data to be protected through performing the cyclic field operation on the first update data and the second update data, the method further includes:

[0024] Comparing the information data to be protected with preset comparison data, and verifying whether the first security program and the second security program are correctly executed based on the comparison result.

[0025] In a second aspect, an embodiment of the present application further provides an information data protection device, including:

[0026] A data operation module, configured to obtain a first sub-data, a second sub-data, and a random number corresponding to the information data to be protected, perform a cyclic field operation on the first sub-data and the random number to obtain first update data, and the information data to be protected is generated based on the first sub-data and the second sub-data;

[0027] A data replacement module, configured to replace the stored first sub-data with the first update data;

[0028] The data operation module is further configured to perform an inverse operation of the number obtained by performing the cyclic field operation on the random number to obtain an inverse operation value, and perform a cyclic field operation on the second sub-data and the inverse operation value to obtain second update data;

[0029] The data replacement module is further configured to replace the stored second sub-data with the second update data, where the result of performing the cyclic field operation on the first sub-data and the second sub-data is the same as the result of performing the cyclic field operation on the first update data and the second update data.

[0030] In a third aspect, an embodiment of the present application further provides an information data protection device, and the device includes:

[0031] One or more processors;

[0032] A storage device, configured to store one or more programs,

[0033] When the one or more programs are executed by the one or more processors, the one or more processors implement the information data protection method described in the embodiments of the present application.

[0034] Fourthly, an embodiment of the present application further provides a storage medium storing computer-executable instructions, and the computer-executable instructions are used to execute the information data protection method described in the embodiments of the present application when executed by a computer processor.

[0035] In the embodiments of the present application, by obtaining a first sub-data, a second sub-data, and a random number corresponding to the information data to be protected, performing a cyclic field operation on the first sub-data and the random number to obtain a first updated data, replacing the stored first sub-data with the first updated data, the information data to be protected is generated based on the first sub-data and the second sub-data, performing an inverse operation on the number obtained by performing a cyclic field operation on the random number to obtain an inverse operation value, performing a cyclic field operation on the second sub-data and the inverse operation value to obtain a second updated data, and replacing the stored second sub-data with the second updated data. Among them, the result of performing a cyclic field operation on the first sub-data and the second sub-data is the same as the result of performing a cyclic field operation on the first updated data and the second updated data. This solution makes the split information sub-data change dynamically through cyclic field operations, solves the problem in the related art that the information data to be protected is fixedly stored in the memory, cannot effectively resist multiple attacks by attackers, and the security of the information data is relatively low, and enables the sub-data for generating the information data to change dynamically, achieving the purpose that it is difficult for attackers to monitor and analyze the information. Description of the Drawings

[0036] Figure 1 It is a flowchart of an information data protection method provided by an embodiment of the present application;

[0037] Figure 2 It is a flowchart of an information data protection method including information data generation provided by an embodiment of the present application;

[0038] Figure 3 It is a flowchart of an information data protection method including information data generation with iteration flag generation provided by an embodiment of the present application;

[0039] Figure 4 It is a flowchart of an information data protection method including a cyclic field operation method provided by an embodiment of the present application;

[0040] Figure 5 It is a flowchart of an information data protection method including key information data provided by an embodiment of the present application;

[0041] Figure 6 It is a flowchart of an information data protection method including security program execution verification provided by an embodiment of the present application;

[0042] Figure 7 It is a module structure block diagram of an information data protection device provided by an embodiment of the present application;

[0043] Figure 8 The structural schematic diagram of an information data protection device provided by an embodiment of the present application. Specific embodiments

[0044] The following further describes in detail the embodiments of the present application with reference to the accompanying drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the embodiments of the present application, rather than limiting the embodiments of the present application. In addition, it should be noted that for the sake of description, only parts related to the embodiments of the present application are shown in the drawings, rather than all structures.

[0045] The terms "first", "second", etc. in the specification and claims of the present application are used to distinguish similar objects, rather than to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances, so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first", "second", etc. are usually of the same type, and the number of objects is not limited. For example, the first object can be one or multiple. In addition, "and / or" in the specification and claims means at least one of the connected objects, and the character "or" generally represents an "or" relationship between the associated objects before and after.

[0046] An information data protection method provided by an embodiment of the present application can be applied to information protection scenarios of cryptographic algorithms such as symmetric algorithms, message digest algorithms, and asymmetric algorithms. For an information data protection method provided by an embodiment of the present application, the execution subject of each step can be a computer device, which refers to any electronic device with data calculation, processing, and storage capabilities, such as terminal devices such as mobile phones, PCs (Personal Computers), and tablet computers, or devices such as servers. The embodiments of the present application do not limit this.

[0047] Figure 1 The flowchart of an information data protection method provided by an embodiment of the present application, as Figure 1 shown, specifically includes:

[0048] Step S101: Obtain a first sub-data, a second sub-data, and a random number corresponding to the information data to be protected, perform a cyclic domain operation on the first sub-data and the random number to obtain a first updated data, and replace the stored first sub-data with the first updated data, where the information data to be protected is generated based on the first sub-data and the second sub-data.

[0049] Among them, the information data to be protected is the information data that needs to be protected. This information data to be protected is generated based on the first sub-data and the second sub-data. For example, this information data to be protected is generated by performing an operation on the first sub-data and the second sub-data. The first sub-data and the second sub-data are respectively stored in the memory. A random number refers to a randomly generated value, such as generated by a random number generator, or a random number can also be generated by a set algorithm module. The first update data is obtained by performing a cyclic domain operation on the first sub-data and the random number.

[0050] Among them, the cyclic domain operation refers to an operation method with the characteristic of f(A1, B1) = f(f(A1, R), f(B1, R -1 )) = f(A2, B2), where A1 is the first sub-data, B1 is the second sub-data, R is the random number, and R -1 is the inverse operation value of this random number, A2 is the first update data, and B2 is the second update data.

[0051] In one embodiment, before performing a cyclic domain operation on the first sub-data and the random number to obtain the first update data, a random number can be generated by a random number generator, and this random number is saved to a register. The random number in the register is sent to a cyclic domain operation data temporary storage module for storage. The first sub-data in the memory is read and saved to the register for use in obtaining the first update data through a cyclic domain operation. Correspondingly, after obtaining the first update data, the originally stored first sub-data is replaced to avoid it being directly exposed and easily attacked and stolen.

[0052] Step S102: Perform an inverse operation on the number obtained by performing a cyclic domain operation on the random number to obtain an inverse operation value.

[0053] Among them, the inverse operation of a number can be a reverse operation process that completely cancels a specified operation. Exemplarily, in multiplication operation, the inverse operation of a number is division operation. If the random number is 3, the corresponding inverse operation value is 1 / 3. In one embodiment, the obtained random number is sent to an inverse operation module corresponding to the cyclic domain operation for calculation to obtain the inverse operation value corresponding to this random number.

[0054] Step S103: Perform a cyclic domain operation on the second sub-data and the inverse operation value to obtain the second update data, and replace the stored second sub-data with the second update data, where the result of performing a cyclic domain operation on the first sub-data and the second sub-data is the same as the result of performing a cyclic domain operation on the first update data and the second update data.

[0055] In one embodiment, after calculating the inverse operation value of the random number, the inverse operation value is stored in the cyclic domain operation data temporary storage module, the second sub-data in the memory is read, and the second sub-data is saved in the register for cyclic domain operation to obtain the second updated data. Correspondingly, after obtaining the second updated data, the originally stored second sub-data is overwritten.

[0056] Among them, the result of the cyclic domain operation on the first sub-data and the second sub-data is the same as the result of the cyclic domain operation on the first updated data and the second updated data, and both are the information data to be protected. By making the split sub-information change dynamically while the integrated information remains unchanged, the purpose of making it difficult for attackers to monitor and analyze the information can be achieved.

[0057] As can be seen from the above, by obtaining the first sub-data, the second sub-data, and the random number corresponding to the information data to be protected, performing a cyclic domain operation on the first sub-data and the random number to obtain the first updated data, and replacing the stored first sub-data with the first updated data, wherein the information data to be protected is generated based on the first sub-data and the second sub-data, performing an inverse operation on the number obtained by performing a cyclic domain operation on the random number to obtain the inverse operation value, performing a cyclic domain operation on the second sub-data and the inverse operation value to obtain the second updated data, and replacing the stored second sub-data with the second updated data, wherein the result of the cyclic domain operation on the first sub-data and the second sub-data is the same as the result of the cyclic domain operation on the first updated data and the second updated data. This solution makes the split information sub-data change dynamically through cyclic domain operations, solves the problem in the related art that the information data to be protected is fixedly stored in the memory, cannot effectively resist multiple attacks by attackers, and the security of the information data is relatively low, and makes the sub-data generating the information data change dynamically, achieving the purpose of making it difficult for attackers to monitor and analyze the information.

[0058] Figure 2 It is a flowchart of an information data protection method including information data generation provided by an embodiment of the present application. As Figure 2 shown, it specifically includes:

[0059] Step S201: Obtain the first sub-data, the second sub-data, and the random number corresponding to the information data to be protected, perform a cyclic domain operation on the first sub-data and the random number to obtain the first updated data, and replace the stored first sub-data with the first updated data, wherein the information data to be protected is generated based on the first sub-data and the second sub-data.

[0060] Step S202: Perform an inverse operation on the number obtained by performing a cyclic domain operation on the random number to obtain the inverse operation value.

[0061] Step S203: Perform a cyclic field operation on the second sub-data and the inverse operation value to obtain the second updated data, and replace the stored second sub-data with the second updated data. Among them, the result of performing a cyclic field operation on the first sub-data and the second sub-data is the same as the result of performing a cyclic field operation on the first updated data and the second updated data.

[0062] Step S204: When the data of the information to be protected is called, perform a cyclic field operation on the first updated data and the second updated data to generate the data of the information to be protected.

[0063] Among them, after replacing the stored second sub-data with the second updated data, when it is determined to call the data of the information to be protected, perform a cyclic field operation on the first updated data and the second updated data to generate the data of this information. In other cases, the first updated data and the second updated data remain in the stored state.

[0064] In one embodiment, when a call instruction for the data of the information to be protected is received, obtain the first updated data and the second updated data stored in the memory, save the first updated data to the cyclic field operation data temporary storage module, save the second updated data to the cyclic field operation data register, and send the first updated data stored in the cyclic field operation data temporary storage module and the second updated data stored in the cyclic field operation data register to the cyclic field operation module for operation to obtain the data of this information.

[0065] As can be seen from the above, after replacing the stored second sub-data with the second updated data, when the data of the information to be protected is called, perform a cyclic field operation on the first updated data and the second updated data to generate the data of the information to be protected. In this solution, when the protected data is called, the updated data is operated to obtain the protected data, which can improve the confidentiality of the protected information data.

[0066] Figure 3 It is a flowchart of an information data protection method including iterative flag generation provided by an embodiment of the present application. As Figure 3 shown, it specifically includes:

[0067] Step S301: Generate an iterative flag, obtain the first sub-data and the second sub-data corresponding to the data of the information to be protected, and a random number. Perform a cyclic field operation on the first sub-data and the random number to obtain the first updated data, and replace the stored first sub-data with the first updated data. Among them, the iterative flag is generated based on a fixed program triggered when the chip is powered on, or based on an iterative instruction detected in external transmission. The data of the information to be protected is generated based on the first sub-data and the second sub-data.

[0068] Among them, the iteration flag can be a flag indicating the execution of the update operation of the first sub-data and the second sub-data. The iteration flag can be generated based on a fixed program triggered when the chip is powered on, or based on the detected iteration instruction of the external transmission. The fixed program may include an instruction to set the iteration flag, which is executed after the chip is powered on. In one embodiment, a method for generating an iteration flag can be that when the chip is powered on, a fixed program including an instruction to set the iteration flag is automatically executed to generate a corresponding iteration flag. The generation of the iteration flag does not need to rely on external signal input, avoiding the risk of interruption of the iteration process due to communication link failure or instruction delay; in addition, the fixed program is solidified inside the chip (such as ROM) and cannot be tampered with externally, which can prevent malicious instruction injection attacks and meet the protection requirements of functional safety certification for key parameters. In another embodiment, a method for generating an iteration flag can be to detect the received external transmission instruction, and when it is detected that the external transmission instruction is an instruction to generate an iteration flag, a corresponding iteration flag is generated according to the content of the instruction, and the timing and logic of the iteration flag generation are controlled in real time through external instructions, supporting remote upgrades or parameter adjustments (such as OTA updates) to adapt to dynamic requirements such as algorithm iterations and environmental changes. The iteration flag may include the number of iterations and an end condition.

[0069] Step S302: Perform an inverse operation of the cyclic domain operation on the random number to obtain an inverse operation value.

[0070] Step S303, performing a loop domain operation on the second sub-data and the inverse operation value to obtain second updated data, and replacing the stored second sub-data with the second updated data, wherein a result of performing the loop domain operation on the first sub-data and the second sub-data is the same as a result of performing the loop domain operation on the first update data and the second update data.

[0071] As can be seen from the above, by generating an iteration flag, obtaining the first sub-data and the second sub-data corresponding to the information data to be protected, and the random number, performing a loop domain operation on the first sub-data and the random number to obtain the first update data, and replacing the stored first sub-data with the first update data, wherein the iteration flag is generated based on a fixed program triggered when the chip is powered on, or based on an iteration instruction detected by external transmission. The iteration flag of this solution determines whether to update the sub-data, which can reasonably control the update of the sub-data and make the sub-data change dynamically.

[0072] Figure 4 A flowchart of an information data protection method including a loop domain operation method provided in an embodiment of the present application is shown in FIG. Figure 4 As shown, specifically including:

[0073] Step S401: Obtain the first sub - data, the second sub - data corresponding to the data to be protected, and a random number. Perform a cyclic field operation on the first sub - data and the random number to obtain the first updated data, and replace the stored first sub - data with the first updated data. Here, the data to be protected is generated based on the first sub - data and the second sub - data, and the cyclic field operation includes any one of exclusive - OR operation, modular addition operation, modular multiplication operation, and mapping operation.

[0074] Among them, the exclusive - OR operation means operating on two operands. If they are different, the result is true (1); if they are the same, the result is false (0). The modular addition operation is an addition operation carried out under the limitation of a modulus (a positive integer), and its result is the remainder obtained by taking the modulus of the addition result. The modular multiplication operation is a multiplication operation carried out under the limitation of a modulus, and its result is the remainder obtained by taking the modulus of the multiplication result. The mapping operation is a mathematical correspondence relationship that maps the elements in one set to the elements in another set. Optionally, when the cyclic field operation is a modular multiplication operation, one operation method of the first updated data can be to calculate the first product result of the random number and the first sub - data, and perform a remainder operation with a preset modulus on the first product result to obtain the first updated data. Exemplarily, the random number is 3, the first sub - data is 105, and the preset modulus is 25. Calculate the first product result of the random number and the first sub - data as 315, and calculate the remainder of 315 divided by 25 as 15, that is, the first updated data is 15.

[0075] In one embodiment, when the cyclic field operation is a mapping operation, one operation method of the first updated data can be to substitute the random number and the first sub - data into a preset function to obtain the first updated key sub - information. In another embodiment, when the cyclic field operation is a modular addition operation, one operation method of the first updated data can be to calculate the sum of the random number and the first sub - data, and perform a remainder operation with a preset modulus on the sum of the random number and the first sub - data to obtain the first updated data.

[0076] Step S402: Perform the inverse operation of the number for the cyclic field operation on the random number to obtain the inverse operation value.

[0077] Among them, the inverse operation of the number for the exclusive - OR operation is the number itself. The inverse operation of the number for the modular addition operation is the additive inverse of the number for the modular addition operation with respect to the modulus. The inverse operation of the number for the modular multiplication operation is the multiplicative inverse of the number for the modular multiplication operation with respect to the modulus. The inverse operation of the number for the mapping operation is the inverse mapping.

[0078] Among them, the additive inverse is an integer whose sum with an integer has a remainder of 0 when divided by the modulus. Exemplarily, when the random number is 3 and the cyclic domain operation is modular addition, the modulus is 12, and the integer whose sum with 3 has a remainder of 0 when divided by 12 is determined to be 9, then 9 is determined as the inverse operation value. The multiplicative inverse refers to an integer whose product with an integer has a remainder of 1 when divided by the modulus. Exemplarily, when the random number is 2 and the cyclic domain operation is modular multiplication, the modulus is 11, and the integer whose product with 2 has a remainder of 1 when divided by 11 is determined to be 6, then 6 is determined as the inverse operation value. The inverse mapping can be the mapping relationship from a function to its inverse function. Exemplarily, when the random number is 5 and the cyclic domain operation is a mapping operation, the preset function is f = kx + b, where b is a constant, and k corresponds to the random number. Its inverse function is x = (y - b) / k, which can be written as x = k'y + b', where k' = 1 / k. That is, the inverse mapping of k is 1 / k, and the inverse operation value corresponding to the random number 5 is 1 / 5.

[0079] Step S403: Perform a cyclic domain operation on the second sub-data and the inverse operation value to obtain second updated data, and replace the stored second sub-data with the second updated data. Among them, the result of the cyclic domain operation on the first sub-data and the second sub-data is the same as the result of the cyclic domain operation on the first updated data and the second updated data.

[0080] Among them, optionally, when the cyclic domain operation is modular multiplication, one operation method of the second updated data can be to calculate the second product result of the inverse operation value and the second sub-data, and perform a remainder operation with the preset modulus on the second product result to obtain the second updated data. Exemplarily, the inverse operation value is 6, the second sub-data is 45, and the preset modulus is 25. Calculate the first product result of the random number and the first sub-data to be 270, and calculate the remainder of 270 divided by 25 to be 20, that is, the second updated data is 20.

[0081] In one embodiment, when the cyclic domain operation is a mapping operation, one operation method of the second updated data can be to substitute the inverse operation value and the second sub-data into the preset function to obtain the second updated key sub-information. In another embodiment, when the cyclic domain operation is modular addition, one operation method of the first updated data can be to calculate the sum of the inverse operation value and the second sub-data, and perform a remainder operation with the preset modulus on the sum of the inverse operation value and the second sub-data to obtain the first updated data.

[0082] In one embodiment, when the cyclic field operation is a modular multiplication operation, the result of the modular multiplication operation on the first sub-data and the second sub-data is the same as the result of the modular multiplication operation on the first updated data and the second updated data. Exemplarily, the random number is 2, the first sub-data is 17, the second sub-data is 15, the preset modulus is 7, the first updated data obtained based on the modular multiplication operation is 6, the inverse operation value is 4, the second updated data is 4. Calculate the product of the first sub-data 17 and the second sub-data 15 to be 255, and the remainder of 255 divided by 7 is 3. Calculate the product of the first updated data 6 and the second updated data 4 to be 24, and the remainder of 24 divided by 7 is 3.

[0083] As can be seen from the above, the cyclic field operation in the information data protection method includes any one of exclusive OR operation, modular addition operation, modular multiplication operation, and mapping operation. The inverse operation of the number in the exclusive OR operation is the number itself. The inverse operation of the number in the modular addition operation is the additive inverse element of the number in the modular addition operation with respect to the modulus. The inverse operation of the number in the modular multiplication operation is the multiplicative inverse element of the number in the modular multiplication operation with respect to the modulus. The inverse operation of the number in the mapping operation is the inverse mapping. Through the characteristics of the cyclic field operation, this solution makes the sub-data of the generated information data change dynamically, but the integrated data remains unchanged, and it can achieve the purpose that it is difficult for attackers to monitor and analyze the information.

[0084] Figure 5 The flowchart of an information data protection method including key information data provided by an embodiment of the present application is as Figure 5 shown, and specifically includes:

[0085] Step S501, obtain the first sub-data and the second sub-data corresponding to the information data to be protected, and a random number, perform a cyclic field operation on the first sub-data and the random number to obtain the first updated data, and replace the stored first sub-data with the first updated data, where the information data to be protected is generated based on the first sub-data and the second sub-data, the information data to be protected includes key information data, the first sub-data includes a custom algorithm input, and the second sub-data includes a custom algorithm key.

[0086] Among them, the key information data is used to represent the core parameters for encrypting, decrypting, and verifying data security, and its function is to protect the confidentiality and integrity of the data. The custom algorithm input and the custom algorithm key are sub-data obtained by splitting the key information data through a custom algorithm. In one embodiment, before obtaining the random number, the key information data is split into a custom algorithm input and a custom algorithm key according to a custom-set cyclic field operation method and stored in a memory, and the result of the cyclic field operation on the custom algorithm input and the custom algorithm key is the key information data.

[0087] Step S502: Perform the inverse operation on the number obtained by performing the cyclic field operation on the random number to obtain an inverse operation value.

[0088] Step S503: Perform a cyclic field operation on the second sub-data and the inverse operation value to obtain second updated data, and replace the stored second sub-data with the second updated data. Among them, the result of performing a cyclic field operation on the first sub-data and the second sub-data is the same as the result of performing a cyclic field operation on the first updated data and the second updated data.

[0089] As can be seen from the above, the information data to be protected in the information data protection method includes key information data, the first sub-data includes the custom algorithm input, and the second sub-data includes the custom algorithm key. This solution solves the problem in the related technology that the key information data is fixedly stored in the memory and cannot effectively resist multiple attacks by attackers, and the security of the key information data is relatively low, making the sub-data for generating the key information data change dynamically, achieving the purpose that it is difficult for attackers to monitor and analyze the information.

[0090] Figure 6 It is a flowchart of an information data protection method including security program execution verification provided by an embodiment of the present application. As Figure 6 shown, it specifically includes:

[0091] Step S601: Execute the program task corresponding to the first security program, obtain the first sub-data and the second sub-data corresponding to the information data to be protected, and a random number. Perform a cyclic field operation on the first sub-data and the random number to obtain first updated data, and replace the stored first sub-data with the first updated data. Among them, the information data to be protected is generated based on the first sub-data and the second sub-data.

[0092] Among them, the program task is a task that needs to be completed when the first security program is executed, such as risk identification and control, detecting malicious code, etc. The operation method of the first updated data is embedded in the first security program, and the operation of the first updated data is executed after the program task is completed.

[0093] Step S602: Execute the program task corresponding to the second security program, and perform the inverse operation on the number obtained by performing the cyclic field operation on the random number to obtain an inverse operation value.

[0094] Among them, the security program can be the program executed corresponding to each security program block, which is used to protect computer systems, networks, data, and applications from security threats such as malicious attacks, illegal access, and data leakage. The operation methods of the inverse operation value, the second updated data, and the data to be protected are embedded in the second security program, and the operations of the inverse operation value, the second updated data, and the data to be protected are executed after the program task corresponding to the second security program is completed. In one embodiment, after the first updated data is calculated, the program task corresponding to the second security program is executed. After the program task corresponding to the second security program is executed, the inverse operation of the random number and subsequent operations are performed.

[0095] Step S603: Perform a cyclic field operation on the second sub-data and the inverse operation value to obtain the second updated data, and replace the stored second sub-data with the second updated data. Among them, the result of the cyclic field operation on the first sub-data and the second sub-data is the same as the result of the cyclic field operation on the first updated data and the second updated data.

[0096] Step S604: After generating the data to be protected by performing a cyclic field operation on the first updated data and the second updated data, compare the data to be protected with the preset comparison data, and verify whether the first security program and the second security program are correctly executed based on the comparison result.

[0097] Among them, the preset comparison data can be the result of the cyclic field operation on the first sub-data and the second sub-data, that is, the data to be protected. In one embodiment, a verification method can be that when the generated data to be protected is the same as the preset comparison data, it is determined that each security program is correctly executed; when the generated information data is different from the preset comparison data, it is determined that each security program is not correctly executed. Exemplarily, the preset comparison data is the same as the data to be protected, and the second security program is executed after the first security program. After the first security program (embedded with the operation method of the first updated data) is executed, a program jump occurs and the second security program is not executed. Then the output data is the first updated data calculated by the first security program. Compare the calculated first updated data with the preset comparison data, and the comparison result is different, so it is determined that each security program is not correctly executed.

[0098] In another embodiment, in the case where there are more than two security programs, the first sub-data and / or the second sub-data are split according to the number of security programs and the cyclic field operation method, and the operations of the split data, the first sub-data, and the second sub-data are respectively embedded into the corresponding security programs for the verification of the security programs. Exemplarily, the information data to be protected is generated based on the first sub-data and the second sub-data. Currently, there are 4 security programs, so 4 copies of data are required. The 4 security programs are arranged in the execution order as Security Program 1, Security Program 2, Security Program 3, and Security Program 4. The first sub-data is split into the first split data and the second split data according to the cyclic field operation method, and the second sub-data is split into the third split data and the fourth split data according to the cyclic field algorithm. The operation method of the updated data of the first split data is embedded into Security Program 1, the inverse operation value, the operation method of the updated data of the second split data, and the operation method of the first sub-data are embedded into Security Program 2, the operation method of the updated data of the third split data is embedded into Security Program 3, and the inverse operation value, the operation method of the updated data of the fourth split data, the second sub-data, and the operation method of the information data to be protected are embedded into Security Program 4. After the security programs are executed, the output data is compared with the preset comparison data, and based on the comparison result, it is verified whether each security program is correctly executed.

[0099] In one embodiment, the operation method of the first updated data is embedded into the first security program, and the inverse operation value and the operation method of the second updated data are embedded into the second security program. The first security program and the second security program are run simultaneously. After the run is completed, the cyclic field operation is performed on the output data to generate the data to be compared, and the data to be compared is compared with the preset comparison data. Based on the comparison result, it is verified whether the first security program and the second security program are completely executed. By embedding the operation methods of the first updated data and the second updated data into the security programs, as long as all the security programs are executed, the finally calculated result is the same as the expected result, which can prevent the security programs from being jumped out of or tampered with during the execution process. If the comparison result is different, it means that the security programs are not completely executed, and the attacker may have used a certain part as a springboard to attack other data.

[0100] In another embodiment, in the case where there are more than two security programs, the first sub-data and / or the second sub-data are split according to the number of security programs and the cyclic field operation method, and the operations of the updated data of each of the split data are respectively embedded into different security programs for verifying the integrity of the execution of the security programs. By splitting the first sub-data and / or the second sub-data in the same way, the integrity verification of more than two security programs that must be executed can be achieved.

[0101] As described above, by executing the program tasks corresponding to the first security program, the first sub-data, the second sub-data, and a random number corresponding to the information data to be protected are obtained. The first sub-data and the random number are subjected to a cyclic field operation to obtain first updated data, and the stored first sub-data is replaced with the first updated data. The information data to be protected is generated based on the first sub-data and the second sub-data. Then, the program tasks corresponding to the second security program are executed. The inverse operation value of the number obtained by performing the inverse operation of the cyclic field operation on the random number is obtained, and the second sub-data and the inverse operation value are subjected to a cyclic field operation to obtain second updated data. The stored second sub-data is replaced with the second updated data. After the information data is generated by performing a cyclic field operation on the first updated data and the second updated data, the information data to be protected is compared with preset comparison data, and whether each security program is correctly executed is verified based on the comparison result. In this solution, each sequentially executed security program is inserted, and whether each security program is correctly executed is verified through the comparison result between the generated information data and the preset comparison data, which can prevent each security program from being skipped during execution.

[0102] Figure 7 This is a module structure block diagram of an information data protection device provided by an embodiment of the present application. The device is used to execute an information data protection method provided by the above embodiment and has corresponding functional modules and beneficial effects for executing the method. As Figure 7 shown, the device specifically includes:

[0103] A data operation module 101, configured to obtain a first sub-data, a second sub-data, and a random number corresponding to the information data to be protected, and perform a cyclic field operation on the first sub-data and the random number to obtain first updated data. The information data to be protected is generated based on the first sub-data and the second sub-data;

[0104] A data replacement module 102, configured to replace the stored first sub-data with the first updated data;

[0105] The data operation module 101 is further configured to perform an inverse operation on the number obtained by performing the cyclic field operation on the random number to obtain an inverse operation value, and perform a cyclic field operation on the second sub-data and the inverse operation value to obtain second updated data;

[0106] The data replacement module 102 is further configured to replace the stored second sub-data with the second updated data, where the result of performing the cyclic field operation on the first sub-data and the second sub-data is the same as the result of performing the cyclic field operation on the first updated data and the second updated data.

[0107] As can be seen from the above solution, by obtaining the first sub-data and the second sub-data corresponding to the data of the information to be protected, as well as a random number, performing a cyclic field operation on the first sub-data and the random number to obtain the first updated data, and replacing the stored first sub-data with the first updated data, wherein the data of the information to be protected is generated based on the first sub-data and the second sub-data, performing an inverse operation on the number for the cyclic field operation on the random number to obtain an inverse operation value, performing a cyclic field operation on the second sub-data and the inverse operation value to obtain the second updated data, and replacing the stored second sub-data with the second updated data, wherein the result of performing the cyclic field operation on the first sub-data and the second sub-data is the same as the result of performing the cyclic field operation on the first updated data and the second updated data. In this solution, the split information sub-data is dynamically changed through the cyclic field operation, solving the problem in the related art that the data of the information to be protected is fixedly stored in the memory, cannot effectively resist multiple attacks by attackers, and the security of the data of the information is relatively low, making the sub-data for generating the data of the information dynamically changed, achieving the purpose that it is difficult for attackers to monitor and analyze the information.

[0108] In a possible embodiment, the data operation module 101 is specifically configured to:

[0109] When the data of the information to be protected is called, performing the cyclic field operation on the first updated data and the second updated data to generate the data of the information to be protected.

[0110] In a possible embodiment, it further includes a flag generation module, which is specifically configured to:

[0111] Generate an iteration flag, where the iteration flag is generated based on a fixed program triggered when the chip is powered on, or based on an iteration instruction detected and transmitted externally.

[0112] In a possible embodiment, the cyclic field operation includes any one of exclusive OR operation, modular addition operation, modular multiplication operation, and mapping operation. The inverse operation of the number for the exclusive OR operation is the number itself. The inverse operation of the number for the modular addition operation is the additive inverse of the number for the modular addition operation with respect to the modulus. The inverse operation of the number for the modular multiplication operation is the multiplicative inverse of the number for the modular multiplication operation with respect to the modulus. The inverse operation of the number for the mapping operation is the inverse mapping.

[0113] In a possible embodiment, the data operation module 101 is further configured to:

[0114] Calculate a first product result of the random number and the first sub-data, and perform a remainder operation with a preset modulus on the first product result to obtain the first updated data;

[0115] Correspondingly, the data operation module 101 is further configured to:

[0116] Calculate a second product result of the inverse operation value and the second sub-data, and perform a modulo operation on the second product result with the preset modulus to obtain second updated data.

[0117] In a possible embodiment, the information data to be protected includes key information data, the first sub-data includes a custom algorithm input, and the second sub-data includes a custom algorithm key.

[0118] In a possible embodiment, it further includes a security program execution module, specifically used for:

[0119] Execute the program tasks corresponding to the first security program;

[0120] The security program execution module is further used for:

[0121] Execute the program tasks corresponding to the second security program;

[0122] It further includes a security verification module, specifically used for:

[0123] Compare the information data to be protected with preset comparison data, and verify whether the first security program and the second security program are correctly executed based on the comparison result.

[0124] Figure 8 The structure diagram of an information data protection device provided by an embodiment of the present application is as Figure 8 shown. The device includes a processor 201, a memory 202, an input device 203, and an output device 204; the number of processors 201 in the device can be one or more, Figure 8 taking one processor 201 as an example; the processor 201, memory 202, input device 203, and output device 204 in the device can be connected through a bus or other means, Figure 8 taking the connection through a bus as an example. The memory 202, as a computer-readable storage medium, can be used to store software programs, computer-executable programs, and modules, such as program instructions or modules corresponding to an information data protection method in an embodiment of the present application. The processor 201 executes various functional applications and data processing of the device by running the software programs, instructions, and modules stored in the memory 202, that is, implements the above-mentioned information data protection method. The input device 203 can be used to receive input digital or character information, and generate key signal inputs related to user settings and function controls of the device. The output device 204 may include a display device such as a display screen.

[0125] An embodiment of the present application further provides a storage medium containing computer-executable instructions. The computer-executable instructions are used to execute an information data protection method when executed by a computer processor. The method includes:

[0126] Obtain a first sub - data, a second sub - data corresponding to the information data to be protected, and a random number. Perform a cyclic field operation on the first sub - data and the random number to obtain a first updated data, and replace the stored first sub - data with the first updated data. The information data to be protected is generated based on the first sub - data and the second sub - data;

[0127] Perform an inverse operation on the number obtained by performing the cyclic field operation on the random number to obtain an inverse operation value;

[0128] Perform the cyclic field operation on the second sub - data and the inverse operation value to obtain a second updated data, and replace the stored second sub - data with the second updated data. Among them, the result of performing the cyclic field operation on the first sub - data and the second sub - data is the same as the result of performing the cyclic field operation on the first updated data and the second updated data.

[0129] It should be noted that in the embodiments of the above - mentioned information data protection method system, the various units and modules included are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be realized; in addition, the specific names of the functional units are only for the convenience of mutual distinction and do not limit the protection scope of the embodiments of the present application.

[0130] Note that the above is only the preferred embodiment of the embodiments of the present application and the applied technical principles. Those skilled in the art will understand that the embodiments of the present application are not limited to the specific embodiments described here, and various obvious changes, re - adjustments and substitutions can be made by those skilled in the art without departing from the protection scope of the embodiments of the present application. Therefore, although the embodiments of the present application have been described in more detail through the above embodiments, the embodiments of the present application are not limited to the above embodiments. Without departing from the concept of the embodiments of the present application, more other equivalent embodiments can be included, and the scope of the embodiments of the present application is determined by the scope of the appended claims.

Claims

1. An information data protection method, characterized in that, Including: Obtain a first sub-data, a second sub-data, and a random number corresponding to the data of the information to be protected, perform a cyclic field operation on the first sub-data and the random number to obtain a first updated data, and replace the stored first sub-data with the first updated data, where the data of the information to be protected is generated based on the first sub-data and the second sub-data; Perform an inverse operation of the number for the cyclic field operation on the random number to obtain an inverse operation value; Perform the cyclic field operation on the second sub-data and the inverse operation value to obtain a second updated data, and replace the stored second sub-data with the second updated data, where the result of performing the cyclic field operation on the first sub-data and the second sub-data is the same as the result of performing the cyclic field operation on the first updated data and the second updated data.

2. The information data protection method according to claim 1, wherein, After replacing the stored second sub-data with the second updated data, it further includes: When the data of the information to be protected is called, perform the cyclic field operation on the first updated data and the second updated data to generate the data of the information to be protected.

3. The information data protection method according to claim 1, characterized in that, Before obtaining the first sub-data, the second sub-data, and the random number corresponding to the data of the information to be protected, it further includes: Generate an iteration flag, where the iteration flag is generated based on a fixed program triggered when the chip is powered on, or based on an iteration instruction transmitted externally detected.

4. The information data protection method according to any one of claims 1-3, characterized in that, The cyclic field operation includes any one of exclusive OR operation, modular addition operation, modular multiplication operation, and mapping operation. The inverse operation of the number for the exclusive OR operation is the number itself. The inverse operation of the number for the modular addition operation is the additive inverse of the number for the modular addition operation with respect to the modulus. The inverse operation of the number for the modular multiplication operation is the multiplicative inverse of the number for the modular multiplication operation with respect to the modulus. The inverse operation of the number for the mapping operation is the inverse mapping.

5. The information data protection method according to claim 4, characterized in that, When the cyclic field operation is a modular multiplication operation, the performing the cyclic field operation on the first sub-data and the random number to obtain a first updated data includes: Calculate a first product result of the random number and the first sub-data, and perform a remainder operation with a preset modulus on the first product result to obtain a first updated data; Correspondingly, the performing the cyclic field operation on the second sub-data and the inverse operation value to obtain a second updated data includes: Calculate a second product result of the inverse operation value and the second sub-data, and perform the remainder operation with the preset modulus on the second product result to obtain a second updated data.

6. The information data protection method according to any one of claims 1-3, characterized in that, The data of the information to be protected includes key information data, the first sub-data includes a custom algorithm input, and the second sub-data includes a custom algorithm key.

7. The information data protection method according to claim 2, wherein Before obtaining the first sub-data, the second sub-data, and the random number corresponding to the data of the information to be protected, it further includes: Execute the program tasks corresponding to the first security program; Correspondingly, before performing the inverse operation of the number for the cyclic field operation on the random number to obtain an inverse operation value, it further includes: Execute the program tasks corresponding to the second security program; Correspondingly, after performing the cyclic field operation on the first updated data and the second updated data to generate the data of the information to be protected, it further includes: Compare the to-be-protected information data with preset comparison data, and verify whether the first security program and the second security program are correctly executed based on the comparison result.

8. An information data protection device, characterized in that, Comprising: A data operation module, configured to obtain a first sub-data, a second sub-data, and a random number corresponding to the to-be-protected information data, perform a cyclic field operation on the first sub-data and the random number to obtain a first updated data, and the to-be-protected information data is generated based on the first sub-data and the second sub-data; A data replacement module, configured to replace the stored first sub-data with the first updated data; The data operation module is further configured to perform an inverse operation of the number for the cyclic field operation on the random number to obtain an inverse operation value, and perform the cyclic field operation on the second sub-data and the inverse operation value to obtain a second updated data; The data replacement module is further configured to replace the stored second sub-data with the second updated data, wherein the result of performing the cyclic field operation on the first sub-data and the second sub-data is the same as the result of performing the cyclic field operation on the first updated data and the second updated data.

9. An information data protection device, the device comprising: One or more processors; A storage device, configured to store one or more programs, and when the one or more programs are executed by the one or more processors, enable the one or more processors to implement the information data protection method according to any one of claims 1-7.

10. A storage medium storing computer-executable instructions, where the computer-executable instructions are used to execute the information data protection method according to any one of claims 1-7 when executed by a computer processor.