File encryption and decryption method and system based on hardware cryptographic equipment
Through the multi-level key nested encryption and one-to-one communication methods of hardware cryptographic devices, the problem of keys being easily attacked in soft algorithm encryption tools is solved, and higher file transmission and storage security is achieved, and data security and integrity are enhanced.
Patent Information
- Application Number
- CN202510493347.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-18
- Publication Date
- 2025-07-11
AI Technical Summary
Existing file encryption tools based on soft algorithms have the risk that keys are susceptible to attack and stealing, resulting in sensitive data leakage and insufficient security for network transmission and cloud storage.
The multi-level key nested encryption method based on hardware cryptographic devices is adopted, combined with a one-by-one communication method, the file is encrypted and decrypted through the hardware cryptographic device and the super encryption server, and the key file is embedded in the header of the file, and the national secret algorithms SM2, SM3, SM4, and SM6 are used for encryption and signature.
Improves the security of file transfer and storage, reduces the risk of key cracking, enhances communication security, and ensures data integrity and authenticity.
Smart Images

Figure CN120301656A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of file encryption and decryption, and particularly to a file encryption and decryption method and system based on a hardware cryptographic device. Background Art
[0002] Internet-based office work has become the mainstream of people's work, and more and more electronic files need to be transmitted over the network or stored in the cloud. As people's attention to data security gradually increases, encryption technology has been widely used in file encryption protection, and many file encryption tools have emerged. However, most of them are based on soft algorithms. For encryption tool software based on soft algorithms, the encryption key inevitably appears in the host memory, making the key vulnerable to attack and theft, and the ciphertext is easily cracked, resulting in the leakage of sensitive data. Therefore, it is necessary to provide a file encryption and decryption method and system based on a hardware cryptographic device to ensure the security of network-transmitted files and cloud storage. Summary of the Invention
[0003] This application provides a file encryption and decryption method and system based on a hardware cryptographic device to solve at least the above technical problems existing in the prior art.
[0004] According to the first aspect of this application, a file encryption and decryption method based on a hardware cryptographic device is provided, including file encryption and file decryption; The process of the file encryption is as follows: Initialize the user shield to generate a user shield certificate and an encryption rule; Randomly generate a symmetric key to encrypt the file; Encrypt the symmetric key with the user shield public key to generate a first key file; Encrypt the first key file with the super encryption server public key to generate a second key file; The process of the file decryption is as follows: Sign the second key file with the user shield private key to generate a third key file; Verify the validity of the user shield through the super encryption server. If the user shield is verified to be valid, decrypt the second key file with the super encryption server private key to generate a first key file; Decrypt the first key file with the user shield private key to generate a symmetric key, and decrypt the ciphertext body of the file with the symmetric key to generate a plaintext body.
[0005] In certain embodiments of the first aspect of the present application, the communication of the file adopts the one-time pad method. During each session of the session initiator, a symmetric key is randomly generated, and the randomly generated symmetric key is encrypted by the public key of the recipient's user shield to generate the first key file. The session recipient decrypts the first key file with the private key of the user shield to restore the symmetric key.
[0006] In certain embodiments of the first aspect of the present application, in the process of file encryption, the generated key file is placed at the head of the ciphertext body as a part of the ciphertext body.
[0007] In certain embodiments of the first aspect of the present application, in the process of file encryption, at least one of the national cryptography algorithms SM2, SM3, SM4, and SM6 is adopted.
[0008] In certain embodiments of the first aspect of the present application, a file digital signature process is further included; the file digital signature process includes digital signature and digital verification; The process of the digital signature is as follows: A digital signature is performed on the original file to generate a first signature file, and the first signature file is encrypted by the private key of the user shield to generate an encrypted signature file. The encrypted signature file and the original file are transmitted to the verification party together; The process of the digital verification is as follows: The verification party decrypts the encrypted signature file with the public key of the CA server digital certificate to restore the first signature file, performs a digital signature on the original file to generate a second signature file, and compares the first signature file and the second signature file to complete the authenticity verification of the file digital signature.
[0009] In certain embodiments of the first aspect of the present application, the HSAH module is adopted for performing a digital signature on the original file.
[0010] According to the second aspect of the present application, a file encryption and decryption system based on a hardware cryptographic device is provided, including a user shield, a CA server, and a super encryption server; The CA server initializes the user shield, generates a user shield certificate and an encryption rule; a hardware cryptographic module is set in the user shield, a symmetric key is randomly generated, and the file is encrypted; the public key of the user shield encrypts the symmetric key to generate a first key file; the public key of the super encryption server encrypts the first key file to generate a second key file to complete file encryption; Sign the second key file with the user shield private key to generate a third key file; verify the validity of the user shield through the super encryption server. If the user shield is verified to be valid, decrypt the second key file with the super encryption server private key to generate the first key file; decrypt the first key file with the user shield private key to generate a symmetric password, and decrypt the ciphertext body of the file with the symmetric key to generate the plaintext body to complete file decryption. In some embodiments of the first aspect of the present application, the communication of the file adopts the one-time-one-key method. During each session of the session initiator, a symmetric key is randomly generated, and the randomly generated symmetric key is encrypted with the public key of the recipient's user shield to generate the first key file. The session recipient decrypts the first key file with the user shield private key to restore the symmetric key.
[0011] In some embodiments of the first aspect of the present application, in the process of file encryption, the generated key file is placed at the head of the ciphertext body as a part of the ciphertext body.
[0012] In some embodiments of the first aspect of the present application, it further includes a file digital signature module; the file digital signature module performs digital signature and digital signature verification. The process of the digital signature is as follows: Perform a digital signature on the original file to generate a first signature file, encrypt the first signature file with the user shield private key to generate an encrypted signature file, and transmit the encrypted signature file and the original file to the signature verification party together. The process of the digital signature verification is as follows: The signature verification party decrypts the encrypted signature file with the public key of the CA server digital certificate to restore the first signature file, performs a digital signature on the original file to generate a second signature file, and compares the first signature file and the second signature file to complete the authenticity verification of the file digital signature.
[0013] Compared with the prior art, the present application has the following beneficial effects: 1. The present application uses the user shield and the super encryption server to perform multi-level key nested encryption on the file. Compared with the traditional soft algorithm encryption, it is more difficult to be cracked and cause the risk of file and data leakage, thereby reducing the risk of the public network transmission key being cracked. 2. The present application adopts the one-time-one-key method. Each time a new session is initiated, a symmetric key is randomly generated to re-establish a secure session communication channel for ciphertext communication, improving the communication security and further reducing the risk of the password being deciphered.
[0014] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present application, nor is it used to limit the scope of the present application. Other features of the present application will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] By referring to the following detailed description with reference to the accompanying drawings, the above and other objects, features, and advantages of the exemplary embodiments of the present application will become readily understood. In the drawings, several embodiments of the present application are shown in an exemplary rather than restrictive manner, wherein: In the drawings, the same or corresponding reference numerals denote the same or corresponding parts.
[0016] Figure 1 A schematic diagram of the file encryption implementation process of the first embodiment of the present application is shown.
[0017] Figure 2 A schematic diagram of the file decryption implementation process of the first embodiment of the present application is shown.
[0018] Figure 3 A schematic diagram of the ciphertext communication implementation process of the first embodiment of the present application is shown.
[0019] Figure 4 A schematic diagram of the file digital signature implementation process of the first embodiment of the present application is shown.
[0020] Figure 5 A system framework diagram of the second embodiment of the present application is shown. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0021] In order to make the objectives, features, and advantages of the present application more obvious and understandable, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without creative efforts fall within the scope of protection of the present application.
[0022] Embodiment 1: The first embodiment provides a file encryption and decryption method based on a hardware password device, mainly including two processes: file encryption and file decryption.
[0023] Please refer to Figure 1 , the process of the file encryption is as follows: Initialize the user shield through the CA server to generate the user shield certificate and encryption rules; the user shield hardware password module randomly generates a symmetric key K to encrypt the file to obtain the ciphertext body; encrypt the symmetric key K with the user shield public key UPK to generate the first key file UPK(K); encrypt the first key file UPK(K) with the super encryption server public key SPK to generate the second key file SPK(UPK(K)); To enhance the security of the secret key, multi-level key nested encryption is adopted here, and the generated key file is placed at the head of the ciphertext body as part of the ciphertext body.
[0024] Please refer to Figure 2 , and the process of decrypting the file is as follows: Use the user shield private key USK to sign the second key file SPK(UPK(K)) to generate the third key file USK(SPK(UPK(K))); verify the validity of the user shield through the super encryption server. If the user shield is verified to be valid, decrypt the second key file SPK(UPK(K)) through the super encryption server private key to generate the first key file UPK(K); then, decrypt the first key file UPK(K) through the user shield private key to generate the symmetric cipher K, and decrypt the ciphertext body of the file through the symmetric key K to generate the plaintext body.
[0025] The characteristic of ciphertext communication is real-time. Both communication parties must be online in real time. Considering that multi-level nested encryption strengthens the security of the password, but it will reduce the performance in real-time communication. Considering the above characteristics, the communication of the file adopts the method of one cipher per conversation. Please refer to Figure 3 , during each session of the session initiator, a random symmetric key K is generated, and the randomly generated symmetric key K is encrypted through the public key of the recipient's user shield to generate the first key file UPK(K). The session recipient decrypts the first key file UPK(K) through the user shield private key to restore the symmetric key K.
[0026] Through the above method of one cipher per conversation, a secure session communication channel is established for ciphertext communication. Each time a new session is initiated, a random symmetric key is generated to re-establish the secure session communication channel for ciphertext communication, improving the communication security and further reducing the risk of the password being cracked.
[0027] In the above file encryption process, at least one of the national cryptography algorithms SM2, SM3, SM4, and SM6 is adopted.
[0028] In some embodiments of the first aspect of the present application, it further includes a file digital signature process; the file digital signature process includes two parts: digital signature and digital signature verification; Please refer to Figure 4 , and the process of the digital signature is as follows: Use the user shield HASH module to digitally sign the file original text to generate the first signature file HASH1, and encrypt the first signature file HASH1 through the user shield private key USK to generate the encrypted signature file USK(HASH1). The encrypted signature file USK(HASH1) and the file original text are transmitted to the signature verification party together; Please refer toFigure 4 , the process of digital signature verification is as follows: The signature verification party decrypts and restores the first signature file HASH1 from the encrypted signature file USK (HASH1) using the public key of the CA server digital certificate, digitally signs the original file to generate the second signature file HASH2, and compares the first signature file HASH1 and the second signature file HASH2 to complete the authenticity verification of the file digital signature. If the two are consistent, the digital signature is true.
[0029] Embodiment 2: Embodiment 2 provides a file encryption and decryption system based on a hardware cryptographic device. Please refer to Figure 5 , including a user shield, a CA server, and a super encryption server; User shield: A hardware device used for file or data encryption and decryption on the user side. Its form can be a USB shield, a Bluetooth shield, a WIFI shield, etc. Its independent hardware cryptographic module incorporates national cryptographic algorithms (SM2, SM3, SM4, SM6) to support commercial cryptographic applications.
[0030] CA server: Its functions include initializing the user shield, certificate issuance, certificate management, certificate sharing, management of user shield encryption rules, and management of user shield PIN. Its independent hardware cryptographic module incorporates national cryptographic algorithms (SM2, SM3, SM4, SM6) to support commercial cryptographic applications.
[0031] Super encryption server: Its functions are as follows: 1. Decryption control for decrypting the outer layer key of the user shield's usage right (user shield suspension); 2. Time domain management, which can authorize the user shield according to a time list. 2. Can batch encrypt the files authorized by the user shield. 3. Global log collection, which can monitor and trace the usage behavior of the user shield. Its independent hardware cryptographic module incorporates national cryptographic algorithms (SM2, SM3, SM4, SM6) to support commercial cryptographic applications.
[0032] In addition, it also includes a device management shield: Its function is the management key for the CA server and the super encryption server, supporting hierarchical authorization. There are 2 groups of root management shields, and the number of each group is greater than 2. Its independent hardware cryptographic module incorporates national cryptographic algorithms (SM2, SM3, SM4, SM6) to support commercial cryptographic applications.
[0033] The file encryption and decryption system executes the following process: The CA server initializes the user shield, generates the user shield certificate and encryption rules; a hardware cryptographic module is set in the user shield, which randomly generates a symmetric key to encrypt the file; the public key of the user shield encrypts the symmetric key to generate the first key file; the public key of the super encryption server encrypts the first key file to generate the second key file to complete file encryption; Sign the second key file with the user shield private key to generate a third key file; verify the validity of the user shield through the super encryption server. If the user shield is verified to be valid, decrypt the second key file with the super encryption server private key to generate a first key file; decrypt the first key file with the user shield private key to generate a symmetric password, and decrypt the ciphertext body of the file with the symmetric key to generate a plaintext body to complete file decryption; The communication of the file adopts the method of one-time pad encryption. In each session process of the session initiator, a symmetric key is randomly generated, and the randomly generated symmetric key is encrypted with the public key of the recipient's user shield to generate the first key file. The session recipient decrypts the first key file with the user shield private key to restore the symmetric key.
[0034] In the process of file encryption, the generated key file is placed at the head of the ciphertext body as a part of the ciphertext body.
[0035] In some embodiments of the first aspect of the present application, it further includes a file digital signature module; the file digital signature module performs digital signature and digital signature verification; The process of the digital signature is as follows: Perform a digital signature on the original file to generate a first signature file, encrypt the first signature file with the user shield private key to generate an encrypted signature file, and transfer the encrypted signature file and the original file to the signature verification party together; The process of the digital signature verification is as follows: The signature verification party decrypts the encrypted signature file with the public key of the CA server digital certificate to restore the first signature file, performs a digital signature on the original file to generate a second signature file, and compares the first signature file and the second signature file to complete the authenticity verification of the file digital signature.
[0036] For the specific execution process and effects of the file encryption and decryption system, please refer to the file encryption and decryption method in Embodiment 1, which will not be elaborated here.
[0037] It should be understood that various forms of processes shown above can be used, re-ordered, steps added or deleted. For example, the steps described in the present application can be executed in parallel, sequentially, or in a different order, as long as the results expected by the technical solution of the present application can be achieved. No limitations are imposed herein.
[0038] In addition, the terms "first" and "second" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include at least one of such features. In the description of the present application, "a plurality" means two or more unless otherwise specifically defined.
[0039] As described above, it is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claimed rights.
Claims
1. A file encryption and decryption method based on a hardware cryptographic device, characterized in that, Including file encryption and file decryption; The process of the file encryption is as follows: Initialize the user shield to generate a user shield certificate and an encryption rule; Randomly generate a symmetric key pair to encrypt the file; Encrypt the symmetric key with the user shield public key to generate a first key file; Encrypt the first key file with the super encryption server public key to generate a second key file; The process of the file decryption is as follows: Sign the second key file with the user shield private key to generate a third key file; Verify the validity of the user shield through the super encryption server. If the user shield is verified to be valid, decrypt the second key file with the super encryption server private key to generate a first key file; Decrypt the first key file with the user shield private key to generate a symmetric password, and decrypt the ciphertext body of the file with the symmetric key to generate a plaintext body.
2. The file encryption and decryption method based on a hardware password device according to claim 1, characterized in that, The communication of the file adopts the one-time-one-key method. In each session process of the session initiator, a symmetric key is randomly generated, and the randomly generated symmetric key is encrypted with the recipient user shield public key to generate the first key file. The session recipient decrypts the first key file with the user shield private key to restore the symmetric key.
3. A file encryption and decryption method based on a hardware password device according to claim 1, characterized in that, In the process of file encryption, the generated key file is placed at the head of the ciphertext body as a part of the ciphertext body.
4. A file encryption and decryption method based on a hardware password device according to claim 1 or 3, characterized in that, In the process of file encryption, at least one of the national cryptography algorithms SM2, SM3, SM4, and SM6 is adopted.
5. A file encryption and decryption method based on a hardware password device according to claim 1, characterized in that, It also includes a file digital signature process; the file digital signature process includes digital signature and digital signature verification; The process of the digital signature is as follows: Perform a digital signature on the file original text to generate a first signature file, encrypt the first signature file with the user shield private key to generate an encrypted signature file, and transmit the encrypted signature file and the file original text to the signature verification party together; The process of the digital signature verification is as follows: The signature verification party decrypts the encrypted signature file with the CA server digital certificate public key to restore the first signature file, performs a digital signature on the file original text to generate a second signature file, and compares the first signature file and the second signature file to complete the authenticity verification of the file digital signature.
6. A file encryption and decryption method based on a hardware password device according to claim 5, characterized in that, The HSAH module is adopted to perform a digital signature on the file original text.
7. A file encryption and decryption system based on a hardware cryptographic device, characterized in that, Including a user shield, a CA server, and a super encryption server; The CA server initializes the user shield to generate a user shield certificate and an encryption rule; a hardware password module is set in the user shield to randomly generate a symmetric key to encrypt the file; the user shield public key encrypts the symmetric key to generate a first key file; The super encryption server public key encrypts the first key file to generate a second key file to complete the file encryption; Sign the second key file with the user shield private key to generate a third key file; Verify the validity of the user shield through the super encryption server. If the user shield is verified to be valid, decrypt the second key file with the super encryption server private key to generate a first key file; decrypt the first key file with the user shield private key to generate a symmetric password, and decrypt the ciphertext body of the file with the symmetric key to generate a plaintext body to complete the file decryption.
8. A file encryption and decryption system based on a hardware cryptographic device according to claim 7, wherein, The communication of the said file adopts the one-time pad method. In each session of the session initiator, a symmetric key is randomly generated, and the randomly generated symmetric key is encrypted by the public key of the recipient's user shield to generate the said first key file. The session recipient decrypts the first key file with the private key of the user shield to restore the symmetric key.
9. A file encryption and decryption system based on a hardware password device according to claim 7, characterized in that, In the process of file encryption, the generated key file is placed at the head of the ciphertext body as a part of the ciphertext body.
10. A file encryption and decryption system based on a hardware cryptographic device according to claim 7, characterized in that, It also includes a file digital signature module; the file digital signature module performs digital signature and digital signature verification. The process of the said digital signature is as follows: Perform a digital signature on the original file to generate a first signature file, encrypt the first signature file with the private key of the user shield to generate an encrypted signature file, and the encrypted signature file and the original file are transmitted to the signature verification party together. The process of the said digital signature verification is as follows: The signature verification party decrypts the encrypted signature file with the public key of the CA server digital certificate to restore the first signature file, performs a digital signature on the original file to generate a second signature file, and compares the first signature file and the second signature file to complete the authenticity verification of the file digital signature.