Dynamic key generation method and device, dynamic key application method and device, electronic equipment and computer program product
By generating and applying dynamic keys, using periodic updates of base addresses, offsets and fixed values, combined with key conversion rules, the problem of existing encryption algorithms being easily reproduced and decrypted is solved, and higher data transmission security is achieved.
Patent Information
- Application Number
- CN202510751389.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-06
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2045-06-06
AI Technical Summary
Existing encryption algorithms are easily reproduced and decrypted, and lack effective protection measures.
By generating a dynamic key, the base address, offset and fixed value updated by the preset update cycle is used, combined with the preset key conversion rules, a dynamic termination key is generated and converted into a first dynamic key for encryption or decryption of data transmission.
It improves the difficulty of the encryption and decryption algorithm being reproduced and decrypted, enhances the security of data transmission, and prevents the key from being reversely analyzed.
Smart Images

Figure CN120342613A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computers, and in particular, to a method, device, electronic device, and computer program product for generating and applying dynamic keys. Background Art
[0002] Current data stream encryption methods often use conventional encryption methods, such as DES and its derivatives, RSA, or AES, and another type of hash-related encryption, such as md5, sha1, sha128, sha256, etc.
[0003] However, even self-written encryption algorithms are easily reproduced and decrypted. Moreover, if it is a hash algorithm, both the client and the server process encrypted text communication matching, and the response data body will not be hashed because it is irreversible. For commonly used DES and 3DES encrypted data bodies, RSA is used to encrypt the data encrypted by DEC. Although the transmission speed is relatively fast, it is also easily reproduced.
[0004] In view of the problem that the encryption algorithms of the above-mentioned prior art are easily reproduced and decrypted, no effective solution has been proposed yet. Summary of the Invention
[0005] Embodiments of the present invention provide a method, device, electronic device, and computer program product for generating and applying dynamic keys, so as to at least solve the technical problem that the encryption algorithms of the prior art are easily reproduced and decrypted.
[0006] According to one aspect of the embodiments of the present invention, a method for generating a dynamic key is provided, including: obtaining an updated base address, offset, and fixed value according to a preset update period, where the base address and the fixed value are preset variables set in advance, and the offset is an update variable updated according to the preset update period; generating a dynamic termination key based on the base address, the offset, and the fixed value; and converting the dynamic termination key into a first dynamic key according to a preset key conversion rule, where the first dynamic key is used to encrypt or decrypt data transmitted between a client and a server.
[0007] Optionally, generating a dynamic termination key based on the base address, the offset, and the fixed value includes: determining the sum of the base address and the offset as an intermediate key; and determining the product of the intermediate key and the fixed value as the dynamic termination key.
[0008] Optionally, the method further includes: obtaining a target font set number code randomly determined by a client, where the target font set number code is used to indicate the code of a corresponding target font file in a preset font file library, and the preset font file library stores a preset number of preset font files in advance, and a preset font set number code corresponding to each preset font file; converting the target font set number code into a font file set number key that conforms to a preset length according to a preset code conversion rule; splicing the font file set number key with the first dynamic key to obtain a second dynamic key.
[0009] Optionally, after obtaining the target font set number code randomly determined by the client, the method further includes: obtaining the target font file corresponding to the target font set number code from among the multiple preset font files recorded in the preset font file library; extracting the conversion rule indicated in the target font file as the preset key conversion rule.
[0010] According to another aspect of the embodiments of the present invention, there is also provided a method for applying a dynamic key, including: using the above-mentioned dynamic key generation method to obtain the first dynamic key; generating a data query request through a client; encrypting the data query request using the forward order of the first dynamic key as the first key in a target key rule to obtain an encrypted query request.
[0011] Optionally, the method further includes: receiving, through the client, an encrypted query result returned by a server, where the server is used to respond to the encrypted query request sent by the client to generate the encrypted query result; decrypting the encrypted query result using the reverse order of the first dynamic key as the second key in the target key rule to obtain the data query result corresponding to the data query request.
[0012] Optionally, the method further includes: obtaining a font file set number key randomly determined by the client, where the font file set number key is obtained by converting a target font set number code using a preset code conversion rule, the target font set number code is the preset font set number code corresponding to a target font file randomly selected by the client from a preset font file library, and the preset font file library stores a preset number of preset font files in advance, and the preset font set number code corresponding to each preset font file; splicing the font file set number key with the encrypted query request to obtain a spliced query request.
[0013] Optionally, the method further includes: receiving, by the client, a spliced query result returned by the server, where the spliced query result includes: a spliced font file set number feedback key and an encrypted query result, and the server is configured to respond to the encrypted query request in the spliced query request, generate the encrypted query result, and use the font file set number key in the server response to the spliced query request as the font file set number feedback key spliced with the encrypted query result; performing a consistency comparison between a first set number key and a second set number key, where the first set number key is the font file set number key in the spliced query request sent by the client, and the second set number key is the font file set number feedback key in the spliced query result received by the client; and when the first set number key is consistent with the second set number key, using the reverse order of the first dynamic key as the second key in the target key rule to decrypt the encrypted query result to obtain the data query result corresponding to the data query request.
[0014] According to another aspect of the embodiments of the present invention, there is also provided a method for applying a dynamic key, including: using the above method for generating a dynamic key to obtain the first dynamic key; receiving, by the server, an encrypted query request sent by the client; and using the forward order of the first dynamic key as the first key in the target key rule to decrypt the encrypted query request to obtain the data query request generated by the client.
[0015] Optionally, the method further includes: generating, by the server in response to the data query request, a data query result; and using the reverse order of the first dynamic key as the second key in the target key rule to encrypt the data query result to obtain an encrypted query result in response to the encrypted query request.
[0016] Optionally, the method further includes: receiving a spliced query request sent by the client, where the spliced query request includes: a spliced font file set number key and the encrypted query request, the font file set number key is obtained by converting a target font set number code using a preset encoding conversion rule, the target font set number code is a preset font set number code corresponding to a target font file randomly selected by the client in a preset font file library, the preset font file library pre-stores a preset number of preset font files and the preset font set number code corresponding to each preset font file; and using the font file set number key in the spliced query request as the font file set number feedback key to splice with the encrypted query result generated by the server in response to the encrypted query request in the same spliced query request to obtain a spliced query result.
[0017] According to another aspect of the embodiments of the present invention, there is also provided a device for generating a dynamic key, including: an acquisition module, configured to acquire an updated base address, offset, and fixed value according to a preset update period, where the base address and the fixed value are preset variables set in advance, and the offset is an update variable updated according to the preset update period; a generation module, configured to generate a dynamic termination key based on the base address, the offset, and the fixed value; a conversion module, configured to convert the dynamic termination key into a first dynamic key according to a preset key conversion rule, where the first dynamic key is used to encrypt or decrypt data transmitted between a client and a server.
[0018] According to another aspect of the embodiments of the present invention, there is also provided a device for applying a dynamic key, including: a client acquisition module, configured to use the above-mentioned device for generating a dynamic key to acquire the first dynamic key; a client generation module, configured to generate a data query request through the client; a client encryption module, configured to use the forward order of the first dynamic key as the first key in a target key rule to encrypt the data query request to obtain an encrypted query request.
[0019] According to another aspect of the embodiments of the present invention, there is also provided a device for applying a dynamic key, including: a server acquisition module, configured to use the above-mentioned device for generating a dynamic key to acquire the first dynamic key; a server reception module, configured to receive the encrypted query request sent by the client through the server; a server decryption module, configured to use the forward order of the first dynamic key as the first key in a target key rule to decrypt the encrypted query request to obtain the data query request generated by the client.
[0020] According to another aspect of the embodiments of the present invention, there is also provided an electronic device, including a memory and a processor, where a computer program is stored in the memory, and the processor is configured to execute the above-mentioned method for generating a dynamic key or execute the above-mentioned method for applying a dynamic key through the computer program.
[0021] According to another aspect of the embodiments of the present invention, there is also provided a computer program product, including computer instructions, where when the computer instructions are executed by a processor, the above-mentioned method for generating a dynamic key is implemented, or the above-mentioned method for applying a dynamic key is executed.
[0022] In the above embodiments of the present application, the first dynamic key used for encrypting or decrypting the data transmitted between the client and the server is determined based on a base address, an offset, and a fixed value. Since the base address and the fixed value are preset variables set in advance, and the offset is an updated variable updated according to a preset update period, by updating the offset, the update of the first dynamic key can be achieved. Furthermore, encryption is performed using the first dynamic key updated according to the preset update period, thereby achieving the technical effect of increasing the difficulty of reproducing and decrypting the encryption and decryption algorithms, and further solving the technical problem that the encryption algorithms in the prior art are easily reproduced and decrypted. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] The drawings described herein are used to provide a further understanding of the present invention, and constitute a part of this application. The illustrative embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:
[0024] Figure 1 is a flowchart of a method for generating a dynamic key according to an embodiment of the present invention;
[0025] Figure 2 is the flow of a method for applying a dynamic key according to an embodiment of the present invention Figure 1 ;
[0026] Figure 3 is the flow of a method for applying a dynamic key according to an embodiment of the present invention Figure 2 ;
[0027] Figure 4 is a schematic diagram of a preset font file library according to an embodiment of the present invention;
[0028] Figure 5 is a schematic diagram of data transmission from a client / web to a server according to an embodiment of the present invention;
[0029] Figure 6 is a schematic diagram of a server receiving parameter data submitted by a client / web according to an embodiment of the present invention;
[0030] Figure 7 is a schematic diagram of a device for generating a dynamic key according to an embodiment of the present invention;
[0031] Figure 8 is a schematic diagram of a device for applying a dynamic key according to an embodiment of the present invention Figure 1 ;
[0032] Figure 9 is a schematic diagram of a device for applying a dynamic key according to an embodiment of the present invention Figure 2 ;
[0033] Figure 10 It is a structural block diagram of a computer terminal according to an embodiment of the present invention. Specific implementation manners
[0034] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative work shall fall within the protection scope of the present invention.
[0035] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and do not have to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described here can be implemented in an order different from those illustrated or described here. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units does not have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0036] According to an embodiment of the present invention, an embodiment of a method for generating a dynamic key is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that here.
[0037] Figure 1 It is a flowchart of a method for generating a dynamic key according to an embodiment of the present invention. As Figure 1 shown, the method includes the following steps:
[0038] Step S102, obtain the updated base address, offset and fixed value according to a preset update period, where the base address and the fixed value are preset variables set in advance, and the offset is an update variable updated according to the preset update period;
[0039] Step S104, generate a dynamic termination key based on the base address, offset and fixed value;
[0040] Step S106, convert the dynamic termination key into a first dynamic key according to a preset key conversion rule, where the first dynamic key is used to encrypt or decrypt the data transmitted between the client and the server.
[0041] In the above embodiments of the present application, the first dynamic key used for encrypting or decrypting the data transmitted between the client and the server is determined based on a base address, an offset, and a fixed value. Since the base address and the fixed value are preset variables, and the offset is an update variable updated according to a preset update period, by updating the offset, the update of the first dynamic key can be achieved. Furthermore, encryption is performed using the first dynamic key updated according to the preset update period, thereby achieving the technical effect of increasing the difficulty of reproducing and decrypting the encryption and decryption algorithms, and further solving the technical problem that the encryption algorithms in the prior art are easily reproduced and decrypted.
[0042] In the above step S102, the preset update period can be one day.
[0043] In the above step S102, the offset can be the difference relative to a set value. For example, the set value can be a preset date, and the offset can be the number of days of deviation from the preset date.
[0044] For example, if the preset date is: 2024.11.13 and the current date is 2024.11.19, then the amount of the offset is 6.
[0045] In the above step S102, the base address and the fixed value can be preselected and changeable variables. The variable values of the base address and the fixed value can be different, and the base address and the fixed value can be updated according to the preset update period.
[0046] In the above step S104, the dynamic termination key can be a combination of the base address, the offset, and the fixed value.
[0047] In the above step S106, the first dynamic key can be the result of converting the dynamic termination key according to a preset key conversion rule. By converting the dynamic termination key according to the preset key conversion rule, the complexity of the key can be further increased, and the difficulty of reproducing and decrypting the encryption algorithm can be improved.
[0048] In the above step S106, the preset key conversion rule can convert the dynamic termination key into a string in a specific form, such as a hash string.
[0049] For example, when the dynamic termination key is 6880965, after converting this dynamic termination key, the obtained first dynamic key (FKey) is: FKey = ef73f68aed96ed96f89ceb1ef68aeedd.
[0050] As an alternative embodiment, generating a dynamic termination key based on a base address, an offset, and a fixed value includes: determining the sum of the base address and the offset as an intermediate key; and determining the product of the intermediate key and the fixed value as the dynamic termination key.
[0051] In the above embodiments of the present application, by performing addition operations and multiplication operations to combine the base address, the offset, and the fixed value, the complexity of generating the dynamic termination key can be increased, and further the difficulty of reproducing and decrypting the encryption algorithm can be increased.
[0052] Optionally, (base address + offset) * fixed value = dynamic termination key.
[0053] For example, if the base address is 99, the offset is 6, and the fixed value is 65533, then the dynamic termination key (DKey) is: DKey = (99 + 6) * 65533 = 6880965.
[0054] As an alternative embodiment, the method further includes: obtaining a target font set number encoding randomly determined by a client, where the target font set number encoding is used to indicate the encoding of a corresponding target font file in a preset font file library. The preset font file library pre-stores a preset number of preset font files and the preset font set number encoding corresponding to each preset font file; converting the target font set number encoding into a font file set number key that conforms to a preset length according to a preset encoding conversion rule; and concatenating the font file set number key with a first dynamic key to obtain a second dynamic key.
[0055] In the above embodiments of the present application, the preset font file library pre-stores a preset number of preset font files, and each preset font file is pre-set with a corresponding preset font set number encoding. Furthermore, the client can randomly select a preset font file in the preset font file library to obtain a target font file, and the preset font set number encoding corresponding to the target font file is the target font set number encoding. Then, by converting the target font set number encoding according to the preset encoding conversion rule, a font file set number key can be obtained. Then, by combining the first dynamic key with the font file set number key, the complexity of the key can be increased, and further the difficulty of reproducing and decrypting the encryption algorithm can be increased.
[0056] Optionally, converting the target font set number encoding into a font file set number key that conforms to a preset length according to a preset encoding conversion rule includes: converting the target font set number encoding according to the preset encoding conversion rule to obtain a target font conversion string; and intercepting a string that conforms to the preset length in the target font conversion string to obtain the font file set number key.
[0057] Optionally, the preset length can be 4 bits, such as 4 character positions.
[0058] Optionally, the preset encoding conversion rule may be the same as the preset key conversion rule.
[0059] Optionally, the preset encoding conversion rule may be different from the preset key conversion rule.
[0060] Optionally, the content recorded in the preset font file may be a font conversion rule. When the preset encoding conversion rule is different from the preset key conversion rule, the converted font conversion rule in the preset font file may be used as the preset key conversion rule.
[0061] As an alternative embodiment, after obtaining the target font set number encoding randomly determined by the client, the method further includes: obtaining, from multiple preset font files recorded in the preset font file library, the target font file corresponding to the target font set number encoding; extracting the conversion rule indicated in the target font file as the preset key conversion rule.
[0062] In the above embodiments of the present application, the conversion rule indicated in the target font file is used as the preset key conversion rule, and the target font set number encoding corresponding to the target font file is converted into a font file set number key and combined with the first dynamic key to obtain a second dynamic key, which can increase the complexity of the key and further increase the difficulty of reproducing and decrypting the encryption algorithm.
[0063] According to an embodiment of the present invention, an embodiment of an application method for a dynamic key is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings may be executed in a computer system such as a set of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than here.
[0064] Figure 2 is the flowchart of an application method for a dynamic key according to an embodiment of the present invention Figure 1 as Figure 2 shown, the method includes the following steps:
[0065] Step S202, using the above method for generating a dynamic key, obtain a first dynamic key;
[0066] Step S204, generate a data query request through the client;
[0067] Step S206, use the forward order of the first dynamic key as the first key in the target key rule to encrypt the data query request to obtain an encrypted query request.
[0068] In the above embodiments of the present application, when the client needs to send a data query request to the server, the client can obtain a first dynamic key generated based on a base address, an offset, and a fixed value. Since the base address and the fixed value are preset variables set in advance, and the offset is an update variable updated according to a preset update period, by updating the offset, the update of the first dynamic key can be realized. Furthermore, by using the first dynamic key, a first dynamic key for encrypting the data query request can be obtained, and the data query request generated by the client can be encrypted to obtain an encrypted query request that is difficult to be reproduced and decrypted, thereby achieving the technical effect of increasing the difficulty of reproducing and decrypting the encryption and decryption algorithms, and further solving the technical problem that the encryption algorithms in the prior art are easily reproduced and decrypted.
[0069] In step S206 above, the client can send a data query request to the server. To ensure the transmission security of this data query request, the positive order of the first dynamic key can be used as the key for encrypting the data query request.
[0070] Optionally, the data query request can be encrypted by combining the DES algorithm and the RSA algorithm.
[0071] It should be noted that the DES algorithm is the data encryption standard, and this DES algorithm needs to use an initial vector iv and a standard key key.
[0072] Optionally, the target key rule is the DES algorithm, and the first key is the initial vector iv and the standard key key required by the DES algorithm.
[0073] As an optional example, using the positive order of the first dynamic key as the first key in the target key rule to encrypt the data query request, the obtained encrypted query request includes: when the target key rule is the DES algorithm, using the positive order of the first dynamic key as the initial vector iv and the standard key key required by the DES algorithm to encrypt the data query request to obtain a preset query request; using the RSA algorithm to encrypt the preset query request to obtain an encrypted query request.
[0074] Optionally, when decrypting the encrypted query request encrypted by combining the DES algorithm and the RSA algorithm, the RSA algorithm can be used to decrypt the encrypted query request to obtain a preset query request; then, using the positive order of the first dynamic key as the initial vector iv and the standard key key required by the DES algorithm to perform secondary decryption on the preset query request, the data query request originally generated by the client can be obtained.
[0075] As an alternative embodiment, the method further includes: receiving, by the client, an encrypted query result returned by the server, where the server is configured to respond to the encrypted query request sent by the client to generate the encrypted query result; using the reverse order of the first dynamic key as the second key in the target key rule to decrypt the encrypted query result to obtain the data query result corresponding to the data query request.
[0076] In the above embodiment of the present application, the server can respond to the encrypted query request sent by the client to generate an encrypted query result, which is the result of encrypting the data query result generated by the server using the reverse order of the first dynamic key as the second key in the target key rule. Therefore, after receiving the encrypted query result returned by the server, the client can use the reverse order of the first dynamic key as the second key in the target key rule to decrypt the encrypted query result to obtain the data query result corresponding to the data query request, realizing the decryption of the encrypted query result.
[0077] As an alternative embodiment, the method further includes: obtaining a font file set number key randomly determined by the client, where the font file set number key is obtained by converting the target font set number encoding using a preset encoding conversion rule, and the target font set number encoding is the preset font set number encoding corresponding to the target font file randomly selected by the client in a preset font file library, and the preset font file library pre-stores a preset number of preset font files and the preset font set number encoding corresponding to each preset font file; concatenating the font file set number key with the encrypted query request to obtain a concatenated query request.
[0078] In the above embodiment of the present application, when the client generates a data query request, it can also randomly determine a font file set number key. Then, when generating an encrypted query request based on the data query request, it can concatenate the font file set number key with the encrypted query request to obtain a concatenated query request, thereby increasing the complexity of the key and further increasing the difficulty of reproducing and decrypting the encryption algorithm.
[0079] Optionally, when applying the second dynamic key, the second dynamic key includes: a font file set number key and a first dynamic key. Then, the first dynamic key can be directly extracted from the second dynamic key to encrypt the data query request to obtain an encrypted query request, and then the font file set number key is extracted from the second dynamic key and concatenated with the encrypted query request to obtain a concatenated query request, realizing the combined application of the font file set number key and the first dynamic key in the second dynamic key, thereby increasing the complexity of the key and further increasing the difficulty of reproducing and decrypting the encryption algorithm.
[0080] As an alternative embodiment, the method further includes: receiving, by the client, the spliced query result returned by the server, where the spliced query result includes: the spliced font file set number feedback key and the encrypted query result, and the server is configured to respond to the encrypted query request in the spliced query request, generate the encrypted query result, and use the font file set number key in the spliced query request responded by the server as the font file set number feedback key for splicing with the encrypted query result; comparing the first set number key and the second set number key for consistency, where the first set number key is the font file set number key in the spliced query request sent by the client, and the second set number key is the font file set number feedback key in the spliced query result received by the client; in the case where the first set number key and the second set number key are consistent, using the reverse order of the first dynamic key as the second key in the target key rule to decrypt the encrypted query result to obtain the data query result corresponding to the data query request.
[0081] In the above embodiment of the present application, the spliced query result returned by the server based on the spliced query request carries the font file set number key in the spliced query request, and the font file set number key carried in the spliced query result can be used as the font file set number feedback key. Then, after the client receives the spliced query result returned by the server, the client can use the font file set number key in the spliced query request sent by the client as the first key, and the font file set number feedback key in the spliced query result returned by the server as the second key. By comparing the first key and the second key for consistency, it can be verified whether the spliced query result returned by the server is a response to the spliced query request sent by the client. Then, in the case where it is determined that the spliced query result is a response to the spliced query request sent by the client, the reverse order of the first dynamic key is used as the second key in the target key rule to decrypt the encrypted query result in the spliced query result to obtain the data query result corresponding to the data query request.
[0082] Figure 3 is a flow of an application method of a dynamic key according to an embodiment of the present invention Figure 2 , such as Figure 3 shown, the method includes the following steps:
[0083] Step S302, using the above method for generating a dynamic key to obtain a first dynamic key;
[0084] Step S304, receiving, by the server, the encrypted query request sent by the client;
[0085] Step S306, using the forward order of the first dynamic key as the first key in the target key rule to decrypt the encrypted query request to obtain the data query request generated by the client.
[0086] In the above embodiments of the present application, when the server receives the encrypted query request sent by the client, the client can obtain the first dynamic key generated based on the base address, offset, and fixed value. Since the base address and the fixed value are preset variables set in advance, and the offset is an updated variable updated according to a preset update period, by updating the offset, the update of the first dynamic key can be realized. Furthermore, by using the first dynamic key, the first dynamic key used to encrypt the data query request can be obtained, and the data query request generated by the client can be encrypted to obtain an encrypted query request that is difficult to be reproduced and decrypted, thus achieving the technical effect of increasing the difficulty of reproducing and decrypting the encryption and decryption algorithms, and further solving the technical problem that the encryption algorithm in the prior art is easily reproduced and decrypted.
[0087] In step S306 above, the server can respond to the data query request of the client. Since the data query request is encrypted and transmitted by the client using the forward order of the first dynamic key as the first key, in order to extract the data query request from the encrypted query request, the server also needs to use the forward order of the first dynamic key as the first key in the target key rule to decrypt the encrypted query request.
[0088] As an optional embodiment, the method further includes: generating a data query result by the server in response to the data query request; using the reverse order of the first dynamic key as the second key in the target key rule to encrypt the data query result to obtain an encrypted query result in response to the encrypted query request.
[0089] In the above embodiments of the present application, the server can respond to the data query request to generate a data query result, and the data query result generated by the server can be encrypted and then transmitted to the client. Furthermore, the server can use the reverse order of the first dynamic key as the second key in the target key rule to encrypt the data query result. Thus, the client and the server respectively use the forward order and the reverse order of the first dynamic key as keys, which can increase the complexity of the key and further increase the difficulty of reproducing and decrypting the encryption algorithm.
[0090] As an optional example, using the reverse order of the first dynamic key as the second key in the target key rule to encrypt the data query result to obtain an encrypted query result in response to the encrypted query request includes: when the target key rule is the DES algorithm, using the reverse order of the first dynamic key as the initial vector iv and the standard key key required by the DES algorithm to encrypt the data query result to obtain a preset query result; using the RSA algorithm to encrypt the preset query result to obtain an encrypted query result.
[0091] Optionally, in the case of decrypting an encrypted query result obtained by combining the DES algorithm and the RSA algorithm, the RSA algorithm can be used to decrypt the encrypted query result to obtain a preset query result; then, the reverse order of the first dynamic key can be used as the initial vector iv and the standard key key required by the DES algorithm to perform secondary decryption on the preset query result, and the data query result originally generated by the server can be obtained.
[0092] As an alternative embodiment, the method further includes: receiving a spliced query request sent by a client, where the spliced query request includes: a spliced font file set number key and an encrypted query request. The font file set number key is obtained by converting the target font set number encoding using a preset encoding conversion rule. The target font set number encoding is the preset font set number encoding corresponding to the target font file randomly selected by the client in a preset font file library. The preset font file library stores a preset number of preset font files in advance, and the preset font set number encoding corresponding to each preset font file; using the font file set number key in the spliced query request as the font file set number feedback key, and splicing it with the encrypted query result generated by the server in response to the encrypted query request in the same spliced query request to obtain a spliced query result.
[0093] In the above embodiments of the present application, the data query request sent by the client can be an encrypted query request. The encrypted query request can also carry a font file set number key pre-generated by the client, that is, the server can receive a spliced query request spliced with the font file set number key and the encrypted query request sent by the client. Then, the server can decrypt the encrypted query request in the spliced query request to obtain the data query request, make a response to the data query request to generate a data query result. Then, the server can encrypt the data query result to obtain an encrypted query result, and use the font file set number key in the spliced query request as the font file set number feedback key, and splice it with the responded encrypted query result to obtain a spliced query result. Then, the server can send the spliced query result to the client to achieve encrypted transmission of the data query result.
[0094] In the above embodiments of the present application, the font file set number feedback key carried in the spliced query result returned by the server is the font file set number key in the spliced query request responded by the server. Therefore, when the client receives the spliced query result, it can perform a consistency check based on the font file set number feedback key carried in the spliced query result and the font file set number key in the spliced query request sent by the client to determine whether the spliced query result is the response result of the server to the spliced query request sent by the client.
[0095] Optionally, by recognizing and splicing the query request, the server can obtain the key for the number of font file sets spliced in the spliced query request. This key for the number of font file sets is the unique result encoded according to the number of target font sets corresponding to the target font file. Therefore, through this key for the number of font file sets, the target font file can be determined. Furthermore, based on the target font file, the preset encoding conversion rule for the key can be extracted. Then, after the server obtains the base address, offset, and fixed value updated according to the preset update period, a dynamic termination password can be generated, and the preset encoding conversion rule is used to convert the dynamic termination key, and the first dynamic key consistent with the client can be obtained. Furthermore, this first dynamic key can be used to decrypt the encrypted query request sent by the client.
[0096] The present invention also provides a preferred embodiment, which provides a data flow dynamic encryption method. By adding dynamic values on the basis of maintaining the original conventional encryption, the dynamic update of data flow encryption is realized; and through dynamic encryption, the security of data transmission from the url to the data response data set can be guaranteed.
[0097] The technical solution provided in this application sets a base address as a reference quantity, sets an offset, encrypts the data flow with the dynamic nature of the time dimension, then sets a fixed value, and the set base address, offset, and fixed value can all be changed. Then, the base address, offset, and fixed value are combined according to a formula to obtain a dynamic termination key. Then, the combined key is standardized through multiple sets of random font files (that is, converted according to the preset key conversion rule) to obtain the first dynamic key. Finally, a number (such as the key for the number of font file sets) is added in front of the standardization, and then it is encrypted through the font file together.
[0098] Optionally, the number added in front of the standardization represents telling the server which set of font files has been randomized, and a string will be obtained, which is the key (such as the key for the number of font file sets).
[0099] Optionally, after the server encrypts the id locally with DES, it is spliced with the key and then encrypted twice through the DES key (such as iv and key, that is, the first dynamic key), and then transmitted to the client through RSA encryption.
[0100] Optionally, after the client obtains the encrypted value, it first performs RSA decryption, constructs the key through the font file, and then can obtain the plaintext through DES decryption.
[0101] Optionally, the formula for generating the dynamic termination key based on the base address, offset, and fixed value is: (base address + offset) * fixed value = end address.
[0102] As an alternative embodiment, the base address is a settable variable that can be set to 99; the offset is the offset from the set value. For example, if the set value is 2024.11.13, an offset of 6 represents 2024.11.19, and an offset of 7 represents 2024.11.20. The preset update period of this offset can be 1 day; the fixed value is a changeable variable that can be set to 65533, and the dynamic termination key (DKey) is: DKey = (99 + 6) * 65533 = 6880965.
[0103] Figure 4 is a schematic diagram of a preset font file library according to an embodiment of the present invention, as Figure 4 shown, 10 sets of preset font files for random extraction are preset, and one set of preset font files is randomly extracted as the target font file.
[0104] Optionally, the 10 sets of preset font files preset can be pre-encoded by the number of sets (such as encoded as 0 - 9), that is, a corresponding preset font set number encoding is set for each preset font file, and through the number encoding, it can be determined which set of preset font files is randomly extracted.
[0105] It should be noted that the purpose of randomly extracting the preset font file is to generate random font encryption.
[0106] As an alternative embodiment, as Figure 4 shown, assuming that the third set of fonts is extracted, then the final dynamic key (i.e., the first dynamic key FKey) is: FKey = the transformation of the third set of fonts (taking the last four digits in the transformation process) + the transformation of DKey.
[0107] Optionally, the transformation of the third set of fonts (taking the last four digits in the transformation process), that is, the transformation result corresponding to the number "3" in the third set is ef73, and the transformation result of the dynamic termination key DKey "6880965" (also the first dynamic key) is "f68aed96ed96f89ceb1ef68aeedd", then the second dynamic key FKey is ef73f68aed96ed96f89ceb1ef68aeedd.
[0108] As an alternative example, the data transmitted between the client and the server can first be encrypted using the DES algorithm and then encrypted a second time using the RSA algorithm.
[0109] Optionally, the encryption principle of the DES algorithm is: plaintext + iv + key = ciphertext; the decryption principle is: ciphertext + iv + key = plaintext, where iv and key are keys that can be determined based on the first dynamic key.
[0110] Optionally, the encryption principle of the RSA algorithm is: plaintext + public key = ciphertext; the decryption principle is: ciphertext + private key = plaintext.
[0111] Optionally, the data transmitted between the client and the server can be a data query request initiated by the client to the server, or a data query result returned by the server to the client.
[0112] Optionally, the data query requests sent by the client to the server can be Get requests and Post requests. Among them, the logic of the Get request is: submit the parameter url (followed by the submitted data parameter) to obtain a data set; the logic of the Post request is: submit the parameter data to obtain a data set.
[0113] It should be noted that GET requests and POST requests are the two most commonly used request methods in the HTTP protocol. The GET request is used to request data from the server (such as loading a web page, query result), and the request parameters are usually appended to the URL; the POST request is used to send data to the server (such as submitting a form, uploading a file), and the request parameters are included in the request body and the URL is invisible.
[0114] As an optional example, the overall encryption logic is: first generate a second dynamic key FKey, and encrypt the data to be encrypted through DES. Among them, if it is the request parameter data (such as a data query request), the iv value and the key value (that is, the first key) are encrypted with the second dynamic key FKey starting from the fifth bit and padding with 0 if the length is insufficient (that is, the forward order of the first dynamic key); if it is the transmission of the data body result set (such as a data query result), the iv value and the key value (that is, the second key) are encrypted with the reverse order of the second dynamic key FKey up to the penultimate fifth bit and padding with 0 if the length is insufficient (that is, the reverse order of the first dynamic key); after encryption, use RSA for secondary encryption to obtain the final encrypted result ciphertext (such as splicing a query request or splicing a query result).
[0115] As an optional example, the overall decryption logic is: given the second dynamic key FKey, first decrypt the encrypted result (such as splicing a query request or splicing a query result) through RSA, and then decrypt the RSA decryption result through DES for the second time. If it is the request parameter data (such as a data query request), the iv value and the key value (that is, the first key) are decrypted with the second dynamic key FKey starting from the fifth bit and padding with 0 if the length is insufficient (that is, the forward order of the first dynamic key); if it is the transmission of the data body result set (such as a data query result), the iv value and the key value (that is, the second key) are decrypted with the reverse order of the generated dynamic key FKey up to the penultimate fifth bit and padding with 0 if the length is insufficient (that is, the reverse order of the first dynamic key) to obtain the plaintext (such as a data query request or a data query result).
[0116] Figure 5 It is a schematic diagram of a client / web transmitting data to a server according to an embodiment of the present invention. As Figure 5 shown, the steps are as follows:
[0117] In step S501, when the client loads a page, first obtain a random set of font files (such as the target font file) through obfuscation. For example, the third set of files and a set of corresponding font set numbers (such as the target font set number code) are saved through variables. At the same time, obtain a number of the final value after offset, that is, the offset is 6, the fixed value is 65533, and the base address is 99, and save them in different places with obfuscated variables.
[0118] In step S502, obtain the dynamic termination key for the current day through the obfuscated variable formula: (99 + 6) * 65533 = 6880965.
[0119] In step S503, obtain the first dynamic key DKey for today by reading the target font file: f68aed96ed96f89ceb1ef68aeedd.
[0120] In step S504, obtain the font file set key as: ef73 through the number of the font file set (such as the target font set number code) and the corresponding set of font files.
[0121] In step S505, combine to obtain the final dynamic key for today (that is, the second dynamic key FKey) as: ef73f68aed96ed96f89ceb1ef68aeedd.
[0122] In step S506, the client constructs the parameter data (such as a data query request) to be requested from the server, encrypts the data through DES. Among them, the key key and iv (that is, the first key) of the DES encryption use the second final dynamic key FKey for today, and fill in 0 for the insufficient length starting from the fifth bit (that is, the positive order of the first dynamic key).
[0123] In step S507, re-encrypt the DES-encrypted data (such as a preset query request) through RSA.
[0124] In step S508, the client submits the ciphertext of the final parameter (such as an encrypted query request or a spliced query request) to the server.
[0125] Figure 6 It is a schematic diagram of a server receiving parameter data submitted by a client / web according to an embodiment of the present invention. As Figure 6 shown, the steps are as follows:
[0126] Step S601: The server automatically generates the dynamic termination key for the current day every day through the base address, offset, and fixed value. When the server receives the parameter ciphertext submitted by the client (such as the spliced query request), it takes the first 4 digits (such as the font file set number key) and decrypts them through the corresponding set of digital font files to determine the number of digital font encryption file sets used (such as the target font set number encoding), reads the corresponding number of sets, converts the dynamic termination key for the current day into the first dynamic key DKey, and finally obtains the second dynamic key FKey = font file set ciphertext (such as the font file set number key) + DKey.
[0127] Step S602: Decrypt through RSA.
[0128] Step S603: Perform secondary decryption through DES. Among them, for the key key and iv of DES, when using the second dynamic key DKey of today, if the length is not enough starting from the fifth digit, fill it with 0 (that is, the positive order of the first dynamic key).
[0129] Step S604: The server obtains the final plaintext of the client (such as the data query request).
[0130] Step S605: Respond to the data according to the client parameter requirements (such as generating an encrypted query result or splicing a query result).
[0131] As an optional example, the steps for the server to transmit data are as follows:
[0132] Step S611: The server responds to the data according to the client parameter requirements.
[0133] It should be noted that at this time, the plaintext transmitted by the client (such as the data query request) has been obtained.
[0134] Step S612: Encrypt the data (such as the data query result) that needs to be responded to the client through the second dynamic key FKey in the parameter data (such as the spliced query request) submitted by the server receiving the client / web using DES. For the iv value and key key value of DES encryption, use the reverse order of the generated second dynamic key FKey until the penultimate fifth digit, and fill it with 0 if the length is not enough (such as the reverse order of the first dynamic query key) for encryption.
[0135] Step S613: Continue to perform secondary RSA encryption on the encrypted result.
[0136] Step S614, concatenate the ciphertext obtained (such as the encrypted query result) with the ciphertext of the number of font file sets in the parameter data submitted by the client / web to the server (such as concatenating the query request), that is, the ciphertext of the number of font file sets (such as the key of the number of font file sets, which is also the feedback key of the number of font file sets) + the encrypted ciphertext (such as the encrypted query result) = the final ciphertext (such as the concatenated query result).
[0137] Step S615, transmit the final ciphertext (such as the concatenated query result) to the client.
[0138] As an optional example, the client / web receives data, including the following steps:
[0139] Step S511, the client receives the final ciphertext (such as the concatenated query result) transmitted by the server.
[0140] Step S512, by reading the first four digits of the final ciphertext (such as the feedback key of the number of font file sets) and comparing them with the font files of the page loaded by the client (such as the key of the number of font file sets), if they are inconsistent, the data response is invalid.
[0141] Step S513, if they are consistent, decrypt by RSA.
[0142] Step S514, perform secondary decryption by DES. Among them, the key key and iv value of DES are decrypted using the reverse order of FKey in the data transmitted from the client / web to the server (such as the concatenated query request), and padded with 0 if the length is not enough until the fifth digit from the end (such as the reverse order of the first dynamic key).
[0143] Step S515, obtain the plaintext of the final data result set (such as the data query result) and give it to the user.
[0144] The technical solution provided by this application is more secure for the dynamic encrypted data stream compared with conventional encryption, making the restoration and reproduction more complex. Moreover, the base address, offset, and fixed value in this application can be changed without affecting all encryption / decryption logics. However, after the change, it can increase the cumbersome operations such as duplicate removal after data theft under a large amount of data, further protecting data privacy and preventing leakage.
[0145] The technical solution provided by this application has a more complex dynamic key than a fixed key, providing greater protection against restoration and theft. By using a combination of popular encryptions, it does not affect the server performance even for large text data.
[0146] The technical solution provided by this application can automatically change the base address, fixed value, and offset in a timed manner, without affecting the business interaction result and data transmission result, but will greatly increase the difficulty of information theft. In the case of a large amount of data, the difficulty of stealing all the data will become complicated due to the change of the base address, fixed value, and offset. If data is leaked, it can also ensure that the degree of data leakage is minimized.
[0147] According to an embodiment of the present invention, there is also provided an embodiment of a dynamic key generation device. It should be noted that this dynamic key generation device can be used to execute the dynamic key generation method in the embodiment of the present invention, and the dynamic key generation method in the embodiment of the present invention can be executed in this dynamic key generation device.
[0148] Figure 7 is a schematic diagram of a dynamic key generation device according to an embodiment of the present invention, as Figure 7 shown, the device may include: an acquisition module 72, configured to acquire the updated base address, offset, and fixed value according to a preset update period, where the base address and fixed value are preset variables set in advance, and the offset is an update variable updated according to the preset update period; a generation module 74, configured to generate a dynamic termination key based on the base address, offset, and fixed value; a conversion module 76, configured to convert the dynamic termination key into a first dynamic key according to a preset key conversion rule, where the first dynamic key is used to encrypt or decrypt the data transmitted between the client and the server.
[0149] It should be noted that the acquisition module 72 in this embodiment can be used to execute step S102 in the embodiment of this application, the generation module 74 in this embodiment can be used to execute step S104 in the embodiment of this application, and the conversion module 76 in this embodiment can be used to execute step S106 in the embodiment of this application. The examples and application scenarios implemented by the above modules and the corresponding steps are the same, but are not limited to the content disclosed in the above embodiments.
[0150] In the above embodiments of this application, the first dynamic key used to encrypt or decrypt the data transmitted between the client and the server is determined based on the base address, offset, and fixed value. And since the base address and fixed value are preset variables set in advance, and the offset is an update variable updated according to the preset update period, by updating the offset, the update of the first dynamic key can be realized, and then encryption is performed using the first dynamic key updated according to the preset update period, thereby achieving the technical effect of increasing the difficulty of reproducing and decrypting the encryption and decryption algorithms, and further solving the technical problem that the encryption algorithms in the prior art are easily reproduced and decrypted.
[0151] As an alternative embodiment, the generation module includes: a first determination unit configured to determine the sum of the base address and the offset as an intermediate key; and a second determination unit configured to determine the product of the intermediate key and a fixed value as a dynamic termination key.
[0152] As an alternative embodiment, the apparatus further includes: an acquisition sub-module configured to acquire a target font set number code randomly determined by a client, where the target font set number code is used to indicate the code of a corresponding target font file in a preset font file library, the preset font file library pre-stores a preset number of preset font files and a preset font set number code corresponding to each preset font file; a conversion sub-module configured to convert the target font set number code into a font file set number key that conforms to a preset length according to a preset coding conversion rule; and a splicing sub-module configured to splice the font file set number key and a first dynamic key to obtain a second dynamic key.
[0153] As an alternative embodiment, the apparatus further includes: an acquisition sub-unit configured to, after acquiring a target font set number code randomly determined by a client, acquire a target font file corresponding to the target font set number code from a plurality of preset font files recorded in the preset font file library; and an extraction sub-unit configured to extract a conversion rule indicated in the target font file as a preset key conversion rule.
[0154] According to an embodiment of the present invention, there is also provided an embodiment of an apparatus for applying a dynamic key. It should be noted that the apparatus for applying a dynamic key can be used to execute the method for applying a dynamic key in the embodiment of the present invention, and the method for applying a dynamic key in the embodiment of the present invention can be executed in the apparatus for applying a dynamic key.
[0155] Figure 8 is a schematic diagram of an apparatus for applying a dynamic key according to an embodiment of the present invention Figure 1 , such as Figure 8 shown, the apparatus may include: a client acquisition module 82 configured to use the above-mentioned dynamic key generation device to acquire a first dynamic key; a client generation module 84 configured to generate a data query request through the client; and a client encryption module 86 configured to use the forward order of the first dynamic key as the first key in the target key rule to encrypt the data query request to obtain an encrypted query request.
[0156] It should be noted that the client acquisition module 82 in this embodiment can be used to execute step S202 in the embodiment of the present application, the client generation module 84 in this embodiment can be used to execute step S204 in the embodiment of the present application, and the client encryption module 86 in this embodiment can be used to execute step S206 in the embodiment of the present application. The examples and application scenarios implemented by the above modules and the corresponding steps are the same, but are not limited to the content disclosed in the above embodiments.
[0157] In the above embodiments of the present application, when the client needs to send a data query request to the server, the client can obtain a first dynamic key generated based on a base address, an offset, and a fixed value. Since the base address and the fixed value are preset variables set in advance, and the offset is an update variable updated according to a preset update period, the first dynamic key can be updated by updating the offset. Furthermore, by using the first dynamic key, a first dynamic key for encrypting the data query request can be obtained, and the data query request generated by the client can be encrypted to obtain an encrypted query request that is difficult to be reproduced and decrypted, thereby achieving the technical effect of increasing the difficulty of reproducing and decrypting the encryption and decryption algorithms, and further solving the technical problem that the encryption algorithm in the prior art is easily reproduced and decrypted.
[0158] As an alternative embodiment, the device further includes: a client first receiving sub-module, configured to receive, through the client, an encrypted query result returned by the server, where the server is configured to respond to the encrypted query request sent by the client and generate an encrypted query result; a client first decryption sub-module, configured to use the reverse order of the first dynamic key as the second key in the target key rule to decrypt the encrypted query result to obtain the data query result corresponding to the data query request.
[0159] As an alternative embodiment, the device further includes: a client obtaining sub-module, configured to obtain a font file set number key randomly determined by the client, where the font file set number key is obtained by converting a target font set number code using a preset encoding conversion rule, and the target font set number code is the preset font set number code corresponding to a target font file randomly selected by the client in a preset font file library. The preset font file library stores a preset number of preset font files in advance, and the preset font set number code corresponding to each preset font file; a client splicing sub-module, configured to splice the font file set number key and the encrypted query request to obtain a spliced query request.
[0160] As an alternative embodiment, the apparatus further includes: a second client receiving sub-module, configured to receive, via the client, the spliced query result returned by the server, where the spliced query result includes: the spliced font file set number feedback key and the encrypted query result, and the server is configured to respond to the encrypted query request in the spliced query request, generate the encrypted query result, and use the font file set number key in the spliced query request responded by the server as the font file set number feedback key spliced with the encrypted query result; a client comparison sub-module, configured to perform a consistency comparison between the first set number key and the second set number key, where the first set number key is the font file set number key in the spliced query request sent by the client, and the second set number key is the font file set number feedback key in the spliced query result received by the client; a second client decryption sub-module, configured to, when the first set number key and the second set number key are consistent, use the reverse order of the first dynamic key as the second key in the target key rule to decrypt the encrypted query result to obtain the data query result corresponding to the data query request.
[0161] Figure 9 is a schematic diagram of an apparatus for applying a dynamic key according to an embodiment of the present invention Figure 2 , such as Figure 9 shown, the apparatus may include: a server acquisition module 92, configured to use the above-mentioned dynamic key generation apparatus to acquire a first dynamic key; a server reception module 94, configured to receive, via the server, the encrypted query request sent by the client; a server decryption module 96, configured to use the forward order of the first dynamic key as the first key in the target key rule to decrypt the encrypted query request to obtain the data query request generated by the client.
[0162] It should be noted that the server acquisition module 92 in this embodiment may be configured to execute step S302 in the embodiment of the present application, the server reception module 94 in this embodiment may be configured to execute step S304 in the embodiment of the present application, and the server decryption module 96 in this embodiment may be configured to execute step S306 in the embodiment of the present application. The examples and application scenarios implemented by the above modules and the corresponding steps are the same, but are not limited to the content disclosed in the above embodiments.
[0163] In the above embodiments of the present application, when the server receives the encrypted query request sent by the client, the client can obtain the first dynamic key generated based on the base address, offset, and fixed value. Since the base address and fixed value are preset variables set in advance, and the offset is an update variable updated according to the preset update period, the first dynamic key can be updated by updating the offset. Furthermore, by using the first dynamic key, the first dynamic key for encrypting the data query request can be obtained, and the data query request generated by the client can be encrypted to obtain an encrypted query request that is difficult to be reproduced and decrypted, thereby achieving the technical effect of increasing the difficulty of reproducing and decrypting the encryption and decryption algorithms, and further solving the technical problem that the encryption algorithms in the prior art are easily reproduced and decrypted.
[0164] As an alternative embodiment, the device further includes: a server generation sub-module, configured to generate a data query result by the server in response to the data query request; a server encryption sub-module, configured to use the reverse order of the first dynamic key as the second key in the target key rule to encrypt the data query result to obtain an encrypted query result in response to the encrypted query request.
[0165] As an alternative embodiment, the device further includes: a server reception sub-module, configured to receive the spliced query request sent by the client, where the spliced query request includes: the spliced font file set number key and the encrypted query request. The font file set number key is obtained by converting the target font set number code using a preset encoding conversion rule, and the target font set number code is the preset font set number code corresponding to the target font file randomly selected by the client in the preset font file library. The preset font file library stores a preset number of preset font files and the preset font set number code corresponding to each preset font file in advance; a server splicing sub-module, configured to splice the font file set number key in the spliced query request as the font file set number feedback key with the encrypted query result generated by the server in response to the encrypted query request in the same spliced query request to obtain a spliced query result.
[0166] Embodiments of the present invention can provide an electronic device, which can be a computer terminal, and the computer terminal can be any one of the computer terminal devices in a computer terminal group. Optionally, in this embodiment, the above computer terminal can also be replaced with a terminal device such as a mobile terminal.
[0167] Optionally, in this embodiment, the above computer terminal can be located in at least one of multiple network devices in a computer network.
[0168] In this embodiment, the above computer terminal may execute the program code of the following steps in the method for generating a dynamic key: Obtain an updated base address, offset, and fixed value according to a preset update period, where the base address and the fixed value are preset variables set in advance, and the offset is an update variable updated according to the preset update period; Generate a dynamic termination key based on the base address, offset, and fixed value; According to a preset key conversion rule, convert the dynamic termination key into a first dynamic key, where the first dynamic key is used to encrypt or decrypt data transmitted between the client and the server.
[0169] In this embodiment, the above computer terminal may execute the program code of the following steps in the method for applying a dynamic key: Use the above method for generating a dynamic key to obtain a first dynamic key; Generate a data query request through the client; Use the forward order of the first dynamic key as the first key in the target key rule to encrypt the data query request to obtain an encrypted query request.
[0170] In this embodiment, the above computer terminal may execute the program code of the following steps in the method for applying a dynamic key: Use the above method for generating a dynamic key to obtain a first dynamic key; Receive the encrypted query request sent by the client through the server; Use the forward order of the first dynamic key as the first key in the target key rule to decrypt the encrypted query request to obtain the data query request generated by the client.
[0171] Figure 10 is a structural block diagram of a computer terminal according to an embodiment of the present invention, as Figure 10 shown, the computer terminal 1000 may include: one or more (only one is shown in the figure) processors 1002, and a memory 1004.
[0172] Among them, the memory can be used to store software programs and modules, such as the method and device for generating a dynamic key in the embodiment of the present invention, and the program instructions / modules corresponding to the method and device for applying a dynamic key. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, that is, implements the above methods for generating and applying a dynamic key. The memory may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memories. In some instances, the memory may further include a memory remotely set relative to the processor, and these remote memories can be connected to the terminal 1000 through a network. Examples of the above network include but are not limited to the Internet, enterprise intranets, local area networks, mobile communication networks, and combinations thereof.
[0173] The processor can call the information and application programs stored in the memory through the transmission device to execute the following steps: Obtain the updated base address, offset, and fixed value according to a preset update period, where the base address and fixed value are preset variables set in advance, and the offset is an update variable updated according to the preset update period; Generate a dynamic termination key based on the base address, offset, and fixed value; Convert the dynamic termination key into a first dynamic key according to a preset key conversion rule, where the first dynamic key is used to encrypt or decrypt the data transmitted between the client and the server.
[0174] Optionally, the above-mentioned processor can also execute the program code of the following steps: Determine the sum of the base address and the offset as the intermediate key; Determine the product of the intermediate key and the fixed value as the dynamic termination key.
[0175] Optionally, the above-mentioned processor can also execute the program code of the following steps: Obtain the target font set number encoding randomly determined by the client, where the target font set number encoding is used to indicate the encoding of the corresponding target font file in the preset font file library. The preset font file library stores a preset number of preset font files in advance, and the preset font set number encoding corresponding to each preset font file; Convert the target font set number encoding into a font file set number key that meets the preset length according to a preset encoding conversion rule; Concatenate the font file set number key with the first dynamic key to obtain a second dynamic key.
[0176] Optionally, the above-mentioned processor can also execute the program code of the following steps: Obtain the target font file corresponding to the target font set number encoding from the multiple preset font files recorded in the preset font file library; Extract the conversion rule indicated in the target font file as the preset key conversion rule.
[0177] The processor can call the information and application programs stored in the memory through the transmission device to execute the following steps: Use the above dynamic key generation method to obtain the first dynamic key; Generate a data query request through the client; Encrypt the data query request using the forward order of the first dynamic key as the first key in the target key rule to obtain an encrypted query request.
[0178] Optionally, the above-mentioned processor can also execute the program code of the following steps: Receive the encrypted query result returned by the server through the client, where the server is used to respond to the encrypted query request sent by the client and generate an encrypted query result; Decrypt the encrypted query result using the reverse order of the first dynamic key as the second key in the target key rule to obtain the data query result corresponding to the data query request.
[0179] Optionally, the above-mentioned processor may also execute the program code of the following steps: Obtain the font file set number key randomly determined by the client, where the font file set number key is obtained by converting the target font set number encoding using a preset encoding conversion rule, and the target font set number encoding is the preset font set number encoding corresponding to the target font file randomly selected by the client in the preset font file library. The preset font file library stores a preset number of preset font files in advance, and the preset font set number encoding corresponding to each preset font file; Concatenate the font file set number key with the encrypted query request to obtain a concatenated query request.
[0180] Optionally, the above-mentioned processor may also execute the program code of the following steps: Receive, through the client, the concatenated query result returned by the server, where the concatenated query result includes: the concatenated font file set number feedback key and the encrypted query result. The server is used to respond to the encrypted query request in the concatenated query request, generate the encrypted query result, and use the font file set number key in the concatenated query request responded by the server as the font file set number feedback key for concatenating with the encrypted query result; Perform a consistency comparison between the first set number key and the second set number key, where the first set number key is the font file set number key in the concatenated query request sent by the client, and the second set number key is the font file set number feedback key in the concatenated query result received by the client; When the first set number key and the second set number key are consistent, use the reverse order of the first dynamic key as the second key in the target key rule to decrypt the encrypted query result to obtain the data query result corresponding to the data query request.
[0181] The processor may call the information and application programs stored in the memory through the transmission device to execute the following steps: Use the above-mentioned dynamic key generation method to obtain the first dynamic key; Receive, through the server, the encrypted query request sent by the client; Use the forward order of the first dynamic key as the first key in the target key rule to decrypt the encrypted query request to obtain the data query request generated by the client.
[0182] Optionally, the above-mentioned processor may also execute the program code of the following steps: Generate, through the server in response to the data query request, a data query result; Use the reverse order of the first dynamic key as the second key in the target key rule to encrypt the data query result to obtain the encrypted query result in response to the encrypted query request.
[0183] Optionally, the above-mentioned processor may also execute the program code of the following steps: receiving a splicing query request sent by a client, where the splicing query request includes: a key for the number of font file sets to be spliced and an encrypted query request. The key for the number of font file sets is obtained by converting the target font set number encoding using a preset encoding conversion rule. The target font set number encoding is the preset font set number encoding corresponding to the target font file randomly selected by the client in a preset font file library. The preset font file library pre-stores a preset number of preset font files and the preset font set number encoding corresponding to each preset font file; using the key for the number of font file sets in the splicing query request as the feedback key for the number of font file sets, and splicing it with the encrypted query result generated by the server in response to the encrypted query request in the same splicing query request to obtain a splicing query result.
[0184] Those of ordinary skill in the art can understand that Figure 10 the structure shown is only illustrative, and the computer terminal can also be a smart phone (such as , a tablet computer, a palm computer, and mobile Internet devices (Mobile Internet Devices, MID), PAD and other terminal devices. Figure 10 It does not limit the structure of the above-mentioned electronic device. For example, the computer terminal 1000 may further include more or fewer components (such as a network interface, a display device, etc.) than those shown Figure 10 in the figure, or have a different configuration from that shown Figure 10 in the figure.
[0185] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing the relevant hardware of the terminal device through a computer program. The computer program can be stored in a non-volatile medium, and the non-volatile storage medium can include: a flash drive, a read-only memory (Read-Only Memory, ROM), a random access memory (Random Access Memory, RAM), a magnetic disk or an optical disc, etc.
[0186] An embodiment of the present invention also provides a non-volatile storage medium. Optionally, in this embodiment, the above-mentioned non-volatile storage medium can be used to store the program code executed by the method for generating a dynamic key provided in the above embodiment.
[0187] Optionally, in this embodiment, the above-mentioned non-volatile storage medium can be located in any one of the computer terminals in a computer terminal group in a computer network, or in any one of the mobile terminals in a mobile terminal group.
[0188] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for performing the following steps: obtaining an updated base address, offset, and fixed value according to a preset update period, where the base address and the fixed value are preset variables set in advance, and the offset is an update variable updated according to the preset update period; generating a dynamic termination key based on the base address, offset, and fixed value; and converting the dynamic termination key into a first dynamic key according to a preset key conversion rule, where the first dynamic key is used to encrypt or decrypt data transmitted between the client and the server.
[0189] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for performing the following steps: determining the sum of the base address and the offset as an intermediate key; and determining the product of the intermediate key and the fixed value as the dynamic termination key.
[0190] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for performing the following steps: obtaining a target font set number encoding randomly determined by the client, where the target font set number encoding is used to indicate the encoding of the corresponding target font file in a preset font file library, and the preset font file library pre-stores a preset number of preset font files and the preset font set number encoding corresponding to each preset font file; converting the target font set number encoding into a font file set number key that meets a preset length according to a preset encoding conversion rule; and concatenating the font file set number key with the first dynamic key to obtain a second dynamic key.
[0191] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for performing the following steps: obtaining the target font file corresponding to the target font set number encoding from among the multiple preset font files recorded in the preset font file library; and extracting the conversion rule indicated in the target font file as the preset key conversion rule.
[0192] An embodiment of the present invention further provides a non-volatile storage medium. Optionally, in this embodiment, the above non-volatile storage medium can be used to save the program code executed by the application method of the dynamic key provided in the above embodiment.
[0193] Optionally, in this embodiment, the above non-volatile storage medium can be located in any one of the computer terminals in a computer terminal group in a computer network, or in any one of the mobile terminals in a mobile terminal group.
[0194] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for performing the following steps: obtaining a first dynamic key using the above-mentioned dynamic key generation method; generating a data query request through a client; encrypting the data query request using the forward order of the first dynamic key as the first key in the target key rule to obtain an encrypted query request.
[0195] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for performing the following steps: receiving, through the client, an encrypted query result returned by the server, where the server is used to respond to the encrypted query request sent by the client to generate an encrypted query result; decrypting the encrypted query result using the reverse order of the first dynamic key as the second key in the target key rule to obtain the data query result corresponding to the data query request.
[0196] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for performing the following steps: obtaining a font file set number key randomly determined by the client, where the font file set number key is obtained by converting the target font set number encoding using a preset encoding conversion rule, and the target font set number encoding is the preset font set number encoding corresponding to the target font file randomly selected by the client in a preset font file library, and the preset font file library pre-stores a preset number of preset font files and the preset font set number encoding corresponding to each preset font file; splicing the font file set number key with the encrypted query request to obtain a spliced query request.
[0197] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for performing the following steps: receiving, through the client, a spliced query result returned by the server, where the spliced query result includes: a spliced font file set number feedback key and an encrypted query result, and the server is used to respond to the encrypted query request in the spliced query request to generate an encrypted query result, and use the font file set number key in the spliced query request responded by the server as the font file set number feedback key spliced with the encrypted query result; performing a consistency comparison between a first set number key and a second set number key, where the first set number key is the font file set number key in the spliced query request sent by the client, and the second set number key is the font file set number feedback key in the spliced query result received by the client; in the case where the first set number key and the second set number key are consistent, decrypting the encrypted query result using the reverse order of the first dynamic key as the second key in the target key rule to obtain the data query result corresponding to the data query request.
[0198] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for performing the following steps: obtaining a first dynamic key using the above-described method for generating a dynamic key; receiving, through a server, an encrypted query request sent by a client; and decrypting the encrypted query request using the forward order of the first dynamic key as the first key in the target key rule to obtain a data query request generated by the client.
[0199] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for performing the following steps: generating a data query result by a server in response to a data query request; and encrypting the data query result using the reverse order of the first dynamic key as the second key in the target key rule to obtain an encrypted query result in response to the encrypted query request.
[0200] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for performing the following steps: receiving a concatenated query request sent by a client, where the concatenated query request includes: a concatenated font file set number key and an encrypted query request, the font file set number key is obtained by converting a target font set number code using a preset encoding conversion rule, the target font set number code is a preset font set number code corresponding to a target font file randomly selected by the client in a preset font file library, the preset font file library stores a preset number of preset font files in advance, and a preset font set number code corresponding to each preset font file; and concatenating the font file set number key in the concatenated query request as a font file set number feedback key with the encrypted query result generated by the server in response to the encrypted query request in the same concatenated query request to obtain a concatenated query result.
[0201] An embodiment of the present invention further provides a computer program product, including a computer program. Optionally, in this embodiment, when the computer program is executed by a processor, it implements the steps of the method for generating a dynamic key provided in the above embodiment, or implements the steps of the method for applying a dynamic key provided in the above embodiment.
[0202] The serial numbers of the above embodiments of the present invention are only for description and do not represent the advantages or disadvantages of the embodiments.
[0203] In the above embodiments of the present invention, the descriptions of the respective embodiments have their own emphases. For parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.
[0204] In several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are merely illustrative. For example, the division of the units can be a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the couplings, direct couplings, or communication connections shown or discussed among each other can be through some interfaces. The indirect couplings or communication connections of units or modules can be in electrical or other forms.
[0205] The units described as separate components may or may not be physically separated. The components shown as units may or may not be physical units, that is, they can be located in one place or distributed to multiple units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0206] In addition, in each embodiment of the present invention, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.
[0207] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a non-volatile storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a non-volatile storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present invention. And the aforementioned non-volatile storage medium includes: USB flash drives, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), mobile hard disks, magnetic disks, or optical discs and other various media that can store program codes.
[0208] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.
Claims
1. A method for generating a dynamic key, characterized in that, Including: Obtain the updated base address, offset, and fixed value according to a preset update period, where the base address and the fixed value are preset variables set in advance, and the offset is an update variable updated according to the preset update period; Generate a dynamic termination key based on the base address, the offset, and the fixed value; Convert the dynamic termination key into a first dynamic key according to a preset key conversion rule, where the first dynamic key is used to encrypt or decrypt data transmitted between the client and the server.
2. The method according to claim 1, wherein Generating a dynamic termination key based on the base address, the offset, and the fixed value includes: Determine the sum of the base address and the offset as the intermediate key; Determine the product of the intermediate key and the fixed value as the dynamic termination key.
3. The method according to claim 1, characterized in that, The method further includes: Obtain a target font set number code randomly determined by the client, where the target font set number code is used to indicate the code of the corresponding target font file in a preset font file library, and the preset font file library stores a preset number of preset font files in advance, and a preset font set number code corresponding to each preset font file; Convert the target font set number code into a font file set number key that meets a preset length according to a preset code conversion rule; Concatenate the font file set number key and the first dynamic key to obtain a second dynamic key.
4. The method according to claim 3, wherein After obtaining the target font set number code randomly determined by the client, the method further includes: Obtain the target font file corresponding to the target font set number code from the multiple preset font files recorded in the preset font file library; Extract the conversion rule indicated in the target font file as the preset key conversion rule.
5. A method for applying a dynamic key, characterized in that, Including: Use the dynamic key generation method described in any one of claims 1-4 to obtain the first dynamic key; Generate a data query request through the client; Use the forward order of the first dynamic key as the first key in the target key rule to encrypt the data query request to obtain an encrypted query request.
6. The method according to claim 5, wherein The method further includes: Receive an encrypted query result returned by the server through the client, where the server is used to respond to the encrypted query request sent by the client and generate the encrypted query result; Use the reverse order of the first dynamic key as the second key in the target key rule to decrypt the encrypted query result to obtain the data query result corresponding to the data query request.
7. The method according to claim 5, characterized in that, The method further includes: Obtain the font file set number key randomly determined by the client, where the font file set number key is obtained by converting the target font set number code using a preset code conversion rule, the target font set number code is the preset font set number code corresponding to the target font file randomly selected by the client in the preset font file library, and the preset font file library stores a preset number of preset font files in advance, and the preset font set number code corresponding to each preset font file; Concatenate the font file set number key and the encrypted query request to obtain a concatenated query request.
8. The method according to claim 7, wherein The method further includes: Receive, by the client, the spliced query result returned by the server, where the spliced query result includes: the spliced font file set number feedback key and the encrypted query result, and the server is used to respond to the encrypted query request in the spliced query request, generate the encrypted query result, and use the font file set number key in the spliced query request responded by the server as the font file set number feedback key spliced with the encrypted query result; Perform a consistency comparison between the first set number key and the second set number key, where the first set number key is the font file set number key in the spliced query request sent by the client, and the second set number key is the font file set number feedback key in the spliced query result received by the client; When the first set number key and the second set number key are consistent, use the reverse order of the first dynamic key as the second key in the target key rule to decrypt the encrypted query result to obtain the data query result corresponding to the data query request.
9. A method for applying a dynamic key, characterized in that, Include: Use the dynamic key generation method described in any one of claims 1-4 to obtain the first dynamic key; Receive, by the server, the encrypted query request sent by the client; Use the forward order of the first dynamic key as the first key in the target key rule to decrypt the encrypted query request to obtain the data query request generated by the client.
10. The method according to claim 9, wherein The method further includes: Generate, by the server in response to the data query request, a data query result; Use the reverse order of the first dynamic key as the second key in the target key rule to encrypt the data query result to obtain the encrypted query result in response to the encrypted query request.
11. The method according to claim 10, wherein The method further includes: Receive the spliced query request sent by the client, where the spliced query request includes: the spliced font file set number key and the encrypted query request, the font file set number key is obtained by converting the target font set number code using a preset encoding conversion rule, the target font set number code is the preset font set number code corresponding to the target font file randomly selected by the client in the preset font file library, and the preset font file library pre-stores a preset number of preset font files and the preset font set number code corresponding to each preset font file; Use the font file set number key in the spliced query request as the font file set number feedback key, and splice it with the encrypted query result generated by the server in response to the encrypted query request in the same spliced query request to obtain the spliced query result.
12. A device for generating dynamic keys, characterized in that, Include: An acquisition module, configured to acquire the updated base address, offset, and fixed value according to a preset update period, where the base address and the fixed value are preset variables set in advance, and the offset is an update variable updated according to the preset update period; A generation module, configured to generate a dynamic termination key based on the base address, the offset, and the fixed value; A transformation module, configured to transform the dynamic termination key into a first dynamic key according to a preset key transformation rule, wherein the first dynamic key is used to encrypt or decrypt data transmitted between a client and a server.
13. An application device for a dynamic key, characterized in that, It includes: A client acquisition module, configured to use the dynamic key generation device according to claim 12 to acquire the first dynamic key; A client generation module, configured to generate a data query request through the client; A client encryption module, configured to use the forward order of the first dynamic key as the first key in the target key rule to encrypt the data query request to obtain an encrypted query request.
14. An application device for dynamic keys, characterized in that, It includes: A server acquisition module, configured to use the dynamic key generation device according to claim 12 to acquire the first dynamic key; A server reception module, configured to receive the encrypted query request sent by the client through the server; A server decryption module, configured to use the forward order of the first dynamic key as the first key in the target key rule to decrypt the encrypted query request to obtain the data query request generated by the client.
15. An electronic device, comprising a memory and a processor, characterized in that, A computer program is stored in the memory, and the processor is configured to execute the dynamic key generation method according to any one of claims 1 to 4 or execute the dynamic key application method according to any one of claims 5 to 11 through the computer program.
16. A computer program product, comprising computer instructions, characterized in that, When the computer instructions are executed by the processor, the dynamic key generation method according to any one of claims 1 to 4 is implemented, or the dynamic key application method according to any one of claims 5 to 11 is executed.
Citation Information
Patent Citations
Intelligent device security access method and system
CN106330456A
Dynamic cipher key acquisition method, dynamic cipher key acquisition device, terminal equipment, and storage medium
CN108462686A
Anti-crawler method and device
CN112182603A
File encryption method and device, system platform and file decryption method
CN114329568A
Key variable generator for an encryption / decryption device
US4369332A