Data processing method, device and system based on software hybrid encryption

Through the software hybrid encryption method, combined with symmetric and asymmetric encryption algorithms, asymmetric key pairs are generated and symmetric keys are encrypted, which solves the performance bottlenecks and security risks in the PCIe-to-gigabit Ethernet security system and achieves efficient and secure data transmission.

CN120342778APending Publication Date: 2025-07-18BEIJING URBAN CONSTR INTELLIGENT CONTROL TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510778066.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-11
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

There are performance bottlenecks, security risks and high costs in the existing PCIe to Gigabit Ethernet security systems, which are difficult to meet the needs of data transmission efficiency, security and cost at the same time.

Method used

Using a software hybrid encryption method, combining symmetric encryption and asymmetric encryption algorithms, the secure transmission and encryption of symmetric keys are achieved by generating asymmetric key pairs and encrypting symmetric keys using asymmetric public keys, thereby improving data transmission rate and reducing latency.

Benefits of technology

It significantly improves data transmission rate, reduces system implementation and operation costs, enhances system security, effectively prevents various attacks, and finds a balance between performance and cost.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342778A_ABST
    Figure CN120342778A_ABST
Patent Text Reader

Abstract

The invention provides a data processing method, device and system based on software hybrid encryption, and the method is applied to a data transmitting end, and comprises the steps: determining service message data, and generating an asymmetric key pair according to the service message data, the asymmetric key pair comprising an asymmetric public key and an asymmetric private key; sending the asymmetric public key to a data receiving end, and receiving an encrypted symmetric key encrypted by the data receiving end according to the asymmetric public key; decrypting the encrypted symmetric key according to the asymmetric private key to obtain a symmetric key; and encrypting the service message data according to the symmetric key to obtain encrypted service message data, and sending the encrypted service message data to a data receiving end. According to the application, a hybrid encryption algorithm of two encryption algorithms is fused, the asymmetric RSA secret key with high security is used for encrypting the symmetric key which is easy to crack, and then the symmetric key with relatively high efficiency is used for encrypting the service message data, so that the data transmission rate can be remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and particularly to a data processing method based on software hybrid encryption. This application also relates to a data processing device and system based on software hybrid encryption, a computing device, a computer-readable storage medium, and a computer program product. Background Art

[0002] A PCI Express (PCIe) to Gigabit Ethernet security system based on software hybrid encryption is a comprehensive solution that combines PCIe high-speed transmission technology and the wide connectivity of Gigabit Ethernet, and ensures the security of data transmission through software hybrid encryption technology. This system aims to meet the network environment with high requirements for data transmission rate, connection flexibility, and data security. Using hybrid encryption technology in the PCIe to Gigabit Ethernet security system means combining symmetric encryption and asymmetric encryption algorithms to improve data security and efficiency. The symmetric encryption algorithm uses the same key for encryption and decryption, with high speed and low computational complexity. The asymmetric encryption algorithm uses different keys for encryption and decryption, mainly for key exchange and authentication.

[0003] Currently, the encryption schemes of the PCIe to Gigabit Ethernet security system include hardware encryption cards, software encryption, software hybrid encryption, software and hardware hybrid encryption, etc. In practical applications, the above several encryption schemes have problems such as performance bottlenecks, security risks, and high costs. Therefore, how to improve the data transmission efficiency in the PCIe to Gigabit Ethernet security system, enhance system security, and reduce costs has become an urgent problem for technicians to solve. Summary of the Invention

[0004] In view of this, the embodiments of this application provide a data processing method based on software hybrid encryption. This application also relates to a data processing device and system based on software hybrid encryption, a computing device, a computer-readable storage medium, and a computer program product to solve the above problems existing in the prior art.

[0005] According to the first aspect of the embodiments of this application, a data processing method based on software hybrid encryption is provided, which is applied to a data sending end and includes: Determine service message data, and generate an asymmetric key pair according to the service message data, where the asymmetric key pair includes an asymmetric public key and an asymmetric private key; Send the asymmetric public key to a data receiving end, and receive the encrypted symmetric key encrypted by the data receiving end according to the asymmetric public key; Decrypt the encrypted symmetric key according to the asymmetric private key to obtain a symmetric key; Encrypt the service message data according to the symmetric key to obtain encrypted service message data, and send the encrypted service message data to the data receiving end.

[0006] According to a second aspect of the embodiments of the present application, a data processing method based on software hybrid encryption is provided, which is applied to a data receiving end and includes: Randomly generate a symmetric key, and encrypt the symmetric key with an asymmetric public key to generate an encrypted symmetric key, where the asymmetric public key is generated by a data sending end; Send the encrypted symmetric key to the data sending end, and receive the encrypted service message data generated by the data sending end according to the encrypted symmetric key; Decrypt the encrypted service message data according to the symmetric key to obtain service message data; Execute the service operation corresponding to the service message data.

[0007] According to a third aspect of the embodiments of the present application, a data processing system based on software hybrid encryption is provided. The system includes a data sending end and a data receiving end; The data sending end is configured to generate an asymmetric key pair according to service message data, and send the asymmetric public key in the asymmetric key pair to the data receiving end; The data receiving end is configured to randomly generate a symmetric key, encrypt the symmetric key with the asymmetric public key to obtain an encrypted symmetric key, and send the encrypted symmetric key to the data sending end; The data sending end is further configured to decrypt the encrypted symmetric key with the asymmetric private key in the asymmetric key pair to obtain the symmetric key, encrypt the service message data with the symmetric key to obtain encrypted service message data, and send the encrypted service message data to the data receiving end; The data receiving end is further configured to decrypt the encrypted service message data according to the symmetric key to obtain the service message data.

[0008] According to a fourth aspect of the embodiments of the present application, a data processing device based on software hybrid encryption is provided, which is applied to a data sending end and includes: A key generation module configured to determine service message data and generate an asymmetric key pair according to the service message data, where the asymmetric key pair includes an asymmetric public key and an asymmetric private key; An interaction module configured to send the asymmetric public key to the data receiving end and receive the encrypted symmetric key encrypted by the data receiving end according to the asymmetric public key; A decryption module, configured to decrypt the encrypted symmetric key according to the asymmetric private key to obtain a symmetric key; An encryption module, configured to encrypt the service message data according to the symmetric key to obtain encrypted service message data, and send the encrypted service message data to the data receiving end.

[0009] According to a fifth aspect of the embodiments of the present application, there is provided a computing device, including: A memory and a processor; The memory is used to store computer programs / instructions, and the processor is used to execute the computer programs / instructions. When the computer programs / instructions are executed by the processor, the steps of the above-mentioned data processing method based on software hybrid encryption are implemented.

[0010] According to a sixth aspect of the embodiments of the present application, there is provided a computer-readable storage medium, which stores computer programs / instructions. When the computer programs / instructions are executed by a processor, the steps of the above-mentioned data processing method based on software hybrid encryption are implemented.

[0011] According to a seventh aspect of the embodiments of the present application, there is provided a computer program product, including computer programs / instructions. When the computer programs / instructions are executed by a processor, the steps of the above-mentioned data processing method based on software hybrid encryption are implemented.

[0012] The data processing method based on software hybrid encryption provided by the present application is applied to a data sending end, and includes: determining service message data, and generating an asymmetric key pair according to the service message data, where the asymmetric key pair includes an asymmetric public key and an asymmetric private key; sending the asymmetric public key to the data receiving end, and receiving the encrypted symmetric key encrypted by the data receiving end according to the asymmetric public key; decrypting the encrypted symmetric key according to the asymmetric private key to obtain a symmetric key; encrypting the service message data according to the symmetric key to obtain encrypted service message data, and sending the encrypted service message data to the data receiving end.

[0013] An embodiment of the present application implements a hybrid encryption algorithm that combines two encryption algorithms. The symmetric key that is easy to be cracked is encrypted with the highly secure asymmetric RSA key, and then the service message data is encrypted with the relatively efficient symmetric key, which can significantly improve the data transmission rate and reduce the latency. Compared with the traditional hardware encryption card, the hybrid encryption scheme finds a balance between performance and cost, reduces the costs of system implementation and operation. Through the method of hybrid encryption, the security of the system is also improved, and various attacks can be effectively prevented. Description of the Drawings

[0014] Figure 1It is a flowchart of a data processing method based on software hybrid encryption provided by an embodiment of the present application; Figure 2 It is a flowchart of a data processing method based on software hybrid encryption provided by another embodiment of the present application; Figure 3 It is a schematic structural diagram of a data processing system based on software hybrid encryption provided by an embodiment of the present application; Figure 4 It is an interaction flowchart of a data processing method based on software hybrid encryption provided by an embodiment of the present application; Figure 5 It is a schematic structural diagram of a data processing device based on software hybrid encryption provided by an embodiment of the present application; Figure 6 It is a structural block diagram of a computing device provided by an embodiment of the present application. Detailed implementation manners

[0015] Many specific details are set forth in the following description in order to provide a thorough understanding of the present application. However, the present application can be implemented in many other ways different from those described herein, and those skilled in the art can make similar extensions without departing from the connotation of the present application. Therefore, the present application is not limited by the specific implementations disclosed below.

[0016] The terms used in one or more embodiments of the present application are only for the purpose of describing specific embodiments, and are not intended to limit one or more embodiments of the present application. The singular forms "a", "the", and "said" used in one or more embodiments of the present application and the appended claims are also intended to include the plural forms, unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used in one or more embodiments of the present application refers to and includes any or all possible combinations of one or more of the associated listed items.

[0017] It should be understood that although the terms first, second, etc. may be used in one or more embodiments of the present application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of one or more embodiments of the present application, the first may also be referred to as the second, and similarly, the second may also be referred to as the first. Depending on the context, the word "if" as used herein may be interpreted as "when" or "while" or "in response to determining".

[0018] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data that have been authorized by the user or fully authorized by all parties. Moreover, the collection, use, and processing of relevant data need to comply with the relevant laws, regulations, and standards in the relevant regions, and corresponding operation entrances are provided for users to choose to authorize or refuse.

[0019] First, explain the noun terms involved in one or more embodiments of this application.

[0020] PCI Express: Abbreviated as PCIe, it is a high-speed serial computer expansion bus standard. It uses serial communication and has a higher transmission rate and lower interference compared to traditional parallel buses.

[0021] Symmetric encryption algorithm: Also known as single-key encryption or private-key encryption, it refers to an encryption algorithm that uses the same key for encryption and decryption. In this encryption method, the data sender combines the plaintext and the encryption key and undergoes special encryption processing to generate complex encrypted ciphertext. The data receiver uses the same key to decrypt the encrypted ciphertext and restore it to plaintext. Common symmetric encryption algorithms include DES (Data Encryption Standard), 3DES (Triple Data Encryption Algorithm), AES (Advanced Encryption Standard), etc.

[0022] Asymmetric encryption algorithm: Also known as public-key encryption algorithm, it is an encryption algorithm that uses a pair of public and private keys. The asymmetric encryption algorithm uses a pair of keys for encryption and decryption operations. This pair of keys includes a public key and a private key. The public key can be made available to anyone, while the private key can only be accessed by the holder of the key. The data is encrypted using the public key and then decrypted using the corresponding private key. Since there is a mathematical relationship between the public key and the private key, but one cannot be derived from the other, even if the public key is leaked, the data cannot be decrypted. Common asymmetric encryption algorithms include RSA (Rivest-Shamir-Adleman), ECC (Elliptic Curve Cryptography), DSA (Digital Signature Algorithm).

[0023] The PCI Express (PCIe) to Gigabit Ethernet security system based on software hybrid encryption is an integrated solution that combines the high-speed transmission technology of PCIe and the extensive connectivity of Gigabit Ethernet, and ensures the security of data transmission through software hybrid encryption technology. This system aims to meet the network environment with high requirements for data transmission rate, connection flexibility, and data security. The use of hybrid encryption technology in the PCIe to Gigabit Ethernet security system refers to the combination of symmetric encryption and asymmetric encryption algorithms to improve data security and efficiency. The symmetric encryption algorithm uses the same key for encryption and decryption, with high speed and low computational complexity. The asymmetric encryption algorithm uses different keys for encryption and decryption, mainly for key exchange and authentication.

[0024] The PCI Express (PCIe) to Gigabit Ethernet security system based on software hybrid encryption includes the following key technologies: High-speed data transmission and processing: High-speed data transmission and processing capabilities are required to ensure the real-time nature and efficiency of data.

[0025] Security algorithms and protocols: Support for multiple security algorithms and protocols is needed to adapt to different security requirements and scenarios.

[0026] Reliability and stability: The system needs to have high reliability and stability to ensure the secure transmission of data and the continuous operation of the system.

[0027] Currently, the existing solutions for the PCI Express (PCIe) to Gigabit Ethernet security system based on software hybrid encryption mainly include: Hardware encryption card: Encryption and decryption processing are implemented using dedicated hardware, usually concentrated in the PCIe card. However, dedicated hardware encryption cards usually have a high cost, which will increase the cost of the system.

[0028] Software encryption method: Data is encrypted using software algorithms, usually executed on the CPU of the host. However, in the case of high-speed data transmission, the asymmetric software encryption method will become a performance bottleneck, resulting in a decrease in the data transmission rate.

[0029] Software hybrid encryption method: Combining symmetric encryption algorithm and asymmetric encryption algorithm to improve data security and efficiency. Similarly, in the case of high-speed data transmission, the asymmetric software encryption method will become a performance bottleneck, resulting in a decrease in the data transmission rate. The symmetric encryption algorithm is easily cracked, and there are potential security risks.

[0030] Hardware-software hybrid encryption method: Combining hardware and software, using dedicated hardware to accelerate encryption calculations, and at the same time using software to implement more complex encryption operations. In this method, some hardware encryption cards may be affected by physical attacks or side-channel attacks, and there are potential security risks. Moreover, symmetric encryption algorithms are easily cracked and their security is also unstable.

[0031] Based on this, in this application, a data processing method based on software hybrid encryption is provided. This application also relates to a data processing device, a system, a computing device, a computer-readable storage medium, and a computer program product based on software hybrid encryption, which will be described in detail one by one in the following embodiments.

[0032] Figure 1 The flowchart of a data processing method based on software hybrid encryption provided by an embodiment of this application is shown. This method is applied to the data sending end and specifically includes the following steps: Step 102: Determine the service message data and generate an asymmetric key pair according to the service message data, where the asymmetric key pair includes an asymmetric public key and an asymmetric private key.

[0033] Among them, the service message data can be understood as the message data that needs to be transmitted in the embodiments of this application. In actual applications, in order to ensure data security, the service message data needs to be encrypted during the data transmission process.

[0034] The service message data can be transmitted multiple times according to actual service requirements. The lengths of different service message data are different. In the method provided in the embodiments of this application, an asymmetric key pair needs to be generated according to the service message data. The asymmetric key pair includes an asymmetric public key and an asymmetric private key. It should be noted that in the method provided in the embodiments of this application, an asymmetric encryption algorithm is required to generate the asymmetric key pair, and during the process of generating the asymmetric key pair, it needs to be generated according to the service message data provided in the embodiments of this application. Specifically, the asymmetric key pair is generated according to the length of the service message data.

[0035] Generating an asymmetric key pair according to the service message data can make the generated asymmetric public key and asymmetric private key closer to the actual service situation, generate the asymmetric key pair according to the actual service situation, and flexibly adjust the complexity of generating the asymmetric key pair to make it more adaptable to the data transmission rate.

[0036] In a specific embodiment provided by this application, generating an asymmetric key pair according to the service message data includes: S1022. Determine a preset quantity according to the service message data, and generate an array of data to be processed according to the preset quantity, where the array of data to be processed includes the data to be processed corresponding to the preset quantity.

[0037] In the specific embodiment provided by the present application, in the process of generating an asymmetric key pair according to the service message data, it is necessary to first determine a preset quantity according to the service message data, generate a preset number of data to be processed, and generate an array of data to be processed according to the preset number of data to be processed. Generating an array of data to be processed according to the preset quantity specifically means generating an array of data to be processed, and the array of data to be processed includes a preset number of data to be processed.

[0038] For example, taking the preset quantity determined according to the service message data as 100 as an example, generate an array of data to be processed according to the preset quantity of 100, and the array of data to be processed includes 100 data to be processed; another example, taking the preset quantity determined according to the service message data as 3000 as an example, generate an array of data to be processed according to the preset quantity of 3000, and the array of data to be processed includes 3000 data to be processed.

[0039] Determining the preset quantity according to the service message data specifically means determining the preset quantity according to the length information of the service message data. In a specific embodiment provided by the present application, determining the preset quantity according to the service message data includes: Determine the length range information corresponding to the service message data, and determine the preset quantity according to the length range information.

[0040] Among them, the length range information can be understood as the length interval of the service message data. For example, in the method provided in the embodiment of the present application, the length range of the service message data is 64 bytes - 1518 bytes, that is, in the method provided in the embodiment of the present application, the minimum length of the service message data is 64 bytes, and the maximum is 1518 bytes. In this embodiment, an asymmetric key pair needs to be generated according to the service message data. In the process of generating the asymmetric key pair, two prime numbers P and Q are required. In this embodiment, the prime numbers P and Q are generated according to the length range information of the service message data. In the subsequent processing process, the values of P and Q need to be determined according to the actual length of the service message data. Therefore, the preset quantity is determined according to the length interval of the service message data, and the data to be processed corresponding to the preset quantity is prepared for determining the values of P and Q later.

[0041] In the specific embodiments provided in the present application, the preset quantity is determined according to the formula (maximum value - minimum value + 1) * 2. Taking the length range of service message data as an example of 64 bytes - 1518 bytes for explanation, substituting it into the above formula, the preset quantity can be calculated as 2910. That is, in the embodiments of the present application, 2910 pieces of data to be processed are to be generated to form an array of data to be processed.

[0042] In another specific embodiment provided in the present application, the array of data to be processed is generated through the following steps: Randomly generate data to be processed with a preset number of digits; Determine whether the data to be processed is a prime number; If so, add the data to be processed to the array of data to be processed; If not, delete the data to be processed.

[0043] In the above steps, it can be determined that the data to be processed corresponding to the preset quantity is to be generated, and the array of data to be processed is composed of the preset quantity of arrays of data to be processed. In this embodiment, taking the generation method of one of the data to be processed as an example for explanation, it is illustrated how each piece of data to be processed in the array of data to be processed is generated. In practical applications, the method in this embodiment is executed in parallel multiple times to obtain multiple pieces of data to be processed.

[0044] In this embodiment, according to the actual business requirements, data to be processed with a preset number of digits is generated. For example, the preset number of digits can be 1024 bits, 2048 bits, 2024 bits, etc. The preset number of digits is not limited in the embodiments provided in the present application, as long as an asymmetric key pair can be generated in the subsequent processing.

[0045] When the number of digits is determined, the data to be processed with the preset number of digits is generated through a random number generator. For example, if the preset number of digits is 2024, a random 2024-bit number is generated through the random number generator as the data to be processed.

[0046] Since two large prime numbers are required for processing in the process of generating an asymmetric key pair, in the method provided in the embodiments of the present application, it is also necessary to further determine whether the generated data to be processed is a prime number. Specifically, the Miller-Rabin algorithm can be used to verify whether the data to be processed is a prime number.

[0047] If the generated data to be processed is a prime number, it can be added to the array of data to be processed. If the generated data to be processed is not a prime number, it can be deleted and not used. Repeat the above steps until the number of data to be processed in the array of data to be processed reaches the preset quantity, and at this time, the array of data to be processed can be obtained.

[0048] S1024. Determine the first data to be processed and the second data to be processed in the array of data to be processed according to the service message data.

[0049] After determining the array of data to be processed, the first data to be processed and the second data to be processed can be determined in the array of data to be processed according to the service data message data. Among them, the first data to be processed and the second data to be processed can be understood as a pair of relatively large prime numbers in the RAS algorithm for subsequent encryption and decryption processing. In the method provided in the embodiments of the present application, the first data to be processed and the second data to be processed are determined according to the service message data to be encrypted and transmitted.

[0050] In a specific implementation manner provided in the present application, determining the first data to be processed and the second data to be processed in the array of data to be processed according to the service message data includes: Split the data to be processed corresponding to the preset quantity into a first array of data to be processed and a second array of data to be processed; Determine the first data to be processed in the first array of data to be processed according to the service message data, and determine the second data to be processed in the second array of data to be processed.

[0051] Specifically, the array of data to be processed includes a preset quantity of data to be processed. In this implementation manner, the preset quantity of data to be processed is randomly divided into two groups on average, namely the first array of data to be processed and the second array of data to be processed. Among them, the first array of data to be processed and the second array of data to be processed are used to determine the prime number pair for subsequent encryption and decryption processing.

[0052] Then, determine the first data to be processed in the first array of data to be processed and the second data to be processed in the second array of data to be processed according to the actual length information of the service message data.

[0053] For example, continuing with the above example, taking the array of data to be processed including 2910 data to be processed as an example for explanation, the 2910 data to be processed are randomly divided into a first array of data to be processed and a second array of data to be processed, and each of the first array of data to be processed and the second array of data to be processed has 1455 data to be processed. Determine the first data to be processed and the second data to be processed in the first group of data to be processed and the second group of data to be processed respectively according to the service message data.

[0054] In another specific implementation manner provided in the present application, after randomly dividing the data to be processed into the first array of data to be processed and the second array of data to be processed on average, the data to be processed in the first array of data to be processed and the second array of data to be processed can be sorted in ascending order respectively. This is convenient for dynamically selecting the first data to be processed and the second data to be processed according to the length information of the service message data in the subsequent processing process.

[0055] Specifically, determining the first data to be processed in the first array to be processed and the second data to be processed in the second array according to the service message data includes: Mapping the data length of the service message data to the first array to be processed, and determining the first data to be processed according to the first mapping result; Mapping the data length of the service message data to the second array to be processed, and determining the second data to be processed according to the second mapping result.

[0056] In the method provided in the embodiment of the present application, the first data to be processed and the second data to be processed are determined from the first array to be processed and the second array to be processed through the specific data length of the service message data.

[0057] Specifically, the first array to be processed includes multiple arranged data to be processed. The data length information of the service message data is mapped to the first array to be processed, and the first data to be processed is determined through the data length of the service message data. In practical applications, the minimum number of bits of the service message data is 64 bits. Then, the first data to be processed in the first array is aligned with 64 bits. For example, when the data length of the service message data is 65 bits, the second data to be processed in the first array is selected as the first data to be processed; for another example, when the data length of the service message data is 1518 bits, the 1455th data to be processed in the first array is selected as the first data to be processed.

[0058] Based on the same processing method, the data length of the service message data is mapped to the second array to be processed to obtain the second mapping result, and the second data to be processed is determined in the second array according to the second mapping result. Regarding the mapping method of the service message data in the second array to be processed, refer to the processing method of the first array to be processed, which will not be elaborated here.

[0059] Since all the generated data to be processed in the above steps are prime numbers, the first data to be processed and the second data to be processed determined in this step are also prime numbers.

[0060] S1026. Generate an asymmetric public key and an asymmetric private key according to the first data to be processed and the second data to be processed.

[0061] After the above steps are processed, the first data to be processed and the second data to be processed can be obtained. That is, an asymmetric public key and an asymmetric private key can be generated according to the first data to be processed and the second data to be processed. The process of generating the asymmetric public key and the asymmetric private key according to the first data to be processed and the second data to be processed refers to the RSA encryption algorithm.

[0062] In a specific embodiment provided by the present application, generating an asymmetric public key and an asymmetric private key based on the first data to be processed and the second data to be processed includes: Determining a modulus and an Euler's totient function according to the first data to be processed and the second data to be processed; Determining an encryption exponent and a decryption exponent according to the Euler's totient function; Generating an asymmetric public key according to the modulus and the encryption exponent, and generating an asymmetric private key according to the modulus and the decryption exponent.

[0063] The RSA (Rivest-Shamir-Adleman) encryption algorithm is an asymmetric encryption algorithm, which is widely used in fields such as data transmission, digital signature, and security authentication. In the RSA encryption algorithm, two different large prime numbers P and Q need to be selected first, that is, the first data to be processed and the second data to be processed in the embodiment provided by the present application.

[0064] After determining P and Q, the modulus can be calculated by multiplying the two. Specifically, see the following formula 1: N = P * Q Formula 1 Where N is the modulus, and the modulus is an important part of the subsequent generation of the asymmetric public key and the asymmetric private key.

[0065] After determining the modulus, an Euler's totient function also needs to be generated according to the first data to be processed and the second data to be processed. Specifically, see the following formula 2: φ(N) = (P - 1) * (Q - 1) Formula 2 Where φ(N) is the Euler's totient function, and the Euler's totient function φ(N) represents the number of positive integers less than or equal to N that are relatively prime to N.

[0066] After determining the Euler's totient function, the encryption exponent and the decryption exponent need to be further determined according to the Euler's totient function. Specifically, select an integer E that is relatively prime to the Euler's totient function φ(N) as the encryption exponent. The encryption exponent E is usually selected as a prime number less than φ(N). In the case of determining the encryption exponent E, calculate the modular multiplicative inverse D of E with respect to φ(N) as the decryption exponent. Here, methods such as the extended Euclidean algorithm need to be used to solve it, and the modular multiplicative inverse D satisfies E * D ≡ 1 (mod φ(N)).

[0067] After determining the encryption exponent and the decryption exponent, they can be combined with the modulus respectively to generate an asymmetric public key and an asymmetric private key. Specifically, combine the modulus N and the encryption exponent E to form the asymmetric public key (N, E); combine the modulus N and the decryption exponent D to form the asymmetric private key (N, D).

[0068] Step 104: Send the asymmetric public key to the data receiving end and receive the encrypted symmetric key encrypted by the data receiving end based on the asymmetric public key.

[0069] After the above processing, the asymmetric public key and the asymmetric private key in the asymmetric key can be obtained. That is, the asymmetric public key can be sent to the data receiving end so that the data receiving end can encrypt the symmetric key located at the data receiving end according to the asymmetric public key, and thus an encrypted symmetric key generated by encrypting with the asymmetric public key can be generated at the data receiving end. After the data receiving end generates the encrypted symmetric key, it will also send the encrypted symmetric key to the data sending end. The data sending end can receive the encrypted symmetric key.

[0070] Step 106: Decrypt the encrypted symmetric key according to the asymmetric private key to obtain the symmetric key.

[0071] When the data sending end obtains the encrypted symmetric key, the encrypted symmetric key can be decrypted by the asymmetric private key to generate the symmetric key. In practical applications, the encrypted symmetric key is generated by encrypting the symmetric key with the asymmetric public key. Therefore, the encrypted symmetric key can be decrypted with the asymmetric private key corresponding to the asymmetric public key to generate the symmetric key.

[0072] Step 108: Encrypt the service message data according to the symmetric key to obtain the encrypted service message data, and send the encrypted service message data to the data receiving end.

[0073] After obtaining the symmetric key, the service message data is encrypted with the symmetric key to obtain the encrypted service message data, and then the encrypted service message data is sent to the data receiving end. The symmetric key is also stored in the data receiving end, and the encrypted service message data can be decrypted with the symmetric key to obtain the service message data sent by the data sending end.

[0074] Through the method provided by the embodiments of the present application, the data sending end generates an asymmetric key according to the actual service message data to be transmitted, and sends the asymmetric public key in the asymmetric key to the data receiving end, so that the data receiving end encrypts the symmetric key used for subsequent data encryption with the asymmetric public key. Then decrypt the encrypted symmetric key with the asymmetric private key to obtain the symmetric key, and further encrypt the service message data with the symmetric key. This method combines a hybrid encryption algorithm of two encryption algorithms, uses the highly secure asymmetric RSA key to encrypt the easily cracked symmetric key, and then uses the relatively efficient symmetric key to encrypt the service message data, which can significantly improve the data transmission rate and reduce the latency. Compared with the traditional hardware encryption card, the hybrid encryption scheme finds a balance between performance and cost, reduces the cost of system implementation and operation, and also improves the security of the system through the hybrid encryption method, and can effectively prevent various attacks.

[0075] Figure 2 The flowchart of a data processing method based on software hybrid encryption provided by another embodiment of the present application is shown. This method is applied to the data receiving end and specifically includes the following steps: Step 202: Randomly generate a symmetric key, and encrypt the symmetric key with the asymmetric public key to generate an encrypted symmetric key, where the asymmetric public key is generated by the data sending end.

[0076] In the method provided by the embodiments of the present application, the data receiving end can be understood as a terminal corresponding to the data sending end and receiving the service message data sent by the data sending end. In this embodiment, a symmetric key is randomly generated in the data receiving end. Then encrypt the symmetric key with the asymmetric public key to generate an encrypted symmetric key.

[0077] The asymmetric public key is generated by the data sending end according to the service message data and sent to the data receiving end. In practical applications, the generation of the symmetric key by the data receiving end and the reception of the asymmetric public key do not have a sequence, and the two are executed independently of each other without affecting each other.

[0078] Step 204: Send the encrypted symmetric key to the data sending end, and receive the encrypted service message data generated by the data sending end according to the encrypted symmetric key.

[0079] After the data receiving end generates the encrypted symmetric key, it also needs to send the encrypted symmetric key to the data sending end and receive the encrypted service message data generated by the data sending end according to the encrypted symmetric key. In practical applications, the specific manner of generating the encrypted service message data by the data sending end refers to the description in the above embodiments and will not be elaborated here.

[0080] Step 206: Decrypt the encrypted service message data with the symmetric key to obtain the service message data.

[0081] After receiving the encrypted service message data sent by the data sending end, the symmetric key stored at this end can be used to decrypt the encrypted service message data, so as to obtain the corresponding service message data.

[0082] Step 208: Execute the service operation corresponding to the service message data.

[0083] After obtaining the service message data, the service operation corresponding to the service message data can be executed. In practical applications, after decrypting to obtain the service message data, the service data corresponding to the service message data will be obtained at the chip physical layer of the data receiving end, and then, after being converted into the PCIe bus form, it will communicate with the processor of the data receiving end, and the corresponding service processing operation will be completed by the processor of the data receiving end. For example, upgrade the secure APP under Linux through a secure Ethernet.

[0084] The method provided by the embodiment of the present application integrates a hybrid encryption algorithm of two encryption algorithms, uses the asymmetric RSA key with high security to encrypt the symmetric key that is easy to be cracked, and then uses the symmetric key with high efficiency to encrypt the service message data, which can significantly improve the data transmission rate and reduce the delay. Compared with the traditional hardware encryption card, the hybrid encryption scheme finds a balance between performance and cost, reduces the cost of system implementation and operation, and also improves the security of the system through the hybrid encryption method, and can effectively prevent various attacks.

[0085] Figure 3 FIG. shows a schematic structural diagram of a data processing system based on software hybrid encryption provided by an embodiment of the present application. The system includes a data sending end 302 and a data receiving end 304; The data sending end 302 is configured to generate an asymmetric key pair according to the service message data, and send the asymmetric public key in the asymmetric key pair to the data receiving end; The data receiving end 304 is configured to randomly generate a symmetric key, encrypt the symmetric key through the asymmetric public key, obtain an encrypted symmetric key, and send the encrypted symmetric key to the data sending end; The data sending end 302 is further configured to decrypt the encrypted symmetric key through the asymmetric private key in the asymmetric key pair, obtain the symmetric key, encrypt the service message data through the symmetric key, obtain the encrypted service message data, and send the encrypted service message data to the data receiving end; The data receiving end 304 is further configured to decrypt the encrypted service message data according to the symmetric key to obtain the service message data.

[0086] Through the system provided by the embodiments of the present application, the data sending end generates an asymmetric key according to the actual service message data to be transmitted, and sends the asymmetric public key in the asymmetric key to the data receiving end. The data receiving end encrypts the symmetric key with the asymmetric public key, and then sends the encrypted symmetric key to the data sending end. The data sending end decrypts the encrypted symmetric key with the asymmetric private key to obtain the symmetric key. Then, the service message data is encrypted with the symmetric key, and the encrypted service message data after encryption is sent to the data receiving end, and the data receiving end decrypts it with the symmetric key. This system integrates a hybrid encryption algorithm that combines two encryption algorithms. The symmetric key that is easy to be cracked is encrypted with the highly secure asymmetric RSA key, and then the service message data is encrypted with the relatively efficient symmetric key, which can significantly improve the data transmission rate and reduce the latency. Compared with the traditional hardware encryption card, the hybrid encryption scheme finds a balance between performance and cost, reduces the costs of system implementation and operation, and also improves the security of the system through the hybrid encryption method, and can effectively prevent various attacks.

[0087] Figure 4 FIG. shows an interaction flowchart of a data processing method based on software hybrid encryption according to another embodiment of the present application. This method is applied to a data processing system based on software hybrid encryption, and this system includes a data sending end and a data receiving end; Step 402: The data sending end generates an asymmetric key pair according to the service message data.

[0088] Step 404: The data sending end sends the asymmetric public key in the asymmetric key pair to the data receiving end.

[0089] Step 406: The data receiving end randomly generates a symmetric key, and encrypts the symmetric key with the asymmetric public key to obtain an encrypted symmetric key.

[0090] Step 408: Send the encrypted symmetric key to the data sending end.

[0091] Step 410: The data sending end decrypts the encrypted symmetric key with the asymmetric private key in the asymmetric key pair to obtain the symmetric key.

[0092] Step 412: The data sending end encrypts the service message data with the symmetric key to obtain encrypted service message data.

[0093] Step 414: The data sending end sends the encrypted service message data to the data receiving end.

[0094] Step 416: The data receiving end decrypts the encrypted service message data according to the symmetric key to obtain the service message data.

[0095] Through the method provided by the embodiments of the present application, the data sending end generates an asymmetric key according to the service message data to be actually transmitted, and sends the asymmetric public key in the asymmetric key to the data receiving end. The data receiving end encrypts the symmetric key with the asymmetric public key, and then sends the encrypted symmetric key to the data sending end. The data sending end decrypts the encrypted symmetric key with the asymmetric private key to obtain the symmetric key. Then, the service message data is encrypted with the symmetric key, and the encrypted service message data is sent to the data receiving end, and the data receiving end decrypts it with the symmetric key. This method combines a hybrid encryption algorithm of two encryption algorithms, uses the highly secure asymmetric RSA key to encrypt the easily cracked symmetric key, and then uses the more efficient symmetric key to encrypt the service message data, which can significantly improve the data transmission rate and reduce the latency. Compared with the traditional hardware encryption card, the hybrid encryption scheme finds a balance between performance and cost, reduces the cost of system implementation and operation, and also improves the security of the system through the hybrid encryption method, and can effectively prevent various attacks.

[0096] Corresponding to the above method embodiments, the present application also provides an embodiment of a data processing device based on software hybrid encryption. Figure 5 FIG. shows a schematic structural diagram of a data processing device based on software hybrid encryption provided by an embodiment of the present application. The device is applied to the data sending end, as Figure 5 shown, the device includes: A key generation module 502, configured to determine service message data and generate an asymmetric key pair according to the service message data, where the asymmetric key pair includes an asymmetric public key and an asymmetric private key; An interaction module 504, configured to send the asymmetric public key to the data receiving end and receive the encrypted symmetric key encrypted by the data receiving end according to the asymmetric public key; A decryption module 506, configured to decrypt the encrypted symmetric key according to the asymmetric private key to obtain the symmetric key; An encryption module 508, configured to encrypt the service message data according to the symmetric key to obtain encrypted service message data, and send the encrypted service message data to the data receiving end.

[0097] Optionally, the key generation module 502 is further configured to: Determine a preset quantity according to the service message data, and generate an array of data to be processed according to the preset quantity, where the array of data to be processed includes the data to be processed corresponding to the preset quantity; Determine a first data to be processed and a second data to be processed in the array of data to be processed according to the service message data; Generate an asymmetric public key and an asymmetric private key based on the first data to be processed and the second data to be processed.

[0098] Optionally, the key generation module 502 is further configured to: Split the data to be processed corresponding to the preset quantity into a first array of data to be processed and a second array of data to be processed; Determine the first data to be processed in the first array of data to be processed according to the service message data, and determine the second data to be processed in the second array of data to be processed.

[0099] Optionally, the key generation module 502 is further configured to: Map the data length of the service message data into the first array of data to be processed, and determine the first data to be processed according to the first mapping result; Map the data length of the service message data into the second array of data to be processed, and determine the second data to be processed according to the second mapping result.

[0100] Optionally, the key generation module 502 is further configured to: Determine the modulus and Euler's totient function according to the first data to be processed and the second data to be processed; Determine the encryption exponent and the decryption exponent according to the Euler's totient function; Generate an asymmetric public key according to the modulus and the encryption exponent, and generate an asymmetric private key according to the modulus and the decryption exponent.

[0101] Optionally, the key generation module 502 is further configured to: Determine the length range information corresponding to the service message data, and determine the preset quantity according to the length range information.

[0102] The key generation module 502 is further configured to: Randomly generate data to be processed with a preset number of digits; Determine whether the data to be processed is a prime number; If so, add the data to be processed to the array of data to be processed; If not, delete the data to be processed.

[0103] Through the device provided by the embodiments of the present application, the data sending end generates an asymmetric key according to the actual service message data to be transmitted, and sends the asymmetric public key in the asymmetric key to the data receiving end, so that the data receiving end encrypts the symmetric key used for subsequent data encryption with the asymmetric public key. Then, the encrypted symmetric key is decrypted with the asymmetric private key to obtain the symmetric key. This device integrates a hybrid encryption algorithm that combines two encryption algorithms. The highly secure asymmetric RSA key is used to encrypt the easily cracked symmetric key, and then the more efficient symmetric key is used to encrypt the service message data, which can significantly improve the data transmission rate and reduce latency. Compared with traditional hardware encryption cards, the hybrid encryption scheme finds a balance between performance and cost, reduces the costs of system implementation and operation, and also improves the security of the system through the hybrid encryption method, and can effectively prevent various attacks.

[0104] The above is a schematic solution of a data processing device based on software hybrid encryption according to this embodiment. It should be noted that the technical solution of the data processing device based on software hybrid encryption and the technical solution of the above-mentioned data processing method based on software hybrid encryption belong to the same concept. For the details not described in the technical solution of the data processing device based on software hybrid encryption, reference can be made to the description of the technical solution of the above-mentioned data processing method based on software hybrid encryption.

[0105] Figure 6 The structural block diagram of a computing device 600 provided according to an embodiment of the present application is shown. The components of the computing device 600 include, but are not limited to, a memory 610 and a processor 620. The processor 620 is connected to the memory 610 through a bus 630, and a database 650 is used to store data.

[0106] The computing device 600 also includes an access device 640, which enables the computing device 600 to communicate via one or more networks 660. Examples of such networks include the Public Switched Telephone Network (PSTN), Local Area Network (LAN), Wide Area Network (WAN), Personal Area Network (PAN), or a combination of communication networks such as the Internet. The access device 640 may include one or more of any type of wired or wireless network interfaces (e.g., a network interface controller (NIC)), such as an IEEE 802.11 Wireless Local Area Network (WLAN) wireless interface, a Worldwide Interoperability for Microwave Access (Wi-MAX) interface, an Ethernet interface, a Universal Serial Bus (USB) interface, a cellular network interface, a Bluetooth interface, a Near Field Communication (NFC) interface, and so on.

[0107] In one embodiment of the present application, the above components of the computing device 600 and Figure 6 other components not shown may also be connected to each other, for example, via a bus. It should be understood that Figure 6 the block diagram of the computing device shown is for illustrative purposes only and is not a limitation on the scope of the present application. Those skilled in the art can add or replace other components as needed.

[0108] The computing device 600 can be any type of stationary or mobile computing device, including a mobile computer or mobile computing device (e.g., a tablet computer, a personal digital assistant, a laptop computer, a notebook computer, a netbook, etc.), a mobile phone (e.g., a smartphone), a wearable computing device (e.g., a smartwatch, smart glasses, etc.) or other types of mobile devices, or a stationary computing device such as a desktop computer or a Personal Computer (PC). The computing device 600 can also be a mobile or stationary server.

[0109] Among them, the processor 620 is used to execute the following computer program / instructions, and when the computer program / instructions are executed by the processor, the steps of the above data processing method based on software hybrid encryption are implemented.

[0110] The above is a schematic solution of a computing device according to this embodiment. It should be noted that the technical solution of this computing device and the technical solution of the above data processing method based on software hybrid encryption belong to the same concept. For the details not described in detail in the technical solution of the computing device, reference can be made to the description of the technical solution of the above data processing method based on software hybrid encryption.

[0111] An embodiment of this specification also provides a computer-readable storage medium, which stores computer programs / instructions. When the computer programs / instructions are executed by a processor, the steps of the above data processing method based on software hybrid encryption are implemented.

[0112] The above is a schematic solution of a computer-readable storage medium according to this embodiment. It should be noted that the technical solution of this storage medium and the technical solution of the above data processing method based on software hybrid encryption belong to the same concept. For the details not described in detail in the technical solution of the storage medium, reference can be made to the description of the technical solution of the above data processing method based on software hybrid encryption.

[0113] An embodiment of this specification also provides a computer program product, including computer programs / instructions. When the computer programs / instructions are executed by a processor, the steps of the above data processing method based on software hybrid encryption are implemented.

[0114] The above is a schematic solution of a computer program product according to this embodiment. It should be noted that the technical solution of this computer program product and the technical solution of the above data processing method based on software hybrid encryption belong to the same concept. For the details not described in detail in the technical solution of the computer program product, reference can be made to the description of the technical solution of the above data processing method based on software hybrid encryption.

[0115] The above describes specific embodiments of this application. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be executed in a different order than in the embodiments and still achieve the desired results. Additionally, the processes depicted in the figures do not necessarily require the particular order or sequential order shown to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0116] The computer instructions include computer program code, which may be in the form of source code, object code, executable files or some intermediate forms, etc. The computer-readable medium may include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc. It should be noted that the content included in the computer-readable medium can be appropriately increased or decreased according to the requirements of patent practice. For example, in some regions, according to patent practice, the computer-readable medium does not include electrical carrier signals and telecommunication signals.

[0117] It should be noted that for the foregoing method embodiments, for the sake of simplicity of description, they are all expressed as a series of action combinations. However, those skilled in the art should know that this application is not limited by the described action sequence, because according to this application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to this application.

[0118] In the above embodiments, the descriptions of the respective embodiments have their own emphases. For the parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0119] The preferred embodiments of the present application disclosed above are only used to help explain the present application. The alternative embodiments do not elaborate all the details and do not limit the invention to the specific embodiments described. Obviously, many modifications and variations can be made according to the content of this application. The present application selects and specifically describes these embodiments to better explain the principle and practical application of the present application, so that those skilled in the art can understand and utilize the present application well. The present application is only limited by the claims and their full scope and equivalents.

Claims

1. A data processing method based on software hybrid encryption, characterized in that, Applied to the data sending end, including: Determine the service message data, and generate an asymmetric key pair according to the service message data, where the asymmetric key pair includes an asymmetric public key and an asymmetric private key; Send the asymmetric public key to the data receiving end, and receive the encrypted symmetric key encrypted by the data receiving end according to the asymmetric public key; Decrypt the encrypted symmetric key according to the asymmetric private key to obtain the symmetric key; Encrypt the service message data according to the symmetric key to obtain the encrypted service message data, and send the encrypted service message data to the data receiving end.

2. The method according to claim 1, characterized in that, Generating an asymmetric key pair according to the service message data includes: Determine a preset quantity according to the service message data, and generate an array of data to be processed according to the preset quantity, where the array of data to be processed includes the data to be processed corresponding to the preset quantity; Determine the first data to be processed and the second data to be processed in the array of data to be processed according to the service message data; Generate an asymmetric public key and an asymmetric private key according to the first data to be processed and the second data to be processed.

3. The method according to claim 2, wherein Determining the first data to be processed and the second data to be processed in the array of data to be processed according to the service message data includes: Split the data to be processed corresponding to the preset quantity into a first array of data to be processed and a second array of data to be processed; Determine the first data to be processed in the first array of data to be processed according to the service message data, and determine the second data to be processed in the second array of data to be processed.

4. The method according to claim 3, wherein Determining the first data to be processed and the second data to be processed in the first array of data to be processed according to the service message data, and determining the second data to be processed in the second array of data to be processed includes: Map the data length of the service message data to the first array of data to be processed, and determine the first data to be processed according to the first mapping result; Map the data length of the service message data to the second array of data to be processed, and determine the second data to be processed according to the second mapping result.

5. The method according to claim 2, wherein Generating an asymmetric public key and an asymmetric private key according to the first data to be processed and the second data to be processed includes: Determine the modulus and the Euler's totient function according to the first data to be processed and the second data to be processed; Determine the encryption exponent and the decryption exponent according to the Euler's totient function; Generate an asymmetric public key according to the modulus and the encryption exponent, and generate an asymmetric private key according to the modulus and the decryption exponent.

6. The method according to claim 2, wherein Determining a preset quantity according to the service message data includes: Determine the length range information corresponding to the service message data, and determine the preset quantity according to the length range information.

7. The method according to claim 2, wherein The array of data to be processed is generated through the following steps: Randomly generate data to be processed with a preset number of digits; Judge whether the data to be processed is a prime number; If so, add the data to be processed to the array of data to be processed; If not, delete the data to be processed.

8. A data processing method based on software hybrid encryption, characterized in that, Applied to the data receiving end, including: Randomly generate a symmetric key, and encrypt the symmetric key with the asymmetric public key to generate an encrypted symmetric key, where the asymmetric public key is generated by the data sending end; Send the encrypted symmetric key to the data sender, and receive the encrypted service message data generated by the data sender according to the encrypted symmetric key; Decrypt the encrypted service message data according to the symmetric key to obtain the service message data; Execute the service operation corresponding to the service message data.

9. A data processing system based on software hybrid encryption, characterized in that, The system includes a data sender and a data receiver; The data sender is configured to generate an asymmetric key pair according to the service message data, and send the asymmetric public key in the asymmetric key pair to the data receiver; The data receiver is configured to randomly generate a symmetric key, encrypt the symmetric key with the asymmetric public key to obtain an encrypted symmetric key, and send the encrypted symmetric key to the data sender; The data sender is further configured to decrypt the encrypted symmetric key with the asymmetric private key in the asymmetric key pair to obtain the symmetric key, encrypt the service message data with the symmetric key to obtain the encrypted service message data, and send the encrypted service message data to the data receiver; The data receiver is further configured to decrypt the encrypted service message data according to the symmetric key to obtain the service message data.

10. A data processing device based on software hybrid encryption, characterized in that, Applied to the data sender, it includes: A key generation module configured to determine service message data and generate an asymmetric key pair according to the service message data, where the asymmetric key pair includes an asymmetric public key and an asymmetric private key; An interaction module configured to send the asymmetric public key to the data receiver and receive the encrypted symmetric key encrypted by the data receiver according to the asymmetric public key; A decryption module configured to decrypt the encrypted symmetric key according to the asymmetric private key to obtain the symmetric key; An encryption module configured to encrypt the service message data according to the symmetric key to obtain the encrypted service message data, and send the encrypted service message data to the data receiver.

11. A computing device, characterized in that, It includes: A memory and a processor; The memory is used to store computer programs / instructions, and the processor is used to execute the computer programs / instructions. When the computer programs / instructions are executed by the processor, the steps of the method according to any one of claims 1 to 8 are implemented.

12. A computer-readable storage medium storing a computer program / instructions, characterized in that, When the computer programs / instructions are executed by the processor, the steps of the method according to any one of claims 1 to 8 are implemented.

13. A computer program product, comprising a computer program / instructions, characterized in that, When the computer programs / instructions are executed by the processor, the steps of the method according to any one of claims 1 to 8 are implemented.

Citation Information

Cited By

  • End-to-end network audio stream encryption transmission method and device, equipment and medium

    CN122001663A