Character encryption method, electronic equipment and computer readable medium
Through the dynamic key encryption mechanism and preset data structure, the plaintext prompt words are converted into ciphertext prompt words and decrypted to obtain plaintext response, which solves the data security and efficiency problems of traditional natural language processing systems and achieves high security and efficient human-computer interaction.
Patent Information
- Application Number
- CN202510855009.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-25
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2045-06-25
AI Technical Summary
Traditional natural language processing systems have problems such as high risk of data leakage, high risk of tampering, low processing efficiency and poor data security.
The dynamic key encryption mechanism is adopted, and the original characters are encapsulated into encrypted characters through preset data structures, and the plaintext prompt words are converted into ciphertext prompt words based on the character mapping relationship. After input into the natural language processing system, decryption is obtained to obtain a plaintext response.
Significantly reduce the risks of data leakage and tampering, improve data security, avoid occupying computing resources, improve natural language processing efficiency, and improve user human-computer interaction experience.
Smart Images

Figure CN120358014A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of artificial intelligence technology. Specifically, it relates to a character encryption method, an electronic device, and a computer-readable medium. Background Art
[0002] Natural language processing is an important branch of artificial intelligence (AI) models. One important way of human-computer interaction is to output natural language responses based on the prompt words input by users. In terms of data security, traditional natural language processing systems have many problems such as a high risk of data leakage and tampering, low processing efficiency, and low data security. Summary of the Invention
[0003] This application aims to solve one of the technical problems in the related art to a certain extent. For this purpose, this application provides a character encryption method, an electronic device, and a computer-readable medium.
[0004] As the first aspect of this application, a character encryption method is provided. The method includes: When the key switching condition is met, determine the switched target key group and the target key in the target key group from a pre-constructed key library. The key library includes a first preset number of key groups, and each key group includes a second preset number of keys. Encapsulate the original character according to the target key group, the target key, and the original character to obtain an encrypted character that conforms to a preset data structure. Update the local character mapping table according to the character mapping relationship between the original character and the encrypted character, so that the gateway associated with this device converts the plaintext prompt word sent by the user device into a ciphertext prompt word based on the updated character mapping table. Input the ciphertext prompt word into a natural language processing system encrypted based on the character mapping relationship to obtain the ciphertext response output by the natural language processing system, so that the gateway decrypts the ciphertext response to obtain the plaintext response and sends the plaintext response to the user device.
[0005] Optionally, the step of encapsulating the original character according to the target key group, the target key, and the original character to obtain an encrypted character that conforms to a preset data structure includes: Generate encrypted data bytes according to the target key and the original character. Generate an encrypted data byte length field, an encryption algorithm field, a key group identifier field, and a key identifier field in sequence according to the byte length of the encrypted data byte, the currently used encryption algorithm, the identifier of the target key group, and the identifier of the target key to form control data; wherein, the encrypted character includes the encrypted data byte and the control data.
[0006] Optionally, each field in the control data includes a corresponding preset number of bit positions, and the byte length of the encrypted data byte does not exceed the maximum value that can be represented by the encrypted data byte length field; the byte length of the encrypted data byte includes: (1); In formula (1), represents the byte length of the encrypted data byte, is related to the currently used encryption algorithm, represents the original byte length of the encrypted data, represents the extended byte length, and the value of
[0007] Optionally, updating the character mapping table stored locally according to the character mapping relationship between the original character and the encrypted character includes: For any one of the original characters, replace the character mapped in the locally stored character mapping table with the encrypted character corresponding to it in the character mapping relationship.
[0008] Optionally, the key switching condition includes any one of the following: key life cycle termination condition, security policy update condition, preset policy dynamic adjustment condition, key usage frequency condition, character processing quantity condition, external instruction trigger condition, resource load awareness condition, user behavior pattern condition.
[0009] Optionally, the key life cycle termination condition includes: the expiration of the current key validity period; the key validity period is determined by the following key aging algorithm: (2); In formula (2), represents the current key validity period, represents the current security level and its value is an integer, represents the usage frequency of the current target key, and represents a preset constant.
[0010] Optionally, the security policy update condition includes any one of the following: for in the key aging algorithm, and It has been updated, a geographical location limit for the key has been added, and a quantum-resistant encryption algorithm has been enabled; The dynamic adjustment conditions of the preset policy include: the update in the key aging algorithm results in the update of T.
[0011] Optionally, the key usage frequency condition includes: the usage frequency of the current target key exceeds a preset frequency threshold; The character processing quantity condition includes: a continuous preset number of original characters have been encrypted according to the current target key.
[0012] As a second aspect of the present application, an electronic device is provided, wherein the electronic device includes: One or more processors; A memory, on which one or more computer programs are stored. When the one or more computer programs are executed by the one or more processors, the one or more processors implement the character encryption method according to the first aspect of the present application.
[0013] As a third aspect of the present application, a computer-readable medium is provided, on which a computer program is stored. When the computer program is executed by a processor, it implements the character encryption method according to the first aspect of the present application.
[0014] The character encryption method provided by the present application, by establishing a dynamic key encryption mechanism and presetting a special data structure, obtains encrypted characters that conform to the preset data structure according to the encapsulation of the original characters, and then converts the plaintext prompt words sent by the user device into ciphertext prompt words based on the character mapping relationship between the original characters and the encrypted characters, and provides them to a natural language processing system that can directly process the ciphertext prompt words to obtain the output ciphertext response. Finally, the ciphertext response is decrypted to obtain the plaintext response and fed back to the user device. It can not only significantly reduce the risk of data leakage and tampering and improve data security based on the character-level fine-grained dynamic encryption method, but also avoid occupying the computing resources of the natural language processing system, avoid increasing the inference latency of the natural language processing system, thereby improving the natural language processing efficiency, and also improve the user's human-computer interaction experience. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] The present application will be further described below with reference to the accompanying drawings: Figure 1 is a flowchart of an implementation manner of the character encryption method provided by an embodiment of the present application; Figure 2 is a flowchart of an implementation manner of encapsulating encrypted characters provided by an embodiment of the present application; Figure 3It is a flowchart of an implementation manner for updating a character mapping table stored locally provided by an embodiment of the present application; Figure 4 It is a module diagram of an implementation manner of an electronic device provided by an embodiment of the present application; Figure 5 It is a schematic diagram of a computer-readable medium provided by an embodiment of the present application.
[0016] Description of Reference Numerals 101: Processor 102: Memory 103: I / O Interface 104: Bus Detailed Embodiment The embodiments of the present application will be described in detail below. Examples of the embodiments are shown in the accompanying drawings, where the same or similar reference numerals represent the same or similar elements or elements with the same or similar functions from beginning to end. Based on the embodiments in the implementation manners, it is intended to explain the present application and should not be construed as a limitation to the present application.
[0017] The "one embodiment" or "instance" or "example" cited in this specification means that the specific features, structures or characteristics described in connection with the embodiment itself can be included in at least one embodiment disclosed in the present application. The appearance of the phrase "in one embodiment" at various positions in the specification does not necessarily refer to the same embodiment.
[0018] Natural language processing is an important branch of artificial intelligence (AI) models. One important way of human-computer interaction is to output natural language responses based on the prompt words input by users. Traditional natural language processing systems usually have plaintext input and plaintext output, which have risks of data leakage and being tampered with. There are also some natural language processing systems that adopt a key encryption mechanism to deal with this, but traditional encryption methods require additional computing resources to support real-time encryption, which seriously affects the processing efficiency. Moreover, fixed keys are easily cracked by brute force. In short, in terms of data security, traditional natural language processing systems have many problems such as relatively large risks of data leakage and being tampered with, low processing efficiency, and low data security.
[0019] Based on the above important findings, the applicant of this application has pioneered the establishment of a dynamic key encryption mechanism and a preset special data structure. Encryption characters conforming to the preset data structure are obtained according to the encapsulation of the original characters. Then, based on the character mapping relationship between the original characters and the encryption characters, the plaintext prompt words sent by the user device are converted into ciphertext prompt words and provided to a natural language processing system that can directly process the ciphertext prompt words to obtain the output ciphertext response. Finally, the ciphertext response is decrypted to obtain the plaintext response and fed back to the user device, which can not only significantly reduce the risk of data leakage and tampering and improve data security, but also avoid occupying the computing resources of the natural language processing system and thus improve the efficiency of natural language processing.
[0020] As the first aspect of the embodiments of this application, a character encryption method is provided. As Figure 1 shown, the method includes: Step S110, when the key switching condition is met, determine the switched target key group and the target key located in the target key group from a pre-constructed key library; wherein, the key library includes a first preset number of key groups, and each key group includes a second preset number of keys; Step S120, encapsulate the original characters according to the target key group, the target key, and the original characters to obtain encryption characters conforming to the preset data structure; Step S130, update the locally stored character mapping table according to the character mapping relationship between the original characters and the encryption characters, so that the gateway associated with this device converts the plaintext prompt words sent by the user device into ciphertext prompt words based on the updated character mapping table; Step S140, input the ciphertext prompt words into a natural language processing system encrypted based on the character mapping relationship to obtain the ciphertext response output by the natural language processing system, so that the gateway decrypts the ciphertext response to obtain the plaintext response and sends the plaintext response to the user device.
[0021] Among them, the embodiments of this application do not make specific limitations on the key switching conditions. For example, different key switching conditions with different switching frequencies and different switching times can be specified according to the actual industry scenarios of natural language processing (such as intelligent question answering in the financial field, medical health consultation, enterprise confidential document generation, etc.). The embodiments of this application switch the target key group and the target key based on the key switching conditions, which belongs to the dynamic key encryption mechanism.
[0022] Among them, embodiments of the present application do not specifically limit how to determine the target key group and target key after switching from a pre-constructed key library. For example, it can be determined according to a random selection algorithm, or the target key can be rotated and selected according to the Fibonacci sequence algorithm within the key group. Embodiments of the present application do not specifically limit the random selection algorithm. For example, random sampling, reservoir sampling, stratified sampling, random number generators, etc. can be used.
[0023] Among them, embodiments of the present application first generate a basic key matrix in a secure key generation manner, and then divide the key matrix into a first preset number of key groups according to a grouping strategy. Each key group includes a second preset number of keys, thereby constructing a key library.
[0024] Among them, embodiments of the present application can pre-construct an original character set that supports the Unicode standard (including terms, symbols, etc. in the corresponding industry, and characters can be extended if necessary), and then encrypt and encapsulate each original character in the original character set to obtain the character mapping relationship between each original character and its corresponding encrypted character.
[0025] Among them, embodiments of the present application do not make special limitations on whether all original characters are encrypted and encapsulated using exactly the same target key group and target key. That is to say, different target key groups and target keys can be used to encrypt and encapsulate different original characters. As long as it is ensured that one original character is uniquely mapped to one encrypted character and one encrypted character is also uniquely mapped to one original character. Of course, in order to prevent data ambiguity or security vulnerabilities caused by collisions, it can also be considered to further ensure that the collision probability between different original characters and is less than a certain threshold, such as , so as to ensure that the possibility of different original characters being mapped to the same encrypted character is also extremely low.
[0026] Among them, embodiments of the present application do not specifically limit how to encrypt and obtain a natural language processing system based on the character mapping relationship, as long as the obtained natural language processing system can accurately process the ciphertext prompt words converted based on the character mapping relationship.
[0027] Among them, the embodiments of the present application do not make specific limitations on the natural language processing system. For example, the natural language processing system may include a natural language processing model and its associated text processing module. The embodiments of the present application also do not make specific limitations on the natural language processing model. For example, the natural language processing model may include any one of the following: Large Language Model (LLM), Multimodal Large Language Model (MLLM).
[0028] Among them, the embodiments of the present application do not make special limitations on whether the gateway associated with this device (i.e., the device that executes the character encryption method and loads or installs the natural language processing system) is independent of this device. That is, the gateway may include an independent device installed on the communication link between the user device and this device, or may include a module integrated with the gateway function in this device.
[0029] The gateway converts the plaintext prompt word sent by the user device into a ciphertext prompt word based on the character mapping table updated in real time, then inputs the ciphertext prompt word into the encrypted natural language processing system to obtain the ciphertext response output by the encrypted natural language processing system. Finally, the gateway decrypts the ciphertext response to obtain the plaintext response and sends the plaintext response to the user device. In this way, for the user device, there is no need to encrypt the prompt word, and sending the plaintext prompt word can receive the plaintext response. The human-computer interaction process is transparent and burden-free, which can not only improve data security but also improve the user's human-computer interaction experience.
[0030] The character encryption method provided by the embodiments of the present application establishes a dynamic key encryption mechanism and presets a special data structure, obtains encrypted characters that conform to the preset data structure according to the original characters, and then converts the plaintext prompt word sent by the user device into a ciphertext prompt word based on the character mapping relationship between the original characters and the encrypted characters, and provides it to the natural language processing system that can directly process the ciphertext prompt word to obtain the output ciphertext response. Finally, the ciphertext response is decrypted to obtain the plaintext response and fed back to the user device. It can not only significantly reduce the risk of data leakage and tampering and improve data security based on the character fine-grained dynamic encryption method, but also avoid occupying the computing resources of the natural language processing system, avoid increasing the inference latency of the natural language processing system, thereby improving the natural language processing efficiency, and can also improve the user's human-computer interaction experience.
[0031] The applicant of the present application further proposes to encapsulate the byte length of the encrypted data byte, the currently used encryption algorithm, the identifier of the target key group, and the identifier of the target key as control data (ControlByte) in the encrypted character structure, which can not only significantly improve data security by virtue of the irregular characteristics of the dynamic key encryption mechanism, but also enable the gateway to directly decrypt the ciphertext response output by the natural language processing system, thereby further improving the natural language processing efficiency.
[0032] Correspondingly, in some embodiments, the encapsulating to obtain an encrypted character conforming to a preset data structure according to the target key group, the target key, and the original character (i.e., involved in step S120) is as Figure 2 shown and includes: Step S210, generating an encrypted data byte according to the target key and the original character; Step S220, generating an encrypted data byte length field, an encryption algorithm field, a key group identifier field, and a key identifier field in sequence according to the byte length of the encrypted data byte, the currently used encryption algorithm, the identifier of the target key group, and the identifier of the target key to form control data; wherein, the encrypted character includes the encrypted data byte and the control data.
[0033] Among them, the present application embodiment does not make specific limitations on the encryption algorithm. For example, the Advanced Encryption Standard (AES) algorithm, SMS4 block cipher algorithm, Base64 encoding algorithm, etc. can be used as the encryption algorithm.
[0034] Among them, the present application embodiment is not limited to generating the encryption algorithm field according to the currently used encryption algorithm. For example, the encryption algorithm field can also be generated according to the currently used encryption algorithm and the corresponding encryption mode (such as Counter (CTR), Cipher Block Chaining (CBC), Electronic Codebook (ECB), etc.).
[0035] Among them, the present application embodiment does not make specific limitations on the order between the encrypted data byte and the control data in the encrypted character. That is to say, in the data structure of the encrypted character, the control data can be in the front and the encrypted data byte can be in the back, or the encrypted data byte can be in the front and the control data can be in the back.
[0036] The definable control data structure provided by the present application embodiment can control the length of the control data to a minimum of 1 byte, and can also save storage space and reduce resource consumption.
[0037] Among them, it can be understood that whether the gateway is independent of this device or not, the gateway needs to synchronize information such as the key library, the number of bit positions of each field in the preset data structure, and the specific content indicated by the value of each field with the module that executes the character encryption method of this device. In this way, after the natural language processing system in this device outputs a ciphertext response, the gateway can directly parse out the control data and encrypted data bytes from each encrypted character of the ciphertext response, decrypt the encrypted data bytes according to the content indicated by the control data in the same encrypted character, and finally obtain a plaintext response.
[0038] In some embodiments, each field in the control data includes a corresponding preset number of bit positions, and the byte length of the encrypted data byte does not exceed the maximum value that can be represented by the encrypted data byte length field; the byte length of the encrypted data byte includes: (1); In formula (1), represents the byte length of the encrypted data byte, is related to the currently used encryption algorithm, represents the original byte length of the encrypted data, represents the extended byte length, and the value of is greater than or equal to 1.
[0039] Hereinafter, the number of bit positions included in the encrypted data byte length field and the encryption algorithm field in the control data are respectively represented as N and M, and examples are given to illustrate the information indicated by these two fields: For example, N = 2. If the value of the encrypted data byte length field is "00", it means the byte length of the encrypted data byte is 1; if the value of the encrypted data byte length field is "01", it means the byte length of the encrypted data byte is 2; if the value of the encrypted data byte length field is "10", it means the byte length of the encrypted data byte is 3; if the value of the encrypted data byte length field is "11", it means the byte length of the encrypted data byte is 4.
[0040] For example, M = 4. If the value of the encryption algorithm field is "0000", it means the currently used encryption algorithm and the corresponding encryption mode are SM4 and CTR respectively; if the value of the encryption algorithm field is "0001", it means the currently used encryption algorithm and the corresponding encryption mode are SM4 and CBC respectively; if the value of the encryption algorithm field is "0100", it means the currently used encryption algorithm and the corresponding encryption mode are AES and ECB respectively; if the value of the encryption algorithm field is "1111", it means the currently used encryption algorithms are AES and SM4.
[0041] For another example, when M = 2, if the value of the encryption algorithm field is "00", it indicates that the currently used encryption algorithm and the corresponding encryption mode are SM4 and CTR respectively; if the value of the encryption algorithm field is "01", it indicates that the currently used encryption algorithm and the corresponding encryption mode are SM4 and ECB respectively; if the value of the encryption algorithm field is "10", it indicates that the currently used encryption algorithm and the corresponding encryption mode are AES and CTR respectively; if the value of the encryption algorithm field is "11", it indicates that the currently used encryption algorithm and the corresponding encryption mode are AES and ECB respectively.
[0042] It should be emphasized that the embodiments of the present application are not limited to the number of bits, values, and indicated contents of the above-mentioned example fields. The above is only an exemplary illustration.
[0043] The key group identification field in the control data indicates the key group number of the target key group currently used. The key group number can be infinitely expanded to ensure global uniqueness; the key identification field in the control data indicates the key number of the target key currently used. The key number can be infinitely expanded to ensure global uniqueness.
[0044] In the embodiments of the present application, the character mapping relationship can be dynamically updated (as long as it is ensured that before and after the update, an original character is uniquely mapped to an encrypted character, and an encrypted character is also uniquely mapped to an original character). When the character mapping relationship is updated, the locally stored character mapping table is synchronously updated to ensure that the character mapping table also maintains the latest version in real time. Correspondingly, in some embodiments, updating the locally stored character mapping table according to the character mapping relationship between the original character and the encrypted character (i.e., involved in step S130) is as follows Figure 3 shown, including: Step S310, for any one of the original characters, replace the character mapped by it in the locally stored character mapping table with the encrypted character corresponding to it in the character mapping relationship.
[0045] It can be understood that the locally stored character mapping table records the mapping relationship between all original characters and corresponding encrypted characters. When the encrypted character corresponding to a certain original character changes, it is necessary to update the character mapped by it in the character mapping table.
[0046] It can be understood that the character mapping relationship includes both the forward mapping relationship from the original character to the encrypted character (for example, represented as , 、 respectively representing the encrypted character and the encrypted original character), and the reverse mapping relationship from the encrypted character to the original character (for example, represented as ). Although in the embodiments of the present application, the update of the character mapping table stored locally is based on the forward mapping relationship, the applicant of the present application also proposes that the reverse mapping relationship of each historical version (i.e., the reverse mapping relationship obtained each time step S120 is executed) can be stored. In this way, according to the reverse mapping relationship, the character mapping table stored locally can be rolled back to the version before any key switch. Through this lightweight parameter update mechanism, it is possible to support second-level switching and version rollback, improving disaster tolerance and processing efficiency.
[0047] The applicant of the present application further proposes that the key switch conditions can be formulated based on various factors. Correspondingly, in some embodiments, the key switch conditions include any one of the following: key life cycle termination condition, security policy update condition, preset policy dynamic adjustment condition, key usage frequency condition, character processing quantity condition, external instruction trigger condition, resource load perception condition, user behavior pattern condition.
[0048] Among them, the key life cycle termination condition, security policy update condition, and preset policy dynamic adjustment condition are all related to the key aging algorithm, the key usage frequency condition is related to the key usage frequency, the character processing quantity condition is related to the number of characters continuously processed by a certain key, and the external instruction trigger condition refers to receiving an externally input key switch instruction.
[0049] Correspondingly, in some embodiments, the key life cycle termination condition includes: the expiration of the current key validity period; the key validity period is determined by the following key aging algorithm: (2); In formula (2), represents the current key validity period, represents the current security level and takes an integer value, represents the usage frequency of the current target key, and represent preset constants.
[0050] Among them, it can be understood that "current" in formula (2) refers to when calculating the key validity period based on formula (2).
[0051] Among them, in the embodiments of the present application, the value range of the security level is not specifically limited. For example, the value range of the security level can be [1, 5].
[0052] Correspondingly, in some embodiments, the security policy update condition includes any one of the following: for , and It has been updated, a geographical location limit for the key has been added, and a quantum-resistant encryption algorithm has been enabled; The preset policy dynamic adjustment conditions include: in the key aging algorithm The update of led to the update of T.
[0053] Among them, security policy update refers to the operation of modifying or upgrading the set security rules, parameters or processes according to external environment changes (such as security threat escalation, business requirement adjustment) or internal state changes (such as system resource load, user permission change). Its core goal is to dynamically adapt to new security requirements and ensure that the system is always in the optimal protection state.
[0054] In the embodiment of the present application, the calculation of the key validity period depends on the security level in the key aging algorithm and a preset constant 、 , when the security policy is updated, can be adjusted 、 、 . For example, in a financial transaction scenario, if an abnormal attack behavior is detected, the system can actively increase the security level (for example, from S = 3 to S = 5), thereby shortening the key validity period and enhancing the anti-cracking ability. For the preset constant 、 , it can be adjusted according to industry standards (for example, switching from general data encryption to medical privacy protection). Adjusting a is used to control the sensitivity of the security level, and adjusting b is used to balance the influence of the usage frequency to adapt to the security requirements of different scenarios.
[0055] The embodiment of the present application is not limited to this for the security policy update. The security policy update can also add a geographical location limit (for example, prohibiting access from overseas IPs). At this time, the key can also be switched to restrict the key to take effect only in a specific area. For another example, the security policy update can also force the use of a quantum-resistant encryption algorithm when a quantum computing threat is detected. At this time, the key can also be switched.
[0056] It can be understood that after the security policy is updated, the gateway and this device will automatically synchronize the latest version of the character mapping relationship.
[0057] Through the security policy update, the embodiment of the present application can flexibly respond to new attack means (such as quantum computing, side-channel attack) or compliance requirements (such as GDPR, HIPAA), and avoid security vulnerabilities caused by fixed policies.
[0058] Among them, the preset policy dynamic adjustment means automatically adjusting the preset policy parameters or rules according to the real-time operating status (such as load, performance metrics) or external inputs (such as user instructions, environmental sensor data) to optimize resource utilization efficiency or security. Its characteristics are that no manual intervention is required, and the adjustment process conforms to the predefined logical framework. In the embodiments of the present application, the key aging algorithm adaptively and dynamically adjusts the policy parameters, and the key validity period and the key usage frequency are in a logarithmic relationship, avoiding a sudden drop in the validity period due to high-frequency use (for example, when increasing from 100 times per second to 1000 times per second, the validity period only decreases by log(10) times). This design dynamically adjusts the key life cycle through preset policy to balance security and availability.
[0059] It can be understood that if key conflicts are caused by security policy updates, preset policy dynamic adjustments, etc., the character mapping table in a stable state can be quickly rolled back based on the character reverse mapping relationship of historical versions.
[0060] Correspondingly, in some embodiments, the key usage frequency condition includes: the usage frequency of the current target key exceeds a preset frequency threshold; the character processing quantity condition includes: a continuous preset number of original characters have been encrypted according to the current target key.
[0061] For example, when a continuous N original characters have been encrypted according to the current target key, the target key group is automatically switched, and the target key is rotated and selected according to the Fibonacci sequence algorithm within the switched target key group.
[0062] In addition, the resource load awareness condition and the user behavior pattern condition both belong to the scenario-based policy switching conditions. The resource load awareness condition means that if it is detected that the processor load exceeds the threshold (such as CPU occupancy > 80%), it is dynamically switched to an encryption algorithm with low computational overhead (such as switching from SM4 to ChaCha20), and at the same time, the key validity period is shortened to compensate for the security loss. The user behavior pattern condition means that the key switching frequency is dynamically adjusted according to the key aging length selected by the user input (such as enabling short-term keys during high-frequency interactions of chatbots and using long-term keys for low-frequency tasks such as document generation).
[0063] As the second aspect of the embodiments of the present application, an electronic device is provided, wherein, as Figure 4 shown, the electronic device includes: One or more processors 101; A memory 102 stores one or more computer programs. When the one or more computer programs are executed by the one or more processors 101, the one or more processors 101 implement the character encryption method provided in the first aspect of the embodiments of the present application.
[0064] The electronic device may further include one or more I / O interfaces 103 connected between the processor 101 and the memory 102 and configured to implement information interaction between the processor 101 and the memory 102.
[0065] Among them, the processor 101 is a device with data processing capabilities, including but not limited to a central processing unit (CPU), etc.; the memory 102 is a device with data storage capabilities, including but not limited to a random access memory (RAM, more specifically such as SDRAM, DDR, etc.), a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), a flash memory (FLASH); the I / O interface (read / write interface) is connected between the processor and the memory and can implement information interaction between the processor and the memory, including but not limited to a data bus (Bus), etc.
[0066] In some embodiments, the processor 101, the memory 102, and the I / O interface 103 are interconnected through a bus 104 and further connected to other components of the computing device.
[0067] As the third aspect of the embodiments of the present application, as Figure 5 shown, a computer-readable medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the character encryption method provided in the first aspect of the embodiments of the present application is implemented.
[0068] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. Accordingly, the computer program can be stored in a non-volatile computer-readable storage medium, and when the computer program is executed, the methods of any of the above embodiments can be implemented. Among them, any reference to a memory, storage, database, or other medium used in the embodiments provided in the embodiments of the present application may include non-volatile and / or volatile memories. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory may include random access memory (RAM) or an external cache memory. By way of illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.
[0069] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Those skilled in the art should understand that the present application includes but is not limited to the content described in the drawings and the above specific implementation manner. Any modification that does not deviate from the functional and structural principles of the present application will be included in the scope of the claims.
Claims
1. A character encryption method, characterized in that, The method includes: When the key switching condition is met, determine, from a pre-constructed key library, a target key group after switching and a target key located in the target key group; wherein, the key library includes a first preset number of key groups, and each key group includes a second preset number of keys; Encapsulate, according to the target key group, the target key, and the original characters, to obtain encrypted characters conforming to a preset data structure; Update a locally stored character mapping table according to the character mapping relationship between the original characters and the encrypted characters, so that a gateway associated with this device converts a plaintext prompt word sent by a user device into a ciphertext prompt word based on the updated character mapping table; Input the ciphertext prompt word into a natural language processing system encrypted according to the character mapping relationship, to obtain a ciphertext response output by the natural language processing system, so that the gateway decrypts the characters of the ciphertext response to obtain a plaintext response and sends the plaintext response to the user device.
2. The method according to claim 1, characterized in that, The encapsulating, according to the target key group, the target key, and the original characters, to obtain encrypted characters conforming to a preset data structure includes: Generate encrypted data bytes according to the target key and the original characters; Generate an encrypted data byte length field, an encryption algorithm field, a key group identifier field, and a key identifier field in sequence according to the byte length of the encrypted data bytes, the currently used encryption algorithm, the identifier of the target key group, and the identifier of the target key, to form control data; wherein, the encrypted characters include the encrypted data bytes and the control data.
3. The method according to claim 2, wherein Each field in the control data includes a corresponding preset number of bit positions, and the byte length of the encrypted data bytes does not exceed the maximum value that can be represented by the encrypted data byte length field; the byte length of the encrypted data bytes includes: (1); In formula (1), represents the byte length of the encrypted data bytes, which is related to the currently used encryption algorithm, represents the original byte length of the encrypted data, represents the extended byte length, and the value of is greater than or equal to 1.
4. The method according to claim 1, wherein The updating the locally stored character mapping table according to the character mapping relationship between the original characters and the encrypted characters includes: For any one of the original characters, replace the character mapped by it in the locally stored character mapping table with the encrypted character corresponding to it in the character mapping relationship.
5. The method according to any one of claims 1 to 4, characterized in that The key switching condition includes any one of the following: key life cycle termination condition, security policy update condition, preset policy dynamic adjustment condition, key usage frequency condition, character processing quantity condition, external instruction trigger condition, resource load perception condition, user behavior pattern condition.
6. The method according to claim 5, characterized in that, The key life cycle termination condition includes: the expiration of the current key validity period; the key validity period is determined by the following key aging algorithm: (2); In formula (2), represents the current key validity period, represents the current security level and takes an integer value, represents the usage frequency of the current target key, and represents a preset constant.
7. The method according to claim 6, characterized in that, The security policy update conditions include any of the following: for the , , and in the key aging algorithm have been updated, a key geographical location restriction has been added, or a quantum-resistant encryption algorithm has been enabled; The preset policy dynamic adjustment conditions include: in the key aging algorithm the update of which results in the update of T.
8. The method according to claim 5, wherein The key usage frequency condition includes: the usage frequency of the current target key exceeds a preset frequency threshold; The character processing quantity condition includes: a continuous preset number of original characters have been encrypted according to the current target key.
9. An electronic device, characterized in that, The electronic device includes: One or more processors; A memory storing one or more computer programs, which, when executed by one or more processors, cause the one or more processors to implement the character encryption method according to any one of claims 1-8.
10. A computer-readable medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the character encryption method according to any one of claims 1-8.
Citation Information
Patent Citations
Unconditional security cryptosystem
CN106341230A
Lightweight block cipher discriminator model based on deep learning
CN114567424A
Homomorphic encryption method of deep learning model for natural language processing
CN115987479A
Method and device for digital data blocks encryption and decryption
US20150263858A1
Encryption method
US20200235922A1