Encryption method and device suitable for large file, computer equipment and storage medium

By dividing large files into sub-data blocks and generating unique sub-data keys, encrypting and merging verification chain values, the key leakage and memory overflow problems in traditional large file encryption methods are solved, and security and efficiency are improved.

CN120358101AActive Publication Date: 2025-07-22ASPIRE TECH (SHENZHEN) LTD

Patent Information

Application Number
CN202510848792.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-24
Publication Date
2025-07-22
Estimated Expiration
2045-06-24

AI Technical Summary

Technical Problem

Traditional large file encryption methods have inter-block correlations that lead to the risk of key leakage, lack of integrity verification mechanisms and memory overflow problems, making it difficult to meet the needs of secure storage and transmission.

Method used

The large file is divided into sub-data blocks, a unique sub-data key is generated and encrypted, and the ciphertext is generated by combining the verification chain value. Dynamic sub-key and multi-dimensional encryption algorithm are used to realize block processing and integrity verification.

Benefits of technology

Effectively cut off the association between blocks, reduce the risk of key leakage, improve encryption strength and processing efficiency, and ensure safe storage and transmission of large files.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120358101A_ABST
    Figure CN120358101A_ABST
Patent Text Reader

Abstract

The invention discloses an encryption method and device suitable for a large file, computer equipment and a medium, and the method comprises the steps: segmenting a to-be-encrypted large file into a plurality of sub-data blocks according to a preset rule, and coding each sub-data block to obtain an index value of each sub-data block; generating a master key, and generating a sub-data key corresponding to each sub-data block based on the index value of each sub-data block and the master key; based on the sub-data key corresponding to each sub-data block, performing encryption processing on each sub-data block to obtain a plurality of encrypted sub-data blocks; obtaining a check chain value of the to-be-encrypted large file based on each encrypted sub-data block; and merging the plurality of encrypted sub-data blocks and the check chain value to obtain a ciphertext of the to-be-encrypted large file. According to the method, association between blocks can be effectively cut off, the key leakage risk can be effectively reduced, the encryption strength is enhanced through the dynamic sub-keys, memory overflow is avoided through block processing, the security, reliability and processing efficiency of large file encryption are improved, and the requirements of large file secure storage and transmission are met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of encryption technology, and in particular to an encryption method, device, computer device and storage medium applicable to large files. Background Art

[0002] In the digital age, the application scenarios of large files such as video materials, industrial data, backup images, etc. are becoming more and more extensive, and their requirements for secure storage and transmission are becoming more and more urgent with the explosive growth of data volume. However, traditional encryption methods applicable to large files have many defects and are difficult to meet the security requirements.

[0003] In the traditional simple block encryption mode, due to the correlation between blocks, attackers may use this feature to carry out attacks, leading to the risk of key leakage. At the same time, lacking an effective integrity verification mechanism, if a large file is tampered with during transmission or storage, the system cannot detect it in time, which may result in the use of incorrect data and cause losses to the data owner. Moreover, in the traditional solution, each block is encrypted with the same key. Once this key is cracked, all block ciphertexts will face the risk of leakage, and the security is weak. In addition, traditional encryption methods need to load large files into memory for encryption operations at one time. When the file size exceeds the system physical memory capacity, it is very easy to cause the system to crash and the encryption process to be interrupted, which not only affects work efficiency but also may cause data loss or damage. Summary of the Invention

[0004] Based on this, it is necessary to provide an encryption method, device, computer device and storage medium applicable to large files for the above technical problems to solve at least one of the above existing technical problems.

[0005] In a first aspect, an encryption method applicable to large files is provided, including: Dividing the large file to be encrypted into multiple sub-data blocks according to a preset rule, and encoding each sub-data block to obtain an index value of each sub-data block; Generating a master key, and generating a sub-data key corresponding to each sub-data block based on the index value of each sub-data block and the master key; Based on the sub-data key corresponding to each sub-data block, performing an encryption process on each sub-data block to obtain multiple encrypted sub-data blocks; Based on each encrypted sub-data block, obtaining a check chain value of the large file to be encrypted; Combining the multiple encrypted sub-data blocks and the check chain value to generate the ciphertext of the large file to be encrypted.

[0006] In an embodiment of the present application, the generating a sub-data key corresponding to each sub-data block based on the index value of each sub-data block and the master key includes: Calculate the remainder of each sub-data block index value divided by a preset value respectively; Based on the remainder, adopt the corresponding encryption algorithm, and generate a sub-data key corresponding to the corresponding sub-data block through the index value of the corresponding sub-data block and the main key, wherein different remainders adopt different encryption algorithms.

[0007] In an embodiment of the present application, the obtaining the check chain value of the large file to be encrypted based on each encrypted sub-data block includes: Calculate the hash value corresponding to each encrypted sub-data block; Based on the hash values corresponding to each encrypted sub-data block, calculate the check chain value of the large file to be encrypted.

[0008] In an embodiment of the present application, the merging the multiple encrypted sub-data blocks and the check chain value to generate the ciphertext of the large file to be encrypted includes: Splice the multiple encrypted sub-data blocks in sequence according to the index value; Splice the spliced encrypted sub-data blocks with the check chain value to obtain the ciphertext of the large file to be encrypted.

[0009] In an embodiment of the present application, the dividing the large file to be encrypted into multiple sub-data blocks according to a preset rule includes: Based on the actual size of the large file to be encrypted, determine a preset block size; Divide the large file to be encrypted into multiple sub-data blocks of the preset block size; If there are non-standard sub-data blocks smaller than the preset block size in the sub-data blocks, fill the non-standard sub-data blocks with corresponding bytes.

[0010] In an embodiment of the present application, the check chain value includes a first main check chain value and a first secondary check chain value. After merging the multiple encrypted sub-data blocks and the check chain value to generate the ciphertext of the large file to be encrypted, it includes: Based on the ciphertext of the large file to be encrypted, obtain each encrypted sub-data block; Calculate the hash value corresponding to each encrypted sub-data block respectively; Based on the hash values corresponding to each encrypted sub-data block, and the main hash algorithm, calculate the second main check chain value of the large file to be encrypted; Based on the hash values corresponding to each encrypted sub-data block, and the secondary hash algorithm, calculate the second secondary check chain value of the large file to be encrypted; Compare the first main check chain value with the second main check chain value, and compare the first secondary check chain value with the second secondary check chain value; If any comparison fails, it means that the data has been tampered with or damaged.

[0011] In one embodiment of the present application, the first main verification chain and the first secondary verification chain are dynamically switched based on a time period or a file type.

[0012] In a second aspect, an encryption device applicable to large files is provided, including: An index value generation unit, configured to divide a large file to be encrypted into multiple sub-data blocks according to a preset rule, and encode each sub-data block to obtain an index value of each sub-data block; A sub-data key generation unit, configured to generate a main key, and generate a sub-data key corresponding to each sub-data block based on the index value of each sub-data block and the main key; An encrypted sub-data block generation unit, configured to perform an encryption process on each sub-data block based on the sub-data key corresponding to each sub-data block to obtain a plurality of encrypted sub-data blocks; A verification chain value generation unit, configured to obtain a verification chain value of the large file to be encrypted based on each encrypted sub-data block; A ciphertext generation unit, configured to combine the plurality of encrypted sub-data blocks and the verification chain value to generate a ciphertext of the large file to be encrypted.

[0013] In a third aspect, a computer device is provided, including a memory, a processor, and computer-readable instructions stored in the memory and executable on the processor. When the processor executes the computer-readable instructions, the steps of the encryption method applicable to large files as described above are implemented.

[0014] In a fourth aspect, a readable storage medium is provided. The readable storage medium stores computer-readable instructions, and when the computer-readable instructions are executed by a processor, the steps of the encryption method applicable to large files as described above are implemented.

[0015] The above encryption method, device, computer equipment and storage medium applicable to large files, the implementation of the method includes: splitting the large file to be encrypted into multiple sub-data blocks according to a preset rule, and encoding each sub-data block to obtain the index value of each sub-data block; generating a main key, and generating a sub-data key corresponding to each sub-data block based on the index value of each sub-data block and the main key; encrypting each sub-data block based on the sub-data key corresponding to each sub-data block to obtain multiple encrypted sub-data blocks; obtaining a check chain value of the large file to be encrypted based on each encrypted sub-data block; merging the multiple encrypted sub-data blocks and the check chain value to generate the ciphertext of the large file to be encrypted. In the embodiment of the present application, by splitting the large file to be encrypted into sub-data blocks according to a preset rule and encoding, a unique sub-key is generated for each sub-block based on the main key and the sub-data block index value for encryption, and at the same time, a check chain value is generated based on the encrypted sub-data blocks, and finally, the encrypted sub-data blocks and the check chain value are merged to obtain the ciphertext. It can effectively cut off the association between blocks, reduce the risk of key leakage, enhance the encryption strength with dynamic sub-keys, avoid memory overflow by block processing, comprehensively improve the security, reliability and processing efficiency of large file encryption, and meet the urgent needs of secure storage and transmission of large files. Description of the Drawings

[0016] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for the description of the embodiments of the present application will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0017] Figure 1 is a flowchart of an encryption method applicable to large files in an embodiment of the present application; Figure 2 is a structural diagram of an encryption device applicable to large files in an embodiment of the present application; Figure 3 is a schematic diagram of a computer device in an embodiment of the present application. Detailed Embodiments

[0018] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are some, but not all, of the embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the protection scope of the present application.

[0019] In one embodiment, as Figure 1 shown, an encryption method applicable to large files is provided, including the following steps: In step S110, the large file to be encrypted is divided into multiple sub-data blocks according to a preset rule, and each sub-data block is encoded to obtain the index value of each sub-data block; Among them, the large file to be encrypted File refers to files with a relatively large amount of data such as video materials, industrial data, backup images, etc.

[0020] Optionally, the large file to be encrypted File can be block-processed by a fixed-size block strategy or a dynamic-size block strategy. The fixed-size block strategy means that the large file to be encrypted is cut according to a fixed size such as 1MB, 4MB, or 16MB to obtain data blocks of the same size. The dynamic-size block strategy means that block division can be performed based on file content features, such as key frames of a video, paragraphs of text, etc., and the size of each obtained data block can be different. In addition, the fixed-size block strategy or the dynamic-size block strategy can also be selected for block processing according to the type of the file. For example, for video files, the fixed-size block strategy can be adopted, and for database files, the dynamic-size block strategy can be adopted.

[0021] It should be noted that if the fixed-size block strategy is used to block-process the large file to be encrypted, the size of each sub-data block after division can be detected, and the sub-data blocks smaller than the fixed size, such as 1MB, are filled to ensure the integrity of the block division. When filling, fixed bytes, such as 0x80, can be used for filling, or alternatively, random bytes (such as random bytes generated by a cryptographically secure random number generator) can also be used for filling. After the filling is completed, the hash value of the filled sub-data block can be calculated and embedded in the ciphertext of the large file to be encrypted. During decryption, the hash value can be recalculated and compared with the originally calculated hash value. If the comparison is consistent, it means that the data has not been tampered with, so as to prevent attackers from maliciously modifying the filled content and ensure data integrity.

[0022] In addition, when dividing, if the division is paused due to an abnormal event, the current division position can be recorded. When the division continues, the division can continue based on the recorded current division position without having to start the division again. And when the large file to be encrypted is incrementally updated, only the incrementally updated content needs to be re-blocked, and the block division results of the unmodified blocks do not need to be re-divided.

[0023] Optionally, after the division is completed, multiple sub-data blocks can be obtained, and then each sub-data block can be encoded according to a preset encoding rule to obtain the index value of each sub-data block. This index value can be understood as the unique digital fingerprint of each sub-data block, and different data blocks have different index values. This index value can be determined according to the position of the data block. For example, the block sequence number can be directly used, such as Values (1, 2, …, n) are used as index values, or a preset algorithm such as SHA-256, BLAKE3, etc. can be used to calculate the index value of each sub-data block. For example, the index value = SHA-256(sub-data block content), or the index value can also be calculated by combining the block serial number and the sub-data block content, such as the index value = SHA-256(block serial number || sub-data block content). In this way, even if the sub-data block contents are the same, due to different block serial numbers, their index values are different.

[0024] In step S120, a master key is generated, and based on the index values of the respective sub-data blocks and the master key, sub-data keys corresponding to the respective sub-data blocks are generated; Among them, the master key (MK) is the core trust foundation of the large file encryption system, and its security directly affects the effectiveness of the entire encryption system. Therefore, a random generation mechanism is adopted to ensure its high unpredictability. When randomly generating the master key, a true random number generator (TRNG) is usually used to obtain unpredictable random bits through physical entropy sources such as hardware circuit thermal noise and quantum tunneling effects, or software entropy sources such as system keyboard keystroke times and disk I / O delays, and after strict entropy value evaluation and verification, a key that meets the security strength requirements is generated, such as 128 bits or 256 bits. At the same time, to further enhance security, a salt value (such as a 16-byte random number) is also introduced, and the key derivation process is optimized through a key derivation function (KDF) and an iteration mechanism. The key derivation function (KDF) can include salt (salt value), c (number of iterations), hash function (used hash function, such as HMAC-SM3), and length (the length of the key hoped to be derived), and finally the derived key key can be output. In addition, the master key can be rotated regularly to ensure the security of the master key throughout the processes of generation, use, and storage.

[0025] Optionally, when the master key MK and the index value are obtained, the master key MK and the index value can be mapped to the key of the sub-data block through a key derivation function (KDF), and each sub-data block corresponds to a unique sub-key, ensuring that the leakage of a single block key does not affect other blocks.

[0026] Among them, the sub-data block key can be calculated through the following formula: ; Among them, represents the master key, represents the index value, represents the key derivation function.

[0027] In step S130, based on the sub-data keys corresponding to the respective sub-data blocks, the respective sub-data blocks are encrypted to obtain a plurality of encrypted sub-data blocks; Optionally, for each sub-data block perform block-by-block encryption using the corresponding encryption algorithm alg, such as 3DES algorithm, SM4 algorithm, AES algorithm, etc., to obtain the corresponding ciphertext , and during the encryption process, output the ciphertext stream in real time to avoid caching the entire large file data.

[0028] It should be noted that different sub-data blocks can use different encryption algorithms. Different encryption algorithms can be assigned to different blocks according to the index value of the sub-data block. By using different encryption algorithms for different sub-data blocks, data security and processing efficiency can be improved from multiple dimensions. Moreover, it can disperse the risk of a single algorithm being cracked, resist targeted attacks, and dynamically adjust the encryption strategy according to the data sensitivity level to improve security.

[0029] In step S140, based on each encrypted sub-data block, obtain the checksum chain value of the large file to be encrypted; Optionally, first, a preset hash algorithm, such as SM3, SHA-256, BLAKE3, etc., can be used to calculate the hash value of each encrypted sub-data block , and the hash calculation needs to cover all the content of the encrypted sub-data block (including ciphertext data, authentication tag, and initialization vector). Then, after obtaining the hash values of all encrypted blocks, concatenate them into a checksum chain value according to the rules. For example, a chained hash structure or a Merkle tree structure: The chained structure means starting from the hash of the first ciphertext block, and each subsequent node is the cascade and re-hash of the hash of the previous node and the current block hash, finally forming a root hash; the Merkle tree groups the ciphertext block hashes in layers, calculates layer by layer upward, and finally obtains a unique root hash. Thus, the checksum chain value is obtained.

[0030] In step S150, merge the multiple encrypted sub-data blocks and the checksum chain value to generate the ciphertext of the large file to be encrypted.

[0031] Optionally, merge the multiple encrypted sub-data blocks and the checksum chain value h into complete ciphertext data, then the ciphertext data after encrypting the large file File to be encrypted can be obtained. Specifically , and then, the ciphertext stream of the large file can be output to avoid caching the entire file.

[0032] An embodiment of the present application provides an encryption method applicable to large files, including: splitting a large file to be encrypted into multiple sub-data blocks according to a preset rule, and encoding each sub-data block to obtain an index value of each sub-data block; generating a main key, and generating a sub-data key corresponding to each sub-data block based on the index value of each sub-data block and the main key; encrypting each sub-data block based on the sub-data key corresponding to each sub-data block to obtain multiple encrypted sub-data blocks; obtaining a check chain value of the large file to be encrypted based on each encrypted sub-data block; and merging the multiple encrypted sub-data blocks and the check chain value to generate a ciphertext of the large file to be encrypted. In the embodiment of the present application, by splitting the large file to be encrypted into sub-data blocks and encoding them according to a preset rule, a unique sub-key is generated for each sub-block based on the main key and the sub-data block index value for encryption. At the same time, a check chain value is generated based on the encrypted sub-data blocks, and finally the encrypted sub-data blocks and the check chain value are merged to obtain the ciphertext. It can effectively cut off the association between blocks, reduce the risk of key leakage, enhance the encryption strength with dynamic sub-keys, avoid memory overflow through block-by-block processing, comprehensively improve the security, reliability and processing efficiency of large file encryption, and meet the urgent needs of secure storage and transmission of large files.

[0033] In an embodiment of the present application, the generating a sub-data key corresponding to each sub-data block based on the index value of each sub-data block and the main key includes: Calculating the remainder of the index value of each sub-data block divided by a preset value respectively; Based on the remainder, using a corresponding encryption algorithm, generating a sub-data key corresponding to the corresponding sub-data block through the index value of the corresponding sub-data block and the main key, where different remainders use different encryption algorithms.

[0034] Exemplarily, if the remainder is 0, the first encryption algorithm is used to generate a sub-data key corresponding to the corresponding sub-data block based on the index value of the corresponding sub-data block and the main key; If the remainder is 1, the second encryption algorithm is used to generate a sub-data key corresponding to the corresponding sub-data block based on the index value of the sub-data block and the main key; If the remainder is 2, the third encryption algorithm is used to generate a sub-data key corresponding to the corresponding sub-data block based on the index value of the sub-data block and the main key; If the remainder is 4, the fourth encryption algorithm is used to generate a sub-data key corresponding to the corresponding sub-data block based on the index value of the sub-data block and the main key; ......。

[0035] Specifically, the index value of each sub-data block can be divided by a preset value respectively. For example, when the preset value N = 3, the remainders 0, 1, and 2 correspond to the 3DES, AES, and SM4 algorithms respectively, forming a cyclic mapping relationship. Exemplarily, if the remainder is 0, the 3DES algorithm can be selected to calculate the sub-data key corresponding to the sub-data block; if the remainder is 1, the AES algorithm can be selected to calculate the sub-data key corresponding to the sub-data block; if the remainder is 2, the SM4 algorithm can be selected to calculate the sub-data key corresponding to the sub-data block. Exemplarily, the index value can be the block number of the sub-data block. Then, the algorithm used for the sub-data block with an index value of 6 is 3DES, the algorithm used for the sub-data block with an index value of 7 is AES, and the algorithm used for the sub-data block with an index value of 8 is SM4. Using different algorithms for adjacent blocks can prevent attackers from performing batch cracking on a single algorithm mode.

[0036] In an embodiment of the present application, obtaining the check chain value of the large file to be encrypted based on each encrypted sub-data block includes: Calculating the hash value corresponding to each encrypted sub-data block; Based on the hash values corresponding to each encrypted sub-data block, calculating the check chain value of the large file to be encrypted.

[0037] Optionally, a preset hash algorithm, such as SM3, can be used to calculate the hash values of each encrypted sub-data block , which can be specifically expressed as . Then, the hash values are sequentially concatenated according to the block numbers of the sub-data blocks, and the preset hash algorithm, such as SM3, is used again to calculate the check chain value h of the entire large file to be encrypted.

[0038] Among them, the check chain value h can be expressed as: ; In an embodiment of the present application, merging the multiple encrypted sub-data blocks and the check chain value to generate the ciphertext of the large file to be encrypted includes: Sequentially concatenating the multiple encrypted sub-data blocks according to the index value; Concatenating the concatenated encrypted sub-data blocks with the check chain value to obtain the ciphertext of the large file to be encrypted.

[0039] Optionally, the multiple encrypted sub-data blocks are sequentially concatenated according to the index value to ensure that the ciphertext can accurately restore the original file structure. After concatenation, the check chain value is incorporated into it to generate complete ciphertext data, and thus the ciphertext data after encrypting the large file to be encrypted, File, can be obtained, which is specifically expressed as , then, the ciphertext stream of the large file can be output to avoid caching the entire file. Generated based on all encrypted blocks, it can effectively detect whether the ciphertext has been tampered with during storage or transmission, realizing both the orderly integration of the large file after block encryption and endowing the ciphertext with self-verification ability.

[0040] In an embodiment of the present application, the splitting the large file to be encrypted into multiple sub-data blocks according to a preset rule includes: Based on the actual size of the large file to be encrypted, determine the preset block size; Split the large file to be encrypted into multiple sub-data blocks of the preset block size; If there are non-standard sub-data blocks smaller than the preset block size in the sub-data blocks, fill the non-standard sub-data blocks with corresponding bytes.

[0041] Optionally, the large file to be encrypted File can be split into n sub-data blocks according to a preset rule. For example, each sub-data block is split with a size of 1MB, or split according to a size of 1GB for each sub-data block. Among them, the preset block size, such as 1MB, 1GB or other values, can be dynamically adjusted according to the size of the large file. For example, a 10GB file can be block-split by 1GB (a total of 10 blocks), while a 500MB file can be block-split by 1MB (a total of 500 blocks), avoiding excessive small blocks from affecting efficiency.

[0042] It should be noted that if the fixed-size block strategy is adopted to split the large file to be encrypted, after splitting, the sizes of the sub-data blocks can be detected, and the sub-data blocks smaller than the fixed size, such as 1MB, are filled to ensure the integrity of the blocks. When filling, fixed bytes, such as 0x80, can be used for filling, or alternatively, random bytes (such as random bytes generated by a cryptographically secure random number generator) can also be used for filling. After filling is completed, the hash value of the filled sub-data block can be calculated, and this hash value can be embedded into the ciphertext of the large file to be encrypted. During decryption, the hash value can be recalculated and compared with the originally calculated hash value. If the comparison is consistent, it means the data has not been tampered with, preventing attackers from maliciously modifying the filled content and ensuring data integrity.

[0043] In an embodiment of the present application, the verification chain value includes a first main verification chain value and a first secondary verification chain value. After merging the multiple encrypted sub-data blocks and the verification chain value to generate the ciphertext of the large file to be encrypted, it includes: Based on the ciphertext of the large file to be encrypted, obtain each encrypted sub-data block; Calculate the hash value corresponding to each encrypted sub-data block respectively; Calculate the second main verification chain value of the large file to be encrypted based on the hash values corresponding to the respective encrypted sub-data blocks and the main hash algorithm; Calculate the second secondary verification chain value of the large file to be encrypted based on the hash values corresponding to the respective encrypted sub-data blocks and the secondary hash algorithm; Compare the first main verification chain value with the second main verification chain value, and compare the first secondary verification chain value with the second secondary verification chain value; If any comparison fails, it indicates that the data has been tampered with or damaged.

[0044] Optionally, split each encrypted sub-data block from the complete ciphertext according to a preset rule (such as a fixed size or an index marker) to ensure that each block is exactly the same as the division during encryption. Calculate the main hash value and the secondary hash value for each encrypted sub-data block, cascade and calculate all the main hash values in a specific order (such as a Merkle tree or a chained hash) to finally obtain the second main verification chain value. At the same time, use the same order and rule to calculate the second secondary verification chain value based on the secondary hash values. Then, compare the second main verification chain value generated during decryption with the first main verification chain value stored during encryption, and compare the second secondary verification chain value with the first secondary verification chain value at the same time. If both verification chains match successfully, it indicates that the data is complete and has not been tampered with. If the main verification chain matches successfully but the secondary verification chain fails to match, it indicates that the secondary hash algorithm has been targeted attacked. If both verification chains fail to match, it indicates that the data has been tampered with or damaged during transmission. By constructing verification chains using two main and secondary hash algorithms respectively and comparing the first verification chain generated during encryption with the second verification chain recalculated during decryption, double verification of the integrity of the ciphertext is achieved. Even if an attacker cracks or tampers with the verification chain of a single algorithm, the other algorithm can still detect the abnormality, greatly enhancing the anti-attack ability.

[0045] Among them, the main hash algorithm is different from the secondary hash algorithm, such as SHA-256 and BLAKE3.

[0046] Among them, the first main verification chain and the first secondary verification chain can automatically switch the algorithm combination based on a time period (such as time granularity of hours, days, weeks, etc.) or dynamically switch based on the file type (such as sensitivity level, file type), thereby effectively increasing the cracking difficulty for attackers and avoiding pattern leakage caused by long-term fixed use of a single algorithm.

[0047] In the embodiments of the present application, by splitting a large file to be encrypted into sub-data blocks according to a preset rule and encoding them, and generating a unique sub-key for each sub-block based on the master key and the sub-data block index value for encryption, and at the same time generating a check chain value based on the encrypted sub-data blocks, finally, the encrypted sub-data blocks and the check chain value are merged to obtain the ciphertext. It can effectively cut off the association between blocks, reduce the risk of key leakage, enhance the encryption strength with dynamic sub-keys, avoid memory overflow by block processing, and comprehensively improve the security, reliability and processing efficiency of large file encryption, meeting the urgent needs of large file secure storage and transmission.

[0048] It should be understood that the magnitudes of the sequence numbers of the steps in the above embodiments do not mean the order of execution. The order of execution of each process should be determined according to its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.

[0049] In one embodiment, an encryption device applicable to large files is provided. The encryption device applicable to large files corresponds one-to-one with the encryption method applicable to large files in the above embodiments. As Figure 2 shown, the encryption device applicable to large files includes an index value generation unit 10, a sub-data key generation unit 20, an encrypted sub-data block generation unit 30, a check chain value generation unit 40, and a ciphertext generation unit 50. The detailed description of each functional module is as follows: The index value generation unit 10 is configured to split a large file to be encrypted into a plurality of sub-data blocks according to a preset rule, and encode each sub-data block to obtain the index value of each sub-data block; The sub-data key generation unit 20 is configured to generate a master key, and generate a sub-data key corresponding to each sub-data block based on the index value of each sub-data block and the master key; The encrypted sub-data block generation unit 30 is configured to perform an encryption process on each sub-data block based on the sub-data key corresponding to each sub-data block to obtain a plurality of encrypted sub-data blocks; The check chain value generation unit 40 is configured to obtain the check chain value of the large file to be encrypted based on each encrypted sub-data block; The ciphertext generation unit 50 is configured to merge the plurality of encrypted sub-data blocks and the check chain value to generate the ciphertext of the large file to be encrypted.

[0050] In an embodiment of the present application, the sub-data key generation unit 20 is further configured to: Calculate the remainder of the index value of each sub-data block divided by a preset value respectively; Based on the remainder, adopt a corresponding encryption algorithm, and generate a sub-data key corresponding to the corresponding sub-data block through the index value of the corresponding sub-data block and the master key, wherein different remainders adopt different encryption algorithms.

[0051] In an embodiment of the present application, the verification chain value generation unit 40 is further configured to: Calculate the hash value corresponding to each encrypted sub-data block; Based on the hash values corresponding to each encrypted sub-data block, calculate the verification chain value of the large file to be encrypted.

[0052] In an embodiment of the present application, the ciphertext generation unit 50 is further configured to: Sequentially splice a plurality of encrypted sub-data blocks according to the index value; Splice the spliced encrypted sub-data blocks with the verification chain value to obtain the ciphertext of the large file to be encrypted.

[0053] In an embodiment of the present application, the index value generation unit 10 is further configured to: Based on the actual size of the large file to be encrypted, determine a preset block size; Divide the large file to be encrypted into multiple sub-data blocks of the preset block size; If there are non-standard sub-data blocks smaller than the preset block size in the sub-data blocks, fill the non-standard sub-data blocks with corresponding bytes.

[0054] In an embodiment of the present application, the verification chain value includes a first main verification chain value and a first secondary verification chain value, and the device further includes a verification unit for: Based on the ciphertext of the large file to be encrypted, obtain each encrypted sub-data block; Calculate the hash value corresponding to each encrypted sub-data block respectively; Based on the hash values corresponding to each encrypted sub-data block and the main hash algorithm, calculate the second main verification chain value of the large file to be encrypted; Based on the hash values corresponding to each encrypted sub-data block and the secondary hash algorithm, calculate the second secondary verification chain value of the large file to be encrypted; Compare the first main verification chain value with the second main verification chain value, and compare the first secondary verification chain value with the second secondary verification chain value; If any comparison fails, it means that the data has been tampered with or damaged.

[0055] In an embodiment of the present application, the first main verification chain and the first secondary verification chain are dynamically switched based on a time period or a file type.

[0056] In the embodiments of the present application, the large file to be encrypted is segmented into sub-data blocks and encoded according to preset rules, and unique sub-keys are generated for each sub-block based on the master key and the sub-block index value for encryption. At the same time, a check chain value is generated based on the encrypted sub-data blocks, and finally the encrypted sub-data blocks and the check chain value are merged to obtain the ciphertext. It can effectively cut off the association between blocks, reduce the risk of key leakage, enhance the encryption strength with dynamic sub-keys, avoid memory overflow through block processing, comprehensively improve the security, reliability and processing efficiency of large file encryption, and meet the urgent needs of large file secure storage and transmission.

[0057] For the specific limitations of the encryption device applicable to large files, reference can be made to the limitations of the encryption method applicable to large files in the above text, which will not be elaborated here. Each module in the above encryption device applicable to large files can be implemented in whole or in part by software, hardware and their combination. The above modules can be embedded in the processor in the computer device in the form of hardware or independent of it, or stored in the memory in the computer device in the form of software, so as to be called by the processor to execute the operations corresponding to the above modules.

[0058] In one embodiment, a computer device is provided. This computer device can be a terminal device, and its internal structure diagram can be as Figure 3 shown. The computer device includes a processor, a memory, and a network interface connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a readable storage medium. The readable storage medium stores computer-readable instructions. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer-readable instructions are executed by the processor, an encryption method applicable to large files is implemented. The readable storage medium provided in this embodiment includes a non-volatile readable storage medium and a volatile readable storage medium.

[0059] In the embodiments of the present application, a computer device is provided, including a memory, a processor, and computer-readable instructions stored in the memory and executable on the processor. When the processor executes the computer-readable instructions, the steps of the encryption method applicable to large files as described above are implemented.

[0060] In the embodiments of the application, a readable storage medium is provided. The readable storage medium stores computer-readable instructions. When the computer-readable instructions are executed by the processor, the steps of the encryption method applicable to large files as described above are implemented.

[0061] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through computer-readable instructions. The computer-readable instructions can be stored in a non-volatile readable storage medium or a volatile readable storage medium. When the computer-readable instructions are executed, they can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the embodiments provided in this application can include non-volatile and / or volatile memories. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or an external cache memory. By way of illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.

[0062] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the above-mentioned division of each functional unit and module is used as an example. In actual applications, the above functions can be allocated to different functional units and modules according to needs, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.

[0063] The above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them; although this application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included in the protection scope of this application.

Claims

1. An encryption method applicable to large files, characterized in that, The method includes: Dividing a large file to be encrypted into multiple sub-data blocks according to a preset rule, and encoding each sub-data block to obtain an index value of each sub-data block; Generating a main key, and generating a sub-data key corresponding to each sub-data block based on the index value of each sub-data block and the main key; Based on the sub-data key corresponding to each sub-data block, performing an encryption process on each sub-data block to obtain multiple encrypted sub-data blocks; Based on each encrypted sub-data block, obtaining a check chain value of the large file to be encrypted; Combining the multiple encrypted sub-data blocks and the check chain value to generate a ciphertext of the large file to be encrypted.

2. The encryption method applicable to large files according to claim 1, characterized in that, The generating a sub-data key corresponding to each sub-data block based on the index value of each sub-data block and the main key includes: Calculating the remainder of the index value of each sub-data block divided by a preset value respectively; Based on the remainder, using a corresponding encryption algorithm, and generating a sub-data key corresponding to the corresponding sub-data block through the index value of the corresponding sub-data block and the main key, wherein different remainders use different encryption algorithms.

3. The encryption method applicable to large files according to claim 1, characterized in that, The obtaining a check chain value of the large file to be encrypted based on each encrypted sub-data block includes: Calculating a hash value corresponding to each encrypted sub-data block; Based on the hash value corresponding to each encrypted sub-data block, calculating the check chain value of the large file to be encrypted.

4. The encryption method applicable to large files as described in claim 1, characterized in that, The combining the multiple encrypted sub-data blocks and the check chain value to generate a ciphertext of the large file to be encrypted includes: Sequentially splicing the multiple encrypted sub-data blocks according to the index value; Splicing the spliced encrypted sub-data blocks with the check chain value to obtain the ciphertext of the large file to be encrypted.

5. The encryption method applicable to large files according to claim 1, wherein The dividing the large file to be encrypted into multiple sub-data blocks according to a preset rule includes: Determining a preset block size based on the actual size of the large file to be encrypted; Dividing the large file to be encrypted into multiple sub-data blocks of the preset block size; If there is a non-standard sub-data block smaller than the preset block size in the sub-data blocks, filling the non-standard sub-data block with corresponding bytes.

6. The encryption method applicable to large files according to any one of claims 1-5, characterized in that, The check chain value includes a first main check chain value and a first secondary check chain value. After combining the multiple encrypted sub-data blocks and the check chain value to generate a ciphertext of the large file to be encrypted, it includes: Obtaining each encrypted sub-data block based on the ciphertext of the large file to be encrypted; Calculating the hash value corresponding to each encrypted sub-data block respectively; Based on the hash value corresponding to each encrypted sub-data block, calculating a second main check chain value of the large file to be encrypted by using a main hash algorithm; Based on the hash value corresponding to each encrypted sub-data block, calculating a second secondary check chain value of the large file to be encrypted by using a secondary hash algorithm; Comparing the first main check chain value with the second main check chain value, and comparing the first secondary check chain value with the second secondary check chain value; If any comparison fails, it indicates that the data has been tampered with or damaged.

7. The encryption method applicable to large files as described in claim 6, characterized in that, The first main check chain and the first secondary check chain are dynamically switched based on a time period or a file type.

8. An encryption device applicable to large files, characterized in that, The device includes: An index value generation unit, configured to divide a large file to be encrypted into multiple sub-data blocks according to a preset rule, and encode each sub-data block to obtain an index value of each sub-data block; A sub-data key generation unit, configured to generate a master key, and generate a sub-data key corresponding to each sub-data block based on the index value of each sub-data block and the master key; An encrypted sub-data block generation unit, configured to perform an encryption process on each sub-data block based on the sub-data key corresponding to each sub-data block to obtain a plurality of encrypted sub-data blocks; A checksum chain value generation unit, configured to obtain a checksum chain value of the large file to be encrypted based on each encrypted sub-data block; A ciphertext generation unit, configured to merge the plurality of encrypted sub-data blocks and the checksum chain value to generate a ciphertext of the large file to be encrypted.

9. A computer device, comprising a memory, a processor, and computer-readable instructions stored in the memory and executable on the processor, characterized in that, When the processor executes the computer-readable instructions, the steps of the encryption method for large files according to any one of claims 1 to 7 are implemented.

10. A readable storage medium storing computer-readable instructions, characterized in that, When the computer-readable instructions are executed by the processor, the steps of the encryption method for large files according to any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Exclusive encrypted file format of universal water, gas, sound and residue pollutant data acquisition instrument

    CN119603012A

  • Encryption transmission method and system of video data

    CN119729054A

  • Key rotation method, device, electronic apparatus, and medium

    WO2021239059A1

Cited By

  • Encryption method, decryption method and system for firmware upgrade file

    CN121664434A

  • Encryption method, decryption method and system for firmware upgrade file

    CN121664434B