Picture encryption method and device

By dynamically generating public and private keys in the edge function service of CDN nodes, encrypting comic pictures, combined with content caching technology, the piracy and illegal dissemination problems in comic pictures distribution are solved, security and distribution efficiency are improved, and latency and load are reduced.

CN120387175APending Publication Date: 2025-07-29SHANGHAI HODE INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510444919.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-09
Publication Date
2025-07-29

AI Technical Summary

Technical Problem

Prior Art In the comic industry, the distribution of comic pictures faces the problems of piracy and illegal dissemination, while the encryption process leads to high latency and server load.

Method used

In the edge function service of CDN nodes, the target image is encrypted and decrypted by dynamically generating matching public and private keys, combined with content caching technology, dynamic encryption and decryption are realized, and multi-version encryption algorithm coexistence is supported.

Benefits of technology

It improves the security and distribution efficiency of comic pictures, reduces the latency of the client to acquire pictures and the load on the server, and enhances the flexibility and security of the encryption process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120387175A_ABST
    Figure CN120387175A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a picture encryption method and related equipment / products, and relates to the field of information security. The method is used in the edge function service of the CDN node. The method comprises the following steps: receiving a picture request sent by a client, wherein the picture request comprises encryption indication information and a first public key matched with a first private key in the client; generating a second private key and a second public key which are matched with each other; encrypting a target picture corresponding to the picture request according to the first public key, the second private key and the encryption indication information to obtain an encrypted picture corresponding to the target picture; generating a picture ciphertext according to the second public key, the encrypted picture and the encryption indication information; and returning the picture ciphertext to the client, so that the client decrypts the encrypted picture according to the second public key, the first private key and the encryption indication information to obtain the target picture. According to the technical scheme of the embodiment of the invention, the security and efficiency of picture encryption can be improved, and the delay of picture acquisition by the client and the load of the server are reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present application relate to the field of information security technology, and in particular, to a method, apparatus, computer device, computer-readable storage medium, and computer program product for encrypting pictures. Background Art

[0002] Today, with the rapid development of Internet technology, the distribution and protection of digital content have become key issues of wide concern. Especially in the booming field of the comic industry, the distribution of comic pictures faces severe challenges of piracy and illegal dissemination. However, in the general process of picture encryption, it is not only difficult to effectively protect comic pictures from being stolen, but also there will be relatively high latency and increased server load.

[0003] It should be noted that the above content is not necessarily prior art and is not used to limit the patent protection scope of the present application. Summary of the Invention

[0004] Embodiments of the present application provide a method, apparatus, computer device, computer-readable storage medium, and computer program product for encrypting pictures to solve or alleviate one or more of the above-mentioned technical problems.

[0005] One aspect of the embodiments of the present application provides a method for encrypting pictures for an edge function service of a CDN node, and the method includes: Receiving a picture request sent by a client, where the picture request includes encryption indication information and a first public key matching a first private key in the client; Generating a mutually matching second private key and second public key; Encrypting a target picture corresponding to the picture request according to the first public key, the second private key, and the encryption indication information to obtain an encrypted picture corresponding to the target picture; Generating a picture ciphertext according to the second public key, the encrypted picture, and the encryption indication information; Returning the picture ciphertext to the client so that the client decrypts the encrypted picture according to the second public key, the first private key, and the encryption indication information to obtain the target picture.

[0006] Optionally, the encryption indication information includes an encryption algorithm version and a client type; the method further includes: Obtaining a target binary string according to the encryption indication information; Generating a target data buffer according to the target binary string; Reading the encryption algorithm version from the target data buffer according to a first preset character position; Read the client type from the target data buffer according to the second preset character position.

[0007] Optionally, the picture request further includes a client salt value and a preset time threshold, and the client salt value is generated by the client according to the first private key; Generating a matching second private key and second public key includes: Determine whether the picture request is qualified according to the client salt value and the first public key; Determine whether the picture request times out according to the preset time threshold and the current time; Generate the second private key and the second public key when the picture request is qualified and the picture request does not time out.

[0008] Optionally, encrypting the target picture corresponding to the picture request according to the first public key, the second private key and the encryption indication information to obtain an encrypted picture corresponding to the target picture, including: Generate a shared key according to the first public key and the second private key; Determine the picture information corresponding to the target picture; Generate a derived key corresponding to the shared key through a preset derivation function according to the picture information and the shared key; Encrypt the target picture according to the encryption indication information and the derived key to obtain an encrypted picture corresponding to the target picture.

[0009] Optionally, the CDN node stores multiple candidate encryption algorithm configuration information updated from the server at preset time intervals, and one candidate encryption algorithm configuration information corresponds to one candidate encryption algorithm version; Encrypting the target picture according to the encryption indication information and the derived key includes: Dynamically select the corresponding target encryption algorithm configuration information from multiple candidate encryption algorithms according to the encryption algorithm version; Encrypt the target picture according to the target encryption algorithm configuration information and the derived key.

[0010] Optionally, the encryption indication information includes an encryption algorithm version and a client type; encrypting the target picture according to the encryption indication information and the derived key includes: Determine multiple groups of candidate random variables according to the client type, and each group of candidate random variables corresponds to a target algorithm version; Determine a group of candidate random variables with the target algorithm version being the encryption algorithm version as the target random variable corresponding to the target picture; Encrypt the target image according to the target random variable, the encryption indication information, and the derived key.

[0011] Optionally, encrypt the target image corresponding to the image request according to the first public key, the second private key, and the encryption indication information to obtain the encrypted image corresponding to the target image, including: Determine whether the size of the target image is greater than a preset threshold; In the case where the size of the target image is greater than the preset threshold, divide the target image to obtain multiple image slices; Encrypt the multiple image slices in sequence according to the first public key, the second private key, and the encryption indication information to obtain multiple encrypted slices, where one image slice corresponds to one encrypted slice; Combine the multiple encrypted slices to obtain the encrypted image.

[0012] Optionally, the first private key is a first elliptic curve private key, and the first public key is a first elliptic curve public key generated according to the first elliptic curve private key and a preset base point on a preset elliptic curve; the second private key is a second elliptic curve private key, and the second public key is a second elliptic curve public key generated according to the second elliptic curve private key and the preset base point.

[0013] Optionally, the first public key and the first private key are dynamically generated by the client at preset time intervals; the second public key and the second private key are dynamically generated by the CDN node when receiving the image request sent by the client.

[0014] Another aspect of the embodiments of the present application provides an image encryption device for use in the edge function service of a CDN node. The device includes: A receiving module, configured to receive an image request sent by a client, where the image request includes encryption indication information and a first public key that matches a first private key in the client; A first generation module, configured to generate a second private key and a second public key that match each other; An encryption module, configured to encrypt the target image corresponding to the image request according to the first public key, the second private key, and the encryption indication information to obtain the encrypted image corresponding to the target image; A second generation module, configured to generate an image ciphertext according to the second public key, the encrypted image, and the encryption indication information; A return module, configured to return the image ciphertext to the client, so that the client decrypts the encrypted image according to the second public key, the first private key, and the encryption indication information to obtain the target image.

[0015] Another aspect of the embodiments of the present application provides a computer device, including: At least one processor; and A memory communicatively connected to the at least one processor; Wherein: the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the method as described above.

[0016] Another aspect of the embodiments of the present application provides a computer-readable storage medium, in which computer instructions are stored, and when the computer instructions are executed by a processor, the method as described above is implemented.

[0017] Another aspect of the embodiments of the present application provides a computer program product, including a computer program, and when the computer program is executed by a processor, the method as described above is implemented.

[0018] The embodiments of the present application adopting the above technical solutions may include the following advantages: The CDN node and the client respectively encrypt and decrypt the target picture through mutually matching key pairs (i.e., the first public key and the second private key, the first private key and the second public key), realizing key negotiation in the picture transmission process and ensuring the security of picture information. At the same time, using the edge function of the CDN node for dynamic encryption based on the encryption indication information further improves the security and efficiency of picture encryption, reduces the delay for the client to obtain the picture, and reduces the load on the server side. BRIEF DESCRIPTION OF THE DRAWINGS The drawings exemplarily show embodiments and form a part of the specification, and are used together with the written description of the specification to explain the exemplary embodiments. The shown embodiments are only for illustrative purposes and do not limit the scope of the claims. In all the drawings, the same reference numerals refer to similar but not necessarily identical elements.

[0019] Figure 1 Schematically shows an operating environment diagram of the picture encryption method according to Embodiment 1 of the present application; Figure 2 Schematically shows a flowchart of the picture encryption method according to Embodiment 1 of the present application; Figure 3 Schematically shows an additional flowchart of the picture encryption method according to Embodiment 1 of the present application; Figure 4 Schematically shows Figure 2 A sub-step flowchart of step S202 in; Figure 5 Schematically shows Figure 2 A sub-step flowchart of step S204 in; Figure 6Schematically shows Figure 5 The sub-step flowchart of step S506 in Figure 7 Schematically shows Figure 5 Another sub-step flowchart of step S506 in Figure 8 Schematically shows Figure 2 Another sub-step flowchart of step S204 in Figure 9 Schematically shows the exemplary application flowchart of the picture encryption method according to Embodiment 1 of the present application; Figure 10 Schematically shows the block diagram of the picture encryption device according to Embodiment 2 of the present application; Figure 11 Schematically shows the hardware architecture schematic diagram of the computer device according to Embodiment 3 of the present application; Figure 12 Schematically shows an exemplary picture caching process; and Figure 13 Schematically shows an exemplary picture sharding encryption process flowchart. Detailed implementation manners

[0020] In order to make the purpose, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts shall fall within the protection scope of the present application.

[0021] It should be noted that the descriptions involving "first", "second", etc. in the embodiments of the present application are only for descriptive purposes and cannot be understood as indicating or implying their relative importance or implicitly indicating the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include at least one of such features. In addition, the technical solutions between the various embodiments may be combined with each other, but it must be based on the fact that those of ordinary skill in the art can implement them. When the combination of technical solutions appears to be contradictory or unable to be implemented, it should be considered that such a combination of technical solutions does not exist and is not within the protection scope required by the present application.

[0022] In the description of the present application, it should be understood that the numerical labels before the steps do not identify the order of execution of the steps, but are only used to facilitate the description of the present application and distinguish each step, and thus cannot be understood as a limitation to the present application.

[0023] First, the term explanations involved in the present application are provided: CDN (Content Delivery Network): A network layout that caches website business content in cloud servers around the world through a distributed server layout, allowing users to access it nearby to improve access speed.

[0024] Edge function service: Symmetric encryption: A cryptographic technique that uses the same key to encrypt and decrypt plaintext. During symmetric encryption, the sender uses the key to encrypt the plaintext, generates ciphertext, and sends it to the receiver. After receiving the ciphertext, the receiver uses the same key to decrypt it and recover the original plaintext.

[0025] Asymmetric encryption: A cryptographic technique that uses a pair of keys, namely a public key and a private key. The public key can be made public and is used to encrypt data; the private key is kept secret by the receiver and is used to decrypt data.

[0026] Public-private key pair: A pair of keys used for encryption and authentication in cryptography. The public key can be made public and is used to encrypt data or verify signatures; the private key needs to be kept secret and is used to decrypt data or generate signatures.

[0027] Digital signature: A method of signing electronic documents using cryptographic techniques. The private key is used to encrypt the data to generate a signature, and the receiver decrypts and verifies the signature using the public key.

[0028] Initialization Vector (IV): A random or pseudorandom value used in cryptography to enhance encryption security. The IV is used in combination with the key to ensure that the same plaintext generates different ciphertexts in different encryption operations.

[0029] RSA: An asymmetric encryption algorithm. Based on the mathematical problem of large number factorization, it can generate a pair of keys: one public key for encrypting data and one private key for decrypting.

[0030] ECDHE (Elliptic Curve Diffie-Hellman Ephemeral): A key exchange protocol based on elliptic curve cryptography that allows two communicating parties to securely exchange keys over an insecure channel.

[0031] Atob function: A built-in function in JavaScript for web development that converts a Base64-encoded string into its original binary string.

[0032] ASCII encoding (American Standard Code for Information Interchange): It is a character encoding standard based on the Latin alphabet. It uses 7-bit or 8-bit binary numbers to represent characters, with a total of 128 possible character encodings, including English letters, numbers, punctuation marks, and control characters.

[0033] Data buffer: It is an area allocated in the computer memory for temporarily storing data.

[0034] UnityXArray: It is a series of data structures in the Unity development engine for storing and operating array data, such as Unity8Array, Unity16Array, and Unity32Array, etc. It allows developers to define arrays with a fixed size for storing multiple elements of the same type.

[0035] HKDF (HMAC-based Extract-and-Expand Key Derivation Function): It is a key derivation function based on HMAC that extracts a key from the given key material and expands it into a key of the required length.

[0036] PBKDF2 (Password-Based Key Derivation Function 2): It is a password-based key derivation function that generates a key by combining a password with a salt value and repeating the hashing operation.

[0037] SSL / TLS protocol (Secure Sockets Layer / Transport Layer Security protocol): It is a network security protocol that mainly achieves secure communication in the following aspects: First, it encrypts data using encryption technology; Second, it verifies the identities of both communication parties through digital certificates and the Public Key Infrastructure (PKI); Finally, it can also provide data integrity protection.

[0038] Secondly, to facilitate those skilled in the art to understand the technical solutions provided by the embodiments of the present application, the related technologies are described below: With the rapid development of the Internet, the distribution and protection of digital content have become increasingly important. In the comic industry, the distribution of comic pictures faces problems of piracy and illegal dissemination. Encryption methods are usually carried out on the central server, which leads to high latency and server load. To improve the distribution efficiency and security, CDN technology is applied to content distribution. However, CDN technology has deficiencies in terms of security and cannot effectively protect comic pictures from being stolen.

[0039] In recent years, CDN edge computing technology has gradually emerged. As a Serverless computing service, EdgeRoutine runs on CDN edge nodes, which can effectively reduce latency, improve response speed, and relieve the load on the central server.

[0040] Therefore, the embodiments of this application provide a picture encryption technical solution. In this technical solution, (1) by deploying an encryption function on the CDN edge node, dynamic encryption and decryption of comic pictures can be achieved. Combining with the content caching technology, the distribution efficiency of comic content can be further improved; (2) the security of comic pictures can be enhanced, effectively preventing theft and illegal dissemination; (3) flexible encryption policies can be provided to dynamically adjust encryption parameters according to actual situations (such as picture information); (4) coexistence of multiple versions of encryption algorithms can be supported to ensure the smooth transition and compatibility of the system. See the following text for details.

[0041] Finally, for easy understanding, an exemplary operating environment is provided below.

[0042] As Figure 1 shown, the operating environment diagram includes: a server 2, a CDN node 4, and a client 6, where: The server 2 can be composed of multiple computing devices. The multiple computing devices can include virtualized computing instances. The virtualized computing instances can include virtual machines, such as emulations of computer systems, operating systems, servers, etc. The computing devices can load virtual machines based on virtual images and / or other data that define specific software (such as operating systems, dedicated applications, servers) for emulation. As the demand for different types of processing services changes, different virtual machines can be loaded and / or terminated on one or more computing devices. A hypervisor can be implemented to manage the use of different virtual machines on the same computing device.

[0043] The server 2 can provide services such as storage and distribution of application programs and encryption algorithm configurations.

[0044] The server 2 can be configured to communicate with the CDN node 4, the client 6, etc. through a network.

[0045] The CDN node 4 can be configured with edge computing services and is used to provide content distribution services. The CDN node 4 can be configured to: in response to a request for a specific resource (such as a target picture), when the specific resource is local to the CDN node, encrypt it and return the encrypted file; when the specific resource is not local to the CDN node, obtain it from the server 2.

[0046] The client 6 can be configured to send a data acquisition request to the CDN node 4 or the server 2. The viewer terminal can be any type of computer device, such as a smart phone, a tablet device, a laptop computer, a smart TV, a vehicle-mounted terminal, etc. The viewer terminal can be built-in with a browser, a dedicated program or a player for receiving data and outputting content to the user. The content can include pictures, etc.

[0047] The server 2, the CDN node 4 and the client 6 can be connected through a network. The network can include various network devices, such as routers, switches, multiplexers, hubs, modems, bridges, repeaters, firewalls and / or proxy devices, etc. The network can include physical links, such as coaxial cable links, twisted pair cable links, fiber optic links and their combinations and / or analogs. The network can include wireless links, such as cellular links, satellite links, Wi-Fi links and / or analogs.

[0048] It should be noted that the numbers of the server 2, the CDN node 4 and the client 6 in the figure are only illustrative and are not used to limit the patent protection scope of the present application. According to the actual situation, there can be any number of servers 2, CDN nodes 4 and clients 6.

[0049] The following takes the CDN node 4 as the execution subject and introduces the technical solution of the present application through multiple embodiments. It should be noted that these embodiments can be implemented in various different forms and should not be construed as being limited only to the embodiments described herein.

[0050] Embodiment 1 Figure 2 A flowchart of a picture encryption method according to Embodiment 1 of the present application is schematically shown.

[0051] As Figure 2 shown, the picture encryption method can include steps S200 to S208, where: Step S200, receiving a picture request sent by the client, where the picture request includes encryption indication information and a first public key matching the first private key in the client; Step S202, generating a mutually matching second private key and second public key; Step S204, encrypting the target picture corresponding to the picture request according to the first public key, the second private key and the encryption indication information to obtain an encrypted picture corresponding to the target picture; Step S206, generating a picture ciphertext according to the second public key, the encrypted picture and the encryption indication information; Step S208, return the encrypted image ciphertext to the client, so that the client decrypts the encrypted image according to the second public key, the first private key, and the encryption indication information to obtain the target image.

[0052] In the image encryption method provided in this embodiment, the CDN node and the client encrypt and decrypt the target image through mutually matching key pairs (i.e., the first public key and the second private key, the first private key and the second public key), realizing key negotiation during the image transmission process and ensuring the security of image information. At the same time, using the edge function of the CDN node for dynamic encryption based on the encryption indication information further improves the security and efficiency of image encryption, reduces the latency for the client to obtain the image, and reduces the load on the server.

[0053] The following combines Figure 2 to elaborate in detail on each step in steps S200 - S208 and other optional steps.

[0054] Step S200 , receive an image request sent by the client, where the image request includes encryption indication information and a first public key that matches the first private key in the client.

[0055] The encryption indication information can cover encryption algorithm versions, image details, timestamps, and random values (such as salt values, random numbers, additional data, and random initialization vectors, etc.). In some embodiments, its composition is fixed. In other embodiments, different information components can also be selected according to the image type, user permissions, or network conditions, etc. In addition, random values for obfuscation can also be embedded in the encryption indication information according to preset rules to enhance security.

[0056] In some embodiments, the client can generate the first public key and the first private key through Elliptic Curve Cryptography (ECC). In other embodiments, the client can also generate the first public key and the first private key through encryption algorithms such as RSA and ECDHE.

[0057] For example, when generating the first public key and the first private key through elliptic curve encryption, the first private key can be a random number a, and the first public key can be calculated from the random number a and a point G on a pre - determined elliptic curve O.

[0058] In some embodiments, the client can generate a new client key pair (the first public key and the first private key) each time it sends an image request to the server. In other embodiments, the client can also update the client key pair it uses at regular intervals according to a preset time interval and cache it in the client.

[0059] As described above, the encryption indication information may include multiple pieces of data. Correspondingly, the CDN node can also obtain this data from the encryption indication information through various methods. The following provides an exemplary composition of the encryption indication information and the corresponding data acquisition method.

[0060] In an alternative embodiment, the encryption indication information includes an encryption algorithm version and a client type. As Figure 3 shown, the method further includes: S300, obtaining a target binary string according to the encryption indication information.

[0061] S302, generating a target data buffer according to the target binary string.

[0062] S304, reading the encryption algorithm version from the target data buffer according to a first preset character position.

[0063] S306, reading the client type from the target data buffer according to a second preset character position.

[0064] In some embodiments, the encryption indication information can be converted into a target binary string through the atob function. In other embodiments, the target binary string can also be obtained through other functions or methods adapted to the format of the encryption indication information.

[0065] The target data buffer can be of various types such as Uint8Array, Uint16Array, or Uint32Array based on ASCII encoding. In some embodiments, after generating the target data buffer, the data can also be verified through methods such as CRC check and hash algorithm to ensure that the data has not been tampered with during transmission and processing.

[0066] The target data buffer caches multiple characters, and the first preset character position and the second preset character position can respectively correspond to one or more of these characters. For example, the 10th to 16th characters (i.e., the first preset character position) can be used to store the encryption algorithm version, and the 100th character (i.e., the second preset character position) can be used to store the client type. The client type can include the web side and the APP side, etc.

[0067] In some embodiments, in addition to the encryption algorithm version and the client type, other information such as the encryption mode (such as CBC, CTR, etc.), padding method, key length, etc. can also be extracted from the encryption indication information.

[0068] In this embodiment, the CDN node can obtain key information such as the encryption algorithm version and the client type by parsing the encryption indication information. Thus, the CDN node can accurately obtain the encryption algorithm and related settings to be used for this encryption, improving the flexibility and adaptability of the image encryption process and ensuring the accuracy and effectiveness of the image encryption.

[0069] Step S202 , generate a matching second private key and second public key.

[0070] In some embodiments, the CDN node can generate the second public key and the second private key through the Elliptic Curve Cryptography (ECC). In other embodiments, the CDN node can also generate the second public key and the second private key through encryption algorithms such as RSA and ECDHE.

[0071] For example, when generating the second public key and the second private key through the Elliptic Curve Cryptography, the second private key can be a random number b, and the second public key can be calculated from the random number b and a point G on a pre-determined elliptic curve O. The elliptic curve O and the point G can be set by the client and the CDN node or the server through a secure channel at regular intervals, or can be dynamically determined by the client and transmitted to the CDN node each time the target image is requested.

[0072] Before generating the second public-private key pair, the CDN node can also verify through the received image request to avoid wasting computing resources due to illegal or incorrect image requests. The following provides an exemplary verification method.

[0073] In an alternative embodiment, the image request further includes a preset salt value and a preset time threshold, and the preset salt value is generated by the client according to the first private key. As Figure 4 shown, step S202 includes: S400, determine whether the image request is qualified according to the preset salt value and the first public key.

[0074] S402, determine whether the image request times out according to the preset time threshold and the current time.

[0075] S404, generate the second private key and the second public key when the image request is qualified and the image request does not time out.

[0076] In some embodiments, the preset salt value can be preset data signed by the client using the first private key. At this time, after receiving the preset salt value, the CDN node can verify the signature through the first public key in the image request. If the verification passes, it indicates that the image request is qualified. In other embodiments, the preset salt value can also be generated by other means and verified using corresponding methods.

[0077] In some embodiments, the preset time threshold may be fixed. In other embodiments, the preset time threshold may also be adjusted in real time according to system load, network conditions, etc. For example, when the load is high or the network latency is large, the threshold is appropriately extended; when the load is low or the network is good, the threshold is shortened.

[0078] Set a preset salt value and a preset time threshold in the picture request, so that the CDN node can verify the eligibility and timeliness of the picture request, and generate a key pair only when the picture request is eligible and not timed out. The process of verifying the picture request can improve the security and efficiency of the picture encryption process, and help protect the security of the picture content.

[0079] Step S204 , encrypt the target picture corresponding to the picture request according to the first public key, the second private key and the encryption indication information to obtain the encrypted picture corresponding to the target picture.

[0080] In some embodiments, multi-threading technology can be used to encrypt different regions of the target picture simultaneously. For example, the target picture is divided into multiple small blocks, and each thread is responsible for encrypting a part of it.

[0081] The CDN node can extract the previously cached target picture from the node cache. When the target picture has not been cached before, it can also obtain the target picture from the server or the picture source site and cache the obtained target picture in the node cache. By deploying the encryption function at the CDN edge node, dynamic encryption and decryption of comic pictures can be realized, and combined with the content caching technology, the distribution efficiency of comic content can be further improved. Figure 12 An exemplary picture caching process is provided.

[0082] In other embodiments, the CDN node can also perform a security check on the running environment before encryption, such as whether there is malware or virus, whether it is connected to an insecure network, etc. When encrypting, a hash algorithm can also be used to calculate a check value to perform integrity verification on the data of the target picture. After the encrypted picture is obtained, the encrypted picture can also be cached in the local cache of the CDN node.

[0083] According to the actual situation, the CDN node can encrypt through a single encryption algorithm such as AES, RSA or a combination of multiple encryption algorithms. Different encryption algorithms can also adopt different padding methods. For example, AES can adopt the CBC mode and PKCS#7 padding. In some embodiments, coexistence of multiple versions of encryption algorithms can also be supported to ensure the smooth transition and compatibility of the system.

[0084] In this embodiment, the CDN node can adopt different encryption methods or configurations each time when encrypting a picture according to the negotiated keys (i.e., the first public key and the second private key) and the corresponding encryption indication information, so as to realize the dynamic encryption of the target picture. The realization of dynamic encryption can improve the complexity of picture encryption, increase the cracking difficulty of the encrypted picture, and thus ensure the security of picture data.

[0085] When using the keys for encryption, the CDN node can also combine other information and adopt the corresponding encryption method to increase the complexity of encryption. The following provides an exemplary encryption method.

[0086] In an alternative embodiment, as Figure 5 shown, step S204 includes: S500, generating a shared key according to the first public key and the second private key.

[0087] S502, determining the picture information corresponding to the target picture.

[0088] S504, generating a derived key corresponding to the shared key through a preset derivation function according to the picture information and the shared key.

[0089] S506, encrypting the target picture according to the encryption indication information and the derived key to obtain the encrypted picture corresponding to the target picture.

[0090] The picture information may include the size, type, importance of the picture, and the picture number or file name, etc. The derivation function for generating the derived key may be a combination of one or more of HKDF, PBKDF2, etc.

[0091] In some embodiments, appropriate derivation functions can be dynamically selected according to parameters such as the size of the picture, and relevant parameters such as the length and iteration times of the derived key can be adjusted accordingly to achieve a more optimized encryption effect. In other embodiments, after generating the derived key, the integrity of the generated derived key can also be verified by calculating the hash value of the derived key, etc., to ensure that it has not been tampered with during the generation and transmission process.

[0092] It should be noted that in addition to the picture information, according to the actual situation, a salt value (i.e., a random value) and additional information generated based on the picture request time, picture encryption time, etc. can be added, and these information are jointly used as the input for generating the derived key to further enhance the security and unpredictability of the derived key.

[0093] In this embodiment, a flexible encryption policy can be provided to dynamically adjust encryption parameters according to actual situations (such as picture information). Encrypting the target picture with the derived key generated according to the picture information can increase the information density in the derived key, thereby increasing the complexity of the encryption and decryption processes, enabling the CDN node to encrypt the target picture more securely and improving the security of the picture data.

[0094] As described above, the encryption indication information can be composed of various types of data, and different encryption methods correspond to each type of data composition. Several exemplary encryption methods and their corresponding data compositions are provided below.

[0095] Method 1: The CDN node stores multiple candidate encryption algorithm configuration information updated from the server at preset time intervals. One candidate encryption algorithm configuration information corresponds to one candidate encryption algorithm version. As Figure 6 shown, S506 includes: S600, dynamically select the corresponding target encryption algorithm configuration information from multiple candidate encryption algorithms according to the encryption algorithm version; S602, encrypt the target picture according to the target encryption algorithm configuration information and the derived key.

[0096] In some embodiments, the CDN node and the server can negotiate regularly through a secure channel based on the SSL / TLS protocol to update the encryption algorithm configuration information. In other embodiments, when the CDN node receives an encryption algorithm version not stored in the node's storage, it can directly query the corresponding encryption algorithm configuration information from the server.

[0097] The target encryption algorithm configuration information can include the size of the encrypted area, the location of the encrypted area, and the encryption algorithm, etc. For example, the target encryption algorithm configuration information can be "encrypt the 500×500 pixel area in the center of the picture using the AES encryption method".

[0098] In some embodiments, after obtaining the target encryption algorithm configuration information, the CDN node can also adjust the parameters in the target encryption algorithm configuration information, such as offsetting the location of the encrypted area, etc., and inform the client of the adjustment result.

[0099] In this embodiment, the CDN node encrypts the target picture according to the dynamically selected target encryption algorithm configuration information, which can improve the flexibility and reliability of the encryption process, as well as the intensity of picture encryption, increase the difficulty of cracking the encrypted picture, and help protect the security of picture data.

[0100] Method 2: The encryption indication information includes the encryption algorithm version and the client type. As Figure 7 shown, S506 includes: S700. Determine multiple groups of candidate random variables according to the client type, where each group of candidate random variables corresponds to a target algorithm version. S702. Determine a group of candidate random variables with the target algorithm version being the encryption algorithm version as the target random variable corresponding to the target picture. S704. Encrypt the target picture according to the target random variable, the encryption indication information, and the derived key.

[0101] In some embodiments, the candidate random variables may include salt values / random values, random initialization vectors, random variables for different types of clients, etc. In other embodiments, other types of data may also be set as candidate random variables according to the actual situation.

[0102] The candidate random variables may be stored in the CDN node in the form of a data table and can be queried using the algorithm version as an index to obtain a group of candidate random variables corresponding to each target algorithm version. In some embodiments, the candidate random variables may also be periodically updated by the server according to a preset update rule.

[0103] In some embodiments, the CDN node may encrypt using the complete target random variable obtained. In other embodiments, the CDN node may also select part of the random variables from the target random variable, or adjust part of the random variables, and then use the selected or adjusted target random variables for encryption and inform the client of the selection and adjustment results.

[0104] In this embodiment, a target random variable corresponding to the encryption algorithm version and the client type is added during the encryption process. The application of the target random variable can make the complexity of the data used for each encryption higher, thus making the encryption process more complex and unpredictable, enhancing the security and flexibility of the picture encryption.

[0105] As previously mentioned, a series of operations can be adopted to improve the encryption efficiency during the picture encryption process. The following provides an exemplary operation.

[0106] In an alternative embodiment, as Figure 8 shown, step S204 includes: S800. Determine whether the size of the target picture is greater than a preset threshold.

[0107] S802. In the case where the size of the target picture is greater than the preset threshold, divide the target picture to obtain multiple picture slices.

[0108] S804: Encrypt the plurality of image slices in sequence according to the first public key, the second private key, and the encryption indication information to obtain a plurality of encrypted slices, where one image slice corresponds to one encrypted slice.

[0109] S806: Combine the multiple encrypted fragments to obtain the encrypted image.

[0110] The preset threshold value may be a fixed value, or may be dynamically adjusted according to network conditions, CDN node load, user needs, etc. In some embodiments, different preset threshold values may be used for images of different formats.

[0111] In some embodiments, the target image can be divided into image slices of the same size. In other embodiments, intelligent segmentation can be performed based on the image's content features, important areas, etc. After the segmentation is completed, the image slices can be indexed, identified, or recorded in an order.

[0112] In some embodiments, different encryption algorithms or encryption strengths may be selected for different image segments based on the importance and sensitivity of their content. In other embodiments, the encryption algorithm or encryption strength used may be marked in the header of the image metadata.

[0113] After combining the encrypted fragments, the integrity of the combined encrypted image can be checked, such as by calculating a checksum, using a hash function, etc. The combined encrypted image can also be further optimized, such as by compression, format conversion, etc.

[0114] By encrypting and combining the fragments of a larger target image, the efficiency, security, and flexibility of the encryption process are improved. This effectively reduces the resource consumption and time cost of the encryption process while ensuring the integrity of the encrypted image. The image fragment encryption process of this embodiment can be as follows: Figure 13 shown.

[0115] Step S206 , generating a picture ciphertext according to the second public key, the encrypted picture and the encryption indication information.

[0116] In some embodiments, the image ciphertext may also include a random value used to obfuscate the encrypted information. Before decryption, the client can remove this random value from the image ciphertext according to pre-negotiated rules to correctly identify the encryption instruction information, the second public key, and the encrypted image. In other embodiments, the image ciphertext may also include information such as a timestamp and client identification to facilitate legitimacy verification and logging by the client during the decryption process.

[0117] In some embodiments, the encrypted image can be divided into multiple parts, and a corresponding ciphertext can be generated for each part. The ciphertext corresponding to each part can be combined to obtain the image ciphertext. In other embodiments, the encrypted image can also be divided into random sizes, and each divided part can be encrypted using different parameters or encryption algorithms.

[0118] The ciphertext may be transmitted via an encrypted communication protocol such as SSL / TLS. In some embodiments, the ciphertext may be split into multiple segments, transmitted via different paths or methods, and then reassembled at the client.

[0119] By including the second public key and encryption instructions in the image ciphertext, the client can decrypt the encrypted image using the correct data and method after parsing the image ciphertext. This configuration of the image ciphertext ensures the correct decryption process, improving the stability and reliability of the image encryption method. It also reduces the number of communications between the client and the CDN node, improving the security and efficiency of the image encryption method.

[0120] Step S208 , returning the picture ciphertext to the client, so that the client decrypts the encrypted picture according to the second public key, the first private key and the encryption indication information to obtain the target picture.

[0121] In some embodiments, the client may use multi-threading technology to decrypt different areas of the encrypted image simultaneously, for example, dividing the encrypted image into multiple small blocks, and each thread is responsible for decrypting a part of the blocks.

[0122] In other embodiments, the client can also be embedded with environmental detection and crawler detection code, which can build a multi-dimensional environmental profile by analyzing device hardware information, operating system version, browser type, etc., to determine whether there are any anomalies. During decryption, a checksum can also be calculated using a hash algorithm to verify the integrity of the encrypted image data.

[0123] The image ciphertext may also include some random values used to obfuscate the encrypted information. Before decryption, the client may remove these random values from the image ciphertext according to pre-negotiated rules to correctly identify the encryption indication information, the second public key, and the encrypted image.

[0124] After decrypting and obtaining the target image, the client can render and display the target image on the corresponding interface, and can also cache the target image in the client's local cache.

[0125] In this embodiment, the client decrypts the encrypted image obtained by the CDN node using the first public key and the second private key with the first private key and the second public key. Since the first public key and the first private key match each other, and the second public key and the second private key match each other, it is ensured that the client can correctly decrypt and view the target image, protecting the security and privacy of the target image and effectively preventing theft and illegal dissemination.

[0126] As mentioned above, there can be various types of key pairs used in this embodiment. The following provides an exemplary key pair type setting.

[0127] In an alternative embodiment, the first private key is a first elliptic curve private key, and the first public key is a first elliptic curve public key generated based on the first elliptic curve private key and a preset base point on a preset elliptic curve; the second private key is a second elliptic curve private key, and the second public key is a second elliptic curve public key generated based on the second elliptic curve private key and the preset base point.

[0128] For example, the first elliptic curve private key generated by the client is a random value a, and the preset elliptic curve is set as O. The client selects a base point G on the curve O, and according to the elliptic curve encryption algorithm, calculates the first elliptic curve public key K = aG through G and a.

[0129] The second elliptic curve private key generated by the CDN node is a random value b. The CDN node calculates the second elliptic curve public key C = bG according to the elliptic curve encryption algorithm using the base point G and b.

[0130] When the image is transmitted, the key Key1 for encrypting the target image = K × b = (aG) × b = abG; the key Key2 for decrypting the target image = C × a = (bG) × a = abG. That is, Key1 = Key2, and correct encryption and decryption can be achieved.

[0131] It should be noted that the above calculation process and results are examples. In actual implementation, other information can be added to the key, or different methods can be used to calculate keys with different compositions or forms.

[0132] In some embodiments, the preset elliptic curve and the preset base point can be negotiated by the client and the target node through a secure channel regularly. In other embodiments, they can also be carried by the client in the image request or other data when generating a new first elliptic curve public key and the first elliptic curve private key and sent to the target node.

[0133] The calculation of points on the elliptic curve is one-way. Given the base point and the elliptic curve private key, it is easy to calculate the public key; but given the public key and the base point, it is difficult to calculate the private key. [[ID=z5]]

[0134] Based on this feature, in this embodiment, elliptic curve public and private key pairs (i.e., elliptic curve public keys and elliptic curve private keys) are used to encrypt and decrypt pictures, which can improve the security of picture transmission, contribute to enhancing the picture transmission efficiency and protecting the security of picture information.

[0135] In addition to having multiple choices for the type of key pair generation, there can also be various settings for the key pair generation time. The following provides an exemplary key pair generation time rule.

[0136] In an alternative embodiment, the first public key and the first private key are dynamically generated by the client at a predetermined time interval; The second public key and the second private key are dynamically generated by the CDN node when receiving a picture request sent by the client.

[0137] In some embodiments, the predetermined time interval can be calculated according to absolute time (such as Beijing time). For example, the first public key and the first private key are generated at 8 o'clock, 16 o'clock, and 24 o'clock every day respectively. In other embodiments, the predetermined time interval can also be calculated according to the time when the client is opened or the time of the current picture request. For example, after the client is opened, the first public key and the first private key are generated every 20 minutes.

[0138] In this embodiment, the client regularly generates a new client key pair, and the CDN node responds to the client request to generate a new CDN key pair (i.e., the second public key and the second private key). This setting of the key pair generation time rule is beneficial to protecting the security and confidentiality of the key pair, and also helps to alleviate the computing pressure on the client caused by generating key pairs too frequently.

[0139] To make the present application easier to understand, the following is combined with Figure 9 An exemplary application is provided. Wherein: S11, User A clicks on a comic (i.e., the target picture) on the client 6; S12, After being guided by the server, the client 6 sends a picture request to the CDN node 4. The picture request contains a cpx parameter (i.e., encryption indication information) carrying the client public key K (i.e., the first elliptic curve public key), the encryption algorithm version EncryptVersion, and the client type EncrypType; The client public key K is generated by the client according to the random value a of the client private key (i.e., the first elliptic curve private key) generated at 8 o'clock in the morning of the day, and a base point G on the elliptic curve O negotiated with the CDN node 4 in advance, where K = aG; S13, CDN node 4 uses the atob function to convert the cpx parameter into a binary string decodedCpx (i.e., the target binary string) and generates a data buffer (i.e., the target data buffer); S14, CDN node 4 extracts the x1th byte from the generated data buffer. The x1th byte represents the encryption algorithm version EncryptVersion, and the result is 0.0.1. The x2th byte is extracted from the generated data buffer. The x2th byte represents the client type EncrypType, and the result is the APP end. S15 , CDN node 4 queries and obtains the corresponding encryption configuration information based on the encryption algorithm version EncryptVersion , determines that the encryption algorithm EncryptMethod is the AES algorithm, the encryption area position EncryptSizePos is the center of the image, and the encryption area size EncryptSize is 100×500 pixels; S16, CDN node 4 generates a CDN private key b (i.e., a second elliptic curve private key), and generates a CDN public key C = bG (i.e., a second elliptic curve public key) based on a pre-negotiated base point G on the elliptic curve O; S17, CDN node 4 generates a shared key S=bK=b(aG)=abG based on the CDN private key b and the client public key K; S18, CDN node 4 obtains a symmetric key (i.e., a derived key) through a derivation function based on the shared key S, the salt value salt, and the additional information info; S19, CDN node 4 obtains a set of random variables (i.e., target random variables) by querying the encryption algorithm version EncryptVersion and the client type EncrypType, including the salt value (salt), the initialization variable (iv), etc. S20, CDN node 4 encrypts the comic image extracted from the node cache using the symmetric key and the obtained random variable according to the queried encryption configuration information; S21, CDN node 4 combines the encrypted comic image (i.e., encrypted image), encryption algorithm version EncryptVersion, and CDN public key C to generate an encrypted file (i.e., image ciphertext); S22, CDN node 4 sends the encrypted file back to client 6; S23, client 6 parses the encrypted file to obtain the encrypted comic image, encryption algorithm version EncryptVersion, and CDN public key C, and removes some random values used to obfuscate the data; S24, client 6 generates a shared key S=aC=a(bG)=abG based on the CDN public key C and the client private key a; S25. The client 6 obtains a symmetric key through a derivation function based on the shared key S, the salt value salt, and the additional information info. S26. The client 6 decrypts the obtained encrypted comic picture using the symmetric key and the obtained random variable (i.e., the target random variable) according to the queried encryption configuration information to obtain the decrypted comic picture. S27. The client 6 displays the decrypted comic picture.

[0140] Embodiment 2 Figure 10 A block diagram of a picture encryption device according to Embodiment 2 of the present application is schematically shown. The device can be divided into one or more program modules. One or more program modules are stored in a storage medium and executed by one or more processors to complete the embodiments of the present application. The program modules referred to in the embodiments of the present application refer to a series of computer program instruction segments that can complete specific functions. The following description will specifically introduce the functions of each program module in this embodiment. As Figure 10 shown, the device 1000 may include: a receiving module 1100, a first generating module 1200, an encryption module 1300, a second generating module 1400, and a returning module 1500, where: The receiving module 1100 is configured to receive a picture request sent by a client. The picture request includes encryption indication information and a first public key that matches a first private key in the client. The first generating module 1200 is configured to generate a mutually matching second private key and second public key. The encryption module 1300 is configured to encrypt the target picture corresponding to the picture request according to the first public key, the second private key, and the encryption indication information to obtain an encrypted picture corresponding to the target picture. The second generating module 1400 is configured to generate a picture ciphertext according to the second public key, the encrypted picture, and the encryption indication information. The returning module 1500 is configured to return the picture ciphertext to the client, so that the client decrypts the encrypted picture according to the second public key, the first private key, and the encryption indication information to obtain the target picture.

[0141] As an optional embodiment, the encryption indication information includes an encryption algorithm version and a client type. The device 1000 further includes a reading module for: obtaining a target binary string according to the encryption indication information; generating a target data buffer according to the target binary string; reading the encryption algorithm version from the target data buffer according to a first preset character position; Read the client type from the target data buffer according to the second preset character position.

[0142] As an optional embodiment, the picture request further includes a client salt value and a preset time threshold. The client salt value is generated by the client according to the first private key. The first generation module 1200 is further configured to: Determine whether the picture request is qualified according to the client salt value and the first public key; Determine whether the picture request times out according to the preset time threshold and the current time; Generate the second private key and the second public key when the picture request is qualified and the picture request does not time out.

[0143] As an optional embodiment, the encryption module 1300 is further configured to: Generate a shared key according to the first public key and the second private key; Determine the picture information corresponding to the target picture; Generate a derived key corresponding to the shared key through a preset derivation function according to the picture information and the shared key; Encrypt the target picture according to the encryption indication information and the derived key to obtain an encrypted picture corresponding to the target picture.

[0144] As an optional embodiment, the CDN node stores multiple candidate encryption algorithm configuration information updated from the server at preset time intervals. One candidate encryption algorithm configuration information corresponds to one candidate encryption algorithm version. The encryption module 1300 is further configured to: Dynamically select the corresponding target encryption algorithm configuration information from multiple candidate encryption algorithms according to the encryption algorithm version; Encrypt the target picture according to the target encryption algorithm configuration information and the derived key.

[0145] As an optional embodiment, the encryption indication information includes an encryption algorithm version and a client type. The encryption module 1300 is further configured to: Determine multiple groups of candidate random variables according to the client type. Each group of candidate random variables corresponds to a target algorithm version; Determine a group of candidate random variables with the target algorithm version being the encryption algorithm version as the target random variable corresponding to the target picture; Encrypt the target picture according to the target random variable, the encryption indication information and the derived key.

[0146] As an optional embodiment, the encryption module 1300 is further configured to: Determine whether the size of the target picture is greater than a preset threshold; When the size of the target picture is greater than the preset threshold, divide the target picture to obtain multiple picture slices; Encrypt multiple picture slices in sequence according to the first public key, the second private key, and the encryption indication information to obtain multiple encrypted slices, where one picture slice corresponds to one encrypted slice; Combine multiple encrypted slices to obtain the encrypted picture.

[0147] As an optional embodiment, the first private key is a first elliptic curve private key, and the first public key is a first elliptic curve public key generated according to the first elliptic curve private key and a preset base point on a preset elliptic curve; the second private key is a second elliptic curve private key, and the second public key is a second elliptic curve public key generated according to the second elliptic curve private key and the preset base point.

[0148] As an optional embodiment, the first public key and the first private key are dynamically generated by the client at preset time intervals; the second public key and the second private key are dynamically generated by the CDN node when receiving a picture request sent by the client.

[0149] Embodiment III Figure 11 Schematically shows a hardware architecture diagram of a computer device 10000 suitable for implementing the picture encryption method according to Embodiment III of the present application. In some embodiments, the computer device 10000 may be a terminal device such as a smart phone, a wearable device, a tablet computer, a personal computer, a vehicle-mounted terminal, a game console, a virtual device, a workbench, a digital assistant, a set-top box, a robot, etc. In other embodiments, the computer device 10000 may be a rack server, a blade server, a tower server, or a cabinet server (including an independent server or a server cluster composed of multiple servers), etc. As Figure 11 shown, the computer device 10000 includes, but is not limited to: a memory 10010, a processor 10020, and a network interface 10030 that can be communicatively linked to each other through a system bus. Among them: The memory 10010 includes at least one type of computer-readable storage medium. The readable storage medium includes flash memory, hard disk, multimedia card, card-type memory (such as SD or DX memory), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, magnetic disk, optical disc, etc. In some embodiments, the memory 10010 may be an internal storage module of the computer device 10000, such as the hard disk or memory of the computer device 10000. In other embodiments, the memory 10010 may also be an external storage device of the computer device 10000, such as a plug-in hard disk, Smart Media Card (SMC), Secure Digital (SD) card, Flash Card, etc. equipped on the computer device 10000. Of course, the memory 10010 may also include both the internal storage module and the external storage device of the computer device 10000. In this embodiment, the memory 10010 is generally used to store the operating system and various application software installed in the computer device 10000, such as the program code of the picture encryption method, etc. In addition, the memory 10010 may also be used to temporarily store various data that have been output or will be output.

[0150] In some embodiments, the processor 10020 may be a central processing unit (CPU), a controller, a microcontroller, a microprocessor, or other chips. The processor 10020 is generally used to control the overall operation of the computer device 10000, such as performing control and processing related to data interaction or communication with the computer device 10000. In this embodiment, the processor 10020 is used to run the program code stored in the memory 10010 or process data.

[0151] The network interface 10030 may include a wireless network interface or a wired network interface, which is generally used to establish a communication link between the computer device 10000 and other computer devices. For example, the network interface 10030 is used to connect the computer device 10000 to an external terminal through a network, and establish a data transmission channel and a communication link between the computer device 10000 and the external terminal. The network may be a wireless or wired network such as an enterprise intranet (Intranet), the Internet, the Global System of Mobile communication (abbreviated as GSM), Wideband Code Division Multiple Access (abbreviated as WCDMA), a 4G network, a 5G network, Bluetooth, Wi-Fi, etc.

[0152] It should be noted that Figure 11 Only the computer device with components 10010 - 10030 is shown, but it should be understood that it is not required to implement all the shown components, and more or fewer components can be implemented alternatively.

[0153] In this embodiment, the picture encryption method stored in the memory 10010 can also be divided into one or more program modules and executed by one or more processors (such as the processor 10020) to complete the embodiments of the present application.

[0154] Embodiment 4 The embodiments of the present application further provide a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the picture encryption method in the embodiments are implemented.

[0155] In this embodiment, the computer-readable storage medium includes flash memory, hard disks, multimedia cards, card-type memories (such as SD or DX memories, etc.), random access memories (RAM), static random access memories (SRAM), read-only memories (ROM), electrically erasable programmable read-only memories (EEPROM), programmable read-only memories (PROM), magnetic memories, magnetic disks, optical disks, etc. In some embodiments, the computer-readable storage medium may be an internal storage unit of a computer device, such as the hard disk or memory of the computer device. In other embodiments, the computer-readable storage medium may also be an external storage device of the computer device, such as a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, etc., equipped on the computer device. Of course, the computer-readable storage medium may also include both the internal storage unit and the external storage device of the computer device. In this embodiment, the computer-readable storage medium is generally used to store the operating system installed on the computer device and various application software, such as the program code of the picture encryption method in the embodiment. In addition, the computer-readable storage medium may also be used to temporarily store various data that have been output or will be output.

[0156] Embodiment 5 The embodiment of the present application also provides a computer program product, including a computer program, which when executed by a processor implements the method in the above embodiment.

[0157] Obviously, those skilled in the art should understand that the above-mentioned modules or steps of the embodiments of the present application can be implemented by a general-purpose computer device. They can be concentrated on a single computer device or distributed on a network composed of multiple computer devices. Optionally, they can be implemented by program codes executable by the computer device. Thus, they can be stored in a storage device and executed by the computer device. And in some cases, the steps shown or described can be executed in a different order from here, or they can be separately made into individual integrated circuit modules, or multiple modules or steps among them can be made into a single integrated circuit module to implement. In this way, the embodiments of the present application are not limited to any specific combination of hardware and software.

[0158] It should be noted that the above are only the preferred embodiments of the present application, and do not limit the patent protection scope of the present application. Any equivalent structure or equivalent process transformation made by using the content of the specification and drawings of the present application, or directly or indirectly applied in other related technical fields, shall be equally included in the patent protection scope of the present application.

Claims

1. A method for encrypting pictures, characterized in that, In the edge function service for CDN nodes, the method includes: Receiving an image request sent by a client, where the image request includes encryption indication information and a first public key that matches a first private key in the client; Generating a second private key and a second public key that match each other; Encrypting the target image corresponding to the image request according to the first public key, the second private key, and the encryption indication information to obtain an encrypted image corresponding to the target image; Generating an image ciphertext according to the second public key, the encrypted image, and the encryption indication information; Returning the image ciphertext to the client so that the client decrypts the encrypted image according to the second public key, the first private key, and the encryption indication information to obtain the target image.

2. The method according to claim 1, wherein The encryption indication information includes an encryption algorithm version and a client type; the method further includes: Obtaining a target binary string according to the encryption indication information; Generating a target data buffer according to the target binary string; Reading the encryption algorithm version from the target data buffer according to a first preset character position; Reading the client type from the target data buffer according to a second preset character position.

3. The method according to claim 1, characterized in that, The image request further includes a preset salt value and a preset time threshold, and the preset salt value is generated by the client according to the first private key; Generating a second private key and a second public key that match each other includes: Determining whether the image request is qualified according to the preset salt value and the first public key; Determining whether the image request times out according to the preset time threshold and the current time; Generating the second private key and the second public key when the image request is qualified and the image request does not time out.

4. The method according to claim 1, wherein Encrypting the target image corresponding to the image request according to the first public key, the second private key, and the encryption indication information to obtain an encrypted image corresponding to the target image, includes: Generating a shared key according to the first public key and the second private key; Determining the image information corresponding to the target image; Generating a derived key corresponding to the shared key through a preset derivation function according to the image information and the shared key; Encrypting the target image according to the encryption indication information and the derived key to obtain an encrypted image corresponding to the target image.

5. The method according to claim 4, wherein The CDN node stores multiple candidate encryption algorithm configuration information updated from the server at preset time intervals, and one candidate encryption algorithm configuration information corresponds to one candidate encryption algorithm version; Encrypting the target image according to the encryption indication information and the derived key, includes: Dynamically selecting corresponding target encryption algorithm configuration information from multiple candidate encryption algorithms according to the encryption algorithm version; Encrypting the target image according to the target encryption algorithm configuration information and the derived key.

6. The method according to claim 4, wherein The encryption indication information includes an encryption algorithm version and a client type; Encrypting the target image according to the encryption indication information and the derived key, includes: Determining multiple groups of candidate random variables according to the client type, and each group of candidate random variables corresponds to a target algorithm version; Determine a set of candidate random variables with the target algorithm version being the encryption algorithm version as the target random variables corresponding to the target picture; Encrypt the target picture according to the target random variables, the encryption indication information, and the derived key.

7. The method according to any one of claims 1 to 6, characterized in that, Encrypt the target picture corresponding to the picture request according to the first public key, the second private key, and the encryption indication information to obtain the encrypted picture corresponding to the target picture, including: Determine whether the size of the target picture is greater than a preset threshold; In the case where the size of the target picture is greater than the preset threshold, divide the target picture to obtain a plurality of picture slices; Encrypt the plurality of picture slices in sequence according to the first public key, the second private key, and the encryption indication information to obtain a plurality of encrypted slices, one picture slice corresponding to one encrypted slice; Combine the plurality of encrypted slices to obtain the encrypted picture.

8. The method according to any one of claims 1 to 6, characterized in that The first private key is a first elliptic curve private key, and the first public key is a first elliptic curve public key generated according to the first elliptic curve private key; the second private key is a second elliptic curve private key, and the second public key is a second elliptic curve public key generated according to the second elliptic curve private key.

9. The method according to any one of claims 1 to 6, characterized in that, The first public key and the first private key are dynamically generated by the client at a predetermined time interval; the second public key and the second private key are dynamically generated by the CDN node when receiving a picture request sent by the client.

10. An image encryption device, characterized in that, In an edge function service for a CDN node, the device includes: A receiving module, configured to receive a picture request sent by a client, where the picture request includes encryption indication information and a first public key matching a first private key in the client; A first generation module, configured to generate a mutually matching second private key and second public key; An encryption module, configured to encrypt the target picture corresponding to the picture request according to the first public key, the second private key, and the encryption indication information to obtain the encrypted picture corresponding to the target picture; A second generation module, configured to generate a picture ciphertext according to the second public key, the encrypted picture, and the encryption indication information; A return module, configured to return the picture ciphertext to the client, so that the client decrypts the encrypted picture according to the second public key, the first private key, and the encryption indication information to obtain the target picture.

11. A computer device, characterized in that, Includes: At least one processor; And A memory communicatively connected to the at least one processor; wherein: The memory stores instructions executable by the at least one processor, and when the instructions are executed by the at least one processor, the at least one processor is enabled to execute the method according to any one of claims 1 to 9.

12. A computer-readable storage medium, characterized in that, Computer instructions are stored in the computer-readable storage medium, and when the computer instructions are executed by a processor, the method according to any one of claims 1 to 9 is implemented.

13. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 9 are implemented.