Data encryption and decryption method and device, computer equipment and storage medium

By combining dynamic salt values and random initialization vectors with AES128 encryption algorithm and PKCS7 Padding filling method, the problem of key leakage in the static encryption method is solved, and high-security data encryption and decryption in the financial and medical health fields is realized, and the system's protection capabilities and data integrity are enhanced.

CN120389899APending Publication Date: 2025-07-29PING AN TECH (SHENZHEN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510694833.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-27
Publication Date
2025-07-29

AI Technical Summary

Technical Problem

The existing encryption methods at rest have the risk of key leakage in the financial and medical health fields, resulting in insufficient data security and inability to effectively resist external threats and enhance internal management security.

Method used

Dynamic salt value and random initialization vector are used to combine AES128 encryption algorithm and PKCS7Padding filling method to obtain dynamic salt value through OAuth authentication, randomly generate 16-bit secure random numbers as initialization vectors, and Base64 encoding is performed to ensure that different ciphertexts are generated each time encryption is generated.

Benefits of technology

It improves the security and confidentiality of data, effectively resists replay attacks and dictionary attacks, enhances the security of internal management, ensures that only authorized users can obtain sensitive information, and improves the overall security and data integrity of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120389899A_ABST
    Figure CN120389899A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data security, finance and medical health, and discloses a data encryption and decryption method and device, computer equipment and a storage medium. The method comprises the steps of obtaining a dynamic salt value; randomly generating an initialization vector to obtain a random vector; when data encryption needs to be carried out, acquiring a to-be-encrypted plaintext; encrypting the to-be-encrypted plaintext by using the dynamic salt value and the random vector, and encoding to obtain an encoding result; and transmitting the coding result to a specified end, so that the specified end verifies the validity of the initialization vector according to the ID of the random vector, reversely decrypts the coding result by using the corresponding random vector and the original initial vector to recover the plaintext to be encrypted, and returns the plaintext to be encrypted. By implementing the method provided by the invention, the overall security of the system can be improved, external threats can be effectively resisted, and the security of internal management can be enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical fields of data security, finance, and medical and health technologies, and more specifically, to a data encryption and decryption method, apparatus, computer device, and storage medium. Background Art

[0002] In modern data transmission and storage systems, especially in the fields of finance and medical and health, ensuring the security of users' sensitive information is of utmost importance. Traditionally, static encryption methods have been widely used to protect the confidentiality and integrity of this information. However, this method has significant security risks: once the encryption key is leaked, attackers can easily access all encrypted data; moreover, the long-term use of the same key increases the risk of it becoming a target of attack.

[0003] For financial institutions, the high sensitivity of customer information such as bank accounts and transaction records requires more advanced security measures to prevent potential data leakage risks. Similarly, in the field of medical and health, the protection of patient personal information and medical records not only relates to personal privacy but also may affect the quality and security of medical services. Therefore, relying solely on static encryption is no longer sufficient to meet the high standards of data protection required by these industries.

[0004] Therefore, it is necessary to design a new method to improve the overall security of the system, which can not only effectively resist external threats but also enhance the security of internal management. Summary of the Invention

[0005] The purpose of the present invention is to overcome the defects of the prior art and provide a data encryption and decryption method, apparatus, computer device, and storage medium.

[0006] To achieve the above purpose, the present invention adopts the following technical solutions: A data encryption and decryption method, comprising:

[0007] Obtain a dynamic salt value;

[0008] Randomly generate an initialization vector to obtain a random vector;

[0009] When data encryption is required, obtain the plaintext to be encrypted;

[0010] Use the dynamic salt value and the random vector to encrypt the plaintext to be encrypted and perform encoding to obtain an encoding result;

[0011] Transmit the encoding result to a specified end, so that the specified end verifies the validity of the initialization vector according to the ID of the random vector, reversely decrypts the encoding result using the corresponding random vector and the original initialization vector to restore the plaintext to be encrypted, and returns the plaintext to be encrypted.

[0012] Its further technical solution is: The obtaining of the dynamic salt value includes:

[0013] Sending a request through OAuth authentication to obtain the dynamic salt value and the corresponding ID.

[0014] Its further technical solution is: The randomly generating an initialization vector to obtain a random vector includes:

[0015] Using a 16-bit secure random number as the random vector.

[0016] Its further technical solution is: The using of the dynamic salt value and the random vector to encrypt the plaintext to be encrypted and perform encoding to obtain an encoded result includes:

[0017] Using the dynamic salt value and the random vector to perform AES128 encryption on the plaintext to be encrypted to obtain encrypted data;

[0018] Performing Base64 encoding on the encrypted data to obtain an encoded result.

[0019] Its further technical solution is: The using of the dynamic salt value and the random vector to perform AES128 encryption on the plaintext to be encrypted to obtain encrypted data includes:

[0020] Dividing the plaintext to be encrypted into blocks of 16 bytes each, and padding the last block with less than 16 bytes using PKCS7Padding to obtain multiple plaintext blocks;

[0021] Adopting a chained encryption processing method to process all the plaintext blocks in sequence to obtain encrypted data.

[0022] Its further technical solution is: The adopting of a chained encryption processing method to process all the plaintext blocks in sequence to obtain encrypted data includes:

[0023] XORing the first plaintext block with the random vector and then using AES encryption to generate the first ciphertext block; XORing each subsequent plaintext block with the previous ciphertext block and then using AES encryption to process all the plaintext blocks in sequence to obtain encrypted data.

[0024] Its further technical solution is: The using of the corresponding random vector and the original initialization vector to decrypt the encoded result in reverse to recover the plaintext to be encrypted includes:

[0025] Decode the encoded result, split the decoded ciphertext data into multiple 16-byte ciphertext blocks, and after decrypting the first ciphertext block using the AES algorithm, perform an exclusive OR operation with the random vector to recover the first plaintext block; starting from the second ciphertext block, each ciphertext block is first decrypted using the AES algorithm and then performs an exclusive OR operation with the previous ciphertext block, and so on, to recover the plaintext to be encrypted.

[0026] The present invention also provides a data encryption and decryption device, including:

[0027] A salt value acquisition unit for acquiring a dynamic salt value;

[0028] A random generation unit for randomly generating an initialization vector to obtain a random vector;

[0029] A plaintext acquisition unit for acquiring the plaintext to be encrypted when data encryption is required;

[0030] An encryption and encoding unit for encrypting the plaintext to be encrypted using the dynamic salt value and the random vector and performing encoding to obtain an encoded result;

[0031] A transmission unit for transmitting the encoded result to a specified end, so that the specified end verifies the validity of the initialization vector according to the ID of the random vector, reversely decrypts the encoded result using the corresponding random vector and the original initialization vector to recover the plaintext to be encrypted, and returns the plaintext to be encrypted.

[0032] The present invention also provides a computer device, the computer device includes a memory and a processor, a computer program is stored on the memory, and when the processor executes the computer program, the above method is implemented.

[0033] The present invention also provides a storage medium, the storage medium stores a computer program, and when the computer program is executed by a processor, the above method is implemented.

[0034] The beneficial effects of the present invention compared with the prior art are as follows: By dynamically obtaining the salt value unique to each encryption operation and randomly generating an initialization vector, and combining the AES128 algorithm with the PKCS7Padding padding method during the data encryption process, the present invention ensures that even the same plaintext encrypted at different times will generate different ciphertexts, greatly enhancing the security and confidentiality of the data. This mechanism not only effectively resists external threats such as replay attacks and dictionary attacks, but also protects the access rights of the saltKey through OAuth authentication, ensuring that only authorized users can obtain sensitive salt value information, thereby enhancing the security of internal management. In addition, using Base64 encoding ensures the integrity and compatibility of the encrypted data during network transmission, and transmits the encrypted result through a secure communication channel, further improving the overall security of the system. Finally, by verifying the validity of the random vector ID to decrypt the data, the security of the decryption process and the integrity of the data are ensured, providing a solid guarantee for application scenarios with high requirements for data security such as financial transactions and medical and health fields.

[0035] The following further describes the present invention with reference to the accompanying drawings and specific embodiments. Description of the Drawings

[0036] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other accompanying drawings can be obtained based on these drawings without creative efforts.

[0037] Figure 1 It is a schematic diagram of the application scenario of the data encryption and decryption method provided by the embodiment of the present invention;

[0038] Figure 2 It is a schematic flowchart of the data encryption and decryption method provided by the embodiment of the present invention;

[0039] Figure 3 It is a schematic sub - flowchart of the data encryption and decryption method provided by the embodiment of the present invention;

[0040] Figure 4 It is a schematic sub - flowchart of the data encryption and decryption method provided by the embodiment of the present invention;

[0041] Figure 5 It is a schematic block diagram of the data encryption and decryption device provided by the embodiment of the present invention;

[0042] Figure 6 It is a schematic block diagram of the encryption encoding unit of the data encryption and decryption device provided by the embodiment of the present invention;

[0043] Figure 7Schematic block diagram of the encryption subunit of the data encryption and decryption device provided by an embodiment of the present invention;

[0044] Figure 8 Schematic block diagram of the computer device provided by an embodiment of the present invention. Detailed implementation manners

[0045] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0046] It should be understood that when used in this specification and the appended claims, the terms "comprises" and "comprising" indicate the presence of the described features, wholes, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or their combinations.

[0047] It should also be understood that the terms used in this specification of the present invention are only for the purpose of describing specific embodiments and are not intended to limit the present invention. As used in this specification of the present invention and the appended claims, unless the context clearly indicates otherwise, the singular forms "a", "an", and "the" are intended to include the plural forms.

[0048] It should be further understood that the term " / and / " used in this specification of the present invention and the appended claims refers to any combination and all possible combinations of one or more of the related listed items, and includes these combinations.

[0049] Please refer to Figure 1 and Figure 2 , Figure 1 Schematic diagram of the application scenario of the data encryption and decryption method provided by an embodiment of the present invention. Figure 2Schematic flowchart of the data encryption and decryption method provided by the embodiments of the present invention. This data encryption and decryption method is applied to a terminal. The server interacts with the terminal for data. The specified end can be the server or the terminal. By combining a dynamic salt value, a randomly generated IV (Initialization Vector), and the AES128 encryption algorithm, and adopting a chained encryption processing method to perform block encryption and Base64 encoding on the data, the confidentiality and integrity of the data during transmission are ensured. The dynamic salt value and its ID are obtained by using OAuth authentication, which increases the security and unpredictability of the salt value. At the same time, by performing PKCS7Padding padding on the plaintext block and performing an exclusive OR operation with the previous ciphertext block, the encryption strength is further enhanced, making it difficult for attackers to easily crack the encrypted data through known plaintext attacks or other means. This method not only effectively resists external threats such as man-in-the-middle attacks and data leakage, but also enhances the security of internal management by verifying the validity of the initialization vector at the specified end, ensuring that only legitimate users can correctly decrypt and access the original data, thus comprehensively improving the security of the system.

[0050] Figure 2 is a schematic flowchart of the data encryption and decryption method provided by the embodiments of the present invention. As Figure 2 shown, the method includes the following steps S110 to S150.

[0051] S110. Obtain a dynamic salt value.

[0052] In this embodiment, the dynamic salt value means that each time data encryption operation is performed, the salt value (saltKey) used is dynamically obtained rather than fixed. This mechanism significantly improves the security of the data by ensuring that different salt values are used for each encryption operation, and prevents the risk of large-scale data leakage caused by key leakage.

[0053] Specifically, a request is sent through OAuth authentication to obtain the dynamic salt value and the corresponding ID.

[0054] Specifically, in order to implement the management of the dynamic salt value, the system designs a dynamic acquisition interface, which requires a request to be sent through OAuth authentication to obtain the dynamic salt value and the corresponding ID. OAuth authentication, as an open standard, is used to authorize users to access resources without exposing their credentials. In this scenario, OAuth is used to verify the identity of the requester, ensuring that only legitimate users can obtain the dynamically generated salt value and its corresponding unique identifier. This step not only enhances the confidentiality and unpredictability of the salt value itself, but also provides the necessary parameter support for the subsequent data encryption and decryption processes.

[0055] When the business system needs to encrypt data, it first sends a request to the salt value service through OAuth authentication. Once the request is verified as legitimate, the salt value service generates a time-limited saltKey and returns this saltKey along with its unique identifier to the requester. This approach ensures that even if the same plaintext data is encrypted at different time points, completely different encryption results will be produced due to the use of different saltKeys, greatly enhancing the data security and privacy protection level.

[0056] In addition, by using dynamic salt values and randomly generated initialization vectors, even the same plaintext data will generate a unique ciphertext during each encryption process, which further enhances the system's security and enables it to effectively resist common security threats such as replay attacks and dictionary attacks. Therefore, the introduction of dynamic salt values is not just a simple technical improvement, but an important upgrade to the existing encryption scheme, especially suitable for application fields with high requirements for data security, such as finance, healthcare, etc.

[0057] S120. Randomly generate an initialization vector to obtain a random vector.

[0058] In this embodiment, the random vector refers to a 16-byte random value used during the encryption process. This IV is used to ensure that even when the same plaintext data is encrypted at different time points, different ciphertext outputs will be generated, thus greatly enhancing the security of the encryption. Specifically, before performing the AES128 encryption operation, the system generates a 16-bit secure random number as the IV.

[0059] Specifically, a 16-bit secure random number is used as the random vector.

[0060] The random vector is a 16-byte random numerical value that plays a crucial role in the encryption process. Especially in the CBC (Cipher Block Chaining) mode, the IV is used to perform an exclusive OR operation with the first plaintext block and then encrypted through the AES algorithm. This mechanism ensures that even for exactly the same plaintext data, as long as different IVs are used, the generated ciphertexts will be completely different, effectively preventing potential replay attacks and dictionary attacks.

[0061] A 16-bit secure random number is used as the random vector. This means that the system will use a secure random number generator to create a 16-byte random sequence. This random sequence must have sufficient entropy to ensure its unpredictability and uniqueness. A common practice is to use the secure random number generation service provided by the operating system or a specially designed cryptographically secure pseudo-random number generator.

[0062] Since the IV directly affects the security of encryption, its generation process must follow strict security standards. On the one hand, it is required to use a brand-new and independently generated IV for each encryption operation. On the other hand, the IV itself should not contain any sensitive information, and it also needs to be properly protected during transmission and storage to prevent security risks caused by leakage.

[0063] In practical applications, after the business system receives the saltKey and before preparing to start the encryption operation, it will perform a self-call operation to generate this random IV. The generated IV will be processed together with the data to be encrypted. First, it will be filled into the data header, and then encrypted according to the specified process of the AES128 CBC mode. For the decrypting party, the correct saltKey and IV are required to accurately restore the original plaintext data.

[0064] Through the above steps, the method of this embodiment not only strengthens the security of the encryption scheme, but also overcomes many security hazards existing in traditional static encryption methods by dynamically managing the salt value and randomly generating the IV. It is particularly suitable for applications in fields with high requirements for data security, such as financial transactions, medical health records, etc. This method significantly improves the overall security protection ability of the system and ensures the security and privacy of user information.

[0065] S130. When data encryption is required, obtain the plaintext to be encrypted.

[0066] In this embodiment, the plaintext to be encrypted refers to the original information or data to be encrypted, which can be any form of data, such as text, numbers, file content, etc. These data exist in plaintext before encryption and may contain sensitive information, so encryption is required to protect their confidentiality and integrity.

[0067] S140. Encrypt the plaintext to be encrypted using the dynamic salt value and the random vector, and perform encoding to obtain an encoding result.

[0068] In this embodiment, the encoding result refers to the output after being processed by the AES128 encryption algorithm and encoded using Base64. This encoding method enables binary data to be safely transmitted or stored on the network, avoiding data corruption or loss problems caused by invisible characters.

[0069] In one embodiment, please refer to Figure 3 , the above step S140 may include steps S141 to S142.

[0070] S141. Encrypt the plaintext to be encrypted using the dynamic salt value and the random vector with AES128 to obtain encrypted data.

[0071] In this embodiment, the encrypted data refers to the ciphertext generated using the AES128 encryption algorithm in combination with the CBC mode and the PKCS7Padding padding method. Each plaintext block is converted into a corresponding ciphertext block after specific processing, and finally a complete encrypted data stream is formed.

[0072] In one embodiment, refer to Figure 4 , the above step S141 may include steps S1411 to S1412.

[0073] S1411. Divide the plaintext to be encrypted into blocks of 16 bytes each, and pad the last block with less than 16 bytes using PKCS7Padding to obtain multiple plaintext blocks.

[0074] In this embodiment, multiple plaintext blocks refer to the data blocks obtained by dividing the plaintext to be encrypted into blocks of 16 bytes each.

[0075] First, divide the plaintext to be encrypted into multiple blocks of 16 bytes in size. If the length of the last block is less than 16 bytes, use the PKCS7Padding method to pad it until its size reaches 16 bytes.

[0076] S1412. Process all the plaintext blocks in sequence using a chained encryption processing method to obtain the encrypted data.

[0077] In this embodiment, after performing an exclusive OR operation on the first plaintext block and the random vector, use AES encryption to generate the first ciphertext block; each subsequent plaintext block is exclusive ORed with the previous ciphertext block and then encrypted with AES, and all the plaintext blocks are processed in sequence to obtain the encrypted data.

[0078] Specifically, perform an exclusive OR operation on the first plaintext block and a randomly generated 16-byte IV (initialization vector), and then encrypt it with AES128 to generate the first ciphertext block.

[0079] For each subsequent plaintext block, first perform an exclusive OR operation with the previous ciphertext block, and then apply AES128 encryption. Repeat this process until all plaintext blocks are processed, thereby forming a complete ciphertext sequence. This chained processing method ensures that even if the same plaintext is encrypted twice, as long as different IVs are used, the corresponding ciphertexts will be completely different, greatly enhancing the security of encryption.

[0080] S142. Perform Base64 encoding on the encrypted data to obtain the encoding result.

[0081] In this embodiment, the last step is to perform Base64 encoding on the encrypted binary data. This not only facilitates the transmission of data over the network but also ensures that the data can be correctly exchanged between different systems because the Base64-encoded string contains only characters from the ASCII character set, avoiding many potential compatibility issues. Base64 encoding not only improves the security and reliability of data transmission but also simplifies the cross-platform data exchange process.

[0082] Through the above steps, the method of this embodiment effectively improves the data security protection level by introducing a dynamic refresh mechanism to update the salt value, combining the randomly generated IV, and the powerful encryption ability of the AES128 algorithm. In addition, the final output is the Base64-encoded result, which further enhances the compatibility and stability of the data in the network environment and is applicable to various application scenarios with high security requirements. It is particularly suitable for application scenarios with high security requirements, such as financial transactions and personal privacy protection. This method not only improves the security of data but also ensures the flexibility and usability of the system.

[0083] S150. Transmit the encoded result to a specified end, so that the specified end verifies the validity of the initialization vector according to the ID of the random vector, and uses the corresponding random vector and the original initialization vector to decrypt the encoded result in reverse to recover the plaintext to be encrypted, and return the plaintext to be encrypted.

[0084] In this embodiment, the encoded result is decoded, the decoded ciphertext data is split into multiple 16-byte ciphertext blocks, and after the first ciphertext block is decrypted by the AES algorithm, it is XORed with the random vector to recover the first plaintext block; starting from the second ciphertext block, each ciphertext block is first decrypted by the AES algorithm and then XORed with the previous ciphertext block, and so on, to recover the plaintext to be encrypted.

[0085] Specifically, in this embodiment, step S150 involves transmitting the encrypted encoded result to a specified end, and this end performs verification and decryption operations to recover the original plaintext to be encrypted.

[0086] The data (i.e., the encoded result) after AES128 encryption and Base64 encoding is sent to a specified end.

[0087] During the transmission process, the encoded result is usually sent through a secure communication channel to ensure the security of the data during transmission.

[0088] After the specified end receives the encoded result, it first verifies the validity of the random vector (IV) according to its ID.

[0089] This ID is generated together with the saltKey and transmitted along with the encoded result during encryption, used to identify the specific IV used. If the IV ID is valid, the corresponding random vector is obtained; if invalid, the decryption request is rejected.

[0090] Use the Base64 decoding method to decode the encoded result to obtain the ciphertext data in binary form.

[0091] Divide the decoded ciphertext data into multiple ciphertext blocks according to a size of 16 bytes. Each ciphertext block corresponds to a 16-byte block of the original plaintext or a padded block.

[0092] For the first ciphertext block, use the same saltKey as the key and decrypt it through the AES algorithm. Then, perform an exclusive OR operation on the decrypted result with the original random vector (IV) to recover the first plaintext block.

[0093] Starting from the second ciphertext block, apply AES decryption to each ciphertext block in turn. Then, perform an exclusive OR operation on the decrypted result with the previous ciphertext block to gradually recover each plaintext block.

[0094] This process is repeated until all ciphertext blocks are processed, and finally the complete original plaintext data is obtained.

[0095] After completing the above decryption steps, the recovered plaintext data will be returned to the business system as a response result.

[0096] If any abnormal situation occurs during the decryption process (such as saltKey failure, data corruption, etc.), the corresponding exception handling mechanism should be triggered to ensure the stability of the system and the security of the data.

[0097] By introducing dynamic salt value management and random initialization vector (IV), the method of this embodiment provides an efficient and secure data encryption and decryption solution. Especially the decryption process described in step S150 not only ensures the security of data transmission, but also can effectively prevent the risk of large-scale data leakage caused by key leakage. In addition, this method can be seamlessly integrated without large-scale transformation of the existing system, having significant technical advantages and market competitiveness. This solution is particularly suitable for application scenarios that require high security, such as the financial and medical and health fields, and helps to protect the security of user information.

[0098] In this embodiment, when the business system needs to encrypt data, first send a request to the salt value service through OAuth authentication to obtain a valid saltKey (salt value). This step ensures that only the verified business system can access sensitive salt value information.

[0099] Once the salt value service verifies the legitimacy of the request, it will generate a time-limited saltKey and return its ID and key to the business system together. The purpose of doing this is to ensure the validity and security of the saltKey and prevent its abuse.

[0100] After receiving the saltKey, the business system will perform a self-call operation to generate a random initialization vector (IV). This random IV is used for subsequent encryption processes to ensure that even for the same plaintext, the ciphertext generated each time is unique, increasing the security of the encryption.

[0101] The business system uses the saltKey obtained from the salt value service as a dynamic key. This strategy significantly improves the security of the data because the key used for each encryption is different. The previously generated random IV is filled into the data to be encrypted to ensure that each encryption block has a unique starting point, further enhancing the security of the encryption. According to the provided SDK, the business system selects the AES128 CBC mode to encrypt the data containing the IV. This mode combines the Advanced Encryption Standard (AES) and Cipher Block Chaining (CBC) to provide high security.

[0102] After receiving the encrypted data, the service system first determines its validity based on the ID of the saltKey. If it is invalid, the decryption request is rejected; if it is valid, the next step is continued. The service system obtains the corresponding saltKey from the salt value service based on the valid saltId for decryption operations. Using the obtained saltKey and the previously filled random IV, the service system performs reverse decryption on the data in the same AES128 CBC mode as the business system to restore the original data.

[0103] If the decryption is successful, the service system returns the decrypted data to the business system as the response result, thus completing the entire encryption and decryption process. If any problems occur during the decryption process (such as saltKey expiration, data corruption, etc.), the service system should have corresponding exception handling mechanisms to ensure the stability of the system and the security of the data.

[0104] The entire process significantly enhances the security of data transmission and storage by dynamically refreshing the use of saltKey and random IV. Especially in the financial and healthcare fields, this mechanism can effectively prevent data leakage and illegal access, safeguarding the security of user information. The method of this embodiment solves the security risks existing in the static encryption method in the existing system by introducing dynamic salt value management and AES128 encryption method, improving the security of data and the stability of the system. This solution not only improves the processing capacity and response speed of the system, but also enhances the consistency and security of data, and is applicable to efficient data query and update operations in large-scale distributed systems, with significant technical advantages and market competitiveness.

[0105] Specifically, each encryption operation uses a different saltKey, significantly improving the security of data and preventing the risk of large-scale data leakage caused by key leakage. Most static encryption methods use fixed keys, while the present invention achieves a higher security standard by dynamically refreshing the salt value.

[0106] Using a randomly generated 16-byte IV ensures the uniqueness of each encryption, and even the same plaintext will produce different ciphertexts. Some systems may use fixed or predictable IVs, which may lead to the predictability of encryption results and thus reduce security.

[0107] Adopting the AES128 algorithm and PKCS7Padding padding method, combined with dynamic salt value and random IV, provides an efficient and secure encryption solution. Although AES128 is a widely used encryption algorithm, the combination of dynamic salt value and random IV is not common in practical applications, and the present invention makes an innovation on this basis. Many encryption solutions require major modifications to the existing system, increasing the implementation difficulty and cost, while the method of this embodiment realizes seamless integration through a dynamic interface.

[0108] For example: In financial transactions, it is crucial to protect customers' sensitive information such as bank account information, transaction details, etc. Traditional static encryption methods are vulnerable to attacks due to the use of fixed keys and predictable IVs, resulting in data leakage.

[0109] When a user initiates an online transfer request, the business system first sends a request to the salt value service through OAuth authentication to obtain a valid saltKey. After verifying the request, the salt value service generates a time-limited saltKey and returns the saltKey and its ID to the business system.

[0110] After receiving the saltKey, the business system generates a random 16-byte IV. This random IV ensures that even the same transaction information will produce different ciphertexts when encrypted at different time points, increasing security.

[0111] Use the dynamic saltKey as the key, combined with a random IV, and encrypt the data containing transaction information in AES128 CBC mode. The encrypted data is then Base64 encoded for easy transmission over the network.

[0112] The encrypted data is transmitted to the receiving end through a secure communication channel. The receiving end obtains the corresponding saltKey from the salt value service according to the ID of the saltKey, and uses this saltKey and the original random IV to decrypt the data in reverse to restore the original transaction information.

[0113] The dynamic refresh of the saltKey and the random IV significantly improves the security of the data, preventing the risk of large-scale data leakage caused by key leakage.

[0114] Combined with the AES128 encryption algorithm and the PKCS7Padding padding method, it provides an efficient and secure data encryption solution.

[0115] Take another example: In the healthcare industry, patients' personal information (such as medical records, diagnosis results, etc.) is highly sensitive. Traditional encryption methods may not provide sufficient security, especially in scenarios of data sharing and remote access.

[0116] When a doctor needs to view a patient's electronic medical record, the system first sends a request to the salt value service through OAuth authentication to obtain a valid saltKey. After verifying the request, the salt value service generates a time-limited saltKey and returns the saltKey and its ID to the business system.

[0117] The system generates a random 16-byte IV for the subsequent encryption process. The random IV ensures that even the same medical record information will produce different ciphertexts when encrypted at different time points, enhancing security.

[0118] Use the dynamic saltKey as the key, combined with a random IV, and encrypt the patient's medical record data in AES128 CBC mode. The encrypted data is Base64 encoded for easy transmission or storage over the network.

[0119] The encrypted medical record data is transmitted to the doctor's workstation or other designated locations through a secure communication channel. After receiving the data, the system obtains the corresponding saltKey from the salt value service according to the ID of the saltKey, and uses this saltKey and the original random IV to decrypt the data in reverse to restore the original medical record information.

[0120] Dynamically refreshing the saltKey and random IV greatly enhances the security of data transmission and storage, effectively preventing data leakage and unauthorized access.

[0121] Adopting the AES128 encryption algorithm and PKCS7Padding padding method provides an efficient and secure data encryption solution, which is particularly suitable for application scenarios with high requirements for data security.

[0122] This solution can achieve seamless integration without large-scale transformation of the existing system, has significant technical advantages and market competitiveness, and is suitable for data protection requirements in the financial and healthcare fields.

[0123] The above data encryption and decryption method dynamically obtains the salt value unique to each encryption operation and randomly generates an initialization vector, and combines the AES128 algorithm with the PKCS7Padding padding method during the data encryption process to ensure that even the same plaintext encrypted at different times will generate different ciphertexts, greatly enhancing the security and confidentiality of the data. This mechanism not only effectively resists external threats such as replay attacks and dictionary attacks, but also protects the access rights of the saltKey through OAuth authentication to ensure that only authorized users can obtain sensitive salt value information, thereby enhancing the security of internal management. In addition, using Base64 encoding ensures the integrity and compatibility of the encrypted data during network transmission, and transmits the encrypted result through a secure communication channel, further improving the overall security of the system. Finally, the data is decrypted by verifying the validity of the random vector ID, ensuring the security of the decryption process and the integrity of the data, providing a solid guarantee for application scenarios with high requirements for data security such as financial transactions and healthcare.

[0124] Figure 5 It is a schematic block diagram of a data encryption and decryption device 300 provided by an embodiment of the present invention. As Figure 5 shown, corresponding to the above data encryption and decryption method, the present invention also provides a data encryption and decryption device 300. The data encryption and decryption device 300 includes units for executing the above data encryption and decryption method, and the device can be configured in terminals such as desktop computers, tablet computers, laptops, etc. Specifically, please refer to Figure 5 , the data encryption and decryption device 300 includes a salt value acquisition unit 301, a random generation unit 302, a plaintext acquisition unit 303, an encryption encoding unit 304, and a transmission unit 305.

[0125] A salt value acquisition unit 301 for acquiring a dynamic salt value; a random generation unit 302 for randomly generating an initialization vector to obtain a random vector; a plaintext acquisition unit 303 for acquiring a plaintext to be encrypted when data encryption is required; an encryption and encoding unit 304 for encrypting the plaintext to be encrypted using the dynamic salt value and the random vector and performing encoding to obtain an encoding result; a transmission unit 305 for transmitting the encoding result to a specified end, so that the specified end verifies the validity of the initialization vector according to the ID of the random vector, reversely decrypts the encoding result using the corresponding random vector and the original initialization vector to recover the plaintext to be encrypted, and returns the plaintext to be encrypted.

[0126] In one embodiment, the salt value acquisition unit 301 is configured to send a request through OAuth authentication to acquire a dynamic salt value and a corresponding ID.

[0127] In one embodiment, the random generation unit 302 is configured to use a 16-bit secure random number as the random vector.

[0128] In one embodiment, as Figure 6 shown, the encryption and encoding unit 304 includes an encryption subunit 3041 and an encoding subunit 3042.

[0129] The encryption subunit 3041 is configured to perform AES128 encryption on the plaintext to be encrypted using the dynamic salt value and the random vector to obtain encrypted data; the encoding subunit 3042 is configured to perform Base64 encoding on the encrypted data to obtain an encoding result.

[0130] In one embodiment, as Figure 7 shown, the encryption subunit 3041 includes a partitioning module 30411 and a chained encryption processing module 30412.

[0131] The partitioning module 30411 is configured to partition the plaintext to be encrypted into blocks of 16 bytes each, and pad the last block with less than 16 bytes using PKCS7Padding to obtain a plurality of plaintext blocks; the chained encryption processing module 30412 is configured to sequentially process all the plaintext blocks in a chained encryption processing manner to obtain encrypted data.

[0132] In one embodiment, the chained encryption processing module 30412 is configured to perform an exclusive OR operation on the first plaintext block and the random vector and then use AES encryption to generate the first ciphertext block; each subsequent plaintext block is exclusive ORed with the previous ciphertext block and then encrypted using AES, and all the plaintext blocks are sequentially processed to obtain encrypted data.

[0133] In one embodiment, the transmission unit 305 is configured to decode the encoding result, split the decoded ciphertext data into multiple 16-byte ciphertext blocks, and perform an exclusive OR operation between the decrypted first ciphertext block using the AES algorithm and the random vector to recover the first plaintext block; starting from the second ciphertext block, each ciphertext block is first decrypted using the AES algorithm and then subjected to an exclusive OR operation with the previous ciphertext block, and so on, to recover the plaintext to be encrypted.

[0134] It should be noted that those skilled in the art can clearly understand the specific implementation processes of the above data encryption and decryption device 300 and each unit. They can refer to the corresponding descriptions in the foregoing method embodiments. For the sake of convenience and brevity of description, they will not be elaborated here.

[0135] The above data encryption and decryption device 300 can be implemented in the form of a computer program, and this computer program can run on a computer device as Figure 8 shown.

[0136] Please refer to Figure 8 , Figure 8 which is a schematic block diagram of a computer device provided by an embodiment of the present application. The computer device 500 can be a terminal or a server. Among them, the terminal can be an electronic device with communication functions such as a smart phone, a tablet computer, a notebook computer, a desktop computer, a personal digital assistant, and a wearable device. The server can be an independent server or a server cluster composed of multiple servers.

[0137] Referring to Figure 8 , the computer device 500 includes a processor 502, a memory, and a network interface 505 connected through a system bus 501. Among them, the memory can include a non-volatile storage medium 503 and an internal memory 504.

[0138] The non-volatile storage medium 503 can store an operating system 5031 and a computer program 5032. The computer program 5032 includes program instructions. When the program instructions are executed, the processor 502 can be made to execute a data encryption and decryption method.

[0139] The processor 502 is used to provide computing and control capabilities to support the operation of the entire computer device 500.

[0140] The internal memory 504 provides an environment for the operation of the computer program 5032 in the non-volatile storage medium 503. When the computer program 5032 is executed by the processor 502, the processor 502 can be made to execute a data encryption and decryption method.

[0141] The network interface 505 is used for network communication with other devices. Those skilled in the art can understand thatFigure 8 The structure shown is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device 500 to which the solution of this application is applied. Specifically, the computer device 500 may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.

[0142] Among them, the processor 502 is used to run the computer program 5032 stored in the memory to implement the following steps:

[0143] Obtain a dynamic salt value; randomly generate an initialization vector to obtain a random vector; when data encryption is required, obtain the plaintext to be encrypted; use the dynamic salt value and the random vector to encrypt the plaintext to be encrypted and perform encoding to obtain an encoding result; transmit the encoding result to a specified end, so that the specified end verifies the validity of the initialization vector according to the ID of the random vector, and uses the corresponding random vector and the original initialization vector to decrypt the encoding result in reverse to restore the plaintext to be encrypted, and return the plaintext to be encrypted.

[0144] In one embodiment, when the processor 502 implements the step of obtaining the dynamic salt value, the following steps are specifically implemented:

[0145] Send a request through OAuth authentication to obtain the dynamic salt value and the corresponding ID.

[0146] In one embodiment, when the processor 502 implements the step of randomly generating an initialization vector to obtain a random vector, the following steps are specifically implemented:

[0147] Use a 16-bit secure random number as the random vector.

[0148] In one embodiment, when the processor 502 implements the step of using the dynamic salt value and the random vector to encrypt the plaintext to be encrypted and perform encoding to obtain an encoding result, the following steps are specifically implemented:

[0149] Use the dynamic salt value and the random vector to perform AES128 encryption on the plaintext to be encrypted to obtain encrypted data; perform Base64 encoding on the encrypted data to obtain an encoding result.

[0150] In one embodiment, when the processor 502 implements the step of using the dynamic salt value and the random vector to perform AES128 encryption on the plaintext to be encrypted to obtain encrypted data, the following steps are specifically implemented:

[0151] The plaintext to be encrypted is divided into blocks of 16 bytes each, and the last block with less than 16 bytes is padded using PKCS7Padding to obtain multiple plaintext blocks; a chained encryption processing method is used to process all the plaintext blocks in sequence to obtain the encrypted data.

[0152] In one embodiment, when the processor 502 implements the step of using a chained encryption processing method to process all the plaintext blocks in sequence to obtain the encrypted data, the specific implementation is as follows:

[0153] After performing an exclusive OR operation on the first plaintext block and the random vector, AES encryption is used to generate the first ciphertext block; each subsequent plaintext block is exclusive ORed with the previous ciphertext block and then encrypted using AES, and all the plaintext blocks are processed in sequence to obtain the encrypted data.

[0154] In one embodiment, when the processor 502 implements the step of reversely decrypting the encoded result using the corresponding random vector and the original initial vector to recover the plaintext to be encrypted, the specific implementation is as follows:

[0155] The encoded result is decoded, the decoded ciphertext data is split into multiple 16-byte ciphertext blocks, and after decrypting the first ciphertext block using the AES algorithm, an exclusive OR operation is performed with the random vector to recover the first plaintext block; starting from the second ciphertext block, each ciphertext block is first decrypted using the AES algorithm and then exclusive ORed with the previous ciphertext block, and so on, to recover the plaintext to be encrypted.

[0156] It should be understood that in the embodiments of the present application, the processor 502 may be a central processing unit (CPU), and this processor 502 may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Among them, the general-purpose processor may be a microprocessor or this processor may also be any conventional processor, etc.

[0157] Those of ordinary skill in the art can understand that all or part of the processes in the methods of implementing the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program includes program instructions, and the computer program can be stored in a storage medium, which is a computer-readable storage medium. The program instructions are executed by at least one processor in the computer system to implement the process steps of the embodiments of the above methods.

[0158] Therefore, the present invention also provides a storage medium. The storage medium can be a computer-readable storage medium. The storage medium stores a computer program, wherein when the computer program is executed by a processor, the processor performs the following steps:

[0159] Obtain a dynamic salt value; randomly generate an initialization vector to obtain a random vector; when data encryption is required, obtain the plaintext to be encrypted; use the dynamic salt value and the random vector to encrypt the plaintext to be encrypted and perform encoding to obtain an encoding result; transmit the encoding result to a designated end, so that the designated end verifies the validity of the initialization vector according to the ID of the random vector, reversely decrypts the encoding result using the corresponding random vector and the original initialization vector to restore the plaintext to be encrypted, and returns the plaintext to be encrypted.

[0160] In one embodiment, when the processor executes the computer program to implement the step of obtaining the dynamic salt value, the following steps are specifically implemented:

[0161] Send a request through OAuth authentication to obtain a dynamic salt value and the corresponding ID.

[0162] In one embodiment, when the processor executes the computer program to implement the step of randomly generating an initialization vector to obtain a random vector, the following steps are specifically implemented:

[0163] Use a 16-bit secure random number as the random vector.

[0164] In one embodiment, when the processor executes the computer program to implement the step of using the dynamic salt value and the random vector to encrypt the plaintext to be encrypted and perform encoding to obtain an encoding result, the following steps are specifically implemented:

[0165] Use the dynamic salt value and the random vector to perform AES128 encryption on the plaintext to be encrypted to obtain encrypted data; perform Base64 encoding on the encrypted data to obtain an encoding result.

[0166] In one embodiment, when the processor executes the computer program to implement the step of performing AES128 encryption on the plaintext to be encrypted by using the dynamic salt value and the random vector to obtain the encrypted data, the specific implementation is as follows:

[0167] Divide the plaintext to be encrypted into blocks of 16 bytes each, and pad the last block with less than 16 bytes using PKCS7Padding to obtain multiple plaintext blocks; process all the plaintext blocks in sequence using a chained encryption method to obtain the encrypted data.

[0168] In one embodiment, when the processor executes the computer program to implement the step of processing all the plaintext blocks in sequence using a chained encryption method to obtain the encrypted data, the specific implementation is as follows:

[0169] XOR the first plaintext block with the random vector and then use AES encryption to generate the first ciphertext block; XOR each subsequent plaintext block with the previous ciphertext block and then use AES encryption to process all the plaintext blocks in sequence to obtain the encrypted data.

[0170] In one embodiment, when the processor executes the computer program to implement the step of reversely decrypting the encoded result by using the corresponding random vector and the original initial vector to restore the plaintext to be encrypted, the specific implementation is as follows:

[0171] Decode the encoded result, divide the decoded ciphertext data into multiple ciphertext blocks of 16 bytes each, and after decrypting the first ciphertext block using the AES algorithm, perform an XOR operation with the random vector to restore the first plaintext block; starting from the second ciphertext block, decrypt each ciphertext block using the AES algorithm and then perform an XOR operation with the previous ciphertext block, and so on, to restore the plaintext to be encrypted.

[0172] The storage medium can be various computer-readable storage media such as a USB flash drive, a portable hard drive, a read-only memory (ROM), a magnetic disk, or an optical disc that can store program codes.

[0173] Those of ordinary skill in the art will realize that the units and algorithm steps of the examples described in conjunction with the embodiments disclosed herein can be implemented with electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of the examples have been generally described in terms of function in the above description. Whether these functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of the present invention.

[0174] In several embodiments provided by the present invention, it should be understood that the disclosed apparatus and method can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative. For example, the division of each unit is only a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed.

[0175] The steps in the method embodiments of the present invention can be adjusted, combined, and deleted according to actual needs. The units in the apparatus embodiments of the present invention can be combined, divided, and deleted according to actual needs. In addition, the functional units in each embodiment of the present invention can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit.

[0176] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a terminal, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present invention.

[0177] As described above, the above is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of various equivalent modifications or substitutions, and these modifications or substitutions should all be covered within the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.

Claims

1. A data encryption and decryption method, characterized in that, Comprising: Obtain a dynamic salt value; Randomly generate an initialization vector to obtain a random vector; When data encryption is required, obtain the plaintext to be encrypted; Use the dynamic salt value and the random vector to encrypt the plaintext to be encrypted and perform encoding to obtain an encoded result; Transmit the encoded result to a specified end, so that the specified end verifies the validity of the initialization vector according to the ID of the random vector, reversely decrypt the encoded result using the corresponding random vector and the original initialization vector to restore the plaintext to be encrypted, and return the plaintext to be encrypted.

2. The data encryption and decryption method according to claim 1, wherein The obtaining of the dynamic salt value includes: Send a request through OAuth authentication to obtain a dynamic salt value and the corresponding ID.

3. The data encryption and decryption method according to claim 1, wherein The randomly generating an initialization vector to obtain a random vector includes: Adopt a 16-bit secure random number as the random vector.

4. The data encryption and decryption method according to claim 1, characterized in that, The using the dynamic salt value and the random vector to encrypt the plaintext to be encrypted and perform encoding to obtain an encoded result includes: Use the dynamic salt value and the random vector to perform AES128 encryption on the plaintext to be encrypted to obtain encrypted data; Perform Base64 encoding on the encrypted data to obtain an encoded result.

5. The data encryption and decryption method according to claim 4, wherein The using the dynamic salt value and the random vector to perform AES128 encryption on the plaintext to be encrypted to obtain encrypted data includes: Divide the plaintext to be encrypted into blocks of 16 bytes each, and pad the last block with less than 16 bytes using PKCS7Padding to obtain multiple plaintext blocks; Adopt a chained encryption processing method to process all the plaintext blocks in sequence to obtain encrypted data.

6. The data encryption and decryption method according to claim 5, characterized in that, The adopting a chained encryption processing method to process all the plaintext blocks in sequence to obtain encrypted data includes: After performing an exclusive OR operation on the first plaintext block and the random vector, use AES encryption to generate the first ciphertext block; each subsequent plaintext block is exclusive ORed with the previous ciphertext block and then encrypted with AES, and all the plaintext blocks are processed in sequence to obtain encrypted data.

7. The data encryption and decryption method according to claim 1, characterized in that The using the corresponding random vector and the original initialization vector to reversely decrypt the encoded result to restore the plaintext to be encrypted includes: Decode the encoded result, divide the decoded ciphertext data into multiple ciphertext blocks of 16 bytes each, and after decrypting the first ciphertext block through the AES algorithm, perform an exclusive OR operation with the random vector to restore the first plaintext block; starting from the second ciphertext block, each ciphertext block is first decrypted through the AES algorithm and then exclusive ORed with the previous ciphertext block, and so on, to restore the plaintext to be encrypted.

8. Data encryption and decryption device, characterized in that, Comprising: A salt value obtaining unit for obtaining a dynamic salt value; A random generation unit for randomly generating an initialization vector to obtain a random vector; A plaintext obtaining unit for obtaining the plaintext to be encrypted when data encryption is required; An encryption and encoding unit for using the dynamic salt value and the random vector to encrypt the plaintext to be encrypted and perform encoding to obtain an encoded result; A transmission unit, configured to transmit the encoded result to a designated end, so that the designated end verifies the validity of the initialization vector according to the ID of the random vector, and reversely decrypts the encoded result by using the corresponding random vector and the original initialization vector to recover the plaintext to be encrypted, and returns the plaintext to be encrypted.

9. A computer device, characterized in that, The computer device includes a memory and a processor. A computer program is stored on the memory. When the processor executes the computer program, the method according to any one of claims 1 to 7 is implemented.

10. A storage medium, characterized in that, The storage medium stores a computer program. When the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.