Encryption method and device, equipment, storage medium and computer program product
By constructing a cryptographic algorithm combination set and using an optimization algorithm to determine the optimal combination, the problem of low encryption performance is solved, and efficient encryption and security improvement in different scenarios is achieved.
Patent Information
- Application Number
- CN202510906073.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-02
- Publication Date
- 2025-08-05
- Estimated Expiration
- 2045-07-02
AI Technical Summary
In the prior art, the encryption performance is low and the preset goals cannot be met.
By determining the application scenarios based on the data volume, security requirements and encryption sequence of the encryption device, building a collection of cryptographic algorithms, and determining the optimal cryptographic algorithm combination using genetic algorithms, particle swarm algorithms or reinforcement learning algorithms, combining real-time security situation awareness, the encryption process is optimized.
Improve the computing performance and security of encryption algorithms to ensure the efficient encryption capabilities of encryption devices in different scenarios.
Smart Images

Figure CN120434044A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data encryption technology, and in particular to an encryption method, device, equipment, storage medium and computer program product. Background Art
[0002] In the encryption and decryption system, the controller is connected to the data flow control module and transmits the data to be operated to the data flow control module; the data flow control module sends the data to be operated in groups to the algorithm engine core module. The algorithm engine core module integrates the AES cryptographic algorithm engine and SM4 cryptographic algorithm engine that can independently complete their respective algorithm operations. The algorithm engine core module uses the data to be operated provided by the data flow control module and the key and initial vector required for the encryption and decryption operation configured in the register stack module to perform encryption and decryption operations and feeds back the operation results to the data flow control module. The data flow control module outputs the operation result data through the controller to realize encryption and decryption processing based on the AES algorithm and SM4 algorithm. However, when using the AES algorithm and SM4 algorithm for encryption and decryption, it cannot be guaranteed that the encryption and decryption performance reaches the preset target.
[0003] It can be seen that although encryption can be implemented at present, the encryption performance is low. How to improve the encryption performance is a technical problem that those skilled in the art urgently need to solve. Summary of the Invention
[0004] In view of this, an object of the present invention is to provide an encryption method, apparatus, device, storage medium and computer program product to solve the technical problem of low encryption performance in the prior art.
[0005] To solve the above technical problems, the present invention provides an encryption method, comprising: Determine the application scenario based on the amount of data encrypted by the encryption device, security requirements, and encryption order; Determining compatibility based on a decryption condition of a decryption device; wherein the compatibility is a decryption type supported by the decryption device; A cryptographic algorithm combination set is constructed based on the application scenario and the compatibility performance, and the cryptographic algorithm combination set is used as input, and the target performance of the preset encryption device is used as the target, and the optimal cryptographic algorithm combination is determined in the cryptographic algorithm combination set to encrypt the encrypted data based on the optimal cryptographic algorithm combination.
[0006] On the one hand, the application scenarios are determined based on the amount of data encrypted by the encryption device, security requirements, and encryption order, including: determining a type of cryptographic algorithm based on the amount of data and the security requirements; determining order constraints between cryptographic algorithms based on the encryption order; The application scenario is determined based on the type of the cryptographic algorithm and the sequence limitation.
[0007] On the one hand, the types of cryptographic algorithms and / or the execution order of cryptographic algorithms in different cryptographic algorithm combinations in the cryptographic algorithm combination set are different; the execution order of the cryptographic algorithms includes parallel execution and serial execution according to the priority of each cryptographic algorithm.
[0008] On the one hand, a cryptographic algorithm combination set is constructed based on the application scenario and the compatibility performance, and the cryptographic algorithm combination set is used as input, a preset target performance of the encryption device is used as a target, and an optimal cryptographic algorithm combination is determined in the cryptographic algorithm combination set, including: Encoding the cryptographic algorithm combinations in the cryptographic algorithm combination set into individuals to form an initial population containing the same number of individuals as the cryptographic algorithm combinations; wherein each individual represents a cryptographic algorithm combination; Determining an individual fitness value of each cryptographic algorithm combination; wherein the individual fitness value represents the degree to which the cryptographic algorithm combination meets the target performance of the preset encryption device; Based on the individual fitness values, a selection operator is used to select individuals with individual fitness values higher than a set individual fitness value from the current initial population as parent individuals; After performing a crossover operator operation on the parent individuals according to a preset crossover probability, a mutation operator operation is performed to obtain a set of offspring individuals; Based on the offspring individual set, replace individuals with low individual fitness values in the current initial population to form a new generation population; wherein the low individual fitness value is a value lower than the set individual fitness value; Repeat the steps of calculating individual fitness values to form a new generation population until the preset algorithm termination condition is met, decode the individual with the highest individual fitness value in the final population, and obtain the optimal cryptographic algorithm combination that meets the target performance of the preset encryption device.
[0009] On the one hand, the individual fitness value of each cryptographic algorithm combination is determined, including: For each individual in the current initial population, decode it into the corresponding decoding cryptographic algorithm combination; Running the decoding cryptographic algorithm combination on the encryption device to obtain operation result data; The individual fitness value of the current decoding cryptographic algorithm is calculated based on the operation result data and the preset target performance of the encryption device.
[0010] On the one hand, after constructing a cryptographic algorithm combination set based on the application scenario and the compatibility performance, taking the cryptographic algorithm combination set as input and a preset target performance of the encryption device as a target, and determining the optimal cryptographic algorithm combination in the cryptographic algorithm combination set, the method further includes: Encrypting the data to be encrypted based on the optimal cryptographic algorithm combination, obtaining a master key corresponding to each cryptographic algorithm in the optimal cryptographic algorithm combination, and generating a backup key corresponding to each master key; The master key and the backup key are stored in a random order.
[0011] On the one hand, storing the master key and the backup key in a random order includes: The master key and the backup key are stored in a disordered manner, and an identity is assigned to each of the master key and the backup key, so that the decryption device obtains a key based on the identity for calculation.
[0012] On the one hand, a cryptographic algorithm combination set is constructed based on the application scenario and the compatibility performance, including: Conduct real-time dynamic perception of security situation and obtain actual security situation results; The cryptographic algorithm combination set is constructed based on the application scenario, the compatibility performance and the actual security situation results.
[0013] On the one hand, constructing the cryptographic algorithm combination set based on the application scenario, the compatibility performance and the actual security situation results includes: When the security requirement in the application scenario is consistent with the actual security situation result, or the security requirement is higher than the actual security situation result, the cryptographic algorithm combination set is directly constructed based on the application scenario and the compatibility performance; When the security requirement in the application scenario is lower than the actual security situation result, the cryptographic algorithm combination set is constructed based on the encryption order in the application scenario, the compatibility performance and the actual security situation result.
[0014] On the one hand, it is applied to baseboard management controller.
[0015] On the one hand, the cryptographic algorithm combination includes one or more algorithms selected from symmetric cryptographic algorithms, asymmetric cryptographic algorithms, hash cryptographic algorithms, and post-quantum cryptographic algorithms.
[0016] An embodiment of the present invention further provides an encryption device, comprising: An application scenario determination module, used to determine the application scenario based on the amount of data encrypted by the encryption device, security requirements, and encryption order; a compatibility performance determination module, configured to determine compatibility performance based on a decryption condition of a decryption device; wherein the compatibility performance is a decryption type supported by the decryption device; An encryption algorithm determination module is used to construct a cryptographic algorithm combination set based on the application scenario and the compatibility performance, and take the cryptographic algorithm combination set as input and the target performance of a preset encryption device as a target, to determine the optimal cryptographic algorithm combination in the cryptographic algorithm combination set, so as to encrypt the data to be encrypted based on the optimal cryptographic algorithm combination.
[0017] An embodiment of the present invention further provides an encryption device, comprising: memory for storing computer programs; A processor is used to execute the computer program to implement the steps of the above encryption method.
[0018] An embodiment of the present invention further provides a storage medium (ie, a computer-readable storage medium), on which a computer program is stored. When the computer program is executed by a processor, the steps of the above encryption method are implemented.
[0019] An embodiment of the present invention further provides a computer program product, comprising a computer program / instruction, which implements the steps of the above encryption method when executed by a processor.
[0020] To solve the above technical problems, an embodiment of the present invention provides an encryption method, which may include: determining an application scenario based on the amount of data, security requirements and encryption order during encryption by an encryption device; determining compatible performance based on the decryption situation of a decryption device; wherein the compatible performance is the decryption type supported by the decryption device; constructing a cryptographic algorithm combination set based on the application scenario and compatible performance, and taking the cryptographic algorithm combination set as input, taking the target performance of a preset encryption device as a target, determining the optimal cryptographic algorithm combination in the cryptographic algorithm combination set, and encrypting the encrypted data based on the optimal cryptographic algorithm combination.
[0021] It can be seen from the above technical solution that the beneficial effect of the present invention is that compared with the current encryption based directly on random cryptographic algorithms in multiple encryption algorithm scenarios, the present invention will take the performance goals of the encryption device as the target based on the application scenario and compatibility performance when determining the cryptographic algorithm, and determine the optimal cryptographic algorithm combination, thereby improving the computing performance of the cryptographic algorithm. Since security requirements are taken into account in the application scenario, security can be ensured. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] In order to more clearly illustrate the embodiments of the present invention, the following is a brief introduction to the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0023] Figure 1 A flowchart of an encryption method provided by an embodiment of the present invention; Figure 2 An example flow chart of an encryption method provided in an embodiment of the present invention; Figure 3 A schematic diagram of a cryptographic algorithm accelerator provided by an embodiment of the present invention; Figure 4 An example diagram of the calculation process of a cryptographic algorithm accelerator provided by an embodiment of the present invention; Figure 5 A schematic diagram of a BMC chip based on the above encryption method provided in an embodiment of the present invention; Figure 6 A schematic diagram of the structural framework of an encryption device provided by an embodiment of the present invention; Figure 7 A schematic diagram of the structural framework of an encryption device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0024] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making any creative efforts shall fall within the scope of protection of the present invention.
[0025] The terms "including" and "having," as used in the present description and accompanying drawings, and any variations thereof, are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or apparatus comprising a series of steps or elements is not limited to the listed steps or elements and may include steps or elements that are not listed.
[0026] In order to enable those skilled in the art to better understand the present invention, the present invention will be further described in detail below with reference to the accompanying drawings and specific implementation methods.
[0027] Next, a flowchart of an encryption method provided by an embodiment of the present invention is described in detail. Figure 1 An encryption method provided in an embodiment of the present invention includes: S101, determining an application scenario based on the amount of data encrypted by the encryption device, security requirements, and encryption order.
[0028] The encryption method in this embodiment can be applied to baseboard management controllers and other chips, such as CPUs (central processing units), GPUs (graphics processing units), and NPUs (neural processing units). The execution entity of this embodiment is an electronic device, which can be a computer, mobile phone, or other electronic device. The data volume during encryption by the encryption device in this embodiment refers to the amount of data to be encrypted. The security requirements in this embodiment refer to the security requirements of the data to be encrypted. The encryption order in this embodiment refers to the order requirements of the encrypted data for each cryptographic algorithm. Regarding data volume and security requirements during encryption, for example, the AES symmetric encryption algorithm is widely used in the data storage field. It uses the same key for encryption and decryption, efficiently encrypting large amounts of data (data volumes greater than the maximum number), protecting the security of data stored on hard drives and in the cloud. In the financial transaction field, the RSA asymmetric encryption algorithm is used to ensure the security of online bank transfers. It uses public key encryption and private key decryption to ensure that transaction information is not tampered with or eavesdropped during transmission. In the field of digital signatures, the SHA-256 secure hash algorithm is used to protect content from tampering during transmission and storage. The encryption order means that, for example, when the current scenario requires the asymmetric cryptographic algorithm to be calculated first and then the hash cryptographic algorithm to be calculated, the hash cryptographic module and the asymmetric cryptographic module in the cryptographic calculation module are controlled to perform calculations in sequence; when the application scenario requires the symmetric cryptographic algorithm and the asymmetric cryptographic algorithm to be calculated at the same time, the symmetric cryptographic module and the asymmetric cryptographic module in the cryptographic calculation module are controlled to perform calculations at the same time.
[0029] It should be further explained that, based on any of the above embodiments, the application scenarios determined based on the amount of data encrypted by the encryption device, security requirements, and encryption order may include: S1011, determining the type of cryptographic algorithm based on the data volume and security requirements; S1012, determining the order restriction between cryptographic algorithms based on the encryption order; S1013, determining the application scenario based on the type and sequence of the cryptographic algorithm.
[0030] This embodiment can divide different amounts of data based on the data volume threshold to obtain the quantity priority corresponding to each level of data volume. Different quantity priorities correspond to different types of cryptographic algorithms. Security is divided into different levels of security priorities based on security requirements. Different security priorities correspond to different types of cryptographic algorithms. Therefore, different comprehensive priorities are determined based on the data volume and security requirements, and the cryptographic algorithms corresponding to each comprehensive priority are determined. When the data volume and security requirements are obtained, all types of cryptographic algorithms that meet the requirements can be obtained. Determining the order limitation between cryptographic algorithms based on the encryption order means that after determining the type of cryptographic algorithm, some cryptographic algorithms have a certain order, so it is necessary to determine the order limitation, so that the order of some cryptographic algorithms in the type of cryptographic algorithm can be limited. Determining the application scenario through this step can enable the cryptographic algorithm to balance security and data processing efficiency.
[0031] S102: Determine compatibility performance based on the decryption status of the decryption device; wherein the compatibility performance is the decryption type supported by the decryption device.
[0032] The compatibility performance in this embodiment refers to the decryption types supported by the decryption device, ensuring that the decryption device can decrypt data encrypted by the encryption device. This embodiment takes into account the different cryptographic algorithm compatibility of different decryption devices. For example, after data is encrypted and decrypted by a decryption device, the decryption device may only support one or more of the following algorithms: symmetric cryptographic algorithms, asymmetric cryptographic algorithms, hash cryptographic algorithms, and post-quantum cryptographic algorithms. Therefore, the decryption performance of the decryption device must be considered when encrypting data.
[0033] It should be further explained that the cryptographic algorithm combination set constructed based on application scenarios and compatibility performance may include: S1021, performing real-time dynamic security situation perception to obtain actual security situation results; S1022, construct a cryptographic algorithm combination set based on application scenarios, compatibility performance and actual security situation results.
[0034] This embodiment performs real-time dynamic perception of security situation, which means dynamic perception of the security situation of the encryption device. If the security situation of the encryption device is vulnerable to attack, then it is necessary to select a cryptographic algorithm whose security performance meets the set security requirements. This embodiment can perceive the security situation of the current encryption device in real time, and does not limit the specific content of the perception, as long as the content is related to security. Through perception, the actual security situation results of the current encryption device can be obtained, and based on the security requirements and actual security situation results in the application scenario, the cryptographic algorithm that meets the security requirements and can defend against the current actual security situation is determined, and a cryptographic algorithm combination is constructed based on the screened cryptographic algorithms and compatible performance. When constructing a cryptographic algorithm combination set, this embodiment will take into account the actual security situation results of the encryption device, thereby improving the security of the subsequent optimal cryptographic algorithm combination for encryption.
[0035] It should be further explained that, based on the above embodiment, constructing a cryptographic algorithm combination set based on the application scenario, compatibility performance, and actual security situation results may include: when the security requirements in the application scenario are consistent with the actual security situation results, or the security requirements are higher than the actual security situation results, directly constructing the cryptographic algorithm combination set based on the application scenario and compatibility performance; when the security requirements in the application scenario are lower than the actual security situation results, constructing the cryptographic algorithm combination set based on the encryption order in the application scenario, compatibility performance, and actual security situation results. This embodiment is equivalent to determining the security requirements of the encryption device based on the actual security situation results, thereby calculating the intersection of the security requirements in the application scenario and the security requirements of the encryption device, and taking the one with the highest security requirement as the final security requirement, thereby determining the security requirements for data encryption and the security requirements for the encryption device to defend against attacks. This embodiment provides a specific process for constructing a cryptographic algorithm combination set based on the application scenario, compatibility performance, and actual security situation results, thereby improving the accuracy of determining the cryptographic algorithm combination set.
[0036] S103, constructing a cryptographic algorithm combination set based on application scenarios and compatibility performance, and taking the cryptographic algorithm combination set as input, taking the target performance of the preset encryption device as the target, determining the optimal cryptographic algorithm combination in the cryptographic algorithm combination set, and encrypting the encrypted data based on the optimal cryptographic algorithm combination.
[0037] This embodiment constructs a cryptographic algorithm combination set based on application scenarios and compatibility performance. This means that when determining the available encryption algorithms based on the application scenarios and compatibility performance, the execution order of the encryption algorithms must be determined. This execution order can achieve the preset target performance of the encryption device, thereby ensuring the performance of the encryption device during encryption. This embodiment includes various types of cryptographic algorithm combinations. Each cryptographic algorithm combination has different encryption algorithm types. When the encryption algorithms are of the same type, the execution order of the encryption algorithms is different. The execution order is based on the priority of each cryptographic algorithm. If the priorities are the same, the algorithms can be executed in parallel. This embodiment summarizes the cryptographic algorithm combinations as including one or more algorithms from symmetric cryptographic algorithms, asymmetric cryptographic algorithms, hash cryptographic algorithms, and post-quantum cryptographic algorithms. For example, a combination of individual algorithms from symmetric cryptographic algorithms, or a combination of cryptographic algorithms from symmetric cryptographic algorithms and cryptographic algorithms from asymmetric cryptographic algorithms. This embodiment does not limit the specific method for determining the optimal cryptographic algorithm combination from the cryptographic algorithm combination set using the cryptographic algorithm combination set as input and the preset target performance of the encryption device as the goal. For example, this embodiment may determine the optimal cryptographic algorithm combination from the cryptographic algorithm combination set based on a genetic algorithm; or this embodiment may determine the optimal cryptographic algorithm combination from the cryptographic algorithm combination set based on a particle swarm algorithm; or this embodiment may determine the optimal cryptographic algorithm combination from the cryptographic algorithm combination set based on a neural network algorithm; or this embodiment may determine the optimal cryptographic algorithm combination from the cryptographic algorithm combination set based on a reinforcement learning algorithm. The process of searching for an optimal solution based on the particle swarm algorithm may include: taking the cryptographic algorithm combination set as input and taking the target performance of a preset encryption device as the optimization target. Initialize a particle swarm, where each particle represents a cryptographic algorithm combination and has a position and velocity; define a fitness function to evaluate the degree to which the algorithm combination represented by the particle meets the preset target performance of the encryption device; in each iteration, guide the particle to update its speed and position based on the individual extreme value of the particle and the global extreme value of the particle swarm, and then search for a better solution; repeat the particle position and velocity update and fitness evaluation until the preset algorithm termination condition is met; finally, decode the global optimal particle to obtain the optimal cryptographic algorithm combination that meets the target performance of the encryption device; the optimization process based on the reinforcement learning algorithm may include: taking the cryptographic algorithm combination set as the state space and taking the preset target performance of the encryption device as the optimization target.Each cryptographic algorithm combination is considered a state in the environment. The reinforcement learning agent selects an action based on the current strategy and changes the cryptographic algorithm combination. The environment provides a reward value based on the performance of the selected combination, which measures the degree to which the selected cryptographic algorithm combination meets the target performance of the encryption device. The agent continuously updates the policy function or value function based on the reward value, thereby improving its ability to select high-quality cryptographic algorithm combinations. Through multiple rounds of interaction, the agent gradually converges to the optimal strategy and ultimately selects the cryptographic algorithm combination with the maximum cumulative reward as the optimal solution that meets the preset target performance of the encryption device. This embodiment does not limit the specific preset target performance of the encryption device. For example, the preset target performance of the encryption device is that the target computing speed of the encryption device reaches a set computing speed value; or the preset target performance of the encryption device in this embodiment is that the resource consumption of the encryption device is lower than a set threshold; or the preset target performance of the encryption device in this embodiment includes resource consumption reaching a set threshold and computing speed reaching a set speed value; or the preset target performance of the encryption device in this embodiment can take into account the three dimensions of security strength, processing efficiency, and resource usage. Security strength can be anti-attack capability, processing efficiency includes throughput and latency, and resource usage includes power consumption and memory usage. This embodiment is a process of encrypting encrypted data based on the optimal cryptographic algorithm combination. For example, for a group of data X to be encrypted, the optimal cryptographic algorithm combination is hash cryptographic algorithm calculation and asymmetric cryptographic algorithm calculation, then the encrypted data X is copied, and hash cryptographic algorithm calculation and asymmetric cryptographic algorithm calculation are performed simultaneously; for multiple groups of data X1, X2, and X3 to be encrypted, the optimal cryptographic algorithm combination is symmetric cryptographic algorithm calculation, asymmetric cryptographic algorithm calculation, and hash cryptographic algorithm calculation, then the corresponding cryptographic algorithm calculations are performed on the data X1, X2, and X3 respectively.
[0038] It should be further explained that, based on any of the above embodiments, the types of cryptographic algorithms and / or the execution order of the cryptographic algorithms of different cryptographic algorithm combinations in the above cryptographic algorithm combination set are different; the execution order of the cryptographic algorithms includes parallel execution and serial execution according to the priority of each cryptographic algorithm.
[0039] In this embodiment, cryptographic algorithms can be processed in parallel, thereby improving encryption efficiency. In this embodiment, determining the cryptographic algorithm combination can include serial and parallel execution, which improves the comprehensiveness of the cryptographic algorithm combination and thus improves the accuracy of subsequent determination of the optimal cryptographic algorithm combination.
[0040] It should be further explained that, based on any of the above embodiments, the above-mentioned construction of a cryptographic algorithm combination set based on application scenarios and compatibility performance, taking the cryptographic algorithm combination set as input and the preset target performance of the encryption device as a target, and determining the optimal cryptographic algorithm combination in the cryptographic algorithm combination set may include: S1031, encode the cryptographic algorithm combinations in the cryptographic algorithm combination set into individuals to form an initial population containing the same number of individuals as the cryptographic algorithm combinations; wherein each individual represents a cryptographic algorithm combination.
[0041] In this embodiment, all cryptographic algorithm combinations in a set of cryptographic algorithm combinations are encoded as individuals in a genetic algorithm, forming an initial population of several individuals. Each individual represents a cryptographic algorithm combination, and the number of cryptographic algorithm combinations is equal to the number of individuals in the initial population. The encoding in this embodiment can map one or more elements of each cryptographic algorithm combination, including the algorithm identifier, operating mode, key length, and padding method, to a chromosome sequence composed of discrete gene bits.
[0042] S1032, determining the individual fitness value of each cryptographic algorithm combination; wherein the individual fitness value represents the degree to which the cryptographic algorithm combination meets the preset target performance of the encryption device.
[0043] This embodiment decodes each individual in the current population into a corresponding cryptographic algorithm combination; runs the cryptographic algorithm combination on an encryption device or in a simulation environment; collects the resulting data and calculates its individual fitness value based on the target performance indicator. The individual fitness value represents the degree to which the cryptographic algorithm combination meets the preset target performance of the encryption device. In this embodiment, the fitness value is calculated by constructing an evaluation function based on one or more of the preset target performance of the encryption device: encryption strength, computing speed, resource consumption, and attack resistance. The output of this function is the individual fitness value.
[0044] S1033, based on the fitness values of each individual, using a selection operator to select individuals with fitness values higher than a set individual fitness value from the current initial population as parent individuals.
[0045] This embodiment uses a selection operator to select individuals with high individual fitness values from the current population as parent individuals based on the calculated fitness values of each individual.
[0046] S1034, after performing a crossover operator operation on the parent individuals according to a preset crossover probability, performing a mutation operator operation to obtain a set of offspring individuals.
[0047] This embodiment performs a crossover operator operation on the selected parent individuals according to a preset crossover probability, including: a. exchanging some gene segments of the two parent individuals; b. generating new offspring individuals; wherein the gene segments correspond to specific algorithm elements or configurations in the cryptographic algorithm combination; based on the offspring individuals generated by the crossover operation, performing a mutation operator operation according to a preset mutation probability, including: randomly changing one or more gene segments of the offspring individual; the change operation is performed within the range allowed by the cryptographic algorithm combination set to generate a set of offspring individuals, replace individuals with low individual fitness values in the current population, and form a new generation population.
[0048] S1035, based on the offspring individual set, replace individuals with low individual fitness values in the current initial population to form a new generation population; wherein the low individual fitness value is a value lower than the set individual fitness value.
[0049] S1036, repeatedly executing the steps of calculating individual fitness values to form a new generation population until the preset algorithm termination condition is met, decoding the individual with the highest individual fitness value in the final population, and obtaining the optimal cryptographic algorithm combination that meets the preset target performance of the encryption device.
[0050] This embodiment repeatedly executes steps S1032 to S1035 until a preset algorithm termination condition is met. This embodiment does not limit the specific preset algorithm termination conditions; for example, the algorithm termination conditions may include reaching the maximum number of iterations, the optimal fitness value of the population not improving for several consecutive generations, or the individual fitness value exceeding a set threshold. The individual with the highest individual fitness value in the final population is then decoded, resulting in an optimal cryptographic algorithm combination that meets the preset target performance of the encryption device. This embodiment provides a method for determining the optimal cryptographic algorithm combination within a set of cryptographic algorithm combinations, thereby improving the accuracy of the algorithm.
[0051] It should be further explained that, based on any of the above embodiments, in order to improve the accuracy of determining individual fitness values, the above determination of the individual fitness value of each cryptographic algorithm combination may include: decoding each individual in the current initial population into a corresponding decoding cryptographic algorithm combination; running the decoding cryptographic algorithm combination on an encryption device to obtain operation result data; and calculating the individual fitness value of the current decoding cryptographic algorithm based on the operation result data and the preset target performance of the encryption device. This embodiment can compare different operation result data with the divided performance intervals to obtain individual fitness values. Alternatively, this embodiment can also perform a weighted calculation based on various parameters related to the target performance in the operation result data to obtain the individual fitness value. The operation result data in this embodiment refers to the operation performance corresponding to the current decoding cryptographic algorithm combination, and thus the individual fitness value is determined based on the operation performance and the preset target performance of the encryption device. This embodiment provides a specific process for determining individual fitness values, thereby improving the accuracy of determining individual fitness values.
[0052] It should be further explained that, based on any of the above embodiments, after constructing a cryptographic algorithm combination set based on application scenarios and compatibility performance, taking the cryptographic algorithm combination set as input, taking the target performance of the preset encryption device as the target, and determining the optimal cryptographic algorithm combination in the cryptographic algorithm combination set, it may also include: encrypting the data to be encrypted based on the optimal cryptographic algorithm combination, obtaining the master key corresponding to each cryptographic algorithm in the optimal cryptographic algorithm combination, and generating a backup key corresponding to each master key; storing the master key and the backup key in a disordered manner. When the master key is leaked or invalid, the backup key is enabled. This embodiment will generate a backup password corresponding to each master key, and when storing the key, it will be stored in a disordered manner. The disorder means that the storage is not in the order of encryption, so that the encryption device is more secure when attacked.
[0053] It should be further explained that, based on the above embodiment, storing the master key and backup key in a random order may include: storing the master key and backup key in a random order and assigning an identity to each master key and backup key so that the decryption device can obtain the key for calculation. In this embodiment, the decryption process performed by the decryption device may include initiating a key request based on the encryption algorithm type; the encryption device traversing all physical units based on the encryption algorithm used to search for the key based on the identity; returning the key value to the decryption device; and the decryption device performing decryption based on the received key value.
[0054] An encryption method provided by an embodiment of the present invention may include: S101, determining an application scenario based on the amount of data, security requirements, and encryption order during encryption by an encryption device; S102, determining compatibility performance based on the decryption status of a decryption device; wherein the compatibility performance is the decryption type supported by the decryption device; S103, constructing a cryptographic algorithm combination set based on the application scenario and the compatibility performance, and using the cryptographic algorithm combination set as input and the preset target performance of the encryption device as a target, determining an optimal cryptographic algorithm combination in the cryptographic algorithm combination set, and encrypting the data to be encrypted based on the optimal cryptographic algorithm combination. Compared with the current encryption method directly based on the cryptographic algorithm, the present invention takes the performance target of the encryption device as a target based on the application scenario and the compatibility performance when determining the cryptographic algorithm, and determines the optimal cryptographic algorithm combination, thereby improving the computing performance and security of the cryptographic algorithm.
[0055] In order to make the present invention easier to understand, please refer to Figure 2 , Figure 2 An example flow chart of an encryption method provided in an embodiment of the present invention may specifically include: S201, the encryption device determines an application scenario based on the amount of data encrypted by the encryption device, security requirements, and encryption order.
[0056] S202: The encryption device determines a compatible performance based on the decryption status of the decryption device; wherein the compatible performance is a decryption type supported by the decryption device.
[0057] S203, the encryption device performs real-time dynamic security situation perception on the encryption device to obtain actual security situation results.
[0058] S204, the encryption device constructs a set of cryptographic algorithm combinations based on application scenarios, compatibility performance and actual security situation results; wherein, different cryptographic algorithm combinations have different types of cryptographic algorithms and / or execution orders of cryptographic algorithms; the execution order of cryptographic algorithms includes parallel execution and serial execution according to the priority of each cryptographic algorithm.
[0059] This embodiment can be constructed based on a cryptographic algorithm accelerator when constructing a cryptographic algorithm combination. The cryptographic algorithm accelerator is in the encryption device and includes an information analysis module, an intelligent control module, a cryptographic calculation module, and a key module. For details, please refer to Figure 3 , Figure 3 A schematic diagram of a cryptographic algorithm accelerator provided in an embodiment of the present invention. The information analysis module is used to analyze the application scenarios and compatibility performance of the cryptographic algorithm accelerator. Different application scenarios require different cryptographic algorithms. For example, in the field of data storage, symmetric encryption algorithms are widely used. They use the same key for encryption and decryption, can efficiently encrypt large amounts of data, and protect the security of data stored on hard drives and in the cloud. In the field of financial transactions, asymmetric encryption algorithms are used to ensure the security of online bank transfers. They use public key encryption and private key decryption to ensure that transaction information is not tampered with or stolen during transmission. In the field of digital signatures, hash algorithms are used to ensure that content is not tampered with during transmission and storage. Different decryption devices have different cryptographic algorithm compatibility. For example, data is encrypted by a cryptographic algorithm accelerator and decrypted by a decryption device. The decryption device only supports one or more of the following algorithms: symmetric cryptographic algorithms, asymmetric cryptographic algorithms, hash cryptographic algorithms, and post-quantum cryptographic algorithms. Therefore, the cryptographic algorithm accelerator needs to consider the decryption status of the decryption device when encrypting data.
[0060] Based on the results of the information analysis module and the actual security situation results, the intelligent control module constructs a cryptographic algorithm combination set, determines the cryptographic algorithm combination set, and then determines the cryptographic algorithm combination from the cryptographic algorithm set that optimizes the performance of the encryption device. For example, when the application scenario requires the asymmetric cryptographic algorithm to be calculated first and then the hash cryptographic algorithm, the hash cryptographic module and the asymmetric cryptographic module in the cryptographic calculation module are controlled to calculate sequentially; when the application scenario requires the simultaneous calculation of symmetric cryptographic algorithms and asymmetric cryptographic algorithms, the symmetric cryptographic module and the asymmetric cryptographic module in the cryptographic calculation module are controlled to calculate simultaneously.
[0061] The cryptographic computing module includes symmetric, asymmetric, hash, and post-quantum cryptographic modules, enabling accelerated computation of various cryptographic algorithms, including symmetric cryptographic algorithms (3DES (Triple Data Encryption Standard), AES (Advanced Encryption Standard), and SM4 (Commercial Secret SM4 Block Cipher), asymmetric cryptographic algorithms (RSA (Public Key Cryptography), ECC (Elliptic Curve Cryptography), and SM2 (Commercial Secret SM2 Elliptic Curve Public Key Cryptography), hash cryptographic algorithms (MD5 (Message Digest Algorithm), SHA-256 (Secure Hash Algorithm - 256-bit), and post-quantum cryptographic algorithms (CRYSTALS-Kyber (Crystal-Kyber Key Encapsulation Mechanism), CRYSTALS-Dilithium (Crystal-Dilithium Digital Signature Algorithm), and Falcon (Lightweight Digital Signature Algorithm). In symmetric cryptographic algorithms, the sender uses a key to encrypt plaintext data, generating ciphertext. The receiver then uses the same key to decrypt the ciphertext, restoring the original data. Because the encryption and decryption processes are symmetrical and use the same key, this is called symmetric encryption. Symmetric cryptographic algorithms offer advantages such as fast encryption speed, low computational overhead, and simple implementation, making them ideal for protecting the transmission and storage of large amounts of data. Common symmetric cryptographic algorithms include 3DES, AES, and the SM4 algorithm. Asymmetric cryptographic algorithms, also known as public-key cryptographic algorithms, use a pair of keys (public and private) for encryption and decryption. Unlike symmetric cryptographic algorithms, asymmetric encryption uses different keys for encryption and decryption. The public key can be made public and is used to encrypt information or verify signatures, while the private key must be kept strictly confidential and is used to decrypt information or generate signatures. Compared to symmetric cryptographic algorithms, asymmetric cryptographic algorithms facilitate key distribution and support digital signatures and key exchange, but they are computationally less efficient. Common algorithms include RSA, ECC, and the SM2 algorithm. Hash cryptographic algorithms use a mathematical function to map input data (plaintext) of arbitrary length to an output (hash value) of fixed length. The core principle is that the hash function "compresses" data into a unique value. Any slight change in the input results in a significant change in the hash value, making it suitable for data integrity verification and identity authentication. Hash algorithms are one-way, meaning the original data cannot be deduced from the hash value. Common hash algorithms include MD5 and SHA-256. Post-quantum cryptographic algorithms are designed to resist attacks from quantum computers. Quantum computers possess powerful computing power and are capable of cracking currently used asymmetric cryptographic algorithms, such as RSA and ECC, in a short period of time. Therefore, the research goal of post-quantum cryptographic algorithms is to design cryptographic schemes that remain secure even in the face of quantum computing threats. These schemes are typically based on mathematical problems that are difficult for quantum computers to crack. Common post-quantum cryptographic algorithms include CRYSTALS-Kyber, CRYSTALS-Dilithium, and the Falcon algorithm.
[0062] The key module includes multiple master key storage units ( Figure 3 master keys 1-1 and 1-2) and multiple backup key storage units ( Figure 3 When the master key is leaked or invalid, the backup key is used. The keys of multiple cryptographic algorithms are stored in a centralized and disordered manner, such as in Figure 3 In the example, the first key 1-1 stores the RSA algorithm key, and the second key 1-2 stores the SM4 algorithm key. Each key is assigned an identity, and the key is selected based on the identity during cryptographic algorithm calculations.
[0063] The calculation process corresponding to the cryptographic algorithm accelerator in this embodiment is as follows: Figure 4 As shown, Figure 4 An example diagram of the computing process of a cryptographic algorithm accelerator provided for an embodiment of the present invention may specifically include: application scenario and compatibility performance analysis, determining a cryptographic algorithm combination set based on the application scenario and compatibility performance analysis using a cryptographic computing module, determining an optimal cryptographic algorithm combination, encrypting based on the optimal cryptographic algorithm combination, and obtaining a master key and a backup key.
[0064] S205 , the encryption device takes the cryptographic algorithm combination set as input, takes the preset target performance of the encryption device as a target, and determines the optimal cryptographic algorithm combination in the cryptographic algorithm combination set.
[0065] S206, the encryption device encrypts the data to be encrypted based on the optimal cryptographic algorithm combination, obtains multiple master keys, and sets a backup key corresponding to each master key, stores the master key and the backup key in an unordered manner, and sets identity identifiers corresponding to the master key and the backup key.
[0066] S207: The decryption device obtains the corresponding master key and backup key based on the identity identifier and decrypts the data to be decrypted.
[0067] It should be noted that when the above method is applied to BMC, the specific structure is as follows: Figure 5 As shown, Figure 5A schematic diagram of a BMC chip based on the above-mentioned encryption method is provided in an embodiment of the present invention. The BMC (Baseboard Management Controller) is a key component in a server, responsible for hardware monitoring, fault management, and remote control. The BMC chip monitors various server hardware parameters, including voltage, temperature, fan speed, and power status; detects and records server faults; and allows administrators to remotely control the server, including powering on, off, and restarting it. The BMC chip's cryptographic module is a crucial security component. It protects data communicated between the BMC and other devices (such as server management data and firmware update data) and sensitive data stored within the BMC (such as passwords and certificates). The BMC chip's cryptographic module typically supports multiple cryptographic algorithms, including symmetric, asymmetric, and hash algorithms. A BMC chip based on the above-mentioned encryption method includes a processor, memory, a cryptographic algorithm accelerator, and other modules. The processor is the core control and computing module of the BMC chip. The processor can be an x86 processor, an Arm processor (a reduced instruction set processor designed by the British company Arm), or a RISC-V processor (an open-source reduced instruction set processor architecture). The memory is used for data storage of BMC chip, including DDR SDRAM (double data rate synchronous dynamic random access memory), ROM (read-only memory), FLASH (flash memory), etc. The cryptographic algorithm accelerator is Figure 3 The cryptographic algorithm accelerator in the BMC is used to implement the calculation of various encryption and decryption algorithms, such as the AES algorithm, ECC algorithm, SHA-256 algorithm, etc. Other functional modules include clock modules, power modules, etc. The processor, memory, cryptographic algorithm accelerator, and other modules are connected through buses, including the AXI bus (Advanced Extensible Interface Bus), AHB bus (High-Performance System Bus), and APB bus (Advanced Peripheral Bus). The cryptographic algorithm accelerator is a device corresponding to the encryption algorithm. Encryption and decryption calculations of various cryptographic algorithms are implemented according to the different types of servers (such as AI servers, storage servers, and edge servers) and different application scenarios (such as high-performance computing and large-capacity data storage) used by the BMC chip.
[0068] This paper proposes an encryption method that supports encryption and decryption calculations for multiple cryptographic algorithms, including symmetric, asymmetric, hash, and post-quantum cryptographic algorithms. It can determine the optimal combination of cryptographic algorithms based on application scenarios and compatibility, and intelligently control the calculations of multiple cryptographic algorithms. This method is beneficial for improving the computing performance and security of cryptographic algorithms in multi-algorithm scenarios.
[0069] The encryption device provided by an embodiment of the present invention is introduced below. The encryption device described below and the encryption method described above can be referenced to each other.
[0070] Figure 6 A schematic diagram of the structural framework of an encryption device provided in an embodiment of the present invention may include: An application scenario determination module 100 is used to determine an application scenario based on the amount of data encrypted by the encryption device, security requirements, and encryption order; A compatibility performance determination module 200 is configured to determine compatibility performance based on a decryption condition of a decryption device; wherein the compatibility performance is a decryption type supported by the decryption device; The encryption algorithm determination module 300 is used to construct a cryptographic algorithm combination set based on the application scenario and the compatibility performance, and take the cryptographic algorithm combination set as input and the target performance of the preset encryption device as the target, to determine the optimal cryptographic algorithm combination in the cryptographic algorithm combination set, so as to encrypt the data to be encrypted based on the optimal cryptographic algorithm combination.
[0071] Furthermore, based on the above embodiment, the application scenario determination module 100 may include: a cryptographic algorithm type determination unit, configured to determine a type of cryptographic algorithm based on the amount of data and the security requirement; An order limiting unit, configured to determine order limits between cryptographic algorithms based on the encryption order; An application scenario determining unit is configured to determine the application scenario based on the type of the cryptographic algorithm and the sequence limitation.
[0072] Furthermore, based on any of the above embodiments, the types of cryptographic algorithms and / or the execution order of the cryptographic algorithms of different cryptographic algorithm combinations in the cryptographic algorithm combination set are different; the execution order of the cryptographic algorithms includes parallel execution and serial execution according to the priority of each cryptographic algorithm.
[0073] Further, based on any of the above embodiments, the encryption algorithm determination module 300 may include: an initial population determining unit, configured to encode the cryptographic algorithm combinations in the cryptographic algorithm combination set into individuals, to form an initial population containing the same number of individuals as the cryptographic algorithm combinations; wherein each individual represents a cryptographic algorithm combination; An individual fitness value determining unit, configured to determine an individual fitness value of each cryptographic algorithm combination; wherein the individual fitness value represents the degree to which the cryptographic algorithm combination meets the target performance of the preset encryption device; A parent individual determination unit is configured to select, based on the fitness values of the individuals, an individual whose fitness value is higher than a set fitness value from the current initial population using a selection operator as a parent individual; an offspring individual set determining unit, configured to perform a crossover operator operation on the parent individual according to a preset crossover probability, and then perform a mutation operator operation to obtain an offspring individual set; a new generation population determination unit, configured to replace individuals with low individual fitness values in the current initial population based on the set of offspring individuals, to form a new generation population; wherein the low individual fitness value is a value lower than the set individual fitness value; The optimal cryptographic algorithm combination determination unit is used to repeatedly execute the steps of calculating individual fitness values to form a new generation population until the preset algorithm termination condition is met, decode the individual with the highest individual fitness value in the final population, and obtain the optimal cryptographic algorithm combination that meets the preset target performance of the encryption device.
[0074] Furthermore, based on the above embodiment, the individual fitness value determining unit may include: A decoding subunit, configured to decode each individual in the current initial population into a corresponding decoding cryptographic algorithm combination; an operation result data determining subunit, configured to execute the decoding cryptographic algorithm combination on the encryption device to obtain operation result data; The individual fitness value determination subunit is used to calculate the individual fitness value of the current decoding cryptographic algorithm based on the operation result data and the target performance of the preset encryption device.
[0075] Furthermore, based on any of the above embodiments, the encryption device may further include: an encryption module, configured to encrypt the data to be encrypted based on the optimal cryptographic algorithm combination, obtain a master key corresponding to each cryptographic algorithm in the optimal cryptographic algorithm combination, and generate a backup key corresponding to each master key; The storage module is used to store the master key and the backup key in a disordered manner.
[0076] Furthermore, based on the above embodiment, the storage module may include: The storage unit is used to store the master key and the backup key in a disordered manner, and assign an identity identifier to each of the master key and the backup key, so that the decryption device obtains the key based on the identity identifier for calculation.
[0077] Further, based on any of the above embodiments, the encryption algorithm determination module 300 may include: The security situation dynamic perception unit is used to perform real-time security situation dynamic perception and obtain the actual security situation results; A cryptographic algorithm combination set determination unit is used to construct the cryptographic algorithm combination set based on the application scenario, the compatibility performance and the actual security situation result.
[0078] Furthermore, based on the above embodiment, the cryptographic algorithm combination set determination unit may include: A first construction subunit is configured to construct the cryptographic algorithm combination set directly based on the application scenario and the compatibility performance when the security requirement in the application scenario is consistent with the actual security situation result, or the security requirement is higher than the actual security situation result; The second construction subunit is used to construct the cryptographic algorithm combination set based on the encryption order in the application scenario, the compatibility performance and the actual security situation result when the security requirement in the application scenario is lower than the actual security situation result.
[0079] Furthermore, based on any of the above embodiments, the above encryption device is applied to a baseboard management controller.
[0080] Furthermore, based on any of the above embodiments, the cryptographic algorithm combination includes one or more of a symmetric cryptographic algorithm, an asymmetric cryptographic algorithm, a hash cryptographic algorithm, and a post-quantum cryptographic algorithm.
[0081] It should be noted that the order of the modules and units in the above encryption device can be changed without affecting the logic.
[0082] Figure 6 The description of the features in the corresponding embodiment can be found in Figure 6 The relevant descriptions of the corresponding embodiments will not be repeated here one by one.
[0083] An encryption device provided by an embodiment of the present invention may include: an application scenario determination module 100, for determining an application scenario based on the amount of data, security requirements, and encryption order when the encryption device encrypts; a compatibility performance determination module 200, for determining compatibility performance based on the decryption status of the decryption device; wherein the compatibility performance is the decryption type supported by the decryption device; an encryption algorithm determination module 300, for constructing a cryptographic algorithm combination set based on the application scenario and the compatibility performance, and taking the cryptographic algorithm combination set as input and the preset target performance of the encryption device as a target, determining the optimal cryptographic algorithm combination in the cryptographic algorithm combination set, and encrypting the data to be encrypted based on the optimal cryptographic algorithm combination. Compared with the current encryption directly based on the cryptographic algorithm, the present invention takes the performance target of the encryption device as a target based on the application scenario and the compatibility performance when determining the cryptographic algorithm, and determines the optimal cryptographic algorithm combination, thereby improving the computing performance and security of the cryptographic algorithm.
[0084] An encryption device provided by an embodiment of the present invention is introduced below. The encryption device described below and the encryption method described above can be referenced to each other.
[0085] Figure 7 A schematic diagram of the structural framework of an encryption device provided by an embodiment of the present invention is shown as follows: Figure 7 As shown, the encryption device includes: a memory 60 for storing a computer program; The processor 61 is configured to implement the steps of the encryption method in the above embodiment when executing a computer program.
[0086] The encryption device provided in this embodiment may include but is not limited to a smart phone, a tablet computer, a laptop computer, or a desktop computer.
[0087] The processor 61 may include one or more processing cores, such as a quad-core processor or an octa-core processor. The processor 61 may be implemented using at least one of the following hardware forms: a digital signal processing (DSP), a field-programmable gate array (FPGA), or a programmable logic array (PLA). The processor 61 may also include a main processor and a coprocessor. The main processor is a processor for processing data in the awake state, also known as a central processing unit (CPU); the coprocessor is a low-power processor for processing data in the standby state. In some embodiments, the processor 61 may be integrated with a graphics processing unit (GPU), which is responsible for rendering and drawing content required to be displayed on the display screen. In some embodiments, the processor 61 may also include an artificial intelligence (AI) processor for handling computational operations related to machine learning.
[0088] The memory 60 may include one or more computer-readable storage media, which may be non-transitory. The memory 60 may also include a high-speed random access memory, and a non-volatile memory, such as one or more disk storage devices, flash memory storage devices. In this embodiment, the memory 60 is at least used to store the following computer program 601, wherein, after the computer program is loaded and executed by the processor 61, it can implement the relevant steps of the encryption method disclosed in any of the aforementioned embodiments. In addition, the resources stored in the memory 60 may also include an operating system 602 and data 603, etc., and the storage method may be temporary storage or permanent storage. Among them, the operating system 602 may include Windows, Unix, Linux, etc. The data 603 may include but is not limited to data required for the encryption method, etc.
[0089] In some embodiments, the encryption device may further include a display screen 62 , an input / output interface 63 , a communication interface 64 , a power supply 65 , and a communication bus 66 .
[0090] Those skilled in the art will understand that Figure 7 The structure shown in the figure does not constitute a limitation on the encryption device, and may include more or fewer components than shown in the figure.
[0091] It is understood that if the encryption method in the above-mentioned embodiment is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the current technology, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and performs all or part of the steps of the various embodiments of the present invention. The aforementioned storage medium includes: USB flash drives, mobile hard drives, read-only memory (ROM), random access memory (RAM), electrically erasable programmable ROM, registers, hard drives, removable disks, CD-ROMs, magnetic disks, or optical disks, and other media that can store program code.
[0092] Based on this, an embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the above encryption method are implemented.
[0093] Based on this, an embodiment of the present invention further provides a computer program product, including a computer program / instruction, which implements the steps of the above encryption method when executed by a processor.
[0094] The above describes in detail the encryption method, apparatus, device, storage medium, and computer program product provided by the present invention. Specific examples are used herein to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is intended only to facilitate understanding of the method and core concepts of the present invention. It should be noted that those skilled in the art may make various improvements and modifications to the present invention without departing from the principles of the present invention, and such improvements and modifications fall within the scope of protection of the present invention.
[0095] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the above description has generally described the components and steps of each example according to their functions. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present invention.
Claims
1. An encryption method, characterized in that: include: Determine the application scenario based on the amount of data encrypted by the encryption device, security requirements, and encryption order; Determining compatibility based on a decryption condition of a decryption device; wherein the compatibility is a decryption type supported by the decryption device; A cryptographic algorithm combination set is constructed based on the application scenario and the compatibility performance, and the cryptographic algorithm combination set is used as input, and the target performance of the preset encryption device is used as the target, and the optimal cryptographic algorithm combination is determined in the cryptographic algorithm combination set to encrypt the encrypted data based on the optimal cryptographic algorithm combination.
2. The encryption method according to claim 1, wherein: Determine the application scenario based on the amount of data encrypted by the encryption device, security requirements, and encryption order, including: determining a type of cryptographic algorithm based on the amount of data and the security requirements; determining order constraints between cryptographic algorithms based on the encryption order; The application scenario is determined based on the type of the cryptographic algorithm and the sequence limitation.
3. The encryption method according to claim 1, wherein: The types of cryptographic algorithms and / or execution orders of cryptographic algorithms of different cryptographic algorithm combinations in the cryptographic algorithm combination set are different; the execution order of the cryptographic algorithms includes parallel execution and serial execution according to the priority of each cryptographic algorithm.
4. The encryption method according to any one of claims 1 to 3, characterized in that: Constructing a cryptographic algorithm combination set based on the application scenario and the compatibility performance, taking the cryptographic algorithm combination set as input and a preset target performance of the encryption device as a target, and determining an optimal cryptographic algorithm combination in the cryptographic algorithm combination set, including: Encoding the cryptographic algorithm combinations in the cryptographic algorithm combination set into individuals to form an initial population containing the same number of individuals as the cryptographic algorithm combinations; wherein each individual represents a cryptographic algorithm combination; Determining an individual fitness value of each cryptographic algorithm combination; wherein the individual fitness value represents the degree to which the cryptographic algorithm combination meets the target performance of the preset encryption device; Based on the individual fitness values, a selection operator is used to select individuals with individual fitness values higher than a set individual fitness value from the current initial population as parent individuals; After performing a crossover operator operation on the parent individuals according to a preset crossover probability, a mutation operator operation is performed to obtain a set of offspring individuals; Based on the set of offspring individuals, individuals with low individual fitness values in the current initial population are replaced to form a new generation population; wherein the low individual fitness value is a value lower than the set individual fitness value; Repeat the steps of calculating individual fitness values to form a new generation population until the preset algorithm termination condition is met, decode the individual with the highest individual fitness value in the final population, and obtain the optimal cryptographic algorithm combination that meets the target performance of the preset encryption device.
5. The encryption method according to claim 4, wherein: Determine the individual fitness value of each cryptographic algorithm combination, including: For each individual in the current initial population, decode it into the corresponding decoding cryptographic algorithm combination; Running the decoding cryptographic algorithm combination on the encryption device to obtain operation result data; The individual fitness value of the current decoding cryptographic algorithm is calculated based on the operation result data and the preset target performance of the encryption device.
6. The encryption method according to claim 1, wherein: After constructing a cryptographic algorithm combination set based on the application scenario and the compatibility performance, taking the cryptographic algorithm combination set as input and a preset target performance of the encryption device as a target, and determining an optimal cryptographic algorithm combination in the cryptographic algorithm combination set, the method further includes: Encrypting the data to be encrypted based on the optimal cryptographic algorithm combination, obtaining a master key corresponding to each cryptographic algorithm in the optimal cryptographic algorithm combination, and generating a backup key corresponding to each master key; The master key and the backup key are stored in a random order.
7. The encryption method according to claim 6, wherein: Storing the master key and the backup key in a random order includes: The master key and the backup key are stored in a disordered manner, and an identity is assigned to each of the master key and the backup key, so that the decryption device obtains a key based on the identity for calculation.
8. The encryption method according to claim 1, wherein: A cryptographic algorithm combination set is constructed based on the application scenario and the compatibility performance, including: Conduct real-time dynamic perception of security situation and obtain actual security situation results; The cryptographic algorithm combination set is constructed based on the application scenario, the compatibility performance and the actual security situation results.
9. The encryption method according to claim 8, wherein: Constructing the cryptographic algorithm combination set based on the application scenario, the compatibility performance, and the actual security situation result includes: When the security requirement in the application scenario is consistent with the actual security situation result, or the security requirement is higher than the actual security situation result, the cryptographic algorithm combination set is directly constructed based on the application scenario and the compatibility performance; When the security requirement in the application scenario is lower than the actual security situation result, the cryptographic algorithm combination set is constructed based on the encryption order in the application scenario, the compatibility performance and the actual security situation result.
10. The encryption method according to claim 1, wherein: Applicable to baseboard management controller.
11. The encryption method according to claim 1, wherein: The cryptographic algorithm combination includes one or more algorithms selected from symmetric cryptographic algorithms, asymmetric cryptographic algorithms, hash cryptographic algorithms, and post-quantum cryptographic algorithms.
12. An encryption device, characterized in that: include: An application scenario determination module, used to determine the application scenario based on the amount of data encrypted by the encryption device, security requirements, and encryption order; a compatibility performance determination module, configured to determine compatibility performance based on a decryption condition of a decryption device; wherein the compatibility performance is a decryption type supported by the decryption device; An encryption algorithm determination module is used to construct a cryptographic algorithm combination set based on the application scenario and the compatibility performance, and take the cryptographic algorithm combination set as input and the target performance of a preset encryption device as a target, to determine the optimal cryptographic algorithm combination in the cryptographic algorithm combination set, so as to encrypt the data to be encrypted based on the optimal cryptographic algorithm combination.
13. An encryption device, characterized in that: include: Memory for storing computer programs; A processor, configured to execute the computer program to implement the steps of the encryption method according to any one of claims 1 to 11.
14. A storage medium, characterized in that The storage medium stores a computer program, which, when executed by a processor, implements the steps of the encryption method according to any one of claims 1 to 11.
15. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instruction is executed by a processor, the steps of the encryption method according to any one of claims 1 to 11 are implemented.
Citation Information
Patent Citations
Adaptive learning method and device based on multi-target dynamic distribution
CN111325284A
Data encryption method and device and data decryption method and device
CN114221766A
Data encryption method and device, equipment and storage medium
CN114244508A
System and method for managing secure information within a hybrid portable computing device
US20120054498A1
Provider and receiver cryptosystems comprising combined algorithms
US20230269080A1
Cited By
Implementation method of anti-quantum hybrid cryptographic optimization algorithm
CN121396434A
An anti-quantum mixing password optimization algorithm implementation method
CN121396434B
Password strategy self-adaptive arrangement method, system, equipment and medium
CN121750229A