Data encryption method and device, electronic equipment and storage medium
Through the invisible encryption method based on tags, the precise traceability problem during power data leakage is solved, the full tracking and traceability of power data is realized, and data security and traceability efficiency are improved.
Patent Information
- Application Number
- CN202510375048.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-27
- Publication Date
- 2025-08-12
AI Technical Summary
In the prior art, digital watermarks are easily targeted, and information is easily tampered with or lost, resulting in the inability to accurately trace when power data is leaked. Traditional encryption technology lacks effective traceability means, making it difficult to determine the source and propagation path of data.
The invisible encryption method based on tags is adopted, and the traceability information of the power data is set according to multiple predetermined tags, and the traceability code is encoded and generated, and converted into an invisible encryption code and inserted into the power data to realize invisible encryption and accurate traceability of the power data.
It realizes full tracking and traceability of power data, improves the efficiency and accuracy of investigation of data leakage incidents, provides comprehensive protection, and ensures data security and traceability.
Smart Images

Figure CN120470596A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data processing technology, and in particular to a data encryption method, device, electronic device and storage medium. Background Art
[0002] Digital watermarking emerged as a result of the need to encrypt data. Digital watermarking technology embeds specific information (such as copyright information and owner information) into digital media (such as text, images, audio, and video) without affecting the original media's usability. Digital watermarking technology offers advantages such as concealment, robustness, and security, providing effective traceability and copyright protection for data without affecting its normal use. However, digital watermarks are vulnerable to attacks, as attackers can exploit algorithms and tools to destroy, modify, or delete the watermark information. If subjected to targeted attacks, the watermark information may be lost or tampered with, making it impossible to accurately trace the data using the watermark information. Summary of the Invention
[0003] In view of this, the purpose of this application is to propose a data encryption method, device, electronic device and storage medium to overcome all or part of the deficiencies in the prior art.
[0004] Based on the above-mentioned purpose, the present application provides a data encryption method, including: in response to determining that power data to be encrypted has been received, setting traceability information corresponding to the power data according to multiple predetermined tags; encoding the traceability information to obtain a traceability code; converting the traceability code into an invisible encryption code, and inserting the invisible encryption code into the power data.
[0005] Optionally, inserting the invisible encryption code into the power data includes: in response to determining that the power data is structured data, inserting the invisible encryption code into the end position of any paragraph in the power data; in response to determining that the power data is unstructured data, inserting the invisible encryption code into the starting position or the ending position of the power data.
[0006] Optionally, after inserting the invisible encryption code into the power data, the method includes: in response to detecting the existence of operation information on the power data, verifying the operation authority of the operator corresponding to the operation information; in response to determining that the operator has not passed the operation authority verification, based on the operation information, generating and sending a first alarm message to the operator, generating and sending a second alarm message to the power data administrator, and tracing the power data.
[0007] Optionally, after inserting the invisible encryption code into the power data, the method includes: in response to determining that there is leaked power data, tracing the source of the power data.
[0008] Optionally, tracing the power data includes: extracting an invisible encryption code from the power data; performing a visible restoration operation on the invisible encryption code to obtain a traceability code corresponding to the power data; and decoding the traceability code to obtain the traceability information.
[0009] Optionally, after inserting the invisible encryption code into the power data, the method further includes: in response to determining that at least one predetermined tag corresponding to the power data is updated, updating the invisible encryption code based on the updated plurality of predetermined tags.
[0010] Optionally, the plurality of predetermined tags include at least the source of power data, sensitive type identification, access source information, storage geographic location, access time and data security status.
[0011] Based on the same inventive concept, the present application also provides a data encryption device, including: a setting module, configured to, in response to determining that power data to be encrypted is received, set traceability information corresponding to the power data according to multiple predetermined tags; an encoding module, configured to encode the traceability information to obtain a traceability code; an insertion module, configured to convert the traceability code into an invisible encryption code and insert the invisible encryption code into the power data.
[0012] Based on the same inventive concept, the present application also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable by the processor, wherein the processor implements the method described above when executing the computer program.
[0013] Based on the same inventive concept, the present application also provides a non-transitory computer-readable storage medium, which stores computer instructions, and the computer instructions are used to enable a computer to execute the method as described above.
[0014] As can be seen from the above, the data encryption method, device, electronic device and storage medium provided by the present application include, in response to determining that the power data to be encrypted is received, setting the traceability information corresponding to the power data according to multiple predetermined tags, and ensuring the accuracy of the traceability information corresponding to the power data set according to the multiple predetermined tags. The traceability information is encoded to obtain a traceability code, which ensures the integrity and confidentiality of the traceability information and, at the same time, compresses the amount of information in the traceability information. The traceability code is converted into an invisible encryption code, and the invisible encryption code is inserted into the power data to achieve the purpose of invisible encryption of the power data, and then the invisible encryption code can be used to accurately trace the power data. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] In order to more clearly illustrate the technical solutions in this application or related technologies, the following briefly introduces the drawings required for use in the embodiments or related technical descriptions. Obviously, the drawings described below are merely embodiments of this application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0016] Figure 1 A flowchart of a data encryption method according to an embodiment of the present application;
[0017] Figure 2 A schematic diagram of the structure of a data encryption device according to an embodiment of the present application;
[0018] Figure 3 This is a schematic diagram of the hardware structure of the electronic device according to an embodiment of the present application. DETAILED DESCRIPTION
[0019] In order to make the objectives, technical solutions and advantages of this application more clear, this application is further described in detail below in combination with specific embodiments and with reference to the accompanying drawings.
[0020] It should be noted that, unless otherwise defined, the technical terms or scientific terms used in the embodiments of the present application should have the usual meanings understood by people with ordinary skills in the field to which this application belongs. The "first", "second" and similar words used in the embodiments of the present application do not indicate any order, quantity or importance, but are only used to distinguish different components. "Include" or "comprise" and similar words mean that the elements or objects appearing before the word cover the elements or objects listed after the word and their equivalents, without excluding other elements or objects. "Connect" or "connected" and similar words are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. "Up", "down", "left", "right" and the like are only used to indicate relative positional relationships. When the absolute position of the described object changes, the relative positional relationship may also change accordingly.
[0021] As described in the background technology section, traditional encryption technology converts data into ciphertext, which can only be decrypted into the original data by the recipient with the correct key. In power systems, encryption technology is often used to protect the security of data during transmission and storage. In terms of data transmission, the SSL / TLS protocol is used to encrypt data for transmission, ensuring that the data is not stolen or tampered with during network transmission. During data storage, important power data is encrypted and stored, such as using the AES encryption algorithm to encrypt user electricity usage information and store it in a database. Encryption technology is divided into symmetric encryption and asymmetric encryption. Symmetric encryption uses the same key for encryption and decryption, which is fast, but key management is difficult. Asymmetric encryption uses public and private keys for encryption and decryption, which is relatively simple to manage, but the encryption speed is slow.
[0022] Traditional encryption technology has significant shortcomings in data traceability. Even if a data leak is detected, the lack of effective traceability makes it difficult to determine the data's source, transmission path, and specific links in the leak. In some large-scale data leaks, traditional encryption technology and access control methods fail to provide sufficient information to accurately determine the department, device, or employee responsible for the data breach. This makes remediation difficult and prevents timely and effective containment of the impact of the data leak.
[0023] Digital watermarking technology embeds specific information (such as copyright information, owner information, etc.) into digital media (such as text, images, audio, video, etc.) without affecting the usability of the original media. In the protection of important power data, digital watermarking technology can be used to track the source and transmission path of data. A digital watermark containing information such as the source of the data and the affiliated unit is embedded in the design drawings of the power equipment. When it is discovered that the drawings have been illegally disseminated, the source of the data can be traced back by extracting the information in the digital watermark. Digital watermarking technology has the characteristics of concealment, robustness, and security. It can provide effective traceability and copyright protection for data without affecting the normal use of the data.
[0024] Electricity data is complex and diverse, encompassing a wide range of information, including data sources and access records. Digital watermarking technology has a limited information capacity and only embeds basic information in power data, such as power equipment design drawings, making it difficult to fully meet traceability requirements. In the event of a data leak, the watermark lacks sufficient information to accurately trace the transmission path, making subsequent investigations difficult and failing to provide sufficient decision-making basis for companies responding to data leaks. Furthermore, digital watermarks are vulnerable to attacks, as attackers can exploit algorithms and tools to destroy, modify, or delete watermark information. During data transmission, if subjected to targeted attacks, the traceability information in the watermark may be lost or tampered with, making it impossible to accurately trace the data source, compromising data security and traceability.
[0025] In view of this, the present application embodiment proposes a data encryption method, referring to Figure 1 , including the following steps:
[0026] Step 101 : In response to determining that power data to be encrypted is received, setting traceability information corresponding to the power data according to a plurality of predetermined tags.
[0027] In this step, encrypting the power data is crucial because it involves sensitive information such as grid operation, supply and demand balance, and user privacy. Encryption ensures data security during transmission and storage, safeguarding the stable operation of the grid. In response to determining that the power data originates from a predetermined source and that the power data has been accessed, it is determined that power data to be encrypted has been received, where the predetermined source is a pre-set source of data requiring encryption, and the power data is determined to be power data to be encrypted. If the power data originates from a predetermined source, the power data is relatively important. If the power data has been accessed, it indicates a risk of data leakage, and in this case, the power data is power data to be encrypted.
[0028] Upon receiving power data to be encrypted, traceability information corresponding to the power data is set based on multiple predetermined tags, wherein the predetermined tags are pre-set tags indicating the source information of the power data and the access information of the operator of the power data. Based on the multiple predetermined tags, traceability information can be captured in the information obtained related to the power data. For example, when the predetermined tags are access source information, the access source to the power data can be captured. A tag-driven approach is used to identify power data, comprehensively considering multi-dimensional factors such as data source, business attributes, data type, and data importance level, defining multiple predetermined tags, and setting traceability information corresponding to the power data based on the multiple predetermined tags. The predetermined tags are accurately associated with the information corresponding to the power data, thereby achieving comprehensive and accurate identification of the power data. In the prior art, due to the visibility of watermark encryption, the information carrying capacity of watermark encryption is limited. However, in the present application, due to the invisible encryption method, the information carrying capacity can be adjusted according to the number of predetermined tags, ensuring the accuracy of the traceability information corresponding to the power data set based on the multiple predetermined tags.
[0029] Step 102: Encode the traceability information to obtain a traceability code.
[0030] In this step, to enhance the security of traceability information, the information is encoded, making it less susceptible to tampering and generating a traceability code. Encoding the traceability information ensures its integrity and confidentiality while also compressing the amount of information. Even with relatively large amounts of traceability information, a traceability code of moderate length can be generated.
[0031] Step 103: convert the traceability code into an invisible encryption code, and insert the invisible encryption code into the power data.
[0032] In this step, the traceability code is converted into an invisible encryption code, where the invisible encryption code is an invisible encryption code, for example, a zero-width character or a specific Unicode character. The invisible encryption code does not affect the display and function of the power data, but can be read later using specialized tools. To obtain zero-width characters using the traceability code, the traceability code needs to be converted into binary form, and then the binary number needs to be mapped into zero-width characters (such as zero-width space, zero-width non-ligature, zero-width ligature, etc.). This process involves an encoding algorithm to ensure that the converted zero-width characters can hide information while not affecting the normal display of the power data. To obtain a specific Unicode character using the traceability code, the traceability code can be treated as a digital code, and then the Python chr() function can be used to convert this digital code into the corresponding Unicode character. This method is direct and effective, and can quickly achieve the conversion of the traceability code to Unicode characters. The invisible encryption code is inserted into the power data. The invisible encryption code is invisible in the power data and cannot be tampered with by the outside world, achieving the purpose of invisible encryption of the power data. The invisible encryption code can then be used to accurately trace the power data.
[0033] By converting traceability codes into invisible characters and inserting them into power data, the entire flow of power data can be tracked and traced, providing strong support for the investigation and handling of power data leaks. This tag-based approach to preventing power data leaks offers unique advantages, including precise identification, efficient traceability, and comprehensive protection. In terms of precise identification, a multi-dimensional identification system enables comprehensive and accurate identification of power data. Both structured and unstructured data can be accurately classified and labeled based on their characteristics and attributes, providing a solid foundation for subsequent security management. In terms of efficient traceability, the traceability code system encompasses a wealth of information, including the source of power data, access source information, storage location, and access time. This information provides comprehensive clues for data leak investigations. In the event of a data leak, the traceability code can be quickly read to quickly locate the data's source and transmission path, identifying the responsible individuals, significantly improving the efficiency and accuracy of traceability. In terms of comprehensive protection, this approach establishes a comprehensive protection system, from data identification and labeling to monitoring and traceability, achieving comprehensive protection for power data.
[0034] With the above solution, in response to determining that power data to be encrypted has been received, traceability information corresponding to the power data is set based on multiple predetermined tags, ensuring the accuracy of the traceability information corresponding to the power data set based on the multiple predetermined tags. The traceability information is encoded to obtain a traceability code, which ensures the integrity and confidentiality of the traceability information while also compressing the amount of information contained in the traceability information. The traceability code is converted into a stealth encryption code, which is then inserted into the power data, achieving the purpose of stealth encryption of the power data. The stealth encryption code can then be used to accurately trace the power data.
[0035] In some embodiments, inserting the invisible encryption code into the power data includes: in response to determining that the power data is structured data, inserting the invisible encryption code into the end position of any paragraph in the power data; in response to determining that the power data is unstructured data, inserting the invisible encryption code into the starting position or the ending position of the power data.
[0036] In this embodiment, for structured data (such as fields in a database table), a suitable position can be selected for insertion without affecting the logical relationship of the data. Therefore, when the power data is structured data, the invisible encryption code is inserted into the end position of any paragraph in the power data. For unstructured data (such as documents, pictures, etc.), it can be inserted into the metadata part of the file or a designated hidden area. Therefore, when the power data is unstructured data, the invisible encryption code is inserted into the starting position and the end position of the power data. In this way, even if the power data is copied, transmitted or stored elsewhere, the traceability code will still exist with the data. For power data of different data types, it is inserted into different positions in the power data to avoid the influence of the invisible encryption code on the power data.
[0037] In some embodiments, after inserting the invisible encryption code into the power data, the method includes: in response to detecting the existence of operation information on the power data, verifying the operation authority of the operator corresponding to the operation information; in response to determining that the operator has not passed the operation authority verification, based on the operation information, generating and sending a first alarm message to the operator, generating and sending a second alarm message to the power data administrator, and tracing the power data.
[0038] In this embodiment, in response to detecting the existence of operation information on power data, wherein the operation information includes copying, transmission or storage. The authority of the operator corresponding to the operation information is verified, for example, a verification information box pops up on the display interface to verify the operator's authority. In the case that the operator fails to pass the operation authority verification, based on the operation information, a first alarm message is generated and sent to the operator, wherein the first alarm message is information that warns the operator to prohibit operations on the power data. Since there are users outside the operation authority operating the power data at this time, it is also necessary to warn the power data administrator. Based on the operation information, a second alarm message is generated and sent to the power data administrator. The second alarm message is information that notifies the power data administrator that there is an illegal operation on the power data. Invisible encryption codes are used to trace the source of power data that may be leaked to strengthen the protection of power data and ensure accurate tracing of power data that may be leaked.
[0039] Traditional access control methods rely primarily on static permission allocations, making them inadequate for addressing complex and volatile internal threats and external attacks. Internal employees may exploit legitimate permissions to conduct illegal data operations, which traditional access control cannot detect and prevent in a timely manner. Traditional access control also proves powerless against external attackers who gain access to legitimate accounts to steal data. In contrast, tag-based methods, through comprehensive data identification and real-time monitoring, can promptly detect anomalous data access and manipulation behaviors, effectively tracking and tracing the attacker, regardless of whether they are an internal employee or an external hacker.
[0040] Compared to other common anti-leakage technologies, such as encryption, which primarily focuses on encrypted data transmission and storage, preventing data theft or tampering during transmission and storage, it lacks effective monitoring and management of data usage and circulation. While digital watermarking can be used for data traceability, its information capacity is limited and it is vulnerable to attacks and tampering. Label-based approaches, on the other hand, not only encrypt and protect data but also enable monitoring and management throughout its entire lifecycle. Through rich traceability code information, they can accurately trace the data's source, transmission path, and relevant responsible individuals.
[0041] In some embodiments, after inserting the invisible encryption code into the power data, the method includes: in response to determining that there is leaked power data, tracing the power data.
[0042] In this embodiment, there is leaked power data in the outside world. In order to obtain relevant information about the power data, the power data is traced. Because the power data in this application contains an invisible encryption code, the invisible encryption code can indicate the source information of the power data and the operator's access information, and the invisible encryption code can prevent external tampering. Therefore, the accuracy of the power data tracing is ensured.
[0043] In some embodiments, tracing the power data includes: extracting an invisible encryption code from the power data; performing a visible restoration operation on the invisible encryption code to obtain a traceability code corresponding to the power data; and decoding the traceability code to obtain the traceability information.
[0044] In this embodiment, an invisible encryption code is present in the power data. The invisible encryption code is extracted from the power data and a visible restoration operation is performed on the invisible encryption code to obtain the traceability code corresponding to the power data. Since the traceability code is the traceability information after encoding, it is also necessary to decode the traceability code to obtain the traceability information. By extracting the traceability code using a method opposite to the embedding process, verifying its integrity, and restoring and reading the information in the traceability code, the source of the data, the transmission path, and the relevant responsible persons can be quickly located, facilitating the timely implementation of countermeasures. Due to the invisibility of the invisible encryption code, tampering with the invisible encryption code is avoided, thereby ensuring the accuracy of the traceability information obtained.
[0045] In some embodiments, after inserting the invisible encryption code into the power data, the method further includes: in response to determining that at least one predetermined tag corresponding to the power data is updated, updating the invisible encryption code based on the updated multiple predetermined tags.
[0046] In this embodiment, when it is determined that at least one predetermined tag corresponding to the power data has been updated, the invisible encryption code is updated based on the updated multiple predetermined tags. Taking into account the changes in the power business and the evolution of security requirements, a dynamic update mechanism for the traceability code coding system is established. The traceability code coding rules are regularly evaluated and optimized to ensure that they adapt to new business scenarios and technical environments. At the same time, the power data that has been inserted with the traceability code is periodically managed and maintained to ensure the validity and integrity of the traceability information. Through real-time power data monitoring and dynamic update management mechanisms, various potential data security threats can be discovered and responded to in a timely manner to ensure the security and confidentiality of data throughout its life cycle. This comprehensive protection system can effectively resist various internal and external attacks, providing reliable protection for the data security of power companies.
[0047] In some embodiments, the plurality of predetermined tags include at least the source of power data, sensitive type identification, access source information, storage geographic location, access time and data security status.
[0048] In this embodiment, a tag-driven approach is first used to identify power data. Based on factors such as the data's source, sensitive type identification, access source information, storage location, access time, and data security status, various predefined tags are defined and associated with the power data. This predefined tagging enables comprehensive and accurate data tracing, facilitating timely response measures.
[0049] The following describes several predefined tags:
[0050] (1) Power data sources: such as the power generation side, transmission side, distribution side, and user side, for example, power plant A, substation B, etc. The above power data sources can be represented by predetermined codes. By searching a pre-built table, the predetermined code corresponding to the power data source can be obtained, making the invisible encryption code have a larger data carrying capacity.
[0051] (2) Sensitive type identification: Different sensitive type identifications are assigned according to the nature of sensitive data (such as user privacy, key equipment operating parameters, etc.).
[0052] (3) Access source information: records the subject who initially accessed the sensitive data (such as an employee in a department, an automated program, etc.), including the subject's identity (user name, IP address, etc.).
[0053] (4) Storing geographic location: Identifying the location information when the data operation occurs (such as the geographic coordinates of the data center, office location, etc.), which can use latitude and longitude or other geographic coding methods.
[0054] (5) Access time: Accurately record the timestamp (year, month, day, hour, minute, second) of data operations to ensure the accuracy of time information.
[0055] (6) Data security status: describes the security status of the data (such as encryption status, integrity check results, etc.), represented by a specific symbol.
[0056] In addition, the predetermined tags may also include business attributes, such as production operations, marketing, customer service, etc.
[0057] In another embodiment provided by the present application, in response to determining that power data has been accessed and an operator is present, the accessed power data is extracted from the data stream accessed by the proxy, and predetermined tag data such as the operator's corresponding access source information, IP address, geographic location, and data source is extracted. Sensitive data types of the power data are obtained. Predetermined tag data such as the power data source, access source, IP address, and sensitive power data type are encoded to generate a traceability code. The traceability code is then converted into invisible characters through abbreviated coding, i.e., an invisible encryption code. The generated invisible characters are inserted into the power data. The processed data is forwarded to the operator. When power data is illegally accessed, copied, transmitted, or stored, the monitoring system automatically detects whether it contains a traceability code. If an anomaly is detected, the traceability process is triggered, and data analysis and responsibility determination are performed by reading the information in the traceability code, which vividly illustrates the mechanism of data monitoring and traceability triggering. When illegal access or storage of sensitive data is detected, an alarm is triggered, and data traceability is initiated. The data stream of the illegal behavior is extracted and checked to see whether it contains the invisible character information generated by the traceability code. Restore the invisible characters of the code to recover the traceability code and restore the information contained in the traceability code.
[0058] For example, the invisible encryption code may be Src=10.12.34.56|Type=01 (identity identifier)User=ZHANGSAN|Geo:39.9042N,116.4074E|Time-2025-02-20T14:30Z.
[0059] It should be noted that the method of the embodiment of the present application can be performed by a single device, such as a computer or server. The method of this embodiment can also be applied in a distributed scenario and performed by multiple devices working together. In such a distributed scenario, one of the multiple devices may only perform one or more steps of the method of the embodiment of the present application, and the multiple devices will interact with each other to complete the method.
[0060] It should be noted that the above description is limited to some embodiments of the present application. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in an order different from that described in the above embodiments and still achieve the desired results. Furthermore, the processes depicted in the accompanying drawings do not necessarily require the specific order or sequential order shown to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0061] Based on the same inventive concept, corresponding to any of the above-mentioned embodiment methods, the present application also provides a data encryption device.
[0062] refer to Figure 2 , the data encryption device comprises:
[0063] The setting module 10 is configured to, in response to determining that power data to be encrypted is received, set traceability information corresponding to the power data according to a plurality of predetermined tags.
[0064] The encoding module 20 is configured to encode the traceability information to obtain a traceability code.
[0065] The inserting module 30 is configured to convert the traceability code into an invisible encryption code and insert the invisible encryption code into the power data.
[0066] In response to receiving the power data to be encrypted, the device sets traceability information corresponding to the power data based on multiple predetermined tags, ensuring the accuracy of the traceability information set based on the multiple predetermined tags. The traceability information is encoded to generate a traceability code, ensuring the integrity and confidentiality of the traceability information while also compressing the amount of information contained in the traceability information. The traceability code is converted into a stealth encryption code, which is then inserted into the power data, achieving stealth encryption of the power data. The stealth encryption code can then be used to accurately trace the power data.
[0067] In some embodiments, the insertion module 30 is further configured to, in response to determining that the power data is structured data, insert the invisible encryption code into the end position of any paragraph in the power data; in response to determining that the power data is unstructured data, insert the invisible encryption code into the starting position or the ending position of the power data.
[0068] In some embodiments, a first traceability module is also included. The first traceability module is configured to, after inserting the invisible encryption code into the power data, in response to detecting the existence of operation information on the power data, verify the operation authority of the operator corresponding to the operation information; in response to determining that the operator has not passed the operation authority verification, generate and send a first alarm message to the operator based on the operation information, generate and send a second alarm message to the power data administrator, and trace the power data.
[0069] In some embodiments, a second tracing module is further included, wherein the first tracing module is configured to trace the power data in response to determining that there is leaked power data after the invisible encryption code is inserted into the power data.
[0070] In some embodiments, the first traceability module or the second traceability module is further configured to extract the invisible encryption code in the power data; perform a visible restoration operation on the invisible encryption code to obtain the traceability code corresponding to the power data; and decode the traceability code to obtain the traceability information.
[0071] In some embodiments, an update module is further included. The update module is configured to update the invisible encryption code based on the updated multiple predetermined tags in response to determining that at least one predetermined tag corresponding to the power data is updated.
[0072] In some embodiments, the setting module is further configured so that the plurality of predetermined tags include at least power data source, sensitive type identification, access source information, storage geographic location, access time and data security status.
[0073] For the convenience of description, the above devices are described as being divided into various modules according to their functions. Of course, when implementing this application, the functions of each module can be implemented in the same or multiple software and / or hardware.
[0074] The apparatus of the above embodiment is used to implement the corresponding data encryption method in any of the above embodiments, and has the beneficial effects of the corresponding method embodiment, which will not be described in detail here.
[0075] Based on the same inventive concept, corresponding to any of the above-mentioned embodiments and methods, the present application also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and runnable on the processor, wherein when the processor executes the program, it implements the data encryption method described in any of the above embodiments.
[0076] Figure 3 10 is a schematic diagram showing a more specific hardware structure of an electronic device provided in this embodiment. The device may include: a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. The processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040 are communicatively connected to each other within the device via the bus 1050.
[0077] The processor 1010 can be implemented using a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this specification.
[0078] The memory 1020 can be implemented in the form of ROM (Read Only Memory), RAM (Random Access Memory), static storage devices, dynamic storage devices, etc. The memory 1020 can store an operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 1020 and is called and executed by the processor 1010.
[0079] The input / output interface 1030 is used to connect an input / output module to implement information input and output. The input / output module can be configured as a component in the device (not shown in the figure) or can be externally connected to the device to provide corresponding functions. Input devices may include a keyboard, mouse, touch screen, microphone, various sensors, etc., and output devices may include a display, speaker, vibrator, indicator light, etc.
[0080] The communication interface 1040 is used to connect to a communication module (not shown) to enable communication between the device and other devices. The communication module can communicate via a wired method (such as USB, network cable, etc.) or a wireless method (such as mobile network, WiFi, Bluetooth, etc.).
[0081] The bus 1050 comprises a path for transmitting information between the various components of the device (eg, the processor 1010 , the memory 1020 , the input / output interface 1030 , and the communication interface 1040 ).
[0082] It should be noted that although the above device only shows the processor 1010, the memory 1020, the input / output interface 1030, the communication interface 1040, and the bus 1050, in a specific implementation, the device may also include other components necessary for normal operation. In addition, it will be understood by those skilled in the art that the above device may only include the components necessary to implement the embodiments of this specification, and does not necessarily include all the components shown in the figure.
[0083] The electronic device of the above embodiment is used to implement the corresponding data encryption method in any of the above embodiments, and has the beneficial effects of the corresponding method embodiment, which will not be repeated here.
[0084] Based on the same inventive concept, corresponding to any of the above-mentioned embodiment methods, the present application also provides a non-transitory computer-readable storage medium, which stores computer instructions, and the computer instructions are used to enable the computer to execute the data encryption method described in any of the above embodiments.
[0085] The computer-readable media of this embodiment include permanent and non-permanent, removable and non-removable media that can be used to store information by any method or technology. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, read-only compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, tape disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device.
[0086] The computer instructions stored in the storage medium of the above embodiment are used to enable the computer to execute the data encryption method described in any of the above embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.
[0087] Based on the same concept, corresponding to any of the above-mentioned embodiment methods, the present application also provides a computer program product, including computer program instructions. When the computer program instructions are run on a computer, the computer executes the data encryption method described in any of the above embodiments, which has the beneficial effects of the corresponding method embodiments and will not be repeated here.
[0088] It should be noted that the embodiments of the present application can be further described in the following manner:
[0089] It is understandable that before using the technical solutions of each embodiment of the present disclosure, the type, scope of use, usage scenarios, etc. of the personal information involved will be informed to the user in an appropriate manner, and the user's authorization will be obtained.
[0090] For example, in response to a user's active request, a prompt message is sent to the user to clearly inform the user that the requested operation will require the acquisition and use of the user's personal information. This allows the user to independently choose whether to provide personal information to the electronic device, application, server, storage medium, or other software or hardware that performs the operation of the disclosed technical solution based on the prompt message.
[0091] As an optional but non-limiting implementation, in response to a user's active request, the prompt information may be sent to the user in the form of a pop-up window, in which the prompt information may be presented in text form. Furthermore, the pop-up window may also contain a selection control for the user to select "agree" or "disagree" to provide personal information to the electronic device.
[0092] It is understandable that the above notification and user authorization process are merely illustrative and do not constitute a limitation on the implementation of the present disclosure. Other methods that comply with relevant laws and regulations may also be applied to the implementation of the present disclosure.
[0093] Those skilled in the art should understand that the discussion of any of the above embodiments is merely illustrative and is not intended to imply that the scope of the present application is limited to these examples. In line with the present application, the technical features in the above embodiments or different embodiments may be combined, the steps may be implemented in any order, and there are many other variations of the different aspects of the embodiments of the present application as described above, which are not provided in detail for the sake of simplicity.
[0094] In addition, for simplicity of description and discussion, and in order not to make the embodiment of the application difficult to understand, the known power supply / ground connection with integrated circuit (IC) chip and other components may or may not be shown in the accompanying drawings provided. In addition, the device can be shown in the form of a block diagram to avoid making the embodiment of the application difficult to understand, and this also takes into account the following fact, that is, the details of the embodiment of these block diagram devices are highly dependent on the platform to be implemented in the embodiment of the application (that is, these details should be fully within the scope of understanding of those skilled in the art). When specific details (for example, circuit) are set forth to describe exemplary embodiments of the application, it will be apparent to those skilled in the art that the embodiment of the application can be implemented without these specific details or when these specific details are changed. Therefore, these descriptions should be considered to be illustrative rather than restrictive.
[0095] Although the present invention has been described in conjunction with specific embodiments thereof, many alternatives, modifications, and variations of these embodiments will be apparent to those skilled in the art based on the foregoing description. For example, other memory architectures (e.g., dynamic RAM (DRAM)) may utilize the embodiments discussed.
[0096] The embodiments of the present application are intended to cover all such substitutions, modifications, and variations that fall within the broad scope of the present application. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the embodiments of the present application should be included in the scope of protection of the present application.
Claims
1. A data encryption method, characterized in that: include: In response to determining that power data to be encrypted is received, setting traceability information corresponding to the power data according to a plurality of predetermined tags; Encoding the traceability information to obtain a traceability code; The traceability code is converted into an invisible encryption code, and the invisible encryption code is inserted into the power data.
2. The method according to claim 1, characterized in that The step of inserting the invisible encryption code into the power data includes: In response to determining that the power data is structured data, inserting the invisible encryption code into any paragraph end position in the power data; In response to determining that the power data is unstructured data, the invisible encryption code is inserted into a start position or an end position of the power data.
3. The method according to claim 1, characterized in that After inserting the invisible encryption code into the power data, the method includes: In response to detecting that there is operation information on the power data, verifying the operation authority of the operator corresponding to the operation information; In response to determining that the operator has not passed the operation authority verification, based on the operation information, a first alarm message is generated and sent to the operator, a second alarm message is generated and sent to the power data administrator, and the power data is traced.
4. The method according to claim 1, wherein After inserting the invisible encryption code into the power data, the method includes: In response to determining that there is leaked power data, the power data is traced to its source.
5. The method according to claim 3 or 4, characterized in that The tracing of the power data includes: extracting the invisible encryption code in the power data; Performing a visible restoration operation on the invisible encryption code to obtain a traceability code corresponding to the power data; The traceability code is decoded to obtain the traceability information.
6. The method according to claim 1, characterized in that After inserting the invisible encryption code into the power data, the method further includes: In response to determining that at least one predetermined tag corresponding to the power data is updated, the invisible encryption code is updated based on the updated predetermined tags.
7. The method according to claim 1, characterized in that The plurality of predetermined tags include at least the source of power data, sensitive type identification, access source information, storage geographic location, access time and data security status.
8. A data encryption device, characterized in that: include: a setting module configured to, in response to determining that power data to be encrypted is received, set traceability information corresponding to the power data according to a plurality of predetermined tags; an encoding module configured to encode the traceability information to obtain a traceability code; The insertion module is configured to convert the traceability code into an invisible encryption code and insert the invisible encryption code into the power data.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that: When the processor executes the program, the method according to any one of claims 1 to 7 is implemented.
10. A non-transitory computer-readable storage medium storing computer instructions, characterized in that: The computer instructions are used to enable a computer to execute the method according to any one of claims 1 to 7.