Data tamper-proofing method and device

By dynamically determining the encryption and digest algorithm before data transmission, generating encrypted files and digest files, and building a two-factor verification mechanism, it solves the problems of security, complexity and flexibility in the data transmission process, and realizes high security, low complexity and high flexibility data tamper-proof.

CN120582818APending Publication Date: 2025-09-02SHENZHEN COMTOP INFORMATION TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510613207.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-13
Publication Date
2025-09-02

AI Technical Summary

Technical Problem

The prior art cannot take into account high security, low complexity and high flexibility during data transmission, resulting in data information leakage or illegal modification of content.

Method used

By dynamically determining the target encryption algorithm and digest extraction algorithm based on the network environment before data transmission, encrypted files and digest files are generated, and prompt messages are output by decrypting the analysis results, a two-factor verification mechanism is built to detect data tampering.

Benefits of technology

It realizes flexible response in different network environments, quickly and accurately screens out applicable algorithms, reduces computing complexity, improves the security and accuracy of data transmission, and significantly improves data tamper-proof ability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120582818A_ABST
    Figure CN120582818A_ABST
Patent Text Reader

Abstract

The invention relates to a data tamper-proofing method and device. The method comprises the following steps: receiving an encrypted file and an abstract file transmitted by a data sending end; the encrypted file is obtained by performing encryption processing on to-be-transmitted data by the data sending end by using a target encryption algorithm; the abstract file is generated by performing abstract extraction on to-be-transmitted data by the data sending end by using a target abstract extraction algorithm; the target encryption algorithm and the target abstract extraction algorithm are dynamically determined based on a network environment before data transmission; outputting a prompt message based on a decryption analysis result of the encrypted file and the abstract file; the prompt message is used for prompting whether the data transmission process is tampered or not. The method is high in safety, low in complexity and high in flexibility.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of data transmission, and in particular to a method and device for preventing data tampering. Background Art

[0002] With the rapid development of the Internet, data may be subject to threats such as attacks and malware tampering during transmission, resulting in data leakage or illegal modification of content, affecting the normal operation of business.

[0003] In related technologies, in order to prevent data from being tampered with during transmission, the data to be transmitted can be encrypted using different encryption algorithms (for example, symmetric algorithms, asymmetric encryption algorithms, hash function encryption algorithms, transport layer security protocols, etc.), and then the encrypted data can be transmitted to reduce the risk of data leakage and tampering.

[0004] However, the data tamper-proofing methods of related technologies cannot achieve high security, low complexity and high flexibility at the same time. Summary of the Invention

[0005] Based on this, it is necessary to provide a data tamper-proofing method and device to address the above technical issues, which can take into account high security, low complexity and high flexibility.

[0006] In a first aspect, the present application provides a data tamper-proofing method, comprising:

[0007] Receive the encrypted file and digest file transmitted by the data sender; the encrypted file is generated by the data sender using the target encryption algorithm to encrypt the data to be transmitted; the digest file is generated by the data sender using the target digest extraction algorithm to extract the digest of the data to be transmitted; the target encryption algorithm and the target digest extraction algorithm are both dynamically determined based on the network environment before data transmission;

[0008] Based on the decryption analysis results of the encrypted file and the digest file, a prompt message is output; the prompt message is used to indicate whether the data transmission process has been tampered with.

[0009] In one embodiment, the target encryption algorithm and the target summary extraction algorithm are based on the security score of the network environment before data transmission, and the algorithms suitable for the network environment are screened out from the national encryption algorithms.

[0010] In one embodiment, the encryption key parameters in the target encryption algorithm are generated based on the security score of the network environment before data transmission; the complexity of the encryption key parameters is negatively correlated with the security score.

[0011] In one embodiment, the method further comprises:

[0012] Determine whether the encryption parameters in the encrypted file have a data encryption identifier;

[0013] If so, determining a decryption analysis result of the transmitted data based on the digest file and the encrypted data in the encrypted file;

[0014] If not present, it is determined that the encryption parameters are not encrypted.

[0015] In one embodiment, determining a decryption analysis result of the transmitted data based on the digest file and the encrypted data includes:

[0016] Obtaining decrypted transmission data and decryption keys from encrypted data;

[0017] Determine whether the decryption key is consistent with the private key of the data to be transmitted;

[0018] If they are consistent, the decryption analysis result of the transmission data is determined based on the decrypted transmission data and the summary file; if they are inconsistent, the decryption analysis result of the transmission data is determined to be a transmission anomaly.

[0019] In one embodiment, obtaining decrypted transmission data and a decryption key from encrypted data includes:

[0020] The encrypted data is decrypted, and the decrypted data and the key are distinguished to obtain the decrypted transmission data and the decryption key.

[0021] In one embodiment, determining an abnormality identification result of the transmission data based on the decrypted transmission data and the digest file includes:

[0022] Extract the summary of the decrypted transmission data and generate a decryption summary file;

[0023] Compare the decrypted summary file with the summary file to obtain a comparison result;

[0024] Based on the comparison results, the decryption analysis results of the transmitted data are determined.

[0025] In one embodiment, the summary file includes device information, a timestamp of the data to be transmitted, and summary data;

[0026] Based on the comparison results, the decryption analysis results of the transmitted data are determined, including:

[0027] If the comparison result shows that the device information, timestamp, and summary data in the decrypted summary file and the summary file are identical, the decryption analysis result of the transmitted data is determined to be normal.

[0028] If the comparison result shows that any one of the device information, timestamp, and summary data in the decrypted summary file is different from that in the summary file, it is determined that the decryption analysis result of the transmitted data is abnormal.

[0029] In one embodiment, the method further comprises:

[0030] Inputting the decrypted summary file and the received summary file into a preset tampering identification model, analyzing the difference locations and difference types between the decrypted summary file and the received summary file, and determining the type of tampering during the data transmission process;

[0031] Determine the optimization strategy for data tampering based on the tampering type.

[0032] In a second aspect, the present application further provides a data tamper-proof device, comprising:

[0033] The receiving module is used to receive the encrypted file and digest file transmitted by the data sending end; the encrypted file is obtained by the data sending end encrypting the data to be transmitted using the target encryption algorithm; the digest file is generated by the data sending end using the target digest extraction algorithm to extract the digest of the data to be transmitted; the target encryption algorithm and the target digest extraction algorithm are both dynamically determined based on the network environment before data transmission;

[0034] The output module is used to output prompt messages based on the decryption analysis results of the encrypted file and the digest file; the prompt messages are used to indicate whether the data has been tampered with during the transmission process.

[0035] In a third aspect, the present application further provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the content of any one of the data tamper-proofing methods in the first aspect is implemented.

[0036] In a fourth aspect, the present application further provides a computer-readable storage medium on which a computer program is stored, and when the computer program is executed by a processor, the content of any one of the data tamper-proofing methods in the first aspect is implemented.

[0037] In a fifth aspect, the present application also provides a computer program product, comprising a computer program, which, when executed by a processor, implements the content of any one of the data tamper-proofing methods in the first aspect.

[0038] The data tamper-proofing method and device receive an encrypted file and a digest file transmitted by a data transmitter; the encrypted file is generated by encrypting the transmitted data using a target encryption algorithm; the digest file is generated by extracting a digest of the transmitted data using a target digest extraction algorithm; both the target encryption algorithm and the target digest extraction algorithm are dynamically determined based on the network environment before data transmission; a prompt message is output based on the decryption analysis results of the encrypted file and the digest file; the prompt message is used to indicate whether the data transmission process has been tampered with. This method dynamically determines the target encryption algorithm and target digest algorithm suitable for the current network environment based on the network environment before data transmission. This method not only flexibly adapts to the needs of different network environments, but also quickly and accurately selects highly used algorithms, reducing unnecessary redundant operations and reducing the complexity of the calculation process. Furthermore, by using the target encryption algorithm and the target digest extraction algorithm in combination, the encrypted file ensures the confidentiality of the data transmission, while the digest file is used to verify the data integrity. The two algorithms work together to form a dual verification mechanism that can more accurately detect tampering during data transmission, significantly improving data security. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following briefly introduces the drawings required for use in the embodiments of the present application or related technical descriptions. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying any creative work.

[0040] Figure 1 A diagram illustrating an application environment of a data tamper-proofing method according to an embodiment;

[0041] Figure 2 1 is a flow chart of a data tamper-proofing method according to an embodiment;

[0042] Figure 3 1 is a flow chart of a data tamper-proofing method according to an embodiment;

[0043] Figure 4 1 is a flow chart of a data tamper-proofing method according to an embodiment;

[0044] Figure 5 1 is a flow chart of a data tamper-proofing method according to an embodiment;

[0045] Figure 6 1 is a flow chart of a data tamper-proofing method according to an embodiment;

[0046] Figure 7 1 is a flow chart of a data tamper-proofing method according to an embodiment;

[0047] Figure 8 1 is a flow chart of a data tamper-proofing method according to an embodiment;

[0048] Figure 9 is a structural block diagram of a data tamper-proof device in one embodiment;

[0049] Figure 10 FIG. 1 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION

[0050] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0051] Before introducing the technical solution of the present application in detail, a brief introduction to the background technology of the present application is first given.

[0052] With the rapid development of the internet, the transmission and use of data across networks has become increasingly frequent and complex. However, data transmission can be subject to threats such as attacks and malware tampering, leading to data leakage or illegal content modification, impacting normal business operations. Therefore, ensuring the integrity and authenticity of data during transmission has become an urgent need.

[0053] Anti-tampering technology for data transmission primarily aims to prevent data from being illegally modified or destroyed during network transmission, thereby safeguarding its integrity, authenticity, and reliability. This development has evolved from basic integrity checks to complex security protocols, encompassing five key phases. The first phase involved using checksums to determine if data has been tampered with. This involves performing mathematical operations on the data to generate a fixed value. If the data has been tampered with, the checksum will change. The second phase included cyclic redundancy checks and message authentication codes. Similar to the checksum concept, cyclic redundancy checks provide a more sophisticated error detection method, providing some resistance to tampering. Message authentication codes combine hash functions and secret key technology, but still rely on both communicating parties sharing the same key. The third phase was symmetric encryption, which uses the same key for encryption and decryption. This method is fast and efficient, but less secure. The fourth phase was asymmetric encryption, which uses a pair of different keys (a public key for encryption and a private key for decryption). This method offers greater security but is slower and requires more complex key management. It's important to note that both symmetric and asymmetric encryption algorithms are data encryption methods based on the Transport Layer Security (TLS) protocol. This method provides a secure link between the application layer and the transport layer in a network to protect data from tampering. This method has a high performance overhead. The fifth stage is the secure transport protocol, which uses specialized TLS protocols (such as Transport Layer Security (TSL) and Secure Sockets Layer (SSL)) to encrypt and authenticate transmitted data. However, this method is complex to configure and lacks flexibility. Alternatively, data can be encrypted using hash function-based encryption, but this method is irreversible and is typically used to verify data integrity and detect tampering during transmission.

[0054] Currently, there are four main types of anti-tampering technologies. The first is data encryption, which encrypts the body of the request data. Common encryption algorithms include the Advanced Encryption Standard (AES), the Data Encryption Standard (DES), and the asymmetric Rivest-Shamir-Adleman (RSA) algorithm. The second is digital signature technology, which generates a data digest for the request data and encrypts it using a private key to generate a digital signature. The third is a security technology (token) mechanism for authentication and authorization. It can carry user information and permission information, and the server can verify the token to prevent malicious requests and tampering. The fourth is the Hypertext Transfer Protocol, a protocol used for secure communication on the Internet.

[0055] To address the above issues, the present application provides a data tamper-proofing method and device, which can achieve high security, low complexity, and high flexibility during data transmission. The technical solution of the present application is described in detail below.

[0056] The data tamper-proof method provided in the embodiment of the present application can be applied to Figure 1 In the application environment shown, the application environment includes a data sending end 101 and a data receiving end 102. The data sending end 101 is used to encrypt the transmitted data, extract the digest file, and send the encrypted file and the digest file to the data receiving end 102 before data transmission. After receiving the encrypted file and the digest file, the data receiving end 102 can determine whether the data has been tampered with during the transmission process.

[0057] In an exemplary embodiment, Figure 2 As shown, a data tamper-proof method is provided, which is applied to Figure 1 The data sending end in FIG. 1 is taken as an example to illustrate the method, which includes the following steps 101 to 102. Among them:

[0058] S101, receiving the encrypted file and digest file transmitted by the data sending end; the encrypted file is obtained by the data sending end encrypting the data to be transmitted using the target encryption algorithm; the digest file is generated by the data sending end using the target digest extraction algorithm to extract the digest of the data to be transmitted; the target encryption algorithm and the target digest extraction algorithm are both dynamically determined based on the network environment before data transmission.

[0059] The network environment may be network status information of a data sending end and / or a data receiving end. For example, the network status information may be information such as network bandwidth, network delay, and packet loss rate.

[0060] Before data transmission, a target encryption algorithm and a target digest extraction algorithm need to be determined based on the network environment. In one embodiment, the target encryption algorithm and the target digest extraction algorithm are based on the security score of the network environment before data transmission, and the algorithms suitable for the network environment are screened from the national encryption algorithms.

[0061] The data sending end can directly obtain its own network status information and determine the network environment's security score based on this network status information. Alternatively, the data sending end can send a network environment detection request to the data receiving end. Upon receiving this request, the data receiving end can feed back its own network status information to the data sending end. The data sending end can determine the network environment's security score based on both the data receiving end's network status information and the sending end's network status information. Alternatively, the network environment's security score can be determined based solely on the data receiving end's network status information. Based on this network environment's security score, a target digest extraction algorithm and target encryption algorithm suitable for this security score are searched from a database.

[0062] The database includes algorithms corresponding to different security scores, which may be national secret algorithms. For example, the target encryption algorithm may be the SM2 algorithm in the national secret algorithm, and the target summary extraction algorithm may be the SM3 algorithm in the national secret algorithm.

[0063] It should be noted that the determination of the network environment security score based on the network status information can be determined by the data sending end, or by the data receiving end after the determination is made and the result is sent to the data sending end.

[0064] After the target encryption algorithm is determined, the encryption key parameters in the target encryption algorithm are fixed. To increase the flexibility of the encryption process, new encryption key parameters can also be generated based on the security score of the network environment.

[0065] In one embodiment, the encryption key parameters in the target encryption algorithm are generated based on the security score of the network environment before data transmission; the complexity of the encryption key parameters is negatively correlated with the security score.

[0066] Among them, the encryption key parameters can be key length and key complexity. For example, the length of the encryption key can be 8, 10 or 16, and the key complexity can be simple letters, alphanumeric combination, alphanumeric special character combination, etc.

[0067] Different security scores correspond to different encryption keys. After obtaining the network environment's security score, the data sender can search the database for encryption key parameters corresponding to that security score. It should be noted that a higher security score indicates a more secure network environment and a lower probability of data tampering. In this case, the encryption key parameters can be shorter letter combinations. A lower security score indicates a less secure network environment and a higher probability of data tampering. In this case, the encryption key parameters can be longer alphanumeric and special character combinations.

[0068] After determining the target encryption algorithm and target digest extraction algorithm, the target encryption algorithm can be encapsulated as a first function and the target digest extraction algorithm as a second function to facilitate calls by the data sending end front-end. Before invoking the Ajax request, the front-end JavaScript code calls the first function to encrypt the data to be transmitted, generating an encrypted file. Simultaneously, the front-end JavaScript code calls the second function to extract a digest of the data to be transmitted, generating a digest file. The data sending end front-end can be configured as a visual interface.

[0069] It is understandable that the summary file includes not only the data summary, but also the timestamp of the data to be transmitted, the device information of the data sending end, the device information of the data receiving end, etc.

[0070] After receiving the encrypted and digest files, the data transmitter sends them to the data receiver. The receiver then receives the encrypted and digest files. Due to the varying sizes of the encrypted and digest files, the order in which they are received may vary.

[0071] S102: Output a prompt message based on the decryption analysis results of the encrypted file and the digest file; the prompt message is used to indicate whether the data has been tampered with during the transmission process.

[0072] In the embodiment of the present application, the data receiving end can decrypt the encrypted file layer by layer to obtain the key data information therein. At the same time, the decryption result of the digest file is analyzed in detail to check the integrity and consistency of the data.

[0073] After analyzing the decrypted encrypted and digest files, a prompt message is output based on the analysis results. If any signs of tampering are detected during data transmission, such as a data checksum mismatch or modification of key file information, a clear prompt message is output, indicating the location and type of possible data tampering. If no data tampering is detected, a prompt message clearly informs the user that the data has not been tampered with during transmission, ensuring data reliability and security.

[0074] It is understood that the data receiving end may also extract a digest of the decrypted data to determine a decrypted digest, and based on the decrypted digest and the received digest, determine the difference between the decrypted digest and the received digest.

[0075] In the data tamper-proofing method, an encrypted file and a digest file are received from a data transmitter. The encrypted file is generated by encrypting the data to be transmitted using a target encryption algorithm. The digest file is generated by extracting a digest of the data to be transmitted using a target digest extraction algorithm. Both the target encryption algorithm and the target digest extraction algorithm are dynamically determined based on the network environment before data transmission. A prompt message is output based on the decryption analysis results of the encrypted file and the digest file. The prompt message indicates whether the data transmission process has been tampered with. This method dynamically determines the target encryption algorithm and target digest algorithm suitable for the current network environment based on the network environment before data transmission. This method not only flexibly adapts to the needs of different network environments, but also quickly and accurately selects highly used algorithms, reducing unnecessary redundant operations and reducing the complexity of the computational process. Furthermore, by using the target encryption algorithm and the target digest extraction algorithm together, the encrypted file ensures the confidentiality of the data transmission, while the digest file verifies the data integrity. The two algorithms work together to form a dual verification mechanism that can more accurately detect tampering during data transmission, significantly improving data security.

[0076] After decrypting the encrypted file, the encryption parameters and encrypted data are obtained. Next, the process of determining the decryption analysis result of the transmitted data is introduced through an embodiment. Figure 3 As shown, the above method also includes:

[0077] S201, determining whether the encryption parameters in the encrypted file have a data encryption identifier.

[0078] Among them, the data encryption identifier is an annotation of a specific marking field reserved in the encryption parameter area of ​​the header of the encrypted file. The marking field follows a specific data format. For example, the data encryption identifier may include information such as the annotation type identifier, annotation version number, annotation content check code, etc.

[0079] In an embodiment of the present application, the data receiving end can parse the encrypted file and extract the tag field of the encryption parameter area. It can then identify whether the tag field contains annotation content. If so, the annotation content can be verified using a verification algorithm. For example, the verification algorithm can be a hash verification algorithm.

[0080] If the verification result shows that the annotation content is valid, it is determined that there is a data encryption identifier in the encryption parameter; if the verification result shows that the annotation content is not valid content, or the annotation content does not exist in the mark field, it is determined that there is no data encryption identifier in the encryption parameter.

[0081] S202: If it exists, determine the decryption analysis result of the transmission data based on the encrypted data in the digest file and the encrypted file.

[0082] In the embodiment of the present application, when it is determined that the encryption parameter contains a data encryption identifier, the first verification process of the transmitted data passes. Next, the transmitted data needs to be further verified based on the digest file and the encrypted data to determine whether there are any abnormalities in the data transmission process.

[0083] S203: If not, determine that the encryption parameter is not encrypted.

[0084] In an embodiment of the present application, when it is determined that there is no data encryption identifier in the encryption parameter, it means that the encryption parameter has not been encrypted before transmission.

[0085] In the above-mentioned data tamper-proofing method, it is determined whether the encryption parameters in the encrypted file have a data encryption identifier; if so, the decryption analysis results of the transmitted data are determined based on the encrypted data in the summary file and the encrypted file; if not, it is determined that the encryption parameters are not encrypted. This method constructs an efficient data security verification mechanism by determining whether the encryption parameters in the encrypted file have a data encryption identifier. The data encryption identifier serves as a key identifier for verifying the legitimacy of the encryption process. If the data encryption identifier exists, it means that the data has undergone a standardized encryption process at the sending end. The subsequent decryption analysis results are determined based on the summary file and the encrypted data, which can further verify the integrity of the data during transmission, effectively prevent the data from being illegally tampered with or forged, and greatly improve the security and credibility of data transmission. If the data encryption identifier does not exist, it is directly determined that the encryption parameters are not encrypted.

[0086] In one embodiment, Figure 4 As shown, the specific contents of the above-mentioned decryption analysis results of the transmission data determined based on the summary file and the encrypted data include:

[0087] S301, obtaining decrypted transmission data and a decryption key from encrypted data.

[0088] To ensure the security of data transmission, an asymmetric algorithm is used during the encryption process. Then, during the decryption process, the data receiving end can decrypt the encrypted data based on the private key corresponding to the public key of the encryption process to obtain the decrypted transmission data and the decryption key.

[0089] It should be noted that the encrypted data may be encrypted by mixing the key and the data. In one embodiment, during the decryption process, the encrypted data is decrypted, and the decrypted data and the key are separated to obtain the decrypted transmission data and the decryption key.

[0090] S302, determining whether the decryption key is consistent with the private key of the data to be transmitted.

[0091] In the embodiments of the present application, after obtaining the decryption key, the data receiving end can compare the decryption key with the private key of the data to be transmitted to determine whether the decryption key has been tampered with during the data transmission process. Generally, if the decryption key has not been tampered with, the decryption key and the private key need to remain consistent; if tampered with, there will be a certain difference between the two.

[0092] S303: If they are consistent, determining the decryption analysis result of the transmission data based on the decrypted transmission data and the digest file; if they are inconsistent, determining that the decryption analysis result of the transmission data indicates that there is a transmission anomaly.

[0093] In this embodiment of the present application, if the decryption key is determined to be identical to the private key of the data to be transmitted, the second verification of the transmitted data is complete. The data receiving end then further verifies the transmitted data based on the decrypted transmitted data and the digest file to determine whether there are any anomalies in the data transmission process.

[0094] If it is determined that there is a difference between the decryption key and the private key of the data to be transmitted, it means that the decryption key has been tampered with during the transmission process, and the decryption analysis result of the transmitted data is determined to be a transmission anomaly.

[0095] In the above-mentioned data tamper-proofing method, the decrypted transmission data and decryption key are obtained from the encrypted data; a determination is made as to whether the decryption key is consistent with the private key of the data to be transmitted; if they are consistent, the decryption analysis result of the transmission data is determined based on the decrypted transmission data and the digest file; if they are inconsistent, the decryption analysis result of the transmission data is determined to indicate a transmission anomaly. This method achieves accurate judgment of the data transmission status through key consistency judgment and analysis based on the decrypted transmission data and the digest file. When the keys are consistent, the decryption analysis result is determined based on the decrypted transmission data and the digest file. The digest file verifies the integrity of the data during transmission. The combination of the two can accurately detect whether the data has been tampered with, thereby improving the accuracy of the judgment of the data transmission status.

[0096] Next, the specific content of the abnormal identification result of the transmission data determined based on the decrypted transmission data and the summary file is introduced through an embodiment. Figure 5 As shown, the specific content includes:

[0097] S401, extracting a summary of the decrypted transmission data to generate a decryption summary file.

[0098] In an embodiment of the present application, in order to ensure the accuracy of subsequent digest comparison results, the data receiving end can use a target digest extraction algorithm to extract the digest of the decrypted transmission data to obtain a decrypted digest file corresponding to the decrypted transmission data.

[0099] S402: Compare the decrypted digest file with the digest file to obtain a comparison result.

[0100] In an embodiment of the present application, after obtaining the decrypted digest file, the data receiving end may compare the decrypted digest file with the digest file to determine whether the decrypted digest file and the digest file are completely consistent. The comparison result may include that the decrypted digest file and the digest file are completely consistent, or that there are differences between the decrypted digest file and the digest file.

[0101] S403: Determine the decryption analysis result of the transmission data based on the comparison result.

[0102] In the embodiment of the present application, when the comparison result shows that the contents of the decrypted summary file are completely consistent with those of the summary file, it is determined that the summary file has not been tampered with during the encrypted transmission process, and thus it can be inferred that the data has not been tampered with during the transmission process. Then, it can be determined that the decryption analysis result of the transmitted data is not abnormal.

[0103] When the comparison result shows that the decrypted summary file and the summary file have different contents, it is determined that the summary file has been tampered with during the encrypted transmission process, and thus it can be inferred that the data has been tampered with during the transmission process. Then, it can be determined that the decryption analysis result of the transmitted data is abnormal.

[0104] Assuming that the summary file includes device information, a timestamp of the data to be transmitted, and summary data, the specific content of determining the decryption analysis result of the transmitted data based on the comparison result will be described below through an embodiment. The specific content includes:

[0105] If the comparison result shows that the device information, timestamp, and summary data in the decrypted summary file and the summary file are identical, the decryption analysis result of the transmitted data is determined to be normal.

[0106] If the comparison result shows that any one of the device information, timestamp, and summary data in the decrypted summary file is different from that in the summary file, it is determined that the decryption analysis result of the transmitted data is abnormal.

[0107] In the above-mentioned data tamper-proofing method, a digest is extracted from the decrypted transmission data to generate a decrypted digest file; the decrypted digest file is compared with the digest file to obtain a comparison result; and based on the comparison result, the decryption analysis result of the transmission data is determined. This method extracts a digest from the decrypted transmission data to generate a decrypted digest file, and compares it with the original digest file. Based on the comparison result of the two digest files, it can accurately determine whether the data has been tampered with during transmission.

[0108] When it is determined that the data has been tampered with during transmission, the tampering type and optimization measures can be determined based on the decrypted digest file and the received digest file. Figure 6 As shown, the method further includes:

[0109] S501: Input the decrypted digest file and the received digest file into a preset tampering identification model, analyze the difference position and difference type between the decrypted digest file and the received digest file, and determine the tampering type in the data transmission process.

[0110] Among them, the tampering identification model can be a long short-term memory network (LSTM), a dynamic neural network (DNN), a recurrent neural network (RNN), or a convolutional neural network (CNN). The CNN network can be a residual (ResNet) series network, a CPN network, a dual propagation (SimpleBaseline) network, a Posefix network, a high-resolution network (HRNet), or a deep learning-based human pose estimation algorithm (HigherHRNet) network.

[0111] In an embodiment of the present application, taking the tampering identification model as an LSTM model as an example, the LSTM model can convert the decrypted summary file and the received summary file into a fixed-length feature vector sequence, and then use the bidirectional LSTM layer to simultaneously process the word vector sequences of the two summary files to capture the long-distance dependencies in the sequence. Then determine the positions with larger differences in the two sequences and assign higher weights to these positions. By comparing the hidden states of the two sequences at each time step, the model can output a difference score sequence. The difference score sequence is analyzed using a classifier to determine the type of tampering during data transmission.

[0112] S502: Determine an optimization strategy for data tampering based on the tampering type.

[0113] In the embodiment of the present application, different optimization strategies are used for different tampering types. If the tampering type is partial data missing, the optimization strategy for determining data tampering is to predict the missing data based on other data. If the tampering type is partial data error, the optimization strategy for determining data tampering is to predict the error data based on other data.

[0114] In the aforementioned data tamper prevention method, the decrypted digest file and the received digest file are input into a preset tamper identification model. The difference locations and difference types between the decrypted digest file and the received digest file are analyzed to determine the type of tampering during data transmission. Based on the tampering type, an optimization strategy for data tampering is determined. By leveraging the tamper identification model, this method can identify differences in the digest files, accurately locate the specific location of tampering during data transmission, and clearly identify the tampering type, thereby enabling the determination of a targeted optimization strategy.

[0115] In a detailed embodiment, Figure 7 As shown, the data tamper-proof method further includes:

[0116] S601, receiving an encrypted file and a digest file transmitted by a data sending end;

[0117] S602, determine whether the encryption parameters in the encrypted file have a data encryption identifier. If so, execute step S603; if not, execute step S608;

[0118] S603, decrypting the encrypted data and distinguishing the decrypted data from the key to obtain decrypted transmission data and a decryption key;

[0119] S604, determining whether the decryption key is consistent with the private key of the data to be transmitted, if they are consistent, executing step S605; if they are inconsistent, executing step S609;

[0120] S605, extracting a summary of the decrypted transmission data to generate a decryption summary file;

[0121] S606, comparing the decrypted digest file with the digest file to obtain a comparison result. If the comparison result shows that the two files are consistent, step S607 is executed; if the comparison result shows that the two files are inconsistent, step S609 is executed;

[0122] S607, determining that the decryption analysis result of the transmitted data is normal, that is, the transmitted data has not been tampered with;

[0123] S608, determining that the encryption parameter is not encrypted;

[0124] S609: Determine that the decryption analysis result of the transmitted data is abnormal, that is, the transmitted data has been tampered with, and execute step S610;

[0125] S610, inputting the decrypted digest file and the received digest file into a preset tampering identification model, analyzing the difference locations and difference types between the decrypted digest file and the received digest file, and determining the type of tampering in the data transmission process;

[0126] S611: Determine an optimization strategy for data tampering based on the tampering type.

[0127] Figure 8 This is a schematic diagram of a data tamper-proofing method. The front-end represents the data transmitter, and the back-end represents the data receiver. Before invoking an Ajax request, the front-end encrypts the parameter data (the data to be transmitted, as described above) using the SM2 algorithm (target encryption algorithm) to produce encrypted data. Furthermore, the SM3 algorithm (target digest extraction algorithm) extracts a digest from the parameter data to produce a data digest. Both the encrypted data and the data digest are then sent to the back-end (data receiver). The data receiver checks whether the encrypted data contains a custom annotation (the data encryption identifier, as described above). If not, the encrypted parameters are considered unencrypted. If so, the receiver determines whether the decryption key matches the private key. If not, the data is determined to have been tampered with during transmission. If they match, the SM3 algorithm is used to extract the recovered digest from the decrypted data (the decryption digest file, as described above) and determine whether the recovered digest matches the received data digest. If so, the data is transmitted normally. If not, the data is determined to have been tampered with during transmission.

[0128] In one embodiment, taking the execution subject as the data sending end as an example for explanation, the data tamper-proof method includes: obtaining the network environment before data transmission; analyzing the network environment to obtain a security score of the network environment; based on the security score, screening out a target encryption algorithm and a target summary extraction algorithm suitable for the network environment from the national encryption algorithm; based on the security score, adjusting the encryption key parameters in the target encryption algorithm; using the adjusted target encryption algorithm to encrypt the data to be transmitted to obtain an encrypted file, and using the target summary extraction algorithm to extract the summary of the data to be transmitted to obtain a summary file; and sending the encrypted file and the summary file to the data receiving end.

[0129] It should be understood that, although the steps in the flowcharts of the above embodiments are shown in sequence as indicated by the arrows, these steps are not necessarily performed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be performed in other orders. Moreover, at least a portion of the steps in the flowcharts of the above embodiments may include multiple steps or multiple stages, and these steps or stages are not necessarily performed at the same time, but can be performed at different times. The execution order of these steps or stages is not necessarily to be performed in sequence, but can be performed in turn or alternately with other steps or at least a portion of steps or stages in other steps.

[0130] Based on the same inventive concept, the embodiments of the present application also provide a data tamper-proofing device for implementing the aforementioned data tamper-proofing method. The implementation solution provided by the device is similar to the implementation solution described in the aforementioned method. Therefore, the specific limitations of one or more data tamper-proofing device embodiments provided below can be found in the above-mentioned limitations of the data tamper-proofing method and will not be repeated here.

[0131] In an exemplary embodiment, Figure 9 As shown, a data tamper-proof device is provided, comprising: a receiving module 11 and an output module 12, wherein:

[0132] The receiving module 11 is used to receive the encrypted file and the digest file transmitted by the data sending end; the encrypted file is obtained by the data sending end encrypting the data to be transmitted using the target encryption algorithm; the digest file is generated by the data sending end using the target digest extraction algorithm to extract the digest of the data to be transmitted; the target encryption algorithm and the target digest extraction algorithm are both dynamically determined based on the network environment before the data is transmitted;

[0133] Among them, the target encryption algorithm and target summary extraction algorithm are based on the security score of the network environment before data transmission, and the algorithms suitable for the network environment are selected from the national encryption algorithms;

[0134] The encryption key parameters in the target encryption algorithm are generated based on the security score of the network environment before data transmission; the complexity of the encryption key parameters is negatively correlated with the security score;

[0135] The output module 12 is used to output a prompt message based on the decryption analysis results of the encrypted file and the digest file; the prompt message is used to indicate whether the data has been tampered with during the transmission process.

[0136] In an exemplary embodiment, the data tamper-proof device further includes: a judgment module, a first determination module, and a second determination module, wherein:

[0137] A judgment module, used to judge whether the encryption parameters in the encrypted file have a data encryption identifier;

[0138] A first determination module is used to determine a decryption analysis result of the transmission data based on the digest file and the encrypted data when there is a data encryption identifier;

[0139] The second determining module is configured to determine that the encryption parameter is not encrypted when the data encryption identifier does not exist.

[0140] In an exemplary embodiment, the first determining module includes: an acquiring unit, a judging unit, and a determining unit, wherein:

[0141] An acquisition unit, configured to acquire decrypted transmission data and a decryption key from the encrypted data;

[0142] a judgment unit, configured to judge whether the decryption key is consistent with the private key of the data to be transmitted;

[0143] The determination unit is configured to determine the decryption analysis result of the transmission data based on the decrypted transmission data and the summary file if the decrypted transmission data and the summary file are consistent; and to determine that the decryption analysis result of the transmission data indicates that there is a transmission anomaly if the decrypted transmission data and the summary file are inconsistent.

[0144] In an exemplary embodiment, the acquisition unit is further configured to decrypt the encrypted data and distinguish the decrypted data from the key to obtain the decrypted transmission data and the decryption key.

[0145] In an exemplary embodiment, the determination unit is further configured to extract a summary of the decrypted transmission data to generate a decryption summary file; compare the decryption summary file with the summary file to obtain a comparison result; and determine a decryption analysis result of the transmission data based on the comparison result.

[0146] In an exemplary embodiment, the above-mentioned determination unit is further used to determine that the decryption analysis result of the transmission data is normal when the comparison result shows that the device information, timestamp and summary data in the decrypted summary file are the same as those in the summary file; and to determine that the decryption analysis result of the transmission data is abnormal when the comparison result shows that any one of the device information, timestamp and summary data in the decrypted summary file is different from that in the summary file.

[0147] In an exemplary embodiment, the data tamper-proof device further includes: an identification module and a third determination module, wherein:

[0148] an identification module, configured to input the decrypted summary file and the received summary file into a preset tampering identification model, analyze the difference locations and difference types between the decrypted summary file and the received summary file, and determine the type of tampering during the data transmission process;

[0149] The third determination module is used to determine the optimization strategy for data tampering based on the tampering type.

[0150] Each module in the aforementioned data tamper-proof device can be implemented in whole or in part through software, hardware, or a combination thereof. Each module can be embedded in or independent of a processor in a computer device in the form of hardware, or can be stored in a memory in the computer device in the form of software, so that the processor can call and execute the corresponding operations of each module.

[0151] In an exemplary embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as shown in FIG. Figure 10 As shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O) and a communication interface. The processor, memory and input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The database of the computer device is used to store data tamper-proof data. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, a data tamper-proof method is implemented.

[0152] Those skilled in the art will understand that Figure 10 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.

[0153] In an exemplary embodiment, a computer device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and when the processor executes the computer program, the content of any one embodiment of the above-mentioned data tamper-proofing method is implemented.

[0154] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the content of any embodiment of the above-mentioned data tamper-proofing method is implemented.

[0155] In one embodiment, a computer program product is provided, comprising a computer program, which implements the content of any one embodiment of the above-mentioned data tamper-proofing method when executed by a processor.

[0156] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant regulations.

[0157] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the above-mentioned embodiments. In particular, any reference to a memory, database, or other medium used in the embodiments provided in this application can include at least one of a non-volatile memory and a volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The databases involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the various embodiments provided herein may be, but are not limited to, general-purpose processors, central processing units (CPUs), graphics processing units (GPUs), digital signal processors (DSPs), programmable logic devices (PLDs), quantum computing-based data processing logic devices, artificial intelligence (AI) processors, and the like.

[0158] The technical features of the above embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.

[0159] The above embodiments merely illustrate several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that a person skilled in the art may make various modifications and improvements without departing from the spirit of the present invention, all of which fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.

Claims

1. A data tamper-proof method, characterized in that: The method comprises: receiving an encrypted file and a digest file transmitted by a data sending end; the encrypted file is obtained by the data sending end encrypting the data to be transmitted using a target encryption algorithm; the digest file is generated by the data sending end extracting a digest of the data to be transmitted using a target digest extraction algorithm; the target encryption algorithm and the target digest extraction algorithm are both dynamically determined based on the network environment before data transmission; Based on the decryption analysis results of the encrypted file and the digest file, a prompt message is output; the prompt message is used to indicate whether the data transmission process has been tampered with.

2. The method according to claim 1, characterized in that The target encryption algorithm and the target summary extraction algorithm are based on the security score of the network environment before the data transmission, and the algorithms suitable for the network environment are screened out from the national encryption algorithms.

3. The method according to claim 2, characterized in that The encryption key parameters in the target encryption algorithm are generated based on a security score of the network environment before the data transmission; and the complexity of the encryption key parameters is negatively correlated with the security score.

4. The method according to any one of claims 1 to 3, characterized in that The method further comprises: Determining whether a data encryption identifier exists in the encryption parameters in the encrypted file; If so, determining a decryption analysis result of the transmission data based on the digest file and the encrypted data in the encrypted file; If not present, it is determined that the encryption parameter is not encrypted.

5. The method according to claim 4, characterized in that The step of determining a decryption analysis result of the transmission data based on the digest file and the encrypted data includes: Obtaining decrypted transmission data and a decryption key from the encrypted data; Determining whether the decryption key is consistent with the private key of the data to be transmitted; If they are consistent, a decryption analysis result of the transmission data is determined based on the decrypted transmission data and the digest file; if they are inconsistent, it is determined that the decryption analysis result of the transmission data is that there is a transmission anomaly.

6. The method according to claim 5, characterized in that The obtaining of the decrypted transmission data and the decryption key in the encrypted data includes: The encrypted data is decrypted, and the decrypted data and the key are distinguished to obtain decrypted transmission data and a decryption key.

7. The method according to claim 5, characterized in that The determining, based on the decrypted transmission data and the digest file, an abnormality identification result of the transmission data includes: Extracting a summary of the decrypted transmission data to generate a decryption summary file; Comparing the decrypted summary file with the summary file to obtain a comparison result; Based on the comparison result, a decryption analysis result of the transmission data is determined.

8. The method according to claim 7, characterized in that The summary file includes device information, a timestamp of the data to be transmitted, and summary data; Determining a decryption analysis result of the transmission data based on the comparison result includes: If the comparison result shows that the device information, timestamp, and summary data in the decrypted summary file are identical to those in the summary file, it is determined that the decryption analysis result of the transmitted data is normal; If the comparison result shows that any one of the device information, the timestamp, and the summary data in the decrypted summary file is different from that in the summary file, it is determined that the decryption analysis result of the transmission data is abnormal.

9. The method according to any one of claims 1 to 3, characterized in that The method further comprises: Inputting the decrypted summary file and the received summary file into a preset tampering identification model, analyzing the difference position and difference type between the decrypted summary file and the received summary file, and determining the tampering type in the data transmission process; Based on the tampering type, an optimization strategy for data tampering is determined.

10. A data tamper-proof device, characterized in that: The device comprises: a receiving module configured to receive an encrypted file and a digest file transmitted by a data transmitting end; the encrypted file is generated by the data transmitting end encrypting the data to be transmitted using a target encryption algorithm; the digest file is generated by the data transmitting end extracting a digest of the data to be transmitted using a target digest extraction algorithm; both the target encryption algorithm and the target digest extraction algorithm are dynamically determined based on the network environment before data transmission; The output module is used to output a prompt message based on the decryption analysis results of the encrypted file and the digest file; the prompt message is used to indicate whether the data has been tampered with during the transmission process.