Information encryption processing method and device, equipment, medium and program product

By generating key streams and using encrypted authentication tags, the problem of existing encryption methods being easily cracked is solved, achieving highly secure storage of user information.

CN120934793APending Publication Date: 2025-11-11CHINA MOBILE (XIONGAN) ICT CO LTD +3
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511022967.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-24
Publication Date
2025-11-11

AI Technical Summary

Technical Problem

Existing encryption methods are easily cracked, resulting in low security for stored user information. Attackers can obtain keys and decrypt data through known public encryption algorithms.

Method used

By obtaining user registration information, a key stream is generated based on the initial encryption parameters and encryption key for encryption calculation to obtain ciphertext information. Based on the ciphertext information and authentication key, an encrypted authentication tag is generated and stored in a preset address to ensure information security.

Benefits of technology

It enhances the confidentiality of the key and the security of the encryption process, ensuring the confidentiality, integrity, and authenticity of information, and improving the security of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120934793A_ABST
    Figure CN120934793A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides an information encryption processing method and device, equipment, a medium and a program product, and the method comprises the steps: carrying out the Hash calculation of the obtained user registration information in an information encryption process, obtaining a Hash value, extracting an encryption key and an authentication key from the Hash value, and performing encryption calculation on the user registration information according to a key stream generated based on the initial encryption parameter and the encryption key to obtain ciphertext information, performing encryption calculation based on the ciphertext information and the authentication key to obtain an encryption authentication tag, and storing the ciphertext information and the encryption authentication tag in a preset storage address. And the storage security of the user registration information is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This document relates to the field of data processing technology, and in particular to an information encryption processing method, apparatus, equipment, medium, and program product. Background Technology

[0002] In the field of data storage security, the usual method of data storage is to encrypt the data to be stored using an encryption algorithm to obtain ciphertext data, and then store the ciphertext data. However, current encryption methods are very easy to crack by writing attack programs based on known public encryption algorithms, or to intercept a piece of ciphertext data and brute-force it to obtain the key, and then decrypt and copy the stored ciphertext data, which makes the storage security low and thus causes losses to users. Therefore, how to ensure that attackers cannot obtain any valid or user-specific information even if the data hardware is compromised, thereby improving the security of user data, has become a concern for all parties. Summary of the Invention

[0003] The purpose of one embodiment of this specification is to provide an information encryption processing method, apparatus, device, medium, and program product to solve the problem of low security when storing user registration information.

[0004] To solve the above-mentioned technical problems, one embodiment of this specification is implemented as follows: Firstly, one embodiment of this specification provides an information encryption processing method, the method comprising: Obtain user registration information; The user registration information is encrypted using a key stream generated based on the initial encryption parameters and encryption key to obtain ciphertext information. An encrypted authentication tag is obtained by performing encryption calculations based on the encrypted information and the authentication key; the authentication key and the encryption key are extracted from the hash value obtained by hashing the user registration information. The encrypted information and the encrypted authentication tag are stored in a preset storage address.

[0005] Secondly, one embodiment of this specification provides a login verification processing method, the method comprising: Retrieve the login request containing user login information; The user login information is encrypted using a key stream generated based on the initial encryption parameters and encryption key to obtain ciphertext information. An encrypted authentication tag is obtained by performing encryption calculations based on the encrypted information and the authentication key; the authentication key and the encryption key are generated based on the hash value obtained by hashing the user login information. The encrypted information and the authentication tag are compared with the encrypted information and authentication tag stored in the preset storage address; If the comparison results are consistent, the user login verification is confirmed and a login success result is returned.

[0006] Thirdly, another embodiment of this specification provides an information encryption processing apparatus, comprising: The information acquisition module is used to acquire user registration information; The information encryption calculation module is used to perform encryption calculations on the user registration information based on the key stream generated based on the initial encryption parameters and the encryption key to obtain ciphertext information; The key encryption calculation module is used to perform encryption calculations based on the ciphertext information and the authentication key to obtain an encrypted authentication tag; the authentication key and the encryption key are extracted from the hash value obtained by hashing the user registration information. The storage module is used to store the encrypted information and the encrypted authentication tag in a preset storage address.

[0007] Fourthly, another embodiment of this specification provides a login verification processing apparatus, including: The request retrieval module is used to retrieve login requests containing user login information. The information encryption calculation module is used to perform encryption calculations on the user login information based on the key stream generated based on the initial encryption parameters and the encryption key to obtain ciphertext information; The key encryption calculation module is used to perform encryption calculations based on the ciphertext information and the authentication key to obtain an encrypted authentication tag; the authentication key and the encryption key are generated based on the hash value obtained by hashing the user login information. The comparison module is used to compare the encrypted information and the authentication tag with the encrypted information and authentication tag stored in the preset storage address; If the comparison results are consistent, the result return module is executed. The result return module is used to determine that the user login verification has passed and return a login success result.

[0008] Fifthly, another embodiment of this specification provides an information encryption processing device, including: a memory, a processor, and computer-executable instructions stored in the memory and executable on the processor, wherein the computer-executable instructions, when executed by the processor, implement the steps of the information encryption processing method as described in the first aspect above.

[0009] In a sixth aspect, another embodiment of this specification provides a login verification processing device, including: a memory, a processor, and computer-executable instructions stored in the memory and executable on the processor, wherein the computer-executable instructions, when executed by the processor, implement the steps of the login verification processing method as described in the second aspect above.

[0010] In a seventh aspect, this specification provides a computer-readable storage medium in another embodiment for storing computer-executable instructions that, when executed by a processor, implement the steps of the information encryption processing method described in the first aspect above.

[0011] Eighthly, in another embodiment of this specification, a computer-readable storage medium is provided for storing computer-executable instructions that, when executed by a processor, implement the steps of the login verification processing method as described in the second aspect above.

[0012] In a ninth aspect, this specification provides a computer program product in another embodiment, the computer program product including an information encryption processing program, which, when executed by a processor, implements the steps of the information encryption processing method as described in the first aspect above.

[0013] In a tenth aspect, this specification provides a computer program product in another embodiment, the computer program product including a login verification processing program, which, when executed by a processor, implements the steps of the login verification processing method as described in the second aspect above.

[0014] The information encryption processing method provided in this embodiment first obtains user registration information, then performs hash calculation on the obtained user registration information to obtain a hash value, extracts an encryption key and an authentication key from the hash value, thereby improving the confidentiality of the key, performs encryption calculation on the user registration information based on the key stream generated based on the initial encryption parameters and the encryption key to obtain ciphertext information, thereby enhancing the security of the encryption process and improving encryption efficiency, then performs encryption calculation based on the ciphertext information and the authentication key to obtain an encrypted authentication tag, which is used to verify the authenticity and integrity of the information, and finally stores the ciphertext information and the encrypted authentication tag in a preset storage address, providing strong support for subsequent information management and security audit. Attached Figure Description

[0015] To more clearly illustrate the technical solutions in one or more embodiments or prior art of this specification, the drawings used in the description of the embodiments or prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. Figure 1 A flowchart illustrating an information encryption processing method provided in one or more embodiments of this specification; Figure 2 A flowchart illustrating an information encryption processing method for user information encryption scenarios, provided in one or more embodiments of this specification; Figure 3 A flowchart illustrating a login verification process provided in one or more embodiments of this specification; Figure 4 A schematic diagram of an information encryption processing device provided for one or more embodiments of this specification; Figure 5 A schematic diagram of a login verification processing device provided in one or more embodiments of this specification; Figure 6 A schematic diagram of the structure of an information encryption processing device provided in one or more embodiments of this specification; Figure 7 This is a schematic diagram of the structure of a login verification processing device provided for one or more embodiments of this specification. Detailed Implementation

[0016] To enable those skilled in the art to better understand the technical solutions in one or more embodiments of this specification, the technical solutions in one or more embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this specification, and not all of the embodiments. Based on one or more embodiments of this specification, all other embodiments obtained by those skilled in the art without creative effort should fall within the protection scope of this document.

[0017] This specification provides an example of an information encryption processing method: Reference Figure 1 It shows a flowchart of an information encryption processing method provided in this embodiment, with reference to... Figure 2 This embodiment illustrates a flowchart of an information encryption processing method applied to a user information encryption scenario.

[0018] Reference Figure 1The information encryption processing method provided in this embodiment specifically includes the following steps S102 to S108.

[0019] Step S102: Obtain user registration information.

[0020] In this embodiment, the user registration information refers to the identity information related to the user's identity submitted during the user registration process, or it may also be the verification information submitted during the user registration process to verify the user's identity. The user registration information can be collected through applications or mini-programs installed on the user's terminal, or it can be collected through an API (Application Programming Interface) configured in the user's terminal. After the user's terminal collects the user registration information, it sends a registration request carrying the user registration information to the server. Correspondingly, the server receives the user's registration request and obtains the user registration information carried within it. For example, the user submits registration information containing their ID number, name, gender, and / or verification password through an application installed on their terminal. It should be noted that during the transmission of user registration information, a specific data format (such as JSON or XML) can be used to transmit the user registration information to ensure data integrity and accuracy.

[0021] Furthermore, to ensure the legality of the input information, preliminary verification of the user registration information entered by the user can be performed through the user terminal or API interface, such as format verification and length limit.

[0022] Step S104: Perform encryption calculations on the user registration information based on the key stream generated based on the initial encryption parameters and encryption key to obtain ciphertext information.

[0023] After obtaining the user registration information as described above, in this step, the user registration information is encrypted using a keystream generated based on the initial encryption parameters and the encryption key to obtain ciphertext information. Optionally, the encryption key is extracted from the hash value obtained by hashing the user registration information.

[0024] In the specific execution process, after obtaining the user registration information, a hash value is obtained by hashing the user registration information. The encryption key and authentication key required for subsequent encryption calculations are then obtained based on the hash value. In one optional implementation of this embodiment, the hash value is obtained by hashing the user registration information in the following way: The user registration information is concatenated with each sub-information, and the resulting concatenated user information is hashed to obtain the hash value.

[0025] After obtaining user registration information, a hash value can be obtained by performing a hash calculation on the user registration information based on a hash algorithm. The hash algorithm can be the Blake hash algorithm, a highly parallel hash function that can quickly and securely generate fixed-length hash values. During the hash calculation process based on the Blake hash algorithm, a series of compression and mixing operations are performed on the input data, ultimately outputting a fixed-length hash value.

[0026] For example, a user's ID number, name, gender, and verification password can be concatenated into a string, and then a hash operation can be performed on this string to generate a fixed-length hash value. Specific delimiters can be used to distinguish different fields to ensure the accuracy of the hash operation.

[0027] Furthermore, after performing hash calculations on the user registration information to obtain a hash value, the encryption key and authentication key required for subsequent encryption calculations are obtained based on the hash value. In one optional implementation of this embodiment, the encryption key and authentication key are obtained in the following manner: Extract a first preset field from the hash value as the authentication key, and extract a second preset field as the encryption key.

[0028] Specifically, after completing the hash calculation, the server extracts two parts of data from the generated hash value. One part is used as an encryption key for the subsequent encryption process. The length and complexity of the encryption key should be high enough to ensure the security of the encryption. The other part is used as an authentication key to generate an encrypted authentication tag. The authentication key also needs to have sufficient security to prevent unauthorized access and modification.

[0029] The authentication key can be a Hash-based Message Authentication Code (HMAC) key, and the encrypted authentication label can be a Hash-based Message Authentication Code (HMAC) label, which is a fixed-length binary string used to verify the integrity and authentication of the message.

[0030] In the specific execution process, after obtaining the encryption key, the user registration information can be encrypted using the Output Feedback (OFB) encryption algorithm to obtain ciphertext information. Specifically, in the process of encrypting the user registration information using the Output Feedback encryption algorithm, initial encryption parameters must first be generated. Then, a keystream is generated based on the initial encryption parameters and the encryption key. The ciphertext information is then obtained by encrypting the user registration information using the keystream.

[0031] The generated initial encryption parameters can be a random initialization vector (IV), and the length of the initialization vector can be a preset length. For example, the length of the IV can be 128 bits. The purpose of the IV is to provide an initial, random input value for the encryption process, increasing the randomness and security of the encryption.

[0032] Furthermore, after generating the initial encryption parameters, a key stream is generated based on the initial encryption parameters and the encryption key. Specifically, the user registration information can be split to obtain group information, and the initial encryption parameters can be encrypted based on the encryption key to obtain the key stream.

[0033] It should be noted that the first subkey in the key stream can be generated as follows: the initialization vector (IV) is encrypted based on the encryption key to obtain the first subkey. The second subkey in the key stream can be generated as follows: the initialization vector (IV) is encrypted based on the first subkey to obtain the second subkey, and so on. All other subkeys in the key stream are obtained by encrypting the initialization vector (IV) with the obtained previous subkey.

[0034] In the specific execution process, after obtaining the key stream, the user registration information can be encrypted using the key stream to obtain ciphertext information. In one optional implementation of this embodiment, the user registration information is encrypted using the key stream generated based on the initial encryption parameters and the encryption key to obtain ciphertext information. The user registration information is split to obtain grouping information; The initial encryption parameters are encrypted using the encryption key to obtain the key stream; The ciphertext information is obtained by encrypting the group information according to the key stream.

[0035] Specifically, during the encryption process, the user registration information is first divided into fixed-length data blocks, and then an encryption operation is performed on each data block. Specifically, the data block is XORed with its corresponding keystream to obtain the ciphertext data block. During this process, the state of the encryption algorithm remains unchanged, thus allowing multiple data blocks to be processed in parallel, improving encryption efficiency.

[0036] For example, the first data block is XORed with the first subkey in the key stream to obtain the first ciphertext information, the second data block is XORed with the second subkey in the key stream to obtain the second ciphertext information, and the first and second ciphertext information are concatenated to obtain the ciphertext information.

[0037] In practical applications, during the encryption calculation of the user registration information, the information length of the user registration information may be insufficient. In this case, the grouped information obtained after grouping the user registration information cannot correspond one-to-one with the subkeys in the keystream. To address this, it is necessary to pad the user registration information to complete the encryption. In an optional implementation provided in this embodiment, before the step of splitting the user registration information to obtain the grouped information is executed, the following steps are also included: Detect whether the length of the user registration information has reached the preset length; If so, perform the step of splitting the user registration information to obtain grouping information; If not, populate the user registration information and then perform splitting processing based on the obtained populated information.

[0038] It should be noted that, to further enhance encryption security, a random code can be generated and used in conjunction with the encryption key to perform encrypted calculations on the user registration information, or the random code can be used in conjunction with a keystream to perform encrypted calculations on the user registration information. Specifically, the random code can be concatenated with the encryption key, and a keystream can be generated based on the concatenation result and initial encryption parameters. The user registration information can then be encrypted using the keystream to obtain ciphertext information. Alternatively, the random code can be concatenated with the keystream, and the ciphertext information can be obtained based on the concatenation result. Here, the random code is a randomly generated numerical value or string, and its length and complexity can be adjusted according to the system's security requirements to increase the complexity and security of the encryption.

[0039] Step S106: Perform encryption calculations based on the ciphertext information and authentication key to obtain an encrypted authentication tag.

[0040] After the aforementioned encryption calculation of user registration information based on the keystream generated from the initial encryption parameters and encryption key to obtain ciphertext information, this step performs encryption calculation based on the ciphertext information and the authentication key to obtain an encrypted authentication tag. Optionally, the authentication key is extracted from the hash value obtained by hashing the user registration information.

[0041] In practice, the authentication key and ciphertext information can be used as inputs to generate a fixed-length encrypted authentication tag through an encryption function. The encryption function can be an HMAC algorithm and / or a hash function; commonly used encryption functions include HMAC-SHA1 and HMAC-SHA256.

[0042] In one optional implementation of this embodiment, the encrypted authentication tag is obtained by performing encryption calculations based on the ciphertext information and the authentication key in the following manner: The encrypted information and the authentication key are concatenated to obtain concatenated encrypted information; The concatenated ciphertext information is input into a hash function for encryption calculation to obtain the encrypted authentication tag.

[0043] Specifically, in the process of encryption calculation based on the encryption function, the authentication key and ciphertext information can be concatenated together as input. The concatenation process can involve combining the key and ciphertext into a long byte sequence according to a specific format or order. The concatenation method can be by adding a separator between the authentication key and ciphertext information, or by arranging them according to a specific byte order. Then, a hash function is used to perform a hash operation on the concatenated byte sequence to obtain a hash value. This hash value is a digest of the input data and has high collision resistance, meaning that different input data are almost impossible to produce the same hash value. Here, the calculated hash value is used as the encryption authentication label.

[0044] It should be noted that after calculating and obtaining the encrypted authentication tag, the generated tag can be saved to a database or other appropriate storage location and associated with the ciphertext information. Simultaneously, the encrypted authentication tag can also be returned to the user terminal or its configured API interface for use in subsequent message verification or authentication processes. Here, the generated encrypted authentication tag associated with the ciphertext ensures message integrity and authentication. The generation of the encrypted authentication tag increases data security, enabling the detection and prevention of unauthorized modifications.

[0045] Step S108: Store the encrypted information and the encrypted authentication tag in a preset storage address.

[0046] After obtaining the encrypted authentication tag through encrypted calculations based on the encrypted information and authentication key, this step involves storing the encrypted information and the encrypted authentication tag at a preset storage address. The preset storage address can be a hardware storage address, such as a hard drive or SSD; alternatively, it can be a cloud storage address, such as a cloud storage URL. Specifically, the encrypted information and authentication key can be stored using file storage or database storage methods.

[0047] During the specific execution process, after obtaining the encrypted information and the encrypted authentication tag, the encrypted information and the encrypted authentication tag are stored in a preset storage address. In addition, the log information of the storage operation can be recorded. The log information can include the storage time (recording the exact timestamp of the operation), the storage address (indicating the specific location where the data is saved), the operator (the user or system identity that performed the storage operation), etc., so as to track the flow of data, detect potential security issues, and troubleshoot when necessary.

[0048] It should be noted that before storing the encrypted information and the encrypted authentication label, the encrypted information and the encrypted authentication label can be serialized. Specifically, serialization is the process of converting a data structure or object state into a format that can be stored or transmitted. For the encrypted information and the encrypted authentication label, they can be converted into binary or string format for storage. The specific serialization method can be selected according to the storage method and programming language used. Correspondingly, step S104 can also be replaced by: performing serialization processing on the encrypted information and the encrypted authentication label, and storing the serialization result at a preset storage address.

[0049] Furthermore, to enhance security, after storing the encrypted information and the encrypted authentication tag at a preset storage address, the success of the storage operation can be verified. Specifically, this can be achieved by checking whether the data in the storage address is complete and correct, and whether the log information has been correctly recorded. If the storage operation fails or the data is abnormal, appropriate measures can be taken promptly, such as re-executing the storage operation or reporting the error.

[0050] Here, after storing the encrypted information and encrypted authentication tag in the preset storage address, it can be determined that the encryption and storage of user information is complete. A registration success response can be returned to the user terminal or the API interface configured on the user terminal. Correspondingly, after receiving the response, the user terminal displays the registration success information to the user so that the user can perform subsequent login or other operations.

[0051] It should be noted that the information encryption processing method provided in this embodiment also includes the process of generating a unique user identification code. Specifically, the server can generate a user identification code based on the current timestamp, user ID, or other unique identifier. This user identification code is unique within the system and has a certain degree of randomness to prevent guessing or brute-force attacks. The two can be concatenated, hashed, or otherwise transformed to generate the user identification code. The timestamp can be a number representing a specific time, typically the number of seconds or milliseconds from a fixed point in time. Obtaining the timestamp ensures the uniqueness of the generated identifier over time, reducing the risk of generating duplicate identifiers. The user ID can be a unique identifier assigned by the system during user registration, ensuring each user has a unique identifier. If other available unique identifiers exist in the system, such as phone numbers or email addresses, they can also be used as a reference for generating the unique identifier.

[0052] In addition, the generated identification code can be stored in a database or other appropriate storage location, and the identification code can be returned to the user terminal for use in subsequent user authentication, authorization or data association scenarios.

[0053] In summary, the one or more information encryption processing methods provided in this embodiment first obtain user registration information, then perform hash calculation on the obtained user registration information to obtain a hash value, extract an encryption key and an authentication key from the hash value to improve the confidentiality of the keys, perform encryption calculation on the user registration information based on the key stream generated based on the initial encryption parameters and the encryption key to obtain ciphertext information, enhance the security of the encryption process and improve encryption efficiency, then perform encryption calculation based on the ciphertext information and the authentication key to obtain an encrypted authentication tag for verifying the authenticity and integrity of the information, and finally store the ciphertext information and the encrypted authentication tag in a preset storage address to ensure the confidentiality, integrity and authenticity of the user registration information, improve the security of the system, and provide strong support for subsequent information management and security auditing.

[0054] The following combination Figure 2 Taking the application of the information encryption processing method provided in this embodiment in a user information encryption scenario as an example, the information encryption processing method provided in this embodiment will be further explained. (Refer to...) Figure 2 The information encryption processing method applied to user information encryption scenarios specifically includes steps S202 to S214.

[0055] Step S202: Obtain a registration request carrying user registration information.

[0056] Step S204: Concatenate the sub-information contained in the user registration information, and perform hash calculation on the obtained concatenated user information to obtain a hash value.

[0057] Optional, the sub-information includes: ID number, name, gender and / or verification password.

[0058] Step S206: Extract the first preset field from the hash value as the authentication key, and extract the second preset field as the encryption key.

[0059] Step S208: The user registration information is split to obtain group information.

[0060] Step S210: Encrypt the initial encryption parameters based on the encryption key to obtain the key stream.

[0061] Step S212: Encrypt the block information according to the key stream to obtain ciphertext information.

[0062] Step S214: Perform encryption calculations based on the ciphertext information and authentication key to obtain an encrypted authentication tag.

[0063] Step S216: Store the encrypted information and the encrypted authentication tag in a preset storage address, and return the registration result to the user.

[0064] It should be noted that any one or more of steps S202 to S216 can be combined to form a new implementation method according to the needs of implementation and deployment. Furthermore, any one or more technical features in the technical solution composed of steps S202 to S216 can also be combined to form a new implementation method according to the actual deployment needs, or the technical features of one or more optional implementations provided in steps S102 to S108 can be combined to form a new implementation method. These will not be elaborated on here.

[0065] This specification provides an example of an information encryption processing method: Reference Figure 3 The diagram illustrates a login verification process provided in this embodiment.

[0066] Reference Figure 3 The login verification processing method provided in this embodiment specifically includes the following steps S302 to S310.

[0067] Step S302: Obtain a login request containing user login information.

[0068] The user login information mentioned in this embodiment refers to the relevant information used for user login. The user login information may be a username and / or password.

[0069] Step S304: The user login information is encrypted using a key stream generated based on the initial encryption parameters and encryption key to obtain ciphertext information.

[0070] After obtaining the login request containing user login information as described above, in this step, the user login information is encrypted using a keystream generated based on the initial encryption parameters and encryption key to obtain ciphertext information. Optionally, the encryption key is extracted from the hash value obtained by hashing the user login information.

[0071] In the specific execution process, after obtaining the user login information, a hash value is obtained by hashing the user login information. The encryption key and authentication key required for subsequent encryption calculations are then obtained based on the hash value. In one optional implementation of this embodiment, the hash value is obtained by hashing the user login information in the following way: The user login information is concatenated with each sub-information, and the resulting concatenated user information is hashed to obtain the hash value.

[0072] After obtaining user login information, a hash value can be obtained by performing a hash calculation on the user login information based on a hash algorithm. The hash algorithm can be the Blake hash algorithm, a highly parallel hash function that can quickly and securely generate fixed-length hash values. During the hash calculation process based on the Blake hash algorithm, a series of compression and mixing operations are performed on the input data, ultimately outputting a fixed-length hash value.

[0073] For example, the user's username and verification password can be concatenated into a string, and then a hash operation can be performed on that string to generate a fixed-length hash value. Specific delimiters can be used to distinguish different fields to ensure the accuracy of the hash operation.

[0074] Furthermore, after hashing the user login information to obtain a hash value, the encryption key and authentication key required for subsequent encryption calculations are obtained based on the hash value. In one optional implementation of this embodiment, the encryption key and authentication key are obtained in the following manner: Extract a first preset field from the hash value as the authentication key, and extract a second preset field as the encryption key.

[0075] Specifically, after completing the hash calculation, the server extracts two parts of data from the generated hash value. One part is used as an encryption key for the subsequent encryption process. The length and complexity of the encryption key should be high enough to ensure the security of the encryption. The other part is used as an authentication key to generate an encrypted authentication tag. The authentication key also needs to have sufficient security to prevent unauthorized access and modification.

[0076] The authentication key can be a Hash-based Message Authentication Code (HMAC) key, and the encrypted authentication label can be a Hash-based Message Authentication Code (HMAC) label, which is a fixed-length binary string used to verify the integrity and authentication of the message.

[0077] In the specific execution process, after obtaining the encryption key, the user login information can be encrypted using the Output Feedback (OFB) encryption algorithm to obtain ciphertext information. Specifically, in the process of encrypting the user login information using the Output Feedback encryption algorithm, initial encryption parameters must first be generated. Then, a keystream is generated based on the initial encryption parameters and the encryption key. The ciphertext information is then obtained by encrypting the user login information using the keystream.

[0078] The generated initial encryption parameters can be a random initialization vector (IV), and the length of the initialization vector can be a preset length. For example, the length of the IV can be 128 bits. The purpose of the IV is to provide an initial, random input value for the encryption process, increasing the randomness and security of the encryption.

[0079] Furthermore, after generating the initial encryption parameters, a key stream is generated based on the initial encryption parameters and the encryption key. Specifically, the user login information can be split to obtain group information, and the initial encryption parameters can be encrypted based on the encryption key to obtain the key stream.

[0080] It should be noted that the first subkey in the key stream can be generated as follows: the initialization vector (IV) is encrypted based on the encryption key to obtain the first subkey. The second subkey in the key stream can be generated as follows: the initialization vector (IV) is encrypted based on the first subkey to obtain the second subkey, and so on. All other subkeys in the key stream are obtained by encrypting the initialization vector (IV) with the obtained previous subkey.

[0081] In the specific execution process, after obtaining the key stream, the user login information can be encrypted using the key stream to obtain ciphertext information. In one optional implementation of this embodiment, the user login information is encrypted using the key stream generated based on the initial encryption parameters and the encryption key to obtain ciphertext information. The user login information is split to obtain group information; The initial encryption parameters are encrypted using the encryption key to obtain the key stream; The ciphertext information is obtained by encrypting the group information according to the key stream.

[0082] Specifically, during the encryption process, the user login information is first divided into fixed-length data blocks, and then an encryption operation is performed on each data block. Specifically, the data block is XORed with the corresponding keystream to obtain the ciphertext data block. During this process, the state of the encryption algorithm remains unchanged, thus allowing multiple data blocks to be processed in parallel, improving encryption efficiency.

[0083] For example, the first data block is XORed with the first subkey in the key stream to obtain the first ciphertext information, the second data block is XORed with the second subkey in the key stream to obtain the second ciphertext information, and the first and second ciphertext information are concatenated to obtain the ciphertext information.

[0084] In practical applications, during the encryption calculation of the user login information, the information length of the user login information may be insufficient. In this case, the grouped information obtained after grouping the user login information cannot correspond one-to-one with the subkeys in the key stream. To address this, it is necessary to pad the user login information to complete the encryption. In an optional implementation provided in this embodiment, before the step of splitting the user login information to obtain the grouped information is executed, the following steps are also included: Detect whether the length of the user login information has reached the preset length; If so, perform the step of splitting the user login information to obtain group information; If not, populate the user login information and then perform splitting processing based on the obtained populated information.

[0085] It should be noted that, to further enhance encryption security, a random code can be generated and used in conjunction with the encryption key to perform encrypted calculations on the user login information, or the random code can be used in conjunction with a keystream to perform encrypted calculations on the user login information. Specifically, the random code can be concatenated with the encryption key, and a keystream can be generated based on the concatenation result and initial encryption parameters. The user login information can then be encrypted using the keystream to obtain ciphertext information. Alternatively, the random code can be concatenated with the keystream, and the ciphertext information can be obtained based on the concatenation result. Here, the random code is a randomly generated numerical value or string, and its length and complexity can be adjusted according to the system's security requirements to increase the complexity and security of the encryption.

[0086] Step S306: Perform encryption calculations based on the ciphertext information and authentication key to obtain an encrypted authentication tag.

[0087] After encrypting the user login information using a keystream generated based on the initial encryption parameters and encryption key to obtain ciphertext information, this step performs encryption calculations based on the ciphertext information and the authentication key to obtain an encrypted authentication tag. Optionally, the authentication key is extracted from the hash value obtained by hashing the user login information.

[0088] In practice, the authentication key and ciphertext information can be used as inputs to generate a fixed-length encrypted authentication tag through an encryption function. The encryption function can be an HMAC algorithm and / or a hash function; commonly used encryption functions include HMAC-SHA1 and HMAC-SHA256.

[0089] In one optional implementation of this embodiment, the encrypted authentication tag is obtained by performing encryption calculations based on the ciphertext information and the authentication key in the following manner: The encrypted information and the authentication key are concatenated to obtain concatenated encrypted information; The concatenated ciphertext information is input into a hash function for encryption calculation to obtain the encrypted authentication tag.

[0090] Specifically, in the process of encryption calculation based on the encryption function, the authentication key and ciphertext information can be concatenated together as input. The concatenation process can involve combining the key and ciphertext into a long byte sequence according to a specific format or order. The concatenation method can be by adding a separator between the authentication key and ciphertext information, or by arranging them according to a specific byte order. Then, a hash function is used to perform a hash operation on the concatenated byte sequence to obtain a hash value. This hash value is a digest of the input data and has high collision resistance, meaning that different input data are almost impossible to produce the same hash value. Here, the calculated hash value is used as the encryption authentication label.

[0091] It should be noted that after calculating and obtaining the encrypted authentication tag, the generated tag can be saved to a database or other appropriate storage location and associated with the ciphertext information. Simultaneously, the encrypted authentication tag can also be returned to the user terminal or its configured API interface for use in subsequent message verification or authentication processes. Here, the generated encrypted authentication tag associated with the ciphertext ensures message integrity and authentication. The generation of the encrypted authentication tag increases data security, enabling the detection and prevention of unauthorized modifications.

[0092] Step S308: Compare the encrypted information and the authentication tag with the encrypted information and authentication tag stored in the preset storage address.

[0093] After obtaining the encrypted authentication tag by performing encrypted calculations based on the encrypted information and authentication key, this step compares the encrypted information and authentication tag with the encrypted information and authentication tag stored in the preset storage address. If the comparison result is consistent, the user login verification is confirmed to be successful and a login success result is returned; if the comparison result is inconsistent, the user login verification is confirmed to be unsuccessful and a login failure result is returned.

[0094] Specifically, during the comparison process, the encrypted information and authentication tags of both parties can be concatenated to obtain a first concatenation result and a second concatenation result. The character similarity between the first concatenation result and the second concatenation result is calculated. If the character similarity is greater than the similarity threshold, the comparison result is determined to be consistent. If the character similarity is less than or equal to the similarity threshold, the comparison result is determined to be inconsistent.

[0095] In addition, before comparing the encrypted information and authentication tags with the encrypted information and authentication tags stored in the preset storage address, it is also possible to verify whether the encrypted information and authentication tags are valid or conform to the expected format, so as to improve the comparison effect.

[0096] Step S310: If the comparison results are consistent, the user login verification is confirmed and a login success result is returned.

[0097] In the specific execution process, if the comparison results are consistent, the encrypted information and authentication tag stored in the preset storage address can be decrypted to obtain the user registration information. In addition, the user registration information after decryption can be further checked to see if it is correct. If the user registration information after decryption is correct, the login is successful; otherwise, the login fails.

[0098] Figure 4 This is a schematic diagram of an information encryption processing device provided in an embodiment of the present invention, as shown below. Figure 4 As shown, the device includes: Information acquisition module 402 is used to acquire user registration information; The information encryption calculation module 404 is used to perform encryption calculation on the user registration information according to the key stream generated based on the initial encryption parameters and the encryption key to obtain ciphertext information; The key encryption calculation module 406 is used to perform encryption calculations based on the ciphertext information and the authentication key to obtain an encrypted authentication tag; the authentication key and the encryption key are extracted from the hash value obtained by hashing the user registration information. Storage module 408 is used to store the encrypted information and the encrypted authentication tag in a preset storage address.

[0099] The information encryption processing device provided in this embodiment first runs the information acquisition module 402 to acquire user registration information during the information encryption process. Then, the information encryption calculation module 404 performs encryption calculations on the user registration information based on a key stream generated from initial encryption parameters and an encryption key to obtain ciphertext information. Next, the key encryption calculation module 406 performs encryption calculations based on the ciphertext information and an authentication key to obtain an encrypted authentication tag. The authentication key and the encryption key are extracted from the hash value obtained by hashing the user registration information. Finally, the storage module 408 stores the ciphertext information and the encrypted authentication tag in a preset storage address to ensure the confidentiality, integrity, and authenticity of the user registration information, and improves system security, providing strong support for subsequent information management and security auditing.

[0100] The information encryption processing device provided in one embodiment of this specification can implement the various processes in the foregoing method embodiments and achieve the same functions and effects, which will not be repeated here.

[0101] Figure 5 This is a schematic diagram of an information encryption processing device provided in an embodiment of the present invention, as shown below. Figure 5 As shown, the device includes: The request retrieval module 502 is used to retrieve a login request containing user login information. The information encryption calculation module 504 is used to perform encryption calculation on the user login information according to the key stream generated based on the initial encryption parameters and the encryption key to obtain ciphertext information; The key encryption calculation module 506 is used to perform encryption calculations based on the ciphertext information and the authentication key to obtain an encrypted authentication tag; the authentication key and the encryption key are generated based on the hash value obtained by hashing the user login information. The comparison module 508 is used to compare the encrypted information and the authentication tag with the encrypted information and authentication tag stored in the preset storage address; If the comparison results are consistent, the result return module 510 is used to determine that the user login verification is successful and return a login success result.

[0102] This embodiment provides a login verification processing device. During the login verification process, firstly, a request acquisition module 502 is run to acquire a login request containing user login information. Secondly, an information encryption calculation module 504 is run to perform encryption calculation on the user login information based on a key stream generated based on initial encryption parameters and an encryption key to obtain ciphertext information. Then, a key encryption calculation module 506 is run to perform encryption calculation based on the ciphertext information and an authentication key to obtain an encrypted authentication tag. The authentication key and the encryption key are generated based on the hash value obtained by hash calculation on the user login information. Next, a comparison module 508 is run to compare the ciphertext information and the authentication tag with the ciphertext information and authentication tag stored in a preset storage address. If the comparison result is consistent, the result return module 510 is run to confirm that the user login verification has passed and return a login success result. This ensures the confidentiality, integrity, and authenticity of the user login information and improves the security of the system, providing strong support for subsequent information management and security auditing.

[0103] The information encryption processing device provided in one embodiment of this specification can implement the various processes in the foregoing method embodiments and achieve the same functions and effects, which will not be repeated here.

[0104] Furthermore, one embodiment of this specification also provides an information encryption processing device. Figure 6 This is a schematic diagram of the structure of an information encryption processing device provided in one embodiment of this specification, as shown below. Figure 6 As shown, the device includes a memory 601, a processor 602, a bus 603, and a communication interface 604. The memory 601, the processor 602, and the communication interface 604 communicate via the bus 603. The communication interface 604 may include input / output interfaces, including but not limited to a keyboard, mouse, monitor, microphone, and loudspeaker.

[0105] Figure 6 In the processor 602, the memory 601 stores computer-executable instructions that can run on the processor 602. When the processor 602 executes the computer-executable instructions, the following process is implemented: Obtain user registration information; The user registration information is encrypted using a key stream generated based on the initial encryption parameters and encryption key to obtain ciphertext information. An encrypted authentication tag is obtained by performing encryption calculations based on the encrypted information and the authentication key; the authentication key and the encryption key are extracted from the hash value obtained by hashing the user registration information. The encrypted information and the encrypted authentication tag are stored in a preset storage address.

[0106] The data transmission processing device provided in this embodiment, through the cooperation of the memory 601, processor 602, bus 603, and communication interface 604, first acquires user registration information during the information encryption process. Then, it performs hash calculation on the acquired user registration information to obtain a hash value, extracts the encryption key and authentication key from the hash value, thereby improving the confidentiality of the key. It then performs encryption calculation on the user registration information based on the key stream generated based on the initial encryption parameters and encryption key to obtain ciphertext information, enhancing the security of the encryption process and improving encryption efficiency. Next, it performs encryption calculation based on the ciphertext information and authentication key to obtain an encryption authentication tag, which is used to verify the authenticity and integrity of the information. Finally, it stores the ciphertext information and encryption authentication tag in a preset storage address to ensure the confidentiality, integrity, and authenticity of the user registration information, and improves the security of the system, providing strong support for subsequent information management and security auditing.

[0107] The information encryption processing device provided in one embodiment of this specification can implement the various processes in the foregoing method embodiments and achieve the same functions and effects, which will not be repeated here.

[0108] Furthermore, one embodiment of this specification also provides an information encryption processing device. Figure 7 This is a schematic diagram of the structure of an information encryption processing device provided in one embodiment of this specification, as shown below. Figure 7 As shown, the device includes a memory 701, a processor 702, a bus 703, and a communication interface 704. The memory 701, processor 702, and communication interface 704 communicate via the bus 703. The communication interface 704 may include input / output interfaces, including but not limited to a keyboard, mouse, monitor, microphone, and loudspeaker.

[0109] Figure 7 In the memory 701, computer-executable instructions that can run on the processor 702 are stored. When the processor 702 executes the computer-executable instructions, the following process is implemented: Retrieve the login request containing user login information; The user login information is encrypted using a key stream generated based on the initial encryption parameters and encryption key to obtain ciphertext information. An encrypted authentication tag is obtained by performing encryption calculations based on the encrypted information and the authentication key; the authentication key and the encryption key are generated based on the hash value obtained by hashing the user login information. The encrypted information and the authentication tag are compared with the encrypted information and authentication tag stored in the preset storage address; If the comparison results are consistent, the user login verification is confirmed and a login success result is returned.

[0110] The data transmission processing device provided in this embodiment, through the cooperation of the memory 701, processor 702, bus 703, and communication interface 704, first obtains user registration information during the information encryption process. Then, it performs hash calculation on the obtained user registration information to obtain a hash value, extracts the encryption key and authentication key from the hash value, thereby improving the confidentiality of the key. Based on the key stream generated based on the initial encryption parameters and encryption key, it performs encryption calculation on the user registration information to obtain ciphertext information, thereby enhancing the security of the encryption process and improving encryption efficiency. Then, it performs encryption calculation based on the ciphertext information and authentication key to obtain an encryption authentication tag, which is used to verify the authenticity and integrity of the information. Finally, it stores the ciphertext information and encryption authentication tag in a preset storage address to ensure the confidentiality, integrity, and authenticity of the user registration information, and improves the security of the system, providing strong support for subsequent information management and security auditing.

[0111] The information encryption processing device provided in one embodiment of this specification can implement the various processes in the foregoing method embodiments and achieve the same functions and effects, which will not be repeated here.

[0112] Furthermore, another embodiment of this specification provides a computer-readable storage medium for storing computer-executable instructions that, when executed by a processor, implement the following process: Retrieve the login request containing user login information; The user login information is encrypted using a key stream generated based on the initial encryption parameters and encryption key to obtain ciphertext information. An encrypted authentication tag is obtained by performing encryption calculations based on the encrypted information and the authentication key; the authentication key and the encryption key are generated based on the hash value obtained by hashing the user login information. The encrypted information and the authentication tag are compared with the encrypted information and authentication tag stored in the preset storage address; If the comparison results are consistent, the user login verification is confirmed and a login success result is returned.

[0113] The computer-readable storage medium provided in this embodiment first acquires user registration information during information encryption processing. Then, it performs hash calculation on the acquired user registration information to obtain a hash value. From the hash value, it extracts an encryption key and an authentication key, thereby improving the confidentiality of the keys. Based on the key stream generated based on the initial encryption parameters and the encryption key, it performs encryption calculation on the user registration information to obtain ciphertext information, thereby enhancing the security of the encryption process and improving encryption efficiency. Then, it performs encryption calculation based on the ciphertext information and the authentication key to obtain an encrypted authentication tag, which is used to verify the authenticity and integrity of the information. Finally, it stores the ciphertext information and the encrypted authentication tag in a preset storage address to ensure the confidentiality, integrity, and authenticity of the user registration information and improve the security of the system, providing strong support for subsequent information management and security auditing.

[0114] The computer-readable storage medium includes read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk, etc.

[0115] The computer-readable storage medium provided in one embodiment of this specification can implement the various processes in the foregoing method embodiments and achieve the same functions and effects, which will not be repeated here.

[0116] Furthermore, another embodiment of this specification provides a computer-readable storage medium for storing computer-executable instructions that, when executed by a processor, implement the following process: Retrieve the login request containing user login information; The user login information is encrypted using a key stream generated based on the initial encryption parameters and encryption key to obtain ciphertext information. An encrypted authentication tag is obtained by performing encryption calculations based on the encrypted information and the authentication key; the authentication key and the encryption key are generated based on the hash value obtained by hashing the user login information. The encrypted information and the authentication tag are compared with the encrypted information and authentication tag stored in the preset storage address; If the comparison results are consistent, the user login verification is confirmed and a login success result is returned.

[0117] The computer-readable storage medium provided in this embodiment first acquires user registration information during information encryption processing. Then, it performs hash calculation on the acquired user registration information to obtain a hash value. From the hash value, it extracts an encryption key and an authentication key, thereby improving the confidentiality of the keys. Based on the key stream generated based on the initial encryption parameters and the encryption key, it performs encryption calculation on the user registration information to obtain ciphertext information, thereby enhancing the security of the encryption process and improving encryption efficiency. Then, it performs encryption calculation based on the ciphertext information and the authentication key to obtain an encrypted authentication tag, which is used to verify the authenticity and integrity of the information. Finally, it stores the ciphertext information and the encrypted authentication tag in a preset storage address to ensure the confidentiality, integrity, and authenticity of the user registration information and improve the security of the system, providing strong support for subsequent information management and security auditing.

[0118] The computer-readable storage medium includes read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk, etc.

[0119] The computer-readable storage medium provided in one embodiment of this specification can implement the various processes in the foregoing method embodiments and achieve the same functions and effects, which will not be repeated here.

[0120] Furthermore, another embodiment of this specification provides a computer program product that, when executed by a processor, implements the following process: Obtain user registration information; The user registration information is encrypted using a key stream generated based on the initial encryption parameters and encryption key to obtain ciphertext information. An encrypted authentication tag is obtained by performing encryption calculations based on the encrypted information and the authentication key; the authentication key and the encryption key are extracted from the hash value obtained by hashing the user registration information. The encrypted information and the encrypted authentication tag are stored in a preset storage address.

[0121] The computer product program provided in this embodiment, during the information encryption process, first obtains user registration information, then performs hash calculation on the obtained user registration information to obtain a hash value, extracts the encryption key and authentication key from the hash value, thereby improving the confidentiality of the key, performs encryption calculation on the user registration information based on the key stream generated based on the initial encryption parameters and encryption key to obtain ciphertext information, thereby enhancing the security of the encryption process and improving encryption efficiency, then performs encryption calculation based on the ciphertext information and authentication key to obtain an encryption authentication tag, which is used to verify the authenticity and integrity of the information, and finally stores the ciphertext information and encryption authentication tag in a preset storage address to ensure the confidentiality, integrity and authenticity of user registration information, and improve the security of the system, providing strong support for subsequent information management and security auditing.

[0122] The computer program product provided in one embodiment of this specification can implement the various processes in the foregoing method embodiments and achieve the same functions and effects, which will not be repeated here.

[0123] Furthermore, another embodiment of this specification provides a computer program product that, when executed by a processor, implements the following process: Retrieve the login request containing user login information; The user login information is encrypted using a key stream generated based on the initial encryption parameters and encryption key to obtain ciphertext information. An encrypted authentication tag is obtained by performing encryption calculations based on the encrypted information and the authentication key; the authentication key and the encryption key are generated based on the hash value obtained by hashing the user login information. The encrypted information and the authentication tag are compared with the encrypted information and authentication tag stored in the preset storage address; If the comparison results are consistent, the user login verification is confirmed and a login success result is returned.

[0124] The computer product program provided in this embodiment, during the information encryption process, first obtains user registration information, then performs hash calculation on the obtained user registration information to obtain a hash value, extracts the encryption key and authentication key from the hash value, thereby improving the confidentiality of the key, performs encryption calculation on the user registration information based on the key stream generated based on the initial encryption parameters and encryption key to obtain ciphertext information, thereby enhancing the security of the encryption process and improving encryption efficiency, then performs encryption calculation based on the ciphertext information and authentication key to obtain an encryption authentication tag, which is used to verify the authenticity and integrity of the information, and finally stores the ciphertext information and encryption authentication tag in a preset storage address to ensure the confidentiality, integrity and authenticity of user registration information, and improve the security of the system, providing strong support for subsequent information management and security auditing.

[0125] The computer program product provided in one embodiment of this specification can implement the various processes in the foregoing method embodiments and achieve the same functions and effects, which will not be repeated here.

[0126] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-readable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0127] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0128] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0129] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0130] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0131] Memory may include non-persistent storage in computer-readable storage media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable storage media.

[0132] Computer-readable storage media include both permanent and non-permanent, removable and non-removable media that can store information by any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer-readable storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable storage media does not include transient media, such as modulated data signals and carrier waves.

[0133] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0134] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0135] The above description is merely an embodiment of this application and is not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.

Claims

1. An information encryption processing method, characterized in that, The method includes: Obtain user registration information; The user registration information is encrypted using a key stream generated based on the initial encryption parameters and encryption key to obtain ciphertext information. An encrypted authentication tag is obtained by performing encryption calculations based on the encrypted information and the authentication key; the authentication key and the encryption key are extracted from the hash value obtained by hashing the user registration information. The encrypted information and the encrypted authentication tag are stored in a preset storage address.

2. The information encryption processing method according to claim 1, characterized in that, The authentication key and the encryption key are generated in the following manner: The user registration information is concatenated with each sub-information, and the resulting concatenated user information is hashed to obtain the hash value. Extract a first preset field from the hash value as the authentication key, and extract a second preset field as the encryption key.

3. The information encryption processing method according to claim 1, characterized in that, The step of encrypting the user registration information based on the key stream generated based on the initial encryption parameters and the encryption key to obtain ciphertext information includes: The user registration information is split to obtain grouping information; The initial encryption parameters are encrypted using the encryption key to obtain the key stream; The ciphertext information is obtained by encrypting the group information according to the key stream.

4. The information encryption processing method according to claim 3, characterized in that, Before the step of splitting the user registration information to obtain group information is executed, the method further includes: Detect whether the length of the user registration information has reached the preset length; If so, perform the step of splitting the user registration information to obtain grouping information; If not, populate the user registration information and then perform splitting processing based on the obtained populated information.

5. The information encryption processing method according to claim 1, characterized in that, The step of performing encryption calculations based on the ciphertext information and authentication key to obtain an encrypted authentication tag includes: The encrypted information and the authentication key are concatenated to obtain concatenated encrypted information; The concatenated ciphertext information is input into a hash function for encryption calculation to obtain the encrypted authentication tag.

6. A login verification processing method, characterized in that, The method includes: Retrieve the login request containing user login information; The user login information is encrypted using a key stream generated based on initial encryption parameters and encryption key to obtain ciphertext information. An encrypted authentication tag is obtained by performing encryption calculations based on the encrypted information and the authentication key; the authentication key and the encryption key are generated based on the hash value obtained by hashing the user login information. The encrypted information and the authentication tag are compared with the encrypted information and authentication tag stored in the preset storage address; If the comparison results are consistent, the user login verification is confirmed and a login success result is returned.

7. An information encryption processing device, characterized in that, The device includes: The information acquisition module is used to acquire user registration information; The information encryption calculation module is used to perform encryption calculations on the user registration information based on the key stream generated based on the initial encryption parameters and the encryption key to obtain ciphertext information; The key encryption calculation module is used to perform encryption calculations based on the ciphertext information and the authentication key to obtain an encrypted authentication tag; the authentication key and the encryption key are extracted from the hash value obtained by hashing the user registration information. The storage module is used to store the encrypted information and the encrypted authentication tag in a preset storage address.

8. An information encryption processing device, characterized in that, The device includes a memory and a processor. The memory stores computer-executable instructions, which, when executed on the processor, are capable of implementing the steps of the information encryption processing method according to any one of claims 1-5.

9. A computer-readable storage medium storing computer-executable instructions, characterized in that, When the computer-executable instructions are executed by the processor, they can implement the steps of the information encryption processing method according to any one of claims 1-5.

10. A computer program product, characterized in that, The computer program product includes an information encryption processing program, which, when executed by a processor, can implement the steps of the information encryption processing method according to any one of claims 1-5.