Data encryption method and device, electronic equipment and storage medium
By generating dynamic keys and utilizing a combination of time salt, device fingerprint, and service identifier, along with key lifecycle verification, the problem of static key leakage is solved, thus improving the security and reliability of data encryption.
Patent Information
- Application Number
- CN202511080012.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-01
- Publication Date
- 2025-12-09
AI Technical Summary
Existing technologies use static keys for data encryption, which are vulnerable to data leakage due to brute-force attacks on the keys, and also pose risks of key theft and replay attacks.
By generating a dynamic key, using time salt and device fingerprint to generate a target key, combining it with the service identifier for encryption, setting the key lifecycle and verifying the device fingerprint to ensure security.
It reduces the risk of data leakage caused by brute-force attacks, effectively prevents replay attacks, and improves the security and reliability of data encryption.
Smart Images

Figure CN121098482A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security technology, specifically to a data encryption method, device, electronic device, and storage medium. Background Technology
[0002] With the rapid development of communication and computer technologies, core business data has become a core asset of enterprise operations. Its security is closely related to enterprise development. In data scenarios (such as financial transactions, user privacy protection, and IoT device authentication), encrypting core business data is an important defense against data leakage.
[0003] However, in existing technologies, static key technology is commonly used for data encryption and decryption. This means using a fixed, long-term unchanging key for data encryption or authentication. While this encryption method is easy to manage, the long-term unchanging key increases the risk of brute-force attacks, key theft, or replay attacks. Once the key is leaked, both historical and real-time data may be decrypted in batches, and the leakage of the company's core business data will cause significant losses to the company. Summary of the Invention
[0004] This application provides a data encryption method, apparatus, electronic device, and storage medium to solve the problem that data is easily leaked due to brute-force attacks when using static keys to encrypt data in the prior art.
[0005] Firstly, this application provides a data encryption method, the method comprising:
[0006] In response to a request from a terminal device to obtain target service data, a key factor for the target key is obtained. The key factor includes a time salt value and a device fingerprint. The time salt value is used to characterize the time information of initiating the request, and the device fingerprint is used to characterize the identity information of the terminal device.
[0007] The target key is generated based on the time salt value and the device fingerprint;
[0008] The target service data is encrypted based on the target key, and the encrypted target service data and the target key are sent to the terminal device.
[0009] In some embodiments, generating the target key based on the time salt value and the device fingerprint includes:
[0010] Convert the time salt value and the device fingerprint to the same binary length;
[0011] The converted time salt value and the device fingerprint are XORed to determine the XOR result.
[0012] The secure hash algorithm is used to perform hash calculation on the XOR processing result, and the first processing result is determined based on the generated hash value;
[0013] Based on the first processing result, the target key is determined.
[0014] In some embodiments, the key factor further includes a service identifier, and determining the target key based on the first processing result includes:
[0015] Based on the service identifier, the second processing result is determined;
[0016] The target key is generated based on the first processing result and the second processing result.
[0017] In some embodiments, determining the second processing result based on the service identifier includes:
[0018] The service identifier is encrypted using a symmetric encryption algorithm, and the second processing result is determined based on the encrypted service identifier.
[0019] In some embodiments, generating the target key based on the first processing result and the second processing result includes:
[0020] The target key is generated by performing a modulo operation on the first processing result and the second processing result.
[0021] In some embodiments, before sending the encrypted target business data and the target key to the terminal device, the method further includes:
[0022] Set a lifecycle for the target key;
[0023] Sending the encrypted target service data and the target key to the terminal device includes:
[0024] The encrypted target business data and the target key with the lifecycle set are sent to the terminal device. After receiving the target key and the encrypted data, the terminal device verifies the validity of the target key based on the lifecycle. If the terminal device verifies that it has the viewing permission based on the device fingerprint of the terminal device, it decrypts the encrypted data based on the target key to obtain the decrypted target business data.
[0025] In some embodiments, the device fingerprint is determined based on some or all of the CPU information, MAC information, and IMEI information of the terminal device that initiated the acquisition request.
[0026] Secondly, this application provides a data encryption device, the device comprising:
[0027] The acquisition module is used to respond to a request for acquiring target business data initiated by a terminal device and acquire a key factor of the target key. The key factor includes a time salt value and a device fingerprint. The time salt value is used to characterize the time information of initiating the acquisition request, and the device fingerprint is used to characterize the identity information of the terminal device.
[0028] A generation module is used to generate the target key based on the time salt value and the device fingerprint;
[0029] An encryption module is used to encrypt the target service data based on the target key, and send the encrypted target service data and the target key to the terminal device.
[0030] In some embodiments, the generation module is specifically used for:
[0031] Convert the time salt value and the device fingerprint to the same binary length;
[0032] The converted time salt value and the device fingerprint are XORed to determine the XOR result.
[0033] The secure hash algorithm is used to perform hash calculation on the XOR processing result, and the first processing result is determined based on the generated hash value;
[0034] Based on the first processing result, the target key is determined.
[0035] In some embodiments, the key factor further includes a service identifier, and the generation module is specifically used for:
[0036] Based on the service identifier, the second processing result is determined;
[0037] The target key is generated based on the first processing result and the second processing result.
[0038] In some embodiments, the generation module is specifically used for:
[0039] The service identifier is encrypted using a symmetric encryption algorithm, and the second processing result is determined based on the encrypted service identifier.
[0040] In some embodiments, the generation module is specifically used for:
[0041] The target key is generated by performing a modulo operation on the first processing result and the second processing result.
[0042] In some embodiments, before the encryption module sends the encrypted target business data and the target key to the terminal device, it is further configured to:
[0043] Set a lifecycle for the target key;
[0044] Sending the encrypted target service data and the target key to the terminal device includes:
[0045] The encrypted target business data and the target key with the lifecycle set are sent to the terminal device. After receiving the target key and the encrypted data, the terminal device verifies the validity of the target key based on the lifecycle. If the terminal device verifies that it has the viewing permission based on the device fingerprint of the terminal device, it decrypts the encrypted data based on the target key to obtain the decrypted target business data.
[0046] In some embodiments, the device fingerprint is determined based on some or all of the CPU information, MAC information, and IMEI information of the terminal device that initiated the acquisition request.
[0047] Thirdly, this application provides an electronic device, comprising: at least one processor, and a memory communicatively connected to said at least one processor, wherein:
[0048] The memory stores a computer program that can be executed by at least one processor, which enables the at least one processor to perform the above-described data encryption method.
[0049] Fourthly, this application provides a computer-readable storage medium storing a computer program, the computer program including program instructions, which, when executed by a computer, cause the computer to perform the above-described data encryption method.
[0050] Fifthly, this application provides a computer program product comprising: computer program code, which, when executed on a computer, causes the computer to perform the aforementioned data encryption method.
[0051] In this embodiment, in response to a request from a terminal device to acquire target service data, a key factor of the target key is acquired. The key factor includes a time salt value and a device fingerprint. The time salt value is used to characterize the time information of the acquisition request, and the device fingerprint is used to characterize the identity information of the terminal device. A target key is generated based on the time salt value and the device fingerprint. The target service data is encrypted based on the target key, and the encrypted target service data and the target key are sent to the terminal device. In this way, a dynamic key is generated using the time salt value and the device fingerprint to ensure the uniqueness of the key for each session. Compared with the use of static keys for data encryption in the prior art, this reduces the risk of data leakage caused by brute-force attacks, effectively prevents replay attacks, and improves the security and reliability of data encryption.
[0052] Other features and advantages of the invention will be set forth in the description which follows, and will be apparent in part from the description, or may be learned by practicing the invention. The objects and other advantages of the invention may be realized and obtained by means of the structures particularly pointed out in the written description, claims, and drawings. Attached Figure Description
[0053] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:
[0054] Figure 1 This is a schematic diagram illustrating an application scenario of a data encryption method provided in an embodiment of this application;
[0055] Figure 2 A flowchart illustrating a data encryption method provided in this application embodiment;
[0056] Figure 3 A flowchart illustrating another data encryption method provided in this application embodiment;
[0057] Figure 4 This is a schematic diagram of the structure of a data encryption device provided in an embodiment of this application;
[0058] Figure 5 This is a schematic diagram of the hardware structure of an electronic device for implementing a data encryption method, provided as an embodiment of this application. Detailed Implementation
[0059] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application. Unless otherwise specified, the embodiments and features in the embodiments of this application can be arbitrarily combined with each other. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than that shown here.
[0060] The terms "first" and "second" in the specification, claims, and accompanying drawings of this application are used to distinguish different objects, not to describe a specific order. Furthermore, the term "comprising" and any variations thereof are intended to cover non-exclusive protection. For example, a process, method, system, product, or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to these processes, methods, products, or devices. The term "multiple" in this application can mean at least two, for example, two, three, or more, and the embodiments of this application do not impose limitations.
[0061] The following description, in conjunction with the accompanying drawings, illustrates exemplary embodiments of this application, including various details to aid understanding. These embodiments should be considered merely exemplary. Therefore, those skilled in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope of this application. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description. It should be noted that in the embodiments of this application, certain existing industry solutions such as software, components, and models may be mentioned. These should be considered exemplary, intended only to illustrate the feasibility of implementing the technical solutions of this application, and do not imply that the applicant has already used or necessarily used such solutions.
[0062] The acquisition, transmission, storage, and use of data in this application all comply with the requirements of relevant national laws and regulations.
[0063] Before introducing the data encryption method provided in the embodiments of this application, for ease of understanding, the technical background of the embodiments of this application will be described in detail below.
[0064] With the rapid development of communication and computer technologies, core business data has become a core asset of enterprise operations. Its security is closely related to enterprise development. In data scenarios (such as financial transactions, user privacy protection, and IoT device authentication), encrypting core business data is an important defense against data leakage.
[0065] However, current technologies generally employ static key solutions for data encryption and decryption, which use fixed, long-term unchanging keys for data encryption or authentication. The core characteristics of this approach are the non-updating and centralized management of the keys. However, this approach also has significant drawbacks, such as a high risk of brute-force attacks, as it can be cracked quickly through exhaustive attacks; and key management vulnerabilities, as all devices rely on the same key. If the management center is compromised or the key distribution process is eavesdropped on, the entire system's security collapses, and both historical and real-time data can be decrypted in batches, leading to the leakage of core business data and causing significant losses to the enterprise.
[0066] In view of this, in order to solve the problem that data encryption using static keys in the prior art is easily leaked due to brute-force attacks on the keys, embodiments of this application provide a data encryption method, apparatus, electronic device, and storage medium. Some preferred embodiments of this application are described below with reference to the accompanying drawings.
[0067] The data encryption method in this application is applied to a terminal device. Please refer to [link / reference]. Figure 1 , Figure 1 This is a schematic diagram of an application scenario for a data encryption method provided in an embodiment of this application, including terminal device 10 and terminal device 20.
[0068] Terminal device 10 is used to respond to a request for obtaining target service data initiated by terminal device 20, obtain the key factors of the target key, the key factors include time salt value and device fingerprint; the time salt value is used to represent the time information of initiating the request, and the device fingerprint is used to represent the identity information of terminal device 20, and then generate a target key based on the time salt value and device fingerprint; encrypt the target service data based on the target key, and send the encrypted target service data and target key to terminal device 20.
[0069] Terminal device 20 is used to initiate a request to terminal device 10 to obtain target service data, receive encrypted target service data and target key sent by terminal device 10, and decrypt the encrypted target service data based on the target key.
[0070] Among them, terminal devices can be mobile phones, tablets, computers with wireless transceiver capabilities, virtual reality (VR) terminal devices, augmented reality (AR) terminal devices, wireless terminals in industrial control, vehicle-mounted terminals, etc.
[0071] Terminal device 10 and terminal device 20 are connected via the Internet to enable communication between them. Optionally, the Internet described above uses standard communication technologies and / or protocols. The Internet is typically the Internet, but can also be any network, including but not limited to any combination of Local Area Network (LAN), Metropolitan Area Network (MAN), Wide Area Network (WAN), mobile, wired or wireless networks, private networks or virtual private networks. In some embodiments, technologies and / or formats including Hyper Text Markup Language (HTML), Extensible Markup Language (XML), etc., are used to represent data exchanged over the network. Furthermore, conventional encryption technologies such as Secure Socket Layer (SSL), Transport Layer Security (TLS), Virtual Private Network (VPN), and Internet Protocol Security (IPsec) can be used to encrypt all or some links. In other embodiments, customized and / or dedicated data communication technologies can be used to replace or supplement the aforementioned data communication technologies.
[0072] It should be noted that, Figure 1 This is merely an example of an application scenario and does not constitute a limitation on the technical solutions provided in the embodiments of this application. As those skilled in the art will know, with the emergence of new application scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.
[0073] Please refer to Figure 2 The following is a flowchart of a data encryption method provided in an embodiment of this application, which includes the following steps.
[0074] In step 201, in response to the target service data acquisition request initiated by the terminal device, the key factor of the target key is acquired. The key factor includes a time salt value and a device fingerprint. The time salt value is used to characterize the time information of the acquisition request, and the device fingerprint is used to characterize the identity information of the terminal device.
[0075] The time salt value can be based on the time information of the request being sent, specifically a timestamp. The timestamp can be accurate to 0.1 milliseconds and is typically represented in Unix timestamp format. A Unix timestamp is a way of representing time in seconds since January 1, 1970, UTC. To achieve 0.1 millisecond precision, a decimal part can be added to the standard Unix timestamp. By including a precise timestamp, it ensures that each request is unique, preventing replay attacks even if the content is the same. Adding time as a random element to the key generation process adds an extra layer of security.
[0076] For example, if the UTC time of the retrieval request is 12:30:30.800 on April 20, 2025, then the Unix timestamp is the number of seconds that have elapsed since 00:00:00 UTC on January 1, 1970. Using existing conversion tools, its time salt value with 0.1 millisecond precision can be determined to be 1745286630.800.
[0077] Among them, device fingerprint is used to characterize the identity information of terminal device. In specific implementation, device fingerprint is a unique identifier determined based on part or all of the CPU information, MAC information, and International Mobile Equipment Identity (IMEI) information of the terminal device that initiates the acquisition request. CPU information includes CPU serial number, MAC address, which is the physical address of the network interface controller. Each network card has a globally unique MAC address. International Mobile Equipment Identity (IMEI) is used to identify mobile devices such as mobile phones and satellite phones. For mobile devices, IMEI is a unique identification code assigned to each mobile phone by the device manufacturer.
[0078] In this way, adding the device fingerprint of the terminal device can further ensure the security of the generated key.
[0079] In practice, upon receiving a request to acquire target business data initiated by a terminal device, a sensitive data identification module can be activated to scan the request content in real time using a pre-set rule base (keyword matching, regular expressions). If the request is determined to be sensitive information, an encryption process is triggered, i.e., a dynamic key is generated and encrypted using the data encryption method of this application; otherwise, the data directly enters the regular transmission channel.
[0080] In step 202, a target key is generated based on the time salt value and the device fingerprint.
[0081] After obtaining the time salt value and device fingerprint, preprocessing can be performed on the time salt value and device fingerprint respectively. Preprocessing can include data cleaning, handling default values, standardization, etc. For example, the obtained CPU serial number, MAC address and IMEI can be preprocessed, the preprocessed CPU serial number, MAC address and IMEI can be concatenated, and the concatenated field can be used to generate a 256-bit unique identifier using a hash algorithm (such as SHA3-256); for example, the preprocessed time salt value can be converted to binary, etc.
[0082] In practice, the time salt value and device fingerprint can be converted to the same binary length; the converted time salt value and device fingerprint can be XORed to determine the XOR result; a secure hash algorithm can be used to perform hash calculation on the XOR result, and the first processing result can be determined based on the generated hash value; the target key can be determined based on the first processing result.
[0083] In practice, to facilitate subsequent processing, the time salt value and device fingerprint can be converted into binary formats of the same length. For example, the shorter one can be padded (e.g., with 0s). Assuming the binary representation of the time salt value is 101010 (simplified) and the binary representation of the device fingerprint is 110011 (simplified), the result of the XOR operation is 011001… (simplified). Performing an XOR operation on the time salt value and device fingerprint can enhance randomness. In this way, even if an attacker obtains either the time salt value or the device fingerprint, they cannot reverse-engineer the other parameter. Then, a secure hash algorithm is used to perform hash calculation on the XOR result. Commonly used hash algorithms include SHA-256 and SHA3-512. For example, using SHA-256 to hash the XOR result yields a fixed-length (256-bit) hash value, while using SHA3-512 to hash the XOR result yields a fixed-length (512-bit) hash value. Finally, the target key is determined based on the hash value. For example, the hash value can be used directly as the target key, or the required length can be extracted from the hash value as the target key. For instance, if the required target key is 128 bits (16 bytes), the first 16 bytes can be extracted from the SHA-256 hash value.
[0084] In step 203, the target service data is encrypted based on the target key, and the encrypted target service data and the target key are sent to the terminal device.
[0085] In practice, before sending the encrypted target business data and target key to the terminal device, a lifecycle can be set for the target key. The encrypted target business data and the target key with the set lifecycle are then sent to the terminal device. After receiving the target key and encrypted data, the terminal device verifies the validity of the target key based on the lifecycle. When the terminal device verifies that it has the right to view the data based on its device fingerprint, it decrypts the encrypted data based on the target key to obtain the decrypted target business data.
[0086] In practice, the target key's lifespan can be set, for example, to 30 seconds. This restricts its use to a specific time window; once 30 seconds have passed, the target key automatically expires, further reducing potential security risks. When a terminal device receives information containing the target key and encrypted data, it first checks if the key is within its declared lifespan. If the current time exceeds the key's expiration date, further operation is refused. Next, the terminal device verifies its own device fingerprint to ensure it meets the viewing permission requirements. Since the key is generated based on the terminal device's own device fingerprint, only terminal devices matching that fingerprint have viewing permissions. This effectively ensures that only authorized devices can use the target key to decrypt encrypted data. This effectively sets a lifespan for the target key and ensures that encrypted data can only be accessed at the correct time and on authorized devices, thus significantly improving the overall system security.
[0087] In this embodiment, in response to a request from a terminal device to acquire target service data, a key factor of the target key is acquired. The key factor includes a time salt value and a device fingerprint. The time salt value is used to characterize the time information of the acquisition request, and the device fingerprint is used to characterize the identity information of the terminal device. A target key is generated based on the time salt value and the device fingerprint. The target service data is encrypted based on the target key, and the encrypted target service data and the target key are sent to the terminal device. In this way, a dynamic key is generated using the time salt value and the device fingerprint to ensure the uniqueness of the key for each session. Compared with the use of static keys for data encryption in the prior art, this reduces the risk of data leakage caused by brute-force attacks, effectively prevents replay attacks, and improves the security and reliability of data encryption.
[0088] In practice, in addition to time salt value and device fingerprint, key factors can be further combined with service identifiers. The service identifier is used to characterize the business type corresponding to the target business data. For example, the service identifier of the government system is GOV_SYS_001, or the service identifier of the payment system is PAY_SYS_002.
[0089] Please refer to Figure 3The following is a flowchart of another data encryption method provided in the embodiments of this application, which includes the following steps.
[0090] In step 301, in response to the target service data acquisition request initiated by the terminal device, the key factor of the target key is acquired. The key factor includes time salt value, device fingerprint and service identifier.
[0091] In step 302, the first processing result is determined based on the time salt value and the device fingerprint.
[0092] In practice, the time salt value and device fingerprint can be converted to the same binary length. The converted time salt value and device fingerprint are then XORed to determine the XOR result. A secure hash algorithm is then used to perform hash calculation on the XOR result. The first processing result is determined based on the generated hash value. For example, the secure hash algorithm is SHA3-512.
[0093] In step 303, a second processing result is determined based on the service identifier.
[0094] In practice, a symmetric encryption algorithm can be used to encrypt the service identifier, and the second processing result can be determined based on the encrypted service identifier.
[0095] Among them, the symmetric encryption algorithm is, for example, the SM4 algorithm. In this way, the business identifier is irreversibly encrypted to prevent the business logic from being exposed. Different business identifiers are generated into a unique modulus after being encrypted by SM4, so as to realize the strong binding between the key and the business.
[0096] It should be noted that there is no explicit order between steps 302 and 303. Step 302 can be executed first, or step 303 can be executed first, or they can be performed simultaneously. This application does not impose any restrictions on this.
[0097] In step 304, a target key is generated based on the first processing result and the second processing result.
[0098] In practice, the first and second processing results can be moduloed to generate the target key.
[0099] Assuming the first processing result is a 512-bit hash value generated using the SHA3-512 algorithm, and the second processing result is a 256-bit business identifier encrypted using SM4, then the modulo operation, i.e., finding the remainder after dividing the two numbers, is used to determine the target key.
[0100] In step 305, the target service data is encrypted based on the target key, and the encrypted target service data and the target key are sent to the terminal device.
[0101] In practice, before sending the encrypted target business data and target key to the terminal device, a lifecycle can be set for the target key. The encrypted target business data and the target key with the set lifecycle are then sent to the terminal device. After receiving the target key and encrypted data, the terminal device verifies the validity of the target key based on the lifecycle. When the terminal device verifies that it has the right to view the data based on its device fingerprint, it decrypts the encrypted data based on the target key to obtain the decrypted target business data.
[0102] In this way, by dynamically generating the target key using three elements—device fingerprint, time salt value, and service identifier—the uniqueness of the key for each session is ensured, effectively preventing replay attacks and improving the security and reliability of data encryption.
[0103] The following section uses the encryption of electronic medical records of patients in a hospital as an example to describe in detail the data encryption method of this application embodiment.
[0104] The obtained key factors are shown in Table 1.
[0105] Table 1
[0106] key factor Value / Generation Method Device fingerprint 0x3f2504e04f8911d3 (Generated from CPU serial number + MAC address via SM3-256) Time salinity 0x20250312143232876 (Unix timestamp accurate to 0.1ms, hexadecimal representation) Service Identifier EHR_System_ICU (Service Identifier in Plain Text)
[0107] As shown in Table 1, if the dynamic key generation formula is: Dynamic Key = {Hash SM3-512[(Device Fingerprint) XOR (Time Salt Value)]} Modulo Operation [SM4 (Service Identifier)], then the generated dynamic key is Hash
[0108]
[0109] The specific steps are as follows:
[0110] Step-by-step breakdown:
[0111] 1) SM4 encrypted ServiceID:
[0112] Pre-configured SM4 key: 0x89a3b2c4d5e6f789... (256 bits, stored in the HSM hardware security module)
[0113] Output: SM4(EHR_System_ICU) = 0x5e6f789a3b2c4d5... (128-bit block encryption result)
[0114] 2) XOR operation and hashing:
[0115] bitwise XOR #Bitwise XOR
[0116] Hash_output = SM3_512(xor_result).hexdigest() # Outputs a 512-bit hash
[0117] 3) Generating the key using modular arithmetic:
[0118] key = hash_output%0x5e6f789a3b2c4d5... # Take the last 256 bits as the key
[0119] Target key = 0xd3ab8e78e21b36a45c7d6c893d1b4c2f... # The actual key used
[0120] Finally, the target key is used to encrypt the patient's electronic medical records.
[0121] In this embodiment, a dynamic hybrid entropy pool combining device fingerprints and time salt values significantly increases the difficulty for attackers to guess or predict keys compared to single-factor entropy values in existing technologies. Utilizing device-specific hardware information and precise timestamps ensures that each generated key is unique, enhancing overall system security. The SHA3-512+SM4 dual-layer quantum-resistant architecture significantly improves quantum resistance compared to the existing SHA-256 architecture. SM4 dynamic modulus generation enables service isolation, ensuring each service request uses unique parameters and preventing potential cross-service security threats. Compared to static modulus in existing technologies, it avoids the risk of key reuse. Furthermore, setting a Unix timestamp (0.1ms precision + 30-second lifespan) ensures that even if the same request is intercepted, it cannot be reused outside the validity period. Through these methods, not only is the system's security and quantum resistance significantly improved, but the key reuse risk and replay attack problems in existing technologies are also effectively addressed.
[0122] Based on the same inventive concept, embodiments of this application provide a data encryption device, please refer to... Figure 4 The device includes:
[0123] The acquisition module 401 is used to respond to a request for acquiring target service data initiated by a terminal device and acquire a key factor of the target key. The key factor includes a time salt value and a device fingerprint. The time salt value is used to characterize the time information of initiating the acquisition request, and the device fingerprint is used to characterize the identity information of the terminal device.
[0124] The generation module 402 is used to generate the target key based on the time salt value and the device fingerprint;
[0125] The encryption module 403 is used to encrypt the target service data based on the target key, and send the encrypted target service data and the target key to the terminal device.
[0126] In some embodiments, the generation module 402 is specifically used for:
[0127] Convert the time salt value and the device fingerprint to the same binary length;
[0128] The converted time salt value and the device fingerprint are XORed to determine the XOR result.
[0129] The secure hash algorithm is used to perform hash calculation on the XOR processing result, and the first processing result is determined based on the generated hash value;
[0130] Based on the first processing result, the target key is determined.
[0131] In some embodiments, the key factor further includes a service identifier, and the generation module 402 is specifically used for:
[0132] Based on the service identifier, the second processing result is determined;
[0133] The target key is generated based on the first processing result and the second processing result.
[0134] In some embodiments, the generation module 402 is specifically used for:
[0135] The service identifier is encrypted using a symmetric encryption algorithm, and the second processing result is determined based on the encrypted service identifier.
[0136] In some embodiments, the generation module 402 is specifically used for:
[0137] The target key is generated by performing a modulo operation on the first processing result and the second processing result.
[0138] In some embodiments, before the encryption module 403 sends the encrypted target service data and the target key to the terminal device, it is further configured to:
[0139] Set a lifecycle for the target key;
[0140] Sending the encrypted target service data and the target key to the terminal device includes:
[0141] The encrypted target business data and the target key with the lifecycle set are sent to the terminal device. After receiving the target key and the encrypted data, the terminal device verifies the validity of the target key based on the lifecycle. If the terminal device verifies that it has the viewing permission based on the device fingerprint of the terminal device, it decrypts the encrypted data based on the target key to obtain the decrypted target business data.
[0142] In some embodiments, the device fingerprint is determined based on some or all of the CPU information, MAC information, and IMEI information of the terminal device that initiated the acquisition request.
[0143] Based on the same inventive concept, this application provides an electronic device that can realize the function of the data encryption device described above. Please refer to... Figure 5 The device includes a memory 501, one or more processors 502, and a bus 503.
[0144] The memory 501 is used to store computer programs executed by the processor 501. The memory 501 may mainly include a program storage area and a data storage area. The program storage area may store the operating system and programs required to run instant messaging functions, etc.; the data storage area may store various instant messaging information and operation instruction sets, etc.
[0145] Memory 501 may be volatile memory, such as random-access memory (RAM); memory 501 may also be non-volatile memory, such as read-only memory, flash memory, hard disk drive (HDD), or solid-state drive (SSD); or memory 501 may be any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but is not limited thereto. Memory 501 may be a combination of the above-mentioned memories.
[0146] Processor 502 may include one or more central processing units (CPUs) or digital processing units, etc. Processor 502 is used to implement the data encryption method in the above embodiments when calling computer programs stored in memory 502.
[0147] This application embodiment does not limit the specific connection medium between the memory 501 and the processor 502 described above. This application embodiment... Figure 5The memory 501 and the processor 502 are connected via a bus 503, and the bus 503 is in Figure 5 The connections between other components are shown in thick lines only and are not intended to be limiting. The 503 bus can be divided into address bus, data bus, control bus, etc. For ease of illustration, Figure 5 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.
[0148] Based on the same inventive concept, embodiments of this application provide a computer-readable storage medium. The computer program product includes computer program code, which, when executed on a computer, causes the computer to perform any of the data encryption methods discussed above. Since the principle by which the computer-readable storage medium solves the problem is similar to that of the data encryption methods, the implementation of the computer-readable storage medium can be found in the implementation of the methods, and repeated details will not be elaborated further.
[0149] Based on the same inventive concept, this application also provides a computer program product, which includes computer program code that, when executed on a computer, causes the computer to perform any of the data encryption methods discussed above. Since the principle by which the above computer program product solves the problem is similar to that of the data encryption method, the implementation of the above computer program product can be referred to the implementation of the method, and repeated details will not be elaborated further.
[0150] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0151] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0152] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0153] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of user-operated steps to be executed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0154] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. A data encryption method, characterized in that, include: In response to a request from a terminal device to obtain target service data, a key factor for the target key is obtained, wherein the key factor includes a time salt value and a device fingerprint; The time salt value is used to characterize the time information of initiating the acquisition request, and the device fingerprint is used to characterize the identity information of the terminal device. The target key is generated based on the time salt value and the device fingerprint; The target service data is encrypted based on the target key, and the encrypted target service data and the target key are sent to the terminal device.
2. The method as described in claim 1, characterized in that, The step of generating the target key based on the time salt value and the device fingerprint includes: Convert the time salt value and the device fingerprint to the same binary length; The converted time salt value and the device fingerprint are XORed to determine the XOR result. The secure hash algorithm is used to perform hash calculation on the XOR processing result, and the first processing result is determined based on the generated hash value; Based on the first processing result, the target key is determined.
3. The method as described in claim 2, characterized in that, The key factor further includes a service identifier, and determining the target key based on the first processing result includes: Based on the service identifier, the second processing result is determined; The target key is generated based on the first processing result and the second processing result.
4. The method as described in claim 3, characterized in that, The determination of the second processing result based on the service identifier includes: The service identifier is encrypted using a symmetric encryption algorithm, and the second processing result is determined based on the encrypted service identifier.
5. The method as described in claim 3, characterized in that, The step of generating the target key based on the first processing result and the second processing result includes: The target key is generated by performing a modulo operation on the first processing result and the second processing result.
6. The method as described in claim 1, characterized in that, Before sending the encrypted target business data and the target key to the terminal device, the method further includes: Set a lifecycle for the target key; Sending the encrypted target service data and the target key to the terminal device includes: The encrypted target business data and the target key with the lifecycle set are sent to the terminal device. After receiving the target key and the encrypted data, the terminal device verifies the validity of the target key based on the lifecycle. If the terminal device verifies that it has the viewing permission based on the device fingerprint of the terminal device, it decrypts the encrypted data based on the target key to obtain the decrypted target business data.
7. The method as described in claim 1, characterized in that, The device fingerprint is determined based on some or all of the CPU information, MAC information, and IMEI information of the terminal device that initiated the acquisition request.
8. A data encryption device, characterized in that, include: The acquisition module is used to respond to a request for acquiring target business data initiated by a terminal device and acquire the key factors of the target key, wherein the key factors include time salt value and device fingerprint; The time salt value is used to characterize the time information of initiating the acquisition request, and the device fingerprint is used to characterize the identity information of the terminal device. A generation module is used to generate the target key based on the time salt value and the device fingerprint; An encryption module is used to encrypt the target service data based on the target key, and send the encrypted target service data and the target key to the terminal device.
9. An electronic device, characterized in that, include: At least one processor, and a memory communicatively connected to said at least one processor, wherein: The memory stores a computer program that can be executed by the at least one processor to enable the at least one processor to perform the method as described in any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, the computer program including program instructions that, when executed by a computer, cause the computer to perform the method as described in any one of claims 1-7.