Laboratory data encryption method, system and device and storage medium

By combining two-stage secure access authentication with encryption authentication factors bound to mathematical formulas, and addressing biometrics and security issues, the system solves the problem of weak security in laboratory data storage and access, achieving multi-level access control and anti-counterfeiting of encrypted files, thereby improving data security and reliability.

CN121637566APending Publication Date: 2026-03-10YUNNAN ELECTRIC POWER TESTING & RES INST (GRP) CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610011061.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-01-06
Publication Date
2026-03-10

AI Technical Summary

Technical Problem

Existing laboratory data storage and access methods are weakly secure, single authentication mechanisms are easily cracked, and traditional encryption methods lack dynamic integration, making them unable to effectively prevent unauthorized access.

Method used

A two-tiered secure access authentication mechanism is adopted. First, username and password verification is performed. If successful, the login environment and device are checked, and an SMS verification code is triggered. When accessing encrypted files, fingerprint verification and answering security questions are performed. A unique encrypted verification code and lock are generated by binding encryption authentication factors through mathematical formulas. Finally, access control is performed by combining biometrics and security questions.

Benefits of technology

It improves the security of laboratory data, prevents unauthorized logins and cracking, ensures that only users who pass multi-level authentication can access encrypted files, and enhances the anti-counterfeiting properties of data and the closed-loop security of access control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121637566A_ABST
    Figure CN121637566A_ABST
Patent Text Reader

Abstract

The invention discloses a laboratory data encryption method, system and device and a storage medium, and relates to the technical field of laboratory data encryption, and the method comprises the following steps: when a user accesses an encrypted file, carrying out second-order security access authentication, and after the second-order security access authentication is completed, obtaining a decryption formula J, the decryption formula J and the locking formula D are combined and analyzed, the encryption authentication factor is assigned, and then a to-be-verified value is obtained; and comparing the to-be-verified value with a value corresponding to the encrypted verification code of the encrypted file, and generating an access permission instruction or an access prohibition instruction according to a comparison result. According to the method, the encrypted verification code is generated, the data is encrypted and bound, then, two-order security access authentication is set, the user identity and the data type are verified, and the encrypted data can be accessed only when the user passes all authentication and obtains a correct decryption condition; and the dual security of the data in the storage and access processes is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of laboratory data encryption technology, and is based on a laboratory data encryption method, system, device and storage medium. Background Technology

[0002] With the advent of the big data era, the amount of laboratory data generated is increasing dramatically. This data often contains important scientific research results, intellectual property rights, and even trade secrets. Therefore, how to securely and effectively store, manage, and access this data has become crucial, and data security issues are becoming increasingly prominent.

[0003] However, existing data storage and access methods typically rely on a single account password authentication mechanism, which has relatively weak security measures. Once a user's password is leaked or brute-forced, attackers can easily gain access to the data, leading to data breaches. Furthermore, in certain scenarios, such as when users are in insecure external network environments or logging in using new devices, traditional single authentication mechanisms cannot provide sufficient security, significantly increasing the risk of unauthorized data access.

[0004] On the other hand, most traditional data encryption methods only process at the file storage level and lack dynamic integration with user access control. This means that encrypted files can still be illegally cracked or have their verification bypassed during the access process. In addition, although some laboratories have tried to adopt two-factor authentication, they mostly stay at the basic account + verification code level, lacking multi-dimensional judgment of terminal environment and user behavior, and failing to combine with the encryption and authentication mechanism of the data itself. Security gaps still exist. Based on this, a laboratory data encryption method, system, device and storage medium are proposed. Summary of the Invention

[0005] The purpose of this invention is to provide a laboratory data encryption method, system, device, and storage medium to solve the problems mentioned in the background art.

[0006] A laboratory data encryption method includes the following steps: Step 1: When storing experimental data into the data terminal, set an encryption authentication factor for the encrypted file. At the same time, encrypt the encrypted file according to the preset formula to obtain the encryption verification code corresponding to the encryption authentication factor. Bind the encryption authentication factor, encryption verification code, and locking formula D in the preset formula to the encrypted file.

[0007] Step Two: When a user logs into the data terminal, a first-level security access authentication is required. This authentication consists of two layers of verification factors. The first layer is a knowledge authentication factor consisting of the username and password. Once the first layer is successfully verified, the second layer is triggered based on the login environment and device information. This second layer is a holding factor consisting of a verification code. Once the second layer is successfully verified, the user is deemed to have passed the first-level security access authentication and is granted access to ordinary files. Otherwise, a login failure message is displayed.

[0008] Step 3: When a user accesses an encrypted file, a second level of security access authentication is required. After the second level of security access authentication is completed, the decryption formula J is obtained. The decryption formula J is combined with the locking formula D for analysis, and the encryption authentication factor is assigned a value to obtain the value to be verified.

[0009] Step 4: Compare the value to be verified with the value corresponding to the encryption verification code of the encrypted file, and generate an access permission instruction or an access denial instruction based on the comparison result.

[0010] As a further aspect of the present invention, the method for encrypting the encrypted file is as follows: First, the encryption authentication factor is labeled as HVVH, where the values ​​of H and V conform to the preset formulas: H+H+H=V+V and H+V=30. The values ​​of H and V are solved according to the preset formulas to obtain the values ​​of H and V. The encryption authentication factor HVVH is then assigned a value based on the values ​​of H and V to obtain the encryption verification code M corresponding to the encryption authentication factor. At the same time, H+H+H=V+V is used as the locking method D, and the encryption authentication factor HVVH, the encryption verification code M, and the locking method D are bound to the encrypted file.

[0011] As a further aspect of the present invention: the values ​​of H and V are solved according to a preset formula. First, double H+V=30 to get 2H+2V=60. Since H+H+H=V+V, we know 3H=2V. Transform 2H+2V=60 into 5H=60. From 5H=60, we know that the value of H is 12. Since H+V=30, the value of V is 18. Assign values ​​to the encryption authentication factor HVVH based on the values ​​of H and V, and then obtain the value of the encryption authentication factor corresponding to the encryption verification code M, which is 12181812.

[0012] As a further aspect of the present invention: the method for determining whether the first-level verification factor verification is successful is as follows: When a user logs into the data terminal, the first layer of verification is triggered. The user needs to enter a knowledge authentication factor consisting of username and password as the first layer of verification factor. If the username and password entered by the user are both correct, the first layer of verification factor is considered to have passed. If the username and password entered by the user are incorrect, the login fails and the first layer of security access authentication is considered to have failed.

[0013] As a further aspect of the present invention: the method for determining the triggering of the second-level verification factor based on the login environment and login device information is as follows: After the first layer of verification passes, the system automatically checks the user's login environment and login device information. If either the login environment is an external network or the login device information is a new device, the second layer of verification is immediately triggered. When the second layer of verification is triggered, the system automatically sends an SMS verification code to the mobile phone number bound to the user's account. If the user enters the correct SMS verification code, the second layer of verification is considered to have passed. If the user enters an incorrect SMS verification code, the second layer of verification is considered to have failed, and the login fails, indicating that the first-level security access authentication has failed. If neither of the two conditions of the login environment being an external network or the login device information being a new device is met, the first-level security access authentication is still considered to have passed, and the user is granted access to ordinary files.

[0014] As a further aspect of the present invention: the method for obtaining the decryption formula J after the second-level secure access authentication is as follows: When a user accesses an encrypted file, the system requires the user to verify their fingerprint and answer a pre-set security question. If the user's fingerprint verification matches the system's binding information and the security question is answered correctly, the second-level security access authentication is deemed to have passed securely, and H+V=30 is output as the decryption expression J. If the user's fingerprint verification does not match the system's binding information or the security question is answered incorrectly, the second-level security access authentication is deemed to have failed securely, and V+V=30 is output as the decryption expression J.

[0015] As a further aspect of the present invention, the method for obtaining the value to be verified is as follows: When the second-level secure access authentication fails, the decryption formula V+V=30 and the locking formula H+H+H=V+V are combined, resulting in V being 15 and H being 10. Based on the values ​​of V and H, the encryption authentication factor HVVH is assigned a value, thus obtaining the value to be verified, Mˊ, as 10151510. When the second-level secure access authentication succeeds, the values ​​of H and V are calculated using H+H+H=V+V and H+V=30, resulting in H being 12 and V being 18. Based on the values ​​of H and V, the encryption authentication factor HVVH is assigned a value, thus obtaining the value to be verified, Mˊ, as 12181812.

[0016] As a further aspect of the present invention: the method for generating an access permission instruction or an access denial instruction to obtain the value to be verified is as follows: When the value to be verified Mˊ matches the value corresponding to the encrypted verification code M, an access permission instruction is generated, thereby granting the user permission to access the encrypted experimental data in the encrypted file. When the value to be verified Mˊ does not match the value corresponding to the encrypted verification code M, an access denial instruction is generated, thereby prohibiting the user from accessing the encrypted experimental data in the encrypted file.

[0017] As a further aspect of the present invention: a laboratory data encryption system, which implements a laboratory data encryption method, comprising: The encryption module is used to set an encryption authentication factor for the encrypted file when storing experimental data in the data terminal. At the same time, it encrypts the encrypted file according to a preset formula to obtain the encryption verification code corresponding to the encryption authentication factor, and binds the encryption authentication factor, encryption verification code and locking formula in the preset formula to the encrypted file.

[0018] The first-level secure access authentication module is used to perform first-level secure access authentication when a user logs into the data terminal. First-level secure access authentication includes two layers of verification factors. The first layer of verification factor is a knowledge authentication factor consisting of username and password. When the first layer of verification factor is verified, the second layer of verification factor is triggered based on the login environment and login device information. The second layer of verification factor is a holding factor consisting of verification code. When the second layer of verification factor is verified, the user is determined to have passed the first-level secure access authentication and is granted access to ordinary files; otherwise, a login failure message is displayed.

[0019] The second secure access authentication module is used to perform second secure access authentication when a user accesses an encrypted file. After the second-level secure access authentication is completed, the decryption formula J is obtained. The decryption formula J is combined with the locking formula D for analysis, and the encryption authentication factor is assigned a value to obtain the value to be verified.

[0020] The access instruction generation module is used to compare the value to be verified with the value corresponding to the encryption verification code of the encrypted file, and generate an access permission instruction or an access denial instruction based on the comparison result.

[0021] As a further aspect of the present invention: a laboratory data encryption storage medium storing a computer program, wherein when the computer program is run by a processor, the medium executes a laboratory data encryption method.

[0022] As a further aspect of the present invention: a laboratory data encryption terminal includes a memory and a processor. The memory stores a computer program, and when the computer program is executed by the processor, the processor performs any step in a laboratory data encryption method.

[0023] Compared with the prior art, the beneficial effects of the present invention are: (1) In the experimental data entry stage, the data is divided into ordinary data and encrypted data; ordinary data is stored in ordinary file format, while encrypted data is generated by a preset formula to generate an encryption authentication factor; the hierarchical management of ordinary data and sensitive data is realized to avoid a one-size-fits-all approach; the uniqueness and unforgeability of encrypted files are improved by binding them with mathematical formulas; even if the file is illegally copied, it cannot be decrypted and accessed without the encryption authentication factor.

[0024] (2) In this invention, when a user logs in, the first step is to verify the username and password. If the verification is correct, the user can enter the second layer. The system detects the login environment and device information. When the conditions are met, the system will forcibly trigger a second SMS verification code. Only when both layers of verification are passed can the user complete the first-level secure access authentication. The two-factor authentication mechanism avoids illegal login caused by the leakage of a single credential. Environmental awareness and device detection ensure that authentication is more stringent in non-use scenarios, thereby improving access security.

[0025] (3) In this invention, when a user attempts to access an encrypted file, the system requires a higher level of authentication, including fingerprint verification and answering security questions. If both are correct, the system is deemed to have passed the security test and outputs the decryption formula J=H+V=30. If the test fails, the system outputs the decryption formula J=V+V=30. The decryption formula J is combined with the locking formula D to obtain different values ​​of H and V, thereby calculating different values ​​of the value to be verified M′. This binds access permissions with strong authentication methods such as biometrics and security questions, significantly improving the security of accessing sensitive files. By outputting different decryption formulas, even if an unauthorized user breaks through the pre-authentication, they will not be able to obtain the correct decryption result, thus enhancing the anti-counterfeiting capability.

[0026] (4) In this invention, the value M′ to be verified obtained by the user through decryption is compared with the encrypted verification code M bound to the encrypted file; if they match, an access permission instruction is generated and the user is granted access permission; if they do not match, an access denial instruction is generated and access to the encrypted file is denied, thus forming the final access control closed loop, ensuring that only users who pass the correct authentication link can access the encrypted experimental data; and preventing unauthorized users from bypassing the front-end authentication and directly attempting to brute-force crack the file. Attached Figure Description

[0027] Figure 1 This is a schematic diagram of the method framework structure of the present invention; Figure 2 This is a schematic diagram of the system framework structure of the present invention. Detailed Implementation

[0028] The technical solution of the present invention will be clearly and completely described below with reference to the embodiments. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0029] Example 1: Please refer to Figure 1 This application provides a laboratory data encryption method, comprising the following steps: Step 1: When storing experimental data into the data terminal, classify the data into ordinary data and encrypted data. Package ordinary experimental data into ordinary files and encrypted experimental data into encrypted files. After encrypting the encrypted files, set an encryption authentication factor. Simultaneously, after encrypting the encrypted files, bind the encryption verification code and lock to the encrypted files. The specific method is as follows: The encryption process for encrypted files is as follows: First, the encryption authentication factor is marked as HVVH, where the values ​​of H and V conform to the preset formulas: H+H+H=V+V and H+V=30. Based on H+H+H=V+V and H+V=30, the values ​​of H and V are solved to obtain the value corresponding to the encryption authentication factor marked as HVVH for the encrypted file. At the same time, it is bound to the encrypted file as the encryption verification code M. The method for evaluating H and V based on the preset formulas: H + H + H = V + V and H + V = 30 is as follows: First, double H+V=30 to... That is, 2H + 2V = 60. From H + H + H = V + V, we know 3H = 2V. Therefore, 2H + 2V = 60 can be transformed into 5H = 60, meaning the value of H is 12. Since H + V = 30, the value of V is 18. That is, 12 = H and V = 18. Based on the values ​​of H and V, the encryption authentication factor HVVH of the encrypted file is assigned a value, resulting in a value of 12181812. Simultaneously, the encryption authentication factor... The value of the authentication factor HVVH is 12181812, which is bound to the encrypted file as the encryption verification code M. Thus, the encryption verification code M is 12181812. At the same time, H+H+H=V+V is used as the locking formula D of the encrypted file and bound to the encrypted file. The locking formula DH+H+H=V+V and the encryption authentication factor HVVH are explicitly bound to the encrypted file, while the value of the encryption verification code M, 12181812, is implicitly bound to the encrypted file.

[0030] It should be noted that the distinction between ordinary experimental data and encrypted experimental data is made manually by relevant personnel when entering the experimental data, which is existing technology and will not be elaborated on here. During the experimental data entry phase, the data is divided into ordinary data and encrypted data. Ordinary data is stored in ordinary files, while encrypted data is generated using a preset formula to create an encryption authentication factor. This achieves hierarchical management of ordinary and sensitive data, avoiding a one-size-fits-all approach. By binding the encrypted files with mathematical formulas, the uniqueness and unforgeability of the encrypted files are enhanced. Even if the file is illegally copied, it cannot be decrypted and accessed without the encryption authentication factor.

[0031] The encryption authentication factor, encryption verification code M, and locking mechanism D are explicitly or implicitly bound to the encrypted file to form a unique encryption identifier.

[0032] Step 2: When a user logs into the data terminal, a first-level security access authentication is required, which specifically includes two layers of verification factors. The first layer of verification factors is a knowledge authentication factor consisting of username and password, and the second layer of verification factors is a holding factor consisting of information verification code. The specific method for the first-level secure access authentication is as follows: When a user logs into the data terminal, the first layer of verification is triggered. The user needs to enter a knowledge authentication factor consisting of username and password as the first layer of verification. If the username and password are both correct, the first layer of verification is considered successful. After the first layer of verification is successful, the system forcibly triggers the second layer of verification based on the login environment and login device information. If the username and password are incorrect, login failure is displayed, indicating that the first-level security access authentication has failed. The specific method for triggering the second layer of verification is as follows: After the first layer of verification passes, the system automatically checks the user's login environment and login device information. If either the login environment is an external network or the login device information is a new device, the second layer of verification is immediately triggered. When the second layer of verification is triggered, the system automatically sends an SMS verification code to the mobile phone number bound to the login user's account. If the user enters the correct SMS verification code, the second layer of verification is considered to have passed, and the user is considered to have passed the first-level security access authentication. If neither of the two conditions of the login environment being an external network or the login device information being a new device is met, the user is still considered to have passed the first-level security access authentication. If the user enters an incorrect SMS verification code, the second layer of verification fails, and the login fails, indicating that the first-level security access authentication has failed. If neither of the following conditions is met: the login environment is an external network and the login device information is a new device, then the user is deemed to have passed the first-level security access authentication and is granted access to ordinary files. If a user fails the first-level authentication factor verification, a login failure message will be displayed. If the first-level authentication factor verification passes but fails, a login failure message will also be displayed. When a user logs into the data terminal, the system uses a two-layer authentication factor mechanism to perform the first-level secure access authentication. By combining two independent authentication factors, the system enhances the strength of identity verification and prevents security risks caused by the leakage of a single credential.

[0033] When a user logs in, the knowledge factor (username + password) is triggered first. If the verification is successful, the user proceeds to the second level. The system checks the login environment and device information. When the conditions are met (external network or new device), the holding factor (secondary SMS verification code) is forcibly triggered. Only when both levels of verification pass can the user complete the first-level secure access authentication. The two-factor authentication mechanism prevents unauthorized logins caused by the leakage of a single credential. Environment awareness and device detection ensure stricter authentication in less common scenarios, improving access security. Ordinary files can be directly accessed at this stage, ensuring both security and user experience.

[0034] Step 3: After the user passes the first-level security access authentication, access permissions for ordinary files are granted. The user can access ordinary files. When accessing encrypted files, a second-level security access authentication is required. After the second-level security access authentication is completed, the decryption formula J is obtained. The decryption formula J is combined with the locking formula D, which is explicitly bound to the encrypted file. The values ​​of H and V in the encryption authentication factor are solved. The encryption authentication factor is assigned a value according to the values ​​of H and V, and then the value to be verified Mˊ is obtained.

[0035] The specific method for the second-level secure access authentication is as follows: When a user accesses an encrypted file, the system requires the user to verify their fingerprint and answer a pre-set security question. If the user's fingerprint matches the system's binding information and the security question is answered correctly, the second-level security access authentication is considered to have passed securely, and H+V=30 is output as the decryption expression J. If the user's fingerprint does not match the system's binding information or the security question is answered incorrectly, the second-level security access authentication is considered to have failed securely, and V+V=30 is output as the decryption expression J. It should be noted that the fingerprint verification binding information and the corresponding answers to security questions are both bound to the corresponding user's account. This binding is recorded when the user registers the account and is an existing and mature technology, so it will not be elaborated on here.

[0036] When the second-level secure access authentication fails, V+V=30 is output as the decryption expression J. Combining the decryption expression V+V=30 with the locking expression H+H+H=V+V, we can see that the value of V is 15 and the value of H is 10. Based on the value of V being 15 and the value of H being 10, the encryption authentication factor HVVH is assigned a value, thus obtaining the value to be verified Mˊ as 10151510. When the second secure access authentication passes, H+V=30 is output as the decryption formula J. Then, by calculating the values ​​of H and V based on H+H+H=V+V and H+V=30 in step one, the value of H can be obtained as 12 and the value of V as 18. The encryption authentication factor HVVH is assigned a value based on the values ​​of H and V, and the value to be verified Mˊ is obtained as 12181812. When a user attempts to access an encrypted file, the system requires a higher level of authentication, including fingerprint verification and answering security questions. If both are correct, the access is considered secure, and the system outputs the decryption formula J=H+V=30. If the access fails, the system outputs the decryption formula J=V+V=30. The decryption formula J is combined with the locking formula D to obtain different values ​​of H and V, which in turn calculate different values ​​of the value to be verified, M′. This binds access permissions to strong authentication methods such as biometrics and security questions, significantly improving the security of accessing sensitive files. By outputting different decryption formulas, even if an unauthorized user bypasses the pre-authentication, they will not be able to obtain the correct decryption result, thus enhancing anti-counterfeiting capabilities.

[0037] Step 4: Compare the value to be verified M' with the value corresponding to the encryption verification code M of the encrypted file. Based on the comparison result, generate an access permission command or an access denial command, in the following manner: When the value to be verified Mˊ matches the value corresponding to the encrypted verification code M, an access permission instruction is generated, thereby granting the user permission to access the encrypted experimental data in the encrypted file. When the value to be verified Mˊ does not match the value corresponding to the encrypted verification code M, an access denial instruction is generated, thereby prohibiting the user from accessing the encrypted experimental data in the encrypted file.

[0038] The system compares the decrypted value M′ obtained by the user with the encrypted verification code M bound to the encrypted file. If they match, an access permission instruction is generated, and the user is granted access. If they do not match, an access denial instruction is generated, and access to the encrypted file is denied, thus forming a final access control closed loop. This ensures that only users who have passed the correct authentication link can access the encrypted experimental data, preventing unauthorized users from bypassing front-end authentication and attempting to brute-force the file.

[0039] Example 2: Please refer to Figure 2 As shown, this embodiment also provides a laboratory data encryption system, which implements the aforementioned disclosed laboratory data encryption method, including: The encryption module is used to set an encryption authentication factor for the encrypted file when storing experimental data in the data terminal. At the same time, it encrypts the encrypted file according to a preset formula to obtain the encryption verification code corresponding to the encryption authentication factor, and binds the encryption authentication factor, encryption verification code and locking formula in the preset formula to the encrypted file.

[0040] The first-level secure access authentication module is used to perform first-level secure access authentication when a user logs into the data terminal. First-level secure access authentication includes two layers of verification factors. The first layer of verification factor is a knowledge authentication factor consisting of username and password. When the first layer of verification factor is verified, the second layer of verification factor is triggered based on the login environment and login device information. The second layer of verification factor is a holding factor consisting of verification code. When the second layer of verification factor is verified, the user is determined to have passed the first-level secure access authentication and is granted access to ordinary files; otherwise, a login failure message is displayed.

[0041] The second secure access authentication module is used to perform second secure access authentication when a user accesses an encrypted file. After the second-level secure access authentication is completed, the decryption formula J is obtained. The decryption formula J is combined with the locking formula D for analysis, and the encryption authentication factor is assigned a value to obtain the value to be verified.

[0042] The access instruction generation module is used to compare the value to be verified with the value corresponding to the encryption verification code of the encrypted file, and generate an access permission instruction or an access denial instruction based on the comparison result.

[0043] During the data storage phase, a unique mathematical formula is used to generate an encrypted verification code, which then encrypts and binds the data. Secondly, during the user access phase, a two-tiered security authentication system is implemented, verifying the user's identity and data type respectively. Only after passing all authentications and obtaining the correct decryption conditions can the user access the encrypted data. This strategy, combining static encryption binding with dynamic hierarchical decryption, ensures dual security for data during both storage and access.

[0044] Example 3: This example also provides a laboratory data encryption storage medium, which stores a computer program. When the computer program is run by a processor, the storage medium executes any step in a laboratory data encryption method.

[0045] Example 4: This example also provides a laboratory data encryption device, which includes a computer program configured inside the device. When the computer program is executed by the processor, it causes the processor to perform any step in a laboratory data encryption method.

[0046] Example 5: As Example 5 of the present invention, in specific implementation, compared with Example 1, Example 2, Example 3 and Example 4, the technical solution of this example is to combine the solutions of Example 1, Example 2, Example 3 and Example 4.

[0047] The above formulas are all dimensionless calculations. The formulas are derived from software simulations based on a large amount of collected data to obtain the most recent real-world results. The preset parameters and thresholds in the formulas are set by those skilled in the art according to the actual situation.

[0048] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A laboratory data encryption method, characterized by, Comprise the following steps: Step one: when the experimental data is stored in the data terminal, set the encryption authentication factor for the encrypted file, and obtain the encryption verification code corresponding to the encryption authentication factor according to the preset formula after encrypting the encrypted file, bind the encryption authentication factor, encryption verification code and locking type D in the preset formula with the encrypted file; Step two: when the user logs in the data terminal, first-order security access authentication is required, which includes two layers of verification factors, the first layer of verification factor is the knowledge authentication factor composed of username+password, when the first layer of verification factor is verified, the second layer of verification factor is triggered according to the login environment and login device information, the second layer of verification factor is the possession factor composed of the verification code, when the second layer of verification factor is verified, it is determined that the user passes the first-order security access authentication, and the user's access permission to the ordinary file is opened, otherwise, the login fails; Step three: when the user accesses the encrypted file, second security access authentication is required, after the second-order security access authentication is completed, the decryption formula J is obtained, the decryption formula J is combined with the locking formula D to analyze the encryption authentication factor, and then the to-be-verified value is obtained; Step four: compare the to-be-verified value with the value corresponding to the encryption verification code of the encrypted file, and generate access permission instruction or access prohibition instruction according to the comparison result.

2. The laboratory data encryption method of claim 1, wherein, The encryption processing mode of the encrypted file is: First, mark the encryption authentication factor as HVVH, wherein the value of H and V conforms to the preset formula: H+H+H=V+V and H+V=30, according to the preset formula, first double transform H+V=30 to 2H+2V=60, since H+H+H=V+V, 3H=2V, 2H+2V=60 can be transformed into 5H=60, through 5H=60, the value of H is 12, since H+V=30, the value of V is 18, according to the value of H and V, the encryption authentication factor HVVH is valued, and then the value of the encryption authentication factor corresponding to the encryption verification code M is obtained 12181812, at the same time, H+H+H=V+V is taken as the locking formula D, and the encryption authentication factor HVVH, the encryption verification code M and the locking formula D are bound with the encrypted file.

3. The laboratory data encryption method of claim 2, wherein, The way to determine that the first layer of verification factor is verified is: When the user logs in the data terminal, the first layer of verification factor is triggered, the user needs to input the knowledge authentication factor composed of username+password as the first layer of verification factor, when the user inputs the correct username+password, it is determined that the first layer of verification factor is verified, when the user inputs the incorrect username+password, it is displayed that the login fails, and it is determined that the first-order security access authentication is not passed.

4. The laboratory data encryption method of claim 3, wherein, The way to determine that the second layer of verification factor is triggered according to the login environment and login device information is: When the first layer verification factor is verified, the system automatically detects the login environment and login device information of the user. When one of the following conditions is met, the second layer verification factor is triggered immediately: the login environment is an external network or the login device information is a new device. When the second layer verification factor is triggered, the system automatically sends an SMS verification code to the mobile phone number bound to the user's account. When the user inputs the correct SMS verification code, it is determined that the second layer verification factor verification is passed. When the user inputs the incorrect SMS verification code, it is determined that the second layer verification factor verification is not passed, and the login fails, which is determined as not passing the first level security access authentication. When neither of the two conditions is met, it is also determined as passing the first level security access authentication, and the user's access permission to ordinary files is opened.

5. The laboratory data encryption method of claim 2, wherein, The way to obtain the decryption formula J after the second level security access authentication is completed is: When the user accesses the encrypted file, the system requires the user to perform fingerprint verification and answer a pre-set security question. When the user's fingerprint verification is consistent with the system binding information and the security question is answered correctly, it is determined that the second level security access authentication is passed, and H+V=30 is output as the decryption formula J. When the user's fingerprint verification is inconsistent with the system binding information or the security question is answered incorrectly, it is determined that the second level security access authentication is not passed, and V+V=30 is output as the decryption formula J.

6. The laboratory data encryption method of claim 5, wherein, The way to obtain the verification value is: When the second level security access authentication is not passed, the decryption formula V+V=30 and the lock formula H+H+H=V+V are combined, and it is known that the value of V is 15 and the value of H is 10. According to the value of V being 15 and the value of H being 10, the encrypted authentication factor HVVH is assigned, and the verification value Mˊ is obtained as 10151510. When the second level security access authentication is passed, the values of H and V are obtained by solving H+H+H=V+V and H+V=30, i.e. the value of H is 12 and the value of V is 18. According to the values of H and V, the encrypted authentication factor HVVH is assigned, and the verification value Mˊ is obtained as 12181812.

7. The laboratory data encryption method of claim 6, wherein, The way to generate an access permission instruction or an access prohibition instruction is: When the verification value Mˊ is consistent with the value corresponding to the encrypted verification code M, an access permission instruction is generated, and the user's access permission to the encrypted experimental data in the encrypted file is opened. When the verification value Mˊ is not consistent with the value corresponding to the encrypted verification code M, an access prohibition instruction is generated, and the user's access to the encrypted experimental data in the encrypted file is prohibited.

8. A laboratory data encryption system characterized by, The system is used to implement the laboratory data encryption method of any one of claims 1-7, comprising: An encryption module is configured to set an encrypted authentication factor for an encrypted file when storing experimental data in a data terminal, and to obtain an encrypted verification code corresponding to the encrypted authentication factor by encrypting the encrypted file according to a pre-set formula. The encrypted authentication factor, the encrypted verification code, and the lock formula D in the pre-set formula are bound to the encrypted file. The first security access authentication module is configured to perform first security access authentication when a user logs in a data terminal. The first security access authentication includes two layers of verification factors. The first layer of verification factors is a knowledge authentication factor composed of a username and a password. When the first layer of verification factors is verified, a second layer of verification factors is triggered according to login environment and login device information. The second layer of verification factors is a possession factor composed of a verification code. When the second layer of verification factors is verified, it is determined that the user passes the first security access authentication, and the user is allowed to access normal files. Otherwise, the login fails. The second security access authentication module is configured to perform second security access authentication when a user accesses encrypted files. After the second security access authentication is completed, a decryption formula J is obtained. The decryption formula J is combined with a lock formula D to analyze and assign encrypted authentication factors, and then a to-be-verified value is obtained. The access instruction generation module is configured to compare the to-be-verified value with a value corresponding to an encrypted verification code of the encrypted files, and generate an access permission instruction or an access prohibition instruction according to a comparison result.

9. A laboratory data encryption device, characterized by A computer program is configured in a device. When the computer program is run by a processor, the device performs a laboratory data encryption method according to any one of claims 1-7.

10. A laboratory data encrypted storage medium, characterized by, A computer program is stored in a storage medium. When the computer program is run by a processor, the storage medium performs a laboratory data encryption method according to any one of claims 1-7.