Law enforcement data decryption analysis method and system based on GPU acceleration
By employing a GPU-accelerated law enforcement data decryption and analysis method, and utilizing user information and encryption mechanisms to set cryptographic feature constraints, a candidate cryptographic space is generated. Through GPU parallel processing and iterative testing, the problems of excessive key space and low utilization of computing resources are solved, achieving efficient and accurate data decryption.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-26
- Publication Date
- 2026-04-03
AI Technical Summary
Existing data decryption methods suffer from excessively large key spaces, blind search strategies, and low utilization of computing resources, resulting in low cracking efficiency.
By employing a GPU-accelerated law enforcement data decryption and analysis method, this approach utilizes the target user's basic personal information, historical password patterns, and data encryption mechanisms to set password feature constraints, generate a candidate password space, construct a candidate password layer sequence through trust evaluation and ranking, conduct decryption tests using the parallel processing capabilities of the GPU, and iterate through tests by dynamically updating the test sequence based on failure feedback.
It effectively reduces the key space, improves decryption efficiency and success rate, and enhances the speed and quality of case processing for law enforcement agencies.
Smart Images

Figure CN121786858A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data decryption technology, specifically to a GPU-accelerated law enforcement data decryption and analysis method and system. Background Technology
[0002] With the development of information technology, law enforcement agencies are dealing with an ever-increasing amount of data, including a large amount of encrypted law enforcement data, especially encrypted information from electronic devices. However, traditional data decryption methods suffer from problems such as excessively large key spaces, blind search strategies, and low utilization of computing resources, resulting in low decryption efficiency.
[0003] Graphics Processing Units (GPUs), as computing devices, demonstrate advantages in scientific computing, image processing, and other fields due to their powerful computing capabilities and efficient parallel processing. Applying GPU acceleration technology to law enforcement data decryption and analysis, especially for decrypting complex encryption systems, can significantly improve decryption efficiency and shorten decryption time. Summary of the Invention
[0004] This application provides a GPU-accelerated law enforcement data decryption and analysis method and system, which solves the technical problems of low cracking efficiency caused by excessive key space, blind search strategy and low utilization of computing resources in existing data decryption methods.
[0005] The technical solution to the above-mentioned technical problems in this application is as follows: Firstly, this application provides a GPU-accelerated method for decrypting and analyzing law enforcement data, the method comprising: Based on the target user's personal basic information, historical password patterns, and data encryption mechanisms, password feature constraints are set, and the basic key space is reduced according to the password feature constraints to generate a candidate password space. A trust evaluation is performed on several candidate cryptographys within the candidate cryptography space, and the candidate cryptographys are sorted and layered according to several trust weights to construct a candidate cryptography layer sequence; The first candidate cryptographic layer in the candidate cryptographic layer sequence is selected as the first candidate cryptographic layer, and a decryption test is performed on the target user's electronic device using a computing device equipped with a GPU. If decryption fails once, an initial password is selected from the basic key space according to a preset ratio to update the remaining candidate cryptographic layers in the candidate cryptographic layer sequence, thereby generating an updated candidate cryptographic layer sequence. An iterative testing mechanism based on failure feedback and dynamic update of the test sequence is used to perform data decryption iterative tests on the target user's electronic device through the updated candidate cryptographic layer sequence until decryption is successful.
[0006] Secondly, this application provides a GPU-accelerated law enforcement data decryption and analysis system, including: The space generation module is used to set password feature constraints based on the target user's personal basic information, historical password patterns and data encryption mechanisms, and to reduce the basic key space according to the password feature constraints to generate a candidate password space. The trust evaluation module is used to perform trust evaluation on several candidate cryptographys in the candidate cryptography space, sort and layer the several candidate cryptographys according to several trust weights, and construct a candidate cryptography layer sequence. The decryption test module is used to select the first candidate cryptographic layer in the candidate cryptographic layer sequence as the first candidate cryptographic layer, and to perform a decryption test on the target user's electronic device through a computing device configured with a GPU; The sequence update module is used to update the remaining candidate cryptographic layers in the candidate cryptographic layer sequence by selecting an initial password from the basic key space according to a preset ratio if the decryption fails once, thereby generating an updated candidate cryptographic layer sequence. The iterative testing module is used for an iterative testing mechanism that dynamically updates the test sequence based on failure feedback. It performs data decryption iterative tests on the target user's electronic device through the updated candidate cryptographic layer sequence until decryption is successful.
[0007] This application provides one or more technical solutions, which have at least the following technical effects or advantages: This application provides a GPU-accelerated law enforcement data decryption and analysis method and system. First, it sets cryptographic feature constraints based on the target user's personal information, historical password patterns, and data encryption mechanisms, effectively reducing the basic key space and generating a more targeted candidate password space. This avoids blind searching within a vast key space and improves decryption efficiency. Second, it performs a trustworthiness assessment on candidate passwords within the candidate password space and sorts and layers them according to trust weights, constructing a candidate password layer sequence. This allows decryption testing to prioritize high-trust candidate passwords, further improving the success rate and speed of decryption. Third, it utilizes a GPU-equipped computing device for data decryption testing, fully leveraging the powerful computing capabilities and efficient parallel processing of GPUs to accelerate the decryption process.
[0008] In addition, this application introduces an iterative testing mechanism based on failure feedback to dynamically update the test sequence. When decryption fails once, an initial cipher can be selected in the basic key space to update the remaining candidate cipher layers, generate an updated candidate cipher layer sequence, and continue to perform decryption iterative testing until decryption is successful.
[0009] Through the above technical solution, this application solves the problems of low efficiency and inability to cope with complex encryption mechanisms in existing decryption methods, and also provides law enforcement agencies with a faster and more accurate decryption means when handling cases, which helps to improve law enforcement efficiency and case handling quality. Attached Figure Description
[0010] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0011] Figure 1 This is a flowchart illustrating the GPU-accelerated law enforcement data decryption and analysis method provided in this application embodiment; Figure 2 This is a schematic diagram of the structure of the GPU-accelerated law enforcement data decryption and analysis system provided in the embodiments of this application.
[0012] The components represented by each number in the attached diagram are explained below: Module 11 for spatial generation, Module 12 for trust assessment, Module 13 for decryption testing, Module 14 for sequence update, and Module 15 for iterative testing. Detailed Implementation
[0013] This application provides a GPU-accelerated law enforcement data decryption and analysis method and system to address the technical problems of low cracking efficiency caused by excessive key space, blind search strategies, and low utilization of computing resources in traditional data decryption methods.
[0014] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0015] In the description of this application, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include one or more features. In the description of this application, "multiple" means two or more, unless otherwise explicitly specified.
[0016] In the description of this application, the term "for example" is used to mean "used as an example, illustration, or description." Any embodiment described as "for example" in this application is not necessarily to be construed as being more preferred or advantageous than other embodiments. The following description is provided to enable any person skilled in the art to make and use this application. Details are set forth in the following description for purposes of explanation. It should be understood that those skilled in the art will recognize that this application can be made without using these specific details. In other instances, well-known structures and processes will not be described in detail to avoid unnecessarily obscuring the description of this application. Therefore, this application is not intended to be limited to the embodiments shown, but is consistent with the broadest scope of the principles and features disclosed in this application.
[0017] Example 1, as Figure 1 As shown in the embodiments of this application, a GPU-accelerated law enforcement data decryption and analysis method is provided, including: S10: Based on the target user's personal basic information, historical password patterns, and data encryption mechanisms, set password feature constraints, reduce the basic key space according to the password feature constraints, and generate a candidate password space; This technical solution strictly adheres to relevant regulations and is used only for legitimate law enforcement and evidence collection activities with legal authorization. During the implementation of the solution, the principles of data security and compliance are strictly followed to ensure the relevance, necessity, and legality of the investigation. At the technical implementation level, this solution adopts a strict read-only operation mode. Throughout the entire process of cloud data decryption and extraction, a write protection mechanism is used to ensure that the original backup data is not tampered with or destroyed, thus fully preserving the originality and integrity of electronic evidence.
[0018] In this embodiment of the application, firstly, based on the target user's basic personal information, such as the user's name, birthday, and frequently used contact information, combined with historical password patterns, such as the rules of password combinations used in the past, character preferences, length characteristics, etc., and at the same time, analyzing the characteristics of the data encryption mechanism, including encryption algorithms, key generation rules, etc., comprehensively setting password feature constraints.
[0019] Furthermore, based on cryptographic feature constraints, the basic key space is deeply filtered and significantly reduced to remove invalid keys that clearly do not meet the feature constraints, generating a smaller candidate cryptographic space and providing a set of cryptographic keys for subsequent decryption work.
[0020] Specifically, step S10 in the method includes: Based on personal basic information, historical password patterns, and data encryption mechanisms, we construct a basic password feature rule set, a user habit feature rule set, and a system constraint feature rule set, respectively. By integrating the basic cryptographic feature rule set, the user habit feature rule set, and the system constraint feature rule set from multiple dimensions, a cryptographic feature constraint rule library is generated. Using a cryptographic feature constraint rule base as a constraint, the basic key space is reduced to generate a candidate cryptographic space.
[0021] In this embodiment, firstly, a basic password feature rule set, a user habit feature rule set, and a system constraint feature rule set are constructed. The basic password feature rule set extracts features potentially related to passwords from basic personal information. The user habit feature rule set focuses on users' historical password patterns, analyzing their commonly used character types, password length variation patterns, and usage habits of special symbols. The system constraint feature rule set, based on the data encryption mechanism, clarifies the encryption algorithm's requirements for passwords, such as character set restrictions and length ranges.
[0022] Specifically, when constructing a basic set of cryptographic feature rules, personal basic information can be preprocessed to extract elements that may be used for password construction, such as the first letters or full spelling of the name in pinyin, and the numerical combination of the year, month, and day of birth. These elements are then combined according to certain logical rules to form basic cryptographic feature rules. For example, if a user's name is Zhang San and their birthday is June 13, 2001, possible basic cryptographic feature rules would include "zs20010613" and "zhangsan10613".
[0023] To construct a set of user habit feature rules, it is necessary to analyze users' historical password data. By statistically analyzing users' past passwords, frequently occurring character types, such as uppercase letters, lowercase letters, numbers, and special symbols, as well as the distribution range of password length, can be extracted. Simultaneously, the positional patterns of characters in user passwords should be observed, such as whether users tend to place numbers at the beginning or end, and the frequency and position of special symbols. Based on the analysis results, user habit feature rules can be formulated, such as "password length between 8 and 12 characters, and must contain at least one uppercase letter, one lowercase letter, and one number."
[0024] The construction of the system constraint feature rule set revolves closely around the data encryption mechanism. It studies the encryption algorithm used by the encryption mechanism and understands the specific requirements of the data encryption mechanism for the password, such as character set restrictions (allowed characters), upper and lower limits on password length, and whether repeated characters are allowed. The system-level constraints are organized into system constraint feature rules, such as "the password character set consists of printable characters in ASCII code, with a length range of 8-16 bits."
[0025] Secondly, the basic cryptographic feature rule set, user habit feature rule set, and system constraint feature rule set are integrated in multiple dimensions to form a cryptographic feature constraint rule base. This base includes comprehensive constraints ranging from user information and usage habits to system encryption requirements. During this multi-dimensional integration process, a specific integration algorithm is employed, taking into account the weights and priorities of different rule sets.
[0026] For example, the system constraint feature rule set that is directly related to the system encryption requirements is given a higher priority. Since the rules are mandatory requirements of the data encryption mechanism, the password will be invalid if they are not met. As for the user habit feature rule set, although it reflects the user's usage preferences, it may conflict with the system requirements in some cases. In this case, the weight is dynamically adjusted according to the specific situation.
[0027] Furthermore, the basic key space is reduced by using a rule base of cryptographic feature constraints. Each key in the basic key space is examined to determine whether it conforms to the rules in the rule base. Keys that do not conform to the rules are eliminated, thereby generating a smaller and more targeted candidate key space. This provides a more accurate set of keys for subsequent decryption operations, effectively avoiding blind searching in a large basic key space and improving decryption efficiency.
[0028] For example, firstly, the system constraint feature rule set is used for the first level of strong constraint filtering to eliminate candidate passwords that do not conform to the password strategy; secondly, the user habit feature rule set is used for the second level of probability optimization to assign weights to candidate passwords that conform to the user's historical password habit patterns; thirdly, the basic password feature rule set is used for the third level of space expansion to generate new high-probability candidate passwords based on personal information; through the multi-layer filtering and intelligent generation process, a candidate password space that has been reduced in space and optimized in probability is output.
[0029] S20: Perform a trust evaluation on several candidate cryptographys in the candidate cryptography space, sort and layer the candidate cryptographys according to several trust weights, and construct a candidate cryptography layer sequence; In this embodiment, a specific trust evaluation algorithm is used to score each candidate password within the candidate password space. The trust evaluation algorithm comprehensively considers multiple factors, including but not limited to the matching degree between the candidate password and the user's basic information, the similarity to historical password patterns, and whether it conforms to the system constraints of the data encryption mechanism. For example, if a candidate password contains multiple characters from the user's name and is similar in length and character type to the user's previously used passwords, while also meeting encryption requirements, then this password will receive a high trust weight. Based on the calculated trust weights, the candidate passwords are sorted from high to low and divided into different levels according to the weight range, constructing a candidate password layer sequence.
[0030] This includes conducting a trust evaluation of several candidate cryptographys within the candidate cryptography space, including: Based on the basic cryptographic feature rule set, the semantic relevance and structural similarity between several candidate cryptographys in the candidate cryptography space and personal basic information are calculated respectively, and several basic matching degrees are obtained by weighted calculation. Based on the user habit feature rule set, the consistency evaluation of several candidate passwords and historical password patterns in the candidate password space is carried out respectively, and several habit matching degrees are output. Among them, the consistency evaluation indicators include length features, character distribution and special symbols. A weighted fusion of several basic matching degrees and several habitual matching degrees is performed to output several trust weights for several candidate passwords.
[0031] In this embodiment, firstly, a basic matching degree is calculated based on a basic set of cryptographic feature rules, by analyzing the correlation between candidate passwords and personal basic information. Regarding semantic relevance, the system examines whether candidate passwords contain character combinations of information such as the user's name or birthday, as well as the rationality and frequency of these character combinations. Regarding structural similarity, the system compares the structural features of candidate passwords with possible password structures extracted from personal basic information, such as character order and length patterns. By setting weighting coefficients, the calculation results of semantic relevance and structural similarity are weighted and summed to obtain the basic matching degree of each candidate password.
[0032] For example, assuming a basic password feature rule set, the semantic relevance weight is set to 0.6 and the structural similarity weight is set to 0.4. For a candidate password "zs20010613", analysis shows that it contains the initials "zs" of the user's name in pinyin and a number combination similar to the user's birthday "20010613", resulting in a high semantic relevance score. Structurally, it also shows good consistency with possible password structures extracted from the user's basic information, resulting in a high structural similarity score. Through weighted calculation, if the semantic relevance score is 0.8 and the structural similarity score is 0.7, then the basic matching degree of this candidate password is 0.6 × 0.8 + 0.4 × 0.7 = 0.76. Similarly, the basic matching degrees of other candidate passwords in the candidate password space are calculated.
[0033] Secondly, based on the user habit feature rule set, a comprehensive consistency evaluation is conducted on the candidate passwords and historical password patterns. The consistency evaluation indicators include length features, character distribution, and special symbols.
[0034] Regarding length characteristics, the length of candidate passwords is statistically analyzed and compared with the length distribution range of the user's historical passwords to determine whether it falls within the user's habitual length range. Regarding character distribution, the proportion of various character types in candidate passwords, such as uppercase letters, lowercase letters, numbers, and special symbols, is analyzed and compared with the character distribution in the user's historical passwords. Regarding special symbols, the types and positions of special symbols used in candidate passwords are examined and matched with the user's historical usage habits of special symbols. Based on the importance of each consistency evaluation indicator, appropriate weights are assigned, and the evaluation results of each indicator are weighted and integrated to obtain the habitual matching degree of each candidate password.
[0035] The weights of length features, character distribution, and special symbols are dynamically adjusted based on the actual decryption scenario and user password behavior characteristics. For example, in a law enforcement data decryption scenario, if in-depth analysis of a target user's historical password patterns reveals that their password length is concentrated in the 8-12 digit range more than 90% of the time, and this length range closely matches the password length range required by the data encryption mechanism, then the weight of the length feature can be set to a higher value, such as 0.4, the weight of character distribution can be set to 0.35, and the weight of special symbols can be set to 0.25.
[0036] For example, assuming the target user's length feature evaluation score is 0.9, the character distribution evaluation score is 0.85, and the special symbol evaluation score is 0.95, then the habit matching degree = 0.4×0.9 + 0.35×0.85 + 0.25×0.95 = 0.895.
[0037] Finally, the basic matching degree and habitual matching degree are weighted and fused again according to pre-set weights, taking into account the impact of user basic information and historical password habits on the credibility of candidate passwords, and outputting the credibility weight of each candidate password. Based on the magnitude of the credibility weight, the candidate passwords are sorted from high to low and divided into different levels according to the weight range, constructing a candidate password layer sequence. This provides an ordered set of passwords for subsequent decryption tests, ensuring that decryption tests can prioritize starting with candidate passwords with high credibility, further improving the success rate and speed of decryption.
[0038] Furthermore, during the fusion process, different weight values are assigned to the basic matching degree and habitual matching degree based on the actual application scenario and data characteristics. For example, if the target user's basic personal information has a significant impact on their password settings, the weight of the basic matching degree can be set to 0.55, and the weight of the habitual matching degree can be set to 0.45; if the user tends to follow historical password patterns, the weight of the habitual matching degree can be appropriately increased. By multiplying the basic matching degree and habitual matching degree of each candidate password by their corresponding weights and then summing them, the credibility weight of the candidate password can be obtained. The higher the credibility weight, the greater the likelihood that the candidate password matches the user's password characteristics, and the higher its priority in subsequent decryption tests.
[0039] For example, if the basic matching degree of a candidate password is 0.76, the habitual matching degree is 0.895, and the weight of the basic matching degree is set to 0.55 and the weight of the habitual matching degree is set to 0.45, then its trust weight is 0.76×0.55+0.895×0.45=0.82075.
[0040] For example, suppose that through the above calculations, the trust weight of candidate cipher A is 0.82075, the trust weight of candidate cipher B is 0.7, and the trust weight of candidate cipher C is 0.5. Sorting the trust weights from highest to lowest, candidate cipher A is placed in the first layer, candidate cipher B in the second layer, and candidate cipher C in the third layer, thus constructing a candidate cipher layer sequence. In subsequent decryption tests, candidate cipher A with the high trust weight is tested first. If A fails to decrypt, then B and C are tested in sequence, thereby improving the decryption success rate and speed.
[0041] Furthermore, several candidate cryptography samples are sorted and layered according to several trust weights to construct a candidate cryptography layer sequence, including: A candidate password sequence is generated by sorting several candidate passwords according to their trust weights from largest to smallest. The candidate cryptographic sequences are layered according to a preset step size to generate a candidate cryptographic layer sequence.
[0042] In this embodiment, all candidate cryptography within the candidate cryptography space are first sorted according to their trust weights from largest to smallest, forming an ordered sequence of candidate cryptography. During the sorting process, it is ensured that the trust weight of each candidate cryptography is accurately reflected, with candidate cryptography with higher weights placed at the beginning of the sequence and candidate cryptography with lower weights placed at the end.
[0043] For example, if the confidence weight of candidate cipher D is 0.85 and the confidence weight of candidate cipher E is 0.65, then in the candidate cipher sequence, D should be ranked before E.
[0044] Secondly, the candidate password sequence is layered according to a preset step size. The preset step size can be set according to actual needs, for example, each layer contains 1000 candidate passwords. During layering, starting from the beginning of the candidate password sequence, candidate passwords are selected sequentially according to the step size to divide it into different layers. For example, if the preset step size is 1000, the first layer contains the first 1000 candidate passwords in the sequence, the second layer contains the next 1000 candidate passwords, and so on.
[0045] By employing a hierarchical processing approach, a candidate cipher layer sequence is constructed. This sequence not only preserves the trust weight information of the candidate ciphers but also presents them in a hierarchical format, providing a more ordered and efficient set of ciphers for subsequent decryption testing. During subsequent decryption testing, candidate ciphers can be tested sequentially according to their hierarchical order, prioritizing those with higher trust weights and higher rankings, thereby improving the success rate and speed of decryption.
[0046] S30: Select the first candidate cryptographic layer in the candidate cryptographic layer sequence as the first candidate cryptographic layer, and perform a decryption test on the target user's electronic device using a computing device equipped with a GPU; In this embodiment of the application, when performing the decryption test, the first candidate cryptographic layer in the candidate cryptographic layer sequence is selected as the first candidate cryptographic layer, that is, the layer containing the candidate cryptographic layer with the highest trust weight. The selection is based on the previous trust evaluation and ranking results of the candidate cryptographic layers to ensure that the decryption process starts with the cryptographic layer that is most likely to succeed.
[0047] Subsequently, a decryption test is initiated on the target user's electronic device using a computing device equipped with a GPU. The parallel computing power of the GPU plays a role in this process, accelerating the password attempt and verification speed and improving decryption efficiency.
[0048] Specifically, the computing device sequentially sends each candidate cipher from the first candidate cipher layer to the electronic device to attempt to pass the verification mechanism. Each attempt utilizes the powerful computing capabilities of the GPU to quickly complete complex operations such as cipher hashing and encryption matching, ensuring that a large number of ciphers can be tested in a short time.
[0049] During the decryption test, if a candidate password successfully passes verification, the decryption process immediately terminates and returns the successfully decrypted password and corresponding data. If all passwords in the first candidate password layer fail to pass, subsequent candidate password layers are selected sequentially according to the candidate password layer sequence for decryption testing until the correct password is found or all candidate password layers have been traversed.
[0050] By employing a GPU-accelerated decryption testing method, combined with precise screening and sorting of candidate passwords in the early stages, the success rate and speed of data decryption are improved, providing support for law enforcement data decryption and analysis.
[0051] S40: If decryption fails once, select an initial cipher from the basic key space according to a preset ratio to update the remaining candidate cipher layers in the candidate cipher layer sequence, and generate an updated candidate cipher layer sequence. In this embodiment, when decryption fails once, it means that none of the passwords in the current candidate password layer sequence have passed verification. At this time, a new initial password is selected from the basic key space according to a preset ratio, and the remaining candidate password layers are updated. The preset ratio can be set according to the actual situation, for example, selecting 10% of the passwords in the basic key space as the initial password.
[0052] The specific update process is as follows: First, based on the failure feedback of the current layer, an initial cipher is randomly selected from the basic key space according to a preset ratio, serving as the basis for generating the updated candidate cipher layer. Then, combining the basic cipher feature rule set, the user habit feature rule set, and the system constraint feature rule set, the selected initial cipher is integrated with the remaining candidate cipher layers, and the probability weights of all ciphers are recalculated to generate a new, optimized candidate cipher layer sequence.
[0053] Furthermore, during the update process, the weight and priority relationship between the newly generated candidate cryptography and the original candidate cryptography layer is considered to ensure that the updated candidate cryptography layer sequence remains ordered and efficient.
[0054] By updating the candidate cipher sequence, the search range for ciphers is expanded, increasing the likelihood of finding the correct cipher. Simultaneously, since the update process remains based on the previously established cipher feature constraint rule base, it ensures that the newly generated candidate ciphers still conform to user basic information, usage habits, and system encryption requirements, thereby improving decryption accuracy and efficiency.
[0055] For example, suppose that in a decryption test, all passwords in the first candidate password layer fail to be attempted. At this point, 1000 initial passwords are selected from the basic key space, representing 10% of the total. By filtering and expanding these initial passwords, 2000 new candidate passwords that meet the specified rules are generated. These new candidate passwords are then merged with the remaining candidate password layers to form an updated candidate password layer sequence containing 3000 candidate passwords. In subsequent decryption tests, the updated candidate password layer sequence is used sequentially until the correct password is found or all candidate password layers have been traversed.
[0056] Specifically, according to a preset ratio, an initial cipher is selected from the basic key space to update the remaining candidate cipher layers in the candidate cipher layer sequence, generating an updated candidate cipher layer sequence, including: Initial ciphers, which are not candidate ciphers, are selected from the basic key space according to a preset ratio to construct an initial cipher set; The second candidate cipher space is constructed by fusing multiple initial ciphers from the initial cipher set with multiple remaining candidate ciphers from the remaining candidate cipher layer. The second candidate cryptographic space is processed in layers to generate an updated candidate cryptographic layer sequence.
[0057] In this embodiment, firstly, initial ciphers (not candidate ciphers) are selected from the basic key space according to a preset ratio. These initial ciphers are ciphers that have never entered the previous candidate cipher layer sequence. An initial cipher set is constructed to ensure that the selection process is random and uniform, avoiding over-exploitation of local cipher space due to concentrated selection.
[0058] Subsequently, multiple initial ciphers from the initial cipher set are merged with multiple remaining candidate ciphers from the remaining candidate cipher layer. The fusion process not only includes simple cipher merging, but also requires combining the basic cipher feature rule set, user habit feature rule set, and system constraint feature rule set to further filter and optimize the merged ciphers, ensuring that the newly generated ciphers conform to both user characteristics and system requirements, thereby constructing a second candidate cipher space.
[0059] Finally, the second candidate cryptographic space is layered, using a method similar to that used when constructing the candidate cryptographic layer sequence. The layers are sorted and layered according to trust weights or other preset criteria to generate an updated candidate cryptographic layer sequence. This sequence not only includes the remaining high-trust candidate cryptography but also incorporates new initial cryptography with higher decryption potential, providing richer and more efficient cryptographic resources for subsequent decryption tests.
[0060] Furthermore, the preset ratio is set based on the current number of tests and gradually increases as the number of tests increases.
[0061] In this embodiment of the application, the preset ratio is dynamically set according to the current number of tests. In the early stage of decryption test, since the candidate password layer sequence already contains a certain number of high-confidence passwords that have been screened and sorted, the preset ratio can be set to a relatively low value, such as 5% or 10%.
[0062] If multiple decryption attempts fail consecutively as the number of tests increases, it indicates that the current candidate cryptographic layer sequence may be limited and unable to cover the correct decryption password. In this case, the preset percentage is gradually increased, such as to 15%, 20%, or even higher, to select more initial passwords within the basic key space and to more comprehensively update the candidate cryptographic layer sequence.
[0063] By dynamically adjusting the preset ratio, the password search range can be flexibly controlled based on the actual decryption situation. This avoids wasting computational resources due to an excessively large search range in the initial stage, while increasing the probability of finding the correct password by expanding the search range later. Furthermore, since the adjustment of the preset ratio is based on feedback from previous decryption tests, it ensures that the entire decryption process remains efficient and orderly.
[0064] For example, suppose the initial preset ratio is 10%. In a decryption test, both the first and second candidate cryptographic layers fail. At this point, the preset ratio is increased to 15%, and more initial cryptographic layers are selected from the basic key space to update the remaining candidate cryptographic layers. If the updated candidate cryptographic layer sequence still fails to decrypt successfully, the preset ratio is increased to 20% until the correct cryptographic layer is found or the preset maximum number of tests is reached.
[0065] The process involves layering the second candidate cryptographic space to generate an updated candidate cryptographic layer sequence, including: Calculate and obtain several trusted weights for several second candidate cryptographys within the second candidate cryptography space; Based on several first candidate cryptographys in the first candidate cryptography layer, several second candidate cryptographys are compared for similarity, and several average similarity values are calculated. The ratio of the preset similarity scalar to the mean similarity is set as the weight compensation coefficient, and several weight compensation coefficients are calculated based on several mean similarities. Based on several weight compensation coefficients, several trusted weights of several second candidate cryptography are compensated to obtain several optimized trusted weights; Based on several optimized trust weights, several second candidate cryptographys in the second candidate cryptography space are sorted and layered to generate an updated candidate cryptography layer sequence.
[0066] In this embodiment of the application, firstly, several trust weights of several second candidate cryptographys in the second candidate cryptography space are calculated. Similar to the previous method for calculating the trust weights of candidate cryptographys, the trust level of each second candidate cryptography is determined by comprehensively considering basic cryptographic features, user habit features, and system constraint features.
[0067] Secondly, using several first-candidate ciphers from the first candidate cipher layer as benchmarks, a similarity comparison is performed on each second-candidate cipher in the second-candidate cipher space. Specifically, by comparing features such as cipher length, character distribution, and use of special symbols, the average similarity between each second-candidate cipher and the first candidate cipher layer is calculated. The aim is to evaluate the similarity between the newly generated second-candidate cipher and the previously high-confidence candidate ciphers. The greater the similarity, the closer the representation is to the first-candidate cipher, and therefore the greater the reduction in weight, and the lower the probability of secondary selection.
[0068] Then, the ratio of the preset similarity scalar to the mean similarity is set as the weight compensation coefficient. The preset similarity scalar is set according to actual needs, such as 0.8 or 0.9. The corresponding weight compensation coefficient is obtained by calculating the ratio of the mean similarity of each second candidate cipher to the preset similarity scalar. The purpose is to appropriately compensate the trust weight of the second candidate cipher based on its similarity to the first candidate cipher layer, thereby increasing its priority in subsequent decryption tests.
[0069] For example, assuming the preset similarity scalar is set to 0.8, and the average similarity between a second candidate cipher and the first candidate cipher layer is 0.7, then the weight compensation coefficient of the second candidate cipher is 0.7 divided by 0.8, which is 0.875.
[0070] Furthermore, based on several calculated weight compensation coefficients, the trust weight of each second candidate cipher in the second candidate cipher space is compensated to obtain several optimized trust weights.
[0071] For example, the method for calculating the optimized trust weight is as follows: multiply the original trust weight by the corresponding weight compensation coefficient to obtain the compensated trust weight. If the original trust weight of a second candidate cipher is 0.6, and since this cipher has a high similarity to the first candidate cipher layer, its corresponding weight compensation coefficient is 1.2, then the compensated trust weight is 0.6 multiplied by 1.2 equals 0.72, thereby increasing the priority of this cipher in subsequent decryption tests.
[0072] Finally, based on several calculated optimized trust weights, the second candidate ciphers within the second candidate cipher space are sorted and layered. The sorting method is similar to the previous one, arranging them in descending order of optimized trust weights. During layering, the number of candidate ciphers in each layer can be set according to actual needs, for example, 500 or 1000 candidate ciphers per layer. Through layering, an updated candidate cipher layer sequence is generated.
[0073] S50: An iterative testing mechanism based on failure feedback dynamically updates the test sequence. It performs iterative data decryption tests on the target user's electronic device by updating the candidate cryptographic layer sequence until decryption is successful.
[0074] In this embodiment, an iterative testing mechanism based on failure feedback dynamically updates the test sequence. This mechanism updates the candidate password layer sequence to perform data decryption tests on the target user's electronic device. If all candidate passwords at a certain layer fail to decrypt successfully, the system does not immediately terminate the test but dynamically adjusts the testing strategy based on the failure feedback. Specifically, it records information about the current layer's decryption failures, including the number of passwords tried and the reasons for failure, and optimizes subsequent test sequences accordingly.
[0075] Furthermore, during the iterative testing process, failure feedback is first analyzed to determine whether there are obvious defects or limitations in the current candidate cryptographic layers. For example, if all cryptographic keys in a certain layer are rejected because they do not meet the system's constraint characteristics, then such characteristics will be given more consideration in subsequent updates. Based on the above analysis, the system adjusts the sequence of candidate cryptographic layers, which may include increasing the number of cryptographic keys that meet specific characteristics, adjusting the priority of the cryptographic keys, or resetting the layering criteria.
[0076] The adjusted and updated candidate cipher sequence is then used again for data decryption testing. This time, candidate ciphers for each layer are tried sequentially according to the new sequence. Because each iteration optimizes based on the feedback from the previous failure, ciphers in the new sequence are more likely to meet the decryption requirements, thus improving the decryption success rate.
[0077] The iterative testing mechanism continues until the correct password is found or all updated candidate password sequences have been traversed. Throughout the process, the system maintains sensitivity to failure feedback and the ability to dynamically adjust the test sequence, ensuring the efficiency and accuracy of the decryption process.
[0078] In summary, compared with existing technologies, this application significantly shortens the decryption time while maintaining a high success rate through intelligent key space optimization and computing resource allocation, making full use of computing resources, improving decryption efficiency, and providing efficient and reliable technical support for data forensics.
[0079] In summary, the embodiments of this application have at least the following technical effects: This application provides a GPU-accelerated law enforcement data decryption and analysis method. First, it sets cryptographic feature constraints based on the target user's personal information, historical password patterns, and data encryption mechanisms, effectively reducing the basic key space and generating a more targeted candidate password space. This avoids blind searching within a vast key space and improves decryption efficiency. Second, it performs a trustworthiness assessment on candidate passwords within the candidate password space and sorts and layers them according to trust weights, constructing a candidate password layer sequence. This allows decryption testing to prioritize high-trust candidate passwords, further improving the success rate and speed of decryption. Third, it utilizes GPU-equipped computing devices for data decryption testing, fully leveraging the powerful computing capabilities and efficient parallel processing of GPUs to accelerate the decryption process. Furthermore, this application introduces an iterative testing mechanism based on failure feedback to dynamically update the test sequence. When a decryption attempt fails, an initial password is selected from the basic key space to update the remaining candidate password layers, generating an updated candidate password layer sequence. The iterative decryption test continues until successful decryption. Through the above technical solution, this application solves the problems of low efficiency and inability to cope with complex encryption mechanisms in existing decryption methods, and also provides law enforcement agencies with a faster and more accurate decryption means when handling cases, which helps to improve law enforcement efficiency and case handling quality.
[0080] Example 2, as Figure 2 As shown, based on the same inventive concept as the GPU-accelerated law enforcement data decryption and analysis method provided in Embodiment 1, this application also provides a GPU-accelerated law enforcement data decryption and analysis system, including: The space generation module 11 is used to set cryptographic feature constraints based on the target user's personal basic information, historical cryptographic patterns and data encryption mechanisms, and to reduce the basic key space according to the cryptographic feature constraints to generate candidate cryptographic spaces. The trust evaluation module 12 is used to perform trust evaluation on several candidate cryptographys in the candidate cryptography space, sort and layer the candidate cryptographys according to several trust weights, and construct a candidate cryptography layer sequence. The decryption test module 13 is used to select the first candidate cryptographic layer in the candidate cryptographic layer sequence as the first candidate cryptographic layer, and to perform a decryption test on the target user's electronic device through a computing device configured with a GPU; The sequence update module 14 is used to update the remaining candidate cryptographic layers in the candidate cryptographic layer sequence by selecting an initial password in the basic key space according to a preset ratio if the decryption fails once, and to generate an updated candidate cryptographic layer sequence. The iterative testing module 15 is used for an iterative testing mechanism that dynamically updates the test sequence based on failure feedback. It performs data decryption iterative tests on the target user's electronic device by updating the candidate cryptographic layer sequence until decryption is successful.
[0081] In one embodiment, the space generation module 11 is specifically used for: Based on personal basic information, historical password patterns, and data encryption mechanisms, we construct a basic password feature rule set, a user habit feature rule set, and a system constraint feature rule set, respectively. By integrating the basic cryptographic feature rule set, the user habit feature rule set, and the system constraint feature rule set from multiple dimensions, a cryptographic feature constraint rule library is generated. Using a cryptographic feature constraint rule base as a constraint, the basic key space is reduced to generate a candidate cryptographic space.
[0082] Furthermore, in one embodiment of the application, a trustworthiness assessment is performed on several candidate cryptographys within the candidate cryptography space, including: Based on the basic cryptographic feature rule set, the semantic relevance and structural similarity between several candidate cryptographys in the candidate cryptography space and personal basic information are calculated respectively, and several basic matching degrees are obtained by weighted calculation. Based on the user habit feature rule set, the consistency evaluation of several candidate passwords and historical password patterns in the candidate password space is carried out respectively, and several habit matching degrees are output. Among them, the consistency evaluation indicators include length features, character distribution and special symbols. A weighted fusion of several basic matching degrees and several habitual matching degrees is performed to output several trust weights for several candidate passwords.
[0083] In one embodiment, Furthermore, in one embodiment of the application, several candidate cryptographys are sorted and layered according to several trust weights to construct a candidate cryptography layer sequence, including: A candidate password sequence is generated by sorting several candidate passwords according to their trust weights from largest to smallest. The candidate cryptographic sequences are layered according to a preset step size to generate a candidate cryptographic layer sequence.
[0084] The preset ratio is set based on the current number of tests and gradually increases as the number of tests increases.
[0085] Furthermore, in one embodiment, the second candidate cryptographic space is subjected to layered processing to generate an updated candidate cryptographic layer sequence, including: Calculate and obtain several trusted weights for several second candidate cryptographys within the second candidate cryptography space; Based on several first candidate cryptographys in the first candidate cryptography layer, several second candidate cryptographys are compared for similarity, and several average similarity values are calculated. The ratio of the preset similarity scalar to the mean similarity is set as the weight compensation coefficient, and several weight compensation coefficients are calculated based on several mean similarities. Based on several weight compensation coefficients, several trusted weights of several second candidate cryptography are compensated to obtain several optimized trusted weights; Based on several optimized trust weights, several second candidate cryptographys in the second candidate cryptography space are sorted and layered to generate an updated candidate cryptography layer sequence.
[0086] It should be noted that the order of the embodiments described above is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. Furthermore, the above description focuses on specific embodiments of this specification. Additionally, the processes depicted in the accompanying drawings do not necessarily require a specific or sequential order to achieve the desired results. In some implementations, multitasking and parallel processing are possible or may be advantageous.
[0087] The above description is only a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.
[0088] This specification and accompanying drawings are merely illustrative examples of this application and are intended to cover any and all modifications, variations, combinations, or equivalents within the scope of this application. Clearly, those skilled in the art can make various alterations and modifications to this application without departing from its scope. Therefore, if such modifications and modifications fall within the scope of this application and its equivalents, this application intends to include such modifications and modifications.
Claims
1. A GPU-accelerated method for decrypting and analyzing law enforcement data, characterized in that, The methods include: Based on the target user's personal basic information, historical password patterns, and data encryption mechanisms, password feature constraints are set, and the basic key space is reduced according to the password feature constraints to generate a candidate password space. A trust evaluation is performed on several candidate cryptographys within the candidate cryptography space, and the candidate cryptographys are sorted and layered according to several trust weights to construct a candidate cryptography layer sequence; The first candidate cryptographic layer in the candidate cryptographic layer sequence is selected as the first candidate cryptographic layer, and a decryption test is performed on the target user's electronic device using a computing device equipped with a GPU. If decryption fails once, an initial password is selected from the basic key space according to a preset ratio to update the remaining candidate cryptographic layers in the candidate cryptographic layer sequence, thereby generating an updated candidate cryptographic layer sequence. An iterative testing mechanism based on failure feedback and dynamic update of the test sequence is used to perform data decryption iterative tests on the target user's electronic device through the updated candidate cryptographic layer sequence until decryption is successful.
2. The GPU-accelerated law enforcement data decryption and analysis method according to claim 1, characterized in that, Based on the target user's basic personal information, historical password patterns, and data encryption mechanisms, cryptographic feature constraints are set. The basic key space is then reduced according to these constraints to generate a candidate cryptographic space, including: Based on the aforementioned basic personal information, historical password patterns, and data encryption mechanisms, a basic password feature rule set, a user habit feature rule set, and a system constraint feature rule set are constructed respectively. The basic cryptographic feature rule set, user habit feature rule set, and system constraint feature rule set are fused together in multiple dimensions to generate a cryptographic feature constraint rule library. Using the cryptographic feature constraint rule base as a constraint, the basic key space is reduced to generate a candidate cryptographic space.
3. The GPU-accelerated law enforcement data decryption and analysis method according to claim 2, characterized in that, A trust evaluation is performed on several candidate ciphers within the candidate cipher space, including: Based on the aforementioned basic cryptographic feature rule set, the semantic relevance and structural similarity between several candidate cryptographics in the candidate cryptographic space and personal basic information are calculated respectively, and several basic matching degrees are obtained by weighted calculation. Based on the user habit feature rule set, the consistency evaluation of several candidate passwords and historical password patterns in the candidate password space is performed respectively, and several habit matching degrees are output. Among them, the consistency evaluation index includes length feature, character distribution and special symbols. The several basic matching degrees and several habitual matching degrees are weighted and fused to output several trust weights for the several candidate passwords.
4. The GPU-accelerated law enforcement data decryption and analysis method according to claim 1, characterized in that, The candidate ciphers are sorted and layered according to several trust weights to construct a candidate cipher layer sequence, including: The candidate passwords are sorted according to the trust weights from largest to smallest to generate a candidate password sequence. The candidate cryptographic sequence is layered according to a preset number of steps to generate a candidate cryptographic layer sequence.
5. The GPU-accelerated law enforcement data decryption and analysis method according to claim 1, characterized in that, According to a preset ratio, an initial cipher is selected from the basic key space to update the remaining candidate cipher layers in the candidate cipher layer sequence, generating an updated candidate cipher layer sequence, including: An initial cipher set is constructed by selecting non-candidate ciphers from the basic key space according to a preset ratio. The initial ciphers in the initial cipher set and the remaining candidate ciphers in the remaining candidate cipher layer are merged to construct a second candidate cipher space; The second candidate cryptographic space is processed in layers to generate an updated candidate cryptographic layer sequence.
6. The GPU-accelerated law enforcement data decryption and analysis method according to claim 5, characterized in that, The preset ratio is set based on the current number of tests and gradually increases as the number of tests increases.
7. The GPU-accelerated law enforcement data decryption and analysis method according to claim 5, characterized in that, The second candidate cryptographic space is processed in layers to generate an updated candidate cryptographic layer sequence, including: Calculate and obtain several trusted weights for several second candidate cryptographys within the second candidate cryptography space; Based on several first candidate cryptographys of the first candidate cryptography layer, several second candidate cryptographys are compared for similarity, and several average similarity values are calculated. The ratio of the preset similarity scalar to the mean similarity is set as the weight compensation coefficient, and several weight compensation coefficients are calculated based on the several mean similarities. Based on the aforementioned weight compensation coefficients, several trusted weights of the aforementioned second candidate cryptography are compensated to obtain several optimized trusted weights. Based on the aforementioned optimized trust weights, several second candidate cryptographys within the second candidate cryptography space are sorted and layered to generate an updated candidate cryptography layer sequence.
8. A GPU-accelerated law enforcement data decryption and analysis system, characterized in that, The method for performing the GPU-accelerated law enforcement data decryption and analysis according to any one of claims 1-7 includes: The space generation module is used to set password feature constraints based on the target user's personal basic information, historical password patterns and data encryption mechanisms, and to reduce the basic key space according to the password feature constraints to generate a candidate password space. The trust evaluation module is used to perform trust evaluation on several candidate cryptographys in the candidate cryptography space, sort and layer the several candidate cryptographys according to several trust weights, and construct a candidate cryptography layer sequence. The decryption test module is used to select the first candidate cryptographic layer in the candidate cryptographic layer sequence as the first candidate cryptographic layer, and to perform a decryption test on the target user's electronic device through a computing device configured with a GPU; The sequence update module is used to update the remaining candidate cryptographic layers in the candidate cryptographic layer sequence by selecting an initial password from the basic key space according to a preset ratio if the decryption fails once, thereby generating an updated candidate cryptographic layer sequence. The iterative testing module is used for an iterative testing mechanism that dynamically updates the test sequence based on failure feedback. It performs data decryption iterative tests on the target user's electronic device through the updated candidate cryptographic layer sequence until decryption is successful.