Data processing method and device, medium and program product

By employing a multi-algorithm collaborative mechanism involving hash algorithms, key derivation algorithms, and chaotic systems, the problems of insufficient encryption strength and inability to verify data integrity in data storage are solved, achieving triple protection of data confidentiality, integrity, and availability.

CN122053030APending Publication Date: 2026-05-15INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
INDUSTRIAL AND COMMERCIAL BANK OF CHINA
Filing Date
2026-01-26
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

Existing data storage methods suffer from insufficient encryption strength and data reliability. In particular, encryption algorithms are easily cracked, and the lack of dynamic verification mechanisms makes it impossible to detect data tampering.

Method used

A hash algorithm is used to generate verification data, and a key derivation algorithm and a chaotic system are combined to generate an encryption sequence. Dynamic encryption and verification are performed through a multi-algorithm collaborative mechanism to form a closed-loop protection.

Benefits of technology

Significantly improves the confidentiality, integrity, and availability of data, resists complex attacks, achieves end-to-end data protection, and ensures the security and integrity of data during storage and decryption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122053030A_ABST
    Figure CN122053030A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a data processing method and device, a medium and a program product, and relates to the field of information security. The method comprises the following steps: processing original data through a Hash algorithm to generate first verification data; generating an encryption key through a key derivation algorithm, generating an encryption sequence through a chaotic system based on the encryption key, and combining the encryption sequence with the original data to obtain encrypted data; and decrypting the encrypted data and generating second verification data, and comparing the second verification data with the first verification data. Based on the method, multi-layer protection can be realized, and complex attacks can be resisted. When abnormal decryption is carried out, Hash verification, key derivation and chaotic encryption need to be cracked at the same time, so that the attack cost is remarkably improved, the encryption unpredictability is improved, and the accuracy of data integrity verification is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information security, and in particular to a data processing method, device, medium, and program product. Background Technology

[0002] In practical applications, data storage and security have become core requirements for all industries, especially in sensitive areas such as finance, healthcare, and government, where the confidentiality, integrity, and availability of user data are related to compliance requirements.

[0003] Taking banks as an example, their servers store massive amounts of user information, including personal identification information (such as name and ID number), account information (such as account balance and transaction records), and biometric information (such as fingerprints and facial recognition data). If this data is leaked or tampered with, it will not only damage users' privacy rights but may also lead to more serious consequences.

[0004] Currently, existing data storage and usage methods often suffer from insufficient encryption strength and data reliability. For example, encrypting data using existing encryption algorithms (such as AES short-bit keys) is easily cracked by brute force due to its low computational cost. Furthermore, the data is vulnerable to unauthorized tampering. Therefore, existing data processing methods suffer from low confidentiality, integrity, and availability in data storage. Summary of the Invention

[0005] This application provides a data processing method, apparatus, medium, and program product for improving the confidentiality, integrity, and availability of data storage when storing and using data.

[0006] In a first aspect, embodiments of this application provide a data processing method, the method comprising:

[0007] The original data is processed using a hash algorithm to generate the first verification data;

[0008] An encryption key is generated through a key derivation algorithm, and an encryption sequence is generated based on the encryption key through a chaotic system. The encryption sequence is then combined with the original data to obtain encrypted data.

[0009] Decrypt the encrypted data and generate second verification data, then compare the second verification data with the first verification data.

[0010] Secondly, embodiments of this application provide a data processing apparatus, the apparatus comprising:

[0011] The first processing module is used to process the original data using a hash algorithm to generate the first verification data;

[0012] The second processing module is used to generate an encryption key through a key derivation algorithm, generate an encryption sequence based on the encryption key through a chaotic system, and combine the encryption sequence with the original data to obtain encrypted data.

[0013] The comparison module is used to decrypt encrypted data and generate second verification data, and then compare the second verification data with the first verification data.

[0014] Thirdly, embodiments of this application provide an electronic device, including: a memory and a processor; the memory stores computer-executable instructions; the processor executes the computer-executable instructions stored in the memory, causing the processor to perform the implementation method described in the first aspect above.

[0015] Fourthly, embodiments of this application provide a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the embodiments described in the first aspect above.

[0016] Fifthly, embodiments of this application provide a computer program product, including a computer program, which, when executed by a processor, implements the implementation methods described in the first aspect above.

[0017] The data processing method, device, medium, and program products provided in this application address core security issues in data storage and use through a multi-algorithm collaborative mechanism involving hash algorithms, key derivation algorithms, and chaotic systems. The hash verification in the multi-algorithm collaborative mechanism ensures data integrity through a fixed-length output; even minor data changes will result in significantly different verification data, thus detecting tampering. The key derivation algorithm in the multi-algorithm collaborative mechanism generates a high-strength key through multiple rounds of iterative computation, significantly increasing the cost of brute-force attacks. The chaotic system encryption in the multi-algorithm collaborative mechanism utilizes the initial value sensitivity and long-period randomness of chaotic systems to generate encryption sequences, replacing traditional static keys and making encrypted data unpredictable. This method achieves multi-layered protection against complex attacks. When abnormal decryption occurs, hash verification, key derivation, and chaotic encryption must be cracked simultaneously, significantly increasing the attack cost, enhancing encryption unpredictability, and ensuring the accuracy of data integrity verification. Attached Figure Description

[0018] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0019] Figure 1 One of the flowcharts illustrating the data processing method provided in the embodiments of this application;

[0020] Figure 2A second schematic flowchart illustrating the data processing method provided in this application embodiment;

[0021] Figure 3 This is a schematic diagram of the structure of the data processing apparatus provided in the embodiments of this application;

[0022] Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application.

[0023] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation

[0024] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0025] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of the relevant data all comply with the relevant laws, regulations, and standards of the relevant countries and regions, have taken necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation access points for users to choose to authorize or refuse.

[0026] Furthermore, the technical solution involved in this application, which involves big data analysis of user information (including but not limited to personal biometrics, identity data, consumption data, asset data, electronic terminal operation data, etc.) and the use of artificial intelligence technology for automated decision-making, and makes decisions that have a significant impact on personal rights based on the results of automated decision-making, provides users with corresponding operation entry points for users to choose to agree to or reject the results of automated decision-making; if the user chooses to reject, the process will proceed to the expert decision-making process.

[0027] In this application, the terms "exemplary" or "for example" are used to indicate that something is an example, illustration, or description. Any embodiment or design described as "exemplary" or "for example" in this application should not be construed as being more preferred or advantageous than other embodiments or designs. Specifically, the use of terms such as "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.

[0028] In the embodiments of this application, the use of terms such as "first" and "second" is to distinguish between identical or similar items that have essentially the same function and effect. For example, "first electronic device" and "second electronic device" are merely used to distinguish different electronic devices and do not limit their order of execution. Those skilled in the art will understand that the terms "first" and "second" do not limit the quantity or execution order, and that "first" and "second" do not necessarily imply that they are different.

[0029] In this application embodiment, "at least one" refers to one or more, and "more than one" refers to two or more. "And / or" describes the relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following associated objects have an "or" relationship.

[0030] It should be noted that the data processing methods, devices, media, and program products provided in this application can be used in the field of information security, or in any field outside the field of information security. The application fields of the data processing methods, devices, media, and program products in this application are not limited.

[0031] The following is an explanation of some terms used in the embodiments of this application:

[0032] (1) Chaotic systems. Chaotic systems have characteristics such as extreme sensitivity to initial conditions, internal randomness, and unpredictable trajectories, which are consistent with the requirements of cryptography. For example, the Lorenz chaotic system.

[0033] The Lorenz chaotic system was originally used to simulate atmospheric convection. This model is a milestone in the development of chaos theory, revealing the unpredictability (i.e., the "butterfly effect") that exists in deterministic systems. Its differential form is shown in the following formula:

[0034]

[0035] Where σ represents the ratio of fluid viscosity to thermal diffusivity, controlling energy dissipation. ρ represents the intensity of convection driven by temperature difference, determining whether the system enters a chaotic state. β represents the geometric scaling factor, typically fixed at 8 / 3.

[0036] (2) Secure Hash Algorithm 256-bit (SHA-256) Algorithm. The SHA-256 algorithm is a hash algorithm widely used in the fields of encryption and security. It is an algorithm that converts information of arbitrary length into a fixed-length message digest, and generates a 256-bit hash value through information padding and iterative compression.

[0037] (3) Password-Based Key Derivation Function 2 (PBKDF2). The PBKDF2 function is a widely used cryptographic algorithm primarily used to derive encryption keys from user-provided passwords (or other weak key materials). Its core objective is to enhance password security and resist brute-force and rainbow table attacks. Its main function is to convert simple passwords (such as user-input strings) into more secure, fixed-length encryption keys for encryption, digital signatures, and other operations. Through salt and multiple iterative hashing, it significantly increases the difficulty of cracking passwords when they are abnormally decrypted.

[0038] The method provided in this application can be applied to application fields with high data security requirements, such as finance, healthcare, and government affairs. For example, in the scenario of storing bank user information, user data (such as ID card numbers, account balances, and transaction records) needs to be stored in the database after encryption, while ensuring that the data has not been tampered with. In existing data processing solutions, such as encrypting user information data using the Advanced Encryption Standard 128-bit (AES-128) encryption algorithm, the key length is relatively short and easily cracked, resulting in low data storage security, and there is also a lack of dynamic verification mechanisms.

[0039] The method provided in this application can generate long-period encrypted sequences through a chaotic system. Combined with a multi-algorithm collaborative mechanism such as PBKDF2 key derivation and SHA-256 hash verification, it can form a multi-layered protection. It is suitable for scenarios such as distributed databases and cloud storage platforms in finance, healthcare, and government affairs, and is especially suitable for high-security environments that need to deal with advanced persistent threats (APTs).

[0040] In some scenarios, the security of data storage mainly relies on the following types of solutions.

[0041] Plaintext storage solutions. For example, for cost or compatibility reasons, user data may be stored directly in plaintext. While this approach facilitates fast access, it carries the risk of complete exposure should the data be leaked, and data integrity cannot be verified.

[0042] Single-layer encrypted storage schemes. These schemes typically employ either symmetric encryption (such as AES-128) or asymmetric encryption (such as the RSA algorithm) for data encryption. For example, AES-128 encrypts data using a fixed-length key (128 bits), but short-bit keys are easily cracked by brute force. Using the RSA algorithm, however, is difficult to deploy on a large scale due to its high computational complexity. Furthermore, existing encryption schemes often lack dynamic verification mechanisms, making it impossible to detect whether data has been tampered with during storage or transmission.

[0043] Key derivation algorithms are used in this category. These schemes mostly employ algorithms such as PBKDF2 and bcrypt to enhance key strength. However, they are typically only used for password storage (such as user login credentials) and are not deeply integrated into the data encryption process. For example, PBKDF2 generates keys through multiple rounds of hash iteration, but if the generated keys are directly used for static encryption, improper key management can still lead to data security risks.

[0044] Hash verification schemes. Systems using this type of scheme verify data integrity by calculating hash values ​​using algorithms such as Message-Digest Algorithm 5 (MD5) or Secure Hash Algorithm 3 (SHA-3) during data storage. However, these hash algorithms have been shown to have collision vulnerabilities and are not integrated with the encryption process, thus failing to achieve end-to-end data protection.

[0045] The aforementioned existing solutions all suffer from insufficient security due to their reliance on a single encryption algorithm. Furthermore, they lack a dynamic encryption and verification mechanism, fail to decouple key generation from data encryption, and are unable to handle complex attack scenarios (such as secondary attacks following key leakage). These issues collectively constitute a technological bottleneck in the field of information security.

[0046] For example, in existing technical solutions, data encryption typically relies on static keys (such as AES-128), which have short key lengths and low computational complexity, making them easy to crack through brute-force attacks or rainbow table attacks. For instance, in a banking scenario, if user information is stored encrypted with AES-128, it can be decrypted through brute-force attacks to obtain the key, leading to privacy breaches.

[0047] Furthermore, existing solutions lack dynamic verification mechanisms, making it impossible to detect whether data has been tampered with during storage or transmission. For example, if a user's account balance field is modified in the database during abnormal decryption without the system's detection, data integrity and reliability could be compromised. These issues are particularly prominent in sensitive sectors such as finance and healthcare, necessitating a composite protection solution that combines dynamic encryption with strong verification.

[0048] Starting with the problems of existing technologies, the inventors first analyzed two core shortcomings of encryption algorithms: their lack of uniformity and dynamic verification. To address the insufficient encryption strength, they introduced the dynamic randomness of chaotic systems. For example, a long-period encryption sequence can be generated using the Lorenz chaotic system to replace the traditional static key. To enhance key security, for instance, the PBKDF2 function can be used to perform multiple rounds of hash iteration on the user-input master key to generate a high-strength key, which is then used as the initial parameter of the chaotic system, achieving dynamic binding between the key and the encryption sequence.

[0049] To address data integrity issues, the SHA-256 hash verification mechanism can be introduced. The hash value of the data is calculated before and after encryption, and the comparison verifies whether the data has been tampered with. Ultimately, through the closed-loop protection formed by these three mechanisms, the problem of insufficient encryption strength is solved, and the linkage between dynamic encryption and verification is achieved, thus realizing triple protection of data storage confidentiality, integrity, and availability.

[0050] In summary, it is understood that the method of this application aims to solve the following key technical problems: Insufficient data encryption strength. For example, existing encryption algorithms (such as AES-128) are easily cracked by brute force or attacked through pre-computation tables (rainbow tables) due to their short key lengths or low computational complexity. The inability to verify data integrity. For example, traditional encryption schemes do not integrate dynamic verification mechanisms, making it impossible to detect whether data has been tampered with during storage or transmission.

[0051] The problem of disconnect between key generation and encryption processes. For example, existing key derivation algorithms (such as PBKDF2) typically generate keys independently of the data encryption process, leading to complex key management and vulnerability to reverse engineering. The problem of a lack of multi-layered protection mechanisms. For example, a single encryption or verification method is insufficient to defend against advanced persistent threats, requiring complementary protection through algorithm combinations. The problem of balancing computational cost and security. For example, while increasing encryption strength, it is necessary to avoid performance bottlenecks (such as encryption / decryption delays) caused by excessive algorithm complexity.

[0052] In view of this, embodiments of this application provide a data processing method. This method constructs a composite protection system of dynamic encryption and strong verification through a multi-algorithm collaborative mechanism to achieve triple protection of data storage confidentiality, integrity, and availability. The method provided in this application can generate encryption sequences through the dynamic randomness of chaotic systems, replacing traditional static key encryption. Furthermore, it combines key derivation algorithms to improve key strength and reduce the risk of brute-force attacks. Through the hash verification mechanism of hash algorithms, data integrity can be verified. The above three aspects form a closed loop, which not only solves the problem of insufficient security caused by the single encryption algorithm, but also achieves end-to-end protection through the linkage between dynamic encryption and verification.

[0053] The technical solutions of this application will be described in detail below with reference to specific embodiments. The specific embodiments described below can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of this application will be described below with reference to the accompanying drawings.

[0054] Figure 1 This is one of the flowcharts illustrating a data processing method provided in an embodiment of this application. The executing entity of this method can be an electronic device with corresponding data storage and computing capabilities, such as a computer, server, or server cluster. Figure 1 As shown, the method includes:

[0055] S101, the original data is processed by a hash algorithm to generate the first verification data.

[0056] For example, a hash algorithm is a one-way function that can convert an input of arbitrary length into an output of fixed length, and it has collision resistance properties. Examples include SHA-256 and Secure Hash Algorithm 3 (SHA-3). The original data can be any data that needs to be stored securely, such as user information data, event log data, etc.

[0057] After processing the original data using a hash algorithm, first verification data can be generated. This first verification data can be understood as a data fingerprint generated by the hash algorithm, used to verify data integrity. For example, a 256-bit hash value generated from user information data using SHA-256.

[0058] S102, an encryption key is generated through a key derivation algorithm, and an encryption sequence is generated through a chaotic system based on the encryption key. The encryption sequence is then combined with the original data to obtain encrypted data.

[0059] For example, a key derivation algorithm can be an algorithm that generates a cryptographic key through multiple rounds of iterative computation, which can be used to enhance key security. Examples include PBKDF2, bcrypt, and hash-based key derivation functions (HMAC-based Key Derivation Function, HKDF).

[0060] Chaotic systems are dynamic systems with initial condition sensitivity and nonlinear characteristics, capable of generating unpredictable random sequences. Examples include Lorenz chaotic systems, Rossler chaotic systems, Chen chaotic systems, and Lu chaotic systems. Encryption sequences are long-period random sequences generated by chaotic systems and can be combined with the original data to achieve encryption. For example, the chaotic stream output by a Lorenz system.

[0061] For example, a hash operation can be performed on the original data to generate and store the first verification data. Next, an encryption key is generated using a key derivation algorithm (such as PBKDF2). This key serves as the initial parameter for the chaotic system, driving it to generate an encryption sequence. The encryption sequence is then combined with the original data (using logical operations such as XOR) to generate encrypted data.

[0062] S103, decrypt the encrypted data and generate second verification data, then compare the second verification data with the first verification data.

[0063] For example, the second verification data can be understood as another data fingerprint generated by a hash algorithm for the decrypted encrypted data. This fingerprint can be used to compare the data with the first verification data to verify data integrity. For instance, the decrypted encrypted data can be processed using SHA-256 to generate a 256-bit hash value, which can be used to verify the data integrity against the hash value of the first verification data.

[0064] For example, when the original data is needed, the encrypted data can be decrypted first. Decryption can be performed by repeating key derivation and chaotic system processes to generate an encrypted sequence, then reconstructing the original data through inverse operations. Simultaneously, a hash operation is performed on the reconstructed data to generate second verification data. This second verification data is then compared with the first verification data.

[0065] For example, during comparison, if the first verification data matches the second verification data, it can be determined that the original data has not been tampered with. If the first verification data does not match the second verification data, it can be determined that the original data is not reliable and may have been tampered with, in which case an alarm can be triggered. The overall process of this method combines hash verification, key derivation, and chaotic encryption to form a closed-loop protection mechanism, ensuring the confidentiality and integrity of the original data during storage and decryption.

[0066] The data processing method provided in this application addresses core security issues in data storage through a multi-algorithm collaborative mechanism. The hash verification within this mechanism ensures data integrity through a fixed-length output; even minor data changes will result in significantly different verification data, thus detecting tampering. The key derivation algorithm within the mechanism generates a high-strength key through multiple rounds of iterative computation, significantly increasing the cost of brute-force attacks. For example, PBKDF2 extends key generation time through 100,000 hash iterations, requiring more computational resources to decrypt abnormally.

[0067] Chaotic system encryption in multi-algorithm collaborative mechanisms can utilize the initial value sensitivity and long-period randomness of chaotic systems to generate encryption sequences, replacing traditional static keys and making encrypted data unpredictable. For example, tiny parameter changes in a Lorenz system can lead to completely different output sequences, making it impossible to deduce the encryption pattern from historical data when anomalies occur.

[0068] Therefore, the method provided in this application provides multi-layered protection against complex attacks. When data is abnormally decrypted, it requires simultaneous cracking of hash verification, key derivation, and chaotic encryption, significantly increasing the cost of an attack. For example, even if chaotic encryption is reverse-engineered, decryption is still impossible without the key generated by key derivation; if the data is tampered with, hash verification will trigger an alarm. The method provided in this application also achieves complementary dynamic encryption and static verification. The combination of the dynamic encryption sequence of the chaotic system and the static verification of hash verification improves the unpredictability of encryption while ensuring the accuracy of data integrity verification.

[0069] The method provided in this application also achieves end-to-end data protection capabilities. The entire process, from data acquisition and encrypted storage to decryption and verification, is protected, preventing the exploitation of vulnerabilities in single protection methods. For example, in the event of abnormal decryption, encrypted data cannot be tampered with via a man-in-the-middle attack, as such tampering will be detected by hash verification. The method provided in this application also achieves a balance between security and usability. By combining the efficiency of chaotic systems (such as the low computational overhead of the Lorenz model) with the controllable number of iterations in the key derivation algorithm, it ensures both strong protection and performance, making it suitable for large-scale data storage scenarios.

[0070] For example, existing data storage solutions lack multi-layered collaborative protection mechanisms, which means that data confidentiality, integrity, and availability cannot be guaranteed simultaneously. The method provided in this application can construct a closed-loop protection system through the collaborative use of chaotic system encryption, PBKDF2 key derivation, and SHA-256 hash verification.

[0071] In one possible implementation, generating an encryption key via a key derivation algorithm includes: generating the encryption key through multiple rounds of hash iteration calculation; and determining the encryption key as the initial parameter of the chaotic system.

[0072] For example, multi-round hash iteration can be understood as a computational process of generating an encryption key by repeatedly executing a hash algorithm. For instance, PBKDF2 generates a key through 100,000 SHA-256 iterations. The initial parameters of a chaotic system can be understood as the initial input values ​​for the chaotic system's operation; these initial parameters determine the characteristics of the chaotic system's output sequence. Examples of initial parameters for a chaotic system are the σ, ρ, and β parameters of a Lorenz system.

[0073] Multi-round hash iteration generates encryption keys by repeatedly executing hash algorithms (such as SHA-256), which significantly increases the computational cost of key generation. The encryption key, as the initial parameters (such as σ, ρ, β) of a chaotic system, can drive the chaotic system to generate encrypted sequences.

[0074] For example, the user-input master key is used to generate a 16-byte key via PBKDF2, which is then used as the σ parameter of the Lorenz system to generate a chaotic sequence and XOR it with the data for encryption. This process achieves the generation of a dynamic encryption sequence through the combination of key derivation and a chaotic system.

[0075] In this embodiment, key strength is enhanced through multiple rounds of hash iteration, significantly increasing the cost of brute-force attacks. For example, when anomaly decrypted, 100,000 hash operations are required for each candidate password, while the cracking efficiency of traditional single-round hashing is increased by tens of times. Simultaneously, the encryption key is bound to chaotic system parameters, making it impossible to deduce the original key through the inverse chaotic system when anomaly decrypted, thereby improving encryption unpredictability.

[0076] For example, existing encryption algorithms (such as AES-128) are vulnerable to brute-force attacks or rainbow table attacks due to their short key lengths or low computational complexity, leading to reduced data security. The method in this application embodiment can use the PBKDF2 key derivation algorithm to perform multiple rounds of hash iterations on the user-input master key to generate a high-strength master key.

[0077] In one possible implementation, the multi-round hash iteration includes at least one of the following: hash iteration via a cryptographic-based derivation function PBKDF2; hash iteration via a hash-based key derivation function HKDF.

[0078] For example, the PBKDF2 function is a key derivation function based on Hash-Based Message Authentication Code (HMAC), which can enhance the security of the encryption key through multiple rounds of hash iteration. For example, 100,000 SHA-256 iterations can generate a key.

[0079] PBKDF2 significantly increases the computational cost of key generation by introducing salt and multiple rounds of hash iteration. Salt ensures that the same master key generates different keys in different scenarios, preventing rainbow table attacks. Multiple rounds of hash iteration greatly reduce the feasibility of brute-force attacks by extending computation time.

[0080] HKDF functions are key derivation functions based on the extract-expansion paradigm, suitable for high-entropy input scenarios. For example, they can expand high-entropy inputs (such as hardware random numbers) into multiple keys.

[0081] Multi-round hash iterations can be implemented using PBKDF2 and / or HKDF functions. For example, a user-input master key can be used to generate a 16-byte key via PBKDF2, or expanded into a multi-key via HKDF. Both methods improve key security by increasing computational cost (such as the number of iterations or entropy), ensuring that the generated key is difficult to crack through brute-force attacks or pre-computed tables.

[0082] By combining salt values ​​with user input, the same master key generates unique keys in different scenarios, preventing rapid cracking through pre-calculated tables during abnormal decryption, thus enhancing key uniqueness. For example, the encryption key generated by the user password "uesr123!" under the salt value "mysalt" is "3a7c1b9e...", while the encryption key generated under the salt value "othersalt" is "5f4d2a8b...".

[0083] Multiple rounds of hash iteration can significantly extend the key generation time, requiring more computational resources to decrypt abnormally and increasing the cost of brute-force attacks. For example, a brute-force attack requires performing 100,000 hash operations on each candidate password, while traditional single-round hashing is tens of times more efficient. This method is also compatible with user behavior habits. For example, PBKDF2 allows users to enter simple passwords, such as "uesr123!", enhancing their security through algorithms and preventing users from abandoning the system due to password complexity requirements.

[0084] In the embodiments of this application, optional key derivation algorithms (such as PBKDF2 or HKDF) are used to adapt to different security requirements. For example, PBKDF2 is selected in low-entropy input scenarios to enhance security through multiple rounds of iteration; HKDF is selected in high-entropy input scenarios to directly expand into multiple keys and avoid iteration overhead.

[0085] For example, existing key derivation processes lack dynamism, which can lead to the reverse derivation of keys generated by the same user in different scenarios. The method in this application improves dynamism by introducing a dynamic salt value generation mechanism. The salt value is generated by combining the user's identity identifier, timestamp, and device fingerprint, and is bound to the user's master key.

[0086] In one possible implementation, before generating the encryption key through multiple rounds of hash iteration calculation, the method further includes: generating a dynamic salt value, which includes at least one of a user identity identifier, a timestamp, and a device fingerprint, and the dynamic salt value is used for multiple rounds of hash iteration calculation.

[0087] For example, a dynamic salt value can be a unique random value generated each time, which can be bound to user identity, time, and device. For instance, if the user ID is "user123", the timestamp is "20231010120000", and the device fingerprint (such as the device hardware serial number) is "device_abc123", then a dynamic salt value can be generated by combining user123, 20231010120000, and / or device_abc123. For example, the dynamic salt value generated by combining the three is "user12320231010120000device_abc123".

[0088] For example, a dynamic salt value is generated by combining a user's identity identifier (such as ID), a timestamp (such as login time), and a device fingerprint (such as device MAC address). When a user logs in, the system can generate a unique dynamic salt value based on their ID, login time, and device MAC address. This dynamic salt value, along with the master key, is input into multiple rounds of hash iterations, ensuring that the same master key generates different encryption keys in different scenarios.

[0089] Dynamic salt values, by introducing timestamps and device fingerprints, ensure that each generated salt value is unique and unpredictable. Keys generated by the same user at different times or on different devices cannot be reused, reducing the risk of reverse engineering after key leakage and enhancing the uniqueness of encryption keys. For example, even if the key from a particular login session is obtained during abnormal decryption, it is impossible to deduce keys from other scenarios.

[0090] When decryption is performed abnormally, a rainbow table needs to be generated individually for each user, significantly increasing the difficulty of cracking and raising the cost of attacks. For example, the larger the number of users, the larger the rainbow table needs to be generated when decryption is performed abnormally. Device fingerprints in dynamic salt values ​​can help track key usage scenarios, support behavior auditing, and enhance system auditing capabilities. For example, if a user's key is used by an abnormal device, a security alert can be triggered and the account can be frozen.

[0091] In this embodiment, a dynamic salt value generation mechanism is used to enhance key uniqueness. This ensures that even if a login key is obtained during abnormal decryption, keys for other scenarios cannot be derived, significantly increasing the difficulty of rainbow table attacks.

[0092] In one possible implementation, generating a dynamic salt value includes combining a user identity identifier, a timestamp, and a device fingerprint using a hash algorithm.

[0093] The hash algorithm can be any of the hash algorithms in the various embodiments of this application, such as SHA-256. Through the hash algorithm, user identity, timestamp, and device fingerprint can be combined and mapped to generate a corresponding hash value, which can be used as a dynamic salt value.

[0094] User identity, timestamp, and device fingerprint are combined using a hash algorithm (such as SHA-256) to generate a dynamic salt value. For example, by inputting the user ID "user123", timestamp "20231010120000", and device fingerprint "device_abc123" into SHA-256, a fixed-length dynamic salt value can be generated, such as "a1b2c3d4e5f6...z0". This dynamic salt value ensures that the salt value generated each time is unique and unpredictable.

[0095] In this embodiment, combining user identity, time, and device information using a hash algorithm further enhances the unpredictability of the dynamic salt value. This prevents reverse engineering to deduce the salt value generation rules in the event of abnormal decryption, thereby improving the security of key derivation.

[0096] For example, existing chaotic systems have fixed parameters, which may lead to predictable statistical properties of encrypted sequences. The method in this application introduces a dynamic parameter adjustment mechanism for chaotic systems, which can adjust parameters (such as σ, ρ, β) according to user behavior or environmental changes, thereby improving unpredictability.

[0097] In one possible implementation, the method further includes: acquiring user behavior and / or environmental changes associated with the original data; and generating an encrypted sequence using a chaotic system based on an encryption key, including: adjusting the parameters of the chaotic system according to user behavior and / or environmental changes.

[0098] For example, user behavior and / or environmental changes associated with the original data are user behavior and / or environmental changes corresponding to the data subject (user) of the original data. User behavior can be the user's operating patterns, such as login frequency, access time, etc. Environmental changes can be changes in external conditions, such as Internet Protocol (IP) address, geographical location, etc. The parameters of the chaotic system (such as σ, ρ, β) can be dynamically adjusted according to user behavior or environmental changes.

[0099] Because chaotic systems are sensitive to initial conditions, dynamic parameter adjustment can alter the statistical properties of their output sequences. For example, when users log in frequently, the parameter σ is increased to 10 to reduce the periodicity of the chaotic sequence; when a user's login IP is abnormal, the parameter ρ is adjusted to 28 to enhance the sequence's randomness. Parameter adjustment can be achieved by receiving user behavior or environmental data corresponding to the real-time input raw data, thereby obtaining user behavior and / or environmental data.

[0100] Dynamic parameter adjustment makes it impossible to predict chaotic sequence patterns when anomaly decryption occurs, improving resistance to pattern analysis and enhancing encryption unpredictability. For example, when anomaly decryption occurs, it is impossible to predict future encryption sequences based on historical data. Encryption strength is automatically strengthened for high-risk behaviors (such as abnormal logins), enabling dynamic optimization of protection strategies to adapt to diverse scenario requirements.

[0101] For example, when an abnormal IP address logs in, the encryption strength can be significantly increased, thus reducing the risk of data leakage. This method can avoid systemic risks caused by the cracking of fixed parameters, thereby reducing the risk of fixed parameter vulnerabilities. For example, even if a certain parameter combination is cracked during abnormal decryption, parameter changes in other scenarios can still prevent the reuse of the cracked result.

[0102] In this embodiment, the unpredictability of encryption is enhanced by adjusting dynamic parameters. This prevents the prediction of future encryption sequences based on historical data in the event of abnormal decryption, thereby improving resistance to pattern analysis.

[0103] In one possible implementation, generating an encrypted sequence through a chaotic system based on an encryption key includes: determining a dynamic salt value as one of the initial parameters of the chaotic system; and adjusting the remaining parameters of the chaotic system according to user behavior and / or environmental changes.

[0104] For example, the initial parameters are the starting input values ​​for the operation of the chaotic system, which may include parameters adjusted by dynamic salt values, user behavior, and / or environmental changes.

[0105] The dynamic salt value serves as one of the initial parameters of the chaotic system (such as σ), while other parameters (such as ρ and β) can be dynamically adjusted based on user behavior or environmental changes. For example, the dynamic salt value "a1b2c3d4e5f6...z0" is used as the σ parameter, and the ρ parameter is adjusted to 28 when the user's login IP is abnormal. This process, through the combination of dynamic salt value and parameter adjustment, achieves double randomness in the encrypted sequence.

[0106] In this embodiment, dual randomness of the encrypted sequence is achieved by combining dynamic salt values ​​with chaotic system parameter adjustments. Thus, when an attempt is made to decrypt abnormally, both the dynamic salt value generation rule and the parameter adjustment logic must be cracked simultaneously, significantly increasing the difficulty of decryption.

[0107] For example, existing data integrity verification lacks a dynamic verification mechanism and cannot detect data tampering in real time. In the method provided in this application, SHA-256 hash values ​​can be calculated before and after data encryption, and data integrity can be verified by comparison.

[0108] In one possible implementation, after decrypting the encrypted data and generating the second verification data, the method further includes sending the comparison result of the first verification data and the second verification data to the user terminal for confirmation.

[0109] For example, a user terminal can be understood as a device that performs data access or authentication, such as a personal computer, computer, mobile device, or server.

[0110] After the decrypted second verification data is compared with the first verification data, if they do not match, the comparison result can be sent to the user terminal (such as a bank's user terminal or an administrator's interface). Upon receiving the comparison result, the user terminal triggers a manual verification process. For example, if user order data verification fails, the system sends an SMS or email notification to the user requesting manual verification of data availability.

[0111] For example, the SHA-256 hash algorithm has collision resistance; even if the data changes slightly, the hash value will be significantly different. Before encryption, the hash value of the original data is calculated and stored as the first verification data. After decryption, the hash value is recalculated and compared with the first verification data; if they do not match, an alarm is triggered.

[0112] By comparing hash values, tampering can be detected immediately during the data decryption stage, enabling real-time tamper detection. For example, if a financial field in a user's order is modified during abnormal decryption, the decrypted hash value will differ from the initial verification data, triggering a manual confirmation process. Hash verification ensures that data remains tamper-free throughout storage, transmission, and decryption, preventing business logic errors caused by data contamination. This prevents data contamination.

[0113] For example, if bank transaction records are tampered with, the system will refuse to use the data to prevent losses. Hash values ​​can also be linked to user identities (such as through dynamic salt values), allowing for the tracing of the source of data tampering and supporting audit traceability. For instance, if a user's data hash value is abnormal, the device fingerprint in the salt value can be used to locate the device involved in the abnormal operation.

[0114] In this embodiment, a user terminal confirmation mechanism reduces the risk of misjudgment. This allows hash verification errors (such as data transmission errors) to be eliminated through manual confirmation, preventing service interruptions caused by the system automatically rejecting data.

[0115] Figure 2 This is the second flowchart illustrating the data processing method provided in the embodiments of this application. The following will further illustrate this. Figure 2 The possible implementations of this application are further described below.

[0116] The existing information (i.e., the original data) is stored in plaintext or only encrypted. However, the encrypted data is easily decrypted by exhaustively finding the key. Furthermore, when facing network attacks, it cannot be guaranteed that the information has not been tampered with, and the data needs to be verified.

[0117] Specifically, in existing scenarios, much information is stored in plaintext or encrypted with a short-bit key using the AES algorithm to achieve cost-effectiveness. However, the key used by the AES algorithm can be deduced through brute force to obtain the key for decryption. The encryption key of the method in this application is generated by a complex algorithm, which is difficult to crack through brute force. In chaotic systems, even small differences in input can lead to vastly different calculation results.

[0118] This application provides a data processing method based on multiple algorithm verification methods. This method involves hashing user information (e.g., using the SHA-256 algorithm) and saving the resulting 256-bit hash value for later verification. The user-stored information is then encrypted using the PBKDF2 function and a chaotic system before being saved.

[0119] When user information needs to be used again, the saved information is decrypted, and a 256-bit hash value is generated through hash operation (such as SHA-256 algorithm). This hash value is then compared with the original saved hash value data for verification. If they match, the information is used; otherwise, confirmation with the user is required.

[0120] like Figure 2 As shown, on the one hand, the user information (raw data) is hashed (SHA-256 algorithm) to generate a 256-bit hash value, which is then stored in the database.

[0121] In one implementation, to improve information security, the hash value can be encoded before storage. For example, all 0s and 1s in the hash value can be swapped, and 0s can be inserted into the even-numbered positions after the swap. This data can be retained for future verification. This method is faster and more difficult to crack even if leaked. Encoding can also be used to encode user information before hash calculation.

[0122] Regarding user information, on the other hand, the PBKDF2 function performs multiple rounds of hash iterations (e.g., 100,000 SHA-256 hashes) on the user-input master key and salt value to generate a high-strength master key (encryption key). Similar key derivation algorithms include HKDF, bcrypt, etc., and these algorithms share the common feature of increasing computational cost to resist brute-force attacks.

[0123] For example, the master key (password) is "uesr123!", and the salt is "mysalt". The master key is encoded according to UTF-8 rules, and the initial function calculation is h1 = HMAC - SHA256(salt, password).

[0124] The subsequent values ​​are hn=HMAC-SHA256(salt,hn-1), n=2,3,...,100,000.

[0125] The final output is: 3a7c1b9e2d4a6f0c8b7a5d2e3f1a9c7b4d8e6f2a1b3c5d7e9f0a2d4c6b8a

[0126] The master key output by PBKDF2 is used as the initial parameter of the Lorenz chaotic system to generate a long-period random sequence (chaotic flow).

[0127] Similar chaotic systems include the Rossler chaotic system, the Chen chaotic system, and the Lu chaotic system. Their common characteristic is that even a slight difference in the input will result in a significant difference in the output. The Lorenz system is a classic model, relatively concise in its mathematical expression, and has a very intuitive physical meaning and application background. While the other models are mostly purely mathematical, the Lorenz system is easier to understand.

[0128] For example, in the output of the above steps, the first four bytes, 3a7c1b9e, are used as the chaotic system parameter σ, 2d4a6f0c as the parameter ρ, and parameter β is usually set to 8 / 3. 8b7a5d2e is used as the initial coordinate x0, 3f1a9c7b as the initial coordinate y0, and 4d8e6f2a as the initial coordinate z0. The output sequence after the Lorenz chaotic system simulation is (only the first 64 bits are shown): 3a7c1b9e2d4a6f0c8b7a5d2e3f1a9c7b4d8e6f2a1b3c5d7e9f0a2d4c6b8a.

[0129] Then, the chaotic sequence can be XORed byte by byte with the original data to combine them and achieve digital encryption. For example, after obtaining the chaotic sequence, in addition to XOR operation, digital encryption can also be achieved through algorithms such as XNOR, bitwise AND, and bitwise OR. These methods can all transform and encrypt binary numbers according to a certain rule.

[0130] When decrypting encrypted data, the above steps can be repeated to obtain the original data by performing an XOR inverse operation on the user's encrypted information and key. Simply select the inverse operation during decryption. Afterwards, the original data can be hashed using the first step, or the hash value of the previously stored user information can be retrieved. The two hash values ​​are compared; if they match, the original data can be used; if they do not match, the data is considered correct, and the data can be confirmed with the user.

[0131] The method in this application utilizes chaotic systems and hash algorithms to store encrypted original data in a database, thus avoiding plaintext storage of information in the database. Furthermore, it leverages the characteristics of relevant algorithms to prevent data tampering and adds a data verification step, effectively ensuring data security and availability.

[0132] Figure 3 This is a schematic diagram of the structure of the data processing apparatus provided in the embodiments of this application, such as... Figure 3 As shown, this application embodiment provides a data processing apparatus, the apparatus comprising:

[0133] The first processing module 301 is used to process the original data using a hash algorithm to generate the first verification data;

[0134] The second processing module 302 is used to generate an encryption key through a key derivation algorithm, generate an encryption sequence based on the encryption key through a chaotic system, and combine the encryption sequence with the original data to obtain encrypted data.

[0135] The comparison module 303 is used to decrypt the encrypted data and generate second verification data, and compare the second verification data with the first verification data.

[0136] In one possible implementation, the second processing module 302 is specifically used for:

[0137] The encryption key is generated through multiple rounds of hash iteration calculations;

[0138] The encryption key is determined as the initial parameter of the chaotic system.

[0139] In one possible implementation, multiple rounds of hash iteration include at least one of the following:

[0140] Hash iteration is performed using the cryptographically derived function PBKDF2;

[0141] Hash iteration is performed using the hash-based key derivation function HKDF.

[0142] In one possible implementation, the device further includes a generation module for:

[0143] A dynamic salt value is generated, which includes at least one of the user identity identifier, timestamp, and device fingerprint. The dynamic salt value is used for multiple rounds of hash iteration calculation.

[0144] In one possible implementation, the generation module is specifically used for:

[0145] The user's identity, timestamp, and device fingerprint are combined using a hash algorithm to generate a dynamic salt value.

[0146] In one possible implementation, the device further includes an acquisition module for: acquiring user behavior and / or environmental changes associated with the raw data;

[0147] The second processing module 302 is specifically used to: adjust the parameters of the chaotic system according to user behavior and / or environmental changes.

[0148] In one possible implementation, the second processing module 302 is specifically used for:

[0149] The dynamic salt value is determined as one of the initial parameters of the chaotic system;

[0150] Adjust the remaining parameters of the chaotic system based on user behavior and / or environmental changes.

[0151] In one possible implementation, the device further includes a transmitting module for:

[0152] The comparison result between the first and second verification data is sent to the user terminal for confirmation.

[0153] The data processing apparatus provided in this application embodiment can be used to execute the technical solution of the data processing method in any of the above embodiments of this application. Its implementation principle and technical effect are similar, and will not be described again here.

[0154] Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application, such as... Figure 4 As shown, the electronic device of this embodiment may include: at least one processor 401; and a memory 402 communicatively connected to the at least one processor; wherein the memory 402 stores instructions that can be executed by the at least one processor 401, and the instructions are executed by the at least one processor 401 to cause the electronic device to perform the method as described in any of the above embodiments.

[0155] Optionally, the memory 402 can be either standalone or integrated with the processor 401.

[0156] The implementation principle and technical effects of the electronic device provided in this embodiment can be found in the foregoing embodiments, and will not be repeated here.

[0157] This application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the method of any of the foregoing embodiments.

[0158] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the method of any of the foregoing embodiments.

[0159] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For instance, the division of modules is only a logical functional division, and there may be other division methods in actual implementation. For example, multiple modules may be combined or integrated into another system, or some features may be ignored or not executed.

[0160] The integrated modules described above, implemented as software functional modules, can be stored in a computer-readable storage medium. These software functional modules, stored in a storage medium, include several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute some steps of the methods of the various embodiments of this application.

[0161] It should be understood that the aforementioned processor can be a Central Processing Unit (CPU) or other general-purpose processors. The processor can also be a Digital Signal Processor (DSP) or an Application Specific Integrated Circuit (ASIC), etc. A general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in the application can be directly manifested as being executed by a hardware processor, or executed by a combination of hardware and software modules within the processor.

[0162] The memory may include random access memory (RAM) and may also include non-volatile memory (NVM), such as at least one disk storage device, and may also be various media that can store program code, such as USB flash drives, portable hard drives, read-only memory (ROM), disks or optical discs.

[0163] The aforementioned storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof. Examples of storage media include Static Random-Access Memory (SRAM) or Electrically Erasable Programmable Read Only Memory (EEPROM).

[0164] Storage media can be, for example, erasable programmable read-only memory (EPROM) or programmable read-only memory (PROM). Storage media can also be read-only memory (ROM), magnetic storage, flash memory, magnetic disks, or optical disks. Storage media can be any available medium accessible to general-purpose or special-purpose computers.

[0165] An exemplary storage medium is coupled to a processor, enabling the processor to read information from and write information to the storage medium. Alternatively, the storage medium can be an integral part of the processor. The processor and storage medium can reside within an application-specific integrated circuit (ASIC). Alternatively, the processor and storage medium can exist as discrete components within an electronic device or host device.

[0166] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0167] The sequence numbers of the embodiments in this application are merely for description and do not represent the superiority or inferiority of the embodiments. Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method.

[0168] Based on this understanding, the technical solution of this application, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods of the various embodiments of this application.

[0169] The above are merely preferred embodiments of this application and do not limit the patent scope of this application. Any equivalent structural or procedural transformations made using the content of this application's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of this application.

[0170] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this application. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily essential to this application.

[0171] It should be further noted that although the steps in the flowchart are shown sequentially as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise explicitly stated in this document, there is no strict order requirement for the execution of these steps, and they can be executed in other orders.

[0172] Furthermore, at least some steps in the flowchart may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but may be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but may be executed in turn or alternately with other steps or at least some of the sub-steps or stages of other steps.

[0173] In the above embodiments, the descriptions of each embodiment have their own emphasis. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments. The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as the combination of these technical features does not contradict each other, it should be considered within the scope of this specification.

[0174] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.

[0175] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.

Claims

1. A data processing method, characterized in that, The method includes: The original data is processed using a hash algorithm to generate the first verification data; An encryption key is generated through a key derivation algorithm, and an encryption sequence is generated through a chaotic system based on the encryption key. The encryption sequence is then combined with the original data to obtain encrypted data. The encrypted data is decrypted and a second verification data is generated. The second verification data is then compared with the first verification data.

2. The method according to claim 1, characterized in that, The generation of the encryption key through the key derivation algorithm includes: The encryption key is generated through multiple rounds of hash iteration calculations; The encryption key is determined as the initial parameter of the chaotic system.

3. The method according to claim 2, characterized in that, The multi-round hash iteration includes at least one of the following: Hash iteration is performed using the cryptographically derived function PBKDF2; Hash iteration is performed using the hash-based key derivation function HKDF.

4. The method according to claim 2, characterized in that, Before generating the encryption key through multiple rounds of hash iteration calculations, the method further includes: A dynamic salt value is generated, which includes at least one of a user identity identifier, a timestamp, and a device fingerprint. The dynamic salt value is used for multiple rounds of hash iteration calculation.

5. The method according to claim 4, characterized in that, The generation of dynamic salt values ​​includes: The dynamic salt value is generated by combining the user identity identifier, the timestamp, and the device fingerprint using a hash algorithm.

6. The method according to claim 4, characterized in that, The method further includes: Obtain user behavior and / or environmental changes associated with the raw data; Based on the encryption key, an encryption sequence is generated through a chaotic system, including: The parameters of the chaotic system are adjusted based on the user behavior and / or environmental changes.

7. The method according to claim 6, characterized in that, Based on the encryption key, an encryption sequence is generated through a chaotic system, including: The dynamic salt value is determined as one of the initial parameters of the chaotic system; The remaining parameters of the chaotic system are adjusted based on the user behavior and / or the environmental changes.

8. The method according to any one of claims 1-7, characterized in that, After decrypting the encrypted data and generating the second verification data, the method further includes: The comparison result between the first verification data and the second verification data is sent to the user terminal for confirmation.

9. An electronic device, characterized in that, include: Memory and processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory, causing the processor to perform the method as described in any one of claims 1-8.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1-8.

11. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method according to any one of claims 1-8.