Data encryption method and device, computer device and storage medium

CN122845178APending Publication Date: 2026-09-29CCORE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610857843.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-15
Publication Date
2026-09-29

AI Technical Summary

Technical Problem

然而,目前的对称加密方法存在一个最大问题:对于相同密钥和相同数据,每次加密得到的密文结果完全相同,加密过程中各环节的运算模式也保持稳定不变,导致攻击者能够通过多次观测加密过程的物理特征建立统计规律,进而逆向推断出密钥信息;同时,这种确定性也使得重放攻击容易得手,难以保障数据的语义安全性

Benefits of technology

[0057]上述数据加密方法、装置、计算机设备、存储介质和计算机程序产品,通过初始密钥结合当前时间戳动态生成轮函数调度参数,利用时间戳的唯一性让每一次加密过程的轮运算配置都不重复,使得相同明文在不同时间加密能够得到不同的密文,既保留了轮函数加密的混淆扩散能力,又解决了固定轮函数配置下确定性加密容易被统计分析、存在重放攻击风险的问题,能够有效提升加密数据的安全性,适配各类需要高安全等级数据传输存储的场景。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122845178A_ABST
    Figure CN122845178A_ABST
Patent Text Reader

Abstract

The application relates to a data encryption method and device, computer equipment, a storage medium and a computer program product. The method comprises the following steps: obtaining an initial key, to-be-encrypted data and a current timestamp; generating a round function scheduling parameter by using the initial key and the current timestamp; wherein the round function scheduling parameter comprises at least one of the following data: the number of rounds of encryption, a round key used for encryption, a permutation table used for encryption, and a function combination mode used for encryption; and performing round function encryption on the to-be-encrypted data according to the round function scheduling parameter to obtain encrypted data. The method can effectively improve the difficulty of password analysis and greatly improve the security of encrypted data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data encryption technology, and in particular to a data encryption method, apparatus, computer equipment, storage medium, and computer program product. Background Technology

[0002] With the development of information security technology, symmetric encryption technology has emerged, characterized by fast encryption and decryption speeds and low resource consumption. In traditional technologies, encryption algorithms execute according to a predefined, unified process. However, current symmetric encryption methods have a major problem: for the same key and the same data, the ciphertext obtained from each encryption is exactly the same, and the operational patterns of each step in the encryption process remain stable. This allows attackers to establish statistical patterns by repeatedly observing the physical characteristics of the encryption process, and then reverse-engineer the key information. At the same time, this determinism also makes replay attacks easy to succeed, making it difficult to guarantee the semantic security of the data. Summary of the Invention

[0003] Therefore, it is necessary to provide a data encryption method, apparatus, computer equipment, computer-readable storage medium, and computer program product to address the aforementioned technical problems.

[0004] Firstly, this application provides a data encryption method. The method includes:

[0005] Obtain the initial key, the data to be encrypted, and the current timestamp;

[0006] Using the initial key and the current timestamp, round function scheduling parameters are generated; wherein, the round function scheduling parameters include at least one of the following data: the number of encryption rounds, the round key used for encryption, the permutation table used for encryption, and the function combination method used for encryption;

[0007] Based on the round function scheduling parameters, the data to be encrypted is encrypted using a round function to obtain encrypted data.

[0008] In one embodiment, obtaining the initial key includes:

[0009] Obtain parameters for a lattice-hard problem;

[0010] Based on the parameters of the lattice-hard problem, a local key pair is generated; wherein the local key pair includes a first public key and a private key;

[0011] Send the first public key to the target device and receive the second public key returned by the target device;

[0012] Based on the second public key and the private key, a shared key is determined; and an initial key is generated based on the shared key.

[0013] In one embodiment, obtaining the current timestamp includes:

[0014] Get the current clock time;

[0015] Convert the current clock time into the target format to obtain a timestamp string;

[0016] The timestamp string is hashed to obtain the current timestamp.

[0017] In one embodiment, the step of performing round function encryption on the data to be encrypted according to the round function scheduling parameters to obtain encrypted data includes:

[0018] The data to be encrypted is divided into groups to obtain data groups;

[0019] Using the round function scheduling parameters, each data group is encrypted using a round function to obtain an encrypted data group;

[0020] The encrypted data groups are concatenated to obtain encrypted data.

[0021] In one embodiment, generating round function scheduling parameters using the initial key and the current timestamp includes:

[0022] The initial key and the current timestamp are concatenated to obtain the initial parameters;

[0023] The initial parameters are hashed using a hash function to obtain intermediate parameters.

[0024] The intermediate parameters are grouped, and the round function scheduling parameters are determined based on each parameter group.

[0025] In one embodiment, obtaining the data to be encrypted includes:

[0026] Receive raw plaintext data;

[0027] If the length of the original plaintext data meets the preset length, the original plaintext data is determined as data to be encrypted.

[0028] If the length of the original plaintext data does not meet the preset length, the original plaintext data is padded to obtain the data to be encrypted.

[0029] Secondly, this application also provides a data encryption device. The device includes:

[0030] The data acquisition module is used to acquire the initial key, the data to be encrypted, and the current timestamp;

[0031] The parameter generation module is used to generate round function scheduling parameters using the initial key and the current timestamp; wherein the round function scheduling parameters include at least one of the following data: the number of encryption rounds, the round key used for encryption, the permutation table used for encryption, and the function combination method used for encryption;

[0032] The data encryption module is used to perform round function encryption on the data to be encrypted according to the round function scheduling parameters to obtain encrypted data.

[0033] In one embodiment, the data acquisition module is further configured to:

[0034] Obtain parameters for a lattice-hard problem;

[0035] Based on the parameters of the lattice-hard problem, a local key pair is generated; wherein the local key pair includes a first public key and a private key;

[0036] Send the first public key to the target device and receive the second public key returned by the target device;

[0037] Based on the second public key and the private key, a shared key is determined; and an initial key is generated based on the shared key.

[0038] In one embodiment, the data acquisition module is further configured to:

[0039] Get the current clock time;

[0040] Convert the current clock time into the target format to obtain a timestamp string;

[0041] The timestamp string is hashed to obtain the current timestamp.

[0042] In one embodiment, the data encryption module is further configured to:

[0043] The data to be encrypted is divided into groups to obtain data groups;

[0044] Using the round function scheduling parameters, each data group is encrypted using a round function to obtain an encrypted data group;

[0045] The encrypted data groups are concatenated to obtain encrypted data.

[0046] In one embodiment, the parameter generation module is further configured to:

[0047] The initial key and the current timestamp are concatenated to obtain the initial parameters;

[0048] The initial parameters are hashed using a hash function to obtain intermediate parameters.

[0049] The intermediate parameters are grouped, and the round function scheduling parameters are determined based on each parameter group.

[0050] In one embodiment, the data acquisition module is further configured to:

[0051] Receive raw plaintext data;

[0052] If the length of the original plaintext data meets the preset length, the original plaintext data is determined as data to be encrypted.

[0053] If the length of the original plaintext data does not meet the preset length, the original plaintext data is padded to obtain the data to be encrypted.

[0054] Thirdly, this application also provides a computer device. The computer device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the data encryption method as described in any one of the embodiments of this disclosure.

[0055] Fourthly, this application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program thereon, which, when executed by a processor, implements the data encryption method as described in any one of the embodiments of this disclosure.

[0056] Fifthly, this application also provides a computer program product. The computer program product includes a computer program that, when executed by a processor, implements the data encryption method as described in any of the embodiments of this disclosure.

[0057] The aforementioned data encryption methods, devices, computer equipment, storage media, and computer program products dynamically generate round function scheduling parameters by combining an initial key with the current timestamp. The uniqueness of the timestamp ensures that the round operation configuration is not repeated for each encryption process, so that the same plaintext can be encrypted at different times to obtain different ciphertexts. This not only retains the obfuscation and diffusion capabilities of round function encryption, but also solves the problems of deterministic encryption under fixed round function configuration being easily statistically analyzed and having the risk of replay attacks. It can effectively improve the security of encrypted data and is suitable for various scenarios that require high-security data transmission and storage. Attached Figure Description

[0058] Figure 1 This is a diagram illustrating the application environment of a data encryption method in one embodiment;

[0059] Figure 2 This is a flowchart illustrating a data encryption method in one embodiment;

[0060] Figure 3This is a flowchart illustrating the implementation of a data encryption method in one embodiment;

[0061] Figure 4 This is a structural block diagram of a method apparatus in one embodiment;

[0062] Figure 5 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation

[0063] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0064] The data encryption method provided in this application embodiment can be applied to, for example... Figure 1 In the application environment shown, terminal 102 communicates with server 104 via a network. A data storage system can store the data that server 104 needs to process. The data storage system can be integrated onto server 104 or placed on the cloud or other network servers. Before sending sensitive data, terminal 102 uses a locally acquired initial key and the current timestamp to generate round function scheduling parameters, performs round function encryption on the data to be encrypted, and then sends the encrypted data to server 104 via the network. Upon receiving the encrypted data, server 104 decrypts it using the same initial key and corresponding timestamp. Because the timestamp is different for each encryption, even the same data encrypted at different times will produce dynamically different ciphertexts, thus effectively improving communication security. Terminal 102 can be, but is not limited to, various personal computers, laptops, smartphones, tablets, IoT devices, and portable wearable devices. IoT devices can include smart speakers, smart TVs, smart air conditioners, smart in-vehicle devices, etc. Portable wearable devices can include smartwatches, smart bracelets, head-mounted devices, etc. Server 104 can be implemented using a standalone server or a server cluster composed of multiple servers.

[0065] In one embodiment, such as Figure 2 As shown, a data encryption method is provided, including the following steps:

[0066] Step S200: Obtain the initial key, the data to be encrypted, and the current timestamp.

[0067] The initial key may include a base key used to generate the scheduling parameters required for the encryption process; the data to be encrypted may include the original plaintext data that needs to be protected; and the current timestamp may include a unique random factor generated based on the current system time during this encryption execution, and the current timestamps obtained from different encryption processes are not repeated.

[0068] In one exemplary embodiment, the initial key can be obtained through lattice-based key negotiation. In a two-party communication scenario, both parties generate their own public keys based on a lattice-based hard problem and exchange them. They then obtain the same shared key through homomorphic computation. Hash compression of the shared key yields the initial key used for this encryption. This method can resist attacks from quantum computing on traditional key negotiation schemes, improving the security of the initial key distribution process. Alternatively, the initial key can be obtained directly from a pre-agreed key pool, reducing the communication overhead of the negotiation process and meeting the encryption requirements of low-latency scenarios.

[0069] In one exemplary embodiment, by introducing the current timestamp as a random factor, each encryption process can have an independent random input. Even if the same initial key is used to encrypt the same plaintext, different encryption operations at different times can produce completely different output ciphertexts.

[0070] Step S202: Using the initial key and the current timestamp, generate round function scheduling parameters; wherein the round function scheduling parameters include at least one of the following data: the number of encryption rounds, the round key used for encryption, the permutation table used for encryption, and the function combination method used for encryption.

[0071] The round function scheduling parameters can include dynamic configuration parameters for each round of encryption operations. Different parameter groups correspond to different round operation execution logics. These parameters are generated by combining the initial key with a unique current timestamp, ensuring that the round operation configuration is not repeated in each encryption process. This prevents attackers from building statistical models to crack the key by obtaining the same operational patterns through multiple encryptions. The number of encryption rounds represents the total number of round function operations executed in this encryption process. Different round numbers correspond to different encryption strengths, and can adapt to different security level requirements based on the dynamic changes of the timestamp. The round key used for encryption represents the subkey used individually for each round of round function operations. It is generated by combining the initial key with the current timestamp, and the round key is unique for each encryption operation in each round. The permutation table used for encryption can include a permutation rule table used to permutate and obfuscate data bits in the round function operations. Different permutation tables correspond to different data obfuscation and permutation logics. The function combination method used for encryption can include the order in which the basic round functions called in different rounds of multi-round encryption operations are arranged. Different arrangements correspond to different operation flows.

[0072] In one exemplary embodiment, the initial key and the current timestamp can be concatenated and hashed. The resulting hash is then grouped and assigned to different scheduling parameters. Utilizing the one-way and uniform distribution characteristics of the hash function, the randomness of the generated scheduling parameters is ensured, avoiding predictable parameter patterns. Alternatively, the initial key and the current timestamp can be expanded and transformed separately, using XOR, permutation, and other operations to generate the various scheduling parameters, further enhancing the obfuscation of the parameter generation process. When generating round keys, subkeys for each round can be generated iteratively using the initial key and timestamp, ensuring that the encrypted round key sequence is completely unpredictable.

[0073] Step S204: According to the round function scheduling parameters, perform round function encryption on the data to be encrypted to obtain encrypted data.

[0074] Round function encryption executes each round of encryption operations sequentially based on the dynamically generated round function scheduling parameters. Each round of encryption performs obfuscation and diffusion processing on the data to be encrypted according to preset rules and the configuration parameters of the current round. After all rounds of operations are completed, the final encryption result is obtained. Since the round function configuration for each encryption is dynamically adjusted by the current timestamp, even if the same initial key is used to encrypt the same plaintext, the encrypted data obtained at different times will be completely different. This makes it impossible for attackers to obtain a stable operational pattern through multiple observations, and it is difficult to reverse engineer the key through statistical analysis. It also avoids the replay attack risk brought by deterministic encryption, effectively ensuring the semantic security of the encrypted data. In block encryption scenarios, the data to be encrypted can be divided into fixed-length data blocks, and each data block can be encrypted separately according to the dynamically generated round function scheduling parameters. Finally, all the encrypted data blocks are concatenated and integrated to obtain the complete encrypted data, balancing encryption security and processing efficiency.

[0075] In one exemplary embodiment, round function encryption of the data to be encrypted may include sequentially performing a corresponding obfuscation operation on each round function. After each round, the output result is used as the input for the next round, and this process is repeated until all rounds specified by the scheduling parameters are completed, ultimately outputting the encrypted result of the corresponding data group. In each round, the data bits are swapped according to the permutation table specified by the scheduling parameters, and non-linear obfuscation is performed in combination with the corresponding round key. The single round operation is completed according to the combination order of the basic round functions specified by the parameters, achieving sufficient diffusion obfuscation of the data. This ensures that each bit of the output ciphertext depends simultaneously on the initial key, the current timestamp, and the input plaintext, further enhancing the unpredictability of the encryption result.

[0076] In the above data encryption method, the round function scheduling parameters are dynamically generated by combining the initial key with the current timestamp. The uniqueness of the timestamp ensures that the round operation configuration is not repeated in each encryption process, so that the same plaintext can be encrypted at different times to obtain different ciphertexts. This not only retains the confusion and diffusion capabilities of round function encryption, but also solves the problem that deterministic encryption under fixed round function configuration is easy to be statistically analyzed and has the risk of replay attacks. It can effectively improve the security of encrypted data and is suitable for various scenarios that require high-security data transmission and storage.

[0077] In one embodiment, obtaining the initial key includes:

[0078] Obtain parameters for a difficult problem on a lattice.

[0079] A local key pair is generated based on the parameters of the lattice-hard problem; wherein the local key pair includes a first public key and a private key.

[0080] Send the first public key to the target device and receive the second public key returned by the target device.

[0081] Based on the second public key and the private key, a shared key is determined; and an initial key is generated based on the shared key.

[0082] The lattice-based hard problem parameters serve as the foundational parameters for constructing lattice cryptosystems. These parameters can include the lattice's dimension, modulus, and randomly and uniformly selected basis vectors. The selection of these parameters ensures that the solution complexity for typical hard problems such as the minimum integer solution problem and fault-tolerant learning problems meets security requirements, resisting attacks from both classical and quantum computing. Based on the same lattice-based hard problem parameters, both communicating parties independently generate local key pairs containing public and private keys. After parameter initialization, they exchange their first public keys to obtain the other party's second public key. They then perform homomorphic operations using their own private key and the other party's second public key to obtain a shared key known only to both parties. Hash compression and derivation of this shared key yield the initial key used for encryption. Obtaining the initial key through lattice-based key negotiation resists quantum computing attacks and meets the encryption security requirements of the post-quantum era. The acquisition of the lattice-based hard problem parameters can include pre-agreed public parameters or randomly generated by the initiating party and sent to the target device along with the first public key, satisfying parameter configuration requirements in different scenarios.

[0083] In one exemplary embodiment, the dimensionality parameter of the lattice hard problem can be flexibly adjusted according to security requirements. In high-security scenarios, higher-dimensional lattice parameters can be selected to meet different encryption strength requirements while ensuring quantum security. For devices with limited computing power, lower-dimensional lattice parameters can be selected to reduce the computational overhead of key generation and negotiation processes, adapting to the usage requirements of resource-constrained scenarios.

[0084] In this embodiment, the initial key is generated through lattice key negotiation, which eliminates the need to pre-store a large number of preset keys or rely on a trusted third-party institution to distribute keys. This enables both communicating parties to complete key negotiation independently, ensuring the quantum security of the initial key transmission process while reducing the complexity of key management, thus meeting the needs of end-to-end secure communication scenarios.

[0085] In one embodiment, obtaining the current timestamp includes:

[0086] Get the current clock time.

[0087] Convert the current clock time to the target format to obtain a timestamp string.

[0088] The timestamp string is hashed to obtain the current timestamp.

[0089] The current clock time can be directly obtained from the device's system clock. The time precision can be configured to second, millisecond, or microsecond levels as needed. Higher precision results in a lower probability of the same timestamp repeating, leading to better encryption randomness. After converting the current clock time into a fixed-length string, a hash function can be used to obtain a fixed-length hash value as the current timestamp. This ensures consistent timestamp length and leverages the one-way nature of hashing to improve the unpredictability of the timestamp. For example, converting millisecond-level time to a decimal string, performing SHA-256 hashing, and using the first N bits as the current timestamp can adapt to different length requirements while preventing attackers from predicting the timestamp's pattern in advance.

[0090] In one exemplary embodiment, based on the current clock time, a unique device identifier can be concatenated with the current clock time and hashed to obtain the current timestamp. Even if different devices initiate encryption operations at the same time, different timestamps can be generated, further reducing the probability of timestamp collisions and adapting to the security requirements of multi-device parallel encryption scenarios. For devices without a stable system clock, a timestamp-like parameter can also be generated by combining the currently encrypted sequence number and a random number to ensure the uniqueness of the random factor for each encryption.

[0091] In this embodiment, the current timestamp is generated by concatenating and hashing the time obtained from the system clock. This method is simple to implement, ensures that the random factor obtained in each encryption is unique, does not require additional storage of random number states, and does not require a complex random number generation module. This reduces the implementation complexity of the encryption process and effectively avoids the security risks caused by duplicate timestamps.

[0092] In one embodiment, the step of performing round function encryption on the data to be encrypted according to the round function scheduling parameters to obtain encrypted data includes:

[0093] The data to be encrypted is divided into groups to obtain data groups.

[0094] Using the round function scheduling parameters, each data group is encrypted using a round function to obtain an encrypted data group.

[0095] The encrypted data groups are concatenated to obtain encrypted data.

[0096] The process involves dividing the data to be encrypted into multiple groups of a preset fixed length. If the total length of the data is less than the preset length, it is padded with zeros to a multiple of the preset length, ensuring that each data group meets the length requirements of the round function encryption and preventing length mismatches from affecting the encryption operation logic. Each data group independently completes the round operation encryption sequentially according to the dynamically generated round function scheduling parameters, resulting in the corresponding encrypted data group. All encrypted data groups are then concatenated and integrated according to the original grouping order to obtain the complete final encrypted data. This grouping processing method is adaptable to data of arbitrary length and improves encryption processing efficiency through parallel grouping operations, balancing security and processing performance to meet the encryption needs of data of different lengths.

[0097] In one exemplary embodiment, for data to be encrypted that exceeds a preset block length, the encryption result of the previous block can be introduced into the current block for XOR preprocessing via a cryptographic block chaining mode. This ensures that even with the same scheduling parameters, the encryption result of the same plaintext block will differ depending on the preceding block, further enhancing the randomness of the encryption result. For terminal devices with limited computing power, multi-threaded parallel processing of encryption operations on different blocks can shorten the overall encryption time and adapt to the performance requirements of high-speed data encryption scenarios. In this embodiment, the block processing and concatenation method is compatible with data to be encrypted of arbitrary length and can flexibly adapt to the computing power conditions of different devices. It balances processing performance while ensuring encryption security and can adapt to various application scenarios from low-power IoT devices to high-performance servers.

[0098] In this embodiment, the scheduling parameters of the round function for each encryption are dynamically generated by combining the initial key with the current timestamp. This makes the number of encryption rounds, the round key, the permutation table, and the function combination method change dynamically with each encryption. Even if an attacker intercepts multiple sets of ciphertexts corresponding to the same plaintext, they will not be able to figure out a fixed operation pattern to crack the key. At the same time, the unique timestamp can also effectively resist replay attacks, thus improving the security strength of round function encryption from multiple dimensions.

[0099] In one embodiment, generating round function scheduling parameters using the initial key and the current timestamp includes:

[0100] The initial key and the current timestamp are concatenated to obtain the initial parameters.

[0101] The initial parameters are hashed using a hash function to obtain intermediate parameters.

[0102] The intermediate parameters are grouped, and the round function scheduling parameters are determined based on each parameter group.

[0103] The initial parameters, after being concatenated, can be processed through a complete hash operation to obtain intermediate parameters. These fixed-length intermediate parameters are then split into multiple parameter groups according to the bit requirements of the round function scheduling parameters. Each parameter group corresponds to a round function scheduling parameter item. The grouping results are then converted into scheduling parameters of the corresponding type to complete the generation process. If the total length of the intermediate parameters is insufficient to meet the total bit requirements of all scheduling parameters, a fixed salt value can be appended to the initial parameters, and the hash operation can be re-executed. The newly obtained hash result is then concatenated to the original intermediate parameters before grouping, ensuring that the bit requirements of all scheduling parameters are covered and preventing encryption failure due to insufficient length.

[0104] In one exemplary embodiment, the intermediate parameters obtained by hashing can be sequentially split according to the round number, the key of each round, the index of the permutation table, and the bit requirement of the function arrangement order. Each set of parameters obtained by splitting directly maps to the corresponding configuration. For example, the permutation table may pre-store multiple preset permutation rule tables. The corresponding index can be obtained by taking the modulo of the parameter value obtained by grouping with the total number of permutation tables, and the permutation table used for this encryption can be determined. The function combination method directly arranges the preset basic round functions according to the grouped parameter values ​​to obtain the corresponding order. This generation method can guarantee the randomness of each scheduling parameter by taking the uniform randomness of the hash function, and is simple to implement and has high computational efficiency.

[0105] In this embodiment, the round function scheduling parameters are generated by concatenating the initial key and the current timestamp into a hash and then grouping them. This eliminates the need for complex parameter derivation operations and ensures the randomness of the parameters by leveraging mature and efficient hash operations. The implementation process is simple, has low computational overhead, and can adapt to the operating requirements of resource-constrained devices.

[0106] In one embodiment, obtaining the data to be encrypted includes:

[0107] Receive raw plaintext data.

[0108] If the length of the original plaintext data meets the preset length, the original plaintext data is determined to be the data to be encrypted.

[0109] If the length of the original plaintext data does not meet the preset length, the original plaintext data is padded to obtain the data to be encrypted.

[0110] The preset length can be an integer multiple of the block length required for the corresponding block encryption. When the length of the original plaintext data is exactly an integer multiple of the preset length, it can be directly used as the data to be encrypted in the subsequent encryption process. If the length of the original plaintext data is less than an integer multiple of the preset length, padding bits are added to the end of the original plaintext data according to the agreed padding rules. Typically, a fixed identifier bit is added first, followed by several zero bits, until the total length meets the requirements. Alternatively, standardized padding methods such as PKCS#7 can be used to facilitate accurate identification and removal of padding content by the decryption end, restoring the original plaintext length. The padding rules need to be agreed upon in advance by both communicating parties to ensure that the padding content can be correctly stripped during the decryption process without affecting the integrity of the original plaintext. This preprocessing method can adapt to original plaintext data of any length, ensuring that all data matches the length requirements of subsequent block encryption and that the encryption process is not affected by length issues.

[0111] In one exemplary embodiment, the padding identifier and padding length can be embedded in the padding content. Even if the original plaintext length exactly meets the preset length requirement, an additional complete padding block can be added. This prevents attackers from inferring the original plaintext length information by the presence or absence of padding, further reducing the probability of successful side-channel attacks. In this embodiment, through standardized padding preprocessing, original plaintext of any length can be made to match the length requirements of subsequent encryption processes. At the same time, flexible padding rules can be used to adapt to different security protection requirements, ensuring the stable execution of the encryption process.

[0112] In this embodiment, a dynamic round function configuration is generated by combining the initial key with a timestamp, which solves the deterministic encryption defect of the fixed round function configuration. While retaining the advantages of round function encryption in terms of obfuscation and diffusion, it effectively resists statistical analysis and replay attacks. Furthermore, it ensures the quantum security of the initial key through lattice key negotiation. The overall solution is simple to implement and can be adapted to different computing power devices and various security scenarios.

[0113] In one exemplary embodiment, the architecture of the data encryption method can be as follows: Figure 3 As shown, it may specifically include: a key management module 301, an encryption algorithm engine 303, a storage unit module 305, ciphertext 307, a decryption algorithm engine 309, and a security verification module 311, wherein:

[0114] Key Management Module: A lightweight quantum-resistant key exchange protocol is designed based on the ring learning homomorphism (RLWE) and short integer solution (SIS) problems, compressing the public key size to ≤256 bytes and the private key to ≤64 bytes; it supports three negotiation modes (pure quantum-resistant, national cryptographic hybrid, and traditional compatible) mixed with SM2, and dynamically generates a shared master key.

[0115] Encryption Algorithm Engine: Employs a hybrid structure of "block cipher + stream cipher" to implement a dynamic round function mechanism. Driven by the session key and the current timestamp, it generates the round function structure, round key order, and S-box permutation table in real time (e.g., dynamically selecting from 256 preset S-boxes for round number transitions from 8 to 12). It performs obfuscation, diffusion, and nonlinear transformations on the input plaintext and outputs ciphertext data.

[0116] Storage unit module: used to temporarily store intermediate state data, round function scheduling parameters, 256 pre-set nonlinear permutation tables, and temporary session keys during the encryption process, supporting efficient read and write operations of the encryption and decryption engine.

[0117] Ciphertext: As the output of the encryption algorithm engine, it is organized according to the standard encapsulation format and includes version number, timestamp, identity identifier, algorithm identifier, checksum (SM3 / SHA-256) and ciphertext data body for transmission or storage.

[0118] Decryption algorithm engine: After receiving the ciphertext, it parses the header information, verifies the timestamp window (anti-replay attack) and integrity check code, recovers the session key, and performs the inverse transformation of the dynamic round function (inverse obfuscation, inverse diffusion, inverse S-box permutation) to restore the original plaintext.

[0119] Security verification module: Based on HMAC or the national standard SM9 identifier cryptographic algorithm, it performs identity binding verification on the ciphertext to prevent man-in-the-middle attacks; at the same time, it verifies the timestamp freshness and integrity check value to ensure that the ciphertext has not been tampered with or replayed.

[0120] In another exemplary embodiment, the architecture of the data encryption method may also be as follows, specifically including:

[0121] Key Management Layer: A lightweight construction method based on Ring Learning Homomorphism (RLWE) and Short Integer Solution (SIS) problems is introduced to design a compressed quantum-resistant key exchange protocol. By optimizing the dimension and modulus of the polynomial ring, the public key size is compressed to ≤256 bytes and the private key to ≤64 bytes, which is more than 60% smaller than the traditional NTRU scheme. This layer supports a hybrid mode with the SM2 elliptic curve algorithm, and can dynamically select from three negotiation modes: "purely quantum-resistant", "hybrid with Chinese national cryptography", or "traditional compatible".

[0122] The encryption / decryption core layer employs a hybrid structure of block cipher and stream cipher, featuring a dynamic round function mechanism. The encryption process no longer uses a fixed number of rounds and a fixed S-box; instead, it is driven by the session key and timestamps, generating the round function structure, round key order, and S-box permutation table in real time. For example, at a 128-bit security level, the number of rounds can dynamically change between 8 and 12, and the S-box is dynamically selected from a pre-set table of 256 non-linear permutations, significantly increasing the complexity of cryptanalysis.

[0123] Protocol encapsulation and security enhancement layer: The ciphertext encapsulation format includes a version number, timestamp, identity identifier, algorithm identifier, checksum (SM3 or SHA-256), and ciphertext data. Replay attack resistance is achieved through a timestamp window mechanism, and identity binding is implemented through HMAC or the Chinese national cryptographic standard SM9 to prevent man-in-the-middle attacks.

[0124] In another exemplary embodiment, the data encryption method may also be implemented in the following manner, specifically including:

[0125] Initialization: The system generates RLWE parameters (e.g., n=256, q=3329), noise distribution parameters, and the context of the national cryptographic algorithm.

[0126] Key negotiation: The client and server perform a lightweight quantum-resistant key exchange to generate a shared master key; SM2 can be optionally introduced for authentication and key fusion.

[0127] Session key derivation: Using the KDF function, a 128 / 256-bit session key is generated with "master key + random number + timestamp + both parties' IDs" as input.

[0128] Data encryption: After plaintext is grouped, it enters the dynamic round function engine to perform obfuscation, diffusion, and nonlinear transformation; it supports parallel block processing to improve throughput.

[0129] Ciphertext output: Add header information and integrity check code to form a standard ciphertext packet.

[0130] Decryption and verification: The receiver parses the header, verifies the timestamp and integrity, recovers the session key, and performs an inverse transformation to restore the plaintext.

[0131] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.

[0132] Based on the same inventive concept, this application also provides a data encryption device for implementing the data encryption method described above. The solution provided by this device is similar to the implementation described in the above method; therefore, the specific limitations in one or more data encryption device embodiments provided below can be found in the limitations of the data encryption method described above, and will not be repeated here.

[0133] In one embodiment, such as Figure 4 As shown, a data encryption device 400 is provided, including: a data acquisition module 401, a parameter generation module 403, and a data encryption module 405, wherein:

[0134] The data acquisition module is used to acquire the initial key, the data to be encrypted, and the current timestamp;

[0135] The parameter generation module is used to generate round function scheduling parameters using the initial key and the current timestamp; wherein the round function scheduling parameters include at least one of the following data: the number of encryption rounds, the round key used for encryption, the permutation table used for encryption, and the function combination method used for encryption;

[0136] The data encryption module is used to perform round function encryption on the data to be encrypted according to the round function scheduling parameters to obtain encrypted data.

[0137] In one embodiment, the data acquisition module is further configured to:

[0138] Obtain parameters for a lattice-hard problem;

[0139] Based on the parameters of the lattice-hard problem, a local key pair is generated; wherein the local key pair includes a first public key and a private key;

[0140] Send the first public key to the target device and receive the second public key returned by the target device;

[0141] Based on the second public key and the private key, a shared key is determined; and an initial key is generated based on the shared key.

[0142] In one embodiment, the data acquisition module is further configured to:

[0143] Get the current clock time;

[0144] Convert the current clock time into the target format to obtain a timestamp string;

[0145] The timestamp string is hashed to obtain the current timestamp.

[0146] In one embodiment, the data encryption module is further configured to:

[0147] The data to be encrypted is divided into groups to obtain data groups;

[0148] Using the round function scheduling parameters, each data group is encrypted using a round function to obtain an encrypted data group;

[0149] The encrypted data groups are concatenated to obtain encrypted data.

[0150] In one embodiment, the parameter generation module is further configured to:

[0151] The initial key and the current timestamp are concatenated to obtain the initial parameters;

[0152] The initial parameters are hashed using a hash function to obtain intermediate parameters.

[0153] The intermediate parameters are grouped, and the round function scheduling parameters are determined based on each parameter group.

[0154] In one embodiment, the data acquisition module is further configured to:

[0155] Receive raw plaintext data;

[0156] If the length of the original plaintext data meets the preset length, the original plaintext data is determined as data to be encrypted.

[0157] If the length of the original plaintext data does not meet the preset length, the original plaintext data is padded to obtain the data to be encrypted.

[0158] Each module in the aforementioned data encryption device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in the processor of a computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to each module.

[0159] In one embodiment, a computer device is provided, which may be a terminal, and its internal structure diagram may be as follows: Figure 5 As shown, the computer device includes a processor, memory, input / output interfaces, a communication interface, a display unit, and an input device. The processor, memory, and input / output interfaces are connected via a system bus, and the communication interface, display unit, and input device are also connected to the system bus via the input / output interfaces. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The input / output interfaces are used for exchanging information between the processor and external devices. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, mobile cellular networks, NFC (Near Field Communication), or other technologies. When the computer program is executed by the processor, it implements a data encryption method. The display unit is used to form a visually visible image and can be a display screen, a projection device, or a virtual reality imaging device. The display screen can be an LCD screen or an e-ink screen. The input device of the computer device can be a touch layer covering the display screen, or buttons, trackballs, or touchpads set on the casing of the computer device, or external keyboards, touchpads, or mice, etc.

[0160] Those skilled in the art will understand that Figure 5 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0161] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions.

[0162] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments described above. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.

[0163] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0164] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.

Claims

1. A data encryption method, characterized in that, The method includes: Obtain the initial key, the data to be encrypted, and the current timestamp; Using the initial key and the current timestamp, round function scheduling parameters are generated; wherein, the round function scheduling parameters include at least one of the following data: the number of encryption rounds, the round key used for encryption, the permutation table used for encryption, and the function combination method used for encryption; Based on the round function scheduling parameters, the data to be encrypted is encrypted using a round function to obtain encrypted data.

2. The method according to claim 1, characterized in that, The acquisition of the initial key includes: Obtain parameters for a lattice-based hard problem; Based on the parameters of the lattice-hard problem, a local key pair is generated; wherein the local key pair includes a first public key and a private key; Send the first public key to the target device and receive the second public key returned by the target device; Based on the second public key and the private key, a shared key is determined; and an initial key is generated based on the shared key.

3. The method according to claim 1, characterized in that, The acquisition of the current timestamp includes: Get the current clock time; Convert the current clock time into the target format to obtain a timestamp string; The timestamp string is hashed to obtain the current timestamp.

4. The method according to claim 1, characterized in that, The step of performing round function encryption on the data to be encrypted according to the round function scheduling parameters to obtain encrypted data includes: The data to be encrypted is divided into groups to obtain data groups; Using the round function scheduling parameters, each data group is encrypted using a round function to obtain an encrypted data group; The encrypted data groups are concatenated to obtain encrypted data.

5. The method according to claim 1, characterized in that, The step of generating round function scheduling parameters using the initial key and the current timestamp includes: The initial key and the current timestamp are concatenated to obtain the initial parameters; The initial parameters are hashed using a hash function to obtain intermediate parameters. The intermediate parameters are grouped, and the round function scheduling parameters are determined based on each parameter group.

6. The method according to claim 1, characterized in that, The acquisition of the data to be encrypted includes: Receive raw plaintext data; If the length of the original plaintext data meets the preset length, the original plaintext data is determined as data to be encrypted. If the length of the original plaintext data does not meet the preset length, the original plaintext data is padded to obtain the data to be encrypted.

7. A data encryption device, characterized in that, The device includes: The data acquisition module is used to acquire the initial key, the data to be encrypted, and the current timestamp; The parameter generation module is used to generate round function scheduling parameters using the initial key and the current timestamp; wherein the round function scheduling parameters include at least one of the following data: the number of encryption rounds, the round key used for encryption, the permutation table used for encryption, and the function combination method used for encryption; The data encryption module is used to perform round function encryption on the data to be encrypted according to the round function scheduling parameters to obtain encrypted data.

8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 6.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.

10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.