Data verification method and device, storage medium, and program product
By adding a second processing process outside the encryption process, and using the key construction rules to generate encryption parameters and digest information for reference, the problem of large overhead of the encryption process verification resource in the prior art is solved, and efficient data reliability verification is achieved.
Patent Information
- Application Number
- PCT/CN2024/115292
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-19
- Filing Date
- 2024-08-28
- Publication Date
- 2025-06-26
AI Technical Summary
When checking the encryption process, the prior art requires a large amount of data read and write operations and additional memory applications, resulting in large resource overhead. Especially in scenarios such as cloud storage systems with large data traffic, the verification efficiency is insufficient.
A data verification method is proposed. By adding a second processing process outside the encryption process, using preset key construction rules to generate the second encryption parameters and their digest information for reference, and verifying the digest information of the to be processed and ciphertext data to judge the correctness of the encryption process.
By generating summary information that can be deleted as you like and encryption parameters for reference, efficient data reliability verification of the encryption process is achieved, resource overhead is reduced, and verification efficiency is improved.
Smart Images

Figure CN2024115292_26062025_PF_FP_ABST
Abstract
Description
Data verification method, device, storage medium and program product
[0001] This disclosure claims priority to the Chinese patent application filed with the China Patent Office on December 19, 2023, with application number 202311757888.9 and application name “A Data Verification Method, Device and Storage Medium”, the entire contents of which are incorporated by reference into this disclosure. Technical Field
[0002] The present disclosure relates to the field of data security technology, and in particular to a data verification method, device, storage medium, and program product. Background Art
[0003] Cloud storage systems typically support encrypted data storage. For raw data input into the cloud storage system, the cloud storage system encrypts it, generates corresponding ciphertext data, and stores the ciphertext data. When users read data from the cloud storage system, they can perform a decryption operation to decrypt the ciphertext data.
[0004] However, errors can occur during the encryption process. Current verification schemes for this process typically require extensive data read and write operations and require additional memory to support verification operations, resulting in significant resource overhead. In scenarios with high data traffic, such as cloud storage systems, this resource overhead is even more pronounced, leading to insufficient verification efficiency.
[0005] Summary of the Invention
[0006] Various aspects of the present disclosure provide a data verification method, device, storage medium, and program product to improve the efficiency of verifying the reliability of data in an encryption process.
[0007] The present disclosure provides a data verification method, including:
[0008] In a first encryption process for the data to be processed, encryption calculation is performed on the data to be processed based on a first encryption parameter to generate ciphertext data, wherein the first encryption parameter is generated according to a preset key construction rule;
[0009] In a second processing process outside the first processing process, the key construction rule is continued to be used to generate a second encryption parameter for reference for the first encryption parameter and to generate summary information for the second encryption parameter;
[0010] Obtaining summary information generated for the data to be processed and the ciphertext data respectively;
[0011] If the summary information of the second encryption parameter, the summary information of the data to be processed, and the summary information of the ciphertext data meet a preset verification relationship, it is determined that the first processing process passes the verification.
[0012] Furthermore, the summary information uses a cyclic redundancy check code CRC, and the method further includes:
[0013] Using the calculation rule adopted when performing encryption calculation on the data to be processed based on the first encryption parameter, perform the same calculation operation on the cyclic redundancy check code CRC of the second encryption parameter and the cyclic redundancy check code CRC of the data to be processed;
[0014] If the result obtained by the calculation operation is consistent with the cyclic redundancy check code CRC of the ciphertext data, it is determined that the summary information of the second encryption parameter, the summary information of the data to be processed and the summary information of the ciphertext data meet a preset verification relationship.
[0015] Further, performing encryption calculation on the data to be processed based on the first encryption parameter to generate ciphertext data, including:
[0016] Performing an XOR calculation on the first encryption parameter and the data to be processed to generate ciphertext data;
[0017] Performing a calculation operation according to the same rules on a cyclic redundancy check code CRC of the second encryption parameter and a cyclic redundancy check code CRC of the data to be processed, including:
[0018] An exclusive OR calculation is performed on a cyclic redundancy check code CRC of the second encryption parameter and a cyclic redundancy check code CRC of the data to be processed.
[0019] Furthermore, the data to be processed is a data block generated by grouping the original data according to the block encryption AES technology, and the method further includes:
[0020] Before starting the first processing procedure for encrypting the original data, summary information is generated for each data block corresponding to the original data to obtain summary information generated for the data to be processed.
[0021] Furthermore, the data to be processed is a data block generated by grouping the original data according to the block encryption AES technology, the key construction rule adopts the counter CTR mode, and the method further includes:
[0022] Before starting the first process of encrypting the original data, configuring initial parameters of the counter;
[0023] Generate a first parameter copy and a second parameter copy with the same content for the initial parameters;
[0024] In a first encryption process for the original data, a key stream is generated for the original data according to the first parameter copy to generate first encryption parameters corresponding to each of the data blocks;
[0025] In the second processing, a key stream is generated according to the second parameter copies and the number of data blocks corresponding to the original data, so as to produce second encryption parameters corresponding to the respective first encryption parameters.
[0026] Furthermore, the first processing process and the second processing process are run on different CPU cores, or are run on different processes or threads on the same CPU core.
[0027] Furthermore, the first processing process and the second processing process are run in parallel.
[0028] Furthermore, the method may further include:
[0029] If the summary information of the second encryption parameter, the summary information of the data to be processed, and the summary information of the ciphertext data do not conform to the preset verification relationship, it is determined that the encryption process has failed the verification.
[0030] Furthermore, the method may further include:
[0031] If the data to be processed is a data block generated by grouping original data according to the block encryption AES technology, then, if it is determined that the first encryption process for the data to be processed fails to pass the verification, it is determined that the first encryption process for the original data fails to pass the verification;
[0032] The data to be processed is any data block corresponding to the original data.
[0033] Furthermore, the summary information of the second encryption parameter, the summary information of the data to be processed, and the summary information of the ciphertext data are stored in a register associated with the CPU, and are deleted from the register after verification is completed.
[0034] The present disclosure also provides a computing device including a memory, a processor, and a communication component;
[0035] The memory is used to store one or more computer instructions;
[0036] The processor is coupled to the memory and the communication component, and is configured to execute the one or more computer instructions to perform the aforementioned data verification method.
[0037] An embodiment of the present disclosure further provides a computer-readable storage medium storing computer instructions. When the computer instructions are executed by one or more processors, the one or more processors are caused to execute the aforementioned data verification method.
[0038] An embodiment of the present disclosure further provides a computer program product, including a computer program, which implements the aforementioned data verification method when executed by a processor.
[0039] In the embodiment of the present disclosure, it is proposed to add an additional second processing process in addition to the first processing process for encrypting the data to be processed. In the first processing process, a first encryption parameter can be generated for the data to be processed according to a preset key construction rule, and the data to be encrypted can be encrypted based on the first encryption parameter to generate ciphertext data; and in the second processing process, the same key construction rule is used, so that a second encryption parameter for reference can be generated for the first encryption parameter, and summary information can be generated for the second encryption parameter; in addition, the summary information generated for the data to be processed and its ciphertext data can be obtained. In this way, by judging whether the three types of summary information meet the preset verification relationship, it can be found whether there is an error in the first processing process. Accordingly, on the basis of the original encryption logic, by generating several types of summary information that can be used and deleted at will and encryption parameters for reference, the data reliability verification of the encryption process can be completed according to the verification concept provided by the embodiment of the present disclosure, and the required resource overhead is low, so the verification efficiency can be effectively improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] The drawings described herein are used to provide a further understanding of the present disclosure and constitute a part of the present disclosure. The exemplary embodiments of the present disclosure and their descriptions are used to explain the present disclosure and do not constitute an improper limitation of the present disclosure. In the drawings:
[0041] FIG1 is a schematic diagram showing the principle of a relatively typical and commonly used existing verification scheme discovered by the inventors during their research;
[0042] FIG2 is a flow chart of a data verification method provided by an exemplary embodiment of the present disclosure;
[0043] FIG3 is a logic diagram of a data verification method provided by an exemplary embodiment of the present disclosure;
[0044] FIG4 is a schematic diagram of an encryption principle of a CTR mode provided by an exemplary embodiment of the present disclosure;
[0045] FIG5 is a schematic diagram of an optional implementation logic of a data verification method provided by an exemplary embodiment of the present disclosure;
[0046] FIG6 is a schematic diagram of an application scenario provided by an exemplary embodiment of the present disclosure;
[0047] FIG7 is a schematic structural diagram of a computing device provided by another exemplary embodiment of the present disclosure. DETAILED DESCRIPTION
[0048] To make the objectives, technical solutions, and advantages of the present disclosure more clear, the technical solutions of the present disclosure will be clearly and completely described below in conjunction with the specific embodiments of the present disclosure and the corresponding drawings. Obviously, the described embodiments are only part of the embodiments of the present disclosure, not all of the embodiments. Based on the embodiments of the present disclosure, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present disclosure.
[0049] As mentioned in the background, several solutions have emerged that can verify the data reliability of encryption processes. Figure 1 is a schematic diagram illustrating the principles of a typical and commonly used existing verification solution discovered by the inventors during their research. Referring to Figure 1 , this existing verification solution generally requires the following steps:
[0050] 1. After performing encryption calculation on the original data, the encrypted data is obtained.
[0051] 2. After the encryption is completed, the encrypted data is read and decrypted to reconstruct the original data. Additional memory resources need to be applied for storing the reconstructed original data.
[0052] 3. Compare the reconstructed original data with the actual original data. If the two are consistent, the data is determined to be reliable; if the two are inconsistent, the data is determined to be unreliable.
[0053] As can be seen, in existing verification schemes, after the encryption process is completed, the encrypted data generated during the encryption process is then verified for reliability. However, this verification scheme requires multiple data read / write operations. For example, in step 2 alone, the encrypted data must be read and the reconstructed original data must be written to the memory. Furthermore, additional memory resources must be requested to store the reconstructed original data. This results in considerable resource overhead, especially when the original data is large in size. The resource overhead can be multiplied countless times, which in turn increases the latency of the entire encryption process.
[0054] To this end, this embodiment proposes a data verification method to improve the efficiency of verifying the data reliability of the encryption process.
[0055] The technical solutions provided by various embodiments of the present disclosure are described in detail below with reference to the accompanying drawings.
[0056] FIG2 is a flow chart of a data verification method provided by an exemplary embodiment of the present disclosure. The method may be performed by a data verification device, which may be implemented as software, hardware, or a combination of software and hardware. The data verification device may be integrated into a computing device. Referring to FIG2 , the method may include:
[0057] Step 100: In a first encryption process for data to be processed, encryption calculation is performed on the data to be processed based on a first encryption parameter to generate ciphertext data, wherein the first encryption parameter is generated according to a preset key construction rule;
[0058] Step 101: In a second processing process outside the first processing process, a second encryption parameter for reference is generated for the first encryption parameter using a key construction rule, and summary information is generated for the second encryption parameter.
[0059] Step 102: Obtain summary information generated for the data to be processed and the ciphertext data respectively;
[0060] Step 103: If the summary information of the second encryption parameter, the summary information of the data to be processed, and the summary information of the ciphertext data meet a preset verification relationship, it is determined that the first processing process passes the verification.
[0061] The data verification method provided in this embodiment can be applied to various scenarios that require data encryption, such as encrypted storage, encrypted transmission, or encrypted calculation. This embodiment does not limit the application scenarios. The data verification scheme provided in this embodiment can verify the data reliability of the encryption process occurring in the application scenario. It is worth emphasizing that the technical concept of the data verification scheme provided in this embodiment is no longer to verify the reliability of the ciphertext data itself generated after encryption, but to verify the data reliability of the entire encryption process. In other words, the data verification method provided in this embodiment can be used to detect whether an error has occurred in the encryption process to evaluate the data reliability of the encryption process.
[0062] In addition, it is worth noting that the physical implementation form of the computing device used to implement the data verification method in this embodiment may be different in different application scenarios. The computing device in this embodiment can be implemented as a terminal device, such as a personal computer, a smart phone, or a tablet computer. In this case, in this embodiment, data reliability verification can be performed on the encryption process occurring in the terminal device. The computing device in this embodiment can be implemented as a server device such as a conventional server or a cloud server. For example, an encryption node in a cloud storage system. In this case, in this embodiment, data reliability verification can be performed on the encryption process occurring in various types of servers. This embodiment does not limit the physical implementation form of the computing device used to implement the data verification method.
[0063] FIG3 is a logical diagram of a data verification method provided by an exemplary embodiment of the present disclosure. Referring to FIG3 , in the data verification method provided by this embodiment, a second processing process is provided in addition to the first processing process (i.e., the encryption process), that is, the first processing process and the second processing process are independent of each other, do not interfere with each other, and the two processes can be executed in parallel. In this embodiment, the first processing process and the second processing process can run on different CPU cores, and of course, can also run on different processes or threads on the same CPU core. The two processes running on different CPU cores can better avoid the problem of CPU-related silent errors occurring simultaneously in the two processes. Therefore, it can be used as a more preferred deployment scheme in this embodiment. Of course, this embodiment is not limited to this. In this embodiment, it is sufficient to ensure that the two processes can be executed in parallel. Parallel execution can effectively improve the verification efficiency in this embodiment.
[0064] The first process is used to perform encryption according to the original encryption process, while the second process is used to provide reference data support for the data verification solution provided by this embodiment. In addition, it should be understood that in addition to the first and second processes, a verification calculation process can also be provided in this embodiment to cooperate with the first and second processes to complete the data verification solution provided by this embodiment.
[0065] Based on this, referring to FIG1 , in step 100, during the first encryption process for the data to be processed, encryption calculations can be performed on the data to be processed based on first encryption parameters to generate ciphertext data. As mentioned above, the first encryption process in step 100 can be performed according to the original encryption process. This embodiment does not modify or interfere with the first encryption process.
[0066] The data to be processed in step 100 may be data that needs to be encrypted in an application scenario. During research, the inventors discovered that various encryption technologies are employed in the encryption process in various application scenarios. These technologies may include at least bulk encryption and block encryption (AES). Bulk encryption typically encrypts the original data as a whole; whereas block encryption (AES) typically groups the original data into multiple data blocks and then encrypts each block separately. Bulk encryption is typically used when the original data is relatively small, whereas block encryption (AES) is typically used when the original data is relatively large. The data verification method provided in this embodiment is applicable to various encryption technologies and performs data reliability verification on the unit encryption process in each encryption technology. A unit encryption process here can be understood as the encryption process corresponding to the smallest encryption unit used in the encryption technology. For example, in bulk encryption, the smallest encryption unit is the entire original data. In this embodiment, data reliability verification can be performed on the encryption process that encrypts the entire original data. Accordingly, in this case, the data to be processed in step 100 may be the entire original data. For another example, in the block encryption AES technology, the minimum encryption unit is a data block. In this embodiment, the encryption process of each data block can be subjected to data reliability verification. Accordingly, in this case, the data to be processed in step 100 can be any data block corresponding to the original data.
[0067] Continuing with reference to FIG3 , during the encryption process of the data to be processed, encryption parameters are generated for performing encryption calculations on the data to be processed. These are described as first encryption parameters. In this embodiment, the key construction rules for the first encryption parameters are not limited. The key construction rules specify the key construction process and the various parameters required for use in the process. Preferably, the various parameters used in the key construction rules are unrelated to the data content of the data to be processed; that is, the data to be processed does not need to participate in the key construction process.
[0068] Thus, in step 100, the data to be processed may be encrypted according to the original encryption process to generate ciphertext data corresponding to the data to be processed.
[0069] Continuing with reference to Figures 2 and 3, in step 101, a second encryption parameter for reference can be generated from the first encryption parameter using the key construction rules in a second processing process, independent of the first processing process. That is, the second processing process in this embodiment implements a simple key construction process, and the data to be processed does not need to participate in the second processing process. In other words, the second processing process in this embodiment can be understood as an independent key generator that independently uses the key construction rules used in the encryption process to construct a second encryption parameter for reference from the first encryption parameter, without relying on the data to be processed.
[0070] In addition, in step 101, the second encryption parameter is mentioned as a reference for the first encryption parameter. Here, for the case where the overall encryption technology is adopted in the aforementioned step 100, only one first encryption parameter will be involved in the first processing process for encrypting the original data, and only one second encryption parameter will be generated in step 101, which can be used directly for reference. For the case where the block encryption AES technology is adopted in the aforementioned step 100, multiple first encryption parameters may be involved in the first processing process for encrypting the original data (a first encryption parameter is generated for each data block). Therefore, the second encryption parameter generated in step 101 needs to be aligned with the first encryption parameter corresponding to the data to be processed. For example, if the data to be processed is the Nth data block in the original data, then the Nth first encryption parameter is used in step 100, and accordingly, the Nth second encryption parameter is also generated in step 101.
[0071] Therefore, assuming no errors occur during the first process in step 100, the second encryption parameters generated in step 101 should be consistent with the first encryption parameters used in step 100. However, if an error related to key construction occurs during the first process in step 100, the second encryption parameters generated in step 101 will be inconsistent with the first encryption parameters used in step 100. It is worth emphasizing that in this embodiment, it is not necessary to guarantee that the key construction process in step 101 will be completely error-free. If an error related to key construction occurs during the first process in step 100, even if an error also occurs during the key construction process in step 101, the verification result in this embodiment will not be affected. This is because if errors occur in both key construction processes, the encryption parameters generated by each process are generally unlikely to be consistent. Therefore, if an error related to key construction occurs during the first process in step 100, the second encryption parameters generated in step 101 will be inconsistent with the first encryption parameters used in step 100, regardless of whether an error related to key construction also occurs in step 101.
[0072] Referring to Figures 2 and 3, in step 101, summary information is also generated for the second encryption parameter. In this embodiment, the summary information is used to describe the second encryption parameter. Preferably, in this embodiment, a cyclic redundancy check (CRC) code can be used as the summary information. A cyclic redundancy check (CRC) code is a commonly used checksum with error detection and correction capabilities. The CRC code consists of n bits of information code and k bits of checksum. The k-bit checksum bits are spliced after the n-bit data bits, and n+k is the word length of the CRC code, also known as the (n+k, n) code. The principle of the CRC code will not be further described here. Of course, the format of the summary information in this embodiment is not limited to this, and other formats, such as MD5, can also be used. In practical applications, any summary format that can accurately verify the checksum relationship in place of the original data is applicable to this embodiment. This embodiment does not limit the format of the summary information.
[0073] Referring to Figure 3, in this embodiment, in addition to utilizing the summary information of the second encryption parameter, step 102 also includes obtaining summary information generated for the processed data and the ciphertext data. Similarly, the summary information for the processed data can be used to describe the processed data, while the summary information for the ciphertext data is used to describe the ciphertext data. It should be understood that the summary information does not reveal the original data it describes, but rather describes relevant characteristics of the original data. Therefore, it effectively prevents leakage of various aspects of the original data during the encryption process, including the processed data, encryption parameters, and ciphertext data. Furthermore, the summary information is typically small and can be deleted at will. Therefore, using the summary information as a verification basis can effectively improve verification efficiency.
[0074] On this basis, continuing to refer to Figures 2 and 3, in step 103, if the summary information of the second encryption parameter, the summary information of the data to be processed, and the summary information of the ciphertext data meet the preset verification relationship, it is determined that the first processing process passes the verification.
[0075] During their research, the inventors discovered that the ciphertext data is obtained by performing an encryption calculation on the data to be processed based on the aforementioned first encryption parameter. Therefore, if an error occurs during the encryption process, a mathematical operation relationship exists between the ciphertext data, the first encryption parameter, and the data to be processed. This data operation relationship is generally determined by the calculation rules used during the encryption calculation process. Given the existence of a data operation relationship between these three, a mathematical operation relationship also exists between the summary information of these three. In this embodiment, based on the calculation rules used in the encryption calculation in step 100, the data operation relationship that should exist between the ciphertext data, the first encryption parameter, and the summary information of the data to be processed, if no error occurs during the first processing process, can be mined and used as the verification relationship preset in step 103.
[0076] However, this embodiment does not use the summary information of the first encryption parameter for verification. Instead, it proposes using the summary information of the second encryption parameter for verification. Thus, in step 103, it is determined whether the summary information of the second encryption parameter, the summary information of the data to be processed, and the summary information of the ciphertext data meet a preset verification relationship. If so, it can be determined that the first processing process for the data to be processed has passed verification, that is, no errors occurred in the first processing process, and the data reliability is guaranteed. This is because the summary information of the second encryption parameter, the summary information of the data to be processed, and the summary information of the ciphertext data meet the preset verification relationship, indicating that the first processing process in step 100 was performed according to the correct data to be processed and the correct encryption parameters, and the ciphertext data was generated after the correct encryption calculation was performed. Conversely, if an error occurred in the first processing process in step 100, then in step 103, the summary information of the second encryption parameter, the summary information of the data to be processed, and the summary information of the ciphertext data would not meet the preset verification relationship.
[0077] In step 103, an exemplary judgment scheme may be: when the summary information uses a cyclic redundancy check code CRC, the calculation rules used when performing encryption calculations on the data to be processed based on the first encryption parameter can be used to perform the same calculation operation on the cyclic redundancy check code CRC of the second encryption parameter and the cyclic redundancy check code CRC of the data to be processed; if the result obtained by the calculation operation is consistent with the cyclic redundancy check code CRC of the ciphertext data, it is determined that the summary information of the second encryption parameter, the summary information of the data to be processed, and the summary information of the ciphertext data meet the preset verification relationship. In this exemplary judgment scheme, the cyclic redundancy check code CRC is used as the summary information. During the research process, the inventors found that the data operation relationship between the cyclic redundancy check code CRC of the source data is consistent with the mathematical operation relationship between the source data. Therefore, in this exemplary judgment scheme, the mathematical operation relationship between the ciphertext data, the first encryption parameter, and the data to be processed when no error occurs in the first processing process can be used as the verification relationship. Then, the calculation rules adopted in the encryption calculation can be used to perform calculation operations on the cyclic redundancy check code CRC of the second encryption parameter and the cyclic redundancy check code CRC of the data to be processed, and by judging whether the result obtained by the calculation operation is consistent with the cyclic redundancy check code CRC of the ciphertext data, it is determined whether the CRCs of the three meet the verification relationship.
[0078] Furthermore, in this exemplary judgment scheme, the calculation rule adopted by the encryption calculation can be an XOR calculation. Thus, in the aforementioned step 100, an XOR calculation can be performed on the first encryption parameter and the data to be processed to generate ciphertext data. Accordingly, in step 103, an XOR calculation can be performed on the cyclic redundancy check code CRC of the second encryption parameter and the cyclic redundancy check code CRC of the data to be processed. Furthermore, if the result obtained after performing the XOR calculation on these two CRCs is consistent with the CRC corresponding to the ciphertext data generated in step 100, it can be determined that the CRCs of the three meet the verification relationship, thereby determining that the first processing process for encrypting the data to be processed has passed the verification.
[0079] Continuing to refer to FIG3 , in this embodiment, there is also a judgment result, that is, if the summary information of the second encryption parameter, the summary information of the data to be processed, and the summary information of the ciphertext data do not conform to the preset verification relationship, it can be determined that the first processing process for encrypting the data to be processed has not passed the verification. Further, in response to the aforementioned scenario of encryption using the block encryption AES technology, here, the data to be processed can be any data block corresponding to the original data, and in the case of determining that the first processing process for encrypting the data to be processed has not passed the verification, it can be further determined that the first processing process for encrypting the original data has not passed the verification. That is, for the first processing process for encrypting the original data, if the first processing process for encrypting any data block contained therein has not passed the verification, it can be determined that the first processing process for encrypting the original data as a whole has not passed the verification. In actual applications, the verification result can be output, and the verification result does not indicate which data block corresponds to the first processing process for encryption that has not passed the verification, so as to provide a reference for subsequent repair work.
[0080] The following analyzes the accuracy of the verification result in step 103 through several possible error situations that may occur during the encryption process.
[0081] 1. If a silent memory-related error occurs, the data to be processed may not be correctly read into the memory. In this case, incorrect data to be processed is used during the encryption process, resulting in errors in the generated ciphertext data. Accordingly, the summary information of the ciphertext data is also incorrect. In this case, in step 103, because the summary information of the ciphertext data is incorrect, even if the summary information of the second encryption parameter used and the summary information of the data to be processed are correct, the summary information of the second encryption parameter, the summary information of the data to be processed, and the summary information of the ciphertext data will not conform to the verification relationship. In addition, if a silent memory-related error occurs, the ciphertext data written into the memory may be incorrect, that is, the ciphertext data is not correctly written into the memory. In this case, the summary information of the ciphertext data will also be incorrect. Similarly, in this case, the summary information of the three in step 103 will not conform to the verification relationship. It can be seen that if a silent memory-related error occurs, the first encryption process of the data to be processed in step 103 will fail verification.
[0082] 2. If there is a silent CPU-related error, such as an inaccurate reading of relevant parameters during key construction or anomalies in CPU instruction execution or register data during calculation, the first encryption parameter used for encryption may be incorrect. This will result in errors in the generated ciphertext data and, accordingly, the summary information of the ciphertext data will also be incorrect. In this case, in step 103, since the summary information of the ciphertext data is incorrect, even if the summary information of the second encryption parameter used and the summary information of the processed data are correct, the summary information of the second encryption parameter, the summary information of the processed data, and the summary information of the ciphertext data will inevitably not conform to the verification relationship. If there is a silent CPU-related error, it may also cause errors in the encryption calculation operation performed on the processed data, resulting in incorrect ciphertext data. Similarly, in this case, the summary information of the three in step 103 will also not conform to the verification relationship. It can be seen that if there is a silent CPU-related error, the first encryption process for the processed data in step 103 will fail verification.
[0083] It can be seen that the data verification concept proposed in this embodiment can cover various errors that may occur during the encryption process. Errors occurring during the encryption process will cause the summary information of the second encryption parameter in this embodiment, the summary information of the data to be processed, and the summary information of the ciphertext data to no longer conform to the preset verification relationship. Therefore, in this embodiment, it is possible to detect in time that an error has occurred in the encryption process, and then efficiently determine that the encryption process no longer has data reliability.
[0084] In addition, it is worth emphasizing that in the data verification concept provided by this embodiment, in addition to the resource overhead originally required for the encryption process, the additional resource overhead caused by verification is very low. This is because the second encryption parameter involved in step 101 can be deleted as needed, and the various summary information involved in steps 102 and 103 can also be deleted as needed. In this embodiment, there is no need to apply for additional memory resources to store these data used to support verification. Instead, in the process of the CPU executing the data verification concept provided by this embodiment, the CPU-associated registers can be used to store the second encryption parameters and various summary information used in the verification process, and these data can be deleted as needed in the registers. That is, these data are stored in the registers during the calculation process, and after the calculation is completed, the data that has been used can be deleted from the registers. Therefore, the resource overhead caused by the verification process in this embodiment is very low, and accordingly, the verification efficiency will be higher.
[0085] In summary, in this embodiment, it is proposed to add an additional second processing process in addition to the first processing process for encrypting the data to be processed. In the encryption process, a first encryption parameter can be generated for the data to be processed according to a preset key construction rule, and the data to be encrypted can be encrypted based on the first encryption parameter to generate ciphertext data; and in the second processing process, the same key construction rule is used, so that a second encryption parameter for reference can be generated for the first encryption parameter, and summary information can be generated for the second encryption parameter; in addition, the summary information generated for the data to be processed and its ciphertext data can also be obtained. In this way, by judging whether the three types of summary information meet the preset verification relationship, it can be found whether there is an error in the first processing process. Accordingly, on the basis of the original encryption logic, by generating several types of summary information that can be used and deleted at will and encryption parameters for reference, the data reliability verification of the first processing process can be completed according to the verification concept provided by the embodiment of the present disclosure, and the required resource overhead is low, so the verification efficiency can be effectively improved.
[0086] In the above or following embodiments, as mentioned above, the original data can be encrypted using the block encryption AES technology, and the aforementioned data to be processed can be any data block obtained after the original data is grouped. Moreover, in this case, preferably, in step 100 and step 101, the key construction rule can adopt the CTR mode rule. The full name of the CTR mode is CounTeR mode (counter mode). The CTR mode is a stream cipher that generates a key stream by encrypting a counter that accumulates successively. Figure 4 is a schematic diagram of the encryption principle of a CTR mode provided by an exemplary embodiment of the present disclosure. Referring to Figure 4, in this mode, a counter (software) is configured for the first processing process. The counter can start from the starting count value and accumulate successively according to the number of data blocks grouped in the original data. In this way, each data block can obtain a count value. On this basis, each count value can be encrypted separately using a preset encryption key to generate an encrypted string corresponding to each data block (as a first encryption parameter). Thus, during the first processing of the original data, a corresponding first encryption parameter can be generated for each data block, and then the data block can be XORed with its corresponding first encryption parameter to generate ciphertext data.
[0087] Figure 5 is a schematic diagram of an optional implementation logic of a data verification method provided by an exemplary embodiment of the present disclosure. Referring to Figure 5, in this embodiment, the CTR mode rule is used to generate encryption parameters in both the first processing process and the second processing process.
[0088] Based on this, in this embodiment:
[0089] Before starting the first process of encrypting the original data, initial parameters of the counter may be configured;
[0090] Generate a first parameter copy and a second parameter copy with the same content for the initial parameter;
[0091] In the first processing process for the original data, a key stream may be generated for the original data according to the first parameter copy to generate first encryption parameters corresponding to each data block;
[0092] In the second processing, a key stream may be generated according to the second parameter copies and the number of data blocks corresponding to the original data, so as to generate second encryption parameters corresponding to the respective first encryption parameters.
[0093] That is, the counters in the first and second processing steps follow the same initial parameters. Furthermore, in this embodiment, the number of data blocks corresponding to the original data is used as another parameter in the second processing step. This ensures that the same number of encryption parameters are generated in the first and second processing steps. Therefore, the encryption parameters generated by the counters in the first and second processing steps are one-to-one corresponding. Thus, in this embodiment, the first encryption parameters generated for the data to be processed according to the CTR mode rules can be referenced in the first processing step for encrypting the data to be processed, while in the second processing step, encryption parameters are independently constructed according to the CTR mode rules to generate second encryption parameters for reference based on the first encryption parameters.
[0094] It should be understood that the first process of encrypting the original data generates a keystream in CTR mode. Similarly, the second process also generates a keystream in CTR mode. The encryption parameters in the two keystreams correspond one-to-one. Moreover, as mentioned above, the encryption parameters in the keystream can be deleted as needed and do not occupy memory resources.
[0095] In addition, in this embodiment, during the encryption process, it supports the simultaneous construction of encryption parameters for multiple data blocks in a parallel manner; similarly, in the second processing process, encryption parameters can also be constructed in a parallel manner, which can also effectively improve the encryption parameter construction efficiency in the second processing process, thereby improving the verification efficiency.
[0096] Furthermore, in this embodiment, before initiating the first process for encrypting the original data, digest information can be generated for each data block corresponding to the original data to obtain digest information generated for the data to be processed. In this way, after initiating the first process for encrypting the original data, the already generated digest information can be directly called for verification, which can further improve verification efficiency. Of course, this is only a preferred embodiment. In this embodiment, digest information can also be generated for each data block in the original data during the encryption process, and this embodiment is not limited to this.
[0097] In summary, this embodiment supports the use of block encryption AES technology to group original data into multiple data blocks, and supports the use of the CTR mode to generate a key stream for the encryption process. In the second processing process, the key stream is also generated according to the CTR mode, and the encryption parameters in the two key streams generated in the second processing process and the encryption process can be guaranteed to correspond one-to-one. Therefore, during the verification of the encryption process of a single data block, the correct second encryption parameters can be used, thereby ensuring the accuracy of the verification process. The encryption parameters in the key stream can be deleted at any time, so there is no additional resource overhead, which can effectively improve verification efficiency.
[0098] FIG6 is a schematic diagram of an application scenario provided by an exemplary embodiment of the present disclosure. Referring to FIG6 , the data verification method provided by this embodiment can be applied to a cloud storage system to perform data reliability verification on the encryption process occurring in the cloud storage system. Specifically, referring to FIG6 , the data verification method provided by this embodiment can be implemented by an encryption node in the cloud storage system. Of course, this is merely exemplary. Depending on the deployment architecture in the cloud storage system, the data verification method provided by this embodiment can also be implemented by other nodes in the cloud storage system, and this is not limited here.
[0099] Referring to Figure 6, in this application scenario, the original data input to the cloud storage system is encrypted using the AES encryption technology in CTR mode. The specific encryption process can be referred to in the previous description and will not be repeated here.
[0100] Referring to Figure 6, in this application scenario, a first processing process and a second processing process, which are independent of each other, can be created on the encryption node. These two processes can be deployed on different CPU cores in the encryption node. The encryption process can be used to perform the aforementioned encryption work on the original data.
[0101] Furthermore, two identical parameter copies can be generated for the initial parameters used in CTR mode: parameter copy 1 and parameter copy 2. These two parameter copies can each record the initial parameters required for CTR mode, including but not limited to the initial counter value and the preset encryption key. In this way, the encryption process and the secondary processing can run in parallel to generate key streams based on the number of data blocks grouped into the original data. For example, using the blackened data block in Figure 6, the encryption process and the secondary processing will each generate encryption parameters corresponding to the position of that data block in the entire data stream.
[0102] On this basis, we can obtain the CRC1 corresponding to the data block, the CRC2 of the encryption parameter corresponding to the position of the data block in the entire data stream in the bypass processing flow, and the CRC3 of the ciphertext data generated after the data block is encrypted during the encryption process.
[0103] Afterwards, based on the calculation rules used in the encryption calculation in CTR mode: perform XOR calculation on the encryption parameter and the data block to generate the ciphertext data. The first encryption process for the data block is then determined to have passed verification. If the first encryption process for each data block of the original data passes verification, then the entire encryption process for the original data can be determined to have passed verification. In this case, the ciphertext data corresponding to the original data can be stored in the storage node. If the verification fails, storage can be omitted. In practical applications, re-encryption can be attempted, or relevant repair work can be performed before re-encryption. This ensures the reliability of the ciphertext data stored in the storage node.
[0104] It can be seen that the data verification method provided by this embodiment does not require additional data read and write operations outside the original encryption process, nor does it require additional memory resources. Therefore, the additional resource overhead caused by verification is very low, which can effectively improve verification efficiency and effectively ensure verification accuracy.
[0105] It should be noted that some of the processes described in the above embodiments and the accompanying drawings include multiple operations that appear in a specific order, but it should be clearly understood that these operations may not be executed in the order in which they appear in this document or may be executed in parallel. The serial numbers of the operations, such as 101, 102, etc., are only used to distinguish between different operations, and the serial numbers themselves do not represent any execution order. In addition, these processes may include more or fewer operations, and these operations may be executed in sequence or in parallel. It should be noted that the descriptions of "first", "second", etc. in this document are used to distinguish different encryption parameters, etc., and do not represent the order of precedence, nor do they limit "first" and "second" to different types.
[0106] FIG7 is a schematic diagram of a computing device according to another exemplary embodiment of the present disclosure. As shown in FIG7 , the computing device includes a memory 70 , a processor 71 , and a communication component 72 .
[0107] The processor 71 is coupled to the memory 70 and is configured to execute the computer program in the memory 70 to:
[0108] In a first encryption process for the data to be processed, encryption calculation is performed on the data to be processed based on a first encryption parameter to generate ciphertext data, wherein the first encryption parameter is generated according to a preset key construction rule;
[0109] In a second processing process outside the encryption process, the key construction rule is continued to be used to generate a second encryption parameter for reference for the first encryption parameter and to generate summary information for the second encryption parameter;
[0110] Obtaining summary information generated for the data to be processed and the ciphertext data respectively;
[0111] If the summary information of the second encryption parameter, the summary information of the data to be processed, and the summary information of the ciphertext data meet a preset verification relationship, it is determined that the encryption process passes the verification.
[0112] In an optional embodiment, the summary information uses a cyclic redundancy check code (CRC), and the processor 71 may further be configured to:
[0113] Using the calculation rule adopted when performing encryption calculation on the data to be processed based on the first encryption parameter, perform the same calculation operation on the cyclic redundancy check code CRC of the second encryption parameter and the cyclic redundancy check code CRC of the data to be processed;
[0114] If the result obtained by the calculation operation is consistent with the cyclic redundancy check code CRC of the ciphertext data, it is determined that the summary information of the second encryption parameter, the summary information of the data to be processed and the summary information of the ciphertext data meet a preset verification relationship.
[0115] In an optional embodiment, when the processor 71 performs encryption calculation on the data to be processed based on the first encryption parameter to generate ciphertext data, it can be specifically configured to:
[0116] Performing an XOR calculation on the first encryption parameter and the data to be processed to generate ciphertext data;
[0117] Performing a calculation operation according to the same rules on a cyclic redundancy check code CRC of the second encryption parameter and a cyclic redundancy check code CRC of the data to be processed, including:
[0118] An exclusive OR calculation is performed on a cyclic redundancy check code CRC of the second encryption parameter and a cyclic redundancy check code CRC of the data to be processed.
[0119] In an optional embodiment, the data to be processed is a data block generated by grouping the original data according to the block encryption AES technology, and the processor 71 can also be used to:
[0120] Before starting the first processing procedure for encrypting the original data, summary information is generated for each data block corresponding to the original data to obtain summary information generated for the data to be processed.
[0121] In an optional embodiment, the data to be processed is a data block generated by grouping the original data according to the block encryption AES technology, and the key construction rule adopts the counter CTR mode. The processor 71 can also be used to:
[0122] Before starting the first process of encrypting the original data, configuring initial parameters of the counter;
[0123] Generate a first parameter copy and a second parameter copy with the same content for the initial parameters;
[0124] In a first encryption process for the original data, a key stream is generated for the original data according to the first parameter copy to generate first encryption parameters corresponding to each of the data blocks;
[0125] In the second processing, a key stream is generated according to the second parameter copies and the number of data blocks corresponding to the original data, so as to produce second encryption parameters corresponding to the respective first encryption parameters.
[0126] In an optional embodiment, the encryption process and the second processing process are run on different CPU cores, or are run on different processes or threads on the same CPU core.
[0127] In an optional embodiment, the encryption process and the second processing process are run in parallel.
[0128] In an optional embodiment, the processor 71 may also be configured to:
[0129] If the summary information of the second encryption parameter, the summary information of the data to be processed, and the summary information of the ciphertext data do not conform to the preset verification relationship, it is determined that the encryption process has failed the verification.
[0130] In an optional embodiment, the processor 71 may also be configured to:
[0131] If the data to be processed is a data block generated by grouping original data according to the block encryption AES technology, then, if it is determined that the first encryption process for the data to be processed fails to pass the verification, it is determined that the first encryption process for the original data fails to pass the verification;
[0132] The data to be processed is any data block corresponding to the original data.
[0133] In an optional embodiment, the summary information of the second encryption parameter, the summary information of the data to be processed, and the summary information of the ciphertext data are stored in a register associated with the CPU, and are deleted from the register after verification is completed.
[0134] Furthermore, as shown in Figure 7 , the computing device further includes other components such as a power supply component 73. Figure 7 only schematically illustrates some components, which does not mean that the computing device only includes the components shown in Figure 7 .
[0135] It is worth noting that the technical details in the above-mentioned embodiments of the computing device can be referred to the relevant description in the aforementioned method embodiment. In order to save space, they will not be repeated here, but this should not cause any loss of the scope of protection of this disclosure.
[0136] Accordingly, an embodiment of the present disclosure further provides a computer-readable storage medium storing a computer program, which, when executed, can implement the steps that can be executed by a computing device in the above method embodiment.
[0137] An embodiment of the present disclosure further provides a computer program product, including a computer program, which, when executed by a processor, implements the steps that can be executed by a computing device in the above method embodiment.
[0138] The memory in FIG. 7 is used to store computer programs and can be configured to store various other data to support operations on the computing platform. Examples of such data include instructions for any application or method operating on the computing platform, contact data, phone book data, messages, images, videos, etc. The memory can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk, or optical disk.
[0139] The communication component in Figure 7 above is configured to facilitate wired or wireless communication between the device where the communication component is located and other devices. The device where the communication component is located can access a wireless network based on a communication standard, such as WiFi, 2G, 3G, 4G / LTE, 5G and other mobile communication networks, or a combination thereof. In an exemplary embodiment, the communication component receives a broadcast signal or broadcast-related information from an external broadcast management system via a broadcast channel. In an exemplary embodiment, the communication component also includes a near field communication (NFC) module to facilitate short-range communication. For example, the NFC module can be implemented based on radio frequency identification (RFID) technology, infrared data association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology and other technologies.
[0140] The power supply assembly in Figure 7 provides power to various components of the device in which the power supply assembly is located. The power supply assembly may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power to the device in which the power supply assembly is located.
[0141] Those skilled in the art will appreciate that the embodiments of the present disclosure may be provided as methods, systems, or computer program products. Therefore, the present disclosure may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the present disclosure may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0142] The present disclosure is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present disclosure. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device produce a device for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0143] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a product including an instruction device that implements the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0144] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0145] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.
[0146] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this disclosure are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of relevant countries and regions, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0147] The foregoing description is merely an embodiment of the present disclosure and is not intended to limit the present disclosure. Persons skilled in the art will readily appreciate that various modifications and variations of the present disclosure are possible. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present disclosure are intended to be within the scope of protection of the present disclosure.
Claims
1. A data verification method, wherein: include: In a first processing process for encrypting the data to be processed, encryption calculation is performed on the data to be processed based on a first encryption parameter to generate ciphertext data, wherein the first encryption parameter is generated according to a preset key construction rule; In a second processing process outside the first processing process, the key building rule is used to generate a second encryption parameter for reference for the first encryption parameter and to generate summary information for the second encryption parameter; Obtain summary information generated for the data to be processed and the ciphertext data respectively; If the summary information of the second encryption parameter, the summary information of the data to be processed, and the summary information of the ciphertext data satisfy a preset verification relationship, it is determined that the first processing process passes the verification.
2. The method according to claim 1, wherein: The summary information uses a cyclic redundancy check code CRC, and the method further includes: Using the calculation rule used when performing encryption calculation on the data to be processed based on the first encryption parameter, perform the same calculation operation on the cyclic redundancy check code CRC of the second encryption parameter and the cyclic redundancy check code CRC of the data to be processed; If the result obtained by the calculation operation is consistent with the cyclic redundancy check code CRC of the ciphertext data, it is determined that the summary information of the second encryption parameter, the summary information of the data to be processed and the summary information of the ciphertext data meet a preset verification relationship.
3. The method according to claim 2, wherein: Performing encryption calculation on the data to be processed based on the first encryption parameter to generate ciphertext data, including: Performing an XOR calculation on the first encryption parameter and the data to be processed to generate ciphertext data; Performing a calculation operation according to the same rule on the cyclic redundancy check code CRC of the second encryption parameter and the cyclic redundancy check code CRC of the data to be processed, including: An exclusive OR calculation is performed on a cyclic redundancy check code CRC of the second encryption parameter and a cyclic redundancy check code CRC of the data to be processed.
4. The method according to claim 1, wherein: The data to be processed is a data block generated by grouping the original data according to the block encryption AES technology, and the method further includes: Before starting the first processing procedure for encrypting the original data, summary information is generated for each data block corresponding to the original data to obtain summary information generated for the data to be processed.
5. The method according to claim 1, wherein: The data to be processed is a data block generated by grouping the original data according to the block encryption AES technology, the key construction rule adopts the counter CTR mode, and the method further includes: Before starting the first processing procedure for encrypting the original data, configuring initial parameters of the counter; Generate a first parameter copy and a second parameter copy with the same content for the initial parameters; In a first processing process for encrypting the original data, a key stream is generated for the original data according to the first parameter copy to generate first encryption parameters corresponding to each data block; In the second processing process, a key stream is generated according to the number of data blocks corresponding to the second parameter copies and the original data to produce second encryption parameters corresponding to each first encryption parameter.
6. The method according to claim 1, wherein: The first processing process and the second processing process are run on different CPU cores, or are run on different processes or threads on the same CPU core.
7. The method according to claim 1 or 6, wherein: The first process and the second process are run in parallel.
8. The method according to any one of claims 1 to 6, wherein: Also includes: If the summary information of the second encryption parameter, the summary information of the data to be processed, and the summary information of the ciphertext data do not conform to the preset verification relationship, it is determined that the first processing process has failed the verification.
9. The method according to claim 8, wherein: Also includes: If the data to be processed is a data block generated by grouping the original data according to the block encryption AES technology, then when it is determined that the first processing process for encrypting the data to be processed fails to pass the verification, it is determined that the first processing process for encrypting the original data fails to pass the verification; The data to be processed is any data block corresponding to the original data.
10. The method according to any one of claims 1 to 6, wherein: The summary information of the second encryption parameter, the summary information of the data to be processed and the summary information of the ciphertext data are stored in a register associated with the CPU, and are deleted from the register after verification is completed.
11. A computing device, wherein: Includes memory, processor, and communication components; The memory is used to store one or more computer instructions; The processor is coupled to the memory and the communication component, and is used to execute the one or more computer instructions to execute the data verification method according to any one of claims 1-10.
12. A computer-readable storage medium storing computer instructions, wherein: When the computer instructions are executed by one or more processors, the one or more processors are caused to execute the data verification method according to any one of claims 1 to 10.
13. A computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the data verification method according to any one of claims 1 to 10 is implemented.
Citation Information
Patent Citations
Data encryption / decryption checking method and system
CN102437910A
Data encryption method, checkout method, encryption device and checkout device
CN108920971A
Encryption method and device for positioning error
CN114722406A
Message transmission method, message verification method, device, equipment, medium and product
CN116684102A
Information verification method and related apparatus, device, and storage medium
US20230071847A1