Data encryption method and apparatus, data decryption method and apparatus, and storage medium

By determining the verification data and encryption method according to the data to be transmitted and the target platform during the data transmission process, the data is randomly encrypted, and the problem of insufficient security and reliability of data transmission in the SOME/IP protocol is solved, and the security and reliability of data transmission are improved.

WO2025152971A1PCT designated stage expired Publication Date: 2025-07-24CHONGQING CHANGAN TECH CO LTD

Patent Information

Application Number
PCT/CN2025/072526
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-17
Filing Date
2025-01-15
Publication Date
2025-07-24

AI Technical Summary

Technical Problem

The existing SOME/IP protocol fails to effectively ensure the security and reliability of data transmission in the automotive industry, which affects the security and efficiency of data transmission.

Method used

By obtaining the data to be transmitted at the data sending end, determining the verification data based on the data to be transmitted and the target platform, and selecting the target encryption method from the preset password book, and grouping packets of the data to be transmitted. The encryption process has a certain randomness and improves data security and reliability.

Benefits of technology

Improves the security and reliability during data transmission, ensures the security of data during transmission, and improves the reliability of data by verifying data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025072526_24072025_PF_FP_ABST
    Figure CN2025072526_24072025_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to a data encryption method and apparatus, a data decryption method and apparatus, and a storage medium. The data encryption method comprises: acquiring data to be transmitted of a data sending end, wherein the data sending end corresponds to a target platform; determining check data on the basis of the data to be transmitted and the target platform; determining a target encryption mode from a preset codebook on the basis of the data to be transmitted and the target platform; and on the basis of the target encryption mode and the check data, packing the data to be transmitted, so as to obtain target transmission data. In the present application, the check data can be determined on the basis of the data to be transmitted and the target platform corresponding to the data sending end, and the target encryption mode can be determined from the preset codebook on the basis of the data to be transmitted and the target platform, so that the encryption mode in an encryption process has certain randomness, the security of the target transmission data in a transmission process is improved, the data security is ensured, and the data reliability is improved by means of the check data.
Need to check novelty before this filing date? Find Prior Art

Description

Data encryption method, data decryption method, device and storage medium

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims priority and benefits of patent application No. 202410073081.1 filed with the State Intellectual Property Office of China on January 17, 2024, and the entire text of which is incorporated herein by reference. Technical Field

[0003] The present application relates to the technical field of data transmission, and in particular to a data encryption method, a data decryption method, a device and a storage medium. Background Art

[0004] SOME / IP is an automotive middleware solution suitable for different sizes and different platforms (i.e., different operating systems). It can ensure that vehicles support functions in the infotainment field and other areas of the vehicle. It can be used in both MOST replacement scenarios and more traditional CAN scenarios. It is currently the most core communication protocol for implementing SOA architecture in the automotive industry. However, it does not take into account the security, reliability, and efficiency of the data transmission process, which affects the security of data transmission. Summary of the Invention

[0005] In order to solve the above technical problems or at least partially solve the above technical problems, the present application provides a data encryption method, a data decryption method, a device and a storage medium.

[0006] In a first aspect, the present application provides a data encryption method, the method comprising:

[0007] Acquire data to be transmitted from a data sending end; wherein the data sending end corresponds to a target platform;

[0008] Determining verification data according to the data to be transmitted and the target platform;

[0009] Determining a target encryption method from a preset code book according to the data to be transmitted and the target platform;

[0010] The data to be transmitted is packaged according to the target encryption method and the verification data to obtain target transmission data.

[0011] Optionally, determining verification data according to the data to be transmitted and the target platform includes:

[0012] Obtaining a target time for receiving the data to be transmitted;

[0013] Determining the verification data according to the data to be transmitted, the target time and the target platform;

[0014] Determining a splicing position of the verification data according to the target time;

[0015] Accordingly, the data to be transmitted is packaged according to the target encryption mode and the verification data to obtain target transmission data, including:

[0016] The data to be transmitted is packaged according to the target encryption method, the verification data and the splicing position to obtain target transmission data.

[0017] Optionally, determining a target encryption mode from a preset code book according to the data to be transmitted and the target platform includes:

[0018] Obtaining indication information carried by the data to be transmitted; wherein the indication information is used to indicate an encryption method and / or an encryption level;

[0019] According to the target platform, the encryption method and / or the encryption level, the target encryption method of the data to be transmitted is determined from the preset code book.

[0020] Optionally, if the data to be transmitted does not carry the indication information, determining the target encryption mode from the preset code book according to the data to be transmitted and the target platform includes:

[0021] Determining at least two encryption modes from the preset code book according to the target time of the data to be transmitted and the target platform, and randomly determining a target encryption mode from the at least two encryption modes;

[0022] or,

[0023] All encryption methods with processing speeds greater than a target processing threshold are determined from the preset code book according to the data to be transmitted and the target platform, and a target encryption method is randomly determined from all the encryption methods.

[0024] Optionally, the splicing position includes a data header or a data tail.

[0025] Optionally, the method further includes:

[0026] Get the target encryption and decryption algorithm to be added;

[0027] The code book is updated according to the target encryption and decryption algorithm.

[0028] In a second aspect, the present application provides a data decryption method, the method comprising:

[0029] The data receiving end obtains the received target transmission data; wherein the target transmission data carries verification data;

[0030] Verifying the verification data;

[0031] When the verification data passes the verification, the target transmission data is decrypted according to the preset code book to obtain decrypted data, wherein the preset code book is the same as the code book used by the data sending end for encryption.

[0032] In a third aspect, the present application provides a data encryption device, the device comprising:

[0033] A first acquisition module is used to acquire data to be transmitted from a data sending end; wherein the data sending end corresponds to a target platform;

[0034] A first determining module, configured to determine verification data based on the data to be transmitted and the target platform;

[0035] A second determining module, configured to determine a target encryption method from a preset code book according to the data to be transmitted and the target platform;

[0036] The encryption module is used to package the data to be transmitted according to the target encryption method and the verification data to obtain target transmission data.

[0037] In a fourth aspect, the present application provides a data decryption device, comprising:

[0038] A second acquisition module is used for the data receiving end to acquire the received target transmission data; wherein the target transmission data carries verification data;

[0039] A verification module, configured to verify the verification data;

[0040] The decryption module is used to decrypt the target transmission data according to a preset code book to obtain decrypted data when the verification data passes the verification, wherein the preset code book is the same as the code book used by the data sending end to encrypt.

[0041] In a fifth aspect, the present application provides an electronic device, comprising a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other via the communication bus;

[0042] Memory for storing computer programs;

[0043] The processor is used to implement the data encryption method described in any one of the embodiments of the first aspect or the data decryption method described in any one of the embodiments of the second aspect when executing the program stored in the memory.

[0044] In a sixth aspect, the present application provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, it implements the data encryption method as described in any one of the embodiments of the first aspect or the data decryption method as described in any one of the embodiments of the second aspect.

[0045] Beneficial effects of this application:

[0046] The method provided in the embodiment of the present application obtains the data to be transmitted from the data sending end; wherein the data sending end corresponds to a target platform; verification data is determined based on the data to be transmitted and the target platform; a target encryption method is determined from a preset password book based on the data to be transmitted and the target platform; the data to be transmitted is packaged according to the target encryption method and the verification data to obtain the target transmission data. This method can determine verification data based on the data to be transmitted and the target platform corresponding to the data sending end, and determine the target encryption method from a preset password book based on the data to be transmitted and the target platform, thereby making the encryption method in the encryption process have a certain degree of randomness, thereby improving the security of the target transmission data during the transmission process, ensuring data security, and improving data reliability through verification data. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0048] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0049] FIG1 is a system architecture diagram of a data encryption method provided by one embodiment of the present application;

[0050] FIG2 is a schematic diagram of a flow chart of a data encryption method provided in one embodiment of the present application;

[0051] FIG3 is a data encryption flow chart provided by an embodiment of the present application;

[0052] FIG4 is a flow chart of a data decryption method provided in one embodiment of the present application;

[0053] FIG5 is a data decryption flow chart provided by one embodiment of the present application;

[0054] FIG6 is a schematic diagram of the structure of a data encryption device provided by one embodiment of the present application;

[0055] FIG7 is a schematic structural diagram of a data decryption device provided by one embodiment of the present application;

[0056] FIG8 is a schematic structural diagram of an electronic device provided in one embodiment of the present application. DETAILED DESCRIPTION

[0057] The following will describe the embodiments of the present application with reference to the accompanying drawings and preferred embodiments. Those skilled in the art can easily understand the other advantages and effects of the present application from the contents disclosed in this specification. The present application can also be implemented or applied through other different specific embodiments, and the details in this specification can also be modified or changed in various ways based on different viewpoints and applications without departing from the spirit of the present application. It should be understood that the preferred embodiments are only for the purpose of illustrating the present application and are not intended to limit the scope of protection of the present application.

[0058] The first embodiment of the present application provides a data encryption method, which can be applied to the system architecture shown in Figure 1. The system architecture includes at least a data sending end 101 and a data receiving end 102. The data sending end 101 and the data receiving end 102 establish a communication connection, and the data sending end 101 and the data receiving end 102 transmit data through a Scalable service-oriented communication middleware protocol over IP (SOME / IP protocol for short) based on the IP protocol.

[0059] This method can be applied to the data sending end 101 or the data receiving end 102 in the system architecture. Next, based on the system architecture, the data encryption method and the data decryption method in the data transmission process are described in detail.

[0060] A data encryption method, as shown in FIG2 , includes:

[0061] Step 201: Acquire data to be transmitted from a data sending end, wherein the data sending end corresponds to a target platform.

[0062] The target platform refers to the operating system platform of the data sender, such as Linux, Windows, Android and other platforms.

[0063] Step 202: Determine verification data based on the data to be transmitted and the target platform.

[0064] The verification data can be determined based on the data to be transmitted and the target platform. Of course, other information can also be referenced, such as the data length of the data to be transmitted, the encryption method (or encryption level) specified by the user, or the target time when the data to be transmitted is received. There is no restriction. The verification data can be used as the splicing position of the final generated target transmission data, such as the data header or data tail of the encryption data protocol.

[0065] In one embodiment, verification data is determined based on the data to be transmitted and the target platform, including: obtaining a target time for receiving the data to be transmitted, determining verification data based on the data to be transmitted, the target time and the target platform, and determining a splicing position of the verification data based on the target time, wherein the splicing position can be either the data header or the data tail.

[0066] In this embodiment, the verification data is determined based on the target time, the data to be transmitted and the target platform, which can make the verification data more random and less likely to be cracked, thereby improving the security of the data transmission process. In addition, the splicing position of the verification data is also determined based on the target time, further improving the reliability of the verification data.

[0067] Step 203: Determine the target encryption method from a preset code book according to the data to be transmitted and the target platform.

[0068] The preset code book may include multiple different encryption methods. Different target platforms can correspond to multiple encryption methods. The target encryption method can be determined from multiple different encryption methods based on the target platform and the data to be transmitted, thereby improving the randomness of the encryption and thus improving the security of data transmission.

[0069] In one embodiment, the target encryption method is determined from a preset code book based on the data to be transmitted and the target platform, including: obtaining indication information carried by the data to be transmitted, wherein the indication information can be an encryption method selected by the user, or an encryption level selected. Of course, it can also include both the encryption method and the encryption level without limitation. The target encryption method of the data to be transmitted is determined from a preset code book based on the target platform, as well as the encryption method and the encryption level.

[0070] In this embodiment, the encryption method in the code book may include symmetric encryption algorithms and asymmetric encryption algorithms, for example, digest algorithms and signature algorithms, such as Triple Data Encryption Algorithm (TDEA, Triple DEA or 3DES), Data Encryption Standard (DES), asymmetric encryption algorithm RSA, IDEA encryption algorithm, etc. According to user needs, the corresponding encryption method can be selected to encrypt the data, and then the encrypted data and basic verification data are packaged and sent out.

[0071] In one embodiment, if the data to be transmitted does not carry indication information, the target encryption method is determined from a preset code book based on the data to be transmitted and the target platform, which may include at least the following two methods:

[0072] In the first method, at least two encryption methods are determined from a preset code book according to a target time and a target platform of the data to be transmitted, and a target encryption method is randomly determined from the at least two encryption methods.

[0073] A plurality of encryption methods can be determined from a preset code book according to the target time and the target platform, and then a target encryption method is randomly selected from them.

[0074] The second method is to determine all encryption methods with processing speeds greater than a target processing threshold from a preset code book according to the data to be transmitted and the target platform, and randomly determine a target encryption method from all the encryption methods.

[0075] Different platforms have different data processing capabilities. According to the type of the target platform, a target encryption method can be randomly selected from all encryption methods whose processing speed is greater than the target processing threshold corresponding to the target platform determined from a preset code book.

[0076] In this embodiment, any of the above methods can achieve random encryption mode, and randomly select an encryption mode to encrypt data without the user specifying a specific encryption mode, thereby improving the security of data transmission.

[0077] Step 204: Packaging the data to be transmitted according to the target encryption method and the verification data to obtain target transmission data.

[0078] On the premise that the verification data includes different splicing positions, the data to be transmitted is packaged according to the target encryption method and the verification data to obtain the target transmission data, including: packaging the data to be transmitted according to the target encryption method, the verification data and the splicing position to obtain the target transmission data.

[0079] This method can determine verification data based on the data to be transmitted and the target platform corresponding to the data sending end, and determine the target encryption method from a preset code book based on the data to be transmitted and the target platform, so that the encryption method in the encryption process has a certain degree of randomness, thereby improving the security of the target transmission data during the transmission process, ensuring data security, and improving data reliability through verification data.

[0080] In one embodiment, the method further includes: obtaining a target encryption and decryption algorithm to be added; and updating the code book according to the target encryption and decryption algorithm.

[0081] In this embodiment, the code book can be iteratively updated according to the target encryption and decryption algorithm to be added, thereby improving the sustainability and effectiveness of encryption and decryption.

[0082] In a specific embodiment, the data encryption process is shown in FIG3 .

[0083] In this embodiment, basic verification data is first generated according to the data input by the user.

[0084] The sender obtains the parameters configured by the user, including the selected platform, encryption method (or encryption level), and data length, and generates the corresponding encrypted data protocol header / footer based on the configured parameters. The decryptor verifies the protocol header / footer in the received data to determine the validity of the data before performing the decryption operation.

[0085] The selected platforms can be Linux, Windows, Android, etc., and the encryption methods can be DES, RSA, 3DES, FEAL, IDEA, etc. Of course, the user does not need to specify a specific encryption algorithm, but only needs to give an encryption level. The data length is the actual data length that the user wants to transmit.

[0086] Secondly, the basic data splicing method can be randomly determined. For example, the splicing position (data head or data tail) of the basic verification data generated above can be calculated through a certain algorithm using the current time as a parameter.

[0087] The codebook includes common symmetric and asymmetric encryption algorithms, as well as commonly used digest and signature algorithms such as 3DES, DES, RSA, and IDEA. Users can choose the appropriate encryption method to encrypt their data based on their needs, and then combine the encrypted data with basic verification data for transmission.

[0088] Among them, in the design of the code book, since different encryption methods have different processing speeds, security and correctness, the encryption algorithms will be classified and graded to suit different platforms and then saved in predefined data (not limited to structure arrays, it can be a file, or a database, etc.). The data at least contains key information such as the applicable platform, level, service, encryption and decryption methods, etc.

[0089] In this embodiment, users can specify a specific encryption and decryption method during data transmission. However, sometimes users themselves are unsure of their preferred encryption method. In this case, a random encryption method can be selected to encrypt data without specifying a specific method, thus achieving random encryption and decryption. There are two types of randomization methods: randomly selecting one from the selected platform over time, or selecting a method that processes data faster while ensuring compatibility, security, and reliability. Furthermore, the codebook can be iteratively updated by copying the encryption and decryption algorithms to be added to the specified file and then synchronously updating the predefined data.

[0090] In this embodiment, a universal data security encryption and decryption framework is designed to adapt to different application environments (that is, different platforms). Developers only need to configure reasonable parameters according to their own environment to use it, which greatly reduces the amount of code modification and subsequent maintenance costs for developers. This encryption and decryption solution also supports subsequent encryption and decryption technology updates and synchronous updates to increase its flexibility and timeliness, thereby achieving adaptation to the different needs of multiple platform environments.

[0091] A data decryption method, as shown in FIG4 , includes:

[0092] Step 401: The data receiving end obtains received target transmission data, wherein the target transmission data carries verification data;

[0093] Step 402, verifying the verification data;

[0094] Step 403: If the verification data passes, the target transmission data is decrypted according to a preset code book to obtain decrypted data, wherein the preset code book is the same as the code book used by the data sending end for encryption.

[0095] In this method, the target transmission data is encrypted by a data encryption method at the data sending end. This target transmission data also carries verification data. The verification data is first verified at the data receiving end. If the verification fails, the target transmission data does not need to be decrypted, and a data parsing error is directly returned. If the verification passes, the data is decrypted by querying the same codebook as the one used to encrypt the data at the data sending end, thereby obtaining the decrypted data. By verifying the verification data and decrypting using the codebook, the security of data transmission is improved.

[0096] In a specific embodiment, the data decryption process is shown in Figure 5. In this embodiment, the received data is first verified with basic verification data. If the verification fails, there is no need to decrypt the target transmission data, and a data parsing error is directly returned. After the verification passes, the data can be decrypted by querying the same code book as the code book used to encrypt the data at the data sending end, thereby obtaining decrypted data and sending the decrypted data to the user. The security of data transmission is improved by verifying the verification data and decrypting using the code book.

[0097] Based on the same technical concept, the second embodiment of the present application provides a data encryption device, as shown in FIG6 , which includes:

[0098] The first acquisition module 601 is used to acquire data to be transmitted from a data sending end; wherein the data sending end corresponds to a target platform;

[0099] A first determining module 602 is configured to determine verification data based on the data to be transmitted and the target platform;

[0100] A second determining module 603 is configured to determine a target encryption method from a preset code book according to the data to be transmitted and the target platform;

[0101] The encryption module 604 is configured to package the data to be transmitted according to the target encryption method and the verification data to obtain target transmission data.

[0102] The device can determine verification data based on the data to be transmitted and the target platform corresponding to the data sending end, and determine the target encryption method from a preset code book based on the data to be transmitted and the target platform, so that the encryption method in the encryption process has a certain degree of randomness, thereby improving the security of the target transmission data during the transmission process, ensuring data security, and improving data reliability through verification data.

[0103] A data decryption device, as shown in FIG7 , includes:

[0104] The second acquisition module 701 is used for the data receiving end to acquire the received target transmission data; wherein the target transmission data carries verification data;

[0105] A verification module 702 is used to verify the verification data;

[0106] The decryption module 703 is used to decrypt the target transmission data according to a preset code book to obtain decrypted data when the verification data passes the verification, wherein the preset code book is the same as the code book used by the data sending end to encrypt.

[0107] In this device, the target transmission data is encrypted by a data encryption method at the data sending end. This target transmission data also carries verification data. The verification data is first verified at the data receiving end. If the verification fails, the target transmission data does not need to be decrypted, and a data parsing error is directly returned. If the verification passes, the data is decrypted by querying the same codebook as the one used to encrypt the data at the data sending end, thereby obtaining the decrypted data. By verifying the verification data and decrypting using the codebook, the security of data transmission is improved.

[0108] As shown in Figure 8, the third embodiment of the present application provides an electronic device, including a processor 111, a communication interface 112, a memory 113 and a communication bus 114, wherein the processor 111, the communication interface 112, and the memory 113 communicate with each other through the communication bus 114.

[0109] Memory 113, for storing computer programs;

[0110] In one embodiment, the processor 111 is configured to implement the data encryption method or the data decryption method provided by any one of the aforementioned method embodiments when executing a program stored in the memory 113 .

[0111] The memory and processor in the electronic device communicate via a communication bus and a communication interface. The communication bus can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus. The communication bus can be divided into an address bus, a data bus, a control bus, etc.

[0112] The memory may include random access memory (RAM) or non-volatile memory, such as at least one disk storage. Alternatively, the memory may be at least one storage device located away from the processor.

[0113] The above-mentioned processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, and discrete hardware components.

[0114] A fourth embodiment of the present application provides a computer-readable medium having non-volatile program code executable by a processor.

[0115] Optionally, in an embodiment of the present application, a computer-readable medium is configured to store program code for a processor to execute the above method.

[0116] Optionally, the specific examples in this embodiment may refer to the examples described in the above embodiments, and this embodiment will not be described in detail here.

[0117] When implementing the embodiments of the present application, reference may be made to the above embodiments, which have corresponding technical effects.

[0118] It is understood that the embodiments described herein may be implemented using hardware, software, firmware, middleware, microcode, or a combination thereof. For hardware implementation, the processing unit may be implemented in one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), general-purpose processors, controllers, microcontrollers, microprocessors, other electronic units for performing the functions of the present application, or a combination thereof.

[0119] For software implementation, the technology herein can be implemented by a unit that performs the functions herein. The software code can be stored in a memory and executed by a processor. The memory can be implemented in the processor or external to the processor.

[0120] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0121] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0122] In the embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of modules is only a logical function division. In actual implementation, there may be other division methods, such as multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interface, device or unit, which can be electrical, mechanical or other forms.

[0123] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0124] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0125] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a ROM, a RAM, a magnetic disk, or an optical disk.

[0126] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device that includes a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or device that includes the element.

[0127] The above embodiments are only preferred embodiments for fully illustrating the present application, and the protection scope of the present application is not limited thereto. Any equivalent substitutions or modifications made by those skilled in the art based on the present application are within the protection scope of the present application.

Claims

1. A data encryption method, characterized in that, The method includes: Obtaining the data to be transmitted of the data sending end; wherein, the data sending end corresponds to the target platform; Determining verification data according to the data to be transmitted and the target platform; Determining a target encryption method from a preset password book according to the data to be transmitted and the target platform; Packetizing the data to be transmitted according to the target encryption method and the verification data to obtain target transmission data.

2. The method according to claim 1, characterized in that, Determining verification data according to the data to be transmitted and the target platform includes: Obtaining the target time when the data to be transmitted is received; Determining the verification data according to the data to be transmitted, the target time and the target platform; Determining the splicing position of the verification data according to the target time; Correspondingly, packetizing the data to be transmitted according to the target encryption method and the verification data to obtain target transmission data includes: Packetizing the data to be transmitted according to the target encryption method, the verification data and the splicing position to obtain target transmission data.

3. The method according to claim 1, characterized in that Determining a target encryption method from a preset password book according to the data to be transmitted and the target platform includes: Obtaining the indication information carried by the data to be transmitted; wherein, the indication information is used to indicate the encryption method and / or the encryption level; Determining the target encryption method of the data to be transmitted from the preset password book according to the target platform, and the encryption method and / or the encryption level.

4. The method according to claim 3, wherein If the data to be transmitted does not carry the indication information, determining a target encryption method from a preset password book according to the data to be transmitted and the target platform includes: Determining at least two encryption methods from the preset password book according to the target time of the data to be transmitted and the target platform, and randomly determining one of the at least two encryption methods as the target encryption method; Or, Determining all encryption methods with a processing speed greater than the target processing threshold from the preset password book according to the data to be transmitted and the target platform, and randomly determining one of all the encryption methods as the target encryption method.

5. The method according to claim 2, wherein The splicing position includes the data header or the data tail.

6. The method according to claim 1, characterized in that, The method further includes: Obtaining a target encryption / decryption algorithm to be added; Updating the password book according to the target encryption / decryption algorithm.

7. A data decryption method, characterized in that, The method includes: The data receiving end obtains the received target transmission data; wherein, the target transmission data carries verification data; Verifying the verification data; When the verification data passes the verification, decrypting the target transmission data according to the preset password book to obtain decrypted data, wherein the preset password book is the same as the password book used for encryption by the data sending end.

8. A data encryption device, characterized in that, The device includes: A first obtaining module, configured to obtain the data to be transmitted of the data sending end; wherein, the data sending end corresponds to the target platform; A first determining module, configured to determine verification data according to the data to be transmitted and the target platform; A second determining module, configured to determine a target encryption method from a preset password book according to the data to be transmitted and the target platform; An encryption module, configured to packetize the data to be transmitted according to the target encryption method and the verification data to obtain target transmission data.

9. A data decryption device, characterized in that, The device includes: A second acquisition module, configured to acquire the received target transmission data at the data receiving end; wherein, the target transmission data carries verification data; A verification module, configured to verify the verification data; A decryption module, configured to decrypt the target transmission data according to a preset password book to obtain decrypted data when the verification data passes the verification, wherein the preset password book is the same as the password book used for encryption at the data sending end.

10. An electronic device, characterized in that, It includes a processor, a communication interface, a memory, and a communication bus. Among them, the processor, the communication interface, and the memory complete mutual communication through the communication bus; The memory is used to store computer programs; The processor is configured to implement the data encryption method according to any one of claims 1-6 or implement the data decryption method according to claim 7 when executing the programs stored on the memory.

11. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, and when the computer program is executed by the processor, it implements the data encryption method according to any one of claims 1-6 or implements the data decryption method according to claim 7.

Citation Information

Patent Citations

  • One-time password book encryption method and device, equipment and storage medium

    CN112615715A

  • Vehicle-mounted terminal file encryption upgrading method and device, terminal equipment and storage medium

    CN114661314A

  • Data security transmission method, platform and system based on national cryptographic algorithm

    CN115225365A

  • Information encryption / decryption device, information encryption method, and information decryption method

    CN115801237A

  • Data transmission method

    CN116545613A

Cited By

  • Chip, data transmission method, equipment and medium

    CN122226686A