Data obfuscation method, data restoration method, electronic device and storage medium
Patent Information
- Application Number
- PCT/CN2025/132922
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-03-28
- Filing Date
- 2025-11-06
- Publication Date
- 2026-10-01
Smart Images

Figure CN2025132922_01102026_PF_FP_ABST
Abstract
Description
Data obfuscation methods, data restoration methods, electronic devices and storage media
[0001] Cross-references to related applications
[0002] This application claims priority to Chinese application No. 2025103862484, filed on March 28, 2025, the entire contents of which are incorporated herein by reference for all purposes. Technical Field
[0003] This application relates to the field of electronic information technology, and more specifically, to a data obfuscation method, a data restoration method, an electronic device, and a computer-readable storage medium. Background Technology
[0004] With the development of science and technology, the amount of data generated is exploding, and the amount of sensitive information within this data is also increasing. Therefore, ensuring that sensitive information is not leaked is a pressing issue that needs to be addressed. Summary of the Invention
[0005] This application proposes a data obfuscation method, a data restoration method, an electronic device, and a computer-readable storage medium to provide an information obfuscation means to improve data security.
[0006] In a first aspect, embodiments of this application provide a data obfuscation method, the method comprising:
[0007] Insert the first obfuscation key into the data to be processed to obtain the first obfuscated data;
[0008] The first obfuscated data is obfuscated using the second obfuscation key to obtain the second obfuscated data;
[0009] The first obfuscated key and the second obfuscated key are subjected to key obfuscation processing to obtain the target obfuscated key;
[0010] Based on the target obfuscation key and the second obfuscation data, target data for the data to be processed is obtained.
[0011] Secondly, embodiments of this application provide a data restoration method, the method comprising:
[0012] Obtain the target data to be restored; the target data includes second obfuscated data and a target obfuscation key;
[0013] The target obfuscated key is deobfuscated to obtain a first obfuscated key and a second obfuscated key;
[0014] The second obfuscated data is deobfuscated using the second obfuscation key to obtain the first obfuscated data;
[0015] The first obfuscated data is deobfuscated using the first obfuscation key to obtain the data to be processed after the second obfuscated data is restored.
[0016] Thirdly, embodiments of this application also provide a data obfuscation device, the device comprising:
[0017] The first obfuscation module is used to insert the first obfuscation key into the data to be processed to obtain the first obfuscated data;
[0018] The second obfuscation module is used to obfuscate the first obfuscation data using the second obfuscation key to obtain the second obfuscation data.
[0019] The third obfuscation module is used to perform key obfuscation processing on the first obfuscation key and the second obfuscation key to obtain the target obfuscation key;
[0020] The module is used to obtain target data for the data to be processed based on the target obfuscation key and the second obfuscation data.
[0021] Fourthly, embodiments of this application also provide a data restoration apparatus, the apparatus comprising:
[0022] The acquisition module is used to acquire the target data to be restored; the target data includes the second obfuscated data and the target obfuscated key.
[0023] The first deobfuscation module is used to perform key deobfuscation processing on the target obfuscated key to obtain the first obfuscated key and the second obfuscated key;
[0024] The second deobfuscation module is used to deobfuscate the second obfuscated data using the second obfuscation key to obtain the first obfuscated data.
[0025] The third deobfuscation module is used to deobfuscate the data position of the first obfuscated data using the first obfuscation key, so as to obtain the data to be processed after the second obfuscated data is restored.
[0026] Fifthly, embodiments of this application also provide an electronic device, which includes: one or more processors; a memory; and one or more application programs, wherein the one or more application programs are stored in the memory and configured to be executed by the one or more processors, and the one or more application programs are configured to perform the methods described above.
[0027] Sixthly, embodiments of this application also provide a computer-readable storage medium storing processor-executable program code, which, when executed by the processor, causes the processor to perform the above-described method.
[0028] This application provides a data obfuscation method, data restoration method, apparatus, electronic device, and computer-readable storage medium. In this application, a first obfuscation key is first inserted into the data to be processed, performing a first obfuscation process to obtain first obfuscated data. Then, the first obfuscated data undergoes further obfuscation to obtain second obfuscated data. This achieves dual obfuscation of the data to be processed, improving the security of the second obfuscated data and reducing the risk of its leakage. Furthermore, this application also performs key obfuscation on the first and second obfuscation keys to obtain a target obfuscation key, ensuring that the target obfuscation key is also obfuscated. This improves the security of the target obfuscation key, reduces the risk of leakage of the first and second obfuscation keys, and further enhances the security of the second obfuscated data obtained based on the first and second obfuscation keys.
[0029] Other features and advantages of the embodiments of this application will be set forth in the following description, and will be apparent in part from the description, or may be learned by practicing the embodiments of this application. The objects and other advantages of the embodiments of this application may be realized and obtained by means of the structures particularly pointed out in the written description, claims, and drawings. Attached Figure Description
[0030] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0031] Figure 1 shows a flowchart of a data obfuscation method proposed in one embodiment of this application.
[0032] Figure 2 shows a schematic diagram of a second preprocessed data acquisition process in an embodiment of this application.
[0033] Figure 3 shows a schematic diagram of a process for acquiring first preprocessed data in an embodiment of this application.
[0034] Figure 4 shows a schematic diagram of a second obfuscated data acquisition process in an embodiment of this application.
[0035] Figure 5 shows a schematic diagram of the process of obtaining a target obfuscation key in an embodiment of this application.
[0036] Figure 6 shows a flowchart of a data restoration method proposed in one embodiment of this application.
[0037] Figure 7 illustrates a schematic diagram of the extraction process of a first obfuscation key and a second obfuscation key in an embodiment of this application.
[0038] Figure 8 shows a schematic diagram of a raw data recovery process according to an embodiment of this application.
[0039] Figure 9 shows a schematic diagram of a data obfuscation process in an embodiment of this application.
[0040] Figure 10 shows a schematic diagram of one of the preprocessing procedures corresponding to the raw data in Figure 9.
[0041] Figure 11 shows a schematic diagram of the second preprocessing step corresponding to the raw data in Figure 9.
[0042] Figure 12 shows a schematic diagram of the random key generation process in Figure 9.
[0043] Figure 13 shows a schematic diagram of the data obfuscation process in Figure 9.
[0044] Figure 14 shows a schematic diagram of the key obfuscation process in Figure 9.
[0045] Figure 15 shows a schematic diagram of a data restoration process in an embodiment of this application.
[0046] Figure 16 shows a schematic diagram of the process of restoring the obfuscated key in Figure 15.
[0047] Figure 17 shows a schematic diagram of the de-obfuscation process of the data in Figure 15.
[0048] Figure 18 shows a schematic diagram of the post-processing of the data in Figure 15.
[0049] Figure 19 shows a structural block diagram of a data obfuscation device according to an embodiment of this application.
[0050] Figure 20 shows a structural block diagram of a data restoration apparatus according to an embodiment of this application.
[0051] Figure 21 shows a structural block diagram of an electronic device according to an embodiment of this application. Detailed Implementation
[0052] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present application, and not all of them. The components of the embodiments of the present application described and shown in the accompanying drawings can generally be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the accompanying drawings is not intended to limit the scope of the claimed application, but merely represents selected embodiments of the present application. All other embodiments obtained by those skilled in the art based on the embodiments of the present application without inventive effort are within the scope of protection of the present application.
[0053] It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. Furthermore, in the description of this application, terms such as "first," "second," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.
[0054] Please refer to Figure 1, which shows a flowchart of a data obfuscation method according to an embodiment of this application, for use in an electronic device. The method includes:
[0055] S110. Insert the first obfuscation key into the data to be processed to obtain the first obfuscated data.
[0056] In this application, the data to be processed can refer to the data to be obfuscated, and the first obfuscation key can refer to a randomly generated random number; the data formats of the data to be processed and the first obfuscation key can both be binary data formats.
[0057] One approach is to use a true random number generator to generate a truly random number as the first obfuscation key. Then, the first obfuscation key is inserted into the data to be processed to adjust the positions of each data element, resulting in obfuscated data, which serves as the first obfuscated data.
[0058] In some embodiments, the first obfuscation key can be randomly inserted into any position in the data to be processed to obfuscate the data position and obtain the first obfuscated data.
[0059] In some other embodiments, the data to be processed and the data length of the first obfuscation key can be the same. In this case, the data to be processed is processed by bitwise interpolation according to the first obfuscation key to obtain the data to be processed.
[0060] The first bit of the first obfuscation key can be inserted into the gap between the first and second bits of the data to be processed, the second bit of the first obfuscation key can be inserted into the gap between the second and third bits of the data to be processed, ..., and the last bit of the first obfuscation key can be inserted after the last bit of the data to be processed, thus achieving bit-by-bit interpolation of the data to be processed; alternatively, the first bit of the first obfuscation key can be inserted before the first bit of the data to be processed, the second bit of the first obfuscation key can be inserted into the gap between the first and third bits of the data to be processed, ..., and the last bit of the first obfuscation key can be inserted between the second-to-last bit and the last bit of the data to be processed, thus achieving bit-by-bit interpolation of the data to be processed.
[0061] In some other embodiments, the data to be processed includes multiple ordered data segments; in this case, each data segment is interpolated bitwise according to the first obfuscation key to obtain a first data segment corresponding to each data segment; according to the arrangement order of each data segment in the data to be processed, the first data segments corresponding to each data segment are combined to obtain the second obfuscated data.
[0062] In some implementations, the first obfuscation key can be inserted before or after each data segment to perform bitwise interpolation on each data segment, thereby obtaining the first data segment corresponding to each data segment.
[0063] In some other implementations, if the lengths of the data segments are consistent and the length of the data segments is consistent with the length of the first obfuscation key, then the first bit of the first obfuscation key can be inserted into the gap between the first and second bits of the data segment, the second bit of the first obfuscation key can be inserted into the gap between the second and third bits of the data segment, ..., and the last bit of the first obfuscation key can be inserted after the last bit of the data segment to achieve bitwise interpolation of the data segment; of course, it is also possible to insert the first bit of the first obfuscation key before the first bit of the data segment, insert the second bit of the first obfuscation key into the gap between the first and third bits of the data segment, ..., and insert the last bit of the first obfuscation key between the second-to-last bit and the last bit of the data segment to achieve bitwise interpolation of the data segment.
[0064] After obtaining the first data segment of each data segment, the first data segments corresponding to each data segment can be combined according to the arrangement order of each data segment in the data to be processed to obtain the first obfuscated data. At this time, the first obfuscated data includes multiple ordered first data segments.
[0065] It is worth mentioning that before S110, the method also includes: obtaining first preprocessed data; the first preprocessed data includes multiple ordered data segments; adjusting the order of at least two data segments in the first preprocessed data to obtain the adjusted first preprocessed data, which is used as the data to be processed.
[0066] In other words, when the data to be processed includes multiple ordered data segments, the data to be processed is a sequence of segments composed of multiple data segments. First, the sequence of segments composed of multiple data segments is obtained—the first preprocessed data. The order of the multiple data segments in the first preprocessed data is different from the order of the multiple data segments in the data to be processed. Therefore, the order of at least two data segments in the first preprocessed data is adjusted to obtain the data to be processed.
[0067] For example, the first preprocessed data includes data fragments A, B, and C, and the order of the three is ABC. At this time, the order of A, B, and C is adjusted to obtain BCA. The fragment sequence BCA formed by the data fragments is then used as the data to be processed.
[0068] In some embodiments, before acquiring the first preprocessed data, the method further includes: converting the acquired raw data into second preprocessed data in a target data format; and dividing the second preprocessed data into equal-length segments to obtain multiple ordered data fragments.
[0069] In this embodiment, the original data is the data to be obfuscated. The original data can be in any format, while the target data can be in base64 format. For example, the original data can be in formats such as .txt, .doc, .jpeg, and mysql.
[0070] For example, when the target data format is base64, as shown in Figure 2, the original data in different data formats are converted based on the base64 data format to obtain binary second preprocessed data.
[0071] After obtaining the second preprocessed data, it is divided into equal-length segments to obtain multiple ordered data fragments of the same length. The order of the data fragments can refer to their position in the second preprocessed data. For example, if data fragment A is at the beginning of the second preprocessed data and data fragment B is at the end, then data fragment A is the first data fragment and data fragment B is the last data fragment.
[0072] In some embodiments, the aforementioned process of dividing the second preprocessed data into multiple ordered data segments of equal length includes: starting from the beginning of the second preprocessed data, dividing the second preprocessed data into multiple ordered initial data segments at intervals of a specified data length; if the data length of the last initial data segment is less than the specified data length, padding the last initial data segment to obtain a padded data segment with the specified data length, and acquiring the padded data segment and other initial data segments excluding the last initial data segment as multiple data segments; if the data length of the last initial data segment is the specified data length, acquiring multiple initial data segments as multiple data segments. The specified data length can be a value set based on requirements, for example, a specified data length of 200.
[0073] In other words, starting from the beginning of the second preprocessed data, a cut is made every specified data length to divide the second preprocessed data into multiple segments as multiple initial data segments. However, it is easy to understand that, except for the last initial data segment at the very end, the data length of the other initial data segments is the specified data length. Therefore, to ensure the consistency of data length, if the data length of the last initial data segment is less than the specified data length, the last initial data segment is padded to obtain a padded data segment with the specified data length. The padded data segment and the other initial data segments excluding the last initial data segment are then obtained as multiple data segments. If the data length of the last initial data segment is the specified data length, multiple initial data segments are obtained as multiple data segments. Thus, multiple data segments with consistent data lengths are obtained.
[0074] In this embodiment, the padding process can be to fill in each missing bit of the last initial data segment with a specified value, for example, each bit is filled with a value of 0 or 1.
[0075] As shown in Figure 3, the second preprocessed data in binary format is divided into initial data segments d1, d2, and d3 according to a specified data length L. The data length L1 of the initial data segment d3 is less than L, that is, the initial data segment is missing L-L1 bits. The initial data segment d3 is then padded with L-L1 bits, and the value of each padded bit can be 0, resulting in a padded data segment d31 with a data length of L. At this time, the initial data segment d1, the initial data segment d2, and the padded data segment d31 are three data segments, which are arranged in order to obtain the first preprocessed data.
[0076] As can be seen from the above, the order in which data fragments are arranged in the first preprocessed data is actually the order in which they appear in the second preprocessed data. That is, in the example above, if data fragment d1 is the first data fragment in the second preprocessed data, then data fragment d1 is the first data fragment in the first preprocessed data; if data fragment d3 is the first data fragment in the second preprocessed data, then data fragment d31 is the last data fragment in the first preprocessed data.
[0077] It is worth mentioning that, in order to achieve the aforementioned process of inserting one bit into each gap of the data segment using the first obfuscation key, the data length of the first obfuscation key can be the aforementioned specified data length.
[0078] S120. Obtain second obfuscated data by obfuscating the first obfuscated data using the second obfuscation key.
[0079] The first obfuscation key and the second obfuscation key can be the same or different; the data format of the second obfuscation key can also be binary data format.
[0080] A true random number generator can be used to randomly generate a true random number (which can be different from or the same as the first obfuscation key) as the second obfuscation key. Then, the second obfuscation key is used to obfuscate the first obfuscated data, adjusting the specific values of the data in the first obfuscated data to obtain the obfuscated data, which is then used as the second obfuscated data.
[0081] In some embodiments, a portion of the second obfuscated key can be obfuscated with a portion of the first obfuscated data to obfuscate the first obfuscated data and obtain the second obfuscated data. The obfuscation operation can be an XOR operation, a product operation, or a summation operation, etc.
[0082] In some other embodiments, the first obfuscated data and the second obfuscated key can have the same data length. In this case, the first obfuscated data is obtained by performing an obfuscation operation on each bit of the first obfuscated data according to each bit of the second obfuscated key. The obfuscation operation here can be an XOR operation, a product operation, or a summation operation, etc.
[0083] In some embodiments, the data to be processed includes multiple ordered data segments. In this case, the resulting first obfuscated data includes multiple ordered first data segments. For each first data segment in the first obfuscated data, an obfuscation operation is performed on the first data segment and a second obfuscation key to obtain a second data segment corresponding to the first data segment. Based on the order of the first data segments in the first obfuscated data, the second data segments corresponding to each first data segment are combined to obtain the second obfuscated data. The obfuscation operation here can be an XOR operation, a product operation, or a summation operation, etc.
[0084] In some specific implementations, if the length of the first data segment is greater than the length of the second obfuscation key, a first candidate segment with the same length as the second obfuscation key can be selected from the first data segment, and obfuscation operation can be performed on the candidate segment and the second obfuscation key to obtain the second data segment corresponding to the first data segment.
[0085] Similarly, in some other specific implementations, if the length of the first data segment is less than the length of the second obfuscation key, a second candidate segment with the same length as the first data segment can be selected from the second obfuscation key, and obfuscation operation can be performed on the second candidate segment and the first data segment to obtain the second data segment corresponding to the first data segment.
[0086] In some specific embodiments, if multiple data segments have the same length; the data length of the first obfuscation key is the same as the data length of the data segment; and the data length of the second obfuscation key is the same as the data segment, then the length of the obtained first data segment is twice the length of the data segment. In this case, the aforementioned obfuscation operation performed on the first data segment and the second obfuscation key for each first data segment in the first obfuscated data to obtain the second data segment corresponding to the first data segment includes: for each first data segment in the first obfuscated data, performing an XOR operation between the target segment in the first data segment and the second obfuscation key to obtain the second data segment corresponding to the first data segment; the target segment includes a first local segment and / or a second local segment; the first local segment is the part of the first data segment that belongs to the data segment corresponding to the data segment; and the second local segment is the part of the first data segment that belongs to the first obfuscation key.
[0087] In other words, the first data segment is obtained by positionally obfuscating a data segment with a first obfuscation key. At this time, the first data segment is divided into two parts: the part of the first obfuscation key (the second local segment) and the part of the data segment (the first local segment). At this time, the second local segment can be obfuscated with the second obfuscation key, or the first local segment can be obfuscated with the second obfuscation key, or both the first local segment and the second local segment can be obfuscated with the second obfuscation key to obtain the second data segment corresponding to the first data segment.
[0088] After obtaining the second data segment corresponding to the first data segment, the second data segments corresponding to each first data segment are combined according to the order of arrangement of each first data segment in the first obfuscated data to obtain the second obfuscated data.
[0089] For example, the second obfuscated data acquisition process is shown in Figure 4. First, the original data is divided into equal-length segments to obtain ordered data segments A, B, and C, which serve as the first preprocessed data. Then, the order of A, B, and C is adjusted to obtain the data to be processed after the order adjustment: ordered data segments C, A, and B. After that, the data position of each data segment in the data to be processed is obfuscated using the first obfuscation key (i.e., random number D)—random number D is inserted at the beginning of the data segment. At this time, the data segment after the combination of random number D and C serves as the first data segment corresponding to data segment C, the data segment after the combination of random number D and A serves as the first data segment corresponding to data segment A, and the data segment after the combination of random number D and B serves as the first data segment corresponding to data segment B. Then, using the second obfuscation key (i.e., random number E), an XOR operation is performed on the first local segment (i.e., data segments C, A, and B) and the second local segment (i.e., random number D) in the first data segment to achieve data obfuscation, resulting in the second data segment corresponding to the first data segment. At this time, the second data segments are respectively the segment composed of random number D' (the result of the XOR operation of random number D and random number E) and obfuscation C' (the result of the XOR operation of data segment C and random number E), the segment composed of random number D' and obfuscation A' (the result of the XOR operation of data segment A and random number E), and the segment composed of random number D' and obfuscation B' (the result of the XOR operation of data segment B and random number E). The three second data segments are arranged in sequence to form the second obfuscated data.
[0090] S130. Perform key obfuscation processing on the first obfuscated key and the second obfuscated key to obtain the target obfuscated key.
[0091] In this application, in order to accurately extract the first obfuscated key and the second obfuscated key from the target obfuscated key, the first obfuscated key and the second obfuscated key are subjected to key obfuscation processing. This can refer to obfuscating the data position of the first obfuscated key and the second obfuscated key, so as to achieve the purpose of simultaneously retaining the first obfuscated key and the second obfuscated key.
[0092] In some embodiments, the first obfuscation key can be randomly inserted into any position in the second obfuscation key to obfuscate the data position and obtain the target obfuscation key.
[0093] In some other embodiments, the data to be processed and the data length of the first obfuscation key can be the same. In this case, S130 includes: performing bitwise interpolation on the data to be processed according to the first obfuscation key to obtain the target obfuscation key.
[0094] The first bit of the first obfuscated key can be inserted into the gap between the first and second bits of the second obfuscated key, the second bit of the first obfuscated key can be inserted into the gap between the second and third bits of the second obfuscated key, ..., and the last bit of the first obfuscated key can be inserted after the last bit of the second obfuscated key, thus performing bitwise interpolation on the second obfuscated key to obtain the target obfuscated key; alternatively, the first bit of the first obfuscated key can be inserted before the first bit of the second obfuscated key, the second bit of the first obfuscated key can be inserted into the gap between the first and third bits of the second obfuscated key, ..., and the last bit of the first obfuscated key can be inserted between the second-to-last bit and the last bit of the second obfuscated key, thus performing bitwise interpolation on the second obfuscated key to obtain the target obfuscated key.
[0095] For example, when the lengths of the first obfuscation key and the second obfuscation key are the same, as shown in Figure 5, the length of the first obfuscation key is n, and the length of the second obfuscation key is also n. In this case, the Dn bit in the first obfuscation key is inserted after the En bit in the second obfuscation key, so that the data to be processed is processed by bit interpolation according to the first obfuscation key to obtain the target obfuscation key. At this time, the length of the target obfuscation key is 2n.
[0096] S140. Based on the target obfuscation key and the second obfuscation data, the target data for the data to be processed is obtained.
[0097] That is, after obtaining the target obfuscation key and the second obfuscation data, the target obfuscation key and the second obfuscation data are used as the target data after obfuscation. At this time, the target data includes the target obfuscation key and the second obfuscation data, so that the first obfuscation key and the second obfuscation key can be obtained by decryption based on the target obfuscation key. Then, the first obfuscation key and the second obfuscation key are used to decrypt to obtain the data to be processed or the original data.
[0098] It is worth mentioning that, as mentioned above, the last initial data segment after the second preprocessed data segmentation may also be padded. At this time, it is also necessary to record the padding length and the value of each padded bit, and summarize the padding length, the value of each padded bit, the target obfuscation key, and the second obfuscation data as the target data, so as to restore the original data based on the padding length and the value of each padded bit.
[0099] In this embodiment, a first obfuscation key is first inserted into the data to be processed, achieving one obfuscation of the data to be processed, resulting in first obfuscated data. Then, the first obfuscated data is further obfuscated to obtain second obfuscated data. Thus, double obfuscation of the data to be processed is achieved, improving the security of the second obfuscated data and reducing the risk of leakage of the second obfuscated data. In addition, this application also performs key obfuscation on the first obfuscation key and the second obfuscation key to obtain a target obfuscation key, ensuring that the target obfuscation key has also been obfuscated, improving the security of the target obfuscation key, reducing the risk of leakage of the first obfuscation key and the second obfuscation key, and further increasing the security of the second obfuscated data obtained based on the first obfuscation key and the second obfuscation key.
[0100] Secondly, this application provides multiple obfuscation methods, which increases the diversity of data obfuscation and key obfuscation, and further improves the security of the target data after obfuscation.
[0101] In addition, the data obfuscation method in this application requires low computing resources and does not require any hardware requirements for electronic devices to achieve data obfuscation processing, thereby improving data security. As a result, no additional encryption hardware is needed, reducing data obfuscation costs and making data obfuscation highly economical.
[0102] Please refer to Figure 6, which shows a flowchart of a data restoration method according to an embodiment of this application, used in an electronic device. The method includes:
[0103] S210. Obtain the target data to be restored.
[0104] The target data includes second obfuscated data and a target obfuscated key. The methods for obtaining the second obfuscated data and the target obfuscated key are described in the above embodiment and will not be repeated here.
[0105] S220. Perform key de-obfuscation on the target obfuscated key to obtain the first obfuscated key and the second obfuscated key.
[0106] As mentioned above, de-obfuscation can be performed based on the specific obfuscation methods of the first obfuscation key and the second obfuscation key.
[0107] For example, when the first obfuscation key is randomly inserted into any position in the second obfuscation key to obfuscate the data position and obtain the target obfuscation key, the length of the first obfuscation key and the insertion position can be recorded. Then, based on the length of the first obfuscation key and the insertion position, the first obfuscation key can be extracted from the target obfuscation key, and what remains is the second obfuscation key.
[0108] As mentioned above, if the lengths of the first obfuscated key and the second obfuscated key are the same, S220 may include: performing bitwise operations on the target obfuscated key to extract the first obfuscated key and obtain the second obfuscated key.
[0109] For example, by inserting the first bit of the first obfuscated key into the gap between the first and second bits of the second obfuscated key, inserting the second bit of the first obfuscated key into the gap between the second and third bits of the second obfuscated key, ..., and inserting the last bit of the first obfuscated key after the last bit of the second obfuscated key, bitwise interpolation is performed on the second obfuscated key to obtain the target obfuscated key. Then, all the values in even-numbered positions can be extracted from the target obfuscated key and arranged in order as a data line, which serves as the first obfuscated key. All the remaining values in odd-numbered positions can be arranged in order as a data line, which serves as the second obfuscated key.
[0110] For example, if the target obfuscation key is obtained as shown in Figure 5, the first obfuscation key and the second obfuscation key are extracted as shown in Figure 7. In Figure 5, the Dn of the first obfuscation key is inserted after the En of the second obfuscation key to obtain the target obfuscation key with a length of 2n. Therefore, as shown in Figure 7, the even-numbered bits of the target obfuscation key can be extracted to obtain the first obfuscation key, and the odd-numbered bits of the target obfuscation key can be extracted to obtain the second obfuscation key.
[0111] S230. The second obfuscated data is deobfuscated using the second obfuscation key to obtain the first obfuscated data.
[0112] Similarly, in S230, the process of obfuscating the first obfuscated data according to the aforementioned second obfuscation key is reversed to obtain the deobfuscated data as the first obfuscated data.
[0113] As mentioned above, the second obfuscated data includes a plurality of ordered second data segments; accordingly, S220 may include: for each second data segment, performing a deobfuscation operation on the second data segment based on the second obfuscation key to obtain a first data segment corresponding to the second data segment; and combining the first data segments corresponding to each second data segment according to the arrangement order of each second data segment in the second obfuscated data to obtain the first obfuscated data.
[0114] Specifically, when the lengths of multiple data segments used to obtain the target data are consistent, the length of the first obfuscation key is consistent with the length of the data segments, and the length of the second obfuscation key is consistent with the length of the data segments, the aforementioned process of performing a deobfuscation operation on each second data segment based on the second obfuscation key to obtain the first data segment corresponding to the second data segment can include: for each second data segment in the second obfuscated data, performing an XOR operation (i.e., the inverse operation of the XOR operation) on the candidate segments in the second data segment and the second obfuscation key to obtain the first data segment corresponding to the second data segment; the candidate segments include a third local segment and / or a fourth local segment; the third local segment is the part of the second data segment that belongs to the data segment corresponding to the data segment; the fourth local segment is the part of the second data segment that belongs to the first obfuscation key.
[0115] As mentioned earlier, the first data segment is obtained by bitwise interpolation of a data segment using the first obfuscation key. At this point, the first data segment is divided into two parts: the part containing the first obfuscation key (the second local segment) and the data segment (the first local segment). The second local segment can then be obfuscated using the second obfuscation key, or the first local segment can be obfuscated using the second obfuscation key, or both the first and second local segments can be obfuscated using the second obfuscation key to obtain the second data segment corresponding to the first data segment. Therefore, the second data segment will also be divided into two parts: the part containing the first obfuscation key (the fourth local segment) and the data segment (the third local segment). The fourth local segment can be deobfuscated using the second obfuscation key, or the third local segment can be deobfuscated using the second obfuscation key, or both the third and fourth local segments can be deobfuscated using the second obfuscation key.
[0116] S240. The first obfuscated data is deobfuscated using the first obfuscation key to obtain the data to be processed after the second obfuscated data is restored.
[0117] As mentioned above, when the lengths of the first obfuscation key and the second obfuscation key are the same, S240 may include: for each first data segment, performing bitwise value extraction on the first data segment to extract the first obfuscation key and obtain the data segment corresponding to the first data segment; and combining the data segments corresponding to each first data segment according to the arrangement order of each first data segment in the first obfuscated data to obtain the data to be processed.
[0118] For example, the first bit of the first obfuscation key is inserted into the gap between the first and second bits of the data segment, the second bit of the first obfuscation key is inserted into the gap between the second and third bits of the data segment, ..., and the last bit of the first obfuscation key is inserted after the last bit of the data segment. This achieves bitwise interpolation of the data segment. In this case, each data in the first obfuscation key is inserted into an even-numbered position. Therefore, all values located in even-numbered positions can be extracted from the first data segment and arranged in order to form a data segment, which serves as the first obfuscation key. The remaining data is the data segment.
[0119] For example, the first bit of the first obfuscation key is inserted before the first bit of the data segment, the second bit of the first obfuscation key is inserted into the gap between the first and third bits of the data segment, and so on, and the last bit of the first obfuscation key is inserted between the second-to-last bit and the last bit of the data segment. This achieves bitwise interpolation of the data segment. In this case, each data in the first obfuscation key is inserted into an odd number of positions. Therefore, all the values located in the odd number of positions can be extracted from the first data segment and arranged in order to form a data segment as the first obfuscation key. The remaining data is the data segment.
[0120] Of course, as mentioned above, the data to be processed can be obtained by processing the first preprocessed data. In this case, the process of obtaining the first preprocessed data may include: adjusting the order of at least two data segments in the data to be processed to obtain the first preprocessed data. Here, the adjustment of the order is the reverse of the aforementioned method of adjusting the order of at least two data segments in the first preprocessed data.
[0121] For example, in the first preprocessed data, the positions of data segments a1 and a2 are swapped to obtain the data to be processed. Then, the positions of data segments a1 and a2 in the data to be processed are swapped to obtain the first preprocessed data.
[0122] In some implementations, multiple data segments in the first preprocessed data are derived from the original data. Therefore, the first preprocessed data can be restored to obtain the original data by: combining the multiple data segments in the order they appear in the first preprocessed data to obtain the second preprocessed data; and then converting the format of the second preprocessed data to obtain the original data. As mentioned above, the second preprocessed data is in a target format. Therefore, it is necessary to convert the target format second preprocessed data to a format consistent with the original data to obtain the original data.
[0123] It's worth noting that the second preprocessed data may contain padded data segments. In this case, it's necessary to delete the padded portions. The process includes: based on the padded length and the value of each padded bit, deleting the last data segment in the second preprocessed data to obtain the deleted data segment. Then, according to the order of the data segments in the second preprocessed data, concatenating the data segments before the last segment and the deleted data segment into a single data segment as intermediate data. This intermediate data is then format-converted to match the format of the original data to obtain the original data. This achieves the purpose of deleting the padded data and restoring the original data, which does not include the padded data.
[0124] For example, when the target data format is base64, as shown in Figure 8, after splicing the data segments and removing the padding data, the second preprocessed data in binary format is recovered. Then, the format of the second preprocessed data is restored based on the base64 data format to recover the original data in different formats.
[0125] In this embodiment, after obtaining the obfuscated target data, deobfuscation is performed based on the obfuscation method to restore the original data. No additional decoding is required, thus achieving fast and accurate data recovery.
[0126] In some embodiments, the data obfuscation process is shown in Figure 9. First, the original data is preprocessed to obtain the data to be processed, and obfuscation keys are generated to obtain a first obfuscation key D and a second obfuscation key E. Then, the data is obfuscated according to the first obfuscation key D and the second obfuscation key E to obtain the second obfuscated data. Then, the keys are obfuscated to achieve obfuscation of the first obfuscation key and the second obfuscation key, and obtain the target obfuscated key.
[0127] As shown in Figures 10 and 11, the preprocessing process for the original data involves converting the data format to obtain binary-formatted second preprocessed data. This second preprocessed data is then divided into equal-length segments, and further processing is performed when the length of the last initial data segment is insufficient, resulting in multiple ordered data segments after equal-length segmentation: data segments A, B, and C.
[0128] Referring to Figure 11, combine data segments A, B, and C into a whole, which is the first preprocessed data. Then, swap the positions of AB and X, and then swap the positions of BC in X to obtain data Y as the data to be processed.
[0129] The process of generating the obfuscated key is shown in Figure 12. First, a true first random number is generated and stored to obtain the first obfuscated key; then a true second random number is generated and stored to obtain the second obfuscated key.
[0130] The data obfuscation process in Figure 9 is shown in Figure 13. The first obfuscation key D is read, and the data position of the data to be processed Y is obfuscated using the first obfuscation key D to obtain the first obfuscated data Z = DCDADB. That is, the first obfuscation is inserted at the beginning of each data segment. Then, the second obfuscation key E is read, and the first obfuscation data Z is obfuscated using the second obfuscation key E to obtain the second obfuscated data L = D1C1D1A1D1B1, where D1 is the result of the obfuscation operation of D and E, C1 is the result of the obfuscation operation of C and E, A1 is the result of the obfuscation operation of A and E, and B1 is the result of the obfuscation operation of B and E.
[0131] The key obfuscation process in Figure 9 is shown in Figure 14. The first obfuscated key D and the first obfuscated key E are read respectively, and then D is used to interpolate E to obtain the target obfuscated key.
[0132] Finally, obtain the target obfuscation key and the second obfuscated data, and use them as the target data.
[0133] Correspondingly, the data restoration process is shown in Figure 15. First, the obfuscation key is restored to obtain the first obfuscation key D and the second obfuscation key E. Then, based on the first obfuscation key D and the second obfuscation key E, the data is deobfuscated to restore the data to be processed. After that, the data to be processed is post-processed to restore the original data.
[0134] The process of restoring the obfuscated key in Figure 15 is shown in Figure 16. First, the target obfuscated key is read, and the target obfuscated key is read by even-numbered / odd-numbered bits to obtain the first obfuscated key D and the second obfuscated key E.
[0135] The de-obfuscation process of the data in Figure 15 is shown in Figure 17. The second obfuscated data L = D1C1D1A1D1B1 is read, and then L is de-obfuscated using the second obfuscation key E to obtain the first obfuscated data Z = DCDADB. Then, Z is de-obfuscated using the first obfuscation key D to obtain the data to be processed Y = CAB.
[0136] The post-processing process of the data in Figure 15 is shown in Figure 18. Read the data to be processed Y = CAB, swap the positions of B and C in Y to get data X = BAC. Then, swap the positions of B and A in X to get the first preprocessed data M = ABC. After that, delete the padded part in C in the first preprocessed data, and combine C3 with A and B to form ABC3 to get the second preprocessed data. Then restore the second preprocessed data in binary format to the original data format to get the original data.
[0137] Referring to Figure 19, Figure 19 shows a structural block diagram of a data obfuscation device according to an embodiment of this application, used in an electronic device. The data obfuscation device 800 includes:
[0138] The first obfuscation module 810 is used to insert the first obfuscation key into the data to be processed to obtain the first obfuscated data;
[0139] The second obfuscation module 820 is used to obfuscate the first obfuscation data using the second obfuscation key to obtain the second obfuscation data.
[0140] The third obfuscation module 830 is used to perform key obfuscation processing on the first obfuscation key and the second obfuscation key to obtain the target obfuscation key;
[0141] The module 840 is used to obtain target data for the data to be processed based on the target obfuscation key and the second obfuscation data.
[0142] Optionally, the data to be processed includes multiple ordered data segments; the first obfuscation module 810 is further configured to perform bitwise interpolation on each data segment according to the first obfuscation key to obtain a first data segment corresponding to each data segment; and to combine the first data segments corresponding to each data segment according to the order of each data segment in the data to be processed to obtain the first obfuscated data.
[0143] Optionally, the second obfuscation module 820 is further configured to perform obfuscation operations on each first data segment in the first obfuscation data and the second obfuscation key to obtain a second data segment corresponding to the first data segment; and to combine the second data segments corresponding to each first data segment according to the arrangement order of each first data segment in the first obfuscation data to obtain the second obfuscation data.
[0144] Optionally, the lengths of multiple data segments are consistent; the data length of the first obfuscation key is consistent with the data length of the data segments; the length of the second obfuscation key is consistent with the length of the data segments; the second obfuscation module 820 is further configured to perform an XOR operation on the target segment in each first data segment of the first obfuscated data and the second obfuscation key to obtain the second data segment corresponding to the first data segment; the target segment includes a first local segment and / or a second local segment; the first local segment is the part of the first data segment that belongs to the data segment corresponding to the first data segment; the second local segment is the part of the first data segment that belongs to the first obfuscation key.
[0145] Optionally, the data obfuscation device further includes a preprocessing module for acquiring first preprocessed data; the first preprocessed data includes multiple ordered data segments; the order of at least two data segments in the first preprocessed data is adjusted to obtain adjusted first preprocessed data, which is used as data to be processed.
[0146] Optionally, the preprocessing module is also used to convert the acquired raw data into second preprocessed data in the target data format; and to divide the second preprocessed data into equal-length segments to obtain multiple ordered data fragments.
[0147] Optionally, the preprocessing module is further configured to, starting from the header of the second preprocessed data, divide the second preprocessed data into multiple ordered initial data segments at intervals of a specified data length; if the data length of the last initial data segment is less than the specified data length, the last initial data segment is padded to obtain a padded data segment with a data length of the specified data length, and the padded data segment and other initial data segments excluding the last initial data segment are obtained as multiple data segments; if the data length of the last initial data segment is the specified data length, multiple initial data segments are obtained as multiple data segments.
[0148] Optionally, the first obfuscation key and the second obfuscation key have the same length; the third obfuscation module 830 is further used to perform bitwise interpolation on the second obfuscation key based on the first obfuscation key to obtain the target obfuscation key.
[0149] Referring to Figure 20, which shows a structural block diagram of a data recovery device according to an embodiment of this application, for use in an electronic device, the data recovery device 900 includes:
[0150] The acquisition module 910 is used to acquire the target data to be restored; the target data includes the second obfuscated data and the target obfuscated key.
[0151] The first deobfuscation module 920 is used to perform key deobfuscation processing on the target obfuscated key to obtain the first obfuscated key and the second obfuscated key;
[0152] The second deobfuscation module 930 is used to deobfuscate the second obfuscated data using the second obfuscation key to obtain the first obfuscated data.
[0153] The third deobfuscation module 940 is used to deobfuscate the data position of the first obfuscated data using the first obfuscation key to obtain the data to be processed after the second obfuscated data is restored.
[0154] Optionally, the second deobfuscation module 930 is further configured to perform deobfuscation operation on each second data segment based on the second obfuscation key to obtain the first data segment corresponding to the second data segment; and combine the first data segments corresponding to each second data segment according to the arrangement order of each second data segment in the second obfuscated data to obtain the first obfuscated data.
[0155] Optionally, the first obfuscated data includes multiple ordered first data segments; the third deobfuscated module 940 is further configured to perform bitwise value extraction on each first data segment to extract the first obfuscated key and obtain the data segment corresponding to the first data segment; and combine the data segments corresponding to each first data segment according to the arrangement order of each first data segment in the first obfuscated data to obtain the data to be processed.
[0156] Optionally, the first obfuscation key and the second obfuscation key have the same length; the first deobfuscation module 920 is also used to perform bitwise value extraction on the target obfuscation key to extract the first obfuscation key and obtain the second obfuscation key.
[0157] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working process of the above-described device and module can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0158] Furthermore, the functions in the various embodiments of this application can be integrated into one processing module, or each module can exist physically separately, or two or more modules can be integrated into one module. The integrated module can be implemented in hardware or as a software functional module.
[0159] Please refer to Figure 21, which shows a structural block diagram of an electronic device according to an embodiment of this application. The electronic device 500 can be a smartphone, tablet computer, e-reader, vehicle, or other electronic device capable of running applications. The electronic device 500 in this application may include one or more of the following components: a processor 510, a memory 520, and one or more applications. One or more applications may be stored in the memory 520 and configured to be executed by one or more processors 510, and the one or more applications are configured to perform the methods described in the foregoing method embodiments.
[0160] Processor 510 may include one or more processing cores. Processor 510 connects to various parts within the electronic device 500 using various interfaces and lines, and performs various functions and processes data of the electronic device 500 by running or executing instructions, programs, code sets, or instruction sets stored in memory 520, and by calling data stored in memory 520. Optionally, processor 510 may be implemented using at least one hardware form of Digital Signal Processing (DSP), Field-Programmable Gate Array (FPGA), or Programmable Logic Array (PLA). Processor 510 may integrate one or a combination of several of the following: Central Processing Unit (CPU), Graphics Processing Unit (GPU), and modem. The CPU primarily handles the operating system, user interface, and applications; the GPU is responsible for rendering and drawing the displayed content; and the modem handles wireless communication. It is understood that the modem may also not be integrated into processor 510 and may be implemented separately using a communication chip.
[0161] The memory 520 may include random access memory (RAM) or read-only memory (ROM). The memory 520 can be used to store instructions, programs, code, code sets, or instruction sets. The memory 520 may include a program storage area and a data storage area. The program storage area may store instructions for implementing an operating system, instructions for implementing at least one function (such as touch functionality, sound playback functionality, image playback functionality, etc.), and instructions for implementing the various method embodiments described below. The data storage area may also store data created by the electronic device 500 during use (such as phonebook data, audio and video data, chat log data, etc.).
[0162] Furthermore, the functions in the various embodiments of this application can be integrated into one processing module, or each module can exist physically separately, or two or more modules can be integrated into one module. The integrated module can be implemented in hardware or as a software functional module.
[0163] On the other hand, this application also provides a computer-readable storage medium storing program code that can be called by a processor to execute the methods described in the above method embodiments.
[0164] Computer-readable storage media can be electronic storage devices such as flash memory, EEPROM (Electrically Erasable Programmable Read-Only Memory), EPROM, hard disk, or a cluster of ROMs. Optionally, computer-readable storage media include non-transitory computer-readable storage media. The computer-readable storage medium has storage space for program code that performs any of the method steps described above. This program code can be read from or written to one or more computer program products. The program code can be compressed, for example, in a suitable form.
[0165] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.
Claims
1. A data obfuscation method, characterized in that, The method includes: Insert the first obfuscation key into the data to be processed to obtain the first obfuscated data; The first obfuscated data is obfuscated using the second obfuscation key to obtain the second obfuscated data; The first obfuscated key and the second obfuscated key are subjected to key obfuscation processing to obtain the target obfuscated key; Based on the target obfuscation key and the second obfuscation data, target data for the data to be processed is obtained.
2. The method according to claim 1, characterized in that, The data to be processed includes multiple ordered data segments; The step of inserting the first obfuscation key into the data to be processed to obtain the first obfuscated data includes: Each data segment is interpolated bitwise according to the first obfuscation key to obtain a first data segment corresponding to each data segment; Based on the order in which the data segments are arranged in the data to be processed, the first data segments corresponding to each data segment are combined to obtain the first obfuscated data.
3. The method according to claim 2, characterized in that, The step of obfuscating the first obfuscated data using the second obfuscation key to obtain the second obfuscated data includes: For each first data segment in the first obfuscated data, an obfuscation operation is performed on the first data segment and the second obfuscation key to obtain the second data segment corresponding to the first data segment. Based on the order in which each of the first data segments is arranged in the first obfuscated data, the second data segments corresponding to each of the first data segments are combined to obtain the second obfuscated data.
4. The method according to claim 3, characterized in that, The multiple data segments have the same length; the data length of the first obfuscation key is the same as the data length of the data segments; the data length of the second obfuscation key is the same as the data segment. The step of performing an obfuscation operation on each first data segment in the first obfuscated data and the second obfuscation key to obtain a second data segment corresponding to the first data segment includes: For each first data segment in the first obfuscated data, the target segment in the first data segment is XORed with the second obfuscation key to obtain the second data segment corresponding to the first data segment; the target segment includes a first local segment and / or a second local segment; the first local segment is the part of the first data segment that belongs to the data segment corresponding to the data segment; the second local segment is the part of the first data segment that belongs to the first obfuscation key.
5. The method according to any one of claims 2-4, characterized in that, Before performing bitwise interpolation on each data segment according to the first obfuscation key to obtain the first data segment corresponding to each data segment, the method further includes: Obtain first preprocessed data; the first preprocessed data includes multiple ordered data segments; The order of at least two of the data segments in the first preprocessed data is adjusted to obtain the adjusted first preprocessed data, which is used as the data to be processed.
6. The method according to claim 5, characterized in that, Before acquiring the first preprocessed data, the method further includes: The acquired raw data is converted into second preprocessed data in the target data format; The second preprocessed data is divided into equal-length segments to obtain multiple ordered data fragments.
7. The method according to claim 5, characterized in that, The second preprocessed data is divided into equal-length segments to obtain multiple ordered data fragments, including: Starting from the beginning of the second preprocessed data, the second preprocessed data is divided into multiple ordered initial data segments at intervals of a specified data length. If the data length of the last initial data segment is less than the specified data length, the last initial data segment is padded to obtain a padded data segment with a data length of the specified data length. The padded data segment and other initial data segments excluding the last initial data segment are then obtained as the plurality of data segments. If the data length of the last initial data segment is the specified data length, the plurality of initial data segments are obtained and used as the plurality of data segments.
8. The method according to claim 1, characterized in that, The first obfuscation key and the second obfuscation key have the same length; The step of performing key obfuscation processing on the first obfuscated key and the second obfuscated key to obtain the target obfuscated key includes: The target obfuscated key is obtained by bitwise interpolation of the second obfuscated key based on the first obfuscated key.
9. A data restoration method, characterized in that, The method includes: Obtain the target data to be restored; the target data includes second obfuscated data and a target obfuscation key; The target obfuscated key is deobfuscated to obtain a first obfuscated key and a second obfuscated key; The second obfuscated data is deobfuscated using the second obfuscation key to obtain the first obfuscated data; The first obfuscation key is extracted from the first obfuscation data to obtain the data to be processed after the second obfuscation data is restored.
10. The method according to claim 9, characterized in that, The second obfuscated data comprises multiple ordered second data segments; The step of deobfuscating the second obfuscated data using the second obfuscation key to obtain the first obfuscated data includes: For each of the second data segments, the second data segment is de-obfuscated based on the second obfuscation key to obtain the first data segment corresponding to the second data segment; Based on the order in which each of the second data segments is arranged in the second obfuscated data, the first data segments corresponding to each of the second data segments are combined to obtain the first obfuscated data.
11. The method according to claim 9, characterized in that, The first obfuscated data comprises an ordered plurality of first data segments; The step of retrieving the first obfuscation key from the first obfuscated data to obtain the data to be processed after restoring the second obfuscated data includes: For each of the first data segments, the first data segment is processed bitwise to extract the first obfuscation key and obtain the data segment corresponding to the first data segment. Based on the order in which each of the first data segments is arranged in the first obfuscated data, the data segments corresponding to each of the first data segments are combined to obtain the data to be processed.
12. The method according to claim 9, characterized in that, The first obfuscation key and the second obfuscation key have the same length; The step of performing key de-obfuscation on the target obfuscated key to obtain a first obfuscated key and a second obfuscated key includes: The target obfuscated key is processed bitwise to extract the first obfuscated key and obtain the second obfuscated key.
13. An electronic device, characterized in that, include: One or more processors; Memory; One or more applications, wherein the one or more applications are stored in the memory and configured to be executed by the one or more processors, the one or more applications being configured to perform the method as described in any one of claims 1-8, or to perform the method as described in any one of claims 9-12.
14. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores processor-executable program code, which, when executed by the processor, causes the processor to perform the method of any one of claims 1-8, or to perform the method of any one of claims 9-12.