The invention relates to a
Web application dynamic secret key
encryption method based on SM3 and SM4, and relates to the technical field of
data security. According to the method, a dynamic symmetric secret key is cooperatively generated at a front end and a rear end, a secret key seed is generated by utilizing an SM3 Hash
algorithm, and sensitive data is encrypted and transmitted by combining an SM4 symmetric
encryption algorithm, so that the secret key is not hard-coded and not transmitted; the
session key is dynamically changed each time, the
algorithm support can be completely localized, the
encryption and decryption process is simple and efficient, a complicated
certificate system or
public key infrastructure is not needed, the front and rear ends only need to synchronize the
key generation rule, and the method is suitable for an offline or weak network environment, does not depend on real-time
network verification, and is easy to implement. The method can be used for offline or weak network environments such as an
intranet and a government affair
private network, and can effectively prevent historical data from being replayed by introducing factors such as dates and timestamps, so that sensitive data is effectively prevented from being stolen or tampered in the transmission process, and the overall security protection capability of
Web application is improved.