A data transmission method, apparatus, device, storage medium and program product
By dynamically negotiating a random symmetric key between the industrial gateway and the platform, and using asymmetric encryption and message digest algorithms to build a secure channel, the problems of long key pre-setting time and easy leakage are solved, and efficient and secure data transmission is achieved.
Patent Information
- Application Number
- CN202411083241.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-08
- Publication Date
- 2025-11-28
- Estimated Expiration
- 2044-08-08
AI Technical Summary
In existing technologies, during data transmission between the industrial gateway and the platform, key pre-setting needs to be generated on the platform and copied to the industrial gateway, which is time-consuming and inefficient. Furthermore, the pre-set keys are prone to leakage, resulting in insufficient data transmission security.
Asymmetric encryption algorithms are used to generate public and private keys, and random symmetric keys are dynamically negotiated. Encryption, decryption, and trust verification are performed using message digest algorithms, avoiding the need to pre-set keys on the gateway. A secure channel is built using asymmetric encryption algorithms and message digest algorithms to ensure the security and randomness of key negotiation.
It improves the security of data transmission, reduces labor costs, increases transmission efficiency, enhances the security and difficulty of data transmission, and prevents keys from being tampered with.
Smart Images

Figure CN118827225B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data secure transmission, and in particular to a data transmission method, device, equipment, storage medium and program product. BACKGROUND
[0002] Industrial Internet of Things (IIOT) refers to a technology for realizing real-time monitoring, remote monitoring and intelligent management in industrial systems of different industries. With the continuous development of industrial Internet of Things technology, industrial Internet of Things platforms and industrial intelligent gateways play an increasingly important role, and the two are constantly developing in integration.
[0003] Currently, in the process of data transmission between the industrial gateway side and the platform side, in order to ensure the security of data transmission, a method of preloading a static symmetric key on the industrial gateway is usually used to realize data transmission. The industrial gateway side uses the preloaded key to encrypt the reported data, and the platform side uses the same key to decrypt the data after receiving the data, thereby completing the secure transmission of the data.
[0004] However, the inventors have found that the prior art at least has the following problems: the key preloading needs to generate a symmetric key on the platform side first, and then copy the symmetric key to the industrial gateway. The preloading process is time-consuming and inefficient. Moreover, the preloaded key can only be saved in plaintext on the industrial gateway, which is easy to be leaked, and once leaked, it will cause information theft in the data transmission process. SUMMARY
[0005] The purpose of the embodiments of the present application is to provide a data transmission method, device, equipment, storage medium and program product, which do not need to pre-load keys on the gateway, saving manpower costs, and dynamically negotiating random symmetric keys between gateways for encryption and decryption of data transmission, effectively improving the security of data transmission.
[0006] To achieve the above-mentioned purpose, the embodiments of the present application provide a data transmission method applied to a first gateway, the method comprising:
[0007] generating a public key and a private key using an asymmetric encryption algorithm after establishing a communication connection with a second gateway;
[0008] sending the public key to the second gateway;
[0009] receiving an encrypted data packet sent by the second gateway; wherein the encrypted data packet is generated by the second gateway using a symmetric encryption algorithm to generate a random symmetric key, and then using the public key and a message digest algorithm to encrypt the random symmetric key;
[0010] decrypting the encrypted data packet using the private key and the message digest algorithm to obtain a random symmetric key, and performing a trustworthiness verification on the random symmetric key;
[0011] When the trustworthiness of the random symmetric key is verified, a normal response information is sent to the second gateway;
[0012] In the process of target data transmission with the second gateway, the target data is encrypted and decrypted by using the random symmetric key.
[0013] As an improvement of the above scheme, the encrypted data packet is a first message digest generated by the second gateway by processing the random symmetric key and gateway information of the second gateway by using a message digest algorithm, and is generated by the second gateway by packing and encrypting the random symmetric key, the gateway information and the first message digest by using the public key;
[0014] Then, the random symmetric key is obtained by decrypting the encrypted data packet by using the private key and the message digest algorithm, and the trustworthiness of the random symmetric key is verified, comprising:
[0015] The random symmetric key, the gateway information and the first message digest are obtained by decrypting the encrypted data packet by using the private key;
[0016] The first check message digest is obtained by processing the random symmetric key and the gateway information by using the message digest algorithm;
[0017] The consistency of the first message digest and the first check message digest is compared, and the trustworthiness of the random symmetric key is verified.
[0018] As an improvement of the above scheme, the method further comprises:
[0019] When the trustworthiness of the random symmetric key is not verified, an abnormal response information is sent to the second gateway, so that the second gateway generates a random symmetric key and an encrypted data packet again.
[0020] As an improvement of the above scheme, after the abnormal response information is sent to the second gateway when the trustworthiness of the random symmetric key is not verified, the method further comprises:
[0021] When the number of times that the trustworthiness of the random symmetric key is not verified continuously reaches a preset number threshold, the connection with the second gateway is disconnected, and the connection with the second gateway is re-established, and the public key is sent to the second gateway again.
[0022] As an improvement of the above scheme, after the connection with the second gateway is re-established, and the public key is sent to the second gateway again, the method further comprises:
[0023] When the trustworthiness verification of the random symmetric key still fails, a new public key and a new private key are generated by using an asymmetric encryption algorithm, and the new public key is re-sent to the second gateway.
[0024] As an improvement of the above scheme, the sending of the public key to the second gateway comprises:
[0025] The public key is processed by using a message digest algorithm to generate a second message digest;
[0026] The second message digest is encrypted by using the private key to obtain an encrypted message digest;
[0027] The public key and the encrypted message digest are sent to the second gateway, so that the second gateway decrypts the encrypted message digest by using the public key to perform trustworthiness verification on the public key, and generates the encrypted data packet when the trustworthiness verification passes.
[0028] As an improvement of the above scheme, after the sending of the public key and the encrypted message digest to the second gateway, the method further comprises:
[0029] When a response message sent by the second gateway is received, the response message indicating that the trustworthiness verification of the public key fails, a new public key and a new private key are generated by using an asymmetric encryption algorithm.
[0030] As an improvement of the above scheme, the sending of the normal response information to the second gateway when the trustworthiness verification of the random symmetric key passes comprises:
[0031] When the trustworthiness verification of the random symmetric key passes, a normal response information is generated;
[0032] The normal response information is encrypted by using the private key to obtain encrypted normal response information and send the encrypted normal response information to the second gateway;
[0033] The sending of the abnormal response information to the second gateway when the trustworthiness verification of the random symmetric key fails comprises:
[0034] When the trustworthiness verification of the random symmetric key fails, an abnormal response information is generated;
[0035] The abnormal response information is encrypted by using the private key to obtain encrypted abnormal response information and send the encrypted abnormal response information to the second gateway.
[0036] As an improvement of the above scheme, after the comparison of the consistency of the first message digest and the first check message digest, the trustworthiness verification of the random symmetric key, the method further comprises:
[0037] When the trustworthiness of the random symmetric key is verified, a key-value pair is generated with the gateway information as the key and the random symmetric key as the value, and is cached;
[0038] Then, in the process of target data transmission with the second gateway, the target data is encrypted and decrypted by using the random symmetric key.
[0039] In the process of target data transmission with the second gateway, the random symmetric key corresponding to the gateway information of the second gateway is searched in the key-value pair, and the target data is encrypted and decrypted by using the random symmetric key.
[0040] As an improvement of the above scheme, the method further comprises:
[0041] When the transmission of the target data is completed, the connection with the second gateway is disconnected.
[0042] The private key and the random symmetric key are destroyed.
[0043] Embodiments of the application provide a data transmission method applied to a second gateway, and the method comprises:
[0044] After establishing a communication connection with a first gateway, a public key issued by the first gateway is received, wherein the first gateway generates the public key and a private key by using an asymmetric encryption algorithm.
[0045] A random symmetric key is generated by using a symmetric encryption algorithm.
[0046] The random symmetric key is encrypted by using the public key and a message digest algorithm to generate an encrypted data packet, and the encrypted data packet is sent to the first gateway, so that the first gateway decrypts the encrypted data packet by using the private key and the message digest algorithm to obtain the random symmetric key, and verifies the trustworthiness of the random symmetric key.
[0047] When a normal response information sent by the first gateway after the trustworthiness is verified is received, in the process of target data transmission with the first gateway, the target data is encrypted and decrypted by using the random symmetric key.
[0048] As an improvement of the above scheme, the random symmetric key is encrypted by using the public key and the message digest algorithm to generate an encrypted data packet, and the encrypted data packet is sent to the first gateway, so that the first gateway decrypts the encrypted data packet by using the private key and the message digest algorithm to obtain the random symmetric key, and verifies the trustworthiness of the random symmetric key, which comprises:
[0049] The random symmetric key and gateway information of the second gateway are processed by using a message digest algorithm to generate a first message digest;
[0050] The random symmetric key, the gateway information and the first message digest are packaged and encrypted by using the public key to generate the encrypted data packet;
[0051] The encrypted data packet is sent to the first gateway, so that the first gateway decrypts the encrypted data packet by using the private key to obtain a random symmetric key, gateway information and a first message digest, processes the random symmetric key and the gateway information by using the message digest algorithm to obtain a first check message digest, and compares the consistency of the first message digest and the first check message digest to verify the credibility of the random symmetric key.
[0052] As an improvement of the above scheme, the public key issued by the first gateway is received, including:
[0053] The public key and the encrypted message digest sent by the first gateway are received; wherein the encrypted message digest is generated by the first gateway by processing the public key by using a message digest algorithm to generate a second message digest, and then encrypting the second message digest by using the private key;
[0054] The encrypted message digest is decrypted by using the public key to obtain a second message digest;
[0055] The public key is encrypted by using the message digest algorithm to obtain a second check message digest;
[0056] The consistency of the second message digest and the second check message digest is compared to verify the credibility of the public key.
[0057] The embodiment of the application further provides a data transmission method applied to a data transmission system including a first gateway and a second gateway, and the method includes:
[0058] After the communication connection between the first gateway and the second gateway is established, the first gateway generates a public key and a private key by using an asymmetric encryption algorithm, and sends the public key to the second gateway;
[0059] The second gateway generates a random symmetric key by using a symmetric encryption algorithm, encrypts the random symmetric key by using the public key and a message digest algorithm to generate an encrypted data packet, and sends the encrypted data packet to the first gateway;
[0060] The first gateway decrypts the encrypted data packet by using the private key and the message digest algorithm to obtain a random symmetric key, and verifies the credibility of the random symmetric key;
[0061] The first gateway sends normal response information to the second gateway when the trustworthiness of the random symmetric key is verified to be passed;
[0062] The first gateway encrypts and decrypts target data by using the random symmetric key in the process of target data transmission with the second gateway.
[0063] The embodiment of the application further provides a data transmission device applied to a first gateway, and the device comprises:
[0064] An asymmetric key generation module is configured to generate a public key and a private key by using an asymmetric encryption algorithm after a communication connection with a second gateway is established;
[0065] A public key sending module is configured to send the public key to the second gateway;
[0066] An encrypted data packet receiving module is configured to receive an encrypted data packet sent by the second gateway, wherein the encrypted data packet is generated by encrypting a random symmetric key by using the public key and a message digest algorithm after the second gateway generates the random symmetric key by using a symmetric encryption algorithm;
[0067] A symmetric key obtaining module is configured to decrypt the encrypted data packet by using the private key and the message digest algorithm to obtain a random symmetric key, and to verify the trustworthiness of the random symmetric key;
[0068] A response information sending module is configured to send normal response information to the second gateway when the trustworthiness of the random symmetric key is verified to be passed;
[0069] A first data transmission module is configured to encrypt and decrypt target data by using the random symmetric key in the process of target data transmission with the second gateway.
[0070] The embodiment of the application further provides a data transmission device applied to a second gateway, and the device comprises:
[0071] A public key receiving module is configured to receive a public key issued by a first gateway after a communication connection with the first gateway is established, wherein the first gateway generates the public key and a private key by using an asymmetric encryption algorithm;
[0072] A symmetric key generation module is configured to generate a random symmetric key by using a symmetric encryption algorithm;
[0073] The encryption packet generation module is configured to encrypt the random symmetric key by using the public key and a message digest algorithm, to generate an encryption packet, and to send the encryption packet to the first gateway, so that the first gateway decrypts the encryption packet by using the private key and the message digest algorithm to obtain the random symmetric key, and performs a trustworthiness verification on the random symmetric key.
[0074] The second data transmission module is configured to, when receiving normal response information sent by the first gateway after the trustworthiness verification is passed, perform encryption and decryption on the target data by using the random symmetric key in a process of performing target data transmission with the first gateway.
[0075] The embodiment of the present application further provides a data transmission device, including a processor, a memory and a computer program stored in the memory and configured to be executed by the processor, and the processor implements the data transmission method according to any one of the above when executing the computer program.
[0076] The embodiment of the present application further provides a computer readable storage medium, including a stored computer program, wherein the computer readable storage medium controls a device where the computer readable storage medium is located to execute the data transmission method according to any one of the above when the computer program runs.
[0077] The embodiment of the present application further provides a computer program product, including a computer program or computer instructions, and the computer program or the computer instructions implement the data transmission method according to any one of the above when executed by a processor.
[0078] Compared with the prior art, the data transmission method, device, equipment, storage medium and program product provided by the present application establish a secure channel between the first gateway and the second gateway based on an asymmetric encryption algorithm and a message digest algorithm, and based on the secure channel, the first gateway and the second gateway automatically negotiate a random symmetric key based on a symmetric encryption algorithm, which ensures the security of the process of negotiating the random symmetric key between the first gateway and the second gateway, guarantees the randomness and uncertainty of the generated encryption key, and prevents tampered data. Moreover, the present application does not need to preset a key on the gateway, which saves the labor cost and improves the efficiency, and the data transmitted is encrypted and decrypted by using the random symmetric key, which effectively improves the security of data transmission between gateways and improves the difficulty of data cracking by an outsider. BRIEF DESCRIPTION OF DRAWINGS
[0079] Figure 1 is a flowchart of a data transmission method provided by the embodiment of the present application;
[0080] Figure 2is a structural schematic diagram of an industrial internet of things platform and an industrial gateway in an embodiment of the present application;
[0081] Figure 3 is a flow schematic diagram of a preferred data transmission method in an embodiment of the present application;
[0082] Figure 4 is a flow schematic diagram of another data transmission method provided by an embodiment of the present application;
[0083] Figure 5 is a structural schematic diagram of a data transmission system provided by an embodiment of the present application;
[0084] Figure 6 is a structural schematic diagram of a data transmission device provided by an embodiment of the present application. DETAILED DESCRIPTION
[0085] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work fall within the scope of protection of the present application.
[0086] In the description of the present application, it should be understood that the terms "center", "upper", "lower", "front", "back", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer" and the like indicate the orientation or positional relationship shown in the drawings, and are only intended to facilitate the description of the present application and simplify the description, and do not indicate or imply that the device or element referred to must have a particular orientation, be constructed and operated in a particular orientation, and therefore cannot be understood as a limitation of the present application.
[0087] The terms "first", "second" are only for descriptive purpose, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of the technical features indicated. Therefore, the features defined with "first", "second" can explicitly or implicitly include one or more of the features. In the description of the present application, unless otherwise specified, the meaning of "multiple" is two or more.
[0088] In the description of the present application, it should be noted that, unless otherwise explicitly specified and limited, the terms "mounting", "connecting", "connection" should be understood in a broad sense, for example, it can be fixed connection, or detachable connection, or integral connection; it can be mechanical connection, or electrical connection; it can be direct connection, or indirect connection through intermediate medium, or internal communication of two elements. For those skilled in the art, the specific meaning of the above terms in the present application can be understood according to the specific circumstances.
[0089] Referring to Figure 1 is a flowchart of a data transmission method provided by an embodiment of the present application. The embodiment of the present application provides a data transmission method, which is applied to a first gateway and specifically includes steps S11 to S16.
[0090] S11, generating a public key and a private key by using an asymmetric encryption algorithm after establishing a communication connection with a second gateway;
[0091] S12, sending the public key to the second gateway;
[0092] S13, receiving an encrypted data packet sent by the second gateway; wherein the encrypted data packet is generated by encrypting a random symmetric key by using the public key and a message digest algorithm after the second gateway generates the random symmetric key by using a symmetric encryption algorithm;
[0093] S14, decrypting the encrypted data packet to obtain the random symmetric key by using the private key and the message digest algorithm, and performing a trustworthiness verification on the random symmetric key;
[0094] S15, sending normal response information to the second gateway when the trustworthiness verification on the random symmetric key is passed;
[0095] S16, performing encryption and decryption on target data by using the random symmetric key in a process of performing target data transmission with the second gateway.
[0096] It should be noted that the embodiment of the present application is applicable to a data security transmission process between a first gateway and a second gateway. The first gateway and the second gateway are subjects with data communication needs, for example, in the field of industrial Internet of Things, the first gateway is an industrial Internet of Things platform, and the second gateway is each industrial intelligent gateway. Of course, the first gateway and the second gateway can also be communication subjects in other communication fields, which are not limited here.
[0097] In the embodiment of the present application, the first gateway and the second gateway determine the random symmetric key for data encryption and decryption through dynamic negotiation. Specifically, the first gateway and the second gateway first establish a connection through a preset handshake mode. After the connection is established, when receiving a public key request of the second gateway, the first gateway generates an asymmetric key including a public key and a private key by using a preset asymmetric encryption algorithm. The first gateway distributes the public key to the second gateway for caching, and caches the private key for backup. The second gateway generates a random symmetric key by using a preset symmetric encryption algorithm, and encrypts the random symmetric key by using the public key and a preset message digest algorithm to generate an encrypted data packet, and then sends the encrypted data packet to the first gateway to ensure the secure transmission of the random symmetric key. After receiving the encrypted data packet, the first gateway decrypts the encrypted data packet by using the private key and the message digest algorithm to obtain the random symmetric key, and performs a credibility verification on the random symmetric key. If the first gateway can normally decrypt and the credibility verification is passed, the first gateway sends a normal response information to the second gateway, and the key negotiation stage is completed. Then, the random symmetric key can be used for data encryption and decryption in the data transmission process of the first gateway and the second gateway.
[0098] Preferably, the asymmetric encryption algorithm, the symmetric encryption algorithm and the message digest algorithm use a national encryption algorithm. More preferably, the asymmetric encryption algorithm is an SM2 algorithm, the symmetric encryption algorithm is an SM4 algorithm, and the message digest algorithm is an SM3 algorithm.
[0099] By using the technical means of the embodiment of the present application, a secure channel is constructed between the first gateway and the second gateway based on an asymmetric encryption algorithm and a message digest algorithm. Based on the secure channel, the first gateway and the second gateway automatically negotiate a random symmetric key based on a symmetric encryption algorithm, ensuring the security of the process of negotiating the random symmetric key between the first gateway and the second gateway, ensuring the randomness and uncertainty of the generated encryption key, and preventing tampered data. Moreover, no key needs to be preloaded on the gateway, saving labor costs and improving efficiency. The random symmetric key is used for data encryption and decryption, effectively improving the security of data transmission between gateways and increasing the difficulty of data cracking by external parties.
[0100] As a preferred embodiment, the embodiment of the present application is further implemented on the basis of the above-mentioned embodiment. The encrypted data packet is generated by the second gateway by processing the random symmetric key and gateway information of the second gateway using a message digest algorithm to generate a first message digest, and then packing and encrypting the random symmetric key, the gateway information and the first message digest using the public key.
[0101] Then, step S14, i.e., the step of decrypting the encrypted data packet using the private key and the message digest algorithm to obtain the random symmetric key and performing trustworthiness verification on the random symmetric key, comprises steps S141-S143:
[0102] S141, decrypting the encrypted data packet using the private key to obtain the random symmetric key, gateway information, and a first message digest;
[0103] S142, processing the random symmetric key and the gateway information using the message digest algorithm to obtain a first verification message digest;
[0104] S143, comparing the first message digest and the first verification message digest for consistency to perform trustworthiness verification on the random symmetric key.
[0105] In the embodiment of the present application, the negotiation and verification process of the random symmetric key is further optimized. Specifically, after generating the random symmetric key, the second gateway processes the random symmetric key and its own gateway information using the message digest algorithm to generate a message digest, denoted as a first message digest. Then, the random symmetric key, the gateway information, and the first message digest are packaged and encrypted using the public key received from the first gateway to generate an encrypted data packet and sent to the first gateway. After receiving the encrypted data packet, the first gateway decrypts it using the cached private key to obtain the random symmetric key, the gateway information, and the first message digest. Then, the first gateway performs message digest calculation on the decrypted random symmetric key and gateway information using the message digest algorithm to obtain a first verification message digest. A comparison is made between the first message digest sent by the second gateway and the first verification message digest generated by the first gateway. If they are consistent, it means that the current communication has not been tampered with, and the trustworthiness verification of the random symmetric key is passed. Otherwise, it means that the communication information has been tampered with, and the random symmetric key has been compromised, and the trustworthiness verification is failed.
[0106] By using the technical means of the embodiment of the present application, in the key negotiation phase, the random symmetric key and other data are encrypted and decrypted for transmission through the asymmetric encryption algorithm, and the trustworthiness verification is performed using the message digest verification method to prevent tampering of data. That is, the embodiment of the present application constructs a secure channel based on the asymmetric encryption algorithm and the message digest algorithm, and the first gateway and the second gateway can automatically negotiate the random symmetric key based on the secure channel, ensuring the security of the process of negotiating the random symmetric key between the first gateway and the second gateway, and further improving the security of the subsequent data transmission process.
[0107] As a preferred embodiment, the embodiment of the present application is further implemented on the basis of any of the above embodiments, and after step S14, the method further comprises steps S17-S19:
[0108] S17, when the trustworthiness verification of the random symmetric key fails, sending an abnormal response information to the second gateway to make the second gateway regenerate a random symmetric key and an encrypted data packet.
[0109] S18, when the number of consecutive times of the trustworthiness verification of the random symmetric key failing reaches a preset number threshold, disconnecting the connection with the second gateway and re-establishing the connection with the second gateway, and re-sending the public key to the second gateway.
[0110] S19, when the trustworthiness verification of the random symmetric key still fails, generating a new public key and a new private key by using an asymmetric encryption algorithm, and re-sending the new public key to the second gateway.
[0111] In the embodiment of the present application, the processing means for abnormal situations in the key negotiation process of the first gateway and the second gateway is optimized. After receiving the encrypted data packet, the first gateway decrypts by using the private key and performs trustworthiness verification by using a message digest algorithm. If the private key decryption process is abnormal or the trustworthiness verification fails, the first gateway sends an abnormal response information to the second gateway. When receiving the abnormal response information, the second gateway regenerates a new random symmetric key by using the symmetric encryption algorithm, and generates a new encrypted data packet by using the public key and the message digest algorithm and sends it to the first gateway, to negotiate the random symmetric key again.
[0112] The first gateway counts the number of times of sending the abnormal response information, and when the number of continuous abnormalities reaches a certain number threshold, for example, 3 times, the key negotiation fails, and an abnormal management stage is entered. At this time, it is first considered that the network connection is abnormal, so the first gateway disconnects the connection between the first gateway and the second gateway, and reenters the connection establishment stage. After the first gateway and the second gateway are reconnected, the first gateway reissues the public key to the second gateway, and the second gateway generates the encrypted data packet again using the public key. When reconnection and key negotiation are performed, the credibility verification still fails, and it is considered that the public key issued by the first gateway has been stolen. Therefore, the first gateway generates a new public key and a private key using the asymmetric encryption algorithm, and issues the new public key to the second gateway. The second gateway generates the encrypted data packet again using the new public key. When the new public key is used for key negotiation, the credibility verification still fails, and an alarm management stage is entered. The first gateway notifies the requester to manually access through short message, WeChat, email and the like.
[0113] By using the technical means of the embodiments of the present application, an abnormal management program is introduced in the key negotiation process. If encryption and decryption abnormalities or digest verification abnormalities occur in the key negotiation process, the second gateway is caused to generate a random symmetric key again, to reconnect, or the first gateway is caused to generate a new public key and private key pair, and the like, according to the actual situation, so as to solve the problem. When multiple attempts cannot solve the problem, an alarm management program is entered, and manual intervention is performed for processing, so as to further strengthen the data transmission security.
[0114] As a preferred embodiment, the embodiments of the present application are further implemented on the basis of any of the above embodiments. Step S12, i.e., the step of sending the public key to the second gateway, comprises steps S121 to S123:
[0115] S121, the public key is processed using a message digest algorithm to generate a second message digest;
[0116] S122, the second message digest is encrypted using the private key to obtain an encrypted message digest;
[0117] S123, the public key and the encrypted message digest are sent to the second gateway, so that the second gateway decrypts the encrypted message digest using the public key, and performs credibility verification on the public key, and generates the encrypted data packet when the credibility verification is passed.
[0118] In the embodiment of the present application, the process of issuing the public key to the first gateway is further optimized. Specifically, after the first gateway generates the public key and the private key by using the asymmetric algorithm, the first gateway generates a message digest of the public key by using a message digest algorithm, denoted as a second message digest, and encrypts the second message digest by using the private key. The first gateway issues the public key to the second gateway together with the encrypted message digest.
[0119] The second gateway decrypts the encrypted message digest by using the public key to obtain the second message digest, processes the public key by using the message digest algorithm to obtain a second check message digest, verifies the public key by verifying the consistency between the second message digest and the second check message digest, and generates the encrypted data packet when the verification is passed.
[0120] Preferably, after the step S123, i.e., the step of sending the public key and the encrypted message digest to the second gateway, the method further comprises a step S124:
[0121] S124, when receiving a response message sent by the second gateway and indicating that the verification of the public key is failed, generating a new public key and a new private key by using the asymmetric encryption algorithm.
[0122] If the public key decryption is abnormal or the verification is failed, the second gateway re-sends a public key request to the first gateway or sends a response message indicating that the verification of the public key is failed to the first gateway, and the first gateway generates a new public key and a new private key by using the asymmetric algorithm and re-encrypts and issues the new public key.
[0123] Optionally, if the abnormal response is continuous for three times, the abnormal management stage is also entered, and the specific process of the abnormal management program can refer to the above embodiment, which is not described here again.
[0124] By using the technical means of the embodiment of the present application, the security of the key agreement and the security of the data transmission process are further improved by encrypting and verifying the process of issuing the public key.
[0125] As a preferred embodiment, the embodiment of the present application is further implemented on the basis of any of the above embodiments. The step S15, i.e., the step of sending the normal response information to the second gateway when the verification of the random symmetric key is passed, comprises:
[0126] generating the normal response information when the verification of the random symmetric key is passed;
[0127] encrypting the normal response information by using the private key to obtain the encrypted normal response information and sending the encrypted normal response information to the second gateway;
[0128] Step S17, that is, when the trustworthiness verification of the random symmetric key fails, an abnormal response information is sent to the second gateway, including:
[0129] When the trustworthiness verification of the random symmetric key fails, an abnormal response information is generated;
[0130] The private key is used to encrypt the abnormal response information to obtain encrypted abnormal response information and send to the second gateway.
[0131] In the embodiment of the application, the process of sending normal response information or abnormal response information to the first gateway is optimized. When the encrypted data packet can be normally decrypted and the trustworthiness verification passes, the first gateway generates normal response information, and then sends the normal response information to the second gateway after encrypting the normal response information by using the private key, so that the second gateway decrypts the encrypted normal response information by using the public key to extract the normal response information. When the encrypted data packet is decrypted abnormally or the trustworthiness verification fails, the first gateway generates abnormal response information, and then sends the abnormal response information to the second gateway after encrypting the abnormal response information by using the private key, so that the second gateway decrypts the encrypted abnormal response information by using the public key to extract the abnormal response information.
[0132] By using the technical means of the embodiment of the application, the response information between the first gateway and the second gateway is encrypted and decrypted by using the public key and the private key, which further improves the security of key negotiation and improves the security of the data transmission process.
[0133] As a preferred embodiment, the embodiment of the application is further implemented on the basis of any of the above embodiments. After step S143, that is, the consistency of the first message digest and the first check message digest is compared, the trustworthiness of the random symmetric key is verified, the method further includes:
[0134] When the trustworthiness verification of the random symmetric key passes, the gateway information is used as a primary key, and the random symmetric key is used as a value to generate a key-value pair for caching;
[0135] Step S16, that is, in the process of target data transmission with the second gateway, the random symmetric key is used to encrypt and decrypt the target data, including:
[0136] In the process of target data transmission with the second gateway, the random symmetric key corresponding to the gateway information of the second gateway is searched in the key-value pair, and the random symmetric key is used to encrypt and decrypt the target data.
[0137] In the embodiment of the present application, since the first gateway can establish a connection with multiple gateways, after the first gateway decrypts the random symmetric key used for data transmission between the second gateway, the first gateway generates a key-value pair by taking the gateway ID in the gateway information as the primary key and taking the random symmetric key as the value, and caches the key-value pair to form one machine and one secret. In the subsequent data transmission process of the first gateway and the second gateway, the first gateway finds the corresponding random symmetric key according to the gateway ID of the second gateway, and uses the random symmetric key to encrypt the data sent to the second gateway, and uses the random symmetric key to decrypt the data received from the second gateway.
[0138] As a preferred embodiment, after step S15, the method further comprises:
[0139] When the transmission of the target data is completed, the connection with the second gateway is disconnected, and the private key and the random symmetric key are destroyed.
[0140] In the embodiment of the present application, when the data transmission of the first gateway and the second gateway is completed, the first gateway and the second gateway are disconnected, and the random symmetric key and the public-private key pair residing in the memory of each are destroyed, preventing the keys from being reused or leaked, and also releasing the memory space for the next connection.
[0141] The most preferred data transmission process of the embodiment of the present application is explained in a specific implementation scenario. Taking an industrial Internet of Things scenario as an example, the first gateway is an industrial Internet of Things platform, and the second gateway is an industrial intelligent gateway. Referring to Figure 2 and Figure 3 , Figure 2 is a structural schematic diagram of an industrial Internet of Things platform and an industrial gateway in the embodiment of the present application, Figure 3 is a flowchart of a preferred data transmission method in the embodiment of the present application. The industrial Internet of Things platform (i.e., the platform side) can be connected with multiple industrial gateways (i.e., industrial gateways 1-N). The industrial Internet of Things platform includes a security module, a storage module, a cache module, a key management module, an exception management module, and an alarm management module. The industrial gateway includes a security module. Through the interaction and cooperation of the security module of the industrial Internet of Things platform with the storage module, the cache module, the key management module, the exception management module, and the alarm management module, the data transmission method of the embodiment of the present application is completed. The asymmetric encryption algorithm uses the SM2 algorithm, the symmetric encryption algorithm uses the SM4 algorithm, and the message digest algorithm uses the SM3 algorithm.
[0142] Specifically, the module functions on the industrial gateway side are as follows:
[0143] Security module: deployed at the entrance and exit of all data, responsible for encrypting the data exported by the industrial gateway and decrypting the data imported.
[0144] The functions of the modules on the platform side are as follows:
[0145] Security module: also located at the entrance and exit of all data, responsible for encrypting the data exported by the platform side and decrypting the data imported.
[0146] Storage module: responsible for storing the data reported by each industrial gateway, such as motor speed, temperature, humidity, vibration, etc.
[0147] Cache module: responsible for caching the SM2 public-private key pair and SM4 random symmetric key, which is used for data transmission stage encryption and decryption and is an important module for implementing one-machine-one-key.
[0148] Key management module: responsible for the generation, distribution, and destruction of the asymmetric SM2 public-private key pair, as well as the destruction of the SM4 symmetric key. The SM2 public-private key pair is generated and stored in the cache module.
[0149] Exception management module: in the key negotiation stage, if key negotiation fails for three consecutive times, the exception management module is called for processing. The exception management module first automatically restarts the remote industrial gateway to attempt key negotiation again. If successful, it reports data normally. If unsuccessful, it calls the key management module to generate a new SM2 public-private key pair for the industrial gateway and negotiates keys again based on the new SM2 public-private key pair. If successful, it enters the normal data transmission process. If unsuccessful, it triggers the alarm management module and requests human intervention.
[0150] Alarm management module: triggered after exception handling fails. This module supports three types of alarm notification methods: SMS notification, WeChat notification, and email notification. After human intervention, the problem of key negotiation failure can be basically solved by remotely reinstalling the security module.
[0151] The specific data transmission process is as follows:
[0152] 1. Power-on self-test stage
[0153] After the industrial gateway is powered on, it automatically starts the system and detects whether the data acquisition module, data analysis module, and security module can work normally. If the detection is abnormal, the red light flashes to indicate system abnormalities. If the detection is normal, the white light is always on, and the next stage is entered.
[0154] 2. Connection establishment stage
[0155] After the industrial gateway self-checking is passed, the gateway initiates a connection request to the platform side. After three handshakes, a TCP (Transmission Control Protocol) connection is established between the industrial gateway and the platform.
[0156] In the process of establishing a TCP connection, SYN indicates a connection establishment packet, which is used to request the establishment of a connection and indicates the start of a handshake process to negotiate the parameters required for establishing a connection. ACK indicates an acknowledgement receipt packet, indicating that the data sent has been confirmed to be received without error.
[0157] 3. Key negotiation phase
[0158] ① Gateway side public key request: the security module on the industrial gateway side requests the platform side to issue an SM2 public key.
[0159] ② Platform side public key issuance: the security module on the platform side generates a public-private key pair using the SM2 algorithm, generates a message digest of the SM2 public key using SM3, and encrypts the SM3 message digest using the SM2 private key. The SM2 public key is issued to the industrial gateway side together with the encrypted message digest and is stored in the industrial gateway memory, and the SM2 private key is stored in the platform side memory for backup.
[0160] ③ Gateway side verification of public key: the industrial gateway side parses the SM2 public key and the encrypted message digest two fields. The industrial gateway side uses the SM2 public key issued by the platform side to decrypt the message digest, and if the parsing is successful, it indicates that the public key sent by the platform side is trusted. Use SM3 to generate a message digest of the SM2 public key and compare it with the decrypted message digest result. If they match, it proves that the transmission process is trustworthy, and the next step is processed. Whether the public key is untrusted or the transmission process is untrusted, it needs to start from ① again. If there are three consecutive abnormalities, go to Abnormal processing phase, key negotiation fails.
[0161] ④ Gateway side generation of symmetric key: the security module on the industrial gateway side generates a random symmetric key using the SM4 algorithm.
[0162] ⑤ Gateway side key encryption: the security module on the industrial gateway side uses the SM3 message digest algorithm to generate a digest of the random symmetric key and the gateway's own information, and encrypts the random symmetric key, gateway information, and digest using the public key.
[0163] ⑥ Gateway side information sending: the security module on the industrial gateway side sends the encrypted data packet to the platform side.
[0164] ⑦ Platform side key decryption: the security module on the platform side decrypts the encrypted data packet using the private key stored in the platform side memory to obtain the random symmetric key, gateway information, and digest.
[0165] 8. Platform side summary check: The platform side security module uses the SM3 message digest algorithm to calculate the message digest of the decrypted symmetric key and gateway information, and compares whether the summary sent by the industrial gateway side and the summary generated by the platform side are consistent. If they are consistent, it means that the communication information has not been tampered with, otherwise the communication information has been tampered with, the symmetric key has been leaked, and the symmetric key needs to be re-negotiated from step 4 for security.
[0166] 9. Platform side key backup: The platform side uses the gateway ID in the decrypted gateway information as the primary key and the symmetric key as the value to form a key-value pair in memory, which is used to encrypt the data of the gateway in the subsequent data transmission process, forming a one-machine-one-key.
[0167] 11. Platform side decryption result sending: If the platform side private key is normally decrypted and the summary check is normal, the platform side private key is used to encrypt and send normal response information to the industrial gateway, and the key negotiation phase is completed. If the platform side private key is decrypted abnormally or the summary check is abnormal, the platform side private key is used to encrypt and send abnormal response information to the industrial gateway, and the industrial gateway side will start over from step 4 to re-negotiate the symmetric key. If it is abnormal for 3 times in a row, it will enter the abnormal processing phase, and the key negotiation fails.
[0168] Platform side exception alarm processing: After 3 consecutive key negotiation failures, the exception management module is called for processing. The exception management module first automatically restarts the remote industrial gateway to try key negotiation again, and if successful, it reports the data normally, and if failed, it calls the key management module to generate a new SM2 public and private key pair for the industrial gateway and re-negotiate the key based on the new SM2 public and private key pair. If successful, it enters the normal data transmission process, and if failed, it calls the alarm management module to notify the requester through SMS, WeChat, email, etc. After manual intervention, the problem of key negotiation failure can be basically solved by remotely reinstalling the security module.
[0169] 4. Data encryption transmission phase
[0170] Gateway side data encryption and decryption: The industrial gateway side security module encrypts the export data using the random symmetric key generated in the key negotiation phase and stores it in memory; the import data is decrypted using the symmetric key.
[0171] Platform side data encryption and decryption:
[0172] (1) Export data: The platform side security module encrypts the export data to a certain industrial gateway using the random symmetric key generated in the key negotiation phase based on the gateway ID as the primary key.
[0173] (2) Inlet data: after the platform side security module receives the industrial gateway inlet data, the random symmetric key of the industrial gateway generated in the key negotiation stage is obtained with the gateway ID as the primary key, and the outlet data is decrypted using the random symmetric key.
[0174] 5. Connection closing stage
[0175] After four handshakes, the TCP connection between the industrial gateway security module and the platform side security module is closed.
[0176] In the process of closing the TCP connection, the FIN data packet is used to identify the termination request of the TCP connection, indicating that the sender has no data to send and requests to close the connection.
[0177] 6. Symmetric key destruction stage
[0178] After the connection is closed, the symmetric key residing on the platform side and the network side is destroyed by the security module respectively, to prevent the key from being reused or leaked, release the memory space, and prepare for the next connection.
[0179] By using the SM2 and SM3 to construct a secure channel, the embodiment of the application automatically negotiates the SM4 random symmetric key between the industrial gateway and the platform for data security transmission. In the key negotiation stage, the method of using a public key to encrypt and send a random symmetric key improves the security of the random symmetric key in the key negotiation stage. The method of using message digest verification prevents tampering with data. In the data encryption transmission stage, the method of using a random symmetric key to encrypt data improves the encryption efficiency, ensures the randomness and uncertainty of the encryption key, and greatly improves the difficulty of data cracking. Moreover, through abnormal processing, three consecutive abnormalities in the key negotiation process trigger an alarm, and after confirmation, the gateway is restarted remotely, thereby strengthening the security of data transmission. The embodiment of the application does not need to preinstall a symmetric key on the industrial gateway, greatly reduces the cost through the automatic key negotiation technical solution, improves the efficiency, improves the security of data transmission, solves the technical problem of preinstalling a key on the industrial gateway in the prior art, greatly saves the labor cost, and speeds up the product delivery speed.
[0180] Referring to Figure 4 is a flowchart of another data transmission method provided by the embodiment of the application. The embodiment of the application further provides another data transmission method, which is applied to a second gateway and specifically includes steps S21 to S24:
[0181] S21, after establishing a communication connection with a first gateway, receiving a public key issued by the first gateway; wherein the first gateway generates the public key and a private key using an asymmetric encryption algorithm;
[0182] S22, generating a random symmetric key using a symmetric encryption algorithm;
[0183] S23, encrypt the random symmetric key by using the public key and a message digest algorithm to generate an encrypted data packet, and send the encrypted data packet to the first gateway, so that the first gateway decrypts the encrypted data packet by using the private key and the message digest algorithm to obtain the random symmetric key, and performs credibility verification on the random symmetric key;
[0184] S24, when receiving normal response information sent by the first gateway after passing the credibility verification, encrypts and decrypts target data by using the random symmetric key in the process of transmitting the target data with the first gateway.
[0185] As a preferred embodiment, the step of encrypting the random symmetric key by using the public key and a message digest algorithm to generate an encrypted data packet, and sending the encrypted data packet to the first gateway, so that the first gateway decrypts the encrypted data packet by using the private key and the message digest algorithm to obtain the random symmetric key, and performs credibility verification on the random symmetric key, comprises:
[0186] processing the random symmetric key and gateway information of the second gateway by using a message digest algorithm to generate a first message digest;
[0187] encrypting the random symmetric key, the gateway information, and the first message digest by using the public key to generate the encrypted data packet;
[0188] sending the encrypted data packet to the first gateway, so that the first gateway decrypts the encrypted data packet by using the private key to obtain the random symmetric key, the gateway information, and the first message digest, processes the random symmetric key and the gateway information by using the message digest algorithm to obtain a first check message digest, and compares the first message digest and the first check message digest for consistency to perform credibility verification on the random symmetric key.
[0189] Preferably, the method further comprises:
[0190] when receiving abnormal response information sent by the first gateway after failing the credibility verification, generating a random symmetric key by using a symmetric encryption algorithm again to generate the encrypted data packet.
[0191] when the number of times of receiving the abnormal response information reaches a preset number threshold, disconnecting the connection with the first gateway, re-establishing the connection with the first gateway, and receiving the public key issued by the first gateway again.
[0192] As a preferred embodiment, the step of receiving the public key issued by the first gateway comprises:
[0193] receive the public key and an encrypted message digest sent by the first gateway; wherein the encrypted message digest is generated by the first gateway by processing the public key with a message digest algorithm to generate a second message digest and encrypting the second message digest with the private key;
[0194] decrypt the encrypted message digest with the public key to obtain the second message digest;
[0195] encrypt the public key with the message digest algorithm to obtain a second check message digest;
[0196] compare the second message digest with the second check message digest to verify the credibility of the public key.
[0197] As a preferred embodiment, the method further comprises:
[0198] receive encrypted normal response information sent by the first gateway; wherein the encrypted normal response information is generated by the first gateway by encrypting normal response information generated after the credibility verification is passed with the private key;
[0199] decrypt the encrypted normal response information with the private key to obtain the normal response information.
[0200] As a preferred embodiment, the method further comprises:
[0201] receive encrypted abnormal response information sent by the first gateway; wherein the encrypted abnormal response information is generated by the first gateway by encrypting abnormal response information generated after the credibility verification is not passed with the private key;
[0202] decrypt the encrypted abnormal response information with the private key to obtain the abnormal response information.
[0203] As a preferred embodiment, the method further comprises:
[0204] when the transmission of the target data is completed, disconnect the connection with the first gateway; and destroy the public key and the random symmetric key.
[0205] It should be noted that the data transmission method applied to the second gateway provided by the embodiments of the present application corresponds to all the process steps of the data transmission method applied to the first gateway in the above embodiments one by one, and the working principles and beneficial effects of the two are the same, so they will not be described again.
[0206] The embodiment of the present application further provides another data transmission method, which is applied to the data transmission system 10, and the data transmission system 10 is shown in Fig. 1. Figure 5 Fig. 1 is a structural schematic diagram of a data transmission system provided by the embodiment of the present application, the data transmission system 10 comprises a first gateway 11 and a second gateway 12, and the method comprises steps S31 to S35:
[0207] S31, after the communication connection between the first gateway and the second gateway is established, the first gateway generates a public key and a private key by using an asymmetric encryption algorithm, and sends the public key to the second gateway;
[0208] S32, the second gateway generates a random symmetric key by using a symmetric encryption algorithm, encrypts the random symmetric key by using the public key and a message digest algorithm to generate an encrypted data packet, and sends the encrypted data packet to the first gateway;
[0209] S33, the first gateway decrypts the encrypted data packet by using the private key and the message digest algorithm to obtain the random symmetric key, and performs a credibility verification on the random symmetric key;
[0210] S34, when the credibility verification on the random symmetric key is passed, the first gateway sends normal response information to the second gateway;
[0211] S35, in the process of target data transmission between the first gateway and the second gateway, the random symmetric key is used to encrypt and decrypt the target data.
[0212] It should be noted that the data transmission method applied to the data transmission system provided by the embodiment of the present application corresponds to all the process steps of the data transmission method applied to the first gateway and the second gateway in the above embodiment one by one, and the working principles and beneficial effects of the two are the same, thus the description is not repeated.
[0213] The embodiment of the present application further provides a data transmission device, which is applied to a first gateway, and the device comprises:
[0214] an asymmetric key generation module, configured to generate a public key and a private key by using an asymmetric encryption algorithm after a communication connection with a second gateway is established;
[0215] a public key sending module, configured to send the public key to the second gateway;
[0216] an encrypted data packet receiving module, configured to receive an encrypted data packet sent by the second gateway; wherein the encrypted data packet is generated by encrypting a random symmetric key by using the public key and a message digest algorithm after the random symmetric key is generated by the second gateway by using a symmetric encryption algorithm;
[0217] The symmetric key obtaining module is configured to decrypt the encrypted data packet by using the private key and the message digest algorithm to obtain a random symmetric key, and to perform trustworthiness verification on the random symmetric key;
[0218] The response information sending module is configured to send normal response information to the second gateway when the trustworthiness verification on the random symmetric key is passed.
[0219] The first data transmission module is configured to encrypt or decrypt the target data by using the random symmetric key in the process of target data transmission with the second gateway.
[0220] It should be noted that the data transmission device applied to the first gateway provided in the embodiment of the present application is configured to perform all process steps of the data transmission method applied to the first gateway in the above embodiment, and the working principles and beneficial effects of the two are one-to-one correspondence, thus no longer being described in detail.
[0221] The embodiment of the present application further provides another data transmission device applied to a second gateway, and the device comprises:
[0222] The public key receiving module is configured to receive a public key issued by the first gateway after establishing a communication connection with the first gateway, wherein the first gateway generates the public key and a private key by using an asymmetric encryption algorithm.
[0223] The symmetric key generating module is configured to generate a random symmetric key by using a symmetric encryption algorithm.
[0224] The encrypted data packet generating module is configured to encrypt the random symmetric key by using the public key and a message digest algorithm, to generate an encrypted data packet, and to send the encrypted data packet to the first gateway, so that the first gateway decrypts the encrypted data packet by using the private key and the message digest algorithm to obtain a random symmetric key, and performs trustworthiness verification on the random symmetric key.
[0225] The second data transmission module is configured to encrypt or decrypt the target data by using the random symmetric key in the process of target data transmission with the first gateway when receiving normal response information sent by the first gateway after the trustworthiness verification is passed.
[0226] It should be noted that the data transmission device applied to the second gateway provided in the embodiment of the present application is configured to perform all process steps of the data transmission method applied to the second gateway in the above embodiment, and the working principles and beneficial effects of the two are one-to-one correspondence, thus no longer being described in detail.
[0227] Reference is made to Figure 6is a structural schematic diagram of a data transmission device provided by an embodiment of the present application. The embodiment of the present application further provides a data transmission device 20, which comprises a processor 21, a memory 22, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, the data transmission method according to any one of the above embodiments is implemented.
[0228] The embodiment of the present application further provides a computer readable storage medium, which comprises a stored computer program. When the computer program runs, the computer readable storage medium controls a device where the computer readable storage medium is located to perform the data transmission method according to any one of the above embodiments.
[0229] The embodiment of the present application further provides a computer program product, which comprises a computer program or computer instructions. When the computer program or the computer instructions are executed by a processor, the data transmission method according to any one of the above embodiments is implemented.
[0230] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by a computer program instructing related hardware. The program can be stored in a computer readable storage medium. When the program is executed, the program can include the processes of the above-mentioned embodiments. The storage medium can be a magnetic disc, an optical disc, a read-only memory (ROM), a random access memory (RAM), or the like.
[0231] The above is the preferred embodiment of the present application. It should be noted that those skilled in the art can make several improvements and refinements without departing from the principle of the present application. These improvements and refinements are also considered to be within the protection scope of the present application.
Claims
1. A data transmission method, characterized by, The method applied to a first gateway comprises: After establishing a communication connection with a second gateway, generating a public key and a private key by using an asymmetric encryption algorithm; sending the public key to the second gateway; receiving an encrypted data packet sent by the second gateway; wherein the encrypted data packet is generated by the second gateway by using the public key and a message digest algorithm to encrypt a random symmetric key generated by using a symmetric encryption algorithm; decrypting the encrypted data packet by using the private key and the message digest algorithm to obtain the random symmetric key, and verifying the credibility of the random symmetric key; when the credibility verification of the random symmetric key is passed, sending normal response information to the second gateway; in the process of target data transmission with the second gateway, using the random symmetric key to encrypt and decrypt the target data; the encrypted data packet is generated by the second gateway by using the message digest algorithm to process the random symmetric key and gateway information of the second gateway to generate a first message digest, and then using the public key to package and encrypt the random symmetric key, the gateway information and the first message digest; then the decrypting the encrypted data packet by using the private key and the message digest algorithm to obtain the random symmetric key, and verifying the credibility of the random symmetric key comprises: decrypting the encrypted data packet by using the private key to obtain the random symmetric key, the gateway information and the first message digest; processing the random symmetric key and the gateway information by using the message digest algorithm to obtain a first check message digest; comparing the consistency of the first message digest and the first check message digest to verify the credibility of the random symmetric key.
2. The data transmission method of claim 1, wherein, The method further comprises: when the credibility verification of the random symmetric key is not passed, sending abnormal response information to the second gateway to make the second gateway regenerate the random symmetric key and the encrypted data packet.
3. The data transmission method of claim 2, wherein, after the when the credibility verification of the random symmetric key is not passed, sending abnormal response information to the second gateway, the method further comprises: when the number of consecutive credibility verification failures of the random symmetric key reaches a preset number threshold, disconnecting the connection with the second gateway and re-establishing the connection with the second gateway, and re-sending the public key to the second gateway.
4. The data transmission method of claim 3, wherein, after re-establishing the connection with the second gateway and re-sending the public key to the second gateway, the method further comprises: when the credibility verification of the random symmetric key is still not passed, generating a new public key and a new private key by using the asymmetric encryption algorithm, and re-sending the new public key to the second gateway.
5. The data transmission method of claim 1, wherein, the sending the public key to the second gateway comprises: processing the public key by using the message digest algorithm to generate a second message digest; encrypting the second message digest by using the private key to obtain an encrypted message digest; sending the public key and the encrypted message digest to the second gateway, so that the second gateway decrypts the encrypted message digest by using the public key, performs trustworthiness verification on the public key, and generates the encrypted data packet when the trustworthiness verification is passed.
6. The data transmission method of claim 5, wherein, After the sending of the public key and the encrypted message digest to the second gateway, the method further comprises: when receiving a response message sent by the second gateway and indicating that the trustworthiness verification on the public key is failed, generating a new public key and a new private key by using an asymmetric encryption algorithm.
7. The data transmission method of claim 2 wherein, The sending of the normal response information to the second gateway when the trustworthiness verification on the random symmetric key is passed comprises: generating the normal response information when the trustworthiness verification on the random symmetric key is passed; encrypting the normal response information by using the private key to obtain encrypted normal response information and sending the encrypted normal response information to the second gateway; The sending of the abnormal response information to the second gateway when the trustworthiness verification on the random symmetric key is failed comprises: generating the abnormal response information when the trustworthiness verification on the random symmetric key is failed; encrypting the abnormal response information by using the private key to obtain encrypted abnormal response information and sending the encrypted abnormal response information to the second gateway.
8. The data transmission method of claim 1, wherein, After the comparison of the consistency of the first message digest and the first check message digest and the trustworthiness verification on the random symmetric key, the method further comprises: when the trustworthiness verification on the random symmetric key is passed, taking the gateway information as a primary key and the random symmetric key as a value to generate a key-value pair for caching; The encryption and decryption of the target data by using the random symmetric key in the process of the target data transmission with the second gateway comprises: in the process of the target data transmission with the second gateway, searching for the random symmetric key corresponding to the gateway information of the second gateway in the key-value pair, and encrypting and decrypting the target data by using the random symmetric key.
9. The data transmission method of claim 1, wherein, The method further comprises: after completing the transmission of the target data, disconnecting the connection with the second gateway; destroying the private key and the random symmetric key.
10. A data transmission method, characterized by, The method applied to the second gateway comprises: after establishing a communication connection with a first gateway, receiving a public key issued by the first gateway; wherein the first gateway generates the public key and a private key by using an asymmetric encryption algorithm; generating a random symmetric key by using a symmetric encryption algorithm; encrypting the random symmetric key by using the public key and a message digest algorithm to generate an encrypted data packet, and sending the encrypted data packet to the first gateway, so that the first gateway decrypts the encrypted data packet by using the private key and the message digest algorithm to obtain the random symmetric key, and performs trustworthiness verification on the random symmetric key; when receiving a normal response information sent by the first gateway after the trustworthiness verification is passed, encrypting and decrypting target data by using the random symmetric key in the process of the target data transmission with the first gateway; The random symmetric key is encrypted by using the public key and a message digest algorithm to generate an encrypted data packet, and the encrypted data packet is sent to the first gateway, so that the first gateway decrypts the encrypted data packet by using the private key and the message digest algorithm to obtain a random symmetric key, and performs trustworthiness verification on the random symmetric key, including: The random symmetric key and gateway information of the second gateway are processed by using a message digest algorithm to generate a first message digest; The random symmetric key, the gateway information, and the first message digest are packaged and encrypted by using the public key to generate the encrypted data packet; The encrypted data packet is sent to the first gateway, so that the first gateway decrypts the encrypted data packet by using the private key to obtain a random symmetric key, gateway information, and a first message digest, processes the random symmetric key and the gateway information by using the message digest algorithm to obtain a first check message digest, and compares the consistency of the first message digest and the first check message digest to verify the trustworthiness of the random symmetric key.
11. The data transmission method of claim 10, wherein, The public key issued by the first gateway is received, including: The public key and an encrypted message digest sent by the first gateway are received; wherein the encrypted message digest is generated by the first gateway by processing a public key by using a message digest algorithm to generate a second message digest, and then encrypting the second message digest by using the private key; The encrypted message digest is decrypted by using the public key to obtain a second message digest; The public key is encrypted by using the message digest algorithm to obtain a second check message digest; The consistency of the second message digest and the second check message digest is compared to verify the trustworthiness of the public key.
12. A data transmission method, characterized by, The data transmission system includes a first gateway and a second gateway, and the method includes: After the first gateway and the second gateway establish a communication connection, the first gateway generates a public key and a private key by using an asymmetric encryption algorithm, and sends the public key to the second gateway; The second gateway generates a random symmetric key by using a symmetric encryption algorithm, encrypts the random symmetric key by using the public key and a message digest algorithm to generate an encrypted data packet, and sends the encrypted data packet to the first gateway; The first gateway decrypts the encrypted data packet by using the private key and the message digest algorithm to obtain a random symmetric key, and performs trustworthiness verification on the random symmetric key; When the trustworthiness of the random symmetric key is verified, the first gateway sends normal response information to the second gateway; In the process of target data transmission between the first gateway and the second gateway, the random symmetric key is used to encrypt and decrypt the target data; The random symmetric key is encrypted by using the public key and a message digest algorithm to generate an encrypted data packet, and the encrypted data packet is sent to the first gateway, including: The random symmetric key and gateway information of the second gateway are processed by using a message digest algorithm to generate a first message digest; encrypt the random symmetric key, the gateway information and the first message digest by using the public key to generate the encrypted data packet; send the encrypted data packet to the first gateway; the step of decrypting the encrypted data packet by using the private key and the message digest algorithm to obtain the random symmetric key and verifying the credibility of the random symmetric key, comprising: decrypting the encrypted data packet by using the private key to obtain the random symmetric key, the gateway information and the first message digest; processing the random symmetric key and the gateway information by using the message digest algorithm to obtain a first check message digest; comparing the consistency of the first message digest and the first check message digest to verify the credibility of the random symmetric key.
13. A data transmission apparatus, characterized by comprising: The device is applied to a first gateway and comprises: an asymmetric key generation module configured to generate a public key and a private key by using an asymmetric encryption algorithm after establishing a communication connection with a second gateway; a public key sending module configured to send the public key to the second gateway; an encrypted data packet receiving module configured to receive an encrypted data packet sent by the second gateway; wherein the encrypted data packet is generated by the second gateway by encrypting a random symmetric key generated by using a symmetric encryption algorithm by using the public key and a message digest algorithm; a symmetric key obtaining module configured to decrypt the encrypted data packet by using the private key and the message digest algorithm to obtain the random symmetric key and verify the credibility of the random symmetric key; a response information sending module configured to send normal response information to the second gateway when the credibility verification of the random symmetric key is passed; a first data transmission module configured to encrypt and decrypt target data by using the random symmetric key in the process of transmitting the target data with the second gateway; the encrypted data packet is generated by the second gateway by processing a first message digest generated by processing the random symmetric key and gateway information of the second gateway by using a message digest algorithm and by encrypting the random symmetric key, the gateway information and the first message digest by using the public key; the symmetric key obtaining module is specifically configured to: decrypt the encrypted data packet by using the private key to obtain the random symmetric key, the gateway information and the first message digest; process the random symmetric key and the gateway information by using the message digest algorithm to obtain a first check message digest; compare the consistency of the first message digest and the first check message digest to verify the credibility of the random symmetric key.
14. A data transmission apparatus, characterized by comprising: The device is applied to a second gateway and comprises: a public key receiving module configured to receive a public key sent by a first gateway after establishing a communication connection with the first gateway; wherein the first gateway generates the public key and a private key by using an asymmetric encryption algorithm; a symmetric key generation module configured to generate a random symmetric key by using a symmetric encryption algorithm; The encryption data packet generation module is configured to encrypt the random symmetric key by using the public key and a message digest algorithm, to generate an encryption data packet, and to send the encryption data packet to the first gateway, so that the first gateway decrypts the encryption data packet by using the private key and the message digest algorithm to obtain the random symmetric key, and performs trustworthiness verification on the random symmetric key. The second data transmission module is configured to, when receiving normal response information sent by the first gateway after the trustworthiness verification is passed, perform encryption and decryption on the target data by using the random symmetric key in a process of performing target data transmission with the first gateway. The encryption data packet generation module is specifically configured to: perform processing on the random symmetric key and gateway information of the second gateway by using a message digest algorithm to generate a first message digest; perform packet encryption on the random symmetric key, the gateway information, and the first message digest by using the public key to generate the encryption data packet; send the encryption data packet to the first gateway, so that the first gateway decrypts the encryption data packet by using the private key to obtain the random symmetric key, the gateway information, and the first message digest, performs processing on the random symmetric key and the gateway information by using the message digest algorithm to obtain a first check message digest, and compares the first message digest and the first check message digest for consistency, and performs trustworthiness verification on the random symmetric key.
15. A data transmission device, characterized by The computer readable storage medium comprises a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, and the processor implements the data transmission method according to any one of claims 1 to 12 when executing the computer program.
16. A computer-readable storage medium, characterized in that, The computer readable storage medium comprises a stored computer program, wherein the computer program controls a device where the computer readable storage medium is located to perform the data transmission method according to any one of claims 1 to 12 when the computer program is running.
17. A computer program product, characterised in that, The computer program product comprises a computer program or computer instructions, and the computer program or the computer instructions implement the data transmission method according to any one of claims 1 to 12 when executed by a processor.
Citation Information
Patent Citations
Network data secure transmission method
CN106506470A
Data encryption method and system applied to data transmission
CN107682141A