Data security protection method and device and storage medium

By introducing one-time passwords and ECC algorithm-encrypted channels into the SSH protocol, the problem of man-in-the-middle attacks on initial login is solved, enabling reliable and secure authentication and efficient data transmission in LAN and private environments, thus enhancing the system's protection capabilities and communication efficiency.

CN120880651APending Publication Date: 2025-10-31HONGQIN (BEIJING) TECHNOLOGY CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202511049929.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-29
Publication Date
2025-10-31

AI Technical Summary

Technical Problem

The existing SSH protocol is vulnerable to man-in-the-middle attacks during initial login, especially in local area networks or private remote host environments. It cannot effectively authenticate personally issued certificates, making keys easy to be intercepted and misused, thus affecting data security.

Method used

An encrypted channel employing one-time passwords and SHA-1 and ECC algorithms is established by pre-storing a six-digit short password on a remote host, using the SHA-1 value for encryption, and establishing an encrypted channel at the OSI model transport layer. Multiple one-time passwords are deployed to prevent password brute-force attacks, and a port forwarding mechanism is combined to achieve stable communication through the encrypted channel.

Benefits of technology

It effectively prevents man-in-the-middle attacks, reduces certificate authentication costs, improves system login security and communication efficiency, reduces latency and packet loss, and enhances overall communication performance. It is suitable for remote login and data transmission in LAN and private environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120880651A_ABST
    Figure CN120880651A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data security and encryption, in particular to a data security protection method and device and a storage medium, and can solve the problem that security risks during key exchange in ssh communication cannot be protected in the prior art to a certain extent. Therefore, the key is protected from being intercepted and illegally used by a man-in-the-middle attack means when the key is exchanged for the first time, and the safety of data is ensured. The data security protection method comprises the following steps: establishing an encryption channel using a one-time password; the six-bit short password is stored in a remote host in advance in the form of a configuration file to generate a secret key; a one-time six-bit short password is configured, and an encryption channel and a secret key are encrypted; transmitting the secret key to the client through an encryption channel; deploying a plurality of one-time passwords to complete the deployment of the secret key; setting SSH remote login protection based on the password; and setting SSH remote login protection based on the secret key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the fields of data security and encryption technology, and more specifically, to a data security protection method, device and storage medium. Background Technology

[0002] With the rapid development of information technology, remote login and data transmission have been widely used in various fields, such as remote office work, cloud server management, and IoT device control. SSH (SecureShell), as a widely used security protocol, provides encrypted communication protection for remote login and data transmission. It has been adopted by a large number of enterprises and individual users worldwide. According to relevant statistics, more than 80% of IT companies rely on the SSH protocol for daily remote operation and maintenance and data interaction.

[0003] Since SSHv1.0, symmetric and asymmetric encryption algorithms, including DES and RSA256, have been used.

[0004] The entire process is as follows: (1) When the remote host receives the user's first login request, it uses the RSA256 algorithm to generate a public key and a private key, and sends the public key to the client.

[0005] (2) The user uses this public key to encrypt the login password and send it to the remote host.

[0006] (3) The remote host uses its own private key to decrypt the login password and verify it. If the password is correct, it agrees to log in and uses DES encryption to protect the subsequent communication process.

[0007] (4) The public key fingerprint of the remote host is identified during the second login to prevent identity forgery and man-in-the-middle attacks.

[0008] The process itself is secure, but if someone intercepts the login request during the initial login, impersonates the remote host, sends a forged public key to the user, and uses the forged public key to obtain the user's login password, SSH security will be compromised. Although SSHv2.0 uses officially issued key certificates, their feasibility is weak in local area networks or private remote host environments. Personally issued certificates cannot be reliably authenticated, making the entire process vulnerable to "man-in-the-middle attacks" during the initial login.

[0009] Therefore, there is an urgent need for a method that can protect against security risks during key exchange in SSH communication, thereby preventing keys from being intercepted and misused by man-in-the-middle attacks during the initial key exchange and ensuring data security. Summary of the Invention

[0010] To address the problem that existing technologies cannot protect against security risks during key exchange in SSH communication, thereby preventing keys from being intercepted and misused by man-in-the-middle attacks during the initial key exchange and ensuring data security, this application provides a data security protection method, device, and storage medium.

[0011] The embodiments of this application are implemented as follows: Firstly, this application provides a data security protection method, including: Establish an encrypted channel using a one-time password; Use a configuration file to pre-store the six-digit short password to be used on a remote host to generate a key; Configure a one-time six-digit short password and encrypt the encryption channel and key; The key is then transmitted to the client via an encrypted channel; Deploy multiple one-time passwords to complete the deployment of the secret key; Configure password-based SSH remote login protection; Configure key-based SSH remote login protection.

[0012] In one possible implementation, the encryption channel for the one-time password is established at the transport layer in the OSI model, and the SHA-1 value of the one-time password is used to encrypt the content of the TCP data packets.

[0013] In one possible implementation, the six-digit short password is a combination of letters and numbers.

[0014] In one possible implementation, encrypting the encryption channel and the key further includes: Manipulate the raw socket encrypted data packet content to hide the data packet content of SSH requests and transmissions; Use the SHA-1 value of the one-time password in the configuration file as the key; Real-time encryption and decryption are performed using the ECC encryption algorithm.

[0015] In one possible implementation, the client uses a hash algorithm to obtain the public key fingerprint of the host's public key from the public key sent by the host, and verifies the public key fingerprint. After the user verifies the public key and enters "yes", the client will save the public key of the remote host.

[0016] In one possible implementation, the deployment of multiple one-time passwords to complete the deployment of the key further includes: By deploying multiple one-time passwords, the encrypted channel uses the one-time passwords in the order specified in the configuration file, preventing attackers from completing password brute-force attacks by blocking and delaying the connection.

[0017] One possible implementation also includes establishing a port forwarding mechanism between the client and the remote host to achieve stable communication over the encrypted channel.

[0018] Secondly, this application provides a data security protection device, including a client and a remote host, wherein the client and the remote host transmit data through an encrypted channel; The client includes a first local port, a second local port, and a third local port; The remote host includes a first remote port, a second remote port, and a third remote port.

[0019] In one possible implementation, the client includes: The first processor is used to establish local port forwarding, forward traffic from the third local port to the second local port through the first local port, and open a TCP connection between the second local port and the first remote port of the remote host. The first encryption module is used to read the one-time password in the configuration file and encrypt the contents of the TCP data packets; The first communication module is used to send encrypted data to the first remote port of the remote host through the second local port; The remote host includes: The second processor is used to open the second remote port to forward the decrypted data to the third remote port, and to process the SSH protocol through the third remote port. The second communication module is used to listen on the first remote port and wait for a connection to the second local machine port, and to receive encrypted data. The second encryption module is used to decrypt the received encrypted data.

[0020] Thirdly, this application provides a storage medium storing a computer program thereon, wherein the computer program, when executed by a processor, implements the data security protection method according to any one of claims 1-7. The technical solution provided in this application can achieve at least the following beneficial effects: This invention constructs an encrypted channel based on one-time passwords and SHA-1 and ECC algorithms to provide comprehensive encryption protection for the key exchange process. This makes it difficult for attackers to intercept or forge keys during the initial login phase, thereby blocking the path of man-in-the-middle attacks from the root and effectively ensuring the confidentiality and integrity of data during transmission. It also solves the problem of high risk of man-in-the-middle attacks during the initial login phase in existing technologies.

[0021] This invention does not rely on officially issued key certificates. Instead, it employs a pre-configured one-time password and a locally stored public key fingerprint verification mechanism to achieve effective authentication of remote hosts. This is particularly suitable for local area network environments and private remote host scenarios, reducing the cost and complexity of certificate authentication. It ensures reliable security for remote login and data transmission in these environments, overcoming the certificate authentication challenges of existing SSHv2.0 in private environments.

[0022] This invention significantly increases the difficulty and cost for attackers to launch password brute-force attacks by utilizing a dynamic, one-time six-digit short password usage mechanism and the orderly deployment of multiple passwords. Each connection uses only one one-time password, and these passwords are used sequentially according to a preset order. Attackers cannot attempt to guess the same password multiple times. Furthermore, the system's connection timeout policy further limits the attacker's attempt time, effectively resisting password brute-force attacks, protecting system login security, and solving the problem of high risk of password brute-force attacks under traditional SSH login methods.

[0023] The ECC algorithm used in this invention has significant advantages over the traditional RSA algorithm in terms of computational efficiency and resource consumption. Furthermore, through optimized design of the encrypted channel, such as multi-port forwarding mechanisms and efficient management of one-time passwords, latency and packet loss during data transmission are reduced, improving system throughput and response speed. In addition, for high-concurrency, high-data-volume transmission scenarios, this invention effectively alleviates the performance bottleneck of the existing SSH protocol through reasonable resource scheduling and algorithm optimization, improving overall communication efficiency and meeting the growing business needs of enterprises. Attached Figure Description

[0024] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0025] Figure 1 This is a flowchart illustrating a data security protection method according to an exemplary embodiment of this application; Figure 2 This is a schematic diagram illustrating the structure of the encryption channel establishment process of a data security protection device according to an exemplary embodiment of this application; Figure 3 This is a schematic diagram illustrating the structure of a password-based SSH remote login protection device for a data security protection device according to an exemplary embodiment of this application; Figure 4This is a schematic diagram illustrating the structure of a key-based SSH remote login protection device for a data security protection device, as shown in an exemplary embodiment of this application. Detailed Implementation

[0026] To make the objectives, implementation methods and advantages of this application clearer, the exemplary implementation methods of this application will be clearly and completely described below with reference to the accompanying drawings of the exemplary embodiments of this application. Obviously, the exemplary embodiments described are only some embodiments of this application, and not all embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0027] It should be noted that the brief descriptions of terms in this application are only for the convenience of understanding the embodiments described below, and are not intended to limit the embodiments of this application. Unless otherwise stated, these terms should be understood in their ordinary and common meaning.

[0028] The terms "first," "second," "third," etc., used in the specification, claims, and accompanying drawings of this application are used to distinguish similar or related objects or entities, and do not necessarily imply a specific order or sequence, unless otherwise specified. It should be understood that such terms are interchangeable where appropriate.

[0029] The terms “comprising” and “having”, and any variations thereof, are intended to cover but not exclude inclusion, for example, a product or device that includes a range of components is not necessarily limited to all of the components that are clearly listed, but may include other components that are not clearly listed or that are inherent to such product or device.

[0030] Before explaining the data security protection method provided in the embodiments of this application, the application scenarios and implementation environment of the embodiments of this application will be introduced first.

[0031] With the rapid development of information technology, remote login and data transmission have been widely used in various fields, such as remote office work, cloud server management, and IoT device control. SSH (SecureShell), as a widely used security protocol, provides encrypted communication protection for remote login and data transmission. It has been adopted by a large number of enterprises and individual users worldwide. According to relevant statistics, more than 80% of IT companies rely on the SSH protocol for daily remote operation and maintenance and data interaction.

[0032] Since SSHv1.0, symmetric and asymmetric encryption algorithms, including DES and RSA256, have been used.

[0033] The entire process is as follows: (1) When the remote host receives the user's first login request, it uses the RSA256 algorithm to generate a public key and a private key, and sends the public key to the client.

[0034] (2) The user uses this public key to encrypt the login password and send it to the remote host.

[0035] (3) The remote host uses its own private key to decrypt the login password and verify it. If the password is correct, it agrees to log in and uses DES encryption to protect the subsequent communication process.

[0036] (4) The public key fingerprint of the remote host is identified during the second login to prevent identity forgery and man-in-the-middle attacks.

[0037] The process itself is secure, but if someone intercepts the login request during the initial login, impersonates the remote host, sends a forged public key to the user, and uses the forged public key to obtain the user's login password, SSH security will be compromised. Although SSHv2.0 uses officially issued key certificates, their feasibility is weak in local area networks or private remote host environments. Personally issued certificates cannot be reliably authenticated, making the entire process vulnerable to "man-in-the-middle attacks" during the initial login.

[0038] Therefore, there is an urgent need for a method that can protect against security risks during key exchange in SSH communication, thereby preventing keys from being intercepted and misused by man-in-the-middle attacks during the initial key exchange and ensuring data security.

[0039] Based on this, this application provides a data security protection method, device, and storage medium, which establishes an encrypted channel using one-time passwords; pre-stores a six-digit short password generation key in the form of a configuration file on a remote host; configures a one-time six-digit short password, uses its SHA-1 value as the encryption key, and encrypts the encrypted channel and key using the ECC algorithm; transmits the key to the client via the encrypted channel; deploys multiple one-time passwords; and sets up SSH remote login protection based on the password and key. This invention protects key exchange through an encrypted channel, preventing the risk of man-in-the-middle attacks. Furthermore, the encrypted channel is established based on the port forwarding function on Linux, making it simple and reliable to set up. The one-time key enhances the security of the encrypted channel and defends against attacks such as password brute-force attacks.

[0040] Next, the technical solutions of this application and how they solve the aforementioned technical problems will be described in detail through embodiments and in conjunction with the accompanying drawings. The embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. Obviously, the described embodiments are only some, not all, of the embodiments of this application.

[0041] Figure 1 This is a flowchart illustrating a data security protection method according to an exemplary embodiment of this application; In one exemplary embodiment, such as Figure 1 As shown, a data security protection method is provided. In this embodiment, the method may include the following steps: Step 100: Establish an encrypted channel using a one-time password.

[0042] Step 200: Generate a key by pre-storing the six-digit short password to be used on the remote host using a configuration file.

[0043] Step 300: Configure a one-time six-digit short password and encrypt the encryption channel and key.

[0044] Step 400: Then transmit the key to the client via an encrypted channel.

[0045] Step 500: Deploy multiple one-time passwords to complete the deployment of the key.

[0046] Step 600: Set up password-based SSH remote login protection.

[0047] Step 700: Set up key-based SSH remote login protection.

[0048] In one possible implementation, the specific implementation process of this security protection method is as follows: S1. Establish an encrypted channel using a one-time password.

[0049] The one-time password encryption channel is established at the transport layer in the OSI model and uses the SHA-1 value of the one-time password to encrypt the content of the TCP data packet. By complicating the encryption key, the average success time of brute-force attacks is made to exceed the connection time limit, which can cause the attacker to fail to brute-force the password due to connection timeout during the brute-force attack.

[0050] S2. Generate a key by pre-storing the six-digit short password on the remote host using a configuration file.

[0051] The six-digit short password consists of letters and numbers. By configuring a one-time six-digit short password consisting of letters and numbers, and using the SHA-1 value of the short password to encrypt the encrypted channel using the ECC algorithm, the average successful brute-force attack time exceeds the connection time limit by complicating the encryption key.

[0052] S3. Configure a one-time six-digit short password consisting of letters and numbers, and encrypt the encrypted channel using the ECC algorithm (key encryption) with the SHA-1 value of the short password.

[0053] The encryption method involves hiding the content of SSH requests and transmitted data packets by encrypting the original socket data packet content. It uses the SHA-1 value of a one-time password stored in a local configuration file as the key and performs real-time encryption and decryption using the ECC encryption algorithm.

[0054] S4. Then transmit the key to the client via an encrypted channel (key transmission).

[0055] The client takes the public key sent by the host and uses a hash algorithm to obtain the public key fingerprint of the host's public key. The client then verifies the public key fingerprint (this is not done if it is the first login). After the user verifies the public key and enters "yes", the client will save the public key of the remote host.

[0056] S5. Deploy multiple one-time passwords (key deployment).

[0057] Users can deploy multiple one-time passwords, and the encrypted channel will use the one-time passwords in the order specified in the configuration file, preventing attackers from completing password brute-force attacks by blocking or delaying the connection.

[0058] S6. Configure password-based SSH remote login protection S7. Configure key-based SSH remote login protection master.

[0059] In some embodiments, a configuration file is used to pre-store the six-digit short password on a remote host. The system calls the configuration file containing the stored password to establish an encrypted channel and encrypt the key. The key is then transmitted to the client via the encrypted channel. Even if the key is intercepted during transmission, attackers cannot forge the encrypted key to achieve a man-in-the-middle attack. Since the password is not transmitted in the channel during the process, the password security is guaranteed. By configuring a one-time six-digit short password consisting of letters and numbers, and using the SHA-1 value of the short password to encrypt the encrypted channel using the ECC algorithm, the encryption key is made more complex, so that the average success time of brute-force attacks exceeds the connection time limit. This can cause attackers to fail in a brute-force attack due to connection timeout. Furthermore, only one six-digit password is used per connection. Users can deploy multiple one-time passwords, and the encrypted channel will use the one-time passwords in the order specified in the configuration file, preventing attackers from completing brute-force attacks by blocking or delaying the connection.

[0060] It should be understood that although the steps in the flowcharts of the above embodiments are shown sequentially as indicated, these steps are not necessarily executed in the indicated order. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the above embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages in other steps.

[0061] Corresponding to the aforementioned embodiments of data security protection methods, and employing the same technical concept, this application also provides embodiments of data security protection devices.

[0062] In one exemplary embodiment, the data security protection device includes a client and a remote host, and the client and the remote host transmit data through an encrypted channel.

[0063] The client includes a first local port, a second local port, and a third local port; The remote host includes a first remote port, a second remote port, and a third remote port.

[0064] In one possible implementation, the client further includes: The first processor is used to establish local port forwarding, forward traffic from the third local port to the second local port through the first local port, and open a TCP connection between the second local port and the first remote port of the remote host. The first encryption module is used to read the one-time password in the configuration file and encrypt the contents of the TCP data packets; The first communication module is used to send encrypted data to the first remote port of the remote host through the second local port; The remote host also includes: The second processor is used to open the second remote port to forward the decrypted data to the third remote port, and to process the SSH protocol through the third remote port. The second communication module is used to listen on the first remote port and wait for a connection to the second local machine port, and to receive encrypted data. The second encryption module is used to decrypt the received encrypted data.

[0065] Figure 2 This is a schematic diagram illustrating the structure of the encryption channel establishment process of a data security protection device according to an exemplary embodiment of this application. Figure 3This is a schematic diagram illustrating the structure of a password-based SSH remote login protection device for a data security protection device, as shown in an exemplary embodiment of this application. Figure 4 This is a schematic diagram illustrating the structure of a key-based SSH remote login protection device for a data security protection device, as shown in an exemplary embodiment of this application.

[0066] Working principle and usage process of this invention: 1. The process of establishing an encrypted channel: such as Figure 2 As shown, man-in-the-middle attacks are defended by establishing an encrypted channel using a one-time password. The encrypted channel is established at the transport layer in the OSI model and uses the SHA-1 value of the one-time password to encrypt the contents of TCP packets.

[0067] The encrypted channel process is established when the client enters an SSH login command such as: sshroot@192.168.0.5. It opens two ports on the local machine and enables port forwarding in the system. The behavior is as follows: (1) The first local port (e.g., 127.0.0.1:1022) and the third local port perform local plaintext forwarding; (2) The second local port and the first remote port of the remote host establish a connection through a TCP three-way handshake. The remote host starts listening on the first remote port to wait for the second local port to connect, and starts the second remote port to communicate with the third local port locally.

[0068] By manipulating the raw socket to encrypt the data packet content, the content of SSH requests and transmitted data packets is hidden. The SHA-1 value of the one-time password stored in the local configuration file is used as the key for real-time encryption and decryption using the ECC encryption algorithm.

[0069] 2. Key generation, encryption, transmission, and deployment: 2.1 Password-based SSH remote login protection: such as Figure 3As shown, when the local host inputs a remote login command such as `sshroot@192.168.0.5`, the request is encrypted and forwarded by the local encrypted channel process. The remote host's listening process receives the request and forwards it to the third remote port. Upon receiving the request, the remote host sends its public key to the client according to the SSH protocol standard. The client uses a hash algorithm to obtain the public key fingerprint of the host's public key and verifies it (this is not done for the first login). After the user verifies the public key and enters "yes", the client saves the remote host's public key. The local host then encrypts the password using the remote host's public key and sends it to the server via the encrypted channel. The remote host receives the password encrypted with the public key, decrypts and verifies it using the corresponding private key in ` / etc / ssh`, and returns the login result. Upon receiving the public key, the encrypted channel terminates its task, discards a one-time password, removes it from the configuration file, and directly forwards the communication content to the third remote port without encryption (while still using SSH's own encryption).

[0070] 2.2 Key-based SSH remote login protection: such as Figure 4 As shown, using the `ssh-keygen-trsa` command on the local host to generate an RSA key pair will create a `.ssh` folder in the user's root directory and generate the following files: authorized_keys: Stores the public key for remote passwordless login. This file records the hosts that can be logged into without a password.

[0071] id_rsa: The generated private key file; id_rsa.pub: The generated public key file; know_hosts: A list of known host public keys; Passwordless SSH login can be achieved using a batch script in conjunction with an encrypted channel: Execute `scp -p ~ / .ssh / id_rsa.pubroot@` on the local host.<remote_ip> When setting ` / root / .ssh / authorized_keys`, an encrypted channel is established. Since the `scp` command is a data transfer command based on SSH, both the local host and the remote host can perform the actions described in section 2.1 to complete the configuration of the encrypted channel. After this command is completed (transfer), the encrypted channel ends its work and directly forwards the plaintext traffic of SSH (which is encrypted by SSH itself).

[0072] In subsequent SSH logins, simply type sshroot@ <remoteip>Passwordless login can then be completed. The workflow is as follows: (1) The local host sends a request with its own username and hostname; (2) The remote host looks up the corresponding public key based on the username and hostname of the local host, encrypts a random string with the public key, and sends it to the local host; (3) The local host uses its own private key to decrypt the encrypted string and sends the decrypted string to the remote host; (4) The remote host compares whether the sent and received strings are the same and returns the login result.

[0073] The implementation process of the encrypted channel is as follows: (1) Before deploying encrypted channels to achieve protection, local port forwarding should be established, a batch file should be created to open the port, and port forwarding should be enabled. iptables-tnat-APREROUTING-ptcp--dport22-jREDIRECT--to-ports1 serviceiptablessave serviceiptablesrestart It will return the message: iptables:Savingfirewallrulesto / etc / sysconfig / iptables:[OK] The above commands can be written in a batch file for execution.

[0074] (2) Read the one-time key from the configuration file when establishing an encrypted channel; withopen('config.json','rb')asf: config=json.load(f) SERVER=config['server'] REMOTE_PORT=config['server_port'] PORT=config['local_port'] KEY=config['password'] The configuration file consists of four sections, where password is a list of strings that can be set to multiple one-time keys.

[0075] (3) The local process encrypts the output traffic and configures the port. The local process will open the specified port to listen for forwarded traffic from the third local port and call the encryption function to encrypt the content in the TCP packet.

[0076] defhandle_tcp(self,sock,remote): try: fdset=[sock,remote] whileTrue: r,w,e=select.select(fdset,[],[]) ifsockinr: data = sock.recv(4096) iflen(data)<=0: break result=send_all(remote,self.decrypt(data)) ifresult <len(data): raiseException('failedtosendalldata') ifremoteinr: data = remote.recv(4096) iflen(data)<=0: break result=send_all(sock,self.encrypt(data)) ifresult <len(data): raiseException('failedtosendalldata') finally: sock.close() remote.close() (4) Open a specified port to listen to the remote host and call the decryption function to decrypt the received traffic. The specific implementation is similar to that of the login end. Then, the specified port is forwarded locally to the third remote port of the remote host to realize unimpeded decryption, reception and processing of SSH protocol communication, reduce the risk of man-in-the-middle attack when sending keys and realize certificate-free secure communication.

[0077] For specific limitations regarding data security protection devices, please refer to the limitations on data security protection methods mentioned above, which will not be repeated here. Each module in the aforementioned data security protection device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in the processor of the computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to each module.

[0078] A third aspect of this application provides a computer-readable storage medium storing a computer program that is invoked and executed by a processor to implement some or all of the steps in the above-described method embodiments.

[0079] As an example, the computer-readable storage medium can be a magnetic disk, optical disk, read-only memory, or random access memory, etc.

[0080] It should be understood that the technical solutions in the embodiments of this application can be implemented using software plus necessary general-purpose hardware platforms. Therefore, the technical solutions in the embodiments of this application, in essence or in part that contributes to the prior art, can be embodied in the form of a software product, which can be stored in a computer-readable storage medium.

[0081] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0082] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the invention patent. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this patent application should be determined by the appended claims.< / remoteip>

Claims

1. A data security protection method, characterized in that, include: Establish an encrypted channel using a one-time password; The key is generated by pre-storing the six-digit short password on the remote host using a configuration file. Configure a one-time six-digit short password and encrypt the encryption channel and key; The key is then transmitted to the client via an encrypted channel; Deploy multiple one-time passwords to complete the deployment of the secret key; Configure password-based SSH remote login protection; Configure key-based SSH remote login protection.

2. The data security protection method as described in claim 1, characterized in that, The encryption channel for the one-time password is established at the transport layer in the OSI model, and the SHA-1 value of the one-time password is used to encrypt the content of the TCP data packets.

3. The data security protection method as described in claim 1, characterized in that, The six-character short password consists of a combination of letters and numbers.

4. The data security protection method as described in claim 1, characterized in that, The encryption of the encryption channel and key further includes: Manipulate the raw socket encrypted data packet content to hide the data packet content of SSH requests and transmissions; Use the SHA-1 value of the one-time password in the configuration file as the key; Real-time encryption and decryption are performed using the ECC encryption algorithm.

5. The data security protection method as described in claim 1, characterized in that, The client machine uses a hash algorithm to obtain the public key fingerprint of the host's public key from the public key sent by the host, and verifies the public key fingerprint. After the user verifies the public key and enters "yes", the client machine will save the public key of the remote host.

6. The data security protection method as described in claim 1, characterized in that, The deployment of multiple one-time passwords to complete the deployment of the key further includes: By deploying multiple one-time passwords, the encrypted channel uses the one-time passwords in the order specified in the configuration file, preventing attackers from completing password brute-force attacks by blocking and delaying the connection.

7. The data security protection method as described in claim 1, characterized in that, It also includes establishing a port forwarding mechanism between the client and the remote host to achieve stable communication over the encrypted channel.

8. A data security protection device, characterized in that, It includes a client and a remote host, and the client and the remote host transmit data through an encrypted channel; The client includes a first local port, a second local port, and a third local port; The remote host includes a first remote port, a second remote port, and a third remote port.

9. The data security protection device as described in claim 8, characterized in that, The client includes: The first processor is used to establish local port forwarding, forward traffic from the third local port to the second local port through the first local port, and open a TCP connection between the second local port and the first remote port of the remote host. The first encryption module is used to read the one-time password in the configuration file and encrypt the contents of the TCP data packets; The first communication module is used to send encrypted data to the first remote port of the remote host through the second local port; The remote host includes: The second processor is used to open the second remote port to forward the decrypted data to the third remote port, and to process the SSH protocol through the third remote port. The second communication module is used to listen on the first remote port for connection to the second local port and to receive encrypted data. The second encryption module is used to decrypt the received encrypted data.

10. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by the processor, it implements the data security protection method according to any one of claims 1-7.

Citation Information

Patent Citations

  • Ssh-based data security protection method and device

    CN109981257A

  • Password authentication method for leakage detection

    CN115913561A

  • Data security protection method and device and electronic equipment

    CN118764271A

  • AES-GCM based enhanced security setup for media encryption

    US20150244528A1

  • Techniques for distributing secure communication secrets

    US8645681B1