Data Transmission Method, Processor, Electronic Device, and Computer Readable Storage Medium
By encrypting in the application processor AP of the terminal and adding target identification to the data, the problem of security mechanism being bypassed during data transmission is solved, and the security of data transmission behavior is achieved.
Patent Information
- Application Number
- CN202111574335.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-21
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2041-12-21
AI Technical Summary
In the prior art, when electronic products such as terminals transmit data outward, some data bypasses the system's security mechanism, resulting in the risk of sensitive data leakage.
After determining the data content to be sent in the application processor AP and encrypting it, a target identification is added to the encrypted data content, the target data is generated and sent to the communication processor CP. After receiving the target data, the communication processor CP verifies whether the target identifier is included through a preset verification algorithm. If it is included, it will be sent, otherwise it will not be sent.
Ensure that only data containing target identifiers can be sent out, effectively prevent data leakage, enhance system security, and ensure that the security mechanism cannot be bypassed.
Smart Images

Figure CN114254351B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical fields of data security and data transmission. Specifically, this application relates to a data transmission method, a processor, an electronic device, and a computer-readable storage medium. Background Art
[0002] In the prior art, when electronic products such as terminals transmit data externally, some data bypasses the security mechanisms of the system, such as TEE (Trusted Execution Environment), etc., resulting in a series of problems such as unencrypted sensitive data transmitted externally, which is likely to cause serious consequences such as leakage of user privacy or sensitive data. Summary of the Invention
[0003] Embodiments of this application provide a data transmission method, a processor, an electronic device, and a computer-readable storage medium. The technical solutions are as follows:
[0004] According to one aspect of the embodiments of this application, a data transmission method is provided, which is applied to an application processor AP. The method includes:
[0005] Determine the data content to be sent, and encrypt the data content to be sent through a preset encryption algorithm to obtain encrypted data content;
[0006] Determine the target identifier of the encrypted data content according to the encrypted data content and a preset method;
[0007] Generate target data according to the encrypted data content and the target identifier, and send the target data to a communication processor CP.
[0008] In a possible implementation manner, the generating target data according to the encrypted data content and the target identifier includes:
[0009] Determine the first hash value of the encrypted data content according to a preset hash algorithm;
[0010] Sign the first hash value with a preset private key to obtain the target signature of the encrypted data content;
[0011] Generate target data according to the encrypted data content, the target identifier, and the target signature.
[0012] According to another aspect of the embodiments of this application, a data transmission method is provided, which is applied to a communication processor CP. The method includes:
[0013] Receive the target data sent by the application processor AP;
[0014] If it is determined that the target data contains the target identifier through a preset verification algorithm, then send the target data;
[0015] If it is determined through a preset verification algorithm that the target data does not contain the target identifier, then do not send the target data.
[0016] In a possible implementation, the target data further includes a target signature and encrypted data content;
[0017] Before determining that the target data contains the target identifier, it further includes:
[0018] If it is determined that the target signature meets the preset conditions, then verify whether the target data contains the target identifier;
[0019] Wherein, the target signature is obtained by the AP signing the encrypted data content in the target data according to a preset private key;
[0020] Determining that the target signature meets the preset conditions includes:
[0021] Calculate a second hash value of the encrypted data content through a preset hash algorithm;
[0022] Decrypt the target signature according to a preset public key to obtain the first hash value;
[0023] If the first hash value is the same as the second hash value, then determine that the target signature meets the preset conditions.
[0024] In another possible implementation, after receiving the target data sent by the application processor AP, it further includes:
[0025] If it is determined that the number of target data received within a preset time and not containing the target identifier exceeds a preset number, then send an alarm message to the AP.
[0026] According to another aspect of the embodiments of the present application, there is provided an application processor, and the application processor includes:
[0027] An encryption module, configured to determine the content of the data to be sent, and encrypt the content of the data to be sent through a preset encryption algorithm to obtain encrypted data content;
[0028] An identification module, configured to determine the target identifier of the encrypted data content according to the encrypted data content and a preset method;
[0029] A first sending module, configured to generate target data according to the encrypted data content and the target identifier, and send the target data to the communication processor CP.
[0030] According to another aspect of the embodiments of the present application, there is provided a communication processor, which includes:
[0031] A receiving module, configured to receive target data sent by an application processor AP.
[0032] A second sending module, configured to send the target data if it is determined by a preset verification algorithm that the target data contains a target identifier;
[0033] A rejecting sending module, configured not to send the target data if it is determined by a preset verification algorithm that the target data does not contain the target identifier.
[0034] According to another aspect of the embodiments of the present application, there is provided an electronic device, which includes:
[0035] It includes a memory, a processor, and a computer program stored on the memory, and the processor executes the computer program to implement the steps of the data transmission method.
[0036] According to still another aspect of the embodiments of the present application, there is provided a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the data transmission method are implemented.
[0037] According to one aspect of the embodiments of the present application, there is provided a computer program product, including a computer program, and when the computer program is executed by a processor, the steps of the data transmission method are implemented.
[0038] The beneficial effects brought by the technical solution provided by the embodiments of the present application are as follows: By adding an identifier to the encrypted data, only the data containing the target identifier can be sent outwards, ensuring that the security mechanism of the system cannot be bypassed, and thus ensuring the security of the data sending behavior. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the accompanying drawings required for the description of the embodiments of the present application.
[0040] Figure 1 It is a schematic flowchart of a data transmission method provided by an embodiment of the present application;
[0041] Figure 2 It is a schematic flowchart of another data transmission method provided by an embodiment of the present application;
[0042] Figure 3 It is a schematic flowchart of yet another data transmission method provided by an embodiment of the present application;
[0043] Figure 4Schematic flowchart of yet another data transmission method provided by an embodiment of this application;
[0044] Figure 5 Schematic structural diagram of an application processor provided by an embodiment of this application;
[0045] Figure 6 Schematic structural diagram of a communication processor provided by an embodiment of this application;
[0046] Figure 7 Schematic structural diagram of an electronic device for data transmission provided by an embodiment of this application. Detailed implementation manners
[0047] The embodiments of this application will be described below with reference to the accompanying drawings in this application. It should be understood that the embodiments described below in conjunction with the drawings are exemplary descriptions for explaining the technical solutions of the embodiments of this application, and do not constitute limitations on the technical solutions of the embodiments of this application.
[0048] Those skilled in the art of this technology can understand that, unless specifically stated otherwise, the singular forms "a", "an", "the" and "said" used herein may also include the plural forms. It should be further understood that the terms "including" and "comprising" used in the embodiments of this application mean that the corresponding features can be implemented as the presented features, information, data, steps, operations, elements and / or components, but do not exclude being implemented as other features, information, data, steps, operations, elements, components and / or their combinations supported by this technical field. It should be understood that when we say an element is "connected" or "coupled" to another element, this element can be directly connected or coupled to the other element, or it can mean that this element and the other element establish a connection relationship through an intermediate element. In addition, the "connection" or "coupling" used here can include wireless connection or wireless coupling. The term "and / or" used here indicates at least one of the items defined by this term. For example, "A and / or B" can be implemented as "A", or implemented as "B", or implemented as "A and B".
[0049] To make the objectives, technical solutions and advantages of this application clearer, the embodiments of this application will be further described in detail below in conjunction with the drawings.
[0050] First, several terms related to this application will be introduced and explained:
[0051] An SoC system (System on Chip, also known as a system-on-a-chip) typically includes: an application processor (Application Processor, abbreviated as AP); a communication processor (Communication Processor, abbreviated as CP), such as 3G, 4G, 5G and other mobile communication processors; an operating system runs on the AP, and various application programs run on the operating system.
[0052] The interaction, message passing, etc. between the AP and the CP generally pass through shared memory or a bus. The AP mainly passes commands and parameters to the CP, and the AP also receives data returned by the TEE.
[0053] In the prior art, the security, confidentiality, and integrity of the code and data loaded into this environment are mostly ensured through the TEE (Trusted Execution Environment). However, there are hidden dangers in the design of many TEE products, bringing a large number of security problems. For example, in 2015, the TEE system QSEE of Qualcomm exposed an arbitrary memory vulnerability. In the same year, a vulnerability was exposed in the fingerprint module of the Samsung Galaxy S5 mobile phone. Its fingerprint device was not correctly configured, resulting in the non-secure system being able to directly obtain fingerprint information.
[0054] The data transmission method, processor, electronic device, and computer-readable storage medium provided in this application aim to solve the technical problems existing in the prior art.
[0055] As Figure 1 shown, this application provides a data transmission method. The method is applied to the application processor AP, and the method may include:
[0056] S101. Determine the data content to be sent, and encrypt the data content to be sent through a preset encryption algorithm to obtain encrypted data content.
[0057] In the embodiments of this application, in the system-on-a-chip SOC in electronic products such as terminals, it may include an application processor AP and a communication processor CP. Among them, the operating system running on the application processor AP may be an Android system, an Apple system, or other operating systems. The communication processor CP may be a mobile communication processor or other types of communication processors. After the AP determines the data content to be sent, it may encrypt the data content to be sent through a preset encryption algorithm and obtain the encrypted data content after encryption. Among them, for the specific encryption algorithm, this application does not make specific limitations as long as it can encrypt the data content to be sent.
[0058] Based on the above embodiments, as an alternative embodiment, the security mechanism of the application processor AP in this application may include not only common cryptographic algorithms, key management, etc., but also a trusted UI. Among them, the trusted UI means that when displaying critical information or when the user inputs critical data, for example, when the user inputs a password, hardware resources such as the screen and keyboard lights are completely controlled and accessed by the TEE.
[0059] Based on the above embodiments, as an alternative embodiment, a TEE (Trusted Execution Environment) may be set in an electronic product including an SoC in this application. After the AP determines the data content to be sent, it may send the data content to be sent to the TEE. After receiving the data content to be sent, the TEE may encrypt the data content to be sent through a preset encryption algorithm built therein and obtain the encrypted data content after encryption.
[0060] S102. Determine the target identifier of the encrypted data content according to the encrypted data content and a preset method.
[0061] In the embodiment of this application, the AP adds a target identifier to the encrypted data content according to the encrypted data content after encryption and a preset method. For the specific method, this application does not make specific limitations as long as it can add an identifier to the encrypted data content after encryption. For example, a coloring identifier may be added to the encrypted data content through a data coloring mechanism, and this coloring identifier is used as the target identifier of the encrypted data content. The target identifier is used to represent that the AP has encrypted the data content to be sent.
[0062] Based on the above embodiments, as an alternative embodiment, when designing the application processor AP in this application, a dedicated module may be set for it, and the corresponding daemon process is started when necessary to perform the operation of adding a target identifier to the encrypted data content. For example, a data coloring operation may be performed to add a coloring identifier to the encrypted data content. At the same time, when designing the application processor AP, corresponding extensions may be reserved so that the target identifier, for example, the data coloring identifier, can be written into the physical address space.
[0063] Based on the above embodiments, as an alternative embodiment, a TEE (Trusted Execution Environment) may be set in an electronic product such as a terminal including an SoC. After the application processor AP determines the data content to be sent, it may send the data content to be sent to the TEE. After the TEE receives the data content to be sent, it encrypts it to obtain the encrypted data content after encryption, and adds a target identifier to the encrypted data content according to the encrypted data content after encryption and a preset method. Then, the TEE sends the encrypted data content and the target identifier of the encrypted data content to the AP.
[0064] S103. Generate target data based on the encrypted data content and the target identifier, and send the target data to the communication processor CP.
[0065] In an embodiment of the present application, the application processor AP may package the encrypted data content and the target identifier to obtain target data, and send the target data to the communication processor CP.
[0066] Further, in step S103, the generating target data based on the encrypted data content and the target identifier may include:
[0067] Determine a first hash value of the encrypted data content according to a preset hash algorithm.
[0068] In an embodiment of the present application, the AP calculates a first hash value of the encrypted data content according to a preset hash algorithm. The specific hash algorithm is not specifically limited in the present application, as long as the first hash value of the encrypted data content can be calculated through this hash algorithm.
[0069] Sign the first hash value with a preset private key to obtain a target signature of the encrypted data content.
[0070] In an embodiment of the present application, the AP signs the first hash value with a preset private key built therein to obtain a target signature of the encrypted data content, where the target signature is used to characterize the integrity and authenticity of the encrypted data content.
[0071] On the basis of the above embodiments, as an optional embodiment, the AP of the present application may receive the encrypted data content and the target identifier sent by the TEE. After receiving the encrypted data content, the AP calculates a first hash value of the encrypted data content according to a preset hash algorithm, and signs the first hash value with a preset private key to obtain a target signature of the encrypted data content.
[0072] Generate target data based on the encrypted data content, the target identifier, and the target signature.
[0073] In an embodiment of the present application, the AP packages the encrypted data content, the target identifier, and the target signature to obtain target data, and sends the target data to the communication processor CP.
[0074] As Figure 2 shown, the present application further provides a data transmission method, which is applied to the CP, and the method may include:
[0075] S201. Receive the target data sent by the application processor AP.
[0076] In an embodiment of the present application, a communication processor CP may receive target data sent by an application processor AP within the same SoC system, and may forward the target data, for example, forward the target data to the Internet or the Internet.
[0077] S202. If it is determined through a preset verification algorithm that the target data contains a target identifier, then send the target data.
[0078] In an embodiment of the present application, when designing the communication processor CP, a dedicated verification module may be set up. The verification module may include a preset verification algorithm, which is used to verify whether the received target data contains a target identifier. Among them, the verification algorithm corresponds to a preset method in the AP for adding a target identifier to the encrypted data content. For the specific verification algorithm, the present application does not make specific limitations. For example, in the AP, the data coloring mechanism may be used to add a coloring identifier to the encrypted data content, and in the CP, a corresponding coloring verification algorithm may be set up to further verify whether the target data contains a coloring identifier. If the CP determines through the preset verification algorithm that the target data contains a target identifier, it is determined that the data content in the target data is obtained through encryption, and the target data may be sent, for example, sent to the Internet or the Internet.
[0079] S203. If it is determined through the preset verification algorithm that the target data does not contain the target identifier, then do not send the target data.
[0080] In an embodiment of the present application, if it is determined through the preset verification algorithm that the target data does not contain a target identifier, it is determined that the data content in the received target data is not encrypted, that is, the data content bypasses the security mechanisms of the AP or the TEE. To ensure data security, the CP does not send the target data and discards the received target data, thereby ensuring that relevant privacy or sensitive data does not leak.
[0081] Based on the above embodiments, as an optional embodiment, if the target data received by the CP does not contain a target identifier, then send a verification failure message to the AP to notify the AP to re-send the target data.
[0082] Furthermore, the target data may further include a target signature and encrypted data content.
[0083] In step S202, before determining that the target data contains a target identifier, it may include:
[0084] If it is determined that the target signature meets the preset conditions, then verify whether the target data contains a target identifier; where the target signature is obtained by the AP signing the encrypted data content in the target data according to a preset private key.
[0085] In an embodiment of the present application, the target data received by the CP may further include a target signature and encrypted data content. Before determining whether the target data contains the target signature, it is also necessary to determine whether the target signature in the target data meets a preset condition. If it meets the preset condition, it proves that the target data received by the CP truly comes from the AP, and the data is complete. Among them, the target signature is obtained by the AP signing the encrypted data content in the target data according to its built-in preset private key.
[0086] Specifically, the determination that the target signature meets the preset condition may include:
[0087] Calculating a second hash value of the encrypted data content through a preset hash algorithm.
[0088] In an embodiment of the present application, the CP may calculate the second hash value of the received encrypted data content according to its built-in preset hash algorithm. Regarding the specific hash algorithm, the present application does not make specific limitations as long as it is consistent with the hash algorithm built in the AP.
[0089] Decrypting the target signature according to the preset public key to obtain the first hash value.
[0090] In an embodiment of the present application, the CP decrypts the obtained target signature according to the preset public key and obtains the corresponding first hash value, where the preset public key corresponds to the preset private key in the AP.
[0091] If the first hash value is the same as the second hash value, it is determined that the target signature meets the preset condition.
[0092] In an embodiment of the present application, if the first hash value is the same as the second hash value, it can be determined that the target signature meets the preset condition, and further determine that the target data received by the CP truly comes from the AP within the same SoC system, and the target data is complete.
[0093] Based on the above embodiments, as an optional embodiment, if the first hash value is different from the second hash value, the received target data is discarded.
[0094] Further, after receiving the target data sent by the application processor AP in step S201, it may further include: if more than a preset number of target data that do not contain the target identifier are received within a preset time, an alarm message is sent to the AP.
[0095] In an embodiment of the present application, if the CP receives a certain number of target data within a preset time, and among these target data, more than a preset number or a preset proportion of the target data do not contain a target identifier, it indicates that there is a problem with the security mechanism of the AP or the TEE. An alarm message needs to be sent to the user of electronic products such as the AP or the terminal. The alarm message is used to inform the user that there is a problem with the security mechanism of the current system and that measures need to be taken in a timely manner to block the data from being sent outwards. The specific duration of the preset time, the specific value of the preset number, and the size of the preset proportion are not specifically limited in the present application, as long as it can indicate that the CP has received target data without a target identifier multiple times within a period of time.
[0096] A possible implementation manner is provided in an embodiment of the present application. As Figure 3 shown, after determining the data content to be sent, the application processor AP of the present application encrypts the data content to be sent to obtain the encrypted data content; obtains the target identifier of the encrypted data content according to a preset method and the encrypted data content; calculates the first hash value of the encrypted data content through a preset hash algorithm, and signs it with a preset private key to obtain the target signature of the encrypted data content; packages the encrypted data content, the target identifier, and the target signature to obtain the target data, and sends the target data to the communication processor CP. After receiving the target data, the CP first verifies the signature of the target data. If it is determined that the target data is complete and authentic, it further checks whether the target data contains a target identifier; if the target data contains a target identifier, it sends the target data. For example, it sends the target data to the Internet; if the target data does not contain a target identifier, it does not send the target data and sends a verification failure message to the AP to notify the AP to re-send the relevant data.
[0097] Another possible implementation manner is provided in an embodiment of the present application. As Figure 4As shown, a TEE (Trusted Execution Environment) is usually set in an electronic product, and the security, confidentiality, and integrity of the code and data loaded into its system are ensured through the TEE. After determining the data content to be sent, the application processor AP sends the data content to be sent to the TEE. After receiving the data content to be sent, the TEE obtains the encrypted data content and the corresponding target identifier according to a preset encryption algorithm and a preset method, and sends the encrypted data content and the target identifier to the AP. After receiving the encrypted data content, the AP calculates the first hash value of the encrypted data content through a preset hash algorithm, and signs the first hash value with a built-in preset private key to obtain the target signature of the encrypted data content; the AP packs the encrypted data content, the target identifier, and the target signature to obtain the target data, and sends the target data to the communication processor CP. After receiving the target data, the CP first verifies the signature of the target data. If it is determined that the target data is complete and authentic, it further checks whether the target data contains the target identifier; if the target data contains the target identifier, it sends the target data, for example, sends the target data to the Internet; if the target data does not contain the target identifier, it does not send the target data and sends a verification failure message to the AP to notify the AP to resend the relevant data.
[0098] An embodiment of the present application provides an application processor, such as Figure 5 As shown, the application processor 50 may include: an encryption module 501, an identification module 502, and a sending module 503, where
[0099] The encryption module 501 is configured to determine the data content to be sent, and encrypt the data content to be sent through a preset encryption algorithm to obtain encrypted data content.
[0100] The identification module 502 is configured to determine the target identifier of the encrypted data content according to the encrypted data content and a preset method.
[0101] The first sending module 503 is configured to generate target data according to the encrypted data content and the target identifier, and send the target data to the communication processor CP.
[0102] An embodiment of the present application further provides a communication processor, such as Figure 6 As shown, the communication processor 60 may include: a receiving module 601, a second sending module 602, and a rejecting sending module 603, where
[0103] The receiving module 601 is configured to receive the target data sent by the application processor AP.
[0104] The second sending module 602 is configured to send the target data if it is determined through a preset verification algorithm that the target data contains the target identifier.
[0105] A rejection sending module 603, configured to not send the target data if it is determined that the target data does not contain the target identifier through a preset verification algorithm.
[0106] Furthermore, compared with the prior art, by adding an identifier to the encrypted data, only the data containing the target identifier can be sent outwards, ensuring that the security mechanism of the system cannot be bypassed, and thus ensuring the security of the data sending behavior.
[0107] The device according to the embodiment of the present application can execute the method provided by the embodiment of the present application, and its implementation principle is similar. The actions performed by each module in the device according to the embodiments of the present application correspond to the steps in the method according to the embodiments of the present application. For the detailed function description of each module of the device, reference can be specifically made to the description in the corresponding method shown above, and details are not described herein again.
[0108] In the embodiment of the present application, an electronic device is provided, including a memory, a processor, and a computer program stored on the memory. The processor executes the above computer program to implement the steps of the data transmission method. Compared with the related art, it can be realized that by adding an identifier to the encrypted data, only the data containing the target identifier can be sent outwards, ensuring that the security mechanism of the system cannot be bypassed, and thus ensuring the security of the data sending behavior. In an optional embodiment, an electronic device is provided, as Figure 7 shown Figure 7 The electronic device 7000 shown includes a processor 7001 and a memory 7003. Among them, the processor 7001 and the memory 7003 are connected, such as connected through a bus 7002. Optionally, the electronic device 7000 may further include a transceiver 7004, and the transceiver 7004 may be used for data interaction between the electronic device and other electronic devices, such as data sending and / or data receiving, etc. It should be noted that in practical applications, the transceiver 7004 is not limited to one, and the structure of the electronic device 7000 does not constitute a limitation to the embodiment of the present application.
[0109] The processor 7001 can be a CPU (Central Processing Unit), a general-purpose processor, a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It can implement or execute various exemplary logical blocks, modules, and circuits described in connection with the disclosure of this application. The processor 7001 can also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, etc.
[0110] The bus 7002 can include a path for transmitting information between the above components. The bus 7002 can be a PCI (Peripheral Component Interconnect) bus, an EISA (Extended Industry Standard Architecture) bus, or the like. The bus 7002 can be divided into an address bus, a data bus, a control bus, etc. For the sake of representation, Figure 7 only a thick line is used to represent it herein, but it does not mean that there is only one bus or one type of bus.
[0111] The memory 7003 can be a ROM (Read Only Memory) or other types of static storage devices that can store static information and instructions, a RAM (Random Access Memory) or other types of dynamic storage devices that can store information and instructions, or it can also be an EEPROM (Electrically Erasable Programmable Read Only Memory), a CD-ROM (Compact Disc Read Only Memory), or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media, other magnetic storage devices, or any other medium that can be used to carry or store computer programs and can be read by a computer, which is not limited herein.
[0112] The memory 7003 is used to store the computer program for implementing the embodiments of the present application, and is controlled by the processor 7001 to execute. The processor 7001 is used to execute the computer program stored in the memory 7003 to implement the steps shown in the foregoing method embodiments.
[0113] The embodiments of the present application provide a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps and corresponding contents of the foregoing method embodiments can be implemented.
[0114] The embodiments of the present application further provide a computer program product, including a computer program. When the computer program is executed by a processor, the steps and corresponding contents of the foregoing method embodiments can be implemented.
[0115] Terms such as "first", "second", "third", "fourth", "1", "2", etc. in the specification, claims and the above-mentioned drawings of the present application are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than the illustrated or textually described order.
[0116] It should be understood that although the flowchart of the embodiments of the present application indicates each operation step by an arrow, the execution order of these steps is not limited to the order indicated by the arrow. Unless there is a clear description in this article, in some implementation scenarios of the embodiments of the present application, the implementation steps in each flowchart can be executed in other orders according to requirements. In addition, some or all of the steps in each flowchart may include multiple sub-steps or multiple stages based on the actual implementation scenario. Some or all of these sub-steps or stages can be executed at the same time, and each sub-step or stage among these sub-steps or stages can also be executed at different times respectively. In the scenario where the execution times are different, the execution order of these sub-steps or stages can be flexibly configured according to requirements, and the embodiments of the present application do not limit this.
[0117] The above are only optional implementation manners of some implementation scenarios of the present application. It should be noted that for those of ordinary skill in the art, without departing from the technical concept of the solution of the present application, other similar implementation means based on the technical idea of the present application also belong to the protection scope of the embodiments of the present application.
Claims
1. A data transmission method, characterized in that, The method is applied to an application processor AP, and the method includes: Determine the data content to be sent, and encrypt the data content to be sent through a preset encryption algorithm to obtain an encrypted data content; Determine a target identifier of the encrypted data content according to the encrypted data content and a preset method, where the target identifier is used to represent that the AP has encrypted the data content to be sent; Generate target data according to the encrypted data content and the target identifier, and send the target data to a communication processor CP, so that the CP sends the target data when it is determined through a preset verification algorithm that the target data contains the target identifier, and the verification algorithm corresponds to the preset method for adding the target identifier to the encrypted data content in the AP.
2. The method according to claim 1, characterized in that, The generating target data according to the encrypted data content and the target identifier includes: Determine a first hash value of the encrypted data content according to a preset hash algorithm; Sign the first hash value with a preset private key to obtain a target signature of the encrypted data content; Generate target data according to the encrypted data content, the target identifier, and the target signature.
3. A data transmission method, characterized in that, The method is applied to a communication processor CP, and the method includes: Receive target data sent by an application processor AP; If it is determined through a preset verification algorithm that the target data contains a target identifier, send the target data, where the verification algorithm corresponds to the preset method for adding the target identifier to the encrypted data content in the AP, and the target identifier is used to represent that the AP has encrypted the data content to be sent; If it is determined through a preset verification algorithm that the target data does not contain the target identifier, do not send the target data.
4. The method according to claim 3, characterized in that, The target data further includes a target signature and an encrypted data content; Before determining that the target data contains a target identifier, it further includes: If it is determined that the target signature meets a preset condition, check whether the target data contains the target identifier; Wherein, the target signature is obtained by the AP signing the encrypted data content in the target data with a preset private key; The determining that the target signature meets a preset condition includes: Calculate a second hash value of the encrypted data content through a preset hash algorithm; Decrypt the target signature with a preset public key to obtain the first hash value of the encrypted data content; If the first hash value is the same as the second hash value, determine that the target signature meets a preset condition.
5. The method according to claim 3, characterized in that, After receiving the target data sent by the application processor AP, it further includes: If it is determined within a preset time that the number of received target data that do not contain a target identifier exceeds a preset number, send an alarm message to the AP.
6. An application processor, characterized in that, It includes: An encryption module, configured to determine the data content to be sent, and encrypt the data content to be sent through a preset encryption algorithm to obtain an encrypted data content; An identification module, configured to determine a target identifier of the encrypted data content according to the encrypted data content and a preset method, where the target identifier is used to represent that the AP has encrypted the data content to be sent; A first sending module, configured to generate target data according to the encrypted data content and a target identifier, and send the target data to a communication processor CP, so that when the CP determines that the target data contains the target identifier through a preset verification algorithm, the CP sends the target data, where the verification algorithm corresponds to a preset method for adding the target identifier to the encrypted data content in the AP.
7. A communication processor, characterized in that, Comprising: A receiving module, configured to receive the target data sent by an application processor AP; A second sending module, configured to send the target data if it is determined through a preset verification algorithm that the target data contains the target identifier, where the verification algorithm corresponds to a preset method for adding the target identifier to the encrypted data content in the AP, and the target identifier is used to indicate that the AP has encrypted the data content to be sent; A rejecting sending module, configured to not send the target data if it is determined through a preset verification algorithm that the target data does not contain the target identifier.
8. An electronic device, comprising a memory, a processor, and a computer program stored on the memory, characterized in that, The processor executes the computer program to implement the steps of the data transmission method according to any one of claims 1-5.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the data transmission method according to any one of claims 1-5.
10. A computer program product comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the data transmission method according to any one of claims 1-5.
Citation Information
Patent Citations
Data processing method and device and medium
CN110912920A
Data processing method and device and computer storage medium
CN112188489A