A secure communication method and device
The server determines the terminal device with encryption and decryption capabilities based on the called user's ID and sends encrypted data to it, solving the problem that terminal devices without security chips cannot decrypt, and improving the user's secure communication experience.
Patent Information
- Application Number
- CN202011027265.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-09-25
- Publication Date
- 2025-09-12
- Estimated Expiration
- 2040-09-25
AI Technical Summary
When secure communication is conducted between users, terminal devices that do not carry a security chip cannot decrypt encrypted data, resulting in a poor user experience and an inability to accurately identify terminal devices with encryption and decryption capabilities.
The server determines the terminal device with encryption and decryption capabilities by receiving the called user ID in the message sent by the terminal device, and sends the encrypted data to it, ensuring that only the terminal device with encryption and decryption capabilities can correctly decrypt the data.
It improves the accuracy of sending encrypted data to terminal devices with encryption and decryption capabilities, and enhances the user's secure communication experience.
Smart Images

Figure CN114258008B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of secure communications, and in particular to a secure communications method and apparatus. Background Art
[0002] Currently, users can use terminal devices with security chips to encrypt data before transmitting it, thereby improving data security and avoiding data leakage. After the server receives the encrypted data, if it determines that multiple terminal devices are running applications that have logged into the target account, the server sends the encrypted data to the multiple terminal devices. The terminal devices with security chips among the multiple terminal devices can correctly decrypt the encrypted data and obtain the data. The terminal devices without security chips among the multiple terminal devices cannot decrypt the encrypted data and obtain garbled or confusing messages. However, the user does not know which terminal device among the multiple terminal devices can decrypt the encrypted data, which may cause the user to mistakenly answer or view the garbled or confusing messages received by the terminal device without security chip. At this time, the calling user may need to resend the encrypted data, resulting in a lower user experience for secure communication between users. Therefore, how to accurately send encrypted data to terminal devices with encryption and decryption capabilities is an urgent problem to be solved. Summary of the Invention
[0003] The embodiments of the present application provide a secure communication method and apparatus, which solve the problem of how to accurately send encrypted data to a terminal device with encryption and decryption capabilities.
[0004] In a first aspect, the present application provides a secure communication method, which can be applied to a server, or to a communication device that can support the server in implementing the method, for example, the communication device includes a chip system. The method includes: the server receives a first message sent by a first terminal device, and determines, based on a called user ID included in the first message, a second terminal device with encryption and decryption capabilities bound to the called user ID. When the second terminal device invokes the encryption and decryption capabilities, the server sends the encrypted data contained in the first message to the second terminal device.
[0005] In this way, because the server can identify the second terminal device with encryption and decryption capabilities based on the called user ID, and when the second terminal device invokes encryption and decryption capabilities, it sends the encrypted data contained in the first message to the second terminal device, the server accurately sends the encrypted data to the terminal device with encryption and decryption capabilities. This effectively improves the accuracy of the server's transmission of encrypted data to the terminal device with encryption and decryption capabilities, allowing users to accurately answer or view encrypted data, and improving the user's experience in secure conversations.
[0006] The terminal device with encryption capability may be a terminal device carrying a security chip.
[0007] In addition, a first application is running on the first terminal device, and the first terminal device sends the first message via the first application. A second application is loaded on the second terminal device. Loading the second application on the second terminal device can also be described as installing the second application on the second terminal device. When the second terminal device invokes encryption and decryption capabilities to run the second application, the server sends the first message to the second terminal device, and the second terminal device receives the first message sent by the server via the second application.
[0008] The communication between the first application and the second application means that the first terminal device sends a call message or instant message through the first application, and the second terminal device receives the call message or instant message through the second application, so that the first terminal device and the second terminal device can use the first application and the second application to conduct a call or exchange instant messages. It is understandable that the first terminal device has the first application installed, and the second terminal device has the second application installed.
[0009] It is worth noting that the first application and the second application are the same application. The so-called same application can be understood as meaning that the first application and the second application have the same name, and the first application and the second application communicate using the same protocol. The functions implemented by the first application and the functions implemented by the second application are the same. The version of the installation package of the first application is different from the version of the installation package of the second application. Alternatively, the version of the installation package of the first application and the version of the installation package of the second application are the same.
[0010] In another possible design, the first application and the second application are different applications. Different applications can be understood as meaning that the first application and the second application have different names, and the first application and the second application communicate using a mutually recognizable protocol. The functions implemented by the first application and the second application are similar, but there are also differences between the functions implemented by the first application and the second application.
[0011] In one possible implementation, before sending the first message to the second terminal device, if the second terminal device is running the second application and has not yet invoked encryption and decryption capabilities, the server sends a first instruction message to the second terminal device. The first instruction message instructs the second terminal device to exit the second application and re-activate the encryption and decryption capabilities. Consequently, the server instructs the second terminal device to exit the second application and re-activate the encryption and decryption capabilities, facilitating the server's transmission of encrypted data to the second terminal device. This effectively improves the accuracy of encrypted data sent by the server to the second terminal device, enabling users to accurately receive or view encrypted data and enhancing the user's secure conversation experience.
[0012] In another possible implementation, before sending the first message to the second terminal device, the method further includes: when the second terminal device is not running the second application and has not invoked encryption and decryption capabilities, the server sending a second instruction message to the push server. The second instruction message is used to instruct the second terminal device to invoke encryption and decryption capabilities to run the second application, and the second instruction message includes the identifier of the second terminal device. Thus, the server instructs the second terminal device to invoke encryption and decryption capabilities to run the second application, thereby facilitating the server's transmission of encrypted data to the second terminal device. This effectively improves the accuracy of encrypted data sent by the server to the second terminal device, allowing the user to accurately receive or view encrypted data, thereby enhancing the user's secure conversation experience.
[0013] In another possible implementation, the method further includes: the server receiving security status information and a device identifier sent by at least one terminal device with encryption and decryption capabilities, the security status information being used to indicate whether the terminal device has invoked encryption and decryption capabilities to run the second application, and the terminal device with encryption and decryption capabilities includes the second terminal device. In this manner, since the terminal device with encryption and decryption capabilities reports its user identifier, device identifier, and security status information to the server, the server can determine a terminal device with encryption and decryption capabilities that is bound to the user identifier based on the user identifier and the device identifier. Furthermore, when the security status information of the terminal device with encryption and decryption capabilities indicates that encryption and decryption capabilities have been invoked, the server sends encrypted data to the terminal device with encryption and decryption capabilities. This effectively improves the accuracy of encrypted data sent by the server to the terminal device with encryption and decryption capabilities, allowing users to accurately receive or view encrypted data, thereby enhancing the user's experience in secure conversations.
[0014] In another possible implementation, before receiving the security status information and device identification from at least one terminal device with encryption and decryption capabilities, the method further includes: the server sending a reporting message to the terminal device with encryption and decryption capabilities, the reporting message instructing the terminal device with encryption and decryption capabilities to report the security status information and device identification. This allows the terminal device with encryption and decryption capabilities to promptly report the security status information and device identification, allowing the server to identify the terminal device that has activated the encryption and decryption capabilities and promptly and accurately send encrypted data.
[0015] In another possible implementation, determining the second terminal device bound to the called user identity based on the called user identity includes: determining at least one associated terminal device bound to the called user identity based on the called user identity, the at least one associated terminal device including the second terminal device; and determining the second terminal device based on the identity of the at least one associated terminal device and the device identity of at least one terminal device with encryption and decryption capabilities.
[0016] In another possible implementation, the method further includes: determining, based on security status information of the second terminal device, whether the second terminal device has invoked encryption and decryption capabilities.
[0017] Optionally, if the encrypted data is a chat message, the method further includes: sending an obfuscated message to a terminal device other than the second terminal device in at least one associated terminal device.
[0018] In a second aspect, the present application provides a secure communication method, which can be applied to a terminal device, or a communication device that can support the terminal device to implement the method, for example, the communication device includes a chip system, and the terminal device is a terminal device with encryption and decryption capabilities. The method includes the terminal device receiving an instruction message and invoking the encryption and decryption capabilities to run an application. Then, the terminal device receives a first message, the first message including encrypted data. The instruction message is used to instruct the terminal device to invoke the encryption and decryption capabilities to run the application.
[0019] In this way, when the terminal device does not invoke encryption and decryption capabilities, upon receiving the instruction message, the terminal device invokes encryption and decryption capabilities and reruns the application, allowing the server to send encrypted data to the terminal device. This effectively improves the accuracy of encrypted data sent from the server to the terminal device, allowing users to accurately receive or view encrypted data, and improving the user experience of secure conversations.
[0020] In a possible implementation, the terminal device runs an application but does not call the encryption and decryption capability. Calling the encryption and decryption capability to run the application includes: the terminal device first exits the application and calls the encryption and decryption capability to re-run the application.
[0021] In another possible implementation, the method further includes: the terminal device sending security status information and a device identifier, where the security status information indicates that the terminal device has invoked encryption and decryption capabilities to run an application. In this manner, since the terminal device reports the user identifier, device identifier, and security status information to the server, the server can determine a terminal device bound to the user identifier based on the user identifier and device identifier.
[0022] In another possible implementation, the method further includes: the terminal device receiving a reporting message, where the reporting message is used to instruct the terminal device with encryption and decryption capabilities to report security status information and a device identifier.
[0023] In a third aspect, the present application provides a communication device. The present application provides a communication device. The beneficial effects can be found in the description of the first aspect and will not be repeated here. The communication device has the function of implementing the behavior in the method example of the first aspect. The function can be implemented by hardware, or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions. In one possible design, the communication device includes: a transceiver unit and a processing unit. The transceiver unit is used to receive a first message sent by a first terminal device, and the first message includes a called user identity and encrypted data. The processing unit is used to determine a second terminal device bound to the called user identity based on the called user identity, and the second terminal device is a terminal device with encryption and decryption capabilities. The transceiver unit is also used to send a first message to the second terminal device when the second terminal device calls the encryption and decryption capabilities. These units can perform the corresponding functions in the method example of the first aspect above. Please refer to the detailed description in the method example for details, and will not be repeated here.
[0024] In a fourth aspect, the present application provides a device for distributing data, and the present application provides a communication device. The beneficial effects can be found in the description of the second aspect and will not be repeated here. The communication device has the function of implementing the behavior in the method example of the second aspect. The function can be implemented by hardware, or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions. In one possible design, the communication device includes: a transceiver unit and a processing unit. The transceiver unit is used to receive an indication message, and the indication message is used to instruct the terminal device to call the encryption and decryption capability to run the application, and the terminal device is a terminal device with encryption and decryption capabilities. The processing unit is used to call the encryption and decryption capability to run the application. The transceiver unit is also used to receive a first message, and the first message includes encrypted data. These units can perform the corresponding functions in the method example of the second aspect, and refer to the detailed description in the method example for details, which will not be repeated here.
[0025] In a fifth aspect, the present application provides a server comprising a memory and a processor, wherein the memory is used to store a set of computer instructions; when the processor executes the set of computer instructions, the functions of the various modules of the method in the first aspect or any possible implementation of the first aspect are executed.
[0026] In a sixth aspect, the present application provides a terminal device comprising a memory and a processor, wherein the memory is used to store a set of computer instructions; when the processor executes the set of computer instructions, the functions of the various modules of the method in the second aspect or any possible implementation of the second aspect are executed.
[0027] In a seventh aspect, the present application provides a computer-readable storage medium comprising computer software instructions; when the computer software instructions are executed in a server, the server executes a method as described in the first aspect or any possible implementation of the first aspect.
[0028] In an eighth aspect, the present application provides a computer-readable storage medium comprising computer software instructions; when the computer software instructions are executed in a terminal device, the terminal device executes a method as described in any one of the second aspect or possible implementations of the second aspect.
[0029] In a ninth aspect, the present application provides a computer program product comprising instructions, which, when executed on a server, enables the server to execute the method described in the first aspect or any one of the implementations of the first aspect.
[0030] In a tenth aspect, the present application provides a computer program product comprising instructions, which, when executed on a terminal device, enables the terminal device to execute the method described in the second aspect or any one of the implementations of the second aspect.
[0031] Based on the implementation methods provided in the above aspects, this application can also be further combined to provide more implementation methods. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] Figure 1 A schematic diagram of the architecture of a communication system provided in an embodiment of the present application;
[0033] Figure 2 A schematic diagram of a process for establishing a connection between a security terminal and a service system provided in an embodiment of the present application;
[0034] Figure 3 A flowchart of a secure communication method provided in an embodiment of the present application;
[0035] Figure 4 A flowchart of another secure communication method provided in an embodiment of the present application;
[0036] Figure 5 A flowchart of another secure communication method provided in an embodiment of the present application;
[0037] Figure 6 A flowchart of another secure communication method provided in an embodiment of the present application;
[0038] Figure 7 A flowchart of another secure communication method provided in an embodiment of the present application;
[0039] Figure 8 A schematic diagram of the composition of a communication device provided in an embodiment of the present application;
[0040] Figure 9 A schematic diagram of the composition of another communication device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0041] The terms "first", "second" and "third" in the specification and claims of this application and the above-mentioned drawings are used to distinguish different objects rather than to limit a specific order.
[0042] In the embodiments of this application, words such as "exemplary" or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described as "exemplary" or "for example" in the embodiments of this application should not be interpreted as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.
[0043] "Multiple" means two or more, and other quantifiers are similar. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, for elements (element) in the singular form "a", "an" and "the", unless the context clearly stipulates otherwise, it does not mean "one or only one", but "one or more than one". For example, "a device" means one or more such devices. Furthermore, at least one (at least one of)..." means one or any combination of the subsequent associated objects, for example, "at least one of A, B and C" includes A, B, C, AB, AC, BC, or ABC.
[0044] The implementation of the embodiments of the present application will be described in detail below with reference to the accompanying drawings.
[0045] Figure 1 This is a schematic diagram of the architecture of a communication system provided by this embodiment. Figure 1As shown, the communication system includes a service system 110, at least one terminal device 120, and at least one terminal device 140. Terminal devices 120 and 140 can communicate with service system 110 via a network 130. Network 130 can be the internet. The internet includes at least one network device (e.g., network device 131, network device 132, and network device 133). Network devices include routers, switches, and wireless access network devices. Terminal devices 120 and 140 are connected to the network devices via wireless or wired connections. The network devices are connected via wireless or wired connections. The wireless access network device can be a base station, an evolved NodeB (eNodeB), a transmission reception point (TRP), a next generation NodeB (gNB) in a 5G mobile communication system, a base station in a future mobile communication system, or an access node in a WiFi system, etc.; it can also be a module or unit that completes part of the functions of a base station, for example, it can be a centralized unit (CU) or a distributed unit (DU). This embodiment does not limit the specific technology and specific device form adopted by the wireless access network device. The network device is connected to the service system 110 via wireless or wired means. The terminal device can be fixed or movable. Figure 1 This is just a schematic diagram. The communication system may also include other devices, such as wireless relay devices and wireless backhaul devices. Figure 1 This embodiment does not limit the number of terminal devices, network devices, and servers included in the communication system.
[0046] Among them, terminal devices (such as terminal device 120 and terminal device 140) may also be referred to as terminals, user equipment (UE), mobile stations (MS), mobile terminals (MT), etc. The terminal may be a mobile phone, a tablet computer, a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical surgery, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, etc. This embodiment does not limit the specific technology and specific device form adopted by the terminal device.
[0047] It is worth noting that terminal device 120 can be a terminal device capable of encrypting or decrypting data. A terminal device with encryption and decryption capabilities can use a key to encrypt or decrypt data, thereby improving data security and preventing data leakage. For ease of description, in the following embodiments, a terminal device with encryption and decryption capabilities may be alternatively described as a secure terminal. A terminal device without encryption and decryption capabilities may be alternatively described as a non-secure terminal. In the embodiments of the present application, terminal device 120 is a secure terminal. Terminal device 140 may be a terminal device without encryption and decryption capabilities, that is, terminal device 140 is a non-secure terminal.
[0048] In one possible implementation, a security terminal carries a security chip. This chip independently generates and stores keys, and encrypts and decrypts data. The security chip includes a processor and memory. The processor uses the key to encrypt or decrypt data, providing encryption and security authentication services. The memory stores the key. Because the security terminal uses the security chip to encrypt data, the key is stored in hardware, making it impossible to decrypt stolen data, thereby protecting privacy and data security.
[0049] In another possible implementation, the security terminal may not carry a security chip, but may use a key provided by a third-party key system to encrypt or decrypt data.
[0050] A non-secure terminal refers to a terminal device that does not carry a security chip. Alternatively, a non-secure terminal refers to a terminal device that does not have the ability to encrypt or decrypt data using encryption or decryption algorithms.
[0051] Service system 110 may be a cloud service system. Service system 110 may include multiple servers 111, which form a server cluster. Multiple servers 111 may be independent, distinct physical devices. Different servers implement different service functions. Alternatively, the functions of multiple services may be integrated on the same physical device, or the functions of some services may be integrated on a single physical device.
[0052] In this embodiment, the service system 110 is used to implement a security status service 112, a call service 113, a message service 114, a push service 115, a login service 116, and other services 117. It is worth noting that a service can be understood as a service device or a functional module. These services can be deployed on at least one server 111 in the service system 110. For example, a service is deployed on one server 111. For another example, a service is deployed on at least two servers 111, and each server 111 deploys part of the functions of a service. For another example, multiple services are deployed on one server 111, such as deploying a call service 113 and a message service 114 on one server 111. The server 111 can be called an application server.
[0053] The security status service 112 is used to record the security status information reported by the security terminal and the corresponding device identification. The security status information is used to indicate whether the security terminal has called the encryption and decryption capabilities to run the application. For example, the security status information indicates that the security terminal has started the security chip and loaded the security software development kit (SDK) library. The security SDK library is a software development kit used by the terminal device to obtain keys and encrypt or decrypt data. For another example, the security status information indicates that the security terminal has not started the security chip and has not loaded the security SDK library. For another example, the security status information indicates that the security terminal has the ability to encrypt and transmit data using encryption and decryption algorithms. For another example, the security status information indicates that the security terminal does not have the ability to encrypt and transmit data using encryption and decryption algorithms.
[0054] In one possible implementation, a status flag can be used to indicate the security status of a security terminal. The security status service 112 stores multiple records, each of which includes a device identifier and a corresponding flag. When the status flag of a record is set to 1, it indicates that the security terminal corresponding to the device identifier in the record is conducting a session in a secure state. This means that the security terminal has invoked encryption and decryption capabilities, is running an application, and is transmitting encrypted data through the application. When the status flag of a record is set to 0, it indicates that the security terminal corresponding to the device identifier in the record is conducting a session in an insecure state. This means that the security terminal has not invoked encryption and decryption capabilities. However, the security terminal can run applications and transmit unencrypted data through applications, or the security terminal may not be running an application. It should be noted that the security status service 112 is primarily used to record the security status of security terminals. Insecure terminals do not report information to the security status service. Therefore, the security terminal can be identified based on the records in the security status service. In this embodiment, a session in a secure state is also referred to as a secure session. A session in an insecure state is also referred to as an insecure session.
[0055] The call service 113 is used to transmit data of a voice over internet protocol (VoIP) call and an audio / video conference call to a terminal device of a called user.
[0056] The message service 114 is used to transmit the chat message data to the terminal device of the called user. The chat message can be text, audio, picture, video and other data.
[0057] Push service 115 is used to send push messages to push servers corresponding to terminal devices from different manufacturers. Push messages are used to instruct terminal devices to run applications. In VoIP call scenarios, push messages instruct terminal devices to run applications, enabling services such as voice and video data transmission. In instant messaging scenarios, push messages instruct terminal devices to run applications, enabling services such as instant messaging.
[0058] The login service 116 is used to manage the login information of the user account running the application on the terminal device after the terminal device establishes a connection with the service system 110. It should be noted that the login service 116 stores login information for both secure terminals and non-secure terminals. In other words, as long as the terminal device establishes a connection with the service system, the login information will be left. For example, the login information includes the login time and the logout time. The login time refers to the time when the terminal device (such as a secure terminal or a non-secure terminal) logs in to the application with the user identifier, that is, the time when the terminal device starts running the application. The logout time refers to the time when the terminal device exits the application, that is, the time when the terminal device stops running the application.
[0059] Other services 117 include key management services, monitoring services, and policy management services. Key management services manage the keys used to encrypt or decrypt data. Monitoring services monitor the normal operation of various services within service system 110. Policy management services manage users permitted to engage in secure communications. Policy management services can set security control policies based on different business scenarios or enterprise requirements. For example, they can include a whitelist of members permitted to engage in private chats within an enterprise and control over private chat time. Service system 110 can provide feedback on security control policies to terminal devices via login responses.
[0060] In the method provided in the embodiment of the present application, the security terminal is the basis for realizing a secure session. Before the security terminal and the service system conduct a session in a secure state, the security terminal first establishes a connection with the service system.
[0061] Figure 2 The following is a schematic diagram of the process of establishing a connection between a security terminal and a service system provided in this embodiment. This description uses the example of a terminal device 120 as the security terminal. A user activates terminal device 120 (for example, by long-pressing the power button on terminal device 120). Terminal device 120 responds to the activation operation and loads security chip 121 (S201). A user clicks an application icon (e.g., a WeLink icon) on the main interface of terminal device 120. Terminal device 120 responds to the click operation, activates the application, and loads the security SDK library (S202). After the user enters their user ID and password on the application registration interface, terminal device 120 responds to the input operation and sends a registration request to login service 116 (S203). The registration request includes, among other things, the user ID and the ID of terminal device 120. The user ID is used to distinguish different users and uniquely identifies a user. The user ID can be a user account assigned to the user by login service 116. The ID of terminal device 120 uniquely identifies terminal device 120. Login service 116 records the user ID and the ID of terminal device 120 (S204). Thereafter, the user logs into the application using the user ID on the terminal device 120 , and the login service 116 updates the login time of the user ID, without having to update the binding relationship between the user ID and the ID of the terminal device 120 .
[0062] For example, a user enters a user ID and password on the application login interface. Terminal device 120 responds to the input operation by sending a login request to login service 116 (execution S205). The login request includes, among other things, the user ID, the ID of terminal device 120, and the login time of the user ID. Login service 116 records the user ID, the ID of terminal device 120, and the login time (execution S206). Optionally, after login service 116 receives a logout request from terminal device 120, it records the user ID, the ID of terminal device 120, and the logout time. The logout request includes the user ID, the ID of terminal device 120, and the logout time.
[0063] It is understood that if a user logs into an application with a user ID on a terminal device (e.g., a secure terminal or a non-secure terminal), the user ID can be bound to the ID of the terminal device. If a user logs into an application with a user ID on multiple terminal devices, the user ID can be bound to the IDs of the multiple terminal devices. The terminal device ID (device ID) is used to uniquely identify the terminal device.
[0064] Optionally, the login request may also include the type of terminal device. Terminal device types include, but are not limited to, smartphones, iPads, personal computers (PCs), etc. The login service 116 records the binding relationships between multiple user identifiers, terminal device identifiers, and terminal device types.
[0065] In addition, if the user enters the user ID and password in the application login interface and chooses to log in to the application in a secure manner, the terminal device 120 can also send security status information and the device identification of the terminal device 120 to the security status service 112 (execute S207). The security status information is used to indicate whether the terminal device 120 has called the security capability to run the application. It can also be replaced by describing that the security status information is used to indicate whether the terminal device 120 has called the encryption and decryption capability to run the application or whether the terminal device 120 has loaded the security chip and the security SDK library to run the application. After the security status service 112 receives the security status information and the device identification of the terminal device 120 from the terminal device 120, the security status service 112 records the device identification and security status information of the terminal device 120 (execute S208). It can be understood that the security status service 112 records the binding relationship between the device identification and security status information of multiple security terminals.
[0066] It should be noted that since non-secure terminals (such as terminal device 140) do not have the ability to encrypt and decrypt data, non-secure terminals do not send device identification and security status information to the security status service 112, and no information of non-secure terminals will be stored in the security status service 112.
[0067] In addition, if the user does not call the encryption and decryption capabilities to run the application on the security terminal, the security terminal may not send security status information to the security status service 112. Then, the security terminals can conduct conversations through the service system 110, but cannot conduct secure conversations through the service system 110.
[0068] Optionally, if the security terminal invokes the encryption and decryption capabilities and runs the application, security status information is reported to the security status service 112, indicating that the security terminal invokes the encryption and decryption capabilities and runs the application. The security status service 112 may set the status flag to 1. If the security terminal exits the application, the security status service 112 sets the status flag to 0. If the security terminal runs the application but does not invoke the encryption and decryption capabilities, the security terminal reports security status information to the security status service 112, indicating that the security terminal runs the application but does not invoke the encryption and decryption capabilities. The security status service 112 will not refresh the status flag, and the status flag will remain 0. Alternatively, if the security terminal runs the application but does not invoke the encryption and decryption capabilities, the security terminal will not report security status information to the security status service 112, and the status flag will remain 0.
[0069] After the above steps S201 to S208, the security terminal establishes a connection with the service system. The security terminal can conduct a conversation with the service system in a secure state, that is, encrypted data transmission is performed between the security terminal and the service system.
[0070] Next, combine Figure 3 , the secure communication method provided in this embodiment is described in detail. This description takes a first terminal device and a second terminal device as examples. Both the first terminal device and the second terminal device are terminal devices with encryption and decryption capabilities, i.e., secure terminals. The first terminal device has established a connection with a service system (such as service system 110), has logged into an application using a first user identifier in a secure manner, and is conducting a session with the service system in a secure state.
[0071] S310. The service system receives a first message sent by a first terminal device.
[0072] The first message includes a first user identifier, a second user identifier and encrypted data. The first user identifier indicates the first user. The first user logs in to the first application (such as welink) on the first terminal device in a secure manner with the first user identifier. The first application is running on the first terminal device, and the first terminal device sends the first message through the first application. The service system receives the first message sent by the first terminal device through the first application. The second user identifier indicates the second user. For example, the first user can be called a calling user, and the second user can be called a called user. The first user identifier can be a calling user identifier. The second user identifier can be a called user identifier.
[0073] Optionally, the first message also includes a first encryption identifier. The first encryption identifier is used to indicate that the first message contains encrypted data. The first encryption identifier can be set in the header of the first message. After receiving the first message from the first terminal device, the service system can determine, based on the first encryption identifier, that the first message contains encrypted data. Furthermore, the service system can determine that the first user indicated by the first user identifier is sending encrypted data to the second user indicated by the second user identifier.
[0074] S320: The service system determines, according to the second user identifier, a second terminal device bound to the second user identifier.
[0075] Figure 4 This is a flowchart of another secure communication method provided by this embodiment, wherein: Figure 4 The method flow described is to Figure 3 The specific operation process included in S320 is described as follows: S321. Determine at least one associated terminal device bound to the second user identifier according to the second user identifier.
[0076] If the second user registers the second application on the terminal device with the second user identifier, the service system receives the registration request from the terminal device and records the binding relationship between the device identifier and the second user identifier. After the service system receives the first message sent by the first terminal device, it can determine at least one associated terminal device bound to the second user identifier based on the second user identifier. This embodiment does not limit the number of associated terminal devices bound to the second user identifier. If the user has registered the second application with the second user identifier on a terminal device, the second user identifier is bound to the device identifier of the terminal device. If the user has registered the second application with the second user identifier on multiple terminal devices, the second user identifier is bound to the device identifiers of multiple terminal devices.
[0077] If the second user has not registered the second application on any terminal device with the second user ID, the service system cannot obtain the registration request from the terminal device and thus does not record the binding relationship between the device ID and the second user ID. After the service system receives the first message sent by the first terminal device, it cannot find the associated terminal device bound to the second user ID.
[0078] In an example, the binding relationship between the device ID and the user ID may be presented in a table, as shown in Table 1.
[0079] Table 1
[0080]
[0081] As shown in Table 1, User 1 is bound to Terminal 1, and User 2 is bound to Terminal 2, Terminal 3, and Terminal 4. Assuming the service system receives the user ID of User 2, the service system queries Table 1 based on User 2 to determine that the device IDs of the associated terminal devices bound to User 2 include Terminal 2, Terminal 3, and Terminal 4.
[0082] It should be noted that Table 1 only illustrates the storage form of the corresponding relationship in the storage device in the form of a table, and does not limit the storage form of the corresponding relationship in the storage device. Of course, the storage form of the corresponding relationship in the storage device can also be stored in other forms, and this embodiment does not limit this.
[0083] It is understandable that at least one associated terminal device bound to the second user identifier includes at least one of a secure terminal and a non-secure terminal. For example, all terminal devices bound to the second user identifier are secure terminals. For another example, all terminal devices bound to the second user identifier are non-secure terminals. For another example, the terminal devices bound to the second user identifier include secure terminals and non-secure terminals. Among them, the secure terminal is the implementation basis of the method provided in the embodiment of the present application. As described above, the secure terminal reports the device identification and security status information of the security terminal. The security status information is used to indicate whether the security terminal has called the encryption and decryption capabilities to run the second application.
[0084] like Figure 4 As shown, the method provided in this embodiment further includes step S410. S410: The service system receives a device identification and security status information sent by at least one security terminal. In some embodiments, the security terminal may periodically send the device identification and security status information to the service system.
[0085] Optionally, the service system may first send a reporting message to at least one security terminal (execute S410a). The reporting message is used to instruct the security terminal to report security status information and device identification. After receiving the reporting message, the security terminal sends the device identification and security status information to the service system. If the security terminal has logged into the application in a secure manner, the security status information indicates that the security terminal has invoked the encryption and decryption capabilities. If the security terminal has not logged into the application in a secure manner, the security status information indicates that the security terminal has not invoked the encryption and decryption capabilities. In some embodiments, the service system may periodically send reporting messages to at least one security terminal, and the security terminal sends the device identification and security status information to the service system.
[0086] The security status service in the service system stores records of the device identification and security status information of the security terminal. Therefore, the service system can determine the security terminal bound to the second user identifier based on the device identification recorded in the security status service and the identifier of the associated terminal device bound to the second user identifier, and then execute S322.
[0087] S322: Determine the security terminal bound to the second user identifier based on the identifier of at least one associated terminal device and the device identifier of at least one security terminal. Execute S323.
[0088] S323: Determine whether there is a security terminal that has invoked encryption and decryption capabilities based on the security status information of the security terminal bound to the second user identifier.
[0089] If there is a security terminal that has invoked encryption and decryption capabilities, the first message is sent to the security terminal. Assuming that the second terminal device has invoked encryption and decryption capabilities and runs the second application, the second terminal device is determined based on the security status information of the security terminal bound to the second user identifier, and S330 is executed.
[0090] S330: The service system sends a first message to the second terminal device. It should be understood that the second terminal device is a terminal device with encryption and decryption capabilities, that is, a secure terminal.
[0091] S340. The second terminal device receives the first message sent by the service system.
[0092] A first application is running on a first terminal device, and the first terminal device sends a first message via the first application. A second application is loaded on a second terminal device. Loading the second application on the second terminal device can also be described as installing the second application on the second terminal device. When the second terminal device invokes encryption and decryption capabilities to run the second application, the service system sends the first message to the second terminal device, and the second terminal device receives the first message sent by the service system via the second application.
[0093] It is worth noting that the first application and the second application are the same application. The so-called same application can be understood as the first application and the second application having the same name, and the first application and the second application communicating according to the same protocol. The functions implemented by the first application are the same as the functions implemented by the second application. The version of the installation package of the first application is different from the version of the installation package of the second application. Alternatively, the version of the installation package of the first application is the same as the version of the installation package of the second application. After the first application is installed on the first terminal device and the second application is installed on the second terminal device, the service system can determine the second terminal device bound to the second user identifier according to the method described in S321 to S323, so that the first terminal device communicates with the second application installed on the second terminal device through the first application.
[0094] In another possible design, the first application and the second application are different applications. Different applications can be understood as meaning that the first application and the second application have different names, and the first application and the second application communicate using a mutually recognizable protocol. The functions implemented by the first application and the second application are similar, or the functions implemented by the first application and the second application are different.
[0095] In some embodiments, the service system may also record user identifiers and terminal device identifiers for different applications. For example, if a first user registers a first application using a first terminal device using a first user identifier, and a second user registers a second application using a second terminal device using a second user identifier, the service system may also record the correspondence between the first user identifier, the first terminal device identifier, and the first application identifier. The service system may also record the correspondence between the second user identifier, the second terminal device identifier, and the second application identifier.
[0096] The first message also includes a second application identifier. The service system queries at least one associated terminal device bound to the second application identifier and the second user identifier, and determines the second terminal device bound to the second user identifier according to the method described in S322 to S323. Thus, the first terminal device communicates with the second application installed on the second terminal device through the first application.
[0097] In some embodiments, the service system can determine a security terminal that has invoked encryption and decryption capabilities and is running the second application based on security status information of the security terminal bound to the second user identifier, and the service system sends the first message to the security terminal.
[0098] In one example, the binding relationship between the device identification and security status information of the security terminal can be presented in a table format, that is, Table 2 presents the second corresponding relationship.
[0099] Table 2
[0100] Device identification Security status information Terminal 1 1 Terminal 2 1 Terminal 3 0 Terminal 4 0
[0101] As shown in Table 2, the security status information corresponding to Terminal 1 indicates that the encryption and decryption capabilities are being used to run the second application. The security status information corresponding to Terminal 2 indicates that the encryption and decryption capabilities are being used to run the second application. The security status information corresponding to Terminal 3 indicates that the encryption and decryption capabilities are not being used to run the second application. The security status information corresponding to Terminal 4 indicates that the encryption and decryption capabilities are not being used to run the second application.
[0102] Assume that the device identifiers of the security terminals bound to the second user identifier include Terminal 2, Terminal 3, and Terminal 4. The security status information corresponding to Terminal 2 indicates that the encryption and decryption capabilities are activated and the second application is running. The security status information corresponding to Terminal 3 and Terminal 4 indicates that the encryption and decryption capabilities are not activated and the second application is running. The service system identifies the security terminal indicated by Terminal 2 as the second terminal device, i.e., determines that the second terminal device is a terminal device that has activated the encryption and decryption capabilities and is running the second application, and executes S330, i.e., sends a first message to the second terminal device.
[0103] In other embodiments, the service system may determine, based on the security status information of the security terminal bound to the second user identifier, multiple security terminals that invoked encryption and decryption capabilities to run the second application. The service system may select any one of the multiple security terminals that invoked encryption and decryption capabilities to run the second application and send the first message to the security terminal. Alternatively, the service system may select the security terminal that most recently ran the second application and send the first message to the security terminal.
[0104] For example, as shown in Table 3, the security status information corresponding to Terminal 1 indicates that the encryption and decryption capabilities are activated and the second application is running. The security status information corresponding to Terminal 2 indicates that the encryption and decryption capabilities are activated and the second application is running. The security status information corresponding to Terminal 3 indicates that the encryption and decryption capabilities are activated and the second application is running. The security status information corresponding to Terminal 4 indicates that the encryption and decryption capabilities are not activated and the second application is running. This means that the called user has two devices with a security status of 1.
[0105] Table 3
[0106] Device identification Security status information Terminal 1 1 Terminal 2 1 Terminal 3 1 Terminal 4 0
[0107] Assume that the device identifiers of the security terminals bound to the second user identifier include Terminal 2, Terminal 3, and Terminal 4. The security status information corresponding to Terminal 2 and Terminal 3 indicates that the encryption and decryption capabilities are invoked to run the second application. The security status information corresponding to Terminal 4 indicates that the encryption and decryption capabilities are not invoked to run the second application. The service system selects a security terminal from the security terminals indicated by Terminal 2 and Terminal 3 as the second terminal device, i.e., determines that the second terminal device is a terminal device that has invoked the encryption and decryption capabilities to run the second application, and executes S330, i.e., sends a first message to the second terminal device. The second terminal device may be the terminal device that most recently ran the second application.
[0108] Optionally, the service system may also send obfuscated messages to other terminal devices (such as secure terminals or non-secure terminals) bound to the second user identifier in addition to the second terminal device. Obfuscated messages are randomly generated text messages that are not the actual encrypted and then decrypted message content sent.
[0109] In this way, because the security terminal reports its user ID, device ID, and security status information to the service system, the service system can determine a security terminal bound to the user ID based on the user ID and device ID. Furthermore, when the security terminal's security status information indicates that the security terminal has invoked encryption and decryption capabilities and run an application, the service system sends encrypted data to the security terminal. This effectively improves the accuracy of encrypted data sent by the service system to the security terminal, allowing users to accurately receive or view encrypted data, and enhancing the user experience during secure conversations.
[0110] For example, Figure 5 As shown in (a), when a first user initiates a video call with a second user, the security chip in the first terminal device encrypts the call request and sends a first message via the first application (S51). Service system 110 receives the first message. Call service 113 in service system 110 parses the first message and determines that it contains encrypted data based on the first encryption identifier (S52) (see explanation of S310). Based on the second user identifier, it determines at least one associated terminal device (S53) (see explanation of S321). Call service 113 interacts with security status service 112 to identify a second terminal device among the at least one associated terminal devices (S54) (see explanation of S410, S322, and S323). The second terminal device is a terminal device that has activated encryption and decryption capabilities and is running the second application. Call service 113 sends the first message to the second terminal device (S55) (see explanation of S330). The second terminal device receives the first message from service system 110 (see explanation of S340). At this point, because the second terminal device is a secure terminal, it can correctly decrypt the encrypted data. After the second user answers the call on the second terminal device, they can continue the conversation with the first user normally. Furthermore, if there are multiple secure terminals that have invoked encryption and decryption capabilities and are running the second application, call service 113 does not send the first message to any secure terminals other than the second terminal device. Call service 113 also does not send the first message to any non-secure terminals.
[0111] like Figure 5As shown in (b), when a first user sends a chat message to a second user, the security chip in the first terminal device encrypts the chat message and sends the first message through the first application (execution S51), which is then received by the service system 110. The message service 114 in the service system 110 parses the first message and determines that the first message contains encrypted data based on the first encryption identifier (execution S52) (refer to the explanation of S310). It then determines at least one associated terminal device based on the second user identifier (execution S53) (refer to the explanation of S321). The message service 114 interacts with the security status service 112 to determine the second terminal device among the at least one associated terminal device (execution S54) (refer to the explanation of S410, S322, and S323). The message service 114 sends the first message to the second terminal device (execution S55) (refer to the explanation of S330). At this point, since the second terminal device is a secure terminal, it can correctly decrypt the encrypted data and obtain the chat message. Optionally, if there are multiple secure terminals that have invoked encryption and decryption capabilities and are running the second application, the message service 114 may also send obfuscated messages to other secure terminals except the second terminal device (execution S56).
[0112] like Figure 4 As shown, if it is determined based on the security status information of the security terminal bound to the second user identifier that no security terminal that has invoked encryption and decryption capabilities exists, a determination is made as to whether the security terminal bound to the second user identifier is running the second application. Exemplarily, the determination as to whether the security terminal bound to the second user identifier is running the second application can be made by querying the login information in the login service. Therefore, the service system can execute S420, i.e., determine based on the login information of the security terminal bound to the second user identifier whether a security terminal is running the second application. The login information includes the login time of the security terminal bound to the second user identifier.
[0113] If it is determined based on the login information of the security terminal bound to the second user identifier that the second terminal device has run the second application and has not called the encryption and decryption capabilities, S430 is executed.
[0114] S430: The service system sends a first instruction message to the second terminal device. The first instruction message is used to instruct the second terminal device to exit the second application and invoke encryption and decryption capabilities to re-run the second application.
[0115] In one possible design, the first indication message includes a second encryption identifier, which is used to instruct the second terminal device to exit the second application and invoke the encryption and decryption capabilities to re-run the second application. Alternatively, the second encryption identifier can be used to instruct the second terminal device to exit the second application logged in with the second user identifier and invoke the security capability to log in to the second application with the second user identifier. The second encryption identifier can be set in the payload of the first indication message.
[0116] S440. The second terminal device receives a first indication message sent by the service system.
[0117] S450: The second terminal device exits the second application, invokes encryption and decryption capabilities, and re-runs the second application.
[0118] Furthermore, the second terminal device reports its device identification and security status information to the service system. S410 is then executed. At this point, the security status information of the second terminal device indicates that the second terminal device has invoked encryption and decryption capabilities to run the second application. If the service system receives encrypted data from the first terminal device again, the service system can determine the second terminal device bound to the second user identification based on the second user identification. If it is determined that the second terminal device has invoked encryption and decryption capabilities to run the second application, the service system sends the encrypted data to the second terminal device.
[0119] In some embodiments, the service system determines a security terminal that has not invoked encryption and decryption capabilities and has run the second application based on the login information of the security terminal bound to the second user identifier, and the service system sends a first indication message to the security terminal.
[0120] In other embodiments, the service system may determine, based on the login information of the security terminal bound to the second user identifier, multiple security terminals that have not invoked encryption and decryption capabilities and are running the second application. The service system may select any one of the multiple security terminals that have not invoked encryption and decryption capabilities and are running the second application and send the first indication message to the security terminal. Alternatively, the service system may select the security terminal that most recently ran the second application and send the first indication message to the security terminal.
[0121] For example, as shown in Table 4, the security status information corresponding to terminal 1 indicates that the encryption and decryption capabilities have been invoked to run the second application. The security status information corresponding to terminal 2 indicates that the encryption and decryption capabilities have not been invoked to run the second application. The security status information corresponding to terminal 3 indicates that the encryption and decryption capabilities have not been invoked to run the second application. The security status information corresponding to terminal 4 indicates that the encryption and decryption capabilities have not been invoked to run the second application.
[0122] Table 4
[0123]
[0124]
[0125] Assume that the device identities of the security terminals bound to the second user identity include terminal 2, terminal 3, and terminal 4. Since the security status information corresponding to terminal 2, terminal 3, and terminal 4 all indicates that the encryption and decryption capabilities are not invoked.
[0126] If the login information of the security terminal indicated by terminal 2 indicates that the second application is running, and the login information of the security terminals indicated by terminal 3 and terminal 4 both indicate that the second application is not running, the service system uses the security terminal indicated by terminal 2 as the second terminal device and sends a first indication message to the second terminal device.
[0127] If the login information of the security terminals indicated by Terminal 2, Terminal 3, and Terminal 4 all indicate that the second application is running, the service system selects a security terminal from the security terminals indicated by Terminal 2, Terminal 3, and Terminal 4 as the second terminal device, i.e., determines that the second terminal device is a terminal device that has not invoked encryption and decryption capabilities and is running the second application, and sends a first indication message to the second terminal device. The second terminal device may be the terminal device that most recently ran the second application.
[0128] In this way, because the security terminal reports its user ID, device ID, and security status information to the service system, the service system can determine a security terminal bound to the user ID based on the user ID and device ID. Furthermore, if the security terminal's security status information indicates that the security terminal is running a second application but not invoking encryption and decryption capabilities, the service system instructs the security terminal to exit the second application, invoke encryption and decryption capabilities, and re-run the second application, allowing the service system to send encrypted data to the security terminal. This effectively improves the accuracy of encrypted data sent by the service system to the security terminal, allowing users to accurately receive or view encrypted data, and enhancing the user's secure conversation experience.
[0129] For example, Figure 6As shown in FIG, when a first user initiates a video call with a second user, the security chip in the first terminal device encrypts the call request and sends a first message via the first application (S61). Service system 110 receives the first message. Call service 113 in service system 110 parses the first message and determines that the first message contains encrypted data based on the first encryption identifier (S62) (see explanation of S310). Based on the second user identifier, it determines at least one associated terminal device (S63) (see explanation of S321). Call service 113 interacts with security status service 112 to determine a second terminal device among the at least one associated terminal devices (S64) (see explanation of S410, S322, S323, and S420). The second terminal device is a terminal device that has not activated encryption and decryption capabilities and is running the second application. Call service 113 sends a first indication message to the second terminal device (S65) (see explanation of S430). At this point, because the second terminal device is a secure terminal, it can correctly decrypt the encrypted data. After the second terminal device receives the first indication message from the call service 113, it exits the second application and calls the encryption and decryption capabilities to re-run the second application, that is, it exits the second application logged in with the second user ID and calls the encryption and decryption capabilities to log in to the second application with the second user ID (execute S66) (refer to the explanation of S450). Furthermore, the second terminal device sends the security status information of the second terminal device and the device ID of the second terminal device to the security status service 112 (execute S67). The security status service 112 records the binding relationship between the security status information of the second terminal device and the device ID of the second terminal device (execute S68). The call service 113 queries the security status information of the second terminal device to indicate that the second terminal device has called the encryption and decryption capabilities to run the second application, sends the first message to the second terminal device (execute S69), and the second terminal device receives the first message from the service system 110 (refer to the explanation of S340). After the second user answers the second terminal device, he can have a normal conversation with the first user. The call service 113 can also be replaced by the message service 114.
[0130] like Figure 4 As shown, when the service system executes S420, that is, based on the login information of the security terminal bound to the second user identifier, it determines whether there is a security terminal running the second application. If it is determined based on the login information of the security terminal bound to the second user identifier that none of the security terminals bound to the second user identifier are running the second application and the encryption and decryption capabilities have not been invoked, a second indication message is sent to the push server. The login information includes the exit time of the security terminal bound to the second user identifier. If the security terminal bound to the second user identifier exits the second application, the security terminal bound to the second user identifier will report the exit time to the service system.
[0131] Assuming that the second terminal device is not running the second application and has not called the encryption and decryption capabilities, execute S460.
[0132] S460: The service system sends a second instruction message to the push server. The second instruction message is used to instruct the second terminal device to invoke encryption and decryption capabilities to run the second application. The second instruction message includes an identifier of the second terminal device.
[0133] In one possible design, the second indication message includes a third encryption identifier, which is used to instruct the second terminal device to invoke the encryption and decryption capability to run the second application. Alternatively, the third encryption identifier can be used to instruct the second terminal device to invoke the security capability to log in to the second application using the second user identifier. The third encryption identifier can be set in the payload of the second indication message.
[0134] It should be noted that the push service system is a service system deployed by the manufacturer of the second terminal device. Sending the second indication message to the push service system may be implemented by the push service 115 in the service system 110 .
[0135] S470. The push server sends a second indication message to the second terminal device.
[0136] S480. The second terminal device receives a second indication message sent by the push server.
[0137] S490: The second terminal device invokes encryption and decryption capabilities to run the second application.
[0138] Furthermore, the second terminal device reports its device identification and security status information to the service system. S410 is then executed. At this point, the security status information of the second terminal device indicates that the second terminal device has invoked encryption and decryption capabilities to run the second application. If the service system receives encrypted data from the first terminal device again, the service system can determine the second terminal device bound to the second user identification based on the second user identification. Once it is determined that the second terminal device has invoked encryption and decryption capabilities to run the second application, the service system sends the encrypted data to the second terminal device.
[0139] In this way, because the security terminal reports its user ID, device ID, and security status information to the service system, the service system can determine a security terminal bound to the user ID based on the user ID and device ID. Furthermore, if the security terminal's security status information indicates that the security terminal has not invoked encryption and decryption capabilities and is not running the second application, the service system instructs the security terminal to invoke encryption and decryption capabilities and run the second application, allowing the service system to send encrypted data to the security terminal. This effectively improves the accuracy of encrypted data sent by the service system to the security terminal, allowing users to accurately receive or view encrypted data, and enhancing the user's secure conversation experience.
[0140] For example, Figure 7 As shown, when a first user initiates a video call with a second user, the security chip in the first terminal device encrypts the call request and sends a first message via the first application (S71). Service system 110 receives the first message. Call service 113 in service system 110 parses the first message and determines that it contains encrypted data based on the first encryption identifier (S72) (see explanation of S310). It then determines at least one associated terminal device based on the second user identifier (S73) (see explanation of S321). Call service 113 interacts with security status service 112 to determine a second terminal device among the at least one associated terminal devices (S74) (see explanation of S410, S322, S323, and S420). The second terminal device is not running the second application and has not invoked encryption and decryption capabilities. Call service 113 then sends a second indication message to push service 115 (S75). Push service 115 then sends the second indication message to the push server (S76) (see explanation of S460). The push service system sends a second indication message to the second terminal device (execute S77) (refer to the explanation of S470). At this time, since the second terminal device is a terminal device with encryption capabilities, it can correctly decrypt the encrypted data. After the second terminal device receives the second indication message from the push service system, it calls the encryption and decryption capabilities to run the second application, that is, calls the encryption and decryption capabilities to log in to the second application with the second user identifier (execute S78) (refer to the explanation of S490). The second terminal device sends the security status information of the second terminal device and the device identifier of the second terminal device to the security status service 112 (execute S79). The security status service 112 records the binding relationship between the security status information of the second terminal device and the device identifier of the second terminal device (execute S710). The call service 113 queries the security status information of the second terminal device to indicate that the second terminal device has called the encryption and decryption capabilities to run the second application, sends the first message to the second terminal device (execute S711), and the second terminal device receives the first message from the service system 110. After the second user answers the second terminal device, he can have a normal call with the first user.
[0141] In the above embodiment, all associated terminal devices bound to the second user identifier are first determined. A security terminal bound to the second user identifier is then selected from the associated terminal devices. Finally, based on the security status information of the security terminal bound to the second user identifier, the security terminal that has invoked encryption and decryption capabilities and is running the second application is determined, and encrypted data is sent to the security terminal. This embodiment does not explicitly limit the order of these three steps.
[0142] For example, you can first select a security terminal running the second application from the associated terminal devices bound to the second user identifier, and then select a security terminal that calls the encryption and decryption capabilities to run the second application from the security terminals running the second application, and send encrypted data to the security terminal.
[0143] It is understood that in order to implement the functions in the above embodiments, the server and terminal device include hardware structures and / or software modules corresponding to the execution of each function. It should be readily apparent to those skilled in the art that, in combination with the units and method steps of each example described in the embodiments disclosed in this application, this application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in hardware or in a manner driven by computer software depends on the specific application scenario and design constraints of the technical solution.
[0144] Figure 8 Schematic diagram of the structure of possible communication devices provided in the embodiments of the present application. These communication devices can be used to implement the functions of the terminal device or server in the above method embodiments, and thus can also achieve the beneficial effects of the above method embodiments. In the embodiments of the present application, the communication device can be as follows: Figure 1 The terminal device 120 shown may also be Figure 1 The server 111 shown may also be a module (such as a chip) applied to a terminal device or a server.
[0145] like Figure 8 As shown, the communication device 800 includes a processing unit 810 and a transceiver unit 820. The communication device 800 is used to implement the above Figure 3 or Figure 4 The functions of the terminal device or service system in the method embodiment shown in FIG.
[0146] When the communication device 800 is used to implement Figure 3 In the illustrated method embodiment, the service system functions as follows: the processing unit 810 is configured to execute S320 ; the transceiver unit 820 is configured to execute S310 and S330 .
[0147] When the communication device 800 is used to implement Figure 4 In the method embodiment shown, the function of the service system is as follows: the processing unit 810 is used to execute S321 to S323 and S420; the transceiver unit 820 is used to execute S310, S410, S410a, S330, S430 and S460.
[0148] When the communication device 800 is used to implement Figure 4 In the method embodiment shown, the functions of the second terminal device are: the processing unit 810 is used to execute S450 and S490; the transceiver unit 820 is used to execute S340, S440 and S480.
[0149] For more detailed description of the processing unit 810 and the transceiver unit 820, please refer to Figure 3 or Figure 4 The relevant description in the method embodiment shown is directly obtained and will not be repeated here.
[0150] like Figure 9 As shown, communication device 900 includes a processor 910 and an interface circuit 920. Processor 910 and interface circuit 920 are coupled to each other. It will be appreciated that interface circuit 920 may be a transceiver or an input / output interface. Optionally, communication device 900 may further include a memory 930 for storing instructions executed by processor 910, input data required by processor 910 to execute instructions, or data generated after processor 910 executes instructions.
[0151] When the communication device 900 is used to implement Figure 3 or Figure 4 When performing the method shown, the processor 910 is used to execute the functions of the processing unit 810, and the interface circuit 920 is used to execute the functions of the transceiver unit 820.
[0152] It is understood that the processor in the embodiments of the present application may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.
[0153] The method steps in the embodiments of the present application can be implemented by hardware or by a processor executing software instructions. The software instructions can be composed of corresponding software modules, which can be stored in random access memory (RAM), flash memory, read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), registers, hard disks, mobile hard disks, CD-ROMs, or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be an integral part of the processor. The processor and storage medium can be located in an ASIC. In addition, the ASIC can be located in a network device or a terminal device. Of course, the processor and storage medium can also exist as discrete components in a network device or a terminal device.
[0154] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware or any combination thereof. When implemented using software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the process or function described in the embodiments of the present application is performed in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device or other programmable device. The computer program or instruction can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer program or instruction can be transmitted from one website, computer, server or data center to another website, computer, server or data center via wired or wireless means. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium, such as a floppy disk, a hard disk, or a tape; it can also be an optical medium, such as a digital video disc (DVD); it can also be a semiconductor medium, such as a solid state drive (SSD).
[0155] In the various embodiments of the present application, unless otherwise specified or there is a logical conflict, the terms and / or descriptions between different embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.
[0156] In this application, "at least one" means one or more, and "more" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. In the text description of this application, the character " / " generally indicates that the previous and next associated objects are in an "or" relationship; in the formulas of this application, the character " / " indicates that the previous and next associated objects are in a "division" relationship.
[0157] It is understood that the various numbers used in the embodiments of this application are merely for ease of description and are not intended to limit the scope of the embodiments of this application. The order of the sequence numbers of the above-mentioned processes does not necessarily imply a specific order of execution; the order of execution of the processes should be determined by their functions and inherent logic.
Claims
1. A secure communication method, characterized in that: include: Receiving security status information and a device identification sent by at least one terminal device with encryption and decryption capabilities, the security status information being used to indicate whether the terminal device has invoked encryption and decryption capabilities to run a second application, the terminal device with encryption and decryption capabilities including the second terminal device; receiving a first message sent by a first terminal device, wherein the first message includes a called user identifier and encrypted data; Determining, according to the called user identity, a second terminal device bound to the called user identity, where the second terminal device is a terminal device with encryption and decryption capabilities; The first message is sent to the second terminal device only when the second terminal device calls the encryption and decryption capabilities.
2. The method according to claim 1, characterized in that A first application is run on the first terminal device, wherein the first terminal device sends the first message through the first application; and The second terminal device is loaded with the second application. When the second terminal device calls the encryption and decryption capabilities to run the second application, the first message is sent to the second terminal device, and the first application and the second application can communicate with each other.
3. The method according to claim 2, characterized in that Before sending the first message to the second terminal device, the method further includes: When the second terminal device runs the second application and does not call the encryption and decryption capabilities, a first indication message is sent to the second terminal device, where the first indication message is used to instruct the second terminal device to exit the second application and call the encryption and decryption capabilities to re-run the second application.
4. The method according to claim 2, characterized in that Before sending the first message to the second terminal device, the method further includes: When the second terminal device is not running the second application and has not called the encryption and decryption capabilities, a second indication message is sent to the push server, where the second indication message is used to instruct the second terminal device to call the encryption and decryption capabilities to run the second application, and the second indication message includes an identifier of the second terminal device.
5. The method according to claim 1, wherein Before receiving the security status information and device identification sent by at least one terminal device having encryption and decryption capabilities, the method further includes: A reporting message is sent to the terminal device with encryption and decryption capabilities, where the reporting message is used to instruct the terminal device with encryption and decryption capabilities to report the security status information and the device identifier.
6. The method according to claim 1, characterized in that Determining a second terminal device bound to the called user identity according to the called user identity includes: determining, according to the called user identity, at least one associated terminal device bound to the called user identity, the at least one associated terminal device including the second terminal device; The second terminal device is determined according to the identifier of the at least one associated terminal device and the device identifier of the at least one terminal device having encryption and decryption capabilities.
7. The method according to claim 1, characterized in that The method further comprises: Determine whether the second terminal device has invoked encryption and decryption capabilities based on the security status information of the second terminal device.
8. The method according to claim 6 or 7, characterized in that If the encrypted data is a chat message, the method further includes: Sending a confusing message to a terminal device other than the second terminal device in the at least one associated terminal device.
9. The method according to claim 1, characterized in that The terminal device with encryption and decryption capabilities is a terminal device carrying a security chip.
10. A secure communication method, characterized in that: include: receiving an instruction message, the instruction message being used to instruct a terminal device to invoke encryption and decryption capabilities to run an application, the terminal device being a terminal device with encryption and decryption capabilities, and the terminal device with encryption and decryption capabilities being a terminal device carrying a security chip; Invoke encryption and decryption capabilities to run the application; Sending security status information and a device identifier, wherein the security status information is used to indicate that the terminal device has invoked encryption and decryption capabilities to run the application; A first message is received, the first message including encrypted data.
11. The method according to claim 10, characterized in that The calling of the encryption and decryption capabilities to run the application includes: Exit the application, call the encryption and decryption capabilities and re-run the application.
12. The method according to claim 11, characterized in that The method further comprises: A reporting message is received, where the reporting message is used to instruct the terminal device with encryption and decryption capabilities to report the security status information and the device identification.
13. A communication device, characterized in that: include: a transceiver unit, configured to receive a first message sent by a first terminal device, wherein the first message includes a called user identifier and encrypted data; The transceiver unit is further configured to receive security status information and a device identifier sent by at least one terminal device with encryption and decryption capabilities, wherein the security status information is used to indicate whether the terminal device has invoked the encryption and decryption capabilities to run the second application, and the terminal device with encryption and decryption capabilities includes the second terminal device; a processing unit, configured to determine, according to the called user identity, a second terminal device bound to the called user identity, where the second terminal device is a terminal device having encryption and decryption capabilities; The transceiver unit is further configured to send the first message to the second terminal device only when the second terminal device invokes encryption and decryption capabilities.
14. The device according to claim 13, characterized in that A first application is run on the first terminal device, wherein the first terminal device sends the first message through the first application; and The second terminal device is loaded with the second application. When the second terminal device calls the encryption and decryption capabilities to run the second application, the first message is sent to the second terminal device, and the first application and the second application can communicate with each other.
15. The device according to claim 14, characterized in that The transceiver unit is also used to send a first indication message to the second terminal device when the second terminal device runs the second application and does not call the encryption and decryption capabilities. The first indication message is used to instruct the second terminal device to exit the second application and call the encryption and decryption capabilities to re-run the second application.
16. The device according to claim 14, characterized in that The transceiver unit is also used to send a second indication message to the push server when the second terminal device is not running the second application and has not called the encryption and decryption capabilities. The second indication message is used to instruct the second terminal device to call the encryption and decryption capabilities to run the second application. The second indication message includes the identifier of the second terminal device.
17. The device according to claim 13, characterized in that The transceiver unit is further configured to send a reporting message to the terminal device with encryption and decryption capabilities, wherein the reporting message is configured to instruct the terminal device with encryption and decryption capabilities to report the security status information and the device identifier.
18. The device according to claim 13, characterized in that When the processing unit determines the second terminal device bound to the called user identity according to the called user identity, it is specifically configured to: determining, according to the called user identity, at least one associated terminal device bound to the called user identity, the at least one associated terminal device including the second terminal device; The second terminal device is determined according to the identification of the at least one associated terminal device and the identification of the at least one terminal device with encryption and decryption capabilities.
19. The device according to claim 13, characterized in that The processing unit is further configured to determine whether the second terminal device has invoked encryption and decryption capabilities based on the security status information of the second terminal device.
20. The device according to claim 18 or 19, characterized in that If the encrypted data is a chat message, The transceiver unit is further configured to send a confusion message to a terminal device other than the second terminal device in the at least one associated terminal device.
21. The device according to claim 13, characterized in that The terminal device with encryption and decryption capabilities is a terminal device carrying a security chip.
22. A communication device, characterized in that: include: a transceiver unit, configured to receive an instruction message, wherein the instruction message is used to instruct a terminal device to invoke encryption and decryption capabilities to run an application, wherein the terminal device is a terminal device with encryption and decryption capabilities, and the terminal device with encryption and decryption capabilities is a terminal device carrying a security chip; A processing unit, configured to invoke encryption and decryption capabilities to run the application; The transceiver unit is further configured to send security status information and a device identifier, wherein the security status information is used to indicate that the terminal device has invoked encryption and decryption capabilities to run the application; The transceiver unit is further configured to receive a first message, where the first message includes encrypted data.
23. The device according to claim 22, characterized in that When the processing unit calls the encryption and decryption capabilities to run the application, it is specifically used to: Exit the application, call the encryption and decryption capabilities and re-run the application.
24. The device according to claim 23, characterized in that The transceiver unit is further configured to receive a reporting message, wherein the reporting message is configured to instruct the terminal device having encryption and decryption capabilities to report the security status information and the device identification.
25. A server, characterized in that: The server includes at least one memory and at least one processor, wherein the at least one memory is used to store a set of computer instructions; when the at least one processor executes the set of computer instructions, the server executes the method described in any one of claims 1 to 9.
26. A terminal device, characterized in that: The terminal device includes at least one memory and at least one processor, wherein the at least one memory is used to store a set of computer instructions; when the at least one processor executes the set of computer instructions, the terminal device executes the method described in any one of claims 10 to 12.
Citation Information
Patent Citations
Data processing method and device
CN110138765A
Dual-connection communication method, and device and system thereof
CN110830992A