A Simplified Data Encryption and Decryption Method and Transmission System

By simplifying digital certificate technology and simplifying digital envelope technology, IoT devices are solved by large power consumption, complex protocols and insufficient equipment resources in data encryption transmission, and safe and efficient data transmission is achieved.

CN115333739BActive Publication Date: 2025-06-13TIANJIN CIST SOFTWARE TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210965636.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-12
Publication Date
2025-06-13
Estimated Expiration
2042-08-12

AI Technical Summary

Technical Problem

When IoT devices conduct data encryption transmission, they have problems such as large power consumption, complex protocols and insufficient equipment resources, which are difficult to meet the security needs of small devices.

Method used

Using a simplified data encryption and decryption method, data encryption and transmission is carried out through simplified digital certificate technology and simplified digital envelope technology, and data is directly encrypted using asymmetric keys to reduce the demand for computing and transmission resources.

Benefits of technology

It realizes simple protocol, simple certificate analysis, short data, relatively small computing power consumption and transmission power consumption, reduces the requirements for device resources and ensures the security of data transmission of IoT devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115333739B_ABST
    Figure CN115333739B_ABST
Patent Text Reader

Abstract

The present invention relates to a simplified data encryption and decryption method and transmission system, belonging to the technical field of Internet of Things security applications. According to the first simplified digital certificate serial number of the first module that executes the decryption step, the first public key of the first module is obtained from the certificate management system module, and the plaintext data is encrypted using the first public key to obtain ciphertext data. A digest operation is performed on the ciphertext data to obtain a digest value, and the digest value is signed using the second private key of the second module that executes the encryption step to obtain signature data. A corresponding decryption method is also designed accordingly. In the above manner, simplified digital certificate technology and simplified digital envelope technology are used for data encrypted transmission. Its protocol is simple, certificate parsing is simple, and the data is short. The asymmetric key is used to directly encrypt the data, and the operation power consumption and transmission power consumption are relatively small, reducing the requirements for device resources and solving the problems of large technical power consumption, complex protocol, and insufficient device resources.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of Internet of Things security applications, and particularly to a simplified data encryption and decryption method and transmission system. Background Art

[0002] In recent years, the IoT technology has developed rapidly. The hardware intelligence is an irresistible future trend, and the era of the Internet of Things with everything interconnected is coming. While people enjoy the convenience of the network, the network security problems are becoming increasingly prominent. In reality, the server stores the data resources required by the client, and the client needs to initiate a data request to the server to obtain the data resources of the server. The data resources stored in the server include data information with different security levels. If the data information with a high security level is transmitted in plain text, some security risks will be caused. Therefore, currently, the technology of implementing information encrypted transmission based on the SSL / TLS protocol is often adopted to ensure the security of data transmission. SSL / TLS is a cryptographic communication framework and is the most widely used cryptographic communication method in the world. SSL / TLS comprehensively uses symmetric cryptography, message authentication code, public key cryptography, digital signature, pseudo-random number generator, etc. in cryptography and is a masterpiece in cryptography. The SSL / TLS protocol includes the SSL / TLS handshake layer protocol and the SSL / TLS record layer protocol. The SSL / TLS handshake layer protocol is built on the SSL / TLS record layer protocol and is used for the communication parties to authenticate their identities, negotiate security parameters such as keys and encryption algorithms, and exchange keys before the actual data transmission starts; the SSL / TLS record layer protocol is built on a reliable transport protocol (such as TCP (Transmission Control Protocol)) and is used to provide support for basic functions such as data segmentation, encapsulation, compression and decompression, encryption and decryption for higher-layer protocols.

[0003] However, with the continuous increase of IoT application scenarios, the following problems of this technology need to be solved urgently:

[0004] (1) This technology requires more computing and transmission resources, has high power consumption and a complex protocol during operation:

[0005] When using this technology for data encrypted transmission, an SSLVPN connection needs to be created first. After the connection, the client uses a higher-layer protocol to request data from the server. The client and the server need to negotiate a symmetric key and an encryption algorithm through the SSL / TLS handshake layer protocol first, and then encrypt the requested data through the SSL / TLS record layer protocol and transmit it. Therefore, this technology requires more computing and transmission resources, has high power consumption and a complex protocol.

[0006] (2) The resources of IoT access devices themselves are limited and are not sufficient to deploy the SSL / TLS protocol:

[0007] With the continuous development of the Internet of Things, the access device resources show fragmented characteristics. Some small devices have relatively small storage space, which cannot meet the device resource requirements for deploying the SSL / TLS protocol, resulting in certain security risks.

[0008] To solve the above problems, there is an urgent need for a technology with low power consumption, simple protocol, and small device resource occupancy. Summary of the Invention

[0009] The purpose of the present invention is to provide a simplified data encryption and decryption method and transmission system to solve the problems of high power consumption, complex protocol, and insufficient device resources in the technology.

[0010] To achieve the above purpose, the present invention provides the following solutions:

[0011] A simplified data encryption method, the encryption method includes an encryption authentication step and an encryption step;

[0012] The encryption authentication step includes:

[0013] According to the first simplified digital certificate serial number of the first module that executes the decryption step, obtain the first public key of the first module from the certificate management system module; the certificate management system module is pre - installed with the first simplified digital certificate of the first module; the first simplified digital certificate includes the first simplified digital certificate serial number and the first public key;

[0014] The encryption step includes:

[0015] Encrypt the plaintext data using the first public key to obtain ciphertext data; perform a digest operation on the ciphertext data to obtain a digest value; sign the digest value using the second private key of the second module that executes the encryption step to obtain signature data; the ciphertext data and the signature data form the encrypted data.

[0016] A simplified data decryption method, the decryption method includes a decryption authentication step and a decryption step;

[0017] The decryption authentication step includes:

[0018] According to the second simplified digital certificate serial number of the second module that executes the encryption step, obtain the second public key of the second module from the certificate management system module; the certificate management system module is pre - installed with the second simplified digital certificate of the second module; the second simplified digital certificate includes the second simplified digital certificate serial number and the second public key;

[0019] The decryption step includes:

[0020] Decrypt the signature data using the second public key to obtain a first digest value; perform a digest operation on the ciphertext data to obtain a second digest value; if the first digest value is consistent with the second digest value, decrypt the ciphertext data using the first private key of the first module that executes the decryption step to obtain the plaintext data.

[0021] A simplified data encryption and decryption transmission system, the encryption and decryption transmission system includes a device - end module, a gateway module, a server - end module, and a certificate management system module; the device - end module is communicatively connected to the server - end module through the gateway module; the device - end module, the gateway module, and the server - end module are all communicatively connected to the certificate management system module, and the certificate management system module is pre - installed with simplified digital certificates of the device - end module, the gateway module, and the server - end module;

[0022] When the device - end module reports data to the server - end module:

[0023] The device - end module is used to execute the above - mentioned encryption authentication step and encryption step to obtain encrypted data, and transmit the encrypted data to the gateway module; the gateway module is used to execute the above - mentioned decryption authentication step and decryption step to obtain plaintext data, and transmit the plaintext data to the server - end module;

[0024] The device - end module is used to execute the above - mentioned encryption authentication step and encryption step to obtain encrypted data, and forward the encrypted data to the server - end module through the gateway module; the server - end module is used to execute the above - mentioned decryption authentication step and decryption step to obtain plaintext data;

[0025] Or, the device - end module is used to execute the above - mentioned encryption authentication step and encryption step to obtain encrypted data, and transmit the encrypted data to the gateway module; the server - end module is used to execute the above - mentioned decryption authentication step; the gateway module is used to execute the above - mentioned decryption step to obtain plaintext data, and transmit the plaintext data to the server - end module;

[0026] When the server - end module sends data to the device - end module:

[0027] The server - end module is used to transmit plaintext data to the gateway module; the gateway module is used to execute the above - mentioned encryption authentication step and encryption step to obtain encrypted data, and transmit the encrypted data to the device - end module; the device - end module is used to execute the above - mentioned decryption authentication step and decryption step to obtain the plaintext data;

[0028] The server module is used to execute the above encryption authentication step and encryption step to obtain encrypted data, and forward the encrypted data to the device module through the gateway module; the device module is used to execute the above decryption authentication step and decryption step to obtain plaintext data;

[0029] Alternatively, the server module is used to transmit plaintext data to the gateway module and execute the above encryption authentication step; the gateway module is used to execute the above encryption step to obtain encrypted data, and transmit the encrypted data to the device module; the device module is used to execute the above decryption authentication step and decryption step to obtain plaintext data.

[0030] According to the specific embodiments provided by the present invention, the following technical effects are disclosed by the present invention:

[0031] The present invention is used to provide a simplified data encryption and decryption method and transmission system. According to the first simplified digital certificate serial number of the first module that executes the decryption step, the first public key of the first module is obtained from the certificate management system module, and the plaintext data is encrypted using the first public key to obtain ciphertext data. A digest operation is performed on the ciphertext data to obtain a digest value, and the digest value is signed using the second private key of the second module that executes the encryption step to obtain signature data. A corresponding decryption method is designed accordingly. In the above manner, the present invention uses simplified digital certificate technology and simplified digital envelope technology for data encryption and transmission. Its protocol is simple, certificate parsing is simple, and data is short. It directly encrypts data using asymmetric keys, and the operation power consumption and transmission power consumption are relatively small, reducing the requirements for device resources. Moreover, it provides guarantees for security requirements such as two-way authentication, encrypted transmission, non-repudiation, and anti-tampering during the data transmission of small devices, and solves the problems of large technical power consumption, complex protocols, and insufficient device resources. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0033] Figure 1 It is a principle block diagram of the simplified digital envelope technology of the present invention;

[0034] Figure 2 It is a method flow chart of the encryption method provided in Embodiment 1 of the present invention;

[0035] Figure 3 It is a method flow chart of the decryption method provided in Embodiment 2 of the present invention;

[0036] Figure 4 It is the overall structure diagram of the encryption and decryption transmission system provided in Embodiment 3 of the present invention;

[0037] Figure 5 It is the overall structure diagram of the encryption and decryption transmission system when the server module provided in Embodiment 3 of the present invention does not have authentication and encryption / decryption functions;

[0038] Figure 6 It is the data reporting flow chart when the server module provided in Embodiment 3 of the present invention does not have authentication and encryption / decryption functions;

[0039] Figure 7 It is the data distribution flow chart when the server module provided in Embodiment 3 of the present invention does not have authentication and encryption / decryption functions;

[0040] Figure 8 It is the overall structure diagram of the encryption and decryption transmission system when the server module provided in Embodiment 3 of the present invention has authentication and encryption / decryption functions;

[0041] Figure 9 It is the data reporting flow chart when the server module provided in Embodiment 3 of the present invention has authentication and encryption / decryption functions;

[0042] Figure 10 It is the overall structure diagram of the encryption and decryption transmission system when the server module provided in Embodiment 3 of the present invention has authentication function but does not have encryption / decryption function;

[0043] Figure 11 It is the data reporting flow chart when the server module provided in Embodiment 3 of the present invention has authentication function but does not have encryption / decryption function. Detailed implementation manners

[0044] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0045] The purpose of the present invention is to provide a simplified data encryption and decryption method and transmission system to solve the problems of high technical power consumption, complex protocol, and insufficient device resources.

[0046] To make the above objects, features, and advantages of the present invention more obvious and understandable, the present invention will be further described in detail below in conjunction with the accompanying drawings and specific implementation manners.

[0047] In view of the problems of high power consumption, complex protocols, and insufficient device resources in the prior art proposed in the background art, the present invention can provide a method for solving the above problems by combining simplified digital certificate technology, simplified digital envelope technology, and a public key infrastructure (PKI) certificate system. It can be applied to the scenario of encrypted transmission of Internet of Things devices and meet the security requirements such as two-way authentication, encrypted transmission, non-repudiation, and anti-tampering of Internet of Things devices.

[0048] Here, the simplified digital certificate technology and simplified digital envelope technology used in the present invention will be introduced first:

[0049] Simplified digital certificate technology: The simplified structure of the simplified digital certificate includes a simplified digital certificate serial number, a public key, module information (including device-side information), the application industry, and CA signature data. Only the simplified digital certificate serial number needs to be pre-set. When the simplified digital certificate is needed, a request is sent to the certificate management system module. Then, the certificate management system module finds the corresponding simplified digital certificate by querying the simplified digital certificate serial number, obtains the information of the simplified digital certificate (including the simplified digital certificate serial number, public key, module information, application industry, and CA signature data), and sends the required information back to the requester. Using the simplified digital certificate technology during device filling can reduce the consumption of device resources.

[0050] Simplified digital envelope technology: As Figure 1As shown, it describes the basic process of data encryption and decryption transmission using the simplified digital envelope technology. When the local device and the peer device use the simplified digital envelope technology for data encryption transmission, the data encryption and decryption process from the local device to the peer device is as follows: (1) Encryption process of the local device: First, encrypt the data using the peer public key to obtain ciphertext data; then perform a digest operation on the ciphertext data using the national cryptography SM3 algorithm; finally, sign the digest value using the local private key to obtain signature data; after signing, package the ciphertext data, signature data, and the local simplified digital certificate serial number and send them to the peer device. Since the transmitted is the simplified digital certificate serial number, it can reduce the consumption of transmission resources, and subsequently, the corresponding simplified digital certificate can also be queried from the certificate management system module using the simplified digital certificate serial number to obtain the local public key. (2) Decryption process of the peer device includes: First, authenticate the local simplified digital certificate serial number to obtain the local public key; then decrypt the signature data using the local public key to obtain the first digest value; perform a digest operation on the ciphertext data using the national cryptography SM3 algorithm to obtain the second digest value; compare the first digest value and the second digest value, if the comparison result is consistent, then decrypt the ciphertext data using the peer private key to obtain the plaintext data. The data encryption and decryption process from the peer device back to the local device is the same as the data encryption and decryption process from the local device to the peer device described above, which will not be elaborated here. The simplified digital envelope technology uses asymmetric keys to encrypt and transmit data, with small resource consumption, short data, and simple protocol, and its use of encryption and signature methods ensures the security requirements of data encryption, identity authentication, non-repudiation, and anti-tampering.

[0051] Since the simplified digital certificate adopted by the present invention is used, the simplified structure of the simplified digital certificate only includes the simplified digital certificate serial number, public key, module information, application industry, and signature data. Therefore, the CA module inside the certificate management system module needs to be customized and transformed for non-standard simplified certificate issuance, and the CA module is transformed to be able to issue a simplified digital certificate according to the simplified digital certificate serial number, and the simplified structure of the issued simplified digital certificate only includes the simplified digital certificate serial number, public key, module information, application industry, and signature data. Only need to customize and modify the digital certificate structure when the CA module generates a digital certificate.

[0052] Based on the above content, the present invention provides three embodiments, using the simplified digital certificate technology and the simplified digital envelope technology with lower requirements for computing and transmission resources to encrypt and protect the data transmission of Internet of Things devices, and solving the problems of high power consumption, complex protocol, and insufficient device resources in the prior art.

[0053] Embodiment 1:

[0054] This embodiment is used to provide a simplified data encryption method, as Figure 2As shown, the encryption method includes an encryption authentication step and an encryption step;

[0055] The encryption authentication step includes:

[0056] S1: According to the first simplified digital certificate serial number of the first module that executes the decryption step, obtain the first public key of the first module from the certificate management system module; the certificate management system module is pre - set with the first simplified digital certificate of the first module; the first simplified digital certificate includes the first simplified digital certificate serial number and the first public key;

[0057] In this embodiment, the simplified digital certificate technology can be used to obtain the first public key, that is, the corresponding first simplified digital certificate can be queried from the certificate management system module through the first simplified digital certificate serial number, and the first public key in the first simplified digital certificate is extracted. The first simplified digital certificate of this embodiment also includes module information, application industry, and CA signature data. Of course, in this embodiment, the first public key can also be pre - set in the second module in advance, and at this time, it is no longer necessary to query the first public key using the first simplified digital certificate serial number.

[0058] The encryption step includes:

[0059] S2: Use the first public key to encrypt the plaintext data to obtain ciphertext data; perform a digest operation on the ciphertext data to obtain a digest value; use the second private key of the second module that executes the encryption step to sign the digest value to obtain signature data; the ciphertext data and the signature data form the encrypted data.

[0060] This embodiment uses the simplified digital envelope technology for encryption. Performing a digest operation on the ciphertext data can include: performing a digest operation on the ciphertext data using the national secret SM3 algorithm. The encrypted data of this embodiment can also include the second simplified digital certificate serial number of the second module, and this embodiment can also package and transmit the signature data, ciphertext data, and second simplified digital certificate serial number, so as to achieve encrypted transmission.

[0061] This embodiment adopts the simplified digital certificate technology and the simplified digital envelope technology. The protocol is simple, the certificate parsing is simple, the data is short, the data is directly encrypted using the asymmetric key, the operation power consumption and transmission power consumption are relatively small, the requirements for device resources are reduced, and it provides guarantees for the security requirements such as mutual authentication, encrypted transmission, non - repudiation, and anti - tampering in the data transmission process of small devices.

[0062] The first module of this embodiment can be a device - side module, a gateway module, or a server - side module, and the second module can be a device - side module, a gateway module, or a server - side module. Thus, the simplified digital certificate technology and the simplified digital envelope technology can be used to encrypt and protect the data transmission of Internet of Things devices, solving the problems of high power consumption, complex protocols, and insufficient device resources in the prior art.

[0063] Embodiment 2:

[0064] This embodiment is used to provide a simplified data decryption method. As Figure 3 shown, the decryption method includes a decryption authentication step and a decryption step;

[0065] The decryption authentication step includes:

[0066] T1: According to the second simplified digital certificate serial number of the second module that executes the encryption step, obtain the second public key of the second module from the certificate management system module; the certificate management system module is pre - installed with the second simplified digital certificate of the second module; the second simplified digital certificate includes the second simplified digital certificate serial number and the second public key;

[0067] This embodiment can use the simplified digital certificate technology to obtain the second public key, that is, the corresponding second simplified digital certificate can be queried from the certificate management system module through the second simplified digital certificate serial number, and the second public key in the second simplified digital certificate is extracted. The second simplified digital certificate of this embodiment also includes module information, application industry, and CA signature data. Of course, this embodiment can also pre - install the second public key in the first module in advance. At this time, it is no longer necessary to use the second simplified digital certificate serial number to query the second public key.

[0068] The decryption step includes:

[0069] T2: Use the second public key to decrypt the signature data to obtain the first digest value; perform a digest operation on the ciphertext data to obtain the second digest value; if the first digest value is the same as the second digest value, then use the first private key of the first module that executes the decryption step to decrypt the ciphertext data to obtain the plaintext data.

[0070] This embodiment uses the simplified digital envelope technology for decryption. Performing a digest operation on the ciphertext data can include: performing a digest operation on the ciphertext data using the national cryptography SM3 algorithm. This embodiment uses the second public key for signature verification. If the first digest value and the second digest value are the same, the signature verification is successful, and then the first private key is used to decrypt the ciphertext data to obtain the plaintext data; if the first digest value and the second digest value are different, the signature verification fails, indicating that the transmitted ciphertext data has been changed, and the ciphertext data is discarded and the decryption process is no longer performed.

[0071] This embodiment adopts simplified digital certificate technology and simplified digital envelope technology. The protocol is simple, certificate parsing is simple, the data is short, the data is directly decrypted using asymmetric keys, the operation power consumption and transmission power consumption are relatively small, the requirements for device resources are reduced, and it provides guarantees for security requirements such as two-way authentication, encrypted transmission, non-repudiation, and anti-tampering during the data transmission of small devices.

[0072] The first module of this embodiment can be a device-side module, a gateway module, or a server-side module, and the second module can be a device-side module, a gateway module, or a server-side module. Thus, the simplified digital certificate technology and simplified digital envelope technology can be used to decrypt and protect the data of Internet of Things devices, solving the problems of high power consumption, complex protocol, and insufficient device resources in the prior art.

[0073] Embodiment 3:

[0074] This embodiment is used to provide a simplified data encryption and decryption transmission system. As Figure 4 shown, the encryption and decryption transmission system includes a device-side module, a gateway module, a server-side module, and a certificate management system module. The device-side module is communicatively connected to the server-side module through the gateway module, that is, the communication between the device-side module and the server-side module is realized through the gateway module located between the two. Moreover, the device-side module, the gateway module, and the server-side module are all communicatively connected to the certificate management system module. The certificate management system module is pre-set with the simplified digital certificate serial numbers and simplified digital certificates of the device-side module, the gateway module, and the server-side module.

[0075] The certificate management system module is an independent module, which is used in conjunction with the simplified digital certificate serial number and the simplified digital certificate. During the transmission process of the device-side module, the gateway module, and the server-side module, only the simplified digital certificate serial number is always transmitted. If you want to obtain the corresponding simplified digital certificate according to the simplified digital certificate serial number, it needs to be realized through the certificate management system module.

[0076] The device-side module is pre-set with the public and private key pairs and the simplified digital certificate serial number of the device-side module. The gateway module is pre-set with the public and private key pairs and the simplified digital certificate serial number of the gateway module. The server-side module is pre-set with the public and private key pairs and the simplified digital certificate serial number of the server-side module. The certificate management system module can also be pre-set with the public and private key pairs of the certificate management system module and a modified CA module, and the simplified digital certificate is issued using the modified CA module.

[0077] When the device-side module reports data to the server-side module, there are the following three data encryption and decryption transmission methods:

[0078] (1) The device - side module is used to execute the encryption authentication step and the encryption step described in Embodiment 1, obtain the encrypted data, and transmit the encrypted data to the gateway module; the gateway module is used to execute the decryption authentication step and the decryption step described in Embodiment 2, obtain the plaintext data, and transmit the plaintext data to the server - side module.

[0079] (2) The device - side module is used to execute the encryption authentication step and the encryption step described in Embodiment 1, obtain the encrypted data, and forward the encrypted data to the server - side module through the gateway module; the server - side module is used to execute the decryption authentication step and the decryption step described in Embodiment 2, obtain the plaintext data.

[0080] (3) The device - side module is used to execute the encryption authentication step and the encryption step described in Embodiment 1, obtain the encrypted data, and transmit the encrypted data to the gateway module; the server - side module is used to execute the decryption authentication step described in Embodiment 2, obtain the public key of the device - side module, and transmit the public key of the device - side module to the gateway module; the gateway module is used to execute the decryption step described in Embodiment 2, obtain the plaintext data, and transmit the plaintext data to the server - side module.

[0081] When the server - side module sends data to the device - side module, there are the following three encryption and decryption data transmission methods:

[0082] (1) The server - side module is used to transmit the plaintext data to the gateway module; the gateway module is used to execute the encryption authentication step and the encryption step described in Embodiment 1, obtain the encrypted data, and transmit the encrypted data to the device - side module; the device - side module is used to execute the decryption authentication step and the decryption step described in Embodiment 2, obtain the plaintext data.

[0083] (2) The server - side module is used to execute the encryption authentication step and the encryption step described in Embodiment 1, obtain the encrypted data, and forward the encrypted data to the device - side module through the gateway module; the device - side module is used to execute the decryption authentication step and the decryption step described in Embodiment 2, obtain the plaintext data.

[0084] (3) The server - side module is used to execute the encryption authentication step described in Embodiment 1, obtain the first public key, and transmit the plaintext data and the first public key to the gateway module; the gateway module is used to execute the encryption step described in Embodiment 1, obtain the encrypted data, and transmit the encrypted data to the device - side module; the device - side module is used to execute the decryption authentication step and the decryption step described in Embodiment 2, obtain the plaintext data.

[0085] Here, this embodiment further explains the above 3 cases:

[0086] (1) When the server - side module does not have the authentication and encryption - decryption functions, the gateway module performs the authentication and encryption - decryption operations. For example Figure 5As shown in the figure, the structure of each part is as follows: The device - side module needs to pre - set the device - side public - private key pair, the device - side simplified digital certificate serial number, and the gateway - module public key; The gateway module needs to pre - set the gateway - module public - private key pair, the gateway - module simplified digital certificate serial number (if the device - side module does not pre - set the gateway - module public key, the gateway - module simplified digital certificate serial number can be sent to the device - side module to obtain the gateway - module public key); The certificate management system module needs to pre - set the certificate management system module public - private key pair, the simplified digital certificate serial numbers of the device - side module and the gateway module, the simplified digital certificates of the device - side module and the gateway module, and the transformed CA module.

[0087] When the device - side module reports data to the server - side module, as Figure 6 shown, it mainly includes the following five - step operations:

[0088] 1) The device - side module sends the plain - text data to the cryptographic module (see Figure 6 ① in the figure), and the cryptographic module encrypts the plain - text data using the gateway - module public key, and then returns the obtained cipher - text data to the device - side module (see Figure 6 ② in the figure).

[0089] 2) The device - side module sends the cipher - text data to the cryptographic module (see Figure 6 ③ in the figure), and the cryptographic module performs a digest operation on the cipher - text data using the national cryptography SM3 algorithm to obtain a digest value, and signs the digest value using the device - side private key, and finally returns the signed data to the device - side module (see Figure 6 ④ in the figure).

[0090] 3) After receiving the signed data, the device - side module packs the cipher - text data, the signed data, and the device - side simplified digital certificate serial number into the reported data, and sends it to the gateway module through the communication module (see Figure 6 ⑤ and ⑥ in the figure).

[0091] 4) After receiving the data, the gateway module sends a decryption request to the cryptographic module (see Figure 6 ⑦ in the figure), and the cryptographic module sends the device - side simplified digital certificate serial number to the certificate management system module (see Figure 6 ⑧ in the figure). The certificate management system module uses the transformed CA module to obtain the device - side public key in the simplified digital certificate corresponding to the device - side simplified digital certificate serial number, and sends it back to the cryptographic module (see Figure 6 ⑨ in the figure).

[0092] 5) The cryptographic module uses the public key of the device to verify the signature of the reported data, decrypts the signature data with the public key of the device, obtains the first summary value, and then uses the national secret SM3 algorithm to perform a summary operation on the ciphertext data to obtain the second summary value. The second summary value is compared with the first summary value. If they are consistent, the signature verification is successful. If they are inconsistent, the signature verification fails and the reported data is discarded. After the signature verification is successful, the ciphertext data is decrypted using the private key of the gateway module to obtain the plaintext data, and the plaintext data is sent back to the gateway module (see Figure 6 ⑩), and then the gateway module sends the plaintext data to the server module (see Figure 6 of ).

[0093] When the server module sends data to the device module, Figure 7 As shown, it mainly includes the following four steps:

[0094] 1) The server module sends the plain text data to the gateway module (see Figure 7 ①), then the gateway module sends the plaintext data and the simplified digital certificate serial number of the device to the password module (see Figure 7 ②). The password module sends the device-side simplified digital certificate serial number to the certificate management system module (see Figure 7 The certificate management system module obtains the device-side public key through the modified CA module and returns the device-side public key to the password module (see Figure 7 The cryptographic module uses the device-side public key to encrypt the plaintext data and returns the ciphertext data to the gateway module (see Figure 7 ⑤).

[0095] 2) The gateway module sends the ciphertext data to the password module (see Figure 7 ⑥), the password module uses the national secret SM3 algorithm to perform a summary operation on the ciphertext data to obtain a summary value, and uses the gateway module private key to sign the summary value, and finally returns the signed data to the gateway module (see Figure 7 ⑦).

[0096] 3) After receiving the signature data, the gateway module packages the signature data and ciphertext data into the sent data, and sends it to the device module through the communication module (see Figure 7 ⑧ and ⑨).

[0097] 4) After receiving the data, the device module sends a decryption request to the password module (see Figure 7(10), the password module uses the public key of the gateway module to perform a signature verification operation on the downloaded data. It compares the second digest value obtained by performing a digest operation on the ciphertext data using the national secret SM3 algorithm with the first digest value obtained by decrypting the signature data using the public key of the gateway module. If they are consistent, the signature verification is successful. After the signature verification is successful, the device-side private key is used to decrypt the ciphertext data to obtain the plaintext data, and the plaintext data is sent to the device-side module (see Figure 7 of ).

[0098] (2) When the server-side module has authentication and encryption / decryption functions, the gateway module no longer performs authentication, encryption / decryption operations. After receiving the data packet, the gateway module forwards it to the server-side module, and the server-side module performs authentication and encryption / decryption operations. As Figure 8 shown, the structure of each part is as follows: The device-side module needs to pre-set the device-side public and private key pair, the device-side simplified digital certificate serial number, and the server-side public key; the server-side module needs to pre-set the server-side public and private key pair, the server-side simplified digital certificate serial number; the certificate management system module needs to pre-set the certificate management system public and private key pair, the simplified digital certificate serial number (including the device-side module and the server-side module), the simplified digital certificate (including the device-side module and the server-side module), and the modified CA module.

[0099] When the device-side module reports data to the server-side module, as Figure 9 shown, it mainly includes the following six-step operations:

[0100] 1) The device-side module sends the plaintext data to the password module (see Figure 9 of ①), and the password module encrypts the plaintext data using the server-side public key pre-set by the device-side module, and then returns the ciphertext data to the device-side module (see Figure 9 of ②).

[0101] 2) The device-side module sends the ciphertext data to the password module (see Figure 9 of ③), and the password module performs a digest operation on the ciphertext data using the national secret SM3 algorithm to obtain a digest value, and signs and encrypts the digest value using the device-side private key, and finally returns the signature data to the device-side module (see Figure 9 of ④).

[0102] 3) After receiving the signature data, the device-side module packs the ciphertext data, the signature data, and the device-side simplified digital certificate serial number into the reported data, and sends it to the gateway module through the communication module (see Figure 9 of ⑤ and ⑥).

[0103] 4) After receiving the reported data, the gateway module sends the reported data to the server-side module (see Figure 9 of ⑦).

[0104] 5) After receiving the reported data, the server module sends a decryption request to the password module (see Figure 9 ⑧), the password module sends the simplified digital certificate serial number of the device to the certificate management system module (see Figure 9 ⑨). The certificate management system module uses the modified CA module to obtain the device-side public key in the simplified digital certificate corresponding to the serial number and sends it back to the password module (see Figure 9 ⑩).

[0105] 6) The cryptographic module uses the public key of the device to verify the signature of the reported data, decrypts the signature data with the public key of the device, obtains the first summary value, and then uses the national secret SM3 algorithm to perform a summary operation on the ciphertext data to obtain the second summary value. The second summary value is compared with the first summary value. If they are consistent, the signature verification is successful. After the signature verification is successful, the ciphertext data is decrypted with the private key of the server to obtain the plaintext data, and then the plaintext data is notified to the server module (see Figure 9 of ).

[0106] When the server module sends data to the device module, it mainly includes the following four steps:

[0107] 1) The server module sends the plaintext data to the cryptographic module, which encrypts the plaintext data using the device public key and returns the ciphertext data to the server module.

[0108] 2) The server module sends the ciphertext data to the cryptographic module. The cryptographic module uses the national secret SM3 algorithm to perform a summary operation on the ciphertext data to obtain a summary value, and uses the server module private key to sign the summary value, and finally returns the signed data to the server module.

[0109] 3) After receiving the signature data, the server module packages the signature data and ciphertext data into the sent data, and sends it to the device module through the communication module and the gateway module.

[0110] 4) After receiving the sent data, the device-side module sends a decryption request to the password module. The password module uses the server-side module public key to verify the signature of the sent data. The second digest value obtained by using the national secret SM3 algorithm to perform a digest operation on the ciphertext data is compared with the first digest value obtained by decrypting the signature data using the server-side module public key. If they are consistent, the signature verification is successful. After the signature verification is successful, the ciphertext data is decrypted using the device-side private key to obtain the plaintext data, and the plaintext data is sent to the device-side module.

[0111] (3) When the server module has the authentication function but does not have the encryption and decryption function, the server module performs the authentication and the gateway module performs the data encryption and decryption operations. Figure 10As shown in the figure, the structure of each part is as follows: The device - side module needs to pre - set the device - side public - private key pair, the device - side simplified digital certificate serial number, and the gateway - module public key; the gateway module needs to pre - set the gateway - module public - private key pair; the server - side module needs to pre - set the server - side simplified digital certificate serial number; the certificate management system module needs to pre - set the certificate management system module public - private key pair, the simplified digital certificate serial number (including the device - side module and the server - side module), the simplified digital certificate (including the device - side module and the server - side module), and the modified CA module.

[0112] When the device - side module reports data to the server - side module, as Figure 11 shown, it mainly includes the following five steps of operation:

[0113] 1) The device - side module sends the plain - text data to the cryptographic module (see Figure 11 ①), and the cryptographic module encrypts the plain - text data using the pre - set gateway - module public key, and then returns the cipher - text data to the device - side module (see Figure 11 ②).

[0114] 2) The device - side module sends the cipher - text data to the cryptographic module (see Figure 11 ③), and the cryptographic module performs a digest operation on the cipher - text data using the national cryptographic SM3 algorithm to obtain a digest value, and encrypts the digest value using the device - side private key, and finally returns the signature data to the device - side module (see Figure 11 ④).

[0115] 3) After receiving the signature data, the device - side module packs the cipher - text data, the signature data, and the device - side simplified digital certificate serial number into the reported data, and sends it to the gateway module through the communication module (see Figure 11 ⑤ and ⑥).

[0116] 4) After receiving the data, the gateway module first sends the device - side simplified digital certificate serial number to the server - side module (see Figure 11 ⑦), and the server - side module then sends the device - side simplified digital certificate serial number to the certificate management system module (see Figure 11 ⑧). The certificate management system module uses the modified CA module to obtain the device - side public key in the simplified digital certificate corresponding to this serial number, and sends it back to the server - side module (see Figure 11 ⑨), and the server - side module sends the obtained device - side public key to the gateway module (see Figure 11 ⑩).

[0117] 5) After receiving the device - side public key, the gateway module sends a decryption request to the cryptographic module (see Figure 11 of ). The cryptographic module uses the public key of the device to verify the signature of the reported data, uses the public key of the device to decrypt the signature data, obtains the first summary value, and then uses the national secret SM3 algorithm to perform a summary operation on the ciphertext data to obtain the second summary value. The second summary value is compared with the first summary value. If they are consistent, the signature verification is successful. After the signature verification is successful, the ciphertext data is decrypted using the private key of the gateway module to obtain the plaintext data, and the plaintext data is sent back to the gateway module (see Figure 11 of ), then the gateway module notifies the server module of the plaintext data (see Figure 11 of ).

[0118] When the server module sends data to the device module, it mainly includes the following four steps:

[0119] 1) The server module sends the simplified digital certificate serial number of the device to the certificate management system module, obtains the public key of the device, and sends the plaintext data and the public key of the device to the gateway module. The gateway module sends the plaintext data and the public key of the device to the password module, which encrypts the plaintext data using the public key of the device and returns the ciphertext data to the gateway module.

[0120] 2) The gateway module sends the ciphertext data to the cryptographic module. The cryptographic module uses the national secret SM3 algorithm to perform a summary operation on the ciphertext data to obtain a summary value, and uses the gateway module private key to sign the summary value, and finally returns the signed data to the gateway module.

[0121] 3) After receiving the signature data, the gateway module packages the signature data and ciphertext data into the sent data, and sends it to the device-side module through the communication module.

[0122] 4) After receiving the sent data, the device-side module sends a decryption request to the password module. The password module uses the gateway module public key to verify the signature of the sent data. The second summary value obtained by using the national secret SM3 algorithm to perform a summary operation on the ciphertext data is compared with the first summary value obtained by decrypting the signature data using the gateway module public key. If they are consistent, the signature verification is successful. After the signature verification is successful, the ciphertext data is decrypted using the device-side private key to obtain the plaintext data, and the plaintext data is sent to the device-side module.

[0123] This embodiment uses simplified digital certificate technology and simplified digital envelope technology with low requirements for computing and transmission resources to encrypt and protect the data transmission of IoT devices, thereby ensuring the secure transmission of data of resource-constrained devices.

[0124] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.

[0125] In this text, specific examples are used to elaborate on the principles and implementation manners of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention. At the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to the present invention.

Claims

1. A simplified data encryption method, characterized in that, it uses a simplified digital certificate technology and a simplified digital envelope technology for data encrypted transmission, and the encryption method includes an encryption authentication step and an encryption step; The encryption authentication step includes: According to the first simplified digital certificate serial number of the first module that executes the decryption step, obtain the first public key of the first module from the certificate management system module; the certificate management system module is pre - set with the first simplified digital certificate of the first module; the first simplified digital certificate includes the first simplified digital certificate serial number and the first public key; The encryption step includes: Use the first public key to encrypt the plaintext data to obtain ciphertext data; perform a digest operation on the ciphertext data to obtain a digest value; use the second private key of the second module that executes the encryption step to sign the digest value to obtain signature data; the ciphertext data and the signature data form the encrypted data; the encrypted data also includes the second simplified digital certificate serial number of the second module; During decryption, it includes a decryption authentication step and a decryption step; The decryption authentication step includes: According to the second simplified digital certificate serial number of the second module that executes the encryption step, obtain the second public key of the second module from the certificate management system module; the certificate management system module is pre - set with the second simplified digital certificate of the second module; the second simplified digital certificate includes the second simplified digital certificate serial number and the second public key; The decryption step includes: Use the second public key to decrypt the signature data to obtain a first digest value; perform a digest operation on the ciphertext data to obtain a second digest value; if the first digest value is consistent with the second digest value, then use the first private key of the first module that executes the decryption step to decrypt the ciphertext data to obtain the plaintext data.

2. The encryption method according to claim 1, characterized in that, The first simplified digital certificate further includes module information, application industry, and CA signature data.

3. The encryption method according to claim 1, characterized in that, The first module is a device - end module, a gateway module, or a server - end module; the second module is the device - end module, the gateway module, or the server - end module.

4. The encryption method according to claim 1, characterized in that, The specific operation of performing a digest operation on the ciphertext data includes: using the national cryptography SM3 algorithm to perform a digest operation on the ciphertext data.

5. A simplified data decryption method, characterized in that, the decryption method includes a decryption authentication step and a decryption step; The decryption authentication step includes: According to the second simplified digital certificate serial number of the second module that executes the encryption step, obtain the second public key of the second module from the certificate management system module; the certificate management system module is pre - set with the second simplified digital certificate of the second module; the second simplified digital certificate includes the second simplified digital certificate serial number and the second public key; The decryption step includes: Decrypt the signature data using the second public key to obtain a first digest value; perform a digest operation on the ciphertext data to obtain a second digest value; if the first digest value is consistent with the second digest value, decrypt the ciphertext data using the first private key of the first module that executes the decryption step to obtain the plaintext data.

6. The decryption method according to claim 5, wherein, the second simplified digital certificate further includes module information, application industry, and CA signature data.

7. The decryption method according to claim 5, wherein, the first module is a device-side module, a gateway module, or a server-side module; the second module is the device-side module, the gateway module, or the server-side module.

8. A simplified data encryption and decryption transmission system, wherein, the encryption and decryption transmission system includes a device-side module, a gateway module, a server-side module, and a certificate management system module; the device-side module is communicatively connected to the server-side module through the gateway module; the device-side module, the gateway module, and the server-side module are all communicatively connected to the certificate management system module, and the certificate management system module is preconfigured with simplified digital certificates of the device-side module, the gateway module, and the server-side module; when the device-side module reports data to the server-side module: the device-side module is configured to execute the encryption authentication step and the encryption step of claim 1 to obtain encrypted data, and transmit the encrypted data to the gateway module; the gateway module is configured to execute the decryption authentication step and the decryption step of claim 5 to obtain plaintext data, and transmit the plaintext data to the server-side module; the device-side module is configured to execute the encryption authentication step and the encryption step of claim 1 to obtain encrypted data, and forward the encrypted data to the server-side module through the gateway module; the server-side module is configured to execute the decryption authentication step and the decryption step of claim 5 to obtain plaintext data; alternatively, the device-side module is configured to execute the encryption authentication step and the encryption step of claim 1 to obtain encrypted data, and transmit the encrypted data to the gateway module; the server-side module is configured to execute the decryption authentication step of claim 5; the gateway module is configured to execute the decryption step of claim 5 to obtain plaintext data, and transmit the plaintext data to the server-side module; when the server-side module sends data to the device-side module: the server-side module is configured to transmit plaintext data to the gateway module; the gateway module is configured to execute the encryption authentication step and the encryption step of claim 1 to obtain encrypted data, and transmit the encrypted data to the device-side module; the device-side module is configured to execute the decryption authentication step and the decryption step of claim 5 to obtain the plaintext data; The server module is used to execute the encryption authentication step and the encryption step described in claim 1 to obtain encrypted data, and forward the encrypted data to the device module through the gateway module; the device module is used to execute the decryption authentication step and the decryption step described in claim 5 to obtain plaintext data; Alternatively, the server module is used to transmit plaintext data to the gateway module and execute the encryption authentication step described in claim 1; The gateway module is used to execute the encryption step described in claim 1 to obtain encrypted data, and transmit the encrypted data to the device module; the device module is used to execute the decryption authentication step and the decryption step described in claim 5 to obtain plaintext data.

9. The encryption and decryption transmission system according to claim 8, wherein, The device module is pre - set with the public - private key pair of the device module and the simplified digital certificate serial number; the gateway module is pre - set with the public - private key pair of the gateway module and the simplified digital certificate serial number; the server module is pre - set with the public - private key pair of the server module and the simplified digital certificate serial number.

Citation Information

Patent Citations

  • Hybrid encryption and decryption method, system, device and medium

    CN114697095A