Data verification and encryption method and device, electronic equipment and storage medium
By encrypting Internet Protocol addresses in the NBIOT system and returning them to the terminal, combined with timer control of low-power mode, the problem of high terminal power consumption is solved, and low-power data verification and secure transmission are achieved.
Patent Information
- Application Number
- CN202211004253.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-22
- Publication Date
- 2025-11-28
- Estimated Expiration
- 2042-08-22
AI Technical Summary
In NB-IoT application systems, with the increase in the number of terminal accesses, traditional data transmission security measures result in high terminal power consumption, making it difficult to meet the low power consumption requirements.
The terminal obtains the Internet Protocol address and sends it to the server for encryption. The server returns the encrypted target Internet Protocol address to the terminal and the cloud platform. The terminal makes a data transmission request based on the target address and receives the verification result from the cloud platform. A timer controls a low-power mode to reduce unnecessary data processing.
It reduces the data processing pressure on the terminal, reduces storage space usage, reduces terminal power consumption, and at the same time enables rapid data verification and secure transmission.
Smart Images

Figure CN115412322B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of communication, in particular to a data verification and encryption method and device, electronic equipment, storage medium and computer program product. BACKGROUND
[0002] Narrow Band Internet of Things (NBIOT) technology, as a communication technology for Internet of Things applications, is a new wide area network transmission technology. Compared with traditional wireless wide area network transmission technology, NBIOT technology has the advantages of deep coverage, low power consumption, long standby, large-scale connection and low hardware cost, and can meet the needs of accessing NBIOT in different environments. Therefore, it is widely used in industries such as electricity meters, water meters and gas meters.
[0003] With the rapid growth of the number of terminals containing NBIOT modules and the sharp increase in scale, NBIOT application system interconnection and interconnection, and centralized management of data processing platforms, the industry has an urgent need for secure data transmission. In order to strengthen the security of data transmission, the use of traditional technology is easy to cause the terminal to have large power consumption. SUMMARY
[0004] Therefore, it is necessary to provide a data verification and encryption method and device, electronic equipment, computer readable storage medium and computer program product capable of reducing power consumption to solve the above technical problems.
[0005] In a first aspect, the present application provides a data verification method applied to a terminal, wherein the terminal is in communication connection with a server, the server is in communication connection with a cloud platform, and the terminal is in communication connection with the cloud platform. The method comprises:
[0006] obtaining an Internet protocol address corresponding to the terminal;
[0007] sending the Internet protocol address to the server, wherein the server is configured to encrypt the Internet protocol address to obtain a target Internet protocol address, and send the target Internet protocol address to the terminal and the cloud platform;
[0008] receiving the target Internet protocol address sent by the server, and sending a data transmission request to the cloud platform according to the target Internet protocol address;
[0009] receiving a verification result fed back by the cloud platform according to the data transmission request.
[0010] In one embodiment, the terminal further comprises a timer configured to time a preset time length during which the terminal is in a low-power mode; the method further comprises:
[0011] if the time length from the time of entering the low-power mode to the current time reaches the preset time length, performing the step of sending a data transmission request to the cloud platform according to the target Internet protocol address.
[0012] if the time length from the time of entering the low-power mode to the current time does not reach the preset time length, continuing to enter the low-power mode.
[0013] In a second aspect, the present application further provides a data verification device. The device comprises:
[0014] a data acquisition module configured to acquire an Internet protocol address corresponding to a terminal;
[0015] a data sending module configured to send the Internet protocol address to a server, wherein the server is configured to encrypt the Internet protocol address to obtain a target Internet protocol address, and send the target Internet protocol address to the terminal and a cloud platform;
[0016] a first receiving module configured to receive the target Internet protocol address sent by the server, and send a data transmission request to the cloud platform according to the target Internet protocol address;
[0017] a second receiving module configured to receive a verification result fed back by the cloud platform according to the data transmission request.
[0018] In one embodiment, the terminal further comprises a timer configured to time a preset time length of the terminal in a low-power mode; the device further comprises a timing module configured to:
[0019] if the time length from the time of entering the low-power mode to the current time reaches the preset time length, performing the step of sending a data transmission request to the cloud platform according to the target Internet protocol address;
[0020] if the time length from the time of entering the low-power mode to the current time does not reach the preset time length, continuing to enter the low-power mode.
[0021] In a third aspect, the present application further provides an electronic device. The electronic device comprises a memory and a processor, the memory stores a computer program, and the processor implements the following steps when executing the computer program:
[0022] acquiring an Internet protocol address corresponding to the terminal;
[0023] sending the Internet protocol address to a server, wherein the server is configured to encrypt the Internet protocol address to obtain a target Internet protocol address, and send the target Internet protocol address to the terminal and the cloud platform;
[0024] receiving the target internet protocol address sent by the server, and sending a data transmission request to the cloud platform according to the target internet protocol address;
[0025] receiving a verification result fed back by the cloud platform according to the data transmission request.
[0026] In a fourth aspect, the present application further provides a computer readable storage medium. The computer readable storage medium has a computer program stored thereon, and the computer program is executed by a processor to implement the following steps:
[0027] obtaining an internet protocol address corresponding to the terminal;
[0028] sending the internet protocol address to a server, wherein the server is configured to encrypt the internet protocol address to obtain a target internet protocol address, and send the target internet protocol address to the terminal and the cloud platform;
[0029] receiving the target internet protocol address sent by the server, and sending a data transmission request to the cloud platform according to the target internet protocol address;
[0030] receiving a verification result fed back by the cloud platform according to the data transmission request.
[0031] In a fifth aspect, the present application further provides a computer program product. The computer program product comprises a computer program, and the computer program is executed by a processor to implement the following steps:
[0032] obtaining an internet protocol address corresponding to the terminal;
[0033] sending the internet protocol address to a server, wherein the server is configured to encrypt the internet protocol address to obtain a target internet protocol address, and send the target internet protocol address to the terminal and the cloud platform;
[0034] receiving the target internet protocol address sent by the server, and sending a data transmission request to the cloud platform according to the target internet protocol address;
[0035] The receiving cloud platform feeds back a verification result according to the data transmission request. The data verification method, device, electronic equipment, storage medium and computer program product, through the terminal, obtain a corresponding Internet protocol address, and send the obtained Internet protocol address to a server, wherein the server is configured to encrypt the Internet protocol address to obtain a target Internet protocol address, and send the target Internet protocol address to the terminal and the cloud platform; the terminal receives the target Internet protocol address sent by the server, and sends a data transmission request to the cloud platform according to the target Internet protocol address; and the receiving cloud platform feeds back a verification result according to the data transmission request. The server encrypts the Internet protocol address, and then returns the target Internet protocol address obtained by encryption to the terminal, so that the data processing pressure of the terminal can be reduced, the processing speed of the terminal can be accelerated, the internal scarce storage space of the terminal can be reduced, and the power consumption of the terminal can be reduced.
[0036] In a sixth aspect, the present application further provides a data encryption method applied to a server, wherein the server is in communication connection with a terminal, the server is in communication connection with a cloud platform, and the terminal is in communication connection with the cloud platform. The method comprises the following steps:
[0037] receiving an Internet protocol address sent by the terminal;
[0038] encrypting the Internet protocol address to obtain a target Internet protocol address;
[0039] sending the target Internet protocol address to the terminal and the cloud platform.
[0040] In a seventh aspect, the present application further provides an encryption device, which comprises the following components:
[0041] an address receiving module configured to receive an Internet protocol address sent by the terminal;
[0042] an address encryption module configured to encrypt the Internet protocol address to obtain a target Internet protocol address;
[0043] an address sending module configured to send the target Internet protocol address to the terminal and the cloud platform.
[0044] In an eighth aspect, the present application further provides an electronic equipment. The electronic equipment comprises a memory and a processor, the memory stores a computer program, and the processor realizes the following steps when executing the computer program:
[0045] receiving an Internet protocol address sent by the terminal;
[0046] encrypting the Internet protocol address to obtain a target Internet protocol address;
[0047] sending the target internet protocol address to the terminal and the cloud platform.
[0048] In a ninth aspect, the present application also provides a computer readable storage medium. The computer readable storage medium has a computer program stored thereon, and the computer program, when executed by a processor, implements the following steps:
[0049] receiving an internet protocol address sent by a terminal;
[0050] encrypting the internet protocol address to obtain a target internet protocol address;
[0051] sending the target internet protocol address to the terminal and the cloud platform.
[0052] In a tenth aspect, the present application also provides a computer program product. The computer program product comprises a computer program, and the computer program, when executed by a processor, implements the following steps:
[0053] receiving an internet protocol address sent by a terminal;
[0054] encrypting the internet protocol address to obtain a target internet protocol address;
[0055] sending the target internet protocol address to the terminal and the cloud platform.
[0056] The above data encryption method, device, electronic equipment, storage medium and computer program product can receive an internet protocol address sent by a terminal, encrypt the internet protocol address to obtain a target internet protocol address, and send the target internet protocol address to the terminal and the cloud platform, so as to quickly encrypt the internet protocol address to obtain the target internet protocol address, and send the target internet protocol address to the terminal and the cloud platform.
[0057] In an eleventh aspect, the present application also provides a data verification method applied to a cloud platform, wherein the cloud platform is in communication connection with a server, the cloud platform is in communication connection with a terminal, and the server is in communication connection with the terminal. The method comprises the following steps:
[0058] receiving a data transmission request sent by a terminal, wherein the data transmission request carries a first internet protocol address;
[0059] comparing the first internet protocol address with a target internet protocol address; the target internet protocol address is received by the cloud platform from a server and saved, and the target internet protocol address is obtained by encrypting an internet protocol address corresponding to the terminal by the server;
[0060] When the first internet protocol address is the same as the target internet protocol address, it is determined that the terminal is an authorized terminal, and a verification result of verification passed is sent to the terminal;
[0061] When the first internet protocol address is different from the target internet address, it is determined that the terminal is an unauthorized terminal, and a verification result of verification failed is sent to the terminal.
[0062] In one of the embodiments, the method further comprises:
[0063] When it is determined that the terminal is an authorized terminal, data in the data transmission request is processed;
[0064] When it is determined that the terminal is an unauthorized terminal, data in the data transmission request is discarded.
[0065] In a twelfth aspect, the application further provides a data verification device. The device comprises:
[0066] A request receiving module is configured to receive a data transmission request sent by a terminal, wherein the data transmission request carries a first internet protocol address;
[0067] An address comparing module is configured to compare the first internet protocol address with a target internet protocol address; the target internet protocol address is sent and saved by a cloud platform receiving server, and the target internet protocol address is obtained by encrypting an internet protocol address corresponding to the terminal by a server;
[0068] A terminal determining module is configured to determine that the terminal is an authorized terminal when the first internet protocol address is the same as the target internet protocol address, and send a verification result of verification passed to the terminal; determine that the terminal is an unauthorized terminal when the first internet protocol address is different from the target internet address, and send a verification result of verification failed to the terminal.
[0069] In a thirteenth aspect, the application further provides an electronic device. The electronic device comprises a memory and a processor, the memory stores a computer program, and the processor implements the following steps when executing the computer program:
[0070] A data transmission request sent by a terminal is received, wherein the data transmission request carries a first internet protocol address;
[0071] The first internet protocol address is compared with a target internet protocol address; the target internet protocol address is sent and saved by a cloud platform receiving server, and the target internet protocol address is obtained by encrypting an internet protocol address corresponding to the terminal by a server;
[0072] when the first internet protocol address is same as the target internet protocol address, it is determined that the terminal is an authorized terminal, and a verification result of verification failure is sent to the terminal;
[0073] when the first internet protocol address is different from the target internet address, it is determined that the terminal is an unauthorized terminal, and a verification result of verification failure is sent to the terminal.
[0074] In a fourteenth aspect, the present application further provides a computer readable storage medium. The computer readable storage medium has a computer program stored thereon, and the computer program is executed by a processor to implement the following steps:
[0075] receiving a data transmission request sent by a terminal, the data transmission request carrying a first internet protocol address;
[0076] comparing the first internet protocol address with a target internet protocol address; the target internet protocol address is sent and saved by a cloud platform receiving server, and the target internet protocol address is obtained by encrypting an internet protocol address corresponding to the terminal by a server;
[0077] when the first internet protocol address is same as the target internet protocol address, it is determined that the terminal is an authorized terminal, and a verification result of verification failure is sent to the terminal;
[0078] when the first internet protocol address is different from the target internet address, it is determined that the terminal is an unauthorized terminal, and a verification result of verification failure is sent to the terminal.
[0079] In a fifteenth aspect, the present application further provides a computer program product. The computer program product comprises a computer program, and the computer program is executed by a processor to implement the following steps:
[0080] receiving a data transmission request sent by a terminal, the data transmission request carrying a first internet protocol address;
[0081] comparing the first internet protocol address with a target internet protocol address; the target internet protocol address is sent and saved by a cloud platform receiving server, and the target internet protocol address is obtained by encrypting an internet protocol address corresponding to the terminal by a server;
[0082] when the first internet protocol address is same as the target internet protocol address, it is determined that the terminal is an authorized terminal, and a verification result of verification failure is sent to the terminal;
[0083] When the first internet protocol address is different from the target internet address, it is determined that the terminal is an unauthorized terminal, and a verification result of verification failure is sent to the terminal.
[0084] The data verification method, device, electronic equipment, storage medium and computer program product, by receiving the data transmission request sent by the terminal, wherein the data transmission request carries a first internet protocol address; comparing the first internet protocol address with the target internet protocol address, the target internet protocol address is sent and saved by the cloud platform receiving server, and the target internet protocol address is obtained by encrypting the internet protocol address corresponding to the terminal by the server; when the first internet protocol address is the same as the target internet protocol address, it is determined that the terminal is an authorized terminal, and a verification result of verification pass is sent to the terminal; when the first internet protocol address is different from the target internet protocol address, it is determined that the terminal is an unauthorized terminal, and a verification result of verification failure is sent to the terminal. The application can effectively verify the terminal quickly, so as to confirm whether the terminal is an authorized terminal, and can quickly access the cloud platform to realize safe data transmission. BRIEF DESCRIPTION OF DRAWINGS
[0085] Figure 1 The application environment diagram of the data verification and encryption method in one embodiment;
[0086] Figure 2 The flowchart of the data verification method in one embodiment;
[0087] Figure 3 The flowchart of the data verification method in another embodiment;
[0088] Figure 4 The flowchart of the data encryption method in one embodiment;
[0089] Figure 5 The flowchart of the data encryption method in another embodiment;
[0090] Figure 6 The flowchart of the data verification method in another embodiment;
[0091] Figure 7 The flowchart of the data verification method in another embodiment;
[0092] Figure 8 The flowchart of the data verification and encryption method in one embodiment;
[0093] Figure 9 The structure block diagram of the data verification device in one embodiment;
[0094] Figure 10A structural block diagram of a data encryption device in one embodiment;
[0095] Figure 11 A structural block diagram of a data verification device in another embodiment;
[0096] Figure 12 An internal structural diagram of an electronic device in one embodiment. DETAILED DESCRIPTION
[0097] In order to make the purposes, technical solutions and advantages of the present application clearer, the present application is further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and not to limit the present application.
[0098] The data verification and encryption method provided by the embodiments of the present application can be applied in an application environment as shown in Figure 1 . The terminal 102 communicates with the server 104 and the cloud platform 106 through a network, and the server 104 communicates with the cloud platform 106. The terminal 102 obtains an internet protocol address corresponding to the terminal, and sends the internet protocol address to the server 104. The server 104 encrypts the received internet protocol address sent by the terminal to obtain a target internet protocol address, and sends the target internet protocol address to the terminal 102 and the cloud platform 106. The terminal 102 receives the target internet protocol address sent by the server 104, and sends a data transmission request to the cloud platform 106 according to the target internet protocol address. The cloud platform 106 receives the data transmission request sent by the terminal 102, wherein the data transmission request carries a first internet protocol address. The cloud platform 106 compares the first internet protocol address with the target internet protocol address received and saved by the server 104. When the first internet protocol address is the same as the target internet protocol address, it is determined that the terminal 102 is an authorized terminal, and a verification result of verification passed is sent to the terminal. When the first internet protocol address is different from the target internet protocol address, it is determined that the terminal 102 is an unauthorized terminal, and a verification result of verification failed is sent to the terminal.
[0099] The terminal 102 includes a communication module, such as a narrowband Internet of Things module, which can be but is not limited to various intelligent street lamps, intelligent door locks, electricity meters, water meters, gas meters, intelligent parking meters, intelligent manhole covers, smoke alarms, etc. The server 104 can be implemented by an independent server or a server cluster composed of multiple servers.
[0100] In one embodiment, as shown in Figure 2 , a data verification method is provided, and the method is applied in Figure 1The method is described by taking a terminal as an example. The terminal is in communication connection with a server, the server is in communication connection with a cloud platform, and the terminal is in communication connection with the cloud platform. The method comprises the following steps 202 to 208.
[0101] In step 202, an Internet protocol address corresponding to the terminal is acquired.
[0102] The terminal in the embodiment comprises a narrowband Internet of Things module, so that the terminal can access the narrowband Internet of Things to realize communication with other terminals, servers or cloud platforms and the like. The terminal acquires an Internet protocol address corresponding to the terminal. The Internet protocol address is a logical address allocated to the terminal. Generally, a terminal corresponds to a unique Internet protocol address. The Internet protocol address can be an IP (Internet Protocol Address) address, for example, an IPV4 (Internet Protocol Version 4) address, an IPV4V6 address or an IPV6 (Internet Protocol Version 6) address. The IPV4V6 address means that an IPV4 address and an IPV6 address are acquired at the same time. It can be understood that the Internet protocol address can also be a non-IP address.
[0103] In an optional embodiment, after the narrowband Internet of Things module in the terminal is started, the packet data protocol type is configured as an Internet protocol, which can further be any protocol in the Internet protocol, for example, an IPV6 protocol. After the terminal is successfully registered in a corresponding network node (MME), the terminal is attached to the MME. The terminal attached successfully obtains an Internet protocol address allocated by the network. Specifically, the terminal establishes a PDN (Public Data Network) link with an eNodeB (Evolved Node B) in an LTE network architecture, an SGW (Serving GateWay) and a PGW (PDN GateWay), and acquires an Internet protocol address, for example, an IPV6 address, allocated by the PDN GateWay.
[0104] Optionally, the terminal can also acquire a corresponding Internet protocol address from a DHCP (Dynamic Host Configuration Protocol) server connected to the terminal. After the terminal is logged in to the DHCP server, the server automatically allocates an Internet protocol address corresponding to the terminal.
[0105] Step 204, send the Internet protocol address to the server, wherein the server is used to encrypt the Internet protocol address to obtain a target Internet protocol address, and send the target Internet protocol address to the terminal and the cloud platform.
[0106] After the terminal obtains the corresponding Internet protocol address, the terminal sends the Internet protocol address to the server with which the terminal establishes a communication connection. For example, the terminal communicates with the server through TCP (Transmission Control Protocol).
[0107] After the server receives the Internet protocol address sent by the terminal, the server encrypts the Internet protocol address to obtain a target Internet protocol address corresponding to the Internet protocol address. The server then sends the target Internet protocol address to the terminal and the cloud platform. The server can send the target Internet protocol address to the terminal and the cloud platform at the same time, or can send the target Internet protocol address to the terminal and the cloud platform at a specific time interval.
[0108] Step 206, receive the target Internet protocol address sent by the server, and send a data transmission request to the cloud platform according to the target Internet protocol address.
[0109] The terminal receives the target Internet protocol address sent by the server, and sends a data transmission request to the cloud platform according to the target Internet protocol address, so as to trigger the cloud platform to verify whether the terminal is an authorized terminal according to the data transmission request. Optionally, the data transmission request sent by the terminal carries the target Internet protocol address, and the cloud platform verifies whether the terminal is an authorized terminal according to the received target Internet protocol address, and sends a verification result of verification pass or verification fail to the terminal. The data transmission request includes a login request of the terminal logging into the cloud platform or a data processing request of the terminal sending business data to report to the cloud platform. Correspondingly, if the cloud platform verifies that the terminal is an authorized terminal, the terminal can log in to the cloud platform or can complete the corresponding data processing request of the business data.
[0110] Step 208, receive the verification result fed back by the cloud platform according to the data transmission request.
[0111] After the cloud platform receives the data transmission request sent by the terminal, the cloud platform verifies the data transmission request sent by the terminal according to the target Internet protocol address. Optionally, if the target Internet protocol address carried by the terminal is consistent with the target Internet protocol address stored by the cloud platform, it is determined that the terminal is an authorized terminal, and a verification result of passing verification is sent to the terminal, and the terminal receives the verification result of passing verification fed back by the cloud platform according to the data transmission request; if the target Internet protocol address carried by the terminal is inconsistent with the target Internet protocol address stored by the cloud platform, it is determined that the terminal is an unauthorized terminal, and a verification result of failing to pass verification is sent to the terminal, and the terminal receives the verification result of failing to pass verification fed back by the cloud platform according to the data transmission request.
[0112] The above data verification method, the terminal obtains the corresponding Internet protocol address, and sends the obtained Internet protocol address to the server, wherein the server is configured to encrypt the Internet protocol address to obtain a target Internet protocol address, and send the target Internet protocol address to the terminal and the cloud platform; the terminal receives the target Internet protocol address sent by the server and sends a data transmission request to the cloud platform according to the target Internet protocol address, and receives a verification result fed back by the cloud platform according to the data transmission request. The server encrypts the Internet protocol address, and then returns the target Internet protocol address obtained by encryption to the terminal, which can reduce the data processing pressure of the terminal, speed up the processing speed of the terminal, reduce the occupation of the scarce storage space inside the terminal, and reduce the power consumption of the terminal.
[0113] In one embodiment, the step 202 of obtaining the Internet protocol address corresponding to the terminal comprises:
[0114] After the public data network link is established with the base station and the gateway, the Internet protocol address allocated by the gateway is obtained.
[0115] In this embodiment, the terminal can establish a PDN link with the base station eNodeB, the SGW and the PGW in the LTE network architecture, so as to obtain the Internet protocol address allocated by the PDN gateway, such as the IPV6 address. Optionally, after the terminal obtains the corresponding Internet protocol address, the terminal can store the Internet protocol address, for example, in the non-volatile memory (NVM) or the network card, so as to be used for subsequent data transmission.
[0116] In one embodiment, before the Internet protocol address corresponding to the terminal is obtained, the step further comprises: configuring the packet data protocol type as an Internet protocol.
[0117] In this embodiment, the terminal configures the packet data protocol type as an Internet protocol, so as to further obtain the corresponding Internet protocol address.
[0118] In some embodiments, the terminal further comprises a timer, wherein the timer is configured to time a preset time length during which the terminal is in the low power consumption mode; and the data verification method further comprises:
[0119] If a time length from a time point of entering the low power consumption mode to a current time point reaches the preset time length, the step of sending the data transmission request to the cloud platform according to the target Internet protocol address is performed; if the time length from the time point of entering the low power consumption mode to the current time point does not reach the preset time length, the low power consumption mode is continued.
[0120] In the terminal in the embodiments of the present application, in order to realize low power consumption, the terminal will be in a low power consumption mode (PSM) most of the time, that is, the terminal will turn off signal reception and transmission and related functions of the access layer within a preset time length of the low power consumption mode, so as to reduce power consumption of antennas, signaling, radio frequency processing, etc. A timer in the terminal will start timing each time the terminal enters the low power consumption mode, and if a time length from a time point of entering the low power consumption mode to a current time point reaches a preset time length, a data transmission request is sent to the cloud platform according to a target Internet protocol address; if the time length from the time point of entering the low power consumption mode to the current time point does not reach the preset time length, the low power consumption mode is continued.
[0121] It should be noted that when the terminal enters the low power consumption mode, no data transmission and sending are performed, and no data communication with the server or the terminal is performed. When the terminal is woken up from the low power consumption mode, data transmission and sending are performed, and a data transmission request can be sent to the cloud platform according to the target Internet protocol address.
[0122] In the above embodiments, the timer is used to time a preset time length during which the terminal is in the low power consumption mode, and when the terminal is woken up from the low power consumption mode, a data transmission request can be sent to the cloud platform according to the target Internet protocol address, so that each time a data transmission request is sent, the cloud platform is instructed to verify whether the terminal is an authorized terminal according to the data transmission request, thereby ensuring that the terminal can be comprehensively verified for legality while maintaining low power consumption.
[0123] In one example, as shown in FIG. 3, Figure 3 the data verification method comprises the following steps 302 to 312.
[0124] Step 302, the packet data protocol type is configured as IPV6.
[0125] Step 304, after establishing a public data network link with the base station and the gateway, an IPV6 address allocated by the gateway is obtained.
[0126] Step 306, the IPV6 address is sent to the server, wherein the server is used to encrypt the IPV6 address to obtain a target IPV6 address, and the target IPV6 address is sent to the terminal and the cloud platform.
[0127] Step 308, the target IPV6 address sent by the server is received, and a data transmission request is sent to the cloud platform according to the target IPV6 address.
[0128] Step 310, the verification result fed back by the cloud platform according to the data transmission request is received.
[0129] Step 312, enter the low-power mode. If the time length from the current time to the time of entering the low-power mode reaches the preset time length, step 308 is executed; if the time length from the current time to the time of entering the low-power mode does not reach the preset time length, the low-power mode is continued.
[0130] The above data verification method, the terminal configures the packet data protocol type as IPV6, and then obtains the corresponding IPV6 address. The IPV6 address is returned to the terminal after being encrypted by the server. The terminal sends a data transmission request to the cloud platform according to the encrypted target IPV6 address, so as to trigger the cloud platform to verify whether the terminal is an authorized terminal according to the data transmission request. The verification result fed back by the cloud platform according to the data transmission request is received, which can ensure that each terminal corresponds to a unique IPV6 address, reduce the occupation of the scarce storage space in the terminal, speed up the processing speed of the terminal, and reduce the power consumption of the terminal.
[0131] In one embodiment, as shown in Figure 4 , a data encryption method is provided. The method is applied to the server in Figure 1 for example. The server is in communication connection with the terminal, the server is in communication connection with the cloud platform, and the terminal is in communication connection with the cloud platform. The method includes the following steps 402 to step 406.
[0132] Step 402, receiving an internet protocol address sent by a terminal.
[0133] The server receives the internet protocol address sent by the terminal.
[0134] Step 404, encrypting the internet protocol address to obtain a target internet protocol address.
[0135] The server encrypts the Internet protocol address to obtain a target Internet protocol address. Optionally, the server encrypts the Internet protocol address according to an encryption algorithm to obtain the target Internet protocol address. The encryption algorithm may be, for example, an MD5 (Message-Digest Algorithm version.5) algorithm, an IDEA (International Data Encryption Algorithm) algorithm, an RSA (RSA algorithm) algorithm, or the like.
[0136] In an optional embodiment, the Internet protocol address sent by the terminal is an IPV6 address, and the server encrypts all or part of the IPV6 address, for example, encrypts the last 64 bits of the IPV6 address using an encryption algorithm to obtain the target Internet protocol address.
[0137] Step 406: sending the target Internet protocol address to the terminal and the cloud platform.
[0138] Optionally, the server sends the target Internet protocol address to the terminal and the cloud platform.
[0139] The above data encryption method encrypts the Internet protocol address received from the terminal to obtain a target Internet protocol address, and sends the target Internet protocol address to the terminal and the cloud platform, thereby quickly encrypting the Internet protocol address to obtain the target Internet protocol address, and sending the target Internet protocol address to the terminal and the cloud platform.
[0140] In one example, as shown in Figure 5 the data encryption method includes the following steps 502 to 506.
[0141] Step 502: receiving an IPV6 address sent by a terminal.
[0142] Step 504: encrypting the IPV6 address to obtain a target IPV6 address.
[0143] Step 506: sending the target IPV6 address to the terminal and the cloud platform.
[0144] In one embodiment, as shown in Figure 6 a data verification method is provided, which is applied to the cloud platform in Figure 1 for example. The cloud platform is in communication connection with a server, the cloud platform is in communication connection with a terminal, and the server is in communication connection with the terminal. The method includes the following steps 602 to 606.
[0145] Step 602, receiving a data transmission request sent by a terminal, wherein the data transmission request carries a first Internet Protocol address.
[0146] The cloud platform receives a data transmission request sent by a terminal, and the data transmission request carries a first Internet Protocol address. The first Internet Protocol address can be an Internet Protocol address corresponding to the terminal directly obtained by the terminal, or an address obtained by processing the Internet Protocol address directly obtained by the terminal, for example, an target Internet Protocol address obtained by encrypting the Internet Protocol address obtained by the terminal by a server.
[0147] Step 604, comparing the first Internet Protocol address with the target Internet Protocol address; wherein the target Internet Protocol address is received and saved by the cloud platform from the server, and the target Internet Protocol address is obtained by encrypting the Internet Protocol address corresponding to the terminal by the server.
[0148] The cloud platform compares the first Internet Protocol address with the target Internet Protocol address to determine whether the terminal sending the data transmission request is an authorized terminal. The target Internet Protocol address is received and saved by the cloud platform from the server, and the target Internet Protocol address is obtained by encrypting the Internet Protocol address corresponding to the terminal by the server. It should be noted that the target Internet Protocol address stored by the cloud platform can be multiple, which is obtained by encrypting the Internet Protocol addresses corresponding to multiple terminals by the server. Alternatively, the cloud platform compares the first Internet Protocol address with the target Internet Protocol address in sequence to see whether there is a target Internet Protocol address same as the first Internet Protocol address.
[0149] Step 606, when the first Internet Protocol address is same as the target Internet Protocol address, it is determined that the terminal is an authorized terminal, and a verification result of passing verification is sent to the terminal; when the first Internet Protocol address is different from the target Internet Protocol address, it is determined that the terminal is an unauthorized terminal, and a verification result of failing verification is sent to the terminal.
[0150] When the first Internet Protocol address is same as the target Internet Protocol address, it is determined that the terminal sending the data transmission request carries the target Internet Protocol address, and the terminal is an authorized terminal, and a verification result of passing verification is sent to the terminal; when the first Internet Protocol address is different from the target Internet Protocol address, it is determined that the terminal sending the data transmission request carries the target Internet Protocol address, and the terminal is an unauthorized terminal, and a verification result of failing verification is sent to the terminal.
[0151] The data verification method comprises the following steps: receiving a data transmission request sent by a terminal, wherein the data transmission request carries a first Internet protocol address; comparing the first Internet protocol address with a target Internet protocol address, the target Internet protocol address being sent and saved by a cloud platform receiving server, and the target Internet protocol address being obtained by encrypting an Internet protocol address corresponding to the terminal by the server; when the first Internet protocol address is the same as the target Internet protocol address, it is determined that the terminal is an authorized terminal; and when the first Internet protocol address is different from the target Internet protocol address, it is determined that the terminal is an unauthorized terminal. The terminal can be quickly verified, so as to determine whether the terminal is an authorized terminal, and the authorized terminal can be quickly connected to the cloud platform, thereby realizing safe data transmission.
[0152] In one embodiment, the data verification method further comprises:
[0153] When it is determined that the terminal is an authorized terminal, the data in the data transmission request is processed; and when it is determined that the terminal is an unauthorized terminal, the data in the data transmission request is discarded.
[0154] When it is determined that the terminal sending the data transmission request is an authorized terminal, the data in the data transmission request is processed; and when it is determined that the terminal sending the data transmission request is an unauthorized terminal, the data in the data transmission request is discarded. The authorized terminal can be safely connected to the cloud platform, and the data can be quickly and effectively processed.
[0155] In one example, as shown in FIG. 7, the data verification method comprises the following steps 702 to 708. Figure 7
[0156] Step 702: receiving a data transmission request sent by a terminal, wherein the data transmission request carries a first Internet protocol address.
[0157] Step 704: comparing the first Internet protocol address with a target Internet protocol address; wherein the target Internet protocol address is sent and saved by a cloud platform receiving server, and the target Internet protocol address is obtained by encrypting an Internet protocol address corresponding to the terminal by the server.
[0158] Step 706: when the first Internet protocol address is the same as the target Internet protocol address, it is determined that the terminal is an authorized terminal, the data in the data transmission request is processed, and a verification result of passing the verification is sent to the terminal.
[0159] Step 708: when the first Internet protocol address is different from the target Internet protocol address, it is determined that the terminal is an unauthorized terminal, the data in the data transmission request is discarded, and a verification result of failing the verification is sent to the terminal.
[0160] In one embodiment, as shown in Figure 8 A data verification and encryption method is provided, in which a cloud platform is in communication connection with a server, the cloud platform is in communication connection with a terminal, and the server is in communication connection with the terminal. The method includes the following steps 802 to 820.
[0161] In step 802, the terminal acquires an internet protocol address corresponding to the terminal.
[0162] In step 804, the terminal sends the internet protocol address to the server.
[0163] In step 806, the server receives the internet protocol address sent by the terminal.
[0164] In step 808, the server encrypts the internet protocol address to obtain a target internet protocol address.
[0165] In step 810, the server sends the target internet protocol address to the terminal and the cloud platform.
[0166] In step 812, the terminal receives the target internet protocol address sent by the server and sends a data transmission request to the cloud platform according to the target internet protocol address; and the cloud platform receives the target internet protocol address sent by the server and stores it.
[0167] In step 814, the cloud platform receives the data transmission request sent by the terminal, wherein the data transmission request carries a first internet protocol address.
[0168] In step 816, the cloud platform compares the first internet protocol address with the target internet protocol address.
[0169] In step 818, when the first internet protocol address is the same as the target internet protocol address, the cloud platform determines that the terminal is an authorized terminal and sends a verification result of passing verification to the terminal; and when the first internet protocol address is different from the target internet protocol address, the cloud platform determines that the terminal is an unauthorized terminal and sends a verification result of failing verification to the terminal.
[0170] In step 820, the terminal receives the verification result fed back by the cloud platform according to the data transmission request.
[0171] The above data verification and encryption method can reduce the data processing pressure of the terminal, speed up the processing speed of the terminal, reduce the occupation of the scarce storage space inside the terminal, and reduce the power consumption of the terminal. In addition, the terminal can be safely connected to the cloud platform to realize data transmission and communication.
[0172] It should be understood that although each step in the flowchart involved in each embodiment as described above is shown in sequence according to the direction of the arrow, these steps are not necessarily executed in the order indicated by the arrow. Unless explicitly stated herein, there is no strict order limitation for the execution of these steps, and these steps can be executed in other orders. Moreover, at least some of the steps in the flowchart involved in each embodiment as described above can include multiple steps or multiple stages, which are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily sequential, but can be alternately or alternately executed with at least part of other steps or stages.
[0173] Based on the same inventive concept, the embodiments of the present application also provide a data verification device for implementing the above-mentioned data verification method, and a data encryption device for implementing the data encryption method. The implementation scheme for solving the problem provided by the device is similar to the implementation scheme described in the above method, so the specific limitations in one or more data verification device and data encryption device embodiments provided below can refer to the limitations of the data verification method and the data encryption method described above, which will not be repeated here.
[0174] In one embodiment, as shown in FIG. 9, a data verification device is provided, comprising a data acquisition module 902, a data sending module 904, a first receiving module 906 and a second receiving module 908, wherein: Figure 9
[0175] The data acquisition module 902 is configured to acquire an internet protocol address corresponding to a terminal.
[0176] The data sending module 904 is configured to send the internet protocol address to a server, wherein the server is configured to encrypt the internet protocol address to obtain a target internet protocol address, and send the target internet protocol address to the terminal and a cloud platform.
[0177] The first receiving module 906 is configured to receive the target internet protocol address sent by the server, and send a data transmission request to the cloud platform according to the target internet protocol address.
[0178] The second receiving module 908 is configured to receive a verification result fed back by the cloud platform according to the data transmission request.
[0179] In one embodiment, the data acquisition module 902 is further configured to acquire an internet protocol address allocated by a gateway after establishing a public data network link with the gateway and a base station.
[0180] In one embodiment, the data verification apparatus further comprises a protocol configuration module, configured to configure a packet data protocol type as an Internet protocol before the Internet protocol address corresponding to the terminal is acquired.
[0181] In one embodiment, the terminal further comprises a timer configured to time a preset duration during which the terminal is in a low power consumption mode; and the data verification apparatus further comprises a timing module configured to:
[0182] If a duration from a time point when the terminal enters the low power consumption mode to a current time point reaches the preset duration, the step of sending a data transmission request to the cloud platform according to the target Internet protocol address is performed; if the duration from the time point when the terminal enters the low power consumption mode to the current time point does not reach the preset duration, the terminal continues to enter the low power consumption mode.
[0183] In one embodiment, as shown in FIG. 10, a data encryption apparatus is provided, comprising an address receiving module 1002, an address encryption module 1004 and an address sending module 1006, wherein: Figure 10 The address receiving module 1002 is configured to receive an Internet protocol address sent by a terminal.
[0184] The address encryption module 1004 is configured to encrypt the Internet protocol address to obtain a target Internet protocol address.
[0185]
[0186] The address sending module 1006 is configured to send the target Internet protocol address to the terminal and the cloud platform.
[0187] In one embodiment, as shown in FIG. 11, a data verification apparatus is provided, comprising a request receiving module 1102, an address comparison module 1104 and a terminal determining module 1106, wherein: Figure 11 The request receiving module 1102 is configured to receive a data transmission request sent by a terminal, wherein the data transmission request carries a first Internet protocol address.
[0188] The address comparison module 1104 is configured to compare the first Internet protocol address with a target Internet protocol address; the target Internet protocol address is received and saved by a receiving server of the cloud platform, and the target Internet protocol address is obtained by encrypting an Internet protocol address corresponding to the terminal by a server.
[0189]
[0190] The terminal determination module 1106 is used to determine that the terminal is an authorized terminal when the first Internet Protocol address is the same as the target Internet Protocol address, and to send a verification result indicating that the verification has passed to the terminal; and to determine that the terminal is an unauthorized terminal when the first Internet Protocol address is different from the target Internet address, and to send a verification result indicating that the verification has failed to pass to the terminal.
[0191] In one embodiment, the data verification device further includes a data processing module, which processes the data in the data transmission request when the terminal is determined to be an authorized terminal, and discards the data in the data transmission request when the terminal is determined to be an unauthorized terminal.
[0192] Each module in the aforementioned data verification and data encryption devices can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in the processor of the electronic device in hardware form or independent of it, or stored in the memory of the electronic device in software form, so that the processor can call and execute the operations corresponding to each module.
[0193] In one embodiment, an electronic device is provided, which may be a terminal, and its internal structure diagram may be as follows: Figure 12 As shown, the electronic device includes a processor, memory, communication interface, display screen, and input device connected via a system bus. The processor provides computing and control capabilities. The memory includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage medium. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, mobile cellular networks, NFC (Near Field Communication), or other technologies. When executed by the processor, the computer program implements a data verification method.
[0194] Those skilled in the art will understand that Figure 12 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the electronic device to which the present application is applied. The specific electronic device may include more or fewer components than shown in the figure, or combine certain components, or have different component arrangements.
[0195] Those skilled in the art will understand that the electronic device may be a wireless communication module, or a smart device containing a wireless communication module (such as a smart car, smart cabinet, smart meter, etc.), or a communication device such as a mobile phone, computer, or tablet.
[0196] In an embodiment, an electronic device is provided, comprising a memory and a processor, the memory storing a computer program, the processor implementing the steps of the data verification method of any of the above embodiments when executing the computer program.
[0197] In an embodiment, a computer readable storage medium is provided, storing a computer program, the computer program being executed by a processor to implement the steps of the data verification method of any of the above embodiments.
[0198] In an embodiment, a computer program product is provided, comprising a computer program, the computer program being executed by a processor to implement the steps of the data verification method of any of the above embodiments.
[0199] In an embodiment, an electronic device is provided, comprising a memory and a processor, the memory storing a computer program, the processor implementing the steps of the data encryption method of any of the above embodiments when executing the computer program.
[0200] In an embodiment, a computer readable storage medium is provided, storing a computer program, the computer program being executed by a processor to implement the steps of the data encryption method of any of the above embodiments.
[0201] In an embodiment, a computer program product is provided, comprising a computer program, the computer program being executed by a processor to implement the steps of the data encryption method of any of the above embodiments.
[0202] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or authorized by all parties.
[0203] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer readable storage medium, and when the computer program is executed, the processes of the above-mentioned embodiments of the methods can be included. Any reference to memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (Read-Only Memory, ROM), magnetic tape, floppy disk, flash memory, optical storage, high-density embedded non-volatile memory, resistive memory (ReRAM), magnetoresistive random access memory (Magnetoresistive Random Access Memory, MRAM), ferroelectric memory (Ferroelectric Random Access Memory, FRAM), phase change memory (Phase Change Memory, PCM), graphene memory, etc. Volatile memory can include random access memory (Random Access Memory, RAM) or external cache memory, etc. As an illustration but not limitation, RAM can be in various forms, such as static random access memory (Static Random Access Memory, SRAM) or dynamic random access memory (Dynamic Random Access Memory, DRAM), etc. The database involved in the embodiments provided in the present application can include at least one of a relational database and a non-relational database. The non-relational database can include a distributed database based on a block chain, etc., without being limited thereto. The processor involved in the embodiments provided in the present application can be a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, etc., without being limited thereto.
[0204] Any combination of the technical features of the above embodiments can be made. In order to make the description simple, all possible combinations of the technical features in the above embodiments are not described, however, as long as the combination of the technical features does not exist contradictory, it should be considered as the scope of the present application.
[0205] The above embodiments only express several implementation manners of the present application, and the description is more specific and detailed, but it should not be understood as a limitation on the scope of the patent of the present application. It should be pointed out that for ordinary skilled in the art, without departing from the concept of the present application, a number of modifications and improvements can be made, which are within the scope of protection of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.
Claims
1. A data verification method, characterized in that, Applied to a terminal, wherein the terminal is communicatively connected to a server, the server is communicatively connected to a cloud platform, and the terminal is communicatively connected to the cloud platform, the method includes: After establishing a public data network link with the base station and the gateway, obtain the Internet Protocol address corresponding to the terminal assigned by the gateway; The Internet Protocol address is sent to the server, wherein the server is used to encrypt the Internet Protocol address to obtain the target Internet Protocol address, and then send the target Internet Protocol address to the terminal and the cloud platform; Receive the target Internet Protocol address sent by the server, and send a data transmission request to the cloud platform according to the target Internet Protocol address; Receive the verification result fed back by the cloud platform based on the data transmission request.
2. The method according to claim 1, characterized in that, The terminal further includes a timer, which is used to time a preset duration for which the terminal is in low-power mode; the method further includes: If the time elapsed since the start of the low-power mode reaches the preset time, the step of sending a data transmission request to the cloud platform based on the target Internet Protocol address is executed. If the time elapsed since the start of the low-power mode has not reached the preset time, then the system will continue to enter the low-power mode.
3. A data encryption method, characterized in that, Applied to a server, wherein the server is communicatively connected to a terminal, the server is communicatively connected to a cloud platform, and the terminal is communicatively connected to the cloud platform, the method includes: The receiving terminal sends an Internet Protocol (IP) address; the IP address is assigned to the terminal by the gateway after the terminal establishes a public data network link with the base station and the gateway. The Internet Protocol address is encrypted to obtain the target Internet Protocol address; The target Internet Protocol address is sent to the terminal and the cloud platform to instruct the terminal to send a data transmission request to the cloud platform based on the target Internet Protocol address, and to receive the verification result fed back by the cloud platform based on the data transmission request.
4. A data verification method, characterized in that, Applied to a cloud platform, wherein the cloud platform is communicatively connected to a server, the cloud platform is communicatively connected to a terminal, and the server is communicatively connected to the terminal, the method includes: A data transmission request sent by a receiving terminal, wherein the data transmission request carries a first Internet Protocol address; Compare the first Internet Protocol address with the target Internet Protocol address; the target Internet Protocol address is sent and stored by the cloud platform receiving server, and the target Internet Protocol address is obtained by the server encrypting the Internet Protocol address corresponding to the terminal; When the first Internet Protocol address is the same as the target Internet Protocol address, the terminal is determined to be an authorized terminal, and a verification result indicating successful verification is sent to the terminal. When the first Internet Protocol address is different from the target Internet Protocol address, the terminal is determined to be an unauthorized terminal, and a verification result indicating that the verification failed is sent to the terminal.
5. The method according to claim 4, characterized in that, The method further includes: When the terminal is determined to be an authorized terminal, the data in the data transmission request is processed. When the terminal is determined to be an unauthorized terminal, the data in the data transmission request is discarded.
6. A data verification device, characterized in that, The device includes: The data acquisition module is used to acquire the Internet Protocol address corresponding to the terminal allocated by the gateway after establishing a public data network link with the base station and the gateway. A data sending module is used to send the Internet Protocol address to the server, wherein the server is used to encrypt the Internet Protocol address to obtain a target Internet Protocol address, and send the target Internet Protocol address to the terminal and the cloud platform; The first receiving module is used to receive the target Internet Protocol address sent by the server and send a data transmission request to the cloud platform according to the target Internet Protocol address; The second receiving module is used to receive the verification results fed back by the cloud platform based on the data transmission request.
7. An encryption device, characterized in that, The device includes: The address receiving module is used to receive the Internet Protocol address sent by the terminal; the Internet Protocol address is assigned to the terminal by the gateway after the terminal establishes a public data network link with the base station and the gateway; The address encryption module is used to encrypt the Internet Protocol address to obtain the target Internet Protocol address; The address sending module is used to send the target Internet Protocol address to the terminal and the cloud platform, so as to instruct the terminal to send a data transmission request to the cloud platform according to the target Internet Protocol address, and to receive the verification result fed back by the cloud platform according to the data transmission request.
8. A data verification device, characterized in that, The device includes: A request receiving module is used to receive a data transmission request sent by a terminal, wherein the data transmission request carries a first Internet Protocol address; The address comparison module is used to compare the first Internet Protocol address with the target Internet Protocol address; the target Internet Protocol address is sent and stored by the cloud platform receiving server, and the target Internet Protocol address is obtained by the server encrypting the Internet Protocol address corresponding to the terminal; The terminal determination module is configured to determine that the terminal is an authorized terminal when the first Internet Protocol address is the same as the target Internet Protocol address, and send a verification result indicating that the verification has passed to the terminal; and to determine that the terminal is an unauthorized terminal when the first Internet Protocol address is different from the target Internet Protocol address, and send a verification result indicating that the verification has failed to pass to the terminal.
9. An electronic device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 5.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 5.
11. A computer program product, characterized in that, It includes a computer program that, when executed by a processor, implements the steps of the method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Operation method and system of Internet of Things equipment
CN112468538A
Internet-of-Things system based on NB-IoT and block chain technology and implementation method
CN112887076A
NB-IoT-based animal remote monitoring and nerve regulation and control system
CN212694562U
IP address managing server, user terminal and program
JP2007189620A