A data transmission method, device, equipment and storage medium

By using the encryption method of private key and public key in the inadvertent transmission protocol, combining the key derivation function and the elliptic curve encryption algorithm, the problem of high computational complexity during data transmission is solved, and efficient data transmission is achieved.

CN115604006BActive Publication Date: 2025-07-11AGRICULTURAL BANK OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211261523.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-14
Publication Date
2025-07-11
Estimated Expiration
2042-10-14

AI Technical Summary

Technical Problem

In the existing inadvertent transmission protocol, the data sender and the data receiver have high computational complexity when encrypting/decrypting data, resulting in low transmission efficiency.

Method used

The encryption method based on private key and public key is adopted, combined with the key derived function and the elliptic curve encryption algorithm, and the data is processed through symmetric encryption algorithms and hash functions, reducing exponential operations and improving data transmission efficiency.

Benefits of technology

On the premise of ensuring data privacy, by simplifying the encryption and decryption process, the efficiency of data transmission is improved and the computational complexity is reduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115604006B_ABST
    Figure CN115604006B_ABST
Patent Text Reader

Abstract

The present application discloses a data transmission method, apparatus, device, and storage medium, including: a data sending device may encrypt first data based on a private key and a public key of a data receiving device to obtain a first encrypted number. The first data is processed using a symmetric encryption algorithm to obtain first encrypted data. Then, first target data is determined based on the first encrypted number and the first encrypted data and sent to the data receiving device. The data receiving device may determine second encrypted data based on the public key and the elliptic curve base point of the data sending device, and the data sending device processes the second encrypted data and sends third encrypted data to the data receiving device, so that the data receiving device determines a second encrypted number based on the third encrypted data. Through the above data transmission method, the data sending device and the data receiving device can realize data sending and receiving without complex operations such as exponential products, which can improve the efficiency of data transmission.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of data processing, and in particular, to a data transmission method, apparatus, device, and storage medium. Background Art

[0002] With the rapid development of big data and cloud computing, the amount of information has grown explosively. At the same time, people's attention to privacy has also become increasingly high. Oblivious transfer, as a basic protocol in cryptography, has important applications in fields such as multi-party secure computing, privacy queries, and data mining, and can achieve the full utilization of data while protecting personal privacy.

[0003] In current oblivious transfer protocols, when the data sender and the data receiver perform data encryption / decryption, they usually use exponential product operations, resulting in relatively high computational complexity for the data sender and the data receiver and relatively low data transmission efficiency. Summary of the Invention

[0004] In view of this, this application provides a data transmission method, apparatus, device, and storage medium to improve the efficiency of data transmission.

[0005] In a first aspect, this application provides a data transmission method, which is applied to a data sending device. The data sending device includes first data, and the method includes:

[0006] Determine a first encryption number corresponding to the first data based on the private key of the data sending device and the public key of the data receiving device;

[0007] Determine a first symmetric key based on a key derivation function and the first encryption number;

[0008] Process the first data using a symmetric encryption algorithm and the first symmetric key to obtain first encrypted data;

[0009] Determine a first target data based on the first encrypted data and the first encryption number;

[0010] Send the first target data to the data receiving device.

[0011] In a possible implementation manner, the determining a first symmetric key based on a key derivation function and the first encryption number includes:

[0012] Determine the first symmetric key based on a key derivation function, the first encryption number, and a random number of the data sending device, where the random number of the data sending device corresponds to the first data.

[0013] In a possible implementation, determining the first target data based on the first encrypted data and the first encrypted number includes:

[0014] Determining a first hash value corresponding to the first encrypted number based on a hash function;

[0015] Determining the first target data based on the first hash value, a random number of the data sending device, and the first encrypted data.

[0016] It can be seen that the data sending device can encrypt the first data based on the private key and the public key of the data receiving device and send it to the data receiving device, without complex calculation methods such as exponential product operations, which can improve the efficiency of data transmission.

[0017] In a second aspect, the present application provides a data transmission method, which is applied to a data receiving device. The method includes:

[0018] Determining second encrypted data based on the public key of the data receiving device and the elliptic curve base point of the data sending device;

[0019] Sending the second encrypted data to the data sending device so that the data sending device processes the second encrypted data based on its own private key and obtains third encrypted data;

[0020] Receiving the third encrypted data sent by the data sending device;

[0021] Determining a second encrypted number based on the third encrypted data and the public key of the data sending device;

[0022] Parsing the first target data sent by the data sending device based on the second encrypted number to obtain second target data.

[0023] In a possible implementation, determining the second encrypted data based on the public key of the data receiving device and the elliptic curve base point of the data sending device includes:

[0024] Determining the second encrypted data based on the public key of the data receiving device, a target data number, the elliptic curve base point of the data sending device, and a random number of the data receiving device. The data receiving device includes multiple target data numbers, and the multiple target data numbers, the random number of the data receiving device, and the second target data correspond to each other.

[0025] In a possible implementation, determining the second encrypted number based on the third encrypted data and the public key of the data sending device includes:

[0026] Determine the second encryption number based on the third encrypted data, the random number of the data receiving device, and the public key of the data sending device.

[0027] Through the method described in the second aspect, the data receiving device can encrypt the data it wants to obtain based on its own public key, private key, and the elliptic curve base point of the data sending device, and determine the second encryption number based on the third encrypted data sent by the data sending device, so as to parse the data sent by the data sending device based on the second encryption number, thereby decrypting to obtain the desired data. Through the elliptic curve encryption algorithm, the encryption and decryption of data can be realized without complex exponential operations, which can improve the efficiency of data transmission.

[0028] In a third aspect, the present application provides a data transmission device, which is applied to a data sending device. The data sending device includes first data, and the device includes:

[0029] A first determination unit, configured to determine a first encryption number corresponding to the first data based on the private key of the data sending device and the public key of the data receiving device;

[0030] A second determination unit, configured to determine a first symmetric key based on a key derivation function and the first encryption number;

[0031] A processing unit, configured to process the first data by using a symmetric encryption algorithm and the first symmetric key to obtain first encrypted data;

[0032] A third determination unit, configured to determine first target data based on the first encrypted data and the first encryption number;

[0033] A first sending unit, configured to send the first target data to the data receiving device.

[0034] In a fourth aspect, the present application provides a data transmission device, which is applied to a data receiving device. The device includes:

[0035] A fourth determination unit, configured to determine second encrypted data based on the public key of the data receiving device and the elliptic curve base point of the data sending device;

[0036] A second sending unit, configured to send the second encrypted data to the data sending device, so that the data sending device processes the second encrypted data based on its own private key and obtains third encrypted data;

[0037] A receiving unit, configured to receive the third encrypted data sent by the data sending device;

[0038] A fifth determination unit, configured to determine a second encryption number based on the third encrypted data and the public key of the data sending device;

[0039] An analysis unit, configured to analyze the first target data sent by the data sending device based on the second encryption number to obtain second target data.

[0040] In a fifth aspect, the present application provides a data transmission device, where the device includes: a memory and a processor;

[0041] The memory is used to store relevant program codes;

[0042] The processor is used to call the program codes to execute the data transmission method according to any one of the implementation manners in the first aspect or the second aspect.

[0043] In a sixth aspect, the present application provides a computer-readable storage medium, which is used to store a computer program, and the computer program is used to execute the data transmission method according to any one of the implementation manners in the first aspect or the second aspect. Description of the Drawings

[0044] To more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments provided in the present application. For those of ordinary skill in the art, other drawings can also be obtained according to these drawings.

[0045] Figure 1 It is a flowchart of a data transmission method provided by an embodiment of the present application;

[0046] Figure 2 It is a flowchart of another data transmission method provided by an embodiment of the present application;

[0047] Figure 3 It is a schematic diagram of a data transmission device provided by an embodiment of the present application;

[0048] Figure 4 It is a schematic diagram of another data transmission device provided by an embodiment of the present application;

[0049] Figure 5 It is a schematic diagram of a data transmission device provided by an embodiment of the present application. Detailed Embodiments

[0050] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. The described embodiments are only exemplary embodiments of the present application and not all implementation manners. A person skilled in the art can obtain other embodiments without creative efforts in combination with the embodiments of the present application, and these embodiments are also within the protection scope of the present application.

[0051] Oblivious transfer, as a basic protocol in cryptography, has important applications in fields such as multi-party secure computing, privacy queries, and data mining, and can realize the full utilization of data while protecting personal privacy. The currently used oblivious transfer protocol is the 1-out-of-n OT version (OTn 1 ), in the n-out-of-t oblivious transfer protocol, the data holder (sender) has n pieces of information, and the data receiver wants to obtain t of them. Through the exchange of information, the data receiver can only obtain the t pieces of data it wants and cannot obtain the remaining n - t pieces of data, and the data holder does not know the specific t pieces of data selected by the receiver. This feature of oblivious transfer makes it have important applications in fields such as multi-party secure computing and privacy information queries.

[0052] In the current oblivious transfer protocol, when the data sender and the data receiver perform data encryption / decryption, they usually use exponential product operations, resulting in relatively high computational complexity for the data sender and the data receiver and relatively low data transmission efficiency.

[0053] Based on this, the embodiments of the present application provide a data transmission method, which can improve the data transmission efficiency during the data transmission process between the data sending device and the data receiving device. To facilitate understanding of the technical solutions provided by the embodiments of the present application, the following will be specifically introduced in conjunction with the accompanying drawings.

[0054] See Figure 1 , Figure 1 which is a flowchart of a data transmission method provided by an embodiment of the present application.

[0055] This method is applied to a data sending device, and this method may include the following steps:

[0056] S101: Determine a first encryption number corresponding to the first data based on the private key of the data sending device and the public key of the data receiving device.

[0057] Among them, the data sending device includes first data. When the first data includes multiple data, for any one of the data, an encrypted number corresponding to the data can be determined based on the private key of the data sending device and the public key of the data receiving device, so that the first encrypted number corresponding to the first data can be determined, that is, the encrypted number corresponding to each data in the first data can be determined. It should be noted that the public key of the data sending device can be known by the data receiving device, but the private key of the data sending device is only known by itself, and the data receiving device cannot know it. Similarly, the public key of the data receiving device can be known by the data sending device, but the private key of the data receiving device is only known by itself, and the data sending device cannot know it. In specific implementation, numbers can be assigned to each data in the first data, and then the numbers of each data, the private key of the data sending device, and the public key of the data receiving device are used for elliptic curve multiplication operation to obtain the encrypted number corresponding to each data, so that the first encrypted number corresponding to the first data can be obtained. Subsequently, the first encrypted number can be matched with the encrypted number generated by the data receiving device, so that the data receiving device can obtain the desired data.

[0058] S102: Determine a first symmetric key based on a key derivation function and the first encrypted number.

[0059] After obtaining the first encrypted number, a key derivation function and the first encrypted number can be used to determine the first symmetric key required for the symmetric encryption algorithm. Optionally, the first symmetric key can be determined based on the key derivation function, the first encrypted number, and the random number of the data sending device. Among them, the random number of the data sending device corresponds to the first data. For example, when the first data includes n data, the data sending device includes n random numbers, and the random number can be generated by a random number generator, which is not limited in this embodiment.

[0060] S103: Process the first data using the symmetric encryption algorithm and the first symmetric key to obtain first encrypted data.

[0061] Among them, the symmetric encryption algorithm can be the AES algorithm, the SM4 algorithm, etc., which is not limited in this embodiment.

[0062] S104: Determine a first target data based on the first encrypted data and the first encrypted number.

[0063] After obtaining the first encrypted data, the final first target data can be determined based on the first encrypted data and the first encryption number. In specific implementation, the first hash value corresponding to the first encryption number can be determined based on a hash function first, and then the uniqueness of the hash value can be used to match the encryption numbers of the data receiving device. Then, based on the first hash value, the random number of the data sending device, and the first encrypted data, the first target data can be determined. For example, the first hash value corresponding to the first encryption number, the random number of the data sending device, and the first encrypted data can be concatenated to obtain the first target data.

[0064] S105: Send the first target data to the data receiving device.

[0065] After sending the first target data to the data receiving device, since the first target data is encrypted using the private key of the data sending device, the data sending device needs to encrypt the data it wants to obtain through an encryption algorithm so that it can match the first target data of the data sending device, and thus the desired data can be decrypted. The principle of data transmission by the data sending device will be described in detail below with reference to the accompanying drawings.

[0066] See Figure 2 , Figure 2 which is a flowchart of another data transmission method provided by an embodiment of the present application.

[0067] This method is applied to a data receiving device, and the method may include the following steps:

[0068] S201: Determine the second encrypted data based on the public key of the data receiving device and the elliptic curve base point of the data sending device.

[0069] In this embodiment, when the data receiving device and the data sending device perform data transmission through an encryption algorithm, the data receiving device can only obtain the data it needs from the first data of the data sending device. For the convenience of encryption calculation, optionally, the data receiving device can number the data it wants to obtain. For example, when the data receiving device needs to obtain t data, the data in the t data can be numbered 1, 2,..., t respectively. The data receiving device can determine the second encrypted data based on its own public key, the target data number, the elliptic curve base point of the data sending device, and the random number of the data receiving device. Among them, the target data number is the number of the data that the data receiving device wants to obtain, and the elliptic curve base point of the data sending device can be determined in advance by the data sending device. The number of random numbers of the data receiving device corresponds to the number of target data numbers, and the random number can be generated in advance by a random number generator. This embodiment does not limit this. Specifically, let E tj1 represent any data in the second encrypted data, and let t jIndicates the target data number, denoted as P b Indicates the public key of the data receiving device, denoted as r bj Indicates the random number of the data receiving device, denoted as G A Indicates the elliptic curve base point of the data sending device, then E tj1 The calculation formula of can be expressed as E tj1 =t j P b +r bj G A , where t j ∈[1,t], t represents t data that the data receiving device wants to obtain from the first data of the data receiving device, so that the data receiving device can perform encryption processing on the data it wants to obtain and obtain the second encrypted data.

[0070] S202: Send the second encrypted data to the data sending device so that the data sending device can process the second encrypted data based on its own private key and obtain the third encrypted data.

[0071] After the data receiving device sends the second encrypted data to the data sending device, the data sending device can continue to perform encryption processing on the second encrypted data using its own private key to obtain the third encrypted data. This is to enable the data sending device to encrypt the first data using the same encryption method, that is, calculate the first encryption number, and facilitate the subsequent data receiving device to obtain the target data in the encrypted data constructed by the data receiving device using the same encryption method through encryption calculation when the data receiving device cannot know the private key of the data sending device.

[0072] S203: Receive the third encrypted data sent by the data sending device.

[0073] After the data sending device obtains the third encrypted data through private key encryption processing, it can send the third encrypted data to the data receiving device.

[0074] S204: Determine the second encryption number based on the third encrypted data and the public key of the data sending device.

[0075] After the data receiving device receives the third encrypted data, it can perform encryption calculation based on the third encrypted data and the public key of the data sending device to determine the second encryption number. Specifically, the data receiving device can use the third encrypted data, the random number of the data receiving device, and the public key of the data sending device to determine the second encryption number. For example, for any data that the data receiving device wants to obtain, it can be denoted as D tj Indicates the second encryption number, denoted as E tj1 ’ represents the third encrypted data. Since the third encrypted data E tj1 ’ is obtained by the data sending device using its private key to encrypt the second encrypted data Etj1 Obtained through encryption processing. According to the above embodiments, the second encrypted data E tj1 can be expressed as E tj1 = t j P b + r bj G A . Then the third encrypted data E tj1 ' can be expressed as E tj1 ' = K a E tj1 = K a (t j P b + r bj G A ), where K a represents the private key of the data sending device. P a can be used to represent the public key of the data sending device. Then the calculation formula for the second encryption number D tj can be expressed as D tj = E tj1 ' - r bj P a = K a (t j P b + r bj G A ) - r bj P a = K a P b t j + r bj K a G A - r bj P a . According to the principle of the elliptic curve encryption algorithm, multiplying the elliptic curve base point of the data sending device by the private key can obtain the public key of the data sending device, that is, K a G A = P a . Then D tj can be obtained as D a = K b P j t bj + r a K A G bj P a = K a P b t j .

[0076] S205: Analyze the first target data sent by the data sending device based on the second encryption number to obtain the second target data.

[0077] When the data receiving device does not know the private key of the data sending device, it calculates a second encryption number through an encryption algorithm, which has the same form as the first encryption number obtained by the data sending device for the first data encryption process. Therefore, the data receiving device can parse the first target data sent by the data sending device based on the second encryption number, so as to obtain the required second target data.

[0078] In specific implementation, according to the above embodiments, the first target data can be obtained by splicing the first hash value corresponding to the first encryption number, the random number of the data sending device, and the first encrypted data. Therefore, the data receiving device can use the same hash function to determine the hash value corresponding to the second encryption number, and match the hash value corresponding to the second encryption number with the hash value corresponding to the first encryption number. According to the uniqueness of the hash function, when the corresponding hash values are the same, the first encryption number and the second encryption number are the same. Therefore, the data receiving device can decrypt the data it wants to obtain. For example, when the hash value of the first encryption number matches the hash value of the second encryption number successfully, the key derivation function used by the data sending device can be used to calculate and determine the second symmetric key, that is, the key for decrypting the encrypted data, based on the second encryption number and the random number of the data sending device. Since the key derivation function is the same and the random number is the same, the second symmetric key is the same as the first symmetric key. Since the first encrypted data is encrypted by the data sending device using the symmetric encryption algorithm and the first symmetric key, the data receiving device can use the second symmetric key and the symmetric encryption algorithm used by the data sending device to decrypt the first encrypted data in the first target data, and thus obtain the original data required by the data receiving device.

[0079] Through the data transmission method provided by the above embodiments, the data sending device and the data receiving device perform data sending and receiving after obtaining the encryption number through data encryption processing, so that the data sending device does not know the data that the data receiving device wants to obtain. The data receiving device can only decrypt the data it wants to obtain according to the matching of the encryption number, and cannot decrypt other data of the data sending device. While ensuring data privacy, it does not require complex exponential operations, improving the efficiency of data transmission.

[0080] Based on the above method embodiments, an embodiment of the present application provides a data transmission device. Refer to Figure 3 , Figure 3 which is a schematic diagram of a data transmission device provided by an embodiment of the present application.

[0081] The device 300 can be applied to a data sending device. The data sending device includes first data. The device 300 includes:

[0082] The first determination unit 301 is configured to determine a first encryption number corresponding to the first data based on the private key of the data sending device and the public key of the data receiving device;

[0083] The second determination unit 302 is configured to determine a first symmetric key based on a key derivation function and the first encryption number;

[0084] The processing unit 303 is configured to process the first data by using a symmetric encryption algorithm and the first symmetric key to obtain first encrypted data;

[0085] The third determination unit 304 is configured to determine first target data based on the first encrypted data and the first encryption number;

[0086] The first sending unit 305 is configured to send the first target data to the data receiving device.

[0087] In a possible implementation manner, the second determination unit 302 is specifically configured to determine the first symmetric key based on a key derivation function, the first encryption number, and a random number of the data sending device, where the random number of the data sending device corresponds to the first data.

[0088] In a possible implementation manner, the third determination unit 304 is specifically configured to determine a first hash value corresponding to the first encryption number based on a hash function; and determine the first target data based on the first hash value, the random number of the data sending device, and the first encrypted data.

[0089] In addition, an embodiment of the present application further provides a data transmission device. Refer to Figure 4 , Figure 4 which is a schematic diagram of another data transmission device provided by an embodiment of the present application.

[0090] The device 400 can be applied to a data receiving device, and the device 400 may include:

[0091] The fourth determination unit 401 is configured to determine second encrypted data based on the public key of the data receiving device and the elliptic curve base point of the data sending device;

[0092] The second sending unit 402 is configured to send the second encrypted data to the data sending device, so that the data sending device processes the second encrypted data based on its own private key and obtains third encrypted data;

[0093] The receiving unit 403 is configured to receive the third encrypted data sent by the data sending device;

[0094] A fifth determination unit 404, configured to determine a second encryption number based on the third encrypted data and the public key of the data sending device;

[0095] A parsing unit 405, configured to parse the first target data sent by the data sending device based on the second encryption number to obtain second target data.

[0096] In a possible implementation manner, the fourth determination unit 401 is specifically configured to determine the second encrypted data based on the public key of the data receiving device, a target data number, the elliptic curve base point of the data sending device, and the random number of the data receiving device. The data receiving device includes a plurality of the target data numbers, and the plurality of target data numbers, the random number of the data receiving device, and the second target data correspond to each other.

[0097] In a possible implementation manner, the fifth determination unit 404 is specifically configured to determine the second encryption number based on the third encrypted data, the random number of the data receiving device, and the public key of the data sending device.

[0098] The beneficial effects of the data transmission device provided in the embodiments of the present application can be seen in the above method embodiments, and will not be elaborated here.

[0099] Based on the above method embodiments and device embodiments, the embodiments of the present application further provide a data transmission device. Refer to Figure 5 , Figure 5 which is a schematic diagram of a data transmission device provided in the embodiments of the present application.

[0100] The device 500 includes: a memory 501 and a processor 502;

[0101] The memory 501 is used to store relevant program codes;

[0102] The processor 502 is used to call the program codes to execute the data transmission method described in the above method embodiments.

[0103] In addition, the embodiments of the present application further provide a computer-readable storage medium, and the computer-readable storage medium is used to store a computer program, and the computer program is used to execute the data transmission method described in the above method embodiments.

[0104] It should be noted that the embodiments in this specification are described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. For the similarities and common parts among the embodiments, reference can be made to each other. In particular, for the system or device embodiments, since they are basically similar to the method embodiments, the description is relatively simple. For the relevant parts, reference can be made to the corresponding descriptions in the method embodiments. The device embodiments described above are merely illustrative. The units or modules described as separate components may or may not be physically separated. The components shown as units or modules may or may not be physical modules, that is, they may be located in one place or distributed to multiple network units. Some or all of the units or modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement this without creative efforts.

[0105] It should be understood that in this application, "at least one (item)" means one or more, and "a plurality" means two or more. "And / or" is used to describe the association relationship of associated objects and indicates that three relationships may exist. For example, "A and / or B" may mean: only A exists, only B exists, and both A and B exist at the same time. Here, A and B can be singular or plural. The character " / " generally indicates that the associated objects before and after are in an "or" relationship. "At least one (one)" or its similar expression means any combination of these items, including any combination of single item (one) or plural items (ones). For example, at least one (one) of a, b, or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.

[0106] It should also be noted that in this article, relative terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitations, the element defined by the statement "including one..." does not exclude the existence of additional identical elements in the process, method, article or device including the said element.

[0107] The steps of the methods or algorithms described in connection with the embodiments disclosed herein may be implemented directly in hardware, in software modules executed by a processor, or in a combination thereof. The software modules may be located in random access memory (RAM), memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, a removable disk, a CD-ROM, or any other form of storage medium well known in the art.

[0108] The foregoing description of the disclosed embodiments enables those skilled in the art to make or use the present application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present application. Thus, the present application is not intended to be limited to the embodiments shown herein but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A data transmission method, characterized in that, The method is applied to a data sending device, which includes first data, and the method comprises: Determine a first encryption number corresponding to the first data based on the private key of the data sending device and the public key of the data receiving device; Determine a first symmetric key based on a key derivation function and the first encryption number; Process the first data by using a symmetric encryption algorithm and the first symmetric key to obtain first encrypted data; Determine first target data based on the first encrypted data and the first encryption number, including: Determine a first hash value corresponding to the first encryption number based on a hash function; Determine the first target data based on the first hash value, the random number of the data sending device, and the first encrypted data; Send the first target data to the data receiving device so that the data receiving device parses the first target data by using a second encryption number to obtain second target data; the second hash value corresponding to the second encryption number matches the first hash value, the second encryption number is determined by the data receiving device, and the second hash value is determined by the data receiving device by using the hash function.

2. The method according to claim 1, wherein The determining the first symmetric key based on the key derivation function and the first encryption number includes: Determine the first symmetric key based on the key derivation function, the first encryption number, and the random number of the data sending device, where the random number of the data sending device corresponds to the first data.

3. A data transmission method, characterized in that, The method is applied to a data receiving device, and the method comprises: Determine second encrypted data based on the public key of the data receiving device and the elliptic curve base point of the data sending device; Send the second encrypted data to the data sending device so that the data sending device processes the second encrypted data based on its own private key and obtains third encrypted data; Receive the third encrypted data sent by the data sending device; Determine a second encryption number based on the third encrypted data and the public key of the data sending device; Determine a second hash value corresponding to the second encryption number based on a hash function; If the second hash value successfully matches the first hash value corresponding to the first encryption number, parse the first target data sent by the data sending device based on the second encryption number to obtain second target data, where the first encryption number is determined by the data sending device, the first encryption number is used to determine the first target data, and the first hash value is determined by the data sending device by using the hash function.

4. The method according to claim 3, wherein The determining the second encrypted data based on the public key of the data receiving device and the elliptic curve base point of the data sending device includes: Determine the second encrypted data based on the public key of the data receiving device, a target data number, the elliptic curve base point of the data sending device, and the random number of the data receiving device, where the data receiving device includes multiple target data numbers, and the multiple target data numbers, the random number of the data receiving device, and the second target data correspond to each other.

5. The method according to claim 3, wherein Determining a second encryption number based on the third encrypted data and the public key of the data sending device includes: Determining the second encryption number based on the third encrypted data, the random number of the data receiving device, and the public key of the data sending device.

6. A data transmission device, characterized in that, The apparatus is applied to a data sending device, the data sending device includes first data, and the apparatus includes: A first determination unit, configured to determine a first encryption number corresponding to the first data based on the private key of the data sending device and the public key of the data receiving device; A second determination unit, configured to determine a first symmetric key based on a key derivation function and the first encryption number; A processing unit, configured to process the first data by using a symmetric encryption algorithm and the first symmetric key to obtain first encrypted data; A third determination unit, configured to determine a first hash value corresponding to the first encryption number based on a hash function; determine first target data based on the first hash value, the random number of the data sending device, and the first encrypted data; A first sending unit, configured to send the first target data to the data receiving device, so that the data receiving device parses the first target data by using a second encryption number to obtain second target data; a second hash value corresponding to the second encryption number matches the first hash value, the second encryption number is determined by the data receiving device, and the second hash value is determined by the data receiving device by using the hash function.

7. A data transmission device, characterized in that, The apparatus is applied to a data receiving device, and the apparatus includes: A fourth determination unit, configured to determine second encrypted data based on the public key of the data receiving device and the elliptic curve base point of the data sending device; A second sending unit, configured to send the second encrypted data to the data sending device, so that the data sending device processes the second encrypted data based on its own private key and obtains third encrypted data; A receiving unit, configured to receive the third encrypted data sent by the data sending device; A fifth determination unit, configured to determine a second encryption number based on the third encrypted data and the public key of the data sending device; The fifth determination unit is further configured to determine a second hash value corresponding to the second encryption number based on a hash function; An analysis unit, configured to, if the second hash value successfully matches the first hash value corresponding to the first encryption number, parse the first target data sent by the data sending device based on the second encryption number to obtain second target data, the first encryption number is determined by the data sending device, the first encryption number is used to determine the first target data, and the first hash value is determined by the data sending device by using the hash function.

8. A data transmission device, characterized in that, The device includes: a memory and a processor; The memory is used to store relevant program codes; The processor is used to call the program codes to execute the data transmission method according to any one of claims 1 to 2 or 3 to 5.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium is used to store a computer program, and the computer program is used to execute the data transmission method according to any one of claims 1 to 2 or 3 to 5.

Citation Information

Patent Citations

  • Medical data encryption transmission system and method

    CN107018145A

  • Data encryption transmission method and device, computer device and storage medium

    CN109768979A