Sensitive information security acquisition method, system and device and electronic equipment
By using a multi-level key system in smart home appliance systems, sensitive information encryption packets and identity password packets are stored in different devices. Combining asymmetric and symmetric key decryption, the risk of sensitive information leakage caused by key leakage is solved, and highly secure and reliable acquisition of sensitive information is achieved.
Patent Information
- Application Number
- CN202211679577.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-26
- Publication Date
- 2026-01-02
- Estimated Expiration
- 2042-12-26
AI Technical Summary
In existing smart home appliance systems, keys are stored long-term at the smart appliance end and the application control end, which is prone to leakage, resulting in a high risk of leakage of sensitive information and attack risks, and extremely low security.
The sensitive information encryption package, identity password package, and application programming interface key are pre-generated by the third device and stored in the second device. The first device needs to obtain both the asymmetric and symmetric keys for decryption to ensure that no single device can decrypt the sensitive information alone. This multi-level key system protects against the leakage of non-root keys.
This significantly increases the difficulty of obtaining sensitive information, reduces the risk of leakage and attack, and improves the security and transmission reliability of smart home appliance systems.
Smart Images

Figure CN116015647B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of information security, and in particular to a sensitive information security acquisition method, system, device and electronic equipment. BACKGROUND
[0002] With the development of Internet of Things technology, the fields of Internet of Things such as home appliance networking and Internet of Vehicles have also made great progress in technology and application scenarios. In particular, the Internet of Things of communication equipment has become more convenient, faster and more intelligent with the continuous maturity of Bluetooth technology, wireless network communication (Wi-Fi) technology, face recognition technology and fingerprint recognition technology. The most typical smart home appliance system includes a smart home appliance end, a cloud server end and an application control end. Sensitive information can come from at least one end of the smart home appliance system. Therefore, how to store and acquire sensitive information is particularly important.
[0003] In related technologies, the smart home appliance system usually communicates between the smart home appliance end and the application control end. The smart home appliance end and the application control end determine fixed password information as a key, and the key is stored in the smart home appliance end and the application control end. In this way, the application control end can view the encrypted sensitive information generated by the smart home appliance end through the key.
[0004] However, since the key stored in the existing smart home appliance end and the application control end exists for a long time and is not replaced, the key is easily leaked, which leads to the encrypted information being easily decrypted, thereby making it very easy to acquire sensitive information, and the risk of leakage and attack of sensitive information is very high, and the security is very low. SUMMARY
[0005] The present application aims to at least solve one of the technical problems in the related art. To this end, the present application proposes a sensitive information security acquisition method, which not only realizes the purpose that the leakage of the key stored in a single device does not cause the leakage of sensitive information, but also realizes the purpose that the plaintext information of sensitive information can be acquired only by the cooperation of the keys stored in two different devices, ensuring that any device in the smart home appliance system cannot decrypt sensitive information alone, greatly improving the difficulty of acquiring sensitive information, and greatly reducing the risk of leakage and attack of sensitive information, thereby greatly improving the security of acquiring sensitive information in the smart home appliance system.
[0006] The present application also proposes a sensitive information security acquisition system.
[0007] The present application also proposes a sensitive information security acquisition device.
[0008] The present application also proposes an electronic equipment.
[0009] The application further provides a non-transitory computer readable storage medium.
[0010] The application further provides a computer program product.
[0011] According to the sensitive information security acquisition method of the first aspect of the application, the method comprises:
[0012] acquiring, from the second device, a sensitive information encryption package, an identity password package and an application programming interface key;
[0013] decrypting the sensitive information encryption package and the identity password package based on the first private key of the first device and the application programming interface key, and acquiring sensitive information in the sensitive information encryption package
[0014] The sensitive information encryption package, the identity password package and the application programming interface key are pre-generated by a third device and stored in the second device, and the third device destroys the application programming interface key based on a storage success result.
[0015] According to the sensitive information security acquisition method of the application, the first device acquires sensitive information in the sensitive information encryption package by first acquiring, from the second device, a sensitive information encryption package, an identity password package and an application programming interface key, and then decrypting the sensitive information encryption package and the identity password package based on the first private key of the first device and the application programming interface key. Since the sensitive information encryption package, the identity password package and the application programming interface key are pre-generated by a third device and stored in the second device, and the third device destroys the application programming interface key based on a storage success result, the two keys stored in different devices need to be decrypted before the sensitive information can be viewed by the first device, which not only realizes the purpose of not leaking the keys stored in a single device and not causing the leakage of sensitive information, but also realizes the purpose of obtaining the plaintext information of sensitive information by the mutual cooperation of the keys stored in two different devices, ensures that any device in the smart home system cannot decrypt the sensitive information alone, effectively resists a plurality of known attack methods, guarantees the confidentiality, integrity and availability of sensitive information and the security and reliability of transmission in the smart home system, greatly improves the difficulty of obtaining sensitive information, greatly reduces the risk of leakage and attack of sensitive information, and thus greatly improves the security of obtaining sensitive information in the smart home system.
[0016] According to one embodiment of the application, the acquiring, from the second device, of the sensitive information encryption package, the identity password package and the application programming interface key comprises:
[0017] sending an information use authorization request to the second device, the information use authorization request being used for requesting the second device to issue the stored sensitive information encryption package, the identity password package and the application programming interface key;
[0018] receiving an information use authorization response sent by the second device, the information use authorization response including the sensitive information encryption package, the identity password package and the application programming interface key.
[0019] According to an embodiment of the present application, the decrypting the sensitive information encryption package and the identity password package based on the first private key of the first device and the application programming interface key, and obtaining the sensitive information in the sensitive information encryption package comprises:
[0020] decrypting the identity password package based on the first private key of the first device, and obtaining a key encryption package;
[0021] decrypting the key encryption package based on the application programming interface key, and obtaining a session key;
[0022] decrypting the sensitive information encryption package based on the session key, and obtaining the sensitive information in the sensitive information encryption package.
[0023] According to an embodiment of the present application, the second device is one of a smart home appliance device, a server and an application control device, the second device is different from the first device, and the second device is a device with at least an information storage function.
[0024] The sensitive information security obtaining system according to the second aspect embodiment of the present application comprises a first device and a second device, and the first device and the second device are in communication connection, wherein:
[0025] The first device is configured to obtain a sensitive information encryption package, an identity password package and an application programming interface key from the second device, and decrypt the sensitive information encryption package and the identity password package based on a first private key of the first device and the application programming interface key, and obtain sensitive information in the sensitive information encryption package.
[0026] The second device is configured to store the sensitive information encryption package, the identity password package and the application programming interface key.
[0027] The sensitive information encryption package, the identity password package and the application programming interface key are pre-generated by a third device and stored in the second device, and the third device destroys the application programming interface key based on a storage success result.
[0028] According to the sensitive information security acquisition system of the embodiment of the present application, the first device acquires the sensitive information in the sensitive information encryption package by first acquiring the sensitive information encryption package, the identity password package and the application programming interface key from the second device, and then decrypting the sensitive information encryption package and the identity password package based on the first private key of the first device and the application programming interface key. Since the sensitive information encryption package, the identity password package and the application programming interface key are pre-generated by the third device and stored in the second device, and the third device destroys the application programming interface key based on the storage success result, the asymmetric password and the symmetric password stored in different devices are required to be decrypted before the sensitive information is viewed by the first device, which not only realizes the purpose that the key stored in a single device is leaked without causing the leakage of the sensitive information, but also realizes the purpose that the plaintext information of the sensitive information can be acquired only by the cooperation of the keys stored in two different devices, ensures that any device in the smart home system cannot decrypt the sensitive information alone, effectively resists the currently known attack methods, guarantees the confidentiality, integrity and availability of the sensitive information and the security and reliability of the transmission in the smart home system, greatly improves the difficulty of acquiring the sensitive information, greatly reduces the leakage risk and attack risk of the sensitive information, and thus greatly improves the security of acquiring the sensitive information in the smart home system.
[0029] According to an embodiment of the present application, the third device is further configured to generate a session key, derive an application programming interface key using a root secret key, encrypt the sensitive information based on the session key to determine a sensitive information encryption package, encrypt the session key based on the application programming interface key and a first public key of the first device to determine an identity password package, and send the sensitive information encryption package, the identity password package and the application programming interface key to the second device for storage.
[0030] According to the sensitive information security acquisition device of the second aspect embodiment of the present application, the device comprises:
[0031] The first acquisition module is configured to acquire the sensitive information encryption package, the identity password package and the application programming interface key from the second device.
[0032] The second acquisition module is configured to decrypt the sensitive information encryption package and the identity password package based on the first private key of the first device and the application programming interface key, and acquire the sensitive information in the sensitive information encryption package.
[0033] The sensitive information encryption package, the identity password package and the application programming interface key are pre-generated by a third device and stored in the second device, and the third device destroys the application programming interface key based on a storage success result.
[0034] The sensitive information security acquisition device according to the embodiment of the present application acquires the sensitive information in the sensitive information encryption package by first acquiring the sensitive information encryption package, the identity password package and the application programming interface key from the second device, and then decrypting the sensitive information encryption package and the identity password package based on the first private key of the first device and the application programming interface key. Since the sensitive information encryption package, the identity password package and the application programming interface key are pre-generated by a third device and stored in the second device, and the third device destroys the application programming interface key based on a storage success result, the two keys stored in different devices need to be decrypted before the sensitive information is viewed, which not only realizes the purpose that the leakage of the key stored in a single device does not cause the leakage of the sensitive information, but also realizes the purpose that the plaintext information of the sensitive information can be acquired only by the cooperation of the keys stored in two different devices, so that any device in the smart home system cannot decrypt the sensitive information alone, effectively resisting various attack methods known at present, ensuring the confidentiality, integrity and availability of the sensitive information and the security and reliability of the transmission in the smart home system, greatly improving the difficulty of acquiring the sensitive information, greatly reducing the leakage risk and attack risk of the sensitive information, and thus greatly improving the security of acquiring the sensitive information in the smart home system.
[0035] The one or more technical solutions in the embodiments of the present application have at least one of the following technical effects: the first device obtains the sensitive information in the sensitive information encryption package by first obtaining the sensitive information encryption package, the identity password package and the application programming interface key from the second device, and then decrypting the sensitive information encryption package and the identity password package based on the first private key and the application programming interface key of the first device. Since the sensitive information encryption package, the identity password package and the application programming interface key are pre-generated by the third device and stored in the second device, and the third device destroys the application programming interface key based on the storage success result, the asymmetric password and the symmetric password stored in different devices are required to be decrypted before the first device views the sensitive information, which not only realizes the purpose that the key leakage of a single device does not cause the leakage of sensitive information, but also realizes the purpose that the plaintext information of the sensitive information can be obtained only by the cooperation of the keys stored in two different devices, so that the security of obtaining the sensitive information in the smart home system is greatly improved.
[0036] Further, the first device obtains the sensitive information encryption package, the identity password package and the application programming interface key from the second device by sending an information use authorization request to the second device and receiving an information use authorization response sent by the second device, which realizes the purpose of obtaining the sensitive information encryption package, the identity password package and the application programming interface key from the second device. Since the sensitive information encryption package, the identity password package and the application programming interface key are generated by the third device and pre-stored in the second device, the hardware resources of a device in the smart home system can be effectively utilized, the burden of other devices is reduced, the reliability and security of obtaining the information use authorization response from the second device are improved, and the confidentiality, integrity and availability of the sensitive information in the transmission process are further ensured.
[0037] Further, the first device decrypts the session key by first using the first private key for outer decryption and then using the application programming interface key for outer decryption with respect to the identity password package, and obtains the sensitive information in the sensitive information encryption package by decrypting the sensitive information encryption package using the session key. In this way, the multi-level key system is combined to effectively protect the unauthorized access problem caused by the leakage of the non-root secret key, and the random key exists in the key system, so that the cracking difficulty and the risk threat after cracking are further increased by using one device one key.
[0038] Additional aspects and advantages of the present application will be given in part in the following description, become apparent from the following description, or be understood through practice of the present application. BRIEF DESCRIPTION OF DRAWINGS
[0039] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the related art, the following will briefly introduce the drawings needed to be used in the embodiments or related art description. Obviously, the drawings in the following description only constitute some embodiments of the present application, and for those skilled in the art, other drawings can also be obtained without creative labor based on these drawings.
[0040] Figure 1 is a flowchart of the sensitive information security acquisition method provided by the embodiments of the present application;
[0041] Figure 2 is one of the application scenarios of the sensitive information security acquisition method provided by the embodiments of the present application;
[0042] Figure 3 is another of the application scenarios of the sensitive information security acquisition method provided by the embodiments of the present application;
[0043] Figure 4 is a structural diagram of the sensitive information security acquisition device provided by the embodiments of the present application;
[0044] Figure 5 is a structural diagram of the electronic device provided by the embodiments of the present application. DETAILED DESCRIPTION
[0045] In order to make the objects, technical solutions and advantages of the present application clearer, the technical solutions in the present application will be described clearly and completely below in combination with the drawings in the present application. Obviously, the described embodiments are only some of the embodiments of the present application, not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.
[0046] With the development of Internet of Things technology, the fields of home appliance networking and Internet of Vehicles have also made great progress in technology and application scenarios. Especially, the communication device IoTization has become more convenient, faster and more intelligent with the continuous maturity of Bluetooth technology, Wi-Fi technology, face recognition technology and fingerprint technology. The most typical smart home appliance system includes three important components: smart home appliance end, cloud server end and application control end. The sensitive information may come from any one of the three ends, and the use of the sensitive information may be at least one of the three ends. How to safely process, transmit and use the sensitive information has always been a research hotspot in the industry.
[0047] In the prior art, symmetric encryption or asymmetric encryption is usually set as a key for two of the three ends (such as the smart home appliance end and the application control end), and the key is stored in the smart home appliance end and the application control end, so that the application control end can view the encrypted sensitive information generated by the smart home appliance end through the key.
[0048] However, since the key stored in the existing smart home appliance end and the application control end exists for a long time and is not replaced, there are inevitably problems such as symmetric key leakage, no security management of key life cycle, and / or at least one component in the smart home system cannot reasonably control access. For example, since the key is easy to leak, the encrypted information is easy to be decrypted; thus, it is very low to obtain sensitive information, the risk of sensitive information leakage and attack is very large, and the security is very low.
[0049] To solve the above problems, the present application provides a sensitive information security acquisition method, system, device and electronic equipment, which are described below in combination with Figures 1-5 The sensitive information security acquisition method, system, device and electronic equipment of the present application are described, wherein the execution subject of the sensitive information security acquisition method can be a first device, the first device can be a device in a smart home system, the smart home system at least includes a smart home device, a server and an application control device, the application control device can contain a terminal device of an application program for controlling the smart home device, the terminal device can be a personal computer (PC), a portable device, a notebook computer, a smart phone, a tablet computer and other electronic devices such as a portable wearable device; further, the server can refer to a server, or a server cluster composed of multiple servers, a cloud computing center, etc.; the smart home device can be a home appliance product formed by introducing microprocessor, sensor technology, network communication technology into home appliance, which has automatic perception of residential space state and home appliance itself state, home appliance service state, and can automatically control and receive control instructions of residential users in the residence or remotely, such as a smart speaker, a sweeping robot, a smart door lock or a smart camera, etc. The present application does not limit the specific form of the smart home device, the server and the application control device. The following method embodiment is described by taking the first device as an example.
[0050] Referring to Figure 1 The flowchart of the sensitive information security acquisition method provided by the embodiment of the present application is shown in Figure 1 As shown in the figure, the sensitive information security acquisition method is applied to the first device, which includes the following steps:
[0051] Step 110, obtaining a sensitive information encryption package, an identity password package and an application programming interface key from a second device.
[0052] The sensitive information encryption package, the identity password package, and the application programming interface key are pre-generated by the third device and stored in the second device, and the third device destroys the application programming interface key based on a storage success result; the second device can be a device at least having a storage function, and the third device can be a device at least having a sensitive information generation function and a key derivation function; the first device, the second device, and the third device are different devices in the smart home system, that is, the first device, the second device, and the third device are different from each other. Moreover, the sensitive information encryption package can be an information package after sensitive information is encrypted, the identity password package can be an authorization password package set for the first device having a sensitive information viewing or using demand in the smart home system, and the application programming interface key (API Key) can be an API used for authenticating a user, a developer, or a unique identifier provided by a calling application, or can be an identity document (ID) of a device generating the sensitive information encryption package, that is, the API Key is a key for decrypting the identity password package and is also an authorization key for verifying whether the first device has a sensitive information viewing or using right.
[0053] Specifically, the second device pre-stores the sensitive information encryption package containing sensitive information required to be viewed or used by the first device, the identity password package for verifying whether the first device has a sensitive information viewing or using right, and the API Key for decrypting the identity password package and the sensitive information encryption package. Based on this, when the first device receives a viewing or using instruction of the sensitive information by the user, the first device can obtain the sensitive information encryption package, the identity password package, and the application programming interface key from the second device based on an information interaction protocol established in advance between the first device and the second device, so as to obtain the sensitive information required to be viewed or used by decoding.
[0054] It should be noted that, for the user, data that can bring the user major economic loss or adverse effects is defined as sensitive information, and the sensitive information can include but is not limited to an identity document number, personal biological identification information, a bank account number, communication records and contents, property information, credit information, a trace trajectory, accommodation information, health physiological information, transaction information, personal information of children under 14 years old, and the like, and the sensitive information can be video information, image information, or text information. The specific form of the sensitive information is not limited here.
[0055] Step 120: decrypting the sensitive information encryption package and the identity password package based on the first private key of the first device and the application programming interface key, to obtain the sensitive information in the sensitive information encryption package.
[0056] Specifically, the first device decrypts the sensitive information encryption package and the identity password package based on the application programming interface key obtained from the second device and the first private key of the first device. To ensure the security of the storage and acquisition of the sensitive information in the smart home system, the first device can pre-generate a pair of asymmetric keys of the first public key and the first private key based on a preset public-private key generation algorithm, the first public key and the application programming interface key are used to generate the identity password package, the first private key and the application programming interface key are used to decrypt the identity password package, and the identity password package determined based on the pair of symmetric keys of the first public key of the first device and the application programming interface key is pre-stored in the second device. Moreover, the first device can be pre-set to decrypt the identity password package using the first private key and the application programming interface key, and after successful decryption, the sensitive information encryption package can be further decrypted to obtain the sensitive information in the sensitive information encryption package.
[0057] The sensitive information security acquisition method provided by the application can obtain the sensitive information in the sensitive information encryption package by the first device through the way of first obtaining the sensitive information encryption package, the identity password package and the application programming interface key from the second device, and then decrypting the sensitive information encryption package and the identity password package based on the first private key of the first device and the application programming interface key. Since the sensitive information encryption package, the identity password package and the application programming interface key are pre-generated by the third device and stored in the second device, and the third device will destroy the application programming interface key based on the storage success result, the two keys of the asymmetric password and the symmetric password need to be decrypted before the sensitive information is viewed by the first device, and the two keys are stored in different devices. Not only can the purpose of not causing the leakage of sensitive information be achieved when the key stored in a single device is leaked, but also the purpose of obtaining the plaintext information of the sensitive information through the cooperation of the keys stored in two different devices can be achieved. It is ensured that any device in the smart home system cannot decrypt the sensitive information alone, effectively resisting various attack methods known at present, ensuring the confidentiality, integrity and availability of the sensitive information and the security and reliability of the transmission in the smart home system, greatly improving the difficulty of obtaining the sensitive information, and greatly reducing the leakage risk and attack risk of the sensitive information, thereby greatly improving the security of obtaining the sensitive information in the smart home system.
[0058] It can be understood that, considering that the third device in the smart home system is used to generate the sensitive information encryption package, the identity password package and the application programming interface key, the third device can first determine that the sensitive information encryption package, the identity password package and the application programming interface key generated by the third device are stored in the second device, and then the first device can acquire the information by sending a request to the second device and then receiving a response. Based on this, the specific implementation process of step 110 can include:
[0059] First, the second device sends information usage authorization request, information usage authorization request for requesting the second device to issue stored sensitive information encryption package, identity password package and application programming interface key; further receive the information usage authorization response sent by the second device, the information usage authorization response includes sensitive information encryption package, identity password package and application programming interface key.
[0060] Specifically, in the intelligent household appliance system, the third device can be set to first generate sensitive information encryption package, identity password package and application programming interface key, and then send the generated sensitive information encryption package, identity password package and application programming interface key to the second device for storage. The second device stores the received sensitive information encryption package, identity password package and application programming interface key and can display a storage success identifier. Based on this, when the first device sends an information usage authorization request to the second device, the second device can respond to the information usage authorization request based on the storage success identifier, that is, send an information usage authorization response to the first device, so that the first device receives the sensitive information encryption package, identity password package and application programming interface key sent by the second device. Conversely, when the second device does not detect the storage success identifier for the received information usage authorization request, it can be considered that at least one of the sensitive information encryption package, identity password package and application programming interface key has not been successfully stored or has been stored invalid. At this time, it does not respond to the information usage authorization request, but outputs a prompt information that the information has not been stored or has been stored invalid to the first terminal.
[0061] It should be noted that the third device can first perform three-level key derivation based on a preset key derivation logic algorithm to determine the root key (Rootkey), session key and application programming interface key (APIKey), then encrypt the generated sensitive information based on the session key to determine the sensitive information encryption package, encrypt the session key based on the APIKey to determine the key encryption package, and finally encrypt the key encryption package using the first public key of the first device to determine the identity password package. At this time, the third device can send the sensitive information encryption package, identity password package and APIKey to the second device in the form of a package for storage.
[0062] The sensitive information security acquisition method provided by the application, the first device realizes the purpose of acquiring the sensitive information encryption package, the identity password package and the application programming interface key from the second device by sending the information use authorization request to the second device and receiving the information use authorization response sent by the second device, since the sensitive information encryption package, the identity password package and the application programming interface key are generated by the third device and pre-stored in the second device, the hardware resources of a device in the smart home system can be effectively utilized, the burden of other devices is reduced, the reliability and security of the information use authorization response acquired from the second device are improved, the confidentiality, integrity and availability of the sensitive information in the transmission process are further ensured.
[0063] It can be understood that, in order to ensure the security of acquiring the sensitive information, the key for decrypting the sensitive information encryption package can be stored in the identity encryption package, and the sensitive information can be acquired by first decrypting the identity encryption package and then decrypting the sensitive information encryption package. Based on this, the specific implementation process of step 120 can include:
[0064] Firstly, the identity password package is decrypted based on the first private key of the first device to acquire the key encryption package; then the key encryption package is further decrypted based on the application programming interface key to acquire the session key; and then the sensitive information encryption package is decrypted based on the session key to acquire the sensitive information in the sensitive information encryption package.
[0065] Specifically, since the identity password package is determined by first encrypting the session key using the APIKey to determine the key encryption package and then encrypting the key encryption package using the first public key of the first device, that is, it can be determined that the identity password package includes the outer encryption package encrypted by the first public key of the first device and the inner encryption package encrypted by the APIKey, therefore, the first device can decrypt the outer encryption package of the identity password package based on the first private key of the first device to determine the key encryption package, and then decrypt the inner package using the APIKey, that is, decrypt the key encryption package using the APIKey to determine the session key, at this time, the first device decrypts the sensitive information encryption package using the session key, and the sensitive information in the sensitive information encryption package can be acquired.
[0066] The sensitive information security acquisition method provided by the application, the first device decrypts the session key by first using the first private key to perform outer decryption and then using the application programming interface key to perform outer decryption on the identity password package, and acquires the sensitive information in the sensitive information encryption package by decrypting the sensitive information encryption package using the session key. In this way, the multi-level key system is combined to effectively protect the unauthorized access problem caused by the leakage of the non-root secret key, and the random key exists in the key system, so that the cracking difficulty and the risk threat after cracking can be further increased by using one device one key.
[0067] It can be understood that, with reference to Figure 2 , the application scenario of the sensitive information security acquisition method provided by the embodiment of the present application is shown in Figure 2 , the first device, the second device and the third device all have the function of generating a public-private key pair, that is, the first device can generate Pub_key1 and Pri_key1 based on a preset public-private key generation algorithm; the second device can generate Pub_key2 and Pri_key2 based on a preset public-private key generation algorithm; and the third device can also generate Pub_key3 and Pri_key3 based on a preset public-private key generation algorithm; but in actual processing, only the first device with sensitive information use requirements needs to generate a public-private key pair, and other devices do not need to generate a public-private key pair; further, the third device not only has the function of generating a public-private key pair, but also has the function of multi-level key derivation, that is, based on a preset key derivation logic, a root key RootKey, a session key and an APIKey are generated, and the number of session keys can be the same as and one-to-one corresponding to the number of generated sensitive information; when the sensitive information generated in the third device is different, different session keys are also encrypted to generate different sensitive information encryption packages, that is, sensitive information 1 is encrypted by sessionKey1 to generate a sensitive information 1 encryption package, sensitive information 2 is encrypted by sessionKey2 to generate a sensitive information 2 encryption package, and sensitive information 3 is encrypted by sessionKey3 to generate a sensitive information 3 encryption package; then, the third device first encrypts different session keys using APIKey to generate different key encryption packages, and then encrypts different key encryption packages using Pub_key x to generate different identity password packages, Pub_key x can be the first public key of the first device, that is, Pub_key x can be the first public key of the first device, and Pub_key x can be Pub_key1, Pub_key2 or Pub_key3.
[0068] At this time, the third device sends different sensitive information encryption packages and different identity password packages in the form of a packaged group to other devices for storage, while also sending APIKey to other devices for data storage. In order to facilitate the first device to view sensitive information in the future, different keys are obtained from different devices for decryption. In this way, the third key system of the third device in the smart home system is combined, and the one device one key method meets the randomness, and also realizes the purpose that any end key leakage in the smart home system will not cause sensitive information leakage. Effectively use the hardware resources of a certain device in the smart home system, reduce the burden of other devices, and at the same time, in the case of multiple devices in the smart home system, control a certain device or multiple devices, which cannot store user sensitive information in plaintext and cannot be decrypted, meet the privacy compliance requirements. Further, any device in the smart home system cannot decrypt sensitive data alone, and both asymmetric keys and symmetric keys are required to effectively decrypt and single device is effective, shielding group attack events.
[0069] It can be understood that when the second device is one of the smart home device, the server and the application control device, the second device is different from the first device; and the second device is a device with at least information storage function; can refer to the application scene schematic diagram shown in Figure 3 In Figure 3 , the first device can be an application control device, such as a mobile phone application; the second device is a server, such as a cloud server; the third device is a smart home device, such as a sensitive device; at this time, the sensitive information security acquisition system is a smart home system. The sensitive device is the general term of the disturbed object in the electrical system; the sensitive device can be a very small electronic component, a circuit board assembly, or a single electrical device, or even a large system.
[0070] As shown in Figure 3As shown, when the application control device receives the user's sensitive information viewing requirement instruction, Pub_key1 and Pri_key1 can be generated based on the preset public-private key generation algorithm, and Pub_key1 is sent to the smart home appliance device; when the server receives the user's sensitive information viewing requirement instruction, Pub_key2 and Pri_key2 can also be generated based on the preset public-private key generation algorithm, and Pub_key2 is sent to the smart home appliance device; similarly, the smart home appliance device receiving the user's sensitive information viewing requirement instruction can also generate Pub_key3 and Pri_key3 based on the preset public-private key generation algorithm, and can also generate a root secret key RootKey, a session key and an APIKey based on key derivation logic, and the number of session keys is the same as the number of generated sensitive information and one-to-one correspondence; when the sensitive information generated in the smart home appliance device is different, different session keys are also encrypted to generate different sensitive information encryption packages, that is, when the smart home appliance device generates three sensitive information of video information 1, image information 2 and video information 3, video information 1 is encrypted by sessionKey1 to generate video information 1 encryption package, image information 2 is encrypted by sessionKey2 to generate image information 2 encryption package, and video information 3 is encrypted by sessionKey3 to generate video information 3 encryption package.
[0071] Then, for the current application control device with sensitive information viewing demand, the smart home appliance device first uses APIKey to encrypt different session keys to generate different key encryption packages, that is, 3 key encryption packages; then uses the received Pub_key1 of the application control device to respectively encrypt the 3 key encryption packages to generate 3 identity password packages, namely identity password package 1, identity password package 2 and identity password package 3. At this time, the smart home appliance device further sends the video information 1 encryption package and the identity password package 1 in the form of group package 1, the image information 2 encryption package and the identity password package 2 in the form of group package 2, and the video information 3 encryption package and the identity password package 3 in the form of group package 3 to the server for storage, and also sends the APIKey to the server for storage. Based on this, the application control device can apply for group packages and APIKey to the server based on the sensitive information viewing demand, then use Pri_key1 to decrypt different identity password packages to obtain different key password packages, and then use the APIKey applied from the server to decrypt different key encryption packages to obtain different session passwords sessionKey1 / 2 / 3, and finally use sessionKey1 / 2 / 3 to decrypt the corresponding video information 1 encryption package, image information 2 encryption package or video information 3 encryption package to obtain video information 1, image information 2 or video information 3. In combination with the multi-level key system of the smart home appliance device in the smart home appliance system, the unauthorized access problem caused by the leakage of the non-root secret key is effectively protected, and the random key exists in the multi-level key system, the cracking difficulty and the risk threat after cracking are further increased through the one device one key mode, and the purpose that the leakage of the key of any end in the smart home appliance system does not cause the leakage of sensitive information is also achieved, the plaintext information of the sensitive information is ensured to be obtained by the cooperation of multiple devices in the smart home appliance system, the hardware resources of a certain device in the smart home appliance system are effectively utilized, the burden of other devices is reduced, and in the case that multiple devices are contained in the smart home appliance system, a certain device or multiple devices cannot store the user sensitive information in plaintext or decrypt, and the privacy compliance requirements are met. Further, any device in the smart home appliance system cannot decrypt the sensitive data alone, and the two keys of the asymmetric key and the symmetric key must be obtained to effectively decrypt and the single device is effective, and the group attack event is shielded.
[0072] The application further provides a sensitive information security acquisition system, comprising a first device and a second device, and the first device and the second device are in communication connection, wherein:
[0073] The first device is used for acquiring the sensitive information encryption package, the identity password package and the application programming interface key from the second device, and decrypting the sensitive information encryption package and the identity password package based on the first private key of the first device and the application programming interface key to acquire the sensitive information in the sensitive information encryption package;
[0074] a second device for storing the sensitive information encryption package, the identity password package and the application programming interface key.
[0075] The sensitive information encryption package, the identity password package and the application programming interface key are pre-generated by a third device and stored in the second device, and the third device destroys the application programming interface key based on a storage success result.
[0076] It can be understood that the first device is also used to execute the sensitive information security acquisition method described in the foregoing embodiments, and the second device is also used to execute the sensitive information security acquisition method described in the foregoing embodiments. Details are not described herein again.
[0077] It can be understood that the sensitive information security acquisition system provided by the application can further include a third device, which is used to generate a session key and derive an application programming interface key using a root secret key, encrypt the sensitive information based on the session key, determine a sensitive information encryption package, encrypt the session key based on the application programming interface key and a first public key of the first device, determine an identity password package, and then send the sensitive information encryption package, the identity password package and the application programming interface key to the second device for storage.
[0078] Specifically, the third device can generate the root secret key in a preset random number key generation manner, so as to derive the application programming interface key using the root secret key. In addition, the third device can also generate different session keys in a random number key generation manner, and each session key is used to encrypt corresponding sensitive information.
[0079] It can be understood that, in view of the security of the third device in acquiring the sensitive information, the third device can be pre-configured with a destruction manner of the application programming interface key, and the destruction can be performed when a destruction condition is met. Based on this, the third device in the sensitive information security acquisition method provided by the application can also be used to destroy the APIKey based on a storage success result. Further, the third device can pre-determine a key object to be destroyed and a destruction condition, that is, the key object to be destroyed is the application programming interface key, and the destruction condition of the application programming interface key is that the third device sends the generated sensitive information encryption package, identity password package and application programming interface key to the second device for storage and the storage is successful, and the third device can destroy the APIKey immediately when it is determined that the destruction condition is met.
[0080] It should be noted that the third device can pre-establish an information storage protocol with the second device, such as the information storage protocol can include but is not limited to that the third device sends the sensitive information encryption package, the identity password package and the application programming interface key to the second device for storage, and the second device can feed back identification information representing the storage success result to the third device after successful storage, so that the third device destroys the APIKey in time based on the identification information representing the storage success result fed back by the second device. And, for the case that the Rootkey, the sessionKey and the APIKey can be derived in the third device, the third device can destroy the APIKey in time under the condition that the APIKey, the sensitive information encryption package and the identity password package are successfully stored in the second device, and the Rootkey and the sessionKey continue to be stored in the third device. In this way, by setting the third device to destroy the APIKey in time after successfully storing the generated sensitive information encryption package, identity password package and application programming interface key in the second device, the purpose that the third device also needs to obtain the APIKey, the sensitive information encryption package and the identity password package from the second device before decrypting the sensitive information is achieved, and it is ensured that any device in the entire smart home system cannot decrypt the sensitive information alone, and any device needs to cooperate with other devices to decrypt the sensitive information, effectively resisting many known attack methods, ensuring the confidentiality, integrity and availability of the sensitive information and the security and reliability of the transmission in the smart home system, greatly reducing the attack risk of the sensitive information, and improving the security of the sensitive information security acquisition system.
[0081] It can be understood that the third device is also used to execute the sensitive information security acquisition method described in the foregoing embodiments. Here, no longer be described.
[0082] The sensitive information security acquisition device provided by the application is described below. The sensitive information security acquisition device described below can be referred to in conjunction with the sensitive information security acquisition method described above.
[0083] Reference Figure 4 The structure diagram of the sensitive information security acquisition device provided by the application is shown in Figure 4 The sensitive information security acquisition device 400 includes:
[0084] The first acquisition module 410 is used to acquire the sensitive information encryption package, the identity password package and the application programming interface key from the second device;
[0085] The second acquisition module 420 is used to decrypt the sensitive information encryption package and the identity password package based on the first private key of the first device and the application programming interface key, and acquire the sensitive information in the sensitive information encryption package.
[0086] The sensitive information encryption package, the identity password package and the application programming interface key are generated in advance by a third device and stored in the second device, and the third device destroys the application programming interface key based on a storage success result.
[0087] It can be understood that the first obtaining module 410 can be specifically used for sending an information use authorization request to the second device, the information use authorization request being used for requesting the second device to issue the stored sensitive information encryption package, identity password package and application programming interface key, and receiving an information use authorization response sent by the second device, the information use authorization response including the sensitive information encryption package, the identity password package and the application programming interface key.
[0088] It can be understood that the second obtaining module 420 can be specifically used for decrypting the identity password package based on a first private key of the first device to obtain a key encryption package, decrypting the key encryption package based on the application programming interface key to obtain a session key, and decrypting the sensitive information encryption package based on the session key to obtain sensitive information in the sensitive information encryption package.
[0089] It can be understood that the second device in the sensitive information security obtaining device is one of a smart home appliance, a server and an application control device, and the second device is different from the first device; and the second device is a device at least having an information storage function and a public and private key generation function.
[0090] Figure 5 An example of an entity structure diagram of an electronic device is shown in FIG. 1. Figure 5 As shown in FIG. 1, the electronic device can include a processor 510, a communications interface 520, a memory 530 and a communications bus 540, wherein the processor 510, the communications interface 520 and the memory 530 complete mutual communication through the communications bus 540. The processor 510 can invoke a logical instruction in the memory 530 to execute the following method.
[0091] obtaining, from a second device, a sensitive information encryption package, an identity password package and an application programming interface key;
[0092] decrypting the sensitive information encryption package and the identity password package based on a first private key of the first device and the application programming interface key to obtain sensitive information in the sensitive information encryption package;
[0093] The sensitive information encryption package, the identity password package and the application programming interface key are generated in advance by a third device and stored in the second device, and the third device destroys the application programming interface key based on a storage success result.
[0094] Moreover, the logic instructions in the memory 530 described above can be implemented in the form of software functional units and sold or used as independent products, and can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the present application essentially or the parts that make contributions to the related art or parts of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various media that can store program codes.
[0095] In another aspect, the embodiments of the present application disclose a computer program product, which comprises a computer program stored on a non-transitory computer readable storage medium, and the computer program comprises program instructions, and when the program instructions are executed by a computer, the computer can execute the method provided by the above-mentioned method embodiments, for example, comprising:
[0096] obtaining a sensitive information encryption package, an identity password package and an application programming interface key from the second device;
[0097] decrypting the sensitive information encryption package and the identity password package based on the first private key of the first device and the application programming interface key, and obtaining sensitive information in the sensitive information encryption package;
[0098] The sensitive information encryption package, the identity password package and the application programming interface key are pre-generated by a third device and stored in the second device, and the third device destroys the application programming interface key based on a storage success result.
[0099] In another aspect, the embodiments of the present application further provide a non-transitory computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the transmission method provided by the above-mentioned embodiments, for example, comprising:
[0100] obtaining a sensitive information encryption package, an identity password package and an application programming interface key from the second device;
[0101] decrypting the sensitive information encryption package and the identity password package based on the first private key of the first device and the application programming interface key, and obtaining sensitive information in the sensitive information encryption package;
[0102] Among them, the sensitive information encryption package, the identity password package and the application programming interface key are generated by the third device in advance and stored in the second device, and the third device destroys the application programming interface key based on the storage success result.
[0103] The device embodiments described above are only illustrative, wherein the units described as separate components can or can not be physically separated, and the components displayed as units can or can not be physical units, i.e., can be located in one place or distributed on multiple network units. Part or all of the modules can be selected to achieve the purpose of the embodiment scheme according to actual needs. Those skilled in the art can understand and implement without creative labor.
[0104] Through the description of the above embodiments, those skilled in the art can clearly understand that the embodiments can be realized by means of software and the necessary general hardware platform, and of course can also be realized by hardware. Based on such understanding, the above technical solutions can be embodied in the form of a software product, which can be stored in a computer readable storage medium, such as a ROM / RAM, a magnetic disk, an optical disk, etc., and includes a plurality of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute the methods described in each embodiment or some parts of the embodiments.
[0105] Finally, it should be noted that the above embodiments are only used to illustrate the present application, and are not limited to the present application. Although the present application is described in detail with reference to the embodiments, those skilled in the art should understand that various combinations, modifications or equivalent replacements of the technical solutions of the present application do not deviate from the spirit and scope of the present application, and should be covered in the scope of the claims of the present application.
Claims
1. A method for securely acquiring sensitive information, characterized in that, Applied to the first device, including: Obtain sensitive information encryption packets, identity password packets, and application programming interface keys from the second device; Based on the first private key of the first device and the application programming interface key, the sensitive information encryption packet and the identity password packet are decrypted to obtain the sensitive information in the sensitive information encryption packet; The sensitive information encryption packet, the identity password packet, and the application programming interface key are pre-generated by the third device and stored in the second device, and the third device destroys the application programming interface key based on the successful storage result. The first device, the second device, and the third device are different devices in the smart home appliance system, and no single device in the smart home appliance system can decrypt sensitive information independently.
2. The method for securely acquiring sensitive information according to claim 1, characterized in that, The process of obtaining the sensitive information encryption packet, identity password packet, and application programming interface key from the second device includes: Send an information use authorization request to the second device, the information use authorization request being used to request the second device to send the stored sensitive information encryption package, the identity password package and the application programming interface key; The information use authorization response sent by the second device is received, and the information use authorization response includes the sensitive information encryption packet, the identity password packet, and the application programming interface key.
3. The method for securely acquiring sensitive information according to claim 1, characterized in that, The step of decrypting the sensitive information encryption packet and the identity password packet based on the first private key of the first device and the application programming interface key to obtain the sensitive information in the sensitive information encryption packet includes: The identity password packet is decrypted based on the first private key of the first device to obtain the key encrypted packet; The key encryption packet is decrypted based on the application programming interface key to obtain the session key; The sensitive information encrypted packet is decrypted based on the session key to obtain the sensitive information in the encrypted packet.
4. The method for securely acquiring sensitive information according to any one of claims 1 to 3, characterized in that, The second device is one of smart home appliances, servers, and application control devices, and is different from the first device; and the second device is a device with at least information storage function.
5. A system for securely acquiring sensitive information, characterized in that, It includes a first device and a second device, which are communicatively connected, wherein: The first device is configured to obtain a sensitive information encryption package, an identity password package, and an application programming interface key from the second device, and decrypt the sensitive information encryption package and the identity password package based on the first device's first private key and the application programming interface key to obtain the sensitive information in the sensitive information encryption package; The second device is used to store the sensitive information encryption package, the identity password package, and the application programming interface key; The sensitive information encryption packet, the identity password packet, and the application programming interface key are pre-generated by the third device and stored in the second device, and the third device destroys the application programming interface key based on the successful storage result. The first device, the second device, and the third device are different devices in the smart home appliance system, and no single device in the smart home appliance system can decrypt sensitive information independently.
6. The sensitive information secure acquisition system according to claim 5, characterized in that, It also includes a third device, which is used to generate a session key and derive an application programming interface key using a root key, encrypt sensitive information based on the session key to determine a sensitive information encryption packet, encrypt the session key based on the application programming interface key and the first public key of the first device to determine the identity password packet, and then send the application programming interface key to the second device for storage.
7. A device for securely acquiring sensitive information, characterized in that, include: The first acquisition module is used to acquire sensitive information encryption packets, identity password packets, and application programming interface keys from the second device; The second acquisition module is used to decrypt the sensitive information encryption packet and the identity password packet based on the first private key of the first device and the application programming interface key, and to obtain the sensitive information in the sensitive information encryption packet. The sensitive information encryption packet, the identity password packet, and the application programming interface key are pre-generated by the third device and stored in the second device, and the third device destroys the application programming interface key based on the successful storage result. The first device, the second device, and the third device are different devices in the smart home appliance system, and no single device in the smart home appliance system can decrypt sensitive information independently.
8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the method for securely acquiring sensitive information as described in any one of claims 1 to 4.
9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by a processor, the computer program implements the method for securely acquiring sensitive information as described in any one of claims 1 to 4.
10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the method for securely acquiring sensitive information as described in any one of claims 1 to 4.
Citation Information
Patent Citations
Asynchronous session key negotiation and application method and system, electronic equipment and medium
CN114554485A