A data transmission and encryption method and system for digital collaborative office
Through the method of setting keys in the administrator and user side, the security of data transmission and encryption in the digital collaborative office system is solved, and the security of data in the transmission and storage process is realized, ensuring that only authorized users can decrypt data, reducing the risk of operation and maintenance and technical personnel obtaining data.
Patent Information
- Application Number
- CN202310312819.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-28
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2043-03-28
AI Technical Summary
In the prior art, the data transmission and encryption methods of digital collaborative office systems cannot effectively prevent operation and maintenance personnel or developers from obtaining confidential data, resulting in high risk of data leakage.
The administrator and the user side jointly set the key, and store it in the database through the combination of key A and key Bi as the key ABi, and use different keys for encryption and decryption during the data transmission process to ensure the security of the data during transmission and storage.
It realizes the security of data during transmission and storage, prevents data leakage caused by database leakage or network hijacking, ensures that only authorized users can decrypt data, and reduces the risk of operation and maintenance and technical personnel obtaining data.
Smart Images

Figure CN116366243B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and more specifically to a data transmission and encryption method and system for digital collaborative office work. Background Art
[0002] At present, among many digital system office systems, the storage and transmission of data are realized in plaintext. A few systems use key encryption to encrypt and store and transmit data, and at the same time store the decryption key in the database or file, which ensures the confidentiality of data to a certain extent. However, once the key and the ciphertext are leaked at the same time, it is very easy to decipher the ciphertext and cannot truly ensure the security of the data. If not encrypted, system operation and maintenance personnel can directly see the original data. If key encryption is used and the key is saved, it is also impossible to achieve true confidentiality for developers, because the program is written by developers. If the key is placed with a third party, developers can call the decryption tool to read the data.
[0003] Therefore, how to provide a data transmission and encryption method and system for digital collaborative office work that can solve the problem of operation and maintenance personnel or developers obtaining confidential data is an urgent problem to be solved by those skilled in the art. Summary of the Invention
[0004] In view of this, the present invention provides a data transmission and encryption method and system for digital collaborative office work, enabling the administrator side and the user side to jointly encrypt data. The user side can only view the decrypted data after entering the correct key, preventing data leakage caused by database leakage or network hijacking.
[0005] In order to achieve the above object, the present invention adopts the following technical solutions:
[0006] In the first aspect, the present invention provides a data transmission and encryption method for digital collaborative office work, including:
[0007] For a certain piece of data, send a key collaborative setting instruction to the administrator side and at least one user side, notify the administrator side to set key A, and notify the user side to set their respective keys B i , where i represents the i-th user side;
[0008] Receive the key A set by the administrator side and the key B set by the user side i , and combine the key A with the key B of each user side i into key AB i , and store it in the database in the form of key AB i ;
[0009] On the administrator side, encrypt the data with key A and store it in the database;
[0010] When sending the data to the client i, decrypt the stored ciphertext data using the key A, and retrieve the key AB i , according to the key A and the key AB i Decrypt to obtain the key B i ; Re-encrypt the data using the key B i and then send it to the client i;
[0011] At the client i, decrypt the received ciphertext data using the key B i .
[0012] Furthermore, it also includes:
[0013] When a certain data needs to be sent to multiple clients, the keys set for each client are different. When sending the data, select the specified clients, and use the respective keys of the specified clients to re-encrypt the data respectively, and then distribute it to the specified clients.
[0014] Furthermore, at the administrator side, decrypt the data using the key A, and when saving the data again after an editing operation on the data, automatically enable the key A to encrypt the data.
[0015] Furthermore, use the 3DES algorithm to encrypt and decrypt the data.
[0016] Furthermore, at the administrator side, before performing a certain operation, prompt for secondary password verification.
[0017] In a second aspect, the present invention also provides a data transmission and encryption system for digital collaborative office, including:
[0018] A key collaborative setting module, used to send a key collaborative setting instruction to the administrator side and at least one client for a certain data, notify the administrator side to set the key A, and notify the client to set their respective keys B i , where i represents the i-th client;
[0019] A key storage management module, used to receive the key A set by the administrator side and the key B set by the client i , and combine the key A with the key B of each client i into the key AB i , and store it in the database in the form of the key AB i ;
[0020] An administrator side data encryption module, used to encrypt the data using the key A at the administrator side and then store it in the database;
[0021] A data sending and re-encryption module, which is used to decrypt the stored ciphertext data with key A and retrieve key AB when sending the data to client i. i , according to key A and key AB i decrypt to obtain key B i ; re-encrypt the data with key B i and then send it to client i;
[0022] A client data decryption module, which is used to decrypt the received ciphertext data with key B at client i. i for the received ciphertext data.
[0023] Further, the data sending and re-encryption module is also used to select a specified client when sending data, and re-encrypt the data with the respective keys of the specified clients and then distribute it to the specified clients.
[0024] Further, the administrator-side data encryption module is also used to decrypt the data with key A at the administrator side, and when the data is saved again after an editing operation on the data, automatically enable key A to encrypt the data.
[0025] Further, the system further includes:
[0026] A secondary verification module, which is used to prompt for secondary password verification before performing an operation at the administrator side.
[0027] Through the above technical solutions, compared with the prior art, the present invention discloses a data transmission and encryption method for digital collaborative office. For a certain data, the administrator side and the client side need to cooperate to encrypt the data. When the administrator side operates, the data saved is encrypted with the administrator's secret key, and the data sent to the client side is encrypted with the client side's secret key. The data sent to each client side is decrypted with the secret key it holds, which can also ensure the loss of data caused by reasons such as the loss of the recipient's device.
[0028] At the same time, the secret keys of the administrator and the user are not stored, and the data is stored in the database using an encryption method that does not retain the secret key. The data cannot be decrypted by operation and maintenance and technical personnel, and it can also solve the problem that even if the database and hijacking program are obtained through normal or abnormal means, the secret key cannot be obtained through technical or hacking means, thus ensuring that the data cannot be decrypted. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on the provided drawings.
[0030] Figure 1 It is a flowchart of the data transmission and encryption method for digital collaborative office provided by the present invention;
[0031] Figure 2 It is a structural block diagram of the data transmission and encryption system for digital collaborative office provided by the present invention. Detailed implementation manners
[0032] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of them. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0033] As Figure 1 shown, the embodiments of the present invention disclose a data transmission and encryption method for digital collaborative office, including the following steps:
[0034] For a certain data, send a key collaboration setting instruction to the administrator terminal and at least one user terminal, notify the administrator terminal to set key A, and notify the user terminal to set its own key B i , where i represents the i-th user terminal;
[0035] Receive the key A set by the administrator terminal and the key B set by the user terminal i , and combine the key A with the key B of each user terminal i into key AB i , and store it in the database in the form of key AB i ;
[0036] At the administrator terminal, encrypt the data with key A and store it in the database;
[0037] When sending the data to the user terminal i, decrypt the stored ciphertext data with key A, and retrieve key AB i , and decrypt to obtain key B according to key A and key AB i ; Re-encrypt the data with key B i and send it to the user terminal i; i
[0038] At the client i, the secret key B is used. i Decrypt the received ciphertext data.
[0039] In the embodiment of the present invention, the administrator side and the client side need to cooperate. On the administrator side, before the administrator operates on the data, the decryption key A needs to be input. Use the key A to decrypt the encrypted data in the database. If the key A is incorrect, the correct decryption result cannot be obtained. If the key A is correct, the decrypted data can be obtained and the plaintext is temporarily displayed on the page. The administrator side can edit the data. When saving again, the key A is automatically enabled to encrypt the data and save it to the database.
[0040] The administrator side initiates a collaborative work of setting the user key to the client side. The administrator inputs the key A, and the user inputs the key B. When submitting and saving, the keys A and B are combined to obtain the key AB, and the key AB is stored in the database. Neither the key A nor the key B is saved.
[0041] When the administrator side sends data to the user, the key A needs to be input. The encrypted data in the database is decrypted with the key A to obtain the original data. At the same time, the key AB is retrieved, and the key AB is decrypted with the key A to obtain the key B. Then the original data is encrypted with the key B and transmitted to the client side.
[0042] After the client side receives the encrypted data, each time it views, the key B needs to be input to view the original data. If the key is incorrect, the decrypted data cannot be obtained.
[0043] In the embodiment of the present invention, the data is encrypted and stored in the database. Since the secret keys of the administrator side and the client side are not stored, once the database is leaked, the leaked data cannot be recognized. Therefore, the data cannot be decrypted by the operation and maintenance and technical personnel.
[0044] More preferably, the method further includes: when a certain data needs to be sent to multiple client sides, the keys set by each client side are different. When sending data, select the specified client side, and use the respective keys of the specified client side to re-encrypt the data respectively, and then distribute it to the specified client side.
[0045] In the embodiment of the present invention, one or more specified client sides can be selected to selectively send data. The data is re-encrypted according to the respective keys of the specified client sides, and the re-encrypted data is sent to the corresponding client sides. Since the keys of each client side are different, the data sent to each client side is encrypted by different encryption methods. The encrypted data needs each client side to use its own secret key to decrypt its own data to see the result. Even if the recipient's device is lost, it will not be easily cracked and cause data loss.
[0046] Specifically, whether encrypting and decrypting data with key A at the administrator side, encrypting data with key B, or decrypting data with key B at the user side, the 3DES algorithm can be used to perform encryption and decryption operations on the data.
[0047] More preferably, at the administrator side, before performing a certain operation, a secondary password verification is prompted. In the embodiment of the present invention, by prompting to enter the secondary password verification before entering the relevant page, the situation of data leakage caused by the administrator side being used by others can be avoided.
[0048] As Figure 2 shown, the embodiment of the present invention further provides a data transmission and encryption system for digital collaborative office, including:
[0049] A key collaborative setting module, which is used to send a key collaborative setting instruction to the administrator side and at least one user side for a certain data, notify the administrator side to set key A, and notify the user side to set their respective key B i , where i represents the i-th user side;
[0050] A key storage and management module, which is used to receive key A set by the administrator side and key B set by the user side i , and combine key A with the key B of each user side i into key AB i , and store it in the database in the form of key AB i ;
[0051] An administrator side data encryption module, which is used to encrypt the data with key A at the administrator side and then store it in the database;
[0052] A data sending and re-encryption module, which is used to decrypt the stored ciphertext data with key A and retrieve key AB when sending the data to the i-th user side i , and decrypt to obtain key B according to key A and key AB i ; re-encrypt the data with key B i and then send it to the i-th user side; i
[0053] A user side data decryption module, which is used to decrypt the received ciphertext data with key B at the i-th user side i i ;
[0054] Among them, the administrator side data encryption module is further used to decrypt the data with key A at the administrator side, and when the data is saved again after an editing operation on the data, automatically enable key A to encrypt the data.
[0055] More preferably, when sending data, the data sending and re-encryption module is further configured to select specified clients, re-encrypt the data respectively with the respective keys of the specified clients, and then distribute the data to the specified clients.
[0056] In other embodiments, the system of the present invention further includes:
[0057] A secondary verification module, configured to prompt for secondary password verification at the administrator side before performing an operation.
[0058] The system of the present invention can be applied to various digital collaborative office software to improve the security of digital collaborative office software.
[0059] In this specification, the various embodiments are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The same or similar parts among the various embodiments can be referred to each other. For the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple. For the relevant parts, reference can be made to the description of the method part.
[0060] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present invention. Various modifications to these embodiments will be obvious to those skilled in the art. The general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but will be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A data transmission and encryption method for digital collaborative office, characterized in that, Including: For a certain piece of data, send a key collaboration setting instruction to the administrator side and at least one user side, notify the administrator side to set key A, and notify the user side to set their respective key B i , where i represents the i-th user side; Receive the key A set by the administrator side and the key B set by the user side i , and combine the key A with the key B of each user side i to form the key AB i , and store it in the database in the form of the key AB i ; On the administrator side, the data is encrypted with key A and then stored in the database; When sending the data to the client i, decrypt the stored ciphertext data using the key A, and retrieve the key AB i , according to the key A and the key AB i Decrypt to obtain the key B i ; Re-encrypt the data using the key B i And then send it to the client i; At the user side i, the secret key B is used i to decrypt the received ciphertext data.
2. The data transmission and encryption method for digital collaborative office according to claim 1, characterized in that, It also includes: When a piece of data needs to be sent to multiple user terminals, the keys set for each user terminal are different. When sending data, specify a user terminal, and use the respective keys of the specified user terminal to re-encrypt the data separately, and then distribute it to the specified user terminal.
3. The data transmission and encryption method for digital collaborative office according to claim 1, characterized in that, On the administrator side, the data is decrypted with key A, and when the data is saved again after an edit operation, key A is automatically enabled to encrypt the data.
4. The data transmission and encryption method for digital collaborative office according to claim 1, characterized in that, The 3DES algorithm is used for data encryption and decryption operations.
5. The data transmission and encryption method for digital collaborative office according to claim 1, wherein On the administrator side, before performing a certain operation, a secondary password verification is prompted.
6. A data transmission and encryption system for digital collaborative office, characterized in that, Including: A key collaboration setting module, which is used to send a key collaboration setting instruction to an administrator side and at least one user side for a certain piece of data, notify the administrator side to set a key A, and notify the user side to set their respective keys B i , where i represents the i-th user side; The key storage management module is used to receive the key A set by the administrator side and the key B set by the user side i and combine the key A with the key B of each user side i to form the key AB i and store it in the database in the form of the key AB i ; An administrator-side data encryption module, which is used to encrypt the data with key A on the administrator side and then store it in the database; The data sending and re-encryption module is used to decrypt the stored ciphertext data with key A and retrieve key AB when sending the data to client i. i , according to key A and key AB i to decrypt and obtain key B i ; re-encrypt the data with key B i and then send it to client i. The client data decryption module is used to decrypt the received ciphertext data at the client i using the key B i 7. The data transmission and encryption system for digital collaborative office according to claim 6, characterized in that, The data sending and re-encryption module is also used to specify a user terminal when sending data, and use the respective keys of the specified user terminal to re-encrypt the data separately, and then distribute it to the specified user terminal.
8. The data transmission and encryption system for digital collaborative office according to claim 6, characterized in that The administrator-side data encryption module is also used to decrypt the data with key A on the administrator side, and when the data is saved again after an edit operation, key A is automatically enabled to encrypt the data.
9. The data transmission and encryption system for digital collaborative office according to claim 6, characterized in that, It also includes: A secondary verification module, which is used to prompt for secondary password verification before performing a certain operation on the administrator side.
Citation Information
Patent Citations
Enabling access to data
CN105659231A
Securely storing and distributing sensitive data in a cloud-based application
CN108701094A