Key processing method, apparatus, device, and storage medium

By using a communication key to encrypt the transmission of the target storage key between the terminal and the server, and by performing local data encryption on the terminal, the security issues of data transmission and storage are solved, and secure data transmission and storage are achieved.

CN116405317BActive Publication Date: 2025-12-05APOLLO INTELLIGENT CONNECTIVITY (BEIJING) TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202310611200.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-05-26
Publication Date
2025-12-05
Estimated Expiration
2043-05-26

AI Technical Summary

Technical Problem

In existing technologies, data transmission between data acquisition devices and data processing devices carries a high risk of leakage, and the encryption of local terminal data is not considered, resulting in insufficient security of local terminal data.

Method used

The target storage key is encrypted and transmitted using a communication key, and then decrypted by the terminal to ensure the security of data transmission between the terminal and the server. At the same time, the security of terminal data is improved by encrypting local data by allocating a storage key to the terminal.

Benefits of technology

This reduces the risk of data leakage during transmission and the risk of leakage of local data on the terminal, thereby improving the overall security of the data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116405317B_ABST
    Figure CN116405317B_ABST
Patent Text Reader

Abstract

The present disclosure provides a key processing method and device, equipment and storage medium, relates to the field of data processing, in particular to data security, communication technology, storage technology, Internet of Things technology and the like, and can be applied to the scene of Internet of Things, Internet of Vehicles, intelligent transportation and the like. On the terminal side, the key processing method comprises: receiving a target storage key encrypted by a communication key from a server, the communication key being used for encryption of data transmission between the terminal and the server; and decrypting the encrypted target storage key through the communication key to obtain the target storage key, the target storage key being used for encryption of local data on the terminal. Thus, the communication key is used to reduce the risk of data leakage between the terminal and the server, the storage key is used to reduce the risk of leakage of local data on the terminal, and the communication key is used to encrypt the storage key, thereby reducing the risk of leakage of the storage key and effectively improving the data security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of data processing, specifically to data security, communication technology, storage technology, Internet of Things (IoT) technology, etc., and can be applied to scenarios such as IoT, vehicle networking, and intelligent transportation. In particular, it relates to a key processing method, device, equipment, and storage medium. Background Technology

[0002] In data acquisition and transmission scenarios, data acquisition devices transmit the acquired data to data processing devices, a process that carries the security risk of data leakage.

[0003] In related technologies, data acquisition devices encrypt the acquired data using the public key in asymmetric encryption and transmit the encrypted data to data processing devices; the data processing devices decrypt the encrypted data using the private key in asymmetric encryption.

[0004] However, the above methods carry a high risk of data leakage. Summary of the Invention

[0005] This disclosure provides a key processing method, apparatus, device, and storage medium for reducing the duplication rate of resource recommendations.

[0006] According to a first aspect of this disclosure, a key processing method is provided, applied to a terminal, comprising: receiving a target storage key encrypted with a communication key from a server, the communication key being used for encrypting data transmitted between the terminal and the server; and decrypting the encrypted target storage key using the communication key to obtain the target storage key, the target storage key being used for encrypting local data on the terminal.

[0007] According to a second aspect of this disclosure, a key processing method is provided, applied to a server, comprising: generating a corresponding target storage key for a terminal, the target storage key being used for encrypting local data on the terminal; encrypting the target storage key using a communication key to obtain an encrypted target storage key, the communication key being used for encrypting data transmitted between the terminal and the server; and sending the encrypted target storage key to the terminal.

[0008] According to a third aspect of this disclosure, a key processing apparatus is provided for use in a terminal, comprising: a key receiving unit for receiving a target storage key encrypted with a communication key from a server, the communication key being used for encrypting data transmitted between the terminal and the server; and a key decryption unit for decrypting the encrypted target storage key using the communication key to obtain the target storage key, the target storage key being used for encrypting local data on the terminal.

[0009] According to a fourth aspect of this disclosure, a key processing apparatus is provided, applied to a server, comprising: a storage key generation unit for generating a corresponding target storage key for a terminal, the target storage key being used for encrypting local data on the terminal; a storage key encryption unit for encrypting the target storage key using a communication key to obtain an encrypted target storage key, the communication key being used for encrypting data transmitted between the terminal and the server; and a storage key sending unit for sending the encrypted target storage key to the terminal.

[0010] According to a fifth aspect of this disclosure, an electronic device is provided, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to perform the key processing method described in the first or second aspect.

[0011] According to a sixth aspect of this disclosure, a non-transitory computer-readable storage medium is provided storing computer instructions, wherein the computer instructions are used to cause the computer to perform the key processing method described in the first or second aspect.

[0012] According to a seventh aspect of this disclosure, a computer program product is provided, the computer program product comprising: a computer program stored in a readable storage medium, at least one processor of an electronic device being able to read the computer program from the readable storage medium, the at least one processor executing the computer program causing the electronic device to perform the key processing method described in the first or second aspect.

[0013] According to the technical solution provided in this disclosure, the server encrypts the target storage key using a communication key and sends the encrypted target storage key to the terminal, reducing the risk of target storage key leakage. The terminal decrypts the encrypted target storage key using the communication key to obtain the target storage key, which is used for encrypting local data on the terminal. By providing a communication key for data transmission between the server and the terminal and a storage key for the terminal's local data, the risk of data leakage during data transmission and the risk of data leakage of local data on the terminal are reduced, thereby improving data security.

[0014] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of this disclosure, nor is it intended to limit the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description. Attached Figure Description

[0015] The accompanying drawings are provided to better understand this solution and do not constitute a limitation of this disclosure. Wherein:

[0016] Figure 1 This is a schematic diagram illustrating an application scenario to which this disclosure applies;

[0017] Figure 2 This is a schematic diagram based on the first embodiment of the present disclosure;

[0018] Figure 3 This is a schematic diagram according to the second embodiment of the present disclosure;

[0019] Figure 4 This is a schematic diagram according to the third embodiment of the present disclosure;

[0020] Figure 5 This is a diagram illustrating the storage key processing between the terminal and the server. Figure 1 ;

[0021] Figure 6 This is a diagram illustrating the storage key processing between the terminal and the server. Figure 2 ;

[0022] Figure 7 This is a schematic diagram according to the fourth embodiment of the present disclosure;

[0023] Figure 8 This is a schematic diagram according to the fifth embodiment of the present disclosure;

[0024] Figure 9 This is an example of communication key processing between the terminal and the server. Figure 1 ;

[0025] Figure 10 This is an example of communication key processing between the terminal and the server. Figure 2 ;

[0026] Figure 11 This is a schematic diagram of the sixth embodiment of the present disclosure;

[0027] Figure 12 This is a schematic diagram of the seventh embodiment of the present disclosure;

[0028] Figure 13 This is a schematic block diagram of an example electronic device 1300 that can be used to implement embodiments of the present disclosure. Detailed Implementation

[0029] The exemplary embodiments of this disclosure are described below with reference to the accompanying drawings, including various details of the embodiments to aid understanding, and should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of this disclosure. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.

[0030] Data acquisition devices can encrypt the acquired data and then send it to data processing devices.

[0031] In related technologies, a terminal can inform the server of its RSA public key via message commands. The server uses the RSA public key provided by the terminal to encrypt the data and sends the encrypted data to the terminal. The terminal then uses its own RSA private key to decrypt the encrypted data to obtain the data sent by the server. Alternatively, the server can inform the terminal of its RSA public key via message commands. The terminal uses the RSA public key provided by the server to encrypt the data and sends the encrypted data to the server. The server then uses its own RSA private key to decrypt the encrypted data to obtain the data reported by the terminal to the server.

[0032] However, the above methods only consider the encryption of data transmitted during communication. In real-world scenarios, the terminal also stores some data locally, which may contain sensitive data. The above methods do not take into account the encryption of local terminal data, which poses a risk of data leakage.

[0033] To address the aforementioned issues, this disclosure provides a key processing method, apparatus, device, and storage medium, applicable to the field of data processing and suitable for scenarios such as the Internet of Things (IoT), the Internet of Vehicles (IoV), and intelligent transportation. In this disclosure, a communication key ensures the security of data transmission between the terminal and the server; a storage key ensures the security of data storage on the terminal.

[0034] The terminal can be a personal digital assistant (PDA) device, a handheld device with wireless communication capabilities (such as a smartphone or tablet), a computing device (such as a personal computer (PC)), a wearable device (such as a smartwatch or smart bracelet), a smart home device (such as a smart speaker or smart display device), a vehicle sensor, or a roadside device. The server can be a standalone server or a server cluster, and can be a local server or a cloud server.

[0035] Figure 1This is a schematic diagram of an application scenario to which this disclosure applies. This application scenario includes a data processing platform 101 and multiple terminals 102. Figure 1 (Taking three terminals 102 as an example). In terminal 102, local data can be stored in an encrypted manner; the data processing platform 101 includes a data access service, which can receive data sent by terminal 102 and process the data. To improve data security, the data transmitted between the data processing platform 101 and terminal 102 can be transmitted in an encrypted manner.

[0036] Taking a driving scenario as an example, a vehicle safety monitoring platform can connect to one or more terminals. For example, the vehicle may be a commercial vehicle, and the terminals may include on-vehicle sensors (such as speed sensors and vehicle radar), roadside equipment, parking lot equipment (such as parking lot gate equipment), etc. The vehicle safety monitoring platform can receive data collected by the terminals. Since the collected data may contain sensitive information, this disclosure can encrypt the local data on the terminal and also encrypt the data transmitted between the terminal and the vehicle safety monitoring platform.

[0037] The driving scenario is an example of one application scenario to which this disclosure applies. This disclosure can be applied to scenarios such as terminal-server communication, data collection and storage, terminal data collection and reporting, Internet of Things (IoT), vehicle-to-everything (V2X) communication, and intelligent transportation.

[0038] The technical solutions of this disclosure and how they solve the aforementioned technical problems will be described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of this disclosure will now be described with reference to the accompanying drawings.

[0039] Figure 2 This is a schematic diagram based on the first embodiment of this disclosure. (See diagram below.) Figure 2 As shown, the key processing method provided in the first embodiment of this disclosure includes:

[0040] S201, the server generates a corresponding target storage key for the terminal, which is used to encrypt local data on the terminal.

[0041] In this embodiment, the server can proactively generate a corresponding storage key for the terminal, or it can generate a corresponding storage key for the terminal in response to a storage key generation request (which can be sent by the terminal or triggered by a user on a client connected to the server). To distinguish it from other storage keys in subsequent embodiments, the storage key currently generated by the server for the terminal is referred to as the target storage key.

[0042] S202, the server encrypts the target storage key using the communication key to obtain the encrypted target storage key. The communication key is used to encrypt data transmitted between the terminal and the server.

[0043] In this embodiment, the server needs to transmit the target storage key to the terminal. Since the communication key is used to encrypt the data transmitted between the terminal and the server, the target storage key can be encrypted using the communication key before transmitting the target storage key to obtain the encrypted storage communication key.

[0044] S203, the server sends the encrypted target storage key to the terminal.

[0045] In this embodiment, the server sends the target storage key, encrypted with the communication key, to the terminal, so that the terminal can use the target storage key to encrypt local data. This achieves encrypted transmission of the target storage key and reduces the risk associated with it.

[0046] S204, the terminal decrypts the encrypted target storage key using the communication key to obtain the target storage key.

[0047] In this embodiment, after receiving the target storage key encrypted with the communication key, the terminal can decrypt the encrypted target storage key using the communication key to obtain the target storage key. Subsequently, if the terminal needs to store local data, it can use the target storage key to encrypt the local data before storing the encrypted local data, thereby improving the security of the local data.

[0048] In this embodiment, the server and terminal can encrypt transmitted data using a communication key, improving the security of data transmission between them. The server can also assign a storage key to the terminal, further enhancing data security on the terminal. Thus, the risk of data leakage is reduced from multiple perspectives, effectively improving data security.

[0049] In view of the above embodiments, some optional implementation schemes are provided:

[0050] In some embodiments, the server can communicate with multiple terminals, generating different target storage keys for each terminal. This avoids the risk of data leakage caused by different terminals sharing the same storage key, effectively improving the security of local data on the terminals.

[0051] In one possible implementation of S201, before receiving the target storage key encrypted with the communication key from the server, the terminal may send its terminal identifier to the server. The terminal identifier is used to generate the storage key used by the terminal for data encryption. The server may then generate the target storage key based on the terminal identifier. Since different terminals have different terminal identifiers, different target storage keys can be generated based on different terminal identifiers, thus ensuring the uniqueness of the target storage key.

[0052] In this implementation, after receiving the terminal identifier, the server can input the terminal identifier into the key generation formula to generate the target storage key. The specific representation of the key generation formula depends on the type of the target storage key; therefore, no restrictions are placed on the formula here.

[0053] Optionally, after successfully registering with the server, the terminal sends its terminal identifier to the server. This allows the server to obtain the terminal identifiers of all successfully registered terminals.

[0054] In some embodiments, considering the lower performance of asymmetric encryption, the communication key can be a symmetric key, and / or the target storage key can be a symmetric key. Therefore, encryption of data transmitted between the terminal and the server based on the communication key is symmetric encryption, and / or encryption of local data on the terminal based on the target storage key is symmetric encryption. Symmetric encryption has higher performance, effectively improving encryption efficiency, reducing the resources consumed by data encryption, and is suitable for scenarios with large data volumes.

[0055] Asymmetric encryption requires two keys: a public key and a private key. If data is encrypted using the public key, it must be decrypted using the corresponding private key. Since encryption and decryption use different keys, this encryption method is called asymmetric encryption. Symmetric encryption, on the other hand, uses the same key for both encryption and decryption.

[0056] Based on the fact that the target storage key is a symmetric key, in another possible implementation of S201, the server can input the terminal identifier of the terminal into the symmetric key generation formula, and calculate the target storage key corresponding to the terminal through the symmetric key generation formula. Thus, by using the terminal identifier as an input parameter to the symmetric key generation formula, different target storage keys can be generated for different terminals.

[0057] Optionally, the communication key and / or the target storage key can be an Advanced Encryption Standard (AES) key. Compared to other symmetric keys, such as the Data Encryption Standard (DES), AES keys offer higher security and reliability, and are applicable to a wider range of scenarios. Therefore, using AES keys for the communication key and / or storage key can enhance their security and reliability, and broaden their applicability.

[0058] In another possible implementation of S201, based on the target storage key being an AES key, the server can input the terminal's identifier into the AES key generation formula. Using the AES key generation formula, the target storage key corresponding to the terminal can be calculated. Thus, by using the terminal identifier as an input parameter to the AES key generation formula, different target storage keys can be generated for different terminals.

[0059] In some embodiments, after obtaining the target storage key, the terminal can verify the target storage key. If the target storage key successfully passes verification, the terminal's local storage key can be updated to the target storage key. Then, the terminal can encrypt local data using the local storage key and store the encrypted local data. Therefore, by verifying the target storage key, the use of an invalid target storage key for encrypting local data is avoided, improving the reliability of encryption of local data on the terminal and enhancing the security of the local data.

[0060] Figure 3 This is a schematic diagram according to the second embodiment of this disclosure. (See diagram below.) Figure 3 As shown, the key processing method provided in the second embodiment of this disclosure includes:

[0061] S301, the server generates a corresponding target storage key for the terminal, which is used to encrypt local data on the terminal.

[0062] S302, the server encrypts the target storage key using the communication key to obtain the encrypted target storage key. The communication key is used to encrypt data transmitted between the terminal and the server.

[0063] S303, the server sends the encrypted target storage key to the terminal.

[0064] S304, the terminal decrypts the encrypted target storage key using the communication key to obtain the target storage key.

[0065] The implementation principles and technical effects of S301 to S304 can be referred to in the aforementioned embodiments, and will not be repeated here.

[0066] S305, the terminal performs a conflict check between the target storage key and the terminal's local storage key to determine whether the target storage key conflicts with the terminal's local storage key.

[0067] The local storage key on the terminal is the storage key currently used by the terminal for local data encryption.

[0068] In this embodiment, after the terminal obtains the target storage key, it can compare the target storage key with the terminal's local storage key to obtain the comparison result, and determine whether the target storage key conflicts with the terminal's local storage key based on the comparison result.

[0069] In one possible implementation, if the target storage key is different from the terminal's local storage key, then it is determined that the target storage key and the terminal's local storage key conflict; otherwise, it is determined that the target storage key and the terminal's local storage key do not conflict.

[0070] In another possible implementation, if the terminal's local storage key is empty or differs from the target storage key, it can be determined that the target storage key conflicts with the terminal's local storage key; otherwise, it can be determined that the target storage key does not conflict with the terminal's local storage key. This approach addresses both cases where the terminal has no local storage key and cases where the terminal does have a local storage key, improving the accuracy of conflict detection between the target storage key and the terminal's local storage key.

[0071] In this implementation, if the terminal's local storage key is empty, it means that the server has not yet allocated a storage key to the terminal. The target storage key is the first storage key allocated to the terminal by the server. The target storage key is different from the empty storage key, so it can be determined that the target storage key conflicts with the terminal's local storage key. If the terminal's local storage key is not empty, it means that the server has previously allocated a storage key to the terminal. The target storage key is different from the terminal's non-empty local storage key, that is, the target storage key conflicts with the terminal's local storage key.

[0072] Optionally, before performing conflict verification between the target stored key and the terminal's local stored key, the data length of the target stored key can be determined to be a preset length. That is, before performing conflict verification, the data length of the target stored key can be verified first. If the data length of the target stored key is the preset length, then conflict verification is performed between the target stored key and the terminal's local stored key. Thus, by combining length verification and conflict verification, the accuracy and rationality of the stored key used for local data encryption on the terminal are ensured, thereby improving the accuracy and reliability of local data encryption on the terminal.

[0073] For example, the target storage key is a binary number, and the data length of the target storage key is the number of bits in the target storage key. The preset length of the storage key is 12 bits. If the number of bits in the target storage key is less than 12 bits or more than 12 bits, it means that the target storage key does not meet the length requirements. For example, some numbers may be missing. Therefore, performing length verification on the target storage key can prevent the terminal from using an incorrect storage key to encrypt local data.

[0074] It should be noted that the verification of the target storage key can first perform conflict verification, and then verify the data length of the target storage key; or, the verification of the target storage key can only include verifying the data length of the target storage key. If the data length of the target storage key is the set length, the local storage key on the terminal can be updated to the target storage key.

[0075] S306 If the target storage key conflicts with the terminal's local storage key, then update the terminal's local storage key to the target storage key.

[0076] In this embodiment, if the target storage key conflicts with the local storage key of the terminal, it means that there is a difference between the target storage key and the local storage key of the terminal. The local storage key of the terminal can be updated to the target storage key to realize the setting or updating of the local storage key of the terminal.

[0077] In one possible implementation, if the target storage key is different from the terminal's local storage key, it is determined that the target storage key conflicts with the terminal's local storage key, and the terminal's local storage key is updated to the target storage key. If the target storage key is the same as the terminal's local storage key, it is determined that the target storage key does not conflict with the terminal's local storage key, and in the case of complete identical storage keys, there is no need to update the terminal's local storage key.

[0078] In another possible implementation, if the terminal's local storage key is empty or differs from the target storage key, it can be determined that the target storage key conflicts with the terminal's local storage key, and the terminal's local storage key is updated to the target storage key. Therefore, when the terminal's local storage key is empty, updating it to the target storage key achieves the setting of the terminal's storage key; when the terminal's local storage key is not empty and differs from the target storage key, updating it to the target storage key achieves the updating of the terminal's storage key.

[0079] Optionally, if the target storage key does not conflict with the terminal's local storage key, the terminal may keep its local storage key unchanged.

[0080] In this embodiment of the disclosure, the server transmits the target storage key to the terminal in encryption. After the terminal obtains the target storage key, it verifies the target storage key. After the target storage key successfully passes the verification, the terminal updates its local storage key to the target storage key. Thus, not only is the secure transmission of the target storage key achieved, but the accuracy of the target storage key is also improved, thereby improving the reliability and security of the terminal using the target storage key for local data encryption.

[0081] Figure 4 This is a schematic diagram according to the third embodiment of this disclosure. (See diagram below.) Figure 4 As shown, the key processing method provided in the third embodiment of this disclosure includes:

[0082] S401, the server generates a corresponding target storage key for the terminal, which is used to encrypt local data on the terminal.

[0083] S402, the server encrypts the target storage key using the communication key to obtain the encrypted target storage key. The communication key is used to encrypt data transmitted between the terminal and the server.

[0084] S403, the server sends the encrypted target storage key to the terminal.

[0085] S404, the terminal decrypts the encrypted target storage key using the communication key to obtain the target storage key.

[0086] S405, the terminal performs a conflict check between the target storage key and the terminal's local storage key to determine whether the target storage key conflicts with the terminal's local storage key.

[0087] The implementation principles and technical effects of S401 to S405 can be referred to in the aforementioned embodiments, and will not be repeated here.

[0088] S406, the terminal sends a verification message to the server. The verification message includes the terminal's identifier and indication information indicating whether the target storage key conflicts with the terminal's local storage key.

[0089] In this embodiment, the terminal can determine the indication information based on whether the target storage key conflicts with the terminal's local storage key, and send a verification message to the server based on the indication information and the terminal identifier.

[0090] Optionally, if the target storage key conflicts with the terminal's local storage key, the terminal may send a verification message to the server. The verification message contains indication information indicating a conflict between the target storage key and the terminal's local storage key. This informs the server of the conflict, allowing the server to send an accurate response message to the terminal based on the conflict.

[0091] Alternatively, if the target storage key conflicts with the terminal's local storage key, the terminal may update its local storage key to the target storage key. If the target storage key does not conflict with the terminal's local storage key, the terminal may send a verification message to the server. The indication information in the verification message is used to indicate that the target storage key does not conflict with the terminal's local storage key, so that the server knows that the target storage key does not conflict with the terminal's local storage key, and therefore the terminal does not need to update the storage key, so that the server can send an accurate response message to the terminal.

[0092] Alternatively, the terminal may send a verification message to the server if the target storage key conflicts with the terminal's local storage key, or if the target storage key does not conflict with the terminal's local storage key. If the target storage key conflicts with the terminal's local storage key, the indication information in the verification message indicates that the target storage key conflicts with the terminal's local storage key; if the target storage key does not conflict with the terminal's local storage key, the indication information indicates that the target storage key conflicts with the terminal's local storage key. This accurately reflects whether the target storage key conflicts with the terminal's local storage key to the server, enabling the server to provide an accurate response message.

[0093] Optionally, the verification message may also include the target storage key and / or the terminal's local storage key, so that the server knows the target storage key currently received by the terminal and the storage key used locally.

[0094] S407, the server responds to the verification message by sending an answer message to the terminal.

[0095] The response message may indicate that the terminal updates the storage key used for data storage encryption, or it may indicate that the terminal does not update the storage key used for data storage encryption.

[0096] In this embodiment, after receiving the verification message, the server can determine whether the target storage key conflicts with the terminal's local storage key or whether the target storage key does not conflict with the terminal's local storage key based on the indication information in the verification message. Based on the indication information, the server can send a response message to the terminal.

[0097] Optionally, if the indication message indicates that the target storage key conflicts with the terminal's local storage key, the server can send a response message to the terminal instructing the terminal to update the storage key used for data storage encryption. In this way, when the target storage key and the terminal's local storage key are different, the server updates the terminal's local storage key to the target storage key, thereby achieving accurate updating of the terminal's local storage key.

[0098] Alternatively, if the indication information indicates that the target storage key conflicts with the terminal's local storage key, the server can compare the storage keys previously used by the terminal with the target storage key. If there is no storage key in the terminal's previously used storage keys that is the same as the target storage key, the server sends a response message to the terminal instructing it to update the storage key used for data storage encryption; otherwise, the server sends a response message to the terminal instructing it not to update the storage key used for data storage encryption.

[0099] In this optional method, after the terminal verifies that the target storage key conflicts with the terminal's local storage key, the server verifies whether the target storage key is the same as the storage key used by the terminal in the past. If the target storage key is different from all the storage keys used by the terminal in the past, the server sends a response message to the terminal instructing the terminal to update the storage key for data storage encryption. Otherwise, the server sends a response message to the terminal instructing the terminal not to update the storage key for data storage encryption. This ensures that the storage key updated by the terminal is different from the storage keys used by the terminal in the past, thereby improving the security of the terminal's storage key and thus improving the security of local data on the terminal.

[0100] Optionally, if the indication information indicates that the target storage key does not conflict with the terminal's local storage key, the server sends a response message to the terminal instructing the terminal not to update the storage key used for data storage encryption. Here, the fact that the target storage key does not conflict with the terminal's local storage key means that the target storage key is the same as the terminal's local storage key, and no additional update operation is required. Therefore, the server sends a response message to the terminal instructing the terminal not to update the storage key used for data storage encryption.

[0101] Optionally, after the server sends a response message to the terminal instructing the terminal not to update the storage key used for data storage encryption, the server can continue to generate a new storage key for the terminal and repeat the above verification process until a storage key that meets the update requirements (such as conflicting with the terminal's local storage key or being different from the storage key used by the terminal in the past) is generated for the terminal.

[0102] Optionally, after the server sends a response message to the terminal instructing it to update the storage key used for data storage encryption, it can save the target storage key. Thus, by recording the storage key used by the terminal, it can be used in the storage key verification process.

[0103] S408, if the response message instructs the terminal to update the storage key used for data storage encryption, the terminal updates its local storage key to the target storage key.

[0104] In this embodiment, if the response message instructs the terminal to update the storage key used for data storage encryption, the terminal can update its local storage key to the target storage key according to the instructions in the response message. If the response message instructs the terminal not to update the storage key used for data storage encryption, the terminal can keep its local storage key unchanged.

[0105] In this embodiment of the disclosure, the server transmits the target storage key to the terminal in encryption. After obtaining the target storage key, the terminal verifies the target storage key and sends a verification message to the server. In response to the verification message, the server sends an acknowledgment message to the terminal. Thus, through the interaction between the server and the terminal, the secure transmission of the target storage key is achieved, the accuracy of the target storage key is improved, and the reliability and security of the terminal using the target storage key for local data encryption are enhanced.

[0106] As an example, Figure 5 This is a diagram illustrating the storage key processing between the terminal and the server. Figure 1 .like Figure 5 As shown, after the terminal initiates and successfully registers with the server, it sends a terminal identifier to the server. The server can then generate a unique stored AES key for the terminal based on this identifier. This stored AES key can be encrypted and sent to the terminal via a communication AES key. Once the terminal obtains the stored AES key, it can use it to encrypt subsequently collected and stored local data.

[0107] like Figure 5 As shown, to ensure the security of local data on the terminal, the stored AES key can be periodically updated by the server. To ensure the accuracy of the stored AES key update, upon receiving the AES key for the first time or after receiving an updated stored AES key from the server, the terminal can verify the stored AES key and send the verification result (i.e., the verification message in the aforementioned embodiment) to the server. After receiving the verification result, if the server determines that the stored key can be updated based on the verification result, it can record the new stored key and instruct the terminal to update the stored key through a response message. After receiving the response message from the server instructing the terminal to update the stored key, the terminal updates its local stored AES key.

[0108] As an example, Figure 6 This is a diagram illustrating the storage key processing between the terminal and the server. Figure 2 .like Figure 6As shown, after a terminal successfully registers with the server, it can report its terminal identifier to the server. The server can then generate and encrypt a stored AES key based on the terminal identifier and send the encrypted stored AES key to the terminal. After obtaining the stored AES key, the terminal verifies it and reports the verification message to the server. In response to the verification message, the server returns a response message to the terminal. If the response message instructs the terminal to update its local stored AES key, the terminal updates its local AES key.

[0109] In some embodiments, the communication key used for encrypting data transmission between the server and the terminal can be pre-set by the user. The user can update the communication key at regular intervals to reduce the risk of communication key leakage and improve the security of data transmission between the server and the terminal.

[0110] In some embodiments, the communication key may be generated by the terminal and encrypted before being sent to the server, or the communication key may be generated by the server and encrypted before being sent to the terminal.

[0111] Figure 7 This is a schematic diagram according to the fourth embodiment of this disclosure. (See diagram below.) Figure 7 As shown, based on the communication key generated and encrypted by the terminal and sent to the server, the key processing method provided in the fourth embodiment of this disclosure may include the following steps:

[0112] S701: The terminal encrypts the communication key using the public key in the asymmetric key to obtain the encrypted communication key. The private key in the asymmetric key is located on the server.

[0113] The asymmetric key consists of a public key and a private key; the public key resides on the terminal, and the private key resides on the server. The communication key is a symmetric key, which can still achieve high performance even when transmitting large amounts of data.

[0114] In this embodiment, the terminal can obtain the public key and communication key from the asymmetric key, and encrypt the communication key using the public key to obtain the encrypted communication key.

[0115] Optionally, the server generates the asymmetric key and sends the public key from the asymmetric key to the terminal. This allows data maintenance personnel to control the generation of the asymmetric key on the server, improving their control over its creation.

[0116] Optionally, the server can periodically update the asymmetric key, or the server can update the asymmetric key in response to an asymmetric key update request. Therefore, by updating the asymmetric key, the risk of asymmetric key leakage is reduced, and data security is improved.

[0117] Optionally, the asymmetric key can be an RSA key.

[0118] Optionally, the communication key can be an AES key.

[0119] S702, the terminal sends an encrypted communication key to the server.

[0120] S703: The server decrypts the encrypted communication key using the private key in the asymmetric key to obtain the communication key, which is used for encrypting data transmitted between the terminal and the server.

[0121] In this embodiment, the server can obtain the private key from the asymmetric key, and use the private key to decrypt the received encrypted communication key to obtain the communication key. Since the communication key has a relatively small data size, high performance can still be achieved by encrypting and decrypting it using the asymmetric key. After obtaining the communication key, the server and the terminal can use it to encrypt the data to be transmitted to each other.

[0122] In this embodiment, the server and terminal use an asymmetric key to encrypt the transmission of the communication key. On one hand, the asymmetric key enhances the security of the communication key transmission, ensuring the security of data transmitted between the server and terminal and reducing the risk of data leakage. On the other hand, the symmetric key allows for encryption and decryption of transmitted data, maintaining high performance even with large data volumes and improving data encryption and decryption efficiency.

[0123] In some embodiments, the terminal may generate a communication key in response to the establishment of a communication connection between the terminal and the server. This communication key is used to encrypt data transmitted over the communication connection. Thus, the terminal regenerates the communication key each time a communication connection is established, effectively reducing the risk of communication key leakage.

[0124] Optionally, the terminal can randomly generate a communication key to reduce the risk of communication key leakage.

[0125] Figure 8 This is a schematic diagram according to the fifth embodiment of this disclosure. (See diagram below.) Figure 8 As shown, based on the communication key generated and encrypted by the terminal and sent to the server, the key processing method provided in the fifth embodiment of this disclosure may include the following steps:

[0126] S801 establishes a communication connection between the terminal and the server.

[0127] S802, in response to the establishment of a communication connection between the terminal and the server, the server sends the public key from the asymmetric key to the terminal.

[0128] In this embodiment, the server can pre-generate an asymmetric key. After a communication connection is established between the terminal and the server, the server sends the public key from the asymmetric key to the terminal. Thus, in each communication connection, the terminal only needs to wait for the public key sent by the server, without having to store or maintain the public key used previously, which facilitates the server's management of the asymmetric key.

[0129] Optionally, the server can respond to an asymmetric key update command, update the public and private keys, and send the updated public key to the terminal. This reduces the risk of asymmetric key leakage and improves data security by updating the asymmetric key.

[0130] Furthermore, after the server updates the public and private keys, if the server and the terminal have not established a communication connection, the server can save the updated public key and send the updated public key to the terminal after the server and the terminal establish a communication connection.

[0131] S803, upon receiving the public key, the terminal generates a communication key, which is used for encrypting data transmitted over the communication connection.

[0132] In this embodiment, after receiving the public key, the terminal generates a communication key. This allows the communication key to be regenerated after each communication connection, reducing the risk of communication key leakage. If the public key is not received, there is no need to generate a communication key. Therefore, in cases where server or network anomalies prevent the public key from being issued, the terminal does not need to waste resources on communication key generation.

[0133] S804: The terminal encrypts the communication key using the public key to obtain the encrypted communication key.

[0134] S805, the terminal sends an encrypted communication key to the server.

[0135] S806: The server uses the private key in the asymmetric key to decrypt the encrypted communication key and obtain the communication key.

[0136] The implementation principles and technical effects of S804 to S806 can be referred to in the aforementioned embodiments, and will not be repeated here.

[0137] In this embodiment, after the terminal and server establish a communication connection, the server first sends a public key to the terminal. The terminal then generates a communication key, encrypts the communication key using the public key, and sends the encrypted communication key to the server. The server decrypts the encrypted communication key using its private key to obtain the communication key. This improves both data security and data encryption / decryption efficiency.

[0138] Figure 9 This is an example of communication key processing between the terminal and the server. Figure 1 .like Figure 9As shown, the server generates an RSA public key and an RSA private key. In one round of communication: the terminal establishes a communication connection with the server, and then the server sends the RSA public key to the terminal; the terminal generates the communication AES key required for this round of communication (i.e., the aforementioned communication key), encrypts the communication AES key using the RSA public key, and sends the encrypted communication AES key to the server; the server obtains the communication AES key by encrypting the encrypted communication AES key using the RSA private key. Thus, the exchange of communication AES keys is completed; subsequently, the data transmitted between the terminal and the server can be encrypted using the communication AES key.

[0139] Figure 10 This is an example of communication key processing between the terminal and the server. Figure 2 .like Figure 10 As shown, the server generates a private key and a public key. After a successful communication connection is established between the server and the terminal, the server sends the public key to the terminal. The terminal generates a communication key, encrypts the communication key using the public key, and reports the encrypted communication key to the server. The server decrypts the encrypted communication key using its private key to obtain the communication key. Afterward, the terminal can use the communication key to encrypt transmitted data and report it to the server, and the server can use the communication key to encrypt transmitted data and send it back to the terminal.

[0140] Figure 11 This is a schematic diagram of the sixth embodiment of this disclosure. (See diagram below.) Figure 11 As shown, on the terminal side, the key processing device 1100 provided in the sixth embodiment of this disclosure includes:

[0141] The key receiving unit 1101 is used to receive a target storage key encrypted with a communication key from the server. The communication key is used to encrypt data transmitted between the terminal and the server.

[0142] The key decryption unit 1102 is used to decrypt the encrypted target storage key using the communication key to obtain the target storage key, which is used for encrypting local data on the terminal.

[0143] In some embodiments, the key processing device 1100 further includes: a conflict verification unit 1103, configured to perform conflict verification between the target storage key and the local storage key of the terminal, and determine whether the target storage key and the local storage key of the terminal conflict; and a storage key update unit 1104, configured to update the local storage key of the terminal to the target storage key if the target storage key conflicts with the local storage key of the terminal.

[0144] In some embodiments, the conflict verification unit 1103 includes a conflict verification module (not shown in the figure), which is used to determine that the target storage key conflicts with the local storage key if the local storage key of the terminal is empty or the local storage key of the terminal is different from the target storage key, otherwise determine that the target storage key does not conflict with the local storage key of the terminal.

[0145] In some embodiments, the storage key update unit 1104 includes: a verification message sending module (not shown in the figure), configured to send a verification message to the server, the verification message including the terminal identifier of the terminal and indication information indicating whether the target storage key conflicts with the local storage key of the terminal; a response message receiving module (not shown in the figure), configured to receive a response message from the server; and a storage key update module (not shown in the figure), configured to update the local storage key of the terminal to the target storage key if the response message indicates that the terminal should update the storage key used for data storage encryption.

[0146] In some embodiments, the key processing device 1100 further includes a length determination unit (not shown in the figure) for determining the data length of the target storage key to a set length.

[0147] In some embodiments, the key processing device 1100 further includes a terminal identifier sending unit (not shown in the figure), used to send a terminal identifier of the terminal to the server, the terminal identifier being used to generate a storage key for data storage encryption by the terminal.

[0148] In some embodiments, the communication key is a symmetric key, and the key processing device 1100 further includes: a communication key encryption unit 1105, used to encrypt the communication key using the public key in the asymmetric key to obtain an encrypted communication key, wherein the private key in the asymmetric key is located on the server; and a communication key sending unit 1106, used to send the encrypted communication key to the server.

[0149] In some embodiments, the key processing device 1100 further includes a communication key generation unit (not shown in the figure), which generates a communication key in response to the establishment of a communication connection between the terminal and the server, the communication key being used for encryption of data transmitted over the communication connection.

[0150] In some embodiments, the communication key generation unit includes: a public key receiving module (not shown in the figure), used to receive a public key from the server after establishing a communication connection; and a communication key generation module, used to generate a communication key in response to receiving the public key.

[0151] Figure 11 The provided key processing device can execute the steps involved in the terminal in the above-described corresponding method embodiments. Its implementation principle and technical effect are similar, and will not be described again here.

[0152] Figure 12 This is a schematic diagram of the seventh embodiment of this disclosure. (See diagram below.) Figure 12 As shown, on the server side, the key processing apparatus 1200 provided in the seventh embodiment of this disclosure includes:

[0153] The storage key generation unit 1201 is used to generate a corresponding target storage key for the terminal. The target storage key is used to encrypt local data on the terminal.

[0154] The storage key encryption unit 1202 is used to encrypt the target storage key using a communication key to obtain an encrypted target storage key. The communication key is used for encrypting data transmitted between the terminal and the server.

[0155] The storage key sending unit 1203 is used to send the encrypted target storage key to the terminal.

[0156] In some embodiments, the storage key generation unit 1201 includes a storage key generation module (not shown in the figure), which is used to generate a target storage key based on the terminal identifier of the terminal.

[0157] In some embodiments, the key processing device 1200 further includes: a verification message receiving unit 1204, configured to receive a verification message sent by a terminal, the verification message including a terminal identifier of the terminal and indication information indicating whether the target storage key conflicts with the local storage key of the terminal; and a response message sending unit 1205, configured to send a response message to the terminal in response to the verification message, the response message instructing the terminal to update the storage key used for data storage encryption, or the response message instructing the terminal not to update the storage key used for data storage encryption.

[0158] In some embodiments, the response message sending unit 1205 includes: a key comparison module (not shown in the figure), configured to compare the target storage key with a storage key previously used by the terminal if the indication information indicates that the target storage key conflicts with the storage key locally on the terminal; and a first response message sending module (not shown in the figure), configured to send a response message to the terminal instructing the terminal to update the storage key used for data storage encryption if there is no storage key in the storage keys previously used by the terminal that is the same as the target storage key, otherwise send a response message to the terminal instructing the terminal not to update the storage key used for data storage encryption.

[0159] In some embodiments, the response message sending unit 1205 includes: a second response message sending module (not shown in the figure), configured to send a response message to the terminal instructing the terminal to update the storage key used for data storage encryption if the indication information indicates that the target storage key does not conflict with the local storage key of the terminal.

[0160] In some embodiments, the communication key is a symmetric key, and the key processing device 1200 further includes: a communication key receiving unit 1206, for receiving a communication key encrypted with a public key from a terminal; and a communication key decryption unit 1207, for decrypting the encrypted communication key using the private key in the asymmetric key to which the public key belongs, to obtain the communication key.

[0161] In some embodiments, the communication key receiving unit 1206 includes: a communication key receiving module (not shown in the figure), which is used to receive a communication key encrypted with a public key in response to the establishment of a communication connection between the terminal and the server. The communication key is used for encrypting data transmitted on the communication connection.

[0162] In some embodiments, the communication key receiving module includes: a public key sending submodule (not shown in the figure), used to send a public key to the terminal in response to the establishment of a communication connection; and a communication key receiving submodule (not shown in the figure), used to receive a communication key encrypted with the public key returned by the terminal.

[0163] In some embodiments, the key processing device 1200 further includes: an asymmetric key update unit (not shown in the figure), configured to update the public key and private key in response to an asymmetric key update instruction; and a public key update sending unit, configured to send the updated public key to the terminal.

[0164] Figure 12 The provided key processing device can execute the steps involved in the server in the above-described corresponding method embodiments. Its implementation principle and technical effect are similar, and will not be described again here.

[0165] According to embodiments of the present disclosure, the present disclosure also provides an electronic device, the electronic device including: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to perform the scheme provided in any of the above embodiments.

[0166] According to embodiments of this disclosure, this disclosure also provides a non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to cause a computer to execute the scheme provided in any of the above embodiments.

[0167] According to embodiments of this disclosure, this disclosure also provides a computer program product comprising: a computer program stored in a readable storage medium, at least one processor of an electronic device being able to read the computer program from the readable storage medium, and the at least one processor executing the computer program causing the electronic device to perform the scheme provided in any of the above embodiments.

[0168] According to embodiments of this disclosure, this disclosure also provides a roadside device that includes the electronic equipment provided in the above embodiments. The roadside device may include, for example, a roadside sensing device with computing capabilities and a roadside computing device connected to the roadside sensing device.

[0169] In the intelligent transportation vehicle-road cooperative system architecture, roadside equipment includes roadside sensing devices and roadside computing devices. Roadside sensing devices (e.g., roadside cameras) are connected to roadside computing devices (e.g., roadside computing units, RSCUs), which in turn are connected to server equipment. The server equipment can communicate with autonomous or assisted driving vehicles through various means. In another system architecture, the roadside sensing devices themselves include computing capabilities, and in this case, the roadside sensing devices are directly connected to the server equipment. These connections can be wired or wireless. In this disclosure, the server equipment may be, for example, a cloud control platform, a vehicle-road cooperative management platform, a central subsystem, an edge computing platform, or a cloud computing platform.

[0170] According to embodiments of this disclosure, this disclosure also provides a vehicle that includes the terminal provided in the above embodiments.

[0171] Figure 13 This is a schematic block diagram of an example electronic device 1300 that can be used to implement embodiments of the present disclosure. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present disclosure described and / or claimed herein.

[0172] like Figure 13 As shown, the electronic device 1300 includes a computing unit 1301, which can perform calculations based on data stored in a read-only memory (ROM). Figure 13 Taking ROM 1302 as an example, the computer program is loaded from storage unit 1308 into the random access memory (RAM). Figure 13 The computer program (using RAM 1303 as an example) is used to perform various appropriate actions and processes. RAM 1303 can also store various programs and data required for the operation of electronic device 1300. The computing unit 1301, ROM 1302, and RAM 1303 are interconnected via bus 1304. Input / output (I / O) interface ( Figure 13(Taking I / O interface 1305 as an example) is also connected to bus 1304.

[0173] Multiple components in electronic device 1300 are connected to I / O interface 1305, including: input unit 1306, such as keyboard, mouse, etc.; output unit 1307, such as various types of monitors, speakers, etc.; storage unit 1308, such as disk, optical disk, etc.; and communication unit 1309, such as network card, modem, wireless transceiver, etc. Communication unit 1309 allows electronic device 1300 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0174] The computing unit 1301 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 1301 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, digital signal processors (DSPs), and any suitable processor, controller, microcontroller, etc. The computing unit 1301 performs the various methods and processes described above, such as key processing methods. For example, in some embodiments, the key processing method may be implemented as a computer software program tangibly contained in a machine-readable medium, such as storage unit 1308. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 1300 via ROM 1302 and / or communication unit 1309. When the computer program is loaded into RAM 1303 and executed by the computing unit 1301, one or more steps of the key processing method described above may be performed. Alternatively, in other embodiments, the computing unit 1301 may be configured to perform a key processing method by any other suitable means (e.g., by means of firmware).

[0175] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard parts (ASSPs), systems on a chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a memory system, at least one input device, and at least one output device, and transmitting data and instructions to the memory system, the at least one input device, and the at least one output device.

[0176] The program code used to implement the methods of this disclosure may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, such that when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0177] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, compact disc read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0178] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the computer. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0179] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as a data server), or computing systems that include middleware components (e.g., an application server), or computing systems that include frontend components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., a communication network). Examples of communication networks include local area networks (LANs), wide area networks (WANs), and the Internet.

[0180] Computer systems can include clients and servers. Clients and servers are generally geographically separated and typically interact via communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. A server can be a cloud server, also known as a cloud computing server or cloud host, a hosting product within the cloud computing service ecosystem, addressing the shortcomings of traditional physical hosts and VPS (Virtual Private Server, or simply "VPS") services, such as high management difficulty and weak business scalability. Servers can also be servers for distributed systems or servers incorporating blockchain technology.

[0181] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this disclosure can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution disclosed in this disclosure can be achieved, and this is not limited herein.

[0182] The specific embodiments described above do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.

Claims

1. A key processing method applied to a terminal, comprising: in response to establishing a communication connection between the terminal and a server, receiving a public key in asymmetric keys from the server, a private key in the asymmetric keys being stored in the server; in response to receiving the public key, generating a communication key, the communication key being used for encryption of data transmission between the terminal and the server; encrypting the communication key by using the public key to obtain an encrypted communication key; sending the encrypted communication key and a terminal identifier of the terminal to the server, the terminal identifier being used by the server to generate a target storage key corresponding to the terminal; receiving the target storage key encrypted by the communication key from the server; decrypting the encrypted target storage key by using the communication key to obtain the target storage key, so that the terminal stores local data after encrypting the local data by using the target storage key. 2.The key processing method of claim 1, after the step of decrypting the encrypted target storage key by using the communication key to obtain the target storage key, further comprising: performing conflict checking on the target storage key and a storage key local to the terminal to determine whether the target storage key conflicts with the storage key local to the terminal; if the target storage key conflicts with the storage key local to the terminal, updating the storage key local to the terminal as the target storage key.

3. The key processing method according to claim 2, wherein the step of performing conflict checking on the target storage key and the storage key local to the terminal to determine whether the target storage key conflicts with the storage key local to the terminal comprises: if the storage key local to the terminal is empty or the storage key local to the terminal is different from the target storage key, determining that the target storage key conflicts with the storage key local to the terminal, otherwise, determining that the target storage key does not conflict with the storage key local to the terminal.

4. The key processing method according to claim 2, wherein the step of updating the storage key local to the terminal as the target storage key comprises: sending a checking message to the server, the checking message comprising a terminal identifier of the terminal and indication information indicating whether the target storage key conflicts with the storage key local to the terminal; receiving a response message from the server; if the response message indicates that the terminal updates the storage key used for data storage encryption, updating the storage key local to the terminal as the target storage key. 5.The key processing method of claim 2, before the step of performing conflict checking on the target storage key and the storage key local to the terminal, further comprising: determining that a data length of the target storage key is a set length. 6.A key processing method applied to a server, comprising: in response to establishing a communication connection with a terminal, sending a public key in asymmetric keys to the terminal, a private key in the asymmetric keys being stored in the server, so that the terminal generates a communication key in response to receiving the public key, the communication key being used for encryption of data transmission between the server and the terminal. receive the encrypted communication key from the terminal, decrypt the encrypted communication key by using a private key in the asymmetric key pair, and obtain the communication key; receive a terminal identifier from the terminal, and generate a target storage key according to the terminal identifier, the target storage key being used for encryption of local data on the terminal; encrypt the target storage key by using the communication key, and obtain an encrypted target storage key; send the encrypted target storage key to the terminal, so that the terminal decrypts the encrypted target storage key by using the communication key to obtain the target storage key, and encrypts local data by using the target storage key before storing the local data.

7. The key processing method of claim 6, after the sending the encrypted target storage key to the terminal, further comprising: receiving a check message sent by the terminal, the check message comprising a terminal identifier of the terminal and indication information indicating whether the target storage key conflicts with a storage key stored locally on the terminal; in response to the check message, sending a response message to the terminal, the response message indicating that the terminal updates a storage key used for data storage encryption, or the response message indicating that the terminal does not update the storage key used for data storage encryption.

8. The key processing method according to claim 7, wherein The sending the response message to the terminal in response to the check message comprises: if the indication information indicates that the target storage key conflicts with the storage key stored locally on the terminal, comparing the target storage key with storage keys that have been used by the terminal in the past; if there is no storage key identical to the target storage key in the storage keys that have been used by the terminal in the past, sending a response message to the terminal, the response message indicating that the terminal updates the storage key used for data storage encryption, or sending a response message to the terminal, the response message indicating that the terminal does not update the storage key used for data storage encryption.

9. The key processing method according to claim 7, wherein The sending the response message to the terminal in response to the check message comprises: if the indication information indicates that the target storage key does not conflict with the storage key stored locally on the terminal, sending a response message to the terminal, the response message indicating that the terminal does not update the storage key used for data storage encryption.

10. The key processing method of claim 6, further comprising: in response to an asymmetric key update instruction, updating the public key and the private key; sending the updated public key to the terminal.

11. A key processing apparatus applied to a terminal, comprising: a public key receiving module configured to receive a public key in an asymmetric key pair from a server in response to establishment of a communication connection between the terminal and the server, a private key in the asymmetric key pair being stored in the server; a communication key generating module configured to generate a communication key in response to reception of the public key, the communication key being used for encryption of data transmitted between the terminal and the server; a communication key encrypting unit configured to encrypt the communication key by using the public key, and obtain an encrypted communication key. a terminal identifier sending unit configured to send the encrypted communication key and a terminal identifier of the terminal to the server, the terminal identifier being used by the server to generate a target storage key corresponding to the terminal; a key receiving unit configured to receive a target storage key encrypted by a communication key from the server, the communication key being used for encryption of data transmission between the terminal and the server; a key decryption unit configured to decrypt the encrypted target storage key by the communication key to obtain the target storage key, the target storage key being used for encryption of local data on the terminal.

12. The key processing apparatus of claim 11, further comprising: a conflict checking unit configured to check a conflict between the target storage key and a storage key local to the terminal, and determine whether the target storage key conflicts with the storage key local to the terminal; a storage key updating unit configured to update the storage key local to the terminal as the target storage key if the target storage key conflicts with the storage key local to the terminal.

13. The key processing apparatus according to claim 12, wherein The conflict checking unit comprises: a conflict checking module configured to determine that the target storage key conflicts with the storage key local to the terminal if the storage key local to the terminal is empty or the storage key local to the terminal is different from the target storage key, or determine that the target storage key does not conflict with the storage key local to the terminal.

14. The key processing apparatus according to claim 12, wherein The storage key updating unit comprises: a checking message sending module configured to send a checking message to the server, the checking message comprising a terminal identifier of the terminal and indication information indicating whether the target storage key conflicts with the storage key local to the terminal; a response message receiving module configured to receive a response message from the server; a storage key updating module configured to update the storage key local to the terminal as the target storage key if the response message indicates that the terminal updates the storage key for data storage encryption.

15. The key processing apparatus of claim 12, further comprising: a length judging unit configured to determine that a data length of the target storage key is a set length.

16. A key processing apparatus applied to a server, comprising: a public key sending sub-module configured to send a public key in an asymmetric key to a terminal in response to establishing a communication connection with the terminal, a private key in the asymmetric key being stored in the server, so that the terminal generates a communication key in response to receiving the public key, the communication key being used for encryption of data transmission between the server and the terminal; a communication key receiving unit configured to receive a communication key encrypted by the public key from the terminal; a communication key decryption unit configured to decrypt the encrypted communication key by a private key in the asymmetric key to obtain the communication key; a storage key generating module configured to receive a terminal identifier of the terminal, and generate a target storage key according to the terminal identifier of the terminal. The storage key generation unit is configured to generate the target storage key according to a terminal identifier of the terminal, the target storage key being used for encryption of local data on the terminal. The storage key encryption unit is configured to encrypt the target storage key by using a communication key to obtain an encrypted target storage key, the communication key being used for encryption of data transmission between the terminal and the server. The storage key sending unit is configured to send the encrypted target storage key to the terminal.

17. The key processing apparatus of claim 16, further comprising: The check message receiving unit is configured to receive a check message sent by the terminal, the check message comprising a terminal identifier of the terminal and indication information indicating whether the target storage key conflicts with a locally stored key of the terminal. The response message sending unit is configured to send a response message to the terminal in response to the check message, the response message indicating that the terminal updates a storage key used for data storage encryption, or the response message indicating that the terminal does not update the storage key used for data storage encryption.

18. The key processing apparatus according to claim 17, wherein The response message sending unit comprises: The key comparison module is configured to compare the target storage key with a storage key used by the terminal in the past if the indication information indicates that the target storage key conflicts with the locally stored key of the terminal. The first response message sending module is configured to send a response message indicating that the terminal updates the storage key used for data storage encryption to the terminal if there is no storage key identical to the target storage key in the storage key used by the terminal in the past, or to send a response message indicating that the terminal does not update the storage key used for data storage encryption to the terminal.

19. The key processing apparatus according to claim 17, wherein The response message sending unit comprises: The second response message sending module is configured to send a response message indicating that the terminal does not update the storage key used for data storage encryption to the terminal if the indication information indicates that the target storage key conflicts with the locally stored key of the terminal.

20. The key processing apparatus of claim 16, further comprising: The asymmetric key updating unit is configured to update the public key and the private key in response to an asymmetric key updating instruction. The updated public key sending unit is configured to send the updated public key to the terminal.

21. An electronic device, comprising: at least one processor; and a memory connected to the at least one processor in communication; wherein the memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to perform the key processing method according to any one of claims 1 to 6, or perform the key processing method according to any one of claims 7 to 10. The computer instructions are used to enable the computer to perform the key processing method according to any one of claims 1 to 6, or perform the key processing method according to any one of claims 7 to 10.

22. A non-transitory computer readable storage medium having stored thereon computer instructions, wherein, ​ 23. A computer program product comprising a computer program which, when executed by a processor, implements the steps of the key handling method according to any one of claims 1 to 6, or implements the steps of the key handling method according to any one of claims 7 to 10.

Citation Information

Patent Citations

  • Key management method and device, computer equipment and storage medium

    CN110535641A

  • Intrusion detection method and device, equipment and storage medium

    CN114338114A

  • Data processing method, terminal, server, system, equipment, medium and product

    CN115529130A