Data Transmission Method and Device

By using secure identity authentication information to generate signature strings in the vehicle control app, the customized security problem of data transmission of the vehicle control app is solved, and efficient data protection is achieved.

CN118611928BActive Publication Date: 2025-07-11CHONGQING SELIS PHOENIX INTELLIGENT INNOVATION TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202410708583.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-03
Publication Date
2025-07-11
Estimated Expiration
2044-06-03

AI Technical Summary

Technical Problem

The existing technology cannot customize security protection for data transmission of vehicle-controlled apps. Simple encryption algorithms are prone to attacks, and complex encryption algorithms affect timeliness, making it difficult to ensure the security of user information.

Method used

Secure identity authentication information is adopted, including basic elements, arrangement and combination methods, representation methods, replacement algorithms and position selection algorithms, and the data is signed and encrypted. The order and number of signatures and encryption can be configured to meet different security needs.

Benefits of technology

It realizes customized security protection for data transmission of vehicle-controlled Apps, improves the security and timeliness of data transmission, and prevents attacks and tampering by man in the middle.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118611928B_ABST
    Figure CN118611928B_ABST
Patent Text Reader

Abstract

An embodiment of the present invention provides a data transmission method and apparatus. The method includes: when a client transmits data to a server, obtaining a plurality of basic elements of the client; combining the basic elements in a permutation and combination manner to obtain composite basic elements, and combining the composite basic elements with the basic elements and / or the composite basic elements to obtain a string; representing the string using a representation method to obtain a target string; replacing some characters of the target string using a replacement algorithm to obtain a replacement string; using a selection algorithm to select some characters from the replacement string as an input source, and generating a signature string according to the input source; signing and encrypting the transmission data according to the signature string to obtain encrypted transmission data, and putting the encrypted transmission data into a network request to send the encrypted transmission data to the server through the network request. The embodiment of the present invention meets the security requirements of various clients for transmitted data and realizes secure customization.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present invention relate to the field of computer technology, and in particular, to a data transmission method, a data transmission device, an electronic device, and a computer-readable storage medium. Background Art

[0002] At present, the security solutions on the market vary widely and cannot be customized for a specific product. If conventional encryption algorithms or signature algorithms are simply called, it is easy to be attacked. However, if they are too complex, it is difficult to ensure the timeliness of requests because the more complex the encryption algorithm, the longer the decryption time.

[0003] As is well known, the vehicle control App (Application) attaches great importance to user information. Each vehicle control instruction carries a large amount of user privacy information, which is related to the safety of users and vehicles. Therefore, how to design a security identity authentication scheme suitable for the client to protect the security of transmission data during network transmission has become an urgent problem to be solved. Summary of the Invention

[0004] The purpose of the embodiments of the present invention is to provide a data transmission method to protect the security of transmission data during network transmission. The specific technical solutions are as follows:

[0005] In the first aspect implemented by the present invention, first, a data transmission method is provided. When synchronizing data transmission between a client and a server, security identity authentication information used is synchronized. The security identity authentication information at least includes basic elements, permutation and combination methods, representation methods, replacement algorithms, and selection algorithms. The method includes:

[0006] When the client transmits data to the server, several basic elements of the client are obtained;

[0007] The basic elements are combined using the permutation and combination method to obtain composite basic elements, and the composite basic elements are combined with the basic elements and / or the composite basic elements to obtain a string;

[0008] The string is represented using the representation method to obtain a target string;

[0009] Part of the characters of the target string are replaced using the replacement algorithm to obtain a replacement string;

[0010] Part of the characters are selected from the replacement string as an input source using the selection algorithm, and a signature string is generated based on the input source;

[0011] Sign and encrypt the transmission data according to the signature string to obtain encrypted transmission data, and put the encrypted transmission data into a network request to send the encrypted transmission data to the server through the network request; wherein, the execution order and number of times of the signature and the encryption are configurable.

[0012] An embodiment of the present invention also discloses a data transmission method for synchronizing security authentication information used during data transmission between a client and a server. The security authentication information includes at least basic elements, permutation and combination methods, representation methods, replacement algorithms, and selection algorithms. The method includes:

[0013] When receiving a network request sent by the client, extract the encrypted transmission data from the network request.

[0014] Obtain a number of basic elements of the client.

[0015] Combine the basic elements using the permutation and combination method to obtain composite basic elements, and combine the composite basic elements with the basic elements and / or the composite basic elements to obtain a string.

[0016] Represent the string using the representation method to obtain a target string.

[0017] Replace some characters of the target string using the replacement algorithm to obtain a replacement string.

[0018] Select some characters from the replacement string as an input source using the selection algorithm, and generate a signature string based on the input source.

[0019] Decrypt and authenticate the encrypted transmission data according to the signature string to obtain the transmission data.

[0020] An embodiment of the present invention also discloses a data transmission device for synchronizing security authentication information used during data transmission between a client and a server. The security authentication information includes at least basic elements, permutation and combination methods, representation methods, replacement algorithms, and selection algorithms. The device includes:

[0021] A first acquisition module, configured to obtain a number of basic elements of the client when the client transmits data to the server.

[0022] A first combination module, configured to combine the basic elements using the permutation and combination method to obtain composite basic elements, and combine the composite basic elements with the basic elements and / or the composite basic elements to obtain a string.

[0023] The first representation module is used to represent the string in the representation manner to obtain a target string;

[0024] The first replacement module is used to replace some characters of the target string by using the replacement algorithm to obtain a replacement string;

[0025] The first position selection module is used to select some characters from the replacement string as an input source by using the position selection algorithm, and generate a signature string according to the input source;

[0026] The signature encryption module is used to sign and encrypt the transmission data according to the signature string to obtain encrypted transmission data, and put the encrypted transmission data into a network request to send the encrypted transmission data to the service through the network request; wherein, the execution order and number of times of the signature and the encryption are configurable.

[0027] An embodiment of the present invention also discloses a data transmission device, security authentication information used when synchronously transmitting data between a client and a server, the security authentication information at least includes basic elements, permutation and combination modes, representation modes, replacement algorithms and position selection algorithms, and the device includes:

[0028] The extraction module is used to extract encrypted transmission data from the network request when receiving the network request sent by the client,

[0029] The second acquisition module is used to acquire a plurality of basic elements of the client;

[0030] The second combination module is used to combine the basic elements by using the permutation and combination mode to obtain a composite basic element, and combine the composite basic element with the basic element and / or the composite basic element to obtain a string;

[0031] The second representation module is used to represent the string in the representation manner to obtain a target string;

[0032] The second replacement module is used to replace some characters of the target string by using the replacement algorithm to obtain a replacement string;

[0033] The second position selection module is used to select some characters from the replacement string as an input source by using the position selection algorithm, and generate a signature string according to the input source;

[0034] The decryption module is used to decrypt and authenticate the encrypted transmission data according to the signature string to obtain transmission data.

[0035] In yet another aspect of the implementation of the present invention, there is also provided a computer-readable storage medium storing instructions, which, when running on a computer, cause the computer to execute any one of the above-mentioned data transmission methods.

[0036] In yet another aspect of the implementation of the present invention, there is also provided a computer program product containing instructions, which, when running on a computer, cause the computer to execute any one of the above-mentioned data transmission methods.

[0037] Compared with the related art, the embodiments of the present invention have at least the following advantages:

[0038] A data transmission method provided by an embodiment of the present invention pre-synchronizes security identity authentication information used during data transmission between a client and a server. The security identity authentication information at least includes basic elements, permutation and combination methods, representation methods, replacement algorithms, and selection algorithms. When the client transmits data to the server, several basic elements of the client are obtained, and the basic elements are combined using the permutation and combination method to obtain composite basic elements. Then, the composite basic elements are combined with the basic elements and / or the composite basic elements again to obtain a string. The string is represented using the representation method to obtain a target string. Part of the characters of the target string are replaced using the replacement algorithm to obtain a replacement string. Part of the characters are selected from the replacement string using the selection algorithm as an input source to generate a signature string. Subsequently, the transmission data can be signed and encrypted based on the signature string to obtain encrypted transmission data, and the encrypted transmission data is placed in a network request to send the encrypted transmission data to the server through the network request. Among them, the execution order and number of times of signing and encryption can be configured. The embodiments of the present invention can configure variables for generating signature strings based on the security identity authentication information synchronized between the client and the server, thereby flexibly adjusting the security level during data transmission between the client and the server, meeting the security requirements of various clients for transmitted data, and achieving the purpose of security customization. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art.

[0040] Figure 1 is a flowchart of the steps of a data transmission method provided in an embodiment of the present invention;

[0041] Figure 2 is a schematic diagram of a feasible storage format of identity identification information provided in an embodiment of the present invention;

[0042] Figure 3It is a schematic diagram of the interaction between a client and a server based on an encryptor provided in an embodiment of the present invention;

[0043] Figure 4 It is a schematic diagram of generating a certificate based on an encryptor provided in an embodiment of the present invention;

[0044] Figure 5 It is another schematic diagram of the interaction between a client and a server based on an encryptor provided in an embodiment of the present invention;

[0045] Figure 6 It is a flowchart of the steps of another data transmission method provided in an embodiment of the present invention;

[0046] Figure 7 It is a structural block diagram of a data transmission device provided in an embodiment of the present invention;

[0047] Figure 8 It is a structural block diagram of another data transmission device provided in an embodiment of the present invention;

[0048] Figure 9 It is a structural block diagram of an electronic device provided in an embodiment of the present invention. Detailed implementation manners

[0049] Next, the technical solutions in the embodiments of the present invention will be described with reference to the accompanying drawings in the embodiments of the present invention.

[0050] Refer to Figure 1 , which is a flowchart of the steps of a data transmission method provided in an embodiment of the present invention. As Figure 1 shown, when synchronizing data transmission between the client and the server, the security identity authentication information is used. The security identity authentication information at least includes basic elements, permutation and combination methods, representation methods, replacement algorithms, and selection algorithms. The method may specifically include the following steps:

[0051] Step 101, when the client transmits data to the server, obtain several basic elements of the client.

[0052] Among them, the client can also be called an App (application program, Application). The client can be other types of clients such as a vehicle control client for vehicle control. The server can also be other types of clients such as a server for vehicle control. Embodiments of the present invention can be applied to the client or the encryptor. When applied to the client, the client and the server directly communicate with each other. When applied to the encryptor, the client and the server communicate through the encryptor. When the client communicates with the server, it is necessary to sign the communication data (transmission data) for each transmission to achieve security identity authentication and ensure the security of the transmission data.

[0053] In a specific implementation, HTTP (Hypertext Transfer Protocol) communication can be carried out between the client and the server. Among them, there are many types of HTTP requests (network requests), such as get requests and post requests. In the embodiments of the present invention, the get request and the post request are mainly used for illustration.

[0054] However, in fact, the embodiments of the present invention can be applied not only to get requests and post requests, but also to other HTTP requests such as delete requests and put requests. Exemplarily, in an HTTP request, the most important data is the service data carried by the get request and the post request, which is specific to the get request and the post request. These data can be stored in the service data dictionary; of course, the url (uniform resource locator) of each get request and post request is also unique, and the request time (timestamp) is also unique. These can all be used as the identifiers to distinguish an HTTP request. Therefore, in the embodiments of the present invention, it is appropriate to use some of the above data related to HTTP requests, such as the service data dictionary, url, and timestamp, as the original data (basic elements) for generating the signature string. These basic elements can basically mark an HTTP request, and there are many combination ways of these basic elements.

[0055] In addition, the embodiments of the present invention can also use the identity identification information (AppKey) used by the client to represent its own identity as a basic element. Specifically, the AppKey is a temporarily fixed value, which is assigned by the server to the client to represent its own identity. Different servers can assign different AppKeys according to different clients. For example, the AppKey assigned by the TSP server (the TSP server is a type of vehicle control service, mainly used for vehicle control) to the vehicle control client can be "12345", the AppKey assigned by the OTA server (the OTA server is a type of vehicle control service, mainly used for in-vehicle software update) to the vehicle control client can be "abcde", the AppKey assigned by the TSP server to the overseas version of the vehicle control client can be "444444", and the AppKey assigned by the OTA server to the overseas version of the vehicle control client can be "cccccc".

[0056] In an embodiment of the present invention, for a single request, there may be the following basic elements: A: url; B: business data dictionary, C: timestamp; D: AppKey agreed upon by a certain server and a certain client. When the client and the server transmit data, the client or the encryptor may generate a signature (signature string) using the above basic elements. Furthermore, the server or the encryptor may implement secure identity authentication of the client based on the signature to ensure data security.

[0057] It should be noted that the above basic elements are only the most basic elements of a single request. According to business requirements, the basic elements may be increased or decreased. For example, on the basis of the above basic elements, the following basic elements may be added: E: unique ID (identifie, identifier) assigned to each interface; H: delimiter, where the delimiter is a delimiter between basic elements, and the delimiter may be any character agreed upon, with arbitrary content and length, such as &, or *, or 111... etc. It can be seen that in an embodiment of the present invention, the number of basic elements and what each basic element is are variable. Therefore, the basic elements in an embodiment of the present invention are taken as one of the variables, and are described here as variable 1.

[0058] In an embodiment of the present invention, before the client and the server transmit data, the secure identity authentication information used during data transmission is pre-synchronized between the client and the server. Among them, the secure identity authentication information may at least include basic elements, permutation and combination methods, representation methods, replacement algorithms, and selection algorithms, etc. It should be noted that the secure identity authentication information in an embodiment of the present invention may all be used to generate a signature string, or part of the secure identity authentication information may be selected to generate a signature string, and the secure identity authentication information may be increased or decreased according to business requirements, and the embodiment of the present invention does not need to limit this.

[0059] Step 102: Combine the basic elements using the permutation and combination method to obtain composite basic elements, and combine the composite basic elements with the basic elements and / or the composite basic elements to obtain a string.

[0060] In the embodiments of the present invention, after obtaining the basic elements, the basic elements can be combined by means of permutation and combination to obtain composite basic elements. For example, assuming the basic elements are A, B, C, D, E, H, then these basic elements can be combined pairwise or in multiple combinations. For example, they can be combined into ABCDEH, ACBD, AC, CA, BD... etc. There are many combinations just by performing permutation and combination based on the order of the basic elements. Moreover, in the embodiments of the present invention, the order of the basic elements can be disrupted and then permutation and combination can be performed, and each combination is acceptable. Further, in the embodiments of the present invention, the basic elements can be combined to obtain composite basic elements, and the composite basic elements can be further combined with other basic elements or composite basic elements. For example, (AB)D, (CD)A, (DE)D, where the content in the brackets is the composite basic element. In addition, the basic elements in the embodiments of the present invention can also repeat and be combined, such as permutation and combination methods like AHAHAHB, ABCDABCD... etc. The embodiments of the present invention do not need to limit the combination method of the basic elements. In the embodiments of the present invention, the permutation and combination of the basic elements are variable. Therefore, the embodiments of the present invention take the permutation and combination method as one of the variables, which is described as variable 2 here.

[0061] In the embodiments of the present invention, after combining the basic elements by means of permutation and combination, a string can be obtained. For example, the string:

[0062] "https: / / domain.com / getCarInfo***userid=123&carid=432***timestamp=483839292***c cccccc".

[0063] Step 103, represent the string by using the said representation method to obtain a target string.

[0064] In practical applications, a string can have various representation methods, such as string representation method, binary representation method, ASCII code representation method, base64 representation method, etc. Different representation methods can further convert the string into a target string.

[0065] For example, assume that the string obtained by combining the basic elements by means of permutation and combination is:

[0066] "https: / / domain.com / getCarInfo***userid=123&carid=432***timestamp=483839292***c cccccc".

[0067] If the above string is viewed in string expression, the above string is: "https: / / domain.com / getCarInfo***userid=123&carid=432***timestamp=483839292***ccccccc";

[0068] If the above string is viewed in binary expression, the above string is: 110100011101……;

[0069] If the above string is viewed in ASCII code expression, the above string is: h;t;t;p……

[0070] If the above string is viewed in base64 expression, the above string is: aHR0cHM6Ly9kb21haW4uY29tL2dldENhckluZ…….

[0071] In the embodiment of the present invention, the expression of the string is variable. Therefore, the embodiment of the present invention takes the expression as one of the variables, and is described as variable 3 here.

[0072] Step 104, use the replacement algorithm to replace some characters of the target string to obtain a replacement string.

[0073] In the embodiment of the present invention, after obtaining the target string, some bits of it can be replaced. Specifically, which bits, what to replace them with, and what the replacement algorithm is are variable. Therefore, the embodiment of the present invention takes the replacement algorithm as one of the variables, and is described as variable 4 here.

[0074] For example, assume the target string is

[0075] "https: / / domain.com / getCarInfo***userid=123&carid=432***timestamp=483839292***c cccccc", replace the 1st, 4th, 6th, and 8th bits of the target string. Among them, the 1st

[0076] is replaced with "s", the 4th bit is replaced with "a", and the 6th and 8th bits are replaced with "124". Then the replacement string after replacing some characters can be obtained as

[0077] "sttas124 / 124domain.com / getCarInfo***userid=123&carid=432***timestamp=483839292***c cccccc".

[0078] Step 105: Select some characters from the replacement string as the input source using the selection algorithm, and generate a signature string based on the input source.

[0079] In an embodiment of the present invention, after obtaining the replacement string for generating the signature string, some characters therein can be taken using the selection algorithm as the input source for generating the signature string. An embodiment of the present invention provides a selection algorithm, that is: determine a string of numbers, and perform the selection algorithm according to the numbers to obtain the input source. Among them, since the selection numbers are variable, the selection numbers generated by the selection algorithm in the embodiment of the present invention are used as one of the variables, and are described as variable 5 here.

[0080] For example, assume that a string of selection numbers determined based on the selection algorithm is: 1, 2, 5, 9, 18, then the 1st, 2nd, 5th, 9th, and 18th positions of the replacement string can be taken as the input source.

[0081] For example, assume that the replacement string in the string representation is:

[0082] "sttas124 / 124domain.com / getCarInfo***userid=123&carid=432***timestamp=483839292***c cccccc"

[0083] Then the input source obtained by selecting positions from the replacement string based on the selection numbers is: sts / n.

[0084] Assume that the replacement string in the binary representation is:

[0085] "101101010110111110001111101011……", then the input source obtained by selecting positions from the replacement string based on the selection numbers is: 10000.

[0086] Optionally, if the replacement string itself does not have that many positions, for example, there is no 18th position, then the 18th position can be directly ignored, and only the 1st, 2nd, 5th, and 9th positions of the replacement string are taken.

[0087] Step 106: Sign and encrypt the transmission data according to the signature string to obtain encrypted transmission data, and put the encrypted transmission data into a network request to send the encrypted transmission data to the server through the network request; wherein, the execution order and number of times of the signature and the encryption are configurable.

[0088] In an embodiment of the present invention, processing the basic elements based on the secure identity authentication information can obtain

[0089] to the input source for generating the signature string. Next, when the client interacts with the server, such as when the client requests data from the server or the server sends data to the client, every time data is transmitted, it is necessary to sign the transmitted data with, for example, the signature string to obtain the encrypted transmitted data. Among them, the signature method is to select a popular signature algorithm on the market, such as MD5 (Message Digest Algorithm 5), and attach it to the Header (request header) of the network request to send the encrypted transmitted data to the server through the network request. The server or the encryptor can authenticate and decrypt the encrypted transmitted data according to the secure identity authentication information, so as to complete the data transmission between the client and the server.

[0090] A data transmission method provided by an embodiment of the present invention. The secure identity authentication information used during data transmission is pre-synchronized between the client and the server. Among them, the secure identity authentication information at least includes basic elements, permutation and combination methods, representation methods, replacement algorithms, and selection algorithms. When the client transmits data to the server, several basic elements of the client are obtained, and the basic elements are combined using the permutation and combination method to obtain composite basic elements, and the composite basic elements are combined with the basic elements and / or the composite basic elements again to obtain a string. The string is represented using the representation method to obtain a target string. Part of the characters of the target string are replaced using the replacement algorithm to obtain a replacement string. Part of the characters are selected from the replacement string as the input source using the selection algorithm to generate a signature string based on the input source. Subsequently, the transmitted data can be signed and encrypted according to the signature string to obtain the encrypted transmitted data, and the encrypted transmitted data is placed in the network request to send the encrypted transmitted data to the server through the network request; among them, the execution order and number of times of signing and encrypting can be configured. The embodiment of the present invention can configure the variables for generating the signature string based on the secure identity authentication information synchronized between the client and the server, so as to flexibly adjust the security level during data transmission between the client and the server, and can meet the security requirements of various clients for transmitted data, achieving the purpose of security customization.

[0091] In an embodiment of the present invention, before the step 101, when the client transmits data to the server and obtains several basic elements of the client, the method further includes:

[0092] When the client is started, synchronize the secure identity authentication information used for data transmission between the client and the server;

[0093] After the client is started, obtain the mapping relationship and update the client according to the mapping relationship

[0094] The secure authentication information used for data transmission between the client and the server; wherein, the mapping relationship is the mapping relationship between the server and the permutation and combination method, the representation method, the substitution algorithm, and the selection algorithm.

[0095] After the client is started, obtain the update frequency, and update the secure authentication information used for data transmission between the client and the server according to the update frequency; wherein, the update frequency is predetermined or determined temporarily according to service requirements.

[0096] In the embodiment of the present invention, the determination of the selection digit, that is, variable 5, is crucial because we cannot let a third-party attacker obtain any information about variable 5. Otherwise, it may be subject to various attacks (man-in-the-middle attack, replay, tampering, etc.). Therefore, we cannot transmit this information (that is, synchronize variable 5 between the client and the server) through the ordinary method of mutual communication between the client and the server at the beginning, otherwise variable 5 will be intercepted.

[0097] After the embodiment of the present invention provides the secure authentication information including multiple optional algorithms, it ensures that a man-in-the-middle cannot obtain variable 5. There is no distinction between the several algorithms in the secure authentication information in terms of superiority or inferiority. Here, the several algorithms in the secure authentication information are temporarily called x algorithms.

[0098] Before introducing the x algorithm, first explain the timing of the x algorithm call: At the beginning of the startup of the App (client), before all server interfaces are requested, the client can make a call to the x algorithm to synchronize all the information used in the security policy (including variables 1 - 5) with the server. In this way, the server and the client can reach an agreement on the generation and verification of signatures. It should be noted that the client is not the only end that can initiate the x algorithm. The server can also initiate the x algorithm. Therefore, hereinafter, the A end and the B end are used to refer to the server and the client, these 2 ends.

[0099] Moreover, during the subsequent communication between the client and the server, the x algorithm can also be called at any time, that is: the client and the server can update all the information used in the security policy (including variables 1 - 5) at any time, further ensuring security. This is because if all the information used in the security policy is not updated for a long time, there is a risk of being eavesdropped and the variables being guessed. In the embodiment of the present invention, as long as one party of the client or the server initiates a request and executes the x algorithm, both parties can synchronize to the latest variables. For example, assume that the x algorithm has the following several types: (1) permutation and combination method, (2) representation method, (3) substitution algorithm, and (4) selection algorithm. Then the following 4 ways of the x algorithm can be used alternately or replaced based on the mapping relationship. For example: for the OTA server, because there is a lot of key data,

[0100] (1) and (2) can be adopted. For the community server with relatively low data security requirements, (3) and (4) can be adopted; or for the OTA server, (1) can be adopted for a period of time and (2) for another period of time; for the community server, (1) or (2) with higher security can be adopted for a period of time, and (3) or (4) for another period of time. In the embodiment of the present invention, the mapping relationship between the server and the x algorithm is described as variable 6.

[0101] In the embodiment of the present invention, the update frequency of the x algorithm can be obtained, where the update frequency is predetermined or determined temporarily according to business requirements. For example, the update frequency is predetermined by business requirements: for example, the rule is to update every y minutes (fixed-time update); or call every y minutes and then accumulate or subtract n minutes for the next time (dynamic-time update); or update after a random time (random-time update), etc. The update frequency is determined temporarily by business requirements: in case of sudden emergencies such as malicious attacks or major security incidents, it will be updated immediately one or more times. In the embodiment of the present invention, the update frequency is described as variable 7.

[0102] In an embodiment of the present invention, step 105, selecting some characters from the replacement string as the input source by using the selection algorithm, includes:

[0103] Obtaining a number of flags generated after the client and the server authenticate each other based on the agreed identity identifier; wherein, the flags are generated by the client or the server, and when the client and the server transmit the flags, they are encrypted and decrypted by using a preset encryption and decryption algorithm, and the encryption and decryption algorithm is provided by the client, or the server, or the client and the server each use their own provided encryption and decryption algorithms, or the client and the server interact with each other and use the encryption and decryption algorithms provided by the other party;

[0104] Generating a selection number according to the flags, and selecting some characters from the replacement string as the input source according to the selection number.

[0105] In the embodiment of the present invention, there are various ways to determine the selection number, that is, variable 5.

[0106] In an alternative manner, variable 5 can be based on a number of flags generated after the client and the server authenticate each other based on the agreed identity identifier, and generate a selection number based on the flags, so that some characters can be selected from the replacement string as the input source, and then a signature string can be generated. Among them, there can be multiple flags, which can be generated by the client or the server. When the client and the server transmit the flags, a preset encryption algorithm (which can be abbreviated as the encryption algorithm) needs to be used for

[0107] Encryption and decryption are performed to avoid plaintext transmission. The encryption and decryption algorithms can be provided by the client, or by the server, or the client and the server can each use their own provided encryption and decryption algorithms, or the client and the server can interact with each other and use the encryption and decryption algorithms provided by the other party. The embodiments of the present invention do not need to limit this.

[0108] Among them, generating the selection digits according to the flag includes: combining the flag by using the permutation and combination method to obtain a composite flag, and combining the composite flag with the flag and / or the composite flag to obtain a flag string; representing the flag string by using the representation method to obtain a target flag string; replacing some characters of the target flag string by using the replacement algorithm to obtain a replacement flag string; generating selection digits according to the replacement flag string; wherein, if there are duplicate digits in the selection digits, the selection digits are de-duplicated or the digits are weighted when encountering them.

[0109] In a specific example of the present invention, the A end and the B end can represent the client and the server, and the specific steps of the first generation method of variable 5 are as follows:

[0110] (1-1) The A end sends a request to the B end. The attached information is:

[0111] A flag (encrypted by an encryption algorithm). For the convenience of reference, it is called flag 1. Among them, the implementation methods of the flag include but are not limited to forms such as numbers and strings.

[0112] The encryption algorithm 1 of the A end. The selection of the encryption algorithm 1 can be a commonly used symmetric / non-symmetric encryption algorithm on the market. The encryption algorithm 1 is used to encrypt flag 1 to avoid its transmission in plaintext.

[0113] The encryption algorithm 2 of the A end. The encryption algorithm 2 and the encryption algorithm 1 can be the same or separate. For any subsequent data transmission between the A end and the B end, plaintext transmission needs to be avoided, so it may also be necessary to confirm an encryption algorithm for the data, that is, the encryption algorithm 2 (the encryption algorithm 2 can be the same as the encryption algorithm 1 or different).

[0114] The identity information (identity identifier) of the A end. There are many optional schemes for the identity information of the A end. For example, the AppKey mentioned above is one kind, and it can also be other original agreements, such as device unique identifier, service unique identifier, digital certificate, etc., as long as it is a unique identity information agreed in advance. The embodiments of the present invention do not need to limit this.

[0115] (1-2) The B end receives the data and sends data to the A end.

[0116] The B side checks the data sent by the A side. If the identity authentication is successful based on the identity identifier, it stores the data sent by the A side and returns its own identity information and a flag to the A side. Specifically

[0117] The returned content is:

[0118] The identity information of the B side. There can be many optional solutions. For example, the AppKey mentioned before is one, or it can be other original agreements, such as device unique identifier, service unique identifier, digital certificate, etc., as long as it is a unique identity information agreed in advance. The embodiments of the present invention do not need to limit this

[0119] A flag (encrypted by an encryption algorithm). For the convenience of reference, it is called flag 2. The encryption algorithm can use encryption algorithm 1 or encryption algorithm 2 of the A side, as long as the A side can successfully decrypt the flag

[0120] (1 - 3) The A side receives data and sends data to the B side

[0121] The A side checks the data sent by the B side. If the authentication is successful, it stores the data sent by the B side and returns a flag to the B side: A flag (encrypted by an encryption algorithm), which is called flag 3 for the convenience of reference

[0122] (1 - 4) Obtain variable 5

[0123] After the above three steps, the A side and the B side have mutually confirmed the validity of each other's identities and obtained three flags. These three flags can directly generate variable 5 according to a certain algorithm agreed in advance. Among them, there are many algorithms agreed in advance. Therefore, it can also be used as a variable, called variable 8, and the algorithm agreed in advance can be formulated according to business requirements

[0124] For the convenience of understanding by those skilled in the art, the embodiments of the present invention list the following 3 examples: For example: flag 1, flag 2, and flag 3 are respectively: 123, 456, 789. Select one or some of them, such as 123, and use all of them and simple permutation and combination methods. There are 6 kinds, such as: 123456789, 123789456, 789123456... Follow the custom algorithm (x algorithm) mentioned before, and refer to variables 1 - 4 mentioned before. The steps of generating variables can be used in the generation of selected digits. Specifically: regard flag 1, flag 2, and flag 3 as basic elements, combine the basic elements by permutation and combination methods, select a representation method, replace some bits, select some bits, and finally process them to obtain variable 5

[0125] For example: flag string 123456789 (permutation and combination method) -> target flag string 111010110111100110100010101 (select binary representation method) -> replace flag string 111011111000100111101110101 (replace certain bits with replacement algorithm) -> 11101111100010011110111010 (select bit algorithm to take the first x bits), and variable 5 is

[0126] 11101111100010011110111010. Converted to decimal, the selected bit number is 62793658.

[0127] Optionally, if there are duplicate selected bit numbers in variable 5, de-duplication or bit-weighting when encountering duplicates can be performed. Among them, if the selected bit number is 62793658, de-duplication results in 6279358, and bit-weighting when encountering duplicates is 6, 2, 7, 9, 3, 65, 8. Therefore, for the replacement string, de-duplication can take its 6, 2, 7, 9, 3, 5, 8 bits as the input source for generating the signature string, and bit-weighting when encountering duplicates takes its 6, 2, 7, 9, 3, 65, 8 bits as the input source for generating the signature string.

[0128] In a specific example of the present invention, A side and B side can represent the client side and the server side. The specific steps of the second generation method of variable 5 are as follows:

[0129] According to the previous (1), the encryption algorithm is provided by one end, which is not secure enough. If both ends (A side and B side) use their own encryption algorithms, or interact and use each other's encryption algorithms to transmit data, it will be more secure. Based on this, the improvement is as follows:

[0130] (1-1) The A side sends a request to the B side. The attached information is:

[0131] A flag 1 (encrypted by algorithm 1.A);

[0132] The encryption algorithm 1.A of the A side;

[0133] The encryption algorithm 2.A of the A side;

[0134] The identity information of the A side.

[0135] (1-2) The B side receives the data and sends data to the A side.

[0136] The B side checks the data sent by the A side. If the identity authentication is successful, it stores the data sent by the A side and returns its own identity information and a flag to the A side. The specific return content is:

[0137] The identity information of the B side;

[0138] Encryption algorithm 1.B at the B side;

[0139] Encryption algorithm 2.B at the B side;

[0140] A flag 2 (encrypted by algorithm 1.B).

[0141] (1 - 3) The A side receives data and sends data to the B side.

[0142] The A side checks the data sent by the B side. If the identity authentication is successful, it stores the data sent by the B side and returns a flag to the B side:

[0143] A flag 3 (encrypted by encryption algorithm 1.A or encryption algorithm 1.B. When using encryption algorithm 1.A, it is interactive encryption, and when using encryption algorithm 1.B, each uses its own encryption).

[0144] (1 - 4) Obtain variable 5

[0145] After the above three steps, the A side and the B side mutually confirm the validity of each other's identities and obtain three flags. These three flags can directly generate variable 5 according to a certain pre - agreed algorithm. Here, the pre - agreed algorithm will not be elaborated further.

[0146] From then on, the A side and the B side can each use their own encryption algorithms, or interactively use each other's encryption algorithms to transmit data.

[0147] In a specific example of the present invention, the A side and the B side can represent the client side and the server side. The specific steps of the third generation method of variable 5 are as follows:

[0148] In an embodiment of the present invention, before obtaining several flags generated after the client side and the server side mutually authenticate their identities based on the agreed - upon identity identifiers, the method further includes:

[0149] Determine the current network environment;

[0150] According to the current network environment, determine the number of flags generated after the client side and the server side mutually authenticate their identities based on the agreed - upon identity identifiers.

[0151] According to the previous (1) and (2), there are three interactions between two ends (the A side and the B side). The purpose of doing this is to prevent both sides from having forged identities, so they need to mutually authenticate their identities. While obtaining variable 5, it can also prevent man - in - the - middle attacks and additionally ensure some security measures. However, if the network environment is relatively secure, such as an intranet, or when the project is initially launched, in order to simplify the steps, the three - time interaction can be changed to one - time: The A side signs the mark and then sends the mark + signature to the B side. The B side obtains the mark through regular signature verification.

[0152] In an embodiment of the present invention, step 105, selecting some characters from the replacement string as the input source by using the position selection algorithm, includes:

[0153] Obtaining the random number used during the one-way / two-way authentication phase between the client and the server;

[0154] Using the random number as the position selection number, and selecting some characters from the replacement string as the input source according to the position selection number.

[0155] In a specific implementation, at the transport layer, during the one-way / two-way authentication phase between the client and the server, for example, in the one-way / two-way authentication phase of HTTPS, there is a random number R in this phase, and the random number R is synchronized to the two ends of the client and the server in a secure manner.

[0156] If at the application layer, directly obtaining this random number R, and then with or without the aforementioned processing, the position selection number generated based on the random number R, that is, variable 5, can be obtained. The method based on the random number is the fourth generation method of variable 5.

[0157] In an embodiment of the present invention, before step 101, when the client transmits data to the server and obtains several basic elements of the client, the method further includes:

[0158] Writing the identity information identifier of the client into a specified file in the installation package of the client; wherein, the suffix name of the specified file is modified;

[0159] When installing the client based on the installation package, reading the identity information identifier from the specified file and storing the identity information identifier in the memory;

[0160] Invoking a preset encryption algorithm to encrypt the identity identification information, and storing the encrypted identity identification information in the sandbox.

[0161] In an embodiment of the present invention, information such as identity identification information like AppKey is very important data. As a client, AppKey can only be pre-installed in the installation package, but AppKey cannot be in plain text, otherwise it is easily attacked by decompilation.

[0162] In view of the above problems, an embodiment of the present invention provides a strategy to prevent the leakage of identity identification information caused by decompiling the installation package of the client, thereby leading to the leakage of signature strings. Of course, it is also feasible to apply the idea of the strategy provided by the embodiment of the present invention to the server, because the server should also not store identity identification information and other information in plain text in the code.

[0163] Specifically, taking the client as an example, the identity identification information can be processed in the following manner:

[0164] 1. Write the identity identification information AppKey into a specified file;

[0165] The specific format of the specified file includes but is not limited to formats such as plist (Property List), xml (eXtensible Markup Language), etc. Taking the plist file as an example, for different server sides, different AppKey key-value pairs can be set. Refer to Figure 2 which is a schematic diagram of a feasible storage format of the identity identification information provided in the embodiment of the present invention. Specifically,

[0166] The first-level key-value pairs: prod, uat, test, dev are server environments determined by business requirements: prod is the production environment, uat is the pre-production environment, test is the test environment, and dev is the development environment; the next-level key-value pairs: OP, TSP, OTA, BigData are different server sides, and some have been mentioned before. Each server side has set different appKyes; the next-level key-value pairs: secretKey, accessKey: are the detailed implementations of the AppKey.

[0167] 2. Create a corresponding program model (data model)

[0168] Classes or structures corresponding to the data in the plist are also established in the program.

[0169]

[0170] If a new environment is added to the business requirements in the future, since the key-value pairs have been allocated, it is very convenient to add and delete, and only 2 corresponding places (i.e., the file place and the model place) need to be modified.

[0171] 3. Encrypt the plist file

[0172] Writing the identity identification information into the plist file only solves the problem of obtaining the plaintext AppKey by decompiling the code, but the content in the plist file is still equivalent to plain text. Therefore,

[0173] Encrypt the plist file in one step to ensure that even if decompiled (which allows viewing the source code) or the device is rooted (which allows viewing the contents in the sandbox), the corresponding information cannot be obtained, providing very high security.

[0174] (1) Change the suffix name of the plist file in the pre-installed package to other misleading names, such as "aaaa", "tmp1924483823", etc. That is, suffixes such as plist, xml, and txt must be removed.

[0175] (2) When the client is first installed, read the contents of the plist file, which is the source file, and store the identity information as a string in memory.

[0176] (3) Call common encryption algorithms on the market, such as symmetric encryption, AES / DES, etc., and pass the string as an input parameter to obtain the encrypted output parameter.

[0177] (4) Re-store the encrypted output parameter in the sandbox, naming the file with a misleading name, such as "aaaa", "tmp1924483823", etc. In short, suffixes like plist, xml, and txt must be removed.

[0178] 4. Read from plist into the model (data model)

[0179] Then, at an appropriate time, such as when the client starts, call the system API (Application Programming Interface) to read the identity information of the encrypted plist file into memory and decrypt it.

[0180] Convert the decrypted string into the model through the API provided by the system or the API of a third-party tool library, and use the identity information such as AppKey stored in these models in the aforementioned security signature step.

[0181] In an embodiment of the present invention, when applied to the encryptor, the client and the server include an authentication certificate assigned by the encryptor to the client, and the authentication certificate is obtained by the client requesting from the encryptor, or the client requests from the encryptor through the server.

[0182] Signing and encrypting the transmission data according to the signature string to obtain encrypted transmission data, and putting the encrypted transmission data into a network request to send the encrypted transmission data to the server through the network request, includes:

[0183] Receive the transmission data sent by the client and the authentication certificate of the client;

[0184] According to the signature string and the authentication certificate, sign and encrypt the transmission data to obtain encrypted transmission data, and send the encrypted transmission data to the client, so that the client sends the encrypted transmission data to the server.

[0185] The client sends the encrypted transmission data to the server.

[0186] In the embodiments of the present invention, in addition to data storage such as identity identification information, data transfer (data transmission) is also a key concern of the security policy in the embodiments of the present invention. To address the above problems, the embodiments of the present invention design an encryptor, which has much higher security than the traditional simple symmetric encryption and signature verification of data between Party A and Party B. Specifically, the core idea of the encryptor is as follows:

[0187] The encryptor, as a manager, is responsible for all encryption, decryption, and signature work. The encryptor is in a black box mode, and the outside world does not know the algorithms it selects (such as which x algorithms are selected) and cannot guess. Party A and Party B interact with each other without directly encrypting, decrypting, or synchronizing keys, and only responsible for transmitting data. The encryptor encrypts and signs the data at one end (such as Party A) and decrypts and authenticates the data at the other end (such as Party B).

[0188] Exemplarily, referring to Figure 3 , is an interaction schematic diagram between a client and a server based on an encryptor provided in the embodiments of the present invention. The specific implementation steps are as follows:

[0189] 1. Party A and Party B request the certificate of the encryptor

[0190] For the convenience of those skilled in the art to understand, Party A can be regarded as the client and Party B can be regarded as the server. However, it should be noted that Party A can also be used as the server and Party B can also be used as the client; because the positions and advantages of Party A and Party B are fair and equal in the embodiments of the present invention, Party A can request data from Party B, and Party B can also send data to Party A. It should be noted that the encryptor can of course be developed independently, so the algorithms in the encryptor are transparent.

[0191] Premise: The encryptor has pre-assigned unique identity information identifiers (identity information) to Party A and Party B, and the identity information identifier is used by the encryptor to identify the identity of Party A. Among them, the secure storage of the identity information identifier can refer to the storage method of the AppKey described above and will not be elaborated here.

[0192] At the appropriate time, end A and end B request a certificate (authentication certificate) from the encryptor. This appropriate time may be when all mapping relationships are prepared for the first time. For example, if the mapping relationship is: identity information identifier, the first time to prepare this identity information is when the client is started, the identity information is stored, and the identity information is read; if the mapping relationship is: identity information identifier + user id, the first time to prepare these two pieces of information may be after the user logs in.

[0193] (1) When appropriate, end A requests a certificate from the encryptor.

[0194] End A uses the identity information to generate a p10 certificate request and requests an authentication certificate from the encryptor.

[0195] Of course, the identity information may not be the only mapping relationship generated by the certificate. The A end (understood as the client) can pass in multiple mapping relationships and request multiple certificates according to different dimensions.

[0196] For example:

[0197] (1.1) Only the identity information is transmitted to obtain the certificate. The certificate and identity information, or the client, are in a one-to-one correspondence, and the certificates of all devices and all users are the same.

[0198] (1.2) Pass in the identity information + the user ID obtained after the user logs in on the client to obtain the certificate. The certificate and the user are in a one-to-one correspondence. User A and user B have two different certificates.

[0199] (1.3) Pass in the identity information + device ID to get the certificate. The certificate and the device are in a one-to-one correspondence. iphoneA and iphoneB are two different certificates.

[0200] (1.4) Input the identity information + device ID + user ID to get the certificate. The certificate and device + user are in a one-to-one correspondence.

[0201] Of course, in actual applications, there may be other identifiers that can be formulated according to business needs. For example, each business module may be assigned an ID so that the certificates of different business modules are also different.

[0202] In addition, since the certificate is a third-party certificate, it can also be used as a two-way authentication certificate for HTTPS.

[0203] In a specific implementation, the encryptor may generate a certificate according to a commonly used certificate generation method. Figure 4, which is a schematic diagram of generating a certificate based on an encryptor provided in an embodiment of the present invention. The encryptor signs the mapping relationship (mapping information) passed in by Party A with its own private key, and then combines it with the mapping relationship to form a certificate.

[0204] (2) At an appropriate time, Party B requests a certificate from the encryptor.

[0205] Similarly, according to the regulations of business requirements, Party B passes in the mapping information described above and also obtains the certificate assigned by the encryptor.

[0206] (3) Party A can entrust Party B to

[0207] Party A can directly send a request to Party B, passing in the corresponding mapping information. Then Party B calls the encryptor (equivalent to Party B applying for a certificate on behalf of Party A), obtains Party A's certificate, and then Party B passes Party A's certificate to Party A.

[0208] Whether Party B needs to apply for a certificate from the encryptor is determined by business requirements. If there is no such business requirement (for example, Party B takes the initiative to contact Party A), there is no need to apply for Party A's certificate through Party B.

[0209] In this way, Party A will not have contact with the encryptor. The advantage of doing this is that Party A is unaware of the existence of the encryptor, reducing the risk of a middleman attacking the encryptor (the middleman is also unaware of the existence of the encryptor). Since the encryptor is ultimately responsible for the encryption operation, a middleman attack on Party B will not affect this part of the business. And Party B also knows Party A's certificate and related mapping information, so it can perform some other tasks besides the encryptor, such as the interaction and two-way authentication between Party A and Party B. Exemplarily, referring to Figure 5 , which is another schematic diagram of the interaction between a client and a server based on an encryptor provided in an embodiment of the present invention.

[0210] 2. The encryptor encrypts and signs the data

[0211] When Party A and Party B communicate, the initiating party (such as Party A) calls the encryptor, passes in the data to be transmitted (transmission data), and asks the encryptor to encrypt and sign the transmission data to obtain the encrypted encrypted transmission data, which is then sent to Party B.

[0212] The specific steps of the encryptor are as follows:

[0213] (1) Accept the input parameters

[0214] The input parameters include:

[0215] Certificate of End A: The certificate contains the unique identity information of End A and the mapping information of business requirements (such as user ID, device ID, module ID, etc.). The encryptor can extract them one by one to know the certificate of the client or the server.

[0216] Data to be transmitted by End A

[0217] (2) Signature

[0218] The encryptor uses the aforementioned method to generate a signature string to sign the transmitted data.

[0219] (3) Encryption

[0220] The signature string obtained in the first step can be used as the encryption key to encrypt the transmitted data.

[0221] This is just the simplest processing method. For the generation of the key, any rules can be customized, and the embodiments of the present invention do not need to limit this. For example, the key generation can also be in the following ways:

[0222] (3.1) Signature string + timestamp + special predefined character

[0223] (3.2) Signature string + certificate string

[0224] (3.3) Certain parts extracted from the certificate string + timestamp

[0225] (3.4) Timestamp + signature string +...

[0226] ...

[0227] It can be seen that the examples of the present invention can permute and combine the signature string, timestamp, special predefined character, certain parts extracted from the certificate string, etc., replace certain bits, and finally confirm the algorithm to obtain a key.

[0228] Therefore, in summary, an algorithm (function or module) can be refined from the process of generating the signature string. This algorithm can accept variables 1, 2, 3, 4, 5, 8 as input parameters. In different business requirements and business situations, the values of these input parameters are different. For example, when generating the signature string for the transmitted data as mentioned above, the values of these input parameters are xxx; when obtaining variable 5, these input parameters are ddd; when generating the key here, the values of these input parameters are yyy.

[0229] (4) Configurable items

[0230] (2) and (3) steps can be exchanged, and this order is not restricted and can also be repeated.

[0231] For example: the transmitted data can be encrypted twice first and then the signature can be verified; or, the string after being signed twice can be used as the key and then encryption can be performed. The order and number of times of signing and encryption are configurable. For example:

[0232] (4.1) The string after being signed n times is used as the key, and then the transmitted data is encrypted m times. Between signing and encryption, there can also be other steps, such as replacement, taking partial bits and other steps.

[0233] (4.2) Encrypt m times and then sign n times. Similarly, between encryption and signing, there can also be other steps. The configuration of these steps and order is called variable 9.

[0234] 3. The A-side sends the encrypted + signed data to the B-side

[0235] Now, regardless of the length of the transmitted data to be transmitted and the format of the transmitted data, it is already encrypted data. The format of the data can be binary. The binary data is directly placed in the body (request body) of the HTTP request, or the transmitted data is sent to the B-side through a socket (a communication mechanism).

[0236] 4. The receiving end decrypts and verifies the signature of the data

[0237] After the receiving end (such as the B-side) receives the data, the receiving end can not perform decryption, but call the external API (Application Programming Interface) of the encryptor to perform

[0238] decryption, that is, decrypt through the encryptor. The encryptor decrypts the transmitted data in reverse order according to the order and method when it encrypts and verifies the signature (by relying on reading the value of the variable, it knows all the order and steps).

[0239] In summary, the variables involved in the embodiments of the present invention are:

[0240] Variable 1: How many basic elements of the signature are there and what each is;

[0241] Variable 2: The way of permutation and combination of the basic elements of the signature;

[0242] Variable 3: Select one representation method after the signature combination;

[0243] Variable 4: The transposition after the signature combination: specifically which bits, what to replace with, and what the replacement algorithm is;

[0244] Variable 5: The input parameter (input source) for obtaining the final signature;

[0245] Variable 6: The mapping relationship between the server and the x algorithm;

[0246] Variable 7: Update frequency of the x algorithm;

[0247] Variable 8: The algorithm for finally obtaining Variable 5 in the x algorithm;

[0248] Variable 9: Steps and order for the encryptor to perform encryption + signature;

[0249] In an embodiment of the present invention, a configuration file can be established to configure the values of variables in different situations. And, for the feedback situation, these variables are modified in real time and synchronized across multiple terminals.

[0250] For example:

[0251] When the client detects that the network is relatively slow, the encryption algorithm should be simplified, so the complexity of the variable values is reduced and synchronized to multiple terminals. The degree of reduction can be determined by various algorithms, such as decreasing, increasing (decreasing or increasing a small fixed value each time), sharply decreasing, sharply increasing (increasing or decreasing by 1 / 3 or 1 / 2 each time), etc.

[0252] When the client detects that the network is in a good condition, these variable values are restored to the average level. Among them, the average level is the value obtained through daily repeated operation and maintenance, feedback, and statistics.

[0253] In some extreme situations, the client needs to increase the variable values to a safe level, that is, more complex calculations.

[0254] The embodiment of the present invention is customized according to the security requirements of the vehicle control client. While making it very difficult for a third-party attack, it does not consume too much computing resources. The embodiment of the present invention can flexibly adjust the security level through the configuration of variables, and appropriately increase or decrease

[0255] the computational complexity according to requirements and temporary situations, achieving the purpose of customization while ensuring data security.

[0256] Refer to Figure 6 , which is the step flowchart of another data transmission method provided in the embodiment of the present invention. As Figure 6 shown, when synchronizing data transmission between the client and the server, the secure identity authentication information is used. The secure identity authentication information at least includes basic elements, permutation and combination methods, representation methods, replacement algorithms, and selection algorithms. The method can specifically include the following steps:

[0257] Step 601, when receiving the network request sent by the client, extract the encrypted transmission data from the network request;

[0258] Step 602, obtain several basic elements of the client;

[0259] Step 603: Combine the basic elements in the above permutation and combination manner to obtain composite basic elements, and combine the composite basic elements with the basic elements and / or the composite basic elements to obtain a character string;

[0260] Step 604: Represent the character string in the above representation manner to obtain a target character string;

[0261] Step 605: Replace some characters of the target character string using the above replacement algorithm to obtain a replacement character string;

[0262] Step 606: Select some characters from the replacement character string as an input source using the above position selection algorithm, and generate a signature character string based on the input source;

[0263] Step 607: Decrypt and authenticate the encrypted transmission data according to the signature character string to obtain transmission data.

[0264] In an embodiment of the present invention, when applied to the encryptor, the client and the server include an authentication certificate assigned by the encryptor to the client; Step 607: Decrypt and authenticate the encrypted transmission data according to the signature character string to obtain transmission data, including:

[0265] Receive the encrypted transmission data sent by the server;

[0266] Decrypt and authenticate the encrypted transmission data according to the signature character string and the authentication certificate to obtain transmission data, and send the transmission data to the server.

[0267] Embodiments of the present invention can be applied to a server or an encryptor. When applied to a server, the client and the server directly communicate with each other; when applied to an encryptor, the client and the server communicate through the encryptor. For example, if applied to a server, after receiving the encrypted transmission data sent by the client, the server can, according to the authentication certificate of the client saved locally, and based

[0268] After generating a signature string from the basic elements on the client side, the encrypted transmission data can be decrypted and authenticated based on the signature string and the authentication certificate to obtain the transmission data. If it is applied to an encryptor, after the server receives the encrypted transmission data sent by the client and sends the encrypted transmission data to the encryptor, the encryptor can, according to the authentication certificate of the client saved locally and after generating a signature string based on the basic elements of the client, decrypt and authenticate the encrypted transmission data according to the signature string and the authentication certificate to obtain the transmission data. Finally, the encryptor sends the transmission data to the server. When the client communicates with the server, it is necessary to sign the communication data (transmission data) transmitted each time to achieve secure identity authentication and ensure the security of the transmission data.

[0269] Among them, since the decryption method of the transmission data received by the server or the encryptor is the reverse process of the embodiment of signing and decrypting the foregoing transmission data, it will not be elaborated here.

[0270] It should be noted that for the method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the embodiments of the present invention are not limited by the described action sequences, because according to the embodiments of the present invention, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily essential to the embodiments of the present invention.

[0271] Referring to Figure 7 , which is a structural block diagram of a data transmission device provided in an embodiment of the present invention. As Figure 7 shown, when synchronously transmitting data between the client and the server, the secure identity authentication information used, and the secure identity authentication information at least includes basic elements, permutation and combination methods, representation methods, replacement algorithms, and selection algorithms. The device may specifically include the following modules:

[0272] The first acquisition module 701 is used to acquire a plurality of basic elements of the client when the client transmits data to the server;

[0273] The first combination module 702 is used to combine the basic elements by using the permutation and combination method to obtain a composite basic element, and combine the composite basic element with the basic element and / or the composite basic element to obtain a string;

[0274] The first representation module 703 is used to represent the string by using the representation method to obtain a target string;

[0275] The first replacement module 704 is used to replace part of the target string by using the replacement algorithm

[0276] The character obtains a replacement string;

[0277] A first selection position module 705, configured to select some characters from the replacement string as an input source by using the selection position algorithm, and generate a signature string according to the input source;

[0278] A signature encryption module 706, configured to sign and encrypt the transmission data according to the signature string to obtain encrypted transmission data, and put the encrypted transmission data into a network request, so as to send the encrypted transmission data to the service through the network request; wherein, the execution order and number of times of the signature and the encryption are configurable.

[0279] In an embodiment of the present invention, the device further includes: a synchronization module, configured to:

[0280] When the client is started, synchronize the security authentication information used for data transmission between the client and the server;

[0281] After the client is started, obtain a mapping relationship, and update the security authentication information used for data transmission between the client and the server according to the mapping relationship; wherein, the mapping relationship is a mapping relationship between the server and the permutation and combination mode, the representation mode, the replacement algorithm, and the selection position algorithm;

[0282] After the client is started, obtain an update frequency, and update the security authentication information used for data transmission between the client and the server according to the update frequency; wherein, the update frequency is predetermined or temporarily determined according to service requirements.

[0283] In an embodiment of the present invention, the first selection position module 705 is configured to:

[0284] Obtain a plurality of flags generated after the client and the server authenticate each other based on a pre-agreed identity identifier; wherein, the flags are generated by the client or the server, and when the client and the server transmit the flags, preset encryption and decryption algorithms are used for encryption and decryption, and the encryption and decryption algorithms are provided by the client, or provided by the server, or the client and the server each use their own provided encryption and decryption algorithms, or the client and the server interact with each other and use the encryption and decryption algorithms provided by the other party;

[0285] Generate a selection position number according to the flags, and select some characters from the replacement string as an input source according to the selection position number;

[0286] Wherein, the first selection position module 705 is configured to:

[0287] Combine the marks using the above permutation and combination method to obtain a composite mark, and use the above

[0288] Combine the composite mark with the above mark and / or the composite mark to obtain a mark string;

[0289] Represent the mark string using the above representation method to obtain a target mark string;

[0290] Replace some characters of the target mark string using the above replacement algorithm to obtain a replacement mark string;

[0291] Generate a digit selection number according to the replacement mark string; wherein, if there are duplicate numbers in the digit selection number, de-duplicate the digit selection number or add weight to the digits when encountering them;

[0292] Alternatively, the above digit selection algorithm selects some characters from the replacement string as the input source, including:

[0293] Obtain the random number used in the stage of one-way / two-way authentication between the client and the server;

[0294] Use the random number as the digit selection number, and select some characters from the replacement string as the input source according to the digit selection number.

[0295] In an embodiment of the present invention, the device further includes: a configuration module, configured to:

[0296] Determine the current network environment;

[0297] Determine the number of marks generated after the mutual identity authentication between the client and the server based on the agreed identity identifier according to the current network environment.

[0298] In an embodiment of the present invention, the device further includes: a storage module, configured to:

[0299] Write the identity information identifier of the client into a specified file in the installation package of the client; wherein, the suffix name of the specified file is modified;

[0300] When installing the client based on the installation package, read the identity information identifier from the specified file and store the identity information identifier in the memory;

[0301] Call a preset encryption algorithm to encrypt the identity identifier information, and save the encrypted identity identifier information in the sandbox;

[0302] Among them, the method is applied to a client or an encryptor; when applied to the client, the client and the server communicate directly with each other; when applied to the encryptor, the client and the server communicate through the encryptor.

[0303] In an embodiment of the present invention, when applied to the encryptor, the client and the server include an authentication certificate assigned by the encryptor to the client, and the authentication certificate is

[0304] obtained by the client requesting from the encryptor, or the client requests it from the encryptor through the server; the signature encryption module 706 is used for:

[0305] Receiving the transmission data sent by the client and the authentication certificate of the client;

[0306] According to the signature string and the authentication certificate, signing and encrypting the transmission data to obtain encrypted transmission data, and sending the encrypted transmission data to the client, so that the client sends the encrypted transmission data to the server.

[0307] Refer to Figure 8 , which is a structural block diagram of a data transmission device provided in an embodiment of the present invention. As Figure 8 shown, the security identity authentication information used when synchronizing data transmission between the client and the server, the security identity authentication information includes at least basic elements, permutation and combination methods, representation methods, replacement algorithms, and selection algorithms. The device may specifically include the following modules:

[0308] The extraction module 801 is used to extract encrypted transmission data from the network request when receiving the network request sent by the client.

[0309] The second acquisition module 802 is used to acquire several basic elements of the client;

[0310] The second combination module 803 is used to combine the basic elements by using the permutation and combination method to obtain composite basic elements, and combine the composite basic elements with the basic elements and / or the composite basic elements to obtain a string;

[0311] The second representation module 804 is used to represent the string by using the representation method to obtain a target string;

[0312] The second replacement module 805 is used to replace some characters of the target string by using the replacement algorithm to obtain a replacement string;

[0313] The second selection module 806 is configured to select some characters from the replacement string as an input source by using the selection algorithm, and generate a signature string according to the input source;

[0314] The decryption module 807 is configured to decrypt and authenticate the encrypted transmission data according to the signature string to obtain the transmission data.

[0315] In an embodiment of the present invention, the method is applied to a server or an encryptor; when applied to the server, the client and the server directly communicate with each other; when applied to the encryptor, the client and the server communicate through the encryptor;

[0316] When applied to the encryptor, the client and the server include the authentication certificate assigned by the encryptor for the

[0317] client; the decryption module 807 is configured to:

[0318] Receive the encrypted transmission data sent by the server;

[0319] Decrypt and authenticate the encrypted transmission data according to the signature string and the authentication certificate to obtain the transmission data, and send the transmission data to the server.

[0320] For the above device embodiment, since it is basically similar to the method embodiment, the description is relatively simple. For related parts, refer to the partial description of the method embodiment.

[0321] An embodiment of the present invention further provides an electronic device, as Figure 9 shown, including a processor 901, a communication interface 902, a memory 903, and a communication bus 904. Among them, the processor 901, the communication interface 902, and the memory 903 complete mutual communication through the communication bus 904,

[0322] The memory 903 is used to store a computer program;

[0323] The processor 901 is configured to implement the data transmission method described in any one of the above embodiments when executing the program stored in the memory 903:

[0324] The communication bus mentioned in the above terminal may be a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, or the like. The communication bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, only a thick line is used in the figure, but it does not mean that there is only one bus or one type of bus.

[0325] The communication interface is used for communication between the above terminal and other devices.

[0326] The memory may include a Random Access Memory (RAM), or may also include a non-volatile memory, such as at least one disk memory. Optionally, the memory may also be at least one storage device located far from the aforementioned processor.

[0327] The above-mentioned processor may be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; it may also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.

[0328] In another embodiment provided by the present invention, there is also provided a computer-readable storage medium, in which instructions are stored. When it runs on a computer, it causes the computer to execute the data transmission method described in any one of the above embodiments.

[0329] In another embodiment provided by the present invention, there is also provided a computer program product containing instructions. When it runs on a computer, it causes the computer to execute the data transmission method described in any one of the above embodiments.

[0330] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present invention are generated in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.). The computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more integrated available media. The available medium may be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid state disk (SSD)).

[0331] It should be noted that, in this document, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the element.

[0332] Each embodiment in this specification is described in a related manner. The same or similar parts between the embodiments can be referred to each other, and the differences between each embodiment and other embodiments are emphasized. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the description of the method embodiment.

[0333] The above are only the preferred embodiments of the present invention and are not intended to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention are all included in the protection scope of the present invention.

Claims

1. A data transmission method, characterized in that, The security authentication information used for synchronizing data transmission between the client and the server, where the security authentication information at least includes basic elements, permutation and combination methods, representation methods, replacement algorithms, and selection algorithms. The method includes: When the client transmits data to the server, obtaining a number of basic elements of the client; Combining the basic elements using the permutation and combination method to obtain composite basic elements, and combining the composite basic elements with the basic elements or the composite basic elements to obtain a string; Representing the string using the representation method to obtain a target string; Replacing some characters of the target string using the replacement algorithm, where the replacement algorithm is variable and is used to replace the position and content of the target string; Selecting some characters from the replacement string as an input source using the selection algorithm, and generating a signature string based on the input source; Signing and encrypting the transmitted data based on the signature string to obtain encrypted transmitted data, and putting the encrypted transmitted data into a network request to send the encrypted transmitted data to the server through the network request; where the execution order and number of times of the signature and the encryption are configurable.

2. The method according to claim 1, wherein Before obtaining a number of basic elements of the client when the client transmits data to the server, the method further includes: When the client starts, synchronizing the security authentication information used for data transmission between the client and the server; After the client starts, obtaining a mapping relationship, and updating the security authentication information used for data transmission between the client and the server according to the mapping relationship; where the mapping relationship is the mapping relationship between the server and the permutation and combination method, the representation method, the replacement algorithm, and the selection algorithm; After the client starts, obtaining an update frequency, and updating the security authentication information used for data transmission between the client and the server according to the update frequency; where the update frequency is predetermined or determined temporarily according to service requirements.

3. The method according to claim 1 or 2, characterized in that, The step of selecting some characters from the replacement string as an input source using the selection algorithm includes: Obtaining a number of flags generated after the client and the server authenticate each other based on a pre-agreed identity identifier; where the flags are generated by the client or the server, and when the client and the server transmit the flags, they are encrypted and decrypted using a preset encryption and decryption algorithm, and the encryption and decryption algorithm is provided by the client, or the server, or the client and the server each use their own provided encryption and decryption algorithms, or the client and the server interact with each other using the encryption and decryption algorithms provided by the other party; Generating a selection number based on the flags, and selecting some characters from the replacement string as an input source according to the selection number.

4. The method according to claim 3, characterized in that, The step of generating a selection number based on the flags includes: Combine the signs in the above permutation and combination method to obtain a composite sign, and combine the composite sign with the sign or the composite sign to obtain a sign string; Represent the sign string in the above representation method to obtain a target sign string; Use the above replacement algorithm to replace some characters of the target sign string to obtain a replacement sign string; Generate a selection digit according to the replacement sign string; wherein, if there are duplicate digits in the selection digit, remove the duplicates or add weights to the digits when encountering them.

5. The method according to claim 1 or 2, characterized in that, The above method of selecting some characters from the replacement string as the input source by using the selection algorithm includes: Obtain the random number used in the one-way / two-way authentication phase between the client and the server; Use the random number as the selection digit, and select some characters from the replacement string as the input source according to the selection digit.

6. The method according to claim 3, characterized in that, Before the above method of generating several signs after the client and the server authenticate each other based on the agreed identity identifier, the method further includes: Determine the current network environment; Determine the number of signs generated after the client and the server authenticate each other based on the agreed identity identifier according to the current network environment.

7. The method according to claim 1, characterized in that Before the above method of obtaining several basic elements of the client when the client transmits data to the server, the method further includes: Write the identity information of the client into a specified file in the installation package of the client; wherein, the suffix name of the specified file is modified; When installing the client based on the installation package, read the identity information from the specified file and store the identity information in the memory; Call a preset encryption algorithm to encrypt the identity information, and save the encrypted identity information in the sandbox.

8. The method according to claim 1, characterized in that The above method is applied to the client or the encryptor; when applied to the client, the client and the server communicate directly with each other; when applied to the encryptor, the client and the server communicate through the encryptor.

9. The method according to claim 8, wherein When applied to the encryptor, the client and the server include the authentication certificate assigned by the encryptor to the client, and the authentication certificate is obtained by the client requesting from the encryptor, or the client requests from the encryptor through the server; The above method of signing and encrypting the transmission data according to the signature string to obtain encrypted transmission data, and putting the encrypted transmission data into a network request to send the encrypted transmission data to the server through the network request includes: Receive the transmission data and the authentication certificate of the client sent by the client; Sign and encrypt the transmission data according to the signature string and the authentication certificate to obtain encrypted transmission data, and send the encrypted transmission data to the client so that the client sends the encrypted transmission data to the server.

10. A data transmission method, characterized in that, Security authentication information used for synchronizing data transmission between the client and the server. The security authentication information includes at least basic elements, permutation and combination methods, representation methods, replacement algorithms, and selection algorithms. The method includes: When receiving a network request sent by the client, extract encrypted transmission data from the network request; Obtain several basic elements of the client; Use the permutation and combination method to combine the basic elements to obtain composite basic elements, and use the composite basic elements to combine with the basic elements or the composite basic elements to obtain a string; Use the representation method to represent the string to obtain a target string; Use the replacement algorithm to replace some characters of the target string to obtain a replacement string. The replacement algorithm is variable and is used to replace the position and content of the target string; Use the selection algorithm to select some characters from the replacement string as the input source and generate a signature string according to the input source; Decrypt and authenticate the encrypted transmission data according to the signature string to obtain the transmission data.

11. The method according to claim 10, characterized in that, The method is applied to the server or the encryptor; when applied to the server, the client and the server communicate directly with each other; when applied to the encryptor, the client and the server communicate through the encryptor; When applied to the encryptor, the client and the server include an authentication certificate assigned by the encryptor to the client; The decrypting and authenticating the encrypted transmission data according to the signature string to obtain the transmission data includes: Receive the encrypted transmission data sent by the server; Decrypt and authenticate the encrypted transmission data according to the signature string and the authentication certificate to obtain the transmission data, and send the transmission data to the server.

12. A data transmission device, characterized in that, Security authentication information used for synchronizing data transmission between the client and the server. The security authentication information includes at least basic elements, permutation and combination methods, representation methods, replacement algorithms, and selection algorithms. The device includes: A first acquisition module, configured to obtain several basic elements of the client when the client transmits data to the server; A first combination module, configured to use the permutation and combination method to combine the basic elements to obtain composite basic elements, and use the composite basic elements to combine with the basic elements or the composite basic elements to obtain a string; A first representation module, configured to use the representation method to represent the string to obtain a target string; A first replacement module, configured to use the replacement algorithm to replace some characters of the target string to obtain a replacement string. The replacement algorithm is variable and is used to replace the position and content of the target string; A first selection module, configured to use the selection algorithm to select some characters from the replacement string as the input source and generate a signature string according to the input source; A signature encryption module, which is used to sign and encrypt the transmission data according to the signature string to obtain encrypted transmission data, and put the encrypted transmission data into a network request to send the encrypted transmission data to the service through the network request; wherein, the execution order and number of times of the signature and the encryption are configurable.

13. A data transmission device, characterized in that, Security authentication information used during data transmission synchronization between a client and a server. The security authentication information at least includes basic elements, permutation and combination methods, representation methods, replacement algorithms, and selection algorithms. The device includes: An extraction module, which is used to extract encrypted transmission data from the network request when receiving the network request sent by the client. A second acquisition module, which is used to acquire a number of basic elements of the client. A second combination module, which is used to combine the basic elements by using the permutation and combination method to obtain composite basic elements, and combine the composite basic elements with the basic elements or the composite basic elements to obtain a string. A second representation module, which is used to represent the string by using the representation method to obtain a target string. A second replacement module, which is used to replace some characters of the target string by using the replacement algorithm. The replacement algorithm is variable and is used to replace the position and content of the target string. A second selection module, which is used to select some characters from the replacement string as an input source by using the selection algorithm, and generate a signature string according to the input source. A decryption module, which is used to decrypt and authenticate the encrypted transmission data according to the signature string to obtain transmission data.

14. An electronic device, characterized in that, It includes a processor, a communication interface, a memory, and a communication bus. Among them, the processor, the communication interface, and the memory complete communication with each other through the communication bus. The memory is used to store computer programs. The processor is used to implement the method steps described in any one of claims 1-11 when executing the programs stored on the memory.

15. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the method described in any one of claims 1-11.

Citation Information

Patent Citations

  • API request encryption method and device

    CN110611670A