Method, system, device and medium for improving data security in network transmission process
By using a public and private key generated by an asymmetric encryption algorithm for double encryption and decryption between the client and server, the problem of eavesdropping and tampering during data transmission is solved, and the security and integrity of data during transmission are achieved.
Patent Information
- Application Number
- CN202410798570.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-06-20
- Publication Date
- 2025-11-21
- Estimated Expiration
- 2044-06-20
AI Technical Summary
In existing technologies, data is at risk of being eavesdropped on and tampered with during network transmission, especially in B/S architecture application systems. HTTPS technology cannot completely prevent data from being intercepted and tampered with by tools such as Burp Suite.
An asymmetric encryption algorithm is introduced between the client and the server to generate unique public and private keys, which are then bound to the user's token. Data is transmitted with double encryption using a symmetric encryption algorithm and public key encryption. The server uses the private key for double decryption to ensure data security.
It effectively prevents data from being eavesdropped on and tampered with during transmission, ensures the integrity of the data received by the server, increases the difficulty of data tampering, and prevents tools such as Burp Suite from obtaining customers' personal data.
Smart Images

Figure CN118827157B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data transmission technology, and in particular to methods, systems, devices, and media for improving data security during network transmission. Background Technology
[0002] In the telecommunications industry, customer relationship management (CRM) and customer value management (CVP) systems store large amounts of customers' personal data, such as phone numbers and ages, requiring special attention to data security. Typical application systems ensure personal data security through both data storage and data network transmission. For data transmission, HTTPS technology is generally used to ensure the security of the network channel.
[0003] HTTPS technology involves the client and server negotiating the encryption algorithm to be used during data transmission before data transmission begins. However, in reality, data in B / S (Browser / Server) architecture applications can still be intercepted before transmission. Common tools like Burp Suite can intercept HTTPS requests sent by web applications to servers, identify request addresses, request parameters, and then use parameter keys to guess the database table structure and parameter values to obtain the customer's personal data. This poses a risk of personal data being eavesdropped on and tampered with. Summary of the Invention
[0004] This invention provides methods, systems, devices, and media for improving data security during network transmission, in order to solve the technical problems of insecure data transmission and the risk of personal data being eavesdropped on and tampered with in the prior art.
[0005] This invention provides a method for improving data security during network transmission, applied to a client. A user logs into an application system through the client; the server assigns a unique public key and a unique private key to the user who successfully logs in, and binds the public and private keys to the user's token. The method for improving data security during network transmission includes: receiving a public key sent by the server; encrypting business data using a symmetric encryption algorithm to obtain first encrypted data and an original key; encrypting the original key using the public key to obtain a first key; and sending the first encrypted data and the first key to the server via the network.
[0006] This invention provides a method for improving data security during network transmission, applied to the server side; a user logs into an application system through a client, and the server assigns a unique public key and a unique private key to the user who successfully logs into the application system, and binds the public key and private key to the user's token; the method for improving data security during network transmission includes: receiving first encrypted data and a first key sent by the client; decrypting the first key using the private key to obtain the original key; and decrypting the first encrypted data according to the original key to obtain business data.
[0007] According to the present invention, a method for improving data security during network transmission includes receiving first encrypted data and a first key sent by a client, and decrypting the first key using a private key to obtain an original key. The method includes: obtaining a user's token from the header of the first encrypted data; verifying the user's token to confirm the legitimacy of the request; when the verification passes, finding the bound private key using the user's token; and decrypting the first key using the private key to obtain the original key.
[0008] The method for improving data security during network transmission according to the present invention further includes: deleting the user's private key when the user logs out of the application system, the user login fails, the first encrypted data fails to decrypt, or the first key fails to decrypt; and generating a new public key and private key after the user successfully logs into the application system, and rebinding the public key and private key to the user.
[0009] According to the present invention, a method for improving data security during network transmission is provided, wherein both the public key and the private key are generated by the server program using an asymmetric encryption algorithm and bound to a token that uniquely identifies the user; wherein the public key is sent to the client program for storage, and the user's token and private key are stored by the server's application system background program.
[0010] This invention also provides a system for improving data security during network transmission, comprising a client and a server; a user logs into an application system through the client, and the server assigns a unique public key and a unique private key to the user who successfully logs into the application system, and binds the public key and private key to the user's token; the public key is stored by the client; the private key is stored by the server; the client is used to: encrypt business data using a symmetric encryption algorithm to obtain first encrypted data and an original key; encrypt the original key using the public key to obtain a first key; and send the first encrypted data and the first key to the server via the network; the server is used to: receive the first encrypted data and the first key sent by the client; decrypt the first key using the private key to obtain the original key; and decrypt the first encrypted data using the original key to obtain the business data.
[0011] According to the present invention, a system for improving data security during network transmission is provided. The client uses interceptor technology to encrypt business data and the original key; the server uses interceptor technology to decrypt the first encrypted data and the first key. The interceptor technology can ensure that the original business logic is not affected while the data is encrypted or decrypted without modifying the original data.
[0012] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the method for improving data security during network transmission as described above.
[0013] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the method for improving data security during network transmission as described above.
[0014] The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements the method for improving data security during network transmission as described above.
[0015] This invention provides a method, system, device, and medium for enhancing data security during network transmission. Users log into an application system via a client. The server assigns a unique public key and a unique private key to each successfully logged-in user and binds these keys to the user's token. The method for enhancing data security during network transmission applied to the client includes: receiving a public key sent by the server; encrypting business data using a symmetric encryption algorithm to obtain first encrypted data and an original key; encrypting the original key using the public key to obtain a first key; and sending the first encrypted data and the first key to the server via the network. Through these methods, this invention can effectively ensure that client data received by the server is not tampered with, guaranteeing the security of user data during network transmission. Attached Figure Description
[0016] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0017] Figure 1 This is one of the flowcharts illustrating the method for improving data security during network transmission provided in this embodiment of the invention.
[0018] Figure 2This is the second flowchart illustrating the method for improving data security during network transmission provided in this embodiment of the invention.
[0019] Figure 3 This is a timing diagram of two encryptions and two decryptions provided in an embodiment of the present invention.
[0020] Figure 4 This is a schematic diagram of two encryptions and two decryptions provided in an embodiment of the present invention.
[0021] Figure 5 This is a schematic diagram illustrating the usage of the key, public key, and private key provided in the embodiments of the present invention.
[0022] Figure 6 This is a schematic diagram of the physical structure of the electronic device provided in an embodiment of the present invention. Detailed Implementation
[0023] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.
[0024] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., refer to specific features, structures, materials, or characteristics described in connection with that embodiment or example, which are included in at least one embodiment or example of the present invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.
[0025] In light of the insecure data transmission and the risks of eavesdropping and tampering with personal data in existing technologies, this invention provides a data encryption and decryption scheme for application systems under a B / S architecture. This scheme effectively ensures that client (browser) data received by the server program is not tampered with, guaranteeing the security of user data during network transmission. Furthermore, this method also solves the problem of encryption key updates, thereby increasing the difficulty of data tampering.
[0026] Specifically, this embodiment of the invention provides a method for improving data security during network transmission, applied to a client; a user logs into an application system through the client, and the server assigns a unique public key and a unique private key to the user who successfully logs into the application system, and binds the public key and private key to the user's token.
[0027] Please see Figure 1 , Figure 1 This is one of the flowcharts illustrating a method for improving data security during network transmission provided by an embodiment of the present invention. In this embodiment, the method for improving data security during network transmission may include steps S110 to S140, each of which is detailed below:
[0028] S110, Receive the public key sent by the server.
[0029] S120. Use a symmetric encryption algorithm to encrypt the business data to obtain the first encrypted data and the original key.
[0030] S130. Encrypt the original key using the public key to obtain the first key.
[0031] S140. Send the first encrypted data and the first key to the server via the network.
[0032] This embodiment can be applied to B / S architecture application systems. After a system user logs into the application system through a client (such as a browser), the application system assigns a unique token to the logged-in user. This token is used by the application system to subsequently identify and authenticate the user. The application system is located on the server side.
[0033] Optionally, the server in this embodiment can use an asymmetric encryption algorithm to generate a public key and a private key for the user. The user token and private key can be stored on the server, while the public key can be returned to the browser client for storage.
[0034] Optionally, business data may include business requests. The client can configure specific business requests that require encryption and decryption.
[0035] Specifically, the configuration strategies include the following categories:
[0036] a) Configure all requests to require two encryptions and two decryptions.
[0037] b) Configure all requests to not require double encryption and double decryption.
[0038] c) Set the request URL to be encrypted twice and decrypted twice.
[0039] d) Set the request URL so that it does not require two encryptions and two decryptions.
[0040] In some embodiments, after a user logs in, business requests initiated from the front end (i.e., the client) to the back end (i.e., the server) undergo double encryption. The encryption process can be a public method that does not intrude on the original business logic. For example, when sending data to the server using Axios technology, Axios' interceptor technology can be used to perform the double encryption.
[0041] For example, the first encryption refers to encrypting the business data using a symmetric encryption algorithm. Symmetric encryption algorithms such as AES256 in GCM mode can ensure that the business data can be correctly decrypted when used by the server.
[0042] For example, the second encryption refers to the symmetric encryption key being encrypted with the user's public key. This is because if only symmetric encryption is used, the encryption key can be intercepted, leading to data decryption and leakage. The leaked data structure can then be used to infer the backend logic, modify message parameters, and ultimately alter the data. Asymmetric encryption algorithms, such as RSA, ensure that even if the public key is stolen, the symmetric encryption key cannot be decrypted.
[0043] Before the client transmits data to the server, two encryption operations are performed, and then the encrypted content is transmitted over the network using HTTPS technology. The encryption key is transmitted independently through the HTTPS request header.
[0044] This invention also provides a method for improving data security during network transmission, applied to the server side; users log in to the application system through a client, and the server assigns a unique public key and a unique private key to users who successfully log in to the application system, and binds the public key and private key to the user's token.
[0045] Please see Figure 2 , Figure 2 This is a second flowchart illustrating a method for improving data security during network transmission provided by an embodiment of the present invention. In this embodiment, the method for improving data security during network transmission may include steps S210 to S230, each of which is detailed below:
[0046] S210, Receive the first encrypted data and the first key sent by the client.
[0047] S220. Use the private key to decrypt the first key to obtain the original key.
[0048] S230. Decrypt the first encrypted data using the original key to obtain the business data.
[0049] Optionally, receiving the first encrypted data and the first key sent by the client, and decrypting the first key using the private key to obtain the original key, includes: obtaining the user's token from the header of the first encrypted data; verifying the user's token to verify whether the request is legitimate; when the verification passes, finding the bound private key using the user's token; and decrypting the first key using the private key to obtain the original key.
[0050] Optionally, methods to enhance data security during network transmission also include: deleting the user's private key when the user logs out of the application system, the user's login fails, the first encrypted data fails to decrypt, or the first key fails to decrypt; and generating a new public key and private key after the user successfully logs into the application system, and rebinding the public key and private key to the user.
[0051] Optionally, both the public and private keys are generated by the server program using an asymmetric encryption algorithm and bound to a token that uniquely identifies the user; the public key is sent to the client program for storage, while the user's token and private key are stored by the server's application system background program.
[0052] In this embodiment, the server receives a request from the front end and decrypts it twice. The decryption process is a public method in the program and does not intrude on the original business logic. For example, when using Spring technology in Java, a filter technique can be used to create a highest-priority filter to complete the two-stage decryption function.
[0053] The server verifies the user's token to confirm the validity of the request. If token verification fails, the request is immediately terminated, the saved user's private key is deleted, and the client is notified to require the user to log in again.
[0054] The server uses the user's token to find the user's private key and then uses the private key to decrypt the encrypted key. If decryption fails, it indicates that the encrypted key has been tampered with or that there is an unauthorized access security issue. The server should immediately terminate the request, delete the saved user's private key, and notify the client to require the user to log in again.
[0055] If the server successfully decrypts the encrypted key using the user's private key, it then uses the decrypted key to decrypt the business data again. If the business data decryption fails, it indicates that the business data has been tampered with. The server should immediately terminate the request, delete the saved user's private key, and notify the client to require the user to log in again.
[0056] If the server successfully decrypts the business data, the original system logic will continue to be applied.
[0057] Decrypting the encrypted key using the user's private key requires frequent retrieval of the user's private key. Therefore, a fast way to find the user's private key is needed to reduce the time spent on the decryption process. This invention provides three private key storage schemes:
[0058] a) The user's private key is stored in a relational database. This is suitable for scenarios where only a small number of request URLs require double encryption and decryption; it is easy to implement and widely applicable.
[0059] b) The user's private key is stored in a distributed in-memory database. This is suitable for most scenarios and is the main implementation scheme of this invention. Common distributed in-memory databases include Redis.
[0060] c) The user's private key is stored in the application's local cache. This is suitable for scenarios where all requested URLs require double encryption and decryption, and where network latency between the application and the distributed in-memory database is high. Since distributed in-memory databases are often deployed independently, network I / O is the main time-consuming point for retrieving the private key. The local cache is a memory space allocated within the application, with no network I / O, making it the most efficient way to retrieve in-memory data. Common local caching technologies include Caffeine and JetCache.
[0061] Optionally, after a user successfully logs into the application system, the server can immediately assign the user a public and private key pair. If the server terminates the request during the two decryption processes, it can immediately delete the user's private key. If the user's login expires, such as when the token becomes invalid, the server will immediately delete the user's private key.
[0062] This invention also provides a system for improving data security during network transmission, comprising a client and a server; a user logs into an application system through the client, and the server assigns a unique public key and a unique private key to the user who successfully logs into the application system, and binds the public key and private key to the user's token; the public key is stored by the client; the private key is stored by the server; the client is used to: encrypt business data using a symmetric encryption algorithm to obtain first encrypted data and an original key; encrypt the original key using the public key to obtain a first key; and send the first encrypted data and the first key to the server via the network; the server is used to: receive the first encrypted data and the first key sent by the client; decrypt the first key using the private key to obtain the original key; and decrypt the first encrypted data using the original key to obtain the business data.
[0063] Optionally, the client uses interceptor technology to encrypt business data and the original key; the server uses interceptor technology to decrypt the first encrypted data and the first key. In this way, the interceptor technology can ensure that the original business logic is not affected while the data is encrypted or decrypted without modifying the original data.
[0064] This invention provides a method to enhance data security during network transmission, solving the problem of data theft and tampering before passing through HTTPS technology. It effectively prevents tools like Burp Suite from obtaining customer personal data from the client. For example, intercepted requests only display a string of encrypted text, making it impossible to analyze the parameter structure and content. Therefore, it effectively ensures that the data received by the backend program from the frontend is not tampered with, guaranteeing the security of user data during network transmission. Data is encrypted from the application's client (browser) before being sent over the network via HTTPS, preventing tools like Burp Suite from intercepting requests sent to the server from the browser client. Furthermore, different users use different public and private keys, further ensuring data security.
[0065] Please see Figures 3-5 , Figure 3 This is a timing diagram of two encryptions and two decryptions provided in an embodiment of the present invention; Figure 4 This is a schematic diagram of two encryptions and two decryptions provided in an embodiment of the present invention; Figure 5 This is a schematic diagram illustrating the usage of the key, public key, and private key provided in the embodiments of the present invention.
[0066] Data transmission between the client and server is conducted via an HTTPS network. The client requests a public key from the server. The server generates a public key using an asymmetric encryption algorithm and returns an encrypted public key to the client. The client encrypts its business request using a symmetric encryption algorithm and encrypts the private key using the public key. The client then sends the encrypted business request and the encrypted private key to the server. The server receives the data from the client, decrypts it using its private key to obtain the private key, and then decrypts the business request using the private key and the encrypted private key, thus achieving a double encryption process.
[0067] On the client (browser), the application system business logic is assembled into a request, encrypted twice, and transmitted over HTTPS. On the server, the application system business logic is obtained after receiving the data and decrypting it twice.
[0068] On the client (browser), business data is encrypted using a key to obtain encrypted business data (i.e., the first encrypted data) and a key (i.e., the original key). The key is then encrypted using the public key to obtain the encrypted key (i.e., the first key). The encrypted business data and the encrypted key are sent to the server via an HTTPS network. The server obtains the encrypted business data and the encrypted key; it decrypts the encrypted key using its private key to obtain the encrypted key, and then decrypts the encrypted business data using the encrypted key to obtain the business data.
[0069] In conjunction with the methods provided in the above embodiments, the system for improving data security during network transmission provided in this embodiment has the following characteristics:
[0070] a. Bind a unique public and private key to each logged-in user;
[0071] b. Configure business requests that require encryption and decryption;
[0072] c. The client encrypts the data twice;
[0073] d. The encrypted business data and the encrypted key are transmitted to the server;
[0074] e. The server decrypts the encrypted data twice;
[0075] f. User private key storage design.
[0076] Specifically, the implementation steps of a system to improve data security during network transmission include:
[0077] First, each user who successfully logs into the application system is assigned a unique public and private key, which are then bound to the user's token. Before the client (browser) sends data to the server, the client (browser) program encrypts the business data using a symmetric encryption algorithm and encrypts the symmetric encryption key using the public key. Finally, the encrypted business data and the encrypted key are transmitted over the HTTPS network. The server uses the private key assigned to the user to decrypt the encrypted key and then uses the decrypted key to decrypt the business data.
[0078] Only users who successfully log in to the application system are assigned a public key and a private key. Both the public and private keys are generated by the server-side program using an asymmetric encryption algorithm and are bound to the user's unique identifier token. The public key is sent to the client (browser) program for storage, while the private key is stored by the application system's backend program.
[0079] Optionally, the client program uses interceptor technology to encrypt the sent requests twice. Using interceptor technology eliminates the need to modify each client's business request sent to the server, ensuring that the requests are encrypted without affecting the original business logic.
[0080] Optionally, business data is encrypted using a symmetric encryption algorithm, and the key for the symmetric encryption algorithm is encrypted using the user's public key. The encrypted business data and the encrypted key are sent to the server simultaneously, with the public key transmitted separately via the same request header. The transmission process uses HTTPS technology.
[0081] Optionally, after receiving a request from a client, the server first obtains the user's token and encrypted key from the request header, then determines whether the token is valid. If the token is successfully verified, the server uses the token to query the user's private key, uses the private key to decrypt the encrypted key, and if the key is successfully decrypted, uses the key to decrypt the business data of this request.
[0082] Optionally, interceptor technology can be used to decrypt the requests received by the server twice. Using interceptor technology does not require modifying each business request received by the server, ensuring that the requests are decrypted and does not affect the original business logic.
[0083] Optionally, you can configure which specific requests require double encryption and decryption. Policies include setting all requests to require double encryption and decryption, setting all requests to not require double encryption and decryption, setting request URLs that must undergo double encryption and decryption, and setting request URLs that do not require double encryption and decryption.
[0084] Alternatively, a user's private key can be stored in relational physical data, a distributed in-memory database, or a local cache.
[0085] Optionally, the user's private key is automatically deleted when the user logs out of the application system, the user's login fails, the server-side business data decryption fails, or the server-side key decryption fails. Upon successful login, a new public and private key is generated and re-bound to the user.
[0086] The following describes the apparatus for improving data security during network transmission provided by the present invention. The apparatus for improving data security during network transmission described below and the method for improving data security during network transmission described above can be referred to in correspondence.
[0087] This invention provides a device for improving data security during network transmission, applied to a client; users log in to an application system through the client, and the server assigns a unique public key and a unique private key to users who successfully log in to the application system, and binds the public key and private key to the user's token.
[0088] The device for enhancing data security during network transmission includes a first receiving module, a first encryption module, a second encryption module, and a first sending module.
[0089] The first receiving module is used to receive the public key sent by the server.
[0090] The first encryption module is used to encrypt business data using a symmetric encryption algorithm to obtain the first encrypted data and the original key.
[0091] The second encryption module is used to encrypt the original key using the public key to obtain the first key.
[0092] The first sending module is used to send the first encrypted data and the first key to the server via the network.
[0093] This invention also provides a device for improving data security during network transmission, applied to a server; when a user logs into an application system through a client, the server assigns a unique public key and a unique private key to the user who successfully logs into the application system, and binds the public key and private key to the user's token.
[0094] The device for enhancing data security during network transmission includes a second receiving module, a first decryption module, and a second decryption module.
[0095] The second receiving module is used to receive the first encrypted data and the first key sent by the client.
[0096] The first decryption module is used to decrypt the first key using the private key to obtain the original key.
[0097] The second decryption module is used to decrypt the first encrypted data based on the original key to obtain the business data.
[0098] On the other hand, embodiments of the present invention also provide an electronic device, please refer to... Figure 6 , Figure 6 This is a schematic diagram of the physical structure of the electronic device provided in the embodiments of the present invention, such as... Figure 6 As shown, the electronic device may include: a memory 620, a processor 610, and a computer program stored in the memory 620 and executable on the processor 610. When the processor 610 executes the program, it implements the methods provided above for enhancing data security during network transmission.
[0099] Optionally, the electronic device may further include a communication bus 630 and a communication interface 640, wherein the processor 610, the communication interface 640, and the memory 620 communicate with each other via the communication bus 630. The processor 610 may call a computer program in the memory 620 to execute a method for improving data security during network transmission, which may include:
[0100] Receive the public key sent by the server; encrypt the business data using a symmetric encryption algorithm to obtain the first encrypted data and the original key; encrypt the original key using the public key to obtain the first key; send the first encrypted data and the first key to the server via the network;
[0101] Alternatively, receive the first encrypted data and the first key sent by the client; decrypt the first key using the private key to obtain the original key; and decrypt the first encrypted data using the original key to obtain the business data.
[0102] In this process, users log in to the application system through a client. The server assigns a unique public key and a unique private key to each user who successfully logs in, and then binds the public key and private key to the user's token.
[0103] Furthermore, the logical instructions in the aforementioned memory 620 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, essentially, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0104] On the other hand, the present invention also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can perform the methods provided by the above methods to improve data security during network transmission. The steps and principles of these methods have been described in detail in the above methods and will not be repeated here.
[0105] In another aspect, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon. When executed by a processor, the computer program implements the methods for improving data security during network transmission provided by the above methods. The steps and principles of the methods have been described in detail in the above methods and will not be repeated here.
[0106] Non-transitory computer-readable storage media can be any available medium or data storage device that can be accessed by a processor, including but not limited to magnetic storage (e.g., floppy disks, hard disks, magnetic tapes, magneto-optical disks (MOs), etc.), optical storage (e.g., CDs, DVDs, BDs, HVDs, etc.), and semiconductor storage (e.g., ROMs, EPROMs, EEPROMs, non-volatile memory (NAND flash), solid-state drives (SSDs)).
[0107] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.
[0108] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.
[0109] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for improving data security during network transmission, characterized in that, Applied to the client side; when a user logs into the application system through the client, the server assigns a unique public key and a unique private key to the user who successfully logs into the application system, and binds the public key and the private key to the user's token; The method for enhancing data security during network transmission includes: receiving the public key sent by the server; The business data is encrypted using a symmetric encryption algorithm to obtain the first encrypted data and the original key; The original key is encrypted using the public key to obtain the first key; The first encrypted data and the first key are sent to the server via the network.
2. A method for improving data security during network transmission, characterized in that, Applied to the server side; when a user logs into the application system through a client, the server assigns a unique public key and a unique private key to the user who successfully logs into the application system, and binds the public key and the private key to the user's token; The method for enhancing data security during network transmission includes: receiving first encrypted data and a first key sent by the client; The first key is decrypted using the private key to obtain the original key; The first encrypted data is decrypted using the original key to obtain the business data.
3. The method for improving data security during network transmission according to claim 2, characterized in that, The process of receiving the first encrypted data and the first key sent by the client, and decrypting the first key using the private key to obtain the original key includes: Obtain the user's token from the header of the first encrypted data; Verify the user's token to confirm the validity of the request; When the verification passes, the bound private key is retrieved using the user's token; The first key is decrypted using the private key to obtain the original key.
4. The method for improving data security during network transmission according to claim 2, characterized in that, Also includes: When a user logs out of the application system, the user login fails, the first encrypted data fails to decrypt, or the first key fails to decrypt, the user's private key is deleted. After a user successfully logs into the application system, a new public and private key is generated and then re-bound to the user.
5. The method for improving data security during network transmission according to any one of claims 1 to 4, characterized in that, Both the public key and the private key are generated by the server program using an asymmetric encryption algorithm and bound to a token that uniquely identifies the user; wherein, the public key is sent to the program on the client for storage, and the user's token and the private key are stored by the background program of the application system on the server.
6. A system for improving data security during network transmission, characterized in that, It includes a client and a server; users log in to the application system through the client, and the server assigns a unique public key and a unique private key to users who successfully log in to the application system, and binds the public key and the private key to the user's token; the public key is stored by the client; the private key is stored by the server. The client is used to: encrypt business data using a symmetric encryption algorithm to obtain first encrypted data and an original key; and encrypt the original key using the public key to obtain a first key. The first encrypted data and the first key are sent to the server via the network; The server is configured to: receive the first encrypted data and the first key sent by the client; and decrypt the first key using the private key to obtain the original key; The first encrypted data is decrypted using the original key to obtain the business data.
7. The system for improving data security during network transmission according to claim 6, characterized in that, The client uses interceptor technology to encrypt the business data and the original key; The server uses interceptor technology to decrypt the first encrypted data and the first key; Interceptor technology can ensure that data is encrypted or decrypted without affecting the original business logic, without modifying the original data.
8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the method for improving data security during network transmission as described in any one of claims 1 to 5.
9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method for improving data security during network transmission as described in any one of claims 1 to 5.
10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the method for improving data security during network transmission as described in any one of claims 1 to 5.
Citation Information
Patent Citations
Data safety protection method and system
CN113438086A
Client information authentication method and system of micro-service architecture
CN113783695A