Tcm-based symmetric encryption transmission method, device, medium and program product

The TCM device's built-in private key design and key verification and signature method solves the problem of certificates being easily lost and vulnerable to attacks in traditional digital envelope technology, and achieves highly secure symmetric encryption transmission.

CN119182588BActive Publication Date: 2025-10-10XIAN THERMAL POWER RES INST CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411258132.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-09
Publication Date
2025-10-10
Estimated Expiration
2044-09-09

AI Technical Summary

Technical Problem

The certificates in traditional digital envelope technology are easy to be lost and attacked, resulting in the problem of reduced data transmission security.

Method used

Through the design of built-in private keys in TCM devices, TCM identity and public keys are used for signature verification and signing to establish a secure communication connection. The encryption method of key A and key B is used to encrypt and sign data to build a multi-level security protection system.

Benefits of technology

Ensure the authenticity and security of the starting point of communication, ensure that both parties hold encryption keys recognized by each other, realize the organic combination of symmetric encryption and public key signature, and improve the security of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119182588B_ABST
    Figure CN119182588B_ABST
Patent Text Reader

Abstract

The application discloses a kind of symmetric encryption transmission methods, equipment, medium and program product based on TCM, belong to information security technical field.The symmetric encryption transmission method based on TCM provided by the application first, by verifying the random number after the signature of server, utilize the TCM built-in in equipment to establish the safe communication bridge between with server, ensure the authenticity and security of communication starting point;Second, equipment and server each other send encryption key (key A and key B) to each other, and each other verify the validity of opposite key, ensure that both sides hold the encryption key approved by the other party, in data transmission stage, the joint encryption strategy of key A and key B is used, and the private key of the other party is used for signing after encryption Data, not only realize the organic combination of symmetric encryption and public key signature in technology, more logically build multi-level, multidimensional security protection system, improve the security of data transmission.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to a TCM-based symmetric encryption transmission method, device, medium and program product. Background Art

[0002] Traditional digital envelope technology plays an important role in information security. Combining the advantages of asymmetric encryption (such as RSA) and symmetric encryption, it ensures both secure data transmission and efficient encryption and decryption. However, it also has drawbacks in certificate management and key exchange. First, the asymmetric certificates in traditional digital envelopes are typically stored in the operating system or in a specific file. This means that if the storage medium fails (such as a damaged hard drive), the system is attacked, or the file is deleted or tampered with due to user error, the certificate may be lost or invalidated, affecting the decryption of the digital envelope and making it impossible to correctly recover the encrypted information. Second, certificate storage and management often rely on the security and stability of the operating system. If the operating system has security vulnerabilities or is attacked by malware, the certificates stored there may also be at risk of being stolen or tampered with. Third, each key exchange requires the generation of a new certificate and a series of complex operations (such as certificate issuance, distribution, and verification). This not only increases the system burden but can also cause errors due to improper operation, resulting in the inability to correctly decrypt the digital envelope.

[0003] To address these issues, the research and deployment of trusted computing platforms prioritize cryptographic technology. By embedding chip technology and utilizing proprietary cryptographic algorithms and engines, a Trusted Cryptographic Module (TCM) has been constructed. As a combination of hardware and firmware, the TCM can be packaged independently or integrated as an IP core into other chips, providing TCM functionality for system platforms and software. TCM functions include: The TCM securely stores user identity information and root keys, enabling two-way authentication and preventing impersonation and spoofing; providing high-strength encryption protection for important data, ensuring it is protected from leakage or tampering during transmission and storage; and digitally signing applications and recording software status to prevent malware and hacker attacks. The private key embedded in the TCM is designed to be highly secure and cannot be directly read or written. This design ensures the physical security of the private key, preventing unauthorized access and tampering.

[0004] Therefore, how to provide a TCM-based symmetric encryption transmission method while maintaining the advantages of digital envelope technology has become a key technical problem that needs to be urgently solved by technicians in the current information security field. Summary of the Invention

[0005] The application aims to provide a TCM-based symmetric encryption transmission method, device, medium and program product to overcome the problem of certificate loss and vulnerability in traditional digital envelope technology, leading to reduced data transmission security performance.

[0006] The application solves the above technical problems by the following technical solutions:

[0007] A TCM-based symmetric encryption transmission method comprises the following steps:

[0008] S1, the device A containing TCM verifies the signature of the random number signed by the server B, and when the verification is passed, a secure communication connection with the server B is established; otherwise, the communication is ended.

[0009] S2, the server B verifies the signature of the key A signed by the device A, and when the verification is passed, the key A of the device A is obtained, and a secure communication connection with the device A is established; otherwise, the communication is ended.

[0010] S3, the device A verifies the signature of the key B signed by the server B, and when the verification is passed, the key B of the server B is obtained; otherwise, the communication is ended.

[0011] S4, the device A and the server B encrypt the transmission data by using the encryption mode of the key A+key B, and sign the encrypted transmission data by using the private key of the other party, to realize TCM-based symmetric encryption transmission.

[0012] Further, S1 specifically comprises the following process:

[0013] S1.1, the TCM identity and public key A of the device A are obtained through a driver, and the TCM identity and public key A are sent to the server B.

[0014] S1.2, the server B establishes a mapping relationship for the received TCM identity and public key A, which is used to judge the identity legitimacy of the device A when receiving data; the server generates a public key B, a private key B and a random number, signs the random number by using the private key B, obtains first encrypted data by encrypting the signed random number and the public key B of the server B through the received public key A, encapsulates the first encrypted data and sends it to the device A.

[0015] S1.3, the private key A of the device A is called through a driver to decrypt the first encrypted data, and the signed random number and the public key B of the server B are obtained, the signed random number is verified by using the public key B, when the verification is passed, the device A establishes a secure communication connection with the server B; otherwise, the communication is ended.

[0016] Further, S2 specifically comprises the following process:

[0017] S2.1 Device A generates key A, and uses the driver to call private key A to sign key A, obtaining signed key A. Simultaneously, it encrypts signed key A using public key B to obtain second encrypted data. The encrypted data is encapsulated and sent to server B.

[0018] S2.2 Server B uses private key B to decrypt the second encrypted data to obtain the signed key A; uses public key A to verify the signed key A. When the verification passes, server B obtains device A's key A and establishes a secure communication connection with device A; otherwise, the communication ends.

[0019] Furthermore, S3 specifically includes the following processes:

[0020] S3.1 Server B generates key B and signs key B using private key B to obtain signed key B. Simultaneously, server B encrypts signed key B using public key A to obtain third encrypted data. The encrypted data is encapsulated and sent to device A.

[0021] S3.2 decrypts the third encrypted data by driving the private key A of device A to obtain the signed key B, and uses the public key B to verify the signed key B. When the verification passes, device A obtains the key B of server B; otherwise, the communication ends.

[0022] Furthermore, S4 specifically includes the following processes:

[0023] S4.1 Device A encrypts transmission data A using key A + key B to obtain encrypted transmission data A. Device A then signs the encrypted transmission data A using server B's private key B to obtain signed and encrypted transmission data A. Device A then sends the signed and encrypted transmission data A to server B.

[0024] S4.2 After receiving the signed and encrypted transmission data A, server B verifies the signature using public key B. If the signature verification succeeds, server B decrypts the data using keys A and B to obtain the transmission data A. Otherwise, the communication ends.

[0025] S4.3 Server B encrypts transmission data B using the encryption method of key A + key B to obtain encrypted transmission data B. Server B signs the encrypted transmission data B using device A's private key A to obtain signed and encrypted transmission data B. Server B then sends the signed and encrypted transmission data B to device A.

[0026] S4.4 After device A receives the signed and encrypted transmission data B, it uses public key A to verify the signature. When the signature verification succeeds, it uses keys A and B to decrypt the data to obtain the transmission data B, realizing symmetric encryption transmission based on TCM.

[0027] Furthermore, S4 also includes the following process:

[0028] S4.5When the device A is disconnected again to transmit data to the service end B, the TCM identity of the device A is obtained through driving, the device A encrypts the transmission data C by using the encryption mode of the key A+key B, obtains the encrypted transmission data C, signs the encrypted transmission data C by using the private key B of the service end B, obtains the signed and encrypted transmission data C, and sends the signed and encrypted transmission data C and the TCM identity of the device A to the service end B;

[0029] S4.6After the service end B receives the signed and encrypted transmission data C and the TCM identity of the device A, the identity legality of the device A is judged based on the mapping relationship between the TCM identity and the public key A, when the mapping relationship exists, the identity is legal, the public key B is used for signature verification, otherwise the communication is ended; when the signature verification is passed, the key A and the key B are used for decryption to obtain the transmission data C; otherwise the communication is ended.

[0030] Further, the device A includes a server, a computer and a switch.

[0031] A computer device includes a memory and a processor, the memory stores a computer program, and the processor implements the steps of the above-mentioned TCM-based symmetric encryption transmission method when executing the computer program.

[0032] A computer readable storage medium stores a computer program, and the computer program implements the steps of the above-mentioned TCM-based symmetric encryption transmission method when executed by a processor.

[0033] A computer program product includes a computer program, and the computer program implements the steps of the above-mentioned TCM-based symmetric encryption transmission method when executed by a processor.

[0034] Compared with the prior art, the positive progress effect of the present application is that:

[0035] The TCM-based symmetric encryption transmission method provided by the present application firstly establishes a secure communication bridge between the device and the service end by verifying the random number signed by the service end, and uses the TCM built in the device to ensure the authenticity and security of the communication starting point; secondly, the device and the service end each send an encryption key (key A and key B) to the other party and verify the validity of the encryption key of the other party, so that both parties hold the encryption key approved by the other party, and in the data transmission stage, a joint encryption strategy of key A and key B is adopted, and the private key of the other party is used for signing the encrypted data, which not only realizes the organic combination of symmetric encryption and public key signature in technology, but also logically constructs a multi-level and multi-dimensional security protection system, thereby improving the security of data transmission. BRIEF DESCRIPTION OF DRAWINGS

[0036] The drawings in the specification are used to provide further understanding of the present invention and constitute a part of the present invention. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute improper limitations on the present invention.

[0037] Figure 1 Schematic diagram of the process of exchanging keys A and B between device A and server B in this method. DETAILED DESCRIPTION

[0038] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions of the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Generally, the components of the embodiments of the present invention described and shown in the drawings herein can be arranged and designed in various different configurations.

[0039] Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the invention as claimed, but rather merely represents selected embodiments of the present invention. All other embodiments derived by persons of ordinary skill in the art based on the embodiments of the present invention without creative effort shall fall within the scope of protection of the present invention.

[0040] It should be noted that similar reference numerals and letters denote similar items in the following drawings, and therefore, once an item is defined in one drawing, it does not need to be further defined or explained in subsequent drawings.

[0041] In the description of the embodiments of the present invention, it should be noted that if the terms "upper," "lower," "horizontal," "inner," etc. appear, the orientation or positional relationship indicated is based on the orientation or positional relationship shown in the accompanying drawings, or the orientation or positional relationship in which the inventive product is typically placed when in use. These terms are merely for the convenience of describing the present invention and simplifying the description, and do not indicate or imply that the device or component referred to must have a specific orientation, be constructed, or operate in a specific orientation. Therefore, they should not be construed as limitations on the present invention. In addition, the terms "first," "second," etc. are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.

[0042] In addition, if the term "horizontal" appears, it does not mean that the component must be absolutely horizontal, but can be slightly tilted. For example, "horizontal" only means that its direction is more horizontal than "vertical", and does not mean that the structure must be completely horizontal, but can be slightly tilted.

[0043] In the description of the embodiments of the present invention, it should be noted that, unless otherwise expressly specified or limited, the terms "disposed," "installed," "connected," and "connected" should be understood in a broad sense. For example, they can refer to fixed connections, detachable connections, or integral connections; they can refer to mechanical connections or electrical connections; they can refer to direct connections or indirect connections through an intermediate medium; and they can refer to internal connections between two components. Those skilled in the art will understand the specific meanings of the above terms in the present invention based on specific circumstances.

[0044] The present invention will be further described in detail below with reference to the accompanying drawings, which are intended to explain rather than limit the present invention.

[0045] Devices with TCM can obtain the public key through the driver and send it to the server. However, although the private key is built into the TCM, it cannot be read or written, and cannot be sent to the server. However, the private key in the TCM can be used through software protocols to perform secure operations. The built-in driver calls the private key for secure operations.

[0046] See also Figure 1 , a symmetric encryption transmission method based on TCM, comprising the following steps:

[0047] S1. Device A containing TCM verifies the random number signed by server B. If the verification passes, a secure communication connection with server B is established; otherwise, the communication is terminated.

[0048] S1 specifically includes the following processes:

[0049] S1.1 obtains the TCM identity and public key A of device A through the driver, and sends the TCM identity and public key A to server B;

[0050] S1.2 Server B establishes a mapping relationship between the received TCM identity and public key A to determine the legitimacy of device A's identity when receiving data. The server generates public key B, private key B, and a random number, signs the random number using private key B, encrypts the signed random number using the received public key A and server B's public key B, and obtains first encrypted data. The server then encapsulates the first encrypted data and sends it to device A.

[0051] S1.3 decrypts the first encrypted data by driving the private key A of device A, obtains the signed random number and the public key B of server B, and uses the public key B to verify the signed random number. When the verification passes, device A establishes a secure communication connection with server B; otherwise, the communication ends.

[0052] S2. Server B verifies the signature of key A signed by device A. If the signature is verified, server B obtains key A of device A and establishes a secure communication connection with device A; otherwise, the communication ends.

[0053] S2 specifically includes the following processes:

[0054] S2.1 Device A generates key A, and uses the driver to call private key A to sign key A, obtaining signed key A. Simultaneously, it encrypts signed key A using public key B to obtain second encrypted data. The encrypted data is encapsulated and sent to server B.

[0055] S2.2 Server B uses private key B to decrypt the second encrypted data to obtain the signed key A; uses public key A to verify the signed key A. When the verification passes, server B obtains device A's key A and establishes a secure communication connection with device A; otherwise, the communication ends.

[0056] S3. Device A verifies the key B signed by server B. If the verification passes, device A obtains the key B of server B; otherwise, the communication ends.

[0057] S3 specifically includes the following processes:

[0058] S3.1 Server B generates key B and signs key B using private key B to obtain signed key B. Simultaneously, server B encrypts signed key B using public key A to obtain third encrypted data. The encrypted data is encapsulated and sent to device A.

[0059] S3.2 decrypts the third encrypted data by driving the private key A of device A to obtain the signed key B, and uses the public key B to verify the signed key B. When the verification passes, device A obtains the key B of server B; otherwise, the communication ends.

[0060] S4. Device A and server B encrypt the transmitted data using the encryption method of key A + key B, and use the other party's private key to sign the encrypted transmitted data, realizing symmetric encryption transmission based on TCM.

[0061] S4 specifically includes the following processes:

[0062] S4.1 Device A encrypts transmission data A using key A + key B to obtain encrypted transmission data A. Device A then signs the encrypted transmission data A using server B's private key B to obtain signed and encrypted transmission data A. Device A then sends the signed and encrypted transmission data A to server B.

[0063] S4.2 After receiving the signed and encrypted transmission data A, server B verifies the signature using public key B. If the signature verification succeeds, server B decrypts the data using keys A and B to obtain the transmission data A. Otherwise, the communication ends.

[0064] S4.3 Server B encrypts transmission data B using the encryption method of key A + key B to obtain encrypted transmission data B. Server B signs the encrypted transmission data B using device A's private key A to obtain signed and encrypted transmission data B. Server B then sends the signed and encrypted transmission data B to device A.

[0065] S4.4 After device A receives the signed and encrypted transmission data B, it uses public key A to verify the signature. When the signature verification succeeds, it uses keys A and B to decrypt the data to obtain the transmission data B, realizing symmetric encryption transmission based on TCM.

[0066] In particular, S4 also includes the following processes:

[0067] S4.5 When device A disconnects and starts transmitting data to server B again, it obtains device A's TCM identity through the driver. Device A encrypts the transmitted data C using key A + key B to obtain encrypted transmitted data C. It then signs the encrypted transmitted data C using server B's private key B to obtain the signed and encrypted transmitted data C. It then sends the signed and encrypted transmitted data C and device A's TCM identity to server B.

[0068] S4.6 After server B receives the signed and encrypted transmission data C and the TCM identity of device A, it determines the legitimacy of device A's identity based on the mapping relationship established between the TCM identity and public key A. If a mapping relationship exists, the identity is legal and the signature is verified using public key B. Otherwise, the communication is terminated. If the signature verification is successful, key A and key B are used to decrypt the data to obtain the transmission data C. Otherwise, the communication is terminated.

[0069] Specifically, device A includes a server, a computer, and a switch.

[0070] Example 2

[0071] Based on the same inventive concept, an embodiment of the present application provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the symmetric encryption transmission method based on TCM are implemented. The memory may include a memory, such as a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device. The processor, network interface, and memory are interconnected via an internal bus. The internal bus may be an industrial standard architecture bus, a peripheral component interconnection standard bus, an extended industrial standard structure bus, etc. The bus may be divided into an address bus, a data bus, a control bus, etc. The memory is used to store programs. Specifically, the program may include program code, and the program code includes computer operating instructions. The memory may include memory and non-volatile memory, and provides instructions and data to the processor.

[0072] Example 3

[0073] Based on the same inventive concept, an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the computer-readable storage medium implements the steps of the symmetric encryption transmission method based on TCM. Specifically, the computer-readable storage medium includes, but is not limited to, volatile memory and / or non-volatile memory. The volatile memory may include random access memory (RAM) and / or cache memory, etc. The non-volatile memory may include read-only memory (ROM), hard disk, flash memory, optical disk, magnetic disk, etc.

[0074] Example 4

[0075] Based on the same inventive concept, an embodiment of the present application provides a computer program product, which includes a computer program stored on a computer-readable storage medium, and the computer program includes program instructions. When the program instructions are executed by a computer device, the computer device executes the steps of the above-mentioned TCM-based symmetric encryption transmission method.

[0076] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0077] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer device or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0078] These computer program instructions may also be stored in a computer readable memory that can direct a computer device or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0079] These computer program instructions can also be loaded onto a computer device or other programmable data processing device so that a series of operating steps are executed on the computer device or other programmable device to produce a process implemented by the computer device, thereby providing instructions for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0080] Although the preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention.

[0081] Obviously, those skilled in the art may make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if such changes and modifications fall within the scope of the claims and their equivalents, the present invention is intended to include such changes and modifications.

Claims

1. A symmetric encryption transmission method based on TCM, characterized in that: The following steps are involved: S1. Device A, which contains the TCM, verifies the random number signed by server B. If the verification passes, a secure communication connection with server B is established; otherwise, the communication ends. S2. Server B verifies the signature of Key A signed by Device A. If the signature is verified, Server B obtains Key A of Device A and establishes a secure communication connection with Device A. Otherwise, the communication ends. S3. Device A verifies the key B signed by server B. If the verification passes, it obtains the key B of server B; otherwise, the communication ends. S4. Device A and server B encrypt the transmitted data using the encryption method of key A + key B, and use the other party's private key to sign the encrypted transmitted data, realizing symmetric encryption transmission based on TCM.

2. A TCM-based symmetric encryption transmission method according to claim 1, characterized in that: S1 specifically includes the following processes: S1.1 obtains the TCM identity and public key A of device A through the driver, and sends the TCM identity and public key A to server B; S1.2 Server B establishes a mapping relationship between the received TCM identity and public key A to determine the legitimacy of device A's identity when receiving data. The server generates public key B, private key B, and a random number, signs the random number using private key B, encrypts the signed random number using the received public key A and server B's public key B, and obtains first encrypted data. The server then encapsulates the first encrypted data and sends it to device A. S1.3 decrypts the first encrypted data by driving the private key A of device A, obtains the signed random number and the public key B of server B, and uses the public key B to verify the signed random number. When the verification passes, device A establishes a secure communication connection with server B; otherwise, the communication ends.

3. A TCM-based symmetric encryption transmission method according to claim 2, characterized in that: S2 specifically includes the following processes: S2.1 Device A generates key A, and uses the driver to call private key A to sign key A, obtaining signed key A. Simultaneously, it encrypts signed key A using public key B to obtain second encrypted data. The encrypted data is encapsulated and sent to server B. S2.2 Server B uses private key B to decrypt the second encrypted data to obtain the signed key A; uses public key A to verify the signed key A. When the verification passes, server B obtains device A's key A and establishes a secure communication connection with device A; otherwise, the communication ends.

4. A TCM-based symmetric encryption transmission method according to claim 3, characterized in that: S3 specifically includes the following processes: S3.1 Server B generates key B and signs key B using private key B to obtain signed key B. Simultaneously, server B encrypts signed key B using public key A to obtain third encrypted data. The encrypted data is encapsulated and sent to device A. S3.2 decrypts the third encrypted data by driving the private key A of device A to obtain the signed key B, and uses the public key B to verify the signed key B. When the verification passes, device A obtains the key B of server B; otherwise, the communication ends.

5. A TCM-based symmetric encryption transmission method according to claim 4, characterized in that: S4 specifically includes the following processes: S4.1 Device A encrypts transmission data A using key A + key B to obtain encrypted transmission data A. Device A then signs the encrypted transmission data A using server B's private key B to obtain signed and encrypted transmission data A. Device A then sends the signed and encrypted transmission data A to server B. S4.2 After receiving the signed and encrypted transmission data A, server B verifies the signature using public key B. If the signature verification succeeds, server B decrypts the data using keys A and B to obtain the transmission data A. Otherwise, the communication ends. S4.3 Server B encrypts transmission data B using the encryption method of key A + key B to obtain encrypted transmission data B. Server B signs the encrypted transmission data B using device A's private key A to obtain signed and encrypted transmission data B. Server B then sends the signed and encrypted transmission data B to device A. S4.4 After device A receives the signed and encrypted transmission data B, it uses public key A to verify the signature. When the signature verification succeeds, it uses keys A and B to decrypt the data to obtain the transmission data B, realizing symmetric encryption transmission based on TCM.

6. A TCM-based symmetric encryption transmission method according to claim 5, characterized in that: S4 also includes the following processes: S4.5 When device A disconnects and starts transmitting data to server B again, it obtains device A's TCM identity through the driver. Device A encrypts the transmitted data C using key A + key B to obtain encrypted transmitted data C. It then signs the encrypted transmitted data C using server B's private key B to obtain the signed and encrypted transmitted data C. It then sends the signed and encrypted transmitted data C and device A's TCM identity to server B. S4.6 After server B receives the signed and encrypted transmission data C and the TCM identity of device A, it determines the legitimacy of device A's identity based on the mapping relationship established between the TCM identity and public key A. If a mapping relationship exists, the identity is legal and the signature is verified using public key B. Otherwise, the communication is terminated. If the signature verification is successful, key A and key B are used to decrypt the data to obtain the transmission data C. Otherwise, the communication is terminated.

7. The TCM-based symmetric encryption transmission method according to claim 1, characterized in that: Device A includes servers, computers, and switches.

8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the TCM-based symmetric encryption transmission method according to any one of claims 1 to 7 are implemented.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the TCM-based symmetric encryption transmission method according to any one of claims 1 to 7 are implemented.

10. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the TCM-based symmetric encryption transmission method according to any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Bidirectional authentication method, terminal and server

    CN111931158A

  • Encryption communication method and system

    CN114650173A