An Encryption Method and System for Data Transmission between Information Systems
The data is initially encrypted through the RSA key, and the data packets are split and multi-channel transmission are performed, which solves the problem of insufficient data transmission security in the prior art and improves complexity and security.
Patent Information
- Application Number
- CN202411464234.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-21
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2044-10-21
AI Technical Summary
The existing technology lacks encryption security and complexity during data transmission, and is easy to be cracked. In particular, the probability of the entire piece of data being cracked after the wrong order sorting rules are brute-forced.
The RSA key is used to initially encrypt the data to be transmitted, and it is split into a second first data packet and an equal second data packet through secondary splitting, and it is processed by different encryption methods respectively to generate target encrypted data, and transmitted through random multi-channels.
It greatly improves the security and complexity of data transmission. The cracking process is cumbersome and the workload is huge, making it difficult to obtain complete data through brute force cracking.
Smart Images

Figure CN119363333B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data encryption transmission, and specifically, to an encryption method and system for data transmission between information systems. Background Art
[0002] In today's digital age, data transmission has become an indispensable part of the daily life of enterprises and individuals. With the popularization of the Internet and the increasing demand for information by people, the volume and speed of data transmission have also been continuously improved. However, this has also provided more attack methods for hackers and malware to steal sensitive information and damage system security. Therefore, protecting the security of data during transmission has become increasingly important. Data transmission encryption technology is a method for protecting the security of data during transmission. It encrypts data into an unreadable form to prevent unauthorized access and tampering.
[0003] In the invention patent with the application number CN201810871462.9 and the name of an encrypted data transmission method, an encrypted data transmission method is disclosed, including the following steps: S1. Set that a message body with the number of bytes Ni2 is freely selected for transmission in Ni4 channels, generate a random number Ni1 by using a timing counter, and randomly split the message body with the number of bytes Ni2 to be transmitted into Ni3 segmented message body data packets according to the random number Ni1; S2. Randomly disorder the Ni3 segmented message body data packets completed in the previous step by using an encoder, and then perform dynamic encryption and random multi-channel transmission; S3. Message body restoration. The receiving end receives each segmented message body data packet and stores it, and decrypts and restores the true value of the data through a decoder, that is, recombines each segmented message body data according to the packet sequence number and the disordering rule and splices them in order to form a complete message body data.
[0004] Although the above patent randomly splits the data to be transmitted into multiple data packets, and then disorderly sorts and dynamically encrypts (rolling code) the multiple data packets. Although the disordering rule for each time is not limited, in the process of cracking the encrypted data, only one disordering rule needs to be cracked, and only one dynamic encryption (rolling code) is performed on the multiple data packets. If the disordering rule is violently cracked, the probability of the entire data being cracked is extremely high. Therefore, in terms of the overall solution, the security and complexity of data encryption still need to be optimized. Summary of the Invention
[0005] To solve the deficiencies of the prior art, the present invention provides an encryption method for data transmission between information systems, and the method includes the following steps:
[0006] Obtain the data to be transmitted and the encryption key of the client;
[0007] Based on the key, encrypt the data to be transmitted to obtain initial encrypted data;
[0008] Split the initial encrypted data into several unequal first data packets;
[0009] Split each first data packet into several equal second data packets;
[0010] Use the first method to encrypt the first data packet to obtain a first processing result;
[0011] Use the second method to encrypt the second data packet to obtain a second processing result;
[0012] Generate target encrypted data based on the first processing result and the second processing result;
[0013] Transmit the target encrypted data to a preset server;
[0014] The preset server decrypts the target encrypted data.
[0015] The present invention is implemented through the following technical solutions: First, the data to be transmitted is encrypted by a key to obtain initial encrypted data, then the initial encrypted data is split once to obtain several unequal first data packets, and then each of the split first data packets is split a second time into several equal second data packets. Then, the first method is used to encrypt the first data packet to obtain a first processing result, and the second method is used to encrypt the second data packet to obtain a second processing result. Through the first processing result and the second processing result, target encrypted data is obtained. Finally, the target encrypted data is transmitted to a preset server for decryption.
[0016] This solution initially encrypts the data to be transmitted by a key, uses the method of data packets to transmit the data to be transmitted, splits the initial encrypted data twice. The first split is to split the initial encrypted data into several unequal first data packets, and the second split is to split each first data packet into several equal second data packets. Then, encryption processing is respectively performed on the first data packet and the second data packet. When the data is intercepted, first the key needs to be cracked, and then the encryption rules of all the second data packets need to be cracked. And the second data packets are combined according to the data volume, so permutation and combination tests also need to be performed on all the second data packets to obtain the final first data packets. Finally, the encryption rules of all the first data packets need to be cracked. The entire cracking process is not only cumbersome but also involves a huge amount of work. Therefore, the security and complexity of data transmission are greatly guaranteed.
[0017] As an optional technical solution, the first method includes:
[0018] Determine a first hidden data in each first data packet, perform out-of-order sorting on all the first data packets and obtain the corresponding first sorting rule;
[0019] Extract the first hidden data in each first data packet, based on the first sorting rule, sort all the first hidden data to form a first hidden data chain, pack the first hidden data chain into a first hidden data packet and randomly insert it into the sequence of the first data packets.
[0020] As an optional technical solution, the method further includes:
[0021] Set up a first database on both the client and the preset server, and the first database is used to collect the first sorting rules of all the first data packets;
[0022] When performing out-of-order sorting on all the first data packets subsequently, randomly obtain a first sorting rule from the first database and denote it as the third sorting rule;
[0023] Based on the third sorting rule, sort all the first data packets.
[0024] As an optional technical solution, the second method includes:
[0025] Determine a second hidden data in each second data packet, perform out-of-order sorting on all the second data packets in a single first data packet and obtain the corresponding second sorting rule;
[0026] Extract the second hidden data of each second data packet in a single first data packet, based on the second sorting rule, sort all the second hidden data to form a second hidden data chain, pack the second hidden data chain into a second hidden data packet and randomly insert it into the sequence of the second data packets in a single first data packet.
[0027] As an optional technical solution, the method further includes:
[0028] Set up a second database on both the client and the preset server, and the second database is used to collect the second sorting rules of all the second data packets;
[0029] When performing out-of-order sorting on all the second data packets in a single first data packet subsequently, randomly obtain a second sorting rule from the second database and denote it as the fourth sorting rule;
[0030] Based on the fourth sorting rule, sort all the second data packets in a single first data packet.
[0031] As an optional technical solution, the decryption of the target encrypted data by the preset server includes:
[0032] Obtain the key, and perform primary decryption on the target encrypted data to obtain primary target decrypted data;
[0033] Based on the data capacity, perform data screening on the primary target decrypted data, and place second data packets with the same data capacity into the same set;
[0034] Based on the second hidden data chain, reorganize all the second data packets in the corresponding set to obtain the corresponding first data packet;
[0035] Based on the first hidden data chain, reorganize all the first data packets to obtain the final target decrypted data.
[0036] As an alternative technical solution, the method further includes:
[0037] Perform random multi-channel transmission on the target encrypted data, and the number of channels is greater than or equal to 2.
[0038] As an alternative technical solution, the key uses an RSA key.
[0039] To solve the deficiencies of the existing technology, the present invention also provides an encryption system for data transmission between information systems. The system includes:
[0040] An acquisition unit, configured to acquire the data to be transmitted and the key of the client;
[0041] An initial encryption unit, configured to encrypt the data to be transmitted based on the key to obtain initial encrypted data;
[0042] A primary splitting unit, configured to split the initial encrypted data into a plurality of unequal first data packets;
[0043] A secondary splitting unit, configured to split each first data packet into a plurality of equal second data packets;
[0044] A first encryption unit, which encrypts the first data packet using a first method to obtain a first processing result;
[0045] A second encryption unit, which encrypts the second data packet using a second method to obtain a second processing result;
[0046] A generation unit, configured to generate target encrypted data based on the first processing result and the second processing result;
[0047] A transmission unit, configured to transmit the target encrypted data to a preset server;
[0048] A decryption unit, configured to decrypt the target encrypted data by the preset server.
[0049] One or more technical solutions provided by the present invention have at least the following technical effects or advantages:
[0050] In this solution, the data to be transmitted is initially encrypted with a key, and the data to be transmitted is transmitted in the form of data packets. The initially encrypted data is split twice. The first split divides the initially encrypted data into several unequal first data packets, and the second split divides each first data packet into several equal second data packets. Then, encryption processing is performed on the first data packets and the second data packets respectively. When the data is intercepted, first, the key needs to be cracked, and then the encryption rules of all the second data packets need to be cracked. Moreover, the second data packets are combined according to the data volume, so permutation and combination tests need to be performed on all the second data packets to obtain the final first data packets. Finally, the encryption rules of all the first data packets need to be cracked. The entire cracking process is not only cumbersome but also involves a huge amount of work. Therefore, the security and complexity of data transmission are greatly guaranteed. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] The drawings described herein are used to provide a further understanding of the embodiments of the present invention, form a part of the present invention, and do not limit the embodiments of the present invention;
[0052] Figure 1 is a schematic flowchart of an encryption method for data transmission between information systems in the present invention;
[0053] Figure 2 is a schematic diagram of the composition of an encryption system for data transmission between information systems in the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0054] In order to more clearly understand the above objects, features, and advantages of the present invention, the present invention will be further described in detail below with reference to the drawings and specific embodiments. It should be noted that, without conflict, the embodiments of the present invention and the features in the embodiments can be combined with each other.
[0055] In the following description, many specific details are set forth in order to fully understand the present invention. However, the present invention can also be implemented in other ways different from those described herein. Therefore, the protection scope of the present invention is not limited by the specific embodiments disclosed below.
[0056] Embodiment 1
[0057] Please refer to Figure 1 , Figure 1 which is a schematic flowchart of an encryption method for data transmission between information systems in the present invention. The method includes the following steps:
[0058] Obtain the data to be transmitted and the key of the client;
[0059] Encrypt the data to be transmitted based on the key to obtain initial encrypted data;
[0060] Split the initial encrypted data into several unequal first data packets;
[0061] Split each first data packet into several equal second data packets;
[0062] Use the first method to encrypt the first data packet to obtain a first processing result;
[0063] Use the second method to encrypt the second data packet to obtain a second processing result;
[0064] Generate target encrypted data based on the first processing result and the second processing result;
[0065] Transmit the target encrypted data to a preset server;
[0066] The preset server decrypts the target encrypted data.
[0067] The specific embodiments of the present invention are as follows:
[0068] Obtain the data to be transmitted of the client and denote it as A. The key uses the RSA key. The RSA key system is a cryptographic system that uses different encryption keys and decryption keys, and it is computationally infeasible to derive the decryption key from the known encryption key; use the encryption key in the RSA key to perform initial encryption on the data to be transmitted to obtain the initial encrypted data.
[0069] Split the initial encrypted data into several unequal first data packets, and use the first method to encrypt all the first data packets to obtain a first processing result. The first method specifically includes:
[0070] Determine a first hidden data in each first data packet, perform out-of-order sorting on all the first data packets and obtain the corresponding first sorting rule;
[0071] Extract the first hidden data in each first data packet, based on the first sorting rule, sort all the first hidden data to form a first hidden data chain, and pack the first hidden data chain into a first hidden data packet and randomly insert it into the sequence of the first data packets.
[0072] Among them, if the data A to be transmitted is split into M unequal first data packets, the data volume of each first data packet is not equal. Then, a first hidden data is determined in each first data packet. The determination of the hidden data can randomly mark a data as the first hidden data in each first data packet according to the data annotation method, and the annotation rule is only stored on the server side. Then, all the first data packets are sorted out of order and the corresponding first sorting rule is obtained. The first hidden data in each first data packet is extracted. Based on the first sorting rule, all the first hidden data are sorted to form a first hidden data chain, and the first hidden data chain is packed into a first hidden data packet and inserted into the sequence of the first data packets to play the role of confusing the data.
[0073] In this example, a rule for determining the first hidden data is given, including:
[0074] Sort all the first data packets in ascending order of data volume. The sorted first data packets are {B1, B2,..., B M};
[0075] Obtain the data volume of the first data packet B1 as B 1n , and judge whether B 1n is an even number. If so, use the data of (B 1n / 2 + 1) as the first hidden data of the first data packet B1. If not, use the data of (B 1n - 1) / 2 as the first hidden data of the first data packet B1;
[0076] Obtain the data volume of the second data packet B2 as B 2n . If B 2n is an even number, use the data of (B 1n / 2 - 1) as the first hidden data of the first data packet B2. If B 2n is an odd number, use the data of (B 1n + 1) / 2 as the first hidden data of the second data packet B2;
[0077] Obtain the data volume of the third data packet B3 as B 3n . If B 3n is an even number, use the data of (B 3n / 2 + 1) as the first hidden data of the first data packet B3. If B 3n is an odd number, use the data of (B 3n - 1) / 2 as the first hidden data of the second data packet B3;
[0078] ......
[0079] Obtain the data volume of the Mth data packet B M as B Mn, if M is even, if B Mn is even, then use the data of (B Mn / 2 - 1) as the first hidden data of the first data packet B M . If B Mn is odd, then use the data of (B Mn +1) / 2 as the first hidden data of the second data packet B M . If M is odd, if B Mn is even, then use the data of (B Mn / 2 + 1) as the first hidden data of the first data packet B M . If B Mn is odd, then use the data of (B Mn -1) / 2 as the first hidden data of the second data packet B M .
[0080] Among them, for the first data packets with odd sorting serial numbers, the determination rules of their first hidden data are the same, and for the first data packets with even sorting serial numbers, the determination rules of their first hidden data are the same. Additionally, it should be noted that the determination rules of the second hidden data in the second data packets are also the same as those of the first hidden data, and will not be elaborated further hereinafter.
[0081] Furthermore, this example also provides the reuse of all the first sorting rules, including:
[0082] Set up a first database on both the client and the preset server. The first database is used to collect all the first sorting rules of the first data packets;
[0083] When performing out-of-order sorting on all the first data packets subsequently, randomly obtain a first sorting rule from the first database and denote it as the third sorting rule;
[0084] Based on the third sorting rule, sort all the first data packets.
[0085] Split each first data packet into several equal second data packets, and perform encryption processing on all the second data packets using a second method to obtain a second processing result. The second method includes:
[0086] Determine a second hidden data in each second data packet, perform out-of-order sorting on all the second data packets in a single first data packet and obtain the corresponding second sorting rule;
[0087] Extract the second hidden data of each second data packet in a single first data packet, based on the second sorting rule, sort all the second hidden data to form a second hidden data chain, and pack the second hidden data chain into a second hidden data packet and randomly insert it into the sequence of the second data packets in a single first data packet.
[0088] Among them, if equal splitting is performed on M first data packets, each first data packet is split into several equal second data packets; then, for a single first data packet, a second hidden data is determined in each second data packet, the second data packets are sorted out of order and the corresponding second sorting rule is obtained, the second hidden data of each second data packet in a single first data packet is extracted, and based on the second sorting rule, all the second hidden data are sorted to form a second hidden data chain, and the second hidden data chain is packed into a second hidden data packet and inserted into the first data packet as obfuscated data.
[0089] Furthermore, this example also provides for the reuse of all the second sorting rules, including:
[0090] A second database is set up in both the client and the preset server, and the second database is used to collect the second sorting rules of all the second data packets;
[0091] When subsequent out-of-order sorting is performed on all the second data packets in a single first data packet, a second sorting rule is randomly obtained from the second database and denoted as the fourth sorting rule;
[0092] Based on the fourth sorting rule, all the second data packets in a single first data packet are sorted.
[0093] The data encryption algorithm in this embodiment has security and complexity. Next, it will be described in conjunction with decrypting the target encrypted data. The preset server decrypts the target encrypted data as follows:
[0094] Obtain the key, and perform primary decryption on the target encrypted data to obtain primary target decryption data;
[0095] Based on the data capacity, perform data screening on the primary target decryption data, and place the second data packets with the same data capacity in the same set;
[0096] Based on the second hidden data chain, reorganize all the second data packets in the corresponding set to obtain the corresponding first data packet;
[0097] Based on the first hidden data chain, reorganize all the first data packets to obtain the final target decryption data.
[0098] Furthermore, the method further includes:
[0099] Perform random multi-channel transmission on the target encrypted data, and the number of channels is greater than or equal to 2.
[0100] Among them, in this embodiment, encryption is first performed using the encryption key in the RSA key. When decryption is required, the decryption key in the RSA key is also required for decryption first. Then, the initial encrypted data is split twice. The first split is into several unequal first data packets, and the second split is to split each first data packet into equal second data packets. The concept of hidden data is introduced for the first data packets and the second data packets. The determination rules for the hidden data have also been elaborated in the embodiment. Then, the generated first hidden data chain and second hidden data chain also constitute the confused data, and at the same time, a random multi-channel transmission method is adopted.
[0101] Therefore, when the target encrypted data is intercepted and cracked, first, due to the use of random multi-channel transmission, the possibility of the complete data being intercepted is greatly reduced. When all the data is intercepted, the cracker first needs to screen the confused data, and the confused data is the data packet formed by packing the first hidden data chain and the second hidden data chain. The cracker needs to spend a lot of time screening the confused data. After the screening is completed, since all the target encrypted data is transmitted in several second data packets at this time, the cracker needs to sieve all the second data packets, sieve the second data packets belonging to the same first data packet, and after the screening is completed, all the second data packets need to be arranged and combined to obtain the corresponding first data packet. Then, all the first data packets also need to be arranged and combined to crack the target encrypted data. It can be seen that if the target encrypted data is to be cracked by brute force, without knowing the rules of the second split, the second sorting, and the determination rules of the hidden data, the required workload and time will increase exponentially. Therefore, the security of the data to be transmitted is greatly guaranteed.
[0102] Embodiment 2
[0103] Please refer to Figure 2 , Figure 2 which is a schematic diagram of the composition of an encryption system for data transmission between information systems in the present invention. The system includes:
[0104] An acquisition unit, configured to acquire the data to be transmitted and the key of the client;
[0105] An initial encryption unit, configured to encrypt the data to be transmitted based on the key to obtain initial encrypted data;
[0106] A first split unit, configured to split the initial encrypted data into several unequal first data packets;
[0107] A second split unit, configured to split each first data packet into several equal second data packets;
[0108] The first encryption unit encrypts the first data packet using a first method to obtain a first processing result;
[0109] The second encryption unit encrypts the second data packet using a second method to obtain a second processing result;
[0110] The generation unit is configured to generate target encrypted data based on the first processing result and the second processing result;
[0111] The transmission unit is configured to transmit the target encrypted data to a preset server.
[0112] Although the preferred embodiments of the present invention have been described, additional changes and modifications can be made by those skilled in the art once they learn the basic creative concept. Therefore, the appended claims are intended to be construed to include the preferred embodiments as well as all changes and modifications that fall within the scope of the present invention.
[0113] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these modifications and variations.
Claims
1. An encryption method for data transmission between information systems, characterized in that, The method includes the following steps: Obtain the data to be transmitted and the secret key of the client; Based on the secret key, encrypt the data to be transmitted to obtain initial encrypted data; Split the initial encrypted data into several unequal first data packets; Split each first data packet into several equal second data packets; Use the first method to encrypt the first data packet to obtain a first processing result; Use the second method to encrypt the second data packet to obtain a second processing result; Based on the first processing result and the second processing result, generate target encrypted data; Transmit the target encrypted data to a preset server; The preset server decrypts the target encrypted data; The first method includes: Determine a first hidden data in each first data packet, perform out-of-order sorting on all first data packets and obtain the corresponding first sorting rule; Extract the first hidden data in each first data packet, based on the first sorting rule, sort all the first hidden data to form a first hidden data chain, pack the first hidden data chain into a first hidden data packet and randomly insert it into the sequence of the first data packets; The second method includes: Determine a second hidden data in each second data packet, perform out-of-order sorting on all second data packets in a single first data packet and obtain the corresponding second sorting rule; Extract the second hidden data of each second data packet in a single first data packet, based on the second sorting rule, sort all the second hidden data to form a second hidden data chain, pack the second hidden data chain into a second hidden data packet and randomly insert it into the sequence of the second data packets in a single first data packet; The preset server decrypting the target encrypted data includes: Obtain the secret key, perform initial decryption on the target encrypted data to obtain a first target decryption data; Based on the data capacity, perform data screening on the first target decryption data, and place the second data packets with the same data capacity in the same set; Based on the second hidden data chain, reorganize all the second data packets in the corresponding set to obtain the corresponding first data packet; Based on the first hidden data chain, reorganize all the first data packets to obtain the final target decryption data.
2. The encryption method for data transmission between information systems according to claim 1, characterized in that, The method further includes: Set a first database on both the client and the preset server, and the first database is used to collect the first sorting rules of all first data packets; When performing out-of-order sorting on all first data packets subsequently, randomly obtain a first sorting rule from the first database and denote it as a third sorting rule; Based on the third sorting rule, sort all first data packets.
3. An encryption method for data transmission between information systems according to claim 1, characterized in that, The method further includes: Set a second database on both the client and the preset server, and the second database is used to collect the second sorting rules of all second data packets; When performing out-of-order sorting on all second data packets in a single first data packet subsequently, randomly obtain a second sorting rule from the second database and denote it as a fourth sorting rule; Based on the fourth sorting rule, sort all second data packets in a single first data packet.
4. An encryption method for data transmission between information systems according to claim 1, characterized in that, The method further includes: Random multi-channel transmission is performed on the target encrypted data, and the number of channels is greater than or equal to 2.
5. An encryption method for data transmission between information systems according to claim 1, characterized in that, The key uses an RSA key.
6. An encryption system for data transmission between information systems, adopting an encryption method for data transmission between information systems as described in claim 1, characterized in that, The system includes: An acquisition unit for acquiring the data to be transmitted and the key of the client; An initial encryption unit for encrypting the data to be transmitted based on the key to obtain initial encrypted data; A first splitting unit for splitting the initial encrypted data into a plurality of unequal first data packets; A second splitting unit for splitting each first data packet into a plurality of equal second data packets; A first encryption unit for encrypting the first data packet by using a first method to obtain a first processing result; A second encryption unit for encrypting the second data packet by using a second method to obtain a second processing result; A generation unit for generating target encrypted data based on the first processing result and the second processing result; A transmission unit for transmitting the target encrypted data to a preset server; A decryption unit for decrypting the target encrypted data by the preset server.
Citation Information
Patent Citations
A method for encrypted data transmission
CN108989324B
Data storage method and system
CN106156653A
Data transmission method, data receiving method, remote printing system and mobile terminal
CN109379380A
Network security protection method for converged media platform
CN116318889A