Data transmission method and device

By combining geolocation verification and multi-factor authentication, and utilizing VPN tunnels for data transmission, the problem of insufficient data transmission security in existing technologies is solved, achieving highly secure and efficient data transmission.

CN119583141BActive Publication Date: 2025-12-05AGRICULTURAL BANK OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411691149.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-22
Publication Date
2025-12-05
Estimated Expiration
2044-11-22

AI Technical Summary

Technical Problem

Existing technologies rely on a single method for verifying data transmission, which poses security risks and makes it difficult to guarantee the security of data transmission.

Method used

By combining geolocation verification and multi-factor authentication, VPN tunnels are used for data transmission, ensuring that only terminal devices within a preset area and with verified identities can establish VPN tunnels for data transmission.

Benefits of technology

It significantly improves the security of data transmission, reduces the risk of data leakage, enhances the user experience, and simplifies the operation process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119583141B_ABST
    Figure CN119583141B_ABST
Patent Text Reader

Abstract

The application provides a data transmission method and device. In the method, when a user performs a terminal device data transmission operation, the terminal device first sends a current position of the terminal device to a server, and continues to send identity authentication information to the server when a first verification result returned by the server indicates that the terminal device is currently in a preset area. Then, if a second verification result returned by the server indicates that the identity authentication information passes identity authentication, a VPN channel establishment request is sent to the server. Finally, if an establishment result of the VPN channel returned by the server indicates that the VPN channel is successfully established, data transmission is performed with a target terminal device through the VPN channel. The method realizes safe transmission of message data between different terminal devices, and improves the data transmission efficiency without complex operations of the user.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data transmission technology, and in particular to a data transmission method and device. Background Technology

[0002] In today's information society, data file transmission has become a fundamental aspect of various businesses and applications. Data transmission enables the rapid flow of information between different devices, locations, and users. However, because data files may contain personal privacy or corporate secrets, interception or tampering during transmission can lead to serious economic losses or reputational crises. Therefore, ensuring the efficient and secure transmission of data files is of paramount importance.

[0003] In existing technologies, data transmission is usually carried out online using the Secure File Transfer Protocol (SFTP). First, a person needs to log in to the server of the data receiving department using the corresponding username and password via SFTP, and then transfer the relevant data files to the designated directory.

[0004] However, existing verification methods are simplistic and pose certain security risks, making it difficult to guarantee the security of data transmission. Summary of the Invention

[0005] This application provides a data transmission method and device to solve the problem that existing data transmission methods have a single verification method, certain security risks, and difficulty in ensuring the security of data transmission.

[0006] In a first aspect, embodiments of this application provide a data transmission method applied to a terminal device, comprising:

[0007] In response to the user's data transmission operation, the current location of the terminal device is sent to the server;

[0008] The terminal device receives a first verification result returned by the server, the first verification result being used to indicate whether the terminal device is currently within a preset area;

[0009] If the first verification result indicates that the terminal device is currently in the preset area, then identity authentication information is sent to the server;

[0010] Receive the second verification result corresponding to the identity authentication information returned by the server;

[0011] If the second verification result indicates that the identity authentication information has passed the identity authentication, then a VPN tunnel establishment request is sent to the server;

[0012] Receive the VPN tunnel establishment result returned by the server;

[0013] If the establishment result indicates that the VPN tunnel has been successfully established, then data transmission is performed with the target terminal device through the VPN tunnel.

[0014] In one possible implementation, sending authentication information to the server includes:

[0015] Obtain the username and corresponding password entered by the user;

[0016] Send the account and password to the server;

[0017] Receive the first sub-verification result returned by the server for the account and the password;

[0018] When the first sub-verification result indicates that the verification is successful, the user's facial video is captured through the camera;

[0019] Send the facial video to the server;

[0020] The facial video, the account, and the password corresponding to the account are all part of the identity authentication information.

[0021] In one possible implementation, the step of capturing the user's facial video via a camera when the first sub-verification result indicates that the verification has passed includes:

[0022] When the first sub-verification result indicates that the verification is successful, in response to the user's input operation for the transmission password, the transmission password is sent to the server;

[0023] Receive the second sub-verification result returned by the server for the transmitted password.

[0024] In one possible implementation, the method further includes:

[0025] If the first verification result indicates that the terminal device is not currently in the preset area, a first warning message is output, which is used to remind the user to move the terminal device to the preset area.

[0026] If the second verification result indicates that the identity authentication information has failed the authentication, a second warning message is output. The second warning message is used to remind the user that data transmission is not possible.

[0027] In a first aspect, embodiments of this application provide a data transmission method applied to a server, comprising:

[0028] The terminal device receives the current location of the terminal device.

[0029] Determine whether the current location of the terminal device is within a preset area, and send a first verification result to the terminal device;

[0030] If the first verification result indicates that the terminal device is currently within the preset area, then the identity authentication information sent by the terminal device is received;

[0031] Based on the pre-stored target identity authentication information, the identity authentication information is authenticated, and a second verification result is sent to the terminal device.

[0032] If the second verification result indicates that the identity authentication information has passed the identity authentication, then a VPN tunnel establishment request sent by the terminal device is received;

[0033] The VPN tunnel requested by the terminal device is matched with the VPN tunnel requested by the target terminal device, and the VPN tunnel establishment result is returned to the terminal device. The target terminal device is the terminal device that the terminal device requested to transmit data.

[0034] In one possible implementation, the identity authentication information includes a facial video, an account, and a password corresponding to the account.

[0035] In one possible implementation, the authentication information further includes a transmission password.

[0036] Thirdly, embodiments of this application provide a data transmission apparatus, which is applied to a terminal device and includes:

[0037] The sending module is used to send the current location of the terminal device to the server in response to the user's data transmission operation;

[0038] The receiving module is configured to receive a first verification result returned by the server, wherein the first verification result is used to indicate whether the terminal device is currently in a preset area;

[0039] The sending module is further configured to send identity authentication information to the server if the first verification result indicates that the terminal device is currently in the preset area;

[0040] The receiving module is also used to receive the second verification result corresponding to the identity authentication information returned by the server;

[0041] The sending module is further configured to send a VPN tunnel establishment request to the server if the second verification result indicates that the identity authentication information has passed identity authentication;

[0042] The receiving module is also used to receive the VPN tunnel establishment result returned by the server;

[0043] The transmission module is used to transmit data with the target terminal device through the VPN channel if the establishment result indicates that the VPN channel has been successfully established.

[0044] In one possible implementation, the data transmission device further includes a processing device, the processing module being specifically used for:

[0045] Obtain the username and corresponding password entered by the user;

[0046] Send the account and password to the server;

[0047] Receive the first sub-verification result returned by the server for the account and the password;

[0048] When the first sub-verification result indicates that the verification is successful, the user's facial video is captured through the camera;

[0049] Send the facial video to the server;

[0050] The facial video, the account, and the password corresponding to the account are all part of the identity authentication information.

[0051] In one possible implementation, the processing module is specifically used for:

[0052] When the first sub-verification result indicates that the verification is successful, in response to the user's input operation for the transmission password, the transmission password is sent to the server;

[0053] Receive the second sub-verification result returned by the server for the transmitted password.

[0054] In one possible implementation, the processing module is further configured to:

[0055] If the first verification result indicates that the terminal device is not currently in the preset area, a first warning message is output, which is used to remind the user to move the terminal device to the preset area.

[0056] If the second verification result indicates that the identity authentication information has failed the authentication, a second warning message is output. The second warning message is used to remind the user that data transmission is not possible.

[0057] Fourthly, embodiments of this application provide a data transmission apparatus, which is applied to a server and includes:

[0058] A receiving module is used to receive the current location of the terminal device sent by the terminal device;

[0059] The processing module is used to determine whether the current location of the terminal device is within a preset area and to send a first verification result to the terminal device;

[0060] The receiving module is further configured to receive identity authentication information sent by the terminal device if the first verification result indicates that the terminal device is currently in the preset area;

[0061] The processing module is further configured to perform identity authentication on the pre-stored target identity authentication information and send a second verification result to the terminal device;

[0062] The receiving module is further configured to receive a VPN tunnel establishment request sent by the terminal device if the second verification result indicates that the identity authentication information has passed identity authentication;

[0063] The processing module is further configured to match the VPN channel requested by the terminal device with the VPN channel requested by the target terminal device, and return the VPN channel establishment result to the terminal device, wherein the target terminal device is the terminal device to which the terminal device requests data transmission.

[0064] In one possible implementation, the identity authentication information includes a facial video, an account, and a password corresponding to the account.

[0065] In one possible implementation, the authentication information further includes a transmission password.

[0066] Fifthly, embodiments of this application provide an electronic device, including: a memory and a processor;

[0067] The memory stores computer-executed instructions;

[0068] The processor executes computer execution instructions stored in the memory, causing the processor to perform the first aspect and / or various possible implementations of the first aspect as described above.

[0069] This application provides a data transmission method and apparatus. In this method, when a user performs data transmission operation on a terminal device, the terminal device first sends its current location to the server. When the server returns a first verification result indicating that the terminal device is currently within a preset area, it continues to send authentication information to the server. This geographical restriction ensures that only terminal devices within the preset area can begin further operations, adding a layer of access control. Subsequently, if the server returns a second verification result indicating that the authentication information has passed authentication, a VPN tunnel establishment request is sent to the server. By combining location verification and authentication, a dual authentication mechanism of "region + identity" is formed, significantly improving the security of data transmission. Finally, if the server returns a VPN tunnel establishment result indicating that the VPN tunnel has been successfully established, data is transmitted to the target terminal device through the VPN tunnel. Furthermore, the encrypted communication provided by the VPN tunnel ensures that the data is not eavesdropped on or tampered with during transmission. This method achieves secure transmission of message data between different terminal devices, and eliminates the need for complex user operations during data verification, improving data transmission efficiency and user experience. Attached Figure Description

[0070] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0071] Figure 1 A schematic diagram of the data transmission system provided in the embodiments of this application;

[0072] Figure 2 This is a schematic diagram of the appearance of the terminal device provided in the embodiments of this application;

[0073] Figure 3 A flowchart illustrating the data transmission method provided in the embodiments of this application. Figure 1 ;

[0074] Figure 4 A flowchart illustrating the data transmission method provided in the embodiments of this application. Figure 2 ;

[0075] Figure 5 Schematic diagram of the data transmission device provided in the embodiments of this application Figure 1 ;

[0076] Figure 6 Schematic diagram of the data transmission device provided in the embodiments of this application Figure 2 ;

[0077] Figure 7 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application.

[0078] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation

[0079] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0080] In today's information society, data file transmission has become a fundamental aspect of various businesses and applications. Data transmission enables the rapid flow of information between different devices, locations, and users. However, because data files may contain personal privacy or corporate secrets, interception or tampering during transmission can lead to serious economic losses or reputational crises. Therefore, ensuring the efficient and secure transmission of data files is of paramount importance.

[0081] In existing technologies, data transmission is usually carried out online using the Secure File Transfer Protocol (SFTP). First, a person needs to log in to the server of the data receiving department using the corresponding username and password via SFTP, and then transfer the relevant data files to the designated directory.

[0082] However, existing verification methods are simplistic, relying solely on usernames and passwords for verification. This can easily lead to password leaks and data tampering. Multiple users may share the same username and password, posing a security risk. Furthermore, it cannot distinguish the specific user and makes it difficult to guarantee the security of data transmission.

[0083] Based on this, this application provides a data transmission method. Existing data transmission methods rely solely on "username + password" for authentication, which fails to ensure the uniqueness of the user and confirm whether the operation was performed by the user themselves. To ensure data transmission security, various authentication methods can be used to safeguard user identity and data transmission security. First, to ensure the security of the user's terminal device, the current location of the device is verified. Next, the user's identity is uniquely verified; since biometrics are uncopyable and tamper-proof, authentication information is required before data transmission. Furthermore, to prevent attacks and tampering during transmission, the Virtual Private Network (VPN) channel is verified. Thus, by combining authentication information, geographical location information, and the VPN channel, it is possible to determine the user's identity and ensure the security of the device and data transmission channel. This significantly improves data transmission security, reduces the risk of data leakage, and the entire verification process is seamless, requiring no complex user operations, thus enhancing the user experience and increasing data transmission efficiency.

[0084] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.

[0085] Figure 1 This is a schematic diagram of the data transmission system provided in the embodiments of this application; as shown below. Figure 1 As shown, the data transmission method provided in this application can be applied to a data transmission system, which includes: a terminal device, a server, and a web page. The terminal device includes a data sending end and a data receiving end.

[0086] Both the data sending and receiving ends include a location authentication unit, an identity information authentication unit, a video and audio unit, an early warning detection unit, a VPN communication unit, a data input unit, and a storage unit. The location authentication unit primarily acquires location information for the data sending end of the terminal device. When the location information matches the preset area information of the terminal device, the sending end device can be used normally. The identity information authentication unit is mainly responsible for acquiring the identity information of the user of the data sending end and sending it to the server. When the username, password, and facial information are all successfully verified, the terminal device can be used normally. The video and audio unit is mainly used to acquire facial recognition input, video information, and audio information. The early warning detection unit is mainly responsible for checking and issuing alerts regarding the authentication results of the identity information (second verification result) and the location information (first verification result). The VPN communication unit is mainly used for the data sending and receiving ends to send corresponding VPN tunnel establishment requests to the server. The data input unit supports hard drives and flash drives with USB interfaces. The storage unit stores real-time video and audio information.

[0087] The server includes a control unit, which is mainly used to authenticate the current location, identity authentication information, and VPN tunnel establishment request of the terminal device sent by the data sender, and to provide feedback on the verification results. It also provides access control for the data sender and receiver on the web page.

[0088] The web interface includes an information configuration unit, which is mainly used to preset the location information of the terminal device, enter the identity authentication information of the terminal device user and the VPN tunnel information, and send them to the server for storage.

[0089] Figure 2 This is a schematic diagram of the appearance of the terminal device provided in the embodiments of this application; as shown below. Figure 2 As shown in the schematic diagram, Figure 2 (a) in the figure is a bottom view. Figure 2 (b) in the image is the right view. Figure 2 (c) in the diagram is the front view. Figure 2 (d) in the figure represents the left view. Figure 2 (e) in the figure represents the top view. Figure 2 (f) in the figure represents the side view. Figure 2 (g) in the diagram represents the rear view.

[0090] Figure 3 A flowchart illustrating the data transmission method provided in the embodiments of this application. Figure 1 ;like Figure 3 As shown, the method includes:

[0091] S301. In response to the user's data transmission operation, send the current location of the terminal device to the server.

[0092] The execution subject of this application embodiment is an electronic device, which can be a terminal device or a server. The terminal device can be a laptop, desktop computer, tablet computer, etc. This application embodiment does not impose specific limitations.

[0093] It should be noted that since the data input unit is used to support hard drives and flash drives with USB interfaces, when a user receives a data reporting task and needs to use the terminal device to perform data transmission operations, the user needs to connect the reporting hard drive or flash drive containing the reporting file to the terminal device. At this time, the terminal device will trigger the location information authentication unit to send the current location information of the terminal device to the server for verification.

[0094] For the server, it receives the current location of the terminal device sent by the terminal device.

[0095] S302. Determine whether the current location of the terminal device is within the preset area, and send the first verification result to the terminal device.

[0096] The first verification result is used to indicate whether the terminal device is currently within a preset area. The preset area can be a specific location (such as location coordinates, a specific office location, etc.) or a certain area range (such as a circular area within a preset radius centered on the office building). The specific preset area is determined according to the actual situation, and this application embodiment does not impose specific limitations.

[0097] In this step, after receiving the current location of the terminal device sent by the terminal device, the server compares it with the preset area of ​​the terminal device stored on the server to determine whether the current location of the terminal device is within the preset area. If it is, the server sends a first verification result containing successful verification to the terminal device; otherwise, the server sends a first verification result containing failed verification to the terminal device.

[0098] S303. If the first verification result indicates that the terminal device is currently in a preset area, then send identity authentication information to the server.

[0099] The identity verification information includes facial video, account, and the password corresponding to the account.

[0100] Optionally, when the first verification result indicates that the terminal device is not currently within the preset area, a first warning message is output.

[0101] The first warning message is used to remind the user to move the terminal device to the preset area.

[0102] It should be noted that when the first verification result indicates that the terminal device is not currently within the preset area, it means that the terminal device has shifted, which may pose a certain risk. Therefore, the terminal device will issue a first warning message, namely, "This device is not being used in the designated safe location and is temporarily unavailable. Please move this device to the designated location!" This is to remind the user to adjust the location and re-verify the location information.

[0103] Optionally, after the first verification result indicates that the terminal device is currently within a preset area, the terminal device uses the video and audio unit to record video and audio of the user and stores it in the storage unit. Afterwards, the web page can retrieve the corresponding video and audio recordings from the storage unit for review and comparison. In this way, the data transmission process is auditable and traceable, further improving the security of data transmission.

[0104] Understandably, when the first verification result indicates that the terminal device is currently within a preset area, meaning the current location information of the terminal device matches the preset location information, the terminal device can be used normally for the next step of identity authentication. This method avoids erroneous operations caused by incorrect device location and the risk of device misuse.

[0105] S304. The server performs identity authentication on the pre-stored target identity authentication information and sends the second verification result to the terminal device.

[0106] In this step, the server pre-stores the target identity authentication information and verifies the facial video, account, and corresponding password in the identity authentication information sent by the terminal device one by one. Only when all the information in the identity authentication information passes the authentication will the second verification result indicate that the identity authentication information has passed the authentication; otherwise, the second verification result indicates that the identity authentication information has failed the authentication.

[0107] By using facial video, account, and password for authentication, it effectively prevents single-factor attacks (such as the security risk of relying solely on password cracking); and ensures the identity of the user, thus improving the security of data transmission.

[0108] S305. If the second verification result indicates that the identity authentication information has passed the identity authentication, then send a VPN tunnel establishment request to the server.

[0109] In one possible implementation, if the second verification result indicates that the identity authentication information has failed authentication, a second warning message is output.

[0110] The second warning message is used to remind the user that data transmission is unsuccessful. This warning can be issued through an audible alert, a visual alert (e.g., a flashing red light), or a text alert displayed on the screen. The text alert can include the specific reason for the failure, such as "incorrect password" or "facial recognition not matched," allowing the user to quickly pinpoint the problem. The specific method of notification can be determined based on actual circumstances, and this embodiment does not impose any specific limitations.

[0111] In this step, the terminal device can only send a VPN tunnel establishment request to the server when the second verification result indicates that the identity authentication information has passed the authentication. This effectively prevents unauthorized devices or attackers from establishing fake VPN tunnels and protects network security. Conversely, when the second verification result indicates that the identity authentication information has failed the authentication, the terminal device will output an intuitive second warning message to the user.

[0112] S306. The server matches the VPN tunnel requested by the terminal device with the VPN tunnel requested by the target terminal device, and returns the VPN tunnel establishment result to the terminal device.

[0113] The target terminal device is the terminal device that requests data transmission from the terminal device.

[0114] Understandably, by matching the VPN request from the terminal device with the VPN tunnel established by the target terminal device, the server ensures that the established VPN tunnel is a clear connection requirement from both parties, rather than an accidental or malicious connection, thus preventing incorrect connections to non-target devices and improving the security and accuracy of data transmission.

[0115] S307. If the establishment result indicates that the VPN tunnel has been successfully established, then data transmission is performed with the target terminal device through the VPN tunnel.

[0116] It should be noted that if the VPN tunnel establishment result indicates failure, it means that the VPN tunnel requests from both parties are not compatible. In this case, the terminal device still needs to issue a warning message to remind the user that data transfer is not possible. It should also be noted that after the user completes the data transfer task, they can simply remove the hard drive or USB flash drive from the terminal device and shut it down; no other complex logout procedures are required.

[0117] Understandably, by authenticating users of terminal devices in three ways—location information, identity information, and VPN tunnel establishment requests—not only can multi-dimensional security verification be achieved, but the complexity of user operations is also reduced, ensuring data transmission security while improving data transmission efficiency.

[0118] This application provides a data transmission method in which, when a user performs data transmission operations on a terminal device, the terminal device first sends its current location to the server. If the server returns a first verification result indicating that the terminal device is currently within a preset area, it continues to send authentication information to the server. This geographical restriction ensures that only terminal devices within the preset area can begin further operations, adding a layer of access control. Subsequently, if the server returns a second verification result indicating that the authentication information has passed authentication, a VPN tunnel establishment request is sent to the server. By combining location verification and authentication, a dual authentication mechanism of "region + identity" is formed, significantly improving the security of data transmission. Finally, if the server returns a VPN tunnel establishment result indicating that the VPN tunnel has been successfully established, data is transmitted to the target terminal device through the VPN tunnel. Furthermore, the encrypted communication provided by the VPN tunnel ensures that the data is not eavesdropped on or tampered with during transmission. This method achieves secure transmission of message data between different terminal devices, and eliminates the need for complex user operations during data verification, improving data transmission efficiency and user experience.

[0119] Figure 4 A flowchart illustrating the data transmission method provided in the embodiments of this application. Figure 2 ;like Figure 4 As shown, the embodiments of this application are in Figure 3 Based on this, the specific process of identity information authentication is explained in detail, including:

[0120] S401. Obtain the user's entered account and corresponding password.

[0121] In this step, when the terminal device needs to send authentication information to the server, the terminal device displays an input interface on the screen. The user enters their account and corresponding password in the input area through this screen. Then, the terminal device responds to the user's input to obtain the user's entered account and corresponding password.

[0122] S402, Send the account and password to the server.

[0123] S403. Based on the pre-stored target identity authentication information, perform identity authentication on the identity authentication information and send the first sub-verification result to the terminal device.

[0124] In this step, the server pre-stores the target identity authentication information and authenticates the account and the corresponding password in the identity authentication information sent by the terminal device. Only when the account and the corresponding password are authenticated will the first sub-verification result indicate that the identity authentication information has passed the authentication; otherwise, the first sub-verification result indicates that the identity authentication information has failed the authentication.

[0125] Among them, facial video, account, and the corresponding password are identity authentication information.

[0126] S404. When the first sub-verification result indicates that the verification is successful, in response to the user's input operation for the transmission password, send the transmission password to the server.

[0127] The identity authentication information also includes the transmission password.

[0128] It should be noted that the method by which the terminal device obtains the transmission password is the same as the method by which the account and password are obtained in S401 above, and will not be described in detail here.

[0129] S405. Based on the pre-stored target identity authentication information, perform identity authentication on the identity authentication information and send the second sub-verification result to the terminal device.

[0130] Understandably, the server pre-stores the transmission password of the target identity authentication information and authenticates the transmission password in the identity authentication information sent by the terminal device. Only when the transmission password is authenticated will the second sub-verification result indicate that the identity authentication information has passed the authentication; otherwise, the second sub-verification result indicates that the identity authentication information has failed the authentication.

[0131] Figure 5 Schematic diagram of the data transmission device provided in the embodiments of this application Figure 1 Applied to terminal devices, such as Figure 5 As shown, the data transmission device 50 includes:

[0132] The sending module 501 is used to send the current location of the terminal device to the server in response to the user's data transmission operation;

[0133] The receiving module 502 is used to receive the first verification result returned by the server. The first verification result is used to indicate whether the terminal device is currently in a preset area.

[0134] The sending module 501 is also used to send identity authentication information to the server if the first verification result indicates that the terminal device is currently in a preset area;

[0135] The receiving module 502 is also used to receive the second verification result corresponding to the identity authentication information returned by the server;

[0136] The sending module 501 is also used to send a VPN tunnel establishment request to the server if the second verification result indicates that the identity authentication information has passed the identity authentication.

[0137] The receiving module 501 is also used to receive the VPN tunnel establishment result returned by the server;

[0138] The transmission module 503 is used to transmit data with the target terminal device through the VPN tunnel if the establishment result indicates that the VPN tunnel has been successfully established.

[0139] In one possible implementation, the data transmission apparatus further includes a processing unit, wherein the processing module is specifically used for:

[0140] Obtain the user's entered username and corresponding password;

[0141] Send the username and password to the server;

[0142] Receive the first sub-verification result returned by the server for the account and password;

[0143] When the first sub-verification result indicates that the verification has passed, the user's facial video is captured via camera;

[0144] Send facial video to the server;

[0145] Among them, facial video, account, and the corresponding password are identity authentication information.

[0146] In one possible implementation, the processing module is specifically used for:

[0147] When the first sub-verification result indicates that the verification is successful, in response to the user's input of the transmission password, the transmission password is sent to the server.

[0148] Receive the second sub-verification result returned by the server for the transmitted password.

[0149] In one possible implementation, the processing module is also used for:

[0150] If the first verification result indicates that the terminal device is not currently in the preset area, a first warning message is output. The first warning message is used to remind the user to move the terminal device to the preset area.

[0151] If the second verification result indicates that the identity authentication information has failed authentication, a second warning message will be output. The second warning message is used to remind the user that data transmission operations cannot be performed.

[0152] Figure 6 Schematic diagram of the data transmission device provided in the embodiments of this application Figure 2 Applied to servers, such as Figure 6 As shown, the data transmission device 60 includes:

[0153] The receiving module 601 is used to receive the current location of the terminal device sent by the terminal device;

[0154] Processing module 602 is used to determine whether the current location of the terminal device is within a preset area and to send the first verification result to the terminal device;

[0155] The receiving module 601 is further configured to receive the identity authentication information sent by the terminal device if the first verification result indicates that the terminal device is currently in a preset area;

[0156] The processing module 602 is also used to perform identity authentication on the pre-stored target identity authentication information and send the second verification result to the terminal device;

[0157] The receiving module 601 is further configured to receive a VPN tunnel establishment request sent by the terminal device if the second verification result indicates that the identity authentication information has passed the identity authentication.

[0158] The processing module 602 is also used to match the VPN tunnel requested by the terminal device with the VPN tunnel requested by the target terminal device, and return the VPN tunnel establishment result to the terminal device, where the target terminal device is the terminal device that the terminal device requested to transmit data.

[0159] In one possible approach, the authentication information includes facial video, account, and the password corresponding to the account.

[0160] In one possible approach, the authentication information also includes a transmission password.

[0161] The data transmission device provided in this embodiment can execute the method provided in the above method embodiment. Its implementation principle and technical effect are similar, and will not be described in detail here.

[0162] Figure 7 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Figure 7 As shown, the electronic device 70 provided in this embodiment includes at least one processor 701 and a memory 702. Optionally, the device 70 further includes a communication component 703. The processor 701, memory 702, and communication component 703 are connected via a bus 704.

[0163] In a specific implementation, at least one processor 701 executes computer execution instructions stored in memory 702, causing at least one processor 701 to perform the above-described method.

[0164] The specific implementation process of processor 701 can be found in the above method embodiments, and its implementation principle and technical effect are similar. It will not be repeated here.

[0165] The electronic device provided in this application embodiment can be implemented as Figure 3The terminal device and server in the above method embodiment are used to execute the data transmission method provided by any of the above method embodiments. The implementation principle and technical effect are similar, and will not be repeated here.

[0166] In the above embodiments, it should be understood that the processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this invention can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules within the processor.

[0167] The memory may include random access memory (RAM) and may also include non-volatile memory (NVM), such as at least one disk storage device.

[0168] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of illustration, the buses shown in the accompanying drawings are not limited to a single bus or a single type of bus.

[0169] The division of units is merely a logical functional division; in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or units, and may be electrical, mechanical, or other forms.

[0170] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0171] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0172] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0173] Those skilled in the art will understand that all or part of the steps of the above-described method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments; and the aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.

[0174] Finally, it should be noted that other embodiments of the invention will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This invention is intended to cover any variations, uses, or adaptations of the invention that follow the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein, and is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of the invention is limited only by the appended claims.

Claims

1. A data transmission method, characterized by, The method applied to a terminal device comprises: In response to a data transmission operation of a user, sending a current location of the terminal device to a server; Receiving a first verification result returned by the server, the first verification result being used to indicate whether the terminal device is currently in a preset area; If the first verification result indicates that the terminal device is currently in the preset area, sending identity authentication information to the server; Receiving a second verification result corresponding to the identity authentication information returned by the server; If the second verification result indicates that the identity authentication information passes identity authentication, sending a virtual private network (VPN) channel establishment request to the server; Receiving an establishment result of the VPN channel returned by the server; If the establishment result indicates that the VPN channel is established successfully, performing data transmission with a target terminal device through the VPN channel.

2. The method of claim 1, wherein, The sending of the identity authentication information to the server comprises: Obtaining an account and a corresponding password input by the user; Sending the account and the password to the server; Receiving a first sub-verification result for the account and the password returned by the server; When the first sub-verification result indicates that the verification is passed, collecting a face video of the user through a camera; Sending the face video to the server; The face video, the account and the password corresponding to the account belong to the identity authentication information.

3. The method of claim 2, wherein, The collecting of the face video of the user through the camera when the first sub-verification result indicates that the verification is passed comprises: When the first sub-verification result indicates that the verification is passed, sending a transmission password to the server in response to an input operation of the user for the transmission password; Receiving a second sub-verification result for the transmission password returned by the server.

4. The method according to any one of claims 1 to 3, characterized in that, The method further comprises: If the first verification result indicates that the terminal device is not currently in the preset area, outputting first warning information, the first warning information being used to remind the user to move the terminal device into the preset area; If the second verification result indicates that the identity authentication information does not pass identity authentication, outputting second warning information, the second warning information being used to remind the user that the data transmission operation cannot be performed.

5. A data transmission method, characterized by, The method applied to a server comprises: Receiving a current location of a terminal device sent by the terminal device; Determining whether the current location of the terminal device is in a preset area, and sending a first verification result to the terminal device; If the first verification result indicates that the terminal device is currently in the preset area, receiving identity authentication information sent by the terminal device; According to target identity authentication information stored in advance, performing identity authentication on the identity authentication information, and sending a second verification result to the terminal device; If the second verification result indicates that the identity authentication information passes identity authentication, receiving a virtual private network (VPN) channel establishment request sent by the terminal device; The VPN channel requested to be established by the terminal device is matched with a VPN channel requested to be established by a target terminal device, and an establishment result of the VPN channel is returned to the terminal device, the target terminal device being a terminal device requested by the terminal device to perform data transmission.

6. The method of claim 5, wherein, The identity authentication information includes a face video, an account, and a password corresponding to the account.

7. The method of claim 6, wherein, The identity authentication information further includes a transmission password.

8. A data transmission apparatus, the apparatus being applied to a terminal device, comprising: a sending module configured to send a current location of the terminal device to a server in response to a data transmission operation of a user; a receiving module configured to receive a first verification result returned by the server, the first verification result being used to indicate whether the terminal device is currently in a preset area; the sending module is further configured to send identity authentication information to the server if the first verification result indicates that the terminal device is currently in the preset area; the receiving module is further configured to receive a second verification result corresponding to the identity authentication information returned by the server; the sending module is further configured to send a VPN channel establishment request to the server if the second verification result indicates that the identity authentication information passes identity authentication; the receiving module is further configured to receive an establishment result of a VPN channel returned by the server; a transmission module configured to perform data transmission with a target terminal device through the VPN channel if the establishment result indicates that the VPN channel is successfully established.

9. A data transmission apparatus, the apparatus being applied to a server, comprising: a receiving module configured to receive a current location of a terminal device sent by the terminal device; a processing module configured to judge whether the current location of the terminal device is in a preset area, and send a first verification result to the terminal device; the receiving module is further configured to receive identity authentication information sent by the terminal device if the first verification result indicates that the terminal device is currently in the preset area; the processing module is further configured to perform identity authentication on the identity authentication information according to target identity authentication information stored in advance, and send a second verification result to the terminal device; the receiving module is further configured to receive a VPN channel establishment request sent by the terminal device if the second verification result indicates that the identity authentication information passes identity authentication; the processing module is further configured to match a VPN channel requested to be established by the terminal device with a VPN channel requested to be established by a target terminal device, and return an establishment result of the VPN channel to the terminal device, the target terminal device being a terminal device requested by the terminal device to perform data transmission.

10. An electronic device, comprising: comprising: a memory, a processor; the memory stores computer execution instructions; the processor executes the computer execution instructions stored in the memory, so that the processor executes the method in any one of claims 1-7.

Citation Information

Patent Citations

  • Virtual private network access method and equipment

    CN111371664A

  • Virtual private network access method and device, and storage medium

    CN116938639A