Data transmission method, system, device and storage medium across physically isolated networks

By introducing a task management module and a one-way hash function to calculate session keys in a cross-physical isolation network environment, combining secure sandbox and blockchain technology, the problem of low data transmission security in the existing technology is solved, and more efficient and secure data transmission is achieved.

CN119652670BActive Publication Date: 2025-05-23HUNAN TIAN HE GUO YUN TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510163947.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-14
Publication Date
2025-05-23
Estimated Expiration
2045-02-14

AI Technical Summary

Technical Problem

In a cross-physical isolation network environment, existing data encryption methods may still be intercepted and cracked by attackers during transmission, resulting in lower security of data transmission.

Method used

By establishing a task management module between the data usage end and the data providing end, the session key is calculated using a one-way hash function, and data encryption and decryption is performed based on the key, combining secure sandboxing and blockchain technology to ensure the security of data transmission.

Benefits of technology

Improve the security of data transmission in cross-physical isolation network environments, enhance the computing efficiency and collision resistance of session keys, and ensure the security and privacy of data by automatically destroying security sandboxes and data to be served.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119652670B_ABST
    Figure CN119652670B_ABST
Patent Text Reader

Abstract

The present application is applicable to the field of information security technology, and provides a data transmission method, system, device and storage medium across physically isolated networks. The method is applied to a data user end, and includes: conducting data service negotiation with a data provider end based on a data service order, generating a task identifier after the negotiation is passed, and sending a task registration application to a task management module, carrying the data service order and the task identifier; receiving a session key sent by the task management module, calculating a public key based on the session key, and sending the public key to the task management module; receiving encrypted data sent by the data provider end; starting a security sandbox based on the encrypted data, decrypting the encrypted data in the security sandbox based on the session key to obtain data to be served, and performing data calculation based on the data to be served; and automatically destroying the security sandbox and the data to be served after the data calculation is completed, thereby improving the security of data transmission across a physically isolated network environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the field of information security technology, and in particular, relates to a data transmission method, system, device and storage medium across a physically isolated network. Background Art

[0002] With the rapid development of Internet technology and the deepening of digital transformation, data exchange and sharing across physically isolated networks have become more and more common. In a physically isolated network environment, data privacy protection has become an important issue.

[0003] Traditional data protection methods, such as data encryption and firewall isolation, protect the privacy of data to a certain extent, but they still have many limitations in the data transmission and computing process across physically isolated networks. For example, in a cross-physically isolated network environment, data transmission often faces security risks such as network attacks and data leakage. Although existing data encryption methods can protect the confidentiality of data, they may still be intercepted and cracked by attackers during transmission, resulting in low data transmission security.

[0004] Therefore, how to improve the security of data transmission across physically isolated network environments has become an urgent problem to be solved. Summary of the invention

[0005] Embodiments of the present application provide a method, apparatus, device, and storage medium for data transmission across a physically isolated network, aiming to improve the security of data transmission across a physically isolated network environment.

[0006] In a first aspect, an embodiment of the present application provides a method for data transmission across a physically isolated network, which is applied to a data user end, and the method includes: conducting data service negotiation with a data provider end based on a data service order, wherein the data service order includes data to be served, data volume, number of data services, and data service period; after the data service negotiation with the data provider end is passed, generating a task identifier, and sending a task registration application to a task management module, wherein the task registration application carries the data service order and the task identifier, so that the task management module calculates a session key based on the task identifier using a one-way hash function; receiving the task registration application sent by the task management module The task management module sends the session key, calculates the public key based on the session key, and sends the public key to the task management module, so that the task management module sends the public key to the data provider; receives encrypted data sent by the data provider, wherein the encrypted data is obtained by the data provider encrypting the data to be served based on the public key; starts a security sandbox based on the encrypted data, decrypts the encrypted data in the security sandbox based on the session key to obtain the data to be served, and performs data calculation based on the data to be served; and automatically destroys the security sandbox and the data to be served after the data calculation is completed.

[0007] In a possible implementation, the task registration application also carries an on-chain identifier, and the data service negotiation with the data provider based on the data service order includes: digitally signing the data service order to obtain a first digital signature; sending a data service request to the data provider, the data service request carrying the data service order and the first digital signature; receiving the data service request sent by the data provider via a message, the data service request carrying the second digital signature via a message; uploading the data service order, the first digital signature and the second digital signature to the blockchain to obtain the on-chain identifier.

[0008] In a possible implementation, before the security sandbox is started based on the encrypted data, the encrypted data is decrypted in the security sandbox based on the session key to obtain the data to be served, and data calculation is performed based on the data to be served, the method further includes: obtaining a task certificate from the blockchain based on the task identifier, the task certificate is generated by the task management module based on the task registration application and uploaded to the blockchain, the task certificate includes information related to the data transmission task, and the information related to the data transmission task includes the data volume, data service times and data service period of the data to be served; the encrypted data is verified based on the task certificate, and after the verification passes, the steps of starting the security sandbox based on the encrypted data, decrypting the encrypted data in the security sandbox based on the session key to obtain the data to be served, and data calculation is performed based on the data to be served.

[0009] In a possible implementation, the security sandbox is started based on the encrypted data, and in the security sandbox, the encrypted data is decrypted based on the session key to obtain the data to be served, and data calculation is performed based on the data to be served. It also includes: loading a trusted execution monitoring program in the security sandbox, monitoring the number of times the data to be served is used based on the trusted execution monitoring program, and obtaining a monitoring report; and uploading the monitoring to the blockchain.

[0010] In a second aspect, an embodiment of the present application provides a method for data transmission across a physically isolated network, which is applied to a task management module, and the method includes: receiving a task registration application sent by a data user, the task registration application carries a data service order and the task identifier, the data service order includes data to be serviced, data volume, number of data services, and data service period; generating a task certificate based on the task registration application, and uploading the task certificate to the blockchain, the task certificate including information related to the data transmission task, the data transmission task related information including the data volume, number of data services, and data service period of the data to be serviced; generating a master private key and a system shared key, and calculating a session key based on the master private key, the system shared key, and the task identifier using a one-way hash function; sending the session key to the data user; receiving a public key sent by the data user, and sending the task identifier and the public key to the data provider.

[0011] In one possible implementation, the task registration application also carries an on-chain identifier, and the task certificate is generated based on the task registration application, and the task certificate is uploaded to the blockchain, including: performing on-chain verification on the data service order based on the on-chain identifier; when the verification is passed, generating the task certificate based on the data service order, and uploading the task certificate to the blockchain.

[0012] In the third aspect, an embodiment of the present application provides a method for data transmission across a physically isolated network, which is applied to a data provider, and the method includes: negotiating data services with a data user based on a data service order, wherein the data service order includes data to be served, data volume, number of data services, and data service period; after the data service negotiation with the data user is passed, receiving a task identifier and a public key sent by a task management module; encrypting the data to be served based on the public key to obtain encrypted data; and sending the encrypted data to the data user based on the task identifier.

[0013] In a fourth aspect, an embodiment of the present application provides a data transmission system across a physically isolated network, the system comprising a data usage end, a task management module and a data provider end, the task management module being physically connected to the data usage end and the data provider end respectively, the data usage end and the data provider end being connected via a cross-network isolated data transmission device; the data usage end is used to execute the method described in the first aspect or any one of the implementations thereof; the task management module is used to execute the method described in the second aspect or any one of the implementations thereof; the data provider end is used to execute the method described in the third aspect.

[0014] In a fifth aspect, an embodiment of the present application provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the method described in the first aspect, the second aspect, the third aspect, or any one of the implementation methods thereof is implemented.

[0015] In a sixth aspect, an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method described in the first aspect, the second aspect, the third aspect, or any one of the implementation methods thereof is implemented.

[0016] In the seventh aspect, an embodiment of the present application provides a computer program product, which includes a computer program, and when the computer program is executed by a processor, it implements the steps of the method described in the first aspect, the second aspect, the third aspect, or any one of the implementation methods therein.

[0017] Compared with the prior art, the beneficial effects of the embodiments of the present application are as follows: after the data service negotiation between the data user and the data provider is passed based on the data service order, the data user generates a task identifier and sends a task registration application carrying the data service order and the task identifier to the task management module, so that the task management module calculates the session key based on the task identifier using a one-way hash function, thereby improving the calculation efficiency and anti-collision capability of the session key; receiving the session key sent by the task management module, calculating the public key based on the session key, and sending the public key to the task management module, so that the task management module sends the public key to the data provider, thereby improving the transmission security of the public key; receiving the encrypted data obtained by encrypting the service data based on the public key sent by the data provider; starting a security sandbox based on the encrypted data, decrypting the encrypted data in the security sandbox based on the session key to obtain the service data, and performing data calculation based on the service data; automatically destroying the security sandbox and the service data after the use of the service data is completed, thereby improving the security of data transmission across a physically isolated network environment.

[0018] It can be understood that the data transmission system, electronic device, computer-readable storage medium and computer program product across a physically isolated network provided in the embodiments of the present application have the same beneficial effects as the above-mentioned data transmission method across a physically isolated network, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0020] Figure 1 A schematic diagram of the architecture of a data transmission system across physically isolated networks provided in one embodiment of the present application;

[0021] Figure 2 A schematic diagram of a first data service gateway provided in an embodiment of the present application;

[0022] Figure 3 A schematic diagram of a flow chart of a data transmission method across a physically isolated network provided in one embodiment of the present application;

[0023] Figure 4 A flowchart of another method for transmitting data across physically isolated networks provided in one embodiment of the present application;

[0024] Figure 5A flowchart of another method for transmitting data across a physically isolated network provided in an embodiment of the present application;

[0025] Figure 6 An interactive schematic diagram of a data transmission method across a physically isolated network provided in one embodiment of the present application;

[0026] Figure 7 A schematic diagram of the structure of an electronic device provided in one embodiment of the present application. DETAILED DESCRIPTION

[0027] In the following description, specific details such as specific system structures, technologies, etc. are provided for the purpose of illustration rather than limitation, so as to provide a thorough understanding of the embodiments of the present application. However, it should be clear to those skilled in the art that the present application may also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to prevent unnecessary details from obstructing the description of the present application.

[0028] It should be understood that when used in the present specification and the appended claims, the term "comprising" indicates the presence of described features, wholes, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or combinations thereof.

[0029] It should also be understood that the term “and / or” used in the specification and appended claims refers to any and all possible combinations of one or more of the associated listed items, and includes these combinations.

[0030] As used in the specification and appended claims of this application, the term "if" can be interpreted as "when" or "uponce" or "in response to determining" or "in response to detecting", depending on the context. Similarly, the phrase "if it is determined" or "if [described condition or event] is detected" can be interpreted as meaning "uponce it is determined" or "in response to determining" or "uponce [described condition or event] is detected" or "in response to detecting [described condition or event]", depending on the context.

[0031] In addition, in the description of the present application specification and the appended claims, the terms "first", "second", "third", etc. are only used to distinguish the descriptions and cannot be understood as indicating or implying relative importance.

[0032] References to "one embodiment" or "some embodiments" etc. described in the specification of this application mean that one or more embodiments of the present application include specific features, structures or characteristics described in conjunction with the embodiment. Therefore, the statements "in one embodiment", "in some embodiments", "in some other embodiments", "in some other embodiments", etc. that appear in different places in this specification do not necessarily refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in other ways. The terms "including", "comprising", "having" and their variations all mean "including but not limited to", unless otherwise specifically emphasized in other ways.

[0033] To facilitate understanding, some concepts involved in the embodiments of the present application are first explained.

[0034] Gatekeeper: Also known as security isolation gatekeeper, it is a network security device. Its main function is to exchange data securely between two networks with different security levels, such as a trusted network (such as an internal office network of an enterprise) and an untrusted network (such as the Internet). The gatekeeper can achieve limited and secure data communication on the basis of ensuring the physical isolation of the two networks.

[0035] Key negotiation: Key negotiation is a process of establishing a shared key between two or more communicating parties. This shared key is used to encrypt the content of the communication to ensure the confidentiality and integrity of the communication. This application designs a key negotiation method for asymmetric encryption, through which a publicly available public key is negotiated for data provider to encrypt data, while a private key is only owned by the data user to decrypt data.

[0036] The technical solution of the present application will be described in detail below with reference to the accompanying drawings.

[0037] Figure 1 The following is a schematic diagram of the architecture of a data transmission system across physically isolated networks provided in one embodiment of the present application. Figure 1 As shown, the data transmission system across physically isolated networks includes an intranet at the data user end, an intranet at the data provider end, a blockchain network, a first data service gateway, a second data service gateway, and a cross-network isolated data transmission device.

[0038] Specifically, the first data service gateway is the data service gateway of the data user end, and the second data service gateway is the data service gateway of the data provider end; the intranet of the data user end, the intranet of the data provider end and the blockchain network are built based on the Internet, and the intranet of the data user end and the intranet of the data provider end communicate with each other through a cross-network isolation data transmission device, which can be a network gate, an optical gate or a QR code ferry, etc. In addition, a task management module (not shown in the figure) is also provided in the blockchain network, which is used to register, manage and participate in key negotiation processes for data transmission tasks between the data user end and the data provider end.

[0039] In the specific implementation, physical connections are used between the intranet of the data user end and the first data service gateway, between the intranet of the data provider end and the second data service gateway, between the intranet of the data user end and the cross-network isolated data transmission device, and between the intranet of the data provider end and the cross-network isolated data transmission device, as indicated by dotted arrows. The first data service gateway and the second data service gateway are interconnected through the blockchain network to achieve data sharing and storage during the data transmission process.

[0040] As an example, Figure 2 A schematic diagram of a first data service gateway provided in an embodiment of the present application. Figure 2 As shown, the first data service gateway includes a blockchain node module, a smart contract execution module, a trusted computing area, an algorithm library, a data isolation buffer, a key management center, a task verification area and an external network interface.

[0041] Among them, the blockchain node module is used to connect with other participants, build a blockchain distributed network, and provide chain services, smart contract deployment and other functions; the smart contract execution module is mainly used to execute data service-related smart contracts deployed on the blockchain, and is used to initiate security sandbox startup instructions; the trusted computing area is used to receive smart contract instructions to build a temporary trusted computing security isolation environment (ie, security sandbox); the algorithm library is used to store data utilization-related algorithms published by the data user; the data isolation buffer is used to temporarily store encrypted data provided by the data provider, and after the trusted computing environment starts the service, it is transmitted to the trusted computing security isolation environment for data calculation; the key management center is used to store and manage the keys in the data transmission tasks; the task verification area is used to receive encrypted data obtained by the external network interface; the external network interface is used to connect to the cross-network isolation transmission device and receive encrypted data provided by the data provider.

[0042] Understandably, Figure 1The architecture diagram shown is only an example of a data transmission system across a physically isolated network provided by the present application. In other embodiments of the present application, the data transmission system across a physically isolated network may include more or fewer components than shown in the diagram, or combine certain components, or split certain components, or arrange the components differently. The components shown in the diagram may be implemented in hardware, software, or a combination of software and hardware, and the present application does not limit this.

[0043] Figure 3 A flow chart of a method for transmitting data across a physically isolated network provided in an embodiment of the present application is provided. For ease of explanation, only the part related to the present embodiment is shown. The method provided in the present embodiment is applied to a data user end and specifically includes the following steps:

[0044] S310, conducting data service negotiation with the data provider based on the data service order, where the data service order includes data to be served, data volume, number of data services, and data service period.

[0045] In one possible implementation, the data user generates a data service order based on the data usage demand, digitally signs the data service order, and obtains a first digital signature; sends a data service request to the data provider, and the data service request carries the data service order and the first digital signature; receives the data service request sent by the data provider via a message, and the data service request carries the second digital signature via a message; uploads the data service order, the first digital signature, and the second digital signature to the blockchain to obtain an on-chain identifier.

[0046] In the specific implementation, before performing the data transmission task, the data user needs to initiate a data use request with the data provider. After the request is approved, the data service is negotiated with the data provider to agree on the data service type and data service content, etc. The data user initiates the data service request, which carries a data service order. The data service order includes the data service type, data service content, data volume, data service times, data service period, etc. The data service order is digitally signed to obtain the first data signature. After the data provider agrees and stamps the second data signature, the data service order and the first digital signature and the second digital signature are published to the blockchain. After the negotiation of the data service order and the digital signatures of both parties, the data service order is stored on the chain to facilitate the subsequent use control and trusted monitoring of the data use process, and to prevent the abuse of data and then pursue accountability and confirm ownership.

[0047] As an example, the data service content refers to the data field for the service, that is, the data to be served; the data service type refers to the algorithm type used for the data to be served.

[0048] S320, after the data service negotiation with the data provider is passed, a task identifier is generated, and a task registration application is sent to the task management module. The task registration application carries the data service order and the task identifier, so that the task management module calculates the session key based on the task identifier using a one-way hash function.

[0049] Specifically, after the data service order is confirmed by both the data user and the data provider, the data user initiates a data transmission task registration to the task management module to generate a session key for the data transmission task.

[0050] In the specific implementation, the data user initiates a task registration application to the task management module, carrying the up-chain identifier of the data service order to the task management module. After the task management module initializes the data transmission task, key negotiation is performed.

[0051] As an example, the data user selects a random number As the task identifier and send it to the task management module. Among them, p and q are two large prime numbers randomly selected by the task management module based on the elliptic curve encryption algorithm, one is defined in a finite field Elliptic curve and a step Generators of .

[0052] S330, receiving the session key sent by the task management module, calculating the public key based on the session key, and sending the public key to the task management module, so that the task management module sends the public key to the data provider.

[0053] In the specific implementation, when the data user receives the session key sent by the task management module, based on the session key, the public key of this data transmission task is calculated using the following formula and made public, and the session key of this task is secretly saved locally: To the local task key management center:

[0054] ,

[0055] in, is the session key, is the public key, and P is a large prime number randomly selected by the task management module.

[0056] S340, receiving encrypted data sent by the data provider, where the encrypted data is obtained by encrypting the service data by the data provider based on a public key.

[0057] In a specific implementation, the data user and the data provider respectively establish connections with the cross-network isolation data transmission device, and the data user receives the encrypted data obtained by the data provider based on the public key to encrypt the service data through the cross-network isolation data transmission device.

[0058] S350, starting a security sandbox based on the encrypted data, decrypting the encrypted data in the security sandbox based on the session key to obtain data to be served, and performing data calculation based on the data to be served.

[0059] In a possible implementation, before executing step S350, a task certificate is first obtained from the blockchain based on the task identifier. The task certificate is generated by the task management module based on the task registration application and uploaded to the blockchain. The task certificate includes information related to the data transmission task. The information related to the data transmission task includes the data volume of the data to be served, the number of data services and the data service period. After the encrypted data is verified based on the task certificate and the verification passes, a security sandbox is started based on the encrypted data. In the security sandbox, the encrypted data is decrypted based on the session key to obtain the data to be served, and data calculation is performed based on the data to be served.

[0060] In one possible implementation, while executing step S350, a trusted execution monitoring program is loaded in the security sandbox, and the number of times the service data is used is monitored based on the trusted execution monitoring program to obtain a monitoring report; and the monitoring information is uploaded to the blockchain.

[0061] In the specific implementation, after the data user receives the encrypted data sent by the data provider, the task identifier and task certificate are obtained through the task verification area. The task verification area verifies the encrypted data based on the task certificate, for example, verifies whether the amount of the encrypted data meets the requirements agreed in the task certificate, and sends the task certificate to the smart contract execution module, triggering the smart contract to execute the task start instruction. At the same time, a secure transmission channel is established with the internal data buffer to transmit the encrypted data to the data isolation buffer; after the smart contract execution module receives the task certificate message, it triggers the execution of the security sandbox start instruction to trigger the trusted computing area to start the security sandbox; after the security sandbox is started, the session key of this data transmission task is obtained from the local key management center to the security sandbox, the encrypted data in the data buffer is called to the security sandbox, the algorithm of this data transmission task is called from the algorithm library to the security sandbox, and the trusted execution monitoring program is loaded at the same time to monitor the number of data usage, etc. After the security sandbox is started, data decryption and data calculation operations are automatically performed internally, and the whole process is invisible and cannot be manually intervened. After the data calculation is completed, the calculation result of this task and the monitoring report generated by the trusted execution monitoring program are returned, and the execution record and monitoring report of this data transmission task are uploaded to the blockchain for evidence storage.

[0062] S360, automatically destroys the security sandbox and data to be served after data calculation is completed.

[0063] In the specific implementation, after the data calculation is completed, the calculation results of this data transmission task and the monitoring report generated by the trusted execution monitoring program are returned, and the execution record and monitoring report of this data transmission task are uploaded to the blockchain for evidence storage, and then the security sandbox is automatically destroyed, including the encrypted data used for this calculation is also destroyed from the first data service gateway, so that the data is available but not visible.

[0064] The technical solution provided by this embodiment is that after the data service negotiation between the data user and the data provider is passed based on the data service order, the data user generates a task identifier and sends a task registration application carrying the data service order and the task identifier to the task management module, so that the task management module calculates the session key based on the task identifier using a one-way hash function, thereby improving the calculation efficiency and anti-collision capability of the session key; receives the session key sent by the task management module, calculates the public key based on the session key, and sends the public key to the task management module, so that the task management module sends the public key to the data provider, thereby improving the transmission security of the public key; receives the encrypted data obtained by encrypting the service data based on the public key sent by the data provider; starts a security sandbox based on the encrypted data, decrypts the encrypted data in the security sandbox based on the session key to obtain the service data, and performs data calculation based on the service data; automatically destroys the security sandbox and the service data after the use of the service data is completed, thereby improving the security of data transmission across a physically isolated network environment.

[0065] Figure 4 A flowchart of another method for transmitting data across a physically isolated network provided in an embodiment of the present application is provided. For ease of explanation, only the part related to the present embodiment is shown. The method provided in the present embodiment is applied to a task management module and specifically includes the following steps:

[0066] S410, receiving a task registration application sent by a data user, the task registration application carries a data service order and a task identifier, the data service order includes data to be served, data volume, data service times and data service period.

[0067] In one possible implementation, the task registration application also carries an on-chain identifier obtained when the data user uploads the data service order, the first digital signature, and the second digital signature to the blockchain.

[0068] S420, generating a task certificate based on the task registration application, and uploading the task certificate to the blockchain, the task certificate including information related to the data transmission task, and the information related to the data transmission task including the amount of data to be served, the number of data services, and the data service period.

[0069] In one possible implementation, the data service order is verified on-chain based on the on-chain identifier; when the verification is passed, a task certificate is generated based on the data service order, and the task certificate is uploaded to the blockchain.

[0070] In the specific implementation, the data user initiates a task registration application to the task management module and sends the data service order on-chain identifier to the task management module. After receiving it, the task management module verifies the data service order on-chain to confirm the authenticity of the data service content, generates a task certificate based on the data service order content, and uploads the task certificate to the blockchain.

[0071] As an example, the task certificate includes a certificate identifier, certificate issuance time, certificate validity period, a digital signature of the task management module, data provider information, and task attribute related information.

[0072] Among them, the certificate identifier represents the certificate number issued by the task management module to the data user, which is unique and guarantees its validity; the issuance time and validity period of the certificate indicate the security and validity period of the security sandbox; the digital signature is the signature of the trusted execution space certificate using the private key of the task management module, and the user can verify the validity of the certificate; the data provider information includes the public key of the data provider and its related information, which is used to establish a secure transmission channel when the data provider transmits encrypted data to the data user to resist man-in-the-middle attacks; the task attribute related information represents the attribute information of the task execution, including the expiration time of the data to be served, the number of times the data is used, etc.

[0073] S430, generating a master private key and a system shared key, and calculating a session key using a one-way hash function based on the master private key, the system shared key and the task identifier.

[0074] Specifically, after the task certificate is issued, the task management module initializes the data transmission task.

[0075] In the specific implementation, the task management module randomly selects two large prime numbers based on the elliptic curve encryption algorithm. , a definition over a finite field Elliptic curve and a step Generators of ;The task management module randomly generates its master private key And calculate the system public key , the task management module saves the master private key , and then generate a random number The key is shared as a system and kept secret.

[0076] Furthermore, based on the master private key, the system shared key and the task identifier, a one-way hash function is used to calculate the session key using the following formula:

[0077] ,

[0078] in, is the session key, is a one-way hash function, is the master private key, Share a key with the system, is the task identifier.

[0079] S440, sending the session key to the data user.

[0080] In the specific implementation, the task management module sends the session key to the data user. Share the key with the system .

[0081] S450, receiving the public key sent by the data user, and sending the task identifier and the public key to the data provider.

[0082] The technical solution provided by this embodiment is that the task management module generates a task certificate based on the task registration application sent by the data user, uploads the task certificate to the blockchain, initializes the task for this data transmission task, generates a master private key and a system shared key, calculates the system public key based on the master private key, calculates the session key using a one-way hash function based on the master private key, the system shared key and the task identifier; sends the session key to the data user; receives the public key sent by the data user, and sends the task identifier and the public key to the data provider, thereby improving the security of data transmission across a physically isolated network environment.

[0083] Figure 5 A flowchart of another method for transmitting data across a physically isolated network is provided in an embodiment of the present application. For ease of explanation, only the part related to the present embodiment is shown. The method provided in the present embodiment is applied to a data provider, and specifically includes the following steps:

[0084] S510, negotiating data services with the data user based on the data service order, where the data service order includes data to be served, data volume, number of data services, and data service period.

[0085] In a specific implementation, the data provider receives a data service request sent by the data user, and the data service request carries a data service order and a first digital signature. After the data provider agrees, the data service order is stamped with a second digital signature, and a data service request message is sent to the data user, and the data service request message carries the second digital signature.

[0086] S520, after the data service negotiation with the data user is passed, receiving the task identifier and the public key sent by the task management module.

[0087] S530, encrypt the service data based on the public key to obtain encrypted data.

[0088] In the specific implementation, the data provider packages the service data locally and uses the public key of this data transmission task. The service data is encrypted to obtain encrypted data.

[0089] S540, sending encrypted data to the data user based on the task identifier.

[0090] In a specific implementation, the encrypted data and the task identifier are transmitted to the data user.

[0091] The technical solution provided by this embodiment is that the data provider negotiates data services with the data user based on the data service order. After the data service negotiation is passed, the data provider receives the task identifier and public key sent by the task management module; encrypts the service data based on the public key to obtain encrypted data; and sends the encrypted data to the data user based on the task identifier, thereby improving the security of data transmission across a physically isolated network environment.

[0092] Figure 6 An interactive schematic diagram of a data transmission method across a physically isolated network provided by an embodiment of the present application, combined with Figure 6 As shown, based on the above embodiment, this embodiment further illustrates and optimizes the technical solution. Specifically, the method provided in this embodiment includes:

[0093] The data user sends a data service request to the data provider, where the data service request carries a data service order and a first digital signature;

[0094] The data provider sends a data service request message to the data user, where the data service request message carries a second digital signature;

[0095] The data user uploads the data service order, the first digital signature and the second digital signature to the blockchain, and receives the on-chain identifier returned by the blockchain;

[0096] The data user sends a task registration application to the task management module. The task registration application carries the data service order and task identifier. and on-chain identifier;

[0097] The task management module verifies the data service order on the chain based on the on-chain identifier. After verification, it generates a task certificate based on the data service order and uploads the task certificate to the blockchain.

[0098] The task management module generates the master private key Share the key with the system , computing system public key and session key ;

[0099] The task management module sends the session key to the data user Share the key with the system ;

[0100] Data consumption end based on session key Calculate the public key , and the public key Send to the task management module;

[0101] The task management module sends the task identifier to the data provider and public key ;

[0102] Data provider based on public key Encrypt the service data to obtain encrypted data , and send encrypted data to the data user ;

[0103] The data user obtains the task identifier and task certificate through the task verification area. The task verification area verifies the encrypted data and sends the task certificate to the smart contract execution module, triggering the smart contract to execute the task start instruction. At the same time, a secure transmission channel is established with the internal data buffer to transmit the encrypted data to the data isolation buffer. After receiving the task certificate message, the smart contract execution module triggers the execution of the security sandbox start instruction to trigger the trusted computing area to start the security sandbox. After the security sandbox is started, the session key is obtained from the local key management center. To the security sandbox, call the encrypted data in the data buffer to the security sandbox, call the algorithm of this data transmission task from the algorithm library to the security sandbox, and load the trusted execution monitoring program to monitor the number of times the data is used;

[0104] After the security sandbox is started, data decryption and data calculation are automatically performed internally. The entire process is invisible and cannot be manually intervened. After the data calculation is completed, the calculation results of this task and the monitoring report generated by the trusted execution monitoring program are returned, and the execution record and monitoring report of this task are uploaded to the blockchain for evidence storage. At the same time, the security sandbox is automatically destroyed, including the encrypted data used for this calculation is also destroyed from the gateway, so that the data is available but invisible.

[0105] In summary, this application designs a data encryption key negotiation and data transmission method across physical isolation, which generates a data encryption key through key negotiation, uses the key to encrypt data locally at the data provider end, and uses a secure isolation and information exchange system (such as a network gate) to transmit the encrypted data to the data user end, thereby enabling secure cross-network transmission of data between the two parties under a physically isolated network; it also designs a data service gateway with privacy service capabilities, which solves the problem of privacy leakage of data locally at the data user end by setting up multiple secure isolation partitions, thereby improving the security of data sharing and utilization; it also provides a privacy computing service mechanism based on smart contracts, which realizes the available but invisible data and the incineration after use, and the entire process is automatically executed based on the smart contract, and the execution records are uploaded to the chain for evidence, thereby enabling the available but invisible data.

[0106] The data encryption key negotiation and data transmission method, data service gateway, data privacy computing service method, etc. designed by this application based on blockchain across physically isolated networks can bring the following benefits to data usage security and privacy protection:

[0107] ① It can effectively negotiate encryption keys and encrypt data transmission across physically isolated networks, ensuring the security of encryption keys and thus data transmission security;

[0108] ② It is possible to perform data calculations on the premise that the data content is not leaked locally at the data user end, making the data available but invisible.

[0109] ③ It can ensure that the data is destroyed after use, and only the data calculation results are returned. No traces are left after the data is used, and the data usage records are stored in the blockchain to provide proof of data use.

[0110] Figure 7 This is a schematic diagram of the structure of an electronic device provided by an embodiment of the present application. Figure 7 As shown, the electronic device 7 of this embodiment includes: at least one processor 70 ( Figure 7 Only one is shown in the figure), a memory 71, and a computer program 72 stored in the memory 71 and executable on at least one processor 70, the processor 70 executes the computer program 72 to implement the above Figure 3 , Figure 4 or Figure 5 Steps in a method embodiment.

[0111] The electronic device 7 may be a computing device such as a desktop computer, a notebook, a PDA, or a cloud server. The electronic device 7 may include but is not limited to a processor 70 and a memory 71. Those skilled in the art will appreciate that Figure 7It is only an example of the electronic device 7 and does not constitute a limitation on the electronic device 7. It may include more or fewer components than shown in the figure, or a combination of certain components, or different components. For example, it may also include input and output devices, network access devices, etc.

[0112] The processor 70 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor, etc.

[0113] In some embodiments, the memory 71 may be an internal storage unit of the electronic device 7, such as a hard disk or memory of the electronic device 7. In other embodiments, the memory 71 may also be an external storage device of the electronic device 7, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the electronic device 7. Further, the memory 71 may also include both an internal storage unit and an external storage device of the electronic device 7. The memory 71 is used to store an operating system, an application program, a boot loader (BootLoader), data, and other programs, such as program codes of a computer program. The memory 71 may also be used to temporarily store data that has been output or is to be output.

[0114] The embodiment of the present application further provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments can be implemented.

[0115] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present application implements all or part of the processes in the above-mentioned embodiment method, which can be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium, and the computer program can implement the steps of the above-mentioned various method embodiments when executed by the processor. Among them, the computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium may at least include: any entity or device that can carry the computer program code to an electronic device, a recording medium, a computer memory, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), an electrical carrier signal, a telecommunication signal, and a software distribution medium. For example, a USB flash drive, a mobile hard disk, a disk or an optical disk.

[0116] A computer-readable storage medium provided in an embodiment of the present application has the same beneficial effects as the above-mentioned method for transmitting data across a physically isolated network.

[0117] An embodiment of the present application provides a computer program product, which includes a computer program. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments can be implemented.

[0118] A computer program product provided in an embodiment of the present application has the same beneficial effects as the above-mentioned method for transmitting data across a physically isolated network.

[0119] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0120] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0121] In the embodiments provided in the present application, it should be understood that the disclosed devices / equipment and methods can be implemented in other ways. For example, the device / equipment embodiments described above are merely schematic, for example, the division of the modules or units is only a logical function division, and there may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0122] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0123] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, a person skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features may be replaced by equivalents. Such modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application, and should be included in the protection scope of the present application.

Claims

1. A data transmission method across a physically isolated network, characterized in that: Applied to a data user, the method includes: Conducting data service negotiation with the data provider based on a data service order, wherein the data service order includes data to be served, data volume, number of data services and data service period, and the data user is connected to the data provider via a cross-network isolated data transmission device; After the data service negotiation with the data provider is passed, a task identifier is generated, and a task registration application is sent to a task management module, wherein the task registration application carries the data service order and the task identifier, so that the task management module calculates a session key based on the task identifier using a one-way hash function, and the task management module is set in the blockchain; receiving the session key sent by the task management module, calculating a public key based on the session key, and sending the public key to the task management module, so that the task management module sends the public key to the data provider; Receiving encrypted data sent by the data provider, where the encrypted data is obtained by the data provider encrypting the data to be served based on the public key; Starting a security sandbox based on the encrypted data, decrypting the encrypted data in the security sandbox based on the session key to obtain the data to be served, and performing data calculation based on the data to be served; After the data calculation is completed, the security sandbox and the data to be served are automatically destroyed.

2. The method according to claim 1, characterized in that The task registration application also carries an on-chain identifier, and the data service negotiation with the data provider based on the data service order includes: Digitally signing the data service order to obtain a first digital signature; Sending a data service request to the data provider, wherein the data service request carries the data service order and the first digital signature; Receive a data service request message sent by the data provider, wherein the data service request message carries a second digital signature; The data service order, the first digital signature and the second digital signature are uploaded to the blockchain to obtain the on-chain identifier.

3. The method according to claim 1, characterized in that Before starting the security sandbox based on the encrypted data, decrypting the encrypted data in the security sandbox based on the session key to obtain the data to be served, and performing data calculation based on the data to be served, the method further includes: Obtaining a task certificate from the blockchain based on the task identifier, wherein the task certificate is generated by the task management module based on the task registration application and uploaded to the blockchain, and the task certificate includes relevant information about the data transmission task, and the relevant information about the data transmission task includes the data volume of the data to be served, the number of data services, and the data service period; The encrypted data is verified based on the task certificate. After the verification is passed, the steps of starting a security sandbox based on the encrypted data are executed. In the security sandbox, the encrypted data is decrypted based on the session key to obtain the data to be served, and data calculation is performed based on the data to be served.

4. The method according to claim 1, characterized in that: The method of starting a security sandbox based on the encrypted data, decrypting the encrypted data in the security sandbox based on the session key to obtain the data to be served, and performing data calculation based on the data to be served, further includes: Loading a trusted execution monitoring program in the security sandbox, monitoring the usage times of the data to be serviced based on the trusted execution monitoring program, and obtaining a monitoring report; The monitoring report is uploaded to the blockchain.

5. A data transmission method across a physically isolated network, characterized in that: Applied to a task management module, the task management module is set in a blockchain, and the method includes: Receiving a task registration application sent by a data user, wherein the task registration application carries a data service order and a task identifier, wherein the data service order includes data to be served, data volume, data service times and data service period; Generate a task certificate based on the task registration application, and upload the task certificate to the blockchain, wherein the task certificate includes information related to the data transmission task, and the information related to the data transmission task includes the data volume of the data to be served, the number of data services, and the data service period; Generate a master private key and a system shared key, and calculate a session key using a one-way hash function based on the master private key, the system shared key and the task identifier; Sending the session key to the data user end so that the data user end calculates a public key based on the session key and sends the public key to the task management module; Receive the public key sent by the data user, and send the task identifier and the public key to the data provider, so that the data provider encrypts the data to be served based on the public key to obtain encrypted data; based on the task identifier, send the encrypted data to the data user; so that the data user starts a security sandbox based on the encrypted data, decrypts the encrypted data in the security sandbox based on the session key to obtain the data to be served, and performs data calculation based on the data to be served; after the data calculation is completed, the security sandbox and the data to be served are automatically destroyed, and the data user is connected to the data provider through a cross-network isolation data transmission device.

6. The method according to claim 5, characterized in that The task registration application also carries an on-chain identifier, and the generating of a task certificate based on the task registration application and uploading the task certificate to the blockchain includes: Performing on-chain verification on the data service order based on the on-chain identifier; When the verification is passed, the task certificate is generated based on the data service order and uploaded to the blockchain.

7. A data transmission system across physically isolated networks, characterized in that: The system includes a data user end, a task management module and a data provider end, wherein the task management module is physically connected to the data user end and the data provider end respectively, the data user end and the data provider end are connected via a cross-network isolation data transmission device, and the task management module is arranged in the blockchain; The data user end is used to execute the method according to any one of claims 1 to 4; The task management module is used to execute the method described in claim 5 or 6; the data provider is used to negotiate data services with the data user based on a data service order, wherein the data service order includes data to be served, data volume, number of data services and data service period; after the data service negotiation with the data user is passed, the task identifier and public key sent by the task management module are received; The data to be served is encrypted based on the public key to obtain encrypted data; and the encrypted data is sent to the data user based on the task identifier.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the method according to any one of claims 1 to 4 or 5 to 6 is implemented.

9. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 4 or 5 to 6 is implemented.

Citation Information

Patent Citations

  • Data transmission management method, data processing method and device

    CN115567263A