Call data encryption method and related device

By storing the encrypted private and public keys of call data on the blockchain, the problem of call data being vulnerable to attack and leakage on centralized servers is solved, and secure encryption and authorized access to call data are achieved, ensuring that only authorized parties can decrypt and obtain the data.

CN119696771BActive Publication Date: 2026-04-28CHINA MOBILE INTERNET CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA MOBILE INTERNET CO LTD
Filing Date
2024-11-29
Publication Date
2026-04-28

AI Technical Summary

Technical Problem

When call data is stored and managed on the operator's centralized server, it is vulnerable to attacks, data leakage and misuse risks, and there is a lack of effective access control mechanisms.

Method used

The device-generated private key is encrypted using a pre-stored target public key, and the encrypted private and public keys are stored in the blockchain. The blockchain is then used to encrypt the call data, ensuring that only authorized parties can decrypt and access the call data.

Benefits of technology

It reduces the risk of call data leakage and misuse, improves the security of call data, and ensures that only authorized parties can access call data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119696771B_ABST
    Figure CN119696771B_ABST
Patent Text Reader

Abstract

The application discloses a call data encryption method and related equipment, and belongs to the technical field of communication. The method comprises the following steps: in response to a call request initiated by a first device, a first private key generated by the first device is encrypted by a target public key stored in advance to obtain a first encrypted private key; the first encrypted private key and a first public key corresponding to the first private key are stored in a block chain, and a storage transaction message returned by the block chain is acquired; the storage transaction message is sent to a second device corresponding to the call request, and the storage transaction message is used to instruct the second device to store a second encrypted private key and a second public key in the block chain based on the storage transaction information, wherein the second encrypted private key is obtained by encrypting a second private key of the second device by the target public key; and call data of the first device is encrypted by the second public key in the block chain to obtain first encrypted data. In this way, the risk of call data leakage and abuse can be reduced, and the security of the call data can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to a method and related equipment for encrypting call data. Background Technology

[0002] Currently, telecommunications operators provide work number services to businesses. Businesses activate these work numbers for their employees, and the operators provide call data to allow companies to evaluate employee performance based on call content and other factors. However, this call data is typically stored, managed, and analyzed on the operator's centralized servers. This makes the data vulnerable to attacks and increases the risk of data breaches and misuse. Summary of the Invention

[0003] This application provides a method and related equipment for encrypting call data, which at least solves the problem in the related art where call data is centrally stored and managed by operators, making the call data vulnerable to attacks and posing risks of data leakage and misuse.

[0004] To solve the above-mentioned technical problems, this application is implemented as follows:

[0005] In a first aspect, embodiments of this application provide a method for encrypting call data, comprising: responding to a call request initiated by a first device, encrypting a first private key generated by the first device using a pre-stored target public key to obtain a first encrypted private key; storing the first encrypted private key and a first public key corresponding to the first private key in a blockchain, and obtaining a storage transaction message returned by the blockchain; sending the storage transaction message to a second device corresponding to the call request, wherein the storage transaction message instructs the second device to store a second encrypted private key and a second public key of the second device in the blockchain based on the storage transaction message, wherein the second encrypted private key is obtained by the second device encrypting the second private key using the target public key, and the second public key corresponds to the second private key; and encrypting the call data of the first device using the second public key in the blockchain to obtain first encrypted data.

[0006] Secondly, embodiments of this application provide a method for encrypting call data, comprising: responding to a wake-up request received by a second device, obtaining a first encryption private key and a first public key corresponding to storage transaction information included in the wake-up request from a blockchain; encrypting a second private key generated by the second device using a target public key to obtain a second encryption private key; storing the second encryption private key and the second public key corresponding to the second private key in the blockchain; and encrypting the call data of the second device using the first public key to obtain second encrypted data.

[0007] Thirdly, embodiments of this application provide a call data encryption device, comprising: a first encryption module, configured to, in response to a call request initiated by a first device, encrypt a first private key generated by the first device using a pre-stored target public key to obtain a first encrypted private key; a message acquisition module, configured to store the first encrypted private key and a first public key corresponding to the first private key in a blockchain, and acquire a storage transaction message returned by the blockchain; a message sending module, configured to send the storage transaction message to a second device corresponding to the call request, the storage transaction message instructing the second device to store a second encrypted private key and a second public key of the second device in the blockchain based on the storage transaction message, wherein the second encrypted private key is obtained by the second device encrypting the second private key using the target public key, and the second public key corresponds to the second private key; and a second encryption module, configured to encrypt call data using the second public key in the blockchain to obtain first encrypted data.

[0008] Fourthly, embodiments of this application provide a call data encryption device, comprising: a key acquisition module, configured to, in response to a wake-up request received by a second device, acquire from a blockchain a first encrypted private key and a first public key corresponding to storage transaction information included in the wake-up request; a third encryption module, configured to encrypt a second private key generated by the second device using a target public key to obtain a second encrypted private key; a key storage module, configured to store the second encrypted private key and the second public key corresponding to the second private key in the blockchain; and a fourth encryption module, configured to encrypt call data using the first public key to obtain second encrypted data.

[0009] Fifthly, embodiments of this application provide an electronic device, including a processor and a memory, wherein the memory stores a program or instructions executable on the processor, and the program or instructions, when executed by the processor, implement the steps of the method described in the first or second aspect above.

[0010] In a sixth aspect, embodiments of this application provide a computer-readable storage medium on which a program or instructions are stored, which, when executed by a processor, implement the steps of the method described in the first or second aspect above.

[0011] In a seventh aspect, embodiments of this application provide a computer program product, the computer program product including a computer program stored on a non-transitory computer-readable storage medium, the computer program including program instructions, which, when executed by a computer, cause the computer to perform the steps of the method described in the first or second aspect above.

[0012] In this embodiment, in response to a call request initiated by a first device, a first private key generated by the first device is encrypted using a pre-stored target public key to obtain a first encrypted private key. The first encrypted private key and its corresponding first public key are stored in a blockchain, and a storage transaction message returned by the blockchain is obtained. A storage transaction message is sent to the second device corresponding to the call request, instructing the second device to store its second encrypted private key and second public key in the blockchain based on the storage transaction message. The call data of the first device is encrypted using the second public key in the blockchain to obtain first encrypted data. In this way, third-party users (e.g., enterprises) need to decrypt the second encrypted private key using the target private key corresponding to the target public key to obtain the second private key, and then use this second private key to decrypt the first encrypted data of the first device to obtain the call data. Since the call data of the first device cannot be directly accessed, it ensures that only the enterprise can decrypt and obtain the call data, thereby reducing the risk of call data leakage and misuse, and improving the security of the call data.

[0013] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and do not limit this application. Attached Figure Description

[0014] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0015] Figure 1 This paper illustrates a flowchart of a call data encryption method provided in an embodiment of this application.

[0016] Figure 2 A flowchart illustrating the public key exchange method provided in an embodiment of this application is shown;

[0017] Figure 3 This illustration shows another flowchart of the call data encryption method provided in an embodiment of this application;

[0018] Figure 4 A schematic diagram of the encrypted data exchange process provided in an embodiment of this application is shown;

[0019] Figure 5 This paper shows one of the structural schematic diagrams of the call data encryption device provided in an embodiment of this application;

[0020] Figure 6 A second schematic diagram of the call data encryption device provided in this application embodiment is shown;

[0021] Figure 7 A schematic diagram of the structure of an electronic device provided in an embodiment of this application is shown. Detailed Implementation

[0022] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0023] In related technologies, call data is typically stored on a centralized server operated by the carrier, which manages and analyzes it. This centralized storage and management method by the carrier has at least the following problems:

[0024] 1) Centralized data storage makes it vulnerable to attacks and data leaks;

[0025] 2) Operators have complete access to the recording data, posing a risk of privacy breaches;

[0026] 3) The lack of an effective access control mechanism makes it impossible to guarantee that data is only accessed by authorized parties.

[0027] To address the aforementioned problems in the communication process, this application provides a method for encrypting call data. In response to a call request initiated by a first device, the method encrypts a first private key generated by the first device using a pre-stored target public key to obtain a first encrypted private key. The first encrypted private key and its corresponding first public key are stored in a blockchain, and a storage transaction message returned by the blockchain is obtained. The storage transaction message is sent to a second device corresponding to the call request, causing the second device to store a second encrypted private key and a second public key in the blockchain. Then, the first device encrypts its call data using the second public key in the blockchain to obtain first encrypted data. In this way, third-party users (e.g., enterprises) need to decrypt the second encrypted private key using the target private key corresponding to the target public key to obtain the second private key, and then use the second private key to decrypt the first encrypted data of the first device to obtain the call data. Since the first device's call data cannot be directly accessed, it ensures that only the enterprise can decrypt and obtain the call data, thereby reducing the risk of call data leakage and misuse, and improving the security of call data.

[0028] Figure 1 This diagram illustrates a flowchart of a call data encryption method provided in an embodiment of this application. The execution subject of this method can be a terminal device, such as a personal computer or a mobile terminal device like a mobile phone or tablet. The terminal device can be a user-used terminal device. As shown in the diagram, the call data encryption method 100 may include the following steps:

[0029] Step 101: In response to the call request initiated by the first device, encrypt the first private key generated by the first device using the pre-stored target public key to obtain the first encrypted private key.

[0030] In practical implementation, taking the call data of enterprise employees as an example, an enterprise employee initiates a call request through a first device. The encryption application in the first device can use an asymmetric encryption algorithm to generate a one-time session key pair for each call. The session key pair includes a first private key SK. c PK with the first public key c Among them, asymmetric encryption algorithms include the RSA encryption algorithm.

[0031] The first device uses a pre-stored target public key PK. E The first private key SK generated for the first device c Encryption is performed to obtain the first encryption private key Enc(SK). c ).

[0032] Here, the target public key PK E It can be the authorizing party's public key, which the authorizing party can use to perform a key-click attack on the target public key. E The corresponding target private key SK E For the first encrypted private key Enc(SK) c Decrypt to obtain the first private key SK c .

[0033] Step 102: Store the first encrypted private key and the first public key corresponding to the first private key in the blockchain, and obtain the storage transaction message returned by the blockchain.

[0034] In practical implementation, the first device can use the first encrypted private key Enc(SK) c ) and the first public key PK c The data is stored in the blockchain, and the storage transaction message R returned by the blockchain is retrieved. Optionally, the first device can also store the session identifier ID S corresponding to the call request. id , local number p c The target user number p of the second device t Identification information is stored in the blockchain so that the second device can verify the validity of the stored transaction message R based on the identification information stored in the blockchain.

[0035] Step 103: Send the storage transaction message to the second device corresponding to the call request.

[0036] The storage transaction message is used to instruct the second device to store the second device's second encrypted private key and second public key in the blockchain based on the storage transaction message. The second encrypted private key is obtained by the second device encrypting the second private key with the target public key, and the second public key corresponds to the second private key.

[0037] In practice, the first device sends a storage transaction message R to the second device corresponding to the call request. Here, the target user number p in the call request can be used as a reference. t The second device is identified; after obtaining the storage transaction message R, the second device matches its local number p in the blockchain according to the storage transaction message R. c Target user number p t Verify the identification information, for example, verify p t Is this the local number? Verify if R is p. c The generated transaction, verify p c After verifying whether it corresponds to the user who submitted R, the second device's second encrypted private key Enc(SK) is stored in the blockchain. t ) and the second public key PK t The second encryption private key Enc(SK) c ) is used by the second device to target the public key PK E For the second private key SK t It is obtained through encryption.

[0038] Step 104: Encrypt the call data of the first device using the second public key in the blockchain to obtain the first encrypted data.

[0039] In practice, the first device uses the second public key PK in the blockchain. t The call data of the first device is encrypted to obtain the first encrypted data.

[0040] In this way, third-party users (such as enterprises) need to decrypt the second encrypted private key using the target private key corresponding to the target public key. After obtaining the second private key, they can then use the second private key to decrypt the first encrypted data of the first device and obtain the call data. Since the call data of the first device cannot be directly accessed, it is ensured that only the enterprise can decrypt and obtain the call data, thereby reducing the risk of call data leakage and misuse and improving the security of call data.

[0041] In one possible implementation, step 103 above, sending the storage transaction message to the second device corresponding to the call request, includes:

[0042] The call request and the storage transaction message are sent to the operator, who then determines the second device based on the identification information corresponding to the call request and sends the storage transaction message to the second device.

[0043] In this embodiment, a call request and a storage transaction message can be sent to the operator. The operator determines the second device based on the identification information corresponding to the call request and sends the storage transaction message to the second device. The identification information corresponding to the call request may include the target user number p. t The device serial number of the second device, etc.

[0044] In one exemplary embodiment, such as Figure 2 As shown, the above public key exchange method may include the following steps:

[0045] Step 201: The first device initiates a call request and uploads data to the blockchain;

[0046] Specifically, in response to a call request initiated by the first device, a first private key SK of the first device is generated. c PK with the first public key c ; using the pre-stored target public key PK E For the first private key SK c Encryption is performed to obtain the first encryption private key Enc(SK). c ); the first encrypted private key Enc(SK) c First public key PK c , local number p c Target user number p t Target public key PK E Stored in the blockchain;

[0047] Step 202: The first device obtains the storage transaction message R returned by the blockchain;

[0048] Step 203: The first device sends a call request and a stored transaction message R to the operator;

[0049] Step 204: The first device polls the blockchain to check whether the second device stores the second encrypted private key Enc(SK). c ) and the second public key PK t ;

[0050] Step 205: The operator bases the call request on the corresponding p... t Once the identification information is used to determine the second device, a storage transaction message R is sent to the second device;

[0051] Step 206: The second device creates a second private key SK t Second public key PK t ;

[0052] Step 207: The second device verifies the data p on the blockchain based on the stored transaction message R. t and p c ;

[0053] Step 208: The blockchain returns the verification result to the second device;

[0054] Step 209: If the second device determines that the verification was successful based on the verification result, it stores the second encryption private key Enc(SK). t ) and the second public key PK t To the blockchain, the second encrypted private key Enc(SK) c ) is used by the second device to target the public key PK E For the second private key SK t It is obtained through encryption.

[0055] In one possible implementation, step 104 above involves encrypting the call data of the first device using the second public key in the blockchain to obtain first encrypted data, including:

[0056] The call data of the first device is divided into at least one first audio block; the at least one first audio block is encrypted using the second public key to obtain first encrypted data.

[0057] In one exemplary embodiment, the call data of the first device is... P 1 is divided into at least one first audio block. Use the second public key PK t At least one first audio block is encrypted to obtain first encrypted data. .

[0058] The process further includes, after encrypting the call data of the first device using the second public key in the blockchain to obtain the first encrypted data:

[0059] Obtain the first homomorphic hash value corresponding to the first encrypted data; store the first homomorphic hash value in the blockchain so that the second device can verify the validity of the first encrypted data by comparing the first homomorphic hash value and the second homomorphic hash value, wherein the second homomorphic hash value is determined by the second device based on the received first encrypted data.

[0060] In one exemplary embodiment, after obtaining the first encrypted data, the first device acquires the first homomorphic hash value corresponding to the first encrypted data. H 1:

[0061] ;

[0062] The first homomorphic hash value H 1. Stored in the blockchain, the second device receives the first encrypted data sent by the first device. According to the first encrypted data Determine the second homomorphic hash value The second homomorphic hash value can be determined in the following way. :

[0063] ;

[0064] The second device compares the first homomorphic hash value. H 1 and second homomorphic hash value Verify the first encrypted data The validity, if H 1 and If they are different, then the first encrypted data has been tampered with; if they are different... H 1 and If they are the same, further processing is performed. For example, the second device uses the second private key to encrypt the first data. Decryption is performed to obtain the call data from the first device. P 1.

[0065] In one possible implementation, step 104 above, after sending the storage transaction message to the second device corresponding to the call request, further includes:

[0066] The system obtains the second encrypted data sent by the second device and the third homomorphic hash value corresponding to the second encrypted data from the blockchain; based on the second encrypted data, it determines the fourth homomorphic hash value; if the third homomorphic hash value is the same as the fourth homomorphic hash value, it decrypts the second encrypted data using the first private key to obtain the communication data of the second device.

[0067] In one exemplary embodiment, second encrypted data sent by the second device is obtained. and second encrypted data The corresponding third homomorphic hash value H 2; Based on the second encrypted data Determine the fourth homomorphic hash value Specifically, the fourth homomorphic hash value can be determined in the following way. :

[0068] ;

[0069] If the third homomorphic hash value H 2 and the fourth homomorphic hash value If they are different, then the second encrypted data has been tampered with; if the third homomorphic hash value is different... H 2 and the fourth homomorphic hash value If they are the same, then use the first private key SK. c For the second encrypted data Decryption is performed to obtain the communication data of the second device. P 2-i The specific formula is as follows:

[0070] .

[0071] Figure 3 This diagram illustrates another flowchart of the call data encryption method provided in this application embodiment. The executing entity of this method can be a terminal device, such as a personal computer or a mobile terminal device like a mobile phone or tablet. The terminal device can be a user-used terminal device. As shown in the figure, the call data encryption method 300 may include the following steps:

[0072] Step 301: In response to the wake-up request received by the second device, obtain the first encrypted private key and the first public key from the blockchain corresponding to the stored transaction information included in the wake-up request.

[0073] In practical implementation, taking employee call data as an example, the second device can be a device used by the target user corresponding to the call request initiated by the employee through the first device. The first device sends the call request and storage transaction message to the operator, which then invokes the second device to respond based on the identifier information corresponding to the call request. The second device responds to the invoke request received, which includes the storage transaction message R sent by the first device. The first encrypted private key Enc(SK) corresponding to the storage transaction information R is obtained from the blockchain. c ) and the first public key PK c .

[0074] Step 302: Encrypt the second private key generated by the second device using the target public key to obtain the second encrypted private key.

[0075] In practice, this is achieved through the target public key PK. E The second private key SK generated for the second device t Encryption is performed to obtain the second encryption private key Enc(SK). t ).

[0076] Here, the target public key PK E This could be the authorizing party's public key. The second device can pre-store this target public key or retrieve it from the blockchain based on stored transaction information. The authorizing party can then use the target public key to perform a PK (player kill) operation. EThe corresponding target private key SK E For the second encrypted private key Enc(SK) t Decrypt to obtain the second private key SK t .

[0077] Step 303: Store the second encrypted private key and the second public key corresponding to the second private key in the blockchain.

[0078] In specific implementation, the second encryption private key Enc(SK) will be used. t ) and the second private key SK t The corresponding second public key PK t Stored in the blockchain so that the first device can PK using the second public key in the blockchain. t The call data of the first device is encrypted to obtain the first encrypted data.

[0079] Step 304: Encrypt the call data of the second device using the first public key to obtain the second encrypted data.

[0080] In practice, the second device uses the first public key PK. c The call data from the second device is encrypted to obtain the second encrypted data.

[0081] In this way, third-party users (e.g., enterprises) need to decrypt the first encrypted private key using the target private key corresponding to the target public key to obtain the first private key. Then, they can use the first private key to decrypt the second encrypted data of the second device and obtain the call data. Since the call data of the second device cannot be directly accessed, it is ensured that only the enterprise can decrypt and obtain the call data, thereby reducing the risk of call data leakage and misuse and improving the security of call data.

[0082] In one possible implementation, step 303 above, storing the second encrypted private key and the second public key corresponding to the second private key in the blockchain, includes:

[0083] The identification information corresponding to the stored transaction message in the blockchain is verified. If the identification information verification passes, the second encrypted private key and the second public key corresponding to the second private key are stored in the blockchain.

[0084] In this embodiment of the application, after the second device obtains the storage transaction message R, it checks the local number p corresponding to the storage transaction message R in the blockchain. c Target user number p t Verify the identification information, for example, verify p t Is this the local number? Verify if R is p. c The generated transaction, verify pc After verifying whether it corresponds to the user who submitted R, the second device's second encrypted private key Enc(SK) is stored in the blockchain. t ) and the second public key PK t .

[0085] In one possible implementation, step 304 above involves encrypting the call data of the second device using the first public key to obtain second encrypted data, including:

[0086] The call data of the second device is divided into at least one second audio block; the at least one second audio block is encrypted using the first public key to obtain second encrypted data.

[0087] In one exemplary embodiment, the call data of the second device is... P 2 is divided into at least one second audio block. Use the first public key to PK c At least one second audio block is encrypted to obtain second encrypted data. .

[0088] The process, after encrypting the call data of the second device using the first public key to obtain the second encrypted data, further includes:

[0089] Obtain the third homomorphic hash value corresponding to the second encrypted data; store the third homomorphic hash value in the blockchain so that the first device can verify the validity of the second encrypted data by comparing the third homomorphic hash value and the fourth homomorphic hash value, wherein the fourth homomorphic hash value is determined by the first device based on the received second encrypted data.

[0090] In one exemplary embodiment, after obtaining the second encrypted data, the second device acquires the third homomorphic hash value corresponding to the second encrypted data. H 2:

[0091] ;

[0092] The third homomorphic hash value H 2. Stored in the blockchain, the first device receives the second encrypted data sent by the second device. According to the second encrypted data Determine the fourth homomorphic hash value The fourth homomorphic hash value can be determined in the following way. :

[0093] ;

[0094] The second device compares the third homomorphic hash value. H 2 and the fourth homomorphic hash value Verify the second encrypted data The validity, if H 2 and If they are different, then the second encrypted data has been tampered with; if H 2 and If they are the same, further processing is performed. For example, the first device uses the first private key to encrypt the second data. Decryption is performed to obtain the call data from the second device. P 2.

[0095] In one possible implementation, step 304 above, after storing the second encrypted private key and the second public key corresponding to the second private key in the blockchain, further includes:

[0096] The system obtains the first encrypted data sent by the first device and the first homomorphic hash value corresponding to the first encrypted data from the blockchain; determines the second homomorphic hash value based on the first encrypted data; and decrypts the first encrypted data using the second private key when the first homomorphic hash value and the second homomorphic hash value are the same, thereby obtaining the communication data of the first device.

[0097] In one exemplary embodiment, first encrypted data sent by the first device is obtained. and second encrypted data The corresponding first homomorphic hash value H 1; Based on the first encrypted data Determine the second homomorphic hash value Specifically, the second homomorphic hash value can be determined in the following way. :

[0098] ;

[0099] If the first homomorphic hash value H 1 and the second homomorphic hash value If they are different, then the first encrypted data has been tampered with; if the first homomorphic hash value is different... H 1 and the second homomorphic hash value If they are the same, then use the second private key SK. t For the first encrypted data Decryption is performed to obtain the communication data of the first device. P 1-i The specific formula is as follows:

[0100] .

[0101] Figure 4 The figure shows a schematic diagram of the encrypted data exchange process provided in an embodiment of this application. As shown in the figure, unlike the centralized storage and management of call data by the operator in related technologies, in this embodiment, the first encrypted data C of the first device 420 is forwarded by the operator 410. 1-i To the second device 430, and to forward the second encrypted data C from the second device 430 2-i The data is transmitted to the first device 420 to enable communication data exchange between the first device 420 and the second device 430. The first device 420 uploads the first homomorphic hash value. H 1. Connect to the blockchain and obtain the third homomorphic hash value from the blockchain. H 2. Used to verify the second encrypted data C sent by the second device 430 2-i The validity of the second device 430 uploading the third homomorphic hash value. H 2. Connect to the blockchain and retrieve the first homomorphic hash value from the blockchain. H 1. Used to verify the first encrypted data C sent by the first device 420 1-i The validity of the call request. The authorizing party 440 (e.g., an enterprise) downloads the session S corresponding to the call request from the blockchain. id Obtain encrypted data C 1-i and C 2-i and the first encrypted private key Enc(SK) c ) and the second encrypted private key Enc(SK t Using the target public key PK E The corresponding target private key SK E Decrypting Enc(SK) c ) and Enc(SK t Get the SK of this call c SK t Then through SK c SK t User call data C 1-i and C 2-i Decryption is performed to obtain call data, so that the authorized party 440 can evaluate the performance of the employees of the company corresponding to the first device 420 based on the call content.

[0102] Figure 5 This illustration shows one of the structural schematic diagrams of a call data encryption device provided in an embodiment of this application. This call data encryption device can achieve the following: Figure 1 The call data encryption device 500, as shown in all or part of the embodiments illustrated, includes:

[0103] The first encryption module 510 is used to respond to a call request initiated by the first device by encrypting the first private key generated by the first device using a pre-stored target public key to obtain a first encryption private key.

[0104] The message acquisition module 520 is used to store the first encrypted private key and the first public key corresponding to the first private key into the blockchain, and to acquire the storage transaction message returned by the blockchain;

[0105] Message sending module 530 is used to send a storage transaction message to the second device corresponding to the call request. The storage transaction message is used to instruct the second device to store the second device's second encrypted private key and second public key in the blockchain based on the storage transaction message. The second encrypted private key is obtained by the second device encrypting the second private key with the target public key. The second public key corresponds to the second private key.

[0106] The second encryption module 540 is used to encrypt the call data using the second public key in the blockchain to obtain the first encrypted data.

[0107] In one possible implementation, the message sending module 530, when used to send the storage transaction message to the second device corresponding to the call request, is specifically used for:

[0108] The call request and the storage transaction message are sent to the operator, who then determines the second device based on the identification information corresponding to the call request and sends the storage transaction message to the second device.

[0109] In one possible implementation, the second encryption module 540, when used to encrypt call data using the second public key in the blockchain to obtain the first encrypted data, is specifically used for:

[0110] The call data in the blockchain is divided into at least one first audio block;

[0111] The first audio block is encrypted using the second public key to obtain the first encrypted data.

[0112] In one possible implementation, the second encryption module 540 is also used for:

[0113] Obtain the first homomorphic hash value corresponding to the first encrypted data;

[0114] The first homomorphic hash value is stored in the blockchain so that the second device can verify the validity of the first encrypted data by comparing the first homomorphic hash value and the second homomorphic hash value, wherein the second homomorphic hash value is determined by the second device based on the received first encrypted data.

[0115] In one possible implementation, the message sending module 530 is further configured to:

[0116] Obtain the second encrypted data sent by the second device, and the third homomorphic hash value corresponding to the second encrypted data;

[0117] Based on the second encrypted data, determine the fourth homomorphic hash value;

[0118] If the third homomorphic hash value is the same as the fourth homomorphic hash value, the second encrypted data is decrypted using the first private key to obtain the communication data of the second device.

[0119] This application provides a call data encryption device, including a first encryption module, a message acquisition module, a message sending module, and a second encryption module. The first encryption module, in response to a call request initiated by a first device, encrypts a first private key generated by the first device using a pre-stored target public key to obtain a first encrypted private key. The message acquisition module stores the first encrypted private key and the corresponding first public key in a blockchain, and obtains a storage transaction message returned by the blockchain. The message sending module sends the storage transaction message to the second device corresponding to the call request, instructing the second device to store its second encrypted private key and second public key in the blockchain based on the storage transaction message. The second encryption module encrypts the call data using the second public key in the blockchain to obtain first encrypted data. In this way, third-party users (e.g., enterprises) need to decrypt the second encrypted private key using the target private key corresponding to the target public key to obtain the second private key, and then use the second private key to decrypt the first encrypted data of the first device to obtain the call data. Since the call data of the first device cannot be directly accessed, it ensures that only the enterprise can decrypt and obtain the call data, thereby reducing the risk of call data leakage and misuse, and improving the security of call data.

[0120] Figure 6 This is a second schematic diagram of the structure of the call data encryption device provided in an embodiment of this application. This call data encryption device can achieve the following: Figure 3 The call data encryption device 600, as shown in all or part of the embodiments illustrated, includes:

[0121] The key acquisition module 610 is used to, in response to a wake-up request received by the second device, acquire from the blockchain a first encrypted private key and a first public key corresponding to the stored transaction information included in the wake-up request;

[0122] The third encryption module 620 is used to encrypt the second private key generated by the second device using the target public key to obtain the second encryption private key;

[0123] The key storage module 630 is used to store the second encrypted private key and the second public key corresponding to the second private key into the blockchain;

[0124] The fourth encryption module 640 is used to encrypt the call data using the first public key to obtain the second encrypted data.

[0125] In one possible implementation, the key storage module 630, when storing the second encrypted private key and the second public key corresponding to the second private key in the blockchain, is specifically used for:

[0126] The identification information corresponding to the stored transaction message in the blockchain is verified. If the identification information verification passes, the second encrypted private key and the second public key corresponding to the second private key are stored in the blockchain.

[0127] In one possible implementation, the fourth encryption module 640, when used to encrypt call data using the first public key in the blockchain to obtain second encrypted data, is specifically used for:

[0128] Divide the call data into at least one second audio block;

[0129] The first public key is used to encrypt the at least one second audio block to obtain second encrypted data.

[0130] In one possible implementation, the fourth encryption module 640 is also used for:

[0131] Obtain the third homomorphic hash value corresponding to the second encrypted data;

[0132] The third homomorphic hash value is stored in the blockchain so that the first device can verify the validity of the second encrypted data by comparing the third homomorphic hash value and the fourth homomorphic hash value, wherein the fourth homomorphic hash value is determined by the first device based on the received second encrypted data.

[0133] In one possible implementation, the key storage module 630 is also used for:

[0134] Obtain the first encrypted data sent by the first device, and the first homomorphic hash value corresponding to the first encrypted data;

[0135] Based on the first encrypted data, determine the second homomorphic hash value;

[0136] If the first homomorphic hash value is the same as the second homomorphic hash value, the first encrypted data is decrypted using the second private key to obtain the communication data of the first device.

[0137] This application provides a call data encryption device, including a key acquisition module, a third encryption module, a key storage module, and a fourth encryption module. The key acquisition module, in response to a wake-up request received by a second device, retrieves a first encryption private key and a first public key from the blockchain, corresponding to the storage transaction information included in the wake-up request. The third encryption module encrypts a second private key generated by the second device using a target public key to obtain a second encryption private key. The key storage module stores the second encryption private key and the corresponding second public key in the blockchain. The fourth encryption module encrypts call data using the first public key to obtain second encrypted data. In this way, third-party users (e.g., enterprises) need to decrypt the first encryption private key using the target private key corresponding to the target public key to obtain the first private key, and then use the first private key to decrypt the second encrypted data of the second device to obtain the call data. Since direct access to the call data of the second device is not possible, it ensures that only the enterprise can decrypt and obtain the call data, thereby reducing the risk of call data leakage and misuse, and improving the security of call data.

[0138] Figure 7 This diagram illustrates the hardware structure of an electronic device implementing the embodiments of this application. Referring to the diagram, at the hardware level, the electronic device 700 includes a processor 710, and optionally includes an internal bus 720, a network interface 730, and a memory 740. The memory 740 may include main memory 741, such as high-speed random-access memory (RAM), and may also include non-volatile memory 742, such as at least one disk storage device. Of course, the electronic device 700 may also include other hardware required for other services.

[0139] The processor 710, network interface 730, and memory can be interconnected via an internal bus 720. This internal bus 720 can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be categorized as an address bus, data bus, control bus, etc. For ease of illustration, only a single bidirectional arrow is used in this diagram, but this does not imply that there is only one bus or one type of bus.

[0140] Memory 740 stores programs. Specifically, the program may include program code, which includes computer operation instructions. Memory 740 may include main memory 741 and non-volatile memory 742, and provides instructions and data to processor 710.

[0141] The processor 710 reads the corresponding computer program from the non-volatile memory 742 into memory and then runs it, forming a device for locating the target user at the logical level. The processor 710 executes the program stored in memory and specifically performs the following: Figure 1 or Figure 3 The methods disclosed in the embodiments shown achieve the functions and beneficial effects of the methods described in the preceding method embodiments, and will not be repeated here.

[0142] The above is as stated in this application. Figure 1 or Figure 3The methods disclosed in the illustrated embodiments can be applied to or implemented by processor 710. Processor 710 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above methods can be completed by integrated logic circuits in the hardware of processor 710 or by instructions in software form. The processor 710 can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this application can be directly embodied in the execution of a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software module can reside in a mature storage medium in the field, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, or registers. This storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method.

[0143] The computer device can also execute the methods described in the preceding method embodiments and achieve the functions and beneficial effects of the methods described in the preceding method embodiments, which will not be repeated here.

[0144] Of course, in addition to software implementation, the electronic device 700 of this application does not exclude other implementation methods, such as logic devices or a combination of hardware and software, etc. In other words, the execution subject of the following processing flow is not limited to each logic unit, but can also be hardware or logic devices.

[0145] This application also proposes a computer-readable storage medium that stores one or more programs, which, when executed by an electronic device including multiple applications, cause the electronic device to perform... Figure 1 or Figure 3 The methods disclosed in the embodiments shown achieve the functions and beneficial effects of the methods described in the preceding method embodiments, and will not be repeated here.

[0146] The computer-readable storage medium mentioned above includes read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk, etc.

[0147] Furthermore, embodiments of this application also provide a computer program product, the computer program product including a computer program stored on a non-transitory computer-readable storage medium, the computer program including program instructions, which, when executed by a computer, implement the following process: Figure 1 or Figure 3 The methods disclosed in the embodiments shown achieve the functions and beneficial effects of the methods described in the preceding method embodiments, and will not be repeated here.

[0148] The embodiments of this application can be applied to various scenarios of electronic device collaboration or interconnection, including: collaboration and interconnection between mobile phones and laptops / tablets; collaboration and interconnection between mobile terminals and smart TVs / monitors; collaboration and interconnection between mobile phones or tablets and in-vehicle entertainment systems; collaboration and interconnection between mobile terminals and smart conferencing systems, etc. This satisfies users' diverse needs in smart home, smart office, and smart travel scenarios.

[0149] In summary, the above description is merely a preferred embodiment of this application and does not limit the scope of protection of this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.

[0150] The systems, devices, modules, or units described in the above embodiments can be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, a computer can be, for example, a personal computer, laptop computer, cellular phone, camera phone, smartphone, personal digital assistant, media player, navigation device, email device, game console, tablet computer, wearable device, or any combination of these devices.

[0151] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information by any method or technology. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can store information accessible to a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0152] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0153] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the system embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments.

Claims

1. A method for encrypting call data, characterized in that, include: In response to a call request initiated by the first device, the first private key generated by the first device is encrypted using a pre-stored target public key to obtain a first encrypted private key; The target public key is the public key of the authorizing party; Store the first encrypted private key and the first public key corresponding to the first private key in the blockchain, and obtain the storage transaction message returned by the blockchain; Send the storage transaction message to the second device corresponding to the call request. The storage transaction message is used to instruct the second device to store the second device's second encrypted private key and second public key in the blockchain based on the storage transaction message. The second encrypted private key is obtained by the second device encrypting the second private key with the target public key. The second public key corresponds to the second private key. The call data of the first device is encrypted using the second public key in the blockchain to obtain the first encrypted data. The step of sending the storage transaction message to the second device corresponding to the call request includes: The call request and the storage transaction message are sent to the operator, who then determines the second device based on the identification information corresponding to the call request and sends the storage transaction message to the second device.

2. The method according to claim 1, characterized in that, The step of encrypting the call data of the first device using the second public key in the blockchain to obtain the first encrypted data includes: The call data of the first device is divided into at least one first audio block; The first audio block is encrypted using the second public key to obtain the first encrypted data.

3. The method according to claim 1, characterized in that, After encrypting the call data of the first device using the second public key in the blockchain to obtain the first encrypted data, the method further includes: Obtain the first homomorphic hash value corresponding to the first encrypted data; The first homomorphic hash value is stored in the blockchain so that the second device can verify the validity of the first encrypted data by comparing the first homomorphic hash value and the second homomorphic hash value, wherein the second homomorphic hash value is determined by the second device based on the received first encrypted data.

4. The method according to claim 1, characterized in that, After sending the storage transaction message to the second device corresponding to the call request, the method further includes: Obtain the second encrypted data sent by the second device, and obtain the third homomorphic hash value corresponding to the second encrypted data from the blockchain; Based on the second encrypted data, determine the fourth homomorphic hash value; If the third homomorphic hash value is the same as the fourth homomorphic hash value, the second encrypted data is decrypted using the first private key to obtain the communication data of the second device.

5. A method for encrypting call data, characterized in that, include: In response to a wake-up request received by the second device, a first encrypted private key and a first public key corresponding to the stored transaction information included in the wake-up request are obtained from the blockchain; The storage transaction message is used to instruct the second device to store the second device's second encrypted private key and second public key in the blockchain based on the storage transaction message; The second private key generated by the second device is encrypted using the target public key to obtain the second encrypted private key; The second encrypted private key and the second public key corresponding to the second private key are stored in the blockchain; The call data of the second device is encrypted using the first public key to obtain the second encrypted data. The step of storing the second encrypted private key and the second public key corresponding to the second private key in the blockchain includes: The identification information corresponding to the stored transaction message in the blockchain is verified. If the identification information verification passes, the second encrypted private key and the second public key corresponding to the second private key are stored in the blockchain.

6. The method according to claim 5, characterized in that, The step of encrypting the call data of the second device using the first public key to obtain the second encrypted data includes: The call data of the second device is divided into at least one second audio block; The first public key is used to encrypt the at least one second audio block to obtain second encrypted data.

7. The method according to claim 5, characterized in that, After encrypting the call data of the second device using the first public key to obtain the second encrypted data, the method further includes: Obtain the third homomorphic hash value corresponding to the second encrypted data; The third homomorphic hash value is stored in the blockchain so that the first device can verify the validity of the second encrypted data by comparing the third homomorphic hash value and the fourth homomorphic hash value, wherein the fourth homomorphic hash value is determined by the first device based on the received second encrypted data.

8. The method according to claim 5, characterized in that, After storing the second encrypted private key and the corresponding second public key in the blockchain, the method further includes: Obtain the first encrypted data sent by the first device, and obtain the first homomorphic hash value corresponding to the first encrypted data from the blockchain; Based on the first encrypted data, determine the second homomorphic hash value; If the first homomorphic hash value is the same as the second homomorphic hash value, the first encrypted data is decrypted using the second private key to obtain the communication data of the first device.

9. A call data encryption device, characterized in that, include: The first encryption module is used to respond to a call request initiated by the first device by encrypting the first private key generated by the first device using a pre-stored target public key to obtain a first encryption private key; the target public key is the public key of the authorizing party. The message acquisition module is used to store the first encrypted private key and the first public key corresponding to the first private key into the blockchain, and to acquire the storage transaction message returned by the blockchain; The message sending module is used to send a storage transaction message to the second device corresponding to the call request. The storage transaction message is used to instruct the second device to store the second device's second encrypted private key and second public key in the blockchain based on the storage transaction message. The second encrypted private key is obtained by the second device encrypting the second private key with the target public key. The second public key corresponds to the second private key. The second encryption module is used to encrypt the call data using the second public key in the blockchain to obtain the first encrypted data; Specifically, the message sending module, when used to send the stored transaction message to the second device corresponding to the call request, is used for: The call request and the storage transaction message are sent to the operator, who then determines the second device based on the identification information corresponding to the call request and sends the storage transaction message to the second device.

10. A call data encryption device, characterized in that, include: The key acquisition module is used to, in response to a wake-up request received by the second device, acquire from the blockchain a first encrypted private key and a first public key corresponding to the stored transaction information included in the wake-up request; The storage transaction message is used to instruct the second device to store the second device's second encrypted private key and second public key in the blockchain based on the storage transaction message; The third encryption module is used to encrypt the second private key generated by the second device using the target public key to obtain the second encryption private key; A key storage module is used to store the second encrypted private key and the second public key corresponding to the second private key into the blockchain; The fourth encryption module is used to encrypt the call data using the first public key to obtain the second encrypted data; The key storage module, when used to store the second encrypted private key and the second public key corresponding to the second private key in the blockchain, is specifically used for: The identification information corresponding to the stored transaction message in the blockchain is verified. If the identification information verification passes, the second encrypted private key and the second public key corresponding to the second private key are stored in the blockchain.

11. An electronic device, characterized in that, It includes a processor and a memory, the memory storing a program or instructions that can run on the processor, the program or instructions being executed by the processor to implement the steps of the method as described in any one of claims 1 to 8.

12. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a program or instructions that, when executed by a processor, implement the steps of the method as described in any one of claims 1 to 8.

13. A computer program product, characterized in that, The computer program product includes a computer program stored on a non-transitory computer-readable storage medium, the computer program including program instructions that, when executed by a computer, cause the computer to perform the steps of the method as described in any one of claims 1 to 8.

Citation Information

Patent Citations

  • Wireless sensor network and computer network fused network secret key management method

    CN102315935A

  • Network call method and device based on block chain, and storage medium

    CN116545711A