A data distribution method, system, electronic device and storage medium

By using a group key seed mechanism, the sending and receiving nodes generate symmetric encryption and decryption keys, which solves the problem of low efficiency in traditional data encryption transmission and realizes efficient and secure distribution of data in one-to-many transmission.

CN119696896BActive Publication Date: 2026-01-16AISINO CORPORATION
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411865714.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-17
Publication Date
2026-01-16
Estimated Expiration
2044-12-17

AI Technical Summary

Technical Problem

Traditional data encryption transmission methods are inefficient, leading to a decline in data transmission efficiency and system performance. This is especially true in one-to-many data transmission scenarios, where the need for one-to-one key negotiation increases complexity.

Method used

A group key seed mechanism is adopted, in which a group key seed is generated and distributed by the key management terminal. The sending node and the receiving node generate symmetric encryption and decryption keys based on the identification information to realize data encryption and decryption, avoiding one-to-one key negotiation.

Benefits of technology

It improves data distribution efficiency and security, reduces key management complexity, and ensures the reliability and security of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119696896B_ABST
    Figure CN119696896B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a data distribution method and system, electronic equipment and storage medium, the method comprising: obtaining a group key seed from a key management end; generating an encryption and decryption key according to the group key seed and identification information of a sending node; encrypting to-be-sent data through the encryption and decryption key to obtain encrypted data; and sending the encrypted data to at least one receiving node, so that the receiving node generates the encryption and decryption key according to the identification information and the group key seed obtained from the key management end, and then decrypts the received encrypted data through the encryption and decryption key to obtain the to-be-sent data. The data distribution method provided by the present application can improve the efficiency of one-to-many data distribution.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Embodiments of the present application relate to the technical field of data transmission, and in particular to a data distribution method and system, an electronic device, and a storage medium. BACKGROUND

[0002] Currently, information systems in multiple fields and industries have data one-to-many aggregation and distribution business needs. These data are mostly real-time structured data, with single data capacity being small, capacity size being in the order of KB to MB, and the number of daily processed data being extremely large, usually more than 100 million per day.

[0003] Due to data transmission security considerations, data encryption is usually required in the process of data one-to-many transmission to prevent data leakage. However, the traditional data encryption transmission method usually adopts one-to-one key negotiation, which means that the sender must negotiate the key with each receiver one by one before data transmission. This method is not only inefficient, but also causes the sender to generate different encrypted data for each receiver, which seriously affects the efficiency of data transmission and may cause system performance degradation. SUMMARY

[0004] Therefore, embodiments of the present application provide a data distribution method and system, an electronic device, and a storage medium to at least partially solve the above problems.

[0005] According to a first aspect of embodiments of the present application, a data distribution method is provided, applied to a sending node, comprising: obtaining a group key seed from a key management end; generating an encryption and decryption key according to the group key seed and identification information of the sending node; encrypting to-be-sent data through the encryption and decryption key to obtain encrypted data; and sending the encrypted data to at least one receiving node, so that the receiving node generates the encryption and decryption key according to the identification information and the group key seed obtained from the key management end, and then decrypts the received encrypted data through the encryption and decryption key to obtain the to-be-sent data.

[0006] According to a second aspect of embodiments of the present application, a data distribution method is provided, applied to a receiving node, comprising: receiving encrypted data from a sending node, wherein the encrypted data is obtained by the sending node by encrypting to-be-sent data through an encryption and decryption key, and the encryption and decryption key is generated by the sending node according to identification information of the sending node and a group key seed obtained from a key management end; obtaining the group key seed from the key management end; generating the encryption and decryption key according to the group key seed and the identification information of the sending node; and decrypting the encrypted data through the encryption and decryption key to obtain the to-be-sent data.

[0007] According to a third aspect of the embodiments of the present application, a data distribution system is provided, comprising: a key management end, at least one sending node and at least one receiving node; the sending node is configured to execute any of the data distribution methods applied to the sending node; the receiving node is configured to execute any of the data distribution methods applied to the receiving node; and the key management end is configured to receive a public key of the sending node or the receiving node, encrypt a group key seed by using the public key to obtain an encrypted key, and send the encrypted key to the sending node or the receiving node sending the public key.

[0008] According to a fourth aspect of the embodiments of the present application, a data distribution method is provided, and an electronic device is provided, comprising: a processor, a memory, a communication interface and a communication bus, the processor, the memory and the communication interface are in communication with each other through the communication bus; the memory is configured to store at least one executable instruction, and the executable instruction is configured to make the processor execute the operations corresponding to any of the data distribution methods.

[0009] According to a fifth aspect of the embodiments of the present application, a computer storage medium is provided, and the computer storage medium stores a computer program, and the program is executed by a processor to implement any of the data distribution methods. BRIEF DESCRIPTION OF DRAWINGS

[0010] In order to more clearly illustrate the technical solutions of the embodiments of the present application or the prior art, the drawings needed in the embodiments or the prior art description will be briefly introduced as follows. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can also be obtained by those skilled in the art based on these drawings.

[0011] Figure 1 is a flowchart of a data distribution method of an embodiment of the present application;

[0012] Figure 2 is a flowchart of another data distribution method of an embodiment of the present application;

[0013] Figure 3 is a schematic diagram of a data distribution system of an embodiment of the present application;

[0014] Figure 4 is a data distribution flowchart of a data distribution system of an embodiment of the present application;

[0015] Figure 5 is a schematic diagram of an electronic device of an embodiment of the present application. DETAILED DESCRIPTION

[0016] Data distribution method

[0017] The embodiment of the present application provides a data distribution method, which can be applied to a one-to-many convergent distribution service of data in an information system, and the embodiment of the present application does not limit this. Through the method, the efficiency of sending data from a sending node to multiple receiving nodes can be improved.

[0018] Figure 1 FIG. 1 is a flowchart of a data distribution method according to an embodiment of the present application. The data distribution method according to the embodiment of the present application is applied to a sending node. Through the method according to the embodiment of the present application, the data transmission security can be ensured, and the data distribution efficiency for multiple receiving nodes can be improved.

[0019] As shown in FIG. 1, the data distribution method according to the embodiment of the present application includes the following steps. Figure 1

[0020] Step 101: Obtain a group key seed from a key management end.

[0021] In some embodiments, the key management end can generate the group key seed based on a preset period, encrypt the group key seed based on the public key of each sending node sent to the key management end, and then send the encrypted key information corresponding to the encrypted group key seed to each sending node. Each sending node can obtain the encrypted key information corresponding to the encrypted group key seed from the key management end based on a preset period.

[0022] In some embodiments, the hardware device of each sending node stores a digital certificate, which can be a national secret digital certificate, and includes the public key, the national secret signature algorithm, the signature hash algorithm, the valid period and other information. The sending node can send the identification information and the public key of the node to the key management end, so that the key management end manages the public key of each sending node based on the identification information of the node. The sending node can also update the digital certificate regularly and send the updated digital certificate to the key management end.

[0023] In some embodiments, each sending node can generate a private key corresponding to the node. After receiving the encrypted key information sent by the key management end, each sending node can verify the signature of the encrypted key information through the digital certificate, and after verifying that the signature of the encrypted key information is passed, perform the step of decrypting the encrypted key information through the private key of the sending node. The encrypted key information includes a digital envelope, and the signature of the encrypted key information includes the identity information of the key management end. After obtaining the encrypted key information, the sending node can verify the signature of the encrypted key information through the digital certificate to determine the sender of the encrypted key information. If the sender is the key management end, the sending node decrypts the received encrypted key information through the private key of the sending node to obtain the group key seed.

[0024] ​Step 102: Generate encryption and decryption keys based on the group key seed and the identifier information of the sending node.

[0025] In some embodiments, after obtaining the group key seed, the sending node can generate a symmetric encryption / decryption key based on the group key seed and the sending node's identification information. As an example, the encryption / decryption key can be generated based on the SM3 algorithm (a national cryptographic algorithm) using the group key seed and identification information.

[0026] Step 103: Encrypt the data to be sent using the encryption / decryption key to obtain encrypted data.

[0027] In some embodiments, the sending node can perform symmetric encryption on the data to be sent based on the encryption / decryption key to obtain encrypted data.

[0028] Step 104: Send the encrypted data to at least one receiving node.

[0029] In some embodiments, the sending node can send encrypted data to one or more receiving nodes, so that the receiving nodes can generate encryption / decryption keys based on the identification information and the key seed obtained from the key management terminal, and then decrypt the received encrypted data using the encryption / decryption keys to obtain the data to be sent. If multiple receiving nodes exist, the sending node can directly copy the encrypted data and send the copied data to multiple receiving nodes.

[0030] In this embodiment, the public key of the sending node is centrally managed by the key management terminal, reducing the complexity of key management. The key management terminal generates a group key seed and encrypts it based on the public key of the sending node before sending it to the sending node, ensuring the security of the group key seed transmission process. After receiving the signed encrypted key information, the sending node authenticates the identity by verifying the signature, ensuring the security and reliability of communication. The sending node uses its own identification information and the group key seed to generate a unique symmetric key, i.e., the encryption and decryption key, ensuring the security of encryption. If there are multiple receiving nodes, the sending node only needs to copy the encryption and decryption key to be sent into the encrypted data, avoiding the need for one-to-one key negotiation in one-to-many transmission, and improving the efficiency of data distribution while ensuring reliable data transmission.

[0031] Data distribution method

[0032] Figure 3 This is a processing flow of a data distribution method according to another embodiment of this application. The data distribution method of this embodiment can be applied to receiving nodes. Through the method of this embodiment, the efficiency of multiple receiving nodes receiving data to be sent from sending nodes can be improved, including the following steps:

[0033] Step 201, receiving encrypted data from a sending node.

[0034] In some embodiments, the encrypted data is obtained by the sending node encrypting the data to be sent by a decryption key, which is generated by the sending node according to the identification information of the sending node and a group key seed obtained from a key management end.

[0035] Step 202, obtaining a group key seed from a key management end.

[0036] In some embodiments, the key management end can generate a group key seed based on a preset period, encrypt the group key seed based on the public key of each receiving node sent to the key management end, and send the encrypted group key seed corresponding to the encryption key information to each receiving node. Wherein, each receiving node can obtain the encryption key information corresponding to the encrypted group key seed from the key management end based on a preset period.

[0037] In some embodiments, the hardware device of each receiving node stores a digital certificate, which can be a national secret digital certificate, containing public key, national secret signature algorithm, signature hash algorithm, validity period and other information. The receiving node can send the identification information and public key of the node to the key management end for the key management end to manage the public key of each receiving node based on the identification information of the node. The receiving node can also update the digital certificate regularly and send the updated digital certificate to the key management end.

[0038] In some embodiments, each receiving node can generate a private key corresponding to the node, and after receiving the encryption key information sent by the key management end, the receiving node can verify the signature of the encryption key information through the digital certificate, and after verifying that the signature of the encryption key information is passed, the receiving node can execute the step of decrypting the encryption key information through the private key of the receiving node. Wherein, the encryption key information includes a digital envelope, and the signature of the encryption key information includes the identity information of the key management end. After obtaining the encryption key information, the receiving node can verify the signature of the encryption key information through the digital certificate to determine the sender of the encryption key information. If the sender is the key management end, the receiving node decrypts the received encryption key information through its own private key to obtain the group key seed.

[0039] Step 203, generating a decryption key according to the group key seed and the identification information of the sending node.

[0040] In some embodiments, after obtaining the group key seed, the receiving node can generate a symmetric encryption and decryption key according to the group key seed and the identification information of the sending node. As an example, the encryption and decryption key can be generated based on the group key seed and the identification information based on the SM3 algorithm in the national secret algorithm.

[0041] Step 204, decrypting the encrypted data by the encryption and decryption key to obtain the to-be-sent data.

[0042] In some embodiments, after receiving the encrypted data sent by the sending node, the receiving node can decrypt the encrypted data based on the encryption and decryption key to obtain the to-be-sent data.

[0043] In the embodiments of the present application, the key management end generates a group key seed and encrypts the group key seed based on the public key of the receiving node and then sends the encrypted group key seed to the receiving node, which ensures the security of the group key seed in the transmission process. After receiving the signed encrypted key information, the receiving node performs identity authentication on the signature, which ensures the security and reliability of the communication. The receiving node generates a unique symmetric key, i.e., an encryption and decryption key, using its own identification information and the group key seed, which ensures the security of the encryption. After receiving the encrypted data sent by the sending node, the receiving node only needs to decrypt the encrypted data by using the encryption and decryption key, which avoids the need for one-to-one key negotiation in the one-to-many transmission process. In the process of ensuring reliable data transmission, the efficiency of data reception is improved.

[0044] Data distribution system

[0045] Corresponding to the above data distribution method embodiments, Figure 3 FIG. 3 shows a schematic diagram of a data distribution system according to an embodiment of the present application. As shown in Figure 3 The data distribution system 300 includes:

[0046] The sending node 301 is configured to perform the data distribution method corresponding to the sending node in the above embodiments.

[0047] The receiving node 302 is configured to perform the data distribution method corresponding to the receiving node in the above embodiments.

[0048] The key management end 303 is configured to receive the public key of the sending node or the receiving node, encrypt the group key seed by the public key to obtain encrypted key information, and send the encrypted key information to the sending node or the receiving node corresponding to the public key.

[0049] As an example, as shown in Figure 4 Figure 4 ​In this system, the hardware devices corresponding to sending node A, receiving node B, receiving node C, and receiving node D all store digital certificates, which can be national cryptographic digital certificates. Each node can send its own identification information and public key to the key management terminal, which then manages the public keys of each node uniformly. The key management terminal can periodically generate a group key seed, such as generating a random seed value based on a pseudo-random number generator, and then determining the group key seed based on the seed value using a key derivation function, thus ensuring that the group key seed possesses randomness, unpredictability, and security. The group key seed is then encrypted using the public keys of each node to obtain the encrypted key information.

[0050] Sending node A can obtain the encryption key information corresponding to the group key seed generated by the current key management terminal, and decrypt the encryption key information using its private key to obtain the group key seed. Sending node A calculates the encryption / decryption key based on its own node identification information and the group key seed; it encrypts the data to be sent using the encryption / decryption key to obtain encrypted data, copies the encrypted data, and sends it to receiving nodes B, C, and D.

[0051] Taking receiving node B as an example, receiving node B can obtain the encryption key information corresponding to the group key seed generated by the current key management terminal, and decrypt the encryption key information using its private key to obtain the group key seed. Receiving node B calculates the encryption / decryption key based on the identifier information of sending node A and the group key seed; it then decrypts the encrypted data sent by sending node A using the encryption / decryption key to obtain the data to be sent by the sending node. Similarly, receiving nodes C and D obtain the data to be sent by sending node A in the same way as receiving node B, and will not be described in detail.

[0052] The sending and receiving nodes can also periodically update their respective public keys and send the updated public keys to the key management terminal. If the key management terminal monitors that all nodes have completed the public key updates, it encrypts the group key seed based on the updated public keys of all nodes to obtain the encryption key information.

[0053] The key management terminal and all nodes can also perform authentication when sending and receiving data. For example, after receiving the encryption key information, the sending node or receiving node can verify the signature of the encryption key information through a digital certificate. If the verification is successful, the node will proceed to decrypt the encryption key information using the sending node's private key.

[0054] It should be noted that the data distribution system in this embodiment is used to implement the corresponding data distribution method in the foregoing method embodiments and has the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0055] Electronic device

[0056] Figure 5 The diagram illustrates the structure of an electronic device according to an embodiment of this application. The specific embodiments of this application do not limit the specific implementation of the electronic device.

[0057] like Figure 5 As shown, the electronic device may include: a processor 502, a communications interface 504, a memory 506, and a communications bus 508.

[0058] in:

[0059] The processor 502, communication interface 504, and memory 506 communicate with each other via communication bus 508.

[0060] Communication interface 504 is used to communicate with other electronic devices or servers.

[0061] The processor 502 is used to execute program 510, specifically to perform the relevant steps in the above-described data distribution method embodiment.

[0062] Specifically, program 510 may include program code that includes computer operation instructions.

[0063] The processor 502 may be a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of this application. The smart device includes one or more processors, which may be processors of the same type, such as one or more CPUs; or processors of different types, such as one or more CPUs and one or more ASICs.

[0064] Memory 506 is used to store program 510. Memory 506 may include high-speed RAM memory, and may also include non-volatile memory, such as at least one disk storage device.

[0065] Specifically, program 510 can be used to cause processor 502 to perform the following operations:

[0066] In an alternative implementation, the program 510 is further configured to cause the processor 502 to perform the steps of the program 510. The specific implementation of the steps of the program 510 can be referred to the corresponding description of the steps of the data distribution method embodiments and the corresponding description of the system, which will not be repeated here. It can be clearly understood by those skilled in the art that, for the convenience and brevity of the description, the specific working process of the devices and modules described above can be referred to the corresponding process description in the foregoing method embodiments, which will not be repeated here.

[0067] Computer program product

[0068] The embodiments of the present application also provide a computer program product, comprising computer instructions, which instruct a computing device to perform operations corresponding to any of the data distribution methods in the foregoing method embodiments.

[0069] It should be noted that, according to the needs of implementation, each component / step described in the embodiments of the present application can be split into more components / steps, or two or more components / steps or part of the operations of the components / steps can be combined into a new component / step, to achieve the purpose of the embodiments of the present application.

[0070] Computer-readable storage medium

[0071] The embodiments of the present application also provide a computer readable storage medium, and the method according to the embodiments of the present application can be implemented in hardware, firmware, or as software or computer code that can be stored in a recording medium (such as CD ROM, RAM, floppy disk, hard disk or magneto-optical disk) or downloaded from a network and stored in a local recording medium, so that the method described herein can be processed by such software on a recording medium using a general computer, a special processor or programmable or special hardware (such as ASIC or FPGA). It can be understood that the computer, processor, microprocessor controller or programmable hardware includes a storage component (for example, RAM, ROM, flash memory, etc.) that can store or receive software or computer code, when the software or computer code is accessed and executed by the computer, processor or hardware, the data distribution method described herein is implemented. In addition, when a general computer accesses the code for implementing the data distribution method shown herein, the execution of the code will convert the general computer into a special computer for executing the data distribution method shown herein.

[0072] Those skilled in the art can understand that the units and method steps of each example described in combination with the embodiments disclosed herein can be realized by electronic hardware or a combination of computer software and electronic hardware. Whether the functions are realized in hardware or software manner depends on the specific application and design constraints of the technical solution. The skilled person can use different methods to realize the described functions for each specific application, but such implementation should not be considered as beyond the scope of the embodiments of the present application.

[0073] The above embodiments are only used to illustrate but not to limit the embodiments of the present application. Those skilled in the art can make various changes and modifications without departing from the spirit and scope of the embodiments of the present application, and all equivalent technical solutions belong to the scope of the embodiments of the present application. The patent protection scope of the embodiments of the present application should be defined by the claims.

Claims

1. A data distribution method, characterized by, The method applied to a sending node comprises: obtaining a group key seed from a key management end, each node sending its own identification information and public key to the key management end, and the key management end managing the public key of each node uniformly; generating an encryption and decryption key according to the group key seed and the identification information of the sending node; encrypting the to-be-sent data by using the encryption and decryption key to obtain encrypted data; sending the encrypted data to at least one receiving node, so that the receiving node decrypts the received encrypted data by using the encryption and decryption key generated according to the identification information and the group key seed obtained from the key management end to obtain the to-be-sent data; the step of obtaining the group key seed from the key management end comprises: sending the public key of the sending node to the key management end; receiving encrypted key information sent by the key management end, wherein the encrypted key information is obtained by the key management end by encrypting the group key seed by using the public key of the sending node; decrypting the encrypted key information by using the private key of the sending node to obtain the group key seed.

2. The method of claim 1, wherein, The method further comprises: after receiving the encrypted key information, verifying the signature of the encrypted key information by using a digital certificate, wherein the digital certificate is stored in a key hardware device included in the sending node; after verifying that the signature of the encrypted key information is correct, performing the step of decrypting the encrypted key information by using the private key of the sending node.

3. The method according to claim 1 or 2, characterized in that, The encrypted key information comprises a digital envelope.

4. A data distribution method characterized by, The method applied to a receiving node comprises: receiving encrypted data from a sending node, wherein the encrypted data is obtained by encrypting to-be-sent data by using an encryption and decryption key by the sending node, and the encryption and decryption key is generated by the sending node according to the identification information of the sending node and a group key seed obtained from a key management end; obtaining the group key seed from the key management end, each node sending its own identification information and public key to the key management end, and the key management end managing the public key of each node uniformly; generating the encryption and decryption key according to the group key seed and the identification information of the sending node; decrypting the encrypted data by using the encryption and decryption key to obtain the to-be-sent data; the step of obtaining the group key seed from the key management end comprises: sending the public key of the receiving node to the key management end; receiving encrypted key information sent by the key management end, wherein the encrypted key information is obtained by the key management end by encrypting the group key seed by using the public key of the receiving node; decrypting the encrypted key information by using the private key of the receiving node to obtain the group key seed.

5. The method of claim 4, wherein, The method further comprises: after receiving the encrypted key information, verifying the signature of the encrypted key information by using a digital certificate, wherein the digital certificate is stored in a key hardware device included in the receiving node; After verifying that the signature of the encrypted key information is passed, the step of decrypting the encrypted key information by the private key of the receiving node is performed.

6. A data distribution system characterized by, Comprise: a key management terminal, at least one sending node and at least one receiving node; the sending node is configured to perform the method of any one of claims 1-3; the receiving node is configured to perform the method of any one of claims 4-5; the key management terminal is configured to receive the public key of the sending node or the receiving node, encrypt a group key seed by the public key to obtain an encrypted key, and send the encrypted key to the sending node or the receiving node sending the public key.

7. An electronic device comprising: a processor, a memory, a communication interface and a communication bus, the processor, the memory and the communication interface complete communication with each other through the communication bus; the memory is used to store at least one executable instruction, and the executable instruction makes the processor perform the operation corresponding to the data distribution method of any one of claims 1-3 or 4-5.

8. A computer storage medium having a computer program stored thereon, the program being executed by a processor to implement the data distribution method of any one of claims 1-3 or 4-5.

Citation Information

Patent Citations

  • Key distribution method and device, electronic equipment and storage medium

    CN115834053A

  • Data processing and key management method, data processing device and key management equipment

    CN117527286A