Data encryption method, electronic device and computer-readable storage medium
By flexibly determining the data encryption level based on the network security level of the network node and encrypting it in turn during the data transmission process, the problem of waste of computing resources caused by excessive encryption level in the prior art is solved, and the efficiency and security of data transmission are achieved.
Patent Information
- Application Number
- CN202510208842.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-25
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2045-02-25
AI Technical Summary
The prior art usually uses the highest encryption level when ensuring data transmission security, but this leads to a waste of encrypted computing resources at a large number of terminals and cannot be applied to devices with limited computing resources.
By obtaining the target network transmission path of the data to be transmitted and determining the data encryption level according to the network security level of each network node, the network security level is negatively correlated with the data encryption level, so that the encryption process is performed in turn during the transmission process.
It improves the flexibility and security of data encryption, adapts to the encryption levels of different network nodes, and avoids waste of computing resources caused by excessive encryption levels.
Smart Images

Figure CN119696937B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data processing technology, and in particular to a data encryption method, an electronic device and a computer-readable storage medium. Background Art
[0002] Data transmission methods include network transmission, CD transmission and other methods. Among them, network transmission has gradually become the main data transmission method due to its advantages such as remoteness and speed. Therefore, how to ensure the data security in network transmission is crucial.
[0003] At present, in order to ensure the security of data transmission, the highest encryption level of data encryption is directly used to encrypt the transmitted data to ensure data security. However, this method will bring a large amount of terminal encryption calculations, which not only wastes resources, but also cannot be applied to devices with limited computing resources.
[0004] Therefore, there is an urgent need for a data encryption method that can flexibly adjust the data encryption level. Summary of the invention
[0005] The main technical problem solved by the present application is to provide a data encryption method, an electronic device and a computer-readable storage medium, which can improve the flexibility and security of data encryption.
[0006] To solve the above technical problems, a technical solution adopted in the present application is: a data encryption method is provided, the data encryption method is applied to a data encryption device, the data encryption device includes multiple network nodes, the data encryption method includes: obtaining a target network transmission path of the data to be transmitted, the target network transmission path is used to transmit the data to be transmitted from the starting network node to the target network node; determining the data encryption level of the data to be transmitted when it is transmitted at each network node according to the network security level of each network node in the target network transmission path, the network security level is negatively correlated with the data encryption level; in the process of transmitting the data to be transmitted along the target network transmission path, encrypting the transmission data in turn according to the data encryption level of the corresponding network node to obtain the target data.
[0007] To solve the above technical problems, another technical solution adopted in the present application is: to provide an electronic device, including a memory and a processor, wherein the memory stores program instructions, and the processor retrieves the program instructions from the memory to execute the above data encryption method.
[0008] In order to solve the above technical problems, another technical solution adopted by the present application is: providing a computer-readable storage medium including program data stored therein, wherein the program data is used to implement the above data encryption method when executed by a processor.
[0009] The above scheme obtains the target network transmission path of the data to be transmitted, and the target network transmission path is used to transmit the data to be transmitted from the starting network node to the target network node; the data encryption level of the data to be transmitted when it is transmitted in each network node is determined according to the network security level of each network node in the target network transmission path, and the network security level is negatively correlated with the data encryption level; in the process of transmitting the data to be transmitted along the target network transmission path, the transmission data is encrypted in turn with the data encryption level of the corresponding network node to obtain the target data. In this way, the adaptability of the data encryption level under each network node can be improved, and on the premise of ensuring data security, the waste of computing resources caused by excessively high encryption levels can be avoided. BRIEF DESCRIPTION OF THE DRAWINGS
[0010] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments are briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative work, among which:
[0011] Figure 1 is a flowchart of an exemplary embodiment of a data encryption method shown in the present application;
[0012] Figure 2 It is a specific flow chart of an exemplary embodiment of the data encryption method shown in the present application;
[0013] Figure 3 is a schematic diagram of a framework of an exemplary embodiment of data transmission shown in the present application;
[0014] Figure 4 is a structural schematic diagram of an exemplary embodiment of a data encryption device shown in the present application;
[0015] Figure 5 It is a structural schematic diagram of an embodiment of an electronic device provided by the present application;
[0016] Figure 6 It is a structural schematic diagram of an embodiment of a computer-readable storage medium provided by the present application. DETAILED DESCRIPTION
[0017] The technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. It will be appreciated that the specific embodiments described herein are only used to explain the present application, rather than to limit the present application. It should also be noted that, for ease of description, only some but not all structures related to the present application are shown in the drawings. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in the art without making creative work are within the scope of protection of the present application.
[0018] First of all, it should be noted that with the rapid development of communication technology, data transmission on the network may be at risk of being stolen. This has led to the development of data encryption technology, which is a method of converting data into an unreadable form to ensure that only authorized parties can obtain the original data. The higher the data encryption level, the less likely it is to be cracked. At present, in order to ensure the security of data, the highest data encryption level is usually adopted, but this will bring a large amount of terminal encryption calculations, which cannot be applied to terminals with limited computing resources.
[0019] Based on this, the present application provides a data encryption method, an electronic device, and a computer-readable storage medium, which can flexibly determine the data encryption level according to the network security level and improve the adaptability of the data encryption level. Figure 1 , Figure 1 It is a flowchart of an exemplary embodiment of a data encryption method shown in the present application.
[0020] The execution subject of the data encryption method may be a terminal device or a server or other processing device, wherein the terminal device may be a user equipment (UE), a computer, a mobile device, a user terminal, a terminal, a cellular phone, a cordless phone, a personal digital assistant (PDA), a handheld device, a computing device, a vehicle-mounted device, a wearable device, etc. The execution subject of the data encryption method may also be a data encryption device. In some possible implementations, the data encryption method may be implemented by a processor calling a computer-readable instruction stored in a memory.
[0021] Specifically, the data encryption method of this embodiment includes the following steps:
[0022] S110: Acquire a target network transmission path of the data to be transmitted, where the target network transmission path is used to transmit the data to be transmitted from the starting network node to the target network node.
[0023] The data to be transmitted is data that needs to be transmitted from the starting network node to the target network node. Exemplarily, the data to be transmitted may be data in the format of video stream, image, text, etc. For example, the data to be transmitted may be a video stream collected in real time by a video acquisition device, which needs to be sent from the video acquisition device to the service platform for processing.
[0024] The target network transmission path is the path through which the data to be transmitted is sent from the starting network node to the target network node. In some application scenarios, the target network transmission path may include a starting network node and a target network node, and the data to be transmitted jumps directly from the starting network node to the target network node. In other application scenarios, the target network transmission path includes at least one intermediate network node between the starting network node and the target network node. During the transmission process, the data to be transmitted starts from the starting network node and passes through multiple intermediate network nodes in sequence according to the network node order until it reaches the target network node. In some embodiments, there may be multiple reachable paths from the starting network node to the target network node, and the optimal path can be selected as the target network transmission path based on factors such as cost and transmission efficiency.
[0025] The starting network node may be a transmitting end of the data to be transmitted. Exemplarily, the starting network node may be a service terminal, such as a network camera, which sends the video stream collected in real time to the target network node. In other embodiments, the network camera may also send the video stream after the picture changes to the target network node after detecting the picture changes.
[0026] The target network node may be the receiving end of the data to be transmitted. Exemplarily, the target network node may be a service platform for processing the received data, such as abnormal event detection, traffic flow detection, etc. As an example, before initiating data transmission, the data encryption device may detect the target network transmission path through the service (signaling) corresponding to the data transmission to obtain the node status of each network node in the target network transmission path. The target network transmission path may be represented as: IP0 (service terminal) IP1 IP2 * * * IP3 IP4 IP (service platform), where IP0 represents the starting network node, IP represents the target network node, and IP1, IP2, *, IP3, and IP4 represent intermediate network nodes. Since some network nodes are not allowed to be accessed, such as 5G internal network nodes, the result obtained is *.
[0027] S120: Determine the data encryption level of the data to be transmitted when it is transmitted at each network node according to the network security level of each network node in the target network transmission path, and the network security level is negatively correlated with the data encryption level.
[0028] The network nodes in the target network transmission path refer to all the network nodes through which the data to be transmitted passes from the starting network node to the target network node. Due to the rapid development of communication technology, transmission links have become more diversified. The target network transmission path may contain network nodes such as the Internet public network, business private network, 5G private network and 5G public network. The network security levels of data transmitted by different network nodes are also different.
[0029] The network security level may be the risk of data being destroyed or stolen when data is transmitted over the network. Exemplarily, the data encryption device may query the security level of the corresponding network node in a preset security level query table, which includes the pre-configured network security level of at least one network node.
[0030] The data encryption level is used to limit the probability of data being cracked after encryption. Generally speaking, the higher the data encryption level, the more difficult it is to crack. In this embodiment, in order to ensure the data security of the data to be transmitted during the transmission process, the data encryption level is determined according to the network security level. The lower the network security level, the higher the possibility of data being stolen or destroyed. At this time, a higher data encryption level is required to encrypt the transmitted data to prevent it from being destroyed or stolen on network nodes with lower network security levels; and the higher the network security level, the lower the possibility of data being stolen or destroyed. At this time, only a lower data encryption level is required to meet the encryption requirements. Therefore, the network security level and the data encryption level cooperate with each other, and the two are negatively correlated, which fully guarantees the security of data transmission. As an example, the data encryption level can be divided into three levels. The higher the level, the stronger the encryption capability. Please refer to the following Table 1:
[0031]
[0032] Table 1
[0033] Among them, the encryption capability of data encryption level 1 is the weakest, and only uses two-way authentication capability based on digital certificates. The encryption capability of data encryption level 2 is higher than level 1, and uses two-way authentication capability based on digital certificates and video data signing capability based on digital certificates. The encryption capability of data encryption level 3 is the strongest, and uses two-way authentication capability based on digital certificates, video data signing capability based on digital certificates and video encryption capability.
[0034] S130: In the process of transmitting the data to be transmitted along the target network transmission path, the transmission data is encrypted in turn according to the data encryption level of the corresponding network node to obtain the target data.
[0035] After the data encryption device determines the target network transmission path, it transmits the data to be transmitted along the target network transmission path, and encrypts the transmission data in turn with the data encryption level of the corresponding network node to obtain the target data. It should be noted that data encryption is the encryption processing of the transmission data according to the data encryption level of the corresponding network node before the transmission data enters the corresponding network node. Exemplarily, during the transmission process of the data to be transmitted, each time it reaches a network node, it is encrypted with the data encryption level of the next network node to obtain the target data.
[0036] The data encryption device includes multiple network nodes, and each network node performs encryption processing of the transmitted data. For each network node, it can provide encoding and decoding capabilities and encryption and decryption capabilities, or only provide encryption and decryption capabilities; if each network node provides encoding and decoding capabilities and encryption and decryption capabilities, a code stream encryption method can be used to form an agreed code stream frame (such as a standard NAL unit); if each network node only provides encryption and decryption capabilities, a link encryption and decryption method can be used. In this method, if it is detected that the network security level of all network nodes from the current network node to the target network node is high, it can be decrypted in advance to reduce the pressure of decryption at the target network node. For the key management method, it can be negotiated by the encryption and decryption end, a pre-implantation method can be used, or a KMS key management server can be used for unified management. The key management method can be selected according to the network and specific scenarios, and is not specifically limited here.
[0037] It can be seen that the data encryption method of the embodiment of the present application obtains the target network transmission path of the data to be transmitted, and the target network transmission path is used to transmit the data to be transmitted from the starting network node to the target network node; the data encryption level of the data to be transmitted when it is transmitted at each network node is determined according to the network security level of each network node in the target network transmission path, and the network security level is negatively correlated with the data encryption level; in the process of transmitting the data to be transmitted along the target network transmission path, the transmission data is encrypted in turn with the data encryption level of the corresponding network node to obtain the target data. In this way, the adaptability of the data encryption level under each network node can be improved, and on the premise of ensuring data security, the waste of computing resources caused by too high an encryption level can be avoided.
[0038] Wherein, step S110 may further include: obtaining at least one initial network transmission path for transmitting the data to be transmitted from the starting network node to the target network node; and selecting a target network transmission path from each initial network transmission path according to the path quality of each initial network transmission path.
[0039] Among them, there may be multiple reachable paths from the starting network node to the target network node. In order to ensure the transmission rate and maximize the sharing of network resources, it is necessary to select the optimal network transmission path from each initial network transmission path as the target network transmission path. Exemplarily, the path quality of the initial network transmission path includes the transmission rate, resource utilization, etc. of the initial network transmission path. In some embodiments, the data encryption device can traverse each initial network transmission path; then obtain the path quality of each initial network transmission path; and take the path with the highest quality as the target network transmission path. In other embodiments, the data encryption device can also randomly generate an initial network transmission path from the starting network node to the target network node; then use the genetic algorithm and / or particle swarm algorithm to optimize the initial network transmission path to obtain the target network transmission path. In this way, the target network transmission path is adjusted dynamically according to the transmission service, which can reduce a large number of redundant configurations and meet the real-time dynamic service needs such as video streaming.
[0040] After obtaining the target transmission path of the data to be transmitted, the data encryption device obtains the network security level of the target network transmission path. Specifically, the steps for the data encryption device to determine the network security level include: obtaining the network address of each network node in the target network transmission path; performing matching processing in a preset mapping relationship table according to the network address of each network node to obtain a matching result, the preset mapping relationship table includes a correspondence between a preset network address and a preset network category; in response to the matching result indicating a successful match, the corresponding network category is determined as the network category of the network node; and the network security level of the network node is determined according to the network category of the network node.
[0041] The network address of each network node may also be referred to as an IP address (Internet Protocol Address), which is a unique identifier assigned to each network device connected to a network that communicates using the Internet Protocol.
[0042] The network category can also be referred to as the network standard. Exemplarily, the network categories include 5G public network, 5G private network, business intranet, Internet public network, etc. There are differences in the communication technologies used by different network categories, and their security levels are also different. The data encryption device is pre-configured with a preset mapping relationship table, which stores the correspondence between the preset network address and the preset network category. The corresponding network category can be found through the network address of each network node, and the private network and public network in each network node can be determined.
[0043] The data encryption device may also pre-store a preset security level query table, which includes the correspondence between preset network categories and preset network security levels. After obtaining the network category of each network node, the data encryption device traverses the preset security level query table according to the network category of each network node to obtain the network security level of each network node. In other embodiments, the preset security level query table includes the correspondence between the preset network address, the preset network category and the preset network security level. When the data encryption device obtains the network address of each network node, it traverses the preset security level query table according to the network address of each network node to obtain the network security level of each network node.
[0044] In this embodiment, the starting network node (service terminal) first detects the target network transmission path to obtain the node address of each network node in the target network transmission path; the starting network node sends the node address of each network node obtained by detection to the target network node (service platform); the target network node pre-stores a preset mapping relationship table, and the target network node traverses the preset mapping relationship table to obtain the network category corresponding to each network node; and determines the network security level of the corresponding network node according to the network category.
[0045] Among them, an example of a result of a failed match is as follows: a match result is obtained by performing a match process in a preset mapping relationship table according to the network address of each network node, and the preset mapping relationship table includes a correspondence between a preset network address and a preset network category; in response to the matching result indicating a failed match, the target network node sends the network address of the starting network node and the network address of the target network node to an external network element of the corresponding network node; the external network element of the network node sends the network address of the starting network node and the network address of the target network node to an internal network element of the network node, and the internal network element of the network node analyzes and processes the network address of the starting network node and the network address of the target network node to obtain the network category of the network node in the target network transmission path; the internal network element of the network node sends the network category to the external network element of the network node, and the external network element sends it to the target network node; the target network node determines the network security level of the network node according to the network category of the network node.
[0046] The reasons why the network address of the network node fails to match in the preset mapping relationship table include: the network address of the network node is empty and the corresponding network node network address is not obtained; the network address of the network node exists, but the network address is not stored in the preset mapping relationship table, and other reasons that may cause the matching failure. Among them, the situation where the network address of the network node is empty is explained. For some internal networks, such as home LANs, 5G internal network nodes, etc., in order to ensure privacy and security, access to the network addresses of such network nodes is not allowed, so the network address of the network node cannot be obtained. As an example, when it is detected that the network address of the 5G network node cannot be obtained, the target network node sends the network address of the starting network node and the network address of the target network node to an external network element in the 5G network node that can interact with the outside world. The external network element can be NWDAF (Network Data Analytics Function), and then the external network element reports the received network address of the starting network node and the network address of the target network node to the internal network element of the 5G network node. The internal network element can be UPF (User Plane Function), and the UPF analyzes and processes the connection relationship between the network address of the starting network node and the network address of the target network node to obtain the network category of the 5G network node under the connection, and obtains whether it is a 5G private network or a 5G public network under the target network transmission path, and sends the corresponding network category to the external network element, which sends the network category to the target network node; the target network node determines the network security level of the network node according to the network category of the 5G network node. This solves the problem that the 5G network cannot be detected.
[0047] As an example, the network categories include public networks and private networks, and the step of determining the network security level of the network node according to the network category of the network node includes: in response to the network nodes in the target network transmission path including network nodes with a network category of public networks and network nodes with a network category of private networks, determining the first preset network security level as the network security level of the network nodes with a network category of public networks; determining the second preset network security level as the network security level of the network nodes with a network category of private networks, the first preset network security level is lower than the second preset network security level.
[0048] Among them, the public network has fewer access restrictions than the private network, which leads to a lower network security level. In this embodiment, the network security level of each network category can be pre-configured, and the corresponding network security level can be quickly found after the network category of the network node is obtained. As another example, the network categories can also include private network, 5G private network, public network, 5G public network, and their network security levels decrease in sequence. The network security level can be divided into three levels, from high to low, they are network security level 3, network security level 2, network security level 1, the private network corresponds to network security level 3, the 5G private network corresponds to network security level 2, and the public network and 5G public network correspond to network security level 1. For example, for a target network transmission path:
[0049] IP0 (business terminal) IP1 IP2 * * * IP3 IP4 IP (business platform), after marking the network security level of each network node, can be expressed as: IP0 (private network, network security level 3) IP1 (private network, network security level 3) IP2 (private network, network security level 3) * (5G private network, network security level 2) * (5G private network, network security level 2) * (5G private network, network security level 2) IP3 (public network, network security level 1) IP4 (public network, network security level 1) IP (public network, network security level 1).
[0050] After determining the network security level of each network node in the target network transmission path, the data encryption device can implement hierarchical encryption of data according to the network security level. Exemplarily, in response to the presence of network nodes with a first preset network security level and network nodes with a second preset network security level in the target network transmission path, the first preset data encryption level is determined as the data encryption level of the network nodes corresponding to the first preset network security level; the second preset data encryption level is determined as the data encryption level of the network nodes corresponding to the second preset network security level, and the first preset data encryption level is higher than the second preset data encryption level.
[0051] Among them, the network security level includes a first preset network security level and a second preset network security level, and the first preset network security level is lower than the second preset network security level. In order to ensure data security, the data encryption level is negatively correlated with the network security level. The lower the network security level, the higher the data encryption level, and vice versa. Therefore, the first preset data encryption level executed under the network node corresponding to the first preset network security level is higher than the second preset data encryption level executed under the network node corresponding to the second preset network security level.
[0052] As another example, the data encryption level can be divided into three levels, from high to low: data encryption level 3, data encryption level 2, data encryption level 1. Network security level 3 corresponds to data encryption level 1, network security level 2 corresponds to data encryption level 2, and network security level 1 corresponds to data encryption level 3.
[0053] After determining the data encryption level of each network node, the data to be transmitted begins to be transmitted, and the data to be transmitted is transmitted along the target network transmission path. Among them, the data encryption action is completed by a network node with data encryption capability before entering a network node. Exemplarily, the target network transmission path includes adjacent first network nodes, second network nodes and third network nodes, and the data to be transmitted is transmitted to the first network node, the second network node and the third network node in sequence from early to late according to the transmission time. In the process of transmitting the data to be transmitted along the target network transmission path, in response to the transmission data being transmitted to the first network node, the first network node encrypts the transmission data according to the data encryption level of the second network node to obtain the target data; the target data is determined as the transmission data, and the transmission data is transmitted from the first network node to the second network node, and the second network node encrypts the transmission data according to the data encryption level of the third network node to obtain the target data. This ensures that the corresponding data encryption processing has been completed when entering the corresponding network node to prevent data leakage.
[0054] As an example, if the first network node is a private network and the network security level is network level 3, the data encryption level is data encryption level 1; the second network node is a 5G private network and the network security level is network level 2, the data encryption level is data encryption level 2; the third network node is a public network and the network security level is network level 1, the data encryption level is data encryption level 3. The process of transmitting the data to be transmitted along the first network node, the second network node and the third network node in sequence can be expressed as:
[0055] :… First network node (private network, network level 3, data encryption level 2) Second network node (5G private network, network level 2, data encryption level 3) First network node (public network, network level 1, ...).
[0056] For an exemplary target network transmission path:
[0057] IP0 (private network) IP1 (private network) IP2 (private network) * (5G private network) * (5G private network) * (5G private network) IP3 (public network) IP4 (public network) IP (public network), its corresponding data encryption scheme can be expressed as: IP0 (private network, network security level 3, execution data encryption level 1) IP1 (private network, network security level 3, no need to change encryption) IP2 (private network, network security level 3, data encryption level 2) *(5G private network, network security level 2, no need to change encryption) *(5G private network, network security level 2, no need to change encryption) *(5G private network, network security level 2, data encryption level 3) IP3 (public network, network security level 1, no need to change encryption) IP4 (public network, network security level 1, no need to change encryption) IP (public network, network security level 1, business platform decryption).
[0058] Therein, no need to change the encryption means that there is no need to perform decryption and re-encryption operations, and the transmission data encrypted by the previous network node is directly transmitted to the next network node.
[0059] In other embodiments, in order to reduce the waste of computing resources, for adjacent first network nodes, second network nodes, and third network nodes, if the data encryption level of the first network node is higher than the data encryption level of the second network node, and the data encryption level of the second network node is higher than the data encryption level of the third network node, then after the data transmission executes the data encryption level corresponding to the first network node, there is no need to perform decryption and change to a lower data encryption level on the first network node and the second network node, thereby reducing the waste of computing resources. As an example, for an example target network transmission path:
[0060] IP0 (private network) IP1 (private network) IP2 (private network) * (5G private network) * (5G private network) * (5G private network) IP3 (Private Network) IP4 (private network) IP (private network), its encryption scheme can be optimized as: IP0 (private network, network security level 3, execution data encryption level 1) IP1 (private network, network security level 3, no need to change encryption) IP2 (private network, network security level 3, data encryption level 2) *(5G private network, network security level 2, no need to change encryption) *(5G private network, network security level 2, no need to change encryption) *(5G private network, network security level 2, no need to change encryption) IP3 (private network, network security level 3, no need to change encryption) IP4 (private network, network security level 3, no need to change encryption) IP (private network, network security level 3, no need to change encryption).
[0061] It can be seen from this that when the transmission data is transmitted from the 5G private network to IP3, the network security level changes from network security level 2 to network security level 3. At this time, the data encryption level should be changed from data encryption level 2 to data encryption level 1, but changing to data encryption level 1 after decryption will result in a waste of computing power. In summary, the data encryption device can perform a higher data encryption level based on a lower data encryption level, but if there is already a higher data encryption level, there is no need to perform decryption to change to a lower data encryption level.
[0062] In other embodiments, the data encryption device can generate encryption values corresponding to each data encryption level; sort the encryption values of the data encryption levels of each network node from early to late according to each network node in the target network transmission path to obtain an encryption field; in the process of transmitting the data to be transmitted along the target network transmission path, encrypt the transmission data according to the corresponding encryption value in the encryption field to obtain the target data, and remove the corresponding encryption value from the encryption field to obtain the encryption field after the removal process; encrypt the transmission data with the encryption field after the removal process to obtain the target data. In this way, the hierarchical encryption of the data to be transmitted at each network node is completed through the encryption field.
[0063] The encryption values corresponding to each data encryption level can be taken from high to low according to the data encryption level, with the highest data encryption level taking the maximum value and the lowest data encryption level taking the minimum value. As an example, the data encryption level is divided into three levels, the encryption value of data encryption level 1 corresponds to 1, the encryption value of data encryption level 2 corresponds to 2, the encryption value of data encryption level 3 corresponds to 3, and the encryption value without changing the encryption corresponds to 0.
[0064] For an exemplary target network transmission path:
[0065] IP0 (private network, network security level 3, execution data encryption level 1) IP1 (private network, network security level 3, no need to change encryption) IP2 (private network, network security level 3, data encryption level 2) *(5G private network, network security level 2, no need to change encryption) *(5G private network, network security level 2, no need to change encryption) *(5G private network, network security level 2, data encryption level 3) IP3 (public network, network security level 1, no need to change encryption) IP4 (public network, network security level 1, no need to change encryption) IP (public network, network security level 1, business platform decryption).
[0066] According to the encryption values of the data encryption levels of each network node in the target network transmission path, the encryption fields obtained are sorted from early to late, and can be expressed as shown in Table 2:
[0067]
[0068] Table 2
[0069] Among them, 1 means executing data encryption level 1 on network node IP0, 0 means no need to change the encryption, 2 means executing data encryption level 2 on network node IP2, and 3 means executing data encryption level 3 on the network node of the last 5G private network.
[0070] The data encryption device generates encryption fields from morning to night according to each network node in the target network transmission path, ensuring that the encrypted value removed after each encryption process is the front end of the encryption field. Each time the transmitted data passes through a network node, the data encryption level corresponding to the first encrypted value in the encryption field is executed, and the encrypted value is removed from the encryption field until the last encrypted value is removed. The transmitted data is just transmitted to the target network node, and the target network node performs data decryption.
[0071] In order to elaborate on the data encryption method of the present application, Figure 2 The flowchart and Figure 3 The framework diagram shown further illustrates it, as follows:
[0072] exist Figure 2 and Figure 3 An example is given of a target network transmission path for data to be transmitted, with the service terminal serving as the starting network node for the data to be transmitted. The service terminal may be a network camera capable of collecting video streams in real time. The service platform serves as the target network node for the data to be transmitted. The service platform is pre-configured with a preset mapping relationship table, a preset security level query table, and a preset encryption level query table. The preset mapping relationship table includes the correspondence between preset network addresses and preset network categories, the preset security level query table includes the correspondence between preset network categories and preset network security levels, and the preset encryption level query table includes the correspondence between preset network security levels and preset data encryption levels.
[0073] After the service terminal establishes a network connection to the service platform, in order to obtain the node information of each network node in the target network transmission path, before initiating data transmission, the service terminal can first perform a service detection on the target network transmission path to obtain the node information of each network node in the target network transmission path. The node information includes the network address and transmission order of each network node, and the node information of each network node in the target network transmission path is sent to the service platform; the service platform analyzes and processes the node information of each network node in the target network transmission path to obtain the network category of each network node; if there is an undetectable 5G network node in the target network transmission path, the service platform transmits the service information (service terminal IP and service platform IP) to the external network element in the 5G network node, which can be the NWDAF network element (Network Data Analytics Function), and the internal path of the 5G network is fed back by the NWDAF network element in the 5G network node. The NWDAF network element notifies the internal network element of the service information for service identification, and the internal network element can be the UPF network element (User Plane Function, user plane function), UPF network element identifies service information and feeds back the network transmission path corresponding to the service information to NWDAF network element, and NWDAF network element feeds back the network transmission path of the service in the 5G network node to the service platform, thereby obtaining the network category of the corresponding 5G network node. Therefore, a service identification and network status synchronization mechanism is established between the service platform and the NWDAF network element in the 5G network to realize the readiness perception of the transmission path of the entire target network.
[0074] After the business platform analyzes and obtains the network category of each network node in the target network transmission path, it determines the network security level of each network node according to the network category; determines the data encryption level of the corresponding network node according to the network security level of each network node, formulates a hierarchical encryption scheme, forms a corresponding encryption field, and sends the encryption field to the business terminal; the business terminal places the encryption field in the packet header of the data to be transmitted and starts data transmission; executes the first encryption value of the encryption field on the transmission data on the business terminal, and removes the first encryption value from the encryption field to obtain the encrypted field and target data after the first removal; transmits the encrypted field and target data after the first removal from the business terminal as transmission data to network router 1, and network router 1 executes the first The first encrypted value in the encrypted field after removal is used to obtain the encrypted field and target data after the second removal; the encrypted field and target data after the second removal are transmitted from network route 1 to the 5G network as transmission data, and the 5G network executes the first encrypted value in the encrypted field after the third removal to obtain the encrypted field and target data after the third removal; the encrypted field and target data after the third removal are transmitted from the 5G network to network route 2 as transmission data, and network route 2 executes the first encrypted value in the encrypted field after the fourth removal to obtain the encrypted field and target data after the fourth removal; and so on, the business platform receives the final target data, decrypts the target data, and completes the entire data transmission process.
[0075] See also Figure 4 , Figure 4 It is a structural diagram of an exemplary embodiment of a data encryption device shown in the present application. The data encryption device 400 includes an acquisition module 410, a determination module 420 and an encryption module 430. The acquisition module 410 is used to acquire the target network transmission path of the data to be transmitted, and the target network transmission path is used to transmit the data to be transmitted from the starting network node to the target network node; the determination module 420 is used to determine the data encryption level of the data to be transmitted when it is transmitted at each network node according to the network security level of each network node in the target network transmission path, and the network security level is negatively correlated with the data encryption level; the encryption module 430 is used to encrypt the transmission data in turn with the data encryption level of the corresponding network node during the transmission of the data to be transmitted along the target network transmission path to obtain the target data.
[0076] In the above scheme, the data encryption device obtains the target network transmission path of the data to be transmitted, and the target network transmission path is used to transmit the data to be transmitted from the starting network node to the target network node; the data encryption level of the data to be transmitted when it is transmitted at each network node is determined according to the network security level of each network node in the target network transmission path, and the network security level is negatively correlated with the data encryption level; in the process of transmitting the data to be transmitted along the target network transmission path, the transmission data is encrypted in turn with the data encryption level of the corresponding network node to obtain the target data. In this way, the adaptability of the data encryption level under each network node can be improved, and on the premise of ensuring data security, the waste of computing resources caused by excessively high encryption levels can be avoided.
[0077] Among them, the functions of each module can be found in the data encryption method embodiment, which will not be repeated here.
[0078] In order to implement the data encryption method of the above embodiment, this application proposes another electronic device, please refer to Figure 5 , Figure 5 It is a structural schematic diagram of an embodiment of an electronic device provided by the present application.
[0079] The electronic device 500 includes a memory 510 and a processor 520 , wherein the memory 510 and the processor 520 are coupled.
[0080] The memory 510 is used to store program data, and the processor 520 is used to execute the program data to implement the data encryption method of the above embodiment.
[0081] In this embodiment, the processor 520 may also be referred to as a CPU (Central Processing Unit). The processor 520 may be an integrated circuit chip having signal processing capabilities. The processor 520 may also be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. A general-purpose processor may be a microprocessor or the processor 520 may also be any conventional processor, etc.
[0082] The present application also provides a computer-readable storage medium, such as Figure 6 As shown, the computer-readable storage medium 600 is used to store program data 610. When the program data 610 is executed by the processor, it is used to implement the data encryption method in the method embodiment of the present application.
[0083] The method involved in the data encryption method embodiment of the present application, when implemented in the form of a software functional unit and sold or used as an independent product, can be stored in a device, such as a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or part of the contribution to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, server, or network device, etc.) or a processor (processor) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk and other media that can store program code.
[0084] The above description is only an implementation method of the present application, and does not limit the patent scope of the present application. Any equivalent structure or equivalent process transformation made using the contents of the present application specification and drawings, or directly or indirectly used in other related technical fields, are also included in the patent protection scope of the present application.
Claims
1. A data encryption method, characterized in that: The data encryption method is applied to a data encryption device, the data encryption device includes a plurality of network nodes, and the data encryption method includes: Acquire a target network transmission path for the data to be transmitted, wherein the target network transmission path is used to transmit the data to be transmitted from the starting network node to the target network node; Determining the data encryption level of the data to be transmitted when it is transmitted at each network node according to the network security level of each network node in the target network transmission path, wherein the network security level is negatively correlated with the data encryption level; In the process of transmitting the data to be transmitted along the target network transmission path, encrypting the transmission data in turn according to the data encryption level of the corresponding network node to obtain the target data; The network nodes include adjacent first network nodes, second network nodes and third network nodes. The data encryption level of the second network node is higher than the data encryption level of the third network node. After the data encryption level corresponding to the second network node is executed on the transmission data on the first network node, there is no need to perform decryption and re-encryption operations on the second network node, and the transmission data encrypted by the data encryption level corresponding to the second network node is directly transmitted to the third network node.
2. The data encryption method according to claim 1, characterized in that: The network security level includes a first preset network security level and a second preset network security level, the first preset network security level is lower than the second preset network security level, and the step of determining the data encryption level of the data to be transmitted when transmitted at each network node according to the network security level of each network node in the target network transmission path, wherein the network security level is negatively correlated with the data encryption level, comprises: In response to the presence of a network node of the first preset network security level and a network node of the second preset network security level in the target network transmission path, determining the first preset data encryption level as the data encryption level of the network node corresponding to the first preset network security level; The second preset data encryption level is determined as the data encryption level of the network node corresponding to the second preset network security level, and the first preset data encryption level is higher than the second preset data encryption level.
3. The data encryption method according to claim 1, characterized in that: Before the step of determining the data encryption level of the data to be transmitted when transmitted at each network node according to the network security level of each network node in the target network transmission path, the method further includes: Obtaining the network address of each network node in the target network transmission path; Performing matching processing in a preset mapping relationship table according to the network address of each network node to obtain a matching result, wherein the preset mapping relationship table includes a correspondence between a preset network address and a preset network category; In response to the matching result indicating a successful match, determining the corresponding network category as the network category of the network node; The network security level of the network node is determined according to the network category of the network node.
4. The data encryption method according to claim 3, characterized in that: The network category includes a public network and a private network, and the step of determining the network security level of the network node according to the network category of the network node includes: In response to the network nodes in the target network transmission path including network nodes whose network category is a public network and network nodes whose network category is a private network, determining the first preset network security level as the network security level of the network nodes whose network category is a public network; The second preset network security level is determined as the network security level of the network node whose network category is a private network, and the first preset network security level is lower than the second preset network security level.
5. The data encryption method according to claim 1, characterized in that: The network node includes an external network element and an internal network element. Before the step of determining the data encryption level of the data to be transmitted when transmitted at each network node according to the network security level of each network node in the target network transmission path, the method further includes: Performing matching processing in a preset mapping relationship table according to the network address of each network node to obtain a matching result, wherein the preset mapping relationship table includes a correspondence between a preset network address and a preset network category; In response to the matching result indicating a matching failure, the target network node sends the network address of the starting network node and the network address of the target network node to an external network element of the corresponding network node; The external network element of the network node sends the network address of the starting network node and the network address of the target network node to the internal network element of the network node, and the internal network element of the network node analyzes and processes the network address of the starting network node and the network address of the target network node to obtain the network category of the network node in the transmission path of the target network; The internal network element of the network node sends the network category to the external network element of the network node, and the external network element sends it to the target network node; The target network node determines the network security level of the network node according to the network category of the network node.
6. The data encryption method according to claim 1, characterized in that: The target network transmission path includes a first network node, a second network node, and a third network node that are adjacent to each other, and the data to be transmitted is transmitted to the first network node, the second network node, and the third network node in sequence from early to late according to the transmission time. The step of encrypting the transmission data in sequence at the data encryption level of the corresponding network node during the transmission of the data to be transmitted along the target network transmission path to obtain the target data includes: In the process of transmitting the data to be transmitted along the target network transmission path, in response to the transmission data being transmitted to the first network node, the first network node encrypts the transmission data according to the data encryption level of the second network node to obtain the target data; The target data is determined as transmission data, and the transmission data is transmitted from the first network node to the second network node, and the second network node encrypts the transmission data according to the data encryption level of the third network node to obtain the target data.
7. The data encryption method according to claim 1, characterized in that: The step of encrypting the transmission data in turn with the data encryption level of the corresponding network node during the transmission of the data to be transmitted along the target network transmission path to obtain the target data includes: Generate encryption values corresponding to each data encryption level; According to each network node in the target network transmission path, the encrypted values of the data encryption level of each network node are sorted from early to late to obtain an encrypted field; In the process of transmitting the data to be transmitted along the target network transmission path, encrypting the transmission data according to the corresponding encryption value in the encryption field to obtain the target data, and removing the corresponding encryption value from the encryption field to obtain the encrypted field after the removal process; The transmission data is encrypted using the removed encryption field to obtain the target data.
8. The data encryption method according to claim 1, characterized in that: The step of obtaining a target network transmission path for the data to be transmitted, wherein the target network transmission path is used to transmit the data to be transmitted from the starting network node to the target network node, comprises: Acquire at least one initial network transmission path for transmitting the data to be transmitted from the starting network node to the target network node; The target network transmission path is selected from each initial network transmission path according to the path quality of each initial network transmission path.
9. An electronic device, characterized in that: include: A memory and a processor, wherein the memory stores program instructions, and the processor retrieves the program instructions from the memory to execute the method according to any one of claims 1 to 8.
10. A computer-readable storage medium, characterized in that: include: Program data is stored, and when the program data is executed by a processor, it is used to implement the method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Message transmission method and device, dynamic encryption method and device, electronic equipment and medium
CN114915457A
Secure support for hop-by-hop encrypted messaging
US20080065890A1