Data protection method, device, and storage medium

Through dual encryption processing between the data sending end and the server, encrypted frames are generated and merged, the problem of incomplete data protection in the prior art is solved, and the security of data transmission and storage is improved.

CN119788436BActive Publication Date: 2025-07-04ZHEJIANG DAHUA TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510281998.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-11
Publication Date
2025-07-04
Estimated Expiration
2045-03-11

AI Technical Summary

Technical Problem

The existing encryption methods fail to fully cover the communication link, resulting in insufficient data protection effect, especially in data transmission and storage processes.

Method used

After establishing a communication connection between the data sending end and the server, the communication data is encrypted using the data encryption key, and the data encryption key is further encrypted through the server's key encryption key to generate a stored encrypted frame, and finally the encrypted data and the stored encrypted frame are merged and stored to realize dual encryption protection.

Benefits of technology

Through dual encryption processing, the security in data transmission and stored procedures is improved, data leakage is prevented, and the integrity and security of communication data in transmission and stored procedures is ensured.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119788436B_ABST
    Figure CN119788436B_ABST
Patent Text Reader

Abstract

The present application discloses a data protection method, device, and storage medium. The data protection method is applied to a data sending end and includes: in response to a communication connection existing between the data sending end and a server, encrypting communication data by using an obtained data encryption key to obtain encrypted data; sending the data encryption key and the encrypted data to the server so that the server encrypts the data encryption key by using an obtained key encryption key to obtain a stored encryption frame, and merging the stored encryption frame and the encrypted data to obtain encrypted storage data. The above solution can effectively achieve data protection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data encryption technology, and in particular, to a data protection method, device, and storage medium. Background Art

[0002] Information security is crucial for current Internet communication scenarios.

[0003] Usually, the data sender encrypts the communication data and then sends the encrypted data to the data receiver, which decrypts the data to achieve data protection during the communication process. For example, encrypting the data stream such as audio and video before transmission can effectively avoid information security problems caused by the leakage of the data stream during transmission.

[0004] However, the current encryption methods do not fully cover the communication link, and there are still defects in the data protection effect. Summary of the Invention

[0005] This application provides at least one data protection method, device, equipment, and computer-readable storage medium.

[0006] In a first aspect of this application, a data protection method is provided. The method is applied to a data sender and includes: in response to a communication connection existing between the data sender and a server, encrypting communication data using an obtained data encryption key to obtain encrypted data; sending the data encryption key and the encrypted data to the server, so that the server encrypts the data encryption key using an obtained key encryption key to obtain a stored encrypted frame, and merges the stored encrypted frame and the encrypted data to obtain encrypted storage data.

[0007] In an embodiment, the encrypting the communication data using the obtained data encryption key to obtain encrypted data includes: encrypting the communication data according to the obtained encryption algorithm and the data encryption key to obtain encrypted data; generating a transmission encrypted frame according to the data encryption key and the encrypted data; and merging the transmission encrypted frame and the encrypted data to obtain the encrypted data.

[0008] In an embodiment, after the merging the transmission encrypted frame and the encrypted data to obtain the encrypted data, the method further includes: sending the data encryption key and the encrypted data to the server, so that the server merges and stores the stored encrypted frame and the transmission encrypted frame to obtain the encrypted storage data.

[0009] In one embodiment, before encrypting communication data with the obtained data encryption key to obtain encrypted data in response to the existence of a communication connection between the data sender and the server, the method further includes: exchanging authentication information with the server and performing two-way authentication processing to obtain a two-way authentication result; in response to the two-way authentication result indicating that the data sender and the server have passed the two-way authentication, establishing the communication connection according to the access token sent by the server received.

[0010] In one embodiment, the exchanging authentication information with the server and performing two-way authentication processing to obtain a two-way authentication result includes: sending the security information supported by the data sender to the server for security verification to obtain a security verification result; in response to the security verification result indicating that the verification is passed, generating first signature information and sending it to the server, so that after the server verifies the first signature information and passes, generating second signature information and sending it to the data sender; in response to the second signature information being verified and passed, encrypting the device information of the data sender with the key of the server to obtain encrypted device information; sending the encrypted device information to the server, so that the server decrypts the encrypted device information with the key to obtain the device information, and performing a verification process on the device information to obtain the two-way authentication result.

[0011] The second aspect of the present application provides a data protection method, which is applied to the server, and the method includes: in response to the existence of a communication connection between the server and the data sender, receiving the data encryption key and the encrypted data sent by the data sender; encrypting the data encryption key with the obtained key encryption key to obtain a stored encryption frame; the encrypted data is obtained by the data sender encrypting communication data with the data encryption key; merging the stored encryption frame and the encrypted data to obtain encrypted storage data.

[0012] In one embodiment, the encrypted data includes video data, and the merging the stored encryption frame and the encrypted data to obtain encrypted storage data includes: identifying key frame data in the video data; adding a stored encryption frame to each key frame data respectively to obtain the encrypted storage data.

[0013] In one embodiment, before receiving the data encryption key and the encrypted data sent by the data sending end in response to the existence of a communication connection between the server and the data sending end, the method further includes: in response to the authentication request of the received data sending end, exchanging authentication information with the data sending end and performing two-way authentication processing to obtain a two-way authentication result; in response to the two-way authentication result indicating that the data sending end and the server pass the two-way authentication, sending an access token to the server and establishing the communication connection.

[0014] The third aspect of the present application provides a data protection device, which is applied to the data sending end and includes: a data encryption module, configured to encrypt communication data using the obtained data encryption key to obtain encrypted data in response to the existence of a communication connection between the data sending end and the server; a data sending module, configured to send the data encryption key and the encrypted data to the server, so that the server encrypts the data encryption key using the obtained key encryption key to obtain a stored encryption frame, and merges the stored encryption frame and the encrypted data to obtain encrypted storage data.

[0015] The fourth aspect of the present application provides a data protection device, which is applied to the server and includes: a data receiving module, configured to receive the data encryption key and the encrypted data sent by the data sending end in response to the existence of a communication connection between the server and the data sending end; a key encryption module, configured to encrypt the data encryption key using the obtained key encryption key to obtain a stored encryption frame; the encrypted data is obtained by the data sending end encrypting communication data using the data encryption key; a data storage module, configured to merge the stored encryption frame and the encrypted data to obtain encrypted storage data.

[0016] The fifth aspect of the present application provides an electronic device, including a memory and a processor, and the processor is configured to execute program instructions stored in the memory to implement the above data protection method.

[0017] The sixth aspect of the present application provides a computer-readable storage medium, on which program instructions are stored, and when the program instructions are executed by a processor, the above data protection method is implemented.

[0018] In the above solution, if there is a communication connection between the data sender and the server, the data sender can use the obtained data encryption key to encrypt the communication data to obtain encrypted data; send the data encryption key and the encrypted data to the server; the server can then encrypt the data encryption key of the data sender using the obtained key encryption key to obtain a storage encryption frame, and then merge the storage encryption frame and the encrypted data to obtain encrypted storage data and store it. Thus, transmission protection and storage protection of communication data can be achieved during the communication process, improving data security.

[0019] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and do not limit this application. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] The accompanying drawings herein are incorporated into the specification and constitute a part of this specification. These drawings illustrate embodiments consistent with this application and, together with the specification, are used to explain the technical solutions of this application.

[0021] Figure 1 is a schematic flowchart of an exemplary embodiment of the data protection method of this application;

[0022] Figure 2 is a timing diagram of an exemplary two-way authentication process in the data protection method of this application;

[0023] Figure 3 is a schematic diagram of the architecture of an exemplary video cloud storage system in the data protection method of this application;

[0024] Figure 4 is a timing diagram of an exemplary one-way authentication process in the data protection method of this application;

[0025] Figure 5 is a simple schematic diagram of the certificate management process in the data protection method of this application;

[0026] Figure 6 is a block diagram of a data protection device shown in an exemplary embodiment of this application;

[0027] Figure 7 is a schematic diagram of the structure of an embodiment of an electronic device of this application;

[0028] Figure 8 is a schematic diagram of the structure of an embodiment of a computer-readable storage medium of this application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0029] The solutions of the embodiments of this application will be described in detail below with reference to the accompanying drawings of the specification.

[0030] In the following description, specific details such as specific system architectures, interfaces, technologies, etc. are presented for purposes of illustration rather than limitation, in order to provide a thorough understanding of the present application.

[0031] The term "and / or" in this article is merely a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this article generally indicates that the associated objects before and after are in an "or" relationship. In addition, "plurality" in this article means two or more than two. In addition, the term "at least one" in this article means any one of a plurality or any combination of at least two of a plurality. For example, including at least one of A, B, and C can represent including any one or more elements selected from the set composed of A, B, and C.

[0032] For ease of explanation, one of the applicable scenarios of the present application is exemplarily described below. The data protection method of the present application can be used to protect various types of data in the process of network communication, such as text data, image data, video data, audio data, etc., which are not limited here. For ease of understanding, the present application is mainly described by taking video data as an example, but it does not limit the applicable scenarios of the present application.

[0033] Please refer to Figure 1 , Figure 1 is a schematic flowchart of an exemplary embodiment of the data protection method of the present application. This method is applied to the data sending end. Specifically, it may include the following steps:

[0034] Step S110, in response to the existence of a communication connection between the data sending end and the server end, encrypt the communication data by using the obtained data encryption key to obtain encrypted data.

[0035] Among them, the data sending end refers to the device end responsible for sending data in the communication process, and the server end refers to the server end that provides relevant services for the data sending end. In addition, the server end can also provide relevant services for the data receiving end, which will not be elaborated here.

[0036] For example, when the communication data is video data, the data sending end can be a front-end device for collecting video data, such as a network camera (IP Camera, IPC), etc.; and the server end can be a server that provides relevant services such as data storage service and / or data management service for the IPC device. Among them, the IPC device can transmit the collected video data (such as video stream) to the server for data storage, which is one of the communication processes between the data sending end and the server end.

[0037] It is understandable that for the communication process in the above example, a communication connection is required between the data sender and the server. Then, the data sender can encrypt the video data according to the obtained data encryption key to obtain encrypted data. Here, the data encryption key is used to encrypt the communication data during the communication process, that is, to encrypt the video stream data in the video application scenario. The data encryption key can be pre-set in the data sender, or can be obtained by the data sender from the server and / or other devices (other servers) and / or other systems (such as a Key Management System (KMS)). And a data sender can have one or more data encryption keys. Different data senders can have the same or different data encryption keys, which is not limited here.

[0038] By encrypting the communication data with the data encryption key by the data sender to obtain encrypted data, the data sender can transmit the encrypted data during the communication process, thereby avoiding problems such as data leakage during the data transmission process and ensuring the data security during the data transmission process.

[0039] Step S120: Send the data encryption key and the encrypted data to the server so that the server encrypts the data encryption key according to the obtained key encryption key to obtain a stored encrypted frame, and combines the stored encrypted frame and the encrypted data to obtain encrypted storage data.

[0040] Illustrated in combination with the foregoing steps, the data sender can send the data encryption key and the encrypted data to the server.

[0041] Among them, the data encryption key and the encrypted data can be sent simultaneously or at different times; and it can be that the data sender sends the corresponding data encryption key each time it sends encrypted data, or is sent by the data sender at some pre-set specified time (for example, the data encryption key is sent during the process of establishing a communication connection between the data sender and the server, and / or the data encryption key is sent after the data sender and the server establish a communication connection, and / or the data encryption key is sent when the data sender first sends encrypted data to the server, and / or the data encryption key is sent when the data sender modifies and updates the data encryption key, etc.), which is not limited here.

[0042] Alternatively, it can also be obtained by the server from the KMS system. The KMS system can be a key management system set in the server of the present application, or a key management system set in other devices (other servers) that have a communication connection with the server, which is not limited here. The KMS system can have communication connections with the data sender and the server respectively to facilitate the management of keys in the data sender and the server. The key management services that the KMS system can provide can refer to existing KMS technologies, which will not be elaborated here specifically.

[0043] Furthermore, after the server receives the encrypted data sent by the data sender and the data encryption key used to encrypt the communication data, it can use the obtained key encryption key to process the data encryption key to obtain a stored encryption frame. Here, the values of the key encryption key and the data encryption key can be the same or different, which is not limited; however, the uses of the key encryption key and the data encryption key are different. The data encryption key is used to encrypt communication data (such as a video stream), while the key encryption key is used to encrypt a key (such as the data encryption key), that is, the key encryption key is used by the server to encrypt the data encryption key of the data sender with a key. Thus, a stored encryption frame can be obtained, and the stored encryption frame is mainly used for auxiliary encryption during the data storage process.

[0044] The server combines the stored encryption frame and the encrypted data to obtain encrypted storage data, and stores the encrypted storage data, thereby realizing data protection during the data storage process, avoiding data leakage problems when the data is stored in the server, and ensuring the data security during the data storage process.

[0045] In summary, through the method of the present application, during the communication process between the data sender and the server, through two encryption processes, data transmission encryption and data storage encryption can be realized, improving the reliability and security of data transmission and data storage.

[0046] It can be seen that through the above method of the present application, if there is a communication connection between the data sender and the server, the data sender can use the obtained data encryption key to encrypt the communication data to obtain encrypted data; send the data encryption key and the encrypted data to the server; the server can then use the obtained key encryption key to encrypt the data encryption key of the data sender to obtain a stored encryption frame, and then combine the stored encryption frame and the encrypted data to obtain encrypted storage data and store it, thereby realizing transmission protection and storage protection of the communication data during the communication process and improving data security.

[0047] Based on the above embodiments, the embodiments of the present application will describe the steps of encrypting communication data using the obtained data encryption key to obtain encrypted data. Specifically, the method of this embodiment includes the following steps:

[0048] Encrypt the communication data according to the obtained encryption algorithm and data encryption key to obtain the encrypted data; generate a transmission encryption frame according to the data encryption key and the encrypted data; perform a merging process on the transmission encryption frame and the encrypted data to obtain the encrypted data.

[0049] Among them, the encryption algorithm in the data sender can be preset in advance, or obtained from the server, or obtained from other devices (other servers), which is not limited here.

[0050] It should be noted that the encryption algorithm of the data sender of the present application can include but is not limited to asymmetric encryption algorithms, hash algorithms, symmetric encryption algorithms, and signature algorithms, etc. One or more encryption algorithms can be set in the data sender according to the requirements of specific application scenarios, which is not limited here. The data sender encrypts the communication data using the available encryption algorithm and data encryption key to obtain the encrypted data (encrypted communication data).

[0051] If the data sender needs to transmit the encrypted communication data, a transmission encryption frame also needs to be added to the encrypted communication data, and the transmission encryption frame format is used for transmission during the data transmission process. The transmission encryption frame can be sent separately or extended on the basis of the communication data and then sent together, which is not limited here. Among them, the transmission encryption frame includes encryption information of the communication data, such as encryption type, encryption offset, and encryption length, etc., which will not be elaborated here.

[0052] Exemplarily, as shown in the following Table 1, Table 1 is an exemplary frame structure of the transmission encryption frame in the data protection method of the present application:

[0053]

[0054] Among them, the first row of the table represents the byte sequence number, and the second row represents the field corresponding to the byte sequence number. The main fields of this transmission encryption frame are described in this embodiment. In actual application scenarios, it can include but is not limited to the above fields, which will not be elaborated here.

[0055] For example, it can be known from the transmission encryption frame shown in Table 1 above that the transmission encryption frame header type is 0xB5; the frame length refers to the length of this transmission encryption frame; the encryption type can include but is not limited to:

[0056] 0: Keep the original data without encryption;

[0057] 1: AES256-OFB-NOPADDING;

[0058] 2: SM4-OFB-NOPADDING;

[0059] 3: SM4-ECB-NOPADDING;

[0060] 4: SM1-OFB-NOPADDING;

[0061] 5: SM1-ECB-NOPADDING;

[0062] Among them, 0-5 respectively represent their corresponding encryption types. For example, AES256, SM4, SM1, etc. refer to encryption algorithms, while OFB (Output feedback) and ECB (Electronic CodeBook) refer to encryption modes. More types of encryption algorithms and encryption modes can be set in different application scenarios, which will not be elaborated here. Among them, if the communication data is audio data (audio bitstream) or video data (video bitstream), the OFB mode and the NOPADDING mode (non-padding mode, which will not pad the plaintext data block during the encryption process) can be preferably used. The OFB mode and the non-padding mode can be efficiently used as stream encryption and are applicable to audio and video bitstreams, such as type 2 or type 4. And the PKCS5 padding mode needs to be used under the GB35114 standard.

[0063] In addition, the encrypted frame in the transmission also includes an encryption offset. For video data, it is the bitstream encryption offset, which is used to represent the current video data corresponding to the current transmission encrypted frame. It starts from the starting position of the original raw bitstream data and is encrypted after offsetting a certain number of bytes, that is, it is equivalent to representing the encryption offset position of the current video data. The encryption length represents the length of the data encrypted starting from the encryption offset position, and the unit can be bytes, that is, it represents how much data in the current video data needs to be decrypted to be played normally.

[0064] The key ID (key identifier) refers to the identifier of the data encryption key used when encrypting the current video data. Since there can be one or more data encryption keys in the data sender, the key identifier can be used to represent which key is used. Among them, for video encryption, the data encryption key can be the video encryption key VK (Video Key), also known as VEK (Video Encryption Key), and the key identifier can be VKID (Video Key Identity Document). The data sender, the server, and the data receiver can all look up the corresponding VK according to the VKID to decrypt the corresponding video data, which will not be elaborated here. CRC16 is a type of data verification algorithm, namely cyclic redundancy check, mainly used to detect or check for errors that may occur after data transmission or storage. The CRC16 checksum can be calculated through the verification algorithm before encrypting the communication data and stored in the transmission encryption frame, and then can be used by the server and / or the data receiver to perform verification when decoding the data (such as decoding the video stream) to determine whether the data is complete. IV refers to the initialization vector (Initialization Vector) commonly used in the encryption process, which will not be elaborated here.

[0065] In summary, during the execution of this embodiment, the transmission encryption frame can be generated according to the relevant information of the data encryption key and the relevant information of the encrypted data as exemplified in the above embodiments. Then, the transmission encryption frame can be written into the streaming file corresponding to the video stream for merging processing to obtain encrypted data.

[0066] Based on the above embodiments, the embodiments of the present application will describe the steps after merging the transmission encryption frame and the encrypted data to obtain the encrypted data. Specifically, the method of this embodiment includes the following steps:

[0067] Send the data encryption key and the encrypted data to the server so that the server can merge and store the stored encryption frame and the transmission encryption frame to obtain the encrypted storage data.

[0068] Combined with the foregoing embodiments, the encrypted data can include the encrypted communication data and the transmission encryption frame. After obtaining the encrypted data, the data sender can send the encrypted data to the server for data storage.

[0069] Exemplarily, before transmitting the encrypted data, the data encryption key corresponding to the segment of encrypted data can be pushed in the form of a digital envelope (encrypting the key by means of asymmetric encryption). The specific key sending process can be that the data sender sends it to the server and / or the data receiver, or the KMS system sends it to the data sender, the server and / or the data receiver respectively. For specific details, reference can be made to the foregoing examples, and it can also be adaptively adjusted according to the specific application scenario, which will not be elaborated here. Thus, the server can obtain the data encryption key of the data sender.

[0070] After the server receives the data encryption key of the data sender, or after receiving the encrypted data of the data sender and the corresponding data encryption key, it can use the key encryption key to encrypt the data encryption key of the data sender to obtain a stored encrypted frame, and then merge and store the stored encrypted frame with the transmission encrypted frame to obtain encrypted stored data.

[0071] Among them, for video data, the data encryption key (video encryption key) is VK, and the key encryption key (video key encryption key) is VKEK (Video Key Encryption Key). The VKEK of the server can refer to the key acquisition process mentioned in the foregoing embodiments, for example, obtained from the KMS system. Then the server can use VKEK to encrypt VK to obtain a stored encrypted frame.

[0072] Exemplarily, as shown in the following Table 2, Table 2 is an exemplary frame structure of the stored encrypted frame in the data protection method of the present application:

[0073]

[0074] Among them, the format of the stored encrypted frame can also refer to the example description of the transmission encrypted frame in the foregoing embodiments. This embodiment mainly describes the main fields in the stored encrypted frame. In specific application scenarios, it can include but is not limited to the above field information. For example, the frame header type of the stored encrypted frame is 0x04; the VKEK ID can be the identifier of the VKEK assigned by the KMS system to the server; the VKEK type can indicate how the VKEK in this stored encrypted frame is obtained. For example, the VKEK type can include but is not limited to 0x00 (indicating KMS allocation), 0x01 (indicating user allocation), 0x02 (indicating allocation by USBKey), etc. Both a and b can be adaptively set according to the specific application scenario and are not limited here. Other relevant data can also be appended to the stored encrypted frame as needed, which is not limited here.

[0075] In summary, after the server obtains the transmission encryption frame and the storage encryption frame, it can merge and store the storage encryption frame and the transmission encryption frame and store the encrypted data to obtain the encrypted storage data. For example, the storage encryption frame is inserted before the frame header of the transmission encryption frame to achieve merged storage. Among them, the storage encryption frame can be made an adjacent frame of the transmission encryption frame and the frame sequence of the storage encryption frame is earlier than the frame sequence of the transmission encryption frame.

[0076] Based on the above embodiments, the embodiments of the present application will describe the steps before encrypting communication data with the obtained data encryption key to obtain encrypted data in response to the existence of a communication connection between the data sender and the server. Specifically, the method of this embodiment includes the following steps:

[0077] Exchange authentication information with the server and perform two-way authentication processing to obtain a two-way authentication result; in response to the two-way authentication result indicating that the data sender and the server pass the two-way authentication, establish a communication connection according to the access token sent by the server received.

[0078] Combined with the foregoing embodiments, in the data protection method of the present application, in addition to protecting the data transmission process and the data storage process, it is also possible to protect the process of the data sender accessing the server. Therefore, before establishing a communication connection between the data sender and the server, the present application can also provide a data protection method that enables the data sender and the server to perform two-way authentication processing to ensure that the data sender will not connect to an unauthorized server (or an insecure server), and similarly, it can also ensure that the server will not access an unauthorized device (such as an unauthorized data sender), etc., thereby ensuring the data security in the data sender and the server.

[0079] Exemplarily, the two-way authentication process of the present application may include, but is not limited to, both parties mutually verifying information such as each other's certificates and signatures, thereby determining the validity, compliance, etc. of both parties to obtain a two-way authentication result. If the two-way authentication result indicates that the data sender and the server pass the two-way authentication, the server can send an access token to the data sender, and the data sender can establish a communication connection with the server according to the received access token.

[0080] Based on the above embodiments, the embodiments of the present application will describe the steps of exchanging authentication information with the server and performing two-way authentication processing to obtain a two-way authentication result. Specifically, the method of this embodiment includes the following steps:

[0081] Send the security information supported by the data sender to the server for security verification to obtain a security verification result; in response to the security verification result indicating successful verification, generate first signature information and send it to the server, so that after the server verifies the first signature information, generate second signature information and send it to the data sender; in response to the successful verification of the second signature information, use the server's key to encrypt the device information of the data sender to obtain encrypted device information; send the encrypted device information to the server, so that the server uses the key to decrypt the encrypted device information to obtain the device information, and perform a verification process on the device information to obtain a two-way authentication result.

[0082] Among them, the security information may include but is not limited to the set of security algorithms supported by the data sender. There may be one or more security algorithms (encryption algorithms) in the set of security algorithms. For specific reference, please refer to the foregoing examples, and the steps here will not be elaborated. The security information of the data sender can characterize the security capabilities of the data sender. For example, if the data sender A has an asymmetric encryption algorithm and a symmetric encryption algorithm, and the data sender B has a symmetric encryption algorithm, it can be determined that the security capabilities of the data sender A are stronger than those of the data sender B, that is, it shows that the security of the data sender A is better than that of the data sender B.

[0083] Exemplarily, the method for evaluating security capabilities in this application may include but is not limited to, as in the above example, it can be evaluated according to the types of security algorithms supported by the data sender. For example, a corresponding security score is preset for each type of security algorithm, and the security capabilities of the data sender are determined according to the sum of the security scores of each security algorithm in the security algorithm set of the data sender. If the security capabilities of the data sender are greater than the preset security threshold, it can be determined that the data sender passes the security verification of the server; otherwise, it can be determined that the data sender fails the security verification of the server, and if the security verification fails, the data sender and the server cannot establish a communication connection this time.

[0084] Or, the criterion for security verification can be preset as "there is a specified security algorithm (which can be one or more specified algorithms) in the set of security algorithms". If there is a specified security algorithm type (which can be partially present or fully present, set as required) in the security algorithm set of the data sender, it can be determined that the data sender passes the security verification of the server; otherwise, it can be determined that the data sender fails the security verification of the server.

[0085] In addition, it is also possible to combine various relevant information of the data sender with the security algorithm type to evaluate the security capabilities of the data sender. Among them, the relevant information may include, but is not limited to, network information, device identification information, etc. For example, the network information may be the network type (external network or internal network, which can be judged according to the network where the server is located, and will not be elaborated here). For example, the security score of the same data sender when accessing the same internal network as the server may be higher than that when accessing the external network. Also, for example, the network information may include the IP address, and IP addresses in different regions may correspond to the same or different security scores respectively. The device identification information may be the unique identifier of the data sender (such as MAC address, IMEI, serial number, device ID, SIM card number, Internet of Things card number, etc.). The server may pre-store the identification information of the security device or the rules for judging the security device identification information (such as regular expressions, etc.), so as to judge whether the data sender is a security device, and then assign a security score to it from the perspective of the device identification information.

[0086] In summary, in the specific implementation process, one or more of the above methods can be selected to determine the final security score of the data sender. If multiple methods are selected for evaluation, it may be necessary for each method to pass the judgment criteria (for example, the data sender needs to have a specified security algorithm, be in a specified IP address area, and have a compliant device identifier, etc.). In addition, weighted judgment can also be performed. For example, each evaluation criterion is preset with its corresponding security weight. For example, the weight of the security algorithm type is 50%, the weight of the network information is 30%, and the weight of the device identification information is 20%; according to the above security weights, the security scores of each criterion are weighted and summed to obtain the final security score.

[0087] Exemplarily, it can be referred to as Figure 2 shown Figure 2It is a timing diagram of an exemplary two-way authentication process in the data protection method of this application. The data sender can send a connection request (or a registration request) and carry the set of security algorithms it possesses. After receiving the connection request, the server can determine the security capabilities of the data sender by verifying the set of security algorithms possessed by the data sender. If the security capabilities of the data sender reach a preset security threshold (or meet a preset security evaluation criterion), it can be considered that the data sender passes the security verification result. Then the server needs to select a target security algorithm from the set of security algorithms possessed by the data sender (the target security algorithm is an algorithm that can encrypt the data transmitted between the data sender and the server during the verification process of establishing a communication connection. In the subsequent verification process, the data sent by the data sender to the server and / or the data sent by the server to the data sender can be encrypted using this target security algorithm. The specific details are not elaborated here), and also generate a random number to obtain the first random number R1. The target security algorithm and the first random number R1 are returned to the data sender as the data carried in the security verification result to inform the data sender that it has passed the security verification. Among them, the security verification result can be encrypted using the public key of the data sender and then sent, and the data sender can decrypt it using its own private key after receiving the security verification result.

[0088] After the data sender confirms that it has passed the security verification of the server, it can send the generated second random number R2 and generate its own first signature information (digital signature S1, which can be generated using its own private key. The specific generation method can refer to the existing signature generation method and will not be elaborated here). For example, send the first verification token TokenCS to the server. TokenCS can be composed of R1, R2, the data sender certificate ID, and S1. The specific composition method can be numerical splicing, or fusing the above data into other operation results through a preset algorithm, etc., which is not limited here. Among them, the data sender certificate ID refers to the ID of the authorization certificate (Certificate Authority) of the data sender. The CA certificate is the technical foundation guarantee for digital signatures and also the proof of the identity of online entities. It can prove the identity of an entity and the legitimacy of its public key, and prove the matching relationship between the entity and the public key. Each device in this application (such as the data sender, the server, and the data receiver) can have its own certificate, and each device can have one or more certificates. The certificates can be pre-set (such as applied for and issued) in each device, which will not be elaborated here.

[0089] After the server receives TokenCS, it can verify the digital signature S1 therein. The specific verification method can refer to various existing verification technologies (such as whether the CA certificate of the data sender is valid, and / or whether the digital signature S1 can be decrypted using the public key corresponding to the certificate, and / or performing numerical matching, etc.), which are not limited here. If the verification fails, the establishment of the current communication connection is suspended or stopped, and the server returns a two-way authentication result (indicating the failure of two-way authentication) to the data sender; if the verification passes, the server generates and returns a second signature information (digital signature S2, which can be generated using the private key of the server). Similarly, the server can return a second verification token TokenSC to the data sender. TokenSC can be composed of R2, the server certificate ID, and S2. The server certificate is also pre-set, and the composition method can refer to the foregoing description, which will not be elaborated here.

[0090] Correspondingly, after the data sender receives TokenSC, it will also perform a signature verification process on the digital signature S2. If the verification fails, the establishment of the current communication connection is suspended or stopped, and the server returns a two-way authentication result (indicating the failure of two-way authentication) to the data sender; if the verification passes, the data sender generates a third random number R3, and can form the device information of the data sender by combining the identification information in the data sender (such as user name information, password information, and / or other unique identification information, etc.) and the random number R3, and then encrypts the device information using the public key of the server to obtain the encrypted device information in ciphertext state. The data sender sends the encrypted device information to the server, and the server can decrypt it using its own private key to obtain information such as user name and key, and verify the legality and compliance of these information, as well as verify the validity of R3. If at least one of the information verifications fails, the establishment of the current communication connection is suspended or stopped, and the server returns a two-way authentication result (indicating the failure of two-way authentication) to the data sender; if all verifications pass, the server can return a two-way authentication result (indicating the success of two-way authentication, and an access token of the server can also be carried) to the data sender, and establish a communication connection between the two ends.

[0091] It should be noted that each data sender can have two certificates (which can be used for encryption and signature respectively) or multiple certificates. The certificates of the data sender can be preset in the server so that the server can directly search for the corresponding certificate of the data sender locally during the two-way verification process between the data sender and the server. However, in the video application scenario, the video cloud server (server) may connect tens of thousands of IPC devices (data senders), and it is difficult to pre-install so many certificates inside the cloud storage nodes of the server. Therefore, in the actual application process, it is also possible to select to perform certificate exchange based on the protocol of the communication process (such as the Transport Layer Security protocol TLS) during the process of establishing a communication connection between the data sender and the server, so that the server can flexibly handle the certificate management of a large number of data senders.

[0092] In summary, in the above embodiments, the two-way verification process is realized when the data sender accesses the server. Through the two-way verification, the process of the data sender accessing the server is protected, which can prevent the data sender from accessing an unauthorized server and also prevent the server from accessing an unauthorized data sender.

[0093] The data protection method of this application can be applied not only to the data sender but also to the server. When the data protection method of this application is applied to the server, the method of this application can at least include the following steps:

[0094] In response to the existence of a communication connection between the server and the data sender, receive the data encryption key and the encrypted data sent by the data sender; use the obtained key encryption key to encrypt the data encryption key to obtain a stored encrypted frame; the encrypted data is obtained by the data sender encrypting the communication data with the data encryption key; merge the stored encrypted frame and the encrypted data to obtain the encrypted storage data.

[0095] Combined with the foregoing embodiments for description, if the server and the data sender pass the two-way authentication and establish a communication connection, the server can receive the data encryption key and the encrypted data sent by the data sender. Then the server can encrypt the data encryption key (such as VK) using the obtained key encryption key (such as VKEK) and generate a stored encrypted frame. Among them, the encrypted data is obtained by the data sender encrypting the communication data (such as the video stream) with the obtained data encryption key.

[0096] The encrypted data may include encrypted communication data and transmission encrypted frames. After receiving the encrypted data, the server may merge the stored encrypted frames and the transmission encrypted frames to obtain merged encrypted frames, and store the encrypted communication data and the merged encrypted frames as encrypted storage data (either stored together or separately, which is not limited here). Or merge the stored encrypted frames, the transmission encrypted frames, and the encrypted communication data to obtain encrypted storage data for storage.

[0097] Based on the above embodiments, the embodiments of the present application illustrate the steps of merging the stored encrypted frames and the encrypted data to obtain encrypted storage data. Among them, the encrypted data includes video data. Specifically, the method of this embodiment includes the following steps:

[0098] Identify the key frame data in the video data; add a stored encrypted frame to each key frame data respectively to obtain encrypted storage data.

[0099] Combined with the foregoing embodiments for explanation, the type of communication data in the present application may be video data (such as a video stream). Therefore, the encrypted data (encrypted data) may also be video data.

[0100] It can be understood that key frames (also called I-frames, Intra-coded Frames) usually exist in a video stream, which is a complete image frame and can be independently decoded without relying on the information of other frames. The video stream may also include non-key frames, such as P-frames, B-frames, etc., which will not be elaborated here.

[0101] Specifically, during the implementation of the data protection method of the present application, the key frame data in the video data can be identified, that is, the I-frames in the video data are determined. For each I-frame in the video file, a stored encrypted frame can be generated and added correspondingly to obtain encrypted storage data, thereby realizing the data protection of the video key frames.

[0102] Among them, the method of adding the stored encrypted frame can refer to the process in the foregoing embodiments where the server encrypts the VK of the data sender using the VKEK, which will not be elaborated here. Exemplarily, the server can obtain the key ciphertext containing the VKEK from the KMS, and then the server can decrypt the key ciphertext through an encryption hardware such as an encryption machine with an existing communication connection to obtain the VKEK in the plaintext state (key plaintext). The server then encrypts the key plaintext to obtain the form of the stored encrypted frame and writes it into the internal of the video streaming file. Among them, the encryption machine refers to an encryption device that has passed the national cipher authentication and is approved for use. The encryption machine and the host can communicate using the TCP / IP protocol, so the encryption machine has no special requirements for the type of the host and the host operating system.

[0103] Based on the above embodiments, the embodiments of the present application describe the steps before receiving the data encryption key and encrypted data sent by the data sending end in response to the existence of a communication connection between the server and the data sending end. Specifically, the method of this embodiment includes the following steps:

[0104] In response to the authentication request of the received data sending end, exchange authentication information with the data sending end and perform two-way authentication processing to obtain a two-way authentication result; in response to the two-way authentication result indicating that the data sending end and the server pass the two-way authentication, send an access token to the server and establish a communication connection.

[0105] Combined with the foregoing embodiments for description, this embodiment mainly describes that before the server and the data sending end formally transmit data, it also includes the two-way authentication process between the server and the data sending end.

[0106] Exemplarily, if the server receives the authentication request of the data sending end, it exchanges authentication information (such as certificates, signatures, and / or keys, etc.) with the data sending end and performs two-way authentication processing to obtain a two-way authentication result. If the two-way authentication result indicates that the data sending end and the server pass the two-way authentication, the server can send an access token to the server and establish a communication connection, and then the server can receive the communication data transmitted by the data sending end. If the two-way authentication result indicates that the data sending end and the server do not pass the two-way authentication, the server suspends or stops the current connection establishment process.

[0107] It should also be noted that the certificates involved in the two-way authentication process between the data sending end and the server may include:

[0108] 1. CA root certificate (used to verify the certificates of each other in the two-way authentication process of the Transport Layer Security (TLS) protocol based on national cryptography).

[0109] 2. Signature certificate and encryption certificate. Among them, the signature certificate is used for two-way authentication of identities in national cryptography TLS. The data sending end and / or the server can generate a certificate signing request file CSR (Certificate Signing Request). After the CA center issues the corresponding signature certificate according to the CSR file, the signature certificate can be imported locally. The encryption certificate can also be generated by the CA center to generate a public-private key pair and an encryption certificate, and is imported into the data sending end and / or the server in the form of a digital envelope (encrypted using the signature public key). After the data sending end and / or the server decrypt it with their respective signature private keys, the encryption certificate is securely stored locally.

[0110] In addition, it can also be referred to as Figure 3 as shownFigure 3 This is a schematic diagram of an exemplary video cloud storage system architecture in the data protection method of the present application. Among them, the business platform is a platform interface for visualizing video cloud storage services, the video cloud storage cluster is mainly a server for providing storage services, and the network camera IPC is the data sender. In addition, a password infrastructure may be provided in this system, which may include a certificate management module (mainly responsible for issuing digital certificates to various devices and users in the cloud storage system, such as national cryptography CA certificates); it may also include a KMS key management system (mainly responsible for managing the keys used in the cloud storage system, such as the key encryption key (VKEK) for image and audio / video data and / or other symmetric keys, etc. The KMS can ensure the security of key data; it is independent of the cluster scale and can manage the keys for periodic updates (for example, update once every 4 hours)), which may include a primary KMS system and a standby KMS system; in addition, an encryptor (also called a cipher machine, mainly responsible for generating asymmetric keys and storing private keys, etc., and can provide the computing power for storing encrypted frames) may also be included, which may include one or more encryptors.

[0111] The data protection method of the present application can be applied not only to the data sender and the server, but also to the data receiver. The data receiver of the present application can be a terminal device such as a mobile phone, a computer, a tablet computer, a smart watch, a smart glasses, etc. (which can also be called a client). When the data protection method of the present application is applied to the data receiver, the implementation process of the present application can at least include:

[0112] The data receiver needs to be verified by the server and establish a communication connection with the server to access the server; the data receiver that has successfully established a communication connection with the server can obtain the encrypted storage data from the server (its type can be video data as in the foregoing embodiments); the data receiver decrypts the encrypted storage data by using the obtained key, and then the communication data (such as the video stream in plain text state) can be obtained.

[0113] Exemplarily, the overall encryption principle of the present application follows the principle that whoever generates the data is responsible for encryption and whoever uses the data decrypts it. For example, the front-end device (data sender) encrypts the collected video and audio data and transmits it, that is, the transmission encryption at the source end; the storage device or platform stores the encrypted video and audio data, that is, the storage encryption; the storage device and the business platform support the user (data receiver) to perform operations such as playing, downloading, and / or exporting the encrypted video and audio data within the scope of their permissions.

[0114] Specifically, after the data receiving end obtains the encrypted stored data, its main implementation steps may include but are not limited to: first, use the corresponding key to decrypt the storage encryption frame in the encrypted stored data to obtain the VKEK ID in the storage encryption frame; search for the VKEK corresponding to the VEKE ID, and use the VKEK to decrypt the transmission encryption frame, then the VK ID in the transmission encryption frame can be obtained; search for the corresponding VK according to the VK ID, and then use the VK to decrypt the encrypted data (such as the encrypted video stream), then the original raw stream can be obtained. Among them, other information carried in the storage encryption frame and the transmission encryption frame can also be referred to as a reference during the decryption process. For example, when the data receiving end decodes the data, it can also perform verification through CRC16, which will not be specifically described here.

[0115] Another example is that for the authentication process between the data receiving end and the server, it can be similarly referred to the authentication process between the data sending end and the server in the foregoing embodiment. The authentication process between the data receiving end and the server can be a one-way authentication process, that is, the server authenticates the data receiving end. For example, it can be referred to as Figure 4 shown Figure 4 is a timing diagram of an exemplary one-way authentication process in the data protection method of the present application. The data receiving end can initiate a connection request and carry its own security information (such as the security algorithm set in the foregoing embodiment, etc.); the server judges its security ability according to the security information of the data receiving end; if the data receiving end passes the security verification of the server, the server generates a random number R1 and selects a target security algorithm from the security algorithm set and returns them to the data receiving end together; after the data receiving end learns that it has passed the security verification, it can generate a digital signature and combine it with the random number R4 and its own certificate ID to form a verification token Token and send it to the server for signature verification; after the server receives the Token, it can verify the digital signature therein; if the verification is passed, the server returns the public key of the server to the data receiving end; then the data receiving end can generate a random number R5, and use the public key of the server to encrypt the identification information (username, password) of the data receiving end and R5 to obtain the identification information in ciphertext state and send it to the server; afterwards, the server can use its own private key to decrypt it, verify the legality of the username and password and the validity of R5; after passing the verification, the server sends an access token to the data receiving end, thereby establishing a communication connection between the data receiving end and the server. For the specific implementation process of the one-way authentication process in this embodiment, it can also be similarly referred to the description of some steps in the two-way authentication process in the foregoing embodiment, which will not be elaborated here.

[0116] Among them, the certificates involved in the process of the data receiving end logging in to the server can also be pre-arranged and set. The certificates of the data receiving end and the server can be imported into the USBKey used by the data receiving end and the internal platform of the server respectively, and used for the verification during the login process of the data receiving end. Among them, the USBKey is a security tool that combines physical devices and PKI (Public Key Infrastructure) technology. By storing digital certificates and user private keys, it provides an additional layer of security for the communication process. In the scenario of the certificate application and import process, the USBKey can communicate with the data receiving end. The data receiving end generates a user certificate request file CSR based on the currently connected USBKey. After being signed by the CA center, the user certificate is imported into the USBKey for subsequent use when the user logs in to the server. The server can use a cryptographic machine with an existing communication connection to generate an operation and maintenance certificate request CSR file. After being signed by the CA center, the platform certificate is imported into the server cryptographic machine for use when the user (data receiving end) and the front-end device (data sending end) log in to the server platform in the subsequent process.

[0117] For ease of understanding, taking the video cloud storage system as an example, the certificate management process of the video cloud storage system can also be referred to as Figure 5 shown as Figure 5 a simple schematic diagram of the certificate management process in the data protection method of this application. Based on Figure 5 the main process shown, the application and issuance functions of the national secret CA certificate can be realized and used to implement the encryption and signature verification of the subsequent national secret authentication. In some application scenarios (the video cloud storage system and its business platform can provide operation and maintenance services and storage services), the certificates involved in the whole solution mainly include but are not limited to: cloud storage operation and maintenance user certificates, cloud storage operation and maintenance platform certificates, video cloud PaaS signature certificates, video cloud PaaS encryption certificates, device signature certificates, device encryption certificates, etc.; in the national secret encryption scenario of this application, the certificates and private keys are used in pairs.

[0118] In summary, the data protection method of the present application can design processes such as the client (data receiving end) logging in to the server and the device (data sending end) logging in to the server through the issuance and management of CA national cryptography certificates, and finally realize the access of national cryptography devices. Overall, based on the principle of "who generates the data encrypts it, and who uses the data decrypts it", the transmission encryption of communication data is finally realized. The national cryptography security of the transmission link is realized through the design of the transmission encryption frame, and the encrypted storage security of the data stream is realized through the design of the storage encryption frame. The key management system in the system of the present application can also introduce the KMS key management system: mainly used for the life cycle management of keys (such as VKEK, etc.), and responsible for the issuance of keys in the system. To solve the problems of network isolation between subsystems in the video cloud storage system and the differences in the docking methods of KMSs of different manufacturers, a KMS proxy service can be introduced in the storage device and the storage system. The KMS proxy service can directly connect to the KMS or can also be cascaded with the upper-level KMS proxy, which will not be elaborated here.

[0119] Therefore, the data protection method of the present application can realize the digital certificate authentication of user login and data encrypted transmission through the application, issuance, and cluster allocation processes of the national cryptography CA digital certificate provided in the foregoing embodiments. Through the design of one-way national cryptography authentication for client login in the cloud storage system, the national cryptography security of user login to the cloud storage system is realized; and through the design of the national cryptography two-way authentication process between the front-end device and the cloud storage system, the national cryptography security of the authentication interaction between the device and the cloud storage system is realized. In addition, through the method of generating the transmission encryption frame and the storage encryption frame in the present application, the secondary encrypted transmission and encrypted storage of the full-link data stream are realized, improving the data protection effect.

[0120] It should be further noted that the execution subject of the data protection method can be a data protection device. For example, the data protection method can be executed by a terminal device, a server, or other processing devices. Among them, the terminal device can be a user equipment (UE), a computer, a mobile device, a user terminal, a terminal, a cellular phone, a cordless phone, a personal digital assistant (PDA), a handheld device, a computing device, a vehicle-mounted device, a wearable device, etc. In some possible implementation manners, the data protection method can be implemented by a processor calling computer-readable instructions stored in a memory.

[0121] Figure 6 It is a block diagram of a data protection device shown in an exemplary embodiment of the present application. The data protection device can be applied to a data sending end. As Figure 6 shown, the exemplary data protection device 600 includes: a data encryption module 610 and a data sending module 620. Specifically:

[0122] A data encryption module 610, configured to encrypt communication data by using an obtained data encryption key to obtain encrypted data in response to the existence of a communication connection between a data sending end and a server end.

[0123] A data sending module 620, configured to send the data encryption key and the encrypted data to the server end, so that the server end encrypts the data encryption key by using an obtained key encryption key to obtain a stored encrypted frame, and merges the stored encrypted frame and the encrypted data to obtain encrypted stored data.

[0124] In this exemplary data protection device, if there is a communication connection between the data sending end and the server end, the data sending end can encrypt communication data by using the obtained data encryption key to obtain encrypted data; send the data encryption key and the encrypted data to the server end; and the server end can encrypt the data encryption key of the data sending end by using the obtained key encryption key to obtain a stored encrypted frame, and then merge the stored encrypted frame and the encrypted data to obtain encrypted stored data and store it, thereby realizing the transmission protection and storage protection of communication data during the communication process and improving data security.

[0125] In addition, the present application can also provide a data protection device, which can be applied to a data receiving end and includes:

[0126] A data receiving module, configured to receive the data encryption key and the encrypted data sent by the data sending end in response to the existence of a communication connection between the server end and the data sending end.

[0127] A key encryption module, configured to encrypt the data encryption key by using the obtained key encryption key to obtain a stored encrypted frame; the encrypted data is obtained by the data sending end encrypting the communication data by using the data encryption key.

[0128] A data storage module, configured to merge the stored encrypted frame and the encrypted data to obtain encrypted stored data.

[0129] It should be noted that the device provided in the above embodiment and the method provided in the above embodiment belong to the same concept. The specific manners in which each module and unit perform operations have been described in detail in the method embodiment, and will not be elaborated here. In practical applications, the device provided in the above embodiment can, according to needs, allocate the above functions to different functional modules, that is, divide the internal structure of the device into different functional modules to complete all or part of the functions described above. This is not limited here.

[0130] Among them, the functions of each module can be referred to in the data protection method embodiment, and will not be elaborated here.

[0131] Please refer to Figure 7 , Figure 7 which is a schematic structural diagram of an embodiment of the electronic device of the present application. The electronic device 100 includes a memory 101 and a processor 102. The processor 102 is configured to execute program instructions stored in the memory 101 to implement the steps in any of the above-described embodiments of the data protection method. In a specific implementation scenario, the electronic device 100 may include, but is not limited to, a microcomputer, a server. In addition, the electronic device 100 may also include mobile devices such as a laptop computer, a tablet computer, etc., which are not limited herein.

[0132] Specifically, the processor 102 is configured to control itself and the memory 101 to implement the steps in any of the above-described embodiments of the data protection method. The processor 102 may also be referred to as a CPU (Central Processing Unit). The processor 102 may be an integrated circuit chip with signal processing capabilities. The processor 102 may also be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. Additionally, the processor 102 may be implemented jointly by integrated circuit chips.

[0133] In this exemplary electronic device, if there is a communication connection between the data sending end and the server, the data sending end may encrypt the communication data using the obtained data encryption key to obtain encrypted data; send the data encryption key and the encrypted data to the server; the server may then encrypt the data encryption key of the data sending end using the obtained key encryption key to obtain a stored encryption frame, and then merge the stored encryption frame and the encrypted data to obtain encrypted storage data and store it, thereby enabling the transmission protection and storage protection of the communication data during the communication process and improving data security.

[0134] Please refer to Figure 8 , Figure 8 which is a schematic structural diagram of an embodiment of the computer-readable storage medium of the present application. The computer-readable storage medium 110 stores program instructions 111 that can be run by a processor. The program instructions 111 are used to implement the steps in any of the above-described embodiments of the data protection method.

[0135] In the exemplary storage medium, by running the program instructions in the storage medium, if there is a communication connection between the data sending end and the server, the data sending end can encrypt the communication data by using the obtained data encryption key to obtain encrypted data; send the data encryption key and the encrypted data to the server; the server can then encrypt the data encryption key of the data sending end by using the obtained key encryption key to obtain a storage encryption frame, and then merge the storage encryption frame and the encrypted data to obtain encrypted storage data and store it. Thus, the transmission protection and storage protection of the communication data can be realized during the communication process, and the data security can be improved.

[0136] In some embodiments, the functions or modules included in the device provided by the embodiments of the present disclosure can be used to execute the methods described in the above method embodiments. The specific implementation can refer to the description of the above method embodiments. For the sake of brevity, it will not be repeated here.

[0137] The above descriptions of the various embodiments tend to emphasize the differences between the various embodiments. The same or similar parts can be referred to each other. For the sake of brevity, they will not be repeated here.

[0138] In several embodiments provided in the present application, it should be understood that the disclosed methods and devices can be implemented in other ways. For example, the device embodiments described above are only illustrative. For example, the division of modules or units is only a logical function division. In actual implementation, there may be other division methods. For example, units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of the device or unit can be in an electrical, mechanical or other form.

[0139] In addition, each functional unit in various embodiments of the present application may be integrated into one processing unit, or each unit may exist physically alone, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of a software functional unit. If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it may be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, may be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) or a processor to execute all or part of the steps of the methods in various embodiments of the present application. The foregoing storage medium includes: various media such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disc that can store program codes.

Claims

1. A data protection method, characterized in that, The method is applied to a data sending end, and the method includes: Exchanging authentication information with a server and performing two-way authentication to obtain a two-way authentication result; the authentication information includes certificate information, and the certificate information is obtained by applying for signing from a certificate management module; if the two-way authentication result indicates that the two-way authentication is passed, a communication connection with the server is established; In response to the existence of the communication connection between the data sending end and the server, encrypting communication data by using an obtained data encryption key to obtain encrypted data; the communication data includes data collected by the data sending end; The encrypting the communication data by using the obtained data encryption key to obtain encrypted data includes: encrypting the communication data according to the obtained encryption algorithm and the data encryption key to obtain encrypted data; generating a transmission encryption frame according to the data encryption key and the encrypted data; the transmission encryption frame includes an encryption type, a key identifier, and redundant check data; performing a merging process on the transmission encryption frame and the encrypted data to obtain the encrypted data; Sending the data encryption key and the encrypted data to the server, so that the server encrypts the data encryption key by using an obtained key encryption key to obtain a storage encryption frame, and performing a merging process on the storage encryption frame and the encrypted data to obtain encrypted storage data; wherein, the key encryption key is obtained from a key management system.

2. The method according to claim 1, wherein After performing the merging process on the transmission encryption frame and the encrypted data to obtain the encrypted data, the method further includes: Sending the data encryption key and the encrypted data to the server, so that the server merges and stores the storage encryption frame and the transmission encryption frame to obtain the encrypted storage data.

3. The method according to claim 1, characterized in that, Before, in response to the existence of the communication connection between the data sending end and the server, encrypting the communication data by using the obtained data encryption key to obtain encrypted data, the method further includes: Exchanging authentication information with the server and performing two-way authentication processing to obtain a two-way authentication result; In response to the two-way authentication result indicating that the data sending end and the server pass the two-way authentication, establishing the communication connection according to the received access token sent by the server.

4. The method according to claim 3, characterized in that, The exchanging authentication information with the server and performing two-way authentication processing to obtain a two-way authentication result includes: Sending security information supported by the data sending end to the server for security verification to obtain a security verification result; In response to the security verification result indicating that the verification is passed, generating first signature information and sending it to the server, so that after the server verifies the first signature information, generating second signature information and sending it to the data sending end; In response to the verification of the second signature information passing, encrypting device information of the data sending end by using the key of the server to obtain encrypted device information; Send the encrypted device information to the server so that the server decrypts the encrypted device information using the key to obtain the device information, and performs a verification process on the device information to obtain the two-way authentication result.

5. A data protection method, characterized in that, The method is applied to a server, and the method includes: Based on an authentication request sent by a received data sender, exchange authentication information with the data sender and perform two-way authentication to obtain a two-way authentication result; the authentication information includes certificate information, and the certificate information is obtained by applying for signing from a certificate management module; if the two-way authentication result indicates that the two-way authentication is passed, establish a communication connection with the server; In response to the existence of the communication connection between the server and the data sender, receive the data encryption key and encrypted data sent by the data sender; the encrypted data includes the data collected by the data sender encrypted using the data encryption key; The step of the data sender encrypting the collected data using the data encryption key includes: the data sender encrypts the data according to the obtained encryption algorithm and the data encryption key to obtain encrypted data; generates a transmission encryption frame according to the data encryption key and the encrypted data; the transmission encryption frame includes an encryption type, a key identifier, and redundant check data; merges the transmission encryption frame and the encrypted data to obtain the encrypted data; Encrypt the data encryption key using the obtained key encryption key to obtain a storage encryption frame; the encrypted data is obtained by the data sender encrypting data using the data encryption key; wherein, the key encryption key is obtained from a key management system; Merge the storage encryption frame and the encrypted data to obtain encrypted storage data.

6. The method according to claim 5, wherein The encrypted data includes video data, and the step of merging the storage encryption frame and the encrypted data to obtain encrypted storage data includes: Identify the key frame data in the video data; Add a storage encryption frame to each key frame data respectively to obtain the encrypted storage data.

7. The method according to claim 5, characterized in that, Before the step of, in response to the existence of a communication connection between the server and the data sender, receiving the data encryption key and encrypted data sent by the data sender, the method further includes: In response to the authentication request of the received data sender, exchange authentication information with the data sender and perform a two-way authentication process to obtain a two-way authentication result; In response to the two-way authentication result indicating that the data sender and the server pass the two-way authentication, send an access token to the server and establish the communication connection.

8. An electronic device, characterized in that, It includes a memory and a processor, and the processor is used to execute the program instructions stored in the memory to implement the method according to any one of claims 1 to 7.

9. A computer-readable storage medium having program instructions stored thereon, characterized in that, When the program instructions are executed by the processor, the method according to any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Content protection

    CN107925795A

  • Authentication method, system, device and storage medium

    CN110430043A

  • Multimedia data storage method, computer equipment and storage device

    CN115834035A

  • Video security downloading and playing method based on GB35114 protocol

    CN119172569A