Equipment communication method and device, computer equipment and computer readable medium

By determining whether the server receives the key during the initialization process of IoT devices and temporarily decrypts and forwards it through the client, the data security problem caused by the key is solved, and higher communication quality and data security are achieved.

CN119995843AActive Publication Date: 2025-05-13GREE ELECTRIC APPLIANCE INC OF ZHUHAI +1

Patent Information

Application Number
CN202411937981.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-26
Publication Date
2025-05-13
Estimated Expiration
2044-12-26

AI Technical Summary

Technical Problem

During the initialization process of IoT devices, the keys are not synchronized, resulting in data security issues, and the prior art has failed to provide a more reliable solution.

Method used

By generating the first data packet on the device side, sending it to the server based on the client, and determining whether the server has received the key. If the key is received, a second data packet is sent; if the key is not received, the second data packet is sent to the client, decrypted through the client and then sent to the server.

Benefits of technology

When the key is not sent synchronously, data interaction between the device and the server is realized, enhancing the communication quality and data security with the server during initialization of the device.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995843A_ABST
    Figure CN119995843A_ABST
Patent Text Reader

Abstract

The invention relates to an equipment communication method and device, computer equipment and a computer readable medium. The method comprises the steps that a first data packet generated by an equipment end is sent to a server based on a client, whether the server receives the first data packet is judged, and the first data packet comprises a secret key; if the server receives the secret key, a second data packet of the device end is sent to the server, and the second data packet comprises the encrypted data to be encrypted; and if the server does not receive the secret key, sending a second data packet of the device end to the client, decrypting the second data packet through the client, and sending the decrypted second data packet to the server. In the initial binding stage of the device end and the server, a path for decrypting the data through the client and forwarding the data to the server is temporarily established, so that the device end and the server are decoupled and data interaction is completed under the condition that the secret key is not synchronously sent; and the communication quality and the data security between the device end and the server during initialization can be enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and in particular to a device communication method, apparatus, computer equipment, and computer-readable medium. Background Art

[0002] With the rapid development of science and technology, IoT technology has been widely used in our daily lives. IoT devices, such as smart home devices and smart security systems, achieve information exchange and remote control between devices through connection with the Internet. In the process of establishing a communication connection between IoT devices and servers, the choice of communication method is crucial. Common communication methods include wired communication and wireless communication. In addition, some IoT devices also use key encryption technology to ensure data security during communication. These exclusive keys will be sent to the server when the device is initialized for subsequent communication encryption and decryption.

[0003] However, in the process of initializing IoT devices, information security issues have become increasingly prominent. In order to ensure the security of communication between the device and the server, the client-side relay method is usually adopted in the prior art. The client first undergoes user authentication on the server, and then establishes connections with the device and the server respectively. Although this method improves the security of communication to a certain extent, there are still some problems. In particular, before the key is successfully sent to the server, the device is decoupled from the server. The device may send a data packet to the server first for various reasons. At this time, since the server has not received the key, it is unable to correctly decrypt the received data packet, resulting in data processing failure or data loss.

[0004] It can be seen that the existing technology has not yet proposed a more reliable solution to the data security problem caused by key asynchrony during the initialization process of IoT devices. Summary of the invention

[0005] The present application provides a device communication method, apparatus, computer equipment and computer-readable medium to solve the technical problem of data security caused by key asynchrony during the initialization process of the Internet of Things devices in the above-mentioned prior art.

[0006] According to one aspect of an embodiment of the present application, the present application provides a device communication method, the method comprising: sending a first data packet generated by a device end to a server based on a client, and determining whether the server has received the first data packet, the first data packet including a key; if the server receives the key, sending a second data packet from the device end to the server, the second data packet including encrypted data to be encrypted; if the server does not receive the key, sending the second data packet from the device end to the client, and decrypting the second data packet through the client and sending it to the server.

[0007] Optionally, before sending the first data packet generated by the device side to the server based on the client, the method also includes: constructing a first transmission channel between the device side and the server and a second transmission channel between the device side and the client with the client as a transit platform; generating the key according to a preset encryption algorithm by a key generation center based on the device side; sending the key to the server through the first transmission channel, and sending the key to the client based on the second transmission channel.

[0008] Optionally, the device-based key generation center generates the key according to a preset encryption algorithm, including: determining the key length based on the data type of the data to be encrypted in the device; based on the determined key length, generating the key on the device through a symmetric encryption algorithm to obtain the key.

[0009] Optionally, the first data packet also includes device information, and the first data packet generated by the device side is sent to the server based on the client, and it is determined whether the server has received the first data packet, including: extracting the device information of the device side, sending the device information to the client and the server, and performing device authentication on the client and the device side based on the device information; if the device authentication is passed, the key generated by the device side is sent to the client through the second transmission channel, and the key is forwarded to the server through the client; and it is determined whether the server has received the key according to the feedback information of the server.

[0010] Optionally, judging whether the server has received the key according to feedback information from the server includes: obtaining the feedback information from the server, the feedback information being determined according to a state in which the server receives the key, and including first feedback information and second feedback information; if the feedback information is the first feedback information, judging that the server has not received the key; if the feedback information is the second feedback information, judging that the server has received the key.

[0011] Optionally, if the server does not receive the key, the second data packet on the device side is sent to the client, and the second data packet is decrypted by the client and sent to the server, including: if the server does not receive the key, the data to be encrypted is encrypting the data based on the key on the device side to obtain the second data packet; the second data packet on the device side is sent to the client; the second data packet is decrypted based on the key temporarily stored on the client to obtain the decrypted data, and the temporarily stored key is temporarily stored when the client sends it to the server; the decrypted data obtained by decryption on the client is forwarded to the server.

[0012] Optionally, after forwarding the decrypted data obtained by decrypting the client to the server, the method also includes: sending the encrypted data on the device side as verification data to the server; obtaining a first verification result generated by the server based on the verification data, and obtaining a second verification result returned by the server based on the decrypted data; comparing the first verification result with the second verification result to determine whether the first verification result is consistent with the second verification result; if the first verification result is consistent with the second verification result, it is determined that the communication through the first transmission channel between the device side and the server is normal, and the second transmission channel with the client as the forwarding node is cut off; if the first verification result is inconsistent with the second verification result, it is determined that the communication through the first transmission channel between the device side and the server is abnormal, and the second transmission channel with the client as the forwarding node is maintained.

[0013] According to another aspect of an embodiment of the present application, the present application provides a device communication device, including a judgment module for sending a first data packet generated by the device end to a server based on a client, and judging whether the server has received the first data packet, the first data packet including a key; a first sending module for sending a second data packet from the device end to the server if the server has received the key, the second data packet including encrypted data to be encrypted; and a second sending module for sending the second data packet from the device end to the client if the server has not received the key, and decrypting the second data packet through the client and sending it to the server.

[0014] According to another aspect of an embodiment of the present application, the present application provides a computer device, including a memory, a processor, a communication interface and a communication bus, wherein the memory stores a computer program that can be run on the processor, the memory and the processor communicate through the communication bus and the communication interface, and the processor implements the steps of the device communication method when executing the computer program.

[0015] According to another aspect of an embodiment of the present application, the present application provides a computer-readable medium having a non-volatile program code executable by a processor, wherein the program code enables the processor to execute the steps of the device communication method.

[0016] The above technical solution provided by the embodiment of the present application has the following advantages compared with the related art:

[0017] The present application provides a device communication method, which can not only encrypt data by generating a key to ensure the security of data transmission during device initialization, but also determine whether the server receives the key. When the key is not received, that is, when the device is decoupled from the server, a temporary way is built to decrypt the data through the client and forward it to the server. When the key is not sent synchronously, data interaction between the device and the server is achieved, which is more conducive to enhancing the communication quality and data security between the device and the server during initialization. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0019] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the related technologies, the drawings required for use in the embodiments or the related technical descriptions are briefly introduced below. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.

[0020] Figure 1 A schematic diagram of a hardware environment for an optional device communication method provided according to an embodiment of the present application;

[0021] Figure 2 A schematic diagram of an optional device communication method flow chart provided according to an embodiment of the present application;

[0022] Figure 3 This is a schematic diagram of an optional data interaction provided according to an embodiment of the present application;

[0023] Figure 4 A schematic diagram of another optional device communication method flow chart provided according to an embodiment of the present application;

[0024] Figure 5 A schematic diagram of an optional device communication apparatus structure provided according to an embodiment of the present application;

[0025] Figure 6 A schematic diagram of an optional computer device structure provided for an embodiment of the present application. DETAILED DESCRIPTION

[0026] In order to make the purpose, technical solution and advantages of the embodiments of the present application clearer, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application.

[0027] In order to solve the problem mentioned in the background technology, according to one aspect of the embodiments of the present application, an embodiment of a device communication method is provided.

[0028] like Figure 1 As shown, the above device communication method can be applied to Figure 1 In the hardware environment shown. The system architecture 100 of the hardware environment includes a terminal device 101 and a server 103. The server 103 is connected to the terminal 101 through a network and can be used to provide services for the terminal or a client installed on the terminal. A database 105 can be set on the server or independently of the server to provide data storage services for the server 103. The network can include various connection types, such as wired, wireless communication links or optical fiber cables, etc.

[0029] It should be noted that the device end provided in this embodiment may be the terminal device 101 mentioned above, and the client provided in this embodiment may be an APP installed on the terminal device 101.

[0030] The user can use the terminal device 101 to interact with the server 103 through the network to receive or send messages, etc. Various communication client applications can be installed on the terminal device 101, such as web browser applications, search applications, instant messaging tools, etc. Among them, the terminal device 101 can be various electronic devices with a display screen and supporting web browsing, including but not limited to smart phones, tablet computers, e-book readers, MP3 players (Moving Picture Experts Group Audio Layer III, dynamic image experts compression standard audio layer 3), MP4 (Moving Picture Experts Group Audio Layer IV, dynamic image experts compression standard audio layer 4) players, laptops and desktop computers, etc. The server 103 can be a server that provides various services, such as a background server that supports the pages displayed on the terminal device 101.

[0031] It should be noted that the device communication method provided in the embodiment of the present application is generally executed by a server and / or a terminal device, and accordingly, a device communication apparatus is generally provided in a server / terminal device. And it should be understood that Figure 1 The number of terminal devices, networks and servers in the embodiment is only for illustration. Any number of terminal devices, networks and servers may be provided according to implementation requirements.

[0032] like Figure 2 As shown, Figure 2 A flow chart of a device communication method provided by an embodiment of the present invention. Taking the device communication method executed by a server as an example, a device communication method includes the following steps:

[0033] Step S202: Send a first data packet generated by the device to the server based on the client, and determine whether the server has received the first data packet, where the first data packet includes a key.

[0034] In this embodiment, combined with Figure 3 As shown, the device side, client side and server can build a device communication system, and the server can process data; the client side can establish communication between the device and the server, and forward various data of the device to the server; the device side can establish communication with the server and perform related actions. After the correct communication link is established, the device side and the server can directly exchange data, the device side and the client side can exchange data, and the client side can exchange data with the server.

[0035] In this embodiment, the above-mentioned device communication method can be used in the initial binding stage between the device and the server. In the initial binding stage, the client sends a key to the server. At this time, it is assumed that the server does not receive the key. The client is used as a transit platform to forward the first data packet of the device to the server. After the server and the device establish a correct connection link, the server can correctly receive the key sent by the device. At this time, the standby connection with the client as the transit platform can be disconnected.

[0036] Step S204: If the server receives the key, a second data packet of the device is sent to the server, where the second data packet includes the encrypted data to be encrypted.

[0037] Combination Figure 4 As shown, in this embodiment, the server will feedback information whether it receives the key or not, and the information fed back when the key is received and not received is different. The information fed back can be preset information or customized. By analyzing the information fed back by the server, it can be determined whether the server has received the key.

[0038] Furthermore, when the server receives the key, it means that the device and the server have established a correct communication link, and the key can be successfully sent to the server for temporary storage. Therefore, when the server receives the key, it can send the second data packet of the device to the server, and the server can decrypt the second data packet according to the received key to obtain the decrypted data.

[0039] Step S206: If the server does not receive the key, the second data packet on the device side is sent to the client, and the client decrypts the second data packet and sends it to the server.

[0040] Combination Figure 4 As shown, in this embodiment, when the server does not receive the key, if the device side directly sends the second data packet to the server, the server cannot decrypt the second data packet, and the device side has sent the key to the client for temporary storage. In this regard, the client can be used as a transit platform to build a temporary backup link, and the second data packet that the device side needs to send is first sent to the client, and the decrypted data is obtained by decrypting it with the key temporarily stored in the client, and then the decrypted data is forwarded to the server. Regardless of whether the server receives the key, it will not affect the acquisition of decrypted data from the server, so that the server can quickly respond based on the decrypted data to ensure the reliability of data response.

[0041] In some examples, if there are multiple device ends, the keys generated by different device ends are different, and different device ends correspond to different keys, which can achieve point-to-point encryption between the server and the device end, thereby improving data transmission security, reducing the possibility of malicious batch attacks on data during transmission and storage, and improving system defense.

[0042] In an embodiment of the present invention, when the device is initialized, not only can data be encrypted by generating a key to ensure the security of data transmission, but also it can determine whether the server receives the key. When the key is not received, that is, when the device is decoupled from the server, a temporary way is built to decrypt the data through the client and forward it to the server. When the key is not sent synchronously, data interaction between the device and the server is achieved, which is more conducive to enhancing the communication quality and data security between the device and the server when the device is initialized.

[0043] In an optional embodiment, before the above step S202, the method further specifically includes:

[0044] Establishing a first transmission channel between the device and the server and a second transmission channel between the device and the client using the client as a transfer platform;

[0045] The key is generated by a key generation center based on the device end according to a preset encryption algorithm.

[0046] In this embodiment, in order to realize data transmission between the device side, the client and the server, a network connection needs to be established between the device side, the client and the server. Common network connection methods include wired connection and wireless connection. Wired connection includes but is not limited to Ethernet, USB connection, HDMI connection, etc.; wireless connection includes but is not limited to Wi-Fi, Bluetooth, Zigbee, 4G / 5G, etc. In addition, establishing a communication protocol is the basis for data exchange between the device side, the client and the server. The communication protocol includes but is not limited to HTTP / HTTPS protocol, SSL protocol, TLS protocol, MQTT protocol, WebSocket protocol, etc. And hardware devices need to be configured on the device side to realize network communication, including configuring Wi-Fi module, GPRS module, 3G / 4G / 5G module, etc. These modules can be connected to the device through serial port, SPI, I2C and other interfaces.

[0047] In this embodiment, the server also needs to have high-performance server hardware equipment to ensure that it can handle data transmission requests from a large number of devices, including selecting a stable network connection and configuring the corresponding network address and port so that the device can establish a connection with it. A cloud platform can be built on the server, such as an MQTT server, HTTP server, etc., which is responsible for processing the data and instructions sent by the device and providing services such as data storage, device management, and data analysis. In addition, the server needs to provide a communication interface and API for communicating with the device to facilitate data exchange and communication between the device and the server.

[0048] In this embodiment, a key can be generated based on a preset encryption algorithm by a key generation center on the device side, and the preset encryption algorithm can be a symmetric encryption algorithm or an asymmetric encryption algorithm. Among them, symmetric encryption algorithms usually have a faster encryption speed and are suitable for processing large amounts of data. Under the same key length, the encryption efficiency of symmetric encryption algorithms is usually higher than that of asymmetric encryption algorithms. Common symmetric encryption algorithms include AES (Advanced Encryption Standard), DES (Data Encryption Standard), 3DES (Triple Data Encryption Standard), etc., which can be used in network transmission, file encryption, database encryption and other fields. For example, based on HTTPS and SSL / TLS protocols, symmetric encryption algorithms are used to protect the transmission of the second data packet in network communication. Among them, asymmetric encryption algorithms include RSA (Rivest-Shamir-Adleman algorithm), ECC (Elliptic Curve Cryptography), etc., which can be applied to digital signatures, key exchange, encrypted communications and other fields. Since the encryption and decryption speed of asymmetric encryption algorithms is slow, they are usually used to encrypt small amounts of data or for digital signatures and other scenarios.

[0049] In this embodiment, the corresponding encryption algorithm can be selected according to the specific usage scenario of the device communication method. For scenarios where a large amount of data is encrypted, a symmetric encryption algorithm can be used to generate a symmetric key. For scenarios where a small amount of data is encrypted and data security requirements are high, an asymmetric encryption algorithm can be selected to generate a private key and a public key. For example, some public news information is encrypted using the DES encryption algorithm, and personal privacy information is encrypted using the RSA encryption algorithm.

[0050] Furthermore, based on the above communication foundation, a first data transmission channel for direct data exchange between the device and the server can be constructed, as well as a second transmission channel between the device, the client and the server. The device can send the first data packet, the second data packet and other data directly to the server through the first transmission channel, or send the first data packet, the second data packet and other data to the client through the second transmission channel, and then transfer them to the server through the client.

[0051] In this embodiment, by building a first transmission channel between the device and the server, secure data interaction between the client and the server can be ensured; by building a second transmission channel between the device, the client and the server, in the event of an abnormality in the first transmission channel or the server not receiving the key, the client can be used as a transit platform to achieve temporary data interaction between the device and the server based on the second transmission channel, maintaining secure transmission of data and keys, ensuring data security, and improving the stability and reliability of the system. Generating keys through a preset encryption algorithm can achieve data encryption and key distribution.

[0052] In an optional embodiment, a key generation center based on a device generates the key according to a preset encryption algorithm, including:

[0053] Determine the key length based on the data type of the data to be encrypted on the device;

[0054] Based on the determined key length, the key is generated on the device side through a symmetric encryption algorithm.

[0055] In some examples, the data to be encrypted may be text, image, audio or other file formats, and the file suffix may be dump, bak, csv, xls or xlsx, etc. The present invention does not impose specific restrictions on the file type and file suffix of the data to be encrypted, and they can be selected according to actual needs.

[0056] In this embodiment, different data types have different security level requirements for encrypted data, so the key length can be determined based on the data type, thereby ensuring the security requirements of different types of data. Among them, data types with higher security level requirements can be used as sensitive data, including personal identity information, financial information, chat information, medical record information, etc. Data types with lower security levels can be used as non-sensitive data, including public news, announcements, ordinary files, etc.

[0057] Furthermore, the key length corresponding to the data type with higher security requirements is longer. If the amount of data encrypted and transmitted in the applicable system is small, a symmetric key can be generated by a symmetric encryption algorithm according to the determined key length. Of course, if the amount of data encrypted and transmitted in the applicable system is large, a key pair can also be generated by an asymmetric encryption algorithm, including a public key and a private key. After the public key is generated, it is distributed to the client and the server. For example, the key pair is generated on the device side using the genrsa command of OpenSSL.

[0058] In some examples, for data types with higher security requirements, a key length of 2048 bits or longer can be used, which can provide higher security and reduce the risk of data being cracked. For data types with lower security requirements, a key length of less than 2048 bits can be used, which can reduce the computational complexity of encryption and decryption operations and improve performance. For example: the data type of the data to be encrypted is the user's personal financial information, select the RSA algorithm for encryption, and use a key length of 2048 bits.

[0059] In this embodiment, by determining the key length according to the data type of the data to be encrypted, the requirements for different security levels of protection can be met for different data types, which is more conducive to improving the security of data encryption and data transmission; by generating keys through a symmetric encryption algorithm, data encryption efficiency and data processing efficiency can be guaranteed.

[0060] In an optional embodiment, the above step S202 specifically includes:

[0061] Extracting the device information from the device side, sending the device information to the client and the server, and performing device authentication on the client and the device side based on the device information;

[0062] If the device authentication is successful, the key generated by the device is sent to the client through the second transmission channel, and the key is forwarded to the server through the client;

[0063] It is determined whether the server has received the key according to the feedback information of the server.

[0064] In this embodiment, the first data packet may include device information of the device end. When there are multiple device ends, based on the device information, the client and the server end may obtain the device information of the device end for analysis to implement device authentication. The device information includes: device name, device ID, device type, brand / model, serial number, production date, manufacturer information, status information, timestamp, etc.

[0065] Furthermore, when setting up a temporary communication link, the device information can be extracted from the static data repository on the device side, and the client needs to obtain the device information for device authentication. After passing the device authentication, the generated key can be sent to the client, and then based on the client forwarding the device information to the server for device authentication, the client also forwards the key to the server. If the authentication fails, it can be said that there is an abnormality on the device side, and the key will not be distributed to ensure data security. The above feedback information can be determined based on the status of the server receiving the key. The feedback information corresponding to not receiving the key and receiving the key is different.

[0066] In this embodiment, by obtaining device information and performing device verification first, point-to-point data transmission between the device side, the client side and the server can be guaranteed; by using the client side as a transit platform, temporary data interaction between the device side and the server is realized based on the second transmission channel, and the device and the server can be decoupled during the initial binding stage at each end, preventing the device from having to maintain a long connection during the key transmission and confirmation process, which causes resource crowding, thereby ensuring the reliability of system operation.

[0067] In an optional embodiment, judging whether the server has received the key according to the feedback information of the server specifically includes:

[0068] Acquire the feedback information of the server, where the feedback information is determined according to a state in which the server receives the key, and includes first feedback information and second feedback information;

[0069] If the feedback information is the first feedback information, determining that the server has not received the key;

[0070] If the feedback information is the second feedback information, it is determined that the server has received the key.

[0071] In this embodiment, during the initial binding phase between the device and the server, it is assumed that the server has not received the key, and data is transferred through the client. Key reception is a continuous process. If the server has not received the key at a preset time interval, it returns the first feedback information. The first feedback information can be empty information or information pre-agreed between the server and the device for not receiving the key. The second feedback information can be a confirmation message, which is used to indicate that the key has been received.

[0072] In some examples, after the server receives the key sent by the device, the server can verify the key according to preset verification rules, such as checking the format, length, and whether the key has expired. If the key verification passes, the server considers that the key has been successfully received; if the verification fails, the server considers that the received key is invalid. The server generates corresponding feedback information based on the verification result of the key. If the key verification passes, the second feedback information returned may include words such as "The key has been successfully received"; if the verification fails, the first feedback information returned may include words such as "The key is invalid, please resend". Among them, because the key is forwarded based on the client as a transit platform before the server receives the key, when the server gives feedback based on whether the key is received, the feedback information is also sent to the client through the established second transmission channel, and forwarded to the device through the client.

[0073] In some examples, the server, client, and device may also encrypt the feedback information using a predetermined encryption method to ensure the security of the feedback information, for example, encrypting it using a fixed string of characters.

[0074] Furthermore, after receiving the feedback information sent by the server, the device parses the feedback content. If the feedback information indicates that the key has been successfully received, the device can perform subsequent operations, such as continuing to send the encrypted second data packet, etc. If the feedback information indicates that the key is invalid, the device may need to regenerate the key and send it to the server again to ensure the uniqueness of the key and continue to establish a connection with the server.

[0075] In this embodiment, when the key is sent to the server based on the client, it is possible to determine whether the key is received by verifying the feedback information of the server. When the key is received, the device directly sends the second data packet to the server through the first transmission channel, or uses the client as a transit platform to send the second data packet to the server based on the second transmission channel when the key is not received. This not only completes the data transmission between the device and the server, but also decouples the device and the server, preventing the device from having to maintain a long connection during the key transmission and confirmation process, which causes resource crowding, thereby ensuring the reliability of system operation.

[0076] In an optional embodiment, the above step S206 specifically includes:

[0077] S2061, if the server does not receive the key, encrypting the data to be encrypted based on the key in the device end to obtain the second data packet;

[0078] S2062, sending the second data packet of the device end to the client;

[0079] S2063, decrypting the second data packet based on the key temporarily stored by the client to obtain decrypted data, wherein the temporarily stored key is temporarily stored when the client sends the key to the server;

[0080] S2064, forwarding the decrypted data obtained by the client decryption to the server.

[0081] In this embodiment, if the server does not receive the key, for the transmission of the data to be encrypted, the data will first be encrypted on the device side using the public key in the generated key pair or the generated symmetric key to obtain a second data packet, wherein the second data packet may include information such as the data to be encrypted and the encrypted timestamp.

[0082] In some examples, data preprocessing may be performed before encryption, including missing value processing, outlier processing, data transformation, format conversion, standardization, etc. For example, if the data to be encrypted is text, the text format is converted into a file format that can be received and recognized by the server. For another example, if the data to be encrypted is a table, the table content is extracted and converted into text or other file formats so that the server can receive and recognize it.

[0083] Furthermore, combined with Figure 4 As shown, after the data is encrypted on the device side, the second data packet can be sent to the client based on the second transmission channel. The key sent by the device side is temporarily stored in the client, so the second data packet can be decrypted in the client, the decrypted data can be extracted, and then the decrypted data can be forwarded to the server through the second transmission channel by the client for response. After the server receives the decrypted data decrypted by the client, it can return confirmation information to the client, and then the client returns the confirmation information to the device side.

[0084] In other examples, when the data of the second data packet is successfully uploaded to the server, a corresponding log file can be generated in the server to record the transmission completion status of the decrypted data. If the decrypted data log file is not recorded in the server, it means that the upload is not successful. In this way, by recording the log file on the server, it is possible to detect whether the decrypted data is uploaded successfully based on the log file. If the upload is not successful, feedback can be given to the device in a timely manner to re-upload.

[0085] In this embodiment, by preprocessing the encrypted data, the data can be converted into a form that can be received and processed by the server, thereby ensuring the efficiency and uniformity of data transmission; by encrypting the encrypted data with a key on the device side to generate a second data packet, the security of the data can be guaranteed; using the client as a transit platform to decrypt the second data packet and then forward it to the server, not only can the data transmission between the device side and the server be completed, but also the device side and the server can be decoupled, preventing the device from having to maintain a long connection during the key transmission and confirmation process, which causes resource crowding, thereby ensuring the reliability of system operation.

[0086] In an optional embodiment, after the above step S2064, the method further includes:

[0087] Send the encrypted data on the device to the server as verification data;

[0088] Obtaining a first verification result generated by the server according to the verification data, and obtaining a second verification result returned by the server according to the decrypted data;

[0089] Compare the first verification result with the second verification result to determine whether the first verification result is consistent with the second verification result;

[0090] If the first verification result is consistent with the second verification result, it is determined that the first transmission channel between the device and the server is communicating normally, and the second transmission channel with the client as the forwarding node is cut off;

[0091] If the first verification result is inconsistent with the second verification result, it is determined that the communication of the first transmission channel between the device end and the server is abnormal, and the second transmission channel with the client as the forwarding node is maintained.

[0092] In this embodiment, the reasons why the server did not receive the key may include disconnection of the communication link, network delay, etc. In fact, establishing a connection between the server and the device is a continuous process. In the initial binding stage, the server may not receive the key, but in the subsequent process, the communication between the server and the device will continue to return to normal. Therefore, after the recovery, the server can directly interact with the device based on the first transmission channel for data. At this time, the temporary backup connection that uses the client as a transit platform and interacts with data based on the second transmission channel will be disconnected.

[0093] In this embodiment, if the server can receive the key, it can be said that the device side can directly interact with the device side based on the first transmission channel. In order to continuously detect whether the server can receive the key, the encrypted data of the device side can be sent to the server as verification data. If the server receives the key, it will decrypt the verification data, obtain the decrypted data, and generate a first verification result. In addition, after the server receives the decrypted data sent by the client, it will also return a second verification result. If the server can already receive the key, the generated first verification result and the second verification result should be the same.

[0094] Furthermore, by comparing the first verification result and the second verification result, it is possible to know whether the server can receive the key. If the two are consistent, it is determined that the first transmission channel between the device and the server is communicating normally, and the second transmission channel with the client as the forwarding node (transfer platform) is cut off, that is, the backup channel is disconnected, and the data interaction between the device and the server is restored to the first transmission channel. Otherwise, the second transmission channel will be maintained for data interaction.

[0095] In this embodiment, the verification data is directly sent to the server through the result verification method, and a first verification result generated based on the verification data and a second verification result generated by temporarily building decrypted data through the client and sending it to the server are obtained for comparison to determine whether the server receives the key. After the first transmission channel between the device and the server communicates normally, the backup channel can be cut off in time to restore direct data interaction between the device and the server, reducing the impact of the forwarding method of the transit platform on data transmission and processing efficiency, as well as reducing the coupling between the server and the device, avoiding resource crowding caused by long-term long connections.

[0096] In some examples, the communication status between the client, device, and server can also be monitored. If the communication status between the server and the device or client changes, for example, the communication terminal or the signal is weak, the technicians can be notified to troubleshoot the problem through early warning methods, including sound and light prompts, text messages, emails, etc. Once an abnormality is found, timely measures can be taken to troubleshoot and repair it to ensure the stability of the system.

[0097] In this embodiment, key management and update can also be performed to ensure the freshness and security of the key. By establishing a key management system, full life cycle management such as key generation, distribution, storage and destruction can also be achieved. Specifically, it is possible to detect whether the current key state meets the key update conditions for key update. Among them, the key update conditions include update cycle, key usage times, key risk assessment value, event-driven update, etc. The update cycle can refer to the periodic update of the key; the key usage times can refer to the number of times the key is called during data transmission and retrieval; the key risk assessment value can refer to the risk level of the key determined based on the risk assessment results according to the system risk assessment; event-driven update can refer to the user or specific conditions driving the key update. Among them, the detection of whether the current key state meets the key update conditions can be performed on the device side, the server side or the client side. If any end triggers the key update, the key update synchronization can be performed on the other ends to achieve the overall key update of the system to ensure the uniformity of the key and the encryption method of the encrypted data.

[0098] In this embodiment, key updates are triggered based on any one of the update cycle, key usage times, key risk assessment value, and event-driven updates, so personalized management can be achieved. By managing and updating the keys, the freshness and security of the keys can be ensured, thereby achieving full life cycle management of the keys.

[0099] According to another aspect of the embodiment of the present application, Figure 5 As shown, corresponding to the device communication method in the above embodiment, this embodiment provides a device communication apparatus, the apparatus comprising:

[0100] A judgment module 501 is used to send a first data packet generated by the device end to the server based on the client, and judge whether the server has received the first data packet, wherein the first data packet includes a key;

[0101] A first sending module 503, configured to send a second data packet of the device end to the server if the server receives the key, wherein the second data packet includes the encrypted data to be encrypted;

[0102] The second sending module 505 is used to send the second data packet of the device end to the client if the server does not receive the key, and the client decrypts the second data packet and then sends it to the server.

[0103] It should be noted that, in this embodiment, the judgment module 501 can be used to execute step S202 in the embodiment of the present application, the first sending module 503 in this embodiment can be used to execute step S204 in the embodiment of the present application, and the second sending module 505 in this embodiment can be used to execute step S206 in the embodiment of the present application.

[0104] Optionally, the device also includes: a construction module, used to construct a first transmission channel between the device side and the server and a second transmission channel between the device side and the client side with the client side as a transit platform; a key generation module, used to generate the key based on a preset encryption algorithm based on a key generation center on the device side.

[0105] Optionally, the key generation module includes: a key length determination submodule, used to determine the key length based on the data type of the data to be encrypted on the device side; a key generation submodule, used to generate the key on the device side through a symmetric encryption algorithm based on the determined key length to obtain the key.

[0106] Optionally, the judgment module 501 includes: a first sending submodule, used to extract the device information of the device end, send the device information to the client and the server, and perform device authentication on the client and the device end based on the device information; a second sending submodule, used to send the key generated by the device end to the client through the second transmission channel if the device authentication is passed, and forward the key to the server through the client; a judgment submodule, used to judge whether the server has received the key based on the feedback information of the server.

[0107] Optionally, the judgment submodule includes: an acquisition unit, used to acquire the feedback information of the server, the feedback information is determined according to the state of the server receiving the key, including first feedback information and second feedback information; a first judgment unit, used to judge that the server has not received the key if the feedback information is the first feedback information; and a second judgment unit, used to judge that the server has received the key if the feedback information is the second feedback information.

[0108] Optionally, the second sending module 505 includes: a data encryption submodule, used to encrypt the data to be encrypted based on the key on the device side to obtain the second data packet if the server has not received the key; a third sending submodule, used to send the second data packet on the device side to the client; a decryption submodule, used to decrypt the second data packet based on the key temporarily stored on the client side to obtain decrypted data, wherein the temporarily stored key is temporarily stored when the client sends it to the server; and a fourth sending submodule, used to forward the decrypted data obtained by decryption by the client to the server.

[0109] Optionally, the device also includes: a verification data sending module, which is used to send the encrypted data on the device side as verification data to the server; a verification result acquisition module, which is used to obtain a first verification result generated by the server according to the verification data, and obtain a second verification result returned by the server according to the decrypted data; a comparison module, which is used to compare the first verification result with the second verification result to determine whether the first verification result is consistent with the second verification result; a first channel control module, which is used to determine that the communication of the first transmission channel between the device side and the server is normal if the first verification result is consistent with the second verification result, and cut off the second transmission channel with the client as the forwarding node; a second channel control module, which is used to determine that the communication of the first transmission channel between the device side and the server is abnormal if the first verification result is inconsistent with the second verification result, and maintain the second transmission channel with the client as the forwarding node.

[0110] It should be noted that the examples and application scenarios implemented by the above modules and corresponding steps are the same, but are not limited to the contents disclosed in the above embodiments. It should be noted that the above modules as part of the device can be run in Figure 1 In the hardware environment shown, it can be implemented by software or by hardware.

[0111] It should be noted here that the suffixes such as module, component, unit, sub-module, and sub-unit used to represent elements described in the above device are only for the convenience of description of this application and have no specific meaning in themselves. Therefore, they can be used in combination.

[0112] According to another aspect of the embodiment of the present application, the present application provides a computer device, such as Figure 6 As shown, it includes a memory 601, a processor 603, a communication interface 605 and a communication bus 607. The memory 601 stores a computer program that can be run on the processor 603. The memory 601 and the processor 603 communicate through the communication interface 605 and the communication bus 607. When the processor 803 executes the computer program, the steps of the above-mentioned device communication method are implemented.

[0113] The memory and processor in the above-mentioned computer device communicate through a communication bus and a communication interface. The communication bus can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The communication bus can be divided into an address bus, a data bus, a control bus, etc.

[0114] The memory may include a random access memory (RAM) or a non-volatile memory, such as at least one disk memory. Optionally, the memory may also be at least one storage device located away from the aforementioned processor.

[0115] The above-mentioned processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.

[0116] According to another aspect of the embodiments of the present application, a computer program product or a computer program is provided, the computer program product or the computer program includes a computer instruction, and the computer instruction is stored in a computer-readable storage medium. A processor of a computer device reads the computer instruction from the computer-readable storage medium, and the processor executes the computer instruction, so that the computer device executes the steps of the device communication method in any of the above embodiments.

[0117] Optionally, in an embodiment of the present application, a computer-readable medium is configured to store a program code for the processor to execute the steps of the device communication method described in the above embodiment, and the device communication method includes:

[0118] Step S202, sending a first data packet generated by the device to the server based on the client, and determining whether the server has received the first data packet, wherein the first data packet includes a key;

[0119] Step S204: if the server receives the key, a second data packet of the device is sent to the server, where the second data packet includes the encrypted data to be encrypted;

[0120] Step S206: If the server does not receive the key, the second data packet on the device side is sent to the client, and the client decrypts the second data packet and sends it to the server.

[0121] Optionally, the specific examples in this embodiment can refer to the examples described in the above embodiments, and this embodiment will not be repeated here. And when the embodiments of this application are specifically implemented, they can refer to the above embodiments and have corresponding technical effects.

[0122] It is understood that the embodiments described herein may be implemented in hardware, software, firmware, middleware, microcode, or a combination thereof. For hardware implementation, the processing unit may be implemented in one or more application specific integrated circuits (ASIC), digital signal processors (DSP), digital signal processing devices (DSPD), programmable logic devices (PLD), field programmable gate arrays (FPGA), general purpose processors, controllers, microcontrollers, microprocessors, other electronic units for performing the functions described in the present application, or a combination thereof.

[0123] For software implementation, the technology described herein can be implemented by a unit that performs the functions described herein. The software code can be stored in a memory and executed by a processor. The memory can be implemented in the processor or outside the processor.

[0124] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0125] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0126] In the embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the modules is only a logical function division. There may be other division methods in actual implementation, such as multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.

[0127] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. In addition, each functional unit in each embodiment of the present application may be integrated into a processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0128] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application is essentially or the part that contributes to the prior art or the part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a ROM, a RAM, a magnetic disk, or an optical disk.

[0129] It should be noted that, in this article, relational terms such as first, second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms include, include or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "including a ..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.

[0130] The above description is only a specific implementation of the present application, so that those skilled in the art can understand or implement the present application. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to the embodiments shown herein, but will conform to the widest range consistent with the principles and novel features applied for herein.

Claims

1. A device communication method, characterized in that: The method comprises: Sending a first data packet generated by the device to the server based on the client, and determining whether the server has received the first data packet, wherein the first data packet includes a key; If the server receives the key, it sends a second data packet from the device to the server, where the second data packet includes the encrypted data to be encrypted; If the server does not receive the key, the second data packet on the device side is sent to the client, and the client decrypts the second data packet and then sends it to the server.

2. The device communication method according to claim 1, characterized in that: Before sending the first data packet generated by the device to the server based on the client, the method further includes: Establishing a first transmission channel between the device and the server and a second transmission channel between the device and the client using the client as a transfer platform; The key is generated by a key generation center based on the device end according to a preset encryption algorithm.

3. The device communication method according to claim 2, characterized in that: The device-based key generation center generates the key according to a preset encryption algorithm, including: Determine the key length based on the data type of the data to be encrypted on the device; Based on the determined key length, the key is generated on the device side through a symmetric encryption algorithm.

4. The device communication method according to claim 2, characterized in that: The first data packet also includes device information, and the step of sending the first data packet generated by the device to the server based on the client, and determining whether the server has received the first data packet includes: Extracting the device information from the device side, sending the device information to the client and the server, and performing device authentication on the client and the device side based on the device information; If the device authentication is successful, the key generated by the device is sent to the client through the second transmission channel, and the key is forwarded to the server through the client; It is determined whether the server has received the key according to the feedback information of the server.

5. The device communication method according to claim 4, characterized in that: The determining, according to feedback information from the server, whether the server has received the key comprises: Acquire the feedback information of the server, where the feedback information is determined according to a state in which the server receives the key, and includes first feedback information and second feedback information; If the feedback information is the first feedback information, determining that the server has not received the key; If the feedback information is the second feedback information, it is determined that the server has received the key.

6. The device communication method according to claim 3, characterized in that: If the server does not receive the key, the second data packet of the device is sent to the client, and the client decrypts the second data packet and sends it to the server, including: If the server does not receive the key, encrypting the data to be encrypted based on the key in the device to obtain the second data packet; Sending the second data packet on the device side to the client side; Decrypting the second data packet based on a key temporarily stored in the client to obtain decrypted data, wherein the temporarily stored key is temporarily stored when the client sends the key to the server; The decrypted data obtained by decryption on the client is forwarded to the server.

7. The device communication method according to claim 6, characterized in that: After forwarding the decrypted data obtained by decrypting the client to the server, the method further includes: Send the encrypted data on the device to the server as verification data; Obtaining a first verification result generated by the server according to the verification data, and obtaining a second verification result returned by the server according to the decrypted data; Compare the first verification result with the second verification result to determine whether the first verification result is consistent with the second verification result; If the first verification result is consistent with the second verification result, it is determined that the first transmission channel between the device and the server is communicating normally, and the second transmission channel with the client as the forwarding node is cut off; If the first verification result is inconsistent with the second verification result, it is determined that the communication of the first transmission channel between the device end and the server is abnormal, and the second transmission channel with the client as the forwarding node is maintained.

8. A device communication apparatus, characterized in that: The device comprises: A judgment module, used to send a first data packet generated by the device end to the server based on the client, and judge whether the server has received the first data packet, wherein the first data packet includes a key; A first sending module, configured to send a second data packet of the device end to the server if the server receives the key, wherein the second data packet includes the encrypted data to be encrypted; The second sending module is used to send the second data packet of the device end to the client if the server does not receive the key, and the client decrypts the second data packet and then sends it to the server.

9. A computer device, comprising a memory, a processor, a communication interface and a communication bus, wherein the memory stores a computer program that can be run on the processor, and the memory and the processor communicate through the communication bus and the communication interface, characterized in that: When the processor executes the computer program, the steps of the device communication method described in any one of claims 1 to 7 are implemented.

10. A computer readable medium having a non-volatile program code executable by a processor, characterized in that: The program code enables the processor to execute the steps of the device communication method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Method for taking smartphone as electronic key of personal computer

    CN107370598A

  • Cloud storage data safety protection method and device, storage medium, camera and computing device

    CN108777677A

  • Network connection method for cooperation of person and robot

    CN110099105A

  • Transmission method, client and transmission system

    CN112202882A

  • Communication method and device, electronic equipment and storage medium

    CN112511550A

Cited By

  • Secret key distribution method and device, medium and product

    CN121664420A