Key communication negotiation method and device based on hardware
By loading the encryption card on the client and using the encryption card to generate and manage the key, the problem of low security in key communication negotiation in the prior art is solved, and higher data transmission security is achieved.
Patent Information
- Application Number
- CN202411965358.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-30
- Publication Date
- 2025-05-13
AI Technical Summary
In the prior art, the security of key communication negotiation is low and vulnerable to attacks by third parties through software vulnerabilities, resulting in key and data leakage.
Using the hardware-based key communication negotiation method, by loading the encryption card on the client and generating and managing the keys using the encryption card, the entire key negotiation process is carried out by the encryption card through the client's communicator to ensure that the key only exists in the encryption card and avoids storage in the client's memory.
Improve the security of key communication negotiation, avoid the risk of key leakage caused by software vulnerabilities, and ensure the security of data transmission.
Smart Images

Figure CN119995846A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data communication, and in particular, to a hardware-based key communication negotiation method and device. Background Art
[0002] In the Internet age, the exchange of internal data between two parties is mostly carried out through network communication. In order to prevent data leakage, the two parties need to confirm a data encryption key before transmitting the internal data through the network communication. Both parties use the data encryption key to encrypt and decode the data.
[0003] In the prior art, keys are mostly generated by computer software, and the software is used to implement key negotiation, data encryption, and data decoding between the two parties. Key negotiation and encryption and decoding operations performed by software may be implanted with eavesdropping code by a third party through software vulnerabilities, so that the keys and data stored in the computer memory can be obtained by the third party, and data security cannot be guaranteed. Summary of the invention
[0004] In view of this, the purpose of the present application is to provide a hardware-based key communication negotiation method and device to solve the problem of low security of key communication negotiation in the prior art.
[0005] In a first aspect, an embodiment of the present application provides a hardware-based key communication negotiation method, which is applied to a data communication system, wherein the data communication system includes a first client, a first encryption card, a second client, and a second encryption card; the first encryption card is electrically connected to the first client through a first physical interface, the second encryption card is electrically connected to the second client through a second physical interface, a first communicator is provided inside the first client, the first encryption card communicates data with the second client through the first communicator, a second communicator is provided inside the second client, the second encryption card and the second communicator communicate data with the first client, and the first client and the second client communicate data by establishing a real-time transport protocol communication channel; the method includes:
[0006] The second client generates a key negotiation request in response to a confidential data transmission request issued by a user to the first client, and sends the key negotiation request to the first client;
[0007] After the first client receives the key negotiation request sent by the second client and returns a negotiation permission message corresponding to the key negotiation request to the second client, the first encryption card generates a first key negotiation data packet; the first key negotiation data packet includes an encrypted first key, and the first key is generated by the first encryption card;
[0008] The first encryption card sends a first key negotiation data packet to the second client via a first communicator in the first client;
[0009] After receiving the first key negotiation data packet through the second communicator, the second client transmits the first key negotiation data packet to the second encryption card;
[0010] The second encryption card parses the first key negotiation data packet to obtain the first key, and confirms the target key according to the first key and the second key generated by the second encryption card;
[0011] The second client transmits the confidential data selected by the user to the second encryption card;
[0012] The second encryption card encrypts the confidential data according to the target key to generate an encrypted data packet, and sends the encrypted data packet to the first client via a second communicator in the second client;
[0013] After receiving the encrypted data packet sent by the second client, the first client transmits the encrypted data packet to the first encryption card;
[0014] The first encryption card parses the encrypted data packet according to the target key to obtain the confidential data.
[0015] In some embodiments, the method further comprises:
[0016] After the second client receives the negotiation permission message returned by the first client, the second encryption card generates a second key negotiation data packet; the second key negotiation data packet includes an encrypted second key, and the second key is generated by the second encryption card;
[0017] The second encryption card sends a second key negotiation data packet to the first client via a second communicator in the second client;
[0018] After receiving the second key negotiation data packet through the first communicator, the first client transmits the second key negotiation data packet to the first encryption card;
[0019] The first encryption card parses the second key negotiation data packet to obtain the second key, and confirms the target key according to the second key and the first key generated by the first encryption card;
[0020] The first client transmits the confidential data selected by the user to the first encryption card;
[0021] The first encryption card encrypts the confidential data according to the target key to generate an encrypted data packet, and sends the encrypted data packet to the second client via the first communicator in the first client;
[0022] After receiving the encrypted data packet sent by the first client, the second client transmits the encrypted data packet to the second encryption card;
[0023] The second encryption card parses the encrypted data packet according to the target key to obtain the confidential data.
[0024] In some embodiments, after the first client receives the second key negotiation data packet through the first communicator and transmits the second key negotiation data packet to the first encryption card, the method further includes:
[0025] The first encryption card checks whether the second key negotiation data packet is complete;
[0026] If the second key negotiation data packet is complete, the first encryption card generates a first confirmation receipt message and sends it to the second client via the first client;
[0027] After the second client receives the first key negotiation data packet through the second communicator and transmits the first key negotiation data packet to the second encryption card, the method further includes:
[0028] The second encryption card checks whether the first key negotiation data packet is complete;
[0029] If the first key negotiation data packet is complete, the second encryption card generates a second confirmation receipt message and sends it to the first client via the second client.
[0030] In some embodiments, the second encryption card parses the first key negotiation data packet to obtain the first key, and confirms the target key according to the first key and the second key generated by the second encryption card, including:
[0031] The second encryption card compares the first key and the second key to see whether they are the same;
[0032] If the first key and the second key are the same, the second encryption card confirms the second key as the target key;
[0033] If the first key and the second key are different, the second encryption card generates a third key according to the first key and the second key, and confirms the third key as the target key.
[0034] In some embodiments, the first encryption card parses the second key negotiation data packet to obtain the second key, and confirms the target key according to the second key and the first key, including:
[0035] The first encryption card compares the first key and the second key to see whether they are the same;
[0036] If the first key and the second key are the same, the first encryption card confirms the first key as the target key;
[0037] If the first key and the second key are different, the first encryption card generates a third key according to the first key and the second key, and confirms the third key as the target key.
[0038] In some embodiments, after the first encryption card parses the second key negotiation data packet to obtain the second key, and confirms the target key according to the second key and the first key, the method further includes:
[0039] The first encryption card generates a first negotiation confirmation message and sends it to the second client through the first client;
[0040] After receiving the first negotiation confirmation message, the second client confirms that the key negotiation using the target key as the communication key is successful;
[0041] After the second encryption card parses the first key negotiation data packet to obtain the first key, and confirms the target key according to the first key and the second key generated by the second encryption card, the method further includes:
[0042] The second encryption card generates a second negotiation confirmation message and sends it to the first client via the second client;
[0043] After receiving the second negotiation confirmation message, the first client confirms that the key negotiation using the target key as the communication key is successful.
[0044] In a second aspect, the embodiment of the present application further provides a hardware-based key communication negotiation device, which is applied to a data communication system, wherein the data communication system includes a first client, a first encryption card, a second client, and a second encryption card; the first encryption card is electrically connected to the first client through a first physical interface, the second encryption card is electrically connected to the second client through a second physical interface, a first communicator is provided inside the first client, the first encryption card communicates data with the second client through the first communicator, a second communicator is provided inside the second client, the second encryption card and the second communicator communicate data with the first client, and the first client and the second client communicate data by establishing a real-time transport protocol communication channel; the device includes:
[0045] A request module, configured for the second client to generate a key negotiation request in response to a confidential data transmission request issued by a user to the first client, and to send the key negotiation request to the first client;
[0046] A first key module, configured for the first encryption card to generate a first key negotiation data packet after the first client receives the key negotiation request sent by the second client and returns a negotiation permission message corresponding to the key negotiation request to the second client; the first key negotiation data packet includes an encrypted first key, and the first key is generated by the first encryption card;
[0047] A first sending module, used for the first encryption card to send a first key negotiation data packet to the second client via a first communicator in the first client;
[0048] A first transmission module, configured to transmit the first key negotiation data packet to the second encryption card after the second client receives the first key negotiation data packet through the second communicator;
[0049] A first confirmation module, configured for the second encryption card to parse the first key negotiation data packet, obtain the first key, and confirm a target key according to the first key and a second key generated by the second encryption card;
[0050] A second transmission module, used for the second client to transmit the confidential data selected by the user to the second encryption card;
[0051] a first encryption module, used for the second encryption card to encrypt the confidential data according to the target key, generate an encrypted data packet, and send the encrypted data packet to the first client via the second communicator in the second client;
[0052] A third transmission module, configured to transmit the encrypted data packet to the first encryption card after the first client receives the encrypted data packet sent by the second client;
[0053] The first parsing module is used for the first encryption card to parse the encrypted data packet according to the target key to obtain the confidential data.
[0054] In some embodiments, the first confirmation module includes:
[0055] The first comparison module is used for the second encryption card to compare whether the first key and the second key are the same; if the first key and the second key are the same, the second encryption card confirms the second key as the target key; if the first key and the second key are different, the second encryption card generates a third key based on the first key and the second key, and confirms the third key as the target key.
[0056] An embodiment of the present application also provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the method described in any one of the above-mentioned first aspect and its embodiments when executing the computer program.
[0057] An embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the method described in any one of the above-mentioned first aspect and its embodiments are executed.
[0058] The embodiment of the present application proposes a hardware-based key communication negotiation method, which generates keys and encrypts and decodes data by loading encryption cards for the first client and the second client. The entire key negotiation process is performed by the encryption card through the client's communicator. The target key obtained after the negotiation only exists in the encryption card, and there is no target key in the client's memory. The embodiment of the present application proposes a hardware-based key communication negotiation method, which generates, negotiates, stores keys, and encrypts and decodes data by using encryption cards, avoids key leakage caused by software vulnerabilities, and improves the security of key communication negotiation.
[0059] In order to make the above-mentioned objects, features and advantages of the present application more obvious and easy to understand, preferred embodiments are specifically cited below and described in detail with reference to the attached drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0060] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.
[0061] Figure 1 A schematic diagram of the structure of a data communication system provided in an embodiment of the present application;
[0062] Figure 2 A flowchart of a hardware-based key communication negotiation method provided in an embodiment of the present application;
[0063] Figure 3 A schematic diagram of the structure of a hardware-based key communication negotiation device provided in an embodiment of the present application;
[0064] Figure 4 A schematic diagram of the structure of a computer device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0065] To make the purpose, technical scheme and advantages of the embodiments of the present application clearer, the technical scheme in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all of the embodiments. The components of the embodiments of the present application generally described and shown in the drawings here can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the application claimed for protection, but merely represents the selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without making creative work belong to the scope of protection of the present application.
[0066] The present application embodiment provides a hardware-based key communication negotiation method, which is applied to a data communication system, such as Figure 1 As shown, the data communication system includes a first client, a first encryption card, a second client, and a second encryption card; the first encryption card is electrically connected to the first client through a first physical interface, the second encryption card is electrically connected to the second client through a second physical interface, a first communicator is provided inside the first client, the first encryption card communicates data with the second client through the first communicator, a second communicator is provided inside the second client, the second encryption card communicates data with the first client, and the first client and the second client communicate data by establishing a real-time transport protocol communication channel; as Figure 2 As shown, the method comprises the following steps:
[0067] Step S201: The second client generates a key negotiation request in response to a confidential data transmission request issued by a user to the first client, and sends the key negotiation request to the first client;
[0068] Step S202: After the first client receives the key negotiation request sent by the second client and returns a negotiation permission message corresponding to the key negotiation request to the second client, the first encryption card generates a first key negotiation data packet; the first key negotiation data packet includes an encrypted first key, and the first key is generated by the first encryption card;
[0069] Step S203: the first encryption card sends a first key negotiation data packet to the second client via the first communicator in the first client;
[0070] Step S204: After receiving the first key negotiation data packet through the second communicator, the second client transmits the first key negotiation data packet to the second encryption card;
[0071] Step S205: The second encryption card parses the first key negotiation data packet to obtain the first key, and confirms the target key according to the first key and the second key generated by the second encryption card;
[0072] Step S206: The second client transmits the confidential data selected by the user to the second encryption card;
[0073] Step S207: The second encryption card encrypts the confidential data according to the target key to generate an encrypted data packet, and transmits the encrypted data packet to the first client via the second communicator in the second client;
[0074] Step S208: After receiving the encrypted data packet sent by the second client, the first client transmits the encrypted data packet to the first encryption card;
[0075] Step S209: The first encryption card parses the encrypted data packet according to the target key to obtain confidential data.
[0076] Specifically, the encryption card is a piece of hardware that can be electrically connected to the client through a communication interface. The function of the encryption card is to derive keys through random numbers, generate key negotiation data packets, and parse the key negotiation data packets received by the client to obtain the negotiation key of the other end; it also encrypts data sent by the client to another designated client, and decodes encrypted data sent by another client.
[0077] The user generates a key negotiation request by clicking or inputting the IP address of the first client with which confidential data communication is desired on the second client, and the second client sends the key negotiation request to the first client via the second communicator installed on itself.
[0078] After receiving the key negotiation request, the first client confirms that the IP address of the second client is the IP address of the partner, and then generates a negotiation permission message and sends it to the second client, and starts the key communication negotiation between the first client and the second client.
[0079] The first client sends a key negotiation start instruction to the first encryption card, the first encryption card obtains a random number and derives a first key; the first encryption card encapsulates the first key and related data in a first key negotiation data packet, and transmits it to the first communicator in the first client to send it to the second client.
[0080] After receiving the first key negotiation data packet, the second communicator in the second client directly transmits the first key negotiation data packet to the second encryption card; the second encryption card parses the first key negotiation data packet to obtain the first key, and jointly determines the target key with the second key generated by the second encryption card itself to serve as the encryption key for data transmission between the first client and the second client.
[0081] In the subsequent data transmission between the first client and the second client, the data must first be transmitted to the connected encryption card for encryption and then sent through its own communicator; after receiving the encrypted data sent by the other end, the encrypted data must also be transmitted to the connected encryption card for decoding, and the encryption card then transmits the decoded data to the client.
[0082] A hardware-based key communication negotiation method is provided in an embodiment of the present application. Since the key is not stored in the client's memory during the key communication negotiation process, and all subsequent key-related operations are performed on the encryption card, the risk of key leakage due to the client performing key negotiation through software is avoided, thereby improving the security of the key communication negotiation.
[0083] In an optional embodiment, the method further comprises:
[0084] Step 301: After the second client receives the negotiation permission message returned by the first client, the second encryption card generates a second key negotiation data packet; the second key negotiation data packet includes an encrypted second key, and the second key is generated by the second encryption card;
[0085] Step 302: The second encryption card sends a second key negotiation data packet to the first client via a second communicator in the second client;
[0086] Step 303: After receiving the second key negotiation data packet through the first communicator, the first client transmits the second key negotiation data packet to the first encryption card;
[0087] Step 304: The first encryption card parses the second key negotiation data packet to obtain the second key, and confirms the target key according to the second key and the first key generated by the first encryption card;
[0088] Step 305: The first client transmits the confidential data selected by the user to the first encryption card;
[0089] Step 306: The first encryption card encrypts the confidential data according to the target key to generate an encrypted data packet, and sends the encrypted data packet to the second client via the first communicator in the first client;
[0090] Step 307: After receiving the encrypted data packet sent by the first client, the second client transmits the encrypted data packet to the second encryption card;
[0091] Step 308: The second encryption card parses the encrypted data packet according to the target key to obtain confidential data.
[0092] Specifically, after the second client receives the negotiation permission message of the first client in response to the key negotiation request, the second client also performs the same key negotiation process as the first client. The target keys finally obtained by the first client and the second client are the same.
[0093] In an optional embodiment, after the first client receives the second key negotiation data packet through the first communicator and transmits the second key negotiation data packet to the first encryption card, the method further includes:
[0094] Step 401: The first encryption card checks whether the second key negotiation data packet is complete;
[0095] Step 402: If the second key negotiation data packet is complete, the first encryption card generates a first confirmation reception message and sends it to the second client via the first client;
[0096] After the second client receives the first key negotiation data packet through the second communicator and transmits the first key negotiation data packet to the second encryption card, the method further includes:
[0097] Step 403: The second encryption card checks whether the first key negotiation data packet is complete;
[0098] Step 404: If the first key negotiation data packet is complete, the second encryption card generates a second confirmation receipt message and sends it to the first client via the second client.
[0099] Specifically, after the encryption card receives the key negotiation data packet, it needs to first check the integrity of the key negotiation data packet. If the key negotiation data packet is found to be damaged, a data packet damage message is immediately sent to the other end through the communicator to enable the other end to resend the key negotiation data packet.
[0100] When the encryption card confirms that the key negotiation data packet sent by the peer end is complete, it generates a confirmation reception message and sends it to the peer end through the communicator in the connected client to inform the peer end that the key negotiation data packet has been confirmed.
[0101] This is to ensure that the target key finally confirmed by the first encryption card and the second encryption card is the same.
[0102] In an optional embodiment, the second encryption card parses the first key negotiation data packet to obtain the first key, and confirms the target key according to the first key and the second key generated by the second encryption card, including:
[0103] Step 501: The second encryption card compares the first key and the second key to see if they are the same;
[0104] Step 502: If the first key and the second key are the same, the second encryption card confirms the second key as the target key;
[0105] Step 503: If the first key and the second key are different, the second encryption card generates a third key according to the first key and the second key, and confirms the third key as the target key.
[0106] In an optional embodiment, the first encryption card parses the second key negotiation data packet to obtain the second key, and confirms the target key according to the second key and the first key, including:
[0107] Step 601: The first encryption card compares the first key and the second key to see if they are the same;
[0108] Step 602: If the first key and the second key are the same, the first encryption card confirms the first key as the target key;
[0109] Step 603: If the first key and the second key are different, the first encryption card generates a third key according to the first key and the second key, and confirms the third key as the target key.
[0110] Specifically, since the random numbers used by the first encryption card and the second encryption card when generating keys may be the same or different, the target key needs to be confirmed after comparing the first key with the second key.
[0111] When the first key and the second key are the same, either the first key or the second key can be selected as the target key.
[0112] When the first key and the second key are different, it is necessary to calculate the target key according to the first key and the second key through the processing algorithm preset in the encryption card. The processing algorithms used by the first encryption card and the second encryption card can be the same algorithm preset in advance, or can be confirmed through negotiation during the key negotiation process.
[0113] In an optional embodiment, after the first encryption card parses the second key negotiation data packet to obtain the second key and confirms the target key based on the second key and the first key, the method further includes:
[0114] Step 701: The first encryption card generates a first negotiation confirmation message and sends it to the second client via the first client;
[0115] Step 702: After receiving the first negotiation confirmation message, the second client confirms that the key negotiation using the target key as the communication key is successful;
[0116] After the second encryption card parses the first key negotiation data packet to obtain the first key, and confirms the target key according to the first key and the second key generated by the second encryption card, the method further includes:
[0117] Step 703: The second encryption card generates a second negotiation confirmation message and sends it to the first client via the second client;
[0118] Step 704: After receiving the second negotiation confirmation message, the first client confirms that the key negotiation using the target key as the communication key is successful.
[0119] Specifically, unlike the key communication negotiation performed by the software in the client, the key communication negotiation performed by the encryption card, after the first encryption card and the second encryption card confirm the target key, the first encryption card and the second encryption card send a negotiation confirmation message to the other end through the communicator in the client connected to themselves. When the client receives the negotiation confirmation message, it confirms that the key communication negotiation is successful, and then starts the communication and transmission of confidential data with the other end.
[0120] The embodiment of the present application also provides a hardware-based key communication negotiation device, characterized in that it is applied to a data communication system, the data communication system includes a first client, a first encryption card, a second client, and a second encryption card; the first encryption card is electrically connected to the first client through a first physical interface, the second encryption card is electrically connected to the second client through a second physical interface, a first communicator is provided inside the first client, the first encryption card communicates data with the second client through the first communicator, a second communicator is provided inside the second client, the second encryption card and the second communicator communicate data with the first client, and the first client and the second client communicate data by establishing a real-time transport protocol communication channel; Figure 3 As shown, the device comprises:
[0121] A request module 81, configured for the second client to generate a key negotiation request in response to a confidential data transmission request issued by a user to the first client, and to send the key negotiation request to the first client;
[0122] The first key module 82 is used for the first encryption card to generate a first key negotiation data packet after the first client receives the key negotiation request sent by the second client and returns a negotiation permission message corresponding to the key negotiation request to the second client; the first key negotiation data packet includes the encrypted first key, and the first key is generated by the first encryption card;
[0123] A first sending module 83, configured for the first encryption card to send a first key negotiation data packet to the second client via the first communicator in the first client;
[0124] A first transmission module 84, configured to transmit the first key negotiation data packet to the second encryption card after the second client receives the first key negotiation data packet through the second communicator;
[0125] A first confirmation module 85 is used for the second encryption card to parse the first key negotiation data packet to obtain the first key, and confirm the target key according to the first key and the second key generated by the second encryption card;
[0126] The second transmission module 86 is used for the second client to transmit the confidential data selected by the user to the second encryption card;
[0127] The first encryption module 87 is used for the second encryption card to encrypt the confidential data according to the target key, generate an encrypted data packet, and transmit the encrypted data packet to the first client through the second communicator in the second client;
[0128] The third transmission module 88 is used for transmitting the encrypted data packet to the first encryption card after the first client receives the encrypted data packet sent by the second client;
[0129] The first parsing module 89 is used for the first encryption card to parse the encrypted data packet according to the target key to obtain confidential data.
[0130] In an optional embodiment, the first confirmation module includes:
[0131] The first comparison module 851 is used for the second encryption card to compare whether the first key and the second key are the same; if the first key and the second key are the same, the second encryption card confirms the second key as the target key; if the first key and the second key are different, the second encryption card generates a third key based on the first key and the second key, and confirms the third key as the target key.
[0132] Corresponds to Figure 2 A hardware-based key communication negotiation method, the present application embodiment also provides a computer device 900, such as Figure 4 As shown, the device includes a memory 901, a processor 902, and a computer program stored in the memory 901 and executable on the processor 902, wherein the processor 902 implements the hardware-based key communication negotiation method when executing the computer program.
[0133] Specifically, the above-mentioned memory 901 and processor 902 can be general-purpose memory and processor, which are not specifically limited here. When the processor 902 runs the computer program stored in the memory 901, it can execute the above-mentioned hardware-based key communication negotiation method, which solves the problem of low security of key communication negotiation in the prior art.
[0134] Corresponds to Figure 2 A hardware-based key communication negotiation method in the present application, an embodiment of the present application also provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the above-mentioned hardware-based key communication negotiation method are executed.
[0135] Specifically, the storage medium can be a general storage medium, such as a mobile disk, a hard disk, etc. When the computer program on the storage medium is run, it can execute the above-mentioned hardware-based key communication negotiation method, which solves the problem of low security of key communication negotiation in the prior art. The hardware-based key communication negotiation method proposed in the embodiment of the present application loads an encryption card for the first client and the second client, and uses the encryption card to generate keys and encrypt and decode data. The entire key negotiation process is performed by the encryption card through the client's communicator. The target key obtained after the negotiation only exists in the encryption card, and there is no target key in the client's memory. The hardware-based key communication negotiation method proposed in the embodiment of the present application generates, negotiates, stores, and encrypts and decodes data through an encryption card, which avoids key leakage caused by software vulnerabilities and improves the security of key communication negotiation.
[0136] In the embodiments provided in the present application, it should be understood that the disclosed methods and devices can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some communication interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0137] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0138] In addition, each functional unit in the embodiments provided in the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0139] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0140] It should be noted that similar numbers and letters represent similar items in the following figures. Therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. In addition, the terms "first", "second", "third", etc. are only used to distinguish the description and are not to be understood as indicating or implying relative importance.
[0141] Finally, it should be noted that the above-described embodiments are only specific implementation methods of the present application, which are used to illustrate the technical solutions of the present application, rather than to limit them. The protection scope of the present application is not limited thereto. Although the present application is described in detail with reference to the above-mentioned embodiments, ordinary technicians in the field should understand that any technician familiar with the technical field can still modify the technical solutions recorded in the above-mentioned embodiments within the technical scope disclosed in the present application, or can easily think of changes, or make equivalent replacements for some of the technical features therein; and these modifications, changes or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application. They should all be included in the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims.
Claims
1. A hardware-based key communication negotiation method, characterized in that: The invention is applied to a data communication system, wherein the data communication system comprises a first client, a first encryption card, a second client and a second encryption card; the first encryption card is electrically connected to the first client via a first physical interface, the second encryption card is electrically connected to the second client via a second physical interface, a first communicator is arranged inside the first client, the first encryption card performs data communication with the second client via the first communicator, a second communicator is arranged inside the second client, the second encryption card performs data communication with the first client, and the first client and the second client perform data communication by establishing a real-time transport protocol communication channel; the method comprises: The second client generates a key negotiation request in response to a confidential data transmission request issued by a user to the first client, and sends the key negotiation request to the first client; After the first client receives the key negotiation request sent by the second client and returns a negotiation permission message corresponding to the key negotiation request to the second client, the first encryption card generates a first key negotiation data packet; the first key negotiation data packet includes an encrypted first key, and the first key is generated by the first encryption card; The first encryption card sends a first key negotiation data packet to the second client via a first communicator in the first client; After receiving the first key negotiation data packet through the second communicator, the second client transmits the first key negotiation data packet to the second encryption card; The second encryption card parses the first key negotiation data packet to obtain the first key, and confirms the target key according to the first key and the second key generated by the second encryption card; The second client transmits the confidential data selected by the user to the second encryption card; The second encryption card encrypts the confidential data according to the target key to generate an encrypted data packet, and sends the encrypted data packet to the first client via a second communicator in the second client; After receiving the encrypted data packet sent by the second client, the first client transmits the encrypted data packet to the first encryption card; The first encryption card parses the encrypted data packet according to the target key to obtain the confidential data.
2. The method according to claim 1, characterized in that The method further includes: After the second client receives the negotiation permission message returned by the first client, the second encryption card generates a second key negotiation data packet; the second key negotiation data packet includes an encrypted second key, and the second key is generated by the second encryption card; The second encryption card sends a second key negotiation data packet to the first client via a second communicator in the second client; After receiving the second key negotiation data packet through the first communicator, the first client transmits the second key negotiation data packet to the first encryption card; The first encryption card parses the second key negotiation data packet to obtain the second key, and confirms the target key according to the second key and the first key generated by the first encryption card; The first client transmits the confidential data selected by the user to the first encryption card; The first encryption card encrypts the confidential data according to the target key to generate an encrypted data packet, and sends the encrypted data packet to the second client via the first communicator in the first client; After receiving the encrypted data packet sent by the first client, the second client transmits the encrypted data packet to the second encryption card; The second encryption card parses the encrypted data packet according to the target key to obtain the confidential data.
3. The method according to claim 2, characterized in that After the first client receives the second key negotiation data packet through the first communicator and transmits the second key negotiation data packet to the first encryption card, the method further includes: The first encryption card checks whether the second key negotiation data packet is complete; If the second key negotiation data packet is complete, the first encryption card generates a first confirmation receipt message and sends it to the second client via the first client; After the second client receives the first key negotiation data packet through the second communicator and transmits the first key negotiation data packet to the second encryption card, the method further includes: The second encryption card checks whether the first key negotiation data packet is complete; If the first key negotiation data packet is complete, the second encryption card generates a second confirmation receipt message and sends it to the first client via the second client.
4. The method according to claim 1, characterized in that: The second encryption card parses the first key negotiation data packet to obtain the first key, and confirms the target key according to the first key and the second key generated by the second encryption card, including: The second encryption card compares the first key and the second key to see whether they are the same; If the first key and the second key are the same, the second encryption card confirms the second key as the target key; If the first key and the second key are different, the second encryption card generates a third key according to the first key and the second key, and confirms the third key as the target key.
5. The method according to claim 2, characterized in that: The first encryption card parses the second key negotiation data packet to obtain the second key, and confirms the target key according to the second key and the first key, including: The first encryption card compares the first key and the second key to see whether they are the same; If the first key and the second key are the same, the first encryption card confirms the first key as the target key; If the first key and the second key are different, the first encryption card generates a third key according to the first key and the second key, and confirms the third key as the target key.
6. The method according to claim 2, characterized in that After the first encryption card parses the second key negotiation data packet to obtain the second key, and confirms the target key according to the second key and the first key, the method further includes: The first encryption card generates a first negotiation confirmation message and sends it to the second client through the first client; After receiving the first negotiation confirmation message, the second client confirms that the key negotiation using the target key as the communication key is successful; After the second encryption card parses the first key negotiation data packet to obtain the first key, and confirms the target key according to the first key and the second key generated by the second encryption card, the method further includes: The second encryption card generates a second negotiation confirmation message and sends it to the first client via the second client; After receiving the second negotiation confirmation message, the first client confirms that the key negotiation using the target key as the communication key is successful.
7. A hardware-based key communication negotiation device, characterized in that: Applied to a data communication system, the data communication system includes a first client, a first encryption card, a second client and a second encryption card; the first encryption card is electrically connected to the first client through a first physical interface, the second encryption card is electrically connected to the second client through a second physical interface, a first communicator is provided inside the first client, the first encryption card performs data communication with the second client through the first communicator, a second communicator is provided inside the second client, the second encryption card performs data communication with the first client, and the first client and the second client perform data communication by establishing a real-time transport protocol communication channel; the device includes: A request module, configured for the second client to generate a key negotiation request in response to a confidential data transmission request issued by a user to the first client, and to send the key negotiation request to the first client; A first key module, configured for the first encryption card to generate a first key negotiation data packet after the first client receives the key negotiation request sent by the second client and returns a negotiation permission message corresponding to the key negotiation request to the second client; the first key negotiation data packet includes an encrypted first key, and the first key is generated by the first encryption card; A first sending module, used for the first encryption card to send a first key negotiation data packet to the second client via a first communicator in the first client; A first transmission module, configured to transmit the first key negotiation data packet to the second encryption card after the second client receives the first key negotiation data packet through the second communicator; A first confirmation module, configured for the second encryption card to parse the first key negotiation data packet, obtain the first key, and confirm a target key according to the first key and a second key generated by the second encryption card; A second transmission module, used for the second client to transmit the confidential data selected by the user to the second encryption card; a first encryption module, used for the second encryption card to encrypt the confidential data according to the target key, generate an encrypted data packet, and send the encrypted data packet to the first client via the second communicator in the second client; A third transmission module, configured to transmit the encrypted data packet to the first encryption card after the first client receives the encrypted data packet sent by the second client; The first parsing module is used for the first encryption card to parse the encrypted data packet according to the target key to obtain the confidential data.
8. The device according to claim 7, characterized in that The first confirmation module includes: The first comparison module is used for the second encryption card to compare whether the first key and the second key are the same; if the first key and the second key are the same, the second encryption card confirms the second key as the target key; if the first key and the second key are different, the second encryption card generates a third key based on the first key and the second key, and confirms the third key as the target key.
9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are performed.