Cross-domain fusion data transmission and storage method and electronic device
By employing a cross-domain converged data transmission and storage method, and utilizing the generation and verification of dynamic transmission key pairs and asymmetric key pairs, the security issues in sensitive data transmission are resolved, achieving high security for data transmission and storage.
Patent Information
- Application Number
- CN202510083523.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-20
- Publication Date
- 2025-10-21
- Estimated Expiration
- 2045-01-20
AI Technical Summary
Existing technologies lack authentication mechanisms and use a single encryption method when transmitting sensitive data, resulting in a high risk of data leakage.
A cross-domain converged data transmission and storage method is adopted, which uses dynamic transmission key pair generation and verification between the client and the server, combined with asymmetric key pair for encryption and decryption, to ensure the security of data transmission.
It improves the security of data transmission and storage, prevents data leakage, and makes it difficult to crack encrypted data even if the client's private key is leaked.
Smart Images

Figure CN119995958B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present disclosure relate to the field of computers, and in particular to a cross-domain integrated data transmission and storage method and an electronic device. Background Art
[0002] Currently, when transferring sensitive data (internal confidential files) between two data centers, the typical approach is to encrypt the data before transmitting it to enhance data security. However, this data transmission method often presents the following technical issues: It lacks authentication for data transmission and employs a relatively simple encryption method, making it prone to data leaks.
[0003] The above information disclosed in this Background section is only for enhancement of understanding of the background of the inventive concept and therefore it may contain information that does not form the prior art that is already known in this country to a person of ordinary skill in the art. Summary of the Invention
[0004] The content of this disclosure is used to briefly introduce concepts that will be described in detail in the detailed description section below. The content of this disclosure is not intended to identify key features or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.
[0005] Some embodiments of the present disclosure propose a cross-domain integrated data transmission and storage method, an electronic device, and a computer-readable medium to solve one or more of the technical problems mentioned in the above background technology section.
[0006] In the first aspect, some embodiments of the present disclosure provide a cross-domain integrated data transmission and storage method, which is applied to a cross-domain integrated data transmission and storage system. The above-mentioned cross-domain integrated data transmission and storage system includes: a server and a client. The method includes: the client initiates a transmission channel establishment request to the above-mentioned server to establish a data transmission channel; the above-mentioned server requests a dynamic transmission key pair from a trusted password card through a data transmission module, and sends the dynamic transmission public key in the above-mentioned dynamic transmission key pair to the above-mentioned client through the above-mentioned data transmission channel; the above-mentioned client generates an asymmetric key pair in response to receiving the dynamic transmission public key sent by the server according to the client identifier, and sends the data transmission public key in the above-mentioned asymmetric key pair and the received dynamic transmission public key to the above-mentioned server; the above-mentioned server responds to receiving the data transmission public key and the dynamic transmission public key, based on The dynamic transmission public key is verified according to the local dynamic transmission key pair to obtain the dynamic transmission public key verification result; the above-mentioned server generates data transmittable information in response to determining that the above-mentioned dynamic transmission public key verification result represents that the verification is passed, and encrypts the above-mentioned data transmittable information according to the above-mentioned data transmission public key to obtain encrypted data transmittable information, and sends the above-mentioned encrypted data transmittable information to the above-mentioned client; the above-mentioned client responds to receiving the encrypted data transmittable information sent by the server, decrypts the above-mentioned encrypted data transmittable information according to the local asymmetric key pair to obtain decrypted transmission information; the above-mentioned client responds to determining that the above-mentioned decrypted transmission information represents transmittable information, encrypts the data to be stored according to the private key in the local asymmetric key pair, obtains encrypted storage data, and sends the encrypted storage data to the above-mentioned server.
[0007] In a second aspect, some embodiments of the present disclosure provide an electronic device comprising: one or more processors; a storage device on which one or more programs are stored, and when the one or more programs are executed by one or more processors, the one or more processors implement the method described in any implementation of the above-mentioned first aspect.
[0008] In a third aspect, some embodiments of the present disclosure provide a computer-readable medium having a computer program stored thereon, wherein when the program is executed by a processor, the method described in any implementation of the first aspect is implemented.
[0009] The above-described embodiments of the present disclosure have the following beneficial effects: The cross-domain converged data transmission and storage methods of some embodiments of the present disclosure enhance the security of data transmission between data terminals. First, the client initiates a transmission channel establishment request to the server to establish a data transmission channel. This facilitates the establishment of the data communication channel and prevents data transmission failures. Second, the server, through the data transmission module, requests a dynamic transmission key pair from a trusted cryptographic card and sends the dynamic transmission public key from the dynamic transmission key pair to the client via the data transmission channel. This facilitates communication security confirmation with the client using the dynamic transmission key pair. Next, in response to receiving the dynamic transmission public key from the server, the client generates an asymmetric key pair based on the client identifier and sends the data transmission public key from the asymmetric key pair and the received dynamic transmission public key to the server. Third, in response to receiving the data transmission public key and the dynamic transmission public key, the server verifies the dynamic transmission public key using its local dynamic transmission key pair, obtaining a dynamic transmission public key verification result. This allows verification of the exchanged public keys to determine whether the client is receiving data properly. Afterwards, the server, in response to determining that the dynamic transmission public key verification result indicates verification has passed, generates data transmittable information, encrypts the data transmittable information based on the data transmission public key, obtains encrypted data transmittable information, and sends the encrypted data transmittable information to the client. This notifies the client that data transmission is possible and encrypts the data using the key generated by the server. Then, in response to receiving the encrypted data transmittable information sent by the server, the client decrypts the encrypted data transmittable information using a local asymmetric key pair to obtain decrypted transmission information. Finally, in response to determining that the decrypted transmission information indicates transmittable information, the client encrypts the data to be stored using the private key in the local asymmetric key pair to obtain encrypted storage data, and sends the encrypted storage data to the server. Here, since the key is generated by the server and the private key is on the server, the client is unaware of it. Even if the client leaks data during transmission, without the private key, it is difficult to decrypt the leaked encrypted data. Therefore, the security of data transmission between data terminals is improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0010] The above and other features, advantages, and aspects of the various embodiments of the present disclosure will become more apparent with reference to the following detailed description in conjunction with the accompanying drawings. Throughout the drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic and that components and elements are not necessarily drawn to scale.
[0011] Figure 1 is a flowchart of some embodiments of the cross-domain integrated data transmission and storage method according to the present disclosure;
[0012] Figure 2 It is a structural diagram of an electronic device suitable for implementing some embodiments of the present disclosure. DETAILED DESCRIPTION
[0013] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as being limited to the embodiments described herein. On the contrary, these embodiments are provided to provide a more thorough and complete understanding of the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are for illustrative purposes only and are not intended to limit the scope of protection of the present disclosure.
[0014] It should also be noted that, for ease of description, only the parts related to the invention are shown in the drawings. In the absence of conflict, the embodiments and features in the embodiments of the present disclosure may be combined with each other.
[0015] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.
[0016] It should be noted that the modifications of "one" and "multiple" mentioned in the present disclosure are illustrative rather than restrictive, and those skilled in the art should understand that unless otherwise clearly indicated in the context, they should be understood as "one or more".
[0017] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only used for illustrative purposes and are not used to limit the scope of these messages or information.
[0018] The present disclosure will be described in detail below with reference to the accompanying drawings and in conjunction with embodiments.
[0019] Figure 1 This is a flowchart of some embodiments of the cross-domain converged data transmission and storage method according to the present disclosure. It shows a process 100 of some embodiments of the cross-domain converged data transmission and storage method according to the present disclosure. The cross-domain converged data transmission and storage method is applied to a cross-domain converged data transmission and storage system. The cross-domain converged data transmission and storage system includes: a server and a client, and includes the following steps:
[0020] Step 101: The client initiates a transmission channel establishment request to the server to establish a data transmission channel.
[0021] In some embodiments, the client initiates a transmission channel establishment request to the server to establish a data transmission channel. Specifically, the client may be a VPN-C client. The server may be a VPN-S server. The transmission channel establishment request may be a request to establish a VPN channel. The data transmission channel may be a VPN channel. The method for establishing the VPN channel is not specifically limited.
[0022] In step 102, the server requests a dynamic transmission key pair from the trusted password card through the data transmission module, and sends the dynamic transmission public key in the dynamic transmission key pair to the client through the data transmission channel.
[0023] In some embodiments, the above-mentioned server requests a dynamic transmission key pair from the trusted password card through the data transmission module, and sends the dynamic transmission public key in the above-mentioned dynamic transmission key pair to the above-mentioned client through the above-mentioned data transmission channel. The trusted password card may refer to a TCM card, which is a security chip that can effectively protect the PC and prevent illegal users from accessing the computer. That is, the trusted password card is set in the server. The data transmission module is an Internet of Things wireless data terminal set in the server, which is specially used to convert serial port data into IP data or convert IP data into serial port data, and transmit it through a wireless communication network. The dynamic transmission key pair can be a key pair generated by the trusted password card for transmitting information. The dynamic transmission key pair can include a private key and a public key.
[0024] In step 103, the client generates an asymmetric key pair based on the client identifier in response to receiving the dynamic transmission public key sent by the server, and sends the data transmission public key in the asymmetric key pair and the received dynamic transmission public key to the server.
[0025] In some embodiments, the client generates an asymmetric key pair in response to receiving the dynamic transmission public key sent by the server according to the client identifier, and sends the data transmission public key and the received dynamic transmission public key in the asymmetric key pair to the server. The client identifier may refer to the identifier of the client. An asymmetric key pair with the client identifier as characters may be generated by a key generation algorithm (RSA, ECC). For example, the client characters may be converted into Roman numerals (encoded as Roman numerals), and then the Roman data may be keyed by a key generation algorithm. The asymmetric key pair includes: a data transmission public key and a private key.
[0026] In step 104 , in response to receiving the data transmission public key and the dynamic transmission public key, the server verifies the dynamic transmission public key according to the local dynamic transmission key pair to obtain a dynamic transmission public key verification result.
[0027] In some embodiments, in response to receiving the data transmission public key and the dynamic transmission public key, the server verifies the dynamic transmission public key based on a local dynamic transmission key pair, and obtains a dynamic transmission public key verification result. Specifically, the server verifies whether the dynamic transmission public key is the public key in the dynamic transmission key pair. If they are consistent, a dynamic transmission public key verification result is generated, indicating that the verification has passed; if they are inconsistent, a dynamic transmission public key verification result is generated, indicating that the verification has failed.
[0028] In step 105, the server generates data transmittable information in response to determining that the dynamic transmission public key verification result indicates that the verification has passed, and encrypts the data transmittable information according to the data transmission public key to obtain encrypted data transmittable information, and sends the encrypted data transmittable information to the client.
[0029] In some embodiments, the server generates data transmittable information in response to determining that the dynamic transmission public key verification result indicates that the verification has passed, encrypts the data transmittable information based on the data transmission public key to obtain encrypted data transmittable information, and sends the encrypted data transmittable information to the client. The data transmittable information indicates that the client can transmit information. The encryption method can be encryption using an encryption algorithm such as DES, 3DES, or AES.
[0030] Step 106 , in response to receiving the encrypted data transmittable information sent by the server, the client decrypts the encrypted data transmittable information according to the local asymmetric key pair to obtain decrypted transmission information.
[0031] In some embodiments, in response to receiving the encrypted data transmittable information sent by the server, the client decrypts the encrypted data transmittable information using a local asymmetric key pair to obtain decrypted transmission information. That is, the encrypted data transmittable information is decrypted using the private key in the asymmetric key pair.
[0032] In step 107 , in response to determining that the decrypted transmission information represents transmittable information, the client encrypts the data to be stored according to the private key in the local asymmetric key pair to obtain encrypted storage data, and sends the encrypted storage data to the server.
[0033] In some embodiments, in response to determining that the decrypted transmission information represents transmittable information, the client encrypts the data to be stored using the private key in the local asymmetric key pair to obtain encrypted stored data, and sends the encrypted stored data to the server. For example, the client encrypts the data to be stored using the RSA encryption algorithm using the private key in the local asymmetric key pair to obtain encrypted stored data.
[0034] Optionally, the client applies for a transmission key from the data transmission module of the server.
[0035] Optionally, the trusted cryptographic card transmits the public key to the server and the private key to the client.
[0036] Optionally, the server formats and encapsulates the transmitted data, including: encrypting each data with a public key and dynamically placing it into different data bins, updating the encrypted bin dynamic mapping table, and transmitting the encapsulated result carrier to the client.
[0037] Optionally, the client performs a data integrity check after receiving the data. If the data is incomplete, the server is notified to resend it. If the data is complete, the client decrypts the received data using the private key and transmits the decrypted data to the data access control module.
[0038] Optionally, when the data access control module receives the data write instruction, it reads the data storage public key stored in the data access public key interface of the trusted password card with the target identifier, encrypts the data, and writes it into the database. The target identifier may be a legal person ID (client identifier).
[0039] Optionally, when the data access control module receives a data read instruction, it first reads data from the database according to the read conditions, reads the private key from the trusted password card with the target identifier, decrypts the data, and then provides the data to the server.
[0040] Optionally, in response to receiving the encrypted storage data sent by the client, the server decrypts the encrypted storage data according to the corresponding data transmission public key to obtain decrypted storage data.
[0041] In some embodiments, the server, in response to receiving the encrypted stored data sent by the client, decrypts the encrypted stored data according to the corresponding data transmission public key to obtain the decrypted stored data. The data transmission public key may be the data transmission public key previously sent by the client.
[0042] Optionally, the server determines whether there is a storage node corresponding to the client in the local storage node cluster, and in response to determining that there is no storage node corresponding to the client in the storage node cluster, constructs a storage node corresponding to the client as the target storage node.
[0043] In some embodiments, the server determines whether a storage node corresponding to the client exists in a local storage node cluster. In response to determining that a storage node corresponding to the client does not exist in the storage node cluster, the server constructs a storage node corresponding to the client as a target storage node. One storage node corresponds to one client. The storage node can be a Data Node. That is, if a storage node corresponding to the client does not exist, the server creates a new storage node in the storage node cluster identified by the client identifier of the client.
[0044] Optionally, the server constructs an encryption key based on the storage node identifier and current timestamp corresponding to the target storage node, encrypts the decrypted storage data based on the encryption key, and stores the encrypted storage data in the target storage node.
[0045] In some embodiments, the server constructs an encryption key based on the storage node identifier and current timestamp corresponding to the target storage node, encrypts the decrypted stored data based on the encryption key, and stores the encrypted stored data in the target storage node. Specifically, the storage node identifier and current timestamp can be converted into a string of Roman numerals, which can then be converted into an encryption key using a key generation algorithm. The decrypted stored data can be encrypted using an RSA encryption algorithm.
[0046] Here, after receiving the data sent by the client, the server regenerates the encryption key to encrypt and store the data. Thus, through multiple encryption and continuous updating of the encryption key, the security of data storage is greatly improved.
[0047] Optionally, in response to determining that there is a storage node corresponding to the above-mentioned client in the storage node cluster, the above-mentioned server constructs an encryption key based on the node identifier and current timestamp of the storage node corresponding to the above-mentioned client, and encrypts the above-mentioned decrypted storage data based on the above-mentioned encryption key, and stores the encrypted storage data in the above-mentioned storage node.
[0048] In some embodiments, the above-mentioned server, in response to determining that there is a storage node corresponding to the above-mentioned client in the storage node cluster, constructs an encryption key based on the node identifier and current timestamp of the storage node corresponding to the above-mentioned client, and encrypts the above-mentioned decrypted storage data based on the above-mentioned encryption key, and stores the encrypted storage data in the above-mentioned storage node.
[0049] Optionally, in response to receiving the sharing instruction corresponding to the target general information, the client sends transmission mode confirmation information for the target general information to the server.
[0050] In some embodiments, in response to receiving a sharing instruction corresponding to the target general information, the client sends a transmission method confirmation message for the target general information to the server. The sharing instruction may be an instruction input by a technician to synchronize the target general information to the server. The target general information may be shared data that changes to general data (e.g., changes to a personnel table or address change information). The transmission method confirmation message may be information confirming the transmission method of the target general information.
[0051] Optionally, the server determines a transmission state corresponding to the target general transmission mode in response to receiving transmission mode confirmation information for the target general information sent by the client.
[0052] In some embodiments, the server determines a transmission state corresponding to the target general transmission mode in response to receiving transmission mode confirmation information for the target general information sent by the client. The transmission state may be a state indicating whether encryption is required for transmission of the target general information.
[0053] Optionally, the server generates transmission mode feedback information in response to the transmission status characterizing non-encrypted transmission, and sends the transmission mode feedback information to the client.
[0054] In some embodiments, the server generates transmission mode feedback information in response to the transmission state indicating non-encrypted transmission, and sends the transmission mode feedback information to the client, wherein the transmission mode feedback information indicates support for non-encrypted transmission of the target general information.
[0055] Optionally, in response to determining that the transmission mode feedback information sent by the server indicates non-encrypted transmission, the client sends the target general information to the sending server.
[0056] In some embodiments, the client sends the target general information to the sending server in response to determining that the transmission mode feedback information sent by the server indicates non-encrypted transmission.
[0057] Optionally, in response to receiving the data query information sent by the client, the server parses the data query information to obtain a data query field set.
[0058] In some embodiments, the server, in response to receiving data query information sent by the client, parses the data query information to obtain a data query field set. The data query information may represent query information for a specific data item. The data query field may be a field corresponding to key query data in the data query information. For example, the data query field set may include a location data query field and a table data query field.
[0059] Optionally, the server adjusts the field format of the data query field in the data query field set according to the database field set corresponding to the target storage node to generate a data adjustment query field set.
[0060] In some embodiments, the server adjusts the field format of the data query fields in the data query field set based on the database field set corresponding to the target storage node to generate a data adjustment query field set. The database fields may be fields described for the target storage node. For example, the database fields may be table fields of various tables in the target storage node, or data feature fields of key data sets stored in the target storage node. The target storage node may represent the storage node corresponding to the client.
[0061] In practice, the server may adjust the field format of the data query fields in the data query field set by following the steps below to generate a data adjustment query field set:
[0062] The first step is to divide the above data query field set into a non-character query field set and a character data query field set.
[0063] In the second step, for each non-character query field in the non-character query field set, perform the following adjustment steps:
[0064] 1. Determine whether a database field corresponding to the non-character query field exists in the database field set. Use a keyword matching algorithm to determine whether a database field corresponding to the non-character query field exists in the database field set. The keyword matching algorithm may be an Aho-Corasick automaton (AC).
[0065] 2. In response to determining that the query field does not exist, determine the field similarity between each database field in the database field set and the non-character query field to obtain a field similarity set. For example, the field similarity between each database field in the database field set and the non-character query field can be determined using a cosine similarity or Euclidean distance similarity algorithm to obtain the field similarity set.
[0066] 3. Determine the field similarity in the field similarity set that meets a preset similarity condition as the candidate field similarity. The preset similarity condition may be that the field similarity is the highest and the field similarity is greater than a predetermined similarity.
[0067] 4. The database field corresponding to the candidate field similarity is determined as the candidate database field.
[0068] 5. Based on the candidate database field, the non-character query field is adjusted to obtain a non-character adjusted query field. The non-character query field can be replaced with the candidate database field to obtain a non-character adjusted query field.
[0069] In the third step, each non-character adjustment query field and the above character data query field set are determined as a data adjustment query field set.
[0070] Optionally, the server inputs the query correction field set into a pre-trained database statement conversion model to obtain a database statement.
[0071] In some embodiments, the server inputs the query modification field set into a pre-trained database statement conversion model to obtain a database statement. The database statement conversion model can be a pre-trained large neural network model that generates corresponding database statements based on the query modification field set. For example, the database statement conversion model can be a large language model (LLM).
[0072] Optionally, the server executes the database statement to read the query information from the target storage node, and encrypts the query information and sends it to the client.
[0073] In some embodiments, the server executes the database statement to read query information from the target storage node and encrypts and sends the query information to the client, wherein the query information may be query content corresponding to the data query information.
[0074] In practice, the server can read the query information from the target storage node through the following steps:
[0075] The first step is to execute the above database statement to generate statement execution results.
[0076] In the second step, in response to determining that the statement execution result indicates that the statement execution failed, the following processing steps are executed:
[0077] 1. Extract data query fields from the above database statements to generate a statement extraction field set.
[0078] 2. Based on the database field set, adjust the statement extraction fields in the statement extraction field set to obtain a statement adjustment field set. The statement adjustment fields may be adjusted statement extraction fields that match the database fields.
[0079] 3. Generate a database adjustment statement corresponding to the statement adjustment field set. You can combine the statement adjustment fields in the statement adjustment field set to generate a database adjustment statement.
[0080] 4. Execute the above database adjustment statement to generate an adjustment statement execution result. The adjustment statement execution result can indicate whether the database adjustment statement fails to execute.
[0081] 5. In response to determining that the execution result of the adjustment statement does not indicate an execution failure, query information corresponding to the execution result of the adjustment statement is obtained.
[0082] In the third step, in response to determining that the above adjustment statement execution result fails, the adjustment statement execution result is used as the statement execution result, and the database adjustment statement is used as the database statement, and the above processing steps are executed again.
[0083] This improves the accuracy of database statement generation and ensures the efficiency and accuracy of query information. If a statement execution result indicates a failure, the database field set is used to adjust the various data query fields to generate more precise query statements, further improving the accuracy of information queries.
[0084] Reference below Figure 2 , which shows a schematic diagram of the structure of an electronic device 200 (e.g., a computing device) suitable for implementing some embodiments of the present disclosure. The electronic devices in some embodiments of the present disclosure may include, but are not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), etc., as well as fixed terminals such as digital TVs and desktop computers. Figure 2 The electronic device shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present disclosure.
[0085] like Figure 2 As shown, the electronic device 200 may include a processing device (e.g., a central processing unit, a graphics processing unit, etc.) 201, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 202 or a program loaded from a storage device 208 into a random access memory (RAM) 203. Various programs and data required for the operation of the electronic device 200 are also stored in the RAM 203. The processing device 201, the ROM 202, and the RAM 203 are connected to each other via a bus 204. An input / output (I / O) interface 205 is also connected to the bus 204.
[0086] Typically, the following devices may be connected to the I / O interface 205: an input device 206 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 207 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 208 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 209. The communication device 209 may allow the electronic device 200 to communicate with other devices wirelessly or by wire to exchange data. Figure 2 The electronic device 200 is shown with various devices, but it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed instead. Figure 2 Each block shown in the figure may represent one device, or may represent multiple devices as needed.
[0087] In particular, according to some embodiments of the present disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, some embodiments of the present disclosure include a computer program product comprising a computer program carried on a computer-readable medium, the computer program comprising program code for executing the method shown in the flowchart. In some such embodiments, the computer program can be downloaded and installed from a network via the communication device 209, or installed from the storage device 208, or installed from the ROM 202. When the computer program is executed by the processing device 201, the above-mentioned functions defined in the method of some embodiments of the present disclosure are performed.
[0088] It should be noted that the computer-readable medium described in some embodiments of the present disclosure may be a computer-readable signal medium or a computer-readable storage medium, or any combination of the two. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or device, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In some embodiments of the present disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, device, or device. In some embodiments of the present disclosure, the computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium may be transmitted using any suitable medium, including but not limited to wires, optical cables, RF (radio frequency), etc., or any suitable combination thereof.
[0089] In some embodiments, the client and server can communicate using any currently known or future developed network protocol, such as HTTP (HyperText Transfer Protocol), and can be interconnected with any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network ("LAN"), a wide area network ("WAN"), an internet (e.g., the Internet), and a peer-to-peer network (e.g., an ad hoc peer-to-peer network), as well as any currently known or future developed network.
[0090] The above-mentioned computer-readable medium may be included in the above-mentioned electronic device; or it may exist independently and not be assembled into the electronic device. The above-mentioned computer-readable medium carries one or more programs. When the above-mentioned one or more programs are executed by the electronic device, the electronic device: the client initiates a transmission channel establishment request to the above-mentioned server to establish a data transmission channel; the above-mentioned server requests a dynamic transmission key pair from the trusted password card through the data transmission module, and sends the dynamic transmission public key in the above-mentioned dynamic transmission key pair to the above-mentioned client through the above-mentioned data transmission channel; the above-mentioned client generates an asymmetric key pair according to the client identification in response to receiving the dynamic transmission public key sent by the server, and sends the data transmission public key in the above-mentioned asymmetric key pair and the received dynamic transmission public key to the above-mentioned server; the above-mentioned server, in response to receiving the data transmission public key and the dynamic transmission public key, performs a dynamic transmission on the server according to the local dynamic transmission key pair. The public key is input for verification to obtain a dynamic transmission public key verification result; the above-mentioned server generates data transmittable information in response to determining that the above-mentioned dynamic transmission public key verification result represents that the verification is passed, and encrypts the above-mentioned data transmittable information according to the above-mentioned data transmission public key to obtain encrypted data transmittable information, and sends the above-mentioned encrypted data transmittable information to the above-mentioned client; the above-mentioned client responds to receiving the encrypted data transmittable information sent by the server, decrypts the above-mentioned encrypted data transmittable information according to the local asymmetric key pair, and obtains decrypted transmission information; the above-mentioned client responds to determining that the above-mentioned decrypted transmission information represents transmittable information, encrypts the data to be stored according to the private key in the local asymmetric key pair, obtains encrypted storage data, and sends the encrypted storage data to the above-mentioned server.
[0091] Computer program code for performing the operations of some embodiments of the present disclosure may be written in one or more programming languages, or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).
[0092] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the module, program segment, or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of the boxes in the block diagram and / or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0093] The functions described above herein may be performed, at least in part, by one or more hardware logic components. For example, and without limitation, exemplary types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chip (SOCs), complex programmable logic devices (CPLDs), and the like.
[0094] The above description is only an illustration of some preferred embodiments of the present disclosure and the technical principles used. Those skilled in the art should understand that the scope of the invention involved in the embodiments of the present disclosure is not limited to the technical solutions formed by the specific combination of the above-mentioned technical features, but should also cover other technical solutions formed by any combination of the above-mentioned technical features or their equivalent features without departing from the above-mentioned inventive concept. For example, the above-mentioned features are replaced with (but not limited to) technical features with similar functions disclosed in the embodiments of the present disclosure.
Claims
1. A cross-domain converged data transmission and storage method, applied to a cross-domain converged data transmission and storage system, the cross-domain converged data transmission and storage system comprising: The server and the client, the method includes: The client initiates a transmission channel establishment request to the server to establish a data transmission channel; The server requests a dynamic transmission key pair from the trusted password card through the data transmission module, and sends the dynamic transmission public key in the dynamic transmission key pair to the client through the data transmission channel; In response to receiving the dynamic transmission public key sent by the server, the client generates an asymmetric key pair according to the client identifier, and sends the data transmission public key in the asymmetric key pair and the received dynamic transmission public key to the server; In response to receiving the data transmission public key and the dynamic transmission public key, the server verifies the dynamic transmission public key according to the local dynamic transmission key pair to obtain a dynamic transmission public key verification result; In response to determining that the dynamic transmission public key verification result indicates that the verification is passed, the server generates data transmittable information, encrypts the data transmittable information according to the data transmission public key to obtain encrypted data transmittable information, and sends the encrypted data transmittable information to the client; In response to receiving the encrypted data transmittable information sent by the server, the client decrypts the encrypted data transmittable information according to the local asymmetric key pair to obtain decrypted transmission information; In response to determining that the decrypted transmission information represents transmittable information, the client encrypts the data to be stored according to the private key in the local asymmetric key pair to obtain encrypted storage data, and sends the encrypted storage data to the server.
2. The method according to claim 1, wherein The method further comprises: In response to receiving the encrypted stored data sent by the client, the server decrypts the encrypted stored data according to the corresponding data transmission public key to obtain decrypted stored data; The server determines whether a storage node corresponding to the client exists in a local storage node cluster, and in response to determining that a storage node corresponding to the client does not exist in the storage node cluster, constructs a storage node corresponding to the client as a target storage node; The server constructs an encryption key according to the storage node identifier corresponding to the target storage node and the current timestamp, encrypts the decrypted storage data according to the encryption key, and stores the encrypted storage data in the target storage node.
3. The method according to claim 2, wherein: The method further comprises: In response to determining that there is a storage node corresponding to the client in the storage node cluster, the server constructs an encryption key based on the node identifier and current timestamp of the storage node corresponding to the client, encrypts the decrypted storage data based on the encryption key, and stores the encrypted storage data in the storage node.
4. The method according to claim 1, wherein The method further comprises: In response to receiving the sharing instruction corresponding to the target general information, the client sends transmission mode confirmation information for the target general information to the server; The server determines a transmission state corresponding to the target general transmission mode in response to receiving transmission mode confirmation information for the target general information sent by the client; The server generates transmission mode feedback information in response to the transmission state indicating non-encrypted transmission, and sends the transmission mode feedback information to the client, wherein the transmission mode feedback information indicates that non-encrypted transmission of target general information is supported; In response to determining that the transmission mode feedback information sent by the server indicates non-encrypted transmission, the client sends the target general information to the sending server.
5. The method according to claim 4, wherein The method further comprises: The server, in response to receiving the data query information sent by the client, parses the data query information to obtain a data query field set; The server adjusts the field format of the data query field in the data query field set according to the database field set corresponding to the target storage node to generate a data adjustment query field set; The server inputs the query field set into a pre-trained database statement conversion model to obtain a database statement; The server executes the database statement to read the query information from the target storage node, and encrypts the query information and sends it to the client.
6. An electronic device comprising: one or more processors; a storage device having one or more programs stored thereon; When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 5.
7. A computer-readable medium having a computer program stored thereon, wherein: When the program is executed by a processor, the method according to any one of claims 1 to 5 is implemented.
Citation Information
Patent Citations
Secret data transmission protection method based on isomorphism of asymmetrical encryption algorithm
CN101808089A
Secure network communication method for dynamically generating key
CN112235103A