Data transmission method and device based on network interface encryption of swan mongolian APP, and medium

By building network transmission security components based on Hongmeng official components and arkts language in the Hongmeng system, the problem of low data transmission security is solved, data encryption, signature and dynamic switching of multiple network libraries is realized, and the security and flexibility of data transmission are improved.

CN120017373APending Publication Date: 2025-05-16SHENZHEN LEXIN SOFTWARE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510170529.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-17
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

The prior art lacks mature open source components in the Hongmeng system to support encryption and signature verification of data transmission, resulting in low security during data transmission.

Method used

By building mature network transmission security components based on Hongmeng official components and arkts language, data encryption and signature capabilities are realized, and dynamic switching kernel capabilities of multiple network libraries are realized by switching the underlying network components.

Benefits of technology

It enhances the security of data during transmission, provides signature verification and AES encryption capabilities, and realizes dynamic switching of multiple network libraries, making up for the gap in network components in Hongmeng applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017373A_ABST
    Figure CN120017373A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data transmission, and discloses a data transmission method and device based on network interface encryption of a swan mongolian APP, and a medium, and the method comprises the steps: constructing a service request parameter according to a service node, and carrying out the analysis of the service request parameter; sorting the data objects of the business request parameters according to the alphabetic sequence and the key value pairs, converting the sorted data objects into character strings, and salting the character strings; carrying out signature processing on the salted character string, and carrying out data encryption processing on the signed character string; packaging the character string ciphertext into a data packet, packaging the data packet into a network transmission component, and calling the network transmission component through a service network request; and transmitting the data packet to a preset service requester through the called network transmission component, and reversely decrypting the data packet transmitted to the service requester to obtain request transmission data corresponding to the service network request. According to the invention, the security during data transmission can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data transmission technology, and in particular to a data transmission method, device and medium based on Hongmeng APP network interface encryption. Background Art

[0002] Currently, the Hongmeng system is still in the early stages of its ecosystem. There are no mature open source components on the market to directly support the encryption and signature verification solutions for Hongmeng data applications in network transmission. In addition, in the Hongmeng third-party library, there is no mature framework for network transmission and signature based on the ArkTS code. Each company needs to conduct its own feasibility research and develop the ArkTS code. Therefore, in order to ensure the security of data transmission, the data needs to be signed and encrypted before the network component sends the request.

[0003] Existing data transmission technologies build a data transmission system through the cooperation of various network components to achieve data transmission. In actual applications, network requests are only sent through network components without encrypting the data, which can easily lead to data leakage when calling network components, thus reducing the security of data transmission. Summary of the invention

[0004] The present invention provides a data transmission method, device and medium based on Hongmeng APP network interface encryption, the main purpose of which is to solve the problem of low security during data transmission.

[0005] To achieve the above purpose, the present invention provides a data transmission method based on Hongmeng APP network interface encryption, including:

[0006] Constructing a service request parameter according to a preset service node, parsing the service request parameter, and obtaining a key-value pair of the service request parameter;

[0007] sorting the data objects of the service request parameters according to a preset alphabetical order and the key-value pairs, converting the sorted data objects into strings, and performing salting on the strings;

[0008] Sign the salted string and encrypt the signed string to obtain the ciphertext of the string;

[0009] Encapsulating the ciphertext of the character string into a data packet, encapsulating the data packet into a preset network transmission component, and calling the network transmission component through a preset service network request;

[0010] The data packet is transmitted to a preset service requester through the called network transmission component, and the data packet transmitted to the service requester is reversely decrypted to obtain the request transmission data corresponding to the service network request.

[0011] Optionally, constructing a service request parameter according to a preset service node includes:

[0012] Extract the business data and business code corresponding to the preset business node;

[0013] Determine the system data of the service request according to the service code;

[0014] The service data and the system data are encapsulated as the service request parameters.

[0015] Optionally, the parsing the service request parameter to obtain a key-value pair of the service request parameter includes:

[0016] Parsing the business data in the business request parameters into business objects, and parsing the system data in the business request parameters into system objects;

[0017] Encapsulate the parsed business objects and the parsed system objects as data objects of business request parameters;

[0018] Extracting key-value pairs of business parameters corresponding to the business object in the data object;

[0019] Extract key-value pairs of system parameters corresponding to the system object in the data object.

[0020] Optionally, converting the sorted data objects into strings includes:

[0021] Extract the key attributes and value attributes of the business objects in the sorted data objects one by one;

[0022] Concatenate the key attribute and the value attribute of the business object into a business data string;

[0023] Extract the key attributes and value attributes of the system objects in the sorted data objects one by one;

[0024] The key attribute and the value attribute of the system object are concatenated into a system data string.

[0025] Optionally, the step of performing data encryption processing on the signed character string to obtain a ciphertext of the character string includes:

[0026] Convert the data type of the signed string into an array type, and perform data compression on the string converted into the array type;

[0027] Convert the pre-acquired encryption key into an array type, and use the preset symmetric key generator to convert the encryption key converted into the array type into an encryption key that complies with AES encryption;

[0028] The compressed character string is encrypted using the encryption key that complies with AES encryption to obtain a ciphertext of the character string.

[0029] Optionally, encapsulating the data packet into a preset network transmission component includes:

[0030] Extracting component code data of a preset network transmission component;

[0031] Extract the signature interface and encryption interface corresponding to the data packet;

[0032] The signature interface and the encryption interface are encapsulated into the component code data to obtain an encapsulated network transmission component.

[0033] Optionally, calling the network transmission component through a preset service network request includes:

[0034] Encapsulate all network transmission components into a preset unified interface;

[0035] Dynamically matching any network transmission component in the network transmission components according to the service network request;

[0036] The matched network transmission component is determined as the target network transmission component corresponding to the business network request, and the target network transmission component is called through the unified interface.

[0037] Optionally, the reverse decrypting of the data packet transmitted to the service requester to obtain the request transmission data corresponding to the service network request includes:

[0038] Decrypting the data packet transmitted to the service requester;

[0039] Perform signature verification on the decrypted data packet;

[0040] When the signature verification of the data packet is passed, the service logic is determined through the service network request;

[0041] The request transmission data is extracted according to the business logic.

[0042] In order to solve the above problem, the present invention further provides an electronic device, the electronic device comprising:

[0043] at least one processor; and,

[0044] a memory communicatively connected to the at least one processor; wherein,

[0045] The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the above-mentioned data transmission method based on Hongmeng APP network interface encryption.

[0046] In order to solve the above problems, the present invention also provides a computer-readable storage medium, in which at least one computer program is stored. The at least one computer program is executed by a processor in an electronic device to implement the above-mentioned data transmission method based on Hongmeng APP network interface encryption.

[0047] The embodiment of the present invention is based on the pure Hongmeng system, and builds a mature network transmission security component based on the Hongmeng official component and the arkts language to achieve data encryption and signature capabilities, fill the gap in the network components of pure arkts, and provide signature verification, AES encryption capabilities and network component kernel switching capabilities. By switching the underlying network component capabilities, the dynamic switching kernel capabilities of multiple network libraries (third-party libraries) are achieved, and the packaged finished lx-net component can be provided to other apps as a network component. Therefore, the data transmission method, device and medium based on the Hongmeng APP network interface encryption proposed in the present invention can solve the problem of low security during data transmission. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] Figure 1 A flowchart of a data transmission method based on Hongmeng APP network interface encryption provided by an embodiment of the present invention;

[0049] Figure 2 A framework diagram of a data transmission method based on Hongmeng APP network interface encryption provided by an embodiment of the present invention;

[0050] Figure 3 A schematic diagram of the structure of an electronic device for implementing the data transmission method based on Hongmeng APP network interface encryption provided in one embodiment of the present invention.

[0051] The realization of the purpose, functional features and advantages of the present invention will be further explained in conjunction with embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION

[0052] It should be understood that the specific embodiments described herein are only used to explain the present invention, and are not used to limit the present invention.

[0053] The embodiment of the present application provides a data transmission method based on the encryption of the Hongmeng APP network interface. The execution subject of the data transmission method based on the encryption of the Hongmeng APP network interface includes but is not limited to at least one of the electronic devices such as the server, the terminal, etc. that can be configured to execute the method provided by the embodiment of the present application. In other words, the data transmission method based on the encryption of the Hongmeng APP network interface can be executed by software or hardware installed on the terminal device or the server device, and the software can be a blockchain platform. The server includes but is not limited to: a single server, a server cluster, a cloud server or a cloud server cluster, etc. The server can be an independent server, or it can be a cloud server that provides cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery networks (Content Delivery Network, CDN), and basic cloud computing services such as big data and artificial intelligence platforms.

[0054] Reference Figure 1 As shown, it is a flow chart of a data transmission method based on Hongmeng APP network interface encryption provided by an embodiment of the present invention. In this embodiment, the data transmission method based on Hongmeng APP network interface encryption includes:

[0055] S1. Construct a service request parameter according to a preset service node, parse the service request parameter, and obtain a key-value pair of the service request parameter.

[0056] In an embodiment of the present invention, the business request parameters refer to business-related request data and system data, and the request data refers to fields specifically related to business logic, which may vary according to different business scenarios; the system data refers to fields related to request processing and internal system operations, including but not limited to system identification, version information, request source, and environmental information.

[0057] In the embodiment of the present invention, constructing the service request parameter according to the preset service node includes:

[0058] Extract the business data and business code corresponding to the preset business node;

[0059] Determine the system data of the service request according to the service code;

[0060] The service data and the system data are encapsulated as the service request parameters.

[0061] In detail, the business node includes relevant business data and business codes. For example, if the business request is a request for the front-end page to obtain data or a request for a certain business to send data, the business code corresponds to the business request. The system data required at this time is determined according to the business request, and the business node refers to the data that needs to be transmitted. Among them, the business data and business code corresponding to the business node can be obtained from a pre-stored storage area through a computer statement with a data capture function (such as Java statements, Python statements, etc.), and the storage area includes but is not limited to a database and a blockchain.

[0062] Specifically, the business data and system data are converted into corresponding formats, and the business data and system data are encapsulated as business request parameters. For example, the data format of the business request parameter corresponding to the business data is "data":{…}, and the data format of the business request parameter corresponding to the system data is "system":{…}. Then, the request parameters constructed according to the business node are {"data":{…};"system":{…}}.

[0063] Furthermore, the constructed business request parameters are parsed and the signature generation business process is entered. That is, in order to ensure the security of data during transmission, the data needs to be signed and encrypted, thereby obtaining a network request component that includes signing and encryption capabilities.

[0064] In an embodiment of the present invention, the key-value pair is a data representation method, in which each data item consists of two parts, a key and a value, the key is a unique identifier of a data item, the value is the data associated with the key, and the value can be any type of data, such as a string, a number, an array, etc.

[0065] In the embodiment of the present invention, the parsing of the service request parameters to obtain the key-value pairs of the service request parameters includes:

[0066] Parsing the business data in the business request parameters into business objects, and parsing the system data in the business request parameters into system objects;

[0067] Encapsulate the parsed business objects and the parsed system objects as data objects of business request parameters;

[0068] Extracting key-value pairs of business parameters corresponding to the business object in the data object;

[0069] Extract key-value pairs of system parameters corresponding to the system object in the data object.

[0070] In detail, first, based on the original business request parameter structure, which is in JSON format, the structure contains two parts, business data data and system data system. The function receives two parameters, namely the repData request data string and the system system parameter, and uses the JiQN.parse function to parse the request data req0ata into an object data, and the system parameter system into an object system, and extracts the data key-value pairs in the business object data and the parameter key-value pairs in the system object system, wherein the data key-value pairs in the business object and the data key-value pairs in the system object can be lifted from the pre-stored storage area through a statement with data crawling function.

[0071] Specifically, two maps dataMap and systenMap are initialized to store key-value pairs of request data and system parameters respectively. Each key-value pair in data is traversed. If the value is a string and not empty, the current element is skipped and the validity of the system parameters is checked. If the parameter exists and the type is not an object and is in SYSTEM_FIELDS, it is stored in systenMap.

[0072] Furthermore, it is necessary to sort the business object data and the system object system(json) objects based on the key-value pairs of the obtained business parameters and the key-value pairs of the system parameters, so as to encrypt the business data and system data subsequently to ensure the security of data transmission.

[0073] S2. Sort the data objects of the service request parameters according to a preset alphabetical order and the key-value pairs, convert the sorted data objects into character strings, and perform salting on the character strings.

[0074] In an embodiment of the present invention, business objects and system objects are respectively alphabetically sorted according to the key in the key-value pair, that is, based on the key in each object, the objects are arranged in alphabetical order of the key. For example, the key extracted from the business object is username, password, userId, and the key extracted from the system object is systemId, timestamp, version, and environment. Then, the sequence obtained after sorting the business objects in alphabetical order of the keys is password, userId, and username; the sequence obtained after sorting the system objects in alphabetical order of the keys is environment, systemId, timestamp, and version. Therefore, arranging the keys of the objects in alphabetical order can improve the readability of the data structure, and when multiple keys are included, the required keys can be quickly found.

[0075] Furthermore, in order to ensure a consistent format in different requests, the data objects in the request parameters need to be converted into strings, and data in string format takes less time in network transmission, especially when using JSON to transmit data, which can reduce bandwidth consumption.

[0076] In the embodiment of the present invention, the sorted business objects and system objects are converted into character strings to ensure that they meet the request standards during the data request process. In HTTP requests, many parameters are transmitted in the form of character strings.

[0077] In the embodiment of the present invention, converting the sorted data objects into character strings includes:

[0078] Extract the key attributes and value attributes of the business objects in the sorted data objects one by one;

[0079] Concatenate the key attribute and the value attribute of the business object into a business data string;

[0080] Extract the key attributes and value attributes of the system objects in the sorted data objects one by one;

[0081] The key attribute and the value attribute of the system object are concatenated into a system data string.

[0082] In detail, traverse the sorted system and data (JSON objects), extract the key and value of each data in the object, and concatenate them into a string in the form of "key" + "value". For example, if the key in the data object is username and the value is testUser, the corresponding string is username+testUser, thereby traversing all the data, converting all the data in the business objects and system objects into strings, and storing the converted strings in dataAndsys.

[0083] Specifically, the incoming dataAndsys string is concatenated with a fixed salt value, that is, the salt value is added to the generated string to generate a salted string to increase security. The fixed salt value is used to prevent the same input from producing the same hash result, thereby improving security. The fixed salt value is a randomly generated additional data, such as the salting logic is message = dataAndsys + 'fql&a! 8* + p% & xs068ec981e6c53d4d19764be07938c9e0', where the fixed salt value is 'fql&a! 8* + p% & xs068ec981e6c53d4d19764be07938c9e0'.

[0084] Furthermore, the generated salted string needs to be encrypted with SM3 to generate the final signature string, which is then placed in the system field to ensure security during data transmission.

[0085] S3. Sign the salted string and perform data encryption on the signed string to obtain a ciphertext of the string.

[0086] In an embodiment of the present invention, the salted string after salting is signed by using the SM3 encryption algorithm, wherein the SM3 encryption algorithm first fills the salted string to a certain length so that its length is 448 mod 512 (that is, 64 bits less than an integer multiple of 512), and then adds a 64-bit field representing the length of the original message at the end, divides the padded data into 512-bit blocks, and defines 8 initial hash values ​​(constants), performs 64 rounds of transformation and operation on each 512-bit data block, updates the hash value, and finally uses the obtained 256-bit hash value as the signature string.

[0087] Furthermore, in order to further ensure the security of data transmission, after the data is signed, it is also necessary to encrypt the data to implement a dual security mechanism of data signing and encryption to ensure the security of data during transmission.

[0088] In the embodiment of the present invention, the string ciphertext refers to the string data after encryption processing, which is an unreadable form of the original data (plaintext) and aims to protect the privacy and security of the data. Encryption is the process of converting plaintext into ciphertext through a specific algorithm. Only a person with the corresponding decryption key can restore the ciphertext to plaintext.

[0089] In the embodiment of the present invention, the data encryption processing is performed on the signed character string to obtain the ciphertext of the character string, including:

[0090] Convert the data type of the signed string into an array type, and perform data compression on the string converted into the array type;

[0091] Convert the pre-acquired encryption key into an array type, and use the preset symmetric key generator to convert the encryption key converted into the array type into an encryption key that complies with AES encryption;

[0092] The compressed character string is encrypted using the encryption key that complies with AES encryption to obtain a ciphertext of the character string.

[0093] In detail, the native component @kit.CryptoArchitectureKit based on arkts is used to implement AES encryption and generate string ciphertext. First, a static asynchronous function is defined to receive two parameters, reportJsonStr: the JSON string to be encrypted, and pukey: the key used for AES encryption (usually the public key). Then, the pako library is used to perform Gzip compression on reportJsonStr and return a Uint8Array type of data to reduce the size of the data to be encrypted, thereby improving the efficiency of encryption and transmission.

[0094] Specifically, initialize a string variable globalResult to store the encrypted result. During the encryption process, use the try-catch structure to handle possible errors, and then define the encryption algorithm as AES128, use the ECB mode and PKCS7 padding method, and create an encryptor instance. Then create a symmetric key generator, decode the pukey into a Uint8Array type, and then convert it into a key suitable for AES encryption. Initialize the encryptor to encryption mode, use the converted key, and then call the doFinal method to encrypt the compressed data and return the encryption result. Encode the encryption result as a string for easy storage or transmission, and output the encrypted result. Finally, the encrypted string is obtained, that is, console.info('Encrypted plaintext:'+globalResult).

[0095] Furthermore, unlike Android's OkHttp, which is the officially recommended network request component, there is currently no officially recommended third-party network library on the Hongmeng system. Therefore, in its own network components, multiple sets of network components are encapsulated to achieve low-cost dynamic switching capabilities and ensure that the network components have digital signature and encryption capabilities.

[0096] S4. Encapsulate the ciphertext of the character string into a data packet, encapsulate the data packet into a preset network transmission component, and call the network transmission component through a preset service network request.

[0097] In the embodiment of the present invention, the structure of the data packet is first defined, and then the ciphertext data is used as part of the data packet. The data packet includes fields such as header, payload, and checksum, wherein the header is the packet header, including information such as version and type, the payload is the effective load, storing the ciphertext, and the checksum is the checksum, which is used to verify the integrity of the data. Then, through the DataPacket interface, the structure of the data packet is defined, including the header, payload, and checksum, and the createDataPacket function is used to encapsulate the ciphertext into a data packet, construct the header, calculate the checksum, and return the complete data packet, thereby encapsulating the string ciphertext into a data packet.

[0098] Furthermore, in order to ensure the security of data transmission through the network transmission component, the signature interface and encryption interface corresponding to the encrypted data packet need to be encapsulated into the network transmission component, so that when the network transmission requests data, the data can be signed and encrypted to ensure the security of the data.

[0099] In an embodiment of the present invention, the signature interface and encryption interface corresponding to the encrypted data packet are encapsulated into a network transmission component, so that a network component with data signature verification and data encryption capabilities can be obtained, thereby making up for the lack of signature verification and encryption capabilities of the third-party network library of the Hongmeng application.

[0100] In the embodiment of the present invention, encapsulating the data packet into a preset network transmission component includes:

[0101] Extracting component code data of a preset network transmission component;

[0102] Extract the signature interface and encryption interface corresponding to the data packet;

[0103] The signature interface and the encryption interface are encapsulated into the component code data to obtain an encapsulated network transmission component.

[0104] In detail, the code data in the network transmission component is obtained, and the code data includes the basic methods for sending and receiving data, and based on the created signature interface class (such as SignatureInterface), it includes a method for signing the data, generates a signature for verifying the integrity and authenticity of the data, creates an encryption interface class (such as EncryptionInterface), implements a method to encrypt the data, protects the data from unauthorized access, and then creates a comprehensive network transmission component that can not only send data, but also sign and encrypt the data before sending, thereby enhancing the security of the data.

[0105] Specifically, define a new class (for example, EncapsulatedNetworkComponent), which will integrate the previously extracted network components, signature interfaces, and encryption interfaces. In the constructor of the encapsulated class, the network components, signature interfaces, and encryption interfaces are passed in as parameters and stored in instance variables for subsequent use. In the encapsulated class, the sending method is rewritten so that before calling the sending method of the original network component, the data is first signed and encrypted, that is, the signature interface is first called to sign the data to be sent and generate signature data, and then the encryption interface is called to encrypt the signature data to obtain the encrypted data. Finally, the sending method of the network component is called to send the encrypted data.

[0106] Furthermore, building a fully functional network transmission component with the ability to send, sign and encrypt data not only enhances the security of data during network transmission, but also improves the modularity and reusability of the code. End users only need to interact with the encapsulated network components without having to pay attention to the underlying implementation details.

[0107] In the embodiment of the present invention, through a unified interface, different network components are used to implement the same request interface, thereby realizing the selection of the network request implementation component of arkts, that is, dynamically selecting the network framework.

[0108] In the embodiment of the present invention, the calling of the network transmission component through a preset service network request includes:

[0109] Encapsulate all network transmission components into a preset unified interface;

[0110] Dynamically matching any network transmission component in the network transmission components according to the service network request;

[0111] The matched network transmission component is determined as the target network transmission component corresponding to the business network request, and the target network transmission component is called through the unified interface.

[0112] In detail, a unified interface is defined to ensure that all network components can follow this interface to facilitate subsequent expansion and dynamic selection, so that different network components follow the same request method, and multiple network request components are implemented to handle network requests separately, and the appropriate network component is dynamically selected according to the request requirements.

[0113] Specifically, network transmission components (such as httpclient components, rpc components, and ohos.net.http components) send network requests through a unified interface. Each component represents a different transmission protocol, and the component will implement the send method to process specific network requests and match different network transmission components based on different business requests, so that the network transmission component can be dynamically selected, so that any network component can be selected, and the network component can be extended, and then the network transmission component can be selected to request data according to the business configuration.

[0114] Furthermore, by switching the capabilities of the underlying network components, the kernel capabilities of various network libraries (third-party libraries) can be dynamically switched, and the request data is sent through the dynamically selected network transmission component.

[0115] S5. The data packet is transmitted to a preset service requester through the called network transmission component, and the data packet transmitted to the service requester is reversely decrypted to obtain the request transmission data corresponding to the service network request.

[0116] In the embodiment of the present invention, the data packet is transmitted to the preset service requester by the called network transmission component, that is, the data is transmitted by the lx-net component, then the net.postLx <t>(body,{...}) to transfer data, where lx-net: is a tool component for network requests, encapsulating the logic of network requests, postLx <t>It is a method of the lx-net component, which means executing a POST request. <t>It is a generic type used to indicate the type of response data. Body represents the request body to be sent to the server, which is usually a JSON object containing the data to be transmitted. The configurable parameters of the network component (lx-net) are the timeout and the default item. The default value of the timeout is 5000, in milliseconds, and the default item is configured as a cookie.

[0117] In detail, after the network transmission component lx-net completes the request to transmit the data packet to the preset business requester, one of the two callback functions will be called according to the request result. The two callback functions are onSuccess:(res:T)=>{...} and onFailure:(code:number,errorInfo:string)=>{...}, where onSuccess is a callback function executed when the request is successful. It accepts a parameter res, which is of generic type T and represents the response data returned by the request. resolve(res): This function is usually a Promise resolution function. It passes the response data res to the success callback of Promise so that the place where postLx is called can process the successful result. Then the lx-net component is called. Through the encapsulation of the lx-net component, the operation of network requests is simplified. The code is not aware of the signing and encryption process. When using this component, the caller does not need to care about these details; onFailure: This is a callback function executed when the request fails. It accepts two parameters. Code represents the error code, which is usually used to indicate the type of error. ErrorInfo is a string that provides detailed information about the error. reject(new Error(Error code:code, info:code, info:{errorInfo})), this function is the rejection function of Promise, it will create a new Error object and pass the error information to it, which will cause the failure callback of Promise to be executed where postLx is called. The response data after the callback is sent to the server, and the corresponding business logic can be determined based on the information in the data packet. The decrypted data will be analyzed to determine what operation or response should be performed, and then the request transmission data will be extracted based on the determined business logic.

[0118] Furthermore, the data is transmitted to the service requester through the network transmission component. For example, when the client requests data from the server, the server transmits the data to the client through the network transmission component. Before receiving the data, the client also needs to decrypt the data and verify the signature to ensure the security of data transmission.

[0119] In the embodiment of the present invention, the requested transmission data refers to the data after decryption of the data requested by the service requester, that is, the original data transmitted by the server, including the user's request content, parameters, etc.

[0120] In the embodiment of the present invention, the reverse decryption of the data packet transmitted to the service requester to obtain the request transmission data corresponding to the service network request includes:

[0121] Decrypting the data packet transmitted to the service requester;

[0122] Perform signature verification on the decrypted data packet;

[0123] When the signature verification of the data packet is passed, the service logic is determined through the service network request;

[0124] The request transmission data is extracted according to the business logic.

[0125] In detail, the received data packet is decrypted by AES, and the data packet is decrypted by the decryption key to convert the information in the data packet into a readable format. After decryption, the data packet needs to be signed and verified, that is, the signature part is extracted from the decrypted data packet. The signature part is a field in the data packet, which represents the encrypted hash value of the content of the data packet by the sender when the data packet is generated. The message body and related metadata of the decrypted data packet are used to reconstruct the original content used by the sender to generate the signature when sending. The reconstructed message content is hashed using the same hash algorithm (such as SHA-256) to obtain a new hash value. The regenerated hash value is compared with the initial encrypted hash value to ensure the integrity of the data packet and the authenticity of the source.

[0126] Specifically, after comparing the regenerated hash value with the initial encrypted hash value, if the hash values ​​are the same, the signature verification is successful, indicating that the data packet has not been tampered with during transmission and is indeed generated by the sender who owns the corresponding private key; if they are different: the signature verification fails, which may mean that the data packet has been modified during transmission or the sender is unidentified. Once the signature verification is successful, the corresponding business logic can be determined based on the information in the data packet. The decrypted data will be analyzed to determine what operation or response should be performed, and then the requested transmission data will be extracted based on the determined business logic.

[0127] For example, Figure 2 As shown, it is a framework diagram of the data transmission method based on the Hongmeng APP network interface encryption, including business code, network components, and a server, wherein the request parameters are constructed through the business nodes corresponding to the business code; the request parameters are parsed in the network component, and the signature generation process is entered, firstly, the system and data (json objects) are obtained, the keys are sorted in alphabetical order, the sorted json is traversed, the key and value are extracted, and they are concatenated into a string in the form of "key" + "value", and a salt value is added to the generated string to generate a string with more salt, the generated salted string is encrypted by SM3, the final signature string is generated, and put into the system field, and then the data is encrypted, and AES encryption is implemented using a native component based on arkts to generate a ciphertext, and then the same request interface is implemented with different network components through a unified interface, and the network request implementation component of arkts is selected, and the network request is sent through the network component; the server performs AES decryption on the sent data and verifies the signature. After the signature is verified, the business logic is entered to execute the business operation.

[0128] The embodiment of the present invention is based on the pure Hongmeng system, and builds a mature network transmission security component based on the Hongmeng official component and the arkts language to achieve data encryption and signature capabilities, fill the gap in the network components of pure arkts, and provide signature verification, AES encryption capabilities and network component kernel switching capabilities. By switching the underlying network component capabilities, the dynamic switching kernel capabilities of multiple network libraries (third-party libraries) are achieved, and the packaged finished lx-net component can be provided to other apps as a network component. Therefore, the data transmission method, device and medium based on the Hongmeng APP network interface encryption proposed in the present invention can solve the problem of low security during data transmission.

[0129] like Figure 3 The figure is a schematic diagram of the structure of an electronic device that implements a data transmission method based on Hongmeng APP network interface encryption provided by an embodiment of the present invention.

[0130] The electronic device may include a processor 10, a memory 11, a communication bus 12 and a communication interface 13, and may also include a computer program stored in the memory 11 and executable on the processor 10, such as a data transmission program encrypted based on the Hongmeng APP network interface.

[0131] Among them, the processor 10 can be composed of an integrated circuit in some embodiments, for example, it can be composed of a single packaged integrated circuit, or it can be composed of multiple integrated circuits with the same function or different functions, including one or more central processing units (CPU), microprocessors, digital processing chips, graphics processors and various control chips. The processor 10 is the control core (ControlUnit) of the electronic device, which uses various interfaces and lines to connect the various components of the entire electronic device, and executes or executes the program or module stored in the memory 11 (for example, executing the data transmission program encrypted based on the Hongmeng APP network interface, etc.), and calls the data stored in the memory 11 to execute various functions of the electronic device and process data.

[0132] The memory 11 includes at least one type of readable storage medium, and the readable storage medium includes flash memory, mobile hard disk, multimedia card, card-type memory (for example: SD or DX memory, etc.), magnetic memory, disk, optical disk, etc. In some embodiments, the memory 11 may be an internal storage unit of an electronic device, such as a mobile hard disk of the electronic device. In other embodiments, the memory 11 may also be an external storage device of an electronic device, such as a plug-in mobile hard disk, a smart memory card (Smart Media Card, SMC), a secure digital (Secure Digital, SD) card, a flash card (Flash Card), etc. equipped on the electronic device. Furthermore, the memory 11 may also include both an internal storage unit of the electronic device and an external storage device. The memory 11 can not only be used to store application software and various types of data installed in the electronic device, such as the code of the data transmission program encrypted based on the Hongmeng APP network interface, but also can be used to temporarily store data that has been output or is to be output.

[0133] The communication bus 12 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus may be divided into an address bus, a data bus, a control bus, etc. The bus is configured to realize connection and communication between the memory 11 and at least one processor 10, etc.

[0134] The communication interface 13 is used for communication between the above-mentioned electronic device and other devices, including a network interface and a user interface. Optionally, the network interface may include a wired interface and / or a wireless interface (such as a WI-FI interface, a Bluetooth interface, etc.), which is generally used to establish a communication connection between the electronic device and other electronic devices. The user interface may be a display (Display), an input unit (such as a keyboard (Keyboard)), and optionally, the user interface may also be a standard wired interface, a wireless interface. Optionally, in some embodiments, the display may be an LED display, a liquid crystal display, a touch-sensitive liquid crystal display, and an OLED (Organic Light-Emitting Diode, organic light-emitting diode) touch device, etc. Among them, the display may also be appropriately referred to as a display screen or a display unit, which is used to display information processed in the electronic device and to display a visual user interface.

[0135] The figure only shows an electronic device with components. Those skilled in the art will understand that the structure shown in the figure does not constitute a limitation on the electronic device, and may include fewer or more components than shown in the figure, or combine certain components, or arrange the components differently.

[0136] For example, although not shown, the electronic device may also include a power source (such as a battery) for supplying power to each component. Preferably, the power source may be logically connected to the at least one processor 10 through a power management device, so that the power management device can realize functions such as charging management, discharging management, and power consumption management. The power source may also include one or more DC or AC power sources, recharging devices, power failure detection circuits, power converters or inverters, power status indicators, and other arbitrary components. The electronic device may also include a variety of sensors, Bluetooth modules, Wi-Fi modules, etc., which will not be repeated here.

[0137] It should be understood that the embodiment is for illustration only and the scope of the patent application is not limited to this structure.

[0138] The data transmission program based on the Hongmeng APP network interface encryption stored in the memory 11 in the electronic device is a combination of multiple instructions. When running in the processor 10, it can achieve:

[0139] Constructing a service request parameter according to a preset service node, parsing the service request parameter, and obtaining a key-value pair of the service request parameter;

[0140] sorting the data objects of the service request parameters according to a preset alphabetical order and the key-value pairs, converting the sorted data objects into strings, and performing salting on the strings;

[0141] Sign the salted string and encrypt the signed string to obtain the ciphertext of the string;

[0142] Encapsulating the ciphertext of the character string into a data packet, encapsulating the data packet into a preset network transmission component, and calling the network transmission component through a preset service network request;

[0143] The data packet is transmitted to a preset service requester through the called network transmission component, and the data packet transmitted to the service requester is reversely decrypted to obtain the request transmission data corresponding to the service network request.

[0144] Specifically, the specific implementation method of the processor 10 for the above instructions can refer to the description of the relevant steps in the corresponding embodiment of the accompanying drawings, which will not be repeated here.

[0145] Furthermore, if the module / unit integrated in the electronic device is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. The computer-readable storage medium can be volatile or non-volatile. For example, the computer-readable medium may include: any entity or device capable of carrying the computer program code, a recording medium, a USB flash drive, a mobile hard disk, a magnetic disk, an optical disk, a computer memory, and a read-only memory (ROM).

[0146] The present invention further provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor of an electronic device, the computer program can implement:

[0147] Constructing a service request parameter according to a preset service node, parsing the service request parameter, and obtaining a key-value pair of the service request parameter;

[0148] sorting the data objects of the service request parameters according to a preset alphabetical order and the key-value pairs, converting the sorted data objects into strings, and performing salting on the strings;

[0149] Sign the salted string and encrypt the signed string to obtain the ciphertext of the string;

[0150] Encapsulating the ciphertext of the character string into a data packet, encapsulating the data packet into a preset network transmission component, and calling the network transmission component through a preset service network request;

[0151] The data packet is transmitted to a preset service requester through the called network transmission component, and the data packet transmitted to the service requester is reversely decrypted to obtain the request transmission data corresponding to the service network request.

[0152] In the several embodiments provided by the present invention, it should be understood that the disclosed devices, media and methods can be implemented in other ways. For example, the device embodiments described above are only illustrative, for example, the division of the modules is only a logical function division, and there may be other division methods in actual implementation.

[0153] The modules described as separate components may or may not be physically separated, and the components shown as modules may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0154] In addition, each functional module in each embodiment of the present invention may be integrated into one processing unit, each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of hardware plus software functional modules.

[0155] It is obvious to those skilled in the art that the present invention is not limited to the details of the above exemplary embodiments, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention.

[0156] Therefore, no matter from which point of view, the embodiments should be regarded as illustrative and non-restrictive, and the scope of the present invention is not limited only according to the above description, and it is intended that all changes within the meaning and scope of equivalent elements within the scope of protection are included in the present invention.

[0157] The embodiments of the present application can acquire and process relevant data based on artificial intelligence technology. Among them, artificial intelligence (AI) is the theory, method, technology and application system that uses digital computers or machines controlled by digital computers to simulate, extend and expand human intelligence, perceive the environment, acquire knowledge and use knowledge to obtain the best results.

[0158] In addition, it is clear that the word "comprising" does not exclude other units or steps, and the singular does not exclude the plural. Multiple units or devices stated in the system can also be implemented by one unit or device through software or hardware. The words first, second, etc. are used to indicate names, and do not indicate any particular order.

[0159] Finally, it should be noted that the above embodiments are only used to illustrate the technical solution of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solution of the present invention can be modified or replaced by equivalents without departing from the spirit and scope of the technical solution of the present invention.< / t> < / t> < / t>

Claims

1. A data transmission method based on Hongmeng APP network interface encryption, characterized in that: The method comprises: Constructing a service request parameter according to a preset service node, parsing the service request parameter, and obtaining a key-value pair of the service request parameter; sorting the data objects of the service request parameters according to a preset alphabetical order and the key-value pairs, converting the sorted data objects into strings, and performing salting on the strings; Sign the salted string and encrypt the signed string to obtain the string ciphertext; Encapsulating the ciphertext of the character string into a data packet, encapsulating the data packet into a preset network transmission component, and calling the network transmission component through a preset service network request; The data packet is transmitted to a preset service requester through the called network transmission component, and the data packet transmitted to the service requester is reversely decrypted to obtain the request transmission data corresponding to the service network request.

2. The data transmission method based on Hongmeng APP network interface encryption as claimed in claim 1 is characterized in that: The constructing of the service request parameters according to the preset service node includes: Extract the business data and business code corresponding to the preset business node; Determine the system data of the service request according to the service code; The service data and the system data are encapsulated as the service request parameters.

3. The data transmission method based on Hongmeng APP network interface encryption as claimed in claim 1 is characterized in that: The parsing of the service request parameters to obtain key-value pairs of the service request parameters includes: Parsing the business data in the business request parameters into business objects, and parsing the system data in the business request parameters into system objects; Encapsulate the parsed business objects and the parsed system objects as data objects of business request parameters; Extracting key-value pairs of business parameters corresponding to the business object in the data object; Extract key-value pairs of system parameters corresponding to the system object in the data object.

4. The data transmission method based on Hongmeng APP network interface encryption as claimed in claim 1 is characterized in that: The step of converting the sorted data objects into strings includes: Extract the key attributes and value attributes of the business objects in the sorted data objects one by one; Concatenate the key attribute and the value attribute of the business object into a business data string; Extract the key attributes and value attributes of the system objects in the sorted data objects one by one; The key attribute and the value attribute of the system object are concatenated into a system data string.

5. The data transmission method based on Hongmeng APP network interface encryption as claimed in claim 1 is characterized in that: The data encryption process is performed on the signed string to obtain the string ciphertext, including: Convert the data type of the signed string into an array type, and perform data compression on the string converted into the array type; Convert the pre-acquired encryption key into an array type, and use the preset symmetric key generator to convert the encryption key converted into the array type into an encryption key that complies with AES encryption; The compressed character string is encrypted using the encryption key that complies with AES encryption to obtain a ciphertext of the character string.

6. The data transmission method based on Hongmeng APP network interface encryption as claimed in claim 1 is characterized in that: The step of encapsulating the data packet into a preset network transmission component includes: Extracting component code data of a preset network transmission component; Extract the signature interface and encryption interface corresponding to the data packet; The signature interface and the encryption interface are encapsulated into the component code data to obtain an encapsulated network transmission component.

7. The data transmission method based on Hongmeng APP network interface encryption as claimed in claim 1 is characterized in that: The calling of the network transmission component through a preset service network request includes: Encapsulate all network transmission components into a preset unified interface; Dynamically matching any network transmission component in the network transmission components according to the service network request; The matched network transmission component is determined as the target network transmission component corresponding to the business network request, and the target network transmission component is called through the unified interface.

8. The data transmission method based on Hongmeng APP network interface encryption as claimed in claim 1 is characterized in that: The reverse decryption of the data packet transmitted to the service requester to obtain the request transmission data corresponding to the service network request includes: Decrypting the data packet transmitted to the service requester; Perform signature verification on the decrypted data packet; When the signature verification of the data packet is passed, the service logic is determined through the service network request; The request transmission data is extracted according to the business logic.

9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and, a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the data transmission method based on Hongmeng APP network interface encryption as described in any one of claims 1 to 8.

10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by the processor, it implements the data transmission method based on Hongmeng APP network interface encryption as described in any one of claims 1 to 8.