Data transmission and storage method and device, electronic equipment and computer readable medium

By dynamically matching the key category information of the mobile terminal and the server, the target key category information is generated, which solves the problem of low data transmission security caused by the mobile terminal using the same shared key, and achieves higher data transmission security.

CN120018122APending Publication Date: 2025-05-16HARBIN ENG UNIV
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510257217.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-05
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

The mobile terminal uses the same shared key every time the data is transmitted, which causes the attacker to obtain all the data transmitted using the key after the key is leaked, and the data transmission is less secure.

Method used

By responding to the transmission key negotiation request information sent by the mobile terminal, user authentication information is generated and key category information of the mobile terminal and the server are dynamically matched to generate target key category information, and then transmission key information is generated for encryption and decryption of data transmission.

Benefits of technology

By dynamically matching the key category information, ensuring that each data transmission uses a different key, reducing the risk of data leakage after key leakage and improving the security of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120018122A_ABST
    Figure CN120018122A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a data transmission and storage method and device, electronic equipment and a computer readable medium. A specific embodiment of the method comprises the following steps: in response to received transmission key negotiation request information sent by a mobile terminal, generating user identity verification information based on the transmission key negotiation request information; accessing a key request port of the security password card to obtain a server key category information list; performing dynamic matching processing on the mobile end key category information list and the server end key category information list to generate target key category information; generating transmission key information based on the target key category information; transmitting the transmission public key information to the mobile terminal; in response to received encrypted storage data corresponding to the transmission public key information sent by the mobile terminal, decrypting the encrypted storage data based on the transmission private key information to obtain transmission storage data; and destroying the key pair corresponding to the transmission key information. According to the embodiment, the security of data transmission is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present disclosure relate to the field of computer technology, and in particular to a data transmission and storage method, device, electronic device, and computer-readable medium. Background Art

[0002] Data transmission and storage is a technology that provides a mobile terminal (e.g., a smartphone, tablet computer, smart watch, etc.) with a transmission key for encrypting the transmission data and receiving and storing the transmission data sent by the mobile terminal. At present, the commonly used method for data transmission and storage is to configure the same shared key in advance on the mobile terminal and the data receiving terminal (e.g., the server) to transmit and store the transmission data.

[0003] However, when the above method is used to transmit and store the transmission data, the following technical problems often occur:

[0004] The mobile terminal uses the same shared key every time it transmits data. Once the mobile device is hacked and the key is leaked, the attacker can use the key to obtain all data transmitted using the key, and the security of data transmission is low.

[0005] The above information disclosed in this Background section is only for enhancement of understanding of the background of the inventive concept and therefore it may contain information that does not form the prior art that is already known to a person of ordinary skill in the art. Summary of the invention

[0006] The content of this disclosure is used to introduce concepts in a brief form, which will be described in detail in the detailed implementation section below. The content of this disclosure is not intended to identify the key features or essential features of the technical solution claimed for protection, nor is it intended to limit the scope of the technical solution claimed for protection.

[0007] Some embodiments of the present disclosure propose data transmission and storage methods, devices, electronic devices, and computer-readable media to solve one or more of the technical problems mentioned in the above background technology section.

[0008] In a first aspect, some embodiments of the present disclosure provide a data transmission and storage method, the method comprising: in response to receiving a transmission key negotiation request information sent by a mobile terminal, generating user identity authentication information based on the transmission key negotiation request information, wherein the transmission key negotiation request information includes a user identifier, a mobile terminal key category information list, and an access token information; in response to determining that the user identity authentication information indicates that the user is a legitimate user, accessing the key request port of a security password card to obtain a server-side key category information list; dynamically matching the mobile-side key category information list and the server-side key category information list to generate target key category information; generating transmission key information based on the target key category information, wherein the transmission key information includes transmission private key information and transmission public key information; storing the transmission key information; sending the transmission public key information to the mobile terminal so that the mobile terminal can encrypt and transmit the stored data; in response to receiving the encrypted storage data corresponding to the transmission public key information sent by the mobile terminal, decrypting the encrypted storage data based on the transmission private key information to obtain the transmission storage data, and storing the transmission storage data; destroying the key pair corresponding to the transmission key information.

[0009] In a second aspect, some embodiments of the present disclosure provide a data transmission and storage device, the device comprising: a first generation unit, configured to generate user identity authentication information based on the transmission key negotiation request information in response to receiving the transmission key negotiation request information sent by the mobile terminal, wherein the transmission key negotiation request information includes a user identifier, a mobile terminal key category information list, and access token information; an access unit, configured to access a key request port of a security password card in response to determining that the user identity authentication information indicates that the user is a legitimate user, so as to obtain a server-side key category information list; a second generation unit, configured to dynamically match the mobile-side key category information list and the server-side key category information list to generate a target key category information list. a third generating unit configured to generate transmission key information based on the target key category information, wherein the transmission key information includes transmission private key information and transmission public key information; a storage unit configured to store the transmission key information; a transmission unit configured to send the transmission public key information to the mobile terminal so that the mobile terminal can encrypt and transmit the stored data; a decryption processing unit configured to, in response to receiving the encrypted storage data corresponding to the transmission public key information sent by the mobile terminal, decrypt the encrypted storage data based on the transmission private key information to obtain the transmission storage data, and store the transmission storage data; a destruction unit configured to destroy the key pair corresponding to the transmission key information.

[0010] In a third aspect, some embodiments of the present disclosure provide an electronic device comprising: one or more processors; a storage device on which one or more programs are stored, and when the one or more programs are executed by the one or more processors, the one or more processors implement the method described in any implementation manner of the above-mentioned first aspect.

[0011] In a fourth aspect, some embodiments of the present disclosure provide a computer-readable medium having a computer program stored thereon, wherein when the program is executed by a processor, the method described in any implementation manner of the above-mentioned first aspect is implemented.

[0012] The above-mentioned embodiments of the present disclosure have the following beneficial effects: through the data transmission and storage methods of some embodiments of the present disclosure, the security of data transmission is improved. Specifically, the reason for the low security of data transmission is that the mobile terminal uses the same shared key every time it performs data transmission. Once the mobile terminal device is hacked and the key is leaked, the attacker can use the key to obtain all data transmitted using the key, and the security of data transmission is low. Based on this, the data transmission and storage methods of some embodiments of the present disclosure, first, in response to receiving the transmission key negotiation request information sent by the mobile terminal, based on the above-mentioned transmission key negotiation request information, generate user identity authentication information, wherein the above-mentioned transmission key negotiation request information includes user identification, mobile terminal key category information list, and access token information. Thus, the identity of the user transmitting the data can be verified to obtain the user identity authentication information, which avoids the key being arbitrarily allocated and used without authorization, and reduces the risk of key leakage. Afterwards, in response to determining that the above-mentioned user identity authentication information indicates that the user is a legitimate user, the key request port of the security password card is accessed to obtain the server key category information list. Thus, the server key category information list corresponding to each key pair of the adaptation server can be obtained. Next, the mobile terminal key category information list and the server terminal key category information list are dynamically matched to generate target key category information. Thus, the target key category information for data transmission can be matched by the mobile terminal key category information list of each key pair of the mobile terminal and the server terminal key category information list corresponding to each key pair of the server terminal. By dynamically matching to ensure that the keys corresponding to the key category information applied for each data transmission are different, the risk of data leakage in the subsequent data transmission process caused by the leakage of the key of a single data transmission is reduced, and the security of data transmission is improved. Afterwards, based on the target key category information, the transmission key information is generated, wherein the transmission key information includes the transmission private key information and the transmission public key information. Then, the transmission key information is stored. Afterwards, the transmission public key information is sent to the mobile terminal for the mobile terminal to encrypt and transmit the stored data. Thus, the transmission public key information can be sent to the mobile terminal for the mobile terminal to encrypt and transmit the stored data. Next, in response to receiving the encrypted storage data corresponding to the above-mentioned transmission public key information sent by the above-mentioned mobile terminal, the above-mentioned encrypted storage data is decrypted based on the above-mentioned transmission private key information to obtain the transmission storage data, and the above-mentioned transmission storage data is stored. In this way, the transmission storage data sent by the mobile terminal can be stored. Finally, the key pair corresponding to the above-mentioned transmission key information is destroyed. In this way, after the transmission data is stored, the key pair corresponding to the transmission key information can be destroyed to ensure that the key pair is valid once during the data transmission process.Also, in the process of data encryption transmission on the mobile terminal, the target key category information for data transmission is matched by using the mobile terminal key category information list of each key pair adapted to the mobile terminal and the server terminal key category information list corresponding to each key pair adapted to the server terminal. Dynamic matching is used to ensure that the key corresponding to the key category information applied for each data transmission is different, thereby reducing the risk of data leakage in the subsequent data transmission process caused by the leakage of a single data transmission key, and improving the security of data transmission. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] The above and other features, advantages and aspects of the embodiments of the present disclosure will become more apparent with reference to the following detailed description in conjunction with the accompanying drawings. Throughout the accompanying drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic and that components and elements are not necessarily drawn to scale.

[0014] Figure 1 is a flow chart of some embodiments of the data transmission and storage method according to the present disclosure;

[0015] Figure 2 is a schematic diagram of the structure of some embodiments of the data transmission and storage device according to the present disclosure;

[0016] Figure 3 It is a schematic diagram of the structure of an electronic device suitable for implementing some embodiments of the present disclosure. DETAILED DESCRIPTION

[0017] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as being limited to the embodiments set forth herein. On the contrary, these embodiments are provided to provide a more thorough and complete understanding of the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are only for exemplary purposes and are not intended to limit the scope of protection of the present disclosure.

[0018] It should also be noted that, for ease of description, only the parts related to the invention are shown in the drawings. In the absence of conflict, the embodiments and features in the embodiments of the present disclosure can be combined with each other.

[0019] It should be noted that the concepts such as "first" and "second" mentioned in the present disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.

[0020] It should be noted that the modifications of "one" and "plurality" mentioned in the present disclosure are illustrative rather than restrictive, and those skilled in the art should understand that unless otherwise clearly indicated in the context, it should be understood as "one or more".

[0021] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only used for illustrative purposes and are not used to limit the scope of these messages or information.

[0022] The present disclosure will be described in detail below with reference to the accompanying drawings and in conjunction with embodiments.

[0023] Figure 1 The process 100 of some embodiments of the data transmission and storage method according to the present disclosure is shown. The data transmission and storage method comprises the following steps:

[0024] Step 101: in response to receiving a transmission key negotiation request message sent by a mobile terminal, generating user identity authentication information based on the transmission key negotiation request message.

[0025] In some embodiments, the execution subject (e.g., computing device) of the data transmission and storage method may generate user identity authentication information based on the transmission key negotiation request information in response to receiving the transmission key negotiation request information sent by the mobile terminal. The transmission key negotiation request information includes a user identifier, a mobile terminal key category information list, and access token information. The execution subject may be a service end (e.g., a VPN server) that receives and stores the transmission data sent by each mobile terminal. Each of the above-mentioned mobile terminals may be a device that encrypts and transmits the stored data (e.g., a smart phone, a tablet computer, a smart watch, etc.). The user identifier may be a symbol or code for indicating the user identity. The mobile terminal key category information list may be a list containing key category information of each mobile terminal. Each mobile terminal key category information in the above-mentioned mobile terminal key category information may represent an asymmetric key pair category adapted to the above-mentioned mobile terminal. For example, the mobile terminal key category information may be an "RSA-2048 key pair". The access token information includes header information, payload information, and signature information. The header information may represent the header of the token represented by the access token information. The payload information may represent the payload of the token represented by the access token information. The above-mentioned signature information may represent the signature of the token represented by the access token information.

[0026] In some optional implementations of some embodiments, the execution subject may generate user identity authentication information based on the transmission key negotiation request information through the following steps:

[0027] The first step is to obtain the system time.

[0028] In the second step, in response to determining that the system time is within the token validity period included in the access token information, the header information and the payload information are encoded to obtain a first code corresponding to the header information and a second code corresponding to the payload information. In practice, the execution subject may perform Base64 encoding on the header information and the payload information to obtain a first code corresponding to the header information and a second code corresponding to the payload information.

[0029] The third step is to concatenate the first code and the second code to obtain a concatenated code. As an example, the first code may be "R29vZ". The second code may be "SSBsb3". The concatenated code may be "R29vZSSBsb3".

[0030] The fourth step is to encrypt the concatenated code to obtain the signature information to be verified. In practice, the execution subject can execute a preset encryption algorithm (for example, AES encryption algorithm) to encrypt the concatenated code to obtain the encrypted data as the signature information to be verified.

[0031] In step 5, in response to determining that the signature information to be verified is different from the signature information included in the access token information, the information indicating that the user is an illegal user is determined as user identity verification information. The information indicating that the user is an illegal user may be text information.

[0032] In a sixth step, in response to determining that the signature information to be verified is the same as the signature information included in the access token information, the user identifier is determined as the user identifier to be verified.

[0033] In step 7, in response to determining that the user identification to be verified is the same as a user identification in the preset user identification table, the information indicating that the user is a legitimate user is determined as user identity verification information. The information indicating that the user is a legitimate user may be text information. Each user identification in the preset user identification table may be an identification of an authorized user (i.e., a user who can store data in the server).

[0034] In the eighth step, in response to determining that the preset user identification table does not contain the same user identification as the user identification to be verified, information indicating that the user is an illegal user is determined as user identity verification information.

[0035] Step 102: in response to determining that the user identity authentication information indicates that the user is a legitimate user, access the key request port of the security password card to obtain a server-side key category information list.

[0036] In some embodiments, the above-mentioned execution subject can access the key request port of the security password card in response to determining that the above-mentioned user identity authentication information represents that the user is a legitimate user, so as to obtain the server-side key category information list. Wherein, the above-mentioned key request port can be a communication interface for key-related interaction with an external system. Wherein, the server-side key category information list can be a list containing various server-side key category information. Each server-side key category information in the above-mentioned various server-side key category information can represent an asymmetric key pair category that is adapted to the server (i.e., can be used by the server). For example, the server-side key category information can be an "RSA-2048 key pair". Wherein, the above-mentioned security password card can be a password card embedded in a device such as a server.

[0037] Step 103: Dynamically match the mobile terminal key category information list and the server terminal key category information list to generate target key category information.

[0038] In some embodiments, the execution entity may dynamically match the mobile terminal key category information list and the server terminal key category information list to generate target key category information.

[0039] In the process of adopting technical solutions to solve the problems mentioned in the background technology, the following problems are often accompanied:

[0040] The key used to encrypt the transmitted data is dynamically generated through a simple key rotation method, which is easily threatened by common attack methods such as brute force cracking and dictionary attacks, making the data transmission less secure.

[0041] In the face of the above technical problems, the inventors decided to adopt the following solutions:

[0042] In some optional implementations of some embodiments, the execution subject may dynamically match the mobile terminal key category information list and the server terminal key category information list through the following steps to generate target key category information:

[0043] The first step is to determine the intersection of the mobile terminal key category information list and the server terminal key category information list as the key category information intersection. For example, the mobile terminal key category information list can be "{mobile terminal key category information A, mobile terminal key category information E, mobile terminal key category information C, mobile terminal key category information D, mobile terminal key category information F}". The server terminal key category information list can be "{mobile terminal key category information C, mobile terminal key category information D, mobile terminal key category information B, mobile terminal key category information E, mobile terminal key category information F}". Then the key category information intersection can be {mobile terminal key category information C, mobile terminal key category information D, mobile terminal key category information E, mobile terminal key category information F}.

[0044] In the second step, for each key category information in the intersection of the key category information, determine the security level value corresponding to the key category information. The security level value may be a score for the security of the key corresponding to the key category information. The security level value may be preset manually. For example, the security level value corresponding to the mobile terminal key category information C may be 4. The security level value corresponding to the mobile terminal key category information D may be 6. The security level value corresponding to the mobile terminal key category information E may be 7. The security level value corresponding to the mobile terminal key category information F may be 8.

[0045] The third step is to sort the key category information in the intersection of the key category information based on the determined security level values ​​to obtain a reference key category information sequence. In practice, the execution subject can sort the key category information corresponding to each security level value from small to large to obtain a reference key category information sequence. For example, the reference key category information sequence can be "{mobile terminal key category information C, mobile terminal key category information D, mobile terminal key category information E, mobile terminal key category information F}".

[0046] The fourth step is to shuffle the reference key category information sequence to obtain a target reference key category information sequence. In practice, the execution subject may shuffle the reference key category information sequence using a shuffling algorithm to obtain a target reference key category information sequence. For example, the target reference key category information sequence may be "mobile terminal key category information D, mobile terminal key category information C, mobile terminal key category information E, mobile terminal key category information F".

[0047] Step 5: query the last historical key category information in the historical key category information sequence corresponding to the above user identifier. Each historical key category information in the above historical key category information sequence may be the key category information used by the user corresponding to the above user identifier when transmitting data before this time. For example, the historical key category information may be "mobile terminal key category information B".

[0048] Step 6: Determine the server-side key category information in the server-side key category information list that is the same as the historical key category information as the target server-side key category information. For example, the target server-side key category information may be "mobile-side key category information B" in the server-side key category information list (i.e., {mobile-side key category information C, mobile-side key category information D, mobile-side key category information B, mobile-side key category information E, mobile-side key category information F}).

[0049] Step 7: determine each server key category information after the target server key category information in the server key category information list as each server key category information to be screened. For example, each server key category information to be screened may be "{mobile key category information E, mobile key category information F}".

[0050] Step 8: For the first target reference key category information in the target reference key category information sequence, perform the following frequency modulation generation steps:

[0051] The first sub-step is, in response to determining that there is no server key category information to be screened that is the same as the first target reference key category information in each server key category information to be screened, and there is an intersection between the target reference key category information sequence and each server key category information to be screened, executing the following steps:

[0052] Sub-step 1: deleting the first target reference key category information from the target reference key category information sequence to update the target reference key category information sequence.

[0053] Sub-step 2: Execute the frequency modulation generation step again according to the updated target reference key category information sequence. For example, the updated target reference key category information sequence may be "{mobile terminal key category information C, mobile terminal key category information E, mobile terminal key category information F}".

[0054] The second sub-step is, in response to determining that there is server-side key category information to be screened that is the same as the first target reference key category information among the server-side key category information to be screened, determining the target reference key category information as the target key category information.

[0055] The above technical solution, combined with step 106 and its related contents as an inventive point of an embodiment of the present disclosure, solves the technical problem of "low data transmission security". The factors that lead to low data transmission security are often as follows: through a simple key rotation method, the key used to encrypt the transmitted data is dynamically generated, which is easily threatened by common attack methods such as brute force cracking and dictionary attacks, making the data transmission security low. If the above factors are solved, the effect of improving the security of data transmission can be achieved. In order to achieve this effect, first, the intersection of the above mobile terminal key category information list and the above server terminal key category information list is determined as the key category information intersection. Thus, the intersection of key category information applicable to both the mobile terminal and the server can be determined. Then, for each key category information in the above key category information intersection, the security level value corresponding to the above key category information is determined. Afterwards, based on the determined security level values, the key category information in the above key category information intersection is sorted to obtain a reference key category information sequence. Thus, a reference key category information sequence for generating a target reference key category information sequence can be obtained. Then, the reference key category information sequence is shuffled to obtain a target reference key category information sequence. Thus, a target reference key category information sequence for generating target key category information can be obtained. Next, the last historical key category information in the historical key category information sequence corresponding to the above-mentioned user identifier is queried. Thus, the historical key category information representing the user used in the most recent data transmission can be obtained. Next, the server key category information in the above-mentioned server key category information list that is identical to the above-mentioned historical key category information is determined as the target server key category information. Thus, the target server key category information can be used to generate each server key category information to be screened. Then, each server key category information in the above-mentioned server key category information list that is located after the above-mentioned target server key category information is determined as each server key category information to be screened. Thus, each server key category information to be screened can be determined based on the historical key category information used by the user in the most recent data transmission. Afterwards, for the first target reference key category information in the target reference key category information sequence, the following frequency modulation generation steps are performed: the first step, in response to determining that there is no server-side key category information to be screened that is the same as the first target reference key category information in each server-side key category information to be screened and there is an intersection between the target reference key category information sequence and each server-side key category information to be screened, the following steps are performed: the first sub-step, deleting the first target reference key category information from the target reference key category information sequence to update the target reference key category information sequence.Thus, when there is no server key category information to be screened that is the same as the first target reference key category information in each server key category information to be screened, the target reference key category information sequence is updated. In the second sub-step, the generation is performed again according to the updated target reference key category information sequence. In the second step, in response to determining that there is server key category information to be screened that is the same as the first target reference key category information in each server key category information to be screened, the target reference key category information is determined as the target key category information. Thus, the server key category information to be screened determined by the historical key category information used by the user when transmitting data most recently can be used to randomly select a target key category information suitable for both the mobile terminal and the server from a large number of key category information through the above frequency modulation generation step, so that it is difficult for an attacker to find a pattern through the analysis and statistics of previous keys, and thus it is impossible to effectively implement a targeted attack, thereby improving the security of the transmission private key and the transmission public key corresponding to the target key category information. Combined with step 106, the above transmission public key information is sent to the above mobile terminal for the above mobile terminal to encrypt and transmit the stored data. Therefore, the stored data is encrypted and transmitted through the more secure transmission public key information, thereby improving the security of the transmission data.

[0056] Step 104: Generate transmission key information based on the target key category information.

[0057] In some embodiments, the above-mentioned execution entity may generate transmission key information based on the above-mentioned target key category information. The above-mentioned transmission key information includes transmission private key information and transmission public key information. In practice, the above-mentioned execution entity may send the target key category information to a security password card (for example, a national secret encryption card) to apply for a transmission key pair. The above-mentioned transmission key information may represent a transmission key pair (i.e., a key pair for encrypting and decrypting transmission data). The above-mentioned transmission private key information may represent a key (i.e., a private key) used to decrypt encrypted transmission data. The above-mentioned transmission public key information may represent a key (i.e., a public key) used to encrypt transmission data.

[0058] Step 105: store the transmission key information.

[0059] In some embodiments, the execution entity may store the transmission key information.

[0060] In some optional implementations of some embodiments, the execution subject may store the transmission key information through the following steps:

[0061] The first step is to obtain preset encryption algorithm information and key information from a preset database. The preset encryption algorithm information includes: extended algorithm information and round function information. For example, the extended algorithm information may represent the key extension algorithm of AES. The round function information may represent the round function corresponding to the extended algorithm information for obfuscating and transforming the encrypted data. The preset database may be a MySQL database.

[0062] The second step is to generate a round key information sequence corresponding to the key information according to the extended algorithm information and key information included in the encryption algorithm information. In practice, the execution subject can expand the key corresponding to the key information by executing the key expansion algorithm corresponding to the extended algorithm information to obtain a round key information sequence. The key information can represent a preset initial key. The initial key can include individual characters. One round key information in the round key information sequence can represent a round key. The round key can be individual characters.

[0063] The third step is to determine the above transmission key information as the data to be encrypted.

[0064] Step 4: Perform the following round key encryption process based on the first round key information in the round key information sequence and the data to be encrypted:

[0065] The first sub-step is to encrypt the data to be encrypted according to the round function information and the first round key information included in the encryption algorithm information to obtain the encrypted transmission key information. The round function information can represent the round function. In practice, the execution subject can convert the data to be encrypted into byte data. Then, the execution subject can input the byte data and the round key corresponding to the first round key information into the round function to obtain the encrypted transmission key information.

[0066] The second sub-step is to remove the first round key information from the round key information sequence to update the round key information sequence.

[0067] The third sub-step, in response to determining that the round key information sequence is not empty, executes the following steps:

[0068] Sub-step one: determining the encrypted transmission key information as the data to be encrypted, so as to update the data to be encrypted.

[0069] Sub-step 2: performing the above round key encryption process again according to the updated round key information sequence and the updated data to be encrypted.

[0070] A fourth sub-step, in response to determining that the round key information sequence is empty, storing the encrypted transmission key information.

[0071] Step 106, sending the transmission public key information to the mobile terminal so that the mobile terminal can encrypt and transmit the stored data.

[0072] In some embodiments, the execution entity may send the transmission public key information to the mobile terminal so that the mobile terminal can encrypt and transmit the stored data.

[0073] In the process of adopting technical solutions to solve the problems mentioned in the background technology, the following problems are often accompanied:

[0074] Uncompressed data will occupy a large bandwidth during transmission, resulting in slower transmission speed and waste of bandwidth resources. At the same time, different types of data have different characteristics and redundancy levels. For example, text data may contain a large number of repeated words and sentence structures, image data may contain large areas of similar colors, and video data may have temporal and spatial redundancy. If a single compression method is used, it may not be possible to fully utilize the characteristics of the data for efficient compression, resulting in a large amount of compressed transmission and storage data, and a large bandwidth will still be occupied during transmission, resulting in a waste of bandwidth resources.

[0075] In the face of the above technical problems, the inventors decided to adopt the following solutions:

[0076] In some optional implementations of some embodiments, the mobile terminal may encrypt and transmit the stored data through the following steps:

[0077] The first step is to determine the above-mentioned stored data as the stored data to be compressed.

[0078] The second step is to perform data feature extraction processing on the above-mentioned data to be compressed and stored, and obtain the feature information of the data to be compressed corresponding to the above-mentioned data to be compressed and stored. In practice, the above-mentioned execution subject can perform data feature extraction processing on the above-mentioned data to be compressed and stored through feature engineering technology to obtain the feature information of the data to be compressed. Among them, the above-mentioned feature information of the data to be compressed can represent the data features of the above-mentioned data to be compressed and stored. For example, the above-mentioned feature information of the data to be compressed can be "the data type is text data, and the data distribution is uniform distribution".

[0079] In the third step, the feature information of the data to be compressed is input into the input layer of the pre-trained adaptive data compression model to obtain the feature vector of the data to be compressed corresponding to the feature information of the data to be compressed. The adaptive data compression model includes the input layer, the compression algorithm matching layer and the encoder layer. The adaptive data compression model can be a neural network model for compressing data. The neural network model can be an auto-encoder model. The feature vector of the data to be compressed can be a feature vector representing the feature information of the data to be compressed.

[0080] In the fourth step, the feature vector of the data to be compressed is input into the compression algorithm matching layer to obtain compression algorithm information corresponding to the feature vector of the data to be compressed. The compression algorithm matching layer may be an artificial neural network (ANN). The compression algorithm information may be information of the compression algorithm corresponding to the data to be compressed and stored.

[0081] The fifth step is to input the compression algorithm information and the data to be compressed and stored into the encoder layer to obtain compressed coded data. The compressed coded data may be compressed data obtained by compressing the data to be compressed and stored according to the compression algorithm information.

[0082] The sixth step is to determine the compression algorithm information and the compressed coded data as the transmission storage data.

[0083] Step 7: Based on the above-mentioned transmission public key information, encrypt the above-mentioned transmission storage data to obtain encrypted storage data, and transmit the above-mentioned encrypted storage data. In practice, the above-mentioned mobile terminal can use a preset encryption algorithm to encrypt the transmission storage data based on the public key corresponding to the above-mentioned transmission public key information to obtain encrypted storage data. The above-mentioned encrypted storage data can be the data obtained after encrypting the transmission storage data.

[0084] The above technical solution and its related contents, as an inventive point of the embodiment of the present disclosure, solve the technical problem of "waste of bandwidth resources". The factors that lead to the waste of bandwidth resources are often as follows: uncompressed data will occupy a large bandwidth during the transmission process, resulting in a slow transmission speed and a waste of bandwidth resources. At the same time, different types of data have different characteristics and redundancy. For example, text data may have a large number of repeated words and sentence structures, image data may have large areas of similar colors, and video data has temporal and spatial redundancy. If a single compression method is used, it may not be possible to fully utilize the characteristics of the data for efficient compression, resulting in a large amount of data after compression. The transmission storage data will still occupy a large bandwidth during the transmission process, resulting in a waste of bandwidth resources. If the above factors are solved, the effect of reducing the waste of bandwidth resources can be achieved. In order to achieve this effect, first, the above storage data is determined as the storage data to be compressed. Then, the data feature extraction process is performed on the above storage data to be compressed to obtain the feature information of the data to be compressed corresponding to the above storage data to be compressed. Thus, the feature information of the data to be compressed that characterizes the data features of the storage data to be compressed can be obtained. Afterwards, the feature information of the data to be compressed is input into the input layer of the adaptive data compression model to obtain the feature vector of the data to be compressed corresponding to the feature information of the data to be compressed. Among them, the adaptive data compression model includes the input layer, the compression algorithm matching layer and the encoder layer. Then, the feature vector of the data to be compressed is input into the compression algorithm matching layer to obtain the compression algorithm information corresponding to the feature vector of the data to be compressed. Thus, the compression algorithm information applicable to the data characteristics of the data to be compressed and stored can be obtained. Then, the compression algorithm information and the data to be compressed and stored are input into the encoder layer to obtain the compressed coded data. Thus, the compressed and stored data can be compressed by the compression algorithm information applicable to the data to be compressed and stored. Then, the compression algorithm information and the compressed coded data are determined as the transmission and storage data. Finally, based on the transmission public key information, the transmission and storage data are encrypted to obtain the encrypted storage data, and the encrypted storage data is transmitted. Also because the adaptive data compression model is used to efficiently compress the compressed and stored data by utilizing the characteristics of the data to be compressed and stored, the amount of data to be compressed and stored is reduced. Furthermore, the amount of encrypted storage data transmitted is reduced, the occupation of network bandwidth is reduced, and the waste of bandwidth resources is reduced.

[0085] Step 107, in response to receiving the encrypted storage data corresponding to the transmission public key information sent by the mobile terminal, decrypting the encrypted storage data based on the transmission private key information to obtain the transmission storage data, and storing the transmission storage data.

[0086] In some embodiments, the execution subject may, in response to receiving the encrypted storage data corresponding to the transmission public key information sent by the mobile terminal, decrypt the encrypted storage data based on the transmission private key information to obtain the transmission storage data, and store the transmission storage data. In practice, the execution subject may decrypt the encrypted storage data based on the private key corresponding to the transmission private key information through a preset decryption algorithm to obtain the transmission storage data.

[0087] Step 108: destroy the key pair corresponding to the transmission key information.

[0088] In some embodiments, the execution subject may destroy the key pair corresponding to the transmission key information. In practice, the execution subject may destroy the key pair corresponding to the transmission key information by physical destruction, encryption destruction, logical destruction, etc.

[0089] The above-mentioned embodiments of the present disclosure have the following beneficial effects: through the data transmission and storage methods of some embodiments of the present disclosure, the security of data transmission is improved. Specifically, the reason for the low security of data transmission is that the mobile terminal uses the same shared key every time it performs data transmission. Once the mobile terminal device is hacked and the key is leaked, the attacker can use the key to obtain all data transmitted using the key, and the security of data transmission is low. Based on this, the data transmission and storage methods of some embodiments of the present disclosure, first, in response to receiving the transmission key negotiation request information sent by the mobile terminal, based on the above-mentioned transmission key negotiation request information, generate user identity authentication information, wherein the above-mentioned transmission key negotiation request information includes user identification, mobile terminal key category information list, and access token information. Thus, the identity of the user transmitting the data can be verified to obtain the user identity authentication information, which avoids the key being arbitrarily allocated and used without authorization, and reduces the risk of key leakage. Afterwards, in response to determining that the above-mentioned user identity authentication information indicates that the user is a legitimate user, the key request port of the security password card is accessed to obtain the server key category information list. Thus, the server key category information list corresponding to each key pair of the adaptation server can be obtained. Next, the mobile terminal key category information list and the server terminal key category information list are dynamically matched to generate target key category information. Thus, the target key category information for data transmission can be matched by the mobile terminal key category information list of each key pair of the mobile terminal and the server terminal key category information list corresponding to each key pair of the server terminal. By dynamically matching to ensure that the keys corresponding to the key category information applied for each data transmission are different, the risk of data leakage in the subsequent data transmission process caused by the leakage of the key of a single data transmission is reduced, and the security of data transmission is improved. Afterwards, based on the target key category information, the transmission key information is generated, wherein the transmission key information includes the transmission private key information and the transmission public key information. Then, the transmission key information is stored. Afterwards, the transmission public key information is sent to the mobile terminal for the mobile terminal to encrypt and transmit the stored data. Thus, the transmission public key information can be sent to the mobile terminal for the mobile terminal to encrypt and transmit the stored data. Next, in response to receiving the encrypted storage data corresponding to the above-mentioned transmission public key information sent by the above-mentioned mobile terminal, the above-mentioned encrypted storage data is decrypted based on the above-mentioned transmission private key information to obtain the transmission storage data, and the above-mentioned transmission storage data is stored. In this way, the transmission storage data sent by the mobile terminal can be stored. Finally, the key pair corresponding to the above-mentioned transmission key information is destroyed. In this way, after the transmission data is stored, the key pair corresponding to the transmission key information can be destroyed to ensure that the key pair is valid once during the data transmission process.Also, in the process of data encryption transmission on the mobile terminal, the target key category information for data transmission is matched by using the mobile terminal key category information list of each key pair adapted to the mobile terminal and the server terminal key category information list corresponding to each key pair adapted to the server terminal. Dynamic matching is used to ensure that the key corresponding to the key category information applied for each data transmission is different, thereby reducing the risk of data leakage in the subsequent data transmission process caused by the leakage of a single data transmission key, and improving the security of data transmission.

[0090] Further references Figure 2 As an implementation of the methods shown in the figures, the present disclosure provides some embodiments of a data transmission and storage device, and these device embodiments are Figure 1 Corresponding to the method embodiments shown, the device can be specifically applied to various electronic devices.

[0091] like Figure 2 As shown, the data transmission and storage device 200 of some embodiments includes: a first generation unit 201, an access unit 202, a second generation unit 203, a third generation unit 204, a storage unit 205, a transmission unit 206, a decryption processing unit 207 and a destruction unit 208. The first generation unit 201 is configured to generate user identity authentication information based on the transmission key negotiation request information in response to receiving the transmission key negotiation request information sent by the mobile terminal, wherein the transmission key negotiation request information includes a user identifier, a mobile terminal key category information list, and access token information; the access unit 202 is configured to access the key request port of the security password card in response to determining that the user identity authentication information represents that the user is a legitimate user, so as to obtain the server-side key category information list; the second generation unit 203 is configured to dynamically match the mobile-side key category information list and the server-side key category information list to generate target key category information; the third generation unit 204 ... It is configured to generate transmission key information based on the above-mentioned target key category information, wherein the above-mentioned transmission key information includes transmission private key information and transmission public key information; the storage unit 205 is configured to store the above-mentioned transmission key information; the transmission unit 206 is configured to send the above-mentioned transmission public key information to the above-mentioned mobile terminal, so that the above-mentioned mobile terminal can encrypt and transmit the stored data; the decryption processing unit 207 is configured to respond to receiving the encrypted storage data corresponding to the above-mentioned transmission public key information sent by the above-mentioned mobile terminal, decrypt the above-mentioned encrypted storage data based on the above-mentioned transmission private key information, obtain the transmission storage data, and store the above-mentioned transmission storage data; the destruction unit 208 is configured to destroy the key pair corresponding to the above-mentioned transmission key information.

[0092] It is understood that the units described in the device 200 are similar to those described in the reference Figure 1Therefore, the operations, features and beneficial effects described above for the method are also applicable to the device 200 and the units contained therein, and will not be described in detail here.

[0093] Reference below Figure 3 , which shows a structural schematic diagram of an electronic device 300 suitable for implementing some embodiments of the present disclosure. Figure 3 The electronic device shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present disclosure.

[0094] like Figure 3 As shown, the electronic device 300 may include a processing device (e.g., a central processing unit, a graphics processing unit, etc.) 301, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 302 or a program loaded from a storage device 308 into a random access memory (RAM) 303. In the RAM 303, various programs and data required for the operation of the electronic device 300 are also stored. The processing device 301, the ROM 302, and the RAM 303 are connected to each other via a bus 304. An input / output (I / O) interface 305 is also connected to the bus 304.

[0095] Typically, the following devices may be connected to the I / O interface 305: input devices 306 including, for example, a touch screen, a touch pad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; output devices 307 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; storage devices 308 including, for example, a magnetic tape, a hard disk, etc.; and communication devices 309. The communication devices 309 may allow the electronic device 300 to communicate with other devices wirelessly or by wire to exchange data. Although Figure 3 The electronic device 300 is shown with various devices, but it should be understood that it is not required to implement or possess all the devices shown. More or fewer devices may be implemented or possessed instead. Figure 3 Each block shown in the figure may represent one device, or may represent multiple devices as required.

[0096] In particular, according to some embodiments of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program. For example, some embodiments of the present disclosure include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a program code for executing the method shown in the flowchart. In some such embodiments, the computer program can be downloaded and installed from the network through the communication device 309, or installed from the storage device 308, or installed from the ROM 302. When the computer program is executed by the processing device 301, the functions defined in the method of some embodiments of the present disclosure are executed.

[0097] It should be noted that the computer-readable medium recorded in some embodiments of the present disclosure may be a computer-readable signal medium or a computer-readable storage medium or any combination of the two. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In some embodiments of the present disclosure, a computer-readable storage medium may be any tangible medium containing or storing a program that may be used by or in conjunction with an instruction execution system, device or device. In some embodiments of the present disclosure, a computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, in which a computer-readable program code is carried. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. The computer readable signal medium may also be any computer readable medium other than a computer readable storage medium, which may send, propagate or transmit a program for use by or in conjunction with an instruction execution system, apparatus or device. The program code contained on the computer readable medium may be transmitted using any suitable medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination thereof.

[0098] In some embodiments, the client and the server may communicate using any currently known or future developed network protocol such as HTTP (HyperText Transfer Protocol), and may be interconnected with any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network ("LAN"), a wide area network ("WAN"), an internet (e.g., the Internet), and a peer-to-peer network (e.g., an ad hoc peer-to-peer network), as well as any currently known or future developed network.

[0099] The computer-readable medium may be included in the electronic device; or may exist separately without being incorporated into the electronic device. The computer-readable medium carries one or more programs. When the one or more programs are executed by the electronic device, the electronic device: in response to receiving a transmission key negotiation request information sent by a mobile terminal, based on the transmission key negotiation request information, generates user identity authentication information, wherein the transmission key negotiation request information includes a user identifier, a mobile terminal key category information list, and access token information; in response to determining that the user identity authentication information indicates that the user is a legitimate user, accesses the key request port of the security password card to obtain a server key category information list; dynamically matches the mobile terminal key category information list and the server key category information list to generate target key category information; based on the target key category information, generates transmission key information, wherein the transmission key information includes transmission private key information and transmission public key information; stores the transmission key information; sends the transmission public key information to the mobile terminal so that the mobile terminal can encrypt and transmit the stored data; in response to receiving the encrypted storage data corresponding to the transmission public key information sent by the mobile terminal, decrypts the encrypted storage data based on the transmission private key information to obtain the transmission storage data, and stores the transmission storage data; and destroys the key pair corresponding to the transmission key information.

[0100] Computer program code for performing the operations of some embodiments of the present disclosure may be written in one or more programming languages ​​or a combination thereof, including object-oriented programming languages, such as Java, Smalltalk, C++, and conventional procedural programming languages, such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0101] The flow chart and block diagram in the accompanying drawings illustrate the possible architecture, function and operation of the system, method and computer program product according to various embodiments of the present disclosure. In this regard, each square box in the flow chart or block diagram can represent a module, a program segment or a part of a code, and the module, the program segment or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some implementations as replacements, the functions marked in the square box can also occur in a sequence different from that marked in the accompanying drawings. For example, two square boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each square box in the block diagram and / or flow chart, and the combination of the square boxes in the block diagram and / or flow chart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0102] The units described in some embodiments of the present disclosure may be implemented by software or by hardware. The units described may also be provided in a processor, for example, may be described as: a processor including a first generation unit, an access unit, a second generation unit, a third generation unit, a storage unit, a transmission unit, a decryption processing unit, and a destruction unit. The names of these units do not, in some cases, constitute limitations on the units themselves, for example, a storage unit may also be described as a "unit for storing the above-mentioned transmission key information".

[0103] The functions described above herein may be performed at least in part by one or more hardware logic components. For example, without limitation, exemplary types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), complex programmable logic devices (CPLDs), and the like.

[0104] The above descriptions are only some preferred embodiments of the present disclosure and an explanation of the technical principles used. Those skilled in the art should understand that the scope of the invention involved in the embodiments of the present disclosure is not limited to the technical solutions formed by a specific combination of technical features, but should also cover other technical solutions formed by any combination of technical features or their equivalent features without departing from the inventive concept. For example, a technical solution formed by replacing the features with (but not limited to) the technical features with similar functions disclosed in the embodiments of the present disclosure.

Claims

1. A data transmission and storage method, comprising: In response to receiving a transmission key negotiation request message sent by the mobile terminal, generating user identity authentication information based on the transmission key negotiation request message, wherein the transmission key negotiation request message includes a user identifier, a mobile terminal key category information list, and access token information; In response to determining that the user identity authentication information indicates that the user is a legitimate user, accessing a key request port of the security password card to obtain a server-side key category information list; Dynamically matching the mobile terminal key category information list and the server terminal key category information list to generate target key category information; Based on the target key category information, generating transmission key information, wherein the transmission key information includes transmission private key information and transmission public key information; storing the transmission key information; Sending the transmission public key information to the mobile terminal so that the mobile terminal can encrypt and transmit the stored data; In response to receiving the encrypted storage data corresponding to the transmission public key information sent by the mobile terminal, decrypting the encrypted storage data based on the transmission private key information to obtain the transmission storage data, and storing the transmission storage data; Destroy the key pair corresponding to the transmission key information.

2. The method according to claim 1, wherein: The step of generating transmission key information based on the target key category information includes: The target key category information is sent to the security password card to obtain transmission key information corresponding to the target key category information from the security password card.

3. The method according to claim 1, wherein: The decrypting the encrypted storage data based on the transmission private key information to obtain the transmission storage data includes: Acquire decryption algorithm information corresponding to the transmission private key information from a preset database; Based on the decryption algorithm information and the transmission private key information, a decryption operation is performed on the encrypted storage data to obtain the transmission storage data after the decryption operation.

4. The method according to claim 1, wherein: The access token information includes header information, payload information, and signature information, and the payload information includes the token validity period; And the generating user identity authentication information based on the transmission key negotiation request information includes: Get system time; In response to determining that the system time is within the token validity period included in the access token information, encoding the header information and the payload information to obtain a first code corresponding to the header information and a second code corresponding to the payload information; concatenating the first code and the second code to obtain a concatenated code; Encrypting the concatenated code to obtain signature information to be verified; In response to determining that the signature information to be verified is different from the signature information included in the access token information, determining information indicating that the user is an illegal user as user identity verification information; In response to determining that the signature information to be verified is the same as the signature information included in the access token information, determining the user identifier as the user identifier to be verified; In response to determining that the to-be-verified user identifier is identical to a user identifier in a preset user identifier table, determining information indicating that the user is a legitimate user as user identity verification information; In response to determining that the preset user identification table does not contain the same user identification as the user identification to be verified, information indicating that the user is an illegal user is determined as user identity verification information.

5. The method according to claim 1, wherein: The storing of the transmission key information comprises: Acquire preset encryption algorithm information and key information from a preset database, wherein the preset encryption algorithm information includes: extended algorithm information and round function information; Generate a round key information sequence corresponding to the key information according to the extended algorithm information and key information included in the encryption algorithm information; Determining the transmission key information as data to be encrypted; According to the first round key information in the round key information sequence and the data to be encrypted, the following round key encryption process is performed: According to the round function information and the first round key information included in the encryption algorithm information, the data to be encrypted is encrypted to obtain the encrypted transmission key information; Removing the first round key information from the round key information sequence to update the round key information sequence; In response to determining that the round key information sequence is not empty, performing the following steps: Determine the encrypted transmission key information as the data to be encrypted, so as to update the data to be encrypted; Execute the round key encryption process again according to the updated round key information sequence and the updated data to be encrypted; In response to determining that the round key information sequence is empty, the encrypted transmission key information is stored.

6. A data transmission and storage device, comprising: A first generating unit is configured to generate user identity authentication information based on the transmission key negotiation request information in response to receiving the transmission key negotiation request information sent by the mobile terminal, wherein the transmission key negotiation request information includes a user identifier, a mobile terminal key category information list, and access token information; An access unit is configured to access a key request port of a security password card to obtain a server-side key category information list in response to determining that the user identity authentication information indicates that the user is a legitimate user; a second generating unit, configured to dynamically match the mobile terminal key category information list and the server terminal key category information list to generate target key category information; a third generating unit, configured to generate transmission key information based on the target key category information, wherein the transmission key information includes transmission private key information and transmission public key information; A storage unit, configured to store the transmission key information; A transmission unit, configured to send the transmission public key information to the mobile terminal, so that the mobile terminal can encrypt and transmit the stored data; a decryption processing unit, configured to, in response to receiving the encrypted storage data corresponding to the transmission public key information sent by the mobile terminal, decrypt the encrypted storage data based on the transmission private key information to obtain the transmission storage data, and store the transmission storage data; The destroying unit is configured to destroy the key pair corresponding to the transmission key information.

7. An electronic device comprising: one or more processors; a storage device having one or more programs stored thereon; When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 5.

8. A computer readable medium having a computer program stored thereon, wherein: When the program is executed by a processor, the method according to any one of claims 1 to 5 is implemented.

Citation Information

Patent Citations

  • Front-end encryption method and device, electronic equipment and storage medium

    CN117951720A

  • Data transmission method and device, equipment and storage medium

    CN118944884A

  • Data encryption transmission method and system

    CN119051878A