Data processing method and device, computer equipment and storage medium
By using the encryption and decryption platform in the DC applet to generate session keys and encrypt and decrypt plaintext data, the sensitive data leakage caused by plaintext transmission in the DC applet is solved, and the security of data transmission is achieved.
Patent Information
- Application Number
- CN202411995838.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-31
- Publication Date
- 2025-05-27
AI Technical Summary
In DC applets, business data flows from DC applets to DC SDKs and the internal transmission of DC SDKs is in plain text transmission, resulting in security risks of leaking sensitive user data.
By sending the session identifier and application identifier corresponding to the pending plaintext data to the encryption and decryption platform, a first session key is generated, and the plaintext data is encrypted and decrypted based on the key to ensure the security of the data during transmission.
Effectively prevent the leakage of sensitive user data during transmission, improve the security of data transmission, and is suitable for use scenarios of DC terminals or third-party DC servers.
Smart Images

Figure CN120050063A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of wireless communication technologies, and in particular, to a data processing method, apparatus, computer device, and storage medium. Background Art
[0002] With the strong promotion and development of the operator's enhanced call service, the development of business applets based on DC (Data Channel) has become increasingly rich, and the usage scenarios have become more extensive. Among them, DC is the infrastructure for enhanced calls built by the operator. This technology consists of a terminal supporting a DC chip, a DC applet, a DC (Software Development Kit) SDK, an IMS (IP Multimedia Subsystem) DC network, and DC network elements.
[0003] However, the business data is transmitted in plain text when flowing from the DC applet to the DC SDK and within the DC SDK, which also leads to potential security risks of leakage of some sensitive user data. Summary of the Invention
[0004] Based on this, it is necessary to provide a data processing method, apparatus, computer device, and storage medium that can prevent potential security risks of leakage of sensitive user data for the above technical problems.
[0005] In a first aspect, this application provides a data processing method, which is applied to a data request end. The method includes:
[0006] Sending a session identifier and an application identifier corresponding to the plaintext data to be processed to an encryption and decryption platform, so that the encryption and decryption platform generates a first session key according to the session identifier and the application identifier;
[0007] Encrypting the plaintext data to be processed according to the first session key fed back by the encryption and decryption platform to obtain encrypted data to be processed;
[0008] Sending the encrypted data to be processed and the session identifier to a data response end, so that the data response end decrypts the encrypted data to be processed using the first session key obtained from the encryption and decryption platform based on the session identifier to obtain the plaintext data to be processed, and processes the plaintext data to be processed to obtain response plaintext data;
[0009] Receiving the response ciphertext data sent by the data response end, and decrypting the response ciphertext data to obtain the response plaintext data; where the response ciphertext data is encrypted by the data response end for the response plaintext data.
[0010] In one embodiment, sending the session identifier and the application identifier corresponding to the plaintext data to be processed to the encryption and decryption platform includes:
[0011] Using the first public key to encrypt the session identifier and the application identifier to obtain a first ciphertext identifier;
[0012] Sending the first ciphertext identifier and the first user identifier corresponding to the data request end to the encryption and decryption platform, so that the encryption and decryption platform obtains the first private key according to the first user identifier, and uses the first private key to decrypt the first ciphertext identifier to obtain the session identifier and the application identifier.
[0013] In one embodiment, the first public key is generated by the encryption and decryption platform after determining that the data request end has opened a communication service and obtaining the first user identifier of the data request end.
[0014] In one embodiment, encrypting the plaintext data to be processed according to the first session key fed back by the encryption and decryption platform to obtain encrypted data to be processed includes:
[0015] Receiving the first session key fed back by the encryption and decryption platform; wherein, the first session key has been signed by the encryption and decryption platform using the first private key;
[0016] In the case where the verification signature of the first session key using the first public key passes, encrypt the plaintext data to be processed according to the first session key to obtain encrypted data to be processed.
[0017] In one embodiment, the first session key is fed back by the encryption and decryption platform to the data response end after the data response end sends the session identifier, the second ciphertext identifier, and the second user identifier of the data response end to the encryption and decryption platform, and the encryption and decryption platform determines that the session identifier sent by the data response end is the same as the session identifier sent by the data request end, and according to the second ciphertext identifier and the second user identifier;
[0018] Wherein, the second ciphertext identifier is obtained by the data response end encrypting the first user identifier and the application identifier using the second public key; the second public key is generated by the encryption and decryption platform after determining that the data response end has opened a communication service and obtaining the second user identifier of the data response end.
[0019] In one embodiment, decrypting the response ciphertext data to obtain the response plaintext data includes:
[0020] Receive the session identifier sent by the data response end, and when the session identifier sent by the data response end is consistent with the session identifier of the data request end, decrypt the response ciphertext data into the response plaintext data based on the first session key; wherein, the response ciphertext data is obtained by the data response end encrypting the response plaintext data with the first session key.
[0021] In one embodiment, decrypting the response ciphertext data to obtain the response plaintext data includes:
[0022] Receive the session identifier sent by the data response end, and when the session identifier sent by the data response end is inconsistent with the session identifier of the data request end, encrypt the second user identifier of the data response end and the application identifier according to the first public key to obtain a third ciphertext identifier;
[0023] Send the third ciphertext identifier and the session identifier sent by the data response end to the encryption and decryption platform, so that when the encryption and decryption platform determines that the session identifier sent by the data response end is inconsistent with the session identifier sent by the data request end, decrypt the third ciphertext identifier into the second user identifier and the application identifier according to the first private key corresponding to the first public key, and generate a second session key according to the session identifier sent by the data response end, the second user identifier and the application identifier;
[0024] Receive the second session key fed back by the encryption and decryption platform, and decrypt the response ciphertext data into the response plaintext data based on the second session key; wherein, the response ciphertext data is obtained by the data response end encrypting the response plaintext data with the second session key.
[0025] In a first aspect, the present application provides a data processing method applied to a data response end, and the method includes:
[0026] Receive the encrypted data to be processed and the session identifier sent by the data request end; wherein, the encrypted data to be processed is obtained by the data request end encrypting the plaintext data to be processed with the first session key, and the first session ciphertext is generated by the encryption and decryption platform according to the session identifier and the application identifier corresponding to the plaintext data to be processed;
[0027] Based on the session identifier, obtain the first session key from the encryption and decryption platform;
[0028] Use the first session key to decrypt the encrypted data to be processed to obtain the plaintext data to be processed;
[0029] Perform data processing on the plaintext data to be processed to obtain response plaintext data;
[0030] Encrypt the response plaintext data to obtain response ciphertext data, and feedback the response ciphertext data to the data request end, so that the data request end decrypts the response ciphertext data to obtain the response plaintext data.
[0031] In one embodiment, the encrypting the response plaintext data to obtain response ciphertext data includes:
[0032] Use the first session key to encrypt the response plaintext data to obtain response ciphertext data.
[0033] In one embodiment, the encrypting the response plaintext data to obtain response ciphertext data includes:
[0034] Send the session identifier, the second user identifier, and the application identifier to the encryption and decryption platform; so that the encryption and decryption platform generates a second session key according to the session identifier, the second user identifier, and the application identifier;
[0035] Receive the second session key fed back by the encryption and decryption platform, and use the second session key to encrypt the response plaintext data to obtain response ciphertext data.
[0036] In a third aspect, the present application further provides a data processing device, configured at a data request end, the device includes:
[0037] A first sending module, configured to send a session identifier and an application identifier corresponding to the plaintext data to be processed to an encryption and decryption platform, so that the encryption and decryption platform generates a first session key according to the session identifier and the application identifier;
[0038] An encryption module, configured to encrypt the plaintext data to be processed according to the first session key fed back by the encryption and decryption platform to obtain encrypted data to be processed;
[0039] A second sending module, configured to send the encrypted data to be processed and the session identifier to a data response end, so that the data response end decrypts the encrypted data to be processed using the first session key obtained from the encryption and decryption platform based on the session identifier to obtain the plaintext data to be processed, and perform data processing on the plaintext data to be processed to obtain response plaintext data;
[0040] A first receiving module, configured to receive the response ciphertext data sent by the data response end, and decrypt the response ciphertext data to obtain the response plaintext data; wherein, the response ciphertext data is obtained by encrypting the response plaintext data by the data response end.
[0041] Fourthly, the present application also provides a data processing device, which is configured at the data response end. The device includes:
[0042] A second receiving module, configured to receive the encrypted data to be processed and a session identifier sent by the data request end; wherein, the encrypted data to be processed is obtained by the data request end encrypting the plaintext data to be processed with a first session key, and the first session ciphertext is generated by the encryption and decryption platform according to the session identifier and the application identifier corresponding to the plaintext data to be processed;
[0043] An obtaining module, configured to obtain the first session key from the encryption and decryption platform based on the session identifier;
[0044] A decryption module, configured to decrypt the encrypted data to be processed with the first session key to obtain the plaintext data to be processed;
[0045] A processing module, configured to perform data processing on the plaintext data to be processed to obtain response plaintext data;
[0046] A feedback module, configured to encrypt the response plaintext data to obtain response ciphertext data, and feedback the response ciphertext data to the data request end, so that the data request end decrypts the response ciphertext data to obtain the response plaintext data.
[0047] Fifthly, the present application also provides a computer device. The computer device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:
[0048] Send the session identifier and the application identifier corresponding to the plaintext data to be processed to the encryption and decryption platform, so that the encryption and decryption platform generates a first session key according to the session identifier and the application identifier;
[0049] Encrypt the plaintext data to be processed according to the first session key fed back by the encryption and decryption platform to obtain the encrypted data to be processed;
[0050] Send the encrypted data to be processed and the session identifier to the data response end, so that the data response end decrypts the encrypted data to be processed with the first session key obtained from the encryption and decryption platform based on the session identifier to obtain the plaintext data to be processed, and performs data processing on the plaintext data to be processed to obtain response plaintext data;
[0051] Receive the response ciphertext data sent by the data response end, and decrypt the response ciphertext data to obtain the response plaintext data; wherein, the response ciphertext data is obtained by encrypting the response plaintext data by the data response end.
[0052] In a sixth aspect, the present application further provides a computer device. The computer device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:
[0053] Receive the encrypted data to be processed and the session identifier sent by the data request end; wherein, the encrypted data to be processed is obtained by encrypting the plaintext data to be processed by the data request end using a first session key, and the first session ciphertext is generated by the encryption and decryption platform according to the session identifier and the application identifier corresponding to the plaintext data to be processed;
[0054] Based on the session identifier, obtain the first session key from the encryption and decryption platform;
[0055] Use the first session key to decrypt the encrypted data to be processed to obtain the plaintext data to be processed;
[0056] Perform data processing on the plaintext data to be processed to obtain response plaintext data;
[0057] Encrypt the response plaintext data to obtain response ciphertext data, and feedback the response ciphertext data to the data request end, so that the data request end decrypts the response ciphertext data to obtain the response plaintext data.
[0058] In a seventh aspect, the present application further provides a computer-readable storage medium. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the following steps are implemented:
[0059] Send the session identifier and the application identifier corresponding to the plaintext data to be processed to the encryption and decryption platform, so that the encryption and decryption platform generates a first session key according to the session identifier and the application identifier;
[0060] Encrypt the plaintext data to be processed according to the first session key fed back by the encryption and decryption platform to obtain encrypted data to be processed;
[0061] Send the encrypted data to be processed and the session identifier to the data response end, so that the data response end uses the first session key obtained from the encryption and decryption platform based on the session identifier to decrypt the encrypted data to be processed to obtain the plaintext data to be processed, and perform data processing on the plaintext data to be processed to obtain response plaintext data;
[0062] Receive the response ciphertext data sent by the data response end, and decrypt the response ciphertext data to obtain the response plaintext data; wherein, the response ciphertext data is obtained by encrypting the response plaintext data by the data response end.
[0063] In an eighth aspect, the present application further provides a computer-readable storage medium. The computer-readable storage medium stores a computer program thereon, and when the computer program is executed by a processor, the following steps are implemented:
[0064] Receive the to-be-processed encrypted data and the session identifier sent by the data request end; wherein, the to-be-processed encrypted data is obtained by encrypting the to-be-processed plaintext data by the data request end using a first session key, and the first session ciphertext is generated by the encryption and decryption platform according to the session identifier and the application identifier corresponding to the to-be-processed plaintext data;
[0065] Based on the session identifier, obtain the first session key from the encryption and decryption platform;
[0066] Use the first session key to decrypt the to-be-processed encrypted data to obtain the to-be-processed plaintext data;
[0067] Perform data processing on the to-be-processed plaintext data to obtain response plaintext data;
[0068] Encrypt the response plaintext data to obtain response ciphertext data, and feedback the response ciphertext data to the data request end, so that the data request end decrypts the response ciphertext data to obtain the response plaintext data.
[0069] In a ninth aspect, the present application further provides a computer program product. The computer program product includes a computer program, and when the computer program is executed by a processor, the following steps are implemented:
[0070] Send the session identifier and the application identifier corresponding to the to-be-processed plaintext data to the encryption and decryption platform, so that the encryption and decryption platform generates a first session key according to the session identifier and the application identifier;
[0071] According to the first session key fed back by the encryption and decryption platform, encrypt the to-be-processed plaintext data to obtain to-be-processed encrypted data;
[0072] Send the to-be-processed encrypted data and the session identifier to the data response end, so that the data response end uses the first session key obtained from the encryption and decryption platform based on the session identifier to decrypt the to-be-processed encrypted data to obtain the to-be-processed plaintext data, and perform data processing on the to-be-processed plaintext data to obtain response plaintext data;
[0073] Receive the response ciphertext data sent by the data response end, and decrypt the response ciphertext data to obtain the response plaintext data; wherein, the response ciphertext data is obtained by the data response end encrypting the response plaintext data.
[0074] In a tenth aspect, the present application further provides a computer program product. The computer program product includes a computer program, and when the computer program is executed by a processor, the following steps are implemented:
[0075] Receive the encrypted data to be processed and the session identifier sent by the data request end; wherein, the encrypted data to be processed is obtained by the data request end encrypting the plaintext data to be processed using a first session key, and the first session ciphertext is generated by the encryption and decryption platform according to the session identifier and application identifier corresponding to the plaintext data to be processed;
[0076] Based on the session identifier, obtain the first session key from the encryption and decryption platform;
[0077] Use the first session key to decrypt the encrypted data to be processed to obtain the plaintext data to be processed;
[0078] Perform data processing on the plaintext data to be processed to obtain response plaintext data;
[0079] Encrypt the response plaintext data to obtain response ciphertext data, and feedback the response ciphertext data to the data request end, so that the data request end decrypts the response ciphertext data to obtain the response plaintext data.
[0080] The above data processing method, device, computer device and storage medium. The data request end sends the session identifier and application identifier corresponding to the plaintext data to be processed to the encryption and decryption platform, so that the encryption and decryption platform generates a first session key according to the session identifier and application identifier. Furthermore, the data request end obtains the encrypted data to be processed according to the first session key fed back by the encryption and decryption platform. Furthermore, the data request end sends the encrypted data to be processed and the session identifier to the data response end. The data response end uses the first session key obtained from the encryption and decryption platform based on the session identifier to decrypt the encrypted data to be processed to obtain the plaintext data to be processed, and performs data processing on the plaintext data to be processed to obtain the response plaintext data. The data response end sends the response ciphertext data obtained by encrypting the response plaintext data to the data request end, and the data request end decrypts the response ciphertext data to obtain the response plaintext data. According to the above content, it can be seen that in the process of data processing in this application, the encryption and decryption operations within the IMS network are realized. Through the company and session keys uniformly managed by the encryption and decryption platform, the encryption and decryption operations for the plaintext data to be processed are realized, so as to ensure that during the transmission of the plaintext data to be processed, the secondary encryption and decryption operations between the plaintext data to be processed and the encrypted data to be processed are realized through the encryption and decryption platform. And, the transmission security of the plaintext data to be processed is ensured by continuously updated first session keys, preventing the security risk of leakage of sensitive user data, and is effectively applicable to the use of DC terminals or third-party DC servers, and can greatly improve data security and data transmission rate in P2P (Peer-to-Peer, node-to-node), P2A (Peer-to-Application, node-to-application) or A2P (Application To Person, application-to-node) scenarios, meeting the various indicators of the operator's service quality. BRIEF DESCRIPTION OF THE DRAWINGS
[0081] Figure 1 It is an application environment diagram of a data processing method provided by an embodiment of the present application;
[0082] Figure 2 It is a flowchart of the first data processing method provided by an embodiment of the present application;
[0083] Figure 3 It is a flowchart of the second data processing method provided by an embodiment of the present application;
[0084] Figure 4 It is a flowchart of the third data processing method provided by an embodiment of the present application;
[0085] Figure 5 It is a processing flowchart of the plaintext data to be processed generated by the DC applet provided by an embodiment of the present application;
[0086] Figure 6 It is a processing flow chart of the secondary encryption and decryption process for terminal A and terminal B provided by an embodiment of the present application;
[0087] Figure 7 It is a processing flow chart of the secondary encryption and decryption process for terminal A and the third-party AS provided by an embodiment of the present application;
[0088] Figure 8 It is a structural block diagram of the first data processing device provided by an embodiment of the present application;
[0089] Figure 9 It is a structural block diagram of the second data processing device provided by an embodiment of the present application;
[0090] Figure 10 It is an internal structure diagram of a computer device in an embodiment. Detailed implementation manners
[0091] In order to make the objectives, technical solutions and advantages of the present application clearer and more understandable, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0092] The data processing method provided by the embodiments of the present application can be applied to, for example, Figure 1 the application environment shown. Among them, the data request end 101, the data response end 102, and the encryption and decryption platform 103 communicate with each other through a network. The data request end sends the session identifier and application identifier corresponding to the plaintext data to be processed to the encryption and decryption platform, so that the encryption and decryption platform generates a first session key according to the session identifier and application identifier. Furthermore, the data request end obtains the encrypted data to be processed according to the first session key fed back by the encryption and decryption platform. Furthermore, the data request end sends the encrypted data to be processed and the session identifier to the data response end. The data response end decrypts the encrypted data to be processed using the first session key obtained from the encryption and decryption platform based on the session identifier to obtain the plaintext data to be processed, and performs data processing on the plaintext data to be processed to obtain the response plaintext data. The data response end sends the encrypted response ciphertext data after encrypting the response plaintext data to the data request end, and the data request end decrypts the response ciphertext data to obtain the response plaintext data.
[0093] In one embodiment, as Figure 2 shown, a data processing method is provided. Taking the data request end 101 in Figure 1 as an example, the method includes the following steps:
[0094] S201. Send the session identifier and application identifier corresponding to the plaintext data to be processed to the encryption and decryption platform, so that the encryption and decryption platform generates a first session key according to the session identifier and application identifier.
[0095] In one embodiment of the application, to ensure the transmission security of the session identifier and the application identifier corresponding to the plaintext data to be processed sent to the encryption and decryption platform, the first public key for the data request end can be obtained in advance, so as to encrypt the session identifier and the application identifier according to the first public key to obtain the first ciphertext identifier; furthermore, the session identifier and the application identifier are transmitted to the encryption and decryption platform in the form of the first ciphertext identifier.
[0096] S202, encrypt the plaintext data to be processed according to the first session key fed back by the encryption and decryption platform to obtain the encrypted data to be processed.
[0097] It should be noted that after obtaining the first session key, to prevent security risks such as leakage of the plaintext data to be processed during the transmission process, the first session key can be used to encrypt the plaintext data to be processed, so as to obtain the encrypted data to be processed.
[0098] S203, send the encrypted data to be processed and the session identifier to the data response end, so that the data response end uses the first session key obtained from the encryption and decryption platform based on the session identifier to decrypt the encrypted data to be processed to obtain the plaintext data to be processed, and perform data processing on the plaintext data to be processed to obtain the response plaintext data.
[0099] It should be noted that the first session key is fed back to the data response end by the encryption and decryption platform after the data response end sends the session identifier, the second ciphertext identifier, and the second user identifier of the data response end to the encryption and decryption platform. When the encryption and decryption platform determines that the session identifier sent by the data response end is the same as the session identifier sent by the data request end, it is based on the second ciphertext identifier and the second user identifier;
[0100] Among them, the second ciphertext identifier is obtained by the data response end encrypting the first user identifier and the application identifier according to the second public key; the second public key is generated by the encryption and decryption platform after determining that the data response end has opened the communication service and obtained the second user identifier of the data response end.
[0101] In one embodiment of the present application, the process for the data response end to obtain the first session key is as follows: after the data response end receives the encrypted data to be processed and the session identifier, it encrypts the session identifier and the application identifier according to the second public key to obtain the second ciphertext identifier; and sends the session identifier, the second ciphertext identifier, and the second user identifier of the data response end to the encryption and decryption platform; when the encryption and decryption platform determines that the session identifier sent by the data response end is the same as the session identifier sent by the data request end, it queries the first session key according to the second ciphertext identifier and the second user identifier, and sends the first session key to the data response end.
[0102] S204: Receive the response ciphertext data sent by the data response end, and decrypt the response ciphertext data to obtain the response plaintext data.
[0103] Among them, the response ciphertext data is obtained by the data response end encrypting the response plaintext data.
[0104] It should be noted that to ensure the successful decryption of the response ciphertext data, it is necessary to verify whether the first session key used for encrypting the response plaintext data has changed. Specifically, it can be verified whether the session identifier sent by the data response end is consistent with the session identifier of the data request end. If they are consistent, it is considered that the first session key used for encrypting the response plaintext data has not changed; if they are inconsistent, it is considered that the first session key used for encrypting the response plaintext data has changed.
[0105] In an embodiment of the present application, when decrypting the response ciphertext data, the following may be included: receiving the session identifier sent by the data response end, and when the session identifier sent by the data response end is consistent with the session identifier of the data request end, decrypting the response ciphertext data into the response plaintext data based on the first session key; among them, the response ciphertext data is obtained by the data response end encrypting the response plaintext data through the first session key.
[0106] In another embodiment of the present application, when decrypting the response ciphertext data, the following may also be included: receiving the session identifier sent by the data response end, and when the session identifier sent by the data response end is inconsistent with the session identifier of the data request end, encrypting the second user identifier and the application identifier of the data response end according to the first public key to obtain the third ciphertext identifier;
[0107] Sending the third ciphertext identifier and the session identifier sent by the data response end to the encryption and decryption platform, so that when the encryption and decryption platform determines that the session identifier sent by the data response end is inconsistent with the session identifier sent by the data request end, decrypting the third ciphertext identifier into the second user identifier and the application identifier according to the first private key corresponding to the first public key, and generating a second session key according to the session identifier, the second user identifier and the application identifier sent by the data response end;
[0108] Receiving the second session key fed back by the encryption and decryption platform, and decrypting the response ciphertext data into the response plaintext data based on the second session key; among them, the response ciphertext data is obtained by the data response end encrypting the response plaintext data through the second session key.
[0109] The above data processing method is as follows: The data request side sends the session identifier and application identifier corresponding to the plaintext data to be processed to the encryption and decryption platform, so that the encryption and decryption platform generates a first session key based on the session identifier and application identifier. Furthermore, the data request side obtains the encrypted data to be processed according to the first session key fed back by the encryption and decryption platform. Furthermore, the data request side sends the encrypted data to be processed and the session identifier to the data response side. The data response side decrypts the encrypted data to be processed using the first session key obtained from the encryption and decryption platform based on the session identifier to obtain the plaintext data to be processed, and performs data processing on the plaintext data to be processed to obtain the response plaintext data. The data response side sends the response ciphertext data obtained by encrypting the response plaintext data to the data request side, and the data request side decrypts the response ciphertext data to obtain the response plaintext data. According to the above content, it can be seen that in the process of data processing in this application, encryption and decryption operations within the IMS network are realized. Through the company and session keys uniformly managed by the encryption and decryption platform, encryption and decryption operations on the plaintext data to be processed are realized, so as to ensure that during the transmission of the plaintext data to be processed, secondary encryption and decryption operations between the plaintext data to be processed and the encrypted data to be processed are realized through the encryption and decryption platform; moreover, the continuously updated first session key ensures the transmission security of the plaintext data to be processed, prevents the security risk of leakage of sensitive user data, and is effectively applicable to the use of DC terminals or third-party DC servers. In P2P (Peer-to-Peer), P2A (Peer-to-Application), or A2P (Application To Person) scenarios, data security and data transmission rate can be greatly improved, meeting the various indicators of the operator's service quality.
[0110] In one embodiment, as Figure 3 shown, when it is necessary to send the session identifier and application identifier corresponding to the plaintext data to be processed to the encryption and decryption platform, the following contents may be included:
[0111] S301, encrypt the session identifier and application identifier using the first public key to obtain the first ciphertext identifier.
[0112] Among them, the first public key is generated by the encryption and decryption platform after determining that the data request side has opened a communication service and obtaining the first user identifier of the data request side.
[0113] In one embodiment of this application, if the data request side has opened a communication service, the data request side sends the first user identifier to the encryption and decryption platform, and the encryption and decryption platform generates a first public key and a first private key for the data request side. Among them, the first public key is sent to the data request side; the corresponding relationship between the first public key and the first private key is stored in the storage device corresponding to the encryption and decryption platform.
[0114] Among them, the storage device can be a local storage device or a cloud storage device, and the type of the storage device of the encryption and decryption platform is not limited here.
[0115] S302. Send the first ciphertext identifier and the first user identifier corresponding to the data request end to the encryption and decryption platform, so that the encryption and decryption platform obtains the first private key according to the first user identifier, and uses the first private key to decrypt the first ciphertext identifier to obtain a session identifier and an application identifier.
[0116] The above data processing method encrypts the session identifier and the application identifier by using the first public key, and then sends the encrypted first ciphertext identifier and the first user identifier corresponding to the data request end to the encryption and decryption platform; it provides a data basis for generating the first session key subsequently and encrypting the plaintext data to be processed according to the first session key, and ensures the smooth progress of the subsequent encryption process.
[0117] In one embodiment, as Figure 4 shown, a data processing method is provided. Taking the data response end 102 in Figure 1 as an example for illustration, the method includes the following steps:
[0118] S401. Receive the encrypted data to be processed and the session identifier sent by the data request end.
[0119] Among them, the encrypted data to be processed is obtained by the data request end encrypting the plaintext data to be processed by using the first session key, and the first session ciphertext is generated by the encryption and decryption platform according to the session identifier and the application identifier corresponding to the plaintext data to be processed.
[0120] S402. Based on the session identifier, obtain the first session key from the encryption and decryption platform.
[0121] It should be noted that the first session key is the first private key corresponding to the first public key determined by the encryption and decryption platform according to the first user identifier; and after decrypting the first ciphertext identifier into a session identifier and an application identifier according to the first private key, it is generated according to the session identifier and the application identifier.
[0122] S403. Use the first session key to decrypt the encrypted data to be processed to obtain the plaintext data to be processed.
[0123] It should be noted that after obtaining the first session key, in order to prevent security risks such as leakage of the plaintext data to be processed during the transmission process, the plaintext data to be processed can be encrypted by using the first session key to obtain the encrypted data to be processed.
[0124] S404. Perform data processing on the plaintext data to be processed to obtain the response plaintext data.
[0125] S405, encrypt the response plaintext data to obtain response ciphertext data, and feedback the response ciphertext data to the data request side, so that the data request side decrypts the response ciphertext data to obtain the response plaintext data.
[0126] It should be noted that when encrypting the response plaintext data to obtain the response ciphertext data, the following content may be included: using the first session key to encrypt the response plaintext data to obtain the response ciphertext data.
[0127] Furthermore, when encrypting the response plaintext data to obtain the response ciphertext data, the following content may also be included: sending the session identifier, the second user identifier, and the application identifier to the encryption and decryption platform; enabling the encryption and decryption platform to generate a second session key according to the session identifier, the second user identifier, and the application identifier; receiving the second session key fed back by the encryption and decryption platform, and using the second session key to encrypt the response plaintext data to obtain the response ciphertext data.
[0128] Among them, when sending the session identifier, the second user identifier, and the application identifier to the encryption and decryption platform, the data response side may encrypt the second user identifier and the application identifier according to the second public key, and then send the encrypted second user identifier and application identifier to the encryption and decryption platform.
[0129] In the above data processing method, the data request side sends the session identifier and application identifier corresponding to the plaintext data to be processed to the encryption and decryption platform, so that the encryption and decryption platform generates a first session key according to the session identifier and application identifier. Furthermore, the data request side obtains the encrypted data to be processed according to the first session key fed back by the encryption and decryption platform. Furthermore, the data request side sends the encrypted data to be processed and the session identifier to the data response side. The data response side uses the first session key obtained from the encryption and decryption platform based on the session identifier to decrypt the encrypted data to be processed to obtain the plaintext data to be processed, and performs data processing on the plaintext data to be processed to obtain the response plaintext data. The data response side sends the response ciphertext data obtained by encrypting the response plaintext data to the data request side, and the data request side decrypts the response ciphertext data to obtain the response plaintext data. According to the above content, it can be seen that in the process of data processing in this application, the encryption and decryption operations within the IMS network are realized. Through the company and session keys uniformly managed by the encryption and decryption platform, the encryption and decryption operations for the plaintext data to be processed are realized, so as to ensure that during the transmission of the plaintext data to be processed, the secondary encryption and decryption operations between the plaintext data to be processed and the encrypted data to be processed are realized through the encryption and decryption platform. And, the transmission security of the plaintext data to be processed is ensured by continuously updated first session keys, preventing the security risk of leakage of sensitive user data, and being effectively applicable to the use of DC terminals or third-party DC servers. In P2P (Peer-to-Peer), P2A (Peer-to-Application), or A2P (Application To Person) scenarios, the data security and data transmission rate can be greatly improved, meeting the various indicators of the operator's service quality.
[0130] In one embodiment, during the transmission process of the plaintext data to be processed, a preset encryption method can be used to implement the initial encryption of the plaintext data to be processed. Furthermore, the encrypted data to be processed is transmitted to the SDK, and during the subsequent transmission process, the encrypted data to be processed is encrypted again to further improve the security of data transmission.
[0131] The processing flow of the plaintext data to be processed generated by the DC applet is as Figure 5 shown, and specifically may include the following content:
[0132] The DC applet generates business data; the business data is the plaintext data to be processed. The DC applet calls the JS-API secondary encryption algorithm interface provided by the DC SDK to encrypt the business data and generate the ciphertext of the business data. The DC applet calls the JS-API interface provided by the DC SDK and passes the ciphertext of the business data into the SDK. The SDK calls the send() method in the AIDL interface provided by the chip side to pass the business data into the terminal DC chip side. The terminal DC chip side uses the DTLS protocol stack to encrypt the business data to implement the secondary encryption operation; and sends the encrypted data to the IMSDC network. After the business data is transferred among the IMSDC network elements, the business data is sent to the third-party AS or the peer DC terminal through the Data Channel. The third-party AS or the DTLS protocol stack on the terminal chip side decrypts the received business data and reports the data to the DC SDK through the AIDL interface. The DC SDK returns the business data to the DC business applet through the JS-API. The DC applet calls the JS-API secondary decryption interface provided by the DC SDK to decrypt the ciphertext of the business data and generate the plaintext of the business data. The DC applet processes the business requests from the peer
[0133] In one embodiment, both the data request side and the data response side may be terminal devices. Specifically, the data request side is terminal A and the data response side is terminal B. Specifically, as Figure 6 shown, the secondary encryption and decryption process for terminal A and terminal B is as follows:
[0134] Both terminal A and terminal B have communication services enabled. Terminal A and terminal B respectively send user identifiers to the encryption and decryption platform (i.e., the encryption and decryption AS). The encryption and decryption platform generates a pair of public and private keys for terminal A and terminal B respectively, and saves the corresponding relationship between the user identifier and the public and private keys in the encryption and decryption platform. Then it returns the first public key to terminal A and the second public key to terminal B. Terminal A generates a session identifier locally, which can be the user identifier value. Terminal A encrypts the first ciphertext identifier composed of the session identifier and the application identifier using the first public key, and sends the first user identifier of terminal A and the first ciphertext identifier to the encryption and decryption platform. The encryption and decryption platform queries the first private key corresponding to terminal A according to the user identifier, decrypts the session identifier and the application identifier using the first private key, and then generates the first session key using the first user identifier, the session identifier and the application identifier. The encryption and decryption platform signs the first session key using the first private key corresponding to terminal A, and then returns the signed first session key to terminal A. Terminal A verifies the signature of the returned first session key using the first public key locally. After successful signature verification, it encrypts the plaintext data to be processed using the first session key, and sends the session identifier and the encrypted data to be processed to terminal B. Terminal B first extracts the session identifier and the first user identifier sent by terminal A. Terminal B encrypts the first user identifier and the application identifier of terminal A using the second public key to obtain the second ciphertext identifier, and sends the session identifier, the second user identifier of terminal B and the second ciphertext identifier to the encryption and decryption platform. The encryption and decryption platform uses the second private key corresponding to terminal B found according to the second user identifier of terminal B to decrypt the second ciphertext identifier to obtain the first user identifier and the application identifier of terminal A, and then queries the corresponding first session key according to the session identifier, the first user identifier and the application identifier. It signs the first session key using the second private key of terminal B and returns the signed first session key to terminal B. Terminal B verifies the signature of the first session key using the second public key locally. After passing the signature verification, it decrypts the encrypted data to be processed sent by terminal A using the first session key, then encrypts the response plaintext data using the first session key, and finally sends the session identifier and the response plaintext data to terminal A. Terminal A first checks whether the session identifier has changed. If there is no change, it decrypts the response ciphertext data using the original first session key. If there is a change, it encrypts the second user identifier and the application identifier of terminal B using the first public key, and then sends the session identifier, the first user identifier of terminal A and the encrypted second user identifier and application identifier to the encryption and decryption platform to obtain a new session key 2 again, and finally decrypts the response ciphertext data using the session key 2. Finally, terminal A processes the decrypted response plaintext data.
[0135] In one embodiment, the data request end can be a terminal device, and the data response end can be a third-party AS. Specifically, the data request end is terminal A, and the data response end is a third-party AS. Specifically, as Figure 7 shown, the secondary encryption and decryption process for terminal A and the third-party AS is as follows:
[0136] Both the terminal A and the third - party AS have communication services enabled. The terminal A and the third - party AS respectively send user identifiers to the encryption and decryption platform (i.e., the encryption and decryption AS); the encryption and decryption platform generates a pair of public and private keys for the terminal A and the third - party AS respectively, and saves the corresponding relationship between the user identifier and the public and private keys in the encryption and decryption platform, then returns the first public key to the terminal A and the second public key to the third - party AS; the terminal A generates a session identifier locally, which can be the user identifier value. The terminal A uses the first public key to encrypt the first ciphertext identifier composed of the session identifier and the application identifier, and sends the first user identifier of the terminal A and the first ciphertext identifier to the encryption and decryption platform. The encryption and decryption platform queries the first private key corresponding to the terminal A according to the user identifier, decrypts the session identifier and the application identifier using the first private key, then generates the first session key using the first user identifier, the session identifier and the application identifier. The encryption and decryption platform signs the first session key using the first private key corresponding to the terminal A, and then returns the signed first session key to the terminal A; the terminal A verifies the signature of the returned first session key using the first public key locally. After successful signature verification, it uses the first session key to encrypt the plaintext data to be processed, and sends the session identifier and the encrypted data to be processed to the third - party AS; the third - party AS first extracts the session identifier and the first user identifier sent by the terminal A. The third - party AS uses the second public key to encrypt the first user identifier and the application identifier of the terminal A to obtain the second ciphertext identifier, and sends the session identifier, the second user identifier of the third - party AS and the second ciphertext identifier to the encryption and decryption platform. The encryption and decryption platform uses the second private key corresponding to the second user identifier of the third - party AS to decrypt the second ciphertext identifier to obtain the first user identifier and the application identifier of the terminal A, and then queries the corresponding first session key according to the session identifier, the first user identifier and the application identifier. It signs the first session key using the second private key of the third - party AS and returns the signed first session key to the third - party AS; the third - party AS verifies the signature of the first session key using the second public key locally. After passing the signature verification, it decrypts the encrypted data to be processed sent by the terminal A using the first session key, then encrypts the response plaintext data using the first session key, and finally sends the session identifier and the response plaintext data to the terminal A; the terminal A first checks whether the session identifier has changed. If there is no change, it decrypts the response ciphertext data using the original first session key; if there is a change, it uses the first public key to encrypt the second user identifier and the application identifier of the third - party AS, then sends the session identifier, the first user identifier of the terminal A and the encrypted second user identifier and application identifier to the encryption and decryption platform, re - obtains the new session key 2, and finally decrypts the response ciphertext data using the session key 2; finally, the terminal A processes the decrypted response plaintext data.
[0137] In the above data processing method, the data request end sends the session identifier and application identifier corresponding to the plaintext data to be processed to the encryption and decryption platform, so that the encryption and decryption platform generates a first session key according to the session identifier and application identifier. Further, the data request end obtains the encrypted data to be processed according to the first session key fed back by the encryption and decryption platform. Further, the data request end sends the encrypted data to be processed and the session identifier to the data response end. The data response end uses the first session key obtained from the encryption and decryption platform based on the session identifier to decrypt the encrypted data to be processed to obtain the plaintext data to be processed, and performs data processing on the plaintext data to be processed to obtain the response plaintext data. The data response end sends the response ciphertext data obtained by encrypting the response plaintext data to the data request end, and the data request end decrypts the response ciphertext data to obtain the response plaintext data. According to the above content, it can be seen that in the process of data processing in this application, the encryption and decryption operations within the IMS network are realized. Through the company and session keys uniformly managed by the encryption and decryption platform, the encryption and decryption operations on the plaintext data to be processed are realized, so as to ensure that during the transmission of the plaintext data to be processed, the second encryption and decryption operations between the plaintext data to be processed and the encrypted data to be processed are realized through the encryption and decryption platform. Moreover, the transmission security of the plaintext data to be processed is ensured through the continuously updated first session key, preventing the security risk of leakage of sensitive user data. It is effectively applicable to the use of DC terminals or third-party DC servers, and can greatly improve data security and data transmission rate in P2P (Peer-to-Peer), P2A (Peer-to-Application), or A2P (Application To Person) scenarios, meeting the various indicators of the operator's service quality.
[0138] It should be understood that although the steps in the flowcharts involved in the above embodiments are displayed in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear indication in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or alternately with at least a part of other steps or steps or stages in other steps.
[0139] Based on the same inventive concept, an embodiment of the present application further provides a data processing apparatus for implementing the data processing method involved above. The solution provided by this apparatus to solve the problem is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the data processing apparatus provided below can refer to the limitations on the data processing method in the above text, and will not be repeated here.
[0140] In one embodiment, as Figure 8 shown, a data processing apparatus is provided, including: a first sending module 10, an encryption module 20, a second sending module 30, and a first receiving module 40, where:
[0141] The first sending module 10 is configured to send a session identifier and an application identifier corresponding to the plaintext data to be processed to the encryption and decryption platform, so that the encryption and decryption platform generates a first session key according to the session identifier and the application identifier.
[0142] The encryption module 20 is configured to encrypt the plaintext data to be processed according to the first session key fed back by the encryption and decryption platform to obtain the encrypted data to be processed.
[0143] The second sending module 30 is configured to send the encrypted data to be processed and the session identifier to the data response end, so that the data response end uses the first session key obtained from the encryption and decryption platform based on the session identifier to decrypt the encrypted data to be processed to obtain the plaintext data to be processed, and perform data processing on the plaintext data to be processed to obtain the response plaintext data.
[0144] The first receiving module 40 is configured to receive the response ciphertext data sent by the data response end and decrypt the response ciphertext data to obtain the response plaintext data; where the response ciphertext data is encrypted by the data response end for the response plaintext data.
[0145] In one embodiment, the session identifier and the application identifier are encrypted using a first public key to obtain a first ciphertext identifier;
[0146] The first ciphertext identifier and the first user identifier corresponding to the data request end are sent to the encryption and decryption platform, so that the encryption and decryption platform obtains a first private key according to the first user identifier and decrypts the first ciphertext identifier using the first private key to obtain the session identifier and the application identifier.
[0147] In one embodiment, the first public key is generated by the encryption and decryption platform after determining that the data request end has opened a communication service and obtaining the first user identifier of the data request end.
[0148] In one embodiment, the first session key fed back by the encryption and decryption platform is received; where the first session key has been signed by the encryption and decryption platform using the first private key;
[0149] In the case where the verification signature of the first session key using the first public key passes, encrypt the plaintext data to be processed according to the first session key to obtain the encrypted data to be processed.
[0150] In one embodiment, the first session key is feedback by the encryption and decryption platform to the data response end after the data response end sends the session identifier, the second ciphertext identifier, and the second user identifier of the data response end to the encryption and decryption platform, and when the encryption and decryption platform determines that the session identifier sent by the data response end is the same as the session identifier sent by the data request end, according to the second ciphertext identifier and the second user identifier;
[0151] Among them, the second ciphertext identifier is obtained by the data response end encrypting the first user identifier and the application identifier according to the second public key; the second public key is generated by the encryption and decryption platform when it determines that the data response end has opened a communication service and obtains the second user identifier of the data response end.
[0152] In one embodiment, receive the session identifier sent by the data response end, and when the session identifier sent by the data response end is the same as the session identifier sent by the data request end, decrypt the response ciphertext data into response plaintext data based on the first session key; wherein, the response ciphertext data is obtained by the data response end encrypting the response plaintext data using the first session key.
[0153] In one embodiment, receive the session identifier sent by the data response end, and when the session identifier sent by the data response end is different from the session identifier sent by the data request end, encrypt the second user identifier and the application identifier of the data response end according to the first public key to obtain a third ciphertext identifier;
[0154] Send the third ciphertext identifier and the session identifier sent by the data response end to the encryption and decryption platform, so that when the encryption and decryption platform determines that the session identifier sent by the data response end is different from the session identifier sent by the data request end, decrypt the third ciphertext identifier into the second user identifier and the application identifier according to the first private key corresponding to the first public key, and generate a second session key according to the session identifier, the second user identifier, and the application identifier sent by the data response end;
[0155] Receive the second session key feedback by the encryption and decryption platform, and decrypt the response ciphertext data into response plaintext data based on the second session key; wherein, the response ciphertext data is obtained by the data response end encrypting the response plaintext data using the second session key.
[0156] In one embodiment, as Figure 9 shown, a data processing device is provided, including: a second receiving module 50, an obtaining module 60, a decrypting module 70, a processing module 80, and a feedback module 90, wherein:
[0157] A second receiving module 50, configured to receive the encrypted data to be processed and the session identifier sent by the data request end; wherein, the encrypted data to be processed is obtained by the data request end encrypting the plaintext data to be processed using a first session key, and the first session ciphertext is generated by the encryption and decryption platform according to the session identifier and the application identifier corresponding to the plaintext data to be processed.
[0158] An obtaining module 60, configured to obtain the first session key from the encryption and decryption platform based on the session identifier.
[0159] A decryption module 70, configured to decrypt the encrypted data to be processed using the first session key to obtain the plaintext data to be processed.
[0160] A processing module 80, configured to perform data processing on the plaintext data to be processed to obtain the response plaintext data.
[0161] A feedback module 90, configured to encrypt the response plaintext data to obtain the response ciphertext data, and feedback the response ciphertext data to the data request end, so that the data request end decrypts the response ciphertext data to obtain the response plaintext data.
[0162] In one embodiment, the response plaintext data is encrypted using the first session key to obtain the response ciphertext data.
[0163] In one embodiment, the session identifier, the second user identifier, and the application identifier are sent to the encryption and decryption platform; so that the encryption and decryption platform generates a second session key according to the session identifier, the second user identifier, and the application identifier;
[0164] The second session key fed back by the encryption and decryption platform is received, and the response plaintext data is encrypted using the second session key to obtain the response ciphertext data.
[0165] The above data processing device sends the session identifier and application identifier corresponding to the plaintext data to be processed to the encryption and decryption platform through the data request end, so that the encryption and decryption platform generates a first session key according to the session identifier and application identifier. Furthermore, the data request end obtains the encrypted data to be processed according to the first session key fed back by the encryption and decryption platform. Furthermore, the data request end sends the encrypted data to be processed and the session identifier to the data response end. The data response end decrypts the encrypted data to be processed by using the first session key obtained from the encryption and decryption platform based on the session identifier to obtain the plaintext data to be processed, and processes the plaintext data to be processed to obtain the response plaintext data. The data response end sends the response ciphertext data obtained by encrypting the response plaintext data to the data request end, and the data request end decrypts the response ciphertext data to obtain the response plaintext data. According to the above content, it can be seen that in the process of data processing in this application, the encryption and decryption operations within the IMS network are realized. Through the company and session keys uniformly managed by the encryption and decryption platform, the encryption and decryption operations for the plaintext data to be processed are realized, so as to ensure that in the process of transmitting the plaintext data to be processed, the secondary encryption and decryption operations between the plaintext data to be processed and the encrypted data to be processed are realized through the encryption and decryption platform. Moreover, the transmission security of the plaintext data to be processed is ensured by continuously updating the first session key, preventing the security risk of leakage of sensitive user data, and is effectively applicable to the use of DC terminals or third-party DC servers. In P2P (Peer-to-Peer), P2A (Peer-to-Application), or A2P (Application To Person) scenarios, it can greatly improve data security and data transmission rate, and meet the various indicators of the operator's service quality.
[0166] Each module in the above data processing device can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor of the computer device in hardware form or be independent of it, or can be stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to the above modules.
[0167] In one embodiment, a computer device is provided. The computer device can be a terminal, and its internal structure diagram can be as Figure 10As shown in the figure. The computer device includes a processor, a memory, an input / output interface, a communication interface, a display unit, and an input device. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface, the display unit, and the input device are connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals in a wired or wireless manner, and the wireless manner can be implemented through WIFI, a mobile cellular network, NFC (Near Field Communication), or other technologies. When the computer program is executed by the processor, it implements a data processing method. The display unit of the computer device is used to form a visually visible picture, which can be a display screen, a projection device, or a virtual reality imaging device. The display screen can be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device can be a touch layer covering the display screen, or a button, a trackball, or a touchpad provided on the computer device housing, or an external keyboard, touchpad, or mouse, etc.
[0168] Those skilled in the art can understand that Figure 10 the structure shown in the figure is only a block diagram of some structures related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.
[0169] In one embodiment, a computer device is provided, including a memory and a processor. A computer program is stored in the memory. When the processor executes the computer program, the following steps are implemented:
[0170] Send the session identifier and application identifier corresponding to the plaintext data to be processed to the encryption and decryption platform, so that the encryption and decryption platform generates a first session key according to the session identifier and application identifier;
[0171] Encrypt the plaintext data to be processed according to the first session key fed back by the encryption and decryption platform to obtain the encrypted data to be processed;
[0172] Send the encrypted data to be processed and the session identifier to the data response end, so that the data response end uses the first session key obtained from the encryption and decryption platform based on the session identifier to decrypt the encrypted data to be processed to obtain the plaintext data to be processed, and perform data processing on the plaintext data to be processed to obtain the response plaintext data;
[0173] Receive the response ciphertext data sent by the data response end, and decrypt the response ciphertext data to obtain the response plaintext data; wherein, the response ciphertext data is obtained by the data response end encrypting the response plaintext data.
[0174] In one embodiment, when the processor executes the computer program, the following steps are further implemented:
[0175] Use the first public key to encrypt the session identifier and the application identifier to obtain the first ciphertext identifier;
[0176] Send the first ciphertext identifier and the first user identifier corresponding to the data request end to the encryption and decryption platform, so that the encryption and decryption platform obtains the first private key according to the first user identifier, and uses the first private key to decrypt the first ciphertext identifier to obtain the session identifier and the application identifier.
[0177] In one embodiment, when the processor executes the computer program, the following steps are further implemented:
[0178] The first public key is generated by the encryption and decryption platform after determining that the data request end has opened the communication service and obtaining the first user identifier of the data request end.
[0179] In one embodiment, when the processor executes the computer program, the following steps are further implemented:
[0180] Receive the first session key fed back by the encryption and decryption platform; wherein, the first session key has been signed by the encryption and decryption platform using the first private key;
[0181] In the case where the verification signature of the first session key using the first public key passes, encrypt the plaintext data to be processed according to the first session key to obtain the encrypted data to be processed.
[0182] In one embodiment, when the processor executes the computer program, the following steps are further implemented:
[0183] The first session key is fed back by the encryption and decryption platform to the data response end after the data response end sends the session identifier, the second ciphertext identifier, and the second user identifier of the data response end to the encryption and decryption platform, and the encryption and decryption platform determines that the session identifier sent by the data response end is the same as the session identifier sent by the data request end, and according to the second ciphertext identifier and the second user identifier;
[0184] Wherein, the second ciphertext identifier is obtained by the data response end encrypting the first user identifier and the application identifier according to the second public key; the second public key is generated by the encryption and decryption platform after determining that the data response end has opened the communication service and obtaining the second user identifier of the data response end.
[0185] In one embodiment, when the processor executes the computer program, the following steps are further implemented:
[0186] Receive the session identifier sent by the data response end, and when the session identifier sent by the data response end is the same as the session identifier of the data request end, decrypt the response ciphertext data into response plaintext data based on the first session key; wherein, the response ciphertext data is obtained by the data response end encrypting the response plaintext data with the first session key.
[0187] In one embodiment, when the processor executes the computer program, the following steps are further implemented:
[0188] Receive the session identifier sent by the data response end, and when the session identifier sent by the data response end is different from the session identifier of the data request end, encrypt the second user identifier and the application identifier of the data response end according to the first public key to obtain a third ciphertext identifier;
[0189] Send the third ciphertext identifier and the session identifier sent by the data response end to the encryption and decryption platform, so that when the encryption and decryption platform determines that the session identifier sent by the data response end is different from the session identifier sent by the data request end, decrypt the third ciphertext identifier into the second user identifier and the application identifier according to the first private key corresponding to the first public key, and generate a second session key according to the session identifier, the second user identifier and the application identifier sent by the data response end;
[0190] Receive the second session key fed back by the encryption and decryption platform, and decrypt the response ciphertext data into response plaintext data based on the second session key; wherein, the response ciphertext data is obtained by the data response end encrypting the response plaintext data with the second session key.
[0191] In one embodiment, a computer device is provided, including a memory and a processor. A computer program is stored in the memory. When the processor executes the computer program, the following steps are implemented:
[0192] Receive the encrypted data to be processed and the session identifier sent by the data request end; wherein, the encrypted data to be processed is obtained by the data request end encrypting the plaintext data to be processed with the first session key, and the first session ciphertext is generated by the encryption and decryption platform according to the session identifier and the application identifier corresponding to the plaintext data to be processed;
[0193] Based on the session identifier, obtain the first session key from the encryption and decryption platform;
[0194] Use the first session key to decrypt the encrypted data to be processed to obtain the plaintext data to be processed;
[0195] Perform data processing on the plaintext data to be processed to obtain the response plaintext data;
[0196] Encrypt the response plaintext data to obtain the response ciphertext data, and feedback the response ciphertext data to the data request side, so that the data request side decrypts the response ciphertext data to obtain the response plaintext data.
[0197] In one embodiment, when the processor executes the computer program, the following steps are further implemented:
[0198] Use the first session key to encrypt the response plaintext data to obtain the response ciphertext data.
[0199] In one embodiment, when the processor executes the computer program, the following steps are further implemented:
[0200] Send the session identifier, the second user identifier, and the application identifier to the encryption and decryption platform; so that the encryption and decryption platform generates a second session key according to the session identifier, the second user identifier, and the application identifier;
[0201] Receive the second session key fed back by the encryption and decryption platform, and use the second session key to encrypt the response plaintext data to obtain the response ciphertext data.
[0202] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:
[0203] Send the session identifier and the application identifier corresponding to the plaintext data to be processed to the encryption and decryption platform, so that the encryption and decryption platform generates a first session key according to the session identifier and the application identifier;
[0204] Encrypt the plaintext data to be processed according to the first session key fed back by the encryption and decryption platform to obtain the encrypted data to be processed;
[0205] Send the encrypted data to be processed and the session identifier to the data response side, so that the data response side uses the first session key obtained from the encryption and decryption platform based on the session identifier to decrypt the encrypted data to be processed to obtain the plaintext data to be processed, and performs data processing on the plaintext data to be processed to obtain the response plaintext data;
[0206] Receive the response ciphertext data sent by the data response side, and decrypt the response ciphertext data to obtain the response plaintext data; wherein, the response ciphertext data is obtained by the data response side encrypting the response plaintext data.
[0207] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented:
[0208] Use the first public key to encrypt the session identifier and the application identifier to obtain the first ciphertext identifier;
[0209] Send the first ciphertext identifier and the first user identifier corresponding to the data request end to the encryption and decryption platform, so that the encryption and decryption platform can obtain the first private key according to the first user identifier, and use the first private key to decrypt the first ciphertext identifier to obtain the session identifier and the application identifier.
[0210] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented:
[0211] The first public key is generated by the encryption and decryption platform after determining that the data request end has opened the communication service and obtaining the first user identifier of the data request end.
[0212] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented:
[0213] Receive the first session key fed back by the encryption and decryption platform; wherein, the first session key has been signed by the encryption and decryption platform with the first private key;
[0214] In the case that the verification signature of the first session key passes with the first public key, encrypt the plaintext data to be processed according to the first session key to obtain the encrypted data to be processed.
[0215] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented:
[0216] The first session key is fed back by the encryption and decryption platform to the data response end after the data response end sends the session identifier, the second ciphertext identifier, and the second user identifier of the data response end to the encryption and decryption platform, and the encryption and decryption platform determines that the session identifier sent by the data response end is the same as the session identifier sent by the data request end, and according to the second ciphertext identifier and the second user identifier;
[0217] Wherein, the second ciphertext identifier is obtained by the data response end encrypting the first user identifier and the application identifier according to the second public key; the second public key is generated by the encryption and decryption platform after determining that the data response end has opened the communication service and obtaining the second user identifier of the data response end.
[0218] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented:
[0219] Receive the session identifier sent by the data response end, and in the case that the session identifier sent by the data response end is the same as the session identifier sent by the data request end, decrypt the response ciphertext data into response plaintext data based on the first session key; wherein, the response ciphertext data is obtained by the data response end encrypting the response plaintext data with the first session key.
[0220] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented:
[0221] Receive the session identifier sent by the data response end, and when the session identifier sent by the data response end is inconsistent with the session identifier of the data request end, encrypt the second user identifier and the application identifier of the data response end according to the first public key to obtain the third ciphertext identifier;
[0222] Send the third ciphertext identifier and the session identifier sent by the data response end to the encryption and decryption platform, so that when the encryption and decryption platform determines that the session identifier sent by the data response end is inconsistent with the session identifier sent by the data request end, decrypt the third ciphertext identifier into the second user identifier and the application identifier according to the first private key corresponding to the first public key, and generate a second session key according to the session identifier, the second user identifier and the application identifier sent by the data response end;
[0223] Receive the second session key fed back by the encryption and decryption platform, and decrypt the response ciphertext data into response plaintext data based on the second session key; wherein, the response ciphertext data is obtained by the data response end encrypting the response plaintext data with the second session key.
[0224] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:
[0225] Receive the to-be-processed encrypted data and the session identifier sent by the data request end; wherein, the to-be-processed encrypted data is obtained by the data request end encrypting the to-be-processed plaintext data with the first session key, and the first session ciphertext is generated by the encryption and decryption platform according to the session identifier and the application identifier corresponding to the to-be-processed plaintext data;
[0226] Based on the session identifier, obtain the first session key from the encryption and decryption platform;
[0227] Use the first session key to decrypt the to-be-processed encrypted data to obtain the to-be-processed plaintext data;
[0228] Perform data processing on the to-be-processed plaintext data to obtain the response plaintext data;
[0229] Encrypt the response plaintext data to obtain the response ciphertext data, and feedback the response ciphertext data to the data request end, so that the data request end decrypts the response ciphertext data to obtain the response plaintext data.
[0230] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0231] Use the first session key to encrypt the response plaintext data to obtain the response ciphertext data.
[0232] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0233] Send the session identifier, the second user identifier, and the application identifier to the encryption and decryption platform; so that the encryption and decryption platform generates a second session key based on the session identifier, the second user identifier, and the application identifier;
[0234] Receive the second session key fed back by the encryption and decryption platform, and use the second session key to encrypt the response plaintext data to obtain the response ciphertext data.
[0235] In one embodiment, a computer program product is provided, including a computer program, which when executed by a processor implements the following steps:
[0236] Send the session identifier and the application identifier corresponding to the plaintext data to be processed to the encryption and decryption platform, so that the encryption and decryption platform generates a first session key based on the session identifier and the application identifier;
[0237] Encrypt the plaintext data to be processed according to the first session key fed back by the encryption and decryption platform to obtain the encrypted data to be processed;
[0238] Send the encrypted data to be processed and the session identifier to the data response end, so that the data response end uses the first session key obtained from the encryption and decryption platform based on the session identifier to decrypt the encrypted data to be processed to obtain the plaintext data to be processed, and processes the plaintext data to be processed to obtain the response plaintext data;
[0239] Receive the response ciphertext data sent by the data response end, and decrypt the response ciphertext data to obtain the response plaintext data; wherein, the response ciphertext data is obtained by the data response end encrypting the response plaintext data.
[0240] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0241] Use the first public key to encrypt the session identifier and the application identifier to obtain the first ciphertext identifier;
[0242] Send the first ciphertext identifier and the first user identifier corresponding to the data request end to the encryption and decryption platform, so that the encryption and decryption platform obtains the first private key according to the first user identifier, and uses the first private key to decrypt the first ciphertext identifier to obtain the session identifier and the application identifier.
[0243] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0244] The first public key is generated by the encryption and decryption platform after determining that the data request end has opened the communication service and obtained the first user identifier of the data request end.
[0245] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0246] Receive the first session key fed back by the encryption and decryption platform; wherein, the first session key has been signed by the encryption and decryption platform using the first private key.
[0247] When the verification signature of the first session key using the first public key passes, encrypt the plaintext data to be processed according to the first session key to obtain the encrypted data to be processed.
[0248] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented:
[0249] The first session key is fed back to the data response end by the encryption and decryption platform after the data response end sends the session identifier, the second ciphertext identifier, and the second user identifier of the data response end to the encryption and decryption platform, and when the encryption and decryption platform determines that the session identifier sent by the data response end is the same as the session identifier sent by the data request end, according to the second ciphertext identifier and the second user identifier.
[0250] Wherein, the second ciphertext identifier is obtained by the data response end encrypting the first user identifier and the application identifier using the second public key; the second public key is generated by the encryption and decryption platform when it determines that the data response end has opened a communication service and has obtained the second user identifier of the data response end.
[0251] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented:
[0252] Receive the session identifier sent by the data response end, and when the session identifier sent by the data response end is the same as the session identifier sent by the data request end, decrypt the response ciphertext data into response plaintext data based on the first session key; wherein, the response ciphertext data is obtained by the data response end encrypting the response plaintext data using the first session key.
[0253] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented:
[0254] Receive the session identifier sent by the data response end, and when the session identifier sent by the data response end is different from the session identifier sent by the data request end, encrypt the second user identifier and the application identifier of the data response end using the first public key to obtain the third ciphertext identifier.
[0255] Send the third ciphertext identifier and the session identifier sent by the data response end to the encryption and decryption platform, so that when the encryption and decryption platform determines that the session identifier sent by the data response end is different from the session identifier sent by the data request end, decrypt the third ciphertext identifier into the second user identifier and the application identifier using the first private key corresponding to the first public key, and generate a second session key according to the session identifier, the second user identifier, and the application identifier sent by the data response end.
[0256] Receive the second session key fed back by the encryption and decryption platform, and decrypt the response ciphertext data into response plaintext data based on the second session key; wherein, the response ciphertext data is obtained by the data response end encrypting the response plaintext data with the second session key.
[0257] In one embodiment, a computer program product is provided, including a computer program which, when executed by a processor, implements the following steps:
[0258] Receive the encrypted data to be processed and the session identifier sent by the data request end; wherein, the encrypted data to be processed is obtained by the data request end encrypting the plaintext data to be processed with the first session key, and the first session ciphertext is generated by the encryption and decryption platform according to the session identifier and application identifier corresponding to the plaintext data to be processed;
[0259] Based on the session identifier, obtain the first session key from the encryption and decryption platform;
[0260] Use the first session key to decrypt the encrypted data to be processed to obtain the plaintext data to be processed;
[0261] Perform data processing on the plaintext data to be processed to obtain the response plaintext data;
[0262] Encrypt the response plaintext data to obtain the response ciphertext data, and feed back the response ciphertext data to the data request end so that the data request end decrypts the response ciphertext data to obtain the response plaintext data.
[0263] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented:
[0264] Use the first session key to encrypt the response plaintext data to obtain the response ciphertext data.
[0265] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented:
[0266] Send the session identifier, the second user identifier, and the application identifier to the encryption and decryption platform; so that the encryption and decryption platform generates a second session key according to the session identifier, the second user identifier, and the application identifier;
[0267] Receive the second session key fed back by the encryption and decryption platform, and use the second session key to encrypt the response plaintext data to obtain the response ciphertext data.
[0268] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with the relevant laws, regulations, and standards of relevant countries and regions.
[0269] Those of ordinary skill in the art can understand that all or part of the processes in the above-described embodiment methods can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the above-described method embodiments. Among them, any reference to a memory, database, or other medium used in the various embodiments provided in this application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the various embodiments provided in this application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the various embodiments provided in this application can be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., without limitation.
[0270] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.
[0271] The above embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all fall within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the appended claims.
Claims
1. A data processing method, characterized in that: Applied to a data requesting end, the method comprises: Sending a session identifier and an application identifier corresponding to the plaintext data to be processed to the encryption and decryption platform, so that the encryption and decryption platform generates a first session key according to the session identifier and the application identifier; Encrypting the plaintext data to be processed according to the first session key fed back by the encryption and decryption platform to obtain encrypted data to be processed; Sending the encrypted data to be processed and the session identifier to a data response end, so that the data response end uses the first session key obtained from the encryption and decryption platform based on the session identifier to decrypt the encrypted data to be processed to obtain the plaintext data to be processed, and performs data processing on the plaintext data to be processed to obtain response plaintext data; Receive the response ciphertext data sent by the data response end, and decrypt the response ciphertext data to obtain the response plaintext data; wherein the response ciphertext data is obtained by the data response end encrypting the response plaintext data.
2. The method according to claim 1, characterized in that The sending of the session identifier and application identifier corresponding to the plaintext data to be processed to the encryption and decryption platform includes: Using a first public key, encrypt the session identifier and the application identifier to obtain a first ciphertext identifier; The first ciphertext identifier and the first user identifier corresponding to the data request end are sent to the encryption and decryption platform, so that the encryption and decryption platform obtains a first private key according to the first user identifier, and uses the first private key to decrypt the first ciphertext identifier to obtain the session identifier and the application identifier.
3. The method according to claim 2, characterized in that The first public key is generated by the encryption / decryption platform after determining that the data request end has activated the communication service and obtaining the first user identification of the data request end.
4. The method according to any one of claims 1 to 3, characterized in that The step of encrypting the plaintext data to be processed according to the first session key fed back by the encryption / decryption platform to obtain the encrypted data to be processed includes: Receive the first session key fed back by the encryption / decryption platform; wherein the first session key has been signed by the encryption / decryption platform using a first private key; When the signature of the first session key is successfully verified by using the first public key, the plaintext data to be processed is encrypted according to the first session key to obtain encrypted data to be processed.
5. The method according to any one of claims 1 to 3, characterized in that: The first session key is fed back to the data responder according to the second ciphertext identifier and the second user identifier after the data responder sends the session identifier, the second ciphertext identifier, and the second user identifier of the data responder to the encryption and decryption platform, and when the encryption and decryption platform determines that the session identifier sent by the data responder is consistent with the session identifier sent by the data requester; Among them, the second ciphertext identifier is obtained by the data response end encrypting the first user identifier and the application identifier according to the second public key; the second public key is generated by the encryption and decryption platform after determining that the data response end has opened the communication service and obtained the second user identifier of the data response end.
6. The method according to any one of claims 1 to 3, characterized in that The decrypting the response ciphertext data to obtain the response plaintext data includes: Receive the session identifier sent by the data response end, and when the session identifier sent by the data response end is consistent with the session identifier of the data request end, decrypt the response ciphertext data into the response plaintext data based on the first session key; wherein the response ciphertext data is obtained by the data response end encrypting the response plaintext data using the first session key.
7. The method according to any one of claims 1 to 3, characterized in that The decrypting the response ciphertext data to obtain the response plaintext data includes: receiving a session identifier sent by the data response end, and when the session identifier sent by the data response end is inconsistent with the session identifier of the data request end, encrypting the second user identifier and the application identifier of the data response end according to the first public key to obtain a third ciphertext identifier; Sending the third ciphertext identifier and the session identifier sent by the data response end to the encryption and decryption platform, so that when the encryption and decryption platform determines that the session identifier sent by the data response end is inconsistent with the session identifier sent by the data request end, the third ciphertext identifier is decrypted into the second user identifier and the application identifier according to the first private key corresponding to the first public key, and a second session key is generated according to the session identifier sent by the data response end, the second user identifier and the application identifier; Receive the second session key fed back by the encryption and decryption platform, and decrypt the response ciphertext data into the response plaintext data based on the second session key; wherein the response ciphertext data is obtained by the data response end encrypting the response plaintext data using the second session key.
8. A data processing method, characterized in that: Applied to the data response end, the method includes: Receive the encrypted data to be processed and the session identifier sent by the data request end; wherein the encrypted data to be processed is obtained by the data request end encrypting the plaintext data to be processed using the first session key, and the first session ciphertext is generated by the encryption and decryption platform according to the session identifier and application identifier corresponding to the plaintext data to be processed; Based on the session identifier, obtaining the first session key from the encryption and decryption platform; Using the first session key, decrypting the encrypted data to be processed to obtain the plaintext data to be processed; Performing data processing on the plaintext data to be processed to obtain response plaintext data; The response plaintext data is encrypted to obtain response ciphertext data, and the response ciphertext data is fed back to the data request end, so that the data request end decrypts the response ciphertext data to obtain the response plaintext data.
9. The method according to claim 8, characterized in that The step of encrypting the response plaintext data to obtain the response ciphertext data includes: The first session key is used to encrypt the response plaintext data to obtain response ciphertext data.
10. The method according to claim 8, characterized in that The step of encrypting the response plaintext data to obtain the response ciphertext data includes: Sending the session identifier, the second user identifier and the application identifier to the encryption / decryption platform, so that the encryption / decryption platform generates a second session key according to the session identifier, the second user identifier and the application identifier; The second session key fed back by the encryption / decryption platform is received, and the response plaintext data is encrypt|encrypted by using the second session key, so as to obtain response ciphertext data.
11. A data processing device, characterized in that: Configured at the data request end, the device includes: A first sending module, used to send a session identifier and an application identifier corresponding to the plaintext data to be processed to the encryption and decryption platform, so that the encryption and decryption platform generates a first session key according to the session identifier and the application identifier; an encryption module, configured to encrypt the plaintext data to be processed according to the first session key fed back by the encryption and decryption platform to obtain encrypted data to be processed; A second sending module is used to send the encrypted data to be processed and the session identifier to a data response end, so that the data response end uses the first session key obtained from the encryption and decryption platform based on the session identifier to decrypt the encrypted data to be processed to obtain the plaintext data to be processed, and performs data processing on the plaintext data to be processed to obtain response plaintext data; The first receiving module is used to receive the response ciphertext data sent by the data response end, and decrypt the response ciphertext data to obtain the response plaintext data; wherein the response ciphertext data is obtained by the data response end encrypting the response plaintext data.
12. A data processing device, characterized in that: Configured at the data response end, the device includes: A second receiving module is used to receive the encrypted data to be processed and the session identifier sent by the data request end; wherein the encrypted data to be processed is obtained by the data request end using the first session key to encrypt the plaintext data to be processed, and the first session ciphertext is generated by the encryption and decryption platform according to the session identifier and application identifier corresponding to the plaintext data to be processed; An acquisition module, configured to acquire the first session key from the encryption and decryption platform based on the session identifier; a decryption module, configured to use the first session key to decrypt the encrypted data to be processed to obtain the plaintext data to be processed; A processing module, used for processing the plaintext data to be processed to obtain response plaintext data; The feedback module is used to encrypt the response plaintext data to obtain response ciphertext data, and feed back the response ciphertext data to the data request end, so that the data request end decrypts the response ciphertext data to obtain the response plaintext data.
13. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 10 are implemented.
14. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 10 are implemented.
15. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 10 are implemented.