Data security transmission system based on bidirectional authentication mechanism
By adopting a combination technology of two-way authentication mechanism and hardware encryption machine in the data secure transmission system, the problems of key leakage risks, unclear permission division and lack of authentication mechanism in symmetric key encryption technology are solved, and higher data encryption transmission security and reliability are achieved.
Patent Information
- Application Number
- CN202510226154.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-27
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-02-27
AI Technical Summary
The existing symmetric key encryption technology has shortcomings in key leakage risks, unclear permission division and lack of identity authentication mechanisms, resulting in insufficient security and reliability of data encryption transmission.
A data security transmission system based on a two-way authentication mechanism is adopted to achieve secure data transmission through the use of public and private key pairs and the protection of hardware encryption machines. Specifically, it includes the coordinated work of the data encryption and decryption module, message digest module, signature verification module, session key generation module and hardware encryption machine.
It effectively reduces the risk of key leakage, realizes two-way authentication, enhances the incrackability of data transmission, and ensures the security of key and data processing processes.
Smart Images

Figure CN120074837A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data transmission, and particularly to a data security transmission system based on a two-way authentication mechanism. Background Art
[0002] In the existing field of data encryption transmission, the symmetric key encryption technology is a widely used encryption method. The core of this solution lies in using the same symmetric key to encrypt and decrypt plaintext data. During the key negotiation phase, the relevant parties will synchronize this symmetric key to ensure that during the subsequent data transmission process, the sender can use this key to encrypt the plaintext data to obtain ciphertext data and transmit the ciphertext data to the receiver; while the receiver can use the pre-negotiated symmetric key to decrypt the received ciphertext data and restore the original plaintext data.
[0003] To achieve the storage and invocation of keys, the existing solutions usually provide two methods: software encryption and hardware encryption machines. The software encryption method is flexible and convenient, but may face relatively high security risks; while the hardware encryption machine provides higher security and can ensure the secure storage and use of keys at the physical level.
[0004] However, although the symmetric key encryption technology meets the requirements of data encryption transmission to a certain extent, there are still many deficiencies and problems in its actual application:
[0005] Leakage risk caused by multiple parties holding the symmetric key:
[0006] In the symmetric key encryption scheme, the key needs to be held by multiple relevant parties for data encryption and decryption operations. However, this way of multiple parties holding the key greatly increases the risk of key leakage. Once the key is accidentally leaked, it will be impossible to quickly locate the specific leaking party, and thus impossible to effectively trace and handle the leakage incident. At the same time, the leakage of the key will also directly pose a serious threat to the security of the encrypted data.
[0007] Unclear division of key permissions:
[0008] The symmetric key has the dual functions of encryption and decryption, which means that any party holding the key can encrypt or decrypt data. This unclear division of permissions leads to too much flexibility in key usage, but also brings great security risks. Once the key is leaked, the attacker will be able to use this key to decrypt the encrypted data arbitrarily, resulting in the complete leakage of the data.
[0009] Lack of an identity authentication mechanism:
[0010] In existing symmetric key encryption schemes, there is usually a lack of authentication mechanisms for both communication parties. This means that during data transmission, it is impossible to effectively determine the true identities of the communication parties, nor can it prevent attacks by impostors. An attacker may tamper with or steal encrypted data by forging identities or intercepting the communication link, thus seriously threatening the security and integrity of the data.
[0011] In summary, existing symmetric key encryption schemes have many deficiencies and problems in aspects such as key storage and usage security, key permission division, and authentication. Therefore, there is an urgent need for a new encryption transmission scheme to solve the above problems and improve the security and reliability of data encrypted transmission. Summary of the Invention
[0012] The present invention provides a data security transmission system based on a two-way authentication mechanism. By using public-private key pairs and the protection of a hardware encryption machine, it effectively solves problems such as key leakage risk, unclear permission division, and lack of authentication mechanism in the prior art.
[0013] The present invention achieves the above object through the following technical solutions:
[0014] A data security transmission system based on a two-way authentication mechanism, comprising:
[0015] A data encryption and decryption module, configured to transmit plaintext data, key ID, encryption parameters, and other information to corresponding interfaces of the hardware encryption machine according to an encryption request for encryption processing, and transmit ciphertext data, key ID, encryption parameters, and other information to corresponding interfaces of the hardware encryption machine for decryption processing according to a decryption request;
[0016] A message digest module, configured to process the encrypted ciphertext data to generate a message digest of a fixed length;
[0017] A signature verification module, configured to encrypt the message digest with the private key of the sender to generate a digital signature, and verify the digital signature with the public key of the sender by the receiver to confirm the identity of the data sender;
[0018] A session key generation module, configured to transmit the public key ID of the receiver, encryption parameters, and other information to corresponding interfaces of the hardware encryption machine according to the request of the issuer, randomly generate a session key by the hardware encryption machine, and export the session key after encrypting it with the public key of the receiver;
[0019] A hardware encryption machine, configured to store and call keys, and complete operations of data encryption and decryption, digest generation, signature verification, and random key generation according to the requests of the data encryption and decryption module, message digest module, signature verification module, and session key generation module;
[0020] Among them, during the data transmission process, the sender needs to first generate a session key, then use the session key to encrypt the plaintext data, calculate the digest of the obtained ciphertext data, and then use the sender's private key to sign the digest; the receiver uses the sender's public key to verify the signature, then calculates the digest and compares the digest, and then decrypts to obtain the session key, and then uses the session key to decrypt to obtain the plaintext data, thereby completing the two-way authentication of the sender and the receiver and realizing the secure transmission of data.
[0021] According to a data security transmission system based on a two-way authentication mechanism provided by the present invention, before enabling the data security transmission system, the following steps are performed to complete the key negotiation process:
[0022] Use a self-used hardware encryption machine to generate a dedicated public-private key pair, where the private key is kept securely by the user, and the public key is used for subsequent key negotiation and data encryption transmission;
[0023] Export the generated public key and provide it to the other user so that the other user can import it into his / her own encryption machine;
[0024] At the same time, the public key provided by the other user is received and imported into the self-use encryption machine to establish the key negotiation basis between the two parties;
[0025] When data transmission involves multiple parties, it is necessary to collect the public keys of all relevant parties and import them into the self-use encryption machine at one time to ensure that the key negotiation process can be completed with all relevant parties, thereby achieving secure data transmission between multiple parties;
[0026] After the key negotiation process is completed, the data is encrypted using the negotiated key or the session key generated based on the key to ensure the security of the data during transmission.
[0027] According to a data security transmission system based on a two-way authentication mechanism provided by the present invention, the encryption process of sending designated data from sender A to receiver B includes:
[0028] Sender A imports plaintext data into the data security transmission system and designates recipient B; the data security transmission system initiates a session key generation request, which includes the key ID of recipient B; the system calls the random key generation interface of the hardware encryption machine to generate a session key; the hardware encryption machine encrypts the session key according to the key ID of recipient B to form an encrypted session key - package 1; wherein, the generation and encryption process of the session key is independently completed by the hardware encryption machine to ensure the security and randomness of the session key.
[0029] A data security transmission system based on a two-way authentication mechanism provided by the present invention. The data security transmission system initiates a data encryption request, which includes plaintext data and a session key ID. The system calls the data encryption interface of the hardware encryption machine. The hardware encryption machine encrypts the plaintext data according to the session key ID to obtain ciphertext data. The hardware encryption machine returns the ciphertext data - Packet 2 to the data security transmission system. Among them, the data encryption process is executed by the hardware encryption machine to ensure that the generation of the ciphertext data complies with the predetermined encryption standard.
[0030] A data security transmission system based on a two-way authentication mechanism provided by the present invention. The data security transmission system initiates a message digest request, which includes Packet 2 and algorithm parameters. The system calls the message digest interface of the hardware encryption machine. The hardware encryption machine calculates the message digest based on the ciphertext data. The hardware encryption machine returns the message digest to the data security transmission system. Among them, the calculation process of the message digest is completed by the hardware encryption machine to ensure the accuracy and non-tamperability of the message digest.
[0031] A data security transmission system based on a two-way authentication mechanism provided by the present invention. The data security transmission system initiates a digital signature request, which includes the message digest and the private key ID of sender A. The system calls the digital signature interface of the hardware encryption machine. The hardware encryption machine performs a digital signature on the message digest to generate a digital signature - Packet 3. The hardware encryption machine returns the digital signature to the data security transmission system. Among them, the generation process of the digital signature is executed by the hardware encryption machine to ensure the validity of the digital signature and the authenticity of the sender's identity. The data security transmission system finally outputs a complete encrypted data packet containing the encrypted session key - Packet 1, the ciphertext data - Packet 2, and the digital signature - Packet 3 to sender A.
[0032] A data security transmission system based on a two-way authentication mechanism provided by the present invention. In the decryption process of receiving Packet 1, Packet 2, and Packet 3 by receiver B, it includes: after the data security transmission system receives Packet 1, Packet 2, and Packet 3, it initiates a signature verification request including Packet 3 and the key ID of sender A. The system calls the signature verification interface of the hardware encryption machine. The hardware encryption machine uses the key ID of sender A to verify the signature of Packet 3 and returns the signature verification result. The data security transmission system analyzes the signature verification result. If the signature verification fails, it determines that the data is not sent by sender A and terminates the decryption process.
[0033] According to a data security transmission system based on a two-way authentication mechanism provided by the present invention, after the signature verification is passed, the data security transmission system initiates a digest comparison request including Packet 2 and Packet 3; the system calls the digest comparison interface of the hardware encryption machine; the hardware encryption machine calculates the message digest of Packet 2 using the digest algorithm and compares it with the message digest in Packet 3, and returns the comparison result; the data security transmission system analyzes the comparison result. If the comparison is inconsistent, it determines that the data is incomplete or tampered with, and terminates the decryption process.
[0034] According to a data security transmission system based on a two-way authentication mechanism provided by the present invention, after the digest comparison is consistent, the data security transmission system initiates a decryption request including Packet 1 and the recipient B's private key ID; the system calls the decryption interface of the hardware encryption machine; the hardware encryption machine decrypts Packet 1 using the private key of the recipient B's private key, obtains the plaintext session key, stores it in the encryption machine, and outputs the session key ID; the hardware encryption machine returns the decryption result; the data security transmission system analyzes the decryption result. If the decryption fails, it determines that the recipient of the data is not B, and terminates the decryption process.
[0035] According to a data security transmission system based on a two-way authentication mechanism provided by the present invention, after the session key is successfully decrypted, the data security transmission system initiates a decryption request including Packet 2 and the session key ID; the system calls the decryption interface of the hardware encryption machine; the hardware encryption machine decrypts Packet 2 using the session key, obtains the plaintext data, and returns the decryption result; the data security transmission system analyzes the decryption result. If the decryption fails, it determines that the session key is abnormal, and terminates the decryption process; if the decryption is successful, the data security transmission system outputs the plaintext data to the recipient B.
[0036] Thus, compared with the prior art, the present invention has the following beneficial effects:
[0037] 1. Improve data security and effectively prevent key leakage: By adopting multiple algorithms and allocating independent keys to different holders, the present invention ensures the non-sharing of keys, thus greatly reducing the risk of data leakage of the entire system caused by the leakage of a single key, effectively narrowing the impact range of key leakage, and improving data security.
[0038] 2. Implement two-way authentication and effectively resist spoofing attacks: During the data transmission process, the present invention uses public-private key pairs for two-way authentication. The sender signs with the private key, and the recipient encrypts with the public key to ensure the authenticity and reliability of the sender's identity; at the same time, the recipient decrypts with the private key, and the sender verifies the signature with the public key to verify the recipient's identity. This two-way authentication mechanism effectively detects the attacks or interception behaviors of spoofers, and guarantees the authenticity of the identities of both parties in the data transmission.
[0039] 3. Enhance the uncrackability of single - time data transmission: Before each data transmission, the present invention uses a hardware encryption machine to randomly generate a session key. This method of dynamically generating the session key improves the uncrackability of single - time data transmission. At the same time, the session key is derived by encrypting with the recipient's public key, making the session key invisible to the system and further ensuring the security of the session key.
[0040] 4. Ensure the security of the key and data processing process: The present invention uses a hardware encryption machine to complete the generation, storage, and invocation of keys, ensuring that the private key does not leave the encryption machine and the key is invisible to the system, greatly ensuring the security of the key. At the same time, the encryption machine is also responsible for operations such as data encryption and decryption, session key generation, signature verification, etc. These operations are all completed in a black - box manner inside the encryption machine, effectively avoiding the risks related to system data and key processing and ensuring the security of the data.
[0041] In summary, through the use of various algorithms, two - way authentication mechanisms, dynamic generation of session keys, and hardware encryption machines and other technical means, the present invention effectively improves the security of data, prevents key leakage and spoofing attacks, enhances the uncrackability of single - time data transmission, and ensures the security of the key and data processing process.
[0042] The following further elaborates on the present invention in detail in conjunction with the attached drawings and specific implementation manners. Description of the Drawings
[0043] Figure 1 is the schematic diagram of the principle of an embodiment of the data - secure transmission system based on a two - way authentication mechanism of the present invention.
[0044] Figure 2 is the flow - chart diagram of the encryption process of the sender implemented in an embodiment of the data - secure transmission system based on a two - way authentication mechanism of the present invention.
[0045] Figure 3 is the flow - chart diagram of the decryption process of the recipient implemented in an embodiment of the data - secure transmission system based on a two - way authentication mechanism of the present invention. Specific Implementation Manner
[0046] To make the objectives, technical solutions, and advantages of the present invention clearer, the technical solutions in the present invention will be clearly and completely described below in conjunction with the attached drawings in the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art without making creative efforts based on the embodiments in the present invention belong to the scope of protection of the present invention.
[0047] Reference to "embodiment" in this document means that the specific features, structures, or characteristics described in connection with the embodiment may be included in at least one embodiment of the present application. The phrase appears in various places in the specification and does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art will explicitly and implicitly understand that the embodiments described herein may be combined with other embodiments.
[0048] See Figure 1 , this embodiment provides a data security transmission system based on a two-way authentication mechanism, including:
[0049] A data encryption and decryption module, configured to transmit plaintext data, key IDs, encryption parameters, and other information to the corresponding interface of the hardware encryption machine according to an encryption request for encryption processing, and transmit ciphertext data, key IDs, encryption parameters, and other information to the corresponding interface of the hardware encryption machine for decryption processing according to a decryption request, and output plaintext data by the hardware encryption machine. Among them, the data encryption and decryption module is adapted to the DES algorithm, AES algorithm, and SM4 algorithm.
[0050] A message digest module, configured to process the encrypted ciphertext data to generate a message digest of a fixed length. Among them, the data is encrypted before transmission. To ensure data integrity and non-repudiation, an adapted algorithm is used to process the ciphertext data to generate a message digest of a fixed length. The message digest is irreversible, and when the data changes or is incomplete, the value of the message digest will change. The message digest module is adapted to the MD5 algorithm, SHA1 algorithm, and SM3 algorithm.
[0051] A signature verification module, configured to encrypt the message digest with the private key of the sender to generate a digital signature, and verify the digital signature with the public key of the sender by the receiver to confirm the identity of the data sender. For example, the issuer A encrypts the message digest with A's private key to generate A's digital signature; the receiver B receives the transmission data claimed to be from A, first verifies the digital signature of A with A's public key, and if the verification passes, it is confirmed that the data is transmitted by A. Among them, the signature verification module is adapted to the RSA algorithm and SM2 algorithm.
[0052] A session key generation module, configured to transmit the receiver's public key ID, encryption parameters, and other information to the corresponding interface of the hardware encryption machine according to the request of the issuer, and the hardware encryption machine randomly generates a session key and exports it after encrypting the session key with the receiver's public key.
[0053] A hardware encryption machine is used for the storage and invocation of keys, ensuring that keys do not leave the encryption machine. All data processing is a black-box operation, greatly guaranteeing the security of data and keys; and it completes operations such as data encryption and decryption, digest generation, signature verification, and random key generation according to the requests of the data encryption and decryption module, message digest module, signature verification module, and session key generation module.
[0054] Among them, during the data transmission process, the sender needs to first generate a session key, then use the session key to encrypt the plaintext data, calculate the digest of the obtained ciphertext data, and then sign the digest with the sender's private key; the receiver uses the sender's public key to verify the signature, then calculates the digest and compares the digests, then decrypts to obtain the session key, and then uses the session key to decrypt to obtain the plaintext data, thereby completing the mutual authentication between the sender and the receiver and realizing the secure transmission of data. It can be seen that there are two benefits: First, the session key is symmetric, ensuring the speed of encryption and decryption (asymmetric keys are used for encryption and decryption, which is slow); Second, encrypting the session key with an asymmetric key can ensure both security and the speed of encryption and decryption.
[0055] In this embodiment, in order to adapt to the DES algorithm, AES algorithm, and SM4 algorithm, the data encryption and decryption module needs to support the following functions:
[0056] Key management
[0057] Key generation: It can generate keys that meet the algorithm requirements; Key storage: Securely store and manage keys; Key distribution: Securely distribute keys during the encryption and decryption processes.
[0058] Algorithm selection
[0059] Algorithm configuration: Allows users or systems to configure which encryption algorithm (DES, AES, SM4) to use; Algorithm switching: During the encryption and decryption processes, it can switch different algorithms as needed.
[0060] Data encryption and decryption
[0061] Data chunking: Divide the data into blocks of a fixed length according to the algorithm requirements; Encryption operation: Invoke the corresponding encryption algorithm to encrypt the chunked data; Decryption operation: Invoke the corresponding decryption algorithm to decrypt the ciphertext; Padding mode: For data that is not an integer multiple of the block length, select an appropriate padding mode (such as PKCS5Padding, PKCS7Padding, ZeroPadding, etc.).
[0062] Encryption mode
[0063] ECB mode: Electronic Codebook mode, where each data block is encrypted independently, suitable for encrypting small amounts of data; CBC mode: Cipher Block Chaining mode, where each data block is XORed with the previous ciphertext block before encryption, suitable for encrypting large amounts of data; Other modes: As needed, other encryption modes such as CFB, OFB, and CTR can also be supported.
[0064] In this embodiment, in order to adapt to the MD5 algorithm, SHA-1 algorithm, and SM3 algorithm, the message digest module needs to support the following functions:
[0065] Algorithm selection
[0066] Algorithm configuration: Allows users or the system to configure which hash algorithm (MD5, SHA-1, SM3) to use; Algorithm switching: During the message digest generation process, different algorithms can be switched as needed.
[0067] Message processing
[0068] Message input: Receives input messages of any length; Message padding: Pads the input message according to the algorithm requirements to meet the algorithm processing requirements; Block processing: Divides the padded message into fixed-length blocks for iterative processing.
[0069] Hash value generation
[0070] Initializing the hash value: Initializes a specific hash value for each algorithm; Iterative calculation: Performs iterative calculations on each block to update the hash value; Outputting the hash value: After the calculation is completed, outputs a hash value of a fixed length.
[0071] Hash value output format
[0072] Hexadecimal representation: Converts the hash value into a hexadecimal string for easy reading and storage; Other formats: As needed, other output formats can also be supported, such as Base64 encoding, etc.
[0073] In this embodiment, in order to adapt to the RSA algorithm and SM2 algorithm, the signature verification module needs to support the following functions:
[0074] Algorithm selection
[0075] Algorithm configuration: Allows users or the system to configure which signature verification algorithm (RSA, SM2) to use; Algorithm switching: During the signature verification process, different algorithms can be switched as needed.
[0076] Key management
[0077] Key Generation: Provide the function of generating RSA key pairs and SM2 key pairs; Key Storage: Support securely storing keys locally or on a remote server; Key Loading: Support loading keys from a local or remote server for signature verification operations.
[0078] Signature Verification Process
[0079] Message Digest: Calculate the digest of the original message, usually using the SHA-256 or SM3 algorithm; Signature: Sign the message digest using the private key; RSA Signature: Encrypt the message digest using the private key; SM2 Signature: Sign the message digest using the elliptic curve signature algorithm; Verification: Verify the signature using the public key; RSA Verification: Decrypt the signature using the public key and compare it with the message digest calculated by oneself; SM2 Verification: Verify the signature using the public key to ensure the authenticity and integrity of the message.
[0080] Output Format
[0081] Signature Format: Convert the signature result to a hexadecimal string or a Base64-encoded string for easy storage and transmission; Verification Result: Output the verification result, usually a boolean value indicating whether the signature is valid.
[0082] Before enabling the data security transmission system, perform the following steps to complete the key negotiation process:
[0083] Use a self-owned hardware encryption machine to generate a dedicated public-private key pair, where the private key is securely saved by the user himself, and the public key is used for subsequent key negotiation and data encryption transmission;
[0084] Export the generated public key and provide it to the other user so that the other user can import it into their self-owned encryption machine;
[0085] At the same time, receive the public key provided by the other user and import it into the self-owned encryption machine to establish the basis for key negotiation between the two parties;
[0086] When data transmission involves multiple parties, it is necessary to collect and summarize the public keys of all relevant parties and import them into the self-owned encryption machine at one time to ensure that the key negotiation process can be completed with all relevant parties, thereby realizing secure data transmission between multiple parties. After completing the key negotiation process, use the negotiated key or the session key generated based on this key to encrypt the data to ensure the security of the data during transmission.
[0087] Among them, the hardware encryption machine is used to generate and store the public-private key pair, and perform data encryption and decryption operations; the export and import processes of the public key need to follow a predetermined security protocol to ensure the authenticity and integrity of the public key; the key negotiation process aims to ensure that a secure key can be shared between two or more parties for subsequent encrypted data transmission.
[0088] It can be seen that users using the data security transmission system need to be equipped with an encryption machine. Before enabling the data security transmission system, they need to use their own hardware encryption machine to generate a dedicated public-private key pair, export the public key and provide it to the other party, and import the other party's public key into their own encryption machine to complete the key negotiation process between the two parties. When data transmission involves multiple parties, collect the public keys of all parties and import them into the self-use encryption machine at one time.
[0089] In this embodiment, in the encryption process of sender A sending specified data to receiver B, it includes:
[0090] Sender A imports the plaintext data into the data security transmission system and specifies receiver B; the data security transmission system initiates a session key generation request, which includes the key ID of receiver B; the system calls the random key generation interface of the hardware encryption machine to generate a session key; the hardware encryption machine encrypts the session key according to the key ID of receiver B to form an encrypted session key - Packet 1; among them, the generation and encryption process of the session key are independently completed by the hardware encryption machine to ensure the security and randomness of the session key.
[0091] The data security transmission system initiates a data encryption request, which includes the plaintext data and the session key ID; the system calls the data encryption interface of the hardware encryption machine; the hardware encryption machine encrypts the plaintext data according to the session key ID to obtain ciphertext data; the hardware encryption machine returns the ciphertext data - Packet 2 to the data security transmission system; among them, the data encryption process is executed by the hardware encryption machine to ensure that the generation of the ciphertext data complies with the predetermined encryption standard.
[0092] The data security transmission system initiates a message digest request, which includes Packet 2 and algorithm parameters; the system calls the message digest interface of the hardware encryption machine; the hardware encryption machine calculates the message digest based on the ciphertext data; the hardware encryption machine returns the message digest to the data security transmission system; among them, the calculation process of the message digest is completed by the hardware encryption machine to ensure the accuracy and non-tamperability of the message digest.
[0093] The data security transmission system initiates a digital signature request, which includes a message digest and the sender A's private key ID; the system calls the digital signature interface of the hardware encryption machine; the hardware encryption machine performs a digital signature on the message digest to generate a digital signature - Packet 3; the hardware encryption machine returns the digital signature to the data security transmission system; among them, the generation process of the digital signature is executed by the hardware encryption machine to ensure the validity of the digital signature and the authenticity of the sender's identity; the data security transmission system finally outputs a complete encrypted data packet containing the encrypted session key - Packet 1, ciphertext data - Packet 2, and digital signature - Packet 3 to the sender A.
[0094] Specifically, as Figure 2 shown, the encryption process of the sender in this embodiment includes the following steps:
[0095] 1. Sender A needs to send specified data to receiver B. Sender A imports the plaintext data into the data security transmission system, specifies receiver B, and initiates data encryption.
[0096] 2. The data security transmission system initiates a session key generation request, which includes the key ID of receiver B. At this time, receiver B is specified.
[0097] 3. The data security transmission system calls the random key generation interface of the hardware encryption machine to initiate a request.
[0098] 4. The hardware encryption machine randomly generates a session key.
[0099] 5. The hardware encryption machine encrypts the session key according to the key ID of receiver B.
[0100] 6. The hardware encryption machine returns the encrypted session key - Packet 1 to the data security transmission system.
[0101] 7. The data security transmission system initiates a data encryption request, which includes the plaintext data and the session key ID.
[0102] 8. The data security transmission system calls the data encryption interface of the hardware encryption machine to initiate a request.
[0103] 9. The hardware encryption machine encrypts the plaintext data according to the session key ID to obtain ciphertext data.
[0104] 10. The hardware encryption machine returns the ciphertext data - Packet 2 to the data security transmission system.
[0105] 11. The data security transmission system initiates a message digest request, which includes Packet 2 and algorithm parameters.
[0106] 12. The data security transmission system calls the message digest interface of the hardware encryption machine to initiate a request.
[0107] 13. The hardware encryption machine calculates a message digest based on the ciphertext data;
[0108] 14. The hardware encryption machine returns the message digest to the data security transmission system;
[0109] 15. The data security transmission system initiates a digital signature request, which includes the message digest and A's own key ID. At this time, the specified sender is A;
[0110] 16. The data security transmission system calls the digital signature interface of the hardware encryption machine to initiate a request;
[0111] 17. The hardware encryption machine digitally signs the message digest;
[0112] 18. The hardware encryption machine returns the digital signature - Packet 3 to the data security transmission system;
[0113] 19. The data security transmission system outputs Packet 1, Packet 2, and Packet 3 to the sender A.
[0114] In this embodiment, in the decryption process of the receiver B receiving Packets 1, 2, and 3 from the sender A, it includes: after the data security transmission system receives Packets 1, 2, and 3, it initiates a signature verification request that includes Packet 3 and the sender A's key ID; the system calls the signature verification interface of the hardware encryption machine; the hardware encryption machine uses the sender A's key ID to verify the signature of Packet 3 and returns the signature verification result; the data security transmission system analyzes the signature verification result. If the signature verification fails, it determines that the data is not sent by the sender A and terminates the decryption process.
[0115] After the signature verification passes, the data security transmission system initiates a digest comparison request that includes Packets 2 and 3; the system calls the digest comparison interface of the hardware encryption machine; the hardware encryption machine uses the digest algorithm to calculate the message digest of Packet 2 and compares it with the message digest in Packet 3, and returns the comparison result; the data security transmission system analyzes the comparison result. If the comparison is inconsistent, it determines that the data is incomplete or tampered with and terminates the decryption process.
[0116] After the digest comparison is consistent, the data security transmission system initiates a decryption request that includes Packet 1 and the receiver B's own key ID; the system calls the decryption interface of the hardware encryption machine; the hardware encryption machine uses the private key of the receiver B's own key to decrypt Packet 1, obtains the plaintext session key, stores it in the encryption machine, and outputs the session key ID; the hardware encryption machine returns the decryption result; the data security transmission system analyzes the decryption result. If the decryption fails, it determines that the receiver of the data is not B and terminates the decryption process.
[0117] After the session key is successfully decrypted, the data security transmission system initiates a decryption request containing Packet 2 and the session key ID; the system calls the decryption interface of the hardware encryption machine; the hardware encryption machine decrypts Packet 2 using the session key to obtain the plaintext data and returns the decryption result; the data security transmission system analyzes the decryption result. If the decryption fails, it determines that the session key is abnormal and terminates the decryption process; if the decryption is successful, the data security transmission system outputs the plaintext data to the receiving party B.
[0118] Specifically, as Figure 3 shown, the receiving party decryption process includes the following steps:
[0119] 1. The receiving party B receives Packets 1, 2, and 3 from the sending party A. The receiving party B imports Packets 1, 2, and 3 into the data security transmission system, specifies the sending party as A, and initiates data decryption;
[0120] 2. The data security transmission system initiates a signature verification request, which includes Packet 3 and the key ID of the sending party A;
[0121] 3. The data security transmission system calls the signature verification interface of the hardware encryption machine to initiate a request;
[0122] 4. The hardware encryption machine verifies the signature of Packet 3 using the key ID of the sending party A;
[0123] 5. The hardware encryption machine returns the signature verification result to the data security transmission system;
[0124] 6. The data security transmission system analyzes the signature verification result. If the signature verification fails, it is considered that the data is not sent by the sending party A, and the process ends; if the signature verification passes, the next step is executed;
[0125] 7. The data security transmission system initiates a digest comparison request, which includes Packets 2 and 3;
[0126] 8. The data security transmission system calls the digest comparison interface of the hardware encryption machine to initiate a request;
[0127] 9. The hardware encryption machine calculates the message digest of Packet 2 using the digest algorithm;
[0128] 10. The hardware encryption machine compares the message digest calculated from Packet 2 with the message digest of Packet 3;
[0129] 11. The hardware encryption machine returns the digest comparison result to the data security transmission system;
[0130] 12. The data security transmission system analyzes the digest comparison result. If the comparison is inconsistent, it is considered that the data is incomplete or tampered with, and the process ends; if the comparison is consistent, the next step is executed;
[0131] 13. The data security transmission system initiates a decryption request, and the request includes Packet 1 and the private key ID of Party B for its own use;
[0132] 14. The data security transmission system calls the decryption interface of the hardware encryption machine to initiate a request;
[0133] 15. The hardware encryption machine uses the private key of Party B's private key to decrypt Packet 1 to obtain the plaintext session key;
[0134] 16. The hardware encryption machine stores the plaintext session key in the encryption machine and outputs the session key ID;
[0135] 17. The hardware encryption machine returns the decryption result to the data security transmission system;
[0136] 18. The data security transmission system analyzes the decryption result. If the decryption fails, it is considered that the recipient of the data is not Party B, and the process ends; if the decryption is successful, the next step is executed;
[0137] 19. The data security transmission system initiates a decryption request, and the request includes Packet 2 and the session key ID;
[0138] 20. The data security transmission system calls the decryption interface of the hardware encryption machine to initiate a request;
[0139] 21. The hardware encryption machine uses the session key to decrypt Packet 2 to obtain the plaintext data;
[0140] 22. The hardware encryption machine returns the decryption result to the data security transmission system;
[0141] 23. The data security transmission system analyzes the decryption result. If the decryption fails, it is considered that the session key of the data is abnormal, and the process ends; if the decryption is successful, the next step is executed;
[0142] 24. The data security transmission system outputs the plaintext data to the recipient Party B, and the process ends.
[0143] In summary, in this embodiment, by adopting various algorithms, a two-way authentication mechanism, dynamically generating session keys, and a hardware encryption machine and other technical means, the security of data is effectively improved, the leakage of keys and spoofing attacks are prevented, the non-crackability of a single data transmission is enhanced, and the security of the key and the data processing process is guaranteed.
[0144] Furthermore, in this embodiment, by adopting various algorithms and allocating independent keys to different holders, the non-sharing of keys is ensured, thereby greatly reducing the risk of data leakage of the entire system caused by the leakage of a single key, effectively narrowing the scope of influence of key leakage, and improving the security of data.
[0145] Furthermore, during the data transmission process, this embodiment uses public-private key pairs for two-way authentication. The sender uses the private key for signing, and the receiver uses the public key for encryption, ensuring the authenticity and reliability of the sender's identity. At the same time, the receiver uses the private key for decryption, and the sender uses the public key for signature verification to verify the receiver's identity. This two-way authentication mechanism effectively detects attacks or interception behaviors by impostors and guarantees the authenticity of the identities of both parties in the data transmission.
[0146] Furthermore, before each data transmission, this embodiment uses a hardware encryption machine to randomly generate a session key. This way of dynamically generating the session key improves the uncrackability of a single data transmission. At the same time, the session key is derived from the encryption of the receiver's public key, making the session key invisible to the system and further ensuring the security of the session key.
[0147] Furthermore, this embodiment uses a hardware encryption machine to complete the generation, storage, and invocation of keys, ensuring that the private key does not leave the encryption machine and the key pair is invisible to the system, greatly guaranteeing the security of the key. At the same time, the encryption machine is also responsible for processing data encryption and decryption, session key generation, signature verification, etc. These operations are all completed in a black box manner inside the encryption machine, effectively avoiding risks related to system data and key processing and guaranteeing the security of the data.
[0148] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity in description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.
[0149] The above embodiments are only the preferred embodiments of the present invention and cannot be used to limit the scope of protection of the present invention. Any non-substantial changes and substitutions made by those skilled in the art based on the present invention belong to the scope required to be protected by the present invention.
Claims
1. A data security transmission system based on a two-way authentication mechanism, characterized in that: include: The data encryption and decryption module is used to transmit the information to the corresponding interface of the hardware encryption machine for encryption processing according to the encryption request, and transmit the information to the corresponding interface of the hardware encryption machine for decryption processing according to the decryption request; A message digest module is used to process the encrypted ciphertext data to generate a message digest of a fixed length; The signature verification module is used for the sender to encrypt the message digest using its private key to generate a digital signature, and for the receiver to verify the digital signature using the sender's public key to confirm the identity of the sender of the data; The session key generation module is used to transmit the recipient's information to the corresponding interface of the hardware encryption machine according to the request of the issuer, and the hardware encryption machine randomly generates a session key, and encrypts the session key according to the public key of the recipient and then exports it; Hardware encryption machine, used for key storage and call, and completes data encryption and decryption, digest generation, signature verification, and random key generation operations according to the requests of the data encryption and decryption module, message digest module, signature verification module, and session key generation module; Among them, among them, During the data transmission process, the sender needs to generate a session key first, then use the session key to encrypt the plaintext data, calculate the digest of the ciphertext data, and then sign the digest using the sender's private key; the receiver uses the sender's public key to verify the signature, then calculates the digest and compares the digest, then decrypts it to obtain the session key, and then uses the session key to decrypt the plaintext data, thereby completing the two-way authentication of the sender and receiver and achieving secure data transmission.
2. The system according to claim 1, characterized in that: Before enabling the data security transmission system, perform the following steps to complete the key negotiation process: Use a self-used hardware encryption machine to generate a dedicated public-private key pair, where the private key is kept securely by the user, and the public key is used for subsequent key negotiation and data encryption transmission; Export the generated public key and provide it to the other user so that the other user can import it into his / her own encryption machine; At the same time, the public key provided by the other user is received and imported into the self-use encryption machine to establish the key negotiation basis between the two parties; When data transmission involves multiple parties, it is necessary to collect the public keys of all relevant parties and import them into the self-use encryption machine at one time to ensure that the key negotiation process can be completed with all relevant parties, thereby achieving secure data transmission between multiple parties; After the key negotiation process is completed, the data is encrypted using the negotiated key or the session key generated based on the key to ensure the security of the data during transmission.
3. The system according to claim 2, characterized in that: The encryption process of the sender A sending the specified data to the receiver B includes: Sender A imports plaintext data into the data security transmission system and designates recipient B; the data security transmission system initiates a session key generation request, which includes the key ID of recipient B; the system calls the random key generation interface of the hardware encryption machine to generate a session key; the hardware encryption machine encrypts the session key according to the key ID of recipient B to form an encrypted session key - package 1; wherein, the generation and encryption process of the session key is independently completed by the hardware encryption machine to ensure the security and randomness of the session key.
4. The system according to claim 3, characterized in that: The data security transmission system initiates a data encryption request, which includes plaintext data and a session key ID; the system calls the data encryption interface of the hardware encryption machine; the hardware encryption machine encrypts the plaintext data according to the session key ID to obtain ciphertext data; The hardware encryption machine returns the ciphertext data - package 2 to the data security transmission system; wherein, the data encryption process is executed by the hardware encryption machine to ensure that the generation of the ciphertext data complies with the predetermined encryption standard.
5. The system according to claim 4, characterized in that: The data security transmission system initiates a message digest request, which includes package 2 and algorithm parameters; the system calls the message digest interface of the hardware encryption machine; the hardware encryption machine calculates the message digest based on the ciphertext data; the hardware encryption machine returns the message digest to the data security transmission system; wherein, the calculation process of the message digest is completed by the hardware encryption machine to ensure the accuracy and non-tamperability of the message digest.
6. The system according to claim 5, characterized in that: The data security transmission system initiates a digital signature request, which includes a message digest and the sender A's own key ID; the system calls the digital signature interface of the hardware encryption machine; the hardware encryption machine digitally signs the message digest to generate a digital signature - package 3; the hardware encryption machine returns the digital signature to the data security transmission system; wherein, the digital signature generation process is executed by the hardware encryption machine to ensure the validity of the digital signature and the authenticity of the sender's identity; the data security transmission system finally outputs a complete encrypted data packet to sender A including the encrypted session key - package 1, ciphertext data - package 2 and digital signature - package 3.
7. The system according to claim 6, characterized in that: The decryption process of receiving packet 1, packet 2, and packet 3 from sender A at receiver B includes the following steps: It also includes a signature verification step: after the data security transmission system receives package 1, package 2, and package 3, it initiates a signature verification request containing package 3 and the key ID of sender A; the system calls the signature verification interface of the hardware encryption machine; the hardware encryption machine uses the key ID of sender A to verify the signature of package 3 and return the verification result; the data security transmission system analyzes the signature verification result, and if the verification fails, it is determined that the data is not sent by sender A, and the decryption process is terminated.
8. The system according to claim 7, characterized in that: After the signature verification is passed, the data security transmission system initiates a digest comparison request including package 2 and package 3; the system calls the digest comparison interface of the hardware encryption machine; the hardware encryption machine uses the digest algorithm to calculate the message digest of package 2, and compares it with the message digest in package 3, and returns the comparison result; the data security transmission system analyzes the comparison result, and if the comparison is inconsistent, it is determined that the data is incomplete or tampered with, and the decryption process is terminated.
9. The system according to claim 8, characterized in that: After the digests are matched, the data security transmission system initiates a decryption request containing package 1 and the recipient B's private key ID; the system calls the decryption interface of the hardware encryption machine; the hardware encryption machine uses the private key of the recipient B's private key to decrypt package 1, obtains the plaintext session key, stores it in the encryption machine, and outputs the session key ID; the hardware encryption machine returns the decryption result; The data security transmission system analyzes the decryption result. If the decryption fails, it determines that the recipient of the data is not B and terminates the decryption process.
10. The system according to claim 9, characterized in that: After the session key is successfully decrypted, the data security transmission system initiates a decryption request containing package 2 and the session key ID; the system calls the decryption interface of the hardware encryption machine; the hardware encryption machine uses the session key to decrypt package 2, obtains the plaintext data, and returns the decryption result; The data security transmission system analyzes the decryption result. If the decryption fails, it determines that the session key is abnormal and terminates the decryption process. If the decryption is successful, the data security transmission system outputs the plaintext data to the recipient B.
Citation Information
Patent Citations
Data link trusted transmission method and system
CN114826656A
Lightweight Internet of Things equipment bidirectional authentication and secure communication method and system
CN117997516A
Authentication method and device
CN118057760A
Data transmission method and system based on bidirectional identity authentication
CN118646586A
Trusted industrial control system-based trusted transmission method and system
CN119109657A