Adaptive encryption communication method and device and electronic equipment

By analyzing network configuration parameters and establishing corresponding encryption channels according to encryption type, the security risks of a single encryption method in the prior art are solved, adaptive encrypted communication is realized, and communication security and compatibility are improved.

CN120074938APending Publication Date: 2025-05-30中国邮政储蓄银行股份有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510257820.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-05
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

In the prior art, WebSocket communication only supports one encryption method, which poses security risks and is not compatible with supporting trade secrets and general password standards, and front-end web pages cannot directly select encryption algorithm standards.

Method used

By analyzing network configuration parameters, establish a commercial encryption channel or a general encryption channel according to the encryption type identification. If the general encryption channel is not established successfully, switch to the commercial encryption channel to realize adaptive encrypted communication.

Benefits of technology

It solves the security risks brought by a single encryption method, realizes an adaptive switching encryption solution, improves communication security, and supports the compatibility of trade secrets and common password standards.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074938A_ABST
    Figure CN120074938A_ABST
Patent Text Reader

Abstract

The invention provides a self-adaptive encryption communication method and device and electronic equipment. The method comprises the steps that network configuration parameters are analyzed, the network configuration parameters are parameters representing configuration of a network transmission protocol and at least comprise encryption type identification, and the encryption type identification represents the encryption type; when the encryption type identifier represents that the encryption type is commercial encryption, a commercial encryption channel is established, when the encryption type identifier represents that the encryption type is not commercial encryption, a universal encryption channel is established, the encryption type of the commercial encryption channel is commercial encryption, and the encryption type of the universal encryption channel is universal encryption; the encryption ranges of the commercial encryption and the universal encryption are different; and under the condition that the general encryption channel is not successfully established, establishing a commercial encryption channel, and performing network data transmission through the encryption channel. According to the invention, the problem that the existing communication method only supports one encryption mode and is easy to generate potential safety hazards is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technologies, and in particular, to an adaptive encryption communication method, apparatus, computer-readable storage medium, and electronic device. Background Art

[0002] WebSocket is a network protocol for full-duplex communication established over a single TCP (Transmission Control Protocol) network connection. This approach enables WebSocket to conduct real-time communication between a browser and a server without the need to send multiple HTTP requests to obtain data. For example, in a scenario using HTTP requests, the browser actively requests data from the server based on the user's operations on the web page, and the server returns the response data. However, the server does not actively send messages to the client. In scenarios such as web games, a large amount of data needs to be actively requested between the client and the server. The WebSocket connection is persistent and can remain open until one party actively closes the connection. Therefore, WebSocket does not need to continuously establish and close connections, making it very suitable for scenarios with high requirements for real-time two-way communication.

[0003] For the existing WebSocket communication solutions supported by browsers, they first determine the protocol prefix string of the link address. If it starts with ws: / / , an unencrypted data communication method is used; if it starts with wss: / / , general password standards are directly used for encrypted communication. This solution does not support China's commercial encryption standards at all and cannot support the promotion of the commercial encryption application ecosystem. The disadvantages are as follows:

[0004] ① It does not support China's independent commercial encryption standard system: It completely does not support China's commercial encryption algorithms and the trust system of commercial encryption certificates; thus, it cannot break away from the general password certificate trust management system controlled by Western countries and cannot solve the security risks of general password algorithms.

[0005] ② It cannot adaptively support and be compatible with commercial encryption standards and general password standards: The existing WebSocket encryption communication functions supported by browsers cannot first attempt to establish a connection using general passwords and then switch to commercial passwords to attempt to establish a connection. The existing solutions cannot be compatible with commercial encryption standards and general password standards.

[0006] ③The algorithm standard that does not support the front-end web page to select an encrypted connection: None of the existing solutions provide a JS (JavaScript) interface for controlling the encryption standard selected by WebSocket, resulting in the front-end web page being able to only create an encrypted connection and unable to directly select the encryption algorithm standard. Furthermore, every time the background service of the commercial encryption system is connected, the general password system will be tried first, and if it fails, the commercial encryption system will be used to establish a connection; this reduces the speed of establishing a commercial encryption connection. Summary of the Invention

[0007] The main object of the present application is to provide an adaptive encryption communication method, device, computer-readable storage medium and electronic device, so as to at least solve the problem that the communication method in the prior art only supports one encryption method and is prone to security risks.

[0008] To achieve the above object, according to one aspect of the present application, an adaptive encryption communication method is provided, including: parsing network configuration parameters, where the network configuration parameters are parameters representing the configuration of the network transmission protocol and at least include an encryption type identifier, and the encryption type identifier represents the type of encryption; in the case where the encryption type identifier represents that the encryption type is commercial encryption, establishing a commercial encryption channel, and in the case where the encryption type identifier represents that the encryption type is not the commercial encryption, establishing a general encryption channel, where the encryption type of the commercial encryption channel is the commercial encryption, the encryption type of the general encryption channel is general encryption, and the encryption standards of the commercial encryption and the general encryption are different; in the case where the general encryption channel cannot be established successfully, establishing the commercial encryption channel and performing network data transmission through the encryption channel, where the encryption channel includes the general encryption channel and the commercial encryption channel.

[0009] Optionally, establishing a commercial encryption channel includes: generating a commercial encryption connection request, and sending the commercial encryption connection request to a server so that the server generates a first response message, where the commercial encryption connection request is a request for applying for commercial encryption communication with the server, and the first response message is a response message generated by the server in response to the commercial encryption connection request; receiving the first response message sent by the server, generating commercial encryption key information and sending it to the server to establish the commercial encryption channel, where the commercial encryption key information is the key information in the process of communicating using the commercial encryption channel.

[0010] Optionally, establish a general encryption channel, including: generating a general encryption connection request, and sending the general encryption connection request to a server to enable the server to generate second response information, where the general encryption connection request is a request for general encryption communication with the server, and the second response information is a response message generated by the server in response to the general encryption connection request; receiving the second response information sent by the server, generating general key information and sending it to the server to establish the general encryption channel, where the general key information is the key information during communication using the general encryption channel.

[0011] Optionally, parse network configuration parameters, including: obtaining a communication address, where the communication address is the address for communication connection between a browser and a server and at least includes an identifier indicating whether the browser and the server perform encrypted communication; parsing the network configuration parameters when the communication address indicates that the browser and the server perform encrypted communication.

[0012] Optionally, the method further includes: when the communication address indicates that the browser and the server perform non-encrypted communication, establishing a non-encrypted channel and performing network data transmission through the commercial encryption channel, where the non-encrypted channel is a channel for network data transmission without using a password.

[0013] Optionally, perform network data transmission through an encryption channel, including: encrypting network data using key information and sending the encrypted network data to a server so that the server decrypts the encrypted network data using the key information to obtain the network data when receiving the encrypted network data, where the key information includes commercial encryption key information and general key information, the commercial encryption key information is the key information during communication using the commercial encryption channel, and the general key information is the key information during communication using the general encryption channel; receiving the encrypted network data sent by the server and decrypting the encrypted network data using the key information to obtain the network data.

[0014] Optionally, the method further includes: when the establishment of the commercial encryption channel or the general encryption channel fails, obtaining error information sent by the server and displaying it on the interface, where the error information is information indicating that the encrypted connection between the browser and the server fails.

[0015] According to another aspect of the present application, an adaptive encryption communication device is provided, including: a parsing unit for parsing network configuration parameters, where the network configuration parameters are parameters representing the configuration of a network transmission protocol and at least include an encryption type identifier, and the encryption type identifier characterizes the type of encryption; a establishing unit for establishing a commercial encryption channel when the encryption type identifier characterizes that the encryption type is commercial encryption, and establishing a general encryption channel when the encryption type identifier characterizes that the encryption type is not commercial encryption, where the encryption type of the commercial encryption channel is commercial encryption, the encryption type of the general encryption channel is general encryption, and the encryption standards of the commercial encryption and the general encryption are different; a transmission unit for establishing the commercial encryption channel when the establishment of the general encryption channel fails, and performing network data transmission through the encryption channel, where the encryption channel includes the general encryption channel and the commercial encryption channel.

[0016] According to yet another aspect of the present application, a computer-readable storage medium is provided, where the computer-readable storage medium includes a stored program, and when the program runs, it controls the device where the computer-readable storage medium is located to execute any one of the above-mentioned adaptive encryption communication methods.

[0017] According to still another aspect of the present application, an electronic device is provided, including: one or more processors, a memory, and one or more programs, where the one or more programs are stored in the memory and are configured to be executed by the one or more processors, and the one or more programs include those for executing any one of the above-mentioned adaptive encryption communication methods.

[0018] Applying the technical solution of the present application, network configuration parameters are parsed. The network configuration parameters are parameters representing the configuration of a network transmission protocol and at least include an encryption type identifier, and the encryption type identifier characterizes the type of encryption; when the encryption type identifier characterizes that the encryption type is commercial encryption, a commercial encryption channel is established, and when the encryption type identifier characterizes that the encryption type is not commercial encryption, a general encryption channel is established. The encryption scopes of commercial encryption and general encryption are different; when the establishment of the general encryption channel fails, a commercial encryption channel is established, and network data transmission is performed through the encryption channel. The encryption channel includes the general encryption channel and the commercial encryption channel. Compared with the prior art where there are certain security risks as only one encryption method can be used for encryption, in the present application, commercial encryption channels and general encryption channels are established under different circumstances, and different encryption channels are adaptively adjusted according to different situations, avoiding the security risks brought by only using one encryption method. Therefore, it can solve the problem in the prior art that only one encryption method is supported and is prone to security risks, achieving the effect of adaptively switching the encryption scheme and improving communication security. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] The accompanying drawings forming a part of this application are used to provide a further understanding of this application. The schematic embodiments and descriptions thereof of this application are used to explain this application and do not unduly limit this application. In the drawings:

[0020] Figure 1 A hardware structure block diagram of a mobile terminal for implementing an adaptive encryption communication method provided by an embodiment of this application is shown;

[0021] Figure 2 A flowchart of an adaptive encryption communication method provided by an embodiment of this application is shown;

[0022] Figure 3 A schematic diagram of code modules of a specific adaptive encryption communication method provided by an embodiment of this application is shown;

[0023] Figure 4 A flowchart of a specific adaptive encryption communication method provided by an embodiment of this application is shown;

[0024] Figure 5 A structure block diagram of an adaptive encryption communication device provided by an embodiment of this application is shown.

[0025] Among them, the above-mentioned drawings include the following reference numerals:

[0026] 102, processor; 104, memory; 106, transmission device; 108, input / output device. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0027] It should be noted that, without conflict, the embodiments in this application and the features in the embodiments can be combined with each other. The following will describe this application in detail with reference to the drawings and in combination with the embodiments.

[0028] In order to enable those skilled in the art to better understand the solution of this application, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without creative efforts shall fall within the scope of protection of this application.

[0029] It should be noted that the terms "first", "second", etc. in the description, claims and the above-mentioned drawings of this application are used to distinguish similar objects, and do not necessarily describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so as to implement the embodiments of the present application described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not necessarily limit to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0030] For the convenience of description, some nouns or terms related to the embodiments of this application are described below:

[0031] WebSocket is a real-time two-way communication protocol framework that can support uninterrupted data transmission and is mainly used in scenarios of real-time data communication. WebSocket connections support unencrypted data communication, and unencrypted network connections use the ws: / / protocol prefix. It also supports encrypted data communication, using the TLS (Transport Layer Security) protocol to protect the security of data, and the encrypted connection uses the wss: / / protocol prefix; it can perform encrypted communication between the browser and the server; WebSocket has relatively high security and can protect the security of data. Existing browsers support the above two WebSocket communication methods: unencrypted data communication and encrypted data communication; however, for encrypted data communication, only the general cryptographic standard is supported for encryption.

[0032] The general encryption standard is a set of cryptographic standard systems first proposed and dominated abroad. The standard system was formulated very early and has a relatively wide application range. However, it also has serious disadvantages: (1) The trust management system of general cryptographic certificates is completely controlled by foreign countries, and foreign countries can control and damage the domestic general cryptographic certificate system; (2) The security protocols and encryption algorithms are all formulated abroad, and there may be backdoors in the general cryptographic algorithm system, posing a security risk of being cracked. Therefore, there are uncontrollable factors in the key links of general cryptographic applications. Once exploited and attacked, it will cause a major impact on the network security of this region.

[0033] The commercial encryption standard is a cryptographic algorithm and certificate management standard that is completely independently controllable in China. The advantages of this standard are: (1) The security level of the encryption algorithm is high, the cracking difficulty is large, and it is more secure; (2) The commercial encryption certificate trust system is completely independently controllable, eliminating the uncontrollable factors in the key links of cryptographic applications. However, the commercial encryption standard was formulated relatively late, and the application ecosystem has not been fully established, and there are still relatively few websites and application systems using commercial encryption.

[0034] As introduced in the background art, in the prior art, the communication method only supports one encryption method, which is prone to security risks. To solve the problem of security risks in communication encryption, an embodiment of the present application provides an adaptive encryption communication method, device, computer-readable storage medium, and electronic device.

[0035] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described with reference to the accompanying drawings in the embodiments of the present invention.

[0036] The method embodiments provided in the embodiments of the present application can be executed on a mobile terminal, a computer terminal, or a similar computing device. Taking running on a mobile terminal as an example, Figure 1 is a hardware structure block diagram of a mobile terminal of an adaptive encryption communication method according to an embodiment of the present invention. As Figure 1 shown, the mobile terminal may include one or more ( Figure 1 only one is shown in Figure 1 a processor 102 (the processor 102 may include, but is not limited to, a processing device such as a microprocessor MCU or a programmable logic device FPGA) and a memory 104 for storing data. Among them, the above mobile terminal may further include a transmission device 106 for communication functions and an input / output device 108. Those of ordinary skill in the art can understand that Figure 1 the structure shown in Figure 1 is only schematic and does not limit the structure of the above mobile terminal. For example, the mobile terminal may further include more or fewer components than

[0037] The memory 104 can be used to store computer programs, for example, software programs and modules of application software, such as the computer program corresponding to the adaptive encryption communication method in the embodiments of the present invention. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, that is, implements the above method. The memory 104 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely disposed relative to the processor 102, and these remote memories can be connected to the mobile terminal through a network. Examples of the above network include but are not limited to the Internet, enterprise intranet, local area network, mobile communication network, and combinations thereof. The transmission device 106 is used to receive or send data via a network. Specific examples of the above network may include a wireless network provided by a communication provider of the mobile terminal. In one instance, the transmission device 106 includes a network adapter (Network Interface Controller, abbreviated as NIC), which can be connected to other network devices through a base station and thus can communicate with the Internet. In one instance, the transmission device 106 may be a radio frequency (Radio Frequency, abbreviated as RF) module, which is used to communicate with the Internet wirelessly.

[0038] In this embodiment, an adaptive encryption communication method running on a mobile terminal, a computer terminal, or a similar computing device is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.

[0039] Figure 2 It is a flowchart of the adaptive encryption communication method according to an embodiment of the present application. As Figure 2 shown, the method includes the following steps:

[0040] Step S201, parsing network configuration parameters, where the network configuration parameters are parameters representing the configuration of the network transmission protocol and at least include an encryption type identifier, and the encryption type identifier characterizes the type of encryption;

[0041] Specifically, the present application is a WebSocket adaptive encryption communication method based on a browser. "Parsing network configuration parameters" is the key first step, which refers to the process of the browser analyzing and interpreting the network configuration parameters in the WebSocket connection request sent by the front-end web page when it receives the request. These network configuration parameters contain detailed information about the connection, such as the communication address and the encryption type identifier, where the encryption type identifier is used to characterize the encryption type to be used in this communication. The encryption type identifier is used to indicate whether the WebSocket connection should be encrypted using a general cryptographic standard or a commercial cryptographic standard. The encryption standards for general encryption and commercial encryption are different.

[0042] Step S202, in the case where the encryption type identifier characterizes the encryption type as commercial encryption, establish a commercial encryption channel; in the case where the encryption type identifier characterizes the encryption type as not being the commercial encryption, establish a general encryption channel. Among them, the encryption type of the commercial encryption channel is the commercial encryption, the encryption type of the general encryption channel is general encryption, and the encryption standards for the commercial encryption and the general encryption are different;

[0043] Specifically, in the WebSocket adaptive encryption communication technology based on a browser, the parsing result of the encryption type identifier directly affects the type of encryption channel established subsequently. If the parsed encryption type identifier indicates that the encryption type is commercial encryption (i.e., the domestic commercial cryptographic standard of our country), then the system will establish a commercial encryption channel; conversely, if the identifier indicates that the encryption type is general encryption (i.e., the internationally common cryptographic standard), a general encryption channel will be established. The "different encryption standards" here means that there are differences between commercial encryption and general encryption in aspects such as algorithm selection, certificate management system, and trust root, which are specifically reflected in the following aspects:

[0044] Algorithm selection: The commercial encryption channel will adopt domestic self-designed commercial cryptographic algorithms such as SM2, SM3, SM4, etc., while the general encryption channel may adopt internationally widely recognized algorithms such as RSA, AES, SHA, etc. Commercial cryptographic algorithms usually pay more attention to security and self-control in design, while general cryptographic algorithms have higher interoperability and acceptance internationally.

[0045] Certificate management system: The commercial encryption channel uses the domestic commercial cryptographic certificate system (GMCA), while the general encryption channel relies on the international PKI (Public Key Infrastructure) system.

[0046] Root of trust: The root of trust for the commercial encryption channel is based on China's commercial cryptography certificate system, while the root of trust for the general encryption channel is the internationally common standard system. The difference in the root of trust means that during the authentication process, the system will judge the validity of digital certificates based on different certificate chains.

[0047] Step S203, in the case where the general encryption channel cannot be established successfully, establish the commercial encryption channel and perform network data transmission through the encryption channel, where the encryption channel includes the general encryption channel and the commercial encryption channel.

[0048] Specifically, in a WebSocket connection adopting an adaptive encryption communication strategy, the system first attempts to establish a general encryption channel. The general encryption channel uses internationally widely accepted encryption standards, such as the wss: / / connection based on the TLS protocol. However, if the attempt to establish the general encryption channel fails, the system does not immediately abandon the connection attempt but enters the next stage and attempts to establish a commercial encryption channel. The commercial encryption channel uses China's independent commercial cryptography standards, which include specific encryption algorithms (such as SM2, SM3, SM4) and a digital certificate management system (GMCA). These standards are significantly different from international common standards in terms of algorithm design and the root of trust for certificates, aiming to enhance data security and ensure autonomy and controllability. By first attempting the general encryption channel and then the commercial encryption channel, it is ensured that even when the general encryption standard is unavailable or not supported, the system can still achieve encrypted communication through the commercial encryption channel, avoiding communication interruption caused by the failure to establish the encryption channel. Commercial cryptography standards usually provide a higher encryption level and security guarantee, which is particularly important for the protection of critical data. Therefore, when the general encryption channel fails to be established, encrypted communication through the commercial encryption channel can provide an additional security layer.

[0049] Through this embodiment, network configuration parameters are parsed. The network configuration parameters are parameters representing the configuration of a network transmission protocol and at least include an encryption type identifier, where the encryption type identifier characterizes the type of encryption; in the case where the encryption type identifier characterizes the encryption type as commercial encryption, a commercial encryption channel is established, and in the case where the encryption type identifier characterizes the encryption type as not commercial encryption, a general encryption channel is established, and the encryption scopes of commercial encryption and general encryption are different; in the case where the general encryption channel cannot be successfully established, a commercial encryption channel is established, and network data transmission is performed through the encryption channel. The encryption channel includes a general encryption channel and a commercial encryption channel. Compared with the prior art where there are certain security risks as only one encryption method can be used for encryption, in this application, commercial encryption channels and general encryption channels are established under different circumstances, and different encryption channels are adaptively adjusted according to different situations, avoiding the security risks brought by only using one encryption method. Therefore, it can solve the problem in the prior art that only one encryption method can be supported, which is prone to security risks, and achieve the effect of adaptively switching the encryption scheme and improving communication security.

[0050] In the specific implementation process, the above step S202 of establishing a commercial encryption channel can be achieved through the following steps: Step S2021: Generate a commercial encryption connection request and send the commercial encryption connection request to the server so that the server generates a first response message, where the commercial encryption connection request is a request to apply for commercial encryption communication with the server, and the first response message is a response message generated by the server in response to the commercial encryption connection request; Step S2022: Receive the first response message sent by the server, generate commercial encryption key information and send it to the server to establish the commercial encryption channel, where the commercial encryption key information is the key information during the communication process using the commercial encryption channel. This method establishes a commercial encryption channel through the above steps. In this way, by generating a commercial encryption connection request and exchanging commercial encryption key information, an encryption channel based on commercial cryptography standards is established between the browser and the server. Commercial cryptography standards usually provide a higher level of security protection, making it more difficult for data to be eavesdropped on or tampered with by a third party during the data transmission process, improving the security of data transmission.

[0051] Specifically, the process of establishing a commercial encryption channel involves the negotiation of an encryption communication protocol and key exchange between the browser and the server. The specific steps are as follows:

[0052] Generate a commercial encryption connection request: When the browser determines that a commercial encryption channel needs to be established, it generates a commercial encryption connection request. This request contains information about the browser's support for commercial cryptography standards, such as supported commercial cipher suites, version information, etc., as well as some necessary connection parameters, such as communication addresses. The purpose of this request is to inform the server that the browser wishes to use commercial cryptography standards for encrypted communication. A sample JavaScript code for establishing a commercial encryption channel is as follows: let useGM = true; let socket = new WebSocket("wss: / / testHost.com / hello", useGM).

[0053] Send the commercial encryption connection request to the server: The browser sends the generated commercial encryption connection request to the target server via the network. The commercial cryptography standard information contained in the request will be used by the server for subsequent protocol negotiation.

[0054] The server generates the first response information: After receiving the commercial encryption connection request, the server generates the first response information based on its own support for commercial cryptography. This response information contains the commercial cipher suite, version, and related certificates selected by the server. If the server also supports commercial cryptography standards, it will send a positive response indicating that it can conduct commercial encrypted communication.

[0055] Receive the first response information and generate commercial cryptography key information: After receiving the server's first response information, the browser generates commercial cryptography key information through commercial cryptography algorithms (such as the key exchange algorithm based on SM2), which usually involves the generation of a key pair. Then, the browser sends the commercial cryptography key information (usually the public key) to the server so that the server can also generate the corresponding key pair for subsequent encrypted communication.

[0056] Establish a commercial encryption channel: After both parties have generated commercial cryptography key information, the browser and the server can establish a commercial encryption channel through this key information. Use the keys to encrypt and decrypt data to ensure data security during the communication process.

[0057] In some alternative embodiments, the establishment of the general encryption channel in step S202 above can be achieved through the following steps: Step S2023: Generate a general encryption connection request and send the general encryption connection request to the server so that the server generates second response information. The general encryption connection request is a request for general encryption communication with the server, and the second response information is the response information generated by the server in response to the general encryption connection request; Step S2024: Receive the second response information sent by the server, generate general key information and send it to the server to establish the general encryption channel. The general key information is the key information during the communication process using the general encryption channel. This method establishes a general encryption channel through the above steps. The general encryption channel uses the internationally widely accepted TLS / SSL protocol and can work between different servers and browsers globally, with high interoperability and compatibility.

[0058] In the specific implementation process, the process of establishing the general encryption channel involves the TLS / SSL handshake protocol between the browser and the server to negotiate the key information and security parameters required for encrypted communication. This typically involves the following steps:

[0059] Generate a general encryption connection request: When the browser decides to use the general password standard for encrypted communication, it generates a general encryption connection request, which is a connection request of the wss: / / (WebSocket Secure) type and includes a list of general cipher suites supported by the browser, the preferred encryption algorithm, and protocol version information. The purpose of this request is to let the server know that the browser hopes to establish a secure connection using the general encryption standard. The following is a sample JavaScript code for establishing a handshake connection for encrypted communication using the general password algorithm: let socket = new WebSocket("wss: / / testHost.com / hello").

[0060] Send the general encryption connection request to the server: The browser sends the general encryption connection request to the server through the network and waits for the server's response.

[0061] The server generates second response information: After receiving the general encryption connection request, the server selects a mutually supported cipher suite and protocol version from the support list provided by the browser and generates second response information, which includes the cipher suite selected by the server, the protocol version, the server certificate, and the parameters for subsequent key exchange. This response information is the server's reply to the browser's encrypted communication request, indicating that the server is ready for encrypted communication.

[0062] Receive the second response message and generate the common key information: After the browser receives the second response message from the server, it will use the server certificate and the key exchange parameters in the response to generate a key. This process usually involves steps such as random number generation, use of public and private keys, and derivation of symmetric keys. The generated common key information will be used to encrypt and decrypt the communication data on the common encryption channel.

[0063] Send the common key information to the server: The browser sends the generated common key information to the server via the network to complete the key exchange process. After receiving the common key information, the server will also generate the corresponding key for subsequent data encryption and decryption.

[0064] Establish a common encryption channel: After completing the key exchange and generating the common key information, a common encryption channel is established between the browser and the server. All data transmissions will pass through this channel and be encrypted and decrypted using the previously negotiated key information. This ensures the security of the communication data and prevents unauthorized third parties from eavesdropping on or tampering with the data.

[0065] In some alternative embodiments, the above step S201 of parsing the network configuration parameters can be implemented through the following steps: Step S2011: Obtain the communication address, where the communication address is the address for the browser to communicate with the server and at least includes an identifier indicating whether the browser and the server perform encrypted communication; Step S2012: Parse the network configuration parameters when the communication address indicates that the browser and the server perform encrypted communication. In this case, by parsing the network configuration parameters, the browser can ensure encrypted communication when encryption is required, thereby protecting the privacy and integrity of the data and avoiding the risk of data being eavesdropped on or tampered with during transmission.

[0066] Specifically, parsing the network configuration parameters is an important step in the WebSocket adaptive encryption communication method based on the browser, aiming to determine the encryption type of the communication between the browser and the server, so as to select the correct encrypted communication process.

[0067] Obtain the communication address: When the browser receives a WebSocket connection request from the front-end web page, it first needs to parse the communication address from the request. The communication address is the basis for the browser to establish a connection with the server, and it usually consists of a protocol prefix (ws: / / or wss: / / ), a host name (such as example.com), and an optional port number (such as 8080).

[0068] Identifying Encrypted Communication Identifiers: The protocol prefix in the communication address is crucial as it indicates whether the communication needs to be encrypted. If the protocol prefix is wss: / / , it means the communication requires encryption; if it is ws: / / , it means the communication does not need encryption and is plaintext communication. This identifier is the basis for the browser to determine whether to parse the network configuration parameters for encrypted communication.

[0069] Parsing Network Configuration Parameters: When the browser identifies that the communication address represents encrypted communication (i.e., the communication address starts with wss: / / ), it further parses the network configuration parameters. The network configuration parameters may include information such as the encryption type identifier, the list of supported cipher suites, the preferred encryption algorithm, and the protocol version. These parameters are crucial for the subsequent establishment of the encrypted communication channel and help the browser negotiate consistent encryption standards and key information with the server.

[0070] In some alternative embodiments, the method further includes the following steps: Step S204: In the case where the communication address represents non-encrypted communication between the browser and the server, establish a non-encrypted channel and transmit network data through the commercial encryption channel, where the non-encrypted channel is a channel that does not use a password for network data transmission. This method performs plaintext transmission through the above steps, which is a fast and low-overhead communication method suitable for scenarios with low requirements for data security. However, it also means that the data lacks protection during transmission and is vulnerable to security risks. In practical applications, the choice of establishing a non-encrypted channel or an encrypted channel should be based on specific requirements and security considerations.

[0071] Specifically, the establishment process of the non-encrypted channel is as follows: Parsing the communication address: After the browser receives a WebSocket connection request, it first parses the communication address to check whether it starts with ws: / / (instead of wss: / / ), which indicates that the connection request is for non-encrypted communication. Establishing the non-encrypted channel: Once it is determined that the communication address indicates non-encrypted communication, the browser directly establishes a standard TCP connection with the server without performing the TLS / SSL handshake process. Then, based on this TCP connection, a non-encrypted WebSocket two-way communication channel is established. Transmitting network data through the non-encrypted channel: After the non-encrypted channel is successfully established, the network data between the browser and the server will be transmitted in plaintext, that is, the data is not encrypted or decrypted during sending and receiving.

[0072] In some alternative embodiments, the above step S203 performs network data transmission through an encrypted channel, which can be achieved through the following steps. Step S2031: Encrypt the network data with key information and send the encrypted network data to the server, so that the server decrypts the encrypted network data with the key information to obtain the network data. Among them, the key information includes commercial encryption key information and general key information. The commercial encryption key information is the key information during the communication process using the commercial encryption channel, and the general key information is the key information during the communication process using the general encryption channel. Step S2032: Receive the encrypted network data sent by the server and decrypt the network data with the key information. This method encrypts and decrypts network data using key information through the above steps, ensuring the security of data during transmission. Even if the data is intercepted in the network, due to the confidentiality of the key, a third party cannot interpret the true content of the data.

[0073] Specifically, the process of network data transmission through an encrypted channel involves data encryption and decryption, ensuring the secure transmission of data between the browser and the server. Whether under the general encryption channel or the commercial encryption channel, encryption and decryption are based on a common key information, that is, general key information or commercial encryption key information. This process is divided into the following steps:

[0074] Data Encryption: On the browser side, when it is determined to perform data transmission through an encrypted channel (whether it is a general encryption channel or a commercial encryption channel), the browser uses the key information (i.e., general key information or commercial encryption key information) generated during the establishment of the encrypted channel to encrypt the network data. The choice of encryption algorithm depends on the type of encrypted channel used. When the encrypted data is transmitted in the network, it will exist in ciphertext form.

[0075] Sending Encrypted Data: The browser sends the encrypted network data to the server. Since the data has been encrypted during transmission, even if it is intercepted by a third party, it is not easy to interpret the original content of the data.

[0076] Data Decryption: On the server side, after receiving the encrypted network data, the server uses the same key information (i.e., general key information or commercial encryption key information) to decrypt the data. The decryption process restores the original plaintext form of the data, enabling the server to correctly process and understand the received information.

[0077] Encryption data reception and decryption: Conversely, when the server needs to send data to the browser, it also encrypts the data using the same key information and then sends it to the browser. After receiving the encrypted data, the browser decrypts it using the key information to obtain the original network data.

[0078] In some alternative embodiments, the method further includes step S205: in the case of failure to establish the commercial encryption channel or the general encryption channel, obtaining the error information sent by the server and displaying it on the interface, where the error information is information indicating the failure to establish an encrypted connection between the browser and the server. When the commercial encryption channel or the general encryption channel fails to be established, this method obtains and displays the error information sent by the server, providing necessary information for quickly troubleshooting and resolving problems. The detailed description of the error information provides clues for problem troubleshooting for users and developers, and they can judge whether it is a cipher suite incompatibility, a certificate problem, or a network connection failure based on the error information, and then take corresponding solutions.

[0079] Specifically, during the process of attempting to establish a commercial encryption channel or a general encryption channel, connection failures may occur for various reasons. When this happens, obtaining and displaying the error information sent by the server is an important step to ensure that users can understand the reason for the connection failure, helping users judge what to do next or troubleshoot problems. This process generally includes the following steps:

[0080] Detecting the encryption channel establishment status: During the TLS / SSL handshake protocol between the browser and the server, the browser will detect the handshake status in real time. If any problems occur during the handshake process, resulting in the failure to establish the encryption channel, the browser will receive an error status feedback.

[0081] Receiving the error information from the server: When the server detects the failure to establish the encryption channel, it will generate an error information that details the reason for the failure, such as: unsupported cipher suite, certificate verification failure, network connection problem, etc. The server will send this error information back to the browser via the network (possibly unencrypted, depending on the previous state).

[0082] Parsing the error information: After receiving the error information sent by the server, the browser needs to parse this information to understand the specific reason for the failure to establish the encryption channel. This generally involves reading the status code and error description returned by the server and then converting them into a form that users can understand.

[0083] Display error messages on the interface: Once the error messages are parsed and understood, the browser will display these messages on the user interface, possibly through a pop-up window, dialog box, or an error message area on the page. The displayed information should be clear and accurate to help the user quickly identify the problem, such as: "Failed to establish an encrypted connection: Unsupported cipher suite" or "Failed to establish an encrypted connection: Certificate verification failed".

[0084] To enable those skilled in the art to more clearly understand the technical solution of this application, the implementation process of the adaptive encryption communication method of this application will be described in detail below in combination with specific embodiments.

[0085] This embodiment relates to a schematic diagram of code modules for a specific adaptive encryption communication method, as Figure 3 shown, including a WebSocket network request parameter parsing and configuration module in the browser, which mainly realizes the function of parsing the parameters of WebSocket requests in the front-end web page (including: communication address, commercial cipher flag). The WebSocket network task scheduling and management module is used to manage the scheduling of WebSocket network communication tasks. For non-encrypted WebSocket tasks, it directly calls the TCP network long connection for network communication; for encrypted WebSocket tasks, it involves comprehensive switching control of commercial cipher and international cipher flags. The WebSocket network task scheduling and management module interacts with the SSL switching control module through the encrypted task management. The SSL switching control module includes an adaptive control module for all function modules related to encrypted communication: the cipher suite control and management module is compatible with commercial cipher suites and international cipher suites, the digital certificate management is compatible with commercial cipher digital certificates and international digital certificates, the cryptographic algorithm library is compatible with commercial cipher algorithms and international cryptographic algorithms, and the encrypted channel management is compatible with commercial cipher encrypted channels and international encrypted channels. The WebSocket network task scheduling and management module interacts with the TCP network long connection management module through the non-encrypted task management module. The SSL switching control module and the TCP network long connection management module finally interact with the network background service encrypted communication module.

[0086] This embodiment relates to a specific adaptive encryption communication method, as Figure 4 shown, including the following steps:

[0087] Step S1: Start processing the WebSocket connection;

[0088] Step S2: Determine whether the protocol prefix string of the link address starts with "wss: / / ". If it is, execute Step S3; if not, execute Step 13;

[0089] Step S3: Parse the WebSocket configuration parameter information: address, commercial cipher flag;

[0090] Step S4: Determine whether the commercial encryption flag is set. If yes, execute Step S5; if no, execute Step S9;

[0091] Step S5: Directly use commercial encryption and attempt to establish an encrypted handshake connection using the commercial encryption standard of our country;

[0092] Step S6: Determine whether the establishment of the handshake connection is successful. If yes, execute Step S7; if no, return an error message;

[0093] Step S7: Based on the encrypted handshake connection, establish a WebSocket encrypted communication channel;

[0094] Step S8: Encrypt and transmit network data using the commercial encryption standard;

[0095] Step S9: Attempt to establish an encrypted handshake connection using the general password standard;

[0096] Step S10: Determine whether the establishment of the handshake connection is successful. If yes, execute Step S11; if no, switch the password standard and execute Step S5;

[0097] Step S11: Based on the encrypted handshake connection, establish a WebSocket encrypted communication channel;

[0098] Step S12: Encrypt and transmit network data using the general password standard;

[0099] Step S13: Select to establish a WebSocket communication in the plaintext communication mode;

[0100] Step S14: Based on a persistent standard TCP network connection, establish a WebSocket communication channel;

[0101] Step S15: Directly transmit network data in plaintext;

[0102] Step S16: End.

[0103] The embodiment of the present application also provides an adaptive encryption communication device. It should be noted that the adaptive encryption communication device in the embodiment of the present application can be used to execute the adaptive encryption communication method provided by the embodiment of the present application. The device is used to implement the above-mentioned embodiment and the preferred implementation manner, and those that have been described will not be repeated. As used below, the term "module" can be a combination of software and / or hardware that can achieve a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation in hardware, or a combination of software and hardware is also possible and contemplated.

[0104] The following introduces the adaptive encryption communication device provided by the embodiments of the present application.

[0105] Figure 5 It is a schematic diagram of an adaptive encryption communication device according to an embodiment of the present application. As Figure 5 shown, the device includes:

[0106] A parsing unit 10, configured to parse network configuration parameters, where the network configuration parameters are parameters representing the configuration of a network transmission protocol and at least include an encryption type identifier, and the encryption type identifier characterizes the type of encryption;

[0107] Specifically, the present application is a WebSocket adaptive encryption communication device based on a browser. "Parsing network configuration parameters" is the key first step, which refers to the process of the browser analyzing and interpreting the network configuration parameters in the WebSocket connection request sent by the front-end web page when receiving it. These network configuration parameters contain detailed information about the connection, such as the communication address and the encryption type identifier, where the encryption type identifier is used to characterize the encryption type to be used in this communication. The encryption type identifier is used to indicate whether the WebSocket connection should be encrypted using a general cryptographic standard or a commercial cryptographic standard. The encryption standards for general encryption and commercial encryption are different.

[0108] An establishing unit 20, configured to establish a commercial encryption channel when the encryption type identifier characterizes the encryption type as commercial encryption, and establish a general encryption channel when the encryption type identifier does not characterize the encryption type as commercial encryption, where the encryption type of the commercial encryption channel is commercial encryption, the encryption type of the general encryption channel is general encryption, and the encryption standards for commercial encryption and general encryption are different;

[0109] Specifically, in the WebSocket adaptive encryption communication technology based on a browser, the parsing result of the encryption type identifier directly affects the type of encryption channel established subsequently. If the parsed encryption type identifier indicates that the encryption type is commercial encryption (i.e., the domestic commercial cryptographic standard in China), then the system will establish a commercial encryption channel; conversely, if the identifier indicates that the encryption type is general encryption (i.e., the internationally common cryptographic standard), a general encryption channel will be established. The "different encryption standards" here means that there are differences between commercial encryption and general encryption in aspects such as algorithm selection, certificate management system, and trust root, which are specifically reflected in the following aspects:

[0110] Algorithm Selection: Commercial encryption channels will adopt commercially used cryptographic algorithms independently designed in China, such as SM2, SM3, SM4, etc., while general encryption channels may adopt internationally widely recognized algorithms such as RSA, AES, SHA, etc. Commercially used cryptographic algorithms usually pay more attention to security and self-control in design, while general encryption algorithms have higher interoperability and acceptance internationally.

[0111] Certificate Management System: The commercial encryption channel uses China's commercially used cryptographic certificate system (GMCA), while the general encryption channel relies on the international PKI (Public Key Infrastructure) system.

[0112] Trust Root: The trust root of the commercial encryption channel is based on China's commercially used cryptographic certificate system, while the trust root of the general encryption channel is an internationally common standard system. The difference in trust roots means that during the authentication process, the system will judge the validity of digital certificates based on different certificate chains.

[0113] The transmission unit 30 is used to establish the commercial encryption channel and perform network data transmission through the encryption channel when the establishment of the general encryption channel fails, where the encryption channel includes the general encryption channel and the commercial encryption channel.

[0114] Specifically, in a WebSocket connection adopting an adaptive encryption communication strategy, the system first attempts to establish a general encryption channel. The general encryption channel uses internationally widely accepted encryption standards, such as the wss: / / connection based on the TLS protocol. However, if the attempt to establish the general encryption channel fails, the system will not immediately abandon the connection attempt but enter the next stage and attempt to establish a commercial encryption channel. The commercial encryption channel uses China's independent commercially used cryptographic standards, which include specific encryption algorithms (such as SM2, SM3, SM4) and digital certificate management systems (GMCA). These standards are significantly different from international common standards in terms of algorithm design and certificate trust roots, aiming to enhance data security and ensure self-control. By first attempting the general encryption channel and then the commercial encryption channel, it is ensured that even when the general encryption standard is unavailable or not supported, the system can still achieve encrypted communication through the commercial encryption channel, avoiding communication interruption caused by the failure to establish the encryption channel. Commercially used cryptographic standards usually provide a higher encryption level and security guarantee, which is particularly important for protecting critical data. Therefore, when the establishment of the general encryption channel fails, encrypted communication through the commercial encryption channel can provide an additional security layer.

[0115] Through this embodiment, network configuration parameters are parsed. The network configuration parameters are parameters representing the configuration of a network transmission protocol and at least include an encryption type identifier, and the encryption type identifier characterizes the type of encryption. In the case where the encryption type identifier characterizes the encryption type as commercial encryption, a commercial encryption channel is established. In the case where the encryption type identifier characterizes the encryption type as not commercial encryption, a general encryption channel is established, and the encryption scopes of commercial encryption and general encryption are different. In the case where the general encryption channel cannot be successfully established, a commercial encryption channel is established, and network data transmission is performed through the encryption channel. The encryption channel includes a general encryption channel and a commercial encryption channel. Compared with the prior art where there are certain security risks because only one encryption method can be used for encryption, in this application, commercial encryption channels and general encryption channels are established under different circumstances, and different encryption channels are adaptively adjusted according to different situations, avoiding the security risks brought by only using one encryption device. Therefore, it can solve the problem in the prior art that only one encryption method is supported and it is easy to generate security risks, achieving the effect of adaptively switching the encryption scheme and improving communication security.

[0116] In the specific implementation process, the above-mentioned establishment unit includes a first sending module and a second sending module. The first sending module is used to generate a commercial encryption connection request and send the commercial encryption connection request to the server so that the server generates a first response message. Among them, the commercial encryption connection request is a request to apply for commercial encryption communication with the server, and the first response message is a response message generated by the server in response to the commercial encryption connection request. The second sending module is used to receive the first response message sent by the server, generate commercial encryption key information and send it to the server to establish the commercial encryption channel. Among them, the commercial encryption key information is the key information during the communication process using the commercial encryption channel. The device establishes a commercial encryption channel through the above steps. In this way, by generating a commercial encryption connection request and exchanging commercial encryption key information, an encryption channel based on commercial cryptography standards is established between the browser and the server. Commercial cryptography standards usually provide a higher level of security protection, making it more difficult for data to be eavesdropped or tampered with by a third party during the data transmission process, improving the security of data transmission.

[0117] Specifically, the process of establishing a commercial encryption channel involves the negotiation of an encryption communication protocol and key exchange between the browser and the server. The specific steps are as follows:

[0118] Generate a commercial encryption connection request: When the browser determines that a commercial encryption channel needs to be established, it generates a commercial encryption connection request. This request contains information about the browser's support for commercial cryptography standards, such as supported commercial cipher suites, version information, etc., as well as some necessary connection parameters, such as the communication address. The purpose of this request is to inform the server that the browser wishes to use commercial cryptography standards for encrypted communication. The following is a JavaScript example for establishing a commercial encryption channel: let useGM = true; let socket = new WebSocket("wss: / / testHost.com / hello", useGM).

[0119] Send the commercial encryption connection request to the server: The browser sends the generated commercial encryption connection request to the target server via the network. The commercial cryptography standard information contained in the request will be used by the server for subsequent protocol negotiation.

[0120] The server generates the first response information: After receiving the commercial encryption connection request, the server generates the first response information based on its own support for commercial cryptography. This response information includes the commercial cipher suite, version, and related certificates selected by the server. If the server also supports commercial cryptography standards, it will send a positive response indicating that it can perform commercial encrypted communication.

[0121] Receive the first response information and generate commercial cryptography key information: After receiving the server's first response information, the browser generates commercial cryptography key information through commercial cryptography algorithms (such as the key exchange algorithm based on SM2), which usually involves the generation of a key pair. Then, the browser sends the commercial cryptography key information (usually the public key) to the server so that the server can also generate the corresponding key pair for subsequent encrypted communication.

[0122] Establish a commercial encryption channel: After both parties have generated commercial cryptography key information, the browser and the server can establish a commercial encryption channel using this key information. Use the key to encrypt and decrypt data to ensure data security during the communication process.

[0123] In some alternative embodiments, the establishing unit further includes a third sending module and a fourth sending module. The third sending module is configured to generate a general encryption connection request and send the general encryption connection request to the server, so that the server generates second response information. The general encryption connection request is a request for general encryption communication with the server, and the second response information is a response message generated by the server in response to the general encryption connection request. The fourth sending module is configured to receive the second response information sent by the server, generate general key information and send it to the server to establish the general encryption channel. The general key information is the key information used in the communication process using the general encryption channel. The device establishes the general encryption channel through the above steps. The general encryption channel uses the internationally widely accepted TLS / SSL protocol, which can work between different servers and browsers globally and has high interoperability and compatibility.

[0124] In the specific implementation process, the process of establishing the general encryption channel involves the TLS / SSL handshake protocol between the browser and the server to negotiate the key information and security parameters required for encrypted communication. This usually involves the following steps:

[0125] Generate a general encryption connection request: When the browser decides to use the general password standard for encrypted communication, it generates a general encryption connection request, which is a connection request of the wss: / / (WebSocket Secure) type and contains a list of general cipher suites supported by the browser, the preferred encryption algorithm, and protocol version information. The purpose of this request is to let the server know that the browser hopes to establish a secure connection using the general encryption standard. The following is a sample JavaScript code for establishing a handshake connection for encrypted communication using the general password algorithm: let socket = new WebSocket("wss: / / testHost.com / hello").

[0126] Send the general encryption connection request to the server: The browser sends the general encryption connection request to the server through the network and waits for the server's response.

[0127] The server generates second response information: After receiving the general encryption connection request, the server selects a mutually supported cipher suite and protocol version from the support list provided by the browser and generates second response information, which includes the cipher suite selected by the server, the protocol version, the server certificate, and the parameters for subsequent key exchange. This response information is the server's reply to the browser's encrypted communication request, indicating that the server is ready for encrypted communication.

[0128] Receive the second response information and generate the common key information: After the browser receives the second response information from the server, it will use the server certificate and the key exchange parameters in the response to generate a key. This process usually involves steps such as generating random numbers, using public and private keys, and deriving symmetric keys. The generated common key information will be used to encrypt and decrypt the communication data on the common encryption channel.

[0129] Send the common key information to the server: The browser sends the generated common key information to the server through the network to complete the key exchange process. After receiving the common key information, the server will also generate the corresponding key for subsequent data encryption and decryption.

[0130] Establish a common encryption channel: After completing the key exchange and generating the common key information, a common encryption channel is established between the browser and the server. All data transmissions will pass through this channel and be encrypted and decrypted using the previously negotiated key information. This ensures the security of the communication data and prevents unauthorized third parties from eavesdropping on or tampering with the data.

[0131] In some alternative embodiments, the above parsing unit includes an acquisition module and a parsing module. The acquisition module is used to acquire the communication address, where the communication address is the address for the browser to communicate with the server and at least includes an identifier indicating whether the browser and the server perform encrypted communication; the parsing module is used to parse the network configuration parameters when the communication address indicates that the browser and the server perform encrypted communication. The device parses the network configuration parameters in the above situation. By parsing the network configuration parameters, the browser can ensure that encrypted communication is used when encryption is required, thereby protecting the privacy and integrity of the data and avoiding the risk of the data being eavesdropped on or tampered with during transmission.

[0132] Specifically, parsing the network configuration parameters is an important step in the WebSocket adaptive encryption communication device of the browser, aiming to determine the encryption type of the communication between the browser and the server, so as to select the correct encrypted communication process.

[0133] Acquire the communication address: When the browser receives a WebSocket connection request from the front-end web page, it first needs to parse the communication address from the request. The communication address is the basis for the browser to establish a connection with the server. It usually consists of a protocol prefix (ws: / / or wss: / / ), a host name (such as example.com), and an optional port number (such as 8080).

[0134] Identifying Encrypted Communication Identifiers: The protocol prefix in the communication address is crucial as it indicates whether the communication needs to be encrypted. If the protocol prefix is wss: / / , it means the communication requires encryption; if it is ws: / / , it means the communication does not need encryption and is plaintext communication. This identifier is the basis for the browser to determine whether to parse the network configuration parameters for encrypted communication.

[0135] Parsing Network Configuration Parameters: When the browser identifies that the communication address represents encrypted communication (i.e., the communication address starts with wss: / / ), it will further parse the network configuration parameters. The network configuration parameters may include information such as the encryption type identifier, the list of supported cipher suites, the preferred encryption algorithm, and the protocol version. These parameters are crucial for the subsequent establishment of the encrypted communication channel and help the browser negotiate consistent encryption standards and key information with the server.

[0136] In some alternative embodiments, the device further includes a data transmission unit for establishing an unencrypted channel and transmitting network data through the commercial encryption channel when the communication address represents unencrypted communication between the browser and the server. Here, the unencrypted channel is a channel for transmitting network data without using a password. The device performs plaintext transmission through the above steps, which is a fast and low-overhead communication method suitable for scenarios with low requirements for data security. However, it also means that the data lacks protection during transmission and is vulnerable to security risks. In practical applications, the choice of establishing an unencrypted channel or an encrypted channel should be based on specific requirements and security considerations.

[0137] Specifically, the establishment process of the unencrypted channel is as follows: Parsing the communication address: After receiving a WebSocket connection request, the browser first parses the communication address to check if it starts with ws: / / (instead of wss: / / ), which indicates that the connection request is for unencrypted communication. Establishing the unencrypted channel: Once it is determined that the communication address indicates unencrypted communication, the browser will directly establish a standard TCP connection with the server without performing the TLS / SSL handshake process. Then, based on this TCP connection, an unencrypted WebSocket two-way communication channel is established. Transmitting network data through the unencrypted channel: After the unencrypted channel is successfully established, the network data between the browser and the server will be transmitted in plaintext, that is, the data is not encrypted or decrypted during sending and receiving.

[0138] In some alternative embodiments, the above-mentioned transmission unit includes a fifth sending module and a decryption module. The fifth sending module is used to encrypt network data with key information and send the encrypted network data to the server, so that the server can decrypt the encrypted network data with the key information to obtain the network data. Among them, the key information includes commercial encryption key information and general key information. The commercial encryption key information is the key information during the communication process using the commercial encryption channel, and the general key information is the key information during the communication process using the general encryption channel; the decryption module is used to receive the encrypted network data sent by the server and decrypt it with the key information to obtain the network data. By encrypting and decrypting network data using key information through the above steps, the device ensures the security of data during transmission. Even if the data is intercepted in the network, due to the confidentiality of the key, a third party cannot interpret the true content of the data.

[0139] Specifically, the process of transmitting network data through an encryption channel involves data encryption and decryption, ensuring the secure transmission of data between the browser and the server. Whether it is under the general encryption channel or the commercial encryption channel, encryption and decryption are based on a common key information, that is, general key information or commercial encryption key information. This process is divided into the following steps:

[0140] Data Encryption: On the browser side, when it is determined to transmit data through an encryption channel (whether it is a general encryption channel or a commercial encryption channel), the browser will use the key information (i.e., general key information or commercial encryption key information) generated during the establishment of the encryption channel to encrypt the network data. The choice of encryption algorithm depends on the type of encryption channel used. When the encrypted data is transmitted in the network, it will exist in ciphertext form.

[0141] Encrypted Data Sending: The browser sends the encrypted network data to the server. Since the data has been encrypted during transmission, even if it is intercepted by a third party, it is difficult to interpret the original content of the data.

[0142] Data Decryption: On the server side, after receiving the encrypted network data, the server will decrypt the data with the same key information (i.e., general key information or commercial encryption key information). The decryption process restores the original plaintext form of the data, enabling the server to correctly process and understand the received information.

[0143] Encrypted Data Receiving and Decryption: Conversely, when the server needs to send data to the browser, it also encrypts the data with the same key information and then sends it to the browser. After the browser receives the encrypted data, it decrypts it with the key information to obtain the original network data.

[0144] In some alternative embodiments, the device further includes a display module, configured to obtain error information sent by a server and display it on an interface when establishing the commercial encryption channel or the general encryption channel fails, where the error information is information indicating that the browser fails to establish an encrypted connection with the server. When the device fails to establish the commercial encryption channel or the general encryption channel, obtaining and displaying the error information sent by the server provides necessary information for quickly troubleshooting and resolving problems. The detailed description of the error information provides clues for problem troubleshooting for users and developers, and it can be used to determine whether it is a cipher suite incompatibility, a certificate problem, or a network connection failure based on the error information, and then corresponding solutions can be taken.

[0145] Specifically, during the process of attempting to establish the commercial encryption channel or the general encryption channel, connection failures may occur for various reasons. When this happens, obtaining and displaying the error information sent by the server is an important step to ensure that users can understand the reason for the connection failure and helps users determine what to do next or troubleshoot the problem. This process generally includes the following steps:

[0146] Detect the encryption channel establishment status: During the TLS / SSL handshake protocol between the browser and the server, the browser will detect the handshake status in real time. If any problems occur during the handshake process, resulting in the inability to establish the encryption channel, the browser will receive an error status feedback.

[0147] Receive the error information from the server: When the server detects that the encryption channel establishment fails, it will generate an error information that details the reason for the failure, such as: unsupported cipher suite, certificate verification failure, network connection problem, etc. The server will send this error information back to the browser via the network (which may be unencrypted, depending on the previous state).

[0148] Parse the error information: After receiving the error information sent by the server, the browser needs to parse this information to understand the specific reason for the failure of the encryption channel establishment. This generally involves reading the status code and error description returned by the server and then converting them into a form that can be understood by the user.

[0149] Display the error information on the interface: Once the error information is parsed and understood, the browser will display this information on the user interface, perhaps through a pop-up window, a dialog box, or an error message area on the page. The displayed information should be clear and accurate to help users quickly identify the problem, such as: "Encryption connection failed: Unsupported cipher suite" or "Encryption connection failed: Certificate verification failed".

[0150] The adaptive encryption communication device includes a processor and a memory. The above-mentioned parsing unit, establishing unit, transmission unit, etc. are all stored in the memory as program units, and the processor executes the above-mentioned program units stored in the memory to implement corresponding functions. The above-mentioned modules are all located in the same processor; or, the above-mentioned modules are respectively located in different processors in any combination form.

[0151] The processor contains a kernel, and the kernel retrieves the corresponding program unit from the memory. One or more kernels can be set, and various encryption communication methods are supported by adjusting the kernel parameters.

[0152] The memory may include non-permanent memory in a computer-readable medium, forms such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash memory (flash RAM), and the memory includes at least one storage chip.

[0153] An embodiment of the present invention provides a computer-readable storage medium, and the computer-readable storage medium includes a stored program. When the program runs, the device where the computer-readable storage medium is located is controlled to execute the adaptive encryption communication method.

[0154] Specifically, the adaptive encryption communication method includes:

[0155] Step S201, parse network configuration parameters, where the network configuration parameters are parameters representing the configuration of the network transmission protocol and at least include an encryption type identifier, and the encryption type identifier characterizes the type of encryption;

[0156] Specifically, this application is a WebSocket adaptive encryption communication method based on a browser. "Parsing network configuration parameters" is the key first step, which refers to the process of the browser analyzing and interpreting the network configuration parameters in the request when receiving a WebSocket connection request sent from the front-end web page. These network configuration parameters contain detailed information about the connection, such as the communication address and the encryption type identifier, and the encryption type identifier is used to characterize the encryption type to be used in this communication. The encryption type identifier is used to indicate whether the WebSocket connection should be encrypted using a general cryptographic standard or a commercial cryptographic standard. The encryption standards for general encryption and commercial encryption are different.

[0157] Step S202: When the encryption type identifier indicates that the encryption type is commercial encryption, establish a commercial encryption channel; when the encryption type identifier indicates that the encryption type is not commercial encryption, establish a general encryption channel. Herein, the encryption type of the commercial encryption channel is commercial encryption, and the encryption type of the general encryption channel is general encryption. The encryption standards of commercial encryption and general encryption are different;

[0158] Specifically, in the WebSocket adaptive encryption communication technology based on a browser, the parsing result of the encryption type identifier directly affects the type of encryption channel established subsequently. If the parsed encryption type identifier indicates that the encryption type is commercial encryption (i.e., the domestic commercial cryptography standard in China), the system will establish a commercial encryption channel; conversely, if the identifier indicates that the encryption type is general encryption (i.e., the internationally common cryptography standard), a general encryption channel will be established. The "different encryption standards" here means that there are differences between commercial encryption and general encryption in aspects such as algorithm selection, certificate management system, and trust root, which are specifically reflected in the following aspects:

[0159] Algorithm selection: The commercial encryption channel will adopt domestic self-designed commercial cryptography algorithms such as SM2, SM3, SM4, etc., while the general encryption channel may adopt internationally widely recognized algorithms such as RSA, AES, SHA, etc. Commercial encryption algorithms usually pay more attention to security and self-control in design, while general encryption algorithms have higher interoperability and acceptance internationally.

[0160] Certificate management system: The commercial encryption channel uses the domestic commercial cryptography certificate system (GMCA), while the general encryption channel relies on the international PKI (Public Key Infrastructure) system.

[0161] Trust root: The trust root of the commercial encryption channel is based on the domestic commercial cryptography certificate system, while the trust root of the general encryption channel is the internationally common standard system. The difference in the trust root means that during the authentication process, the system will judge the validity of digital certificates based on different certificate chains.

[0162] Step S203: When the general encryption channel fails to be established, establish the commercial encryption channel and perform network data transmission through the encryption channel. Herein, the encryption channel includes the general encryption channel and the commercial encryption channel.

[0163] Specifically, in a WebSocket connection that adopts an adaptive encryption communication strategy, the system first attempts to establish a general encryption channel. The general encryption channel uses internationally widely accepted encryption standards, such as the wss: / / connection based on the TLS protocol. However, if the attempt to establish the general encryption channel fails, the system does not immediately abandon the connection attempt but enters the next stage and attempts to establish a commercial encryption channel. The commercial encryption channel uses our country's independent commercial cryptography standards, which include specific encryption algorithms (such as SM2, SM3, SM4) and a digital certificate management system (GMCA). These standards are significantly different from international general standards in terms of algorithm design and certificate trust roots, aiming to enhance data security and ensure autonomy and controllability. By first attempting the general encryption channel and then the commercial encryption channel, it is ensured that even when the general encryption standard is unavailable or not supported, the system can still achieve encrypted communication through the commercial encryption channel, avoiding communication interruption caused by the failure to establish the encryption channel. Commercial cryptography standards usually provide a higher encryption level and security guarantee, which is particularly important for protecting critical data. Therefore, when the general encryption channel establishment fails, encrypted communication through the commercial encryption channel can provide an additional security layer.

[0164] An embodiment of the present invention provides an electronic device, including a processor, a memory, and a program stored on the memory and executable on the processor. When the processor executes the program, it implements at least the following steps:

[0165] Step S201, parse network configuration parameters, where the network configuration parameters are parameters representing the configuration of the network transmission protocol and at least include an encryption type identifier, and the encryption type identifier characterizes the type of encryption;

[0166] Specifically, this application is a WebSocket adaptive encryption communication method based on a browser. "Parsing network configuration parameters" is the key first step, which refers to the process of the browser analyzing and interpreting the network configuration parameters in the WebSocket connection request sent by the front-end web page when it receives the request. These network configuration parameters contain detailed information about the connection, such as the communication address and the encryption type identifier, where the encryption type identifier is used to characterize the encryption type to be adopted for this communication. The encryption type identifier is used to indicate whether the WebSocket connection should use general cryptography standards for encryption or commercial cryptography standards for encryption. The encryption standards for general encryption and commercial encryption are different.

[0167] Step S202: When the encryption type identifier indicates that the encryption type is commercial encryption, establish a commercial encryption channel; when the encryption type identifier indicates that the encryption type is not commercial encryption, establish a general encryption channel. Herein, the encryption type of the commercial encryption channel is commercial encryption, and the encryption type of the general encryption channel is general encryption. The encryption standards of commercial encryption and general encryption are different;

[0168] Specifically, in the WebSocket adaptive encryption communication technology based on a browser, the parsing result of the encryption type identifier directly affects the type of encryption channel established subsequently. If the parsed encryption type identifier indicates that the encryption type is commercial encryption (i.e., the domestic commercial cryptography standard of our country), then the system will establish a commercial encryption channel; conversely, if the identifier indicates that the encryption type is general encryption (i.e., the internationally common cryptography standard), a general encryption channel will be established. The "different encryption standards" here means that there are differences between commercial encryption and general encryption in aspects such as algorithm selection, certificate management system, and trust root, which are specifically reflected in the following aspects:

[0169] Algorithm selection: The commercial encryption channel will adopt domestic self-designed commercial cryptography algorithms such as SM2, SM3, SM4, etc., while the general encryption channel may adopt internationally widely recognized algorithms such as RSA, AES, SHA, etc. Commercial encryption algorithms usually pay more attention to security and self-control in design, while general encryption algorithms have higher interoperability and acceptance internationally.

[0170] Certificate management system: The commercial encryption channel uses the domestic commercial cryptography certificate system (GMCA), while the general encryption channel relies on the international PKI (Public Key Infrastructure) system.

[0171] Trust root: The trust root of the commercial encryption channel is based on the domestic commercial cryptography certificate system, while the trust root of the general encryption channel is the internationally common standard system. The difference in the trust root means that during the authentication process, the system will judge the validity of digital certificates based on different certificate chains.

[0172] Step S203: When the general encryption channel fails to be established, establish the commercial encryption channel and perform network data transmission through the encryption channel. Herein, the encryption channel includes the general encryption channel and the commercial encryption channel.

[0173] Specifically, in a WebSocket connection adopting an adaptive encryption communication strategy, the system first attempts to establish a general encryption channel. The general encryption channel uses internationally widely accepted encryption standards, such as the wss: / / connection based on the TLS protocol. However, if the attempt to establish the general encryption channel fails, the system does not immediately abandon the connection attempt but enters the next stage to attempt to establish a commercial encryption channel. The commercial encryption channel uses China's independent commercial cryptography standards, which include specific encryption algorithms (such as SM2, SM3, SM4) and a digital certificate management system (GMCA). These standards have significant differences from international general standards in terms of algorithm design and certificate trust roots, aiming to enhance data security and ensure autonomy and controllability. By the strategy of first attempting the general encryption channel and then the commercial encryption channel, it is ensured that even when the international general encryption standard is unavailable or not supported, the system can still achieve encrypted communication through the commercial encryption channel, avoiding communication interruption caused by the failure to establish the encryption channel. Commercial cryptography standards usually provide a higher encryption level and security guarantee, which is particularly important for the protection of critical data. Therefore, when the general encryption channel fails to be established, encrypted communication through the commercial encryption channel can provide an additional security layer.

[0174] The devices in this article can be servers, PCs, PADs, mobile phones, etc.

[0175] This application also provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the steps of the methods in various embodiments of this application:

[0176] Step S201, parse network configuration parameters, where the network configuration parameters are parameters representing the configuration of the network transmission protocol and at least include an encryption type identifier, and the encryption type identifier characterizes the type of encryption;

[0177] Specifically, this application is a WebSocket adaptive encryption communication method based on a browser. "Parsing network configuration parameters" is the key first step, which refers to the process by which the browser analyzes and interprets the network configuration parameters in the WebSocket connection request sent by the front-end web page when it receives the request. These network configuration parameters contain detailed information about the connection, such as the communication address and the encryption type identifier, where the encryption type identifier is used to characterize the encryption type to be adopted for this communication. The encryption type identifier is used to indicate whether the WebSocket connection should use a general cryptography standard for encryption or a commercial cryptography standard for encryption. The encryption standards for general encryption and commercial encryption are different.

[0178] Step S202: When the encryption type identifier indicates that the encryption type is commercial encryption, establish a commercial encryption channel; when the encryption type identifier indicates that the encryption type is not commercial encryption, establish a general encryption channel. Here, the encryption type of the commercial encryption channel is commercial encryption, and the encryption type of the general encryption channel is general encryption. The encryption standards of commercial encryption and general encryption are different;

[0179] Specifically, in the WebSocket adaptive encryption communication technology based on a browser, the parsing result of the encryption type identifier directly affects the type of encryption channel established subsequently. If the parsed encryption type identifier indicates that the encryption type is commercial encryption (i.e., the domestic commercial cryptography standard in China), then the system will establish a commercial encryption channel; conversely, if the identifier indicates that the encryption type is general encryption (i.e., the internationally common cryptography standard), a general encryption channel will be established. The "different encryption standards" here means that there are differences between commercial encryption and general encryption in aspects such as algorithm selection, certificate management system, and trust root, which are specifically reflected in the following aspects:

[0180] Algorithm selection: The commercial encryption channel will adopt domestically designed commercial cryptography algorithms such as SM2, SM3, SM4, etc., while the general encryption channel may adopt internationally widely recognized algorithms such as RSA, AES, SHA, etc. Commercial encryption algorithms usually pay more attention to security and self - controllability in design, while general encryption algorithms have higher interoperability and acceptance internationally.

[0181] Certificate management system: The commercial encryption channel uses the domestic commercial cryptography certificate system (GMCA), while the general encryption channel relies on the international PKI (Public Key Infrastructure) system.

[0182] Trust root: The trust root of the commercial encryption channel is based on the domestic commercial cryptography certificate system, while the trust root of the general encryption channel is the internationally common standard system. The difference in trust roots means that during the authentication process, the system will judge the validity of digital certificates based on different certificate chains.

[0183] Step S203: When the establishment of the general encryption channel fails, establish the commercial encryption channel and perform network data transmission through the encryption channel, where the encryption channel includes the general encryption channel and the commercial encryption channel.

[0184] Specifically, in a WebSocket connection that adopts an adaptive encryption communication strategy, the system first attempts to establish a general encryption channel. The general encryption channel uses internationally widely accepted encryption standards, such as the wss: / / connection based on the TLS protocol. However, if the attempt to establish the general encryption channel fails, the system does not immediately abandon the connection attempt but enters the next stage to attempt to establish a commercial encryption channel. The commercial encryption channel uses China's independent commercial cryptography standards, which include specific encryption algorithms (such as SM2, SM3, SM4) and a digital certificate management system (GMCA). These standards have significant differences from international general standards in terms of algorithm design and certificate trust roots, aiming to enhance data security and ensure autonomy and controllability. By first attempting the general encryption channel and then the commercial encryption channel, it is ensured that even when the international general encryption standard is unavailable or not supported, the system can still achieve encrypted communication through the commercial encryption channel, avoiding communication interruption caused by the failure to establish the encryption channel. Commercial cryptography standards usually provide a higher level of encryption and security guarantee, which is particularly important for protecting critical data. Therefore, when the general encryption channel fails to be established, encrypted communication through the commercial encryption channel can provide an additional security layer.

[0185] Obviously, those skilled in the art should understand that the various modules or steps of the present invention described above can be implemented by a general computing device. They can be concentrated on a single computing device or distributed on a network composed of multiple computing devices. They can be implemented by program code executable by the computing device, so that they can be stored in a storage device and executed by the computing device. And in some cases, the steps shown or described can be executed in a different order than here, or they can be separately made into individual integrated circuit modules, or multiple modules or steps among them can be made into a single integrated circuit module for implementation. Thus, the present invention is not limited to any specific combination of hardware and software.

[0186] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0187] This application is described with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, and combinations of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing device to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing device produce means for implementing the functions specified in one or more of the flows Figure 1 one or more of the flows and / or blocks Figure 1 or means for implementing the functions specified in one or more of the blocks.

[0188] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the computer-readable memory produce a manufacture including instruction means for implementing the functions specified in one or more of the flows Figure 1 one or more of the flows and / or blocks Figure 1 or means for implementing the functions specified in one or more of the blocks.

[0189] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more of the flows Figure 1 one or more of the flows and / or blocks Figure 1 or means for implementing the functions specified in one or more of the blocks.

[0190] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.

[0191] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM), and / or non-volatile memory such as read-only memory (ROM) or flash memory (flash RAM). The memory is an example of a computer-readable medium.

[0192] A computer-readable medium includes both permanent and non-permanent, removable and non-removable media that can store information by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape disk storage or other magnetic storage devices, or any other non-transitory medium that can be used to store information that can be accessed by a computing device. As defined herein, a computer-readable medium does not include transitory computer-readable media such as modulated data signals and carrier waves.

[0193] It should also be noted that the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising an..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that comprises the element.

[0194] From the above description, it can be seen that the above embodiments of the present application achieve the following technical effects:

[0195] 1) In the adaptive encryption communication method of the present application, network configuration parameters are parsed. The network configuration parameters are parameters representing the configuration of the network transmission protocol and at least include an encryption type identifier, and the encryption type identifier characterizes the type of encryption. When the encryption type identifier characterizes that the encryption type is commercial encryption, a commercial encryption channel is established. When the encryption type identifier characterizes that the encryption type is not commercial encryption, a general encryption channel is established. The encryption scopes of commercial encryption and general encryption are different. When the general encryption channel cannot be successfully established, a commercial encryption channel is established, and network data transmission is carried out through the encryption channel. The encryption channel includes a general encryption channel and a commercial encryption channel. Compared with the prior art where there are certain security risks in that only one encryption method can be used for encryption, the present application establishes commercial encryption channels and general encryption channels under different circumstances, adaptively adjusts the use of different encryption channels according to different situations, and avoids the security risks brought by only using one encryption method. Therefore, it can solve the problem in the prior art that only one encryption method is supported and it is easy to generate security risks, and achieve the effect of adaptively switching the encryption scheme and improving communication security.

[0196] 2) In the adaptive encryption communication device of the present application, network configuration parameters are parsed. The network configuration parameters are parameters representing the configuration of the network transmission protocol and at least include an encryption type identifier, and the encryption type identifier characterizes the type of encryption. When the encryption type identifier characterizes that the encryption type is commercial encryption, a commercial encryption channel is established. When the encryption type identifier characterizes that the encryption type is not commercial encryption, a general encryption channel is established. The encryption scopes of commercial encryption and general encryption are different. When the general encryption channel cannot be successfully established, a commercial encryption channel is established, and network data transmission is carried out through the encryption channel. The encryption channel includes a general encryption channel and a commercial encryption channel. Compared with the prior art where there are certain security risks in that only one encryption method can be used for encryption, the present application establishes commercial encryption channels and general encryption channels under different circumstances, adaptively adjusts the use of different encryption channels according to different situations, and avoids the security risks brought by only using one encryption method. Therefore, it can solve the problem in the prior art that only one encryption method is supported and it is easy to generate security risks, and achieve the effect of adaptively switching the encryption scheme and improving communication security.

[0197] The above are only the preferred embodiments of the present application and are not used to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.

Claims

1. An adaptive encryption communication method, characterized in that: include: Parsing a network configuration parameter, wherein the network configuration parameter is a parameter representing a configuration of a network transmission protocol and includes at least an encryption type identifier, wherein the encryption type identifier represents an encryption type; When the encryption type identifier indicates that the encryption type is commercial encryption, a commercial encryption channel is established; when the encryption type identifier indicates that the encryption type is not commercial encryption, a general encryption channel is established, wherein the encryption type of the commercial encryption channel is the commercial encryption, the encryption type of the general encryption channel is general encryption, and the encryption standards of the commercial encryption and the general encryption are different; In the case that the universal encryption channel cannot be established successfully, the commercial encryption channel is established, and network data transmission is performed through the encryption channel, wherein the encryption channel includes the universal encryption channel and the commercial encryption channel.

2. The adaptive encryption communication method according to claim 1, characterized in that: Establish commercial encryption channels, including: Generate a commercial encryption connection request, and send the commercial encryption connection request to a server, so that the server generates a first response message, wherein the commercial encryption connection request is a request for applying for commercial encryption communication with the server, and the first response message is a response message generated by the server in response to the commercial encryption connection request; Receive the first response information sent by the server, generate commercial key information and send it to the server to establish the commercial encryption channel, wherein the commercial key information is key information used in the communication process using the commercial encryption channel.

3. The adaptive encryption communication method according to claim 1, characterized in that: Establish a common encryption channel, including: Generate a general encryption connection request, and send the general encryption connection request to the server, so that the server generates second response information, wherein the general encryption connection request is a request for requesting general encryption communication with the server, and the second response information is response information generated by the server in response to the general encryption connection request; The second response information sent by the server is received, and general key information is generated and sent to the server to establish the general encryption channel, wherein the general key information is key information in the process of communication using the general encryption channel.

4. The adaptive encryption communication method according to claim 1, characterized in that: Parse network configuration parameters, including: Acquire a communication address, wherein the communication address is an address for the browser to communicate with the server and at least includes an identifier indicating whether the browser and the server perform encrypted communication; When the communication address indicates that the browser and the server perform encrypted communication, the network configuration parameters are parsed.

5. The adaptive encryption communication method according to claim 4, characterized in that: The method further comprises: When the communication address represents that the browser and the server perform non-encrypted communication, a non-encrypted channel is established, and network data transmission is performed through the commercial encrypted channel, wherein the non-encrypted channel is a channel for performing network data transmission without using a password.

6. The adaptive encryption communication method according to claim 1, characterized in that: Transmit network data through encrypted channels, including: Encrypting network data by key information, and sending the encrypted network data to a server, so that the server decrypts the encrypted network data by key information upon receiving the encrypted network data, wherein the key information includes commercial key information and universal key information, the commercial key information is key information in a communication process using the commercial encryption channel, and the universal key information is key information in a communication process using the universal encryption channel; The encrypted network data sent by the server is received, and the network data is decrypted using the key information to obtain the network data.

7. The adaptive encryption communication method according to claim 1, characterized in that: The method further comprises: In the case where the commercial encryption channel or the universal encryption channel fails to be established, error information sent by the server is obtained and displayed on the interface, wherein the error information is information indicating that the browser and the server have failed to establish an encrypted connection.

8. An adaptive encryption communication device, characterized in that: include: A parsing unit, configured to parse a network configuration parameter, wherein the network configuration parameter is a parameter representing a configuration of a network transmission protocol and at least includes an encryption type identifier, wherein the encryption type identifier represents an encryption type; an establishing unit, configured to establish a commercial encryption channel when the encryption type identifier indicates that the encryption type is commercial encryption, and to establish a general encryption channel when the encryption type identifier indicates that the encryption type is not commercial encryption, wherein the encryption type of the commercial encryption channel is the commercial encryption, the encryption type of the general encryption channel is general encryption, and the encryption standards of the commercial encryption and the general encryption are different; A transmission unit is used to establish the commercial encryption channel when the establishment of the general encryption channel fails, and to transmit network data through the encryption channel, wherein the encryption channel includes the general encryption channel and the commercial encryption channel.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a stored program, wherein when the program is executed, the device where the computer-readable storage medium is located is controlled to execute the adaptive encryption communication method according to any one of claims 1 to 7.

10. An electronic device, characterized in that: include: One or more processors, a memory, and one or more programs, wherein the one or more programs are stored in the memory and are configured to be executed by the one or more processors, and the one or more programs include a method for executing the adaptive encryption communication method described in any one of claims 1 to 7.