Cloud edge data transmission method and device, computer equipment and storage medium

By using device certificates and key parameters for key negotiation in cloud-edge data transmission, the application layer data key is generated and the original data is encrypted, which solves the problem of low reliability of cloud-edge data transmission and realizes high-security data transmission.

CN120110683APending Publication Date: 2025-06-06BEIJING VOLCANO ENGINE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510271954.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-07
Publication Date
2025-06-06

AI Technical Summary

Technical Problem

Cloud-edge data transmission is low reliability, and server-side authentication of client legitimacy and sensitive data protection methods are weak, resulting in the risk of data leakage.

Method used

By initiating a certificate signing request to the cloud server, obtaining the device certificate, and using the device certificate and key parameters for key negotiation during the data transmission process, the application layer data key is generated, and the original data is encrypted to ensure that the intermediate network element cannot decrypt the data.

Benefits of technology

Improve the security and reliability of cloud-edge data transmission, prevent data leakage, and effectively avoid data leakage even if transmitted through the public network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120110683A_ABST
    Figure CN120110683A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data transmission, and discloses a cloud side data transmission method and device, computer equipment and a storage medium, and the method comprises the steps: initiating a certificate signature request to a cloud server, and obtaining an equipment certificate issued by the cloud server; sending a device certificate of the edge device and the first key parameter to the cloud server side under the condition of data transmission with the cloud server side; the cloud server side is used for generating a first data key of an application layer according to the first key parameter and a preset private key of the cloud server side, and returning a second key parameter; acquiring a second key parameter returned by the cloud server, and generating a second data key of the application layer according to the second key parameter and a preset private key corresponding to the first key parameter; and encrypting the original data according to the second data key to obtain encrypted data, and sending the encrypted data to the cloud server. According to the invention, data leakage can be effectively avoided, and the security of data transmission can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the technical field of data transmission, and in particular to a method, apparatus, computer equipment and storage medium for cloud-edge data transmission. Background Art

[0002] In the scenario of cloud-edge data transmission, people often only focus on the server's identity identification and basic data encryption (such as encryption through HTTPS), but the server's authentication of the client's legitimacy and protection of sensitive data are relatively weak.

[0003] How to improve the reliability of cloud-edge data transmission is an issue that needs to be addressed urgently. Summary of the invention

[0004] In view of this, the present disclosure provides a method, apparatus, computer device and storage medium for cloud-edge data transmission to solve the problem of low reliability of cloud-edge data transmission.

[0005] In a first aspect, the present disclosure provides a method for cloud-edge data transmission, which is applied to an edge device, and the method includes:

[0006] Initiate a certificate signing request to the cloud server and obtain the device certificate issued by the cloud server;

[0007] In the case of data transmission with the cloud server, the device certificate of the edge device and the first key parameter for key negotiation are sent to the cloud server; the cloud server is used to authenticate the device certificate of the edge device, and if the authentication is successful, generate a first data key of the application layer according to the first key parameter and the preset private key of the cloud server, and return the second key parameter corresponding to the preset private key of the cloud server to the edge device;

[0008] Obtaining the second key parameter returned by the cloud server, and generating a second data key of the application layer according to the second key parameter and a preset private key corresponding to the first key parameter;

[0009] The original data of the application layer is encrypted according to the second data key to obtain encrypted data, and the encrypted data is sent to the cloud service end, instructing the cloud service end to decrypt the encrypted data according to the first data key.

[0010] In a second aspect, the present disclosure provides a method for cloud-edge data transmission, which is applied to a cloud service end, and the method includes:

[0011] Get the certificate signing request initiated by the edge device;

[0012] Issue a corresponding device certificate according to the certificate signing request, and send the issued device certificate to the edge device;

[0013] Acquire a device certificate of the edge device and a first key parameter for key negotiation sent by the edge device;

[0014] Authenticate the device certificate of the edge device, and if the authentication is successful, generate a first data key of the application layer according to the first key parameter and the preset private key of the cloud server, and return a second key parameter corresponding to the preset private key of the cloud server to the edge device;

[0015] Obtaining encrypted data sent by the edge device; the encrypted data is obtained by encrypting original data of the application layer according to a second data key of the application layer, and the second data key is a key generated by the edge device according to the second key parameter and a preset private key corresponding to the first key parameter;

[0016] The encrypted data is decrypted according to the first data key to obtain the original data.

[0017] In a third aspect, the present disclosure provides a cloud-edge data transmission device, which is applied to an edge device, and the device includes:

[0018] A certificate acquisition unit, used to initiate a certificate signing request to a cloud server and obtain a device certificate issued by the cloud server;

[0019] A first key negotiation unit is used to send the device certificate of the edge device and the first key parameter for key negotiation to the cloud server when data is transmitted with the cloud server; the cloud server is used to authenticate the device certificate of the edge device, and if the authentication is successful, generate a first data key of the application layer according to the first key parameter and the preset private key of the cloud server, and return a second key parameter corresponding to the preset private key of the cloud server to the edge device; obtain the second key parameter returned by the cloud server, and generate a second data key of the application layer according to the second key parameter and the preset private key corresponding to the first key parameter;

[0020] The encryption unit is used to encrypt the original data of the application layer according to the second data key to obtain encrypted data, and send the encrypted data to the cloud service end, instructing the cloud service end to decrypt the encrypted data according to the first data key.

[0021] In a fourth aspect, the present disclosure provides a cloud-edge data transmission device, which is applied to a cloud service end, and the device includes:

[0022] The certificate issuing unit is used to obtain the certificate signing request initiated by the edge device; issue the corresponding device certificate according to the certificate signing request, and send the issued device certificate to the edge device;

[0023] an acquiring unit, configured to acquire a device certificate of the edge device and a first key parameter for key negotiation sent by the edge device;

[0024] A second key negotiation unit is configured to authenticate the device certificate of the edge device, and if the authentication is successful, generate a first data key of the application layer according to the first key parameter and the preset private key of the cloud server, and return a second key parameter corresponding to the preset private key of the cloud server to the edge device;

[0025] A decryption unit is used to obtain the encrypted data sent by the edge device; the encrypted data is obtained by encrypting the original data of the application layer according to the second data key of the application layer, and the second data key is a key generated by the edge device according to the second key parameter and a preset private key corresponding to the first key parameter; the encrypted data is decrypted according to the first data key to obtain the original data.

[0026] In a fifth aspect, the present disclosure provides a computer device, comprising: a memory and a processor, the memory and the processor are communicatively connected to each other, computer instructions are stored in the memory, and the processor executes the method of cloud-edge data transmission of the above-mentioned first aspect, second aspect or any corresponding embodiment thereof by executing the computer instructions.

[0027] In a sixth aspect, the present disclosure provides a computer-readable storage medium having computer instructions stored thereon, the computer instructions being used to enable a computer to execute the method for cloud-edge data transmission of the above-mentioned first aspect, second aspect or any corresponding embodiment thereof.

[0028] In a seventh aspect, the present disclosure provides a computer program product, including computer instructions, which are used to enable a computer to execute the method of cloud-edge data transmission of the above-mentioned first aspect, second aspect or any corresponding embodiment.

[0029] The edge device in the present disclosure can instruct the cloud service end to issue a device certificate. When performing data transmission, the edge device provides its own device certificate to prove its legitimacy, and implements key negotiation with the cloud service end using their respective key parameters. Each determines the data key of the application layer. Based on the data key, the original data of the application layer can be encrypted to implement encrypted data transmission at the application layer between the edge device and the cloud service end. Even if the intermediate network element obtains the encrypted data, it cannot decrypt it because it does not have the data key. This is equivalent to point-to-point communication between the cloud and the edge. Even if the public network is used for data transmission, data leakage can be effectively avoided, which can improve the security of data transmission. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] In order to more clearly illustrate the specific embodiments of the present disclosure or the technical solutions in the related technologies, the drawings required for use in the specific embodiments or the related technical descriptions will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0031] Figure 1 is a schematic diagram of a scenario of cloud-edge data transmission according to an embodiment of the present disclosure;

[0032] Figure 2 is a flowchart of a method for cloud-edge data transmission according to an embodiment of the present disclosure;

[0033] Figure 3 is a flowchart of another cloud-edge data transmission method according to an embodiment of the present disclosure;

[0034] Figure 4 is a schematic diagram of a cloud-edge architecture according to an embodiment of the present disclosure;

[0035] Figure 5 It is a schematic diagram of the interaction process of implementing data transmission between the edge device and the cloud service end according to an embodiment of the present disclosure;

[0036] Figure 6 is a structural block diagram of an apparatus for transmitting cloud-edge data of an edge device according to an embodiment of the present disclosure;

[0037] Figure 7 It is a structural block diagram of a cloud-edge data transmission device of a cloud service end according to an embodiment of the present disclosure;

[0038] Figure 8 It is a schematic diagram of the hardware structure of the computer device of the embodiment of the present disclosure. DETAILED DESCRIPTION

[0039] In order to make the purpose, technical solution and advantages of the embodiments of the present disclosure clearer, the technical solution in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are part of the embodiments of the present disclosure, rather than all the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present disclosure.

[0040] When data is transmitted on the cloud side, the edge device on the side generally only authenticates the cloud server on the cloud side. Figure 1 As shown, edge devices on the edge side generally communicate with the cloud server on the cloud side through one or more intermediate network elements (such as gateways, intermediate nodes, etc.), which will lead to unreliable cloud-edge data transmission, and sensitive data such as tokens, keys, personal information, etc. of edge devices are at risk of data leakage.

[0041] For example, in a CDN scenario, an edge device pulls a configuration file from a central node on the cloud side. After the edge device authenticates the central node, it can pull the configuration file based on HTTPS (Hypertext Transfer Protocol Secure), which makes the configuration file accessible on the public network, and other illegal devices can also obtain this data. In addition, each intermediate node between the edge device and the central node can also obtain the configuration file.

[0042] One way to improve security is to implement cloud-edge data transmission based on VPN (Virtual Private Network). Although this method improves the security and reliability of data transmission, the VPN cost is relatively high, is difficult to maintain, and cannot effectively utilize the advantages of the public network.

[0043] With the method for cloud-edge data transmission provided by the embodiments of the present disclosure, a cloud server can issue a corresponding device certificate for each edge device. When cloud-edge data is transmitted, the cloud server can authenticate the edge device based on the device certificate provided by the edge device to ensure the legitimacy of the edge device. Moreover, the cloud and edge negotiate the data key of the application layer, which can be used to transmit encrypted data at the application layer. Intermediate network elements during data transmission cannot restore the original plaintext, which can effectively avoid data leakage and improve the security of data transmission.

[0044] According to an embodiment of the present disclosure, a method embodiment of cloud-edge data transmission is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0045] In this embodiment, a method for cloud-edge data transmission is provided, which can be applied to edge devices. Figure 2 is a flow chart of a method for cloud-edge data transmission according to an embodiment of the present disclosure, such as Figure 2 As shown, the process includes the following steps.

[0046] Step S201, initiate a certificate signing request to the cloud server, and obtain a device certificate issued by the cloud server.

[0047] In this embodiment, the edge device can send a request to the cloud server to instruct the cloud server to issue a corresponding certificate, namely, a certificate signing request; after receiving the certificate signing request, the cloud server can verify the certificate signing request. After the verification is passed, the device certificate of the edge device can be issued and sent to the edge device.

[0048] For example, the edge device can generate a pair of asymmetric keys, which include a device public key and a corresponding device private key. The edge device generates a corresponding certificate signing request based on the asymmetric key, and the certificate signing request includes the device public key and the signature information generated by encryption based on the device private key. After the cloud server obtains the certificate signing request, it can verify the integrity of the certificate signing request and verify the signature information based on the device public key. If the verification passes, the certificate signing request can be considered legal, and the cloud server can sign based on its own private key, and finally obtain a device certificate recognized by the cloud server.

[0049] In step S202, when data is transmitted with the cloud server, the device certificate of the edge device and the first key parameter for key negotiation are sent to the cloud server; the cloud server is used to authenticate the device certificate of the edge device, and if the authentication is successful, the first data key of the application layer is generated according to the first key parameter and the preset private key of the cloud server, and the second key parameter corresponding to the preset private key of the cloud server is returned to the edge device.

[0050] In this embodiment, if the edge device needs to transmit data with the cloud server, for example, there is data on the edge device that needs to be sent to the cloud server, the edge device can negotiate a key with the cloud server.

[0051] Specifically, the edge device sends its current device certificate as proof of identity to the cloud server, so that the cloud server can verify the identity of the edge device, that is, the cloud server authenticates the device certificate of the edge device; if the authentication fails, it means that the edge device is illegal, and the cloud server will not establish a communication connection with the edge device; if the authentication passes, it means that the edge device is legal, and its device certificate is a certificate issued by the cloud server, allowing the edge device to communicate with the cloud server.

[0052] In addition, the edge device side is also provided with a key parameter for key negotiation, namely the first key parameter, and the edge device also sends the first key parameter to the cloud service end; if the device certificate of the edge device is legal (i.e., authenticated), the cloud service end uses the local preset private key, i.e., the preset private key of the cloud service end, and the first key parameter provided by the edge device to generate a data key used in the application layer, i.e., the first data key. It can be understood that the first data key is obtained based on the key parameter negotiation of the cloud edge.

[0053] In order to enable the edge device to complete key negotiation, the cloud server also needs to send the key parameter corresponding to its own preset private key, that is, the second key parameter, to the edge device.

[0054] Optionally, the cloud server itself also has its own certificate. When transmitting cloud-edge data, the cloud server can also send its own certificate to the edge device for the edge device to authenticate the cloud server's certificate to prevent the edge device from accessing an illegal cloud.

[0055] Step S203, obtaining the second key parameter returned by the cloud server, and generating a second data key of the application layer according to the second key parameter and a preset private key corresponding to the first key parameter.

[0056] As described above, if the device certificate of the edge device passes the authentication of the cloud server, the cloud server returns the second key parameter. In addition, the first key parameter provided by the edge device is related to its own pre-examination private key. After the edge device obtains the second key parameter, it can generate an application layer data key, i.e., the second data key, based on the second key parameter and the preset private key corresponding to the first key parameter (i.e., the preset private key of the edge device). Under normal circumstances, the second data key is consistent with the first data key; for example, the second data key is the same as the first data key, and the edge device and the cloud server can implement symmetric encrypted data transmission based on the first data key and the second data key.

[0057] The above-mentioned first key parameter and second key parameter are essentially a public key, which can be generated based on the corresponding preset private key.

[0058] Specifically, the edge device itself has its own preset private key XA , the cloud server itself has a preset private key X B When negotiating the key, the edge device and the cloud server can agree on a method for generating the data key, for example, based on an elliptic curve. A And the agreed data key generation method, the preset private key X can be calculated A The corresponding public key Y A , the public key Y A It can be used as the first key parameter.

[0059] Similar to edge devices, the cloud server uses its own preset private key X B And the agreed data key generation method, the preset private key X can be calculated B The corresponding public key Y B , the public key Y B The cloud server receives the first key parameter (i.e., the public key Y A ) and then combined with its own preset private key X B The corresponding data key, i.e., the first data key, can be calculated; for example, the data key can be obtained based on an elliptic curve algorithm. Similarly, the edge device obtains the second key parameter (i.e., the public key Y B ) and then combined with its own preset private key X A The corresponding data key, namely the second data key, can also be calculated. Moreover, the second data key is paired with the first data key to implement encryption and decryption processing.

[0060] For example, the data key can be determined based on the DH (Diffie-Hellman) algorithm. The edge device and the cloud server agree on the same prime number p and integer a (the prime number p is generally a larger prime number), then Y A =a^X A modp,Y B =a^X B modp, mod means remainder operation. The first data key K calculated by the cloud server B =K B =(Y A )^X B mod p; the second data key K calculated by the edge device A =K A =(Y B )^X A mod p. It can be proved that K A =K B , that is, the first data key is the same as the second data key.

[0061] Step S204, encrypt the original data of the application layer according to the second data key to obtain encrypted data, and send the encrypted data to the cloud server, instructing the cloud server to decrypt the encrypted data according to the first data key.

[0062] The edge device and the cloud server can transmit data based on the standard protocol of the protocol layer (such as the SSL protocol, i.e., the Secure Sockets Layer protocol, etc.), and data encryption can be implemented at the protocol layer. However, if there are other intermediate network elements between the edge device and the cloud server, the intermediate network elements can also crack the encryption of the protocol layer, resulting in the risk of data leakage. In this embodiment, the edge device and the cloud server generate data keys for the application layer, i.e., the first data key and the second data key. When transmitting data, the edge device can encrypt the original data (plaintext) of the application layer based on its own second data key to obtain encrypted data (ciphertext); when transmitting the encrypted data (ciphertext), even if it passes through the intermediate network element, the intermediate network element does not know the data key, so the original data (plaintext) cannot be restored. The cloud server obtains the encrypted data (ciphertext) and can decrypt it based on the previously negotiated first data key to restore the original data (plaintext) for subsequent processing.

[0063] Similarly, when the cloud service sends data to the edge device, it can also be encrypted based on the first data key, and the edge device can then decrypt it based on the second data key to achieve secure cloud-edge data transmission.

[0064] For example, in a CDN scenario, the edge device can pull the configuration file from the central node (cloud server) after authentication. Since the edge device is authenticated, other unauthenticated illegal devices cannot pull the configuration file from the central node. In addition, the edge device and the central node have negotiated data keys, which can effectively avoid data leakage in the intermediate node. In addition, the central node can also actively send the configuration file to the edge device to facilitate the rapid release of the configuration.

[0065] Among them, while implementing application layer encrypted transmission based on data keys, it does not affect the encryption of other layers. For example, the encryption method of the protocol layer can also be used simultaneously, that is, multi-layer encryption can be used, which is not only compatible with the existing protocol layer encryption, but also can improve the security of data transmission.

[0066] In the method for cloud-edge data transmission provided in this embodiment, the edge device can instruct the cloud server to issue a device certificate. When performing data transmission, the edge device provides its own device certificate to prove its own legitimacy, and implements key negotiation with the cloud server using their respective key parameters. Each device determines the data key of the application layer. Based on the data key, the original data of the application layer can be encrypted to achieve encrypted data transmission at the application layer between the edge device and the cloud server. Even if the intermediate network element obtains the encrypted data, it cannot decrypt it because it does not have the data key. This is equivalent to point-to-point communication between the cloud and the edge. Even if the public network is used for data transmission, data leakage can be effectively avoided, which can improve the security of data transmission.

[0067] In some optional implementations, the above step S201 "initiating a certificate signing request to the cloud server and obtaining a device certificate issued by the cloud server" may include the following steps A1 to A4.

[0068] Step A1, generate a first asymmetric key; the first asymmetric key includes a first public key and a first private key.

[0069] Step A2, encrypt the first public key and the identity information of the edge device according to the first private key to obtain the first signature information, and generate a first certificate signing request for issuing a device certificate; the first certificate signing request includes the first public key, identity information and the first signature information.

[0070] Step A3, sending the first certificate signing request to the cloud server, instructing the cloud server to verify the first signature information in the first certificate signing request according to the first public key, and issuing a first device certificate containing the first public key if the verification passes.

[0071] Step A4: Obtain the first device certificate issued by the cloud server.

[0072] In this embodiment, the edge device can pre-generate an asymmetric key, namely, a first asymmetric key, which includes a pair of public key and private key, which are referred to as the first public key and the first private key for ease of description. The asymmetric key is used to request the issuance of a certificate, and is generally different from the above-mentioned preset private key, key parameters, etc.

[0073] Among them, the edge device itself has certain identity information, and the identity information may include, for example, the domain name, organization name, geographic location, etc. corresponding to the edge device, and may also include the requested extension field, etc. This embodiment does not limit the content of the identity information. The first public key and the identity information are used as the part to be signed, and the first private key is used to encrypt the part to be signed (including at least the first public key and the identity information), that is, to sign it, so that the corresponding signature information, that is, the first signature information, can be obtained, and then the first public key, the identity information and the first signature information are combined to generate the corresponding certificate signing request, that is, the first certificate signing request.

[0074] The first signature information can prove the integrity and authenticity of the first certificate signing request.

[0075] Specifically, after sending the first certificate signing request to the cloud service end, the cloud service end verifies the first signature information in the first certificate signing request according to the first public key, that is, decrypts the first signature information, so that the first public key and identity information can be restored, so that it can be verified whether the first certificate signing request contains complete information, and whether the first public key has been tampered with. If the verification is passed, the cloud service end can generate a corresponding device certificate, that is, a first device certificate; for example, the cloud service end can generate information to be signed according to the first certificate signing request, and the information to be signed can include the first public key, and can also include information newly added by the cloud service end, such as the serial number, issuer, and validity period of the device certificate. In addition, the cloud service end signs the information to be signed based on its own private key to generate a signature value; the information to be signed and the signature value are combined to generate a device certificate of the edge device, that is, a first device certificate. The first device certificate is then sent to the edge device.

[0076] In this embodiment, the edge device signs the certificate signing request based on its own private key, so that the cloud server can verify based on the signature to ensure the legitimacy and validity of the certificate signing request.

[0077] Optionally, the certificate signing request includes a timestamp; the above step of "obtaining a device certificate issued by the cloud server" specifically includes: when the timestamp is within the validity period, obtaining a device certificate issued by the cloud server.

[0078] In this embodiment, in order to prevent the certificate signing request of a legitimate edge device from being used by an illegal device, a timestamp is set for the certificate signing request; after the cloud server receives the certificate signing request, it verifies whether the timestamp of the certificate signing request is still within the validity period (the validity period is, for example, 10 minutes, 1 hour, etc.). If it is within the validity period, it means that the certificate signing request is legitimate, and the cloud server can continue with subsequent processing, such as issuing a device certificate.

[0079] For example, the first certificate signing request is provided with a timestamp, and the first public key, identity confidence, and timestamp can be signed based on its first private key. While preventing the timestamp from being tampered with, the cloud service end can also obtain the timestamp to verify whether it is valid.

[0080] Optionally, the above step S201 "initiating a certificate signing request to the cloud server and obtaining a device certificate issued by the cloud server" may include the following steps B1 to B4.

[0081] Step B1: if there is a historical device certificate, generate a second asymmetric key; the second asymmetric key includes a second public key and a second private key.

[0082] Step B2, encrypt the second public key and the identity information of the edge device according to the historical private key corresponding to the historical device certificate, obtain the second signature information, and generate a second certificate signature request for updating the device certificate; the second certificate signature request includes the second public key, identity information and second signature information.

[0083] Step B3, send the second certificate signing request to the cloud server, instruct the cloud server to verify the second signature information in the second certificate signing request according to the historical public key corresponding to the historical device certificate, and if the verification passes, update the device certificate of the edge device from the historical device certificate to the second device certificate containing the second public key.

[0084] Step B4, obtaining the second device certificate issued by the cloud server.

[0085] In this embodiment, the edge device may include a client (such as an application) used by a user, or the edge device may also be a server, etc. In addition, in order to ensure the security of data transmission, the issued device certificate has a certain validity period, such as the first device certificate mentioned above; for example, the validity period is 7 days, that is, after 7 days, the edge device needs to re-request a new device certificate. This requires ensuring that each generated device certificate has a high degree of security.

[0086] For the client used by the user, the user can provide a legitimate certificate signing request based on the information provided by the user (such as face, fingerprint information, etc.). However, for edge devices such as servers, the operation and maintenance personnel are not often next to the server. For this scenario, this embodiment performs self-authentication on the device certificate on the edge device side to ensure the validity of each generated device certificate.

[0087] Specifically, the edge device itself has an existing device certificate, namely a historical device certificate. The historical device certificate can be the latest device certificate of the edge device. It can be understood that the historical device certificate corresponds to the corresponding private key and public key. For the convenience of description, the private key and public key corresponding to the historical device certificate are referred to as: historical private key and historical public key. For example, the historical device certificate can be determined based on the above steps A1 to A4. The above-mentioned first device certificate can be used as a historical device certificate. Correspondingly, the first private key and the first public key are the historical public key and the historical private key. Alternatively, the historical device certificate can also be the certificate initially set for the edge device. When the edge device is initialized, the first device certificate of the edge device can be activated based on the initially set certificate.

[0088] If it is necessary to update the existing historical device certificate, for example, the historical device certificate is about to expire, then similar to the above step A1, the edge device can generate a second asymmetric key, which includes a second public key and a second private key. When generating a certificate signing request, that is, when generating a second certificate signing request, the edge device does not use the second private key at this time to sign, but signs based on the historical private key to obtain the corresponding second signature information, generates a second certificate signing request containing the second public key, identity information and second signature information, and sends it to the cloud service end.

[0089] After the cloud server obtains the second signature information, since the historical device certificate is also issued by the cloud server, the cloud server saves the public key corresponding to the historical device certificate, that is, the historical public key, and then based on the historical public key, the second signature information in the second certificate signature request can be verified. The verification principle is similar to the above step A3 and will not be repeated, except that the second public key in the second certificate signature request is not required for verification at this time. If the verification is successful, it means that the edge device that initiated the second certificate signature request is a device with a credible historical private key, that is, the edge device is credible, so that the edge device can be self-authenticated by using the historical device certificate already existing in the edge device.

[0090] Moreover, the cloud server generates a new device certificate containing the second public key based on the second signature certificate request, namely the second device certificate, and sends the second device certificate to the edge device, thereby realizing the certificate update on the edge device side. In addition, the cloud server also updates the device certificate of the edge device recorded locally from the historical device certificate to the second device certificate to ensure the accuracy of the device certificate.

[0091] It can be understood that the second private key is used in pair with the second device certificate; and when the device certificate is updated next time, the second private key is the historical private key and needs to be signed based on the second private key to generate a new certificate signing request.

[0092] In this embodiment, the edge device uses the historical private key of the existing historical device certificate to sign, so that the cloud server can verify the legitimacy of the historical device certificate of the edge device, thereby issuing a new second device certificate based on the historical device certificate. This process does not require the edge device to provide additional authentication information such as fingerprints, and can safely and conveniently implement self-authentication of the device certificate to ensure the long-term validity of the device certificate.

[0093] In some optional implementations, as described above, the certificate signing request includes a device public key generated by the edge device; for example, the device public key may be the first public key, the second public key, etc. described above.

[0094] Furthermore, the above step S203 "obtaining the second key parameter returned by the cloud server, and generating a second data key of the application layer according to the second key parameter and a preset private key corresponding to the first key parameter" may specifically include the following steps C1 to C3.

[0095] Step C1, obtaining the second key parameter returned by the cloud server and the verification information generated by encrypting the first data key according to the device public key;

[0096] Step C2, generating a pending data key of the application layer according to the second key parameter and a preset private key corresponding to the first key parameter, and decrypting the verification information according to the device private key corresponding to the device public key to obtain the first data key;

[0097] Step C3: When the pending data key matches the first data key, the pending data key is used as the first data key.

[0098] In this embodiment, when the cloud service returns the second key parameter to the edge device, it will also encrypt the first data key generated by itself according to the device public key in the certificate signing request to obtain the corresponding verification information; since the device private key only exists in the edge device, other devices will not obtain the first data key even if they obtain the verification information.

[0099] After the legitimate edge device obtains the second key parameter and verification information, in addition to generating a data key (i.e., pending data key), it can also decrypt the verification information based on its own device private key, thereby obtaining the first data key calculated by the cloud server. By comparing the pending data key with the first data key, if the two match, for example, the two are the same, it can be determined that the key negotiation is successful, and the pending data key is used as the first data key for subsequent use; if the two do not match, it means that the key negotiation has failed and needs to be renegotiated.

[0100] In this embodiment, the cloud server encrypts the first data key according to the device public key to generate verification information, and returns it to the edge device. While ensuring that the data key is not leaked, the edge device can verify the data key generated by itself, thereby ensuring the accuracy of key negotiation.

[0101] Optionally, the above step S202 "sending the device certificate of the edge device and the first key parameter for key negotiation to the cloud service end" may include the following steps D11 to D12, and may also include the following step D2.

[0102] Step D11, sending the device certificate of the edge device to the cloud server, instructing the cloud server to authenticate the device certificate of the edge device.

[0103] Step D12, when the device certificate authentication of the edge device is passed, a network channel is established between the edge device and the cloud server, and a first key parameter for key negotiation is sent to the cloud server based on the network channel.

[0104] Step D2, in the case of data transmission based on a private protocol, the device certificate of the edge device and the first key parameter used for key negotiation are sent to the cloud service end.

[0105] In this embodiment, certificate authentication and key negotiation can be performed between the edge device and the cloud server based on the standard protocol. Generally, the legitimacy must be determined through network authentication before a network channel can be established. The edge device can then perform key negotiation based on the network channel, that is, send the first key parameter to the cloud server, and obtain the second key parameter issued by the cloud server.

[0106] For a more flexible private protocol, the device certificate and the first key parameter of the edge device can be sent to the cloud service end at the same time, reducing the number of interactions between the cloud and the edge and improving communication efficiency. Among them, the private protocol can be a protocol determined by custom design based on the standard protocol.

[0107] For example, in a private protocol, different fields can be defined to represent the device certificate, first key parameters, etc. of the edge device, so that the private protocol can be used to uniformly transmit various information such as the device certificate, first key parameters, etc.

[0108] Optionally, when using a private protocol, the process of issuing certificates and negotiating keys between the edge device and the cloud server can also be combined. Specifically, the edge device directly sends the certificate signing request and the first key parameter to the cloud server based on the private protocol, so that the cloud server can return the device certificate and the second key parameter to complete the key negotiation; for example, when the edge device is initialized, the edge device can upload the certificate signing request and the first key parameter simultaneously.

[0109] Optionally, for the edge device, the preset private key corresponding to the first key parameter (i.e., the preset private key of the edge device) is the persistent key of the edge device. Specifically, for each edge device, its own preset private key can be fixed in advance to achieve one machine and one key, and no repeated generation is required for subsequent key negotiation.

[0110] Similarly, the cloud server also pre-stores a certain number of preset private keys, and these preset private keys form a key ring to achieve efficient management of the cloud server's preset private keys, facilitate regular rotation of keys, reduce computing power, and improve performance.

[0111] In this embodiment, a method for cloud-edge data transmission is provided, which can be applied to a cloud server. Figure 3 is a flow chart of a method for cloud-edge data transmission according to an embodiment of the present disclosure. Figure 3 As shown, the process includes the following steps.

[0112] Step S301: Obtain a certificate signing request initiated by an edge device.

[0113] Step S302: issue a corresponding device certificate according to the certificate signing request, and send the issued device certificate to the edge device.

[0114] Step S303: Acquire a device certificate of the edge device and a first key parameter for key negotiation sent by the edge device.

[0115] Step S304, authenticate the device certificate of the edge device. If the authentication is successful, generate the first data key of the application layer according to the first key parameter and the preset private key of the cloud server, and return the second key parameter corresponding to the preset private key of the cloud server to the edge device.

[0116] Step S305, obtain the encrypted data sent by the edge device; the encrypted data is obtained by encrypting the original data of the application layer according to the second data key of the application layer, and the second data key is a key generated by the edge device according to the second key parameter and the preset private key corresponding to the first key parameter.

[0117] Step S306: decrypt the encrypted data according to the first data key to obtain the original data.

[0118] In this embodiment, the cloud service end can sign the certificate request initiated by the edge device and issue the corresponding device certificate; and after completing the key negotiation with the edge device, the cloud-edge secure data transmission can be realized based on the data key of the application layer. The above process can be specifically referred to the relevant description of steps S201 to S204, which will not be repeated here.

[0119] In some optional embodiments, the certificate signing request is a first certificate signing request for issuing a device certificate; the first certificate signing request includes a first public key generated by an edge device, identity information of the edge device, and first signature information; the first signature information is obtained by encrypting the first public key and the identity information of the edge device based on a first private key corresponding to the first public key.

[0120] In addition, the above step S302 "issuing a corresponding device certificate according to the certificate signing request, and sending the issued device certificate to the edge device" includes:

[0121] The first signature information in the first certificate signing request is verified according to the first public key. If the verification passes, a first device certificate including the first public key is issued; and the first device certificate is sent to the edge device.

[0122] The process of the cloud server issuing the first device certificate may be specifically described in steps A1 to A4 above, and will not be repeated here.

[0123] Optionally, the certificate signing request is a second certificate signing request for updating the device certificate; the second certificate signing request includes a second public key generated by the edge device, identity information of the edge device, and second signature information; the second signature information is obtained by encrypting the second public key and the identity information of the edge device based on the historical private key corresponding to the historical device certificate of the edge device.

[0124] In addition, the above step S302 "issuing a corresponding device certificate according to the certificate signing request, and sending the issued device certificate to the edge device" includes:

[0125] The second signature information in the second certificate signing request is verified according to the historical public key corresponding to the historical device certificate. If the verification passes, the device certificate of the edge device is updated from the historical device certificate to the second device certificate containing the second public key; the second device certificate is sent to the edge device.

[0126] The process of the cloud server issuing the second device certificate may be specifically referred to the relevant descriptions of the above steps B1 to B4, which will not be repeated here.

[0127] Optionally, the certificate signing request includes a device public key generated by the edge device.

[0128] In addition, the above step S304 "returning the second key parameter corresponding to the preset private key of the cloud server to the edge device" specifically includes:

[0129] The first data key is encrypted according to the device public key to generate verification information; the second key parameter and verification information are returned to the edge device; the verification information is used by the edge device to decrypt the verification information according to the device private key corresponding to the device public key to obtain the first data key, and verify the data key generated by itself based on the obtained first data key.

[0130] The process of key negotiation between the cloud server and the edge device can be specifically described in steps C1 to C3 above, which will not be repeated here.

[0131] Figure 4 A schematic diagram of the cloud edge architecture in this embodiment is shown. Figure 4 As shown, the cloud service end may include a trusted computing module, a key negotiation module, a risk control module and a network transmission module, and the cloud service end may also be provided with an identity authentication module, a device management module and a credential management module.

[0132] Among them, the device management module is responsible for initializing and managing the life cycle of edge devices; the credential management module is responsible for generating unique credentials (i.e., device certificates) and providing management capabilities for credential validity; the identity authentication module is responsible for identifying and authenticating identity information; the network transmission module is responsible for realizing network transmission at both ends of the cloud edge; the trusted computing module provides key storage capabilities on the medium (similar to confidentiality cards, etc.); the key exchange module provides a collection of key exchange algorithms, which can realize symmetric encryption key negotiation at the application layer after the cloud server and edge devices are integrated separately; the risk control identification module is used for feature analysis and risk identification capabilities during cloud-edge data transmission.

[0133] In addition, if Figure 4 As shown, the edge device also includes corresponding trusted computing modules, key negotiation modules, network transmission modules and risk control modules.

[0134] Figure 5 The figure shows the interactive process diagram for data transmission between edge devices and cloud servers. Figure 5 As shown, the process includes the following steps S501 to S518.

[0135] Step S501: The edge device generates an asymmetric key, which includes a device public key and a device private key.

[0136] For example, the edge device can generate a public-private key pair, namely, a device public key and a device private key, based on its own trusted computing module or calling interface.

[0137] Step S502: Generate a certificate signing request according to the device private key.

[0138] The certificate signing request includes the device public key and corresponding signature information.

[0139] Step S503: Send the certificate signing request to the cloud service end.

[0140] Among them, the edge device can call the network transmission interface based on the network transmission module and establish a TLS (Transport Layer Security Protocol) link with the cloud server.

[0141] Step S504: The cloud server verifies the certificate signing request.

[0142] Among them, the cloud server can perform weak access identity identification based on the identity authentication module, such as identifying the IP address of the edge device (it can also be the device's MAC address, device serial number and other metadata), and based on this, determine whether the edge device is on the whitelist; and also verify the signature information in the certificate signing request to ensure the integrity and validity of the certificate signature information.

[0143] Step S505: If the verification is successful, the credential management module is called to issue a device certificate for the edge device.

[0144] If the verification fails, the edge device connection is rejected. If the verification passes, the cloud service can register the device management based on the IP address of the edge device, the certificate issuance request, etc. This process can be implemented based on the device management module. In addition, the credential management module is called with the certificate signing request to generate and manage the unique credential of the edge device, i.e., the device certificate.

[0145] Step S506, obtaining the device certificate returned by the credential management module.

[0146] Step S507: The cloud server sends the device certificate to the edge device.

[0147] At this point, the edge device obtains its own device certificate and completes the device initialization process.

[0148] Step S508: The edge device initiates a network request to the cloud server, which includes a device certificate of the edge device.

[0149] Step S509: the cloud server verifies the network request.

[0150] Among them, the cloud server can authenticate the device certificate of the edge device based on the identity authentication module. After the device certificate passes the authentication, the device certificate and network request characteristics (such as IP address, protocol characteristics, etc.) can be further sent to the risk control module. The legitimacy of the network authentication is determined based on the risk control module. If it is legal, the connection is successfully established; completing the network authentication.

[0151] Step S510: if the verification is successful, a network connection is established with the edge device.

[0152] At this point, network authentication has been completed between the edge device and the cloud server.

[0153] In step S511, the edge device generates a first key parameter corresponding to the preset key based on the preset key stored in the edge device.

[0154] Among them, the edge device can generate a key curve based on the trusted computing module, and then call the key negotiation module to calculate the corresponding first key parameter.

[0155] In step S512, the edge device sends the first key parameter to the cloud service end.

[0156] Step S513: The cloud server generates a first data key of the application layer according to the first key parameter and a preset private key of the cloud server.

[0157] In step S514, the cloud server returns a second key parameter corresponding to the preset private key of the cloud server to the edge device.

[0158] The cloud service end may generate the first data key based on its own key negotiation module and determine the second key parameter. For example, the second key parameter may be a corresponding key curve parameter.

[0159] Step S515: The edge device generates a second data key of the application layer according to the second key parameter and a preset private key corresponding to the first key parameter.

[0160] At this point, key negotiation is completed between the edge device and the cloud server.

[0161] Step S516: The edge device encrypts the original data of the application layer according to the second data key to obtain encrypted data.

[0162] In step S517, the edge device sends the encrypted data to the cloud service end.

[0163] In step S518, the cloud server decrypts the encrypted data according to the first data key to obtain the original data.

[0164] At this point, secure data transmission can be carried out between edge devices and cloud servers at the application layer, and the data transmission process has strong encryption and authentication capabilities.

[0165] The method for cloud-edge data transmission provided in this embodiment issues a device certificate for the edge device, and subsequently implements secure communication on the public network based on the device certificate, which can effectively solve the security issues of edge devices accessed by the public network and reduce the security risks caused by API exposure on the public network. Secure transmission can be achieved between the cloud and the edge, not relying solely on transport layer protocol encryption, but ensuring data reliability and privacy through application mechanisms, so that data transmission can ignore intermediate links. In addition, the edge device can implement one machine and one password for data transmission at the application layer, effectively ensuring the reliability and privacy of cloud-edge data intercommunication.

[0166] In this embodiment, a device for cloud-edge data transmission is also provided, which is used to implement the above-mentioned embodiments and preferred implementation modes, and will not be repeated here. As used below, the term "module" can be a combination of software and / or hardware that implements a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, the implementation of hardware, or a combination of software and hardware, is also possible and conceivable.

[0167] This embodiment provides a cloud-edge data transmission device, which is applied to edge devices, such as Figure 6 As shown, it includes:

[0168] The certificate acquisition unit 601 is used to initiate a certificate signing request to the cloud server and obtain a device certificate issued by the cloud server;

[0169] The first key negotiation unit 602 is used to send the device certificate of the edge device and the first key parameter for key negotiation to the cloud server when data is transmitted with the cloud server; the cloud server is used to authenticate the device certificate of the edge device, and if the authentication is successful, generate a first data key of the application layer according to the first key parameter and the preset private key of the cloud server, and return a second key parameter corresponding to the preset private key of the cloud server to the edge device; obtain the second key parameter returned by the cloud server, and generate a second data key of the application layer according to the second key parameter and the preset private key corresponding to the first key parameter;

[0170] The encryption unit 603 is used to encrypt the original data of the application layer according to the second data key to obtain encrypted data, and send the encrypted data to the cloud server, instructing the cloud server to decrypt the encrypted data according to the first data key.

[0171] In some optional implementations, the certificate acquisition unit 601 initiates a certificate signing request to the cloud server and acquires a device certificate issued by the cloud server, including:

[0172] Generate a first asymmetric key; the first asymmetric key includes a first public key and a first private key;

[0173] Encrypt the first public key and the identity information of the edge device according to the first private key to obtain first signature information, and generate a first certificate signing request for issuing a device certificate; the first certificate signing request includes the first public key, the identity information and the first signature information;

[0174] Sending the first certificate signing request to a cloud service end, instructing the cloud service end to verify the first signature information in the first certificate signing request according to the first public key, and issuing a first device certificate containing the first public key if the verification passes;

[0175] Obtain the first device certificate issued by the cloud server.

[0176] In some optional implementations, the certificate acquisition unit 601 initiates a certificate signing request to the cloud server and acquires a device certificate issued by the cloud server, including:

[0177] In the case where the historical device certificate exists, generating a second asymmetric key; the second asymmetric key includes a second public key and a second private key;

[0178] According to the historical private key corresponding to the historical device certificate, the second public key and the identity information of the edge device are encrypted to obtain second signature information, and a second certificate signature request for updating the device certificate is generated; the second certificate signature request includes the second public key, the identity information and the second signature information;

[0179] Sending the second certificate signing request to the cloud server, instructing the cloud server to verify the second signature information in the second certificate signing request according to the historical public key corresponding to the historical device certificate, and if the verification passes, updating the device certificate of the edge device from the historical device certificate to the second device certificate containing the second public key;

[0180] Obtain the second device certificate issued by the cloud server.

[0181] In some optional implementations, the certificate signing request includes a device public key generated by the edge device;

[0182] The first key negotiation unit 602 obtains the second key parameter returned by the cloud server, and generates a second data key of the application layer according to the second key parameter and a preset private key corresponding to the first key parameter, including:

[0183] Obtaining the second key parameter returned by the cloud server and verification information generated by encrypting the first data key according to the device public key;

[0184] Generate a pending data key of the application layer according to the second key parameter and a preset private key corresponding to the first key parameter, and decrypt the verification information according to the device private key corresponding to the device public key to obtain the first data key;

[0185] In the case where the pending data key matches the first data key, the pending data key is used as the first data key.

[0186] In some optional implementations, the first key negotiation unit 602 sends the device certificate of the edge device and the first key parameter for key negotiation to the cloud service end, including:

[0187] Sending the device certificate of the edge device to the cloud service end, instructing the cloud service end to authenticate the device certificate of the edge device;

[0188] When the device certificate of the edge device is authenticated, a network channel is established between the edge device and the cloud service end, and a first key parameter for key negotiation is sent to the cloud service end based on the network channel;

[0189] or,

[0190] In the case of data transmission based on a private protocol, the device certificate of the edge device and the first key parameter used for key negotiation are sent to the cloud service end.

[0191] In some optional implementations, the preset private key corresponding to the first key parameter is a key persisted by the edge device;

[0192] And / or, the preset private key of the cloud server is a key in a key ring maintained by the cloud server.

[0193] This embodiment provides another cloud-edge data transmission device, which is applied to a cloud service end, such as Figure 7 As shown, it includes:

[0194] The certificate issuing unit 701 is used to obtain a certificate signing request initiated by an edge device; issue a corresponding device certificate according to the certificate signing request, and send the issued device certificate to the edge device;

[0195] An acquiring unit 702 is configured to acquire a device certificate of the edge device and a first key parameter for key negotiation sent by the edge device;

[0196] The second key negotiation unit 703 is used to authenticate the device certificate of the edge device, and if the authentication is successful, generate a first data key of the application layer according to the first key parameter and the preset private key of the cloud server, and return a second key parameter corresponding to the preset private key of the cloud server to the edge device;

[0197] The decryption unit 704 is used to obtain the encrypted data sent by the edge device; the encrypted data is obtained by encrypting the original data of the application layer according to the second data key of the application layer, and the second data key is a key generated by the edge device according to the second key parameter and a preset private key corresponding to the first key parameter; the encrypted data is decrypted according to the first data key to obtain the original data.

[0198] In some optional implementations, the certificate signing request is a first certificate signing request for issuing a device certificate; the first certificate signing request includes a first public key generated by the edge device, identity information of the edge device, and first signature information; the first signature information is obtained by encrypting the first public key and the identity information of the edge device according to a first private key corresponding to the first public key;

[0199] The certificate issuing unit 701 issues a corresponding device certificate according to the certificate signing request, and sends the issued device certificate to the edge device, including:

[0200] Verifying the first signature information in the first certificate signing request according to the first public key, and issuing a first device certificate including the first public key if the verification passes;

[0201] The first device certificate is sent to the edge device.

[0202] In some optional implementations, the certificate signing request is a second certificate signing request for updating a device certificate; the second certificate signing request includes a second public key generated by the edge device, identity information of the edge device, and second signature information; the second signature information is obtained by encrypting the second public key and the identity information of the edge device according to a historical private key corresponding to a historical device certificate of the edge device;

[0203] The certificate issuing unit 701 issues a corresponding device certificate according to the certificate signing request, and sends the issued device certificate to the edge device, including:

[0204] Verifying the second signature information in the second certificate signing request according to the historical public key corresponding to the historical device certificate, and if the verification passes, updating the device certificate of the edge device from the historical device certificate to a second device certificate including the second public key;

[0205] The second device certificate is issued to the edge device.

[0206] In some optional implementations, the certificate signing request includes a device public key generated by the edge device;

[0207] The second key negotiation unit 703 returns a second key parameter corresponding to the preset private key of the cloud server to the edge device, including:

[0208] Encrypting the first data key according to the device public key to generate verification information;

[0209] Return the second key parameter and the verification information to the edge device; the verification information is used by the edge device to decrypt the verification information according to the device private key corresponding to the device public key, obtain the first data key, and verify the data key generated by itself according to the obtained first data key.

[0210] The further functional description of each of the above modules and units is the same as that of the above corresponding embodiments and will not be repeated here.

[0211] The cloud-edge data transmission device in this embodiment is presented in the form of a functional unit, where the unit refers to an ASIC (Application Specific Integrated Circuit) circuit, including a processor and memory that executes one or more software or fixed programs, and / or other devices that can provide the above functions.

[0212] The present disclosure also provides a computer device having the above Figure 6 or Figure 7 The device for cloud-edge data transmission is shown.

[0213] See also Figure 8 , Figure 8 is a schematic diagram of a computer device provided by an optional embodiment of the present disclosure, such as Figure 8As shown, the computer device includes: one or more processors 10, a memory 20, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. Various components are connected to each other using different buses for communication, and can be installed on a common mainboard or installed in other ways as needed. The processor can process instructions executed in the computer device, including instructions stored in or on the memory to display the graphical information of the GUI on an external input / output device (such as a display device coupled to the interface). In some optional embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories. Similarly, multiple computer devices can be connected, and each device provides some necessary operations (for example, as a server array, a group of blade servers, or a multi-processor system). Figure 8 A processor 10 is taken as an example.

[0214] The processor 10 may be a central processing unit, a network processor or a combination thereof. The processor 10 may further include a hardware chip. The hardware chip may be a dedicated integrated circuit, a programmable logic device or a combination thereof. The programmable logic device may be a complex programmable logic device, a field programmable gate array, a general purpose array logic or any combination thereof.

[0215] The memory 20 stores instructions executable by at least one processor 10, so that the at least one processor 10 executes the method shown in the above embodiment.

[0216] The memory 20 may include a program storage area and a data storage area, wherein the program storage area may store an operating system, an application required for at least one function; the data storage area may store data created according to the use of the computer device, etc. In addition, the memory 20 may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some optional embodiments, the memory 20 may optionally include a memory remotely arranged relative to the processor 10, and these remote memories may be connected to the computer device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0217] The memory 20 may include a volatile memory, such as a random access memory; the memory may also include a non-volatile memory, such as a flash memory, a hard disk or a solid state drive; the memory 20 may also include a combination of the above types of memory.

[0218] The computer device further comprises a communication interface 30 for the computer device to communicate with other devices or a communication network.

[0219] The embodiments of the present disclosure also provide a computer-readable storage medium. The above-mentioned method according to the embodiments of the present disclosure can be implemented in hardware, firmware, or can be implemented as a computer code that can be recorded in a storage medium, or can be implemented as a computer code that is originally stored in a remote storage medium or a non-temporary machine-readable storage medium and will be stored in a local storage medium and downloaded through a network, so that the method described herein can be stored in such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only storage memory, a random access memory, a flash memory, a hard disk or a solid-state drive, etc.; further, the storage medium can also include a combination of the above-mentioned types of memory. It can be understood that a computer, a processor, a microprocessor controller, or programmable hardware includes a storage component that can store or receive software or computer code. When the software or computer code is accessed and executed by a computer, a processor, or hardware, the method shown in the above embodiment is implemented.

[0220] A part of the present disclosure may be applied as a computer program product, such as a computer program instruction, which, when executed by a computer, can call or provide the method and / or technical solution according to the present disclosure through the operation of the computer. Those skilled in the art should understand that the existence of computer program instructions in computer-readable media includes, but is not limited to, source files, executable files, installation package files, etc., and accordingly, the way in which computer program instructions are executed by a computer includes, but is not limited to: the computer directly executes the instruction, or the computer compiles the instruction and then executes the corresponding compiled program, or the computer reads and executes the instruction, or the computer reads and installs the instruction and then executes the corresponding installed program. Here, the computer-readable medium can be any available computer-readable storage medium or communication medium accessible to the computer.

[0221] Although the embodiments of the present disclosure are described in conjunction with the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present disclosure, and such modifications and variations should all be included in the protection scope of the present disclosure.

Claims

1. A method for cloud-edge data transmission, characterized in that: Applied to an edge device, the method comprises: Initiate a certificate signing request to the cloud server and obtain the device certificate issued by the cloud server; In the case of data transmission with the cloud server, the device certificate of the edge device and the first key parameter for key negotiation are sent to the cloud server; the cloud server is used to authenticate the device certificate of the edge device, and if the authentication is successful, generate a first data key of the application layer according to the first key parameter and the preset private key of the cloud server, and return the second key parameter corresponding to the preset private key of the cloud server to the edge device; Obtaining the second key parameter returned by the cloud server, and generating a second data key of the application layer according to the second key parameter and a preset private key corresponding to the first key parameter; The original data of the application layer is encrypted according to the second data key to obtain encrypted data, and the encrypted data is sent to the cloud service end, instructing the cloud service end to decrypt the encrypted data according to the first data key.

2. The method according to claim 1, characterized in that The initiating a certificate signing request to the cloud server and obtaining a device certificate issued by the cloud server includes: Generate a first asymmetric key; the first asymmetric key includes a first public key and a first private key; Encrypt the first public key and the identity information of the edge device according to the first private key to obtain first signature information, and generate a first certificate signing request for issuing a device certificate; the first certificate signing request includes the first public key, the identity information and the first signature information; Sending the first certificate signing request to a cloud service end, instructing the cloud service end to verify the first signature information in the first certificate signing request according to the first public key, and issuing a first device certificate containing the first public key if the verification passes; Obtain the first device certificate issued by the cloud server.

3. The method according to claim 1 or 2, characterized in that: The initiating a certificate signing request to the cloud server and obtaining a device certificate issued by the cloud server includes: In the case where the historical device certificate exists, generating a second asymmetric key; the second asymmetric key includes a second public key and a second private key; According to the historical private key corresponding to the historical device certificate, the second public key and the identity information of the edge device are encrypted to obtain second signature information, and a second certificate signature request for updating the device certificate is generated; the second certificate signature request includes the second public key, the identity information and the second signature information; Sending the second certificate signing request to the cloud server, instructing the cloud server to verify the second signature information in the second certificate signing request according to the historical public key corresponding to the historical device certificate, and if the verification passes, updating the device certificate of the edge device from the historical device certificate to the second device certificate containing the second public key; Obtain the second device certificate issued by the cloud server.

4. The method according to claim 1, characterized in that: The certificate signing request includes a device public key generated by the edge device; Acquiring the second key parameter returned by the cloud server, and generating a second data key of the application layer according to the second key parameter and a preset private key corresponding to the first key parameter, including: Obtaining the second key parameter returned by the cloud server and verification information generated by encrypting the first data key according to the device public key; Generate a pending data key of the application layer according to the second key parameter and a preset private key corresponding to the first key parameter, and decrypt the verification information according to the device private key corresponding to the device public key to obtain the first data key; In the case where the pending data key matches the first data key, the pending data key is used as the first data key.

5. The method according to claim 1, characterized in that The sending the device certificate of the edge device and the first key parameter for key negotiation to the cloud service end includes: Sending the device certificate of the edge device to the cloud service end, instructing the cloud service end to authenticate the device certificate of the edge device; When the device certificate of the edge device is authenticated, a network channel is established between the edge device and the cloud service end, and a first key parameter for key negotiation is sent to the cloud service end based on the network channel; or, In the case of data transmission based on a private protocol, the device certificate of the edge device and the first key parameter used for key negotiation are sent to the cloud service end.

6. The method according to claim 1, characterized in that The preset private key corresponding to the first key parameter is the key persisted by the edge device; And / or, the preset private key of the cloud server is a key in a key ring maintained by the cloud server.

7. A method for cloud-edge data transmission, characterized in that: Applied to a cloud server, the method includes: Get the certificate signing request initiated by the edge device; Issue a corresponding device certificate according to the certificate signing request, and send the issued device certificate to the edge device; Acquire a device certificate of the edge device and a first key parameter for key negotiation sent by the edge device; Authenticate the device certificate of the edge device, and if the authentication is successful, generate a first data key of the application layer according to the first key parameter and the preset private key of the cloud server, and return a second key parameter corresponding to the preset private key of the cloud server to the edge device; Obtaining encrypted data sent by the edge device; the encrypted data is obtained by encrypting original data of the application layer according to a second data key of the application layer, and the second data key is a key generated by the edge device according to the second key parameter and a preset private key corresponding to the first key parameter; The encrypted data is decrypted according to the first data key to obtain the original data.

8. The method according to claim 7, characterized in that The certificate signing request is a first certificate signing request for issuing a device certificate; the first certificate signing request includes a first public key generated by the edge device, identity information of the edge device, and first signature information; the first signature information is obtained by encrypting the first public key and the identity information of the edge device according to a first private key corresponding to the first public key; The issuing of a corresponding device certificate according to the certificate signing request, and sending the issued device certificate to the edge device, includes: Verifying the first signature information in the first certificate signing request according to the first public key, and issuing a first device certificate including the first public key if the verification passes; The first device certificate is sent to the edge device.

9. The method according to claim 7 or 8, characterized in that: The certificate signing request is a second certificate signing request for updating a device certificate; the second certificate signing request includes a second public key generated by the edge device, identity information of the edge device, and second signature information; the second signature information is obtained by encrypting the second public key and the identity information of the edge device according to a historical private key corresponding to a historical device certificate of the edge device; The issuing of a corresponding device certificate according to the certificate signing request, and sending the issued device certificate to the edge device, includes: Verifying the second signature information in the second certificate signing request according to the historical public key corresponding to the historical device certificate, and if the verification passes, updating the device certificate of the edge device from the historical device certificate to a second device certificate including the second public key; The second device certificate is issued to the edge device.

10. The method according to claim 7, characterized in that The certificate signing request includes a device public key generated by the edge device; The returning the second key parameter corresponding to the preset private key of the cloud server to the edge device includes: Encrypting the first data key according to the device public key to generate verification information; Return the second key parameter and the verification information to the edge device; the verification information is used by the edge device to decrypt the verification information according to the device private key corresponding to the device public key, obtain the first data key, and verify the data key generated by itself according to the obtained first data key.

11. A device for cloud-edge data transmission, characterized in that: Applied to edge devices, the device comprises: A certificate acquisition unit, used to initiate a certificate signing request to a cloud server and obtain a device certificate issued by the cloud server; A first key negotiation unit is used to send the device certificate of the edge device and the first key parameter for key negotiation to the cloud server when data is transmitted with the cloud server; the cloud server is used to authenticate the device certificate of the edge device, and if the authentication is successful, generate a first data key of the application layer according to the first key parameter and the preset private key of the cloud server, and return a second key parameter corresponding to the preset private key of the cloud server to the edge device; obtain the second key parameter returned by the cloud server, and generate a second data key of the application layer according to the second key parameter and the preset private key corresponding to the first key parameter; The encryption unit is used to encrypt the original data of the application layer according to the second data key to obtain encrypted data, and send the encrypted data to the cloud service end, instructing the cloud service end to decrypt the encrypted data according to the first data key.

12. A device for cloud-edge data transmission, characterized in that: Applied to a cloud server, the device comprises: The certificate issuing unit is used to obtain the certificate signing request initiated by the edge device; issue the corresponding device certificate according to the certificate signing request, and send the issued device certificate to the edge device; an acquiring unit, configured to acquire a device certificate of the edge device and a first key parameter for key negotiation sent by the edge device; A second key negotiation unit is configured to authenticate the device certificate of the edge device, and if the authentication is successful, generate a first data key of the application layer according to the first key parameter and the preset private key of the cloud server, and return a second key parameter corresponding to the preset private key of the cloud server to the edge device; A decryption unit is used to obtain the encrypted data sent by the edge device; the encrypted data is obtained by encrypting the original data of the application layer according to the second data key of the application layer, and the second data key is a key generated by the edge device according to the second key parameter and a preset private key corresponding to the first key parameter; the encrypted data is decrypted according to the first data key to obtain the original data.

13. A computer device, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the method for cloud-edge data transmission according to any one of claims 1 to 10 by executing the computer instructions.

14. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the cloud-edge data transmission method described in any one of claims 1 to 10.