Data transmission method, apparatus, device, storage medium, and program product
By deploying proxy services on both the intranet and the extranet for authentication and data transmission, the data security issues of traditional cloud customer service systems are resolved, enabling fast and secure extranet access and data transmission.
Patent Information
- Application Number
- CN202510281113.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-11
- Publication Date
- 2025-12-09
- Estimated Expiration
- 2045-03-11
AI Technical Summary
Traditional cloud customer service systems pose risks to data security and privacy leaks in enterprise applications, especially when accessed from the external network, where frequent network attacks lead to insecure data transmission.
An internal proxy service is deployed on the intranet, and an external proxy service is deployed on the extranet. A communication connection is established and an authentication request is made. After successful authentication, business data is transmitted, ensuring the security of data transmission.
It enables external network system operators to quickly access the enterprise's internal cloud customer service system while improving the data transmission security between the external and internal networks, meeting the enterprise's stringent security requirements.
Smart Images

Figure CN120151020B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of communication, and in particular to a data transmission method and device, equipment, storage medium and program product. BACKGROUND
[0002] The traditional cloud customer service system relies on external network access, allowing system operators to connect to the cloud customer service system through the Internet for customer service management and operation. This design has significant advantages in system operation and management, and can timely handle problems in the process of using the cloud customer service system by enterprises. However, in enterprise-level applications, especially in situations with high standards for data security and privacy, there are obvious security risks, such as data leakage risk, network attack, etc. SUMMARY
[0003] The present application provides a data transmission method, device, equipment, storage medium and program product, which can not only ensure that system operators in the external network can quickly access the cloud customer service system in the internal network, but also improve the security of data transmission between the external network and the internal network.
[0004] In a first aspect, the embodiments of the present application provide a data transmission method, comprising: establishing a communication connection between an internal proxy service and an external proxy service; wherein the internal proxy service is deployed in an internal network, and the external proxy service is deployed in an external network; the internal proxy service sends an identity authentication request to the external proxy service through the communication connection; the external proxy service verifies the identity authentication request and obtains a verification result; if the verification result is verified, the external proxy service and the internal proxy service transmit business data through the communication connection.
[0005] In a second aspect, the embodiments of the present application also provide a data transmission device, comprising: a communication connection establishing module for establishing a communication connection between an internal proxy service and an external proxy service; wherein the internal proxy service is deployed in an internal network, and the external proxy service is deployed in an external network; an identity authentication request sending module for the internal proxy service to send an identity authentication request to the external proxy service through the communication connection; an identity authentication request verifying module for the external proxy service to verify the identity authentication request and obtain a verification result; and a business data transmission module for transmitting business data between the external proxy service and the internal proxy service through the communication connection if the verification result is verified.
[0006] In a third aspect, an electronic device is provided, and the electronic device includes one or more processors; and a storage storing one or more programs, when the one or more programs are executed by the one or more processors, the one or more processors implement the data transmission method according to the embodiments of the present application.
[0007] In a fourth aspect, a storage medium containing computer executable instructions is provided, when the computer executable instructions are executed by a computer processor, the computer executable instructions are used to perform the data transmission method according to the embodiments of the present application.
[0008] In a fifth aspect, a computer program product is provided, and the computer program product includes a computer program, when the computer program is executed by a processor, the computer program implements the data transmission method according to the embodiments of the present application.
[0009] The technical scheme of the embodiments of the present application, the internal proxy service and the external proxy service establish a communication connection; wherein the internal proxy service is deployed in the intranet, and the external proxy service is deployed in the extranet; the internal proxy service sends an identity authentication request to the external proxy service through the communication connection; the external proxy service verifies the identity authentication request and obtains a verification result; if the verification result is verified, the external proxy service and the internal proxy service transmit business data through the communication connection. The embodiments of the present application can not only ensure that the system operators in the extranet can quickly access the cloud customer service system in the intranet, but also improve the data transmission security between the extranet and the intranet by deploying the internal proxy service in the intranet, deploying the external proxy service in the extranet, and transmitting business data through the communication connection after the identity authentication request. BRIEF DESCRIPTION OF DRAWINGS
[0010] The above and other features, advantages, and aspects of the embodiments of the present application will become more apparent with reference to the following detailed description when taken in conjunction with the accompanying drawings. Throughout the drawings, the same or similar reference numerals are used to represent the same or similar elements. It should be understood that the drawings are schematic, and the original and elements are not necessarily drawn according to the scale.
[0011] Figure 1 A data transmission method flowchart provided by the embodiments of the present application;
[0012] Figure 2 A data transmission device structure schematic diagram provided by the embodiments of the present application;
[0013] Figure 3 A structure schematic diagram of an electronic device provided by the embodiments of the present application. DETAILED DESCRIPTION
[0014] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. While certain embodiments of the present disclosure are shown in the drawings, it is understood that the present disclosure can be embodied in various forms and should not be interpreted in a limited sense as set forth in the embodiments set forth herein, but rather, the embodiments are provided to more thoroughly and completely understand the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are only for exemplary purposes and are not intended to limit the scope of protection of the present disclosure.
[0015] It should be understood that each step described in the method embodiments of the present disclosure can be performed in different order and / or in parallel. In addition, the method embodiments can include additional steps and / or omit the steps shown. The scope of the present disclosure is not limited in this respect. The term "comprising" and its variants used herein are open-ended, i.e., "including but not limited to". It should be noted that the concepts of "first", "second", etc. mentioned in the present disclosure are only used to distinguish different devices, modules or units, and are not intended to limit the order or interdependence of the functions performed by these devices, modules or units. It should be noted that the modification of "one" or "multiple" mentioned in the present disclosure is illustrative and not limiting, and those skilled in the art should understand that "one" or "multiple" should be understood as "one or more" unless the context clearly indicates otherwise. It can be understood that the data involved in the technical solution (including but not limited to the data itself, the acquisition or use of the data) should comply with the requirements of the relevant laws and regulations.
[0016] Figure 1 A data transmission method flowchart provided by an embodiment of the present application. The method can be performed by a data transmission device, which can be implemented in the form of software and / or hardware, and can be implemented by an electronic device such as a mobile terminal, a PC terminal or a server. As shown in Figure 1 the method comprises:
[0017] S110, an internal proxy service and an external proxy service establish a communication connection.
[0018] The internal proxy service (Inbound Proxy Service, IPS) is deployed in the intranet, and the external proxy service (Outbound Proxy Service, OPS) is deployed in the extranet.
[0019] The internal proxy service is deployed on an enterprise intranet server, and the external proxy service is deployed on a cloud server in the extranet.
[0020] The external proxy service is configured with a private key of the external proxy service (the private key and the public key of the external proxy service are generated in advance by a certificate tool), and listens for a connection request of the internal proxy service.
[0021] The internal agent service is configured with a private key of the internal agent service (the private key of the internal agent service and the public key of the internal agent service are generated in advance by a certificate tool).
[0022] In this embodiment, after being started, the internal agent service can initiate a connection request to a connection address corresponding to the external agent service, and the external agent service receives the connection request, so that the internal agent service and the external agent service establish a communication connection.
[0023] Optionally, the internal agent service and the external agent service establishing the communication connection comprises: the internal agent service sending a connection request to the external agent service; and the external agent service establishing the communication connection with the internal agent service based on the connection request.
[0024] In this embodiment, the communication protocol of the connection request is not limited, for example, the WebSocket protocol, that is, the communication connection between the internal agent service and the external agent service is a connection of the WebSocket protocol.
[0025] The external agent service opens a port of the WebSocket protocol to monitor the connection request of the internal agent service.
[0026] It should be noted that the internal agent service pre-stores the public key of the external agent service, so that the internal agent service encrypts the data to be sent to the external agent service by using the public key of the external agent service.
[0027] S120, the internal agent service sends an identity authentication request to the external agent service through the communication connection.
[0028] In this embodiment, the content of the identity authentication request is not limited, and the identity of the external agent service can be authenticated.
[0029] In this embodiment, the internal agent service sends an identity authentication request to the external agent service to authenticate the identity of the external agent service establishing the communication connection with the internal agent service, so as to ensure the security of the communication connection.
[0030] Optionally, before sending the identity authentication request to the external agent service through the communication connection, the internal agent service further comprises: obtaining request data; encrypting the request data based on the generated first random key and the set encryption mode to obtain request encrypted data; encrypting the first random key based on the public key of the external agent service to generate a first random encrypted key; and composing the request encrypted data and the first random encrypted key into the identity authentication request.
[0031] In this embodiment, the internal proxy service acquires a timestamp corresponding to the current time as a request timestamp, combines the request timestamp and a public key of the internal proxy service, and combines the request unique identifier to form request data.
[0032] In this embodiment, a random key can be generated by using any symmetric encryption algorithm, such as the SMS4 algorithm, which can be denoted as a first random key. The request data is encrypted in a set encryption mode (such as the SM4_ECB mode) to obtain request encrypted data. The first random key can be encrypted by using the public key of the external proxy service through an asymmetric encryption algorithm (such as the SM2 algorithm) to generate a first random encrypted key. The request encrypted data and the first random encrypted key are combined with the identity verification request name to form an identity verification request.
[0033] In this embodiment, the security of the identity verification request can be improved by encrypting the request data and the first random key used for encrypting the request data.
[0034] S130, the external proxy service verifies the identity verification request to obtain a verification result.
[0035] In this embodiment, the first random encrypted key in the identity verification request is first decrypted to obtain the first random key, and then the request encrypted data in the identity verification request is decrypted by using the first random key to obtain the request data. The request timestamp in the request data is compared with a current timestamp corresponding to the current time of the external proxy service, so that the identity verification request is verified.
[0036] Optionally, the external proxy service verifies the identity verification request to obtain a verification result, including: decrypting the first random encrypted key based on a private key of the external proxy service to obtain the first random key; decrypting the request encrypted data based on the first random key to obtain the request data; and determining the verification result based on the request timestamp and the current timestamp.
[0037] The request data includes the request timestamp.
[0038] In this embodiment, the external proxy service can decrypt the first random encrypted key by using the private key of the external proxy service through an asymmetric encryption algorithm (such as the SM2 algorithm) to obtain the first random key. The request data is decrypted in a set encryption mode (such as the SM4_ECB mode) by using the first random key to obtain the request data. The request timestamp is compared with a current timestamp corresponding to the current time of the external proxy service, and the verification result is obtained according to the difference between the two timestamps.
[0039] In the embodiment, the first random encryption key is decrypted by the private key of the external proxy service, and the first random key obtained by decryption is used to decrypt the request encryption data. Only the private key of the external proxy service corresponding to the public key of the external proxy service can successfully decrypt the first random encryption key, so that the request encryption data can be decrypted, and the security of the identity verification request is improved.
[0040] Optionally, the verification result is determined based on the request timestamp and the current timestamp, including: if the difference between the current timestamp and the request timestamp is greater than a set threshold, the verification result is that the verification fails; and if the difference between the current timestamp and the request timestamp is less than or equal to the set threshold, the verification result is that the verification passes.
[0041] In the embodiment, the set threshold is not limited, for example, it can be 10 seconds. In the embodiment, if the difference between the current timestamp corresponding to the current time of the external proxy service and the request timestamp is greater than the set threshold, it can be considered that the verification fails, and if the difference between the current timestamp and the request timestamp is less than or equal to the set threshold, it can be considered that the verification passes.
[0042] In the embodiment, the difference between the current timestamp and the request timestamp is compared with the set threshold to determine the verification result, which effectively realizes the verification of the identity verification request.
[0043] In S140, if the verification result is that the verification passes, the external proxy service and the internal proxy service perform transmission of business data through the communication connection.
[0044] In the embodiment, if the verification result of the identity verification request is that the verification passes, the communication connection between the external proxy service and the internal proxy service can be normally used, thereby improving the security of the transmission of business data between the external proxy service and the internal proxy service. In the embodiment, if the verification result is that the verification fails, the external proxy service actively gives up the communication connection with the external proxy service.
[0045] In the embodiment, the communication connection between the external proxy service and the internal proxy service through encryption can establish a stable and secure long connection, thereby improving the security of the transmission of business data between the external proxy service and the internal proxy service.
[0046] Optionally, the external proxy service and the internal proxy service transmit the business data through the communication connection, including: the external proxy service, obtaining the business request data; encapsulating the business request data based on the public key of the internal proxy service to obtain a business application request; sending the business application request to the internal proxy service through the communication connection; the internal proxy service, based on the private key of the internal proxy service, decapsulating the business application request to obtain the business request data; determining the response data corresponding to the business request data; encapsulating the response data based on the public key of the external proxy service to form a business response result; sending the business response result to the external proxy service through the communication connection.
[0047] The request data further includes the public key of the internal proxy service.
[0048] The business data includes the business application request and the business response result.
[0049] Exemplarily, the system operator sends the business request data to the external proxy service through the browser (the browser of the cloud customer service system to the outside), which can be a HyperText Transfer Protocol Secure POST Request (HTTPS POST). The external proxy service receives the business request data sent by the browser, and encapsulates the business request data based on the public key of the internal proxy service to obtain a business application request.
[0050] In this embodiment, the encapsulation of the business request data is similar to the encryption of the identity verification request. Exemplarily, any symmetric encryption algorithm can be used to generate a random key, such as an SMS4 algorithm. The random key can be denoted as a second random key. The business request data is encrypted based on the generated second random key and a set encryption mode to obtain business request encryption data. The second random key is encrypted based on the public key of the internal proxy service to generate a second random encryption key. The business request encryption data and the second random encryption key are combined to form the business application request. The business application request is sent to the internal proxy service through the communication connection.
[0051] In this embodiment, the internal proxy service, based on the private key of the internal proxy service, unpacks the business application request in a manner similar to the manner of decrypting the identity verification request. For example, the internal proxy service, based on the private key of the internal proxy service, decrypts the second random encryption key in the business application request to obtain the second random key; and based on the second random key, decrypts the business request encryption data in the business application request to obtain the business request data. The internal proxy service forwards the business request data to the cloud customer service system (a private cloud customer service system in an enterprise). After the cloud customer service system processes and returns the response data (an HTTPS response) corresponding to the business request data, the response data is encapsulated.
[0052] In this embodiment, the manner of encapsulating the response data is similar to the manner of encrypting the identity verification request. For example, a random key can be generated by using any symmetric encryption algorithm, such as the SMS4 algorithm. The random key can be denoted as a third random key. Based on the generated third random key and a set encryption mode, the response data is encrypted to obtain response encryption data. Based on the public key of the external proxy service, the third random key is encrypted to generate a third random encryption key. The response encryption data and the third random encryption key are combined to form a business response result. The business response result is sent to the external proxy service through a communication connection.
[0053] In this embodiment, the manner of unpacking the business response result is similar to the manner of decrypting the identity verification request. For example, the external proxy service, based on the private key of the external proxy service, decrypts the third random encryption key in the business response result to obtain the third random key; and based on the third random key, decrypts the response encryption data in the business response result to obtain the response data. The external proxy service returns the response data to the browser of the system operator and renders a page to display the result. In this embodiment, the content in the response data is not limited. For example, the response data can include a response status identifier (responseCode) and specific information (responseMessage). When the response status identifier is a set value, such as 200, it can be considered that the processing is successful, and the responseMessage is the specific response data. Otherwise, the responseMessage is the description information of the failure.
[0054] The technical scheme of the embodiment of the application is that the internal proxy service and the external proxy service establish a communication connection; the internal proxy service is deployed in an intranet, and the external proxy service is deployed in an extranet; the internal proxy service sends an identity authentication request to the external proxy service through the communication connection; the external proxy service verifies the identity authentication request and obtains a verification result; if the verification result is that the verification is passed, the external proxy service and the internal proxy service perform transmission of business data through the communication connection. According to the embodiment of the disclosure, the internal proxy service is deployed in the intranet, the external proxy service is deployed in the extranet, and the transmission of business data is performed through the communication connection after the identity authentication request, so that not only can system operators in the extranet quickly access the cloud customer service system in the intranet, but also the security of data transmission between the extranet and the intranet can be improved.
[0055] It should be noted that the business application request of all browsers and the business response result of the cloud customer service system are transmitted through the communication connection established by the internal proxy service and the external proxy service, so that the security requirement of the enterprise can be met.
[0056] The technical scheme provided in the embodiment can enable the enterprise to deploy and use the cloud customer service system under strict security requirements without changing the existing network security policy. By deploying the external proxy service in the extranet and the internal proxy service in the intranet, the proxy mechanism ensures the security of data transmission and the availability of the private cloud customer service system. The technical scheme provided in the embodiment of the application ensures that system operators can remotely and quickly use the cloud customer service system while ensuring efficient and secure service level. The technical scheme provided in the embodiment is easy to implement and maintain, and provides an enterprise with a low-cost and high-benefit solution to improve customer service experience.
[0057] Figure 2 A structural schematic diagram of a data transmission device provided in the embodiment of the application is shown in Figure 2 The device includes a communication connection establishing module 210, an identity authentication request sending module 220, an identity authentication request verifying module 230, and a business data transmission module 240.
[0058] The communication connection establishing module 210 is configured to establish a communication connection between the internal proxy service and the external proxy service; the internal proxy service is deployed in an intranet, and the external proxy service is deployed in an extranet.
[0059] The identity authentication request sending module 220 is configured to send an identity authentication request to the external proxy service by the internal proxy service through the communication connection.
[0060] The identity authentication request verifying module 230 is configured to verify the identity authentication request by the external proxy service and obtain a verification result.
[0061] The business data transmission module 240 is configured to, if the verification result is a verification pass, transmit business data between the external proxy service and the internal proxy service through the communication connection.
[0062] The technical scheme of the embodiment of the application comprises the following steps: establishing a communication connection between an internal proxy service and an external proxy service by a communication connection establishing module; wherein the internal proxy service is deployed in an intranet, and the external proxy service is deployed in an extranet; sending an identity verification request from the internal proxy service to the external proxy service through the communication connection by an identity verification request sending module; verifying the identity verification request by the external proxy service to obtain a verification result by an identity verification request verifying module; and transmitting business data between the external proxy service and the internal proxy service through the communication connection if the verification result is a verification pass by a business data transmission module. According to the embodiment of the disclosure, the internal proxy service is deployed in the intranet, the external proxy service is deployed in the extranet, and the business data is transmitted through the communication connection after the identity verification request. In this way, not only can the system operator in the extranet quickly access the cloud customer service system in the intranet, but also the data transmission security between the extranet and the intranet can be improved.
[0063] Optionally, the communication connection establishing module is specifically configured to: send a connection request from the internal proxy service to the external proxy service; and establish the communication connection between the internal proxy service and the external proxy service based on the connection request.
[0064] Optionally, the device further comprises an encryption module, which is specifically configured to: acquire request data by the internal proxy service; encrypt the request data based on the generated first random key and a set encryption mode to obtain request encrypted data; encrypt the first random key based on the public key of the external proxy service to generate a first random encrypted key; and compose the request encrypted data and the first random encrypted key into an identity verification request.
[0065] Optionally, the identity verification request verifying module is specifically configured to: decrypt the first random encrypted key based on the private key of the external proxy service to obtain the first random key; decrypt the request encrypted data based on the first random key to obtain the request data; wherein the request data comprises a request timestamp; and determine a verification result based on the request timestamp and a current timestamp.
[0066] Optionally, the identity authentication request verification module is further configured to: if a difference between the current timestamp and the request timestamp is greater than a set threshold, the verification result is verification failure; and if the difference between the current timestamp and the request timestamp is less than or equal to the set threshold, the verification result is verification success.
[0067] The request data further includes a public key of the internal proxy service, and the business data includes a business application request and a business response result.
[0068] Optionally, the business data transmission module is specifically configured to: the external proxy service, acquire business request data; encapsulate the business request data based on the public key of the internal proxy service to obtain a business application request; and send the business application request to the internal proxy service through the communication connection; the internal proxy service, based on the private key of the internal proxy service, decapsulate the business application request to obtain the business request data; determine response data corresponding to the business request data; encapsulate the response data based on the public key of the external proxy service to form a business response result; and send the business response result to the external proxy service through the communication connection.
[0069] The data transmission apparatus provided by the embodiments of the present application can execute the data transmission method provided by any of the embodiments of the present application, and has the corresponding function modules and beneficial effects of executing the method.
[0070] Figure 3 A structural schematic diagram of an electronic device 10 that can be used to implement embodiments of the present application is shown. The electronic device is intended to represent various forms of digital computers, such as laptops, desktops, tablets, personal digital assistants, servers, blade servers, mainframes, and other appropriate computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular telephones, smart phones, wearable devices (e.g., headsets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions, are meant to be examples only, and are not intended to limit the implementations of the present application described and / or claimed in this document.
[0071] As Figure 3As shown, the electronic device 10 includes at least one processor 11, and a memory, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., communicatively connected to the at least one processor 11, where the memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer programs stored in the read-only memory (ROM) 12 or loaded into the random access memory (RAM) 13 from the storage unit 18. Various programs and data required for the operation of the electronic device 10 can also be stored in the random access memory (RAM) 13. The processor 11, the read-only memory (ROM) 12, and the random access memory (RAM) 13 are connected to each other through a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0072] Various components in the electronic device 10 are connected to the input / output (I / O) interface 15, including an input unit 16, such as a keyboard, a mouse, etc., an output unit 17, such as various types of displays, a speaker, etc., a storage unit 18, such as a magnetic disk, an optical disk, etc., and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network, such as the Internet, and / or various telecommunication networks.
[0073] The processor 11 can be various general and / or special purpose processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 performs various methods and processes described above, such as the method data transmission.
[0074] In some embodiments, the method data transmission can be implemented as a computer program tangibly embodied in a computer readable storage medium, such as the storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 10 via the read-only memory (ROM) 12 and / or the communication unit 19. When the computer program is loaded into the random access memory (RAM) 13 and executed by the processor 11, one or more steps of the method data transmission described above can be performed. Alternatively, in other embodiments, the processor 11 can be configured to perform the method data transmission by any other appropriate means, such as by means of firmware.
[0075] The various embodiments of the systems and techniques described above can be implemented in digital electronic circuitry, integrated circuitry, a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on a chip (SOC), a load programmable logic device (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include implementation in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be special or general purpose, coupled to receive data and instructions from, and to transmit data and instructions to, a storage system, at least one input device, and at least one output device.
[0076] Computer programs used to implement the processes of the present application can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus, such that the computer program
[0077] In the context of the present application, a computer-readable storage medium can be a tangible medium that can contain or store computer programs for use by or in connection with an instruction execution system, apparatus, or device. Computer-readable storage media can include, but are not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium will include one or more lines of a program of instructions in a transitory signal, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0078] To provide for interaction with a user, the systems and techniques described here can be implemented on an electronic device having a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can be used to provide for interaction with a user as well; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form, including acoustic, speech, or tactile input.
[0079] The systems and techniques described here can be implemented in a computing system that includes a back end component (e.g., as a data server), or that includes a middleware component (e.g., an application server), or that includes a front end component (e.g., a user computer having a graphical user interface or a Web browser through which a user can interact with an implementation of the systems and techniques described here), or any combination of such back end, middleware, or front end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0080] The computing system can include clients and servers. A client and server are generally remote from each other and typically interact through a communication network. The relationship of client and server arises by virtue of computer programs running on the respective computers and having a client-server relationship to each other. A server can be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system, to solve the defects of large management difficulty and weak business scalability in traditional physical host and VPS service.
[0081] The embodiments of the present application further provide a computer program product, comprising a computer program which, when executed by a processor, implements the data transmission method provided by any of the embodiments of the present application.
[0082] Computer program product, in the implementation of the process, can be written in one or more programming languages or combinations thereof for computer program code for performing the operations of the present application, programming language includes object-oriented programming language, such as Java, Smalltalk, C++, also includes conventional procedural programming language, such as "C" language or similar programming language. Program code can be completely executed on a user computer, partially executed on a user computer, as an independent software package, partially on a user computer and partially on a remote computer, or completely on a remote computer or server. In the case of remote computer, the remote computer can be connected to the user computer through any kind of network, including local area network (LAN) or wide area network (WAN), or can be connected to an external computer (for example, using an Internet service provider to connect through the Internet).
[0083] It should be noted that the above only the preferred embodiments of the present application and the principles of the technology used. Those skilled in the art will understand that the present application is not limited to the specific embodiments herein, those skilled in the art can make various obvious changes, re-adjustment and replacement without departing from the scope of the present application. Therefore, although the above embodiments of the present application are described in more detail, the present application is not limited to the above embodiments, without departing from the concept of the present application, can also include more other equivalent embodiments, and the scope of the present application is determined by the scope of the appended claims.
Claims
1. A data transmission method, characterized in that, include: The internal proxy service sends a connection request to the external proxy service; The external proxy service establishes a communication connection with the internal proxy service based on the connection request; wherein the internal proxy service is deployed on an enterprise intranet server, and the external proxy service is deployed on an external cloud server; A first random key is generated based on the SM4 symmetric encryption algorithm, and the request data is encrypted using the SM4_ECB encryption mode to obtain encrypted request data; the first random key is encrypted using the SM2 asymmetric encryption algorithm with the public key of the external proxy service to generate a first random encryption key; the encrypted request data and the first random encryption key are combined with the authentication request name to form an authentication request; The internal proxy service sends the authentication request to the external proxy service through the communication connection; Based on the private key of the external proxy service, the first random encryption key is decrypted to obtain the first random key; The request encrypted data is decrypted based on the first random key to obtain the request data; wherein, the request data includes a request timestamp; Determining the verification result based on the request timestamp and the current timestamp includes: if the difference between the current timestamp and the request timestamp is greater than a set threshold, the verification result is verification failed; if the difference between the current timestamp and the request timestamp is less than or equal to the set threshold, the verification result is verification passed. If the verification result is successful, the external proxy service and the internal proxy service will transmit business data through the communication connection. The request data further includes the public key of the internal proxy service; the business data includes business application requests and business response results; the external proxy service and the internal proxy service transmit business data through the communication connection, including: The external proxy service obtains business request data; The business request data is encapsulated based on the public key of the internal proxy service to obtain the business application request; The service application request is sent to the internal proxy service via the communication connection. The internal proxy service, based on its private key, decapsulates the business application request to obtain the business request data. Determine the response data corresponding to the business request data; The response data is encapsulated using the public key of the external proxy service to form a business response result; The service response result is sent to the external proxy service through the communication connection.
2. A data transmission device, characterized in that, include: A communication connection establishment module is used for the internal proxy service to send a connection request to the external proxy service; the external proxy service establishes the communication connection with the internal proxy service based on the connection request; wherein, the internal proxy service is deployed on an enterprise intranet server, and the external proxy service is deployed on an external cloud server; An authentication request sending module is used by the internal proxy service to send authentication requests to the external proxy service through the communication connection; The authentication request sending module is specifically used to generate a first random key based on the SM4 symmetric encryption algorithm, and encrypt the request data using the SM4_ECB encryption mode to obtain encrypted request data; encrypt the first random key using the public key of the external proxy service through the SM2 asymmetric encryption algorithm to generate a first random encryption key; and combine the encrypted request data and the first random encryption key with the authentication request name to form the authentication request. An authentication request verification module is used to decrypt the first random encryption key based on the private key of the external proxy service to obtain a first random key; decrypt the request encrypted data based on the first random key to obtain the request data; wherein, the request data includes a request timestamp; and determine the verification result based on the request timestamp and the current timestamp. The identity verification request verification module is specifically configured to determine the verification result as verification failure if the difference between the current timestamp and the request timestamp is greater than a set threshold, and verification success if the difference between the current timestamp and the request timestamp is less than or equal to the set threshold. The business data transmission module is used to transmit business data between the external proxy service and the internal proxy service through the communication connection if the verification result is successful; wherein the request data further includes the public key of the internal proxy service; wherein the business data includes a business application request and a business response result; The business data transmission module is specifically used by the external proxy service to obtain business request data; encapsulate the business request data based on the public key of the internal proxy service to obtain a business application request; and send the business application request to the internal proxy service through the communication connection. The internal proxy service, based on its private key, decapsulates the business application request to obtain business request data; determines the response data corresponding to the business request data; encapsulates the response data based on the public key of the external proxy service to form a business response result; and sends the business response result to the external proxy service through the communication connection.
3. An electronic device, characterized in that, The electronic device includes: One or more processors; Storage device for storing one or more programs. When the one or more programs are executed by the one or more processors, the one or more processors implement the data transmission method as described in claim 1.
4. A storage medium containing computer-executable instructions, which, when executed by a computer processor, are used to perform the data transmission method as described in claim 1.
5. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the data transmission method as described in claim 1.
Citation Information
Patent Citations
Bidirectional transparent transmission technology based on security isolation gateway
CN110351233A