Data processing method and device, electronic equipment and storage medium
By establishing a data link between electronic devices for voice calls and using the keys generated by itself to decrypt and encrypt data, the problem of voice data leakage caused by attacks on the server is solved, and the data security of voice calls is improved.
Patent Information
- Application Number
- CN202510367985.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-26
- Publication Date
- 2025-06-13
AI Technical Summary
During voice calls, since the server saves the decryption key, if the server is attacked or the decryption key is attacked during the transmission, it may lead to voice data leakage.
By establishing a data link between the first electronic device and the second electronic device, the first electronic device receives the encrypted data forwarded by the server and decrypts it based on the key generated by itself, or the second electronic device generates a key and sends it to the first electronic device through a call link, thereby avoiding the risk of the server transmitting the key.
Improves voice data security during voice calls, preventing attackers from obtaining decryption keys and leaking voice data.
Smart Images

Figure CN120151831A_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of communication technologies, and particularly relates to a data processing method, apparatus, electronic device, and storage medium. Background Art
[0002] With the continuous development of electronic devices, using electronic devices for voice calls has become increasingly common. Currently, users can use electronic devices such as mobile phones to make voice calls through the operator network.
[0003] During a call, problems such as unclear voice calls and call drops may occur due to poor signal quality. Therefore, when the electronic devices of both call parties are simultaneously connected to the data network, the electronic devices of both call parties can establish a data link through the server. Then, the sending device can encrypt the voice data of the call using the encryption key in the key pair allocated by the server, and then use the data link to redundantly backup and transmit the encrypted voice data. After receiving the encrypted voice data, the receiving device can decrypt the encrypted voice data using the decryption key in the key pair allocated by the server, thereby realizing the voice call between the two call parties.
[0004] However, since the server stores the decryption key, if the server is attacked or hijacked by an attacker during the process of transmitting the decryption key by the server, the attacker may obtain the decryption key, decrypt the encrypted voice data using the decryption key, and then obtain the user's voice data, resulting in the leakage of voice data. Summary of the Invention
[0005] The objective of the embodiments of this application is to provide a data processing method, apparatus, electronic device, and storage medium, which can improve the security of voice data during a call.
[0006] In a first aspect, the embodiments of this application provide a data processing method, which is executed by a first electronic device. The method includes:
[0007] During a voice call with a second electronic device, the first electronic device receives first encrypted data forwarded by a server through a first link. The first encrypted data is generated by the second electronic device encrypting voice data using a first key. The first link is a data link established by the first electronic device and the second electronic device through the server;
[0008] The first electronic device obtains voice data based on a second key in the first electronic device and the first encrypted data;
[0009] Among them, the second key is generated by the first electronic device; or, the second key is generated by the second electronic device; in the case where the second key is generated by the second electronic device, the second key is sent by the second electronic device to the first electronic device through the second link, and the second link is the call link between the first electronic device and the second electronic device.
[0010] In a second aspect, an embodiment of the present application provides a data processing method, which is executed by a second electronic device. The method includes:
[0011] During a voice call with the first electronic device, the second electronic device sends the identification information of the first electronic device to the server;
[0012] The second electronic device receives the first key sent by the server based on the identification information of the first electronic device and the first association relationship, where the first association relationship is the association relationship between the identification information of the first electronic device and the first key;
[0013] The second electronic device encrypts the voice data using the first key to generate first encrypted data;
[0014] The second electronic device sends the first encrypted data to the server through the first link, where the first link is the data link established between the first electronic device and the second electronic device through the server.
[0015] In a third aspect, an embodiment of the present application provides a data processing method, which is executed by a second electronic device. The method includes:
[0016] During a voice call with the first electronic device, the second electronic device sends the identification information of the first electronic device to the server;
[0017] The second electronic device receives the third key sent by the server based on the identification information of the first electronic device and the second association relationship, where the second association relationship is the association relationship between the identification information of the first electronic device and the third key;
[0018] The second electronic device encrypts the first key using the third key to generate second encrypted data;
[0019] The second electronic device transmits the second encrypted data to the first electronic device through the second link, where the second link is the call link between the first electronic device and the second electronic device.
[0020] In a fourth aspect, an embodiment of the present application provides a data processing device, and the device includes:
[0021] A transceiver module, configured to receive, during a voice call with a second electronic device, first encrypted data forwarded by a server through a first link, where the first encrypted data is generated by encrypting voice data using a first key by the second electronic device, and the first link is a data link established between a first electronic device and the second electronic device through the server;
[0022] A processing module, configured to obtain voice data based on a second key in the first electronic device and the first encrypted data received by the transceiver module;
[0023] Wherein, the second key is generated by the first electronic device; or, the second key is generated by the second electronic device; in the case where the second key is generated by the second electronic device, the second key is sent by the second electronic device to the first electronic device through a second link, and the second link is a call link between the first electronic device and the second electronic device.
[0024] In a fifth aspect, an embodiment of the present application provides a data processing device, and the device includes:
[0025] A sending module, configured to send identification information of the first electronic device to a server during a voice call with the first electronic device;
[0026] A receiving module, configured to receive a first key sent by the server based on the identification information of the first electronic device sent by the sending module and a first association relationship, where the first association relationship is an association relationship between the identification information of the first electronic device and the first key;
[0027] A processing module, configured to encrypt voice data using the first key received by the receiving module to generate first encrypted data;
[0028] The sending module is further configured to send the first encrypted data generated by the processing module to the server through the first link, where the first link is a data link established between the first electronic device and the second electronic device through the server.
[0029] In a sixth aspect, an embodiment of the present application provides a data processing device, and the device includes:
[0030] A sending module, configured to send identification information of the first electronic device to a server during a voice call with the first electronic device;
[0031] A receiving module, configured to receive a third key sent by the server based on the identification information of the first electronic device sent by the sending module and a second association relationship, where the second association relationship is an association relationship between the identification information of the first electronic device and the third key;
[0032] A processing module, configured to encrypt the first key using the third key to generate second encrypted data;
[0033] The sending module is further configured to transmit, via a second link, the second encrypted data generated by the processing module to the first electronic device, where the second link is a call link between the first electronic device and the second electronic device.
[0034] In a seventh aspect, an embodiment of the present application provides an electronic device, which includes a processor and a memory. The memory stores a program or instructions that can run on the processor. When the program or instructions are executed by the processor, the steps of the data processing method described in the first aspect, or the steps of the data processing method described in the second aspect, or the steps of the data processing method described in the second aspect are implemented.
[0035] In an eighth aspect, an embodiment of the present application provides a readable storage medium, on which a program or instructions are stored. When the program or instructions are executed by a processor, the steps of the data processing method described in the first aspect, or the steps of the data processing method described in the second aspect, or the steps of the data processing method described in the second aspect are implemented.
[0036] In a ninth aspect, an embodiment of the present application provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor, and the processor is configured to run a program or instructions to implement the steps of the data processing method described in the first aspect, or the steps of the data processing method described in the second aspect, or the steps of the data processing method described in the second aspect.
[0037] In a tenth aspect, an embodiment of the present application provides a computer program product, which is stored in a storage medium and is executed by at least one processor to implement the data processing method described in the first aspect, or the data processing method described in the second aspect, or the data processing method described in the second aspect.
[0038] In the embodiments of the present application, during a voice call with a second electronic device, a first electronic device receives first encrypted data forwarded by a server through a first link. The first encrypted data is generated after the second electronic device encrypts voice data using a first key. The first link is a data link established between the first electronic device and the second electronic device through the server. The first electronic device obtains the voice data based on a second key in the first electronic device and the first encrypted data, where the second key is generated by the first electronic device; or, the second key is generated by the second electronic device. In the case where the second key is generated by the second electronic device, the second key is sent by the second electronic device to the first electronic device through a second link, and the second link is a call link between the first electronic device and the second electronic device. Thus, since the second key is generated by the first electronic device or sent by the second electronic device to the first electronic device through the second link, even if the server is attacked by an attacker, the attacker cannot obtain the second key, let alone decrypt the first encrypted data based on the second key to obtain the voice data, thereby improving the security of the voice data during the voice call. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] Figure 1 is a schematic flowchart of a data processing method provided by some embodiments of the present application;
[0040] Figure 2 is a schematic flowchart of a data processing method provided by some embodiments of the present application;
[0041] Figure 3 is a schematic flowchart of a data processing method provided by some embodiments of the present application;
[0042] Figure 4 is a schematic flowchart of a data processing method provided by some embodiments of the present application;
[0043] Figure 5 is a schematic flowchart of a data processing method provided by some embodiments of the present application;
[0044] Figure 6 is a schematic flowchart of a data processing method provided by some embodiments of the present application;
[0045] Figure 7 is a schematic flowchart of a data processing method provided by some embodiments of the present application;
[0046] Figure 8 is a schematic flowchart of a data processing method provided by some embodiments of the present application;
[0047] Figure 9 is a schematic flowchart of a data processing method provided by some embodiments of the present application;
[0048] Figure 10 It is a schematic diagram of a data processing method provided by some embodiments of the present application;
[0049] Figure 11 It is a flowchart of a data processing method provided by some embodiments of the present application;
[0050] Figure 12 It is a schematic diagram of a data processing method provided by some embodiments of the present application;
[0051] Figure 13 It is a flowchart of a data processing method provided by some embodiments of the present application;
[0052] Figure 14 It is a schematic diagram of a data processing method provided by some embodiments of the present application;
[0053] Figure 15 It is a schematic diagram of the structure of a data processing device provided by some embodiments of the present application;
[0054] Figure 16 It is a schematic diagram of the structure of a data processing device provided by some embodiments of the present application;
[0055] Figure 17 It is a schematic diagram of the structure of a data processing device provided by some embodiments of the present application;
[0056] Figure 18 It is a schematic diagram of the structure of an electronic device provided by some embodiments of the present application;
[0057] Figure 19 It is a schematic diagram of the hardware structure of an electronic device provided by some embodiments of the present application. Detailed implementation manners
[0058] Next, the technical solutions in the embodiments of the present application will be clearly described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are some, rather than all, of the embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application belong to the scope of protection of the present application.
[0059] The terms "first", "second", etc. in the description and claims of this application are used to distinguish similar objects, rather than to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of this application can be implemented in an order other than those illustrated or described here, and the objects distinguished by "first", "second", etc. are usually of the same category, and do not limit the number of objects. For example, the first object can be one or multiple. In addition, "and / or" in the description and claims means at least one of the connected objects. The character " / ", generally represents an "or" relationship between the associated objects before and after.
[0060] The terms "at least one (item)", "at least one of", etc. in the description and claims of this application refer to any one, any two or more combinations of the objects it contains. For example, at least one (item) of a, b, and c can represent: "a", "b", "c", "a and b", "a and c", "b and c", and "a, b, and c", where a, b, and c can be single or multiple. Similarly, "at least two (items)" means two or more, and its meaning is similar to that of "at least one (item)".
[0061] Key: A tool used for encrypting and decrypting data. According to whether the encryption key and the decryption key used in the cryptographic algorithm are the same and whether the decryption process can be deduced from the encryption process, the key can be divided into a symmetric key and an asymmetric key.
[0062] Identifier: Words, symbols, images, etc. used to indicate information, which can use controls or other containers as the carrier for displaying information, including but not limited to text identifiers, symbol identifiers, and image identifiers.
[0063] The data processing method, device, electronic device, and storage medium provided by the embodiments of this application will be described in detail below with reference to the accompanying drawings through specific embodiments and their application scenarios.
[0064] The data processing method provided by the embodiments of this application can be applied to the scenario of voice calls. For example, in Scenario 1, in the scenario where two users make a phone call using a mobile phone, in order to improve the security of the voice data of both parties during the call, it is necessary to encrypt and transmit the voice data of both parties. In Scenario 2, in the scenario where two users make a voice call through an instant messaging program, in order to improve the security of the voice data of both parties during the call, it is necessary to encrypt and transmit the voice data of both parties. In Scenario 3, in the scenario where two users make a video call through an instant messaging program, in order to improve the security of the voice data of both parties during the call, it is necessary to encrypt and transmit the voice data of both parties.
[0065] The execution subject of the data processing method provided by the embodiments of the present application may be a data processing device. Exemplarily, the data processing device may be an electronic device, or a functional component or functional entity in the electronic device. Hereinafter, taking the execution subject as an electronic device as an example, the data processing device provided by the embodiments of the present application will be described exemplarily.
[0066] Figure 1 is a schematic flowchart of the data processing method provided by the embodiments of the present application. As Figure 1 shown, the data processing method provided by the embodiments of the present application may include the following steps 101 and 102.
[0067] Step 101: During a voice call with a second electronic device, a first electronic device receives first encrypted data forwarded by a server through a first link.
[0068] In some embodiments of the present application, the first encrypted data is generated after the second electronic device encrypts voice data using a first key, and the first link is a data link established between the first electronic device and the second electronic device through the server.
[0069] For example, in the scenario where user a and user b make a phone call using mobile phones, the mobile phone of user a can receive first encrypted data forwarded through a data link established between the mobile phone of user a and the mobile phone of user b through the server.
[0070] For example, in the scenario where user a and user b have a voice call through an instant messaging program, the electronic device of user a can receive first encrypted data forwarded through a data link established between the electronic device of user a and the electronic device of user b through the server.
[0071] For example, in the scenario where user a and user b have a video call through an instant messaging program, the electronic device of user b can receive first encrypted data forwarded through a data link established between the electronic device of user a and the electronic device of user b through the server.
[0072] In some embodiments of the present application, the voice data may be voice data generated after the first electronic device extracts audio features and performs voice spectrum encoding on the voice of the user's oral call recorded by the microphone.
[0073] For example, in the scenario where user a and user b make a phone call using mobile phones, if the voice of user a's oral call is "Hello", the voice data may be voice data generated after the mobile phone of user a extracts audio features and performs voice spectrum encoding on the voice of user a's oral call "Hello" recorded by the microphone.
[0074] For example, in a scenario where user a and user b have a voice call through an instant messaging program, and the voice of user a's oral call is "How have you been lately", the above voice data can be the voice data generated after the electronic device of user a encodes the audio features and voice spectrum of the voice of the user's oral call "How have you been lately" recorded by the microphone.
[0075] For example, in a scenario where user a and user b have a video call through an instant messaging program, and the voice of user b's oral call is "Goodbye", the above voice data can be the voice data generated after the electronic device of user b encodes the audio features and voice spectrum of the voice of the user's oral call "Goodbye" recorded by the microphone.
[0076] In some embodiments of the present application, the above first key is an encryption key.
[0077] In some embodiments of the present application, the above first key may include information such as the first key type, the first algorithm identifier, the first key data, the first key usage, the first key length, the first validity period, etc. of the above first key. Specifically, it can be determined according to actual needs, and no specific limitation is made here in this embodiment.
[0078] In some embodiments of the present application, the above first key type may be a symmetric key or a public key in an asymmetric key.
[0079] In some embodiments of the present application, when the above first key type is a symmetric key, the above first algorithm identifier may be the algorithm identifier of a symmetric encryption algorithm, such as the algorithm identifier of the Advanced Encryption Standard (AES) algorithm or the algorithm identifier of the Data Encryption Standard (DES) algorithm.
[0080] In some embodiments of the present application, when the above first key type is a symmetric key, the above first algorithm identifier may be the algorithm identifier of an asymmetric encryption algorithm, such as the algorithm identifier of the RSA asymmetric encryption algorithm or the algorithm identifier of Elliptic Curve Cryptography (ECC).
[0081] In some embodiments of the present application, when the above first key type is a symmetric key, the above first key data may be the key value of the symmetric key.
[0082] In some embodiments of the present application, when the above first key type is the public key in an asymmetric key, the above first key data may be the modulus of the asymmetric key and the exponent of the public key in the asymmetric key.
[0083] In some embodiments of the present application, the modulus of the above-mentioned asymmetric key may be the product of two prime numbers.
[0084] For example, the modulus of the above-mentioned asymmetric key may be 35, which is the product of 5 and 7.
[0085] For example, the modulus of the above-mentioned asymmetric key may be 33, which is the product of 3 and 11.
[0086] In some embodiments of the present application, the exponent of the public key in the asymmetric key may be a relatively small integer that is relatively prime to the modulus of the above-mentioned asymmetric key.
[0087] For example, if the modulus of the above-mentioned asymmetric key is 35, the exponent of the public key in the above-mentioned asymmetric key may be 34.
[0088] Another example, if the modulus of the above-mentioned asymmetric key is 33, the exponent of the public key in the above-mentioned asymmetric key may be 37.
[0089] In some embodiments of the present application, the above-mentioned first key usage is used to indicate that the above-mentioned first encryption key is used to encrypt data.
[0090] In some embodiments of the present application, when the above-mentioned first key type is a symmetric key, the above-mentioned first key length may be the key length of the symmetric key. For example, the above-mentioned first key length may be 256, which is the key length of the AES-256 key.
[0091] In some embodiments of the present application, when the above-mentioned first key type is the public key in the asymmetric key, the above-mentioned first key length may be the key length of the public key. For example, the above-mentioned first key length may be 2048 or 4096, which is the key length of the private key in the RSA key.
[0092] For example, the above-mentioned first key may include the public key in the symmetric key of the first key type, the key value of the AES algorithm, the algorithm identifier of the AES algorithm, and the key length 256, the key usage for encrypting data, and the key validity period of 36 hours.
[0093] For example, the above-mentioned first key may include the public key in the asymmetric key of the first key type, the modulus 35 of the asymmetric key, the exponent 34 of the public key in the asymmetric key, the algorithm identifier of the RSA algorithm, and the key length 2048, the key usage for encrypting data, and the key validity period of 24 hours.
[0094] In some embodiments of the present application, the above-mentioned first validity period is used to indicate the validity period of the above-mentioned first key. After exceeding the above-mentioned first validity period, the electronic device that generates the above-mentioned first key needs to update the above-mentioned first key.
[0095] In some embodiments of the present application, the above-mentioned first electronic device and the above-mentioned second electronic device may be the terminals of two users who need to make a voice call, and the two users may use the first electronic device and the second electronic device to make a voice call.
[0096] In some embodiments of the present application, the above-mentioned server may be the background server of the first application. When the first application is running on both the first electronic device and the second electronic device, the first electronic device may receive the first encrypted data forwarded by the background server through the first data link.
[0097] In some embodiments of the present application, the first encrypted data may be encrypted voice data obtained by encrypting the voice data with the first key.
[0098] For example, the first encrypted data may be encrypted voice data generated by encrypting the voice data with the key value of the symmetric key and the AES algorithm.
[0099] For example, the first encrypted data may be encrypted voice data generated by encrypting the voice data with the modulus and exponent of the asymmetric key and the ECC algorithm.
[0100] In some embodiments of the present application, the first application may include, but is not limited to, any one of the following: navigation applications, social software applications, shopping applications, video applications, photo album applications, music applications, etc. Specifically, it can be determined according to actual usage requirements, and the embodiments of the present application are not limited.
[0101] Step 102: The first electronic device obtains voice data based on the second key in the first electronic device and the first encrypted data.
[0102] In some embodiments of the present application, the second key is generated by the first electronic device; or, the second key is generated by the second electronic device.
[0103] In some embodiments of the present application, when the second key is generated by the second electronic device, the second key is sent by the second electronic device to the first electronic device through the second link, and the second link is the call link between the first electronic device and the second electronic device.
[0104] In some embodiments of the present application, when the first key and the second key are symmetric keys, or when the first key and the second key are respectively the public key and the private key of a key pair, the second key is the decryption key, and the first electronic device may use the second key to decrypt the first encrypted data to obtain the voice data.
[0105] In some embodiments of the present application, the above-mentioned second key may include information such as the second key type of the second key, the second algorithm identifier, the second key data, the second key usage, the second key length, the second validity period, etc., which can be specifically determined according to actual requirements and are not specifically limited here in this embodiment.
[0106] In some embodiments of the present application, when the above-mentioned first key and the above-mentioned second key are symmetric keys, the key information included in the above-mentioned second key except for the above-mentioned second key usage is similar to the key information included in the above-mentioned first key except for the above-mentioned first key usage. To avoid overlap, it will not be elaborated here in this embodiment.
[0107] In some embodiments of the present application, the above-mentioned second key type may be a symmetric key or an asymmetric key.
[0108] In some embodiments of the present application, when the above-mentioned second key type is the public key in the asymmetric key, the above-mentioned second key data may be the modulus and exponent of the asymmetric key.
[0109] In some embodiments of the present application, the modulus of the above-mentioned asymmetric key may be the product of two prime numbers.
[0110] For example, the modulus of the above-mentioned asymmetric key may be the product of 5 and 7, which is 35.
[0111] For example, the modulus of the above-mentioned asymmetric key may be the product of 3 and 11, which is 33.
[0112] In some embodiments of the present application, when the above-mentioned second key type is the public key in the asymmetric key, the exponent of the above-mentioned asymmetric key may be a relatively small integer that is relatively prime to the modulus of the above-mentioned asymmetric key.
[0113] For example, when the above-mentioned second key type is the public key in the asymmetric key, the exponent of the above-mentioned asymmetric key may be 34.
[0114] For example, when the above-mentioned second key type is the public key in the asymmetric key, the exponent of the above-mentioned asymmetric key may be 37.
[0115] In some embodiments of the present application, when the above-mentioned second key type is the private key in the asymmetric key, the above-mentioned second key data may be the modulus of the asymmetric key and the private key exponent in the asymmetric key.
[0116] In some embodiments of the present application, the private key exponent in the above-mentioned asymmetric key can be calculated from the exponent of the public key in the above-mentioned asymmetric key and the modulus of the above-mentioned asymmetric key through specific mathematical operations.
[0117] For example, if the modulus of the above asymmetric key is 35 and the exponent of the public key in the above asymmetric key can be 34, then the private key exponent in the above asymmetric key can be 69, which is the sum of the modulus 35 of the above asymmetric key and the exponent 34 of the public key in the above asymmetric key.
[0118] For example, if the modulus of the above asymmetric key is 33 and the exponent of the public key in the above asymmetric key can be 37, then the private key exponent in the above asymmetric key can be 1190, which is the product of the modulus 35 of the above asymmetric key and the exponent 34 of the public key in the above asymmetric key.
[0119] In some embodiments of the present application, when the above second key type is the public key in the asymmetric key, the above second key usage can be used to indicate that the above second encryption key is used to encrypt data.
[0120] In some embodiments of the present application, when the above second key type is the public key in the asymmetric key, the above second key usage can be used to indicate that the above second encryption key is used to decrypt data.
[0121] In some embodiments of the present application, when the above second key type is a symmetric key, the above second key length can be the key length of the symmetric key. For example, the above second key length can be 256, which is the key length of the AES-256 key.
[0122] In some embodiments of the present application, when the above second key type is an asymmetric key, the above second key length can be the key length of the asymmetric key. For example, the above second key length can be 2048 or 4096, which is the key length of the RSA key.
[0123] For example, the above second key may include the public key in the second key type symmetric key, the key value of the AES algorithm, the algorithm identifier of the AES algorithm, and the key length 256, the key usage for encrypting data, and the key validity period of 36 hours.
[0124] For example, the above second key may include the public key in the second key type asymmetric key, the modulus 35 of the asymmetric key, the exponent 34 of the public key in the asymmetric key, the algorithm identifier of the RSA algorithm, and the key length 2048, the key usage for encrypting data, and the key validity period of 24 hours.
[0125] For example, the above second key may include the private key in the second key type asymmetric key, the modulus 35 of the asymmetric key, the exponent 69 of the private key in the asymmetric key, the algorithm identifier of the RSA algorithm, and the key length 2048, the key usage for decrypting data, and the key validity period of 24 hours.
[0126] In the data processing method provided in the embodiments of the present application, during a voice call with a second electronic device, a first electronic device receives first encrypted data forwarded by a server through a first link. The first encrypted data is generated by the second electronic device after encrypting voice data using a first key. The first link is a data link established between the first electronic device and the second electronic device through the server. The first electronic device obtains the voice data based on a second key in the first electronic device and the first encrypted data, where the second key is generated by the first electronic device; or, the second key is generated by the second electronic device. When the second key is generated by the second electronic device, the second key is sent by the second electronic device to the first electronic device through a second link, and the second link is a call link between the first electronic device and the second electronic device. Thus, since the second key is generated by the first electronic device or sent by the second electronic device to the first electronic device through the second link, even if the server is attacked by an attacker, the attacker cannot obtain the second key, nor can the attacker decrypt the first encrypted data based on the second key to obtain the voice data, thereby improving the security of the voice data during the voice call. In addition, adopting the solution of the present application does not require the server to transmit the second key to the first electronic device, thereby effectively avoiding the problem that the second key is hijacked by an attacker during the transmission process from the server to the first electronic device, and further improving the security of the voice data during the voice call.
[0127] In some embodiments of the present application, when the first key and the second key are generated by the second electronic device, in combination with Figure 1 , as Figure 2 shown, before step 101 above, the data processing method provided in the embodiments of the present application may further include the following step 103a and the following step 103b:
[0128] Step 103a: The first electronic device receives the second key sent by the second electronic device through the second link.
[0129] In some embodiments of the present application, the first electronic device may receive the second key sent by the second electronic device through the second link when a call connection is established between the first electronic device and the second electronic device.
[0130] In some embodiments of the present application, the second link may be a telephone link such as Voice over Long-Term Evolution (VoLTE), Voice over New Radio (VoNR), Voice over Wi-Fi (VoWiFi), etc.
[0131] Step 103b: The first electronic device stores the second key in the key storage area of the first electronic device.
[0132] In some embodiments of the present application, the above key storage area may be a protected area of the first electronic device or a built-in hardware area of the first electronic device to prevent the second key from being tampered with or illegally read.
[0133] In some embodiments of the present application, when receiving the second key sent by the second electronic device through the second link, the first electronic device may receive the identification information of the second electronic device and store the identification information of the second electronic device and the second key in a storage unit of the above key storage area at the same time.
[0134] In some embodiments of the present application, the identification information of the second electronic device may be the device identification of the second electronic device, such as the Temporary Mobile Subscriber Identity (TMSI), International Mobile Equipment Identity (IMEI), etc. of the second electronic device. Specifically, it can be determined according to actual needs, and no specific limitation is made here in this embodiment.
[0135] In this way, the first electronic device receives the second key sent by the second electronic device through the second link, and the first electronic device stores the second key in the key storage area of the first electronic device, without the server transmitting the second key to the first electronic device, thus effectively avoiding the problem that the server is hijacked by an attacker during the process of transmitting the second key to the second electronic device, and further improving the security of voice data during the voice call process.
[0136] In some embodiments of the present application, the above first key and second key are symmetric keys or asymmetric keys; in the case where the above first key and second key are asymmetric keys, the above first key and second key are respectively the public key and private key in the above asymmetric keys; combined Figure 2 with Figure 3 as shown, the above step 102 may be implemented by the following step 102a:
[0137] Step 102a: The first electronic device uses the second key stored in the first electronic device to decrypt the first encrypted data to obtain voice data.
[0138] In some embodiments of the present application, while the first electronic device receives the first encrypted data forwarded by the server through the first link, it can also receive the identification information of the second electronic device forwarded by the server through the first link, and based on the identification information of the second electronic device, determine the first storage unit where the identification information of the second electronic device and the second key are located in the key storage area, obtain the second key from the first storage unit, and then use the second key to decrypt the first encrypted data to obtain the voice data.
[0139] It should be noted that after the first electronic device obtains the voice data, it can perform voice spectrum decoding on the voice data and encoding by a vocoder, recover the user's voice from the voice data, and then play the user's voice through a speaker.
[0140] In this way, the electronic device can directly use the second key stored in the first electronic device to decrypt the first encrypted data to obtain the voice data. Without the server transmitting the second key to the first electronic device, the first electronic device can also use the second key to decrypt the first encrypted data, thereby effectively avoiding the problem that the second key is hijacked by an attacker during the process of the server transmitting the second key to the second electronic device, and further improving the security of the voice data during the voice call.
[0141] In some embodiments of the present application, when the first key and the second key are generated by the first electronic device, before step 101, the data processing method provided by the embodiments of the present application may further include the following step 104a and the following step 104b, and step 102 may be implemented through the following step 102b:
[0142] Step 104a: The first electronic device generates a first key pair.
[0143] In some embodiments of the present application, the first key pair may include the first key and the second key, and the first key and the second key are respectively a public key and a private key.
[0144] In some embodiments of the present application, the first key pair may be an asymmetric key, and the first key and the second key are respectively the public key and the private key in the asymmetric key.
[0145] In some embodiments of the present application, the first electronic device may generate the first key pair based on the first identification information and the first key generation algorithm.
[0146] In some embodiments of the present application, the first identification information includes at least one of the following:
[0147] The identification information of the second electronic device, the identification information of the first electronic device, the identification information pre-agreed between the first electronic device and the second electronic device for call marking, the identification information temporarily allocated by the server to both the first electronic device and the second electronic device, and the identification information of the first user, wherein the first user includes at least one of the user of the first electronic device and the user of the second electronic device.
[0148] In some embodiments of the present application, the identification information of the first electronic device may be a device identification of the first electronic device, such as the TMSI of the first electronic device, the IMEI of the first electronic device, etc. The specific identification information may be determined according to actual needs, and this embodiment does not impose any specific restrictions here.
[0149] For example, the TMSI of the first electronic device may be 0x1A2B3C4D, and the IMEI of the first electronic device may be 490154203237518.
[0150] For another example, the TMSI of the first electronic device may be 0x1D2C3B4A, and the IMEI of the first electronic device may be 370154163236827.
[0151] Step 104b: The first electronic device sends the identification information of the first electronic device and the first key to the server through the second link, so that the server establishes a first association relationship between the identification information of the first electronic device and the first key.
[0152] In some embodiments of the present application, after the first electronic device generates the first key pair, it can store the first key pair in the key storage area, and then send the identification information of the first electronic device and the first key to the server through the second link.
[0153] In some embodiments of the present application, after receiving the identification information of the first electronic device and the first key, the server may establish a first association relationship between the identification information of the first electronic device and the first key.
[0154] Step 102b: The first electronic device uses the second key to decrypt the first encrypted data to obtain voice data.
[0155] In some embodiments of the present application, after receiving the first encrypted data forwarded by the server through the first link, the first electronic device can obtain the second key from the key storage area, and then use the second key to decrypt the first encrypted data to obtain the voice data.
[0156] Thus, after the first electronic device generates the first key pair, it only needs to send the identification information of the first electronic device and the public key in the first key pair to the server through the second link. Therefore, even if an attacker attacks the server, they cannot obtain the private key in the asymmetric key, let alone decrypt the first encrypted data to obtain the voice data, thereby improving the security of the voice data during the voice call.
[0157] In some embodiments of the present application, when the above-mentioned first key is generated by the second electronic device and the above-mentioned second key is generated by the first electronic device, before the above-mentioned step 101, the data processing method provided by the embodiments of the present application may further include the following step 105, and the above-mentioned step 102 may be implemented through the following step 102c1 and the following step 102c2:
[0158] Step 105: The first electronic device receives the second encrypted data sent by the second electronic device through the second link.
[0159] In some embodiments of the present application, the above-mentioned second encrypted data is generated by the second electronic device encrypting the above-mentioned first key with a third key, and the above-mentioned third key and the second key are respectively the public key and the private key in the second key pair pre-stored by the above-mentioned first electronic device.
[0160] In some embodiments of the present application, the above-mentioned second key pair may be an asymmetric key pair, and the above-mentioned third key and the above-mentioned second key are respectively the public key and the private key in the asymmetric key pair.
[0161] In some embodiments of the present application, when the above-mentioned third key and the second key are respectively the public key and the private key in the second key pair, the above-mentioned third key may be an encryption key, and the above-mentioned second key may be a decryption key.
[0162] In some embodiments of the present application, the above-mentioned third key may include information such as the third key type, the third algorithm identifier, the third key data, the third key usage, the third key length, the third validity period, etc. of the above-mentioned third key, which can be specifically determined according to actual needs and are not specifically limited here in this embodiment.
[0163] In some embodiments of the present application, when the above-mentioned third key and the second key are respectively the public key and the private key in the second key pair, the above-mentioned third key type may be the private key in the asymmetric key.
[0164] In some embodiments of the present application, when the above-mentioned third key and the second key are respectively the public key and the private key in the second key pair, the above-mentioned third key data may be the modulus, exponent, and other parameters of the asymmetric key.
[0165] In some embodiments of the present application, when the third key and the second key are respectively the public key and the private key in the second key pair, the use of the third key is used to indicate that the third encryption key is used to decrypt data.
[0166] In some embodiments of the present application, when the third key and the second key are respectively the public key and the private key in the second key pair, the length of the second key can be the key length of the private key. For example, the length of the second key can be 2048 or 4096, which is the key length of the private key in the RSA key.
[0167] In some embodiments of the present application, when the third key and the second key are respectively the public key and the private key in the second key pair, the type of the second key can be the public key in the asymmetric key.
[0168] In some embodiments of the present application, when the third key and the second key are respectively the public key and the private key in the second key pair, the data of the second key can be the modulus and exponent of the asymmetric key.
[0169] In some embodiments of the present application, when the third key and the second key are respectively the public key and the private key in the second key pair, the use of the second key is used to indicate that the second encryption key is used to encrypt data.
[0170] In some embodiments of the present application, when the third key and the second key are respectively the public key and the private key in the second key pair, the use of the third key is used to indicate that the third encryption key is used to decrypt data.
[0171] In some embodiments of the present application, when the third key and the second key are respectively the public key and the private key in the second key pair, and when the type of the second key is the public key in the asymmetric key, the length of the second key can be the key length of the public key. For example, the length of the second key can be 2048 or 4096, which is the key length of the public key in the RSA key.
[0172] In some embodiments of the present application, when the third key and the second key are respectively the public key and the private key in the second key pair, the third algorithm identifier can be the algorithm identifier of the asymmetric encryption algorithm, such as the algorithm identifier of the RSA algorithm and the algorithm identifier of the ECC algorithm.
[0173] For example, the third key can include the public key in the symmetric key of the third key type, the key value of the symmetric key, the algorithm identifier of the AES algorithm, the key length 256, the use of the key to decrypt data, and the key validity period of 36 hours.
[0174] For example, the above-mentioned third key may include the public key in the asymmetric key of the third key type, the modulus 35 of the asymmetric key, the exponent 34 of the public key in the asymmetric key, the algorithm identifier of the RSA algorithm, the key length 2048, the key usage for encrypting data, and the key validity period of 24 hours.
[0175] In some embodiments of the present application, the above-mentioned second encrypted data may be the encrypted data obtained by the second electronic device encrypting the above-mentioned first key using the above-mentioned third key.
[0176] For example, when the key type of the above-mentioned third key is the private key in the asymmetric key, the above-mentioned third key data is the modulus, exponent, and other parameters of the asymmetric key, and the asymmetric encryption algorithm indicated by the above-mentioned third encryption algorithm is the ECC algorithm, the above-mentioned second encrypted data may be the encrypted data generated by encrypting the above-mentioned first key using the modulus, exponent, and other parameters of the above-mentioned asymmetric key and the above-mentioned ECC algorithm.
[0177] For example, when the key type of the above-mentioned third key is the private key in the asymmetric key, the above-mentioned third key data is the modulus, exponent, and other parameters of the asymmetric key, and the asymmetric encryption algorithm indicated by the above-mentioned third encryption algorithm is the RSA algorithm, the above-mentioned second encrypted data may be the encrypted data generated by encrypting the above-mentioned first key using the modulus, exponent, and other parameters of the above-mentioned asymmetric key and the above-mentioned RSA algorithm.
[0178] Step 102c1: The first electronic device uses the second key to decrypt the second encrypted data to obtain the first key.
[0179] In some embodiments of the present application, the first electronic device may use the asymmetric encryption algorithm indicated by the above-mentioned second algorithm identifier and the modulus, exponent, and other parameters of the asymmetric key in the above-mentioned second key data to decrypt the second encrypted data to obtain the above-mentioned first key.
[0180] Step 102c2: The first electronic device uses the first key to decrypt the first encrypted data to obtain the voice data.
[0181] In some embodiments of the present application, the above-mentioned first key is a symmetric key, and the above-mentioned first encrypted data is generated using the above-mentioned first key and the symmetric encryption algorithm pre-agreed by the first electronic device and the second electronic device.
[0182] In some embodiments of the present application, when the key type of the above-mentioned first key is a symmetric key, the use of the above-mentioned first key may be for encrypting data, and the use of the above-mentioned first key may also be for decrypting data, that is, the above-mentioned first key may be an encryption key or a decryption key.
[0183] In some embodiments of the present application, when the first key is a symmetric key, the electronic device may use the key value of the first key and the symmetric encryption algorithm indicated by the algorithm identifier to decrypt the first encrypted data to obtain voice data. In this way, the first electronic device receives the second encrypted data sent by the second electronic device through the second link, thereby avoiding the leakage of the first key caused by being hijacked by an attacker during the process of the server sending the second encrypted data to the first electronic device. Furthermore, it can effectively avoid the leakage of voice data caused by the attacker decrypting the first encrypted data with the first key, thereby enhancing the security of voice data during the voice call process.
[0184] In some embodiments of the present application, before the above step 101, the data processing method provided by the embodiments of the present application may further include the following step 106a and the following step 106b:
[0185] Step 106a: The first electronic device generates a second key pair.
[0186] In some embodiments of the present application, the second key pair includes the second key and the third key, and the second key and the third key are a private key and a public key, respectively.
[0187] In some embodiments of the present application, the first electronic device may generate the second key pair based on the first identification information and the first key generation algorithm. For the explanation of the first identification information, reference may be made to the relevant description in the above step 104a, and details will not be elaborated herein in this embodiment.
[0188] Step 106b: The first electronic device sends the identification information of the first electronic device and the third key to the server through the second link, so that the server establishes a second association relationship between the identification information of the first electronic device and the third key.
[0189] In some embodiments of the present application, after the first electronic device generates the second key pair, it may store the second key pair in the key storage area, and then send the identification information of the first electronic device and the third key to the server through the second link.
[0190] In some embodiments of the present application, after the server receives the identification information of the first electronic device and the third key, it may establish the second association relationship between the identification information of the first electronic device and the third key.
[0191] In this way, after the first electronic device generates the second key pair, it only needs to send the identification information of the first electronic device and the public key in the second key pair to the server through the second link. Therefore, even if an attacker attacks the server, they cannot obtain the private key in the asymmetric key, let alone decrypt the first encrypted data to obtain the voice data, thereby improving the security of the voice data during the voice call.
[0192] In some embodiments of the present application, during the voice call between the first electronic device and the second electronic device, the data processing method provided by the embodiments of the present application may further include the following step 107:
[0193] Step 107: The first electronic device receives the voice data sent by the second electronic device through the second link.
[0194] In some embodiments of the present application, when the second key is generated by the second electronic device, the first electronic device may receive the voice data and the second key sent by the second electronic device through the second link at the same time. After receiving the second key from the second electronic device through the second link, the first electronic device may also receive the voice data from the second electronic device through the second link, or may receive the voice data from the second electronic device through the second link before receiving the second key from the second electronic device through the second link. There is no specific limitation in this embodiment.
[0195] In this way, the first electronic device receives the voice data from the second electronic device through the second link, so that the voice data received from the second electronic device through the second link can be backed up redundantly with the voice data corresponding to the first encrypted data, thereby increasing the transmission success rate of the voice data, and further avoiding call drops and improving the call quality.
[0196] Figure 4 It is a schematic flowchart of the data processing method provided by the embodiments of the present application. As Figure 4 shown, the data processing method provided by the embodiments of the present application may include the following steps 201 to step 204.
[0197] Step 201: During the voice call with the first electronic device, the second electronic device sends the identification information of the first electronic device to the server.
[0198] In some embodiments of the present application, the identification information of the first electronic device is used to instruct the server to obtain the first key, where the first key is the public key in the asymmetric key generated by the first electronic device, or the first key is a symmetric key.
[0199] In some embodiments of the present application, the second electronic device may send the identification information of the first electronic device to the server through the first link described above.
[0200] Step 202, the second electronic device receives the first key sent by the server based on the identification information of the first electronic device and the first association relationship.
[0201] In some embodiments of the present application, the first association relationship is the association relationship between the identification information of the first electronic device and the first key.
[0202] In some embodiments of the present application, after receiving the identification information of the first electronic device, the server may obtain the first key based on the identification information of the first electronic device and the first association relationship, and then return the first key to the second electronic device.
[0203] In some embodiments of the present application, the second electronic device may receive the second key returned by the server through the first link.
[0204] Step 203, the second electronic device encrypts the voice data with the first key to generate first encrypted data.
[0205] In some embodiments of the present application, when the first key is a symmetric key, the second electronic device may use the key value of the symmetric key in the first key data and the symmetric encryption algorithm indicated by the first algorithm identifier to encrypt the voice data to generate the first encrypted data.
[0206] In some embodiments of the present application, when the first key is the public key in the asymmetric keys, the second electronic device may use the modulus and exponent of the asymmetric key in the first key data and the asymmetric encryption algorithm indicated by the first algorithm identifier to encrypt the voice data to generate the first encrypted data.
[0207] Step 204, the second electronic device sends the first encrypted data to the server through the first link.
[0208] In some embodiments of the present application, the first link is a data link established by the first electronic device and the second electronic device through the server.
[0209] In some embodiments of the present application, when the second electronic device sends the first encrypted data to the server through the first link, it may also send the identification information of the first electronic device to the server through the first link, so that the server forwards the first encrypted data to the first electronic device through the first link based on the identification information of the first electronic device.
[0210] In the data processing method provided in the embodiments of the present application, during the voice call between the second electronic device and the first electronic device, the second electronic device sends the identification information of the first electronic device to the server; the second electronic device receives the first encryption key sent by the server based on the identification information of the first electronic device and the first association relationship; the second electronic device sends the first encrypted data to the server through the first link. In this way, by adopting the solution of the present application, the server only needs to send the encryption key to the second electronic device. Therefore, even if an attacker attacks the server, they cannot obtain the decryption key, let alone decrypt the first encrypted data to obtain the voice data, thereby improving the security of the voice data during the voice call.
[0211] In some embodiments of the present application, after the above step 201, the data processing method provided in the embodiments of the present application may further include the following step 205, and the above step 203 may be implemented through the following step 203a:
[0212] Step 205: The second electronic device receives the verification information of the server sent by the server based on the identification information of the first electronic device.
[0213] In some embodiments of the present application, the second electronic device may receive the verification information returned by the server based on the identification information of the first electronic device through the first link.
[0214] In some embodiments of the present application, the verification information may be the digital signature of the server.
[0215] It should be noted that the above step 205 may be executed after the above step 202, or may be executed simultaneously with the above step 202. There is no specific limitation in this embodiment.
[0216] Step 203a: When the second electronic device passes the server security verification based on the verification information, the second electronic device encrypts the first data with the first encryption key to generate the first encrypted data.
[0217] In some embodiments of the present application, the second electronic device may perform a server security verification based on the verification information to determine whether the server has been illegally attacked. When it is confirmed that the server has not been illegally attacked, that is, when the server security verification is passed, the second electronic device may encrypt the first data with the first encryption key to generate the first encrypted data.
[0218] In this way, the second electronic device receives the verification information of the server returned by the server based on the identification information of the first electronic device. When the second electronic device performs a security verification of the server based on the verification information, the second electronic device encrypts the first data with the first key to generate first encrypted data, which can encrypt the first data with the first key when it is determined that the server has not been attacked by an attacker, thereby improving the security of the encrypted data.
[0219] Figure 5 It is a schematic flowchart of the data processing method provided by the embodiments of the present application. As Figure 5 shown, the data processing method provided by the embodiments of the present application may include the following steps 301 to 304.
[0220] Step 301: During a voice call with the first electronic device, the second electronic device sends the identification information of the first electronic device to the server.
[0221] In some embodiments of the present application, the above-mentioned identification information of the first electronic device is used to instruct the above-mentioned server to obtain a third key, and the third key is the public key in the asymmetric key generated by the first electronic device.
[0222] In some embodiments of the present application, the second electronic device may send the above-mentioned identification information of the first electronic device to the server through the above-mentioned first link.
[0223] Step 302: The second electronic device receives the third key sent by the server based on the identification information of the first electronic device and the second association relationship.
[0224] In some embodiments of the present application, the above-mentioned second association relationship is the association relationship between the identification information of the first electronic device and the third key.
[0225] In some embodiments of the present application, after receiving the above-mentioned identification information of the first electronic device, the above-mentioned server may obtain the above-mentioned third key based on the above-mentioned identification information of the first electronic device and the above-mentioned second association relationship, and then return the above-mentioned third key to the second electronic device.
[0226] In some embodiments of the present application, the second electronic device may receive the above-mentioned third key sent by the server through the above-mentioned first link.
[0227] Step 303: The second electronic device encrypts the first key with the third key to generate second encrypted data.
[0228] In some embodiments of the present application, the type of the first key may be a symmetric key, and the second electronic device may encrypt the first key by using the modulus and exponent of the asymmetric key in the third key data and the asymmetric encryption algorithm indicated by the third algorithm identifier to generate the second encrypted data.
[0229] Step 304: The second electronic device transmits the second encrypted data to the first electronic device through the second link.
[0230] In some embodiments of the present application, the second link is a call link between the first electronic device and the second electronic device.
[0231] In some embodiments of the present application, when the second electronic device transmits the second encrypted data to the first electronic device through the second link, it may also transmit voice data to the first electronic device through the second link.
[0232] In some embodiments of the present application, the second electronic device may add the second encrypted data to a Real-time Transport Protocol (RTP) data packet for transmitting the voice data, and then transmit the RTP data packet to the first electronic device through the second link to transmit the second encrypted data and the voice data to the first electronic device.
[0233] In some embodiments of the present application, the second electronic device may also add the second encrypted data to a Real-time Transport Control Protocol (RTCP) data packet for transmitting control information, and transmit the RTCP data packet and the RTP data packet to the first electronic device through the second link to transmit the second encrypted data and the voice data to the first electronic device.
[0234] In some embodiments of the present application, the second electronic device adds the second encrypted data to the reserved field of the RTCP data packet.
[0235] In some embodiments of the present application, the RTCP data packet includes channel information, voice coding information, etc.
[0236] In the data processing method provided by the embodiments of the present application, during a voice call between a second electronic device and a first electronic device, the second electronic device sends the identification information of the first electronic device to the server; the second electronic device receives a third key sent by the server based on the identification information of the first electronic device and a second association relationship; the second electronic device encrypts the first key with the third key to generate second encrypted data; the second electronic device transmits the second encrypted data to the first electronic device through a second link. In this way, with the solution of the present application, the server only needs to send an encryption key to the second electronic device. Therefore, even if an attacker attacks the server, the decryption key cannot be obtained, and it is even more impossible to decrypt the second encrypted data to obtain the first key, and further impossible to decrypt the first encrypted data with the first key data to obtain voice data, thereby improving the security of voice data during the voice call.
[0237] Next, in combination with Figure 6 , the data processing method provided by the embodiments of the present application will be further described. As Figure 6 shown, the data processing method provided by the embodiments of the present application may include the following steps:
[0238] Step 401, the first electronic device generates a first key pair.
[0239] In some embodiments of the present application, the above first key pair includes the above first key and the above second key, and the above first key and the above second key are a public key and a private key respectively.
[0240] It should be noted that the implementation process of the above step 401 may refer to the above step 104a, and will not be elaborated here in this embodiment.
[0241] Step 402, the first electronic device sends the identification information of the first electronic device and the first key to the server through a second link.
[0242] Step 403, the server establishes a first association relationship between the identification information of the first electronic device and the first key.
[0243] It should be noted that the implementation processes of the above step 402 and the above step 403 may refer to the above step 104b, and will not be elaborated here in this embodiment.
[0244] Step 404, during a voice call with the first electronic device, the second electronic device sends the identification information of the first electronic device to the server.
[0245] Step 405, the server sends the first key to the second electronic device based on the identification information of the first electronic device and the first association relationship.
[0246] It should be noted that the implementation processes of the above-mentioned step 404 and the above-mentioned step 405 can refer to the above-mentioned step 201, and will not be elaborated here in this embodiment.
[0247] Step 406: The second electronic device receives the first key and the verification information of the server returned by the server based on the identification information of the first electronic device and the first association relationship.
[0248] It should be noted that the implementation process of the above-mentioned step 406 can refer to the above-mentioned step 202 and the above-mentioned step 205, and will not be elaborated here in this embodiment.
[0249] Step 407: When the second electronic device passes the security verification of the server based on the verification information, the second electronic device encrypts the voice data with the first key to generate the first encrypted data.
[0250] It should be noted that the implementation process of the above-mentioned step 407 can refer to the above-mentioned step 203a, and will not be elaborated here in this embodiment.
[0251] Step 408: The second electronic device sends the first encrypted data to the server through the first link.
[0252] In some embodiments of the present application, the above-mentioned first link is a data link established by the above-mentioned first electronic device and the above-mentioned second electronic device through the above-mentioned server.
[0253] It should be noted that the implementation process of the above-mentioned step 408 can refer to the above-mentioned step 204, and will not be elaborated here in this embodiment.
[0254] Step 409: During the voice call between the first electronic device and the second electronic device, the server forwards the first encrypted data to the first electronic device through the first link.
[0255] Step 410: The first electronic device receives the first encrypted data forwarded by the server through the first link.
[0256] It should be noted that the implementation processes of the above-mentioned step 409 and the above-mentioned step 410 can refer to the above-mentioned step 101, and will not be elaborated here in this embodiment.
[0257] Step 411: The first electronic device decrypts the first encrypted data with the second key to obtain the voice data.
[0258] It should be noted that the implementation process of the above-mentioned step 411 can refer to the above-mentioned step 102b, and will not be elaborated here in this embodiment.
[0259] In the data processing method provided by the embodiments of the present application, after the first electronic device generates the first key pair, it only needs to send the public key in the first key pair to the server. After the second electronic device obtains the public key from the server, it can encrypt the voice data, and then forward the encrypted voice data to the first electronic device through the server. Then, the first electronic device decrypts the encrypted voice data with the private key in the first key pair to obtain the voice data. In this way, on the one hand, during the transmission of the voice data, only the public key and the encrypted voice data pass through the server for transmission. Therefore, even if the server is hijacked by an attacker during the transmission of the public key and the encrypted voice data, the attacker cannot obtain the decryption key, nor can they decrypt the encrypted voice data to obtain the voice data, thereby improving the security of the voice data during the voice call. On the other hand, the server only stores the public key. Even if an attacker attacks the server, they cannot obtain the decryption key, nor can they decrypt the encrypted voice data to obtain the voice data, thereby improving the security of the voice data during the voice call.
[0260] Next, in combination with Figure 7 , the data processing method provided by the embodiments of the present application will be further described. As Figure 7 shown, the data processing method provided by the embodiments of the present application may include the following steps:
[0261] Step 501: The first electronic device generates a second key pair.
[0262] In some embodiments of the present application, the above-mentioned second key pair includes the above-mentioned second key and the above-mentioned third key, and the above-mentioned second key and the above-mentioned third key are a private key and a public key respectively.
[0263] It should be noted that the implementation process of the above step 501 can refer to the above step 106a, and will not be elaborated here in this embodiment.
[0264] Step 502: The first electronic device sends the identification information of the first electronic device and the third key to the server through the second link.
[0265] Step 503: The server establishes a second association relationship between the identification information of the first electronic device and the third key.
[0266] It should be noted that the implementation processes of the above step 502 and the above step 503 can refer to the above step 106b, and will not be elaborated here in this embodiment.
[0267] Step 504: During the voice call with the first electronic device, the second electronic device sends the identification information of the first electronic device to the server.
[0268] Step 505: The server sends the third key to the second electronic device based on the identification information of the first electronic device and the second association relationship.
[0269] It should be noted that the implementation processes of the above step 504 and the above step 505 can refer to the above step 301, and will not be elaborated here in this embodiment.
[0270] Step 506: The second electronic device receives the third key sent by the server based on the identification information of the first electronic device and the second association relationship, as well as the verification information of the server.
[0271] It should be noted that the implementation process of the above step 504 can refer to the above step 302, and will not be elaborated here in this embodiment.
[0272] Step 507: In the case of security verification of the server based on the verification information, the second electronic device encrypts the first key with the third key to generate the second encrypted data.
[0273] It should be noted that the implementation process of the above step 507 can refer to the above step 303, and will not be elaborated here in this embodiment.
[0274] Step 508: The second electronic device transmits the second encrypted data to the first electronic device through the second link.
[0275] It should be noted that the implementation process of the above step 506 can refer to the above step 304, and will not be elaborated here in this embodiment.
[0276] Step 509: The first electronic device receives the second encrypted data sent by the second electronic device through the second link.
[0277] It should be noted that the implementation process of the above step 507 can refer to the above step 105, and will not be elaborated here in this embodiment.
[0278] Step 510: The first electronic device decrypts the second encrypted data with the second key to obtain the first key.
[0279] It should be noted that the implementation process of the above step 510 can refer to the above step 102c1, and will not be elaborated here in this embodiment.
[0280] Step 511: During the voice call with the second electronic device, the second electronic device encrypts the voice data with the first key to obtain the first encrypted data.
[0281] Step 512: The second electronic device sends the first encrypted data to the server through the first link.
[0282] It should be noted that the implementation process of step 512 above can refer to step 204 above, and will not be elaborated here in this embodiment.
[0283] Step 513: During the voice call between the first electronic device and the second electronic device, the server forwards the first encrypted data to the first electronic device through the first link.
[0284] Step 514: The first electronic device receives the first encrypted data forwarded by the server through the first link.
[0285] It should be noted that the implementation processes of step 513 and step 514 above can refer to step 101 above, and will not be elaborated here in this embodiment.
[0286] Step 515: The first electronic device decrypts the first encrypted data using the first key to obtain the voice data.
[0287] It should be noted that the implementation process of step 515 above can refer to step 102c2 above, and will not be elaborated here in this embodiment.
[0288] In the data processing method provided in the embodiment of the present application, after the first electronic device generates the second key pair, it only needs to send the public key in the first key pair to the server. After the second electronic device obtains the public key from the server, it can encrypt the first key and forward the encrypted data to the first electronic device through the server. Then, the first electronic device decrypts the encrypted data using the private key in the second key pair to obtain the first key. Then, when receiving the voice data encrypted with the first key, it uses the first key to decrypt the encrypted voice data to obtain the voice data. In this way, on the one hand, during the transmission of the voice data, only the public key and the encrypted data will be transmitted through the server. Therefore, even if the server is hijacked by an attacker during the transmission of the public key and the encrypted data, the attacker cannot obtain the decryption key, nor can they decrypt the encrypted data to obtain the first key, and thus cannot decrypt the encrypted voice data with the first key to obtain the voice data, thereby improving the security of the voice data during the voice call. On the other hand, the server only stores the public key. Even if the attacker attacks the server, they cannot obtain the decryption key, nor can they decrypt the encrypted data to obtain the first key, and thus cannot decrypt the encrypted voice data with the first key to obtain the voice data, thereby improving the security of the voice data during the voice call.
[0289] Next, in combination with Figure 8 , the data processing method provided in the embodiment of the present application will be further described. As Figure 8 shown, the data processing method provided in the embodiment of the present application may include the following steps:
[0290] Step 601: The second electronic device generates a first key pair.
[0291] In some embodiments of the present application, the first key pair includes the first key and the second key, and the first key and the second key are a public key and a private key respectively.
[0292] It should be noted that the implementation process of the above step 601 is similar to the above step 104. To avoid repetition, it will not be elaborated here in this embodiment.
[0293] Step 602: The second electronic device sends the second key to the first electronic device through the second link.
[0294] Step 603: During the voice call with the second electronic device, the first electronic device receives the second key sent by the second electronic device through the second link.
[0295] It should be noted that the implementation process of the above step 603 is similar to the above step 103a. To avoid repetition, it will not be elaborated here in this embodiment.
[0296] Step 604: The first electronic device stores the second key in the key storage area of the first electronic device.
[0297] It should be noted that the implementation process of the above step 604 is similar to the above step 103b. To avoid repetition, it will not be elaborated here in this embodiment.
[0298] Step 605: The first electronic device receives the first encrypted data forwarded by the server through the first link.
[0299] In some embodiments of the present application, the first encrypted data is generated after the above second electronic device encrypts the voice data using the first key pair.
[0300] It should be noted that the implementation process of the above step 605 is similar to the above step 101. To avoid repetition, it will not be elaborated here in this embodiment.
[0301] Step 606: The first electronic device decrypts the first encrypted data using the second key stored in the first electronic device to obtain the voice data.
[0302] It should be noted that the implementation process of the above step 606 is similar to the above step 102a. To avoid repetition, it will not be elaborated here in this embodiment.
[0303] In the data processing method provided in the embodiments of the present application, after the second electronic device generates the first key pair, it directly sends the second key to the first electronic device through the second link. After receiving the second key, the first electronic device can store the second key in the key storage area, and then, after receiving the first encrypted data forwarded by the server through the first link, decrypt the first encrypted data with the second key to obtain the voice data. In this way, even if the server is attacked by an attacker, the attacker cannot obtain the second key, let alone decrypt the first encrypted data with the second key to obtain the voice data, thereby improving the security of the voice data during the voice call. In addition, adopting the solution of the present application, there is no need for the server to transmit the second key to the first electronic device, thereby effectively avoiding the problem that the server is hijacked by an attacker during the process of transmitting the second key to the first electronic device, and further improving the security of the voice data during the voice call.
[0304] The following will further elaborate on the data processing method provided in the embodiments of the present application by taking the electronic device as a terminal and combining Scenarios 1 to 4.
[0305] Scenario 1: The scenario where the terminal has a built-in private key. Exemplarily, as Figure 9 shown, in Scenario 1, the data processing method provided in the embodiments of the present application may include the following steps 701 to the following step 704.
[0306] Step 701: The terminal of the data recipient stores the asymmetric key pair.
[0307] Exemplarily, the terminal of the data recipient may be the above-mentioned first electronic device.
[0308] Exemplarily, the terminal of the data sender generates an asymmetric encryption key pair, including a public key and a private key.
[0309] Exemplarily, the asymmetric encryption key pair may be the above-mentioned first key pair.
[0310] Exemplarily, the public key may be the first key in the above-mentioned first key pair, and the private key may be the second key in the above-mentioned first key pair.
[0311] Exemplarily, before leaving the factory, the terminal of the data sender writes the private key into the protected area of the terminal of the data sender or the built-in hardware key storage area to prevent being tampered with or illegally read; at the same time, the data sender stores the combination of the corresponding public key of the terminal in the manufacturer's server.
[0312] Exemplarily, the manufacturer's server may be the above-mentioned server.
[0313] Exemplarily, the above identification information may be the Embedded MultiMedia Card Identification (EMMCID) of the terminal, the International Mobile Equipment Identity (IMEI), etc.
[0314] Step 702: The terminal of the data sender obtains the public key of the terminal of the data sender from the server.
[0315] Exemplarily, the terminal of the data sender may be the above-mentioned second electronic device.
[0316] Exemplarily, when the terminals of the data senders are all running the first application, the above-mentioned server may be the background server of the first application. The terminals of the data senders can establish a data link through the background server of the first application, and the terminals of the data senders can obtain the public key of the terminals of the data senders from the server through the data link.
[0317] Exemplarily, the terminal of the data receiver and the terminal of the data sender can establish a data link through the server, and request the public key of the terminal of the data sender from the server through the data link; the server sends the public key of the terminal of the data sender and the verification information of the server to the terminal of the data receiver. After receiving the public key, the terminal of the data receiver uses the verification information to verify to ensure that the public key will not be tampered with.
[0318] Step 703: The terminal of the data sender encrypts the voice data with the public key, generates the first encrypted data and sends it.
[0319] Exemplarily, the terminal of the data sender may use an asymmetric encryption algorithm and the public key of the terminal of the data receiver provided by the server to encrypt the voice data, and then send the generated first encrypted data to the server through the data link, or directly send it to the terminal of the data receiver.
[0320] Step 704: The terminal of the data receiver receives the first encrypted data, and decrypts the first encrypted data with the private key in the stored key pair of the asymmetric encryption to obtain the voice data.
[0321] Exemplarily, in combination with Figure 10As shown, the two terminals for voice calls are the terminal of user A and the terminal of user B. When user A is the voice initiator and user B is the voice receiver, the terminal of user A is the terminal of the data sender, and the terminal of user B is the terminal of the data receiver. When user B is the voice initiator and user A is the voice receiver, the terminal of user B is the terminal of the data sender, and the terminal of user A is the terminal of the data receiver. Therefore, the terminal of user A and the terminal of user B can generate their respective asymmetric key pairs and store them, and then send the public keys in their respective asymmetric key pairs to the server.
[0322] Exemplarily, after the server stores the public keys in the respective asymmetric key pairs of the terminal of user A and the terminal of user B, if the terminal of user A needs to transmit the voice data of user A to the terminal of user B, the terminal of user A can send a request to the server to obtain the public key of the terminal of user B. After receiving the request from the terminal of user A, the server can send the public key of the terminal of user B and the verification information of the server to the terminal of user A. After receiving the public key of the terminal of user B and the verification information of the server, the terminal of user A can use the verification information for verification to ensure that the public key of the terminal of user B will not be tampered with, and then encrypt the symmetric encryption key generated by the terminal of user A with the public key of the terminal of user B to obtain the second encrypted data, and forward the second encrypted data to the server, which is then forwarded by the server to the terminal of user B, or directly send the second encrypted data to the terminal of user B. After receiving the second encrypted data, the terminal of user B can decrypt the second encrypted data with the private key in the asymmetric key pair to obtain the symmetric encryption key. Furthermore, after the terminal of user B receives the voice data of user A encrypted by the symmetric encryption key of the user of terminal A, the terminal of user B can encrypt the voice data of user A with the symmetric encryption key to obtain the encrypted voice data of user A.
[0323] In the data processing method provided in the embodiments of the present application, the private key is always stored in the terminal of the data receiver. Therefore, even if an attacker attacks the server or hijacks the communication data between the server and the terminal of the data receiver, the attacker cannot obtain the private key, let alone decrypt the corresponding voice data with the private key, thereby enhancing the security of the voice data during the voice call.
[0324] Scenario 2: A scenario where the symmetric key is protected by the private key built into the terminal. Exemplarily, as Figure 11 shown, in Scenario 2, the data processing method provided in the embodiments of the present application may include the following steps 801 to the following step 806.
[0325] Step 801: The terminal of the data receiver stores the asymmetric key pair.
[0326] Exemplarily, the above-mentioned asymmetric key pair is the above-mentioned second key pair.
[0327] Step 802, the terminal of the data sender obtains the public key of the terminal of the data sender from the server.
[0328] It should be noted that the public key of the terminal of the data sender is the above-mentioned third key.
[0329] It should be noted that the implementation processes of the above step 801 and the above step 802 are similar to those of the above step 701 and the above step 702. To avoid repetition, they are not elaborated here in this embodiment.
[0330] Step 803, the terminal of the data sender encrypts the symmetric encryption key generated by the terminal of the data sender using the public key, generates second encrypted data and sends it.
[0331] Exemplarily, the symmetric encryption key can be the above-mentioned first key.
[0332] Exemplarily, the terminal of the data sender can use the public key of the terminal of the data receiver provided by the server with an asymmetric encryption algorithm to encrypt the symmetric encryption key, and then send the generated second encrypted data to the server through the data link, or directly send it to the terminal of the data receiver.
[0333] Step 804, the terminal of the data receiver receives the second encrypted data, and decrypts the second encrypted data using the private key in the stored asymmetric encryption key pair to obtain the symmetric encryption key.
[0334] Step 805, the terminal of the data sender encrypts the voice data using the symmetric encryption key, generates first encrypted data and sends it.
[0335] Step 806, the terminal of the data receiver decrypts the first encrypted data using the symmetric encryption key to obtain the voice data.
[0336] Exemplarily, in combination with Figure 12 As shown, the two terminals for the voice call are the terminal of user A and the terminal of user B. When user A is the voice initiator and user B is the voice receiver, the terminal of user A is the terminal of the data sender, and the terminal of user B is the terminal of the data receiver. When user B is the voice initiator and user A is the voice receiver, the terminal of user B is the terminal of the data sender, and the terminal of user A is the terminal of the data receiver. Therefore, the terminal of user A and the terminal of user B can generate their respective asymmetric key pairs and store them, and then send the public keys in their respective asymmetric key pairs to the server.
[0337] Exemplarily, after the server stores the public keys in the asymmetric key pairs of the terminals of User A and User B respectively, if the terminal of User A needs to transmit the voice data of User A to the terminal of User B, the terminal of User A can send a request to the server to obtain the public key of the terminal of User B. After receiving the request from the terminal of User A, the server can send the public key of the terminal of User B and the verification information of the server to the terminal of User A. After receiving the public key of the terminal of User B and the verification information of the server, the terminal of User A can use the verification information to verify to ensure that the public key of the terminal of User B will not be tampered with, and then encrypt the voice data of User A with the public key of the terminal of User B, and forward the encrypted voice data to the server, which is then forwarded by the server to the terminal of User B, or directly send the encrypted voice data to the terminal of User B.
[0338] Exemplarily, after the server stores the public keys in the asymmetric key pairs of the terminals of User A and User B respectively, when the terminal of User B needs to transmit the voice data of User B to the terminal of User A, the terminal of User B can send a request to the server to obtain the public key of the terminal of User A. After receiving the request from the terminal of User B, the server can send the public key of the terminal of User A and the verification information of the server to the terminal of User B. After receiving the public key of the terminal of User A and the verification information of the server, the terminal of User B can use the verification information to verify to ensure that the public key of the terminal of User A will not be tampered with, and then encrypt the voice data of User B with the public key of the terminal of User A, and forward the encrypted voice data to the server, which is then forwarded by the server to the terminal of User A, or directly send the encrypted voice data to the terminal of User A.
[0339] In the data processing method provided in the embodiments of the present application, the private key is always stored in the terminal of the data receiver. Therefore, even if an attacker attacks the server or hijacks the communication data between the server and the terminal of the data receiver, the attacker cannot obtain the private key, nor can the attacker use the private key to decrypt the symmetric encryption key, nor can the attacker use the symmetric encryption key to decrypt the corresponding voice data, thereby improving the security of the voice data during the language call process.
[0340] Scenario 3: Scenario of transmitting keys using a three-party channel
[0341] Exemplarily, as Figure 13 shown, in Scenario 3, the data processing method provided in the embodiments of the present application may include the following steps 901 to the following step 904.
[0342] Step 901, the terminals of both parties in the call select a third-party channel.
[0343] Exemplarily, the above-mentioned third-party channel may be a third link, and the third link may be a data link established by the terminals of both parties in a call through the background server of the second application, where the second application and the first application are different applications.
[0344] Exemplarily, the terminals of both parties in a call may use the background server of the second application to verbally negotiate a temporary verification code. For example, by forwarding digital verification code information through the third link, it can be directly used as the public key in the symmetric key or asymmetric key, or as the basic information for generating a key.
[0345] Exemplarily, the above-mentioned third channel may be the above-mentioned second link, such as telephone links like VoLTE, VoNR, VoWiFi, etc.
[0346] Exemplarily, after the terminals of both parties in a call establish a call connection, they use the redundant bits of the control signaling of telephone links such as VoLTE, VoNR, VoWiFi, etc. to transmit key information, such as the redundant fields of the signaling that can be transmitted to the peer end in RTP packets, Session Initialization Protocol (SIP) packets, or RTCP packets;
[0347] It should be noted that in traditional VoLTE, VoNR, and VoWiFi, after a call is established, two types of data packets will be exchanged with the base station: one is the RTP packet for transmitting voice data, which is a protocol format after encapsulating audio such as AMR; the other is the RTCP packet for transmitting control information, which contains negotiation information such as channel information and voice coding. On the one hand, the key information can be put into the RTP packet and transmitted to the peer end, but the original voice data will be damaged, and the call users may perceive abnormal sound quality; on the other hand, the key information can be transmitted by putting it into the reserved field of the RTCP packet.
[0348] Step 902: The terminal of the data receiver uses a third-party channel to transmit the key.
[0349] Exemplarily, the terminal of the data receiver may transmit the public key in the asymmetric encryption key pair of the terminal of the data receiver, or the negotiated key for symmetric encryption, to the peer end through the above-mentioned three-party channel.
[0350] It should be noted that the matter of transmitting the key through the third-party channel can be negotiated in advance by both parties in the call, and the calling end or the called end of the call generates the key and then sends it to the peer end for verification before use.
[0351] Step 903: The terminal of the data sender encrypts the voice data using the key transmitted by the terminal of the data receiver through the third-party channel, generates the first encrypted data, and forwards it to the terminal of the data receiver through the server.
[0352] Step 904: The terminal of the data recipient receives the first encrypted data, and decrypts the first encrypted data using the private key in the asymmetric encryption key pair or the negotiated key of symmetric encryption to obtain the voice data.
[0353] Exemplarily, in combination with Figure 14 As shown, the two terminals of the voice call are the terminal of user A and the terminal of user B. When user A is the voice initiator and user B is the voice recipient, the terminal of user A is the terminal of the data sender, and the terminal of user B is the terminal of the data recipient. When user B is the voice initiator and user A is the voice recipient, the terminal of user B is the terminal of the data sender, and the terminal of user A is the terminal of the data recipient. Therefore, the terminal of user A and the terminal of user B can generate their respective asymmetric key pairs and store them, and then send the public keys in their respective asymmetric key pairs to each other through a third-party channel.
[0354] Exemplarily, if the terminal of user A needs to transmit the voice data of user A to the terminal of user B, after receiving the public key of the terminal of user B through the third channel, the terminal of user A can encrypt the voice data of user A using the public key of the terminal of user B, and forward the encrypted voice data to the server, which forwards it to the terminal of user B.
[0355] Exemplarily, if the terminal of user B needs to transmit the voice data of user B to the terminal of user A, after receiving the public key of the terminal of user A through the third channel, the terminal of user B can encrypt the voice data of user B using the public key of the terminal of user A, and forward the encrypted voice data to the server, which forwards it to the terminal of user A.
[0356] In the data processing method provided in this embodiment of the application, the third channel transmits the key, and the encrypted voice data is forwarded through the server, which can transmit the key and the data through different channels, thereby improving the security of the voice data.
[0357] Scenario 4: The scenario of generating a key using the first identification information and the time stamp
[0358] Exemplarily, in Scenario 4, either party in the voice call can use the first identification information and the time stamp to generate the same symmetric encryption key using the key generation algorithm agreed upon by both parties in the voice call, and use the symmetric key generated by the key generation algorithm agreed upon by both parties in the voice call to encrypt and decrypt the voice data.
[0359] It should be noted that the explanation of the first identification information can refer to the relevant description in Step 104a above, and will not be elaborated here in this embodiment.
[0360] It should be noted that the solution of Scenario 4 is applicable when the third-party channel cannot be established. When the third-party channel cannot be established, the key or key verification information cannot be transmitted to the other end; the symmetric key generated by the key generation algorithm agreed upon by both parties of the voice call can be used to encrypt and decrypt the voice data.
[0361] In the data processing method provided in the embodiments of the present application, when the third-party channel cannot be established, the symmetric key generated by the key generation algorithm agreed upon by both parties of the voice call is used to encrypt and decrypt the voice data. Thus, the voice data can be encrypted and decrypted without transmitting the key through the third-party channel, thereby improving the transmission efficiency of the voice data.
[0362] It should be noted that each of the above method embodiments, or various possible implementation manners in each method embodiment, can be executed independently, or any two or more of them can be combined with each other. It can be specifically determined according to actual usage requirements, and the embodiments of the present application do not limit this.
[0363] For the data processing method provided in the embodiments of the present application, the execution subject can be a data processing device. In the embodiments of the present application, taking the data processing device executing the data processing method as an example, the data processing device provided in the embodiments of the present application is described.
[0364] Figure 15 It is a schematic structural diagram of the data processing device provided in the embodiments of the present application. The data processing device 1500 includes: a transceiver module 1501 and a processing module 1502.
[0365] Among them, the transceiver module 1501 is used to receive, during the voice call with the second electronic device, the first encrypted data forwarded by the server through the first link. The first encrypted data is generated after the second electronic device encrypts the voice data using the first key. The first link is a data link established between the first electronic device and the second electronic device through the server.
[0366] The processing module 1502 is used to obtain the voice data based on the second key in the first electronic device and the first encrypted data received by the transceiver module.
[0367] Among them, the second key is generated by the first electronic device; or, the second key is generated by the second electronic device. In the case where the second key is generated by the second electronic device, the second key is sent by the second electronic device to the first electronic device through the second link. The second link is the call link between the first electronic device and the second electronic device.
[0368] In some embodiments of the present application, when the first key and the second key are generated by the second electronic device, the transceiver module 1501 is further configured to receive the second key sent by the second electronic device through the second link before receiving the first encrypted data forwarded by the server through the first link;
[0369] The processing module 1502 is further configured to store the second key in the key storage area of the first electronic device.
[0370] In some embodiments of the present application, the first key and the second key are symmetric keys or asymmetric keys; when the first key and the second key are asymmetric keys, the first key and the second key are respectively the public key and the private key in the asymmetric keys;
[0371] The processing module 1502 is specifically configured to:
[0372] Use the second key stored in the first electronic device to decrypt the first encrypted data to obtain voice data.
[0373] In some embodiments of the present application, when the first key and the second key are generated by the first electronic device, the processing module 1502 is further configured to generate a first key pair before receiving the first encrypted data forwarded by the server through the first link, the first key pair includes the first key and the second key, and the first key and the second key are respectively the public key and the private key;
[0374] The transceiver module 1501 is further configured to send the identification information of the first electronic device and the first key to the server through the second link, so that the server establishes a first association relationship between the identification information of the first electronic device and the first key;
[0375] The processing module 1502 is specifically configured to:
[0376] Use the second key to decrypt the first encrypted data to obtain voice data.
[0377] In some embodiments of the present application, when the first key is generated by the second electronic device and the second key is generated by the first electronic device, the transceiver module 1501 is further configured to receive the second encrypted data sent by the second electronic device through the second link before receiving the first encrypted data forwarded by the server through the first link, the second encrypted data is generated by the second electronic device encrypting the first key with a third key, and the third key and the second key are respectively the public key and the private key in the second key pair pre-stored in the first electronic device;
[0378] The processing module 152 is specifically configured to:
[0379] Use the second key to decrypt the second encrypted data to obtain the first key;
[0380] Use the first key to decrypt the first encrypted data to obtain voice data.
[0381] In some embodiments of the present application, the processing module 1502 is further configured to generate a second key pair before receiving the first encrypted data forwarded by the server through the first link. The second key pair includes the second key and the third key, and the second key and the third key are a private key and a public key, respectively;
[0382] The transceiver module 1501 is further configured to send the identification information of the first electronic device and the third key to the server through the second link, so that the server establishes a second association relationship between the identification information of the first electronic device and the third key.
[0383] In some embodiments of the present application, during the voice call between the first electronic device and the second electronic device, the transceiver module 1501 is further configured to:
[0384] Receive the voice data sent by the second electronic device through the second link.
[0385] In the data processing device provided in the embodiment of the present application, during a voice call with a second electronic device, the first encrypted data forwarded by the server through a first link is received. The first encrypted data is generated by the second electronic device after encrypting voice data using a first key. The first link is a data link established between the first electronic device and the second electronic device through the server. The first electronic device obtains the voice data based on a second key in the first electronic device and the first encrypted data, where the second key is generated by the first electronic device; or, the second key is generated by the second electronic device. In the case where the second key is generated by the second electronic device, the second key is sent by the second electronic device to the first electronic device through a second link, and the second link is a call link between the first electronic device and the second electronic device. Thus, since the second key is generated by the first electronic device, or the second electronic device sends the second key to the first electronic device through the second link, even if the server is attacked by an attacker, the attacker cannot obtain the second key, nor can the attacker decrypt the first encrypted data based on the second key to obtain the voice data, thereby improving the security of the voice data during the voice call. Thus, since the second key is generated by the first electronic device, or the second electronic device sends the second key to the first electronic device through the second link, even if the server is attacked by an attacker, the attacker cannot obtain the second key, nor can the attacker decrypt the first encrypted data based on the second key to obtain the voice data, thereby improving the security of the voice data during the voice call.
[0386] Figure 16 FIG. 1600 is a schematic structural diagram of a data processing device provided in an embodiment of the present application. The data processing device 1600 includes: a sending module 1601, a receiving module 1602, and a processing module 1603.
[0387] Among them, the sending module 1601 is configured to send the identification information of the first electronic device to the server during a voice call with the first electronic device.
[0388] The receiving module 1602 is configured to receive the first key sent by the server based on the identification information of the first electronic device sent by the sending module and a first association relationship, where the first association relationship is an association relationship between the identification information of the first electronic device and the first key.
[0389] The processing module 1603 is configured to encrypt the voice data using the first key received by the receiving module to generate first encrypted data.
[0390] The sending module 1601 is further configured to send the first encrypted data generated by the processing module to the server through a first link, where the first link is a data link established between the first electronic device and the second electronic device through the server.
[0391] In some embodiments of the present application, the receiving module 1602 is further configured to receive, after sending the identification information of the first electronic device to the server, the verification information of the server sent by the server based on the identification information of the first electronic device;
[0392] The processing module 1603 is specifically configured to:
[0393] When the security verification of the server is passed based on the verification information, encrypt the first data with the first key to generate first encrypted data.
[0394] In the data processing device provided by the embodiments of the present application, during a voice call with a first electronic device, the identification information of the first electronic device is sent to the server; the first key sent by the server based on the identification information of the first electronic device and the first association relationship is received; and the first encrypted data is sent to the server through a first link. In this way, with the solution of the present application, the server only needs to send an encryption key to the second electronic device. Therefore, even if an attacker attacks the server, the decryption key cannot be obtained, and it is even more impossible to decrypt the first encrypted data to obtain voice data, thereby improving the security of voice data during a voice call.
[0395] Figure 17 FIG. 14 is a schematic structural diagram of a data processing device 1700 provided by an embodiment of the present application. The data processing device 1700 includes: a sending module 1701, a receiving module 1702, and a processing module 1703.
[0396] Among them, the sending module 1701 is configured to send the identification information of the first electronic device to the server during a voice call with the first electronic device;
[0397] The receiving module 1702 is configured to receive a third key sent by the server based on the identification information of the first electronic device sent by the sending module and a second association relationship, where the second association relationship is an association relationship between the identification information of the first electronic device and the third key;
[0398] The processing module 1703 is configured to encrypt the first key with the third key to generate second encrypted data;
[0399] The sending module 1701 is further configured to transmit the second encrypted data generated by the processing module to the first electronic device through a second link, where the second link is a call link between the first electronic device and the second electronic device.
[0400] In the data processing device provided in the embodiment of the present application, during a voice call with a first electronic device, the identification information of the first electronic device is sent to a server; a third key sent by the server based on the identification information of the first electronic device and a second association relationship is received; the second electronic device encrypts a first key using the third key to generate second encrypted data; and the second encrypted data is transmitted to the first electronic device via a second link. In this way, with the solution of the present application, the server only needs to send an encryption key to the second electronic device. Therefore, even if an attacker attacks the server, they cannot obtain the decryption key, let alone decrypt the second encrypted data to obtain the first key, and further cannot decrypt the first encrypted data using the first key data to obtain the voice data, thereby improving the security of the voice data during the voice call.
[0401] The data processing device in the embodiment of the present application can be an electronic device or a component in an electronic device, such as an integrated circuit or a chip. The electronic device can be a terminal or other devices other than a terminal. Exemplarily, the electronic device can be a mobile phone, a tablet computer, a laptop computer, a handheld computer, a vehicle-mounted electronic device, a mobile Internet device, an augmented reality / virtual reality device, a robot, a wearable device, a super mobile personal computer, a netbook, or a personal digital assistant, etc. It can also be a server, a Network Attached Storage (NAS), a personal computer (PC), a television (TV), a teller machine, or a self-service machine, etc. The embodiment of the present application does not make specific limitations.
[0402] The data processing device in the embodiment of the present application can be a device with an operating system. The operating system can be an Android operating system, an iOS operating system, or other possible operating systems. The embodiment of the present application does not make specific limitations.
[0403] The data processing device provided in the embodiment of the present application can implement each process implemented by each embodiment of the above data processing method. To avoid repetition, it will not be elaborated here.
[0404] Optionally, as Figure 18 shown, the embodiment of the present application further provides an electronic device 1800, including a processor 1801 and a memory 1802. A program or instruction that can run on the processor 1801 is stored on the memory 1802. When the program or instruction is executed by the processor 1801, it implements each step of the embodiment of the above data processing method and can achieve the same technical effect. To avoid repetition, it will not be elaborated here.
[0405] It should be noted that the electronic devices in the embodiments of the present application include the above-mentioned mobile electronic devices and non-mobile electronic devices.
[0406] Figure 19 Schematic diagram of the hardware structure of an electronic device according to an embodiment of the present application.
[0407] The electronic device 1900 includes, but is not limited to: a radio frequency unit 1901, a network module 1902, an audio output unit 1903, an input unit 1904, a sensor 1905, a display unit 1906, a user input unit 1907, an interface unit 1908, a memory 1909, and a processor 1910 and other components.
[0408] Those skilled in the art can understand that the electronic device 1900 may further include a power source (such as a battery) for supplying power to each component. The power source can be logically connected to the processor 1910 through a power management system, so as to realize functions such as management of charging, discharging, and power consumption management through the power management system. Figure 19 The structure of the electronic device shown in does not constitute a limitation on the electronic device. The electronic device may include more or fewer components than shown in the figure, or combine certain components, or have different component arrangements, which will not be elaborated here.
[0409] Among them, the radio frequency unit 1901 is used to receive the first encrypted data forwarded by the server through the first link during a voice call with the second electronic device. The first encrypted data is generated after the second electronic device encrypts the voice data using the first key. The first link is a data link established between the first electronic device and the second electronic device through the server;
[0410] The processor 1910 is used to obtain the voice data based on the second key in the first electronic device and the first encrypted data received by the transceiver module;
[0411] Among them, the second key is generated by the first electronic device; or, the second key is generated by the second electronic device. In the case where the second key is generated by the second electronic device, the second key is sent by the second electronic device to the first electronic device through the second link. The second link is a call link between the first electronic device and the second electronic device.
[0412] In some embodiments of the present application, in the case where the first key and the second key are generated by the second electronic device, the radio frequency unit 1901 is further used to receive the second key sent by the second electronic device through the second link before receiving the first encrypted data forwarded by the server through the first link;
[0413] The processor 1910 is further configured to store the second key in the key storage area of the first electronic device.
[0414] In some embodiments of the present application, the first key and the second key are symmetric keys or asymmetric keys; when the first key and the second key are asymmetric keys, the first key and the second key are respectively the public key and the private key in the asymmetric keys.
[0415] The processor 1910 is specifically configured to:
[0416] Use the second key stored in the first electronic device to decrypt the first encrypted data to obtain voice data.
[0417] In some embodiments of the present application, when the first key and the second key are generated by the first electronic device, the processor 1910 is further configured to generate a first key pair before receiving the first encrypted data forwarded by the server through the first link, where the first key pair includes the first key and the second key, and the first key and the second key are respectively the public key and the private key.
[0418] The radio frequency unit 1901 is further configured to send the identification information of the first electronic device and the first key to the server through the second link, so that the server establishes a first association relationship between the identification information of the first electronic device and the first key.
[0419] The processor 1910 is specifically configured to:
[0420] Use the second key to decrypt the first encrypted data to obtain voice data.
[0421] In some embodiments of the present application, when the first key is generated by the second electronic device and the second key is generated by the first electronic device, the transceiver module 1501 is further configured to receive the second encrypted data sent by the second electronic device through the second link before receiving the first encrypted data forwarded by the server through the first link, where the second encrypted data is generated by the second electronic device after encrypting the first key with a third key, and the third key and the second key are respectively the public key and the private key in the second key pair pre-stored in the first electronic device.
[0422] The processor 1910 is specifically configured to:
[0423] Use the second key to decrypt the second encrypted data to obtain the first key.
[0424] Use the first key to decrypt the first encrypted data to obtain voice data.
[0425] In some embodiments of the present application, the processor 1910 is further configured to generate a second key pair before receiving the first encrypted data forwarded by the receiving server through the first link, where the second key pair includes the second key and the third key, and the second key and the third key are a private key and a public key, respectively;
[0426] The radio frequency unit 1901 is further configured to send, through the second link, the identification information of the first electronic device and the third key to the server, so that the server establishes a second association relationship between the identification information of the first electronic device and the third key.
[0427] In some embodiments of the present application, during a voice call between the first electronic device and the second electronic device, the radio frequency unit 1901 is further configured to:
[0428] Receive, through the second link, the voice data sent by the second electronic device.
[0429] In the data processing device provided in the embodiments of the present application, during a voice call with a second electronic device, receive first encrypted data forwarded by a receiving server through a first link, where the first encrypted data is generated after the second electronic device encrypts voice data using a first key pair, and the first link is a data link established between the first electronic device and the second electronic device through the server; the first electronic device obtains the voice data based on a second key in the first electronic device and the first encrypted data; where the second key is generated by the first electronic device; or, the second key is generated by the second electronic device; in the case where the second key is generated by the second electronic device, the second key is sent by the second electronic device to the first electronic device through a second link, and the second link is a call link between the first electronic device and the second electronic device. Thus, since the second key is generated by the first electronic device, or is sent by the second electronic device to the first electronic device through the second link, even if the server is attacked by an attacker, the attacker cannot obtain the second key, nor can the attacker decrypt the first encrypted data based on the second key to obtain the voice data, thereby improving the security of the voice data during the voice call.
[0430] In some embodiments of the present application, the radio frequency unit 1901 is configured to send the identification information of the first electronic device to the server during a voice call with the first electronic device;
[0431] Receive a first key sent by the server based on the identification information of the first electronic device sent by the sending module and a first association relationship, where the first association relationship is an association relationship between the identification information of the first electronic device and the first key;
[0432] A processor 1910, configured to encrypt voice data using the first key received by the receiving module to generate first encrypted data;
[0433] The radio frequency unit 1901 is further configured to send the first encrypted data generated by the processing module to a server via a first link, where the first link is a data link established between the first electronic device and the second electronic device via the server.
[0434] In some embodiments of the present application, the radio frequency unit 1901 is further configured to receive verification information of the server sent by the server based on the identification information of the first electronic device after sending the identification information of the first electronic device to the server;
[0435] The processor 1910 is specifically configured to:
[0436] When passing the security verification of the server based on the verification information, encrypt the first data using the first key to generate first encrypted data.
[0437] In the electronic device provided in the embodiments of the present application, during a voice call with a first electronic device, the identification information of the first electronic device is sent to a server; the first key sent by the server based on the identification information of the first electronic device and a first association relationship is received; and the first encrypted data is sent to the server via a first link. In this way, with the solution of the present application, the server only needs to send an encryption key to the second electronic device. Therefore, even if an attacker attacks the server, the decryption key cannot be obtained, and the first encrypted data cannot be decrypted to obtain the voice data, thereby improving the security of the voice data during the voice call.
[0438] In some embodiments of the present application, the radio frequency unit 1901 is configured to send the identification information of the first electronic device to a server during a voice call with the first electronic device;
[0439] Receive a third key sent by the server based on the identification information of the first electronic device sent by the sending module and a second association relationship, where the second association relationship is an association relationship between the identification information of the first electronic device and the third key;
[0440] The processor 1910 is configured to encrypt the first key using the third key to generate second encrypted data;
[0441] The radio frequency unit 1901 is further configured to transmit the second encrypted data generated by the processing module to the first electronic device via a second link, where the second link is a call link between the first electronic device and the second electronic device.
[0442] In the electronic device provided in the embodiment of the present application, during a voice call with a first electronic device, the identification information of the first electronic device is sent to a server; a third key sent by the server based on the identification information of the first electronic device and a second association relationship is received; the second electronic device encrypts a first key with the third key to generate second encrypted data; and the second encrypted data is transmitted to the first electronic device through a second link. In this way, with the solution of the present application, the server only needs to send an encryption key to the second electronic device. Therefore, even if an attacker attacks the server, the decryption key cannot be obtained, and the second encrypted data cannot be decrypted to obtain the first key, and further the first encrypted data cannot be decrypted with the first key data to obtain voice data, thereby improving the security of the voice data during the voice call.
[0443] It should be understood that in the embodiment of the present application, the input unit 1904 may include a graphics processing unit (GPU) 19041 and a microphone 19042. The graphics processing unit 19041 processes the image data of a static picture or a video obtained by an image capture device (such as a camera) in a video capture mode or an image capture mode. The display unit 1906 may include a display panel 19061, and the display panel 19061 may be configured in the form of a liquid crystal display, an organic light-emitting diode, or the like. The user input unit 1907 includes at least one of a touch panel 19071 and other input devices 19072. The touch panel 19071 is also referred to as a touch screen. The touch panel 19071 may include two parts: a touch detection device and a touch controller. The other input devices 19072 may include, but are not limited to, a physical keyboard, function keys (such as volume control keys, switch keys, etc.), a trackball, a mouse, and a joystick, which will not be elaborated here.
[0444] The memory 1909 can be used to store software programs and various data. The memory 1909 may mainly include a first storage area for storing programs or instructions and a second storage area for storing data. Among them, the first storage area may store an operating system, application programs or instructions required for at least one function (such as a sound playback function, an image playback function, etc.). In addition, the memory 1909 may include a volatile memory or a non-volatile memory, or the memory 1909 may include both a volatile and a non-volatile memory. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), a static random access memory (SRAM), a dynamic random access memory (DRAM), a synchronous dynamic random access memory (SDRAM), a double data rate synchronous dynamic random access memory (DDR SDRAM), an enhanced synchronous dynamic random access memory (ESDRAM), a synch link dynamic random access memory (SLDRAM), and a direct rambus random access memory (DRRAM). The memory 1909 in the embodiments of the present application includes, but is not limited to, these and any other suitable types of memories.
[0445] The processor 1910 may include one or more processing units; optionally, the processor 1910 integrates an application processor and a modem processor. Among them, the application processor mainly processes operations related to the operating system, user interface, and application programs, etc., and the modem processor mainly processes wireless communication signals, such as a baseband processor. It can be understood that the above modem processor may not be integrated into the processor 1910 either.
[0446] The embodiments of the present application also provide a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, it implements each process of the data processing method embodiment described above and can achieve the same technical effect. To avoid repetition, it will not be elaborated here.
[0447] Among them, the processor is the processor in the electronic device described in the above embodiments. The readable storage medium includes computer-readable storage media such as computer read-only memory ROM, random access memory RAM, magnetic disks, or optical discs, etc.
[0448] Another embodiment of the present application provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor. The processor is used to run programs or instructions to implement each process of the above data processing method embodiment and can achieve the same technical effects. To avoid repetition, it will not be elaborated here.
[0449] It should be understood that the chip mentioned in the embodiments of the present application can also be referred to as a system-on-chip, system chip, chip system, or system-on-chip, etc.
[0450] The embodiments of the present application provide a computer program product. The program product is stored in a storage medium and is executed by at least one processor to implement each process of the above data processing method embodiment and can achieve the same technical effects. To avoid repetition, it will not be elaborated here.
[0451] It should be noted that in this article, the term "including", "comprising", or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article, or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such process, method, article, or device. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of additional identical elements in the process, method, article, or device including that element. In addition, it should be pointed out that the methods and devices in the embodiments of the present application are not limited to performing functions in the order shown or discussed. They may also include performing functions in a substantially simultaneous manner or in the reverse order according to the functions involved. For example, the described method may be executed in a different order than described, and various steps may be added, omitted, or combined. Additionally, features described with reference to certain examples may be combined in other examples.
[0452] Through the description of the above embodiments, those skilled in the art can clearly understand that the above embodiment methods can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases, the former is a better implementation. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art can be embodied in the form of a computer software product. The computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to enable a terminal (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods described in various embodiments of the present application.
[0453] The embodiments of the present application have been described above in conjunction with the accompanying drawings. However, the present application is not limited to the above specific embodiments. The above specific embodiments are merely illustrative and not restrictive. Under the inspiration of the present application, those of ordinary skill in the art can also make many forms without departing from the purpose of the present application and the scope protected by the claims, and all of them belong to the protection scope of the present application.
Claims
1. A data processing method, executed by a first electronic device, characterized in that: The method comprises: During a voice call with a second electronic device, the first electronic device receives first encrypted data forwarded by a server through a first link, where the first encrypted data is generated after the second electronic device encrypts voice data using a first key, and the first link is a data link established between the first electronic device and the second electronic device through the server; The first electronic device obtains the voice data based on the second key in the first electronic device and the first encrypted data; The second key is generated by the first electronic device, or the second key is generated by the second electronic device; in the case where the second key is generated by the second electronic device, the second key is sent by the second electronic device to the first electronic device through a second link, and the second link is a call link between the first electronic device and the second electronic device.
2. The method according to claim 1, characterized in that: In the case where the first key and the second key are generated by the second electronic device, before the first electronic device receives the first encrypted data forwarded by the server through the first link, the method further includes: The first electronic device receives the second key sent by the second electronic device through the second link; The first electronic device stores the second key in a key storage area of the first electronic device.
3. The method according to claim 2, characterized in that The first key and the second key are symmetric keys or asymmetric keys; when the first key and the second key are asymmetric keys, the first key and the second key are respectively a public key and a private key in the asymmetric key; The first electronic device obtains the voice data based on the second key and the first encrypted data, including: The first electronic device uses the second key stored in the first electronic device to decrypt the first encrypted data to obtain voice data.
4. The method according to claim 1, characterized in that In the case where the first key and the second key are generated by the first electronic device, before the first electronic device receives the first encrypted data forwarded by the server through the first link, the method further includes: The first electronic device generates a first key pair, the first key pair including the first key and the second key, the first key and the second key being a public key and a private key respectively; The first electronic device sends the identification information of the first electronic device and the first key to the server through the second link, so that the server establishes a first association relationship between the identification information of the first electronic device and the first key; The first electronic device obtains voice data based on the second key and the first encrypted data, including: The first electronic device uses the second key to decrypt the first encrypted data to obtain voice data.
5. The method according to claim 1, characterized in that In the case where the first key is generated by the second electronic device and the second key is generated by the first electronic device, before the first electronic device receives the first encrypted data forwarded by the server through the first link, the method further includes: The first electronic device receives second encrypted data sent by the second electronic device through the second link, where the second encrypted data is generated after the second electronic device encrypts the first key using a third key, where the third key and the second key are respectively a public key and a private key in a second key pair pre-stored in the first electronic device; The first electronic device obtains the voice data based on the second key in the first electronic device and the first encrypted data, including: The first electronic device uses the second key to decrypt the second encrypted data to obtain the first key; The first electronic device uses the first key to decrypt the first encrypted data to obtain voice data.
6. The method according to claim 5, characterized in that Before the first electronic device receives the first encrypted data forwarded by the server through the first link, the method further includes: The first electronic device generates a second key pair, the second key pair including the second key and the third key, the second key and the third key being a private key and a public key respectively; The first electronic device sends the identification information of the first electronic device and the third key to the server through the second link, so that the server establishes a second association relationship between the identification information of the first electronic device and the third key.
7. The method according to any one of claims 1 to 6, characterized in that: During a voice call between the first electronic device and the second electronic device, the method further includes: The first electronic device receives the voice data sent by the second electronic device through the second link.
8. A data processing method, executed by a second electronic device, characterized in that: The method comprises: During a voice call with a first electronic device, the second electronic device sends identification information of the first electronic device to a server; The second electronic device receives the first key sent by the server based on the identification information of the first electronic device and a first association relationship, where the first association relationship is an association relationship between the identification information of the first electronic device and the first key; The second electronic device encrypts the voice data using the first key to generate first encrypted data; The second electronic device sends the first encrypted data to the server through a first link, where the first link is a data link established between the first electronic device and the second electronic device through the server.
9. The method according to claim 8, characterized in that After the second electronic device sends the identification information of the first electronic device to the server, the method further includes: The second electronic device receives the verification information of the server sent by the server based on the identification information of the first electronic device; The second electronic device encrypts the voice data using the first key to generate first encrypted data, including: When the second electronic device passes the security verification of the server based on the verification information, the second electronic device encrypts the first data using the first key to generate first encrypted data.
10. A data processing method, executed by a second electronic device, characterized in that: The method comprises: During a voice call with a first electronic device, the second electronic device sends identification information of the first electronic device to a server; The second electronic device receives a third key sent by the server based on the identification information of the first electronic device and a second association relationship, where the second association relationship is an association relationship between the identification information of the first electronic device and the third key; The second electronic device encrypts the first key using the third key to generate second encrypted data; The second electronic device transmits the second encrypted data to the first electronic device via a second link, where the second link is a call link between the first electronic device and the second electronic device.
11. A data processing device, characterized in that: The device comprises: a transceiver module, used to receive first encrypted data forwarded by a server through a first link during a voice call with a second electronic device, wherein the first encrypted data is generated after the second electronic device encrypts voice data using a first key, and the first link is a data link established between the first electronic device and the second electronic device through the server; a processing module, configured to obtain the voice data based on a second key in the first electronic device and the first encrypted data received by the transceiver module; The second key is generated by the first electronic device; or the second key is generated by the second electronic device; in the case where the second key is generated by the second electronic device, the second key is sent by the second electronic device to the first electronic device via a second link, and the second link is a call link between the first electronic device and the second electronic device.
12. The device according to claim 11, characterized in that In the case where the first key and the second key are generated by the second electronic device, the transceiver module is further used to receive the second key sent by the second electronic device through the second link before receiving the first encrypted data forwarded by the server through the first link; The processing module is further configured to store the second key in a key storage area of the first electronic device.
13. The device according to claim 12, characterized in that The first key and the second key are symmetric keys or asymmetric keys; when the first key and the second key are asymmetric keys, the first key and the second key are respectively a public key and a private key in the asymmetric key; The processing module is specifically used for: The first encrypted data is decrypted using the second key stored in the first electronic device to obtain voice data.
14. The device according to claim 11, characterized in that In the case where the first key and the second key are generated by the first electronic device, the processing module is further used to generate a first key pair before receiving the first encrypted data forwarded by the server through the first link, the first key pair including the first key and the second key, the first key and the second key being a public key and a private key respectively; The transceiver module is further used to send the identification information of the first electronic device and the first key to the server through the second link, so that the server establishes a first association relationship between the identification information of the first electronic device and the first key; The processing module is specifically used for: The first encrypted data is decrypted using the second key to obtain voice data.
15. The device according to claim 11, characterized in that The first key is generated by the second electronic device, and when the second key is generated by the first electronic device, the transceiver module is further used to receive second encrypted data sent by the second electronic device through the second link before receiving the first encrypted data forwarded by the server through the first link, the second encrypted data is generated by the second electronic device after encrypting the first key with a third key, and the third key and the second key are respectively a public key and a private key in a second key pair pre-stored in the first electronic device; The processing module is specifically used for: Decrypting the second encrypted data using the second key to obtain the first key; The first encrypted data is decrypted using the first key to obtain voice data.
16. The device according to claim 15, characterized in that The processing module is further configured to generate a second key pair before receiving the first encrypted data forwarded by the server through the first link, wherein the second key pair includes the second key and the third key, wherein the second key and the third key are a private key and a public key respectively; The transceiver module is further used to send the identification information of the first electronic device and the third key to the server through the second link, so that the server establishes a second association relationship between the identification information of the first electronic device and the third key.
17. The device according to any one of claims 11 to 16, characterized in that During the voice call between the first electronic device and the second electronic device, the transceiver module is further used to: The voice data sent by the second electronic device is received through the second link.
18. A data processing device, characterized in that: The device comprises: A sending module, used for sending identification information of the first electronic device to a server during a voice call with the first electronic device; a receiving module, configured to receive a first key sent by the server based on the identification information of the first electronic device and a first association relationship sent by the sending module, wherein the first association relationship is an association relationship between the identification information of the first electronic device and the first key; A processing module, configured to encrypt the voice data using the first key received by the receiving module to generate first encrypted data; The sending module is further used to send the first encrypted data generated by the processing module to the server through a first link, where the first link is a data link established between the first electronic device and the second electronic device through the server.
19. The device according to claim 18, characterized in that The receiving module is further configured to receive verification information of the server sent by the server based on the identification information of the first electronic device after sending the identification information of the first electronic device to the server; The processing module is specifically used for: In a case where the verification information passes the security verification of the server, the first data is encrypted using the first key to generate first encrypted data.
20. A data processing device, characterized in that: The device comprises: A sending module, used for sending identification information of the first electronic device to a server during a voice call with the first electronic device; a receiving module, configured to receive a third key sent by the server based on the identification information of the first electronic device and a second association relationship sent by the sending module, wherein the second association relationship is an association relationship between the identification information of the first electronic device and the third key; A processing module, configured to encrypt the first key using the third key to generate second encrypted data; The sending module is further used to transmit the second encrypted data generated by the processing module to the first electronic device through a second link, and the second link is a call link between the first electronic device and the second electronic device.
21. An electronic device, characterized in that: The method comprises a processor and a memory, wherein the memory stores a program or instruction that can be run on the processor, and when the program or instruction is executed by the processor, the steps of the data processing method according to any one of claims 1 to 7 are implemented.
22. An electronic device, characterized in that: The method comprises a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the programs or instructions are executed by the processor, the steps of the data processing method according to claim 8 or 9 are implemented.
23. An electronic device, characterized in that: The method comprises a processor and a memory, wherein the memory stores a program or instruction that can be run on the processor, and when the program or instruction is executed by the processor, the steps of the data processing method according to claim 10 are implemented.