Data transmission method, system and device and readable storage medium

By using read-only storage unit and private key signature technology in the terminal devices of IoT devices, the first and second signatures of data packets are generated and verified, and the security and cost of IoT devices are both solved, and data transmission with high security and low cost are achieved.

CN120165892APending Publication Date: 2025-06-17BEIJING QISHENG SCIENCE AND TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311734237.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-15
Publication Date
2025-06-17

AI Technical Summary

Technical Problem

Data transmission of IoT devices is difficult to take into account both security and cost. Directly sending data has the problem of low security, while sending data through a dedicated network has the problem of high transmission cost.

Method used

By storing the preset private key using a read-only storage unit in the terminal device, a first signature is signed and a second signature is generated in combination with the first signature in the last sent data packet to form a target data packet and sent to the verification platform for source verification and continuity verification.

Benefits of technology

It is realized that without setting up an additional dedicated network, ensuring high security and low cost of data transmission, and quickly and efficiently verifying the authenticity and continuity of data packets through the first signature and the second signature.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120165892A_ABST
    Figure CN120165892A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a data transmission method, system and device and a readable storage medium, and relates to the technical field of computers. On one hand, the authenticity of the target data set can be ensured through the first signature corresponding to the target data set. On the other hand, according to the embodiment of the invention, the continuity among the data packets can be verified through the second signature and the first signature in the data packet sent last time. Therefore, the data authenticity of each data packet and the continuity among the data packets can be quickly and effectively verified through the first signature and the second signature in the target data packet, an additional private network does not need to be arranged, and high-security and low-cost data transmission is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular, to a data transmission method, system, device, and readable storage medium. Background Art

[0002] Currently, with the continuous increase in the number of Internet of Things (IoT) devices, the data security of IoT devices faces challenges in all aspects. Among them, the trustworthy transmission of IoT device data is an important factor in ensuring data security.

[0003] In the related art, IoT devices generally perform data transmission by directly sending or through a dedicated network. However, the method of directly sending data has low security although the transmission cost is low, while the method of sending data through a dedicated network has high security but high transmission cost. Therefore, how to perform data transmission with high security and low transmission cost is an urgent problem to be solved currently. Summary of the Invention

[0004] In view of this, embodiments of this application provide a data transmission method, system, device, and readable storage medium to achieve high-security and low-cost data transmission.

[0005] In a first aspect, a data transmission method is provided. The method is applied to a terminal device and includes:

[0006] Obtain a target data group to be sent.

[0007] At least sign the target data group according to a preset private key stored in a read-only storage unit to generate a first signature.

[0008] Generate a target data packet according to the target data group, the first signature, and a second signature, where the second signature at least includes the first signature in the previously sent data packet.

[0009] Send the target data packet to a verification platform so that the verification platform performs source verification and continuity verification on the target data packet.

[0010] In some embodiments, each field in the target data packet at least includes header information, data segment information, and the first signature from front to back, and the data segment information at least includes the target data group.

[0011] In some embodiments, generating the target data packet according to the target data group, the first signature, and the second signature includes:

[0012] Write the second signature into a predetermined field before the first signature to generate the target data packet.

[0013] In some embodiments, the second signature includes the first signature in packets sent multiple times in history, and the packets sent multiple times in history include the last sent packet.

[0014] The second signature is determined through the following steps:

[0015] Perform a merging process on the first signatures in the packets sent multiple times in history to generate merged data.

[0016] Sign the merged data with a preset private key to generate the second signature.

[0017] In some embodiments, the performing a merging process on the first signatures in the packets sent multiple times in history to generate merged data includes:

[0018] According to the order of the packets sent multiple times in history, merge the first signatures in the packets sent multiple times in history one by one to generate the merged data.

[0019] In some embodiments, the performing a merging process on the first signatures in the packets sent multiple times in history to generate merged data includes:

[0020] According to the order of the packets sent multiple times in history, perform grouped merging on the first signatures in the packets sent multiple times in history to determine the grouped merging result.

[0021] Perform further merging on each of the grouped merging results to generate the merged data.

[0022] In some embodiments, the performing a merging process on the first signatures in the packets sent multiple times in history to generate merged data includes:

[0023] Obtain historical intermediate results.

[0024] Based on the historical intermediate results, perform a merging process on the first signatures in the packets sent multiple times in history to generate merged data.

[0025] In some embodiments, the method further includes:

[0026] Send a key acquisition request to the verification platform.

[0027] Receive and decrypt the private key data returned by the verification platform to obtain the preset private key.

[0028] In some embodiments, the second signature further includes the first signature corresponding to the target data group.

[0029] In a second aspect, a data transmission method is provided. The method is applied to a verification platform, and the method includes:

[0030] Receive a target data packet sent by a receiving terminal device, where the target data packet includes at least a target data group, a first signature, and a second signature. The first signature is obtained by the terminal device signing at least the target data group according to a preset private key, and the second signature includes at least the first signature in the data packet sent by the terminal device last time.

[0031] Verify the source of the target data packet according to a preset public key and the first signature, and determine the data source verification result.

[0032] Verify the continuity of the target data packet according to the first signature in at least one historically received data packet and the second signature in the target data packet, and determine the data continuity verification result.

[0033] In some embodiments, the verifying the continuity of the target data packet according to the first signature in at least one historically received data packet and the second signature in the target data packet, and determining the data continuity verification result includes:

[0034] Determine the first signature in at least one historically received data packet.

[0035] In response to the first signature in at least one historically received data packet including the second signature in the target data packet, determine that there is continuity between the target data packet and at least one historically received data packet.

[0036] In some embodiments, the method further includes:

[0037] Receive a key acquisition request sent by the terminal device.

[0038] Determine the public-private key pair corresponding to the key acquisition request, where the public-private key pair includes the preset private key and the preset public key.

[0039] Perform an encryption process on the preset private key to generate private key data.

[0040] Send the private key data to the terminal device.

[0041] In a third aspect, a data transmission system is provided. The system includes at least one terminal device and at least one verification platform, and the terminal device includes a read-only storage unit.

[0042] Wherein, the terminal device is configured to execute the data transmission method as described in the first aspect.

[0043] The verification platform is configured to execute the data transmission method as described in the second aspect.

[0044] In some embodiments, the verification platform includes a management platform and a service platform, and target data packets are transmitted between each management platform and each service platform through a network connection.

[0045] Fourthly, a data transmission device is provided, and the device is applied to a terminal device. The device includes:

[0046] A target data group acquisition module, configured to acquire a target data group to be sent.

[0047] A first signature module, configured to sign at least the target data group according to a preset private key stored in a read-only storage unit to generate a first signature.

[0048] A target data packet generation module, configured to generate a target data packet according to the target data group, the first signature, and a second signature, where the second signature at least includes the first signature in the previously sent data packet.

[0049] A target data packet sending module, configured to send the target data packet to a verification platform so that the verification platform performs source verification and continuity verification on the target data packet.

[0050] In some embodiments, each field in the target data packet at least includes header information, data segment information, and the first signature from front to back, and the data segment information at least includes the target data group.

[0051] In some embodiments, the target data packet generation module is specifically configured to:

[0052] Write the second signature into a predetermined field before the first signature to generate the target data packet.

[0053] In some embodiments, the second signature includes the first signatures in multiple historical sent data packets, and the multiple historical sent data packets include the previously sent data packet.

[0054] The second signature is determined by the following modules:

[0055] A merging processing module, configured to perform a merging process on the first signatures in the multiple historical sent data packets to generate merged data.

[0056] A second signature module, configured to sign the merged data with a preset private key to generate the second signature.

[0057] In some embodiments, the merging processing module is specifically configured to:

[0058] Merge the first signatures in the data packets sent multiple times historically one by one according to the order of the data packets sent multiple times historically to generate the merged data.

[0059] In some embodiments, the merging processing module is specifically configured to execute:

[0060] Group and merge the first signatures in the data packets sent multiple times historically according to the order of the data packets sent multiple times historically to determine the result of group merging.

[0061] Further merge each of the group merging results to generate the merged data.

[0062] In some embodiments, the merging processing module is specifically configured to execute:

[0063] Obtain historical intermediate results.

[0064] Based on the historical intermediate results, perform a merging process on the first signatures in the data packets sent multiple times historically to generate merged data.

[0065] In some embodiments, the apparatus further includes:

[0066] A key acquisition request sending module, configured to execute sending a key acquisition request to a verification platform.

[0067] A private key data processing module, configured to execute receiving and decrypting the private key data returned by the verification platform to obtain the preset private key.

[0068] In some embodiments, the second signature further includes the first signature corresponding to the target data group.

[0069] In a fifth aspect, a data transmission apparatus is provided. The apparatus is applied to a verification platform and includes:

[0070] A target data packet receiving module, configured to execute receiving a target data packet sent by a terminal device, where the target data packet includes at least a target data group, a first signature, and a second signature, the first signature is obtained by the terminal device signing at least the target data group according to a preset private key, and the second signature includes at least the first signature in the data packet sent by the terminal device last time.

[0071] A source verification module, configured to execute source verification on the target data packet according to a preset public key and the first signature to determine a data source verification result.

[0072] A continuity verification module, configured to perform continuity verification on the target data packet according to a first signature in at least one packet received historically and a second signature in the target data packet, and determine a data continuity verification result.

[0073] In some embodiments, the continuity verification module is specifically configured to perform:

[0074] Determine a first signature in at least one packet received historically.

[0075] In response to the first signature in the at least one packet received historically including the second signature in the target data packet, determine that there is continuity between the target data packet and the at least one packet received historically.

[0076] In some embodiments, the apparatus further includes:

[0077] A key acquisition request receiving module, configured to receive a key acquisition request sent by the terminal device.

[0078] A public-private key pair determination module, configured to determine a public-private key pair corresponding to the key acquisition request, where the public-private key pair includes the preset private key and the preset public key.

[0079] An encryption module, configured to perform encryption processing on the preset private key to generate private key data.

[0080] A key sending module, configured to send the private key data to the terminal device.

[0081] In a sixth aspect, an embodiment of the present application provides a computer-readable storage medium, on which computer program instructions are stored, and when the computer program instructions are executed by a processor, the method described in the first aspect is implemented.

[0082] In one aspect, the embodiment of the present application can ensure the authenticity of the target data group through the first signature corresponding to the target data group. In another aspect, since the second signature at least includes the first signature in the packet sent last time, the embodiment of the present application can verify the continuity between each packet through the second signature and the first signature in the packet sent last time. That is, if the second signature in the target data packet received by the verification platform at least includes the first signature in the packet sent by the terminal device last time, it indicates that the target data packet received by the verification platform is continuous with the packets received historically. Therefore, the embodiment of the present application can quickly and effectively verify the data authenticity of each packet and the continuity between each packet through the first signature and the second signature in the target data packet, without setting up an additional dedicated network, realizing high-security and low-cost data transmission. Description of the Drawings

[0083] Through the following description of the embodiments of the present application with reference to the accompanying drawings, the above and other objects, features, and advantages of the embodiments of the present application will become clearer. In the drawings:

[0084] Figure 1 It is a schematic diagram of the data transmission system according to the embodiment of the present application;

[0085] Figure 2 It is a flowchart of the data transmission method executed on the terminal device side according to the embodiment of the present application;

[0086] Figure 3 It is a flowchart of the terminal device according to the embodiment of the present application requesting to obtain a preset private key from the verification platform;

[0087] Figure 4 It is a schematic diagram of the data packet structure according to the embodiment of the present application;

[0088] Figure 5 It is a flowchart of the terminal device generating a second signature according to the embodiment of the present application;

[0089] Figure 6 It is a schematic diagram of another data packet structure according to the embodiment of the present application;

[0090] Figure 7 It is a schematic flowchart of generating merged data according to the embodiment of the present application;

[0091] Figure 8 It is a schematic flowchart of another method for generating merged data according to the embodiment of the present application;

[0092] Figure 9 It is a flowchart of the data transmission method executed on the verification platform side according to the embodiment of the present application;

[0093] Figure 10 It is a flowchart of the verification platform issuing a preset private key to the terminal device according to the embodiment of the present application;

[0094] Figure 11 It is a schematic diagram of the structure of the data transmission device applied to the terminal device side according to the embodiment of the present application;

[0095] Figure 12 It is a schematic diagram of the structure of the device for generating a second signature on the terminal device side according to the embodiment of the present application;

[0096] Figure 13 It is a schematic diagram of the structure of the data transmission device applied to the verification platform side according to the embodiment of the present application;

[0097] Figure 14 It is a schematic diagram of the structure of the electronic device according to the embodiment of the present application. Detailed implementation manners

[0098] The present application will be described based on embodiments, but the present application is not limited to these embodiments. In the following detailed description of the present application, some specific details are described in detail. Those skilled in the art can fully understand the present application without the description of these details. In order to avoid obscuring the essence of the present application, well-known methods, processes, procedures, components, and circuits are not described in detail.

[0099] In addition, those of ordinary skill in the art should understand that the drawings provided herein are for illustrative purposes only, and the drawings are not necessarily drawn to scale.

[0100] Unless the context clearly requires otherwise, words such as "including" and "comprising" in the entire application document should be construed as having an inclusive meaning rather than an exclusive or exhaustive meaning; that is, it is the meaning of "including but not limited to".

[0101] In the description of the present application, it should be understood that terms such as "first" and "second" are only used for descriptive purposes and cannot be construed as indicating or implying relative importance. In addition, in the description of the present application, unless otherwise specified, the meaning of "a plurality" is two or more. In addition, for the solutions described in this specification and the embodiments, if they involve personal information processing, they will be processed on the premise of having a legal basis (such as obtaining the consent of the personal information subject, or being necessary for performing a contract, etc.), and will only be processed within the specified or agreed scope. If the user refuses to process personal information other than the necessary information required for the basic functions, it will not affect the user's use of the basic functions.

[0102] Currently, with the development of Internet technology, data interaction can be carried out between electronic devices through a network, thereby forming the Internet of Things, and each electronic device in the Internet of Things is also an Internet of Things device.

[0103] Taking shared devices as an example (shared devices can be any shared devices such as shared bicycles, shared electric bicycles, shared power banks, or shared cars), shared devices are currently a typical type of Internet of Things device. The service platform (Platform as a Service, PaaS) of shared devices can set up multiple shared devices offline and provide them for any user to use. After the shared device is set up, it can maintain a network communication connection with the service platform so that the service platform can send data or instructions to the shared device through the network communication connection. Correspondingly, the shared device can also feedback corresponding data (such as location information, power information, or other relevant information) to the service platform through the network communication connection.

[0104] Of course, Internet of Things devices are not limited to shared devices, and Internet of Things technology has currently been applied in a variety of scenarios.

[0105] With the continuous increase in the number of Internet of Things (IoT) devices, the data security of IoT devices faces challenges in all aspects. To effectively manage each IoT device, in addition to sending data to its corresponding service platform, the IoT device also needs to send the data to relevant management platforms to meet the compliance operation of the IoT device.

[0106] In this process, the trusted transmission of data of IoT devices is an important factor in ensuring data security. That is to say, the IoT device needs to ensure the authenticity of the data sent, so that the relevant management platforms can effectively manage the IoT devices.

[0107] In related technologies, IoT devices generally perform data transmission by directly sending or sending through a dedicated network, where the dedicated network can be an Access Point Name (APN) dedicated network. However, the method of directly sending data has low security although the transmission cost is low, while the method of sending data through a dedicated network has high security but high transmission cost. Therefore, how to perform data transmission with high security and low transmission cost is an urgent problem to be solved at present.

[0108] To solve the above problems, an embodiment of the present application provides a data transmission method and a data transmission system applying the data transmission method. Specifically, as Figure 1 shown, the data transmission system of the embodiment of the present application may include at least one terminal device 11 and at least one verification platform 12. Among them, the terminal device 11 may be a smart phone, a tablet computer, a personal computer (PC), and any of the above IoT devices, etc. The verification platform 12 may be a single server, a server cluster configured in a distributed manner, or a cloud server. The terminal device 11 includes a read-only storage unit 111, and the read-only storage unit 111 may be a One Time Programmable (OTP) module, an Electrically Programmable Read-Only Memory Fuse (eFUSE), or other applicable read-only storage units. The processor of the terminal device 11 may be connected to the read-only storage unit 111 through a serial port, a Serial Peripheral Interface (SPI), or a Controller Area Network (CAN), etc. Data transmission can be performed between each terminal device 11 and each verification platform 12 through a network.

[0109] Specifically, during the data transmission process, the terminal device 11 can be configured to obtain the target data group to be sent, and sign the target data group according to the preset private key stored in the read-only storage unit 111 to generate the first signature. Further, the terminal device 11 can generate a target data packet based on the target data group, the first signature, and the second signature, and send the target data packet to the verification platform 12 so that the verification platform performs source verification and continuity verification on the target data packet. Wherein, the second signature at least includes the first signature in the previously sent data packet. Additionally, since the read-only storage unit 111 has the characteristic of being unchangeable, storing the preset private key in the read-only storage unit 111 by the terminal device 11 can effectively ensure the authenticity of the preset private key, thereby ensuring the authenticity of the first signature.

[0110] Correspondingly, the verification platform 12 can be configured to receive the target data packet sent by the terminal device 11, and perform source verification on the target data packet according to the preset public key and the first signature to determine the data source verification result. At the same time, the verification platform 12 can perform continuity verification on the target data packet according to the first signature in at least one previously received data packet and the second signature in the target data packet to determine the data continuity verification result. Wherein, the target data packet at least includes the target data group, the first signature, and the second signature, the first signature is obtained by the terminal device 11 signing the target data group according to the preset private key, and the second signature at least includes the first signature in the data packet previously sent by the terminal device 11.

[0111] It can be seen that, on the one hand, the embodiment of the present application can ensure the authenticity of the target data group through the first signature corresponding to the target data group. On the other hand, since the second signature at least includes the first signature in the previously sent data packet, the embodiment of the present application can verify the continuity between each data packet through the second signature and the first signature in the previously sent data packet. That is to say, if the second signature in the target data packet received by the verification platform 12 at least includes the first signature in the data packet previously sent by the terminal device 11, it indicates that the target data packet received by the verification platform 12 is continuous with the previously received data packets. Therefore, through the first signature and the second signature in the target data packet, the embodiment of the present application can quickly and effectively verify the data authenticity of each data packet and the continuity between each data packet, without setting up an additional dedicated network, achieving high-security and low-cost data transmission.

[0112] In an alternative embodiment, the verification platform 12 may include the above-mentioned service platform and related management platforms. The number of each service platform and each management platform may be one or multiple, and each management platform and each service platform can transmit the target data packet through network connection.

[0113] In Figure 1For example, each terminal device can send the target data packet to each management platform and each service platform simultaneously, or only send the target data packet to one type of verification platform (management platform or service platform). If the terminal device only sends the target data packet to one type of verification platform, the verification platform that receives the target data packet can send the target data packet to the other type of verification platform through a network connection. For example, if the terminal device only sends the target data packet to the service platform, the service platform can send the target data packet to the management platform through the network connection with the management platform, so that the management platform can also verify the target data packet.

[0114] Through the information transfer between various verification platforms, the embodiments of the present application can effectively increase the data transfer methods and improve the system flexibility.

[0115] Next, the data transmission method of the embodiments of the present application will be described in detail in combination with specific implementation manners. As Figure 2 shown, the data transmission method executed on the terminal device side may include the following steps:

[0116] In step S110, obtain the target data group to be sent.

[0117] Among them, the target data group may include one or more pieces of data that the terminal device needs to send to the verification platform. Taking the shared electric bicycle as an example, the shared electric bicycle may need to send one or more of the information such as power information, vehicle condition information, and location information to the verification platform. The shared electric bicycle can combine one or more of the above information into a data group before sending the data to generate the target data group.

[0118] In step S120, at least sign the target data group according to the preset private key stored in the read-only storage unit to generate the first signature.

[0119] Among them, the read-only storage unit may be an OTP, eFUSE or other applicable read-only storage unit, and the preset private key stored in the storage unit may be issued by the verification platform or obtained by the terminal device requesting the verification platform.

[0120] In an alternative embodiment, as Figure 3 shown, the process of the terminal device requesting to obtain the preset private key from the verification platform may include the following steps:

[0121] In step S210, send a key acquisition request to the verification platform.

[0122] Among them, the key acquisition request may include the device type of the terminal device itself and other relevant information (such as the service platform to which the terminal device belongs and the device number, etc.). After receiving the key acquisition request, the verification platform may determine the public-private key pair corresponding to the key acquisition request according to the information in the key acquisition request, and encrypt and send the preset private key in the public-private key pair to the terminal device. Among them, the encryption of the preset private key may be any applicable encryption method (such as symmetric encryption or asymmetric encryption, etc.).

[0123] In step S220, receive and decrypt the private key data returned by the verification platform to obtain the preset private key.

[0124] Furthermore, after obtaining the preset private key, the terminal device may store the preset private key in the read-only storage unit, and sign the target data group with the preset private key to ensure the security of the data source.

[0125] In step S130, generate a target data packet according to the target data group, the first signature, and the second signature.

[0126] Among them, the second signature can be used to verify the continuity between the target data packet and other already sent data packets. The second signature at least includes the first signature in the previously sent data packet. Specifically, during the verification process of the verification platform, if the second signature in the target data packet received by the verification platform at least includes the first signature in the data packet previously sent by the terminal device, it indicates that the target data packet received by the verification platform is continuous with the previously received data packets. Otherwise, it proves that there are missing data packets between the data packets.

[0127] In step S140, send the target data packet to the verification platform so that the verification platform can perform source verification and continuity verification on the target data packet.

[0128] In one aspect, the embodiment of the present application can ensure the authenticity of the target data group through the first signature corresponding to the target data group. On the other hand, since the second signature at least includes the first signature in the previously sent data packet, the embodiment of the present application can verify the continuity between the data packets through the second signature and the first signature in the previously sent data packet. That is, if the second signature in the target data packet received by the verification platform at least includes the first signature in the data packet previously sent by the terminal device, it indicates that the target data packet received by the verification platform is continuous with the previously received data packets. Therefore, through the first signature and the second signature in the target data packet, the embodiment of the present application can quickly and effectively verify the data authenticity of each data packet and the continuity between the data packets, without setting up an additional dedicated network, realizing high-security and low-cost data transmission.

[0129] In an alternative embodiment, the fields in the target data packet of the embodiments of the present application at least include header information, data segment information, and a first signature from front to back.

[0130] Among them, the data segment information at least includes a target data group. That is to say, the embodiments of the present application can sign the fields before the first signature with a preset private key stored in the read-only storage unit, so that the first signature can ensure the authenticity of the source of the header information and the data segment information (i.e., the target data group).

[0131] In addition, the header information may include a data packet sequence number and a timestamp, and the data segment information at least includes a target data group. Specifically, the data packet sequence number in the header information can be used to identify the order in which the terminal device sends data packets. The verification platform can determine the previous data packet corresponding to the target data packet through the data packet sequence number. The timestamp in the header information can be used to represent the time when the terminal device sends the data packet. The verification platform can also determine the previous data packet corresponding to the target data packet through the timestamp. Of course, the functions of the data packet sequence number and the timestamp in the header information are not limited to determining the order of data packet sending. The embodiments of the present application do not limit other functions of the data packet sequence number and the timestamp.

[0132] It should be noted that, in the embodiments of the present application, the second signature can be written in a predetermined field before the first signature in the target data packet, so that the first signature can ensure the authenticity of the source of the second signature. In addition, the second signature can also be in other positions in the target data packet, and the second signature is separately signed with a preset private key to ensure the authenticity of the source of the second signature.

[0133] In an alternative embodiment, the above step S130 can be executed as: writing the second signature into a predetermined field before the first signature to generate a target data packet.

[0134] Among them, the predetermined field can be any field before the first signature. According to the principle of signature, the first signature is the signature obtained by signing all the fields before itself. That is to say, in the embodiments of the present application, writing the second signature into the predetermined field before the first signature can make the signature range covered by the first signature (i.e., the signed fields corresponding to the first signature) include the second signature, and thus can ensure the authenticity of the source of the second signature.

[0135] For example, as Figure 4 shown, Figure 4 are three data packets with consecutive sending orders. The sending order is data packet 41, data packet 42, and data packet 43 from front to back in sequence (the data packet sequence numbers of each data packet are 411, 421, and 431 respectively). Each data packet includes header information, data segment information, and a first signature. The header information includes a data packet sequence number, a timestamp, and a second signature.

[0136] When generating the target data packet, the embodiment of the present application may write the second signature into a predetermined field before the first signature (for example, Figure 4 writing the second signature into the field where the header information is located), so as to generate the target data packet, and further ensure that in the generated target data packet, the first signature can effectively guarantee the authenticity of the source of the second signature.

[0137] Taking the data packet 42 as an example, when generating the data packet 42 (the data packet 42 at this time is the target data packet), the embodiment of the present application may sign the header information and the data segment information through a preset private key to generate the first signature 423 of the data packet 42. Among them, since the second signature 422 (that is, the first signature 413) is included in the header information, the first signature 423 can effectively guarantee the authenticity of the source of the second signature 422.

[0138] When the verification platform receives the data packet 42 and conducts verification, if it detects that the second signature 422 is the same as the first signature 413, the verification platform may determine that the data packet 42 and the data packet 41 are two consecutive data packets. Correspondingly, if the verification platform detects that the second signature 422 is different from the first signature 413, the verification platform may determine that there is a missing data packet between the data packet 42 and the data packet 41.

[0139] That is to say, in the data packet 41, the second signature 412 is the first signature of the previous data packet of the data packet 41, and the first signature 413 is the second signature 422 of the next data packet (data packet 42). In the data packet 42, the second signature 422 is the first signature 413 of the previous data packet (data packet 41), and the first signature 423 is the second signature 432 of the next data packet (data packet 43). In the data packet 43, the second signature 432 is the first signature 423 of the previous data packet (data packet 42), and the first signature 433 is the second signature of the next data packet of the data packet 43. Therefore, the embodiment of the present application can effectively judge the continuity between the front and rear two data packets by whether the first signature of the previous data packet is consistent with the second signature of the next data packet. In addition, since the first signature can also be used to verify the authenticity of the target data group, the embodiment of the present application can quickly and effectively verify the data authenticity of each data packet and the continuity between each data packet through the first signature and the second signature in the target data packet, without setting up an additional dedicated network, realizing high-security and low-cost data transmission.

[0140] It should be noted that Figure 4 This is only an example of the embodiment of the present application. In practical applications, the predetermined field may be any field before the first signature. Taking the data packet 42 as an example, the predetermined field may also be between the header information and the data segment information or between the data segment information and the first signature 423.

[0141] In an alternative embodiment, the second signature may include the first signature in the data packets sent multiple times in history, where the data packets sent multiple times in history include the last sent data packet. Further, as Figure 5 shown, the second signature in the embodiment of the present application may be determined through the following steps:

[0142] In step S310, the first signatures in the data packets sent multiple times in history are merged to generate merged data.

[0143] Among them, the data packets sent multiple times in history may be all the data packets sent in history, or a predetermined number of data packets sent in history (such as 50 or 100, etc.). The merging method may include merging one by one, grouped merging, and any other applicable merging methods.

[0144] In step S320, the merged data is signed with a preset private key to generate the second signature.

[0145] Among them, in the embodiment of the present application, the first signatures in the data packets (including the last sent data packet) sent multiple times by the terminal device are merged and signed to generate the second signature in the target data packet. Through the merging method, the embodiment of the present application can make the second signature form a digital signature chain, so as to help the verification platform quickly determine the position of the missing data packet and improve the efficiency of security detection.

[0146] In addition, it should be noted that since the embodiment of the present application needs to sign the merged data with a preset private key to generate the second signature, therefore, the embodiment of the present application has ensured the authenticity of the source of the second signature through the preset private key. That is to say, in this case, the embodiment of the present application does not limit the position of the second signature, which can be in any field before the first signature or in any field after the first signature.

[0147] For example, as Figure 6 shown, Figure 6 are multiple data packets with consecutive sending orders, and the sending order is from the first to the last as data packet 61 - data packet 6i - data packet 6n. Among them, n is any natural number greater than or equal to 3, and i is any natural number between 1 and n. Data packet 61 includes header information, data segment information, first signature 611, and second signature 612. Data packet 6i includes header information, data segment information, first signature 6i1, and second signature 6i2. Data packet 6n includes header information, data segment information, first signature 6n1, and second signature 6n2. The header information of each data packet includes the data packet sequence number and the time stamp.

[0148] When generating the target data packet, the embodiment of the present application may first perform a merging process on the first signatures in the data packets sent multiple times in history to generate merged data, and then sign the merged data with a preset private key to generate a second signature. For Figure 6 example, in data packet 6i, the second signature 6i2 may be a signature obtained by merging and signing the first signature 611 - the first signature 6(i - 1)1. In data packet 6n, the second signature 6n2 may be a signature obtained by merging and signing the first signature 611 - the first signature 6(n - 1)1. It can be seen that through the merging process, the embodiment of the present application can make the second signature form a digital signature chain, which can help the verification platform quickly determine the position of the missing data packet and improve the efficiency of security detection.

[0149] It should be noted that the data packets sent multiple times in history may be all the data packets sent in history, or a predetermined number of data packets sent in history. The merging process may include merging one by one, grouping and merging, and any other applicable merging processes. In addition, since the embodiment of the present application needs to sign the merged data with a preset private key to generate the second signature, the embodiment of the present application has ensured the authenticity of the source of the second signature through the preset private key. That is to say, in this case, the embodiment of the present application does not limit the position of the second signature, which can be in any field before the first signature or in any field after the first signature (for example Figure 6 the second signature in is in the field after the first signature).

[0150] Furthermore, when the verification platform receives Figure 6 the data packet shown and performs verification, it can also verify the authenticity of the target data group through the first signature and judge the continuity between the data packets through the digital signature chain formed by the second signature. Specifically, on the verification platform side, the verification platform can judge the continuity between the received data packets through the digital signature chain corresponding to the second signature in the target data packet and the first signatures in each data packet received in history.

[0151] In an optional implementation manner, for the merging process, the above step S310 may specifically be executed as follows: According to the order of the data packets sent multiple times in history, merge the first signatures in the data packets sent multiple times in history one by one to generate merged data.

[0152] As Figure 7 shown, Figure 7 it includes a total of 4 data packets, namely data packet 01 - data packet 04. In the order of historical sending from first to last, they are data packet 01, data packet 02, data packet 03, and data packet 04. The first signatures in each data packet are signature 71, signature 72, signature 73, and signature 74 in sequence.

[0153] In the process of generating merged data based on the method of merging one by one, the embodiments of the present application can merge the first signatures in each data packet one by one from the earliest to the latest according to the historical sending order, so as to Figure 7 For example, the embodiments of the present application can first merge signature 71 and signature 72 to obtain signature 71-72, then merge signature 71-72 and signature 73 to obtain signature 71-72-73, and then further merge signature 71-72-73 and signature 74 to obtain signature 71-72-73-74.

[0154] It can be seen that through the method of merging one by one, the embodiments of the present application can form a digital signature chain for the first signatures of data packets sent multiple times in history, so as to help the verification platform quickly determine the position of missing data packets and improve the efficiency of security detection.

[0155] In an alternative embodiment, for the method of merging processing, step S310 above can also be performed as follows: according to the order of data packets sent multiple times in history, group and merge the first signatures in the data packets sent multiple times in history, determine the result of group merging, and further merge each result of group merging to generate merged data.

[0156] Such as Figure 8 shown, Figure 8 There are a total of 5 data packets including data packet 01 - data packet 05. In the historical sending order from the earliest to the latest, they are data packet 01, data packet 02, data packet 03, data packet 04, and data packet 05. The first signatures in each data packet are signature 71, signature 72, signature 73, signature 74, and signature 75 in sequence.

[0157] In the process of generating merged data based on the method of group merging, the embodiments of the present application can group and merge the first signatures in each data packet in the historical sending order from the earliest to the latest according to the preset grouping rules. Taking Figure 8 as an example, Figure 8 The corresponding grouping rule is pairwise merging. Specifically, the embodiments of the present application can merge signature 71 and signature 72 to obtain signature 71-72, and merge signature 73 and signature 74 to obtain signature 73-74. Further, the embodiments of the present application can merge signature 71-72 and signature 73-74 to obtain signature 71-72-73-74.

[0158] Further, according to the pairwise grouping rule, it can be understood that if the last data packet is an odd-numbered data packet, there will be no data packet to be grouped with it (such as data packet 05). In this case, the embodiments of the present application can determine the merged signature of all data packets before the last data packet (such as Figure 8After the signature 71-72-73-74) in it, the first signature of the last data packet is separately merged with the combined signature corresponding to the previous data packet to determine the combined data. Figure 8 For example, in the embodiment of the present application, after determining the signature 71-72-73-74, the signature 75 can be separately merged with the signature 71-72-73-74 to determine the signature 71-72-73-74-75.

[0159] It can be seen that through the method of grouped merging, the embodiment of the present application can form a digital signature chain for the first signatures of the data packets sent multiple times in history, so as to help the verification platform quickly determine the position of the missing data packet and improve the efficiency of security detection.

[0160] It should be noted that the grouping rule of the embodiment of the present application is not limited to pairwise merging, and can also be any applicable grouping rule such as grouping every 3 data packets, grouping every 4 data packets, and grouping every 5 data packets.

[0161] In an alternative embodiment, for the merging process, the above step S310 can also be executed as: obtaining the historical intermediate result, and based on the historical intermediate result, performing a merging process on the first signatures in the data packets sent multiple times in history to generate combined data.

[0162] Among them, the historical intermediate result is used to represent the signatures that have been merged in history. For example, the historical intermediate result can be Figure 7 the signature 71-72, the signature 71-72-73 or the signature 71-72-73-74 in it, or it can also be Figure 8 the signature 71-72, the signature 73-74, the signature 71-72-73-74 and the signature 71-72-73-74-75 in it.

[0163] In the process of generating the combined data, the embodiment of the present application can obtain the existing historical intermediate result and perform a merging process based on the historical intermediate result to generate the combined data. Figure 7 For example, if the embodiment of the present application needs to merge the first signatures of data packet 01 - data packet 04, and the signature 71-72-73 is the historical intermediate result, then the embodiment of the present application can first obtain the signature 71-72-73, and then directly merge the signature 71-72-73 with the signature 74 to generate the combined data (signature 71-72-73-74). Figure 8For example, if the embodiments of the present application need to merge the first signatures of data packets 01 - 05, and signatures 71 - 72 - 73 - 74 are historical intermediate results, the embodiments of the present application can first obtain signatures 71 - 72 - 73 - 74, and then directly merge signatures 71 - 72 - 73 - 74 with signature 75 to generate merged data (signatures 71 - 72 - 73 - 74 - 75).

[0164] The embodiments of the present application generate merged data based on historical intermediate results, which can effectively reduce the computational amount in the merging process, and thus effectively improve the efficiency of the merging process.

[0165] In an alternative embodiment, the second signature of the embodiments of the present application may further include the first signature corresponding to the target data group.

[0166] That is to say, when generating the second signature, the embodiments of the present application may also add the first signature corresponding to the target data group (i.e., the data group to be sent this time) to the second signature. For Figure 7 example, if data packet 04 is the target data packet to be sent this time, when generating the merged data, the embodiments of the present application may add the first signature corresponding to the target data group to the second signature (i.e., generate the merged data of signatures 71 - 72 - 73 - 74). Further, the embodiments of the present application may sign signatures 71 - 72 - 73 - 74 with a preset private key to generate the second signature corresponding to data packet 04. Through the above method, the embodiments of the present application can make the information in the second signature more complete, thereby helping the verification platform obtain more complete information and improving the efficiency of security detection.

[0167] The above is a detailed description of the data transmission method executed on the terminal device side. Next, the embodiments of the present application will provide a detailed description of the data transmission method executed on the verification platform side, as Figure 9 shown, which may specifically include the following steps:

[0168] In step S410, receive the target data packet sent by the terminal device.

[0169] The target data packet at least includes a target data group, a first signature, and a second signature. The first signature is obtained by the terminal device signing at least the target data group with a preset private key. The second signature at least includes the first signature in the data packet sent by the terminal device last time. In addition, in addition to the first signature in the data packet sent by the terminal device last time, the second signature may further include the first signature in the data packets sent historically multiple times and / or the first signature corresponding to the target data group.

[0170] In an alternative embodiment, as Figure 10 shown, the process of the verification platform sending the preset private key to the terminal device may include the following steps:

[0171] In step S510, a key acquisition request sent by a receiving terminal device is received.

[0172] Among them, the key acquisition request may include the device type of the terminal device itself and other relevant information (such as the service platform to which the terminal device belongs and the device number, etc.).

[0173] In step S520, a public-private key pair corresponding to the key acquisition request is determined. The public-private key pair includes a preset private key and a preset public key.

[0174] Among them, after receiving the key acquisition request, the verification platform can determine the public-private key pair corresponding to the key acquisition request according to the information in the key acquisition request, and encrypt and send the preset private key in the public-private key pair to the terminal device.

[0175] In step S530, the preset private key is encrypted to generate private key data.

[0176] Among them, the encryption of the preset private key can be any applicable encryption method (such as symmetric encryption or asymmetric encryption, etc.).

[0177] In step S540, the private key data is sent to the terminal device.

[0178] Correspondingly, after receiving the private key data, the terminal device can decrypt and obtain the preset private key in the private key data, and then store the preset private key in the read-only storage unit, and sign the target data group with the preset private key to ensure the security of the data source.

[0179] In step S420, according to the preset public key and the first signature, the source of the target data packet is verified to determine the data source verification result.

[0180] Specifically, the preset public key and the preset private key correspond to each other. The verification platform can verify the signature of the preset private key with the preset public key. If the signature verification is successful, it indicates that the source of the target data group in the target data packet is secure and legal, that is, the data source verification result at this time is verification passed.

[0181] In step S430, according to the first signature in at least one data packet received historically and the second signature in the target data packet, the continuity of the target data packet is verified to determine the data continuity verification result.

[0182] Among them, there is no fixed execution order between the above step S420 and step S430. The verification platform can execute step S420 first and then step S430, or execute step S430 first and then step S420, or execute step S420 and step S430 simultaneously.

[0183] Specifically, during the verification process on the verification platform, if the second signature in the target data packet received by the verification platform at least includes the first signature in the data packet sent by the terminal device last time, it indicates that the target data packet received by the verification platform is continuous with the previously received data packets (that is, the data continuity verification result is passed at this time). Otherwise, it proves that there are missing data packets between the data packets (that is, the data continuity verification result is not passed at this time).

[0184] Therefore, in one aspect, the embodiment of the present application can ensure the authenticity of the target data group through the first signature corresponding to the target data group. On the other hand, since the second signature at least includes the first signature in the previously sent data packet, the embodiment of the present application can verify the continuity between the data packets through the second signature and the first signature in the previously sent data packet. That is to say, if the second signature in the target data packet received by the verification platform at least includes the first signature in the data packet sent by the terminal device last time, it indicates that the target data packet received by the verification platform is continuous with the previously received data packets. Therefore, through the first signature and the second signature in the target data packet, the embodiment of the present application can quickly and effectively verify the data authenticity of each data packet and the continuity between the data packets, without setting up an additional dedicated network, realizing high-security and low-cost data transmission.

[0185] In an alternative embodiment, the above step S430 can be specifically executed as follows: determining the first signature in at least one previously received data packet, and in response to the first signature in at least one previously received data packet including the second signature in the target data packet, determining that there is continuity between the target data packet and at least one previously received data packet.

[0186] Among them, the result that there is continuity between the data packets is the data continuity verification result. Through the continuity verification of the target data packet, the embodiment of the present application can detect whether the data packets are continuous (that is, detect whether there are missing data packets between the data packets), so as to realize data security detection in the dimension of data coherence.

[0187] Based on the same technical concept, the embodiment of the present application also provides a data transmission device, as Figure 11 shown. This device is applied to the terminal device and includes: a target data group acquisition module 1101, a first signature module 1102, a target data packet generation module 1103, and a target data packet sending module 1104.

[0188] The target data group acquisition module 1101 is configured to acquire the target data group to be sent.

[0189] The first signature module 1102 is configured to perform signing at least on the target data group according to a preset private key stored in a read-only storage unit to generate a first signature.

[0190] The target data packet generation module 1103 is configured to perform generating a target data packet according to the target data group, the first signature, and a second signature, where the second signature at least includes the first signature in the previously sent data packet.

[0191] The target data packet sending module 1104 is configured to perform sending the target data packet to a verification platform so that the verification platform performs source verification and continuity verification on the target data packet.

[0192] In some embodiments, each field in the target data packet at least includes header information, data segment information, and the first signature from front to back, and the data segment information at least includes the target data group.

[0193] In some embodiments, the target data packet generation module 1103 is specifically configured to perform:

[0194] Writing the second signature into a predetermined field before the first signature to generate the target data packet.

[0195] In some embodiments, the second signature includes the first signatures in the data packets sent multiple times in history, and the data packets sent multiple times in history include the previously sent data packet.

[0196] As Figure 12 shown, the second signature is determined by the following modules:

[0197] The merging processing module 1201 is configured to perform merging processing on the first signatures in the data packets sent multiple times in history to generate merged data.

[0198] The second signature module 1202 is configured to perform signing the merged data with a preset private key to generate the second signature.

[0199] In some embodiments, the merging processing module is specifically configured to perform:

[0200] Successively merging the first signatures in the data packets sent multiple times in history according to the order of the data packets sent multiple times in history to generate the merged data.

[0201] In some embodiments, the merging processing module is specifically configured to perform:

[0202] Grouping and merging the first signatures in the data packets sent multiple times in history according to the order of the data packets sent multiple times in history to determine the grouping and merging result.

[0203] Further merge the results of each of the above-mentioned subgroup merges to generate the merged data.

[0204] In some embodiments, the merge processing module is specifically configured to perform:

[0205] Obtain historical intermediate results.

[0206] Based on the historical intermediate results, perform a merge process on the first signatures in the historical packets sent multiple times to generate merged data.

[0207] In some embodiments, the device further includes:

[0208] A key acquisition request sending module, configured to send a key acquisition request to the verification platform.

[0209] A private key data processing module, configured to receive and decrypt the private key data returned by the verification platform to obtain the preset private key.

[0210] In some embodiments, the second signature further includes the first signature corresponding to the target data group.

[0211] In one aspect, an embodiment of the present application can ensure the authenticity of the target data group through the first signature corresponding to the target data group. On the other hand, since the second signature at least includes the first signature in the previously sent packet, an embodiment of the present application can verify the continuity between each packet through the second signature and the first signature in the previously sent packet. That is, if the second signature in the target packet received by the verification platform at least includes the first signature in the packet previously sent by the terminal device, it indicates that the target packet received by the verification platform is continuous with the previously received packets. Therefore, through the first signature and the second signature in the target packet, an embodiment of the present application can quickly and effectively verify the data authenticity of each packet and the continuity between each packet, without setting up an additional dedicated network, achieving high-security and low-cost data transmission.

[0212] Based on the same technical concept, an embodiment of the present application further provides a data transmission device, as Figure 13 shown. This device is applied to the verification platform and includes: a target packet receiving module 1301, a source verification module 1302, and a continuity verification module 1303.

[0213] A target data packet receiving module 1301, configured to receive a target data packet sent by a terminal device, where the target data packet at least includes a target data group, a first signature, and a second signature, the first signature is obtained by the terminal device signing at least the target data group according to a preset private key, and the second signature at least includes the first signature in the data packet sent by the terminal device last time.

[0214] A source verification module 1302, configured to perform source verification on the target data packet according to a preset public key and the first signature, and determine a data source verification result.

[0215] A continuity verification module 1303, configured to perform continuity verification on the target data packet according to the first signature in at least one historically received data packet and the second signature in the target data packet, and determine a data continuity verification result.

[0216] In some embodiments, the continuity verification module 1303 is specifically configured to perform:

[0217] Determine the first signature in at least one historically received data packet.

[0218] In response to the first signature in at least one historically received data packet including the second signature in the target data packet, determine that there is continuity between the target data packet and at least one historically received data packet.

[0219] In some embodiments, the apparatus further includes:

[0220] A key acquisition request receiving module, configured to receive a key acquisition request sent by the terminal device.

[0221] A public-private key pair determination module, configured to determine a public-private key pair corresponding to the key acquisition request, the public-private key pair including the preset private key and the preset public key.

[0222] An encryption module, configured to perform encryption processing on the preset private key to generate private key data.

[0223] A key sending module, configured to send the private key data to the terminal device.

[0224] In one aspect, the embodiments of the present application can ensure the authenticity of the target data group through the first signature corresponding to the target data group. In another aspect, since the second signature at least includes the first signature in the previously sent data packet, the embodiments of the present application can verify the continuity between data packets through the second signature and the first signature in the previously sent data packet. That is, if the second signature in the target data packet received by the verification platform at least includes the first signature in the data packet previously sent by the terminal device, it indicates that the target data packet received by the verification platform is continuous with the previously received data packets. Therefore, through the first signature and the second signature in the target data packet, the embodiments of the present application can quickly and effectively verify the data authenticity of each data packet and the continuity between each data packet, without setting up an additional dedicated network, realizing high-security and low-cost data transmission.

[0225] Figure 14 is a schematic diagram of the electronic device in the embodiments of the present application. The electronic device can be used as a terminal device or a verification platform in the data transmission system. As Figure 14 shown, Figure 14 The electronic device shown is a general address query device, which includes a general computer hardware structure, and at least includes a processor 1401 and a memory 1402. The processor 1401 and the memory 1402 are connected through a bus 1403. The memory 1402 is suitable for storing instructions or programs executable by the processor 1401. The processor 1401 can be an independent microprocessor or a set of one or more microprocessors. Thus, by executing the instructions stored in the memory 1402, the processor 1401 executes the method flow of the embodiments of the present application as described above to implement the processing of data and the control of other devices. The bus 1403 connects the above-mentioned multiple components together, and at the same time connects the above-mentioned components to a display controller 1404, a display device, and an input / output (I / O) device 1405. The input / output (I / O) device 1405 can be a mouse, a keyboard, a modem, a network interface, a touch input device, a somatosensory input device, a printer, and other devices well-known in the art. Typically, the input / output (I / O) device 1405 is connected to the system through an input / output (I / O) controller 1406.

[0226] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a device (equipment), or a computer program product. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can be implemented as a computer program product on one or more computer-readable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes.

[0227] This application is described with reference to the flowcharts of methods, apparatuses (devices), and computer program products according to embodiments of the present application. It should be understood that each process in the flowchart can be implemented by computer program instructions.

[0228] These computer program instructions can be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory produce a manufactured article including an instruction device that implements the processes Figure 1 specified functions in one process or multiple processes.

[0229] These computer program instructions can also be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing device produce a device for implementing the Figure 1 specified functions in one process or multiple processes.

[0230] Another embodiment of the present application relates to a non-volatile storage medium for storing a computer-readable program, which is used for a computer to execute the above-mentioned partial or all method embodiments.

[0231] That is, those skilled in the art can understand that all or part of the steps of implementing the above-mentioned embodiment methods can be completed by specifying relevant hardware through a program. The program is stored in a storage medium and includes several instructions to enable a device (which can be a single-chip microcomputer, a chip, etc.) or a processor to execute all or part of the steps of the methods described in the embodiments of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs that can store program codes.

[0232] The foregoing are only the preferred embodiments of the present application and are not used to limit the present application. For those skilled in the art, various modifications and changes can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application.

Claims

1. A data transmission method, characterized in that, The method is applied to a terminal device, and the method includes: Obtain a target data group to be sent; At least sign the target data group according to a preset private key stored in a read-only storage unit to generate a first signature; Generate a target data packet according to the target data group, the first signature, and a second signature, where the second signature at least includes the first signature in the packet sent last time; Send the target data packet to a verification platform so that the verification platform performs source verification and continuity verification on the target data packet.

2. The method according to claim 1, characterized in that, Each field in the target data packet at least includes header information, data segment information, and the first signature from front to back, and the data segment information at least includes the target data group.

3. The method according to claim 2, characterized in that, The generating a target data packet according to the target data group, the first signature, and the second signature includes: Write the second signature into a predetermined field before the first signature to generate the target data packet.

4. The method according to claim 2, characterized in that, The second signature includes the first signatures in packets sent multiple times in history, and the packets sent multiple times in history include the packet sent last time; The second signature is determined through the following steps: Perform a merging process on the first signatures in the packets sent multiple times in history to generate merged data; Sign the merged data with a preset private key to generate the second signature.

5. The method according to claim 4, characterized in that, The performing a merging process on the first signatures in the packets sent multiple times in history to generate merged data includes: Sequentially merge the first signatures in the packets sent multiple times in history according to the order of the packets sent multiple times in history to generate the merged data.

6. The method according to claim 4, characterized in that, The performing a merging process on the first signatures in the packets sent multiple times in history to generate merged data includes: Perform grouped merging on the first signatures in the packets sent multiple times in history according to the order of the packets sent multiple times in history to determine a grouped merging result; Further merge each of the grouped merging results to generate the merged data.

7. The method according to claim 4, characterized in that, The performing a merging process on the first signatures in the packets sent multiple times in history to generate merged data includes: Obtain historical intermediate results; Based on the historical intermediate results, perform a merging process on the first signatures in the packets sent multiple times in history to generate merged data.

8. The method according to claim 1, characterized in that, The method further includes: Send a key acquisition request to the verification platform; Receive and decrypt the private key data returned by the verification platform to obtain the preset private key.

9. The method according to claim 1, characterized in that, The second signature further includes the first signature corresponding to the target data group.

10. A data transmission method, characterized in that, The method is applied to a verification platform, and the method includes: Receive a target data packet sent by a terminal device, where the target data packet at least includes a target data group, a first signature, and a second signature, the first signature is obtained by the terminal device signing at least the target data group according to a preset private key, and the second signature at least includes the first signature in the packet sent by the terminal device last time; Perform source verification on the target data packet according to a preset public key and the first signature to determine a data source verification result; Perform continuity verification on the target data packet according to the first signature in at least one data packet received historically and the second signature in the target data packet, and determine the data continuity verification result.

11. The method according to claim 10, characterized in that, The performing continuity verification on the target data packet according to the first signature in at least one data packet received historically and the second signature in the target data packet, and determining the data continuity verification result includes: Determine the first signature in at least one data packet received historically; In response to the first signature in at least one data packet received historically including the second signature in the target data packet, determine that there is continuity between the target data packet and at least one data packet received historically.

12. The method according to claim 10, characterized in that, The method further includes: Receive a key acquisition request sent by the terminal device; Determine the public-private key pair corresponding to the key acquisition request, where the public-private key pair includes the preset private key and the preset public key; Perform encryption processing on the preset private key to generate private key data; Send the private key data to the terminal device.

13. A data transmission system, characterized in that, The system includes at least one terminal device and at least one verification platform, and the terminal device includes a read-only storage unit; Wherein, the terminal device is configured to execute the data transmission method according to any one of claims 1-9; The verification platform is configured to execute the data transmission method according to any one of claims 10-12.

14. The system according to claim 13, characterized in that, The verification platform includes a management platform and a service platform, and target data packets are transmitted between each management platform and each service platform through network connection.

15. A data transmission device, characterized in that, The apparatus is applied to a terminal device, and the apparatus includes: A target data group acquisition module, configured to execute acquiring a target data group to be sent; A first signature module, configured to execute signing at least the target data group according to a preset private key stored in the read-only storage unit to generate a first signature; A target data packet generation module, configured to execute generating a target data packet according to the target data group, the first signature, and a second signature, where the second signature at least includes the first signature in the data packet sent last time; A target data packet sending module, configured to execute sending the target data packet to a verification platform so that the verification platform performs source verification and continuity verification on the target data packet.

16. A data transmission device, characterized in that, The apparatus is applied to a verification platform, and the apparatus includes: A target data packet receiving module, configured to execute receiving a target data packet sent by a terminal device, where the target data packet at least includes a target data group, a first signature, and a second signature, the first signature is obtained by the terminal device signing at least the target data group according to a preset private key, and the second signature at least includes the first signature in the data packet sent by the terminal device last time; A source verification module, configured to execute performing source verification on the target data packet according to a preset public key and the first signature, and determining a data source verification result; The continuity verification module is configured to perform continuity verification on the target data packet according to the first signature in at least one historically received data packet and the second signature in the target data packet, and determine the data continuity verification result.

17. A computer-readable storage medium, characterized in that, A computer program is stored in the computer-readable storage medium, and when the computer program is executed by a processor, the method according to any one of claims 1-12 is implemented.