Secure transmission method of encrypted data, electronic equipment and storage medium

By generating and managing multi-layer encryption keys in a trusted execution environment, the risk of data leakage during data transmission in TEE hardware environment is solved, and the secure isolation of multi-party data and advanced data security in data transmission are achieved.

CN120180518APending Publication Date: 2025-06-20ZHEJIANG MEIRI HUDONG NETWORK TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510342697.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-21
Publication Date
2025-06-20

AI Technical Summary

Technical Problem

The existing TEE hardware environment still has the risk of data leakage during data transmission, and cannot effectively solve the data security problems in data transmission.

Method used

By sending the encrypted data set and data key to a preset trusted execution environment, a public and private key is generated, and the target root key is generated by combining the initial root key and private key, multi-layer encryption and decryption are achieved, increasing the complexity of the key and the encryption strength of the data.

Benefits of technology

Multi-layer encryption and decryption of data is realized, the complexity of data encryption and decryption is increased, data sharing and leakage are prevented by multi-party data, secure isolation of multi-party data, and data security in data transmission is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120180518A_ABST
    Figure CN120180518A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data security processing, in particular to a secure transmission method of encrypted data, electronic equipment and a storage medium, and the method comprises the following steps: sending encrypted data sets and corresponding data keys respectively sent by a plurality of data providers to a preset trusted execution environment, and obtaining a public key and a private key, generating an initial root key according to target attribute information of the trusted execution environment, generating a target root key according to the initial root key and each private key, storing the target root key in the trusted execution environment, encrypting a data key by using a public key, sending an encryption result to the trusted execution environment, sequentially decrypting to obtain the data key and an encrypted data set, and storing the encrypted data set in the trusted execution environment. The encrypted data set is calculated through the calculation code, and then an obtained calculation result is output; according to the method, security isolation of multi-party data can be realized, the key information can be mixed, the encryption strength and the recovery difficulty of the data are increased, and the data security in data transmission is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security processing, and particularly to a secure transmission method for encrypted data, an electronic device, and a storage medium. Background Art

[0002] With the wide popularization of computer applications, a large amount of various information of users is stored. The protection of user sensitive data usually manages user access rights through the system's key management mechanism, or manages the memory by encrypting and decrypting shared data in solid-state drives. In some other scenarios, for example, some enterprise objects want to use certain relevant data of the GeTui system for joint modeling to obtain users who have a tendency for the products currently launched by the enterprise, and be used in scenarios such as supplementary recommendation services and advertising placement. Both the GeTui system and enterprise objects are worried about internal data leakage. Therefore, data needs to be transmitted in a trusted execution environment independent of both parties, such as an environment based on TEE hardware. Although the data encryption in the current TEE hardware environment has good effects, it can only solve some problems, such as data security problems during storage and memory security problems during calculation. There is still a risk of data leakage in the entire process of data transmission. Therefore, improving the encryption intensity and the difficulty of being restored of data is very meaningful for data security during data transmission. Summary of the Invention

[0003] In view of the above technical problems, the present invention provides a secure transmission method for encrypted data, an electronic device, and a storage medium, which can achieve secure isolation of multi-party data and can confuse key information, increase the encryption intensity and the difficulty of being restored of data, and ensure data security problems during data transmission.

[0004] According to a first aspect of the present invention, a secure transmission method for encrypted data is provided, including the following steps:

[0005] Based on the preset service calculation requirements of a target object, encrypted data sets respectively sent by several data providers and corresponding data keys are both sent to a preset trusted execution environment, and each data key is respectively asymmetrically encrypted by the trusted execution environment to generate a public key and a private key; the encrypted data sets corresponding to different data providers are isolated by the corresponding data signatures of the data providers themselves in the trusted execution environment.

[0006] An initial root key is generated according to the target attribute information of the trusted execution environment, and the initial root key and each private key are respectively combined to generate a target root key and stored in the trusted execution environment; the number of characters of the initial root key is equal to the number of characters of the private key.

[0007] Send each public key to the corresponding data provider respectively, encrypt the data key in the data provider with the public key, and send the encrypted result of the data key to the trusted execution environment.

[0008] Decrypt each target root key through the preset decryption algorithm file SO library in the trusted execution environment to obtain the private key, and decrypt the encrypted result of the data key with the private key to obtain the data key and the encrypted data set in sequence.

[0009] Receive the calculation code sent by the target object to the trusted execution environment, calculate the encrypted data set with the calculation code, and output the obtained calculation result to the target object to achieve secure data transmission among multiple parties.

[0010] According to the second aspect of the present invention, there is provided a non-transitory computer-readable storage medium, in which at least one instruction or at least one program segment is stored, and the at least one instruction or the at least one program segment is loaded and executed by a processor to implement the above-mentioned secure transmission method for encrypted data.

[0011] According to the third aspect of the present invention, there is provided an electronic device, including a processor and the above-mentioned non-transitory computer-readable storage medium.

[0012] The present invention has at least the following beneficial effects:

[0013] The present invention provides a secure transmission method for encrypted data. First, the encrypted data sets and the corresponding data keys respectively sent by several data providers are both sent to a preset trusted execution environment to generate a public key and a private key. An initial root key is generated according to the target attribute information of the trusted execution environment, and the initial root key and each private key are respectively merged to generate a target root key and stored in the trusted execution environment, and it is ensured that the number of characters of the initial root key is equal to that of the private key to increase the complexity of the key. The data provider encrypts the data key with the public key and sends the encrypted result to the trusted execution environment. In the trusted execution environment, the target root key is decrypted to obtain the private key, and then the data key and the encrypted data set are obtained by successive decryption. The encrypted data set is calculated with the calculation code and the obtained calculation result is output to the target object. Through the above process, multi-layer encryption and decryption of data are realized, the complexity of data encryption and decryption is increased, and the data of the requester and the data provider are both concentrated in the trusted execution environment for execution, preventing data sharing and leakage among multiple parties. While achieving secure isolation of data among multiple parties, it is also possible to confuse the key information, increase the encryption intensity of the data and the difficulty of being restored, and ensure the data security problem in data transmission. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] To more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.

[0015] Figure 1 It is a flowchart of the secure transmission method for encrypted data provided by the embodiments of the present invention. Specific implementation manners

[0016] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.

[0017] This embodiment provides a secure transmission method for encrypted data, as Figure 1 shown, the method includes the following steps:

[0018] S100, based on the preset service calculation requirements of the target object, send the encrypted data sets respectively sent by several data providers and the corresponding data keys to a preset trusted execution environment, and perform asymmetric encryption on each data key through the trusted execution environment to generate a public key and a private key; the encrypted data sets corresponding to different data providers are isolated by the data signatures corresponding to the data providers themselves in the trusted execution environment. For example, the target object is an enterprise object that puts forward service calculation requirements, and the service calculation requirements are, for example, to provide user information of users who often browse a certain web page. The data provider is a system that provides data, such as the GeTui system. The data of different data providers are isolated by the accounts pre-registered in the trusted execution environment and are invisible to each other.

[0019] Specifically, the trusted execution environment is a hardware-based TEE environment.

[0020] Preferably, the encrypted data set sent by the data provider is a data set obtained by encrypting the data through the AES encryption algorithm; wherein, in the column mixing process of the AES encryption algorithm, the following steps are further included:

[0021] P100, convert each column in the state matrix pre-generated during the AES encryption process into a quartic polynomial.

[0022] Specifically, the AES encryption process includes key expansion, an initial round, multiple rounds of iteration, and a final round. A state matrix is generated during the initial round, and the multiple rounds of iteration include four steps: byte substitution, row shift, column mixing, and round key addition. Those skilled in the art are aware of the specific implementation steps of the AES encryption process and will not be elaborated here.

[0023] P200, perform modulo multiplication operations on each of the quartic polynomials corresponding to each column with the preset polynomial ax 4 +1 to obtain a new column to update the state matrix, where a is a preset weight coefficient and x represents the order of the column corresponding to the quartic polynomial. For example, when calculating using the quartic polynomial of the second column, x = 2.

[0024] Further, a is proportional to the data volume of the encrypted dataset.

[0025] As described above, by converting each column into a quartic polynomial and performing multiplication operations with a preset polynomial, it is possible to perform a linear transformation on the values of each column in the state matrix, and a weight coefficient is introduced during the linear transformation process, further increasing the complexity of the linear transformation, and thus further enhancing the diffusion of bytes and improving the encryption effect.

[0026] Further, before sending the encrypted datasets and corresponding data keys respectively sent by several data providers to a preset trusted execution environment, the following steps are also included:

[0027] S001, test the target storage device to be tested with several dataset samples of different data volumes to obtain several data error rates corresponding to the target storage device to be tested; it can be understood that each dataset sample corresponds to a data error rate.

[0028] In another embodiment, it is also possible to repeatedly test the target storage device to be tested with the same dataset sample, and use the average value of the several data error rates obtained as the several data error rates corresponding to the target storage device to be tested.

[0029] S002, based on the several data error rates corresponding to the target storage device to be tested, perform curve fitting on the several data error rates and the corresponding several data volumes to obtain a key fitting curve, and use the data volume corresponding to the preset error rate threshold in the key fitting curve as the data volume threshold; those skilled in the art set the error rate threshold according to actual needs and will not be elaborated here.

[0030] S003. Obtain the total data volume size of a number of encrypted data sets. When the total data volume size is less than the data volume threshold, send the number of encrypted data sets to the target storage device; otherwise, send the number of encrypted data sets to the trusted execution environment.

[0031] As described above, there are two storage methods for storing encrypted data, storing it in the target storage device or the trusted execution environment. The target storage device has the advantages of being movable and easy to destroy, etc. However, when the data volume is large, it is easy to cause problems such as a high data error rate and insufficient memory. Therefore, before storing data, it is necessary to comprehensively consider the data volume and data error rate of the encrypted data, so as to screen out the most suitable storage method, which is beneficial to data security processing.

[0032] Preferably, before the step of sending the encrypted data sets and the corresponding data keys respectively sent by a number of data providers to the preset trusted execution environment, the following steps are further included:

[0033] S01. Obtain a number of encrypted fields in the encrypted data set and a number of encrypted field values corresponding to each encrypted field.

[0034] S02. For any encrypted field, use the preset encryption audit rule corresponding to the encrypted field to audit the number of encrypted field values corresponding to the encrypted field, and judge whether the number of encrypted field values corresponding to the encrypted field conforms to the preset encryption rule corresponding to the encrypted field.

[0035] S03. When the number of encrypted field values that do not conform to the preset encryption rule corresponding to the encrypted field is less than the preset number threshold, execute the step of sending the encrypted data sets and the corresponding data keys respectively sent by a number of data providers to the preset trusted execution environment.

[0036] Furthermore, when the number of encrypted field values that do not conform to the preset encryption rule corresponding to the encrypted field is not less than the preset number threshold, return the encrypted data set to the data provider and send a data non-compliance prompt to the data provider.

[0037] As described above, before the trusted execution environment receives the encrypted data set, it is also necessary to audit the encryption result of the encrypted data set to ensure that the data is encrypted according to the preset encryption rule, prevent data leakage caused by uploading unencrypted data, and thus ensure the security during data transmission.

[0038] S200. Generate an initial root key according to the target attribute information of the trusted execution environment, and generate a target root key by merging the initial root key and each private key respectively, and store the target root key in the trusted execution environment; the number of characters of the initial root key is equal to the number of characters of the private key.

[0039] Specifically, the target attribute information of the trusted execution environment includes, but is not limited to, CPU model, memory size, chip fingerprint, and secure random number.

[0040] Further, the method further includes the following steps:

[0041] S1. Based on the total number of characters K of the target root key, obtain the number n of the confusion keys to be added and the number of characters of each confusion key to be added; the number of characters of each confusion key to be added is equal to the total number of characters of the target root key; where n meets the following conditions:

[0042] n = 2 K / 32 ; In a specific implementation, since the server is generally 32-bit, this embodiment takes 32-bit as an example. The target root key represents K / 32 words, and the binary characters corresponding to each word are set to two different strings. In theory, a total of n different confusion keys can be set.

[0043] S2. Based on the number of characters of each confusion key to be added, randomly select n groups of preset confusion keys from the preset confusion key library as the confusion keys to be added, and store them together with the target root key in the trusted execution environment.

[0044] As described above, by setting the confusion key to be equal to the number of characters of the target root key, the key is easier to be confused and difficult to distinguish, increasing the difficulty of the key being cracked. And by obtaining the number of confusion keys through the total number of characters of the target root key and the number of characters that the processor can process at one time, when the number of confusions meets the requirements, the degree of confusion can achieve a better effect without adding more confusion keys.

[0045] S300. Send each public key to the corresponding data provider respectively and encrypt the data key in the data provider with the public key, and send the encryption result of the data key to the trusted execution environment; it can be understood that: the public key is stored in the data provider, and the private key is stored in the trusted execution environment and is used to decrypt the data key encrypted by the public key.

[0046] S400. Decrypt each target root key through the preset decryption algorithm file SO library in the trusted execution environment to obtain the private key, and decrypt the encryption result of the data key with the private key to obtain the data key and the encrypted data set in sequence; it can be understood that: first decrypt the encryption result of the data key to obtain the data key, and then decrypt the encrypted data set through the data key.

[0047] The S500 receives the computing code sent by the target object into the trusted execution environment, calculates the encrypted data set through the computing code, and outputs the obtained calculation result to the target object to achieve secure data transmission among multiple parties. It can be understood that the computing code refers to the code corresponding to the preset business computing requirements of the target object.

[0048] Further, before the step of calculating the encrypted data set through the computing code, the following steps are also included:

[0049] S501, when receiving the computing code sent by the target object into the trusted execution environment, according to the preset code review rules, determine whether the computing code meets the preset business computing requirements. For example, review whether the computing code is applicable to the application scenario corresponding to the preset business computing requirements, and review whether the computing code can additionally obtain and output other data. If it can additionally obtain other data, it is a non-compliant code, thus avoiding possible data leakage.

[0050] S502, when the computing code meets the preset business computing requirements, execute the step of calculating the encrypted data set through the computing code.

[0051] As described above, before using the computing code for calculation, first verify the compliance of the computing code. When it meets the preset business computing requirements, then send it to the trusted execution environment, so that the obtained calculation result is the required result, prevent other calculation results from being output or the internal data in the trusted execution environment from being obtained, avoid data leakage, and ensure the security of the data calculation process.

[0052] An embodiment of the present invention also provides a non-transitory computer-readable storage medium, which can be set in an electronic device to store at least one instruction or at least one program related to a method for implementing a method in the method embodiment. The at least one instruction or the at least one program is loaded and executed by the processor to implement the secure transmission method of encrypted data provided in the above embodiment.

[0053] An embodiment of the present invention also provides an electronic device, including a processor and the foregoing non-transitory computer-readable storage medium.

[0054] Although some specific embodiments of the present invention have been described in detail by way of examples, those skilled in the art should understand that the above examples are only for illustration and not for limiting the scope of the present invention. Those skilled in the art should also understand that various modifications can be made to the embodiments without departing from the scope and spirit of the present invention. The scope of the present invention is defined by the appended claims.

Claims

1. A method for securely transmitting encrypted data, characterized in that: The method comprises the following steps: Based on the preset business computing requirements of the target object, the encrypted data sets and corresponding data keys sent by several data providers are sent to the preset trusted execution environment, and each data key is asymmetrically encrypted by the trusted execution environment to generate a public key and a private key; the encrypted data sets corresponding to different data providers are isolated by the corresponding data signatures of the data providers themselves in the trusted execution environment; Generate an initial root key according to the target attribute information of the trusted execution environment, and merge the initial root key and each private key to generate a target root key and store it in the trusted execution environment; the number of characters in the initial root key is equal to the number of characters in the private key; Send each public key to the corresponding data provider and encrypt the data key in the data provider by the public key, and send the encrypted result of the data key to the trusted execution environment; Decrypting each target root key through the decryption algorithm file SO library preset in the trusted execution environment to obtain a private key, and decrypting the encrypted result of the data key through the private key to obtain the data key and the encrypted data set in turn; The computing code sent by the target object to the trusted execution environment is received, and the encrypted data set is calculated by the computing code and the obtained calculation result is output to the target object to realize the secure transmission of data among multiple parties.

2. The method for secure transmission of encrypted data according to claim 1, characterized in that: Before the step of sending the encrypted data sets and corresponding data keys respectively sent by the plurality of data providers to the preset trusted execution environment, the following steps are also included: Using several data set samples with different data sizes to test the target storage device to be tested, and obtaining several data error rates corresponding to the target storage device to be tested; Based on a number of data error rates corresponding to the target storage device to be tested, curve fitting is performed on the data error rates and the corresponding data volumes to obtain a key fitting curve, and the data volume corresponding to the preset error rate threshold in the key fitting curve is used as the data volume threshold; The total data size of the plurality of encrypted data sets is obtained, and when the total data size is less than a data size threshold, the plurality of encrypted data sets are sent to a target storage device; otherwise, the plurality of encrypted data sets are sent to a trusted execution environment.

3. The method for secure transmission of encrypted data according to claim 1, characterized in that: The target attribute information of the trusted execution environment includes CPU model, memory size, chip fingerprint and secure random number.

4. The method for secure transmission of encrypted data according to claim 1, characterized in that: The method further comprises the steps of: Based on the total number of characters K of the target root key, the number n of obfuscated keys to be added and the number of characters of each obfuscated key to be added are obtained; the number of characters of each obfuscated key to be added is equal to the total number of characters of the target root key; wherein n meets the following conditions: n=2 K / 32 ; Based on the number of characters of each obfuscated key to be added, n groups of preset obfuscated keys are randomly selected from the preset obfuscated key library as the obfuscated keys to be added, and are stored in the trusted execution environment together with the target root key.

5. The method for secure transmission of encrypted data according to claim 1, characterized in that: The encrypted data set sent by the data provider is a data set obtained by encrypting the data using the AES encryption algorithm; wherein, the column mixing process in the AES encryption algorithm also includes the following steps: Each column of the state matrix pre-generated during the AES encryption process is converted into a quartic polynomial; Compare the quartic polynomials corresponding to each column with the preset polynomial ax 4 +1 performs modular multiplication to obtain new columns to update the state matrix, where a is the preset weight coefficient and x represents the order of the columns corresponding to the quartic polynomial.

6. The method for secure transmission of encrypted data according to claim 1, characterized in that: Before the step of sending the encrypted data sets and corresponding data keys respectively sent by the plurality of data providers to the preset trusted execution environment, the following steps are also included: Obtaining a number of encrypted fields in the encrypted data set and a number of encrypted field values ​​corresponding to each encrypted field; For any encrypted field, a number of encrypted field values ​​corresponding to the encrypted field are reviewed using a preset encryption review rule corresponding to the encrypted field to determine whether the number of encrypted field values ​​corresponding to the encrypted field comply with the preset encryption rule corresponding to the encrypted field; When the number of encrypted field values ​​that do not comply with the preset encryption rules corresponding to the encrypted field is less than the preset number threshold, the execution step is to send the encrypted data sets and corresponding data keys sent by several data providers to the preset trusted execution environment.

7. The method for secure transmission of encrypted data according to claim 1, characterized in that: Before calculating the encrypted data set by calculating the code in step 1, the following steps are also included: When receiving the computing code sent by the target object to the trusted execution environment, judging whether the computing code meets the preset business computing requirements according to the preset code review rules; When the calculation code meets the preset business calculation requirements, the step of calculating the encrypted data set by using the calculation code is executed.

8. A non-transitory computer-readable storage medium, wherein at least one instruction or at least one program is stored in the storage medium, characterized in that: The at least one instruction or the at least one program is loaded and executed by the processor to implement the method for secure transmission of encrypted data as described in any one of claims 1-7.

9. An electronic device, characterized in that: The invention comprises a processor and the non-transitory computer-readable storage medium as claimed in claim 8.