Data secure transmission method, system and device, electronic equipment and storage medium
By regularly updating the key on the firmware side and viewing side, and obtaining randomly generated update keys from the service server, encrypting the video stream data, the problem of easy cracking of fixed keys in the prior art is solved, and the security of data transmission is improved.
Patent Information
- Application Number
- CN202510265685.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-06
- Publication Date
- 2025-06-20
AI Technical Summary
Existing video stream encryption methods use fixed keys, resulting in high risks during data transmission and are prone to intercept and tampering.
By setting a preset update time interval on the firmware side, a key update request is generated, and a randomly generated update key is obtained from the service server to encrypt the transmitted data. The viewer also obtains the same update key from the service server for decoding.
Encrypting data with a timed updated key improves the security of data transmission and avoids the risk of data interception caused by the key being cracked.
Smart Images

Figure CN120185804A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of data encryption transmission. Specifically, the present application relates to a data security transmission method, system, device, electronic device, computer-readable storage medium, and computer program product. Background Art
[0002] With the popularization of various monitoring systems, the problem of video data transmission security has become increasingly prominent. Especially for live video streams, real-time transmission is required and the correct transmission of the video stream is ensured. In order to ensure that video data is not illegally intercepted and tampered with during the transmission process from the firmware end to the viewing end, key encryption technology has become a necessary means to protect data security.
[0003] Currently, the common video stream encryption method is to encrypt the video stream using a fixed key. However, a fixed key used for a long time is easily cracked, resulting in easy interception of data during transmission and low data transmission security. Summary of the Invention
[0004] Embodiments of the present application provide a data security transmission method, system, device, electronic device, computer-readable storage medium, and computer program product, aiming to solve the technical problem of high transmission risk caused by encrypting video data using a fixed key.
[0005] In a first aspect, a data security transmission method is provided, which is applied to the firmware end. The firmware end is connected to the service server through a network, and the firmware end is connected to the viewing end through a network. The method includes:
[0006] Generating a key update request based on a preset update time interval;
[0007] Sending the key update request to the service server to obtain an updated key; the updated key is randomly generated by the service server;
[0008] Encrypting the transmission data based on the updated key to obtain encrypted data;
[0009] Sending the encrypted data to the viewing end, so that the viewing end generates a key acquisition request based on the encrypted data, and sends the key acquisition request to the service server to obtain the updated key returned by the service server, and decrypts the encrypted data based on the updated key to obtain the transmission data.
[0010] Optionally, sending the key update request to the service server to obtain an updated key includes:
[0011] Sending the key update request to the service server to obtain a corresponding key table;
[0012] Determining the updated key based on the key table.
[0013] Optionally, determining an update key based on a key table includes:
[0014] Using the key at a preset position in the key table as the selected key;
[0015] Determining an update key based on the selected key.
[0016] Optionally, determining an update key based on the selected key includes:
[0017] Obtaining the current key;
[0018] Comparing the current key with the selected key to determine whether the keys are the same;
[0019] If they are the same, using the key at the next position in the key table as the update key; the key table is arranged in order of the creation time of the keys;
[0020] If they are not the same, using the selected key as the update key.
[0021] Optionally, the method further includes:
[0022] Determining the time interval between the current time and the time when the update key was last obtained, and determining whether the key table needs to be updated;
[0023] If it is determined that the key table needs to be updated, generating an update prompt and sending it to the service server so that the service server updates the key table.
[0024] Optionally, determining the time interval between the current time and the time when the update key was last obtained, and determining whether the key table needs to be updated, includes:
[0025] Determining the time interval between the current time and the time when the update key was last obtained;
[0026] Comparing the time interval with a preset time threshold to determine whether the key table needs to be updated; the preset time threshold is greater than the preset update time interval.
[0027] Optionally, comparing the time interval with a preset time threshold to determine whether the key table needs to be updated, includes:
[0028] If the time interval is greater than or equal to the preset time threshold, determining that the key table needs to be updated;
[0029] If the time interval is less than the preset time threshold, determining that the key table does not need to be updated.
[0030] In a second aspect, a data security transmission method is provided, which is applied to a viewing end. The viewing end is connected to a firmware end through a network, and the viewing end is connected to a service server through a network. The method includes:
[0031] Receive the encrypted data sent by the firmware side; the encrypted data is obtained by encrypting the transmission data based on an update key, and the update key is obtained by the firmware side from the service server based on a key update request, and the key update request is generated based on a preset update time interval, and the update key is randomly generated by the service server;
[0032] Generate a key acquisition request based on the encrypted data;
[0033] Send the key acquisition request to the service server to obtain the update key returned by the service server;
[0034] Decode the encrypted data based on the update key to obtain the transmission data.
[0035] Thirdly, a data security transmission method is provided, which is applied to a service server. The service server is connected to the firmware side through a network, and the service server is connected to the viewing side through a network. The method includes:
[0036] Obtain the key update request sent by the firmware side; the key update request is generated based on a preset update time interval;
[0037] Determine the corresponding update key based on the key update request; the update key is randomly generated;
[0038] Send the update key to the firmware side so that the firmware side encrypts the transmission data based on the update key to obtain encrypted data, and sends the encrypted data to the viewing side so that the viewing side generates a key acquisition request based on the encrypted data and sends it to the service server;
[0039] Receive the key acquisition request, determine the corresponding update key and send it to the viewing side so that the viewing side decodes the encrypted data based on the update key to obtain the transmission data.
[0040] Fourthly, a data security transmission system is provided. The system includes: a service server, a firmware side and a viewing side. The service server, the firmware side and the viewing side are connected pairwise, where:
[0041] The firmware side is used to generate a key update request based on a preset update time interval and send the key update request to the service server;
[0042] The service server is used to obtain the key update request, determine the update key from the key table corresponding to the firmware side based on the key update request, and send the update key to the firmware side; the update key is randomly generated by the service server;
[0043] The firmware side is used to encrypt the transmission data based on the update key to obtain encrypted data and send the encrypted data to the viewing side;
[0044] The viewing end is used to receive the encrypted data sent by the firmware end, generate a key acquisition request based on the encrypted data, and send the key acquisition request to the service server;
[0045] The service server is used to receive the key acquisition request, determine the corresponding updated key and send it to the viewing end;
[0046] The viewing end is used to obtain the updated key returned by the service server, and decode the encrypted data based on the updated key to obtain the transmission data.
[0047] In a fifth aspect, a data security transmission device is provided, which is applied to the firmware end. The firmware end is connected to the service server through a network, and the firmware end is connected to the viewing end through a network. The device includes:
[0048] A timing update module is used to generate a key update request based on a preset update time interval;
[0049] An acquisition module is used to send the key update request to the service server to obtain the updated key; the updated key is randomly generated by the service server;
[0050] An encryption module is used to encrypt the transmission data based on the updated key to obtain the encrypted data;
[0051] A sending module is used to send the encrypted data to the viewing end, so that the viewing end generates a key acquisition request based on the encrypted data, and sends the key acquisition request to the service server to obtain the updated key returned by the service server, and decode the encrypted data based on the updated key to obtain the transmission data.
[0052] In a sixth aspect, a data security transmission device is provided. The viewing end is connected to the firmware end through a network, and the viewing end is connected to the service server through a network. The device includes:
[0053] A data receiving module is used to receive the encrypted data sent by the firmware end; the encrypted data is obtained by encrypting the transmission data based on the updated key. The updated key is obtained by the firmware end from the service server based on the key update request. The key update request is generated based on a preset update time interval, and the updated key is randomly generated by the service server;
[0054] A key request module is used to generate a key acquisition request based on the encrypted data;
[0055] A key acquisition module is used to send the key acquisition request to the service server to obtain the updated key returned by the service server;
[0056] A decoding module is used to decode the encrypted data based on the updated key to obtain the transmission data.
[0057] In a seventh aspect, a data security transmission device is provided, which is applied to a service server. The service server is connected to the firmware side through a network, and the service server is connected to the viewing side through a network. The device includes:
[0058] A request acquisition module, configured to acquire a key update request sent by the firmware side;
[0059] A key determination module, configured to determine an update key from a key table corresponding to the firmware side based on the key update request; the update key is randomly generated;
[0060] A first key sending module, configured to send the update key to the firmware side, so that the firmware side encrypts the transmission data based on the update key to obtain encrypted data, and sends the encrypted data to the viewing side, so that the viewing side generates a key acquisition request based on the encrypted data and sends it to the service server;
[0061] A second key sending module, configured to receive the key acquisition request, determine the corresponding update key and send it to the viewing side, so that the viewing side decodes the encrypted data based on the update key to obtain the transmission data.
[0062] In an eighth aspect, an electronic device is provided, which includes:
[0063] A memory, a processor, and a computer program stored on the memory. The processor executes the computer program to implement the steps of any one of the methods in the first aspect, the second aspect, and the third aspect of the present application.
[0064] In a ninth aspect, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, it implements the data security transmission method shown in any one of the first aspect, the second aspect, and the third aspect of the present application.
[0065] In a tenth aspect, a computer program product is provided, including a computer program. When the computer program is executed by a processor, it implements the steps of any one of the methods in the first aspect, the second aspect, and the third aspect of the present application.
[0066] The beneficial effects brought by the technical solutions provided in the embodiments of the present application are:
[0067] For the data security transmission method provided in the present application, by setting an update time interval, the firmware side periodically generates a key update request and obtains an update key from the service server, and then encrypts the data to be transmitted based on the update key, so that the viewing side obtains the corresponding update key from the service server for decryption to obtain the corresponding transmission data. Using the periodically updated key to encrypt the data can avoid the key being cracked and the data being intercepted during the transmission process, improving the security of data transmission. Description of the Drawings
[0068] To more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the accompanying drawings required for the description of the embodiments of the present application.
[0069] Figure 1 Schematic diagram of an application scenario of a data security transmission method provided by an embodiment of the present application;
[0070] Figure 2 Schematic flow diagram of a data security transmission method applied to the firmware side provided by an embodiment of the present application;
[0071] Figure 3 Schematic diagram of key table update in a data security transmission method provided by an embodiment of the present application;
[0072] Figure 4 Schematic flow diagram of a data security transmission method applied to the viewing end provided by an embodiment of the present application;
[0073] Figure 5 Schematic flow diagram of a data security transmission method applied to the business server provided by an embodiment of the present application;
[0074] Figure 6 Schematic diagram of a data security transmission system provided by an embodiment of the present application;
[0075] Figure 7 Schematic flow diagram of an example of a data security transmission method provided by an embodiment of the present application;
[0076] Figure 8 Schematic structural diagram of a data security transmission device applied to the firmware side provided by an embodiment of the present application;
[0077] Figure 9 Schematic structural diagram of a data security transmission device applied to the viewing end provided by an embodiment of the present application;
[0078] Figure 10 Schematic structural diagram of a data security transmission device applied to the business server provided by an embodiment of the present application;
[0079] Figure 11 Schematic structural diagram of an electronic device to which a data security transmission method provided by an embodiment of the present application is applicable. Detailed implementation manners
[0080] The embodiments of the present application are described below with reference to the accompanying drawings in the present application. It should be understood that the embodiments described below in conjunction with the accompanying drawings are exemplary descriptions for explaining the technical solutions of the embodiments of the present application and do not constitute limitations on the technical solutions of the embodiments of the present application.
[0081] Those skilled in the art can understand that, unless specifically stated otherwise, the singular forms "a", "an", "the" and "said" used herein may also include plural forms. It should be further understood that the terms "comprising" and "including" used in the embodiments of the present application mean that the corresponding features can be implemented as the presented features, information, data, steps, operations, elements and / or components, but do not exclude the implementation of other features, information, data, steps, operations, elements, components and / or their combinations supported by the technical field of the present application, etc. It should be understood that when we say an element is "connected" or "coupled" to another element, the one element can be directly connected or coupled to the other element, or it can mean that the one element and the other element establish a connection relationship through an intermediate element. In addition, the "connection" or "coupling" used herein can include wireless connection or wireless coupling. The terms "or", "and / or", "including at least one of the following" and the like used in the present application can be interpreted inclusively, or mean any one or any combination.
[0082] In the embodiments of the present application, the term "module" or "unit" refers to a computer program with a predetermined function or a part of a computer program, which works together with other related parts to achieve a predetermined goal, and can be fully or partially implemented by using software, hardware (such as a processing circuit or a memory), or a combination thereof. Similarly, a processor (or multiple processors or memories) can be used to implement one or more modules or units. In addition, each module or unit can be a part of the overall module or unit that includes the function of the module or unit.
[0083] To make the purpose, technical solutions and advantages of the present application clearer, the embodiments of the present application will be further described in detail below in conjunction with the accompanying drawings.
[0084] First, the technical terms involved in the present application are introduced and explained:
[0085] Key: It is a string or number used for encrypting and decrypting information. The key defines how the encryption algorithm converts plaintext (readable original data) into ciphertext (encrypted data), and how to convert the ciphertext back into plaintext.
[0086] In the prior art, during the transmission of data such as videos, relatively fixed keys are used to encrypt the data, which poses a high risk. Fixed keys for a long time are easily attacked. Once the key is leaked or cracked, all historical and future monitored video data encrypted with this key may be decrypted and accessed, and the transmission risk of the data is relatively high.
[0087] The data security transmission method, system, device, electronic device, computer-readable storage medium and computer program product provided by the present application aim to solve at least one of the above technical problems in the prior art.
[0088] In view of the above at least one technical problem or area for improvement in the related art, the present application proposes a data security transmission method, system, device, electronic device, computer-readable storage medium, and computer program product. The data security transmission method provided by this solution sets an update time interval, and the firmware side periodically generates a key update request and obtains an updated key from the service server. Then, based on the updated key, the data to be transmitted is encrypted, so that the viewing end obtains the corresponding updated key from the service server for decryption to obtain the corresponding transmitted data. Encrypting the data with a periodically updated key makes it difficult for the key to be cracked, avoids data interception during transmission, and ensures the security of data transmission.
[0089] Furthermore, a key table corresponding to the firmware side can be set in the service server. The firmware side sends a key update request to the service server and obtains the returned key table. The firmware side obtains the key table and makes a selection, enabling more flexible acquisition of the updated key. Among them, the key table in the service server can also be updated periodically. Monitor the time interval between the current time and the time when the updated key was last obtained. When the time interval reaches the preset duration threshold, an update prompt is generated to remind the service server to update the key table, which can enable the service server to update the key in a timely manner and improve the security of data encrypted transmission.
[0090] Next, through the description of several exemplary embodiments, the technical solutions of the embodiments of the present application and the technical effects produced by the technical solutions of the present application will be described. It should be noted that the following embodiments can refer to, draw on, or combine with each other. For the same terms, similar features, and similar implementation steps in different embodiments, they will not be described repeatedly.
[0091] Figure 1 It is a schematic diagram of the application scenario of the data security transmission method provided by the embodiments of the present application. Among them, the application environment can include a firmware side 100, a service server 200, and a viewing end 300. The firmware side 100, the service server 200, and the viewing end 300 are connected to each other pairwise through a network.
[0092] Specifically, based on a preset update time interval, the firmware side 100 generates a key update request, sends the key update request to the service server 200, and obtains an updated key. Among them, the updated key is randomly generated by the service server 200. Based on the updated key, the transmission data is encrypted to obtain encrypted data, and the encrypted data is sent to the viewing end 300, so that the viewing end 300 generates a key acquisition request based on the encrypted data and sends the key acquisition request to the service server 200 to obtain the updated key returned by the service server 200, and decodes the encrypted data based on the updated key to obtain the transmission data.
[0093] In the specific implementation process, both the firmware side 100 and the viewing side 300 can obtain the update key from the service server 200. The firmware side 100 can transmit encrypted video data to the viewing side 300. The firmware side 100 encrypts the data based on the update key and sends it to the viewing side 300. The viewing side 300 decrypts the data based on the corresponding update key. Under certain conditions, the viewing side 300 can also periodically obtain the update key to encrypt the data and transfer the encrypted data to the firmware side 100, realizing the secure transmission of video data between the firmware side 100 and the viewing side 300.
[0094] The above application scenario is just an example and does not limit the application scenario of the data security transmission method of this application.
[0095] In some possible implementation manners, taking the firmware side as the execution subject, an embodiment of this application provides a data security transmission method. As Figure 2 shown, it may include the following steps:
[0096] S210, generate a key update request based on a preset update time interval.
[0097] Among them, the firmware side is connected to the service server through a network, and the firmware side is connected to the viewing side through a network.
[0098] Specifically, monitor the time interval between the current time and the time when the update key was last obtained. If the time interval is greater than or equal to the preset update time interval, it is determined that key update is required, generate a key update request, and then send a request to the service server to obtain the update key, so as to encrypt and transmit the data using the new update key.
[0099] In the specific implementation process, the service server stores the key information of the firmware side and the viewing side. The key information is stored in the form of a key table. The service server will update the keys in the key table regularly. The update interval of the key table is generally greater than the above preset update time interval, so that the firmware side and the viewing side can obtain the update key in time to ensure the security of data transmission.
[0100] In the specific implementation process, the service server can notify the firmware side of the time for the next key table update, indicating that the firmware side obtains the update key within this period of time. For example, for the time period T of the service server to update the key, the firmware side can obtain the update key every T / 3 time or every T / 2 time. The period for obtaining the update key needs to be less than the update period of the service server.
[0101] S220, send the key update request to the service server to obtain the update key.
[0102] Among them, the update key is randomly generated by the service server. To ensure the security of the key, the key generation process should not only be random but also meet the following requirements: the key should not have any predictable patterns, each generated key should be unique, and the key should contain sufficient randomness. The randomness of the key is crucial for ensuring the security of the encryption system.
[0103] Specifically, the firmware side sends a key update request to the service server, instructing the service server to return the update key. The service server can select the update key from the saved firmware key table and send it to the firmware side, or send the corresponding key table to the firmware side so that the firmware side can select the update key from the key table by itself. This can be specifically set based on actual requirements.
[0104] In the specific implementation process, the service server needs to be highly reliable, and the key transmission requires higher security. The service server and the firmware side can establish a connection through the https protocol.
[0105] In the specific implementation process, when the connections between all parties are normal, the above method is used to obtain the update key. However, in some extreme cases, when one or more parties cannot connect to the service server and cannot obtain the key or the key table, there are two solutions: directly terminate the data sending and parsing, or consider password downgrading. For example, directly transmit the key between devices, or agree on a default key.
[0106] S230, encrypt the transmitted data based on the update key to obtain encrypted data.
[0107] Among them, the transmitted data can include video data, status data, configuration data, interaction data, control data, etc.
[0108] Specifically, based on the obtained update key, encrypt the transmitted data to obtain encrypted data. The encrypted data can include relevant information of the key, so that the viewing end can obtain the corresponding key based on the relevant information and parse the encrypted data.
[0109] In the specific implementation process, if the transmitted data is video data, encrypt the video data based on the update key so that each frame of the video carries the index and encryption type of the update key. The encryption type is provided by the software development kit (SDK) of the firmware side. The encryption type can include: symmetric encryption, asymmetric encryption, hash-based encryption, and key exchange protocol-based encryption, etc. Among them, the index can be the unique identifier corresponding to the key, or the index of the update key in the corresponding key table. The purpose is to uniquely determine a key.
[0110] S240: Send the encrypted data to the viewing end, so that the viewing end generates a key acquisition request based on the encrypted data, and sends the key acquisition request to the service server to obtain the updated key returned by the service server, and decode the encrypted data based on the updated key to obtain the transmission data.
[0111] Specifically, send the encrypted data to the viewing end. The viewing end receives the encrypted data, generates a key acquisition request based on the key-related information in the encrypted data, and sends the key acquisition request to the service server to obtain the updated key returned by the service server, and decode the encrypted data based on the updated key to obtain the transmission data.
[0112] In the specific implementation process, the firmware end can be a video surveillance device, the viewing end can be a terminal for viewing videos, and the data transmitted from the firmware end to the viewing end can be video data. When the transmission data is video data, the viewing end receives the encrypted data, and uses the index and encryption type carried in each frame of the video data to generate a key acquisition request, obtains the key returned by the service server, and decodes the video data to obtain the original video.
[0113] In the specific implementation process, both the firmware end and the viewing end will regularly obtain the updated key from the service server. However, since they do not obtain it synchronously, after the viewing end receives the encrypted data, it can search for the corresponding updated key in the keys locally stored at the viewing end based on the encrypted data. If it exists, it directly decodes the encrypted data based on the updated key. If it does not exist, it generates a key acquisition request and goes to the service end to obtain the corresponding updated key, thereby completing data decoding to obtain the transmission data.
[0114] In some possible implementation manners, in the above step of sending the key update request to the service server to obtain the updated key, it includes:
[0115] Send the key update request to the service server to obtain the corresponding key table;
[0116] Based on the key table, determine the updated key.
[0117] Among them, the key table can include a preset number of keys and the corresponding indexes. When the key table is initialized, a preset number of keys are generated, and the keys of the entire key table are stored in order. For example, they can be sorted according to the generation time of the keys.
[0118] Specifically, both the service server and the firmware end store the key table corresponding to the firmware end. The service server will regularly update the keys in the key table. The firmware end sends the key update request to the service server, and can obtain the updated key table. Based on the obtained key table, the updated key can be determined.
[0119] In some possible embodiments, determining the update key based on the key table in the above steps includes:
[0120] Taking the key at a preset position in the key table as the selected key;
[0121] Determining the update key based on the selected key.
[0122] Specifically, the key table is arranged in a certain order. When selecting a key, the key at the preset position can be selected as the update key, or based on certain rules, the update key can be determined based on the selected key.
[0123] In the specific implementation process, when the firmware side needs to be encrypted, the key table returned by the service server is obtained. Since there may be a time difference in the update of the key table of the service server when the firmware side pulls a new key, for fault tolerance, if the key table includes n keys, the key can be obtained from the n / 3 position of the key table as the update key. If the number of the key table cannot be divided evenly, then based on certain rules, the key before or after this position can be selected as the update key. How to select specifically is determined according to actual requirements. For example, for a key table with 9 keys, the key at the 1 / 3 position can be selected. Counting in the order of 0, 1, 2, 3... that is, the key at the 4th position is selected as the selected key. If it is a key table with 10 keys, take the 1 / 3 position, that is, round down, and select the key at the 4th position as the selected key.
[0124] In some possible embodiments, determining the update key based on the selected key in the above steps includes:
[0125] Obtaining the current key;
[0126] Comparing the current key with the selected key to determine whether the keys are the same;
[0127] If they are the same, taking the key at the next position in the key table as the update key; the key table is arranged in order according to the creation time of the keys;
[0128] If they are not the same, taking the selected key as the update key.
[0129] Wherein, the key table is arranged in order according to the creation time of the keys.
[0130] Specifically, select the selected key at the preset position, compare the selected key with the currently used key to determine whether the keys are the same. If they are the same, it means that the service server has not updated the key table, then take the key at the next position in the key table as the update key. If they are not the same, take the selected key as the update key.
[0131] In the specific implementation process, when encryption is required at the firmware side, the selected key is obtained. If the selected key has not been updated based on the previous one and the time interval since the last key update has exceeded the update time interval of the key table, the index is directly shifted one position backward until the end of the key table is reached.
[0132] In some possible implementation manners, the above method further includes:
[0133] Determine the time interval between the current time and the time when the updated key was last obtained, and judge whether the key table needs to be updated;
[0134] If it is determined that the key table needs to be updated, an update prompt is generated and sent to the service server so that the service server can update the key table.
[0135] Specifically, since only simple password update operations are included on the service server, it is necessary to monitor the time interval between the current time and the time when the updated key was last obtained based on the firmware side to judge whether the key table needs to be updated. If it is determined that the key table needs to be updated, an update prompt is generated and sent to the service server to prompt the service server to update the key table.
[0136] In the specific implementation process, the firmware side and the viewing side will respectively record the selection time of the updated key. When the preset validity period is reached, the service server is reminded to randomly generate a key and update the corresponding key table. The service server needs to randomly generate a key every preset time interval and update the key table. As Figure 3 shown, there are 9 fixed keys in the key table. When initializing the key table, 9 keys are generated. The 9 keys can be stored in the order of generation. Key 1 is the earliest generated, and key 9 is the latest generated. When updating the key table, the earliest input key 1 is deleted, and the new key 10 is generated and added to the end of the key table to form a new key table. Each key (i.e., the value shown in the figure) has a unique index (i.e., the index shown in the figure). Each time a key is replaced, the index is also updated. However, when selecting an updated key, the index is not considered, and the key at the preset position can be selected.
[0137] In some possible implementation manners, in the above steps, determining the time interval between the current time and the time when the updated key was last obtained, and judging whether the key table needs to be updated includes:
[0138] Determine the time interval between the current time and the time when the updated key was last obtained;
[0139] Compare the time interval with the preset time threshold to judge whether the key table needs to be updated.
[0140] Among them, the preset time threshold is greater than the preset update time interval.
[0141] Specifically, determine the time interval between the current time and the time when the update key was last obtained, compare the time interval with a preset time threshold to determine whether the key table needs to be updated. If it is necessary, remind the service server to update the key table. If not, the original key can be continued to be used for encrypted transmission.
[0142] In the specific implementation process, the service server can, based on the time when the firmware end obtains the update key this time, remind the firmware end that it can update the key before the next key update time. For example, the service server updates the key table every T minutes, and the firmware end can pull the update key at T / 3, T / 2 or other times.
[0143] In some possible implementation manners, in the above step, comparing the time interval with the preset time threshold to determine whether the key table needs to be updated includes:
[0144] If the time interval is greater than or equal to the preset time threshold, it is determined that the key table needs to be updated;
[0145] If the time interval is less than the preset time threshold, it is determined that the key table does not need to be updated.
[0146] Specifically, compare the time interval with the preset time threshold to determine whether the key table needs to be updated. If the time interval is equal to or greater than the preset time threshold, a prompt can be issued to remind the service server to update the key table. If it is not greater than the preset time threshold, the original key can be continued to be used for encrypted transmission. Based on the prompt information of the firmware end, reminding the service server to update the key and the key table can ensure the regular update of the key in the service server, so that the key of the firmware end is also updated in time, improving the security of information encrypted transmission.
[0147] In some possible implementation manners, taking the execution entity as the viewing end as an example, the embodiment of the present application provides a data secure transmission method, as Figure 4 shown, which may include the following steps:
[0148] S410, receive the encrypted data sent by the firmware end.
[0149] Among them, the viewing end is connected to the firmware end through a network, the viewing end is connected to the service server through a network, and data can be transmitted between the firmware end and the viewing end in a point-to-point P2P manner or through the cloud.
[0150] Among them, the encrypted data is obtained by encrypting the transmission data based on the update key. The update key is obtained by the firmware end from the service server based on the key update request. The key update request is generated based on the preset update time interval, and the update key is randomly generated by the service server.
[0151] Specifically, the viewing end receives the encrypted data sent by the firmware end, obtains the information about the key in the encrypted data, and decodes the corresponding updated key pair data based on the key information to obtain the originally sent data.
[0152] In the specific implementation process, both the firmware end and the viewing end regularly obtain the updated key from the service server. However, since the updates are not pulled synchronously, after the viewing end receives the encrypted data, it can search for the corresponding updated key in the keys stored locally at the viewing end based on the encrypted data. If it exists, it directly decodes the encrypted data based on the updated key. If it does not exist, it generates a key acquisition request and goes to the service end to obtain the corresponding updated key, thereby completing the data decoding and obtaining the transmitted data.
[0153] S420, generate a key acquisition request based on the encrypted data.
[0154] Specifically, the encrypted data includes information related to the corresponding encryption key. By obtaining the key-related information, information such as the index or encryption type of the corresponding key can be determined. Based on the key-related information, a key acquisition request is generated and sent to the service server to obtain the corresponding updated key.
[0155] In the specific implementation process, both the firmware end and the viewing end regularly obtain the updated key from the service server. However, since the updates are not obtained synchronously, after the viewing end receives the encrypted data, it can search for the corresponding updated key in the keys stored locally at the viewing end based on the encrypted data. If it exists, it directly decodes the encrypted data based on the updated key. If it does not exist, it generates a key acquisition request and goes to the service end to obtain the corresponding updated key, thereby completing the data decoding and obtaining the transmitted data.
[0156] In the specific implementation process, the viewing end sends the key acquisition request to the service server, instructing the service server to return the updated key. The service server can select the updated key from the saved viewing end key table and send it to the viewing end, or send the corresponding key table to the viewing end so that the viewing end can select the updated key by itself in the key table. Specifically, it can be set based on actual requirements.
[0157] In the specific implementation process, the viewing end can obtain the updated key after receiving the encrypted data, or regularly obtain the updated key from the service server based on a preset time interval. The service server can notify the viewing end of the time for the next update of the key table, instructing the viewing end to obtain the updated key within this period. For example, for the service server's key update time period T, the viewing end can obtain the updated key once every T / 3 time, or once every T / 2 time. The period for obtaining the updated key needs to be less than the service server's update period.
[0158] S430. Send a key acquisition request to the service server and obtain the updated key returned by the service server.
[0159] Specifically, the viewing end sends a key acquisition request to the service server, obtains the updated key returned by the service server, or obtains the corresponding key table returned by the service server, and selects the corresponding updated key from the key table.
[0160] In the specific implementation process, the service server needs to maintain high reliability, and the key transmission requires higher security. The service server and the viewing end can establish a connection through the secure transmission protocol https.
[0161] S440. Decode the encrypted data based on the updated key to obtain the transmitted data.
[0162] Specifically, obtain the updated key corresponding to the encrypted data and the corresponding encryption type, and decode the encrypted data based on the updated key and the encryption type to obtain the transmitted data.
[0163] In the specific implementation process, the firmware end can be a video surveillance device, and the viewing end can be a terminal for viewing videos. The data transmitted from the firmware end to the viewing end can be video data. When the transmitted data is video data, the viewing end receives the encrypted data, generates a key acquisition request using the index and encryption type carried in each frame of the video data, obtains the updated key returned by the service server, and decodes the video data to obtain the original transmitted video.
[0164] In the specific implementation process, the viewing end can also obtain the updated key regularly. When the viewing end sends encrypted data to the firmware end, it can request an updated key from the service server and obtain the key table returned by the service server. Since there may be a time difference in the update of the key table of the service server when the viewing end pulls a new key, for fault tolerance, the key table includes n keys, and the key can be obtained from the n / 3 position of the key table as the updated key. If the number of the key table cannot be divided evenly, the key before or after this position can be selected as the updated key based on certain rules. How to select specifically is determined according to actual needs. For example, for a key table with 9 keys, the key at the 1 / 3 position can be selected. Counting in the order of 0, 1, 2, 3... that is, select the key at the 4th position as the selected key. If it is a key table with 10 keys, take the 1 / 3 position, that is, round down, and select the key at the 4th position as the selected key.
[0165] In some possible implementation manners, taking the execution subject as the service server as an example, the embodiment of the present application provides a data security transmission method, as Figure 5 shown, which may include the following steps:
[0166] S510. Obtain the key update request sent by the firmware end.
[0167] Among them, the service server is connected to the firmware side through a network, and the service server is connected to the viewing side through a network. Specifically, data can be transmitted between the firmware side and the viewing side in a peer-to-peer (P2P) manner or through the cloud. The service server and the firmware side can be connected through the secure network transmission protocol https, and the service server and the viewing side can be connected through https.
[0168] Among them, the key update request is generated based on a preset update time interval.
[0169] Specifically, obtain the key update request sent by the firmware side. Based on the key update request, the corresponding key table can be sent to the firmware side through the https protocol, or an updated key can be selected from the key table and sent to the firmware side.
[0170] S520, determine the corresponding updated key based on the key update request.
[0171] Among them, the updated key is randomly generated.
[0172] Specifically, based on the received key update request, select the updated key after updating from the corresponding key table. Since the key table is arranged in a certain order, when selecting a key, the key at a preset position can be selected as the updated key, or based on a certain rule, the updated key can be determined based on the selected key.
[0173] In the specific implementation process, the service server stores the key tables corresponding to the firmware side and the viewing side respectively. Since only simple key update operations are included on the service server, it is necessary to monitor, through the firmware side or the viewing side, the time interval between the current time and the time of the last key table update to determine whether the key table needs to be updated. If it is determined that the key table needs to be updated, the firmware side or the viewing side generates an update prompt and prompts the service server. When the service server receives the update prompt, it updates the corresponding key table. For example, if the update prompt is sent by the firmware side, it updates the key table corresponding to the firmware side; if the update prompt is sent by the viewing side, it updates the key table corresponding to the viewing side. Among them, the key tables corresponding to the firmware side and the viewing side only need to have an intersection.
[0174] S530, send the updated key to the firmware side so that the firmware side encrypts the transmitted data based on the updated key to obtain encrypted data, and sends the encrypted data to the viewing side so that the viewing side generates a key acquisition request based on the encrypted data and sends it to the service server.
[0175] Specifically, the update key is sent to the firmware side so that the firmware side encrypts the transmitted data based on the update key to obtain encrypted data, and sends the encrypted data to the viewing side. The viewing side checks whether the corresponding update key exists locally. If it exists, it decodes the encrypted data based on the corresponding update key. If it does not exist, it generates a key acquisition request based on the encrypted data, and obtains the corresponding update key from the service server for decoding to obtain the transmitted data.
[0176] S540, receive the key acquisition request, determine the corresponding update key and send it to the viewing side so that the viewing side decodes the encrypted data based on the update key to obtain the transmitted data.
[0177] Specifically, receive the key acquisition request sent by the viewing side, determine the corresponding update key from the key table corresponding to the viewing side and send it to the viewing side so that the viewing side decodes the encrypted data based on the update key to obtain the transmitted data.
[0178] In the specific implementation process, the service server stores the key tables corresponding to the firmware side and the viewing side. The service server updates the corresponding key tables regularly. The key tables corresponding to both ends can be updated with new keys at the same time. After the update, wait for the firmware side and the viewing side to pull the update key regularly. Among them, the time intervals for the firmware side and the viewing side to pull the update key can be different.
[0179] In the above embodiment, by setting the update time interval, the firmware side regularly generates a key update request and obtains the update key from the service server, so as to encrypt the data to be transmitted based on the update key, so that the viewing side obtains the corresponding update key from the service server for decryption to obtain the corresponding transmitted data. Using the regularly updated key to encrypt the data makes the key difficult to be cracked, avoids the data being intercepted during the transmission process, and ensures the security of data transmission.
[0180] Furthermore, a key table corresponding to the firmware side can be set in the service server. The firmware side sends a key update request to the service server to obtain the returned key table. The firmware side obtains the key table and makes a selection, which can obtain the update key more flexibly. Among them, the key table in the service server can also be updated regularly. Monitor the time interval between the current time and the time when the update key was last obtained. When the time interval reaches the preset duration threshold, generate an update prompt to remind the service server to update the key table, which can enable the service server to update the key in time and improve the security of data encrypted transmission.
[0181] In one example, the data secure transmission system of the present application, such as Figure 6As shown, it may include a service server, a firmware side, and a viewing side. Data is transmitted between the firmware side and the viewing side in a peer-to-peer (P2P) manner or through the cloud. The service server transmits an updated key table (i.e., the password table shown in the figure) to the firmware side and the viewing side, where:
[0182] The firmware side is used to generate a key update request based on a preset update time interval and send the key update request to the service server;
[0183] The service server is used to obtain the key update request and, based on the key update request, determine an updated key from the key table corresponding to the firmware side and send the updated key to the firmware side; wherein, the updated key is randomly generated by the service server;
[0184] The firmware side is used to encrypt the transmitted data based on the updated key to obtain encrypted data and send the encrypted data to the viewing side;
[0185] The viewing side is used to receive the encrypted data sent by the firmware side, generate a key acquisition request based on the encrypted data, and send the key acquisition request to the service server;
[0186] The service server is used to receive the key acquisition request, determine the corresponding updated key, and send it to the viewing side;
[0187] The viewing side is used to obtain the updated key returned by the service server and decode the encrypted data based on the updated key to obtain the transmitted data.
[0188] Specifically, the key table includes a fixed number of keys (i.e., the values shown in the figure) and corresponding indexes (i.e., the indexes shown in the figure). When selecting an updated key from the key table, as shown in the figure, for a key table with 9 keys, the 4th key is selected as the updated key. Both the firmware side and the viewing side select the keys at the corresponding positions, thereby realizing the encryption and decoding of the transmitted data and completing the secure transmission of the transmitted data.
[0189] In one example, the data secure transmission method of the present application, as Figure 7 shown, may include:
[0190] The firmware side generates a key update request based on a preset update time interval and sends the key update request to the service server;
[0191] The service server obtains the key update request and, based on the key update request, sends the corresponding key table to the firmware side;
[0192] The firmware side selects the key at the preset position in the key table as the selected key, thereby determining the update key, and encrypts the video data based on the update key to obtain the encrypted data and sends it to the viewing side. Each frame of the video data carries the index and encryption type corresponding to the update key;
[0193] The viewing side receives the encrypted data sent by the firmware side, generates a key acquisition request based on the index and encryption type of each video frame in the encrypted data, and sends the key acquisition request to the service server;
[0194] The service server receives the key acquisition request and sends the corresponding key table to the viewing side;
[0195] The viewing side obtains the corresponding update key based on the returned key table, and decodes the encrypted data based on the update key to obtain the transmitted video data.
[0196] In the above data security transmission method, by setting the update time interval, the firmware side regularly generates a key update request and obtains the update key from the service server, thereby encrypting the data to be transmitted based on the update key, so that the viewing side obtains the corresponding update key from the service server for decryption to obtain the corresponding transmitted data. Using the regularly updated key to encrypt the data makes the key difficult to be cracked, avoids the data being intercepted during the transmission process, and ensures the security of data transmission.
[0197] Furthermore, a key table corresponding to the firmware side can be set in the service server. The firmware side sends a key update request to the service server to obtain the returned key table, and the firmware side obtains and selects the key table, which can obtain the update key more flexibly. Among them, the key table in the service server can also be updated regularly. Monitor the time interval between the current time and the time when the update key was last obtained. When the time interval reaches the preset duration threshold, an update prompt is generated to remind the service server to update the key table, which can enable the service server to update the key in time and improve the security of data encrypted transmission.
[0198] An embodiment of the present application provides a data security transmission device, which is applied to the firmware side, as Figure 8 shown. The data security transmission device 80 may include: a timing update module 801, an acquisition module 802, an encryption module 803, and a sending module 804, where,
[0199] The timing update module 801 is used to generate a key update request based on a preset update time interval;
[0200] The acquisition module 802 is used to send the key update request to the service server to obtain the update key; the update key is randomly generated by the service server;
[0201] An encryption module 803, configured to encrypt the transmitted data based on an updated key to obtain encrypted data;
[0202] A sending module 804, configured to send the encrypted data to a viewing end, so that the viewing end generates a key acquisition request based on the encrypted data, and sends the key acquisition request to a service server to obtain an updated key returned by the service server, and decode the encrypted data based on the updated key to obtain the transmitted data.
[0203] As an alternative embodiment, in this device, the acquisition module 802 is specifically configured to:
[0204] Send a key update request to the service server to obtain a corresponding key table;
[0205] Determine an updated key based on the key table.
[0206] As an alternative embodiment, in this device, the acquisition module 802 is specifically configured to:
[0207] Use the key at a preset position in the key table as the selected key;
[0208] Determine an updated key based on the selected key.
[0209] As an alternative embodiment, in this device, the acquisition module 802 is specifically configured to:
[0210] Obtain the current key;
[0211] Compare the current key with the selected key to determine whether the keys are the same;
[0212] If they are the same, use the key at the next position in the key table as the updated key; the key table is arranged in order of the creation time of the keys;
[0213] If they are not the same, use the selected key as the updated key.
[0214] As an alternative embodiment, in this device, it further includes a key table update module, specifically configured to:
[0215] Determine the time interval between the current time and the time when the updated key was last obtained, and determine whether the key table needs to be updated;
[0216] If it is determined that the key table needs to be updated, generate an update prompt and send it to the service server, so that the service server updates the key table.
[0217] As an alternative embodiment, in this device, the key table update module is specifically configured to:
[0218] Determine the time interval between the current time and the time when the updated key was last obtained;
[0219] Compare the interval duration with a preset duration threshold to determine whether the key table needs to be updated; the preset duration threshold is greater than the preset update time interval.
[0220] As an optional embodiment, in this device, the key table update module is specifically configured to:
[0221] If the interval duration is greater than or equal to the preset duration threshold, it is determined that the key table needs to be updated;
[0222] If the interval duration is less than the preset duration threshold, it is determined that the key table does not need to be updated.
[0223] An embodiment of the present application provides a data security transmission device, which is applied to the viewing end. As Figure 9 shown, the data security transmission device 90 may include: a data receiving module 901, a key request module 902, a key acquisition module 903, and a decoding module 904. Among them,
[0224] The data receiving module 901 is configured to receive encrypted data sent by the firmware end; the encrypted data is obtained by encrypting the transmission data based on an updated key. The updated key is obtained by the firmware end from the service server based on a key update request, and the key update request is generated based on a preset update time interval. The updated key is randomly generated by the service server;
[0225] The key request module 902 is configured to generate a key acquisition request based on the encrypted data;
[0226] The key acquisition module 903 is configured to send the key acquisition request to the service server and obtain the updated key returned by the service server;
[0227] The decoding module 904 is configured to decode the encrypted data based on the updated key to obtain the transmission data.
[0228] An embodiment of the present application provides a data security transmission device. As Figure 10 shown, the data security transmission device 10 may include: a request acquisition module 1001, a key determination module 1002, a first key sending module 1003, and a second key sending module 1004. Among them,
[0229] The request acquisition module 1001 is configured to acquire a key update request sent by the firmware end;
[0230] The key determination module 1002 is configured to determine an updated key from the key table corresponding to the firmware end based on the key update request; the updated key is randomly generated;
[0231] The first key sending module 1003 is configured to send an updated key to the firmware side, so that the firmware side encrypts the transmitted data based on the updated key to obtain encrypted data, and sends the encrypted data to the viewing side, so that the viewing side generates a key acquisition request based on the encrypted data and sends it to the service server;
[0232] The second key sending module 1004 is configured to receive the key acquisition request, determine the corresponding updated key and send it to the viewing side, so that the viewing side decodes the encrypted data based on the updated key to obtain the transmitted data.
[0233] The data security transmission device provided by this application, by setting an update time interval, the firmware side regularly generates a key update request and obtains an updated key from the service server, so as to encrypt the data to be transmitted based on the updated key, so that the viewing side obtains the corresponding updated key from the service server for decryption to obtain the corresponding transmitted data. Using the regularly updated key to encrypt the data makes the key difficult to be cracked, avoids the data being intercepted during transmission, and ensures the security of data transmission.
[0234] Furthermore, a key table corresponding to the firmware side can be set in the service server. The firmware side sends a key update request to the service server to obtain the returned key table. The firmware side obtains the key table and makes a selection, which can obtain the updated key more flexibly. Among them, the key table in the service server can also be updated regularly. Monitor the time interval between the current time and the time when the updated key was last obtained. When the time interval reaches the preset duration threshold, an update prompt is generated to remind the service server to update the key table, which can enable the service server to update the key in time and improve the security of data encrypted transmission.
[0235] The device in the embodiment of this application can execute the method provided by the embodiment of this application. Its implementation principle is similar and has corresponding technical effects. The actions performed by each module in the device of each embodiment of this application correspond to the steps in the method of each embodiment of this application. For the detailed function description of each module of the device, reference can be specifically made to the description in the corresponding method shown above, and details are not described here again.
[0236] In an embodiment of the present application, an electronic device is provided, which includes a memory, a processor, and a computer program stored in the memory. The processor executes the above computer program to implement the steps of the method provided in any optional embodiment of the present application. Compared with the prior art, it can be realized that by setting an update time interval, the firmware side periodically generates a key update request and obtains an updated key from the service server, so as to encrypt the data to be transmitted based on the updated key, so that the viewing end can obtain the corresponding updated key from the service server for decryption to obtain the corresponding transmitted data. Encrypting the data with a periodically updated key makes the key difficult to crack, avoids the data being intercepted during transmission, and ensures the security of data transmission.
[0237] In an optional embodiment, an electronic device is provided, such as Figure 11 shown Figure 11 The electronic device 1100 shown includes: a processor 1101 and a memory 1103. Among them, the processor 1101 and the memory 1103 are connected, such as through a bus 1102. Optionally, the electronic device 1100 may further include a transceiver 1104, and the transceiver 1104 may be used for data interaction between the electronic device and other electronic devices, such as data sending and / or data receiving, etc. It should be noted that in actual applications, the transceiver 1104 is not limited to one, and the structure of the electronic device 1100 does not constitute a limitation on the embodiments of the present application.
[0238] The processor 1101 may be a CPU (Central Processing Unit, central processor), a general-purpose processor, a DSP (Digital Signal Processor, data signal processor), an ASIC (Application Specific Integrated Circuit, application-specific integrated circuit), an FPGA (Field Programmable Gate Array, field programmable gate array), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It can implement or execute various exemplary logical blocks, modules, and circuits described in connection with the disclosure of the present application. The processor 1101 may also be a combination that implements a computing function, such as a combination including one or more microprocessors, a combination of a DSP and a microprocessor, etc.
[0239] The bus 1102 may include a path for transmitting information between the above components. The bus 1102 can be a PCI (Peripheral Component Interconnect) bus, an EISA (Extended Industry Standard Architecture) bus, or the like. The bus 1102 can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, Figure 11 it is only represented by a thick line in Figure 11 , but it does not mean that there is only one bus or one type of bus.
[0240] The memory 1103 can be a ROM (Read Only Memory) or other types of static storage devices that can store static information and instructions, a RAM (Random Access Memory) or other types of dynamic storage devices that can store information and instructions, or it can also be an EEPROM (Electrically Erasable Programmable Read Only Memory), a CD-ROM (Compact Disc Read Only Memory), or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media, other magnetic storage devices, or any other medium that can be used to carry or store computer programs and can be read by a computer, which is not limited here.
[0241] The memory 1103 is used to store the computer program for implementing the embodiments of this application, and is controlled by the processor 1101 to execute. The processor 1101 is used to execute the computer program stored in the memory 1103 to implement the steps shown in the foregoing method embodiments.
[0242] Among them, the electronic device includes but is not limited to: an electronic device installed with a data security transmission system and capable of implementing the data security transmission method.
[0243] The embodiments of this application provide a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps and corresponding contents of the foregoing method embodiments can be implemented.
[0244] It should be noted that the computer-readable storage medium described above in this application can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of a computer-readable storage medium can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.
[0245] The embodiments of this application also provide a computer program product, including a computer program, which when executed by a processor can implement the steps and corresponding content of the foregoing method embodiments.
[0246] The terms "first", "second", "third", "fourth", "1", "2", etc. (if any) in the description and claims of this application and the above-mentioned drawings are used to distinguish similar objects and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of this application described here can be implemented in an order other than that shown in the drawings or described in words.
[0247] The flowcharts and block diagrams in the drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in the flowchart or block diagram can represent a module, a program segment, or a part of code, and this module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks can occur in a different order than that marked in the drawings. For example, two consecutive blocks shown can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0248] It should be understood that although the flowchart of the embodiments of the present application indicates each operation step by arrows, the execution order of these steps is not limited to the order indicated by the arrows. Unless there is a clear description in this article, in some implementation scenarios of the embodiments of the present application, the implementation steps in each flowchart can be executed in other orders according to requirements. In addition, some or all of the steps in each flowchart may include multiple sub-steps or multiple stages based on the actual implementation scenario. Some or all of these sub-steps or stages can be executed at the same time, and each sub-step or stage among these sub-steps or stages can also be executed at different times respectively. In the scenario where the execution times are different, the execution order of these sub-steps or stages can be flexibly configured according to requirements, and the embodiments of the present application do not limit this.
[0249] The above are only optional implementation manners of some implementation scenarios of the present application. It should be noted that for those of ordinary skill in the art, without departing from the technical concept of the solution of the present application, adopting other similar implementation means based on the technical idea of the present application also belongs to the protection scope of the embodiments of the present application.
Claims
1. A data security transmission method, characterized in that: Applied to the firmware end, the firmware end is connected to the service server through a network, and the firmware end is connected to the viewing end through a network, including: Generate a key update request based on a preset update time interval; Sending the key update request to the service server to obtain an updated key; the updated key is randomly generated by the service server; Based on the updated key, encrypting the transmission data to obtain encrypted data; The encrypted data is sent to the viewing end so that the viewing end generates a key acquisition request based on the encrypted data, and the key acquisition request is sent to the business server to obtain the updated key returned by the business server, and the encrypted data is decoded based on the updated key to obtain the transmission data.
2. The data security transmission method according to claim 1, characterized in that: The step of sending the key update request to the service server to obtain an updated key includes: Sending the key update request to the service server to obtain a corresponding key table; Based on the key table, the updated key is determined.
3. The data security transmission method according to claim 2, characterized in that: The step of determining the updated key based on the key table includes: Using a key at a preset position in the key table as a selected key; Based on the selected key, the updated key is determined.
4. The data security transmission method according to claim 3, characterized in that: The step of determining the updated key based on the selected key includes: Get the current key; Compare the current key with the selected key to determine whether the keys are the same; If they are the same, the key at the next position in the key table is used as the updated key; the key table is arranged in order according to the creation time of the keys; If they are not the same, the selected key is used as the updated key.
5. The data security transmission method according to claim 2, characterized in that: The method further comprises: Determine the interval between the current time and the last time the key was updated, and judge whether the key table needs to be updated; If it is determined that the key table needs to be updated, an update prompt is generated and sent to the service server, so that the service server updates the key table.
6. The data security transmission method according to claim 5, characterized in that: The determining of the interval between the current time and the last time the key was updated, and judging whether the key table needs to be updated, includes: Determine the time interval between the current time and the last time the key was updated; The interval duration is compared with a preset duration threshold to determine whether the key table needs to be updated; the preset duration threshold is greater than the preset update time interval.
7. The data security transmission method according to claim 6, characterized in that: The comparing the interval duration with a preset duration threshold to determine whether the key table needs to be updated includes: If the interval duration is greater than or equal to the preset duration threshold, determining that the key table needs to be updated; If the interval duration is less than the preset duration threshold, it is determined that the key table does not need to be updated.
8. A data security transmission method, characterized in that: Applied to a viewing end, the viewing end is connected to a firmware end through a network, and the viewing end is connected to a service server through a network, including: receiving encrypted data sent by the firmware end; the encrypted data is obtained by encrypting the transmission data based on the update key, the update key is obtained by the firmware end from the business server based on a key update request, the key update request is generated based on a preset update time interval, and the update key is randomly generated by the business server; Based on the encrypted data, generating a key acquisition request; Sending the key acquisition request to the service server to obtain the updated key returned by the service server; The encrypted data is decoded based on the updated key to obtain the transmission data.
9. A data security transmission method, characterized in that: Applied to a business server, the business server is connected to a firmware end through a network, and the business server is connected to a viewing end through a network, including: Obtaining a key update request sent by the firmware end; the key update request is generated based on a preset update time interval; Based on the key update request, determining a corresponding update key; the update key is randomly generated; Sending the update key to the firmware end, so that the firmware end encrypts the transmission data based on the update key to obtain encrypted data, and sending the encrypted data to the viewing end, so that the viewing end generates a key acquisition request based on the encrypted data and sends it to the service server; The key acquisition request is received, a corresponding update key is determined and sent to the viewing end, so that the viewing end decodes the encrypted data based on the update key to obtain the transmission data.
10. A data security transmission system, characterized in that: It includes a business server, a firmware end and a viewing end, wherein the business server, the firmware end and the viewing end are connected in pairs, wherein: The firmware end is used to generate a key update request based on a preset update time interval, and send the key update request to the service server; The business server is used to obtain the key update request, and based on the key update request, determine the update key from the key table corresponding to the firmware end, and send the update key to the firmware end; the update key is randomly generated by the business server; The firmware end is used to encrypt the transmission data based on the update key to obtain encrypted data, and send the encrypted data to the viewing end; The viewing end is used to receive the encrypted data sent by the firmware end, generate a key acquisition request based on the encrypted data, and send the key acquisition request to the business server; The service server is used to receive the key acquisition request, determine the corresponding update key and send it to the viewing terminal; The viewing terminal is used to obtain the update key returned by the service server, and decode the encrypted data based on the update key to obtain the transmission data.