Transparent encryption and decryption method and device for data transmission
By designing transparent new sending and receiving functions for the operating system, the encryption and decryption process of network data transmission is realized, and the problems of high burden on user-writing functions in the prior art are solved, fixed encryption and decryption methods are easy to be cracked, and communication error handling is inconsistent, realizing the security and reliability of data transmission.
Patent Information
- Application Number
- CN202510336195.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-21
- Publication Date
- 2025-06-20
AI Technical Summary
In the prior art, in the process of encrypting and decrypting network data, there are problems such as high burden on user writing functions, fixed encryption and decryption methods are easy to be cracked, and inconsistent communication error handling.
Design a transparent encryption and decryption method, and realize transparent encryption and decryption of data transmission by designing new sending functions and new receiving functions for the operating system. The new sending function adds a conventional dynamically changing string to the data and encrypts it, while the new receiving function decrypts and judges the string when receiving the data to ensure the security and integrity of the data.
It realizes transparent encryption and decryption during data transmission, prevents third parties from illegally stealing or forging data, and uniformly handles errors or illegal data packets by monitoring machines, improving the security and reliability of data transmission.
Smart Images

Figure CN120185807A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of computer information technology, and particularly relates to a method and device for transparent encryption and decryption of data transmission. Background Art
[0002] In the information age, geography is no longer a limiting condition for information interaction, and communication can be achieved even between departments scattered in multiple cities within an enterprise or between different enterprises. Communication inevitably requires data transmission over the Internet, and unencrypted data is easily stolen or tampered with by a third party during transmission, resulting in serious consequences such as information leakage and poor security.
[0003] Currently, the methods for encrypting and decrypting network data have the following deficiencies: First, users write encryption functions and decryption functions, which brings a burden to programmers, and this method requires explicit calls to the encryption function and decryption function in the program, and programs without calls to the encryption function and decryption function do not work; second, the encryption and decryption methods are relatively fixed and are easily cracked over time; third, problems such as communication errors discovered by a machine are usually handled by that machine itself or not handled, and there is no mechanism to send them to a designated machine for unified processing. Summary of the Invention
[0004] The purpose of the present invention is to provide a method and device for transparent encryption and decryption of data transmission, which realizes the transparency of encryption and decryption during data transmission, while preventing a third party from illegally stealing or forging data, and realizes unified processing of error data.
[0005] To achieve the above purpose, the present invention adopts the following technical solutions.
[0006] A method for transparent encryption and decryption of data transmission includes:
[0007] S1. Design a new sending function and a new receiving function to replace the network communication sending function and receiving function in the operating system standard library for the operating system, and release them together with the operating system;
[0008] S2. When the user program sends transmission data, the operating system calls the new sending function, adds a predefined dynamically changing string to the transmission data, and encrypts it;
[0009] S3. After the operating system receives the transmission data, it calls the new receiving function to decrypt and judge the predefined dynamically changing string, and after judging correctly, sends it to the receiving user program.
[0010] Further, the design method of the new sending function and the new receiving function in step S1 includes:
[0011] S11: Obtain the sending function and receiving function for network communication in the standard library of the operating system, which are called the original sending function and the original receiving function;
[0012] S12: Create a new file and add a new sending function and a new receiving function, where the new sending function and the new receiving function have the same function name, parameters, and return values as the original sending function and the original receiving function;
[0013] S13: Add encryption code to the new sending function;
[0014] S14: Add decryption code to the new receiving function;
[0015] S15: Compile the new file into a dynamic link library and add it to the operating system;
[0016] S16: Set the dynamic link library as the priority function library.
[0017] Furthermore, step S13 includes:
[0018] S131: The sender and the receiver agree on a dynamically changing string;
[0019] S132: Place the agreed dynamically changing string before the transmission data to be sent by the sender's user program to form new transmission data of "dynamically changing string + transmission data";
[0020] S133: Encrypt the new transmission data to obtain encrypted data;
[0021] S134: Call the original sending function to send the encrypted data to the receiver.
[0022] Furthermore, step S14 includes:
[0023] Step S141: Determine the dynamically changing string agreed upon by the sender and the receiver;
[0024] Step S142: Extract the transmission data from the data packet received over the network;
[0025] Step S143: Decrypt the extracted transmission data;
[0026] Step S144: If decryption fails, send the transmission data to the monitoring machine;
[0027] Step S145: If decryption is successful, determine whether the front part of the transmission data is the agreed dynamically changing string; if not, send the transmission data to the monitoring machine;
[0028] Step S146: Remove the agreed string at the front of the transmission data to obtain new data;
[0029] Step S147: Call the original receiving function to send the newly decrypted data to the receiving party's user program.
[0030] Furthermore, in step S3, if the decryption is unsuccessful or the string judgment is unsuccessful, the received transmission data is sent to the monitoring machine for unified processing.
[0031] The present invention also proposes a transparent encryption and decryption device for data transmission, including:
[0032] New function module: Design a new sending function and a new receiving function that replace the network communication sending function and receiving function in the operating system standard library for the operating system, and release them together with the operating system;
[0033] Sending module: When the user program sends transmission data, the operating system calls the new sending function to add a pre-agreed dynamically changing string to the transmission data and encrypt it;
[0034] Receiving module: After the operating system receives the transmission data, it calls the new receiving function to decrypt and judge the pre-agreed dynamically changing string, and sends it to the receiving party's user program after successful judgment.
[0035] Furthermore, the new function module includes:
[0036] Original function unit: Obtain the network communication sending function and receiving function in the standard library of the operating system, which are called the original sending function and the original receiving function;
[0037] New file unit: Create 1 new file, add the new sending function and the new receiving function, and the new sending function and the new receiving function have the same function name, parameters, and return values as the original sending function and the original receiving function;
[0038] New sending function unit: Add encryption code to the new sending function;
[0039] New receiving function unit: Add decryption code to the new receiving function;
[0040] Compilation unit: Compile the new file into a dynamic link library and add it to the operating system;
[0041] Priority unit: Set the dynamic link library as the priority function library.
[0042] Even further, the new sending function unit includes:
[0043] String subunit: The sender and the receiver agree on a dynamically changing string;
[0044] New transmission data sub-unit: Place the agreed dynamic change string before the transmission data to be sent by the sender's user program to form new transmission data consisting of "dynamic change string + transmission data".
[0045] Encryption sub-unit: Encrypt the new transmission data to obtain encrypted data.
[0046] Call sending sub-unit: Call the original sending function to send the encrypted data to the receiver.
[0047] Furthermore, the new receiving function unit includes:
[0048] Determine string sub-unit: Determine the dynamic change string agreed upon by the sender and the receiver.
[0049] Extraction sub-unit: Extract the transmission data from the data packet received over the network.
[0050] Decryption sub-unit: Decrypt the extracted transmission data.
[0051] Processing sub-unit: If decryption fails, send the transmission data to the monitoring machine.
[0052] Judgment sub-unit: If decryption is successful, determine whether the front part of the transmission data is the agreed dynamic change string; if not, send the transmission data to the monitoring machine.
[0053] New data sub-unit: Remove the agreed string in front of the transmission data to obtain new data.
[0054] Call receiving sub-unit: Call the original receiving function to send the new data obtained by decryption to the receiver's user program.
[0055] Furthermore, in the receiving module, if decryption fails or string judgment fails, the received transmission data is sent to the monitoring machine for unified processing.
[0056] Compared with the prior art, the present invention has the following beneficial effects:
[0057] 1. The present invention realizes transparent encryption and decryption: The sending function in the priority function library encrypts the data sent by the user program, and the receiving function in the priority function library decrypts the TCP / UDP data. This process does not require the participation of the user program and is transparent to the user program.
[0058] 2. The present invention has good security: Through data encryption and decryption technology, it can prevent third parties from illegally stealing data; even if a third party cracks the encryption and decryption functions, the continuously changing agreed string can prevent the third party from cracking or forging data.
[0059] 3. The present invention realizes centralized processing: error or illegal network data packets are forwarded to a monitoring machine for unified processing. BRIEF DESCRIPTION OF THE DRAWINGS
[0060] Figure 1 is a schematic flowchart of Embodiment 1 of the present invention.
[0061] Figure 2 is a schematic diagram of machine deployment in Embodiment 1 of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0062] It should be noted that, without conflict, the embodiments in the present invention and the features in the embodiments may be combined with each other.
[0063] The present invention will be specifically described below in conjunction with specific embodiments and the accompanying drawings:
[0064] Embodiment 1:
[0065] In this embodiment, taking TCP / UDP data for network communication as an example, a transparent encryption and decryption method for data transmission is provided. As Figure 1 shown, it includes the following steps:
[0066] Step 1: Design a dynamic encryption and decryption function library for the Galaxy Kylin operating system, and the dynamic encryption and decryption function library is released together with the Galaxy Kylin operating system.
[0067] The specific design of the dynamic encryption and decryption function library libcrypt.so includes:
[0068] Step 11: Obtain the sending function and receiving function in the standard library libc.so of the operating system, such as the sending function send and receiving function recv for TCP communication, and the sending function sendto and receiving function recvfrom for UDP communication, which are called the original sending function and original receiving function.
[0069] Step 12: Create a new file crypt.c, and add a new sending function send, sendto and new receiving function recv, recvfrom. The new sending function and new receiving function have the same function name, parameters and return values as the original sending function and original receiving function.
[0070] Step 13: Add encryption code to the new sending functions send, sendto.
[0071] The process of adding encryption code is as follows:
[0072] Step 131: The sender and the receiver agree on a dynamically changing string known to both parties; for example, the company's closing price or the number of employees of the company the previous day, etc.;
[0073] Step 132: Place the agreed string before the TCP / UDP data to form new data consisting of "agreed string + TCP / UDP data".
[0074] Step 133: Encrypt the new data to obtain encrypted data.
[0075] Step 134: Call the original sending functions send and sendto to send the encrypted data to the receiving party.
[0076] Step 14: Add decryption code to the new receiving functions recv and recvfrom.
[0077] The process of adding decryption code is as follows:
[0078] Step 141: Determine the dynamically changing string agreed upon by the sending and receiving parties.
[0079] Step 142: Extract the TCP / UDP data from the data packet received from the network.
[0080] Step 143: Decrypt the TCP / UDP data.
[0081] Step 144: If decryption fails, send the TCP / UDP data to the monitoring machine.
[0082] Step 145: If decryption is successful, determine whether the front part of the TCP / UDP data is the agreed string; if not (this situation usually indicates that a third party has cracked the encryption and decryption functions, but does not know the agreed string in the data packet), send the TCP / UDP data to the monitoring machine.
[0083] Step 146: Remove the agreed string in front of the TCP / UDP data to obtain new data.
[0084] Step 147: Call the original receiving functions recv and recvfrom to send the decrypted data to the receiving party's user program. The data received by the receiving party's user program is unencrypted data, and the user program is completely transparent to the encryption and decryption processes during data transmission.
[0085] Step 15: Use the following command to compile the new file crypt.c into a dynamic link library libcrypt.so and add it to the operating system;
[0086] The command is: "gcc -fPIC -shared -o libcrypt.so crypt.c".
[0087] Step 2: Use the following command to set the dynamic encryption and decryption function library as the priority function library;
[0088] The command to set the dynamic encryption and decryption function library described in the previous steps as the priority function library is: "export LD_PRELOAD=$LD_PRELOAD:libcrypt.so".
[0089] Step 3: The sender user program calls the original sending function to send data.
[0090] When the sender user program needs to transmit data, it still calls the original sending functions send and sendto to send data.
[0091] Step 4: The new sending function in the priority function library will be executed first to encrypt the data.
[0092] When the system receives the call of the original sending function by the sender user program, it preferentially executes the new sending function in the priority function library. The execution process is shown in Step 13.
[0093] Step 5: The data is transmitted from the sender to the receiver through the network.
[0094] Step 6: The new receiving function in the receiver's priority function library will be executed first to decrypt the data.
[0095] When the receiver receives data, it preferentially executes the new receiving functions recv and recvfrom in the priority function library to decrypt the data. The process is shown in Step 14.
[0096] Step 7: The receiver user program receives the decrypted data.
[0097] Step 8: The monitoring machine processes the received error data. This data may be caused by network transmission errors or illegally sent by a third party (for example, the sender's IP address is not a legitimate IP address within the company, the TCP / UDP data packet has no agreed string, or the agreed string is incorrect), etc.
[0098] An application example is as follows: The machine deployment method is as Figure 2 shown, and the operating system used is the Galaxy Kylin operating system. A certain company has deployed 4 machines: Machine A and Machine B in City A, and Machine C and Monitoring Machine D in City B. Among them, each of Machine A and Machine B in City A contains 2 network cards (eth0 and eth1) and can be connected to the Internet and the internal local area network respectively; each of Machine C and Monitoring Machine D in City B contains 1 network card (eth0) for connecting to the Internet. In addition, there is another third-party machine E that steals data from the Internet and sends forged data.
[0099] Machines A and B send data. When encrypting, the company's internal regulations stipulate that the company's closing price of the previous day is used as the dynamically changing agreed string. If the third-party machine E cracks the encryption and decryption functions, but there is no encrypted string or the encrypted string is incorrect in the forged data packet sent, the monitoring machine D can determine that there is an illegal third-party machine invading the company's system.
[0100] The machine C in City B is used to receive data, and the monitoring machine D is used to process error and illegal network data packets. When the data is transmitted incorrectly over the network, or the third-party machine E sends illegal data, it is processed by the monitoring machine.
[0101] The user programs of machines A and B send data in plaintext, which is encrypted by the sending function in the priority function library and then transmitted; after machine C receives it, it is decrypted by the receiving function in the priority function library, and the user program receives the plaintext data. During the entire transmission process, the user program is not aware of the encryption and decryption process, so the present invention is a transparent encryption and decryption method. It should be noted that this embodiment focuses on common TCP / UDP data packets and is also applicable to other data packets such as ICMP.
[0102] The advantages of the method proposed in this embodiment are reflected in the following aspects. First, the encryption and decryption process of the data does not require any processing by the user program, realizing the transparency of data encryption and decryption; second, in the data encryption and decryption process, the agreed string technology that changes continuously can effectively prevent third parties from illegally stealing or forging data; third, error or illegal network data packets are forwarded to the monitoring machine for unified processing.
[0103] Embodiment 2:
[0104] This embodiment 2 proposes a transparent encryption and decryption device for data transmission, including:
[0105] New function module: Design a new sending function and a new receiving function that replace the network communication sending function and receiving function in the operating system standard library for the operating system, and are released together with the operating system;
[0106] Sending module: When the user program sends transmission data, the operating system calls the new sending function, adds an agreed dynamically changing string to the transmission data, and encrypts it;
[0107] Receiving module: After the operating system receives the transmission data, it calls the new receiving function to decrypt and judge the agreed dynamically changing string, and sends it to the receiving user program after judging correctly.
[0108] Among them, the new function module includes:
[0109] Original function unit: Obtain the network communication sending function and receiving function in the standard library of the operating system, which are called the original sending function and the original receiving function;
[0110] New file unit: Create 1 new file, add a new sending function and a new receiving function, where the new sending function and the new receiving function have the same function name, parameters, and return values as the original sending function and the original receiving function;
[0111] New sending function unit: Add encryption code to the new sending function;
[0112] New receiving function unit: Add decryption code to the new receiving function;
[0113] Compilation unit: Compile the new file into a dynamic link library and add it to the operating system;
[0114] Priority unit: Set the dynamic link library as the priority function library.
[0115] The new sending function unit includes:
[0116] String subunit: The sender and the receiver agree on a dynamically changing string;
[0117] New transmitted data subunit: Place the agreed dynamically changing string before the transmitted data to be sent by the sender's user program to form new transmitted data consisting of "dynamically changing string + transmitted data";
[0118] Encryption subunit: Encrypt the new transmitted data to obtain encrypted data;
[0119] Call sending subunit: Call the original sending function to send the encrypted data to the receiver.
[0120] The new receiving function unit includes:
[0121] Determine string subunit: Determine the dynamically changing string agreed upon by the sender and the receiver;
[0122] Extraction subunit: Extract the transmitted data from the data packet received over the network;
[0123] Decryption subunit: Decrypt the extracted transmitted data;
[0124] Processing subunit: If decryption fails, send the transmitted data to the monitoring machine;
[0125] Judgment subunit: If decryption is successful, determine whether the front part of the transmitted data is the agreed dynamically changing string; if not, send the transmitted data to the monitoring machine;
[0126] New data subunit: Remove the agreed string in front of the transmitted data to obtain new data;
[0127] Call the receiving subunit: Call the original receiving function to send the newly decrypted data to the receiving party's user program.
[0128] In the receiving module, if the decryption is unsuccessful or the string judgment is unsuccessful, the received transmission data is sent to the monitoring machine for unified processing.
[0129] The transparent encryption and decryption device for data transmission proposed in this embodiment can implement the transparent encryption and decryption method for data transmission described in Embodiment 1, and has the same technical effects as Embodiment 1.
[0130] The above-described embodiments are only the preferred embodiments of the present invention, and are only used to help understand the method and its core idea of the present application. The protection scope of the present invention is not limited to the above embodiments. All technical solutions falling within the idea of the present invention belong to the protection scope of the present invention. It should be noted that for those of ordinary skill in the art, several improvements and refinements made without departing from the principle of the present invention should also be regarded as the protection scope of the present invention.
Claims
1. A transparent encryption and decryption method for data transmission, characterized in that: include: S1. Design a new sending function and a new receiving function for the operating system to replace the sending function and receiving function of network communication in the standard library of the operating system, and release them together with the operating system; S2. When the user program sends transmission data, the operating system calls a new sending function, adds an agreed dynamically changing string to the transmission data, and encrypts it; S3. After receiving the transmission data, the operating system calls the new receiving function to decrypt and determine the agreed dynamically changing string. After the determination is correct, it is sent to the receiving user program.
2. The transparent encryption and decryption method for data transmission according to claim 1, characterized in that: The design method of the new sending function and the new receiving function in step S1 includes: S11: obtaining a sending function and a receiving function of network communication in a standard library of the operating system, which are called an original sending function and an original receiving function; S12: creating a new file, adding a new sending function and a new receiving function, wherein the new sending function and the new receiving function have the same function name, parameters and return value as the original sending function and the original receiving function; S13: adding encryption code to the new sending function; S14: adding a decryption code to the new receiving function; S15: compile the new file into a dynamic link library and add it to the operating system; S16: Setting the dynamic link library as a priority function library.
3. The transparent encryption and decryption method for data transmission according to claim 2, characterized in that: Step S13 includes: S131: The sender and the receiver agree on a dynamically changing string; S132: placing the agreed dynamically changing character string before the transmission data to be sent by the sending user program to form new transmission data consisting of "dynamically changing character string + transmission data"; S133: Encrypt the new transmission data to obtain encrypted data; S134: Call the original sending function to send the encrypted data to the recipient.
4. The transparent encryption and decryption method for data transmission according to claim 2, characterized in that: Step S14 includes: Step S141: Determine the dynamically changing character string agreed upon by the sender and the receiver; Step S142: extracting transmission data from the data packet received on the network; Step S143: decrypting the extracted transmission data; Step S144: If decryption is not possible, the transmission data is sent to the monitoring machine; Step S145: if the decryption is successful, determine whether the front part of the transmission data is the agreed dynamically changing character string; if not, send the transmission data to the monitoring machine; Step S146: remove the agreed character string in front of the transmission data to obtain new data; Step S147: Call the original receiving function to send the decrypted new data to the receiving user program.
5. The transparent encryption and decryption method for data transmission according to claim 1, characterized in that: In step S3, if the decryption is unsuccessful or the character string determination is unsuccessful, the received transmission data is sent to the monitoring machine for unified processing.
6. A transparent encryption and decryption device for data transmission, characterized in that: include: New function module: Design a new sending function and a new receiving function for the operating system to replace the sending function and receiving function of network communication in the standard library of the operating system, and release them together with the operating system; Sending module: When the user program sends transmission data, the operating system calls a new sending function, adds an agreed dynamically changing string to the transmission data, and encrypts it; Receiving module: After the operating system receives the transmitted data, it calls the new receiving function to decrypt and determine the agreed dynamically changing string. After the determination is correct, it is sent to the receiving user program.
7. The transparent encryption and decryption device for data transmission according to claim 6, characterized in that: New function modules include: Original function unit: obtains the sending function and receiving function of network communication in the standard library of the operating system, which are called original sending function and original receiving function; New file unit: create a new file, add a new sending function and a new receiving function, the new sending function and the new receiving function have the same function name, parameters and return value as the original sending function and the original receiving function; New sending function unit: adding encryption code to the new sending function; New receiving function unit: adding decryption code to the new receiving function; Compilation unit: compiles new files into dynamic link libraries and adds them to the operating system; Priority unit: sets the dynamic link library as a priority function library.
8. The transparent encryption and decryption device for data transmission according to claim 7, characterized in that: The new send function unit includes: String subunit: The sender and receiver agree on a dynamically changing string; New transmission data subunit: put the agreed dynamically changing character string before the transmission data to be sent by the sending user program, forming new transmission data consisting of "dynamically changing character string + transmission data"; Encryption subunit: encrypts new transmission data to obtain encrypted data; Call the sending subunit: call the original sending function to send the encrypted data to the receiver.
9. The transparent encryption and decryption device for data transmission according to claim 7, characterized in that: The new receive function unit includes: Determine the string subunit: determine the dynamically changing string agreed upon by the sender and the receiver; Extraction subunit: extracts transmission data from data packets received on the network; Decryption subunit: decrypts the extracted transmission data; Processing subunit: if decryption is not possible, the transmission data is sent to the monitoring machine; Judgment subunit: if the decryption is successful, it determines whether the front part of the transmission data is the agreed dynamically changing character string; if not, it sends the transmission data to the monitoring machine; New data subunit: remove the agreed string in front of the transmitted data to obtain new data; Call the receiving subunit: call the original receiving function to send the decrypted new data to the receiving user program.
10. The transparent encryption and decryption device for data transmission according to claim 6, characterized in that: In the receiving module, if the decryption is unsuccessful or the character string judgment is unsuccessful, the received transmission data is sent to the monitoring machine for unified processing.