Data receiving method, data transmission method, system, device, equipment and medium

By using the negotiated random numbers during data transmission to determine the key bits of the data packet and using hash values ​​to verify the correctness of the data, the problem of not being able to identify and prevent IP spoofing and man-in-the-middle attacks in the prior art is solved, and high security and accuracy of data transmission are achieved.

CN120200759APending Publication Date: 2025-06-24STATE NUCLEAR POWER AUTOMATION SYST ENGCO +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510415464.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-03
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

The prior art cannot effectively identify and prevent IP spoofing and man-in-the-middle attacks, resulting in the accuracy and completeness of data transmission.

Method used

By negotiating random numbers between the sending and receiving ends, the first and second data bits in the data packet are determined, and the correctness of data is verified by using hash values ​​to ensure the security of data transmission.

Benefits of technology

Improve the security of data transmission, prevent data tampering and tampering detection, and ensure the accuracy and completeness of data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200759A_ABST
    Figure CN120200759A_ABST
Patent Text Reader

Abstract

The invention provides a data receiving method, a data transmission method, a system, a device, equipment and a medium. The data receiving method comprises the following steps: establishing communication connection with a sending end and obtaining a random number; receiving a target data message transmitted by the sending end; determining a first data bit and a second data bit in the target data message based on the random number, and calculating to obtain original data according to third data in the first data bit, fourth data in the second data bit and a second hash value corresponding to the target data message except the fourth data; calculating a verification value according to the fourth data, the original data and the second hash value; in response to the fact that the verification value is equal to the third data, replacing the fourth data with the original data to obtain an original data message; or, in response to the fact that the verification value is not equal to the third data, the communication connection is disconnected. According to the invention, the replacement data is calculated through the random process, so that the legality of the transmitted data message cannot be modified, and the security of data transmission is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security, and in particular, to a data receiving method, a data transmitting method, a system, a device, equipment, and a medium. Background Art

[0002] In the existing data transmission environment, data packets are prone to interference and loss during transmission, resulting in the accuracy and integrity of the data being affected. Therefore, network protection is required for the transmission of data packets.

[0003] Currently, network protection is basically based on firewall rules to filter data packets. This type of network protection method cannot identify behaviors such as IP (Internet Protocol) spoofing and man-in-the-middle attacks, and still cannot ensure the accuracy and integrity of the transmitted data. Summary of the Invention

[0004] The technical problem to be solved by the present disclosure is to overcome the defect in the prior art that the accuracy and integrity of the transmitted data cannot be ensured, and to provide a data receiving method, a data transmitting method, a system, a device, equipment, and a medium.

[0005] The present disclosure solves the above technical problem by the following technical solutions:

[0006] According to a first aspect of the present disclosure, there is provided a data receiving method, which is applied to a receiving end, and the data receiving method includes:

[0007] Establish a communication connection with a sending end and obtain a random number, where the random number is negotiated based on the sending end and the receiving end;

[0008] Receive a target data packet transmitted by the sending end, where the target data packet is obtained by replacing the second data in the second data bit of the original data packet with target data; wherein, the first data bit and the second data bit in the original data packet are determined based on the random number, and the target data is calculated based on the first data in the first data bit, the second data, and the first hash value corresponding to the original data packet except the second data;

[0009] Determine the first data bit and the second data bit in the target data packet based on the random number, and calculate the original data based on the third data in the first data bit, the fourth data in the second data bit, and the second hash value corresponding to the target data packet except the fourth data;

[0010] Calculate a check value based on the fourth data, the original data, and the second hash value;

[0011] In response to the verification value being equal to the third data, replace the fourth data with the original data to obtain the original data packet;

[0012] Or,

[0013] In response to the verification value being not equal to the third data, disconnect the communication connection.

[0014] Optionally, the step of determining the first data bit and the second data bit in the target data packet based on the random number includes:

[0015] Generate an offset based on the random number;

[0016] Determine the position corresponding to the offset in the target data packet as the first data bit;

[0017] Determine the position after the first data bit and at a preset number of bits away from the first data bit as the second data bit.

[0018] Optionally, the step of generating an offset based on the random number includes:

[0019] Perform a modulo operation on the length of the target data packet based on the random number to obtain the offset;

[0020] Or,

[0021] Use the random number as a random seed to generate a target random number, and perform a modulo operation on the length of the target data packet based on the target random number to obtain the offset.

[0022] Optionally, the step of calculating the verification value according to the fourth data, the original data, and the second hash value includes:

[0023] Perform an exclusive OR operation on the fourth data, the original data, and the second hash value to obtain the verification value;

[0024] And / or,

[0025] The target data is obtained based on the exclusive OR operation of the first data, the second data, and the first hash value;

[0026] The step of calculating the original data according to the third data in the first data bit, the fourth data in the second data bit, and the second hash value corresponding to the target data packet except the fourth data includes:

[0027] Perform an exclusive OR operation on the third data, the fourth data, and the second hash value to obtain the original data.

[0028] According to a second aspect of the present disclosure, a data transmission method is provided. The data transmission method is applied to a sending end and includes:

[0029] Establish a communication connection with a receiving end and obtain a random number, where the random number is negotiated based on the sending end and the receiving end;

[0030] Determine a first data bit and a second data bit in an original data packet based on the random number, and calculate target data according to a first data in the first data bit, a second data in the second data bit, and a first hash value corresponding to the original data packet except the second data;

[0031] Replace the second data with the target data to generate a target data packet, and transmit the target data packet to the receiving end for the receiving end to process the target data packet;

[0032] Wherein, the steps for the receiving end to process the target data packet include: determining the first data bit and the second data bit in the target data packet based on the random number; calculating original data according to a third data in the first data bit, a fourth data in the second data bit, and a second hash value corresponding to the target data packet except the fourth data; calculating a check value according to the fourth data, the original data, and the second hash value; in response to the check value being equal to the third data, replacing the fourth data with the original data to obtain the original data packet; or, in response to the check value not being equal to the third data, disconnecting the communication connection.

[0033] Optionally, the step of determining the first data bit and the second data bit in the original data packet based on the random number includes:

[0034] Generating an offset based on the random number;

[0035] Determining the position corresponding to the offset in the original data packet as the first data bit;

[0036] Determining the position after the first data bit and at a preset number of bits away from the first data bit as the second data bit.

[0037] Optionally, the step of generating an offset based on the random number includes:

[0038] Performing a modulo operation on the length of the original data packet based on the random number to obtain the offset;

[0039] Or,

[0040] Generate a target random number using the random number as a random seed, and perform a modulo operation on the length of the original data packet based on the target random number to obtain the offset.

[0041] Optionally, the step of calculating the target data according to the first data in the first data bit, the second data in the second data bit, and the first hash value corresponding to the original data packet except the second data includes:

[0042] Perform an exclusive OR operation on the first data, the second data, and the first hash value to obtain the target data.

[0043] According to a third aspect of the present disclosure, a data receiving system is provided. The data receiving system is applied to a receiving end, and the data receiving system includes a first establishment module, a receiving module, a first calculation module, a second calculation module, and a verification module;

[0044] The first establishment module is used to establish a communication connection with a sending end and obtain a random number, and the random number is negotiated based on the sending end and the receiving end;

[0045] The receiving module is used to receive a target data packet transmitted by the sending end, and the target data packet is obtained by replacing the second data in the second data bit of the original data packet with target data; wherein, the first data bit and the second data bit in the original data packet are determined based on the random number, and the target data is calculated according to the first data in the first data bit, the second data, and the first hash value corresponding to the original data packet except the second data;

[0046] The first calculation module is used to determine the first data bit and the second data bit in the target data packet based on the random number, and calculate the original data according to the third data in the first data bit, the fourth data in the second data bit, and the second hash value corresponding to the target data packet except the fourth data;

[0047] The second calculation module is used to calculate a verification value according to the fourth data, the original data, and the second hash value;

[0048] The verification module is used to, in response to the verification value being equal to the third data, replace the fourth data with the original data to obtain the original data packet;

[0049] Or,

[0050] The verification module is used to, in response to the verification value being not equal to the third data, disconnect the communication connection.

[0051] According to a fourth aspect of the present disclosure, a data transmission system is provided. The data transmission system is applied to a sending end and includes a second establishment module, a third calculation module, and a generation module;

[0052] The second establishment module is configured to establish a communication connection with a receiving end and obtain a random number, where the random number is negotiated based on the sending end and the receiving end;

[0053] The third calculation module is configured to determine a first data bit and a second data bit in an original data packet based on the random number, and calculate target data according to a first data in the first data bit, a second data in the second data bit, and a first hash value corresponding to the original data packet except the second data;

[0054] The generation module is configured to replace the second data with the target data to generate a target data packet, and transmit the target data packet to the receiving end for the receiving end to process the target data packet;

[0055] Wherein, the steps for the receiving end to process the target data packet include: determining the first data bit and the second data bit in the target data packet based on the random number; calculating original data according to a third data in the first data bit, a fourth data in the second data bit, and a second hash value corresponding to the target data packet except the fourth data; calculating a check value according to the fourth data, the original data, and the second hash value; in response to the check value being equal to the third data, replacing the fourth data with the original data to obtain the original data packet; or, in response to the check value being not equal to the third data, disconnecting the communication connection.

[0056] According to a fifth aspect of the present disclosure, a data transmission device is provided. The data transmission device includes the data receiving system according to the third aspect of the present disclosure and the data transmission system according to the fourth aspect of the present disclosure.

[0057] According to a sixth aspect of the present disclosure, an electronic device is provided, including a memory, a processor, and a computer program stored on the memory and configured to run on the processor. When the processor executes the computer program, the data receiving method according to the first aspect of the present disclosure and / or the data transmission method according to the second aspect of the present disclosure are implemented.

[0058] According to a seventh aspect of the present disclosure, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the data receiving method according to the first aspect of the present disclosure and / or the data transmission method according to the second aspect of the present disclosure are implemented.

[0059] According to an eighth aspect of the present disclosure, there is provided a computer program product including a computer program which, when executed by a processor, implements the data receiving method described in the first aspect of the present disclosure, and / or the data transmitting method described in the second aspect of the present disclosure.

[0060] Based on common general knowledge in the art, the above preferred conditions can be combined arbitrarily to obtain various preferred examples of the present disclosure.

[0061] The positive and progressive effects of the present disclosure are as follows: the first data bit is determined by a random number generated through a random process to verify the correctness of the hash value according to the data in the first data bit, and the data used for calculating the hash value does not include the data in the second data bit, so it is difficult to crack by experience; the replacement data of the second data bit in the data packet is obtained based on the deformation operation of three numbers, and the real content of the data packet is modified, so it cannot be directly used even if intercepted during data transmission; the data of the second data bit can be inversely calculated through the hash value, and the correctness of the data can be verified by comparison. Even if the hash algorithm is cracked, due to the existence of the random process, the hash value cannot be correctly calculated; in addition, the hash value does not increase the length of the data packet and will not affect subsequent hierarchical communication, thereby ensuring that the legality of the transmitted data packet will not be modified and improving the security of data transmission. BRIEF DESCRIPTION OF THE DRAWINGS

[0062] Figure 1 is a flowchart of the data receiving method of the present disclosure;

[0063] Figure 2 is a schematic diagram of the data packet transmission process of the present disclosure;

[0064] Figure 3 is a flowchart of step S13 in the data receiving method of the present disclosure;

[0065] Figure 4 is a flowchart of the data transmitting method of the present disclosure;

[0066] Figure 5 is a schematic diagram of the modules of the data receiving system of the present disclosure;

[0067] Figure 6 is a schematic diagram of the modules of the data transmitting system of the present disclosure;

[0068] Figure 7 is a schematic diagram of the structure of the data transmitting device of the present disclosure;

[0069] Figure 8 is a flowchart of the operation of the data transmitting device of the present disclosure;

[0070] Figure 9Schematic diagram of the electronic device of the present disclosure. Detailed implementation manners

[0071] The present disclosure will be further described below by way of embodiments, but the present disclosure is not limited to the scope of the described embodiments.

[0072] In the embodiments of the present disclosure, prefix words such as "first" and "second" are only used to distinguish different described objects, and have no limiting effect on the position, order, priority, quantity or content of the described objects. The use of ordinal numbers and other prefix words for distinguishing described objects in the embodiments of the present disclosure does not constitute a limitation on the described objects. For the statement of the described objects, refer to the description in the claims or the context of the embodiments, and no redundant limitation should be constituted due to the use of such prefix words. In addition, in the description of this embodiment, unless otherwise specified, the meaning of "a plurality" is two or more.

[0073] In the embodiments of the present disclosure, the collection, storage, use, processing, transmission, provision and disclosure of the user's personal information and other processing all comply with the provisions of relevant laws and regulations and do not violate public order and good customs.

[0074] Embodiment 1

[0075] In a specific embodiment of the present disclosure, a data receiving method is provided. The data receiving method is applied to a receiving end, as Figure 1 shown, the data receiving method includes:

[0076] S11. Establish a communication connection with a sending end and obtain a random number, where the random number is obtained through negotiation between the sending end and the receiving end.

[0077] After the communication connection is established between the two communication parties (the sending end and the receiving end), a random number can be obtained through negotiation by combining the electrical signals generated in the hardware devices of the two communication parties to enhance the quality of the random number.

[0078] In a specific implementable manner of negotiating the random number, the two communication parties respectively obtain multiple segments of electrical signals generated in their respective hardware devices and synthesize them into a new signal segment. For example, an oscilloscope software can be used to obtain in real time the electrical signals generated by each component in the hardware device (for example, the central processing unit CPU, memory, motherboard bus, etc.). Although these electrical signals are pseudo-random, after simple cropping, arranging, and splicing of multiple segments of electrical signals, the formed new signal segment will become difficult to reproduce, thus presenting the characteristics of true randomness. As for the cropping, arranging, and splicing rules, the user can define them by himself. The synthesized new signal segment D can be expressed as , where D1~D C respectively represent the wave values on different signal stamps, and C represents the total number of signal stamps included in the new signal segment D.

[0079] After synthesizing the new signal segment D, convert the new signal segment D into a specific value and return it. Among them, converting the new signal segment D into a specific value can be achieved through a conversion function T(D):

[0080] ;

[0081] Among them, represents the wave value on the i-th signal stamp in the new signal segment D, where i ∈ [1, C], and C represents the total number of signal stamps contained in the new signal segment D.

[0082] Calculate a random number based on the values returned by both communication parties and the corresponding negotiation factors. Among them, the negotiation factors can be randomly generated by both communication parties, and the generated negotiation factors and the returned values are transmitted to the other party. Both communication parties can calculate the random number by substituting their respective negotiation factors and the values they return into the merging formula. The merging formula is expressed as:

[0083] ;

[0084] Among them, R represents the negotiated random number, represents the value returned by the sender, represents the negotiation factor generated by the sender, represents the value returned by the receiver, represents the negotiation factor generated by the receiver.

[0085] S12. Receive the target data packet transmitted by the sender. The target data packet is obtained by replacing the second data in the second data bit of the original data packet with the target data; among them, the first data bit and the second data bit in the original data packet are determined based on the random number, and the target data is calculated based on the first data in the first data bit, the second data, and the first hash value corresponding to the original data packet except the second data.

[0086] When there is a data packet to be transmitted, the sender determines the first data bit and the second data bit in the original data packet according to the random number R negotiated by both communication parties. For example, starting from the first bit of the original data packet, the data bit corresponding to the random number is used as the first data bit, and the Nth (N is a positive integer) data bit before or after the first data bit is used as the second data bit. Among them, the data corresponding to the first data bit is the first data X, and the data corresponding to the second data bit is the second data K; calculate the first hash value Y corresponding to the original data packet except the second data K, and perform a combined calculation on the first data X, the second data K, and the first hash value Y to obtain the target data M. For example, various logical operation methods such as exclusive OR operation, sum and NOT operation, NOR operation, exclusive OR operation, and exclusive NOR operation are used for combined calculation; such as Figure 2As shown, the original data packet before data packet transmission at the sending end is the first data X and the second data K. Through hash operation, Y is generated and the target data M is calculated. The second data K in the second data bit of the original data packet is replaced with the target data M to obtain the target data packet, so as to transmit the target data packet to the receiving end.

[0087] S13. Determine the first data bit and the second data bit in the target data packet based on a random number. Calculate the original data according to the third data in the first data bit, the fourth data in the second data bit, and the second hash value corresponding to the target data packet except the fourth data.

[0088] Since the target data packet received by the receiving end is the data packet after replacement by the sending end, rather than the original data packet, the original data packet before replacement at the replaced position (the second data bit) in the target data packet can be inversely calculated according to the negotiated random number R. Determine the first data bit and the second data bit in the target data packet according to the random number R negotiated by both communication parties, as well as the third data X' in the first data bit and the fourth data M' in the second data bit. Among them, the first data bit in the target data packet and the first data bit in the original data packet refer to the same data bit. Similarly, the second data bit in the target data packet and the second data bit in the original data packet refer to the same data bit. Then perform a hash operation on the entire target data packet except the fourth data M' to obtain the second hash value Y'. Using the same logical operation method as the sending end, calculate the third data X', the fourth data M', and the second hash value Y' to obtain the original data K' corresponding to the second data bit in the target data packet.

[0089] S14. Calculate the check value according to the fourth data, the original data, and the second hash value.

[0090] Since the target data packet may be interfered with or tampered with during transmission, in order to ensure the security of data transmission and the accuracy of the target data packet, the check value P can be calculated according to the fourth data M', the original data K', and the second hash value Y', so as to verify the target data packet according to the correction value P.

[0091] S15. In response to the check value being equal to the third data, replace the fourth data with the original data to obtain the original data packet; or, in response to the check value not being equal to the third data, disconnect the communication connection.

[0092] If the check value P is equal to the third data X' in the first data bit of the target data packet, it means that the target data packet has not been tampered with during transmission. The calculated original data K' is the data before the replacement of the second data bit of the original data packet by the sending end, that is, X' = X, Y' = Y, K' = K, M' = M.Figure 2 As shown, K’ is calculated by M and verified. If P = X’, the original data K’ replaces the fourth data M’ in the second data bit of the target data packet. At this time, X’ = X and K’ = K. Therefore, the original data packet of the first data X and the second data K can be obtained. If the verification value P is not equal to the third data X’, it indicates that the target data packet has been tampered with during transmission. To ensure the security of transmission, the communication connection between the two communication parties is disconnected.

[0093] In this specific implementation, the first data bit is determined by a random number generated through a random process to verify the correctness of the hash value according to the data in the first data bit, and the data calculated for the hash value does not include the data in the second data bit. Therefore, it is difficult to crack through experience. The replacement data in the second data bit of the data packet is obtained through a transformation operation based on three numbers, and the true content of the data packet is modified, so it cannot be directly used even if it is intercepted during data transmission. The data in the second data bit can be deduced inversely through the hash value, and the correctness of the data can be verified by comparison. Even if the hash algorithm is cracked, due to the existence of the random process, the hash value cannot be correctly calculated. In addition, the hash value does not increase the length of the data packet and will not affect subsequent hierarchical communication, thus ensuring that the legality of the transmitted data packet will not be modified and improving the security of data transmission.

[0094] In a specific implementation, as Figure 3 shown, step S13 includes:

[0095] S131. Generate an offset based on a random number;

[0096] Among them, step S131 includes: performing a remainder operation on the length of the target data packet based on the random number to obtain the offset; or, using the random number as a random seed to generate a target random number, and performing a remainder operation on the length of the target data packet based on the target random number to obtain the offset.

[0097] S132. Determine the position corresponding to the offset in the target data packet as the first data bit;

[0098] S133. Determine the position after the first data bit and at a preset number of bits away from the first data bit as the second data bit.

[0099] Specifically, after receiving the target data packet, the receiving end generates an offset S using the negotiated random number R. For example, the length of the target data packet can be taken modulo with the random number R, or the random number R can be used as a random seed to generate a new random number, and then the length of the target data packet is taken modulo with the new random number to obtain the offset S. The specific calculation method of the offset S at the receiving end is the same as that at the sending end. Among them, the offset S can be determined by cyclically reading the target data packet to ensure that the offset S is less than the length of the target data packet.

[0100] After obtaining the offset S, the data bit at the position corresponding to the offset S in the target data packet is used as the first data bit. Considering that the target data packet is parsed sequentially, a certain data bit after the first data bit can be used as the second data bit to improve data processing efficiency. For example, the Nth data bit after the first data bit is used as the second data bit, and the fourth data M' in the second data bit is the replacement data. Among them, the determination methods of the first data bit and the second data bit are the same as those at the sending end.

[0101] In a specific implementation, the target data is obtained based on the exclusive-or operation of the first data, the second data, and the first hash value;

[0102] Step S13 includes: performing an exclusive-or operation on the third data, the fourth data, and the second hash value to obtain the original data.

[0103] Specifically, if the sending end obtains the target data M for replacement by performing an exclusive-or operation on the first data X, the second data K, and the first hash value Y, that is, M = X ⊕ Y ⊕ K, then after receiving the target data packet, the receiving end can calculate the original data K' by performing an exclusive-or operation on the third data X', the fourth data M', and the second hash value Y', that is, K' = X' ⊕ Y' ⊕ M'.

[0104] In a specific implementation, step S14 includes: performing an exclusive-or operation on the fourth data, the original data, and the second hash value to obtain the check value.

[0105] Specifically, the check value P can be obtained by performing an exclusive-or operation on the fourth data M', the original data K', and the second hash value Y', that is, P = M' ⊕ Y' ⊕ K'.

[0106] In this embodiment, the first data bit is determined by a random number generated through a random process to verify the correctness of the hash value according to the data in the first data bit, and the data for calculating the hash value does not include the data in the second data bit. Therefore, it is difficult to crack by experience. The replacement data of the second data bit in the data packet is obtained based on the deformed operation of three numbers, and the real content of the data packet is modified, so it cannot be directly used even if it is intercepted during data transmission. The data of the second data bit can be deduced inversely through the hash value, and the correctness of the data can be verified by comparison. Even if the hash algorithm is cracked, due to the existence of the random process, the hash value cannot be correctly calculated. In addition, the hash value does not increase the length of the data packet and will not affect subsequent hierarchical communication, so as to ensure that the legality of the transmitted data packet will not be modified and improve the security of data transmission.

[0107] Embodiment 2

[0108] In a specific embodiment of the present disclosure, a data transmission method is provided. The data transmission method is applied to a sending end, as Figure 4 shown, the data transmission method includes:

[0109] S21. Establish a communication connection with the receiving end and obtain a random number, where the random number is obtained through negotiation between the sending end and the receiving end.

[0110] After the communication connection is established between the two communication parties (the sending end and the receiving end), a random number can be obtained through negotiation by combining the electrical signals generated in the hardware devices of the two communication parties to enhance the quality of the random number. For the specific negotiation process, please refer to the foregoing embodiments and will not be elaborated here.

[0111] S22. Determine the first data bit and the second data bit in the original data packet based on the random number, and calculate the target data according to the first data in the first data bit, the second data in the second data bit, and the first hash value corresponding to the original data packet except the second data.

[0112] When a data packet needs to be transmitted, the first data bit and the second data bit in the original data packet are determined according to the random number R negotiated by the two communication parties. For example, starting from the first bit of the original data packet, the data bit corresponding to the random number is used as the first data bit, and the Nth data bit before or after the first data bit is used as the second data bit.

[0113] After determining the first data bit and the second data bit in the original data packet, the corresponding data in the first data bit is used as the first data X, and the corresponding data in the second data bit is used as the second data K. Since the second data K will be replaced, in order to ensure that the second hash value calculated by the receiving end is the same as the first hash value calculated by the sending end when the received data packet has not been tampered with, the entire original data packet except the second data K is hashed to obtain the first hash value Y; then, by performing a combined calculation on the first data X, the second data K, and the first hash value Y, the target data M is obtained. For example, various logical operation methods such as exclusive OR operation, sum and NOT operation, NOR operation, exclusive OR operation, and equivalence operation are used for the combined calculation.

[0114] S23. Replace the second data with the target data to generate a target data packet, and transmit the target data packet to the receiving end for the receiving end to process the target data packet.

[0115] As Figure 2 shown, the original data packet before data packet transmission is the first data X and the second data K. The hash operation generates Y and calculates the target data M. The target data M replaces the second data K in the second data bit of the original data packet to obtain the target data packet, and the target data packet is transmitted to the receiving end. By replacing the second data K in the second data bit of the original data packet with the target data M obtained by the transformation operation based on three numbers, the true content of the original data packet is modified, and it cannot be directly used even if it is intercepted during data transmission, thereby improving the security of data transmission.

[0116] After the receiving end receives the target data packet, through the reverse derivation method negotiated with the sending end, the true data (the second data K) corresponding to the second data bit in the target data packet can be calculated. For the specific reverse derivation method, please refer to the foregoing embodiments and will not be elaborated here.

[0117] Among them, in order to further improve the security of data transmission, after generating the target data packet, other transmission methods can be added. For example, the target data packet is encrypted and then the encrypted target data packet is transmitted, etc. This specific implementation manner does not make any limitations in this regard.

[0118] In this specific implementation manner, the first data bit is determined by a random number generated through a random process to verify the correctness of the hash value according to the data in the first data bit, and the data for calculating the hash value does not include the data in the second data bit. Therefore, it is difficult to crack by experience; the replacement data of the second data bit in the data packet is obtained based on the deformation operation of three numbers, and the real content of the data packet is modified, so it cannot be directly used even if intercepted during data transmission; the data of the second data bit can be deduced inversely through the hash value, and the correctness of the data can be verified by comparison. Even if the hash algorithm is cracked, due to the existence of the random process, the hash value cannot be correctly calculated; in addition, the hash value does not increase the length of the data packet and will not affect the subsequent hierarchical communication, thus ensuring that the legality of the transmitted data packet will not be modified and improving the security of data transmission.

[0119] In a specific implementation manner, step S22 includes:

[0120] S221. Generate an offset based on a random number;

[0121] Among them, step S221 includes: performing a remainder operation on the length of the original data packet based on the random number to obtain an offset; or, using the random number as a random seed to generate a target random number, and performing a remainder operation on the length of the original data packet based on the target random number to obtain an offset.

[0122] S222. Determine the position corresponding to the offset in the original data packet as the first data bit;

[0123] S223. Determine the position after the first data bit and at a preset number of bits away from the first data bit as the second data bit.

[0124] Specifically, taking the negotiated random number R as the starting point, when there is a data packet to be transmitted, an offset S is generated through the random number R. For example, the length of the original data packet can be taken as the remainder by the random number R, or the random number R can be used as the random seed to generate a new random number again, and then the new random number is used to take the remainder of the length of the original data packet to obtain the offset S. Among them, the offset S can be determined by looping through the target data packet to ensure that the offset S is less than the length of the target data packet.

[0125] After obtaining the offset S, the data bit corresponding to the offset S in the target data packet is used as the first data bit. Considering that the target data packet is parsed in order, a certain data bit after the first data bit can be used as the second data bit to improve data processing efficiency. For example, the Nth data bit after the first data bit is used as the second data bit.

[0126] In a specific embodiment, step S22 includes: performing an exclusive OR operation on the first data, the second data, and the first hash value to obtain the target data.

[0127] Specifically, the target data M for replacement can be obtained by performing an exclusive OR operation on the first data X, the second data K, and the first hash value Y, that is, M = X ⊕ Y ⊕ K.

[0128] In this embodiment, the first data bit is determined by a random number generated through a random process to verify the correctness of the hash value according to the data in the first data bit, and the data for calculating the hash value does not include the data in the second data bit. Therefore, it is difficult to crack through experience; the replacement data for the second data bit in the data packet is obtained based on the transformation operation of three numbers, and the real content of the data packet is modified, so it cannot be directly used even if intercepted during data transmission; the data of the second data bit can be inversely calculated through the hash value, and the correctness of the data can be verified by comparison. Even if the hash algorithm is cracked, due to the existence of the random process, the hash value cannot be correctly calculated; in addition, the hash value does not increase the length of the data packet and will not affect subsequent hierarchical communication, thus ensuring that the legality of the transmitted data packet will not be modified and improving the security of data transmission.

[0129] Embodiment 3

[0130] In a specific embodiment of the present disclosure, a data receiving system 100 is provided. The data receiving system 100 is applied to the receiving end, such as Figure 5 shown. The data receiving system 100 includes a first establishing module 101, a receiving module 102, a first calculating module 103, a second calculating module 104, and a verifying module 105;

[0131] The first establishing module 101 is used to establish a communication connection with the sending end and obtain a random number, and the random number is obtained through negotiation between the sending end and the receiving end;

[0132] The receiving module 102 is used to receive the target data packet transmitted by the sending end. The target data packet is obtained by replacing the second data in the second data bit of the original data packet with the target data; wherein, the first data bit and the second data bit in the original data packet are determined based on the random number, and the target data is calculated based on the first data in the first data bit, the second data, and the first hash value corresponding to the original data packet except the second data;

[0133] The first calculating module 103 is used to determine the first data bit and the second data bit in the target data packet based on the random number, and calculate the original data according to the third data in the first data bit, the fourth data in the second data bit, and the second hash value corresponding to the target data packet except the fourth data;

[0134] The second calculation module 104 is used to calculate a check value based on the fourth data, the original data, and the second hash value;

[0135] The verification module 105 is used to replace the fourth data with the original data to obtain the original data packet in response to the check value being equal to the third data; or, the verification module 105 is used to disconnect the communication connection in response to the check value not being equal to the third data.

[0136] In a specific embodiment, the first calculation module 103 includes a first generation unit and a first determination unit;

[0137] The first generation unit is used to generate an offset based on a random number;

[0138] The first determination unit is used to determine the position corresponding to the offset in the target data packet as the first data bit;

[0139] The first determination unit is further used to determine the position after the first data bit and at a preset number of bits away from the first data bit as the second data bit.

[0140] In a specific embodiment, the first generation unit is further used to perform a remainder operation on the length of the target data packet based on a random number to obtain the offset; or, the first generation unit is further used to use the random number as a random seed to generate a target random number, and perform a remainder operation on the length of the target data packet based on the target random number to obtain the offset.

[0141] In a specific embodiment, the second calculation module 104 is further used to perform an exclusive OR operation on the fourth data, the original data, and the second hash value to obtain the check value.

[0142] In a specific embodiment, the target data is obtained based on the exclusive OR operation of the first data, the second data, and the first hash value;

[0143] The first calculation module 103 is further used to perform an exclusive OR operation on the third data, the fourth data, and the second hash value to obtain the original data.

[0144] For the system embodiment, since it basically corresponds to the method embodiment, the relevant parts can refer to the partial description of the method embodiment. The system embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated. The components as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the present disclosure solution.

[0145] In this embodiment, the first data bit is determined by a random number generated through a random process to verify the correctness of the hash value according to the data in the first data bit, and the data used for calculating the hash value does not include the data in the second data bit. Therefore, it is difficult to crack by experience; the replacement data of the second data bit in the data packet is obtained based on the deformation operation of three numbers, and the real content of the data packet is modified, so it cannot be directly used even if it is intercepted during data transmission; the data of the second data bit can be inversely calculated through the hash value, and the correctness of the data can be verified by comparison. Even if the hash algorithm is cracked, due to the existence of the random process, the hash value cannot be correctly calculated; in addition, the hash value does not increase the length of the data packet and will not affect the subsequent hierarchical communication, so as to ensure that the legality of the transmitted data packet will not be modified and improve the security of data transmission.

[0146] Embodiment 4

[0147] In a specific embodiment of the present disclosure, a data transmission system 200 is provided. The data transmission system 200 is applied to a sending end, as Figure 6 shown. The data transmission system 200 includes a second establishment module 201, a third calculation module 202, and a generation module 203;

[0148] The second establishment module 201 is used to establish a communication connection with a receiving end and obtain a random number, and the random number is obtained through negotiation between the sending end and the receiving end;

[0149] The third calculation module 202 is used to determine a first data bit and a second data bit in an original data packet based on the random number, and calculate target data according to the first data in the first data bit, the second data in the second data bit, and a first hash value corresponding to the original data packet except for the second data;

[0150] The generation module 203 is used to replace the second data with the target data, generate a target data packet, and transmit the target data packet to the receiving end for the receiving end to process the target data packet;

[0151] Wherein, the steps for the receiving end to process the target data packet include: determining a first data bit and a second data bit in the target data packet based on the random number; calculating original data according to the third data in the first data bit, the fourth data in the second data bit, and a second hash value corresponding to the target data packet except for the fourth data; calculating a check value according to the fourth data, the original data, and the second hash value; in response to the check value being equal to the third data, replacing the fourth data with the original data to obtain an original data packet; or, in response to the check value not being equal to the third data, disconnecting the communication connection.

[0152] In a specific implementation manner, the third calculation module 202 includes a second generation unit and a second determination unit;

[0153] The second generating unit is used to generate an offset based on a random number;

[0154] The second determining unit is used to determine that the position corresponding to the offset in the original data packet is the first data bit;

[0155] The second determining unit is further used to determine that the position after the first data bit and at a preset number of bits away from the first data bit is the second data bit.

[0156] In a specific embodiment, the second generating unit is further used to perform a remainder operation on the length of the original data packet based on the random number to obtain the offset; or, the second generating unit is further used to use the random number as a random seed to generate a target random number, and perform a remainder operation on the length of the original data packet based on the target random number to obtain the offset.

[0157] In a specific embodiment, the third calculation module 202 is further used to perform an exclusive OR operation on the first data, the second data, and the first hash value to obtain the target data.

[0158] For the system embodiment, since it basically corresponds to the method embodiment, the relevant parts can refer to the partial description of the method embodiment. The system embodiments described above are only illustrative. The units described as separate components may or may not be physically separated. The components as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the present disclosure solution.

[0159] In this embodiment, the first data bit is determined by a random number generated through a random process to verify the correctness of the hash value according to the data in the first data bit, and the data for calculating the hash value does not include the data in the second data bit. Therefore, it is difficult to crack by experience; the replacement data of the second data bit in the data packet is obtained based on the deformation operation of three numbers, and the real content of the data packet is modified, so it cannot be directly used even if it is intercepted during data transmission; the data of the second data bit can be inversely calculated through the hash value, and the correctness of the data can be verified by comparison. Even if the hash algorithm is cracked, due to the existence of the random process, the hash value cannot be correctly calculated; in addition, the hash value does not increase the length of the data packet and will not affect subsequent hierarchical communication, so as to ensure that the legality of the transmitted data packet will not be modified and improve the security of data transmission.

[0160] Embodiment 5

[0161] In a specific embodiment of the present disclosure, a data transmission device is provided, such as Figure 7As shown, the data transmission device includes the data receiving system 100 and the data transmission system 200 described in any of the above embodiments. The data receiving system 100 and the data transmission system 200 establish a communication connection to transmit data packets.

[0162] As Figure 8 shown, the data receiving system establishes a communication connection with the data transmission system and negotiates a random number; the data receiving system generates an offset according to the random number, obtains the first data in the first data bit of the original data packet according to the offset, takes the data in the Nth data bit after the first data bit of the original data packet as the second data, calculates the first hash value of the original data packet except the second data, performs a combined calculation on the first data, the second data and the first hash value to obtain the target data, replaces the second data in the second data bit of the original data packet with the target data to obtain the target data packet, and sends the target data packet to the data receiving system.

[0163] After receiving the target data packet, the data receiving system generates an offset according to the random number, obtains the third data in the first data bit of the target data packet according to the offset, takes the data in the Nth data bit after the first data bit of the target data packet as the fourth data, calculates the second hash value of the target data packet except the fourth data, performs a combined calculation on the third data, the fourth data and the second hash value in the same calculation method as the data transmission system to obtain the original data, calculates a check value according to the fourth data, the original data and the second hash value, and compares whether the check value is equal to the third data in the target data packet. If so, the verification is successful, the data transmission is determined to be secure, the original data replaces the fourth data to obtain the original data packet, otherwise the communication connection is disconnected.

[0164] In this embodiment, the first data bit is determined by the random number generated by the random process to verify the correctness of the hash value according to the data in the first data bit, and the data for calculating the hash value does not include the data in the second data bit. Therefore, it is difficult to crack through experience; the replacement data in the second data bit of the data packet is obtained through a deformed operation based on three numbers, and the real content of the data packet is modified, so it cannot be directly used even if it is intercepted during the data transmission process; the data in the second data bit can be deduced by the hash value, and the correctness of the data can be verified by comparison. Even if the hash algorithm is cracked, due to the existence of the random process, the hash value cannot be correctly calculated; in addition, the hash value does not increase the length of the data packet and will not affect the subsequent hierarchical communication, so the legality of the transmitted data packet can be ensured not to be modified, and the security of data transmission is improved.

[0165] Embodiment 6

[0166] Figure 9The following is a schematic structural diagram of an electronic device shown in an exemplary embodiment of the present disclosure. The electronic device includes a memory, a processor, and a computer program stored in the memory and configured to run on the processor. When the processor executes the computer program, it implements the data receiving method and / or the data transmitting method described in any of the above embodiments. Figure 9 The electronic device 30 shown is merely an example and should not impose any limitation on the functions and usage scope of the embodiments of the present disclosure.

[0167] As Figure 9 shown, the electronic device 30 may be presented in the form of a general-purpose computing device, for example, it may be a server device. The components of the electronic device 30 may include, but are not limited to: at least one of the above-mentioned processors 31, at least one of the above-mentioned memories 32, and a bus 33 connecting different system components (including the memory 32 and the processor 31).

[0168] The bus 33 includes a data bus, an address bus, and a control bus.

[0169] The memory 32 may include volatile memory, such as a random access memory (RAM) 321 and / or a cache memory 322, and may further include a read-only memory (ROM) 323.

[0170] The memory 32 may further include a program tool 325 (or utility) having a set (at least one) of program modules 324. Such program modules 324 include, but are not limited to: an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include the implementation of a network environment.

[0171] The processor 31 executes various functional applications and data processing by running the computer program stored in the memory 32, such as the data receiving method and / or the data transmitting method provided in any of the above embodiments.

[0172] The electronic device 30 may also communicate with one or more external devices 34 (such as a keyboard, a pointing device, etc.). Such communication may be carried out through an input / output (I / O) interface 35. And, the electronic device 30 may further communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through a network adapter 36. As shown in the figure, the network adapter 36 communicates with other modules of the electronic device 30 through the bus 33. It should be understood that although not shown in the figure, other hardware and / or software modules may be used in combination with the electronic device 30, including but not limited to: microcode, device drivers, redundant processors, external disk drive arrays, RAID (disk array) systems, tape drives, and data backup storage systems, etc.

[0173] It should be noted that although several units / modules or sub-units / modules of the electronic device are mentioned in the above detailed description, this division is merely exemplary and not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of two or more units / modules described above can be embodied in one unit / modules. Conversely, the features and functions of one unit / modules described above can be further divided and embodied by multiple units / modules.

[0174] Embodiment 7

[0175] The embodiments of the present disclosure also provide a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the data receiving method and / or data transmitting method provided in any of the above embodiments.

[0176] Among them, the more specific forms that the readable storage medium can adopt may include but are not limited to: portable disks, hard disks, random access memories, read-only memories, erasable programmable read-only memories, optical storage devices, magnetic storage devices, or any suitable combination of the above.

[0177] Embodiment 8

[0178] The embodiments of the present disclosure also provide a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the data receiving method and / or data transmitting method described in any of the above embodiments.

[0179] Among them, the program code for executing the computer program product of the present disclosure can be written in any combination of one or more programming languages, and the program code can be executed entirely on the user device, partially on the user device, executed as an independent software package, partially on the user device and partially on a remote device, or entirely on a remote device.

[0180] Although the specific embodiments of the present disclosure have been described above, those skilled in the art should understand that this is only for illustration, and the protection scope of the present disclosure is defined by the appended claims. Without departing from the principles and essence of the present disclosure, those skilled in the art can make various changes or modifications to these embodiments, but these changes and modifications all fall within the protection scope of the present disclosure.

Claims

1. A data receiving method, characterized in that: The data receiving method is applied to a receiving end, and the data receiving method comprises: Establishing a communication connection with a sending end and obtaining a random number, wherein the random number is obtained based on a negotiation between the sending end and the receiving end; Receive a target data message transmitted by the sending end, wherein the target data message is obtained by replacing the second data in the second data bit of the original data message with the target data; wherein the first data bit and the second data bit in the original data message are determined based on the random number, and the target data is calculated based on the first data in the first data bit, the second data, and a first hash value corresponding to the original data message excluding the second data; Determine the first data bit and the second data bit in the target data message based on the random number, and calculate the original data according to the third data in the first data bit, the fourth data in the second data bit, and the second hash value corresponding to the target data message except the fourth data; A check value is calculated according to the fourth data, the original data, and the second Hash value; In response to the check value being equal to the third data, replacing the fourth data with the original data to obtain the original data message; or, In response to the check value being unequal to the third data, the communication connection is disconnected.

2. The data receiving method according to claim 1, characterized in that: The step of determining the first data bit and the second data bit in the target data message based on the random number comprises: generating an offset based on the random number; Determine that a position in the target data message corresponding to the offset is the first data bit; The position after the first data bit and away from the first data bit by a preset number of bits is determined to be the second data bit.

3. The data receiving method according to claim 2, characterized in that: The step of generating an offset based on the random number comprises: Performing a modulo operation on the length of the target data message based on the random number to obtain the offset; or, The random number is used as a random seed to generate a target random number, and a modulo operation is performed on the length of the target data message based on the target random number to obtain the offset.

4. The data receiving method according to any one of claims 1 to 3, characterized in that: The step of calculating a check value according to the fourth data, the original data, and the second Hash value comprises: Performing an XOR operation on the fourth data, the original data, and the second Hash value to obtain the check value; and / or, The target data is obtained based on an exclusive OR operation of the first data, the second data and the first hash value; The step of calculating the original data according to the third data in the first data bit, the fourth data in the second data bit, and the second hash value corresponding to the target data message except the fourth data comprises: An XOR operation is performed on the third data, the fourth data, and the second Hash value to obtain the original data.

5. A data transmission method, characterized in that: The data transmission method is applied to a transmitting end, and the data transmission method includes: Establishing a communication connection with a receiving end and obtaining a random number, wherein the random number is obtained based on a negotiation between the sending end and the receiving end; Determine a first data bit and a second data bit in the original data message based on the random number, and calculate the target data according to the first data in the first data bit, the second data in the second data bit, and a first hash value corresponding to the original data message except the second data; Replacing the second data with the target data to generate a target data message, and transmitting the target data message to the receiving end so that the receiving end processes the target data message; Among them, the step of the receiving end processing the target data message includes: determining the first data bit and the second data bit in the target data message based on the random number; calculating the original data according to the third data in the first data bit, the fourth data in the second data bit and the second hash value corresponding to the target data message except the fourth data; calculating the check value according to the fourth data, the original data and the second hash value; in response to the check value being equal to the third data, replacing the fourth data with the original data to obtain the original data message; or, in response to the check value being not equal to the third data, disconnecting the communication connection.

6. The data transmission method according to claim 5, characterized in that: The step of determining the first data bit and the second data bit in the original data message based on the random number comprises: generating an offset based on the random number; Determine that a position in the original data message corresponding to the offset is the first data bit; The position after the first data bit and away from the first data bit by a preset number of bits is determined to be the second data bit.

7. The data transmission method according to claim 6, characterized in that: The step of generating an offset based on the random number comprises: Performing a modulo operation on the length of the original data message based on the random number to obtain the offset; or, The random number is used as a random seed to generate a target random number, and a modulo operation is performed on the length of the original data message based on the target random number to obtain the offset.

8. The data transmission method according to any one of claims 5 to 7, characterized in that: The step of calculating the target data according to the first data in the first data bit, the second data in the second data bit, and the first hash value corresponding to the original data message except the second data comprises: The target data is obtained by performing an XOR operation on the first data, the second data, and the first Hash value.

9. A data receiving system, characterized in that: The data receiving system is applied to the receiving end, and the data receiving system includes a first establishing module, a receiving module, a first calculating module, a second calculating module and a checking module; The first establishing module is used to establish a communication connection with the sending end and obtain a random number, where the random number is obtained based on negotiation between the sending end and the receiving end; The receiving module is used to receive a target data message transmitted by the sending end, and the target data message is obtained by replacing the second data in the second data bit of the original data message with the target data; wherein the first data bit and the second data bit in the original data message are determined based on the random number, and the target data is calculated based on the first data in the first data bit, the second data, and a first hash value corresponding to the original data message except the second data; The first calculation module is used to determine the first data bit and the second data bit in the target data message based on the random number, and calculate the original data according to the third data in the first data bit, the fourth data in the second data bit, and the second hash value corresponding to the target data message except the fourth data; The second calculation module is used to calculate a check value according to the fourth data, the original data, and the second Hash value; The verification module is used for replacing the fourth data with the original data in response to the verification value being equal to the third data, so as to obtain the original data message; or, The verification module is used for disconnecting the communication connection in response to the verification value being unequal to the third data.

10. A data transmission system, characterized in that: The data transmission system is applied to the sending end, and the data transmission system includes a second establishing module, a third calculating module and a generating module; The second establishing module is used to establish a communication connection with the receiving end and obtain a random number, where the random number is obtained based on negotiation between the sending end and the receiving end; The third calculation module is used to determine the first data bit and the second data bit in the original data message based on the random number, and calculate the target data according to the first data in the first data bit, the second data in the second data bit, and the first hash value corresponding to the original data message except the second data; The generating module is used to replace the second data with the target data, generate a target data message, and transmit the target data message to the receiving end so that the receiving end processes the target data message; Among them, the step of the receiving end processing the target data message includes: determining the first data bit and the second data bit in the target data message based on the random number; calculating the original data according to the third data in the first data bit, the fourth data in the second data bit and the second hash value corresponding to the target data message except the fourth data; calculating the check value according to the fourth data, the original data and the second hash value; in response to the check value being equal to the third data, replacing the fourth data with the original data to obtain the original data message; or, in response to the check value being not equal to the third data, disconnecting the communication connection.

11. A data transmission device, characterized in that: The data transmission device includes the data receiving system as claimed in claim 9 and the data transmission system as claimed in claim 10.

12. An electronic device comprising a memory, a processor, and a computer program stored in the memory and used to run on the processor, characterized in that: When the processor executes the computer program, the processor implements the data receiving method according to any one of claims 1 to 4 and / or the data transmission method according to any one of claims 5 to 8.

13. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the computer program implements the data receiving method according to any one of claims 1 to 4 and / or the data transmission method according to any one of claims 5 to 8.

14. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the computer program implements the data receiving method according to any one of claims 1 to 4 and / or the data transmission method according to any one of claims 5 to 8.