Data transmission encryption system and method, computer equipment and storage medium

By introducing a key management server in the data transmission system, secondary encryption of the key is solved, and the problem that communication data is easily decrypted by the server and leaked shared encryption keys during transmission is solved, thereby achieving higher data transmission security and reducing key maintenance costs.

CN120200788APending Publication Date: 2025-06-24SUZHOU INST OF BIOMEDICAL ENG & TECH CHINESE ACADEMY OF SCI
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510291767.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-12
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

In the prior art, communication data is easily decrypted by the server during transmission, and the leakage of shared encryption keys leads to data leakage, and the key maintenance cost is high.

Method used

By introducing a key management server in the data transmission system, generating a conversion key, and using the service public key and the communication public key to perform secondary encryption of the key, ensuring the security of the encryption key during the data transmission process.

Benefits of technology

It improves the security of data transmission, reduces the maintenance cost of data transmission client keys, and avoids the risk of data leakage caused by key leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200788A_ABST
    Figure CN120200788A_ABST
Patent Text Reader

Abstract

The invention provides a data transmission encryption system and method, computer equipment and a storage medium. The data transmission encryption system comprises a first client, a data transmission server, a second client and a key management server. According to the invention, the problems of data leakage and high key maintenance cost caused by easy decryption of communication data by a server and leakage of a shared encryption key in the prior art are solved, the security of data transmission is improved through secondary encryption of the key, and the maintenance cost of the key of the data transmission client is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network data transmission encryption, and particularly relates to a data transmission encryption system, method, computer device, and storage medium. Background Art

[0002] At present, there are mainly the following two methods for encrypted transmission of communication data:

[0003] (1) Encryption transmission method based on digital envelope. Specifically, the data transmission client encrypts the communication data using a symmetric key to obtain the ciphertext data of the communication data, and encrypts the symmetric key using the service public key of the data transmission server to obtain the ciphertext data of the symmetric key. The obtained ciphertext data of the communication data and the ciphertext data of the symmetric key are sent to the data transmission server and forwarded by the data transmission server to the target data transmission client.

[0004] Obviously, in this encryption transmission method based on digital envelope, the data transmission server can decrypt all communication data, and there may be a security risk of communication data leakage.

[0005] (2) Encryption transmission method based on shared key. Specifically, the data transmission client encrypts the communication data using the shared key to obtain the ciphertext data of the communication data, and then sends the shared key and the ciphertext data of the communication data to the data transmission server, and the data transmission server forwards it to the target data transmission client.

[0006] Obviously, in the encryption transmission method based on shared key, as long as the shared key is cracked, anyone can decrypt the communication data, resulting in the leakage of communication data. Moreover, the data transmission client needs to maintain a large number of shared keys to be able to perform data transmission with different target data transmission clients, thus increasing the maintenance cost of the shared keys. Summary of the Invention

[0007] To achieve the above objects and other advantages of the present invention, the first object of the present invention is to provide a data transmission encryption system, including a first client, a data transmission server, and a second client; wherein,

[0008] The first client is used to send data, generate an encryption key, encrypt the communication data using the encryption key to obtain the first ciphertext data, perform transformation processing on the encryption key to obtain a hidden key, and encrypt the hidden key using the service public key of the data transmission server to obtain the second ciphertext data, and then send the first ciphertext data and the second ciphertext data to the data transmission server;

[0009] The data transmission server is used to receive the first ciphertext data and the second ciphertext data sent by the first client, decrypt the second ciphertext data by using the service private key stored in the data transmission server to obtain the hidden key, and encrypt the hidden key by using the communication public key between the data transmission server and the second client to obtain the third ciphertext data, and send the first ciphertext data and the third ciphertext data to the second client for processing;

[0010] The second client is used to receive the first ciphertext data and the third ciphertext data, decrypt the third ciphertext data by using the service private key stored in the second client to obtain the hidden key, perform a restoration process on the hidden key to obtain the encryption key, and decrypt the first ciphertext data by using the encryption key to obtain the data to be transmitted.

[0011] Further, a key management server is further included. The key management server is used to generate a conversion key, encrypt the conversion key by using the communication public key of the first client to obtain the first converted ciphertext data, and send the first converted ciphertext data to the first client, encrypt the conversion key by using the communication public key of the second client to obtain the second converted ciphertext data, and send the second converted ciphertext data to the second client.

[0012] Further, the first client decrypts the first converted ciphertext data sent by the key management server by using the built-in conversion key to obtain the conversion key, and performs a transformation process on the encryption key based on the decrypted conversion key to obtain the hidden key;

[0013] The second client decrypts the second converted ciphertext data sent by the key management server by using the built-in conversion key to obtain the conversion key, and performs a restoration process on the hidden key based on the decrypted conversion key to obtain the encryption key.

[0014] The second object of the present invention is to provide a data transmission encryption method, which is applied to the first client described above, and includes the following steps:

[0015] Send data, and generate an encryption key, encrypt the communication data by using the encryption key to obtain the first ciphertext data;

[0016] Perform a transformation process on the encryption key to obtain the hidden key;

[0017] Encrypt the hidden key by using the service public key of the data transmission server to obtain the second ciphertext data;

[0018] Send the first ciphertext data and the second ciphertext data to the data transmission server.

[0019] Further, the step of performing a transformation process on the encryption key to obtain a hidden key includes:

[0020] Decrypt the first transformed ciphertext data sent by the key management server through the built-in transformation key to obtain the transformation key;

[0021] Perform a transformation process on the encryption key based on the decrypted transformation key to obtain a hidden key.

[0022] The third objective of the present invention is to provide a data transmission encryption method, which is applied to the above data transmission server and includes the following steps:

[0023] Receive the first ciphertext data and the second ciphertext data sent by the first client;

[0024] Use the service private key stored in the data transmission server to decrypt the second ciphertext data to obtain a hidden key;

[0025] Encrypt the hidden key using the communication public key between the data transmission server and the second client to obtain the third ciphertext data;

[0026] Send the first ciphertext data and the third ciphertext data to the second client for processing.

[0027] The fourth objective of the present invention is to provide a data transmission encryption method, which is applied to the above second client and includes the following steps:

[0028] Receive the first ciphertext data and the third ciphertext data sent by the data transmission server;

[0029] Use the service private key stored in the second client to decrypt the third ciphertext data to obtain a hidden key;

[0030] Perform a restoration process on the hidden key to obtain an encryption key;

[0031] Use the encryption key to decrypt the first ciphertext data to obtain the data to be transmitted.

[0032] Further, the step of performing a restoration process on the hidden key to obtain an encryption key includes:

[0033] Decrypt the second transformed ciphertext data sent by the key management server through the built-in transformation key to obtain the transformation key;

[0034] Perform a restoration process on the hidden key based on the decrypted transformation key to obtain an encryption key.

[0035] The fifth object of the present invention is to provide a data transmission encryption method, which is applied to the above-mentioned key management server and includes the following steps:

[0036] Generate a conversion key;

[0037] Encrypt the conversion key with the communication public key of the first client to obtain the first converted ciphertext data;

[0038] Send the first converted ciphertext data to the first client;

[0039] Encrypt the conversion key with the communication public key of the second client to obtain the second converted ciphertext data;

[0040] Send the second converted ciphertext data to the second client.

[0041] The sixth object of the present invention is to provide a computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the steps of the above method are implemented.

[0042] The seventh object of the present invention is to provide a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the above method are implemented.

[0043] Compared with the prior art, the beneficial effects of the present invention are:

[0044] The present invention provides a data transmission encryption system, method, computer device, and storage medium, which solves the problems in the prior art that communication data is easily decrypted by the server, shared encryption keys are leaked resulting in data leakage, and the key maintenance cost is high. By double-encrypting the keys, the security of data transmission is improved, and the maintenance cost of the keys of the data transmission client is reduced.

[0045] The above description is only an overview of the technical solution of the present invention. In order to be able to understand the technical means of the present invention more clearly and implement it according to the content of the specification, the following takes the preferred embodiments of the present invention and combines the accompanying drawings to describe in detail as follows. The specific implementation manners of the present invention are given in detail by the following embodiments and their accompanying drawings. Brief Description of the Drawings

[0046] The accompanying drawings described herein are used to provide a further understanding of the present invention, and constitute a part of this application. The illustrative embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:

[0047] Figure 1 It is a schematic diagram of a data transmission encryption system;

[0048] Figure 2Method flow for encrypting data transmission Figure 1 ;

[0049] Figure 3 is a flowchart of encryption key transformation process;

[0050] Figure 4 Encryption method flow for data transmission Figure 2 ;

[0051] Figure 5 Encryption method flow for data transmission Figure 3 ;

[0052] Figure 6 A flowchart for hidden key recovery process;

[0053] Figure 7 Encryption method flow for data transmission Figure 4 ;

[0054] Figure 8 It is a schematic diagram of computer equipment;

[0055] Figure 9 A schematic diagram of a computer-readable storage medium. DETAILED DESCRIPTION

[0056] The present invention is further described below in conjunction with the accompanying drawings and specific implementation methods. Obviously, the described embodiments are only part of the embodiments of the present invention, rather than all of the embodiments. It should be noted that, under the premise of no conflict, the embodiments or technical features described below can be arbitrarily combined to form a new embodiment.

[0057] Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in the field without making any creative work shall fall within the scope of protection of the present invention.

[0058] The figure numbers in this application are only used to distinguish the various steps in the scheme, and are not used to limit the execution order of the various steps. The specific execution order is subject to the description in the specification.

[0059] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art of the present invention. The terms used in the specification of the present invention herein are only for the purpose of describing specific embodiments and are not intended to limit the present invention.

[0060] Example 1

[0061] A data transmission encryption system is used to solve the problems in the prior art that communication data is easily decrypted by the server, shared encryption key leakage leads to data leakage, and key maintenance cost is high. Figure 1As shown, the system includes a first client, a data transmission server, and a second client; among them,

[0062] The first client is used to send data, generate an encryption key, encrypt the communication data using the encryption key to obtain first ciphertext data, perform a transformation process on the encryption key to obtain a hidden key, and encrypt the hidden key using the service public key of the data transmission server to obtain second ciphertext data, and then send the first ciphertext data and the second ciphertext data to the data transmission server;

[0063] The data transmission server is used to receive the first ciphertext data and the second ciphertext data sent by the first client, decrypt the second ciphertext data using the service private key stored in the data transmission server to obtain a hidden key, and encrypt the hidden key using the communication public key with the second client to obtain third ciphertext data, and send the first ciphertext data and the third ciphertext data to the second client for processing;

[0064] The second client is used to receive the first ciphertext data and the third ciphertext data, decrypt the third ciphertext data using the service private key stored in the second client to obtain a hidden key, perform a restoration process on the hidden key to obtain an encryption key, and decrypt the first ciphertext data using the encryption key to obtain the data to be transmitted.

[0065] In some embodiments, as Figure 1 shown, it further includes a key management server, and the key management server is used to generate a conversion key, encrypt the conversion key using the communication public key of the first client to obtain first conversion ciphertext data, and send the first conversion ciphertext data to the first client, encrypt the conversion key using the communication public key of the second client to obtain second conversion ciphertext data, and send the second conversion ciphertext data to the second client.

[0066] Furthermore, the first client decrypts the first conversion ciphertext data sent by the key management server through the built-in conversion key to obtain the conversion key, and performs a transformation process on the encryption key based on the decrypted conversion key to obtain a hidden key;

[0067] The second client decrypts the second conversion ciphertext data sent by the key management server through the built-in conversion key to obtain the conversion key, and performs a restoration process on the hidden key based on the decrypted conversion key to obtain an encryption key.

[0068] Embodiment 2

[0069] A data transmission encryption method is applied to the first client described above. For a detailed description of the first client, reference can be made to the corresponding description in the embodiment of the data transmission encryption system above, which will not be elaborated here. As Figure 2 shown, the method includes the following steps:

[0070] S100. Send data and generate an encryption key, and use the encryption key to encrypt the communication data to obtain the first ciphertext data;

[0071] S110. Perform a transformation process on the encryption key to obtain a hidden key;

[0072] S120. Use the service public key of the data transmission server to encrypt the hidden key to obtain the second ciphertext data;

[0073] S130. Send the first ciphertext data and the second ciphertext data to the data transmission server.

[0074] Further, as Figure 3 shown, the step of performing a transformation process on the encryption key to obtain a hidden key includes:

[0075] S111. Decrypt the first transformed ciphertext data sent by the key management server through the built-in transformation key to obtain the transformation key;

[0076] S112. Perform a transformation process on the encryption key based on the decrypted transformation key to obtain a hidden key.

[0077] Embodiment 3

[0078] A data transmission encryption method is applied to the data transmission server described above. For a detailed description of the data transmission server, reference can be made to the corresponding description in the embodiment of the data transmission encryption system above, which will not be elaborated here. As Figure 4 shown, the method includes the following steps:

[0079] S200. Receive the first ciphertext data and the second ciphertext data sent by the first client;

[0080] S210. Use the service private key stored in the data transmission server to decrypt the second ciphertext data to obtain a hidden key;

[0081] S220. Use the communication public key between the data transmission server and the second client to encrypt the hidden key to obtain the third ciphertext data;

[0082] S230. Send the first ciphertext data and the third ciphertext data to the second client for processing.

[0083] Embodiment 4

[0084] A data transmission encryption method is applied to the second client described above. For a detailed description of the second client, reference can be made to the corresponding description in the embodiments of the above data transmission encryption system, which will not be elaborated here. As Figure 5 shown, the method includes the following steps:

[0085] S300. Receive the first ciphertext data and the third ciphertext data sent by the data transmission server;

[0086] S310. Decrypt the third ciphertext data by using the service private key stored in the second client to obtain a hidden key;

[0087] S320. Perform a reduction process on the hidden key to obtain an encryption key;

[0088] S330. Decrypt the first ciphertext data by using the encryption key to obtain the data to be transmitted.

[0089] Further, as Figure 6 shown, the step of performing a reduction process on the hidden key to obtain an encryption key includes:

[0090] S321. Decrypt the second conversion ciphertext data sent by the key management server by using the built-in conversion key to obtain a conversion key;

[0091] S322. Perform a reduction process on the hidden key based on the decrypted conversion key to obtain an encryption key.

[0092] Embodiment 5

[0093] A data transmission encryption method is applied to the key management server described above. For a detailed description of the key management server, reference can be made to the corresponding description in the embodiments of the above data transmission encryption system, which will not be elaborated here. As Figure 7 shown, it includes the following steps:

[0094] S400. Generate a conversion key;

[0095] S410. Encrypt the conversion key by using the communication public key of the first client to obtain the first conversion ciphertext data;

[0096] S420. Send the first conversion ciphertext data to the first client;

[0097] S430. Encrypt the conversion key by using the communication public key of the second client to obtain the second conversion ciphertext data;

[0098] S440. Send the second conversion ciphertext data to the second client.

[0099] Example 6

[0100] A computer device 500, as Figure 8 shown, includes a memory 510, a processor 520, and a computer program 530 stored on the memory and executable on the processor. When the processor executes the computer program, it implements the steps of a data transmission encryption method. For a detailed description of the method, reference can be made to the corresponding description in the above method embodiments and will not be elaborated here.

[0101] Example 7

[0102] A computer-readable storage medium, as Figure 9 shown, stores a computer program thereon. When the computer program is executed by a processor, it implements the steps of a data transmission encryption method. For a detailed description of the method, reference can be made to the corresponding description in the above method embodiments and will not be elaborated here.

[0103] The number of devices and the scale of processing described here are used to simplify the description of the present invention. Applications, modifications, and variations of the present invention will be apparent to those skilled in the art.

[0104] Although the embodiments of the present invention have been disclosed as above, they are not limited to the applications listed in the specification and embodiments. It can be fully applied to various fields suitable for the present invention. For those skilled in the art, additional modifications can be easily made. Therefore, without departing from the general concept defined by the claims and the equivalent scope, the present invention is not limited to specific details and the illustrated and described examples here.

[0105] The device, computer device, non-volatile computer storage medium, and method provided in the embodiments of this specification are corresponding. Therefore, the device, computer device, and non-volatile computer storage medium also have beneficial technical effects similar to the corresponding method. Since the beneficial technical effects of the method have been described in detail above, the beneficial technical effects of the corresponding device, computer device, and non-volatile computer storage medium will not be elaborated here.

[0106] Those skilled in the art also know that in addition to implementing the controller in the form of pure computer-readable program code, the method steps can be logically programmed to enable the controller to be implemented in the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, embedded microcontrollers, etc. to achieve the same function. Therefore, such a controller can be regarded as a hardware component, and the devices included therein for implementing various functions can also be regarded as the structures within the hardware component. Or even, the devices for implementing various functions can be regarded as both software units for implementing the method and the structures within the hardware component.

[0107] The systems, devices, or units illustrated in the above embodiments can be specifically implemented by computer chips or entities, or by products with certain functions. For the convenience of description, when describing the above devices, they are divided into various units according to their functions and described separately. Of course, when implementing one or more embodiments of this specification, the functions of each unit can be implemented in the same or multiple software and / or hardware.

[0108] Those skilled in the art should understand that the embodiments of this specification can be provided as methods, systems, or computer program products. Therefore, the embodiments of this specification can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the embodiments of this specification can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0109] This specification is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of this specification. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0110] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device that implements the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0111] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0112] It should also be noted that the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, commodity or device comprising a series of elements not only includes those elements but also other elements not expressly listed, or elements inherent to such process, method, commodity or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, commodity or device comprising said element.

[0113] This specification may be described in the general context of computer-executable instructions executed by a computer, such as program units. Generally, program units include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The specification may also be practiced in a distributed computing environment where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program units may be located in local and remote computer storage media including storage devices.

[0114] Each embodiment in this specification is described in a progressive manner. For the same or similar parts among the embodiments, reference may be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for system embodiments, since they are basically similar to method embodiments, they are described relatively simply, and reference may be made to the corresponding parts of the method embodiments for the relevant content.

[0115] The above description is only for the embodiments of this specification and is not intended to limit one or more embodiments of this specification. For those skilled in the art, various changes and modifications can be made to one or more embodiments of this specification. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of one or more embodiments of this specification shall be included within the scope of the claims of one or more embodiments of this specification.

Claims

1. A data transmission encryption system, characterized in that: It includes a first client, a data transmission server, and a second client; wherein, The first client is used to send data and generate an encryption key, use the encryption key to encrypt communication data to obtain first ciphertext data, transform the encryption key to obtain a hidden key, and use the service public key of the data transmission server to encrypt the hidden key to obtain second ciphertext data, and then send the first ciphertext data and the second ciphertext data to the data transmission server; The data transmission server is used to receive the first ciphertext data and the second ciphertext data sent by the first client, decrypt the second ciphertext data using the service private key stored in the data transmission server to obtain the hidden key, and encrypt the hidden key using the communication public key between the second client and the second client to obtain the third ciphertext data, and send the first ciphertext data and the third ciphertext data to the second client for processing; The second client is used to receive the first ciphertext data and the third ciphertext data, decrypt the third ciphertext data using the service private key stored in the second client to obtain a hidden key, restore the hidden key to obtain an encryption key, and decrypt the first ciphertext data using the encryption key to obtain data to be transmitted.

2. A data transmission encryption system as claimed in claim 1, characterized in that: It also includes a key management server, which is used to generate a conversion key, encrypt the conversion key using the communication public key of the first client to obtain first conversion ciphertext data, and send the first conversion ciphertext data to the first client, encrypt the conversion key using the communication public key of the second client to obtain second conversion ciphertext data, and send the second conversion ciphertext data to the second client.

3. A data transmission encryption system as claimed in claim 2, characterized in that: The first client uses a built-in conversion key to decrypt the first converted ciphertext data sent by the key management server to obtain a conversion key, and transforms the encryption key based on the decrypted conversion key to obtain a hidden key; The second client decrypts the second converted ciphertext data sent by the key management server using the built-in conversion key to obtain the conversion key, and restores the hidden key based on the decrypted conversion key to obtain the encryption key.

4. A data transmission encryption method, applied to the first client as claimed in claim 1, characterized in that: The following steps are involved: Sending data, generating an encryption key, and using the encryption key to encrypt the communication data to obtain first ciphertext data; Transforming the encryption key to obtain a hidden key; Encrypting the hidden key using the service public key of the data transmission server to obtain second ciphertext data; The first ciphertext data and the second ciphertext data are sent to the data transmission server.

5. A data transmission encryption method as claimed in claim 4, characterized in that: The step of transforming the encryption key to obtain the hidden key comprises: Decrypting the first conversion ciphertext data sent by the key management server using the built-in conversion key to obtain the conversion key; The encryption key is transformed based on the decrypted conversion key to obtain a hidden key.

6. A data transmission encryption method, applied to the data transmission server as claimed in claim 1, characterized in that: The following steps are involved: Accepting first ciphertext data and second ciphertext data sent by a first client; Decrypting the second ciphertext data using the service private key stored in the data transmission server to obtain a hidden key; Encrypting the hidden key using the communication public key between the client and the second client to obtain third ciphertext data; The first ciphertext data and the third ciphertext data are sent to a second client for processing.

7. A data transmission encryption method, applied to the second client as claimed in claim 1, characterized in that: The following steps are involved: Accepting the first ciphertext data and the third ciphertext data sent by the data transmission server; Decrypting the third ciphertext data using the service private key stored in the second client to obtain a hidden key; Performing a restoration process on the hidden key to obtain an encryption key; The first ciphertext data is decrypted using the encryption key to obtain data to be transmitted.

8. A data transmission encryption method as claimed in claim 7, characterized in that: The step of restoring the hidden key to obtain the encryption key comprises: Decrypting the second conversion ciphertext data sent by the key management server using the built-in conversion key to obtain the conversion key; The hidden key is restored based on the decrypted conversion key to obtain the encryption key.

9. A data transmission encryption method, applied to the key management server as claimed in claim 2, characterized in that: The following steps are involved: Generate conversion key; Encrypting the conversion key using the communication public key of the first client to obtain first conversion ciphertext data; Sending the first converted ciphertext data to the first client; Encrypting the conversion key using the communication public key of the second client to obtain second conversion ciphertext data; The second converted ciphertext data is sent to the second client.

10. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 4 to 9 are implemented.

11. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 4 to 9 are implemented.