A data transmission control method, device, program product, and storage medium

The asymmetric encryption algorithm generates public and private keys to ensure that user information and target data are encrypted during transmission, solving the problem of user privacy data being intercepted and tampered in the information system, and realizing the security of data transmission.

CN120200859BActive Publication Date: 2025-07-22DIGITAL GUANGDONG NETWORK CONSTR CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510686200.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-27
Publication Date
2025-07-22
Estimated Expiration
2045-05-27

AI Technical Summary

Technical Problem

In the information system, user privacy data is easily intercepted and tampered by cyber attackers during transmission and storage, resulting in user privacy leakage.

Method used

Asymmetric encryption algorithm is used to generate public and private keys, and the security of data transmission is ensured by encrypting user information, user information signature values and symmetric keys.

Benefits of technology

Effectively protect user information and target data from intercepting or tampering during transmission, improving the full-chain data security of the data transmission process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200859B_ABST
    Figure CN120200859B_ABST
Patent Text Reader

Abstract

An embodiment of the present invention discloses a data transmission control method, device, program product, and storage medium, including: receiving user information and a data query request sent by a user, and generating a first symmetric key based on the data query request; generating data request information according to the first symmetric key, the user information, and a pre-obtained second asymmetric public key, and sending the data request information to a data storage system; wherein the data request information includes encrypted user information, a user information signature value, and an encrypted first symmetric key; receiving encrypted data information generated by the data storage system based on the data request information; wherein the encrypted data information includes encrypted target data, a data signature value, and an encrypted second symmetric key; obtaining the target data based on a pre-generated first asymmetric private key and the encrypted data information, and presenting the target data to the user. The method of the present invention can improve the security of the entire-chain data in the data transmission process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present invention relate to the field of data processing, and in particular, to a data transmission control method, device, program product, and storage medium. Background Art

[0002] In today's digital age, with the rapid development and wide application of information technology, more and more personal and enterprise information is stored, transmitted, and processed in electronic form. Such information includes, but is not limited to, electronic certificates, personal identity information, financial data, medical records, and communication records, etc., which play important roles in various business scenarios. However, with the wide application of data, the security and protection of user privacy data have become increasingly prominent.

[0003] In current information systems, user privacy data often exists in plain text during transmission and storage. For example, in the government service scenario, the certificate-using system (such as a government service hall or an online government platform) usually needs to use sensitive information such as the user's ID number, name, and certificate number as query conditions to request the electronic certificates required by the user from the certificate system. These information are easily intercepted and tampered with by network attackers during transmission, resulting in the leakage of user privacy data. Summary of the Invention

[0004] Embodiments of the present invention provide a data transmission control method, device, program product, and storage medium, which can ensure that the user's identity information and the queried privacy information will not be intercepted and tampered with by network attackers during the process of the user using identity information to query non-public privacy information, and improve the security of the entire chain of data during the data transmission process.

[0005] In a first aspect, an embodiment of the present invention provides a data transmission control method, which is applied to a data request system and includes:

[0006] Receiving user information and a data query request sent by a user;

[0007] Generating data request information based on the data query request, the user information, and a pre-obtained second asymmetric public key; wherein, the data request information includes encrypted user information, a user information signature value, and an encrypted first symmetric key;

[0008] Sending the data request information to a data storage system, and receiving encrypted data information generated by the data storage system based on the data request information; wherein, the encrypted data information includes encrypted target data, a data signature value, and an encrypted second symmetric key;

[0009] Obtaining target data based on a pre-generated first asymmetric private key and the encrypted data information, and presenting the target data to the user.

[0010] Second aspect, an embodiment of the present invention provides a data transmission control method, which is applied to a data storage system. The method includes:

[0011] Receiving data request information sent by a data request system; wherein, the data request information includes encrypted user information, a user information signature value, and an encrypted first symmetric key;

[0012] Determining user information based on a pre-generated second asymmetric private key and the data request information; wherein, the user information is the decrypted encrypted user information;

[0013] Determining target data corresponding to the user information in a database pre-determined for storing non-public data;

[0014] Generating encrypted data information based on a pre-obtained first asymmetric public key and the target data, and sending the encrypted data information to the data request system; wherein, the encrypted data information includes encrypted target data, a data signature value, and an encrypted second symmetric key.

[0015] Third aspect, an embodiment of the present invention provides a data transmission control device, which includes:

[0016] A first data receiving module, configured to receive user information and a data query request sent by a user, and generate a first symmetric key based on the data query request;

[0017] A data request module, configured to generate data request information based on the data query request, the user information, and a pre-obtained second asymmetric public key; wherein, the data request information includes encrypted user information, a user information signature value, and an encrypted first symmetric key;

[0018] A second data receiving module, configured to send the data request information to a data storage system, and receive encrypted data information generated by the data storage system based on the data request information; wherein, the encrypted data information includes encrypted target data, a data signature value, and an encrypted second symmetric key;

[0019] A first data generating module, configured to obtain target data based on a pre-generated first asymmetric private key and the encrypted data information, and display the target data to the user.

[0020] Fourth aspect, an embodiment of the present invention provides a data transmission control device, which includes:

[0021] A third data receiving module, configured to receive data request information sent by a data request system; wherein, the data request information includes encrypted user information, a user information signature value, and an encrypted first symmetric key;

[0022] The first data determination module is configured to determine user information based on a pre-generated second asymmetric private key and the data request information; wherein, the user information is the decrypted encrypted user information.

[0023] The second data determination module is configured to determine target data corresponding to the user information in a pre-determined database for storing non-public data.

[0024] The second data generation module is configured to generate encrypted data information based on a pre-obtained first asymmetric public key and the target data, and send the encrypted data information to the data request system; wherein, the encrypted data information includes encrypted target data, a data signature value, and an encrypted second symmetric key.

[0025] In a fifth aspect, an embodiment of the present invention further provides an electronic device, where the electronic device includes a memory, a processor, and a computer program stored on the memory and executable on the processor, and when the processor executes the program, it implements a data transmission control method as described in any one of the embodiments of the present invention.

[0026] In a sixth aspect, an embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements a data transmission control method as described in any one of the embodiments of the present invention.

[0027] In a seventh aspect, an embodiment of the present invention provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements a data transmission control method as described in any one of the embodiments of the present invention.

[0028] In an embodiment of the present invention, user information and a data query request sent by a user are received, and a first symmetric key is generated based on the data query request; data request information is generated according to the first symmetric key, the user information, and a pre-obtained second asymmetric public key, and the data request information is sent to a data storage system; wherein, the data request information includes encrypted user information, a user information signature value, and an encrypted first symmetric key; encrypted data information generated by the data storage system based on the data request information is received; wherein, the encrypted data information includes encrypted target data, a data signature value, and an encrypted second symmetric key; the target data is obtained based on a pre-generated first asymmetric private key and the encrypted data information, and the target data is presented to the user. The method of the embodiment of the present invention can ensure that the user information is encrypted during the transmission process and prevent the user information from being intercepted or leaked by obtaining the encrypted user information through the first symmetric key, the user information, and the second asymmetric public key. By means of the user information signature value and the encrypted first symmetric key, it can be ensured that the user information is not tampered with during the transmission process, further protecting user privacy. At the same time, the encrypted target data, the data signature value, and the encrypted second symmetric key returned by the data storage system can ensure that the target data is encrypted during the transmission process and prevent the target data from being intercepted or leaked. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.

[0030] Figure 1 It is a flowchart of a data transmission control method provided by an embodiment of the present invention;

[0031] Figure 2 It is a schematic flowchart of a data request system distributing a first asymmetric public key provided by an embodiment of the present invention;

[0032] Figure 3 It is a schematic flowchart of a data storage system distributing a second asymmetric public key provided by an embodiment of the present invention;

[0033] Figure 4 It is a schematic flowchart of a data request system and a data storage system for data transmission provided by an embodiment of the present invention;

[0034] Figure 5 It is a first structural schematic diagram of a data transmission control device provided by an embodiment of the present invention;

[0035] Figure 6The second schematic structural diagram of a data transmission control device provided by an embodiment of the present invention;

[0036] Figure 7 The schematic structural diagram of an electronic device provided by an embodiment of the present invention. Detailed implementation manners

[0037] The present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the present invention, rather than limiting the present invention. Additionally, it should be noted that for the sake of description, only parts related to the present invention are shown in the drawings, rather than all the structures.

[0038] Figure 1 The flowchart of a data transmission control method provided by an embodiment of the present invention. The method of the embodiment of the present invention can comprehensively and timely discover potential problems existing in the page, improve the robustness and stability of the business system, and further improve the interaction experience between the user and the business system. The information collected in the method of the embodiment of the present invention is information and data authorized by the user or fully authorized by all parties, and the processing of relevant data such as collection, storage, use, processing, transmission, provision, disclosure, and application complies with relevant laws, regulations, and standards of relevant countries and regions, takes necessary confidentiality measures, does not violate public order and good customs, and provides corresponding operation entrances for the user to select authorization or rejection. This method can be executed by a data transmission control device provided by an embodiment of the present invention, and the device can be implemented in a software and / or hardware manner. The following embodiments will be described by taking the integration of the device in an electronic device as an example. The electronic device can be a server or a computer device, etc. Refer to Figure 1 , and the method can specifically include the following steps:

[0039] Step 101: Receive the user information and data query request sent by the user.

[0040] Among them, the user information is relevant information sent by the user to the data request system when querying the target data, which is used to identify the user's identity. The data query request is an operation instruction sent by the user to the data request system for requesting the target data. The data request system is used to find the target data corresponding to the data query request for the user according to the user information and the data query request.

[0041] Specifically, when a user needs to query data through a data request system, the user can send user information and a data query request to the data request system according to their own needs. Exemplarily, in a business scenario where a user needs to handle the business of querying enterprise licenses on a government affairs platform, the data request system can be a license-using system for handling license-related businesses. User information includes, but is not limited to, ID number, username, login account, email address, mobile phone number, enterprise name, business license number, etc. The data query request includes query context information, such as the time range for the user to query data, data type, and other relevant information for auxiliary query or security verification, etc. When the user needs to query license information, the user information can be uploaded on the license-using system, and at the same time, a data query request is sent to the license-using system. The license-using system can receive the user information and data query request sent by the user in real time.

[0042] Step 102: Generate data request information based on the data query request, user information, and the pre-obtained second asymmetric public key.

[0043] Among them, the second asymmetric public key is a public key pre-obtained by the data request system, which is generated by the data storage system and distributed to the data request system. Specifically, when transmitting data between the data request system and the data storage system, it is necessary to ensure the security of the transmitted data. Therefore, before receiving the user information and data query request sent by the user, the data request system can establish a secure communication mechanism with the data storage system and distribute asymmetric public keys to each other. In this solution, optionally, before receiving the user information and data query request sent by the user, it further includes: generating a first asymmetric public key and a first asymmetric private key according to a pre-set first asymmetric encryption algorithm, and sending the first asymmetric public key to the data storage system; obtaining the second asymmetric public key sent by the data storage system.

[0044] Among them, the second asymmetric public key is generated by the data storage system according to a pre-set second asymmetric encryption algorithm. The asymmetric encryption algorithm is a kind of encryption technology. The asymmetric encryption algorithm can generate a public key and a private key. The public key is used to encrypt data, and the private key is used to decrypt data. The first asymmetric encryption algorithm is an asymmetric encryption algorithm pre-determined by the data request system, such as the elliptic curve digital signature algorithm, ElGamal algorithm, or RSA (Rivest-Shamir-Adleman) algorithm, etc. in the asymmetric encryption algorithm. The second asymmetric encryption algorithm is an asymmetric encryption algorithm pre-determined by the data storage system. The first asymmetric encryption algorithm and the second asymmetric encryption algorithm can be the same algorithm or different algorithms.

[0045] Specifically, the data request system generates a first asymmetric public key and a first asymmetric private key using a first asymmetric encryption algorithm. The data request system stores the first asymmetric private key for subsequent decryption of encrypted data. The first asymmetric public key is sent to the data storage system, which stores the first asymmetric public key for subsequent encryption of data to be transmitted, thereby ensuring that only the data request system holding the first asymmetric private key can decrypt the transmitted data. The data storage system generates a second asymmetric public key and a second asymmetric private key using a second asymmetric encryption algorithm. The data storage system stores the second asymmetric private key for subsequent decryption of encrypted data. The second asymmetric public key is sent to the data request system, which stores the second asymmetric public key for subsequent encryption of data to be transmitted, thereby ensuring that only the data storage system holding the second asymmetric private key can decrypt the transmitted data.

[0046] Exemplarily, Figure 2 FIG. is a schematic flow chart of the data request system distributing the first asymmetric public key provided by an embodiment of the present invention. As Figure 2 shown, the data request system generates a first asymmetric public key and a first asymmetric private key according to a first symmetric encryption algorithm, and sends the first asymmetric public key to the data storage system. The data storage system stores the first asymmetric public key and returns a message indicating successful reception to the data request system. After receiving the message, the data request system stores the first asymmetric public key and the first asymmetric private key. Figure 3 FIG. is a schematic flow chart of the data storage system distributing the second asymmetric public key provided by an embodiment of the present invention. As Figure 3 shown, the data storage system generates a second asymmetric public key and a second asymmetric private key according to a second symmetric encryption algorithm, and sends the second asymmetric public key to the data request system. The data request system stores the second asymmetric public key and returns a message indicating successful reception to the data storage system. After receiving the message, the data storage system stores the second asymmetric public key and the second asymmetric private key.

[0047] Through the asymmetric encryption mechanism, the storage system and the data request system can mutually verify their identities. Only the system holding the correct private key can decrypt the data, thereby ensuring the security and reliability of both communication parties. Further, the integrity and authenticity of the data during transmission can be ensured.

[0048] Further, on the premise that the data request system and the data storage system distribute their respective asymmetric public keys to each other, after receiving the user information and the data query request sent by the user, the data request system needs to send the user information to the data storage system so that the data storage system can determine the target data according to the user information. Sensitive information such as phone numbers or ID numbers may be included in the user information. To ensure the secure transmission of the user information, the data request system can encrypt the user information through the second asymmetric public key and a pre-determined symmetric encryption algorithm, and generate a data request message based on the encrypted user information to request the target data from the data storage system. In this solution, the data request message includes the encrypted user information, the user information signature value, and the encrypted first symmetric key. Optionally, generating the data request message based on the data query request, the user information, and the pre-obtained second asymmetric public key includes: generating a first symmetric key in response to the data query request, encrypting the user information according to the first symmetric key to obtain the encrypted user information; performing a one-way encryption calculation on the encrypted user information to obtain the user information signature value; encrypting the first symmetric key according to the pre-obtained second asymmetric public key to obtain the encrypted first symmetric key.

[0049] Among them, the second asymmetric public key is generated by the data storage system and pre-distributed to the data request system. The first symmetric key is a key generated by the data request system according to a pre-determined symmetric encryption algorithm. The symmetric encryption algorithm is an encryption technology whose encryption and decryption processes use the same key. The symmetric encryption algorithm includes the Advanced Encryption Standard algorithm, the Data Encryption Standard algorithm, and the Triple Data Encryption algorithm, etc. The one-way encryption calculation refers to the process of encrypting data through a digest algorithm. The digest algorithm uses a one-way hash function to convert the input data into a fixed-length digest value. The digest algorithm includes the Secure Hash Algorithm - 256, the Secure Hash Algorithm - 1, and the Message Digest Algorithm - 5, etc.

[0050] Specifically, after receiving the user information and the data query request, the data request system generates a first symmetric key according to a pre-determined symmetric encryption algorithm. The user information is encrypted using the first symmetric key. For example, the user information can be divided into blocks of a fixed size and then encrypted block by block to obtain the encrypted user information. The encrypted user information becomes ciphertext and cannot be directly read. Only the system holding the same symmetric key can decrypt it. After obtaining the encrypted user information, a one-way encryption calculation is performed on the encrypted user information using a pre-determined digest algorithm to obtain the user information signature value. The user information signature value is used to verify the integrity and authenticity of the data, ensuring that the data has not been tampered with during transmission. After obtaining the user information signature value, the first symmetric key is encrypted using the second asymmetric public key pre-distributed by the data storage system to obtain the encrypted first symmetric key. The encrypted user information, the user information signature value, and the encrypted first symmetric key are encapsulated into a request data packet to obtain the data request information.

[0051] By encrypting the user information, the security and privacy protection of the user information during transmission are ensured, preventing the user information from being intercepted or tampered with. By generating the user information signature value, the data storage system can verify the integrity and authenticity of the encrypted user information, ensuring that the data has not been tampered with during transmission. Using the asymmetric encryption algorithm to encrypt the symmetric key ensures the security of the symmetric key during transmission.

[0052] Step 103: Send the data request information to the data storage system and receive the encrypted data information generated by the data storage system based on the data request information.

[0053] Among them, the data storage system is used to find the target data corresponding to the data request message in the database according to the data request message. After determining the data request information, the data request system sends the data request information to the data storage system. After receiving the data request information, the data storage system decrypts the encrypted user information in the data request information and queries the target data according to the encrypted user information. The target data is encrypted to generate the encrypted data information, and the encrypted data information is returned to the data request system. In this solution, after the data request system sends the data request information to the data storage system, the data storage system can perform the following steps A1 - step A4:

[0054] Step A1: Receive the data request information sent by the data request system.

[0055] The data request information includes the encrypted user information, the user information signature value, and the encrypted first symmetric key.

[0056] Step A2: Determine the user information based on the pre-generated second asymmetric private key and the data request information.

[0057] Among them, the second asymmetric private key is an asymmetric private key pre-generated by the data storage system according to the second asymmetric encryption algorithm, that is, Figure 2 the asymmetric private key in. Specifically, the encrypted first symmetric key is obtained by the data request system encrypting the first symmetric key using the second asymmetric public key. Therefore, the data storage system can use the second asymmetric private key to decrypt the encrypted first symmetric key. Then use the first symmetric key to decrypt the encrypted user information to obtain the user information. In this solution, optionally, determining the user information based on the pre-generated second asymmetric private key and the data request information includes the following steps A21 - step A23:

[0058] Step A21: Perform a one-way encryption calculation on the user information signature value to obtain the user verification signature value of the user information signature value.

[0059] One-way encryption calculation refers to the process of encrypting data through a digest algorithm. The digest algorithm uses a one-way hash function to convert the input data into a fixed-length digest value. In the digest algorithm, even if there is a slight change in the input data, the generated digest value will change significantly. Therefore, it is possible to determine whether the user information has been tampered with during transmission by comparing the user verification signature value and the user information signature value. After receiving the data request information, the data storage system uses the same digest algorithm as the data request system to calculate the user information signature value to perform a one-way encryption calculation on the user information signature value to obtain the user verification signature value of the user information signature value.

[0060] Step A22: Match the user information signature value and the user verification signature value to obtain the user information matching result. When the user information matching result is a match, decrypt the encrypted first symmetric key according to the second asymmetric private key to obtain the first symmetric key.

[0061] Specifically, after obtaining the user verification signature value, the data storage system matches and compares the user information signature value and the user verification signature value. If the user information signature value and the user verification signature value are exactly the same, it means that the user information has not been tampered with during transmission, and further, it can be determined that the user information matching result is a match. If the user information signature value and the user verification signature value are inconsistent, it means that the user information may have been tampered with during transmission, and the data storage system will reject the data request information.

[0062] In this solution, the encrypted first symmetric key is obtained by the data request system encrypting the first symmetric key using the second asymmetric public key. Therefore, when the user information matching result is a pass, the data storage system can directly decrypt the encrypted first symmetric key using the second asymmetric private key to obtain the first symmetric key. By comparing the user information signature value and the user verification signature value, it can be verified whether the data has been tampered with during transmission, ensuring the secure and error-free transmission of the data.

[0063] Step A23: Decrypt the encrypted user information based on the first symmetric key to obtain the user information.

[0064] Specifically, the encrypted user information is obtained by the data request system encrypting the user information using the first symmetric key. Therefore, the data storage system can directly decrypt the encrypted user information using the first symmetric key to obtain the user information. In the above steps, the encrypted data can be accurately and quickly decrypted using the asymmetric private key and the symmetric key, improving the overall efficiency of the system.

[0065] Step A3: Determine the target data corresponding to the user information in the database pre-determined for storing non-public data.

[0066] Among them, non-public data is data that is not suitable for being publicly disclosed at will. For example, in the business scenario of users applying for electronic licenses and certificates, the non-public data can be the electronic licenses and certificates corresponding to each user, and the target data is the electronic license and certificate corresponding to the user information. After the data storage system obtains the user information, it uses the user information (such as the ID number or certificate number, etc.) as the query condition, accesses the database for storing non-public data through this query condition, and searches for the target data corresponding to the user information in the database.

[0067] Step A4: Generate encrypted data information based on the pre-obtained first asymmetric public key and the target data, and send the encrypted data information to the data request system.

[0068] After the data storage system obtains the target data, it needs to return the target data to the data request system so that the data request system can display the target data for the user. The target data may include non-public data such as electronic licenses and certificates. To ensure the secure transmission of the target data, the data storage system can encrypt the target data using the first asymmetric public key and a pre-determined symmetric encryption algorithm, and send the encrypted target data, that is, the encrypted data information, to the data request system. In this solution, the encrypted data information includes the encrypted target data, the data signature value, and the encrypted second symmetric key. Optionally, generating encrypted data information based on the pre-obtained first asymmetric public key and the target data, and sending the encrypted data information to the data request system, includes the following steps A41 - step A43:

[0069] Step A41: Generate a second symmetric key, and encrypt the target data according to the second symmetric key to obtain encrypted target data.

[0070] Among them, the second symmetric key is a key generated by the data storage system according to a pre-determined symmetric encryption algorithm. The symmetric encryption algorithm is an encryption technology, and its encryption and decryption processes use the same key. The symmetric encryption algorithm for generating the second symmetric key may be the same as or different from the symmetric encryption algorithm for generating the first symmetric key. Specifically, after obtaining the target data, the data storage system generates a second symmetric key according to the pre-determined symmetric encryption algorithm, and encrypts the target data through the second symmetric key to obtain encrypted target data. The encrypted target data will become ciphertext and cannot be directly read, and only the system holding the same symmetric key can decrypt it.

[0071] Step A42: Perform a one-way encryption calculation on the encrypted target data to obtain a data signature value.

[0072] The one-way encryption calculation refers to the process of encrypting data through a digest algorithm. The digest algorithm uses a one-way hash function to convert the input data into a fixed-length digest value. The digest algorithm is a one-way hash function that can convert data of any length into a fixed-length digest value. The data signature value obtained by performing a one-way encryption calculation on the encrypted target data can be used to verify the integrity and authenticity of the license data, ensuring that the encrypted target data has not been tampered with during the transmission process.

[0073] Step A43: Encrypt the second symmetric key according to the first asymmetric public key to obtain an encrypted second symmetric key.

[0074] Among them, the first asymmetric public key is pre-distributed by the data request system to the data storage system. The data storage system uses the first asymmetric public key to encrypt the second symmetric key, which can ensure the security of the second symmetric key during the transmission process, so that only the data request system holding the first asymmetric private key can decrypt the encrypted second symmetric key.

[0075] Furthermore, the data storage system generates encrypted data information according to the encrypted target data, the data signature value, and the encrypted second symmetric key, and sends the encrypted data information to the data request system. By encrypting the target data, the security of the target data during the transmission process is ensured, preventing the target data from being intercepted or tampered with. By generating the data signature value, the data request system can verify the integrity and authenticity of the encrypted target data, ensuring that the data has not been tampered with during the transmission process. Using the asymmetric encryption algorithm to encrypt the symmetric key ensures the security of the symmetric key during the transmission process.

[0076] Step 104: Obtain the target data based on the pre-generated first asymmetric private key and the encrypted data information, and display the target data to the user.

[0077] Specifically, after receiving the encrypted data information, the data request system needs to decrypt the encrypted data information to obtain the target data. The encrypted second symmetric key in the encrypted data information is obtained by the data storage system encrypting the second symmetric key with the first asymmetric public key. Therefore, the data request system can use the first asymmetric private key to decrypt the encrypted second symmetric key, and then use the second symmetric key to decrypt the encrypted target data to obtain the target data. In this solution, optionally, the target data is obtained based on the pre-generated first asymmetric private key and the encrypted data information, and the target data is displayed to the user, including the following steps B1 - B3:

[0078] Step B1: Perform a one-way encryption calculation on the data signature value to obtain the data verification signature value of the data signature value.

[0079] The one-way encryption calculation refers to the process of encrypting data through a digest algorithm. The digest algorithm uses a one-way hash function to convert the input data into a fixed-length digest value. In the digest algorithm, even if there is a slight change in the input data, the generated digest value will change significantly. Therefore, it is possible to determine whether the encrypted target data has been tampered with during transmission by comparing the data verification signature value and the data signature value. After receiving the encrypted data information, the data storage system performs a one-way encryption calculation on the data signature value using the same digest algorithm as the data request system for calculating the data signature value to obtain the data verification signature value of the data signature value.

[0080] Step B2: Match the data signature value and the data verification signature value to obtain the data information matching result; when the data information matching result is a match, decrypt the encrypted second symmetric key according to the first asymmetric private key to obtain the second symmetric key.

[0081] Specifically, after obtaining the data verification signature value, the data storage system matches and compares the data signature value and the data verification signature value. If the data verification signature value and the data signature value are exactly the same, it indicates that the encrypted target data has not been tampered with during transmission, and further, it can be determined that the data information matching result is a match. If the data verification signature value and the data signature value are inconsistent, it indicates that the encrypted target data may have been tampered with during transmission, and the data request system will reject the processing of the encrypted data information.

[0082] In this solution, the encrypted second symmetric key is obtained by the data request system encrypting the second symmetric key with the first asymmetric public key. Therefore, when the data information matching result is a match, the data request system can directly use the first asymmetric private key to decrypt the encrypted second symmetric key to obtain the second symmetric key.

[0083] Step B3: Decrypt the encrypted target data based on the second symmetric key to obtain the target data.

[0084] Specifically, the encrypted target data is obtained by the data request system encrypting the target data with the second symmetric key. Therefore, the data request system can directly use the second symmetric key to decrypt the encrypted target data to obtain the target data. In the above steps, the encrypted target data can be accurately and quickly decrypted by the asymmetric private key and the symmetric key, improving the overall efficiency of the system.

[0085] Figure 4 It is a schematic flowchart of data transmission between the data request system and the data storage system provided by an embodiment of the present invention. As Figure 4 shown, after the data request system receives the user information and the data query request, it generates a first symmetric key, encrypts the user information with the first symmetric key, and calculates the user information signature value. Encrypt the first symmetric key with the second asymmetric public key to obtain the encrypted first symmetric key. Send the encrypted user information, the user information signature value, and the encrypted first symmetric key to the data storage system, and the data storage system receives the encrypted user information, the user information signature value, and the encrypted first symmetric key. The data storage system verifies the user information signature value. After passing the verification, it decrypts the encrypted first symmetric key with the second asymmetric private key to obtain the first symmetric key, and decrypts the encrypted user information with the first symmetric key to obtain the user information. Query and obtain the target data according to the user information, generate a second symmetric key using the second symmetric encryption algorithm, and encrypt the target data with the second symmetric key to obtain the encrypted target data. Calculate the target data signature value, encrypt the second symmetric key with the first asymmetric public key to obtain the encrypted second symmetric key. Send the encrypted target data, the encrypted target data signature value, and the encrypted second symmetric key to the data request system, and the data request system receives the encrypted target data, the encrypted target data signature value, and the encrypted second symmetric key. The data request system verifies the target data signature value. After passing the verification, it decrypts the encrypted second symmetric key with the first asymmetric private key to obtain the second symmetric key, and decrypts the encrypted target data with the second symmetric key to obtain the target data. According to, and display the target data to the user.

[0086] Taking the business scenario where a user needs to query enterprise licenses and certificates on a government affairs platform as an example, the user uploads user information and sends a license and certificate query instruction in the license-using system. The license-using system can encrypt the user information and generate a data query request based on the encrypted user information and the license and certificate query instruction. The data query request is sent to the license and certificate system. After receiving the data query request, the license and certificate system decrypts the encrypted user information to obtain the user information. The target license and certificate corresponding to the user information are searched in the license and certificate database according to the user information, the target license and certificate are encrypted, and the encrypted target license and certificate are returned to the license-using system. The license-using system decrypts the encrypted target license and certificate to obtain the target license and certificate, and displays the target license and certificate to the user. In this way, when the license-using system calls the electronic license and certificate of the certificate holder, all the request parameters and response messages are in encrypted form, ensuring the security of sensitive data during the call of the electronic license and certificate.

[0087] The technical solution of this embodiment receives the user information and data query request sent by the user; generates data request information based on the data query request, user information, and a pre-obtained second asymmetric public key; wherein, the data request information includes encrypted user information, user information signature value, and encrypted first symmetric key; sends the data request information to the data storage system, and receives the encrypted data information generated by the data storage system based on the data request information; wherein, the encrypted data information includes encrypted target data, data signature value, and encrypted second symmetric key; obtains the target data based on the pre-generated first asymmetric private key and the encrypted data information, and displays the target data to the user. The technical solution of this embodiment can ensure that the user information is encrypted during transmission and cannot be intercepted or leaked by obtaining the encrypted user information through the first symmetric key, user information, and second asymmetric public key. By the user information signature value and the encrypted first symmetric key, it can be ensured that the user information is not tampered with during transmission, further protecting user privacy. At the same time, the encrypted target data, data signature value, and encrypted second symmetric key returned by the data storage system can ensure that the target data is encrypted during transmission and cannot be intercepted or leaked.

[0088] Figure 5 FIG. 7 is a schematic diagram of a first structure of a data transmission control device provided by an embodiment of the present invention, and the device is applicable to execute the data transmission control method provided by the embodiment of the present invention. As Figure 5 shown, the device may specifically include:

[0089] A first data receiving module 501, configured to receive the user information and data query request sent by the user, and generate a first symmetric key based on the data query request;

[0090] A data request module 502, configured to generate data request information based on the data query request, the user information, and a pre-obtained second asymmetric public key; wherein, the data request information includes encrypted user information, a user information signature value, and an encrypted first symmetric key;

[0091] A second data receiving module 503, configured to send the data request information to a data storage system, and receive encrypted data information generated by the data storage system based on the data request information; wherein, the encrypted data information includes encrypted target data, a data signature value, and an encrypted second symmetric key;

[0092] A first data generating module 504, configured to obtain target data based on a pre-generated first asymmetric private key and the encrypted data information, and display the target data to the user.

[0093] Optionally, the data request module 502 is specifically configured to: generate a first symmetric key in response to the data query request, and encrypt the user information according to the first symmetric key to obtain the encrypted user information;

[0094] Perform one-way encryption calculation on the encrypted user information to obtain the user information signature value;

[0095] Encrypt the first symmetric key according to the pre-obtained second asymmetric public key to obtain the encrypted first symmetric key.

[0096] Optionally, the first data generating module 504 is specifically configured to: perform one-way encryption calculation on the data signature value to obtain a data verification signature value of the data signature value;

[0097] Match the data signature value and the data verification signature value to obtain a data information matching result; when the data information matching result is a match, decrypt the encrypted second symmetric key according to the first asymmetric private key to obtain the second symmetric key;

[0098] Decrypt the encrypted data information based on the second symmetric key to obtain the target data.

[0099] Optionally, the data request module 502 is specifically configured to: generate a first asymmetric public key and the first asymmetric private key according to a pre-set first asymmetric encryption algorithm, and send the first asymmetric public key to the data storage system;

[0100] Obtain the second asymmetric public key sent by the data storage system; wherein, the second asymmetric public key is generated by the data storage system according to a pre-set second asymmetric encryption algorithm.

[0101] The data transmission control device provided by the embodiments of the present invention can execute the data transmission control method provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects for executing the method. The content not described in detail in this embodiment can be referred to the description in any method embodiment of the present invention.

[0102] Figure 6 FIG. 4 is a second structural schematic diagram of a data transmission control device provided by an embodiment of the present invention, and this device is applicable to execute the data transmission control method provided by the embodiment of the present invention. As Figure 6 shown, this device may specifically include:

[0103] A third data receiving module 601, configured to receive data request information sent by a data request system; wherein, the data request information includes encrypted user information, a user information signature value, and an encrypted first symmetric key;

[0104] A first data determination module 602, configured to determine user information based on a pre-generated second asymmetric private key and the data request information; wherein, the user information is the decrypted encrypted user information;

[0105] A second data determination module 603, configured to determine target data corresponding to the user information in a database for storing non-public data determined in advance;

[0106] A second data generation module 604, configured to generate encrypted data information based on a pre-obtained first asymmetric public key and the target data, and send the encrypted data information to the data request system; wherein, the encrypted data information includes encrypted target data, a data signature value, and an encrypted second symmetric key.

[0107] Optionally, the first data determination module 602 is specifically configured to: perform one-way encryption calculation on the user information signature value to obtain a user verification signature value of the user information signature value;

[0108] Match the user information signature value and the user verification signature value to obtain a user information matching result. When the user information matching result is a pass, decrypt the encrypted first symmetric key according to the second asymmetric private key to obtain a first symmetric key;

[0109] Decrypt the encrypted user information based on the first symmetric key to obtain the user information.

[0110] Optionally, the second data generation module 604 is specifically configured to: generate a second symmetric key, and encrypt the target data according to the second symmetric key to obtain the encrypted target data;

[0111] Perform one-way encryption calculation on the encrypted target data to obtain the data signature value;

[0112] Encrypt the second symmetric key according to the first asymmetric public key to obtain the encrypted second symmetric key.

[0113] The data transmission control device provided by the embodiments of the present invention can execute the data transmission control method provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects for executing the method. The content not described in detail in this embodiment can be referred to the description in any method embodiment of the present invention.

[0114] The embodiments of the present invention also provide a computer program product.

[0115] The various embodiments of the systems and technologies described above in this article can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on a chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: implemented in one or more computer program products, the one or more computer program products can include one or more computer programs, the one or more computer programs can be executed and / or interpreted on a programmable system including at least one programmable processor, the programmable processor can be a dedicated or general programmable processor, and can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.

[0116] Figure 7 It is a schematic structural diagram of an electronic device provided by the embodiments of the present invention. Refer to Figure 7 , Figure 7 The displayed electronic device 12 is only an example and should not bring any limitations to the functions and usage scopes of the embodiments of the present application. As Figure 7 shown, the electronic device 12 is presented in the form of a general computing device. The components of the electronic device 12 can include but are not limited to: one or more processors or processing units 16, a system memory 28, and a bus 18 connecting different system components (including the system memory 28 and the processing unit 16).

[0117] Bus 18 represents one or more of several types of bus architectures, including a memory bus or memory controller, a peripheral bus, an Accelerated Graphics Port, a processor bus, or a local bus using any of a variety of bus architectures. By way of example, such architectures include, but are not limited to, Industry Standard Architecture (ISA) bus, Micro Channel Architecture (MAC) bus, Enhanced ISA bus, Video Electronics Standards Association (VESA) local bus, and Peripheral Component Interconnect (PCI) bus.

[0118] Electronic device 12 typically includes a variety of computer system readable media. These media can be any available media that can be accessed by electronic device 12, including both volatile and nonvolatile media, removable and non-removable media.

[0119] System memory 28 can include computer system readable media in the form of volatile memory, such as random access memory (RAM) 30 and / or cache memory 32. Electronic device 12 can further include other removable / non-removable, volatile / nonvolatile computer system storage media. By way of example only, storage system 34 can be used for reading and writing non-removable, nonvolatile magnetic media ( Figure 7 not shown, and typically referred to as a "hard disk drive"). Although Figure 7 not shown in the figures, a disk drive for reading and writing removable nonvolatile disks (such as a "floppy disk"), and an optical disk drive for reading and writing removable nonvolatile optical disks (such as a CD-ROM, DVD-ROM, or other optical media) can be provided. In these instances, each drive can be connected to bus 18 by one or more data media interfaces. System memory 28 can include at least one program product having a set (e.g., at least one) of program modules that are configured to carry out the functions of embodiments of the present application.

[0120] A program / utility 40 having a set (at least one) of program modules 46 can be stored, for example, in system memory 28, such program modules 46 including, but not limited to, an operating system, one or more application programs, other program modules, and program data, each of which examples or some combination thereof may include an implementation of a network environment. Program modules 46 generally carry out the functions and / or methods of the embodiments described in the present application.

[0121] The electronic device 12 can also communicate with one or more external devices 14 (such as a keyboard, a pointing device, a display 24, etc.), and can also communicate with one or more devices that enable a user to interact with the electronic device 12, and / or communicate with any device that enables the electronic device 12 to communicate with one or more other computing devices (such as a network card, a modem, etc.). Such communication can be carried out through an input / output (I / O) interface 22. In addition, the electronic device 12 can also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through a network adapter 20. As shown in the figure, the network adapter 20 communicates with other modules of the electronic device 12 through a bus 18. It should be understood that although Figure 7 not shown in the figure, other hardware and / or software modules can be used in combination with the electronic device 12, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.

[0122] The processing unit 16 executes various functional applications and data processing by running programs stored in the system memory 28, for example, implementing a data transmission control method provided by an embodiment of the present invention: receiving user information and a data query request sent by a user; generating data request information based on the data query request, the user information, and a pre-acquired second asymmetric public key; wherein, the data request information includes encrypted user information, a user information signature value, and an encrypted first symmetric key; sending the data request information to a data storage system, and receiving encrypted data information generated by the data storage system based on the data request information; wherein, the encrypted data information includes encrypted target data, a data signature value, and an encrypted second symmetric key; obtaining the target data based on a pre-generated first asymmetric private key and the encrypted data information, and presenting the target data to the user.

[0123] An embodiment of the present invention provides a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, it implements a data transmission control method provided by all embodiments of the present invention: receiving user information and a data query request sent by a user; generating data request information based on the data query request, the user information, and a pre-acquired second asymmetric public key; wherein the data request information includes encrypted user information, a user information signature value, and an encrypted first symmetric key; sending the data request information to a data storage system, and receiving encrypted data information generated by the data storage system based on the data request information; wherein the encrypted data information includes encrypted target data, a data signature value, and an encrypted second symmetric key; obtaining the target data based on a pre-generated first asymmetric private key and the encrypted data information, and presenting the target data to the user. The computer-readable medium can be a computer-readable signal medium or a computer-readable storage medium. The computer-readable storage medium can be, for example, but not limited to, an electronic device, apparatus, or device of electricity, magnetism, light, electromagnetic, infrared, or semiconductor, or any combination of the above. More specific examples (non-exhaustive list) of the computer-readable storage medium include: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this document, the computer-readable storage medium can be any tangible medium that contains or stores a program, and the program can be used by or in combination with an instruction execution electronic device, apparatus, or device.

[0124] The computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, and the computer-readable medium can send, propagate, or transmit a program for use by or in combination with an instruction execution electronic device, apparatus, or device.

[0125] The program code contained on the computer-readable medium can be transmitted by any suitable medium, including but not limited to wireless, wire, optical cable, RF, etc., or any suitable combination of the above.

[0126] Computer program code for performing the operations of the present invention may be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., connected through the Internet using an Internet service provider).

[0127] Note that the above is only the preferred embodiment of the present invention and the technical principles applied. Those skilled in the art will understand that the present invention is not limited to the specific embodiments here, and various obvious changes, re-adjustments, and substitutions can be made by those skilled in the art without departing from the protection scope of the present invention. Therefore, although the present invention has been described in more detail through the above embodiments, the present invention is not limited to the above embodiments. Without departing from the concept of the present invention, more other equivalent embodiments may be included, and the scope of the present invention is determined by the scope of the appended claims.

Claims

1. A data transmission control method, characterized in that, Applied to a data request system, the method includes: Receiving user information and a data query request sent by a user; Generating data request information based on the data query request, the user information, and a pre-acquired second asymmetric public key; wherein, the data request information includes encrypted user information, a user information signature value, and an encrypted first symmetric key; including: generating a first symmetric key in response to the data query request, encrypting the user information according to the first symmetric key to obtain the encrypted user information; performing one-way encryption calculation on the encrypted user information to obtain the user information signature value; encrypting the first symmetric key according to the pre-acquired second asymmetric public key to obtain the encrypted first symmetric key; wherein, the second asymmetric public key is generated by the data storage system according to a pre-set second asymmetric encryption algorithm and sent to the data request system; sending the data request information to the data storage system, and receiving encrypted data information generated by the data storage system based on the data request information; wherein, the encrypted data information includes encrypted target data, a data signature value, and an encrypted second symmetric key; the data signature value is obtained by performing one-way encryption calculation on the encrypted target data by the data storage system; Obtaining target data based on a pre-generated first asymmetric private key and the encrypted data information, including: performing one-way encryption calculation on the data signature value to obtain a data verification signature value of the data signature value; matching the data signature value and the data verification signature value to obtain a data information matching result; when the data information matching result is a pass, decrypting the encrypted second symmetric key according to the first asymmetric private key to obtain the second symmetric key; decrypting the encrypted target data based on the second symmetric key to obtain the target data; the first asymmetric private key is generated by the data request system according to a pre-set first asymmetric encryption algorithm; And presenting the target data to the user.

2. The method according to claim 1, wherein Before receiving the user information and the data query request sent by the user, the method further includes: Generating a first asymmetric public key and the first asymmetric private key according to a pre-set first asymmetric encryption algorithm, and sending the first asymmetric public key to the data storage system; Obtaining the second asymmetric public key sent by the data storage system.

3. A data transmission control method, characterized in that, Applied to a data storage system, the method includes: Receiving data request information sent by a data request system; wherein, the data request information includes encrypted user information, a user information signature value, and an encrypted first symmetric key; Determine user information based on a pre-generated second asymmetric private key and the data request information; wherein the user information is the decrypted encrypted user information; including: performing one-way encryption calculation on the user information signature value to obtain a user verification signature value of the user information signature value; matching the user information signature value and the user verification signature value to obtain a user information matching result, and when the user information matching result is a pass, decrypt the encrypted first symmetric key according to the second asymmetric private key to obtain a first symmetric key; decrypt the encrypted user information based on the first symmetric key to obtain the user information; the second asymmetric private key is generated by the data storage system using a second asymmetric encryption algorithm; determine target data corresponding to the user information in a pre-determined database for storing non-public data; Generate encrypted data information based on a pre-obtained first asymmetric public key and the target data, including: generating a second symmetric key, and encrypting the target data according to the second symmetric key to obtain encrypted target data; performing one-way encryption calculation on the encrypted target data to obtain a data signature value; encrypting the second symmetric key according to the first asymmetric public key to obtain the encrypted second symmetric key; the first asymmetric public key is generated by the data request system according to a first asymmetric encryption algorithm; And send the encrypted data information to the data request system; wherein the encrypted data information includes encrypted target data, a data signature value, and an encrypted second symmetric key.

4. A computer program product comprising a computer program, characterized in that, The computer program, when executed by a processor, implements a data transmission control method according to any one of claims 1-3.

5. An electronic device, the electronic device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, it implements a data transmission control method according to any one of claims 1 to 3.

6. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by a processor, it implements a data transmission control method according to any one of claims 1 to 3.

Citation Information

Patent Citations

  • Data transmission method, device and system and storage medium

    CN114726597A

  • Communication method and device based on http protocol, storage medium and electronic equipment

    CN118573666A