Picture transmission method and device
By negotiating keys during image transmission and using the first and second public keys for encryption and decryption, the problem of lack of protection technology in image transmission in comics industry is solved, and efficient and secure image transmission is achieved.
Patent Information
- Application Number
- CN202510444911.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-09
- Publication Date
- 2025-06-24
AI Technical Summary
The comic industry lacks effective asset protection technology during image transmission, resulting in unauthorized access and intercepting comic resources, which harms the interests of creators and platforms.
By transmitting the first public key generated according to the first private key and the second public key generated according to the second private key, key negotiation during the image transmission is realized, so that the target node and the client can obtain the key of the same content, thereby correctly completing the encryption and decryption of the picture.
Improve the efficiency of image transmission, while ensuring the security of image transmission, and preventing unauthorized access and interception.
Smart Images

Figure CN120201131A_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present application relate to the field of information security technology, and in particular, to a method, device, computer device, computer-readable storage medium, and computer program product for picture transmission. Background Art
[0002] With the development of digital technology, the comic industry has become increasingly prosperous under the dissemination of online platforms, and reading comics has also become an important and convenient form of entertainment in people's lives. However, the comic industry lacks effective picture asset protection technology. As a type of digital content, comic works are vulnerable to unauthorized access and the threat of intercepting comic resources during the transmission process. These problems not only involve the resource protection of comic works but also the interests of creators and platforms, causing huge losses to creators and platforms.
[0003] It should be noted that the above content is not necessarily prior art and is not used to limit the patent protection scope of the present application. Summary of the Invention
[0004] Embodiments of the present application provide a method, device, computer device, computer-readable storage medium, and computer program product for picture transmission to solve or alleviate one or more of the above technical problems.
[0005] One aspect of the embodiments of the present application provides a picture transmission method for a client, and the method includes: Obtain a matching first public key and first private key according to a request for a target picture, where the first public key is generated based on the first private key; Send the first public key to the server so that the server returns a target address carrying the first public key and encryption indication information; Request the target picture from a target node according to the target address, so that the target node returns a picture ciphertext; wherein, the picture ciphertext includes an encrypted picture, the encryption indication information, and a second public key; the encrypted picture is obtained by the target node encrypting using the first public key and a second private key; the second public key and the second private key are generated by the target node, and the second public key is generated based on the second private key; Receive the picture ciphertext returned by the target node; Decrypt the encrypted picture according to the encryption indication information, the first private key, and the second public key to obtain the target picture.
[0006] Optionally, sending the first public key to the server so that the server returns a target address carrying the first public key and encryption indication information includes: Generate a picture token corresponding to the target picture; Send the picture token and the first public key to the server, so that when the server verifies that the picture token is valid, it generates and returns the target request address according to the first public key and the encryption indication information.
[0007] Optionally, decrypting the encrypted picture according to the encryption indication information, the first private key and the second public key to obtain the target picture includes: Generate a shared key according to the first private key and the second public key; Determine the encryption algorithm and encryption location according to the encryption indication information; Decrypt the encrypted picture according to the encryption algorithm, the encryption location and the shared key to obtain the target picture.
[0008] Optionally, the picture ciphertext further includes picture information; decrypting the encrypted picture according to the encryption indication information, the first private key and the second public key to obtain the target picture includes: Generate a shared key according to the first private key and the second public key; Generate a derived key corresponding to the shared key according to the shared key and the picture information; Obtain the target picture according to the derived key and the picture ciphertext.
[0009] Optionally, the first private key is a first elliptic curve private key, and the first public key is a first elliptic curve public key generated according to the first elliptic curve private key and a preset base point on a preset elliptic curve; The second private key is a second elliptic curve private key, and the second public key is a second elliptic curve public key generated according to the second elliptic curve private key and the preset base point.
[0010] Another aspect of the embodiments of the present application provides a picture transmission method for an edge function service of a CDN node. The method includes: Receive a picture request sent by a client; Determine encryption indication information, a first public key, and a target picture corresponding to the picture request according to the picture request; wherein, the first public key and the first private key are generated by the client, and the first public key is generated according to the first private key; Generate a second public key and a second private key, and the second public key is generated according to the second private key; Encrypt the target picture according to the first public key, the second private key and the encryption indication information to obtain an encrypted picture corresponding to the target picture; Generate a picture ciphertext according to the second public key, the encrypted picture and the encryption indication information; Return the encrypted image ciphertext to the client, so that the client decrypts the encrypted image according to the second public key, the first private key, and the encryption indication information to obtain the target image.
[0011] Another aspect of the embodiments of the present application provides an image transmission device for a client, and the device includes: A first generation module, which generates a matching first public key and a first private key according to a request for a target image, and the first public key is generated according to the first private key; A sending module, which is used to send the first public key to the server, so that the server returns a target address carrying the first public key and encryption indication information; A request module, which is used to request the target image from a target node according to the target address, so that the target node returns an encrypted image ciphertext; wherein, the encrypted image ciphertext includes an encrypted image, the encryption indication information, and a second public key; the encrypted image is obtained by the target node encrypting with the first public key and a second private key; the second public key and the second private key are generated by the target node, and the second public key is generated according to the second private key; A receiving module, which is used to receive the encrypted image ciphertext returned by the target node; A decryption module, which is used to decrypt the encrypted image according to the encryption indication information, the first private key, and the second public key to obtain the target image.
[0012] Another aspect of the embodiments of the present application provides an image transmission device for an edge function service of a CDN node, and the device includes: A receiving module, which receives an image request sent by a client; A determination module, which is used to determine encryption indication information, a first public key, and a target image corresponding to the image request according to the image request, and the first public key is generated according to the first private key; A first generation module, which is used to generate a second public key and a second private key, and the second public key is generated according to the second private key; An encryption module, which is used to encrypt the target image according to the first public key, the second private key, and the encryption indication information to obtain an encrypted image corresponding to the target image; A second generation module, which is used to generate an encrypted image ciphertext according to the second public key, the encrypted image, and the encryption indication information; A return module, which is used to return the encrypted image ciphertext to the target client, so that the client generates a shared key according to the second public key and the first private key, and decrypts the encrypted image according to the shared key and the encryption indication information to obtain the target image.
[0013] Another aspect of the embodiments of the present application provides a computer device, including: At least one processor; and A memory communicatively connected to the at least one processor; Wherein: the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the method as described above.
[0014] Another aspect of the embodiments of the present application provides a computer-readable storage medium, in which computer instructions are stored, and when the computer instructions are executed by a processor, the method as described above is implemented.
[0015] Another aspect of the embodiments of the present application provides a computer program product, including a computer program, and when the computer program is executed by a processor, the method as described above is implemented.
[0016] The embodiments of the present application adopting the above technical solutions may include the following advantages: By transmitting the first public key generated according to the first private key and the second public key generated according to the second private key, key negotiation in the picture transmission process is realized, so that the target node and the client can obtain keys with the same content, thereby correctly completing the encryption and decryption of the picture, improving the efficiency of picture transmission, and at the same time ensuring the security of picture transmission. Description of the Drawings The drawings exemplarily show the embodiments and form a part of the specification, and are used together with the written description of the specification to explain the exemplary embodiments. The shown embodiments are only for illustrative purposes and do not limit the scope of the claims. In all the drawings, the same reference numerals refer to similar but not necessarily identical elements.
[0017] Figure 1 Schematically shows an operating environment diagram of the picture transmission method according to Embodiment 1 of the present application; Figure 2 Schematically shows a flowchart of the picture transmission method according to Embodiment 1 of the present application; Figure 3 Schematically shows Figure 2 The sub-step flowchart of step S202 in; Figure 4 Schematically shows Figure 2 The sub-step flowchart of step S208 in; Figure 5 Schematically shows Figure 2 Another sub-step flowchart of step S208 in; Figure 6Schematically shows a flowchart of a picture transmission method according to Embodiment 2 of the present application; Figure 7 Schematically shows an exemplary application flowchart according to an embodiment of the present application; Figure 8 Schematically shows a block diagram of a picture transmission device according to Embodiment 3 of the present application; Figure 9 Schematically shows a block diagram of a picture transmission device according to Embodiment 4 of the present application; Figure 10 Schematically shows a schematic diagram of the hardware architecture of a computer device according to Embodiment 5 of the present application; and Figure 11 Schematically shows an application scenario flowchart according to an embodiment of the present application. Detailed implementation manners
[0018] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts shall fall within the protection scope of the present application.
[0019] It should be noted that the descriptions involving "first", "second", etc. in the embodiments of the present application are only for descriptive purposes and cannot be understood as indicating or implying their relative importance or implicitly indicating the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include at least one of such features. In addition, the technical solutions between various embodiments may be combined with each other, but it must be based on the fact that those of ordinary skill in the art can implement them. When the combination of technical solutions appears to be contradictory or unable to be implemented, it should be considered that such a combination of technical solutions does not exist and is not within the protection scope required by the present application.
[0020] In the description of the present application, it should be understood that the numerical labels before the steps do not identify the order of execution of the steps, but are only used to facilitate the description of the present application and to distinguish each step, and thus cannot be understood as a limitation to the present application.
[0021] First, provide the term explanations involved in the present application: Elliptic Curve Cryptography (ECC): An asymmetric encryption algorithm based on the mathematical theory of elliptic curves, which realizes the generation of key pairs and the encryption and decryption processes through point operations on elliptic curves.
[0022] CDN (Content Delivery Network): A network layout that caches website business content in cloud servers around the world through a distributed server layout, allowing users to access it nearby to improve access speed.
[0023] Public-private key pair: A pair of keys used for encryption and authentication in cryptography. The public key can be made public and is used to encrypt data or verify signatures; the private key needs to be kept secret and is used to decrypt data or generate signatures.
[0024] Digital signature: A method of signing electronic documents using encryption technology. The private key is used to encrypt the data to generate a signature, and the recipient decrypts and verifies the signature using the public key.
[0025] Symmetric encryption: An encryption technology that uses the same key to encrypt and decrypt plaintext. During symmetric encryption, the sender uses the key to encrypt the plaintext, generates ciphertext, and sends it to the recipient. After receiving the ciphertext, the recipient uses the same key to decrypt it and recover the original plaintext.
[0026] Asymmetric encryption: An encryption technology that uses a pair of keys, namely the public key and the private key. The public key can be made public and is used to encrypt data; the private key is kept secret by the recipient and is used to decrypt data.
[0027] Initialization Vector (IV): A random or pseudo-random value used in cryptography to enhance encryption security. The IV is used in combination with the key to ensure that the same plaintext generates different ciphertexts in different encryption operations.
[0028] Image token: A unique identifier used to request an image, containing various key information to ensure the legitimacy and security of the request.
[0029] MD5 checksum: A data verification method based on the MD5 algorithm. The MD5 algorithm can convert data of any length into a fixed-length 128-bit digest.
[0030] RSA: An asymmetric encryption algorithm. Based on the mathematical problem of large number factorization, it can generate a pair of keys: one public key for encrypting data and one private key for decrypting.
[0031] ECDHE (Elliptic Curve Diffie-Hellman Ephemeral): A key exchange protocol based on elliptic curve cryptography that allows two communicating parties to securely exchange keys over an insecure channel.
[0032] HKDF (HMAC-based Extract-and-Expand Key Derivation Function): It is a key derivation function based on HMAC that extracts a key from the given key material and expands it into a key of the required length.
[0033] PBKDF2 (Password-Based Key Derivation Function 2): It is a password-based key derivation function that generates a key by combining a password with a salt value and repeating the hashing operation.
[0034] SSL / TLS protocol (Secure Sockets Layer / Transport Layer Security protocol): It is a network security protocol that mainly achieves secure communication in the following aspects: First, it encrypts data using encryption technology; Second, it verifies the identities of both communicating parties through digital certificates and the public key infrastructure (PKI); Finally, it can also provide data integrity protection.
[0035] Second, to facilitate the understanding of the technical solutions provided by the embodiments of the present application by those skilled in the art, the related technologies are described below: In the digital age, the prosperity of the comic industry is inseparable from the dissemination and promotion of online platforms. However, since comic content is usually transmitted on the network in the form of digital pictures, and the comic resource platform lacks effective picture data protection technology, unauthorized personnel can intercept and spread comic resources during the transmission process. This not only disrupts the ecology of the comic market but also seriously dampens the enthusiasm of creators and affects the interests of creators and comic resource platforms. Therefore, exploring effective technical means to protect the secure transmission of comic content has become an urgent problem in the comic industry.
[0036] For this reason, the embodiments of the present application provide a technical solution for picture transmission. In this technical solution, (1) by transmitting the first public key generated according to the first private key and the second public key generated according to the second private key, key negotiation in the picture transmission process is achieved, enabling the target node and the client to obtain keys with the same content, thereby correctly completing the encryption and decryption of pictures, improving the efficiency of picture transmission, and at the same time ensuring the security of picture transmission; (2) deploying an encryption function in the edge function service of the CDN node improves the efficiency of picture transmission; (3) combining various technical means such as synchronous encryption rules and elliptic curve encryption algorithms can build a secure and efficient picture data protection system. See the following for details.
[0037] Finally, for ease of understanding, an exemplary operating environment is provided below.
[0038] Such as Figure 1As shown, the operating environment diagram includes: a server 2, a CDN node 4, and a client 6, where: The server 2 can be composed of multiple computing devices. The multiple computing devices can include virtualized computing instances. The virtualized computing instances can include virtual machines, such as emulations of computer systems, operating systems, servers, etc. The computing devices can load virtual machines based on virtual images and / or other data that define specific software (e.g., operating systems, dedicated applications, servers) for emulation. As the demand for different types of processing services changes, different virtual machines can be loaded and / or terminated on one or more computing devices. A hypervisor can be implemented to manage the use of different virtual machines on the same computing device.
[0039] The server 2 can provide services such as application programs, storage, and distribution of encryption algorithm configurations.
[0040] The server 2 can be configured to communicate with the CDN node 4, the client 6, etc. via a network.
[0041] The CDN node 4 can be configured with edge computing services and is used to provide content distribution services. The CDN node 4 can be configured to: in response to a request for a specific resource (such as a target picture), when the specific resource is local to the CDN node, encrypt it and return the encrypted file; when the specific resource is not local to the CDN node, obtain it from the server 2.
[0042] The client 6 can be configured to send data acquisition requests to the CDN node 4 or the server 2. The viewer terminal can be any type of computer device, such as a smart phone, a tablet device, a laptop computer, a smart TV, a vehicle-mounted terminal, etc. The viewer terminal can be built-in with a browser, a dedicated program, or a player for receiving data and outputting content to the user. The content can include pictures, etc.
[0043] The server 2, the CDN node 4, and the client 6 can be connected via a network. The network can include various network devices, such as routers, switches, multiplexers, hubs, modems, bridges, repeaters, firewalls, and / or proxy devices, etc. The network can include physical links, such as coaxial cable links, twisted pair cable links, fiber optic links, and their combinations and / or analogs. The network can include wireless links, such as cellular links, satellite links, Wi-Fi links, and / or analogs.
[0044] It should be noted that the numbers of the server 2, the CDN node 4, and the client 6 in the figure are only illustrative and are not used to limit the patent protection scope of this application. According to the actual situation, there can be any number of the server 2, the CDN node 4, and the client 6.
[0045] The following takes the CDN node 4 and the client 6 as the execution entities respectively, and introduces the technical solution of this application through multiple embodiments. It should be noted that these embodiments can be implemented in various different forms and should not be construed as being limited only to the embodiments described herein.
[0046] Embodiment 1 The method embodiment of this can be executed in the client. The following takes the client as the single execution entity of this process.
[0047] Figure 2 The flowchart of the picture transmission method according to Embodiment 1 of this application is schematically shown.
[0048] As Figure 2 shown, the picture transmission method may include steps S200 to S208 for the client, where: Step S200, obtain a matching first public key and a first private key according to the request for the target picture, where the first public key is generated according to the first private key; Step S202, send the first public key to the server so that the server returns a target address carrying the first public key and encryption indication information; Step S204, request the target picture from the target node according to the target address, so that the target node returns a picture ciphertext; where the picture ciphertext includes an encrypted picture, the encryption indication information, and a second public key; the encrypted picture is obtained by the target node encrypting with the first public key and a second private key; the second public key and the second private key are generated by the target node, and the second public key is generated according to the second private key; Step S206, receive the picture ciphertext returned by the target node; Step S208, decrypt the encrypted picture according to the encryption indication information, the first private key, and the second public key to obtain the target picture.
[0049] The picture transmission method provided in this embodiment realizes key negotiation in the picture transmission process by transmitting the first public key generated according to the first private key and the second public key generated according to the second private key, so that the target node and the client can obtain keys with the same content, thereby correctly completing the encryption and decryption of the picture, improving the efficiency of picture transmission, and at the same time ensuring the security of picture transmission.
[0050] The following combines Figure 2 to elaborate in detail on each step in steps S200 to S208 and optional other steps.
[0051] Step S200, according to a request for a target image, obtaining a matching first public key and a first private key, wherein the first public key is generated according to the first private key.
[0052] The target image may be a static image, a dynamic image, etc. In some embodiments, the first public key and the first private key may be generated by elliptic curve cryptography (ECC). In other embodiments, the first public key and the first private key may be generated by encryption algorithms such as RSA and ECDHE.
[0053] For example, when the first public key and the first private key are generated by elliptic curve encryption, the first private key may be a random number a, and the first public key may be calculated from the random number a and a point G on a predetermined elliptic curve O.
[0054] The client can generate a new first public key and first private key each time it initiates an image request to the server, or it can periodically update the first public key and first private key used at a preset time interval and cache them in the client. It can also pre-generate a certain number of key pairs when the client is idle to cope with sudden high-concurrency requests and reduce user waiting time.
[0055] In some embodiments, the length of the key (i.e., the first public key and the first private key) generated by the client each time may be pre-defined. In other embodiments, the client may also randomly generate keys of different lengths, or determine the length of the key according to actual conditions (such as the importance of the target image, the attack status of the server or node storing the target image, etc.).
[0056] Step S202 , sending the first public key to the server, so that the server returns a target address carrying the first public key and encryption indication information.
[0057] In some embodiments, the public key can be signed by digital signature technology, and after receiving the public key, the server can verify the digital signature to ensure the integrity of the public key and the reliability of the source. In other embodiments, the public key can also be encrypted using symmetric encryption or asymmetric encryption algorithms before transmission.
[0058] The encryption indication information may include the encryption algorithm version, and may also include picture information used for encryption, time information, or partial random values (such as salt value / random value, additional information, and random initialization vector, etc.). In some embodiments, the composition of the encryption indication information may be fixed. In other embodiments, the server may also select different contents to form the encryption indication information based on factors such as different picture types, user permissions, or network environment. In other embodiments, the server may also add some random values for obfuscation to the encryption indication information according to preset rules to improve the security of the encryption indication information.
[0059] In some embodiments, the target address may include the address of the target node for obtaining the target picture. In other embodiments, the target address may further include some redundant information, such as an alternative node address, so that when the target node has a problem, the client can promptly switch to the alternative node to obtain the target picture.
[0060] By generating a target address carrying the first public key and encryption indication information by the server, the client can transmit the first public key and encryption indication information for encrypting the target picture to the target node when accessing the target node, ensuring the smooth progress of subsequent picture requests and encryption processing.
[0061] As previously mentioned, various methods can be adopted to protect information security during the process of sending the first public key to the server. The following provides an exemplary protection method.
[0062] In an alternative embodiment, as Figure 3 shown, step S202 includes: S300, generating a picture token corresponding to the target picture.
[0063] S302, sending the picture token and the first public key to the server, so that when the server verifies that the picture token is valid, it generates and returns the target address according to the first public key and the encryption indication information.
[0064] The picture token may include information related to the target picture, device information of the client, and network environment information of the client, etc. In some embodiments, the picture token may be generated and saved by the client regularly at a preset time interval based on the static device information of the client. In other embodiments, the picture token may also be dynamically generated by the client according to real-time user behavior or device status.
[0065] In some embodiments, the server can check the integrity and validity of the token. In other embodiments, the server can also perform multi-factor verification in combination with the user's identity authentication information, credibility assessment of the device, etc. When the verification by the server fails or an error is returned, the client can automatically retry, switch to an alternative server, or take other recovery measures.
[0066] In this embodiment, the request from the client to the server is verified by the picture token. Returning the target address only when the picture token verification is valid can improve the security and legitimacy of the client request, help prevent insecure or unqualified clients from obtaining the target address, and thus ensure the security of the target picture.
[0067] Step S204, request the target image from the target node according to the target address, so that the target node returns the encrypted image; wherein, the encrypted image includes an encrypted picture, the encryption indication information, and a second public key; the encrypted picture is obtained by the target node using the first public key and a second private key; the second public key and the second private key are generated by the target node, and the second public key is generated according to the second private key.
[0068] After receiving the target address, the client can also verify the legality and validity of the target address to ensure that it points to the correct target node. Before requesting the target image from the target node, the client can also verify the identity and reliability of the target node.
[0069] In some embodiments, in addition to the target node, the target address may further include multiple backup nodes. At this time, the client can dynamically select the optimal node to obtain the encrypted image according to factors such as the access speed of the target node and multiple backup nodes, and the node occupancy.
[0070] When receiving the client's request, the target node can also perform a legality check on the client's request, such as token verification, md5 verification, and timestamp verification. In some embodiments, the target node can generate the second public key and the second private key through the Elliptic Curve Cryptography (ECC) algorithm. In other embodiments, the target node can also generate the second public key and the second private key through encryption algorithms such as RSA and ECDHE.
[0071] For example, when generating the second public key and the second private key through the Elliptic Curve Cryptography algorithm, the second private key can be a random number b, and the second public key can be calculated from the random number b and a point G on a pre-determined elliptic curve O. The elliptic curve O and the point G can be set by the client and the target node or the server through a secure channel at regular intervals, or can be dynamically determined by the client and transmitted to the target node each time the target image is requested.
[0072] In some embodiments, the target node can obtain the pre-configured encryption algorithm, encryption area location, and encryption area size corresponding to the encryption indication information from the local cache of the target node or the server according to the encryption indication information for encrypting the target image. In other embodiments, the target node can also dynamically adjust the pre-configured encryption area location and encryption area size according to the actual situation.
[0073] In this embodiment, the target node encrypts according to the encryption indication information determined by the server, which can realize the dynamic encryption of the target image, improve the complexity and security of the image encryption process, help prevent illegal acquisition and piracy, and thus protect the security of the target image.
[0074] Step S206 , receive the encrypted image returned by the target node.
[0075] In some embodiments, after receiving the encrypted image, the client can perform integrity verification on the received encrypted image, such as using a hash function (e.g., SHA-256) to verify the received data. In other embodiments, the legitimacy of the second public key can also be verified to ensure that the encrypted image comes from the correct target node.
[0076] In some embodiments, before returning the encrypted image, the target node can perform compression processing on the encrypted image, and the client can perform corresponding decompression operations when receiving the compressed encrypted image. In other embodiments, the client can also perform decoding processing on the encrypted image encoded before transmission to restore the original encrypted data.
[0077] Step S208 , decrypt the encrypted image according to the encryption indication information, the first private key, and the second public key to obtain the target image.
[0078] In some embodiments, multi-threading technology can be used to decrypt different regions of the encrypted image simultaneously. For example, the encrypted image can be divided into multiple small blocks, and each thread is responsible for decrypting a part of it.
[0079] In other embodiments, the client can also perform security detection on the running environment before decryption, such as whether there is malware or virus, whether it is connected to an insecure network, etc. When decrypting, a hash algorithm can also be used to calculate the check value to perform integrity verification on the data of the encrypted image.
[0080] The encrypted image can also include some random values used to obfuscate the encrypted information. Before decryption, the client can remove this part of the random values in the encrypted image according to the pre-negotiated rules to correctly identify the encryption indication information, the second public key, and the encrypted image, etc.
[0081] After decrypting to obtain the target image, the client can render and display the target image on the corresponding interface, and can also cache the target image in the local cache of the client.
[0082] In this embodiment, the client uses the first private key and the second public key to decrypt the encrypted image encrypted by the target node using the first public key and the second private key. Since the first public key is generated based on the first private key and the second private key is generated based on the second public key, the components of the keys used for encryption and decryption are the same, ensuring that only the client with the correct first private key and second public key can decrypt and view the target image, protecting the security and privacy of the target image.
[0083] As described above, during the decryption process by the client, various methods can be adopted to enhance the security of the decryption process. The following provides several exemplary methods.
[0084] Method 1: As Figure 4 shown, step S208 includes: S400, generating a shared key based on the first private key and the second public key.
[0085] S402, determining the encryption algorithm and the encryption location according to the encryption indication information.
[0086] S404, decrypting the encrypted picture according to the encryption algorithm, the encryption location, and the shared key to obtain the target picture.
[0087] Algorithms such as the Elliptic Curve Cryptography (ECC) and ECDHE can be used to calculate the shared key based on the first private key and the second public key. After generating the shared key, the correctness and security of the shared key can be confirmed by verifying whether the shared key satisfies specific mathematical properties and other means.
[0088] The client can cache the generated shared key locally and clear the shared key in the cache according to a preset cleaning period or rule. The encryption algorithm can be a single algorithm used alone or a combination of multiple algorithms.
[0089] In some embodiments, the client can directly query the cached encryption algorithm and encryption location from the relevant configuration table cached locally by the client according to the encryption indication information. In other embodiments, the client can also use the encryption indication information to query the service side for the latest encryption algorithm and encryption location.
[0090] In this embodiment, decrypting according to the encryption algorithm and encryption location corresponding to the encryption indication information can accurately decrypt the received encrypted picture to obtain the target picture, improving the correctness of the decryption process. At the same time, encrypting and decrypting the target picture according to the regional location can improve the efficiency of the picture transmission method.
[0091] Method 2: The picture ciphertext further includes picture information. As Figure 5 shown, step S208 includes: S500, generating a shared key based on the first private key and the second public key.
[0092] S502, generating a derived key corresponding to the shared key according to the shared key and the picture information.
[0093] S504, obtaining the target picture according to the derived key and the picture ciphertext.
[0094] The picture information may include the size, type, importance of the picture, as well as the picture number or file name, etc. The derivation function used to generate the derived key may be a combination of one or more of HKDF, PBKDF2, etc.
[0095] In some embodiments, the derivation function can be dynamically selected according to parameters such as the size of the picture, and the length, iteration times, etc. of the derived key can be adjusted. In other embodiments, after the derived key is generated, the integrity of the generated derived key can be verified by calculating the hash value of the derived key, etc.
[0096] It should be noted that in addition to the picture information, a salt value (i.e., a random value) and additional information generated according to the picture request time, picture encryption time, etc. can also be added according to the actual situation, and they are jointly used to generate the derived key.
[0097] In this embodiment, obtaining the target picture by using the derived key generated according to the picture information can increase the information density in the derived key, thereby increasing the complexity of the encryption and decryption processes, enabling the client to decrypt the encrypted picture more securely, and improving the security of the picture data.
[0098] As mentioned above, the public-private key pair (such as the first public key and the first private key) used in this application can have various type settings. The following provides an exemplary type setting.
[0099] In an alternative embodiment, the first private key is a first elliptic curve private key, and the first public key is a first elliptic curve public key generated according to the first elliptic curve private key and a preset base point on a preset elliptic curve; the second private key is a second elliptic curve private key, and the second public key is a second elliptic curve public key generated according to the second elliptic curve private key and the preset base point.
[0100] For example, the first elliptic curve private key can be a random value a generated by the client, and the preset elliptic curve can be O. The client can determine a base point G on the preset elliptic curve O, and according to the elliptic curve encryption algorithm, calculate the first elliptic curve public key K = aG by using the base point G and the random value a; The second elliptic curve private key can be a random value b generated by the target node, then the target node can calculate the second elliptic curve public key C = bG by using the base point G and the random value b according to the elliptic curve encryption algorithm; Then during the picture transmission process, the key for encrypting the target picture with the combination of the first public key and the second private key can be Key1 = K × b = (aG) × b = abG, and the key for decrypting the target picture with the combination of the second public key and the first private key can be Key2 = C × a = (bG) × a = abG, that is, Key1 = Key2, so that the encryption and decryption processes can be correctly implemented.
[0101] It should be noted that the above calculation process is only an exemplary calculation process. In specific implementation, other information can also be added to the above various keys, or other calculation methods can be used to calculate keys with other components or forms of expression.
[0102] In some embodiments, the preset elliptic curve and the preset base point can be negotiated by the client and the target node through a secure channel regularly. In other embodiments, it can also be carried by the client in a picture request or other data when generating a new first elliptic curve public key and a first elliptic curve private key and sent to the target node.
[0103] The inventor of the present invention found that the point calculation on the elliptic curve has unidirectionality. According to the base point on the elliptic curve and the elliptic curve private key, the elliptic curve public key can be successfully calculated. However, according to the elliptic curve public key, even if the base point is known, it is very difficult to calculate the corresponding elliptic curve private key.
[0104] In view of this, in this embodiment, using the elliptic curve public-private key pair (that is, the elliptic curve public key and the elliptic curve private key) for picture encryption and decryption can improve the security of the picture transmission process, contribute to improving the efficiency of picture transmission and protecting the security of picture information.
[0105] Embodiment 2 The method embodiment of the present invention can be executed in the edge function service of the CDN node. Hereinafter, the CDN node is used as the single execution subject of this process. It should be noted that the technical details and technical effects in this embodiment can refer to Embodiment 1.
[0106] Figure 6 Schematically shows a flowchart of the picture transmission method according to Embodiment 2 of the present application.
[0107] As Figure 6 shown, the picture transmission method may include steps S600 to S610, which are used in the edge function service of the CDN node, where: S600, receiving a picture request sent by the client; S602, determining encryption indication information and a first public key according to the picture request, and a target picture corresponding to the picture request; wherein, the first public key and the first private key are generated by the client, and the first public key is generated according to the first private key; S604, generating a second public key and a second private key, and the second public key is generated according to the second private key; S606, encrypting the target picture according to the first public key, the second private key and the encryption indication information to obtain an encrypted picture corresponding to the target picture; S608, generating a picture ciphertext according to the second public key, the encrypted picture and the encryption indication information; S610 returns the encrypted image ciphertext to the client, so that the client decrypts the encrypted image according to the second public key, the first private key, and the encryption indication information to obtain the target image.
[0108] After receiving a picture request from the client, the CDN node can also perform a legality check on the picture request from the client, such as token check, md5 check, timestamp check, etc.
[0109] In some embodiments, the target node may generate a second public key and a second private key through the Elliptic Curve Cryptography (ECC). In other embodiments, the target node may also generate a second public key and a second private key through encryption algorithms such as RSA and ECDHE.
[0110] For example, when generating a second public key and a second private key through the Elliptic Curve Cryptography, the second private key may be a random number b, and the second public key may be calculated from the random number b and a point G on a predetermined elliptic curve O. The elliptic curve O and the point G may be set by the client and the target node or the server through a secure channel at regular intervals, or may be dynamically determined by the client each time it requests a target picture and transmitted to the target node.
[0111] In some embodiments, the target node may obtain, from the local cache of the target node or the server according to the encryption indication information, the pre-configured encryption algorithm, encryption area location, encryption area size, etc. corresponding to the encryption indication information for encrypting the target picture. In other embodiments, the target node may also dynamically adjust the pre-configured encryption area location, encryption area size, etc. according to the actual situation.
[0112] The encryption rules (i.e., the encryption algorithm, encryption area location, encryption area size, etc. corresponding to the encryption indication information) stored in the node cache of the target node may be negotiated regularly by the target node and the server through a secure channel (such as a secure channel based on the SSL / TLS protocol).
[0113] In this embodiment, an encryption function is deployed in the edge function service of the CDN node, and through key negotiation, the CDN node and the client can obtain keys with the same content, improving the efficiency of picture transmission while ensuring the security of picture transmission. At the same time, by combining various technical means such as synchronous encryption rules and Elliptic Curve Cryptography, a secure and efficient picture data protection system can be constructed.
[0114] To make the present application easier to understand, the following is combined with Figure 7 and Figure 11 An exemplary application is provided. Wherein: S11, User A clicks on a comic (i.e., the target image) on client 6; S12, Client 6 obtains the client private key a (i.e., the first elliptic curve private key) cached locally and the client public key K (i.e., the first elliptic curve public key) generated based on the client private key, where K = aG and G is a base point on the elliptic curve O negotiated in advance with CDN node 4; S13, Client 6 sends the M1 parameter containing the elliptic curve public key K and the image token imageToken corresponding to the comic to server 2; S14, Server 2 checks the legality and integrity of the M1 parameter and the image token imageToken; S15, Server 2 generates and returns an image request address (i.e., the target address) for requesting the image. The image request address includes a cpx parameter carrying the M1 parameter, salt value salt, random initialization vector iv, and other additional information info; S16, Client 6 accesses the corresponding CDN node 4 (i.e., the target node) according to the image request address returned by the server to request the comic file; S17, CDN node 4 verifies the legality of the image request from client 6; S18, After passing the verification, CDN node 4 queries the corresponding encryption configuration information from the node cache according to the encryption algorithm version EncryptVersion parsed from the image request address, including the encryption area size EncryptSize, encryption algorithm EncryptMethod, etc.; S19, CDN node 4 generates a CDN private key b (i.e., the second elliptic curve private key) and generates a CDN public key C = bG (i.e., the second elliptic curve public key) based on a base point G on the elliptic curve O negotiated in advance; S20, CDN node 4 generates a shared key S = bK = b(aG) = abG based on the CDN private key b and the client public key K; S21, CDN node 4 obtains a symmetric key (i.e., the derived key) through a derivation function based on the shared key S, salt value salt, and additional information info; S22, CDN node 4 encrypts the comic image obtained from the node cache using the symmetric key according to the queried encryption configuration information; S23, CDN node 4 combines the encrypted comic image (i.e., the encrypted image), encryption algorithm version EncryptVersion, and CDN public key C to generate an encrypted file (i.e., the image ciphertext); S24, CDN node 4 sends the encrypted file back to client 6; S25, the client 6 parses the encrypted comic pictures, the encryption algorithm version EncryptVersion, the CDN public key C, etc. from the encrypted file, and removes some random values used to obfuscate the data; S26, the client 6 generates a shared key S = aC = a(bG) = abG according to the CDN public key C and the client private key a; S27, the client 6 obtains a symmetric key through a derivation function according to the shared key S, the salt value salt, and the additional information info; S28, the client 6 decrypts the obtained encrypted comic pictures using the symmetric key according to the queried encryption configuration information to obtain the decrypted comic pictures; S29, the client 6 displays the decrypted comic pictures.
[0115] Embodiment III Figure 8 The block diagram of the picture transmission device according to Embodiment III of the present application is schematically shown. This device is applied to the client. This device can be divided into one or more program modules. One or more program modules are stored in the storage medium and are executed by one or more processors to complete the embodiments of the present application. The program modules referred to in the embodiments of the present application refer to a series of computer program instruction segments that can complete specific functions. The following description will specifically introduce the functions of each program module in this embodiment. As Figure 8 shown, the device 1000 may include: a first generation module 1100, a sending module 1200, a request module 1300, a receiving module 1400, and a decryption module 1500, where: The first generation module 1100 generates a matching first public key and a first private key according to the request for the target picture, and the first public key is generated according to the first private key; The sending module 1200 is used to send the first public key to the server so that the server returns a target address carrying the first public key and encryption indication information; The request module 1300 is used to request the target picture from the target node according to the target address so that the target node returns the picture ciphertext; wherein, the picture ciphertext includes an encrypted picture, the encryption indication information, and a second public key; the encrypted picture is obtained by the target node encrypting using the first public key and a second private key; the second public key and the second private key are generated by the target node, and the second public key is generated according to the second private key; The receiving module 1400 is used to receive the picture ciphertext returned by the target node; The decryption module 1500 is used to decrypt the encrypted picture according to the encryption indication information, the first private key, and the second public key to obtain the target picture.
[0116] As an optional embodiment, the sending module 1200 is further configured to: Generate a picture token corresponding to the target picture; Send the picture token and the first public key to the server, so that the server, when verifying that the picture token is valid, generates and returns the target request address according to the first public key and the encryption indication information.
[0117] As an optional embodiment, the decryption module 1500 is further configured to: Generate a shared key according to the first private key and the second public key; Determine the encryption algorithm and the encryption position according to the encryption indication information; Decrypt the encrypted picture according to the encryption algorithm, the encryption position and the shared key to obtain the target picture.
[0118] As an optional embodiment, the picture ciphertext further includes picture information, and the decryption module 1500 is further configured to: Generate a shared key according to the first private key and the second public key; Generate a derived key corresponding to the shared key according to the shared key and the picture information; Obtain the target picture according to the derived key and the picture ciphertext.
[0119] As an optional embodiment, the first private key is a first elliptic curve private key, and the first public key is a first elliptic curve public key generated according to the first elliptic curve private key and a preset base point on a preset elliptic curve; The second private key is a second elliptic curve private key, and the second public key is a second elliptic curve public key generated according to the second elliptic curve private key and the preset base point.
[0120] Embodiment 4 Figure 9 Schematically shows a block diagram of a picture transmission device according to Embodiment 4 of the present application. The device is applied to an edge function service of a CDN node. The device can be divided into one or more program modules. One or more program modules are stored in a storage medium and executed by one or more processors to complete the embodiments of the present application. The program modules referred to in the embodiments of the present application refer to a series of computer program instruction segments that can complete specific functions. The following description will specifically introduce the functions of each program module in this embodiment. As Figure 9 shown, the device 2000 may include: a receiving module 2100, a determining module 2200, a first generating module 2300, an encrypting module 2400, a second generating module 2500, and a returning module 2600, where: A receiving module 2100 that receives a picture request sent by a client; A determining module 2200 that is configured to determine encryption indication information and a first public key according to the picture request, and a target picture corresponding to the picture request, where the first public key is generated according to the first private key; A first generating module 2300 that generates a second public key and a second private key, where the second public key is generated according to the second private key; An encrypting module 2400 that encrypts the target picture according to the first public key, the second private key, and the encryption indication information to obtain an encrypted picture corresponding to the target picture; A second generating module 2500 that generates a picture ciphertext according to the second public key, the encrypted picture, and the encryption indication information; A returning module 2600 that returns the picture ciphertext to the target client, so that the client generates the shared key according to the second public key and the first private key, and decrypts the encrypted picture according to the shared key and the encryption indication information to obtain the target picture.
[0121] Embodiment 5 Figure 10 Schematically shows a hardware architecture diagram of a computer device 10000 suitable for implementing a picture transmission method according to Embodiment 5 of the present application. In some embodiments, the computer device 10000 may be a terminal device such as a smart phone, a wearable device, a tablet computer, a personal computer, a vehicle-mounted terminal, a game console, a virtual device, a workbench, a digital assistant, a set-top box, a robot, etc. In other embodiments, the computer device 10000 may be a rack server, a blade server, a tower server, or a cabinet server (including an independent server or a server cluster composed of multiple servers), etc. As Figure 10 shown, the computer device 10000 includes, but is not limited to: a memory 10010, a processor 10020, and a network interface 10030 that can be communicatively linked to each other through a system bus. Among them: The memory 10010 includes at least one type of computer-readable storage medium. The readable storage medium includes flash memory, hard disk, multimedia card, card-type memory (such as SD or DX memory), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, magnetic disk, optical disc, etc. In some embodiments, the memory 10010 may be an internal storage module of the computer device 10000, such as the hard disk or memory of the computer device 10000. In other embodiments, the memory 10010 may also be an external storage device of the computer device 10000, such as a plug-in hard disk, Smart Media Card (SMC), Secure Digital (SD) card, Flash Card, etc. equipped on the computer device 10000. Of course, the memory 10010 may also include both the internal storage module and the external storage device of the computer device 10000. In this embodiment, the memory 10010 is generally used to store the operating system and various application software installed on the computer device 10000, such as the program code of the picture transmission method. In addition, the memory 10010 can also be used to temporarily store various types of data that have been output or will be output.
[0122] In some embodiments, the processor 10020 may be a central processing unit (CPU), controller, microcontroller, microprocessor, or other chip. The processor 10020 is generally used to control the overall operation of the computer device 10000, such as performing control and processing related to data interaction or communication with the computer device 10000. In this embodiment, the processor 10020 is used to run the program code stored in the memory 10010 or process data.
[0123] The network interface 10030 may include a wireless network interface or a wired network interface, which is generally used to establish a communication link between the computer device 10000 and other computer devices. For example, the network interface 10030 is used to connect the computer device 10000 to an external terminal via a network, and establish a data transmission channel and a communication link between the computer device 10000 and the external terminal. The network may be a wireless or wired network such as an enterprise intranet (Intranet), the Internet, Global System of Mobile communication (GSM for short), Wideband Code Division Multiple Access (WCDMA for short), 4G network, 5G network, Bluetooth, Wi-Fi, etc.
[0124] It should be noted that Figure 10 Only the computer device with components 10010 - 10030 is shown, but it should be understood that it is not required to implement all the shown components, and more or fewer components may be implemented alternatively.
[0125] In this embodiment, the picture transmission method stored in the memory 10010 may also be divided into one or more program modules and executed by one or more processors (such as the processor 10020) to complete the embodiments of the present application.
[0126] Embodiment Six The embodiment of the present application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the picture transmission method in the embodiment are implemented.
[0127] In this embodiment, the computer-readable storage medium includes flash memory, hard disks, multimedia cards, card-type memories (e.g., SD or DX memories, etc.), random access memories (RAM), static random access memories (SRAM), read-only memories (ROM), electrically erasable programmable read-only memories (EEPROM), programmable read-only memories (PROM), magnetic memories, magnetic disks, optical disks, etc. In some embodiments, the computer-readable storage medium may be an internal storage unit of a computer device, such as the hard disk or memory of the computer device. In other embodiments, the computer-readable storage medium may also be an external storage device of the computer device, such as a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, etc., equipped on the computer device. Of course, the computer-readable storage medium may also include both the internal storage unit and the external storage device of the computer device. In this embodiment, the computer-readable storage medium is generally used to store the operating system installed on the computer device and various application software, such as the program code of the picture transmission method in the embodiment. In addition, the computer-readable storage medium may also be used to temporarily store various data that have been output or will be output.
[0128] Embodiment Seven The embodiment of the present application further provides a computer program product, including a computer program, which when executed by a processor implements the method in the above embodiment.
[0129] Obviously, those skilled in the art should understand that the above-mentioned modules or steps of the embodiments of the present application can be implemented by a general-purpose computer device. They can be concentrated on a single computer device or distributed on a network composed of multiple computer devices. Optionally, they can be implemented by program codes executable by the computer device. Thus, they can be stored in a storage device and executed by the computer device. And in some cases, the steps shown or described can be executed in a different order from here, or they can be separately made into individual integrated circuit modules, or multiple modules or steps among them can be made into a single integrated circuit module to implement. In this way, the embodiments of the present application are not limited to any specific combination of hardware and software.
[0130] It should be noted that the above are only the preferred embodiments of the present application, and do not limit the patent protection scope of the present application. Any equivalent structure or equivalent process transformation made by using the content of the specification and drawings of the present application, or directly or indirectly applied in other related technical fields, shall be equally included in the patent protection scope of the present application.
Claims
1. A method for transmitting an image, characterized in that: For a client, the method comprises: According to the request for the target image, obtain a matching first public key and a first private key, where the first public key is generated according to the first private key; Sending the first public key to the server, so that the server returns a target address carrying the first public key and encryption indication information; According to the target address, request the target image from the target node, so that the target node returns the image ciphertext; wherein the image ciphertext includes the encrypted image, the encryption indication information and the second public key; the encrypted image is encrypted by the target node using the first public key and the second private key; the second public key and the second private key are generated by the target node, and the second public key is generated according to the second private key; Receive the image ciphertext returned by the target node; The encrypted picture is decrypted according to the encryption indication information, the first private key and the second public key to obtain the target picture.
2. The method according to claim 1, characterized in that: Sending the first public key to the server so that the server returns a target address carrying the first public key and encryption indication information includes: Generate a picture token corresponding to the target picture; The image token and the first public key are sent to a server, so that the server generates and returns the target request address according to the first public key and the encryption indication information when verifying that the image token is valid.
3. The method according to claim 1, characterized in that Decrypting the encrypted picture according to the encryption indication information, the first private key, and the second public key to obtain the target picture includes: Generate a shared key according to the first private key and the second public key; Determine an encryption algorithm and an encryption position according to the encryption indication information; The encrypted picture is decrypted according to the encryption algorithm, the encryption position and the shared key to obtain the target picture.
4. The method according to claim 1, characterized in that: The picture ciphertext also includes picture information; decrypting the encrypted picture according to the encryption indication information, the first private key and the second public key to obtain the target picture, including: Generate a shared key according to the first private key and the second public key; Generate a derived key corresponding to the shared key according to the shared key and the image information; The target image is obtained according to the derived key and the image ciphertext.
5. The method according to any one of claims 1 to 4, characterized in that: The first private key is a first elliptic curve private key, and the first public key is a first elliptic curve public key generated according to the first elliptic curve private key and a preset base point on a preset elliptic curve; The second private key is a second elliptic curve private key, and the second public key is a second elliptic curve public key generated according to the second elliptic curve private key and the preset base point.
6. A method for encrypting and decrypting a picture, characterized in that: In an edge function service for a CDN node, the method includes: Receive image requests from clients; Determine encryption indication information and a first public key, and a target image corresponding to the image request according to the image request; wherein the first public key and the first private key are generated by the client, and the first public key is generated according to the first private key; Generate a second public key and a second private key, wherein the second public key is generated according to the second private key; Encrypting the target image according to the first public key, the second private key and the encryption indication information to obtain an encrypted image corresponding to the target image; Generate a picture ciphertext according to the second public key, the encrypted picture and the encryption indication information; The ciphertext of the picture is returned to the client, so that the client decrypts the encrypted picture according to the second public key, the first private key and the encryption indication information to obtain the target picture.
7. A picture transmission device, characterized in that: For a client, the device comprises: An acquisition module, which acquires a matching first public key and a first private key according to a request for a target image, wherein the first public key is generated according to the first private key; A sending module, used to send the first public key to a server, so that the server returns a target address carrying the first public key and encryption indication information; A request module, configured to request the target image from the target node according to the target address, so that the target node returns the image ciphertext; wherein the image ciphertext includes the encrypted image, the encryption indication information and the second public key; the encrypted image is encrypted by the target node using the first public key and the second private key; the second public key and the second private key are generated by the target node, and the second public key is generated according to the second private key; A receiving module, used to receive the image ciphertext returned by the target node; A decryption module is used to decrypt the encrypted picture according to the encryption indication information, the first private key and the second public key to obtain the target picture.
8. A picture transmission device, characterized in that: In the edge function service of a CDN node, the device comprises: Receiving module, receiving image requests sent by the client; a determination module, configured to determine encryption indication information and a first public key, and a target image corresponding to the image request according to the image request; wherein the first public key and the first private key are generated by the client, and the first public key is generated according to the first private key; A first generating module, used to generate a second public key and a second private key, wherein the second public key is generated according to the second private key; an encryption module, configured to encrypt the target image according to the first public key, the second private key and the encryption indication information to obtain an encrypted image corresponding to the target image; A second generating module, used to generate a picture ciphertext according to the second public key, the encrypted picture and the encryption indication information; A returning module is used to return the picture ciphertext to the client, so that the client decrypts the encrypted picture according to the second public key, the first private key and the encryption indication information to obtain the target picture.
9. A computer device, characterized in that: include: at least one processor; and a memory communicatively coupled to the at least one processor; wherein: The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1 to 6.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and when the computer instructions are executed by a processor, the method according to any one of claims 1 to 6 is implemented.
11. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.