Communication data leakage prevention method and device, equipment and storage medium

By generating key pairs locally on mobile terminal devices and using symmetric keys and signature public keys for data decryption and permission verification, the difficulty in deploying central nodes for multi-point communication in individual user scenarios is solved, and efficient and secure point-to-point data transmission is achieved.

CN120238296APending Publication Date: 2025-07-01CHENGDU TD TECH LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311872923.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-29
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

The existing inter-point data communication methods cannot effectively deploy central nodes and build a complete account system in the personal user scenario, resulting in difficulty in data communication, especially when the central node is inaccessible.

Method used

By generating signature key pairs and encryption key pairs locally on the mobile terminal device, and using symmetric keys and signature public keys for data decryption and permission verification, point-to-point encrypted communication is realized, avoiding dependence on central nodes.

Benefits of technology

Multi-point communication in individual user scenarios is realized, communication efficiency and security are improved, communication costs are reduced, information management of communication objects is simplified, and user experience is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120238296A_ABST
    Figure CN120238296A_ABST
Patent Text Reader

Abstract

The invention provides a communication data leakage prevention method and device, equipment and a storage medium. The method comprises the following steps: after receiving an encrypted data packet, obtaining a first decryption private key; based on the first decryption private key, decrypting the encrypted additional data in the encrypted data packet to obtain symmetric key information contained in the additional data and user identification information contained in the additional data; based on the symmetric key information, decrypting the encrypted to-be-received data to obtain the to-be-received data; obtaining a first signature public key based on the user identification information, and decrypting the encrypted permission information contained in the additional data based on the first signature public key to obtain the permission information; and enabling the data receiver to receive and use the to-be-received data based on the permission information. According to the method provided by the invention, key exchange can be realized through near-field interaction, so that data leakage prevention of point-to-point communication between users is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technologies, and in particular, to a method, device, equipment, and storage medium for preventing communication data leakage. Background Art

[0002] Existing data leakage prevention methods between multiple points mainly establish a central node between multiple points and create a complete account system for each user who needs to perform data communication between multiple points. Through the account, identity verification is performed, and then data transfer between specific objects is realized, achieving data leakage prevention.

[0003] However, this data leakage prevention method requires the deployment of an additional central node. In the personal user scenario, there is no unified organization or group to create a central node for personal users, nor can a unified account system be established. In addition, in the above implementation, the user needs to communicate with the central node. In the case where the central node cannot be accessed, data communication cannot be achieved. Summary of the Invention

[0004] This application provides a method, device, equipment, and storage medium for preventing communication data leakage, aiming to solve the problem that the existing data communication method between multiple points cannot effectively deploy a central node and construct a complete account system in the personal user scenario, which is likely to affect the user's data communication.

[0005] In a first aspect, this application provides a method for preventing communication data leakage, including:

[0006] After receiving an encrypted data packet, obtain a first decryption private key; wherein, the encrypted data packet includes encrypted data to be received and encrypted additional data; the encrypted data to be received represents the data obtained by encrypting the data to be received based on symmetric key information; the encrypted additional data represents the data obtained by encrypting the additional data based on a first encryption public key; the first encryption public key and the first decryption private key are the encryption key pair of the data receiver; the first encryption public key represents the encryption public key pre-stored in the data sender;

[0007] Based on the first decryption private key, decrypt the encrypted additional data in the encrypted data packet to obtain the symmetric key information included in the additional data and the user identification information included in the additional data; wherein, the user identification information is used to identify the data sender;

[0008] Based on the symmetric key information, decrypt the encrypted data to be received to obtain the data to be received; and based on the user identification information, obtain the first signature public key, and decrypt the encrypted permission information included in the additional data based on the first signature public key to obtain the permission information; wherein, the encrypted permission information is the data obtained by encrypting the permission information based on the first signature private key; the first signature public key and the first signature private key are the signature key pair of the data sender; the first signature public key represents the signature public key pre-stored in the data receiver;

[0009] Based on the permission information, enable the data receiver to receive and use the data to be received.

[0010] In one example, before receiving the encrypted data packet, the method further includes:

[0011] In response to the start instruction of the data leakage prevention function, generate a signature key pair, an encryption key pair and user identification information that match the user of the current mobile terminal device; wherein, the user of the current mobile terminal device represents the data receiver or the data sender.

[0012] In one example, before receiving the encrypted data packet, the method further includes:

[0013] In response to the friend addition instruction, obtain the user identification information corresponding to the friend to be added and the public key information corresponding to the friend to be added; and add the friend to be added to the address book of the user of the current mobile terminal device; wherein, the friend to be added represents the user who needs to communicate with the user of the current mobile terminal device; the public key information includes the public key in the signature key pair and the public key in the encryption key pair;

[0014] Send the user identification information corresponding to the user of the current mobile terminal device and the public key information corresponding to the user of the current mobile terminal device to the friend to be added.

[0015] In one example, before obtaining the user identification information corresponding to the friend to be added and the public key information corresponding to the friend to be added after responding to the friend addition instruction, the method further includes:

[0016] Establish a data exchange channel between the friend to be added and the user of the current mobile terminal device through near-field wireless communication technology.

[0017] In one example, the step of adding the friend to be added to the address book of the user of the current mobile terminal device includes:

[0018] Based on the user identification information corresponding to the friend to be added, create a new communication business card in the address book corresponding to the user of the current mobile terminal device;

[0019] Store the public key information of the friend to be added, and establish an association relationship between the public key information and the communication business card, so as to obtain the public key information based on the communication business card.

[0020] In one example, after receiving the encrypted data packet, the method further includes:

[0021] Display an identity verification interface and verify the identity information of the data recipient;

[0022] After the identity information of the data recipient is verified, obtain the first decryption private key.

[0023] In one example, the method further includes:

[0024] After detecting that the mobile terminal device of the current user has been replaced, generate an updated signature key pair and an updated encryption key pair that match the current user based on the replaced mobile terminal device;

[0025] Read the address book of the current user, and encrypt the public key in the updated signature key pair and the public key in the updated encryption key pair based on the public keys in the encryption key pairs corresponding to each friend in the address book of the current user, to obtain the encrypted updated public key information;

[0026] Broadcast the encrypted updated public key information to each friend in the address book of the current user, so that each friend updates the public key information of the current user.

[0027] In a second aspect, the present application provides a communication data anti-leakage device, including:

[0028] An acquisition unit, configured to obtain a first decryption private key after receiving an encrypted data packet; wherein, the encrypted data packet includes encrypted data to be received and encrypted additional data; the encrypted data to be received represents data obtained by encrypting the data to be received based on symmetric key information; the encrypted additional data represents data obtained by encrypting the additional data based on a first encryption public key; the first encryption public key and the first decryption private key are an encryption key pair of the data recipient; the first encryption public key represents a pre-stored encryption public key of the data sender;

[0029] A first decryption unit, configured to perform decryption processing on the encrypted additional data in the encrypted data packet based on the first decryption private key, to obtain the symmetric key information included in the additional data and the user identification information included in the additional data; wherein the user identification information is used to identify the data sender.

[0030] A second decryption unit, configured to perform decryption processing on the encrypted data to be received based on the symmetric key information, to obtain the data to be received; and obtain a first signature public key based on the user identification information, so as to perform decryption processing on the encrypted permission information included in the additional data based on the first signature public key, to obtain permission information; wherein the encrypted permission information is data obtained by encrypting the permission information based on a first signature private key; the first signature public key and the first signature private key are a signature key pair of the data sender; the first signature public key represents the signature public key pre-stored in the data receiver.

[0031] A receiving unit, configured to enable the data receiver to receive and use the data to be received based on the permission information.

[0032] In one example, the apparatus further includes:

[0033] An initialization module, configured to generate a signature key pair, an encryption key pair, and user identification information that match the user of the current mobile terminal device in response to a start instruction for a data leakage prevention function before receiving an encrypted data packet; wherein the user of the current mobile terminal device represents the data receiver or the data sender.

[0034] In one example, the initialization module is further configured to:

[0035] Before receiving an encrypted data packet, in response to a friend addition instruction, obtain the user identification information corresponding to the friend to be added and the public key information corresponding to the friend to be added; and add the friend to be added to the address book of the user of the current mobile terminal device; wherein the friend to be added represents a user who needs to perform data communication with the user of the current mobile terminal device; the public key information includes the public key in the signature key pair and the public key in the encryption key pair.

[0036] Send the user identification information corresponding to the user of the current mobile terminal device and the public key information corresponding to the user of the current mobile terminal device to the friend to be added.

[0037] In one example, the initialization module is further configured to:

[0038] After receiving a friend addition instruction and before obtaining the user identification information corresponding to the friend to be added and the public key information corresponding to the friend to be added, a data exchange channel is established between the friend to be added and the user of the current mobile terminal device through short-range wireless communication technology.

[0039] In one example, an initialization module is configured to:

[0040] Based on the user identification information corresponding to the friend to be added, create a communication business card in the address book corresponding to the user of the current mobile terminal device;

[0041] Store the public key information of the friend to be added and establish an association relationship between the public key information and the communication business card to obtain the public key information based on the communication business card.

[0042] In one example, the device further includes:

[0043] An identity authentication module is configured to display an identity authentication interface and verify the identity information of the data recipient after receiving an encrypted data packet;

[0044] After the identity information of the data recipient is verified, obtain the first decryption private key.

[0045] In one example, the device further includes:

[0046] An update module is configured to generate an updated signature key pair and an updated encryption key pair that match the current user based on the mobile terminal device after replacement, after detecting a replacement of the mobile terminal device of the current user;

[0047] Read the address book of the current user and encrypt the public key in the updated signature key pair and the public key in the updated encryption key pair based on the public keys in the encryption key pairs corresponding to each friend in the address book of the current user to obtain encrypted updated public key information;

[0048] Broadcast the encrypted updated public key information to each friend in the address book of the current user so that each friend updates the public key information of the current user.

[0049] In a third aspect, the present application provides an electronic device, including: a processor and a memory communicatively connected to the processor;

[0050] The memory stores computer-executable instructions;

[0051] The processor executes the computer-executable instructions stored in the memory to implement the method described in the first aspect.

[0052] In a fourth aspect, the present application provides a computer-readable storage medium storing computer-executable instructions, which are used to implement the method described in the first aspect when executed by a processor.

[0053] In a fifth aspect, the present application provides a computer program product including computer-executable instructions stored in a readable storage medium. At least one processor of an electronic device can read the computer-executable instructions from the readable storage medium, and the at least one processor executes the computer-executable instructions to cause the electronic device to execute the method described in the first aspect.

[0054] The communication data anti-leakage method, device, equipment and storage medium provided by the present application can, after receiving the encrypted data packet sent by the data sender, obtain a first decryption private key locally, and based on the first decryption private key, decrypt the encrypted attachment data in the encrypted data to obtain the symmetric key information for encrypting the data to be received and the user identification information for identifying the data sender. At this time, the encrypted data to be received can be decrypted through the symmetric key information to obtain the data to be received, and based on the user identification information, a first signature public key can be obtained locally to decrypt the encrypted permission information based on the first signature public key to obtain the permission information. This implementation method can effectively ensure the security and reliability of the transmitted data. After that, according to the permission information and the data to be received obtained after the decryption process, the data receiver can receive the data to be received to complete the data communication. This implementation method can realize direct communication between the two communication parties by pre-storing the public key information of the two communication parties for data communication locally without relying on a central node, thereby avoiding the network communication quality of the central node from affecting the data communication effect, not only improving the communication efficiency but also reducing the communication cost. At the same time, this implementation method can establish a communication connection with the communication object by pre-storing the public key information of the communication object in advance without the need to build an account system in advance, which not only streamlines the relevant information of the communication object but also enables individual users to achieve multi-point communication and improves the user communication experience. BRIEF DESCRIPTION OF THE DRAWINGS

[0055] The accompanying drawings herein are incorporated into the specification and constitute a part of the specification, showing embodiments consistent with the present application and used together with the specification to explain the principles of the present application.

[0056] Figure 1 It is a schematic flowchart of a communication data anti-leakage method provided by an embodiment of the present application;

[0057] Figure 2 It is a schematic flowchart of another communication data anti-leakage method provided by an embodiment of the present application;

[0058] Figure 3 It is a schematic flowchart of the initialization of a data leakage prevention method provided by an embodiment of the present application;

[0059] Figure 4 It is a schematic flowchart of adding a friend provided by an embodiment of the present application;

[0060] Figure 5 It is a schematic flowchart of a data sender encrypting data provided by an embodiment of the present application;

[0061] Figure 6 It is a schematic diagram of updating the public key information of a user provided by an embodiment of the present application;

[0062] Figure 7 It is a complete flowchart of communication between communication objects provided by an embodiment of the present application;

[0063] Figure 8 It is a schematic diagram of the structure of a communication data leakage prevention device provided by an embodiment of the present application;

[0064] Figure 9 It is a schematic diagram of the structure of another communication data leakage prevention device provided by an embodiment of the present application;

[0065] Figure 10 It is a schematic diagram of the structure of an electronic device provided by an embodiment of the present application.

[0066] Through the above-mentioned drawings, specific embodiments of the present application have been shown, and there will be more detailed descriptions hereinafter. These drawings and textual descriptions are not intended to limit the scope of the concept of the present application in any way, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. Detailed Embodiments

[0067] Here, the exemplary embodiments will be described in detail, and the examples are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.

[0068] As used herein, the term "and / or" merely describes an associated relationship and indicates that three relationships may exist. For example, A and / or B may represent three cases: A exists alone, A and B exist simultaneously, and B exists alone. Additionally, the term "at least one" as used herein means any one of a plurality or any combination of at least two of a plurality. For example, including at least one of A, B, and C may mean including any one or more elements selected from the set composed of A, B, and C.

[0069] In the communication data leakage prevention methods in the prior art, mainly a central node is established for each user who needs to perform multi-point data communication, and a complete account system is created for each user who needs to perform multi-point data communication, so as to perform identity authentication through the account, and then realize the transfer of data between specific objects and achieve data leakage prevention.

[0070] However, in this implementation method, it is necessary to generate and exchange keys through the central node, and then combine account identity authentication to ensure data leakage prevention. Then, before performing multi-point data communication, it is necessary to additionally arrange a central node and establish a complete account system, which not only increases the communication cost but also is not applicable to multi-point data communication in the personal user scenario.

[0071] In addition, when performing multi-point communication, it is necessary to frequently access the central node. In the case of central node failure or poor network, it is easy to affect the communication quality and efficiency.

[0072] The communication data leakage prevention method provided by this application aims to solve the above technical problems in the prior art.

[0073] The following uses specific embodiments to elaborate in detail on the technical solution of this application and how the technical solution of this application solves the above technical problems. These several specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of this application will be described below in conjunction with the accompanying drawings.

[0074] Figure 1 It is a schematic flow chart of a communication data leakage prevention method provided by an embodiment of this application. This method can be applied to a mobile terminal device, such as Figure 1 As shown, this method includes:

[0075] S101. After receiving the encrypted data packet, obtain the first decryption private key.

[0076] Among them, the encrypted data packet includes the encrypted data to be received and the encrypted additional data; the encrypted data to be received represents the data obtained by encrypting the data to be received based on the symmetric key information; the encrypted additional data represents the data obtained by encrypting the additional data based on the first encryption public key.

[0077] Among them, the first encryption public key and the first decryption private key are the encryption key pair of the data receiver; the first encryption public key represents the encryption public key pre-stored in the data sender.

[0078] In an example, the additional data may include the user identification information of the data sender, the permission information encrypted by the data sender and pre-set for the data receiver to receive the data to be received, and the symmetric key information.

[0079] S102. Based on the first decryption private key, decrypt the encrypted additional data in the encrypted data packet to obtain the symmetric key information included in the additional data and the user identification information included in the additional data.

[0080] Among them, the user identification information is used to identify the data sender.

[0081] In an example, the user identification information may be a UID (User Identification) identifier generated according to the unique identification information of the data sender. For example, the unique identification information may be the mobile phone number corresponding to the data sender, the software account, etc.

[0082] S103. Based on the symmetric key information, decrypt the encrypted data to be received to obtain the data to be received; and based on the user identification information, obtain the first signature public key, so as to decrypt the encrypted permission information included in the additional data based on the first signature public key to obtain the permission information.

[0083] Among them, the encrypted permission information is the data obtained by encrypting the permission information based on the first signature private key; the first signature public key and the first signature private key are the signature key pair of the data sender; the first signature public key represents the signature public key pre-stored in the data receiver.

[0084] S104. Based on the permission information, enable the data receiver to receive and use the data to be received.

[0085] In an example, the permission information may represent the way for the data receiver to read the data to be received. For example, the permission information may be read-only, prohibited from printing, prohibited from taking screenshots, burn after reading, etc. The data validity period of the data to be received may also be limited through the permission information.

[0086] As can be seen from the above description, in the embodiment of the present application, after receiving the encrypted data packet sent by the data sender, the first decryption private key can be obtained locally, and based on the first decryption private key, the encrypted attachment data in the encrypted data is decrypted to obtain the symmetric key information for encrypting the data to be received and the user identification information for identifying the data sender. At this time, the encrypted data to be received can be decrypted through the symmetric key information to obtain the data to be received, and based on the user identification information, the first signature public key is obtained locally to decrypt the encrypted permission information based on the first signature public key to obtain the permission information. This implementation method can effectively ensure the security and reliability of the transmitted data. After that, according to the permission information and the data to be received obtained after the decryption process, the data receiver can receive the data to be received to complete the data communication. This implementation method can realize the direct communication between the two communication parties by pre-storing the public key information of the two communication parties for data communication locally, without relying on a central node, thereby avoiding the influence of the network communication quality of the central node on the data communication effect, not only improving the communication efficiency but also reducing the communication cost. At the same time, this implementation method can establish a communication connection with the communication object by pre-storing the public key information of the communication object in advance, without the need to build an account system in advance, not only streamlining the relevant information of the communication object but also enabling individual users to achieve multi-point communication and improving the user communication experience.

[0087] Figure 2 FIG. is a schematic flowchart of another method for preventing communication data leakage provided by an embodiment of the present application. This method can be applied to a mobile terminal device, such as Figure 2 shown, the method includes:

[0088] S201. In response to a start instruction for the data leakage prevention function, generate a signature key pair, an encryption key pair, and user identification information that match the user of the current mobile terminal device.

[0089] Among them, the user of the current mobile terminal device can represent the data receiver or the data sender.

[0090] Among them, the signature key pair is used to encrypt / decrypt the permission information; the encryption key pair is used to encrypt / decrypt the additional data. At this time, the signature key pair includes a signature public key and a signature private key, and the encryption key pair includes an encryption public key and a decryption private key. Among them, the public key in the signature key pair, the public key in the encryption key pair, and the user identification information are used to be sent to the user who communicates with the user of the current mobile terminal device.

[0091] In one example, when the mobile terminal device supports the data leakage prevention function, a signature key pair, an encryption key pair, and user identification information that match the user of the current mobile terminal device can be generated in response to a start instruction for the data leakage prevention function.

[0092] In one example, Figure 3 is a schematic flowchart of the initialization of a data leakage prevention method provided by an embodiment of the present application. As Figure 3 shown, after detecting that the user triggers the data leakage prevention function, the user identification information, the encryption key pair, and the signature key pair of the user can be generated and saved.

[0093] Among them, each time in response to a start instruction for the data leakage prevention function, the generated signature key pair and encryption key pair are different. And each time in response to a start instruction for the data leakage prevention function, the generated user identification information can be the same. For example, when the user does not change, the user identification information identifying the user does not change either.

[0094] This implementation method can generate a signature key pair, an encryption key pair, and user identification information that match the user according to the mobile terminal device and the user of the mobile terminal device, thereby providing a basis for the encrypted communication of data and further enhancing the security of data communication through multiple encryption information.

[0095] In one example, after triggering an add friend instruction for the user of the current mobile terminal device and the user with whom data communication is to be performed, the public key in the signature key pair, the public key in the encryption key pair, and the user identification information can be sent to the user with whom data communication is to be performed by the user of the current mobile terminal device. For the specific process, refer to the content described in S203 - S204 below.

[0096] S202. In response to the friend add instruction, obtain the user identification information corresponding to the friend to be added and the public key information corresponding to the friend to be added; and add the friend to be added to the address book of the user of the current mobile terminal device.

[0097] Among them, the friend to be added represents the user who needs to perform data communication with the user of the current mobile terminal device, and the public key information includes the public key in the signature key pair and the public key in the encryption key pair.

[0098] During specific implementation, after responding to the friend addition, a data exchange channel between the friend to be added and the user of the current mobile terminal device can be established first through near - field wireless communication technology.

[0099] In one example, the user of the current mobile terminal device and the friend to be added can perform an NFC touch operation through their respective mobile terminal devices, or turn on the Bluetooth of their respective mobile terminal devices to find the communication object and establish a data exchange channel between the communication objects.

[0100] After that, based on the established data exchange channel, the user identification information corresponding to the friend to be added and the public key information corresponding to the friend to be added can be obtained.

[0101] In the above embodiments, key exchange between communication objects can be achieved through near-field interaction, thereby realizing point-to-point encrypted communication between communication objects, avoiding key exchange through establishing a central node, saving costs, omitting the access process between communication objects and the central node, reducing network requirements, and improving communication efficiency.

[0102] Next, based on the user identification information corresponding to the friend to be added, a communication business card can be newly created in the address book corresponding to the user of the current mobile terminal device. Then, the public key information of the friend to be added can be stored, and an association relationship between the public key information and the communication business card can be established to obtain the public key information based on the communication business card.

[0103] In one example, the user identification information of the friend to be added can be used as the friend name saved in the communication business card, or an easy-to-distinguish alias can be set for the friend to be added as the friend name in the communication business card, so as to establish a communication business card in the address book.

[0104] At the same time, the steps described in S203 below can also be executed, so that the friend to be added adds the user of the current mobile terminal device to the address book.

[0105] S203: Send the user identification information corresponding to the user of the current mobile terminal device and the public key information corresponding to the user of the current mobile terminal device to the friend to be added.

[0106] At this time, the user of the current mobile terminal device can be added to the address book of the friend to be added, and a communication business card corresponding to the user of the current mobile terminal device can be newly created in the address book of the friend to be added based on the user identification information corresponding to the user of the current mobile terminal device. At the same time, an association relationship between the communication business card and the public key information of the user of the current mobile terminal device can also be established.

[0107] In one example, Figure 4 is a schematic flowchart of a process for adding a friend provided by an embodiment of the present application. As Figure 4 shown, assume that the users to be added are Figure 4 the user A and user B shown. At this time, when user A and user B follow the aboveFigure 3 After the described process is initialized, the friend addition instruction can be triggered. At this time, the communication object can be discovered through NFC touch or Bluetooth near field (that is, user B is discovered by user A through near field on the side of user A, and user A is discovered by user B through near field on the side of user B). At this time, the communication objects discovered through near field can be triggered to add friends to each other. Specifically, the public key information of user A can be sent to user B, and the public key information of user B can be sent to user A. At this time, user B can be added to the address book of user A, and the public key information of user B can be saved locally on user A. At this time, user A can also be added to the address book of user B, and the public key information of user A can be saved locally on user B.

[0108] In the above embodiments, the data sender can generate a separate permission policy for the data receiver by generating an address book, so that the data receiver can receive data according to the separate permission policy, realizing data leakage prevention.

[0109] In one example, after the communication connection between communication objects is completed, communication can be carried out between the communication objects that have established the communication connection. For example, the data sender can send communication data (that is, an encrypted data packet) to the data receiver. At this time, the data receiver can receive the data according to the steps described in S204 - S209 below.

[0110] S204. Receive the encrypted data packet.

[0111] Among them, the encrypted data packet includes the encrypted data to be received and the encrypted additional data; the encrypted data to be received represents the data obtained by encrypting the data to be received based on the symmetric key information; the encrypted additional data represents the data obtained by encrypting the additional data based on the first encryption public key.

[0112] In one example, Figure 5 is a schematic flowchart of the process for a data sender to encrypt data provided by an embodiment of the present application. As Figure 5 shown, assuming that the data to be sent by the data sender is data A, a symmetric key information for symmetric encryption can be randomly generated, that is, Figure 5 the key 1 shown. At this time, the key 1 can be used to encrypt the data to be sent, such as Figure 5 the data A shown, to obtain the encrypted data to be received, for example, Figure 5 the ciphertext A shown.

[0113] After that, the signature private key of the data sender can be used to encrypt the pre-set permission information of the data sender to obtain the encrypted permission information.

[0114] Next, the encrypted permission information, the user identification information of the data sender, and the key 1 can be concatenated to obtain additional data.

[0115] Then, the obtained additional data can be encrypted using the encryption public key of the data receiver to obtain the encrypted additional data.

[0116] At this time, an encrypted data packet can be determined based on the encrypted additional data and the data to be received after encryption (i.e., ciphertext A), and the encrypted data packet can be sent to the data receiver.

[0117] This implementation manner can encrypt data and package data in an offline environment, thereby reducing network dependence and avoiding affecting communication due to problems with the communication network quality.

[0118] In one example, if the data sender needs to send the encrypted data packet to multiple data receivers simultaneously, the above-mentioned method of generating the data to be received after encryption can be reused, and according to the method of generating the encrypted additional data described above, for each data receiver, their respective corresponding encrypted additional data can be generated. Then, the data to be received after encryption and the encrypted additional data are packaged into an encrypted data packet and sent to each data receiver respectively.

[0119] After the encrypted data packet is sent to the data receiver, the data receiver can continue to execute the steps described in S205 below.

[0120] S205: Display an identity verification interface and verify the identity information of the data receiver.

[0121] In one example, an identity verification interface can be displayed through a pop-up window, and in the identity verification interface, the identity information of the data receiver can be verified. For example, the identity information can be face information, fingerprint information, etc. Here, the identity information is not specifically limited.

[0122] This implementation manner can achieve the identity verification of the data receiver without an account system.

[0123] S206: After the identity information of the data receiver is verified, obtain the first decryption private key.

[0124] Among them, the first encryption public key and the first decryption private key are the encryption key pair of the data receiver; the first encryption public key represents the encryption public key pre-stored in the data sender.

[0125] In one example, this step can refer to the content described in the above S101, and will not be elaborated here in detail.

[0126] S207. Decrypt the additional data in the encrypted data packet based on the first decryption private key to obtain the symmetric key information included in the additional data and the user identification information included in the additional data.

[0127] Among them, the user identification information is used to identify the data sender.

[0128] In one example, this step can refer to the content described in the above S102 and will not be described in detail here.

[0129] S208. Decrypt the data to be received after encryption based on the symmetric key information to obtain the data to be received; and obtain the first signature public key based on the user identification information, so as to decrypt the encrypted permission information included in the additional data based on the first signature public key to obtain the permission information.

[0130] Among them, the encrypted permission information is the data after encrypting the permission information based on the first signature private key; the first signature public key and the first signature private key are the signature key pair of the data sender; the first signature public key represents the signature public key pre-stored in the data receiver.

[0131] In one example, this step can refer to the content described in the above S103 and will not be described in detail here.

[0132] S209. Based on the permission information, enable the data receiver to receive and use the data to be received.

[0133] In one example, this step can refer to the content described in the above S104 and will not be described in detail here.

[0134] In one example, after the mobile terminal device of the user / communication object is replaced, the public key information of the user / communication object can be replaced according to the process described below.

[0135] First, generate an updated signature key pair and an updated encryption key pair that match the current user based on the replaced mobile terminal device.

[0136] Then, read the communication record of the current user, and encrypt the public key in the updated signature key pair and the public key in the updated encryption key pair based on the public keys in the encryption key pairs corresponding to each friend in the communication record of the current user to obtain the encrypted updated public key information.

[0137] Finally, broadcast the encrypted updated public key information to each friend in the communication record of the current user so that each friend can update the public key information of the current user.

[0138] Exemplarily, Figure 6A schematic diagram for updating the public key information of a user provided by an embodiment of the present application. As Figure 6 shown, the public key information of the user can be encrypted using the encryption public key of a contact friend to obtain new public key information, and the new public key information and the user identification information of the user are packaged to obtain update information. Then, the update information can be sent to each friend in the user's address book through an update message broadcast.

[0139] At this time, each friend in the address book can update the local public key information according to the user identification information in the update information.

[0140] Figure 7 A complete flowchart for communication between communication objects provided by an embodiment of the present application. As Figure 7 shown, taking user A and user B as communication objects as an example for illustration. At this time, user A and user B can first complete initialization according to the process described above Figure 3 , and then add friends to each other and save the public key information of the friends according to the process described above Figure 4 .

[0141] After that, the data sender, that is, Figure 7 user A shown, can obtain an encrypted data packet according to the process described above Figure 5 and send the encrypted data packet to the data receiver, that is, Figure 7 user B shown.

[0142] At this time, after receiving the encrypted data packet, user B can first perform local identity verification. For example, user B can be authenticated by presenting the identity verification interface corresponding to user B and verifying the face identity information or fingerprint identity information of user B in the identity verification interface, etc. After the identity verification is passed, a first decryption private key is obtained, and according to the first decryption private key, the encrypted additional data is decrypted to obtain symmetric key information, user identification information, and encrypted permission information.

[0143] At this time, the encrypted data to be received can be decrypted according to the symmetric key information to obtain the data to be received. At the same time, according to the user identification information, the first signature public key corresponding to user A can be obtained from the local of user B, and according to the first signature public key, the encrypted permission information is decrypted to obtain the permission information.

[0144] After obtaining the data to be received and the permission information, user B can receive the data to be received according to the permission information.

[0145] In one example, when the data to be received cannot be obtained or the permission information cannot be obtained, user B cannot receive the data to be received, thus further realizing the confidentiality of the data to be received.

[0146] Those skilled in the art can understand that in the above method of the specific implementation manner, the writing order of each step does not mean a strict execution order and does not constitute any limitation on the implementation process.

[0147] The specific execution order of each step should be determined according to its function and possible internal logic.

[0148] Figure 8 FIG. is a schematic structural diagram of a communication data anti-leakage device provided by an embodiment of the present application. As Figure 8 shown, the communication data anti-leakage device 800 includes:

[0149] An acquisition unit 801, configured to acquire a first decryption private key after receiving an encrypted data packet; wherein, the encrypted data packet includes encrypted data to be received and encrypted additional data; the encrypted data to be received represents data obtained by encrypting the data to be received based on symmetric key information; the encrypted additional data represents data obtained by encrypting the additional data based on a first encryption public key; the first encryption public key and the first decryption private key are an encryption key pair of the data recipient; the first encryption public key represents the encryption public key pre-stored in the data sender.

[0150] A first decryption unit 802, configured to perform decryption processing on the encrypted additional data in the encrypted data packet based on the first decryption private key to obtain the symmetric key information included in the additional data and the user identification information included in the additional data; wherein, the user identification information is used to identify the data sender.

[0151] A second decryption unit 803, configured to perform decryption processing on the encrypted data to be received based on the symmetric key information to obtain the data to be received; and acquire a first signature public key based on the user identification information, so as to perform decryption processing on the encrypted permission information included in the additional data based on the first signature public key to obtain the permission information; wherein, the encrypted permission information is data obtained by encrypting the permission information based on a first signature private key; the first signature public key and the first signature private key are a signature key pair of the data sender; the first signature public key represents the signature public key pre-stored in the data recipient.

[0152] A receiving unit 804, configured to enable the data recipient to receive and use the data to be received based on the permission information.

[0153] Figure 9 FIG. is a schematic structural diagram of another communication data anti-leakage device provided by an embodiment of the present application. As Figure 9As shown in the figure, the communication data anti-leakage device 900 includes:

[0154] An acquisition unit 901, configured to acquire a first decryption private key after receiving an encrypted data packet; wherein, the encrypted data packet includes encrypted data to be received and encrypted additional data; the encrypted data to be received represents data obtained by encrypting the data to be received based on symmetric key information; the encrypted additional data represents data obtained by encrypting the additional data based on a first encryption public key; the first encryption public key and the first decryption private key are an encryption key pair of the data receiver; the first encryption public key represents the encryption public key pre-stored in the data sender.

[0155] A first decryption unit 902, configured to decrypt the encrypted additional data in the encrypted data packet based on the first decryption private key to obtain the symmetric key information included in the additional data and the user identification information included in the additional data; wherein, the user identification information is used to identify the data sender.

[0156] A second decryption unit 903, configured to decrypt the encrypted data to be received based on the symmetric key information to obtain the data to be received; and obtain a first signature public key based on the user identification information, so as to decrypt the encrypted permission information included in the additional data based on the first signature public key to obtain the permission information; wherein, the encrypted permission information is data obtained by encrypting the permission information based on a first signature private key; the first signature public key and the first signature private key are a signature key pair of the data sender; the first signature public key represents the signature public key pre-stored in the data receiver.

[0157] A receiving unit 904, configured to enable the data receiver to receive and use the data to be received based on the permission information.

[0158] In one example, the device further includes:

[0159] An initialization module 905, configured to generate a signature key pair, an encryption key pair, and user identification information that match the user of the current mobile terminal device in response to a start instruction for the data anti-leakage function before receiving the encrypted data packet; wherein, the user of the current mobile terminal device represents the data receiver or the data sender.

[0160] In one example, the initialization module 905 is further configured to:

[0161] Before receiving the encrypted data packet, in response to a friend addition instruction, obtain the user identification information corresponding to the friend to be added and the public key information corresponding to the friend to be added; and add the friend to be added to the address book of the user of the current mobile terminal device; wherein, the friend to be added represents a user who needs to perform data communication with the user of the current mobile terminal device; the public key information includes the public key in the signature key pair and the public key in the encryption key pair;

[0162] Send the user identification information corresponding to the user of the current mobile terminal device and the public key information corresponding to the user of the current mobile terminal device to the friend to be added.

[0163] In one example, the initialization module 905 is further configured to:

[0164] After responding to the friend addition instruction and before obtaining the user identification information corresponding to the friend to be added and the public key information corresponding to the friend to be added, establish a data exchange channel between the friend to be added and the user of the current mobile terminal device through near-field wireless communication technology.

[0165] In one example, the initialization module 905 is configured to:

[0166] Based on the user identification information corresponding to the friend to be added, create a communication business card in the address book of the user of the current mobile terminal device;

[0167] Store the public key information of the friend to be added and establish an association relationship between the public key information and the communication business card, so as to obtain the public key information based on the communication business card.

[0168] In one example, the device further includes:

[0169] The identity authentication module 906 is configured to display an identity authentication interface and verify the identity information of the data recipient after receiving the encrypted data packet;

[0170] After the identity information of the data recipient is verified, obtain the first decryption private key.

[0171] In one example, the device further includes:

[0172] The update module 907 is configured to generate an updated signature key pair and an updated encryption key pair that match the current user based on the replaced mobile terminal device after detecting that the mobile terminal device of the current user has been replaced;

[0173] Read the address book of the current user and encrypt the public key in the updated signature key pair and the public key in the updated encryption key pair based on the public keys in the encryption key pairs corresponding to each friend in the address book of the current user to obtain the encrypted updated public key information;

[0174] Broadcast the encrypted and updated public key information to each friend in the address book of the current user, so that each friend can update the public key information of the current user.

[0175] Figure 10 This is a schematic structural diagram of an electronic device provided by an embodiment of the present application. As Figure 10 shown, the electronic device 1000 includes: a memory 1001 and a processor 1002.

[0176] The memory 1001; a memory for storing executable instructions of the processor 1002.

[0177] Wherein, the processor 1002 is configured to execute the method provided in the above embodiment.

[0178] The electronic device further includes a receiver 1003 and a transmitter 1004. The receiver 1003 is used to receive instructions and data sent by an external device, and the transmitter 1004 is used to send instructions and data to an external device.

[0179] An embodiment of the present application further provides a computer-readable storage medium. Computer-executable instructions are stored in the computer-readable storage medium, and the computer-executable instructions can be used to execute the steps of the communication data anti-leakage method in the above method embodiment. For details, please refer to the above method embodiment and will not be elaborated here.

[0180] An embodiment of the present application further provides a computer program product. The computer program product includes computer-executable instructions, and the computer-executable instructions can be used to execute the steps of the communication data anti-leakage method in the above method embodiment. For details, please refer to the above method embodiment and will not be elaborated here.

[0181] After considering the specification and practicing the invention disclosed herein, those skilled in the art will readily think of other embodiments of the present application. The present application is intended to cover any variations, uses, or adaptations of the present application. These variations, uses, or adaptations follow the general principles of the present application and include common general knowledge or conventional technical means in the technical field not disclosed in the present application. The specification and embodiments are only regarded as exemplary, and the true scope and spirit of the present application are pointed out by the following claims.

[0182] It should be understood that the present application is not limited to the exact structure already described and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present application is only limited by the appended claims.

Claims

1. A method for preventing communication data leakage, characterized in that, The method is applied to a mobile terminal device, and the method includes: After receiving an encrypted data packet, obtaining a first decryption private key; wherein, the encrypted data packet includes encrypted data to be received and encrypted additional data; the encrypted data to be received represents data obtained by encrypting the data to be received based on symmetric key information; the encrypted additional data represents data obtained by encrypting the additional data based on a first encryption public key; the first encryption public key and the first decryption private key are an encryption key pair of a data recipient; the first encryption public key represents an encryption public key pre-stored in a data sender; Based on the first decryption private key, performing decryption processing on the encrypted additional data in the encrypted data packet to obtain the symmetric key information included in the additional data and the user identification information included in the additional data; wherein, the user identification information is used to identify the data sender; Based on the symmetric key information, performing decryption processing on the encrypted data to be received to obtain the data to be received; and based on the user identification information, obtaining a first signature public key to perform decryption processing on the encrypted permission information included in the additional data based on the first signature public key to obtain permission information; wherein, the encrypted permission information is data obtained by encrypting the permission information based on a first signature private key; the first signature public key and the first signature private key are a signature key pair of the data sender; the first signature public key represents a signature public key pre-stored in the data recipient; Based on the permission information, enabling the data recipient to receive and use the data to be received.

2. The method according to claim 1, characterized in that Before receiving the encrypted data packet, the method further includes: In response to an instruction to start a data leakage prevention function, generating a signature key pair, an encryption key pair, and user identification information that match the user of the current mobile terminal device; wherein, the user of the current mobile terminal device represents a data recipient or a data sender.

3. The method according to claim 2, characterized in that, Before receiving the encrypted data packet, the method further includes: In response to a friend addition instruction, obtaining the user identification information corresponding to the friend to be added and the public key information corresponding to the friend to be added; and adding the friend to be added to the address book of the user of the current mobile terminal device; wherein, the friend to be added represents a user who needs to perform data communication with the user of the current mobile terminal device; the public key information includes the public key in the signature key pair and the public key in the encryption key pair; Sending the user identification information corresponding to the user of the current mobile terminal device and the public key information corresponding to the user of the current mobile terminal device to the friend to be added.

4. The method according to claim 3, characterized in that, Before obtaining the user identification information corresponding to the friend to be added and the public key information corresponding to the friend to be added after responding to the friend addition instruction, the method further includes: Establishing a data exchange channel between the friend to be added and the user of the current mobile terminal device through near-field wireless communication technology.

5. The method according to claim 3, wherein Adding the to-be-added friend to the address book of the user of the current mobile terminal device includes: Based on the user identification information corresponding to the to-be-added friend, creating a new communication business card in the address book corresponding to the user of the current mobile terminal device; Storing the public key information of the to-be-added friend and establishing an association relationship between the public key information and the communication business card, so as to obtain the public key information based on the communication business card.

6. The method according to any one of claims 1-5, characterized in that, After receiving the encrypted data packet, the method further includes: Displaying an identity verification interface and verifying the identity information of the data recipient; After the identity information of the data recipient is verified, obtaining the first decryption private key.

7. The method according to claim 1, characterized in that, The method further includes: After detecting that the mobile terminal device of the current user has been replaced, generating an updated signature key pair and an updated encryption key pair that match the current user based on the replaced mobile terminal device; Reading the address book of the current user and encrypting the public key in the updated signature key pair and the public key in the updated encryption key pair based on the public keys in the encryption key pairs corresponding to each friend in the address book of the current user, to obtain the encrypted updated public key information; Broadcasting the encrypted updated public key information to each friend in the address book of the current user, so that each friend updates the public key information of the current user.

8. A communication data anti-leakage device, characterized in that, Including: An acquisition unit, configured to obtain a first decryption private key after receiving an encrypted data packet; wherein, the encrypted data packet includes encrypted data to be received and encrypted additional data; the encrypted data to be received represents data obtained by encrypting the data to be received based on symmetric key information; the encrypted additional data represents data obtained by encrypting the additional data based on a first encryption public key; the first encryption public key and the first decryption private key are the encryption key pair of the data recipient; the first encryption public key represents the encryption public key pre-stored in the data sender; A first decryption unit, configured to decrypt the encrypted additional data in the encrypted data packet based on the first decryption private key to obtain the symmetric key information included in the additional data and the user identification information included in the additional data; wherein, the user identification information is used to identify the data sender; A second decryption unit, configured to decrypt the encrypted data to be received based on the symmetric key information to obtain the data to be received; and obtain a first signature public key based on the user identification information, so as to decrypt the encrypted permission information included in the additional data based on the first signature public key to obtain permission information; wherein, the encrypted permission information is data obtained by encrypting the permission information based on a first signature private key; the first signature public key and the first signature private key are the signature key pair of the data sender; the first signature public key represents the signature public key pre-stored in the data recipient; A receiving unit, configured to enable the data recipient to receive and use the data to be received based on the permission information.

9. An electronic device, characterized in that, Comprising: a processor, and a memory communicatively connected to the processor; the memory stores computer-executable instructions; the processor executes the computer-executable instructions stored in the memory to implement the communication data anti-leakage method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, Computer-executable instructions are stored in the computer-readable storage medium, and when the computer-executable instructions are executed by a processor, they are used to implement the communication data anti-leakage method according to any one of claims 1 to 7.

11. A computer program product, characterized in that, Comprising computer-executable instructions, which implement the communication data anti-leakage method according to any one of claims 1 to 7 when executed by a processor.