Data communication method based on checksum

Through the data communication method of splitting the encryption key into subkeys and performing multi-layer checksum verification, the relay party key exposure and overall data consistency problems are solved, and efficient and secure data transmission is achieved.

CN120263549AActive Publication Date: 2025-07-04MATRICTIME DIGITAL TECH CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510735447.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-04
Publication Date
2025-07-04
Estimated Expiration
2045-06-04

AI Technical Summary

Technical Problem

In the field of quantum information security, the relay party has a risk of key exposure during data transmission, and traditional checksum methods cannot ensure the overall consistency and security of the data, resulting in data leakage or corruption.

Method used

The data communication method based on the checksum is used to split the encryption key into two subkeys, and multi-layer checksum verification is performed during the transmission process to ensure the confidentiality of the key and the integrity of the data. The relay party is only responsible for the transmission and verification of the key and does not participate in the decryption calculation.

Benefits of technology

It improves the security of keys and the efficiency of data transmission, reduces the risk of relay key leakage, ensures the invisibility of data transmission and the integrity of decrypted data, and simplifies key management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263549A_ABST
    Figure CN120263549A_ABST
Patent Text Reader

Abstract

The invention discloses a data communication method based on a checksum, participants of the method comprise a sender, a first relay party and a receiver, the sender is in communication connection with the receiver through the first relay party, and the method comprises the following steps: the sender calculates the checksum based on transmission data, data content in the transmission data is encrypted to generate a first transmission data frame, and the first transmission data frame is sent to the first relay party; the first relay party receives and verifies the first transmission data frame, generates a second transmission data frame after verification is passed, and sends the second transmission data frame to the receiver; and the receiver receives the second transmission data frame and verifies the second transmission data frame, and data content is obtained after verification is passed. According to the method, decryption and verification of the transmission content are only carried out in the receiving party, the relay party only ensures the correctness of the relay key and does not need to participate in decryption calculation, the performance overhead is reduced, meanwhile, the invisibility of the transmission content in the transmission process is effectively guaranteed, and the message exposure risk is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technologies, and in particular, to a data communication method based on checksum. Background Art

[0002] In the field of quantum information security, when the sender and the receiver are located in isolated network environments (such as enterprise intranets and public networks, military networks with different security levels, etc.), or are far apart and cannot communicate directly, a relay party (such as a gateway, proxy server, etc.) is required to relay the data. In a data transmission architecture involving multiple parties collaborating, the security of the data is a more important issue to consider. During the process of data encrypted communication, if a single key is used, once it is obtained by an attacker, all the data can be decrypted, lacking a hierarchical protection mechanism. The relay party may expose the plaintext key during the transmission of the key, increasing the risk of man-in-the-middle attacks or internal leaks. The attacker may tamper with the key, causing the receiver to decrypt using the wrong key. If the integrity of the key cannot be guaranteed, it will lead to data leakage or damage. Therefore, the secure management and efficient transmission of keys are the keys to ensuring the confidentiality, integrity, and availability of data. Traditional checksums usually only target ciphertext or partial data, and cannot ensure the overall consistency of the combined data after decryption. If the decryption is successful but the data is tampered with, the system may not be able to detect it in time, which will lead to business logic errors or security vulnerabilities. The relay party needs to be completely trusted, otherwise the key may be stolen or tampered with, which does not conform to the zero-trust security principle. The coupling degree between key transmission and data decryption is high, and the relay party may be forced to participate in the decryption calculation, increasing the performance overhead and exposure risk. Therefore, there is an urgent need for a data communication method that can ensure the efficiency and accuracy of data verification while guaranteeing data security. Summary of the Invention

[0003] Objective of the Invention: This application provides a data communication method based on checksum to solve the problems existing in the prior art.

[0004] Technical Solution: The present invention provides a data communication method based on checksum. The participating parties of the method include a sender, a first relay party, and a receiver. The sender is communicatively connected to the receiver through the first relay party. The method includes the following steps:

[0005] Step 1: The sender calculates a checksum based on the transmission data and encrypts the data content in the transmission data to generate a first transmission data frame and sends it to the first relay party;

[0006] Step 2: The first relay party receives the first transmission data frame and verifies it. After the verification passes, it generates a second transmission data frame , and sent to the recipient;

[0007] Step 3: The receiver receives the second transmission data frame And verify it, and obtain the data content after the verification passes.

[0008] As an improvement of the present invention, in step 1, the sender transmits data based on Calculating the checksum specifically includes:

[0009] The sender generates transmission data , the transmission data Including frame header and the data content to be transmitted ; The sender is pre-configured with a data transmission format, the data transmission format including a frame header field, a key index field, a checksum field, and a ciphertext field;

[0010] The sender parses the data content , according to the data content The length of the encrypted data is determined by The length of the encryption key ; and obtain the length of the key index field and checksum field from the data transmission format ;

[0011] The sender determines the length and length The first encryption key is determined by Length , based on length Get the first encryption key of the corresponding length from the local key file , and record the first encryption key The first key index ; The sender sends the frame header Fill it into the frame header field of the data transmission format and set the first key index Fill in the key index field of the data transmission format;

[0012] The sender sends the first encryption key Split into two equal-length keys, recorded as the first encryption subkey and the second encryption subkey , and index the first key The corresponding first encryption subkey The first subkey index of and the corresponding second encryption subkey The second subkey index of ;

[0013] The sender calculates the frame header using a checksum algorithm , the first key index and the first encryption key to obtain the first checksum , and fills the first checksum into the key checksum field of the data transmission format; at the same time, the sender calculates the checksum of the data content to obtain the second checksum .

[0014] As an improvement of the present invention, in the step 1, the encryption of the data content in the transmission data to generate the first transmission data frame specifically includes:

[0015] The sender encrypts the second encryption sub-key using the first encryption sub-key to obtain the first sub-ciphertext ; the sender splices the second sub-key index , the second checksum and the data content together, and performs an encryption operation using the second encryption sub-key to obtain the second sub-ciphertext ; the first sub-ciphertext and the second sub-ciphertext are spliced together to obtain the first ciphertext , and the first ciphertext is filled into the ciphertext field in the data transmission format to generate the first transmission data frame .

[0016] As an improvement of the present invention, in the step 2, the verification of the first relay party receiving the first transmission data frame specifically includes:

[0017] The first relay party parses the received first transmission data frame to obtain the frame header , the key index , the checksum , and the ciphertext ; among them, the ciphertext is the splicing of the sub-ciphertext and the sub-ciphertext ;

[0018] The first relay party obtains the first decryption key in the same key file as the sender on the local side of the first relay party according to the key index , calculate the frame header using the checksum algorithm , key index and the first decryption key to obtain the third checksum of the combination, and obtain the third checksum , compare the checksum obtained by parsing with the third checksum to check if they are the same. If so, the verification passes and the verification process continues; otherwise, an error is reported to the sender and the data transmission process ends;

[0019] The first relay party uses the same key index splitting method as the sender to split the key index into sub - key indexes and sub - key index , and obtain the first decryption sub - key from the same key file as the sender on the local side of the first relay party according to the sub - key index , and obtain the second decryption sub - key from the same key file as the sender on the local side of the first relay party according to the sub - key index ; use the first decryption sub - key to decrypt the sub - ciphertext to obtain the first relay sub - key , and compare the second decryption sub - key with the first relay sub - key to check if they are the same. If so, the verification passes and proceed to the next step; otherwise, an error is reported to the sender and the data transmission process ends.

[0020] As an improvement of the present invention, in step 2, the generation of the second transmission data frame specifically includes:

[0021] The first relay party obtains a third encryption sub - key with the same length as the second decryption sub - key from the same key file as the receiver on the local side of the first relay party, and records the third sub - key index of the third encryption sub - key , splice the third sub - key index with the sub - key index to form the second key index , and fill the third sub - key index into the key index field of the data transmission format;

[0022] The first relay party splices the third encryption sub - key with the second decryption sub - key to form the second encryption key , and calculate the frame header using the checksum algorithm , the second key index and the second encryption key to obtain a fourth checksum for the combination, getting the fourth checksum , and filling the fourth checksum into the key checksum field of the data transmission format;

[0023] The first relay party uses the third encryption sub-key to encrypt the second decryption sub-key , obtaining the third sub-ciphertext , using the third sub-ciphertext to replace the sub-ciphertext , and concatenating with the sub-ciphertext to obtain the second ciphertext , and filling the second ciphertext into the ciphertext field in the data transmission format, generating the second transmission data frame .

[0024] As an improvement of the present invention, if the length of the third sub-key index is insufficient to meet the length requirement of the key index field, the part of the third sub-key index with insufficient length in the key index field is automatically supplemented.

[0025] As an improvement of the present invention, step 3 specifically includes:

[0026] The receiving party parses the received second transmission data frame to obtain the frame header , the sub-key index , the checksum , and the ciphertext ; wherein, the ciphertext is the concatenation of the sub-ciphertext and the sub-ciphertext ;

[0027] The receiving party obtains the third decryption sub-key in the same key file as the first relay party at the receiving party according to the sub-key index , uses the third decryption sub-key to perform a decryption operation on the sub-ciphertext , obtaining the second relay sub-key , uses the second relay sub-key to decrypt the sub-ciphertext , obtaining the sub-key index , the checksum and the data content ;

[0028] The receiving party uses the third decryption sub-key With the second relay sub - key Concatenated to form the second decryption key , the sub - key index And the sub - key index Concatenated to form the key index , Use the checksum algorithm to calculate the frame header , key index And the second decryption key To obtain the fifth checksum , Compare the obtained checksum With the fifth checksum . If they are the same, the verification passes and the verification process continues; otherwise, an error is reported to the sender via the first relay direction and the data transmission process ends;

[0029] The receiver uses the checksum algorithm to calculate the checksum of the data content To obtain the sixth checksum ; Compare the obtained checksum after decryption With the sixth checksum . If they are the same, the verification passes and the receiver obtains the data content ; Otherwise, an error is reported to the sender via the first relay direction and the data transmission process ends.

[0030] As an improvement of the present invention, the first relay party and the sender have the same key file pre - installed locally, and the first relay party and the receiver have the same key file pre - installed locally. The key files pre - installed locally by the first relay party and the sender and the key files pre - installed locally by the first relay party and the receiver are the same or different.

[0031] Beneficial effects:

[0032] 1. The encryption key is split into two encryption sub - keys. An attacker must obtain all the sub - keys to recover the complete key, increasing the difficulty of attacking the key data, effectively improving the confidentiality of the key; at the same time, the key to be relayed is encrypted and encapsulated into the ciphertext to be transmitted, reducing the risk of leakage of the relay key, ensuring the correctness of the relay key, simplifying the operation of key management, effectively improving the decryption efficiency on the premise of security, and taking into account both security and practicality;

[0033] 2. Substitute the frame header, key index, and encryption key into the calculation of the checksum. While protecting the frame header information, binding the key index and the key itself can effectively resist the attack of key replacement / replay;

[0034] 3. After decryption, the receiving party recalculates the checksum for the combination of multiple data and compares the checksum, which can ensure that the decrypted data combination has not been tampered with and prevent metadata forgery. At the same time, if decryption fails, it may be due to an incorrect key. If decryption is successful but the checksum fails, it indicates that the data has been tampered with or damaged during transmission, facilitating fault location and troubleshooting.

[0035] 4. The decryption and verification of the transmission content are only performed at the receiving party. The relay party only ensures the correctness of the relay key and does not need to participate in the decryption calculation, reducing the performance overhead while effectively ensuring the invisibility of the transmission content during the transmission process and reducing the risk of message exposure. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0037] Figure 1 It is a schematic flowchart of the method of the present application;

[0038] Figure 2 It is a specific flowchart of step 2 of the present application;

[0039] Figure 3 It is a specific flowchart of step 3 of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0040] In order to make the objectives, technical solutions, and advantages of the present application clearer, the following will further describe the present application in detail with reference to the drawings. Obviously, the described embodiments are only some embodiments of the present application, rather than all embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the scope of protection of the present application.

[0041] The present invention provides a data communication method based on checksum. The participants in the method include a sender and a receiver. In an embodiment of the present invention, there are also multiple relay parties between the sender and the receiver. The sender and the receiver are communicatively connected through one or more relay parties. At this time, it is difficult to directly pre-set the same key file between the sender and the receiver. Therefore, the participants in the data communication method of the present invention also include a first relay party, and the first relay party pre-sets the same key file with the sender and the receiver respectively. In an embodiment of the present invention, the multiple relay parties may of course also include other relay parties other than the first relay party. However, taking the first relay party as an example is sufficient to illustrate the solution described in this application. The processing of other relay parties can be carried out by referring to the first relay party here.

[0042] As Figure 1 shown, the data communication method of the present invention includes the following steps:

[0043] Step 1: The sender calculates the checksum based on the transmission data and encrypts the data content in the transmission data to generate a first transmission data frame , and sends it to the first relay party.

[0044] Specifically, the sender generates transmission data , and the transmission data includes a frame header and the data content to be transmitted . The data content is parsed, and the length of the encryption key for encrypting the data content is determined according to the length of the data content and the encryption ratio; and the lengths of the key index field and the checksum field are obtained from the data transmission format . This data transmission format is pre-configured in the sender and includes a frame header field, a key index field, a checksum field, and a ciphertext field. Among them, the frame header should be filled in the frame header field . The frame header includes a source port number, a destination port number, an encryption ratio, etc. Among them, the sender address and the receiver address can be determined according to the source port number and the destination port number; the encryption ratio is used to indicate the length ratio of the key used for encryption to the plaintext to be encrypted, such as 1:1, 1:2, etc. The sender determines the length

[0045] of the first encryption key according to the sum of the length and the length , and determines the length of the first encryption key Obtain the first encryption key of the corresponding length from the local key file , and record the first encryption key 's first key index ; It should be noted that the corresponding length should conform to the encryption ratio in the frame header . The first key index includes the starting position and key length of the first encryption key in the key file. The sender fills the frame header into the frame header field of the data transmission format, and fills the first key index into the key index field of the data transmission format. Among them, the frame header field and key index field of the data transmission format are in plaintext for subsequent data parsing to be carried out quickly and efficiently

[0046] The sender splits the first encryption key into two equal-length segments of keys, denoted as the first encryption sub-key and the second encryption sub-key , and according to the split offset position in the key file, splits the first key index into the corresponding first sub-key index of the first encryption sub-key and the corresponding second sub-key index of the second encryption sub-key . Among them, the first encryption sub-key is used as the encapsulation key to encrypt the second encryption sub-key ; The second encryption sub-key is used as the encryption key for generating the ciphertext of the data content , and the second encryption sub-key is the key that needs to be relayed. Splitting the first encryption key into the first encryption sub-key and the second encryption sub-key , the attacker must obtain all the sub-keys to restore the complete key, and different algorithms can be used for each sub-key. For example, the first encryption sub-key can be encrypted using the RSA algorithm or the XOR algorithm, etc., and the second encryption sub-key is encrypted using the AES algorithm. The attacker needs to crack both encryption algorithms at the same time, increasing the difficulty of attacking the key data

[0047] The sender substitutes the frame header , the first key index and the first encryption key into the checksum algorithm to calculate the checksum and obtain the first checksum . The first checksum Fill it into the key checksum field of the data transmission format. Among them, the key checksum field of the data transmission format is in plaintext, so that subsequent data parsing can be carried out quickly and efficiently. The sender will put the frame header , the first key index and the first encryption key into the calculation of the checksum together. While protecting the frame header information, it binds the key index and the key itself. If the key index is tampered with, the checksum verification fails, which can effectively resist the replacement / replay attack of the key itself. The key index may be associated with metadata such as the key file name, key version, validity period, usage, etc. The checksum can verify that this information has not been tampered with to ensure the consistency of the key and the metadata. At the same time, the sender also needs to use the checksum algorithm to calculate the checksum of the data content to obtain the second checksum . It should be noted that this second checksum is not filled into the key checksum field. In the embodiment of the present invention, the frame header field, the key index field, and the checksum field should be of fixed lengths respectively. For example, 4 bytes, 8 bytes, etc.

[0048] The sender uses the first encryption sub-key to encrypt the second encryption sub-key to obtain the first sub-ciphertext , so as to encrypt the key to be relayed and encapsulate it into the ciphertext to protect the confidentiality of the relayed key; the sender splices the second sub-key index , the second checksum and the data content together, and uses the second encryption sub-key to perform an encryption operation to obtain the second sub-ciphertext ; splice the first sub-ciphertext and the second sub-ciphertext together to form the complete first ciphertext to be transmitted , and fill this first ciphertext into the ciphertext field in the data transmission format. Encrypt the key to be relayed and encapsulate it into the ciphertext packet to form nested protection, reduce the risk of leakage of the relayed key, ensure the correctness of the relayed key, simplify the operation of key management, effectively improve the decryption efficiency of the data content on the premise of security, and take into account practicality while improving security. So far, the complete content of the data transmission format is completed, denoted as the first transmission data frame . The sender sends the first transmission data frame to the first relay party.

[0049] Step 2: The first relay party receives the first transmission data frame and verifies it. After passing the verification, it generates the second transmission data frame , and send it to the recipient.

[0050] As Figure 2 shown, specifically, the verification process includes the following:

[0051] The first relay party parses the received first transmission data frame to obtain the frame header , key index , checksum , and ciphertext . Among them, the ciphertext is the concatenation of sub-ciphertext and sub-ciphertext .

[0052] The first relay party obtains the first decryption key from the same key file as the sender's at the first relay party's local according to the key index . First, it is necessary to verify the integrity of the first decryption key : Calculate the checksum of the combination of the frame header , key index , and the first decryption key using the checksum algorithm to obtain the third checksum . Compare whether the checksum obtained by parsing is consistent with the value of the third checksum . If so, it means that the first decryption key is the same as the first encryption key , the verification passes, and continue to execute the verification process; otherwise, report an error to the sender and end the data transmission process.

[0053] The first relay party uses the same key index splitting method as the sender to split the key index into sub-key index and sub-key index . According to the sub-key index , obtain the first decryption sub-key from the same key file as the sender's at the first relay party's local. According to the sub-key index , obtain the second decryption sub-key from the same key file as the sender's at the first relay party's local. Use the first decryption sub-key to decrypt the sub-ciphertext to obtain the first relay sub-key . Compare whether the second decryption sub-key is consistent with the first relay sub-key . If so, it means that the first relay sub-key There is no tampering, the verification is passed, the key to be relayed is transmitted correctly, and the next step can be continued; otherwise, the key to be relayed is transmitted incorrectly, the data content cannot be decrypted, and an error needs to be reported to the sender to end the data transmission process.

[0054] The first relay party reconstructs the key index field, checksum field, and ciphertext field to generate the second transmission data frame , where the frame header field remains unchanged and is in plaintext:

[0055] Reconstruct the key index field: The first relay party obtains the third encryption sub-key with the same length as the second decryption sub-key in the same key file of the first relay party locally and the receiving party the same third encryption sub-key , and records the third sub-key index of the third encryption sub-key , and splices the third sub-key index with the sub-key index to form the second key index , and fills the third sub-key index into the key index field of the data transmission format; it should be noted that since the length of the key index field is fixed, if the length of the third sub-key index is not sufficient to meet the length requirement of the key index field, the insufficient part of the third sub-key index in the key index field can be automatically filled, for example, filling the key index field with multiple 0s; when parsing the key index field subsequently, the part with consecutive 0s in the field should be discarded.

[0056] Reconstruct the checksum field: Splice the third encryption sub-key with the second decryption sub-key to form the second encryption key , and substitute the frame header , the second key index and the second encryption key as parameters into the checksum algorithm to calculate the checksum and obtain the fourth checksum , and fill the fourth checksum into the key checksum field of the data transmission format.

[0057] Reconstruct the ciphertext field: The first relay party encrypts the second decryption sub-key with the third encryption sub-key to obtain the third sub-ciphertext , uses the third sub-ciphertext to replace the sub-ciphertext , splices it with the sub-ciphertext to obtain the second ciphertext , and uses this second ciphertext Fill it into the ciphertext field in the data transmission format.

[0058] It should be noted that the first relay party and the sender have the same key file pre - set locally, and the first relay party and the receiver have the same key file pre - set locally. The key files pre - set locally by the first relay party and the sender and the key files pre - set locally by the first relay party and the receiver can be the same or different.

[0059] So far, the complete content of the data transmission format is completed and recorded as the second transmission data frame. . The first relay party sends the second transmission data frame to the receiver.

[0060] Step 3: The receiver receives the second transmission data frame and verifies it. After passing the verification, the data content is obtained.

[0061] Specifically, as Figure 3 shown, the verification process includes the following:

[0062] The receiver parses the received second transmission data frame to obtain the frame header , sub - key index , checksum , ciphertext . Among them, the ciphertext is the concatenation of sub - ciphertext and sub - ciphertext .

[0063] The receiver obtains the third decryption sub - key in the key file that is the same as that of the first relay party locally according to the sub - key index , uses the third decryption sub - key to perform a decryption operation on the sub - ciphertext to obtain the second relay sub - key , and uses the second relay sub - key to decrypt the sub - ciphertext to obtain the sub - key index , checksum and data content .

[0064] The receiver concatenates the third decryption sub - key and the second relay sub - key to form the second decryption key , concatenates the sub - key index and the sub - key index to form the key index , and calculates the frame header , key index and the second decryption key to obtain the fifth checksum , and compare the checksum obtained by parsing with the fifth checksum to check if their values are the same. If so, it indicates that the second decryption key has not been tampered with during transmission, the verification passes, and the verification process continues; otherwise, an error is reported to the sender via the first relay direction, and the data transmission process ends. After decryption, the receiver recalculates the checksum for the combination of multiple data and compares the checksums, which can ensure that the decrypted data combination has not been tampered with and prevent metadata forgery. At the same time, if decryption fails, it may be due to an incorrect key; if decryption is successful but the checksum fails, it indicates that the data has been tampered with or damaged during transmission, which is convenient for fault location and troubleshooting.

[0065] The receiver also needs to calculate the checksum of the data content using the checksum algorithm to obtain the sixth checksum . Compare the checksum obtained by decryption with the sixth checksum to check if their values are the same. If so, it indicates that the data content has not been tampered with during transmission, the verification passes, and the receiver obtains the data content ; otherwise, an error is reported to the sender via the first relay direction, and the data transmission process ends.

[0066] In the data communication method provided by the present invention, the decryption and verification of the transmission content are only performed at the receiver, and the relay party only ensures the correctness of the relay key, effectively guaranteeing the invisibility of the transmission content during transmission and reducing the risk of message exposure.

Claims

1. A data communication method based on checksum, the participants of the method including a sender, a first relay party, and a receiver, the sender and the receiver being communicatively connected through the first relay party, characterized in that, The method includes the following steps: Step 1: The sender calculates a checksum based on the transmission data and encrypts the data content in the transmission data to generate a first transmission data frame and sends it to the first relay party; ​ Step 2: The first relay party receives the first transmission data frame and performs verification. After the verification passes, a second transmission data frame is generated , and is sent to the receiving party; Step 3: The receiver receives the second transmission data frame and performs verification. After the verification passes, the data content is obtained.

2. The data communication method based on checksum according to claim 1, wherein In the step 1, the sender calculates the checksum based on the transmission data The specific calculation of the checksum includes: The sender generates transmission data , and the transmission data includes a frame header and the data content to be transmitted ; A data transmission format is pre-configured in the sender, and the data transmission format includes a frame header field, a key index field, a checksum field, and a ciphertext field; The sender parses the data content , and determines the length of the encryption key for the encrypted data content based on the length of the data content ; and obtains the lengths of the key index field and the checksum field from the data transmission format ; ; The sender determines the length and length The first encryption key is determined by Length , based on length Get the first encryption key of the corresponding length from the local key file , and record the first encryption key The first key index ; The sender sends the frame header Fill it into the frame header field of the data transmission format and set the first key index Fill in the key index field of the data transmission format; The sender splits the first encryption key into two keys of equal length, denoted as the first encryption sub-key and the second encryption sub-key , and correspondingly splits the first key index into the first sub-key index corresponding to the first encryption sub-key and the second sub-key index corresponding to the second encryption sub-key ; The sender calculates the checksum of the frame header using a checksum algorithm , the first key index and the first encryption key to obtain the first checksum , and fills the first checksum into the key checksum field of the data transmission format; meanwhile, the sender calculates the checksum of the data content to obtain the second checksum .

3. The data communication method based on checksum according to claim 2, wherein In the step 1, the transmitted data in the data content is encrypted to generate a first transmission data frame Specifically, it includes: The sender uses the first encryption sub-key to encrypt the second encryption sub-key , obtaining the first sub-ciphertext ; The sender concatenates the second sub-key index , the second checksum and the data content , and performs an encryption operation using the second encryption sub-key , obtaining the second sub-ciphertext ; The first sub-ciphertext and the second sub-ciphertext are concatenated together to obtain the first ciphertext , and the first ciphertext is filled into the ciphertext field in the data transmission format to generate the first transmission data frame .

4. The data communication method based on checksum according to claim 3, characterized in that In the step 2, the first relay party receives a first transmission data frame and the verification specifically includes: The first relay party parses the received first transmission data frame to obtain the frame header , the key index , the checksum , and the ciphertext ; among them, the ciphertext is the concatenation of the sub-ciphertext and the sub-ciphertext . The first relay party obtains, according to the key index a first decryption key from the same key file as the sender's at the first relay party locally , calculates the frame header using the checksum algorithm , the key index and the first decryption key to obtain a third checksum for the combination , and compares whether the value of the parsed checksum is the same as that of the third checksum . If so, the verification passes and the verification process continues; otherwise, an error is reported to the sender and the data transmission process ends. The first relay party uses the same key index splitting method as the sender to split the key index into a sub-key index and a sub-key index . According to the sub-key index , obtain the first decryption sub-key from the same key file as the sender on the local side of the first relay party. According to the sub-key index , obtain the second decryption sub-key from the same key file as the sender on the local side of the first relay party; use the first decryption sub-key to decrypt the sub-ciphertext to obtain the first relay sub-key . Compare whether the second decryption sub-key is consistent with the first relay sub-key . If so, the verification passes and proceed to the next step; otherwise, report an error to the sender and end the data transmission process.

5. The data communication method based on checksum according to claim 4, wherein In the step 2, generating the second transmission data frame Specifically including: The first relay obtains the second decryption subkey with the same length as the receiving party in the first relay's local key file. The same third encryption subkey , and record the third encryption subkey The third subkey index of , index the third subkey Index with subkey Concatenate to the second key index , index the third subkey Fill in the key index field of the data transmission format; The first relay party combines the third encrypted sub-key with the second decryption sub-key to form the second encryption key , and calculates the checksum of the combination of the frame header , the second key index and the second encryption key using a checksum algorithm to obtain the fourth checksum , and fills the fourth checksum into the key checksum field of the data transmission format; The first relay party uses the third encryption sub-key to encrypt the second decryption sub-key , obtaining the third sub-ciphertext , and uses the third sub-ciphertext to replace the sub-ciphertext , and splices it with the sub-ciphertext , obtaining the second ciphertext , and fills the second ciphertext into the ciphertext field in the data transmission format, generating the second transmission data frame .

6. The data communication method based on checksum according to claim 5, wherein If the length of the third sub-key index is insufficient to meet the length requirement of the key index field, the third sub-key index automatically supplements the insufficient part in the key index field.

7. The data communication method based on checksum according to claim 5, characterized in that, Specifically, step 3 includes: The receiving party parses the received second transmission data frame to obtain the frame header , the sub - key index , the checksum , and the ciphertext ; among them, the ciphertext is the concatenation of the sub - ciphertext and the sub - ciphertext . The receiving party obtains, according to the sub-key index a third decryption sub-key from the same key file as that of the first relay party locally at the receiving party , and uses the third decryption sub-key to perform a decryption operation on the sub-ciphertext to obtain a second relay sub-key , and uses the second relay sub-key to decrypt the sub-ciphertext to obtain the sub-key index , the checksum and the data content ; The recipient combines the third decryption sub-key with the second relay sub-key to form the second decryption key , combines the sub-key index with the sub-key index to form the key index , uses a checksum algorithm to calculate the checksum of the combination of the frame header , the key index and the second decryption key to obtain the fifth checksum , and compares whether the value of the parsed checksum is the same as that of the fifth checksum . If so, the verification passes and the verification process continues; otherwise, an error is reported to the sender via the first relay direction, and the data transmission process ends; The receiving party uses a checksum algorithm to calculate the checksum of the data content to obtain the sixth checksum ; compare the checksum obtained by decryption with the sixth checksum to check if their values are the same. If so, the verification passes and the receiving party obtains the data content ; otherwise, report an error to the sender via the first relay direction and end the data transmission process.

8. The data communication method based on checksum according to claim 1, wherein The first relay party and the sender have the same key file pre-set locally, and the first relay party and the receiver have the same key file pre-set locally. The key file pre-set locally by the first relay party and the sender and the key file pre-set locally by the first relay party and the receiver are the same or different.

Citation Information

Patent Citations

  • Quantum communication method and communication network based on secure relay

    CN112787807A

  • Quantum key transmission method, device and system and storage medium

    CN114124377A

  • Key relay method of quantum security network

    CN115514475A

  • Symmetric quantum security encryption communication method based on quantum security service authentication

    CN119966617A

  • Quantum key delivery service platform

    EP4287554A1