Data exchange method in data security sandbox environment
By verifying digital certificates and negotiating the transmission key in a data security sandbox environment, using encryption algorithms and hash functions, the problems of data integrity and security in data exchange are solved, and security protection during data transmission is achieved.
Patent Information
- Application Number
- CN202510646833.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-20
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2045-05-20
AI Technical Summary
The existing data exchange methods have shortcomings in data integrity verification and are difficult to effectively prevent cyber attacks and data leakage, especially during data transmission, where security threats are becoming increasingly serious.
In the data security sandbox environment, Sandbox A verifies the digital certificate of Sandbox B, negotiates the public transmission key, and uses encryption algorithms and hash functions to ensure the security of data transmission, including the entire process of data decryption, encryption, transmission and storage, forming a strict data security protection system.
Effectively identify the legality of sandbox B, ensure the integrity and security of data during transmission, prevent illegal access and tampering, ensure the controllability of data sources and storage security, and form data security protection throughout the process.
Smart Images

Figure CN120281565A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data security, and specifically relates to a method for data exchange in a data security sandbox environment. Background Art
[0002] A data security sandbox is an isolated and controlled computing environment designed to protect the privacy and security of data, enabling users to process and exchange sensitive data in a secure environment. Sandbox technology isolates the operating system and applications to prevent potential security threats and information leakage, ensuring the integrity and availability of data.
[0003] Data exchange requirements: Modern enterprises need to frequently exchange data to achieve effective business cooperation and decision support. The sandbox environment provides a secure foundation for this need.
[0004] Incremental data analysis: With the application of big data and artificial intelligence, enterprises need to perform data analysis and modeling while protecting sensitive data. The sandbox allows analysis without exposing the original data.
[0005] Increasing security threats: Existing data exchange methods have deficiencies in data integrity verification. At the same time, security threats such as network attacks, data leakage, and malware are becoming increasingly serious, making it difficult to effectively prevent data from being tampered with during transmission.
[0006] Under this background, inventing a method for data exchange in a data security sandbox environment has important practical significance and application value. Summary of the Invention
[0007] The purpose of the present invention is to overcome the deficiencies of the prior art and provide a method for data exchange in a data security sandbox environment to solve the problems raised in the above background art.
[0008] The purpose of the present invention can be achieved through the following technical solutions: A method for data exchange in a data security sandbox environment includes the following steps:
[0009] Step 1, Sandbox A verifies the digital certificate of Sandbox B to ensure the legality of Sandbox B;
[0010] Step 2, Sandbox A and Sandbox B negotiate a common transmission key using the digital certificate for subsequent data encrypted transmission;
[0011] Step 3, Sandbox A decrypts the encrypted and stored data using the private key of Party B to obtain the plaintext data;
[0012] Step 4, Sandbox A encrypts the plaintext data using the transmission key to obtain encrypted data and sends the encrypted data to Sandbox B;
[0013] Step Five: Sandbox B obtains the encrypted data and decrypts the data using the transmission key to obtain the plaintext data;
[0014] Step Six: Sandbox B encrypts the plaintext data using its own key and stores it locally.
[0015] As a further solution of the present invention, Sandbox A is the data provider and Sandbox B is the data user.
[0016] As a further solution of the present invention, Step One includes:
[0017] Sandbox B sends its digital certificate to Sandbox A; wherein, the digital certificate is issued by a trusted certificate authority and contains the public key of Sandbox B, the holder identity information, and the digital signature; the data signature is generated by the certificate authority encrypting the hash value of the digital certificate content using the private key;
[0018] Sandbox A receives the digital certificate of Sandbox B and checks and verifies the digital certificate of Sandbox B, including:
[0019] Checking whether the format of the digital certificate is correct;
[0020] Verifying the validity period of the digital certificate to ensure that the digital certificate has not expired;
[0021] Sandbox A decrypts the digital signature on the digital certificate using the public key of the certificate authority, compares the obtained decryption result with the hash value of the digital certificate content. If they are the same, it indicates that the digital certificate has not been tampered with and is indeed issued by the corresponding certificate authority;
[0022] If all the above checks and verifications of the digital certificate of Sandbox B pass, then Sandbox B is considered legitimate.
[0023] As a further solution of the present invention, Step Two includes:
[0024] It should be further noted that in the specific implementation process, the process of Sandbox A and Sandbox B negotiating a common transmission key using digital certificates includes:
[0025] Sandbox A and Sandbox B each randomly generate a pair of key pairs, that is, Sandbox A generates the private key d and the public key D = g d mod p, and Sandbox B generates the private key e and the public key E = g e mod p; where g is the generator, p is a prime number; mod is the modulo operation;
[0026] Sandbox A and Sandbox B exchange their respective public keys, that is, Sandbox A receives the public key E of Sandbox B, and Sandbox B receives the public key D of Sandbox A.
[0027] As a further solution of the present invention, step two further includes:
[0028] Sandbox A uses its own private key d and the public key E of sandbox B to calculate the shared key K1;
[0029] The calculation formula is:
[0030] K1 = E d mod p;
[0031] Wherein, K1 is the shared key calculated by sandbox A using its own private key d and the public key E of sandbox B;
[0032] Sandbox B uses its own private key e and the public key D of sandbox A to calculate the shared key K2;
[0033] The calculation formula is:
[0034] K2 = D e mod p;
[0035] Wherein, K2 is the shared key calculated by sandbox B using its own private key e and the public key D of sandbox A;
[0036] Because:
[0037] K1 = E d mod p = (g e ) d mod p = g ed mod p;
[0038] K2 = D e mod p = (g d ) e mod p = g ed mod p;
[0039] So K1 = K2, that is, the shared keys calculated by both parties are the same, and the calculated shared key is the transmission key.
[0040] As a further solution of the present invention, step four includes:
[0041] Sandbox A calls the internal encryption algorithm, inputs the plaintext data to be encrypted and the transmission key as parameters, and according to the established rules and logic of the encryption algorithm, performs transformation operations on each byte and each segment of information of the plaintext data, and gradually converts the plaintext data into encrypted data.
[0042] As a further solution of the present invention, step four further includes:
[0043] By adding a checksum to the encrypted data, it is used to ensure the integrity and accuracy of the data during transmission; by using the HMAC-SHA256 hash function to calculate the encrypted data and the transmission key, the hash value H1 of the encrypted data and the transmission key is obtained;
[0044] Combine the hash value H1 and the encrypted data into a transmission packet and send it to sandbox B according to the pre-set communication protocol and transmission path.
[0045] As a further solution of the present invention, step five includes:
[0046] Obtain the encrypted data transmission request from sandbox A, and sandbox B starts the receiving program to obtain the encrypted data;
[0047] Perform integrity verification on the obtained encrypted data to verify whether the encrypted data has been tampered with. By using the same HMAC-SHA256 hash function to calculate the hash value H2 of the received encrypted data and the transmission key, and comparing it with the hash value H1 numerically. If H1 = H2, it means that the data has not been tampered with during transmission; otherwise, discard the data and request retransmission;
[0048] After obtaining the complete and error-free encrypted data, sandbox B uses the transmission key to decrypt the encrypted data. Input the encrypted data and the transmission key into the decryption algorithm, which is the inverse operation rule corresponding to the encryption algorithm in step four, and gradually restore each information segment in the encrypted data to finally obtain the original plaintext data.
[0049] Compared with the existing solutions, the beneficial effects achieved by the present invention are:
[0050] The present invention effectively identifies the legitimacy of the identity of sandbox B by sandbox A's verification of the digital certificate of sandbox B, preventing data interaction with illegal or unauthorized sandbox B; on the basis of identity verification, the two parties negotiate a transmission key based on the digital certificate, and this transmission key is only used for the current data exchange process. Even if the transmission key is accidentally leaked, it will not affect the long-term key security of both parties;
[0051] The present invention ensures the controllability of the data source by sandbox A's decryption operation of its own encrypted data. Only sandbox A with the correct private key can restore the original plaintext data; then use the transmission key to encrypt the plaintext data, so that the data exists in ciphertext form during network transmission, resisting external attacks and theft;
[0052] The present invention decrypts the received data by sandbox B with the transmission key to obtain the plaintext data, and then encrypts it with its own key, further ensuring the security of the data during internal storage and subsequent use in sandbox B. The entire process forms a set of strict data security protection systems. Brief Description of the Drawings
[0053] The present invention will be further described below with reference to the accompanying drawings.
[0054] Figure 1 It is a flowchart of a data exchange method in a data security sandbox environment proposed by the present invention. Specific embodiments
[0055] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments.
[0056] As Figure 1 shown, the present invention is a data exchange method in a data security sandbox environment, including the following steps:
[0057] Step 1: Sandbox A verifies the digital certificate of Sandbox B to ensure the legality of Sandbox B; among them, Sandbox A is the data provider, and Sandbox B is the data user;
[0058] It should be further noted that in the specific implementation process, the process of Sandbox A verifying the digital certificate of Sandbox B to ensure the legality of Sandbox B includes:
[0059] Sandbox B sends its digital certificate to Sandbox A; among them, the digital certificate is issued by a trusted certificate authority and contains the public key of Sandbox B, the holder's identity information, and the digital signature; the digital signature is generated by the certificate authority using the private key to encrypt the hash value of the digital certificate content;
[0060] After receiving the digital certificate of Sandbox B, Sandbox A checks and verifies the digital certificate of Sandbox B, including:
[0061] Check whether the format of the digital certificate is correct;
[0062] Verify the validity period of the digital certificate to ensure that the digital certificate has not expired;
[0063] Sandbox A uses the public key of the certificate authority to decrypt the digital signature on the digital certificate, and compares the obtained decryption result with the hash value of the digital certificate content. If they are consistent, it means that the digital certificate has not been tampered with and is indeed issued by the corresponding certificate authority;
[0064] If all the above checks and verifications of the digital certificate of Sandbox B pass, it is considered that Sandbox B is legal.
[0065] Step 2: Sandbox A and Sandbox B use the digital certificate to negotiate a common transmission key for subsequent data encrypted transmission;
[0066] It should be further noted that in the specific implementation process, the process of the sandbox A and the sandbox B negotiating a common transmission key using digital certificates includes:
[0067] The sandbox A and the sandbox B each randomly generate a pair of key pairs, that is, the sandbox A generates a private key d and a public key D = g d mod p, and the sandbox B generates a private key e and a public key E = g e mod p; where g is a generator, p is a prime number; mod is the modulo operation;
[0068] The sandbox A and the sandbox B exchange their respective public keys, that is, the sandbox A receives the public key E of the sandbox B, and the sandbox B receives the public key D of the sandbox A;
[0069] The sandbox A uses its own private key d and the public key E of the sandbox B to calculate the shared key K1;
[0070] The calculation formula is:
[0071] K1 = E d mod p;
[0072] Where K1 is the shared key calculated by the sandbox A using its own private key d and the public key E of the sandbox B;
[0073] The sandbox B uses its own private key e and the public key D of the sandbox A to calculate the shared key K2;
[0074] The calculation formula is:
[0075] K2 = D e mod p;
[0076] Where K2 is the shared key calculated by the sandbox B using its own private key e and the public key D of the sandbox A;
[0077] Because:
[0078] K1 = E d mod p = (g e ) d mod p = g ed mod p;
[0079] K2 = D e mod p = (g d ) e mod p = g ed mod p;
[0080] So K1 = K2, that is, the shared keys calculated by both parties are the same, and the calculated shared key is the transmission key.
[0081] Step 3: Sandbox A uses Party B's private key to decrypt the encrypted and stored data to obtain the plaintext data;
[0082] Among them, the private key used by Sandbox A for Party B is read by Sandbox A from the hardware security module or software key library for its own private key.
[0083] Step 4: Sandbox A uses the transmission key to encrypt the plaintext data to obtain encrypted data, and sends the encrypted data to Sandbox B;
[0084] It should be further noted that in the specific implementation process, the process in which Sandbox A uses the transmission key to encrypt the plaintext data to obtain encrypted data and sends the encrypted data to Sandbox B includes:
[0085] Sandbox A calls the internal encryption algorithm, inputs the plaintext data to be encrypted and the transmission key as parameters, and according to the established rules and logic of the encryption algorithm, performs transformation operations on each byte and each piece of information of the plaintext data, and gradually converts the plaintext data into encrypted data;
[0086] By adding a check code to the encrypted data, it is used to ensure the integrity and accuracy of the data during transmission; by using the HMAC-SHA256 hash function to calculate the hash values of the encrypted data and the transmission key, the hash value H1 of the encrypted data and the transmission key is obtained;
[0087] The hash value H1 and the encrypted data are combined into a transmission packet and sent to Sandbox B according to the pre-set communication protocol and transmission path.
[0088] Step 5: Sandbox B obtains the encrypted data and uses the transmission key to decrypt the data to obtain the plaintext data;
[0089] It should be further noted that in the specific implementation process, the process in which Sandbox B obtains the encrypted data and uses the transmission key to decrypt the data to obtain the plaintext data includes:
[0090] Obtain the encrypted data transmission request from Sandbox A, and Sandbox B starts the receiving program to obtain the encrypted data;
[0091] Perform integrity verification on the obtained encrypted data to verify whether the encrypted data has been tampered with. By using the same HMAC-SHA256 hash function to calculate the hash value H2 of the received encrypted data and the transmission key, and comparing the numerical values with the hash value H1. If H1 = H2, it means that the data has not been tampered with during transmission; otherwise, discard the data and request retransmission;
[0092] After obtaining the complete and error-free encrypted data, Sandbox B calls the transmission key to decrypt the encrypted data. The encrypted data and the transmission key are input into the decryption algorithm, which is the inverse operation rule corresponding to the encryption algorithm in Step 4, to gradually restore each information segment in the encrypted data, and finally obtain the original plaintext data.
[0093] Step 6: Sandbox B uses its own key to encrypt the plaintext data and stores it locally.
[0094] In several embodiments provided by the present invention, it should be understood that the disclosed system can be implemented in other ways. For example, the above-described invention embodiments are merely illustrative. For example, the division of modules is only a logical function division, and there may be other division methods in actual implementation.
[0095] The modules described as separate components may or may not be physically separated. The components shown as modules may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0096] In addition, in each embodiment of the present invention, the functional modules can be integrated into a processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-integrated unit can be implemented in the form of hardware or in the form of a combination of hardware and software functional modules.
[0097] For those skilled in the art, it is obvious that the present invention is not limited to the details of the above-described exemplary embodiments, and without departing from the spirit or basic characteristics of the present invention, the present invention can be implemented in other specific forms.
[0098] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention.
Claims
1. A data exchange method within a data security sandbox environment, characterized in that, It includes the following steps: Step 1: Sandbox A verifies the digital certificate of Sandbox B to ensure the legality of Sandbox B; Step 2: Sandbox A and Sandbox B negotiate a common transmission key using the digital certificate for subsequent encrypted data transmission; Step 3: Sandbox A decrypts the encrypted stored data using the private key of Party B to obtain the plaintext data; Step 4: Sandbox A encrypts the plaintext data using the transmission key to obtain the encrypted data and sends the encrypted data to Sandbox B; Step 5: Sandbox B obtains the encrypted data and decrypts the data using the transmission key to obtain the plaintext data; Step 6: Sandbox B encrypts the plaintext data using its own key and stores it locally.
2. The data exchange method within a data security sandbox environment according to claim 1, wherein Sandbox A is the data provider, and Sandbox B is the data user.
3. A data exchange method in a data security sandbox environment according to claim 2, characterized in that, In Step 1, it includes: Sandbox B sends its digital certificate to Sandbox A; among them, the digital certificate is issued by a trusted certificate authority and contains the public key of Sandbox B, the holder's identity information, and the digital signature; the data signature is generated by the certificate authority encrypting the hash value of the digital certificate content using the private key; Sandbox A receives the digital certificate of Sandbox B and checks and verifies the digital certificate of Sandbox B, including: Checking whether the format of the digital certificate is correct; Verifying the validity period of the digital certificate to ensure that the digital certificate has not expired; Sandbox A decrypts the digital signature on the digital certificate using the public key of the certificate authority, compares the obtained decryption result with the hash value of the digital certificate content. If they are the same, it means that the digital certificate has not been tampered with and is indeed issued by the corresponding certificate authority; If all the above checks and verifications of the digital certificate of Sandbox B pass, then Sandbox B is considered legal.
4. A method for data exchange in a data security sandbox environment according to claim 3, characterized in that, In Step 2, it includes: It should be further noted that in the specific implementation process, the process of Sandbox A and Sandbox B negotiating a common transmission key using the digital certificate includes: Sandbox A and sandbox B each randomly generate a key pair, that is, sandbox A generates a private key d and a public key D = g d modp, sandbox B generates private key e and public key E=g e modp; where g is the generator, p is a prime number; mod is the modulus operation; Sandbox A and Sandbox B exchange their respective public keys, that is, Sandbox A receives the public key E of Sandbox B, and Sandbox B receives the public key D of Sandbox A.
5. A data exchange method within a data security sandbox environment according to claim 4, characterized in that, In Step 2, it also includes: Sandbox A calculates the shared key K1 using its own private key d and the public key E of Sandbox B; The calculation formula is: K1 = E d mod p; Among them, K1 is the shared key calculated by Sandbox A using its own private key d and the public key E of Sandbox B; Sandbox B calculates the shared key K2 using its own private key e and the public key D of Sandbox A; The calculation formula is: K2 = D e mod p; Among them, K2 is the shared key calculated by Sandbox B using its own private key e and the public key D of Sandbox A; Because: K1 = E d modp = (g e ) d modp = g ed modp; K2 = D e modp = (g d ) e modp = g ed modp; So K1 = K2, that is, the shared keys calculated by both parties are the same, and the calculated shared key is the transmission key.
6. A method for data exchange within a data security sandbox environment according to claim 5, characterized in that, In Step 4, it includes: Sandbox A calls the internal encryption algorithm, inputs the plaintext data to be encrypted and the transmission key as parameters, and according to the established rules and logic of the encryption algorithm, performs transformation operations on each byte and each piece of information of the plaintext data, and gradually converts the plaintext data into encrypted data.
7. A method for data exchange within a data security sandbox environment according to claim 6, characterized in that, In Step 4, it also includes: By adding a checksum to the encrypted data, it is used to ensure the integrity and accuracy of the data during transmission; by using the HMAC-SHA256 hash function to calculate the encrypted data and the transmission key, the hash value H1 of the encrypted data and the transmission key is obtained; The hash value H1 and the encrypted data are combined into a transmission packet and sent to sandbox B according to the pre-set communication protocol and transmission path.
8. A data exchange method within a data security sandbox environment according to claim 7, characterized in that, Step five includes: Obtain the encrypted data transmission request from sandbox A, and sandbox B starts the receiving program to obtain the encrypted data; Perform an integrity check on the obtained encrypted data to verify whether the encrypted data has been tampered with. By using the same HMAC-SHA256 hash function to calculate the hash value H2 of the received encrypted data and the transmission key, and comparing the numerical values with the hash value H1. If H1 = H2, it means that the data has not been tampered with during transmission; otherwise, discard the data and request a retransmission; After obtaining the complete and error-free encrypted data, sandbox B decrypts the encrypted data by calling the transmission key. The encrypted data and the transmission key are input into the decryption algorithm, which is the inverse operation rule corresponding to the encryption algorithm in step four, and each information segment in the encrypted data is gradually restored to finally obtain the original plaintext data.
Citation Information
Patent Citations
IPSec mixed anti-quantum computing security method and electronic equipment
CN119652525A
High-Fidelity Model-Driven Deception Platform for Cyber-Physical Systems
US20220191246A1