Data transmission method and device

By adopting secure code encryption and legality detection mechanisms in emergency location services, the problems of complex encryption and low decryption efficiency during data transmission are solved, efficient and secure data transmission and encryption and decryption are achieved, and development costs are reduced.

CN120282133APending Publication Date: 2025-07-08CHINA ACADEMY OF INFORMATION & COMM
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410030272.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-08
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

In the existing emergency location services, there are problems such as complex data encryption, low decryption timeliness, low efficiency and high development costs during data transmission, which affects the efficiency and security of rescue operations.

Method used

The security code encryption and legality detection mechanism are adopted to ensure the security and efficiency of data transmission through the security code acquisition, encrypted data packet reception, legality detection and decryption processes between the first service and the second service.

Benefits of technology

The data encryption and decryption process is simplified, the development cost is reduced, the data transmission and encryption and decryption efficiency in emergency location services is improved, and the data transmission security is ensured.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120282133A_ABST
    Figure CN120282133A_ABST
Patent Text Reader

Abstract

The invention discloses a data transmission method and device, and relates to the technical field of network security, and the method comprises the steps: a first service receives a security code sent by a second service; receiving an encrypted data packet sent by the second service in the boundary area of the first service; the encrypted data packet is obtained by encrypting transmission data by a second service by using a security code; legality detection is conducted on the encrypted data packet, when the detection result is illegal, summary information of the encrypted data packet is recorded, and the encrypted data packet is discarded; and when the detection result is legal, decrypting the encrypted data packet by using the security code to obtain transmission data. According to the invention, the data encryption and decryption process can be simplified, the security of data transmission is ensured, and the efficiency of data transmission and encryption and decryption in the emergency location service is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular, to a data transmission method and apparatus. Background Art

[0002] This section aims to provide background or context for the embodiments of the present invention described in the claims. The description herein is not admitted to be prior art merely by virtue of being included in this section.

[0003] Currently, the rapid development of mobile communication technology and the wide popularity of mobile phone users have made mobile phones the most effective way for emergency calls in current emergency scenarios such as medical first aid and emergency rescue. Emergency location service means that when a person is in an emergency situation, while making an emergency rescue call through a handheld terminal, the handheld terminal automatically sends its location information to a management platform, and the management platform forwards the relevant location information to a rescue agency to provide emergency rescue services for users.

[0004] In the application of emergency location service, for example, in the process of the management platform managing and transmitting user data, there may be a problem of data loss, which affects the information security of users. In the existing data transmission technical solutions, data encryption is too complex, the timeliness and efficiency of data decryption are low, which may affect rescue operations, and the development cost is high, unable to meet the actual needs of emergency location service. Summary of the Invention

[0005] Embodiments of the present invention provide a data transmission method to reduce the development cost of data transmission, improve the efficiency of data transmission and encryption / decryption in emergency location service, and ensure the security of data transmission. The method is applied to a first service and includes:

[0006] Sending a security code acquisition request to a second service;

[0007] Receiving the security code sent by the second service;

[0008] Receiving an encrypted data packet sent by the second service in the boundary area of the first service; the encrypted data packet is obtained by the second service encrypting the transmission data using the security code;

[0009] Performing a legality detection on the encrypted data packet, and when the detection result is illegal, recording the digest information of the encrypted data packet and discarding the encrypted data packet;

[0010] When the detection result is legal, decrypting the encrypted data packet using the security code to obtain the transmission data.

[0011] An embodiment of the present invention further provides a data transmission method, which is used to reduce the data transmission development cost, improve the efficiency of data transmission, encryption and decryption in emergency location services, and ensure the security of data transmission. This method is applied to the second service, and the method includes:

[0012] Generate a security code and provide the security code to the first service according to the security code acquisition request of the first service;

[0013] Encrypt the transmission data using the security code to obtain an encrypted data packet;

[0014] Send the encrypted data packet to the first service, so that the first service: receive the encrypted data packet in the boundary area, perform a legality detection on the encrypted data packet, and when the detection result is legal, decrypt the encrypted data packet using the security code to obtain the transmission data.

[0015] An embodiment of the present invention further provides a data transmission device, which is used to reduce the data transmission development cost, improve the efficiency of data transmission, encryption and decryption in emergency location services, and ensure the security of data transmission. This device is applied to the first service, and the device includes:

[0016] A security code receiving module, configured to receive the security code sent by the second service;

[0017] An encrypted data packet receiving module, configured to receive the encrypted data packet sent by the second service in the boundary area of the first service; the encrypted data packet is obtained by the second service encrypting the transmission data using the security code;

[0018] A legality detection module, configured to perform a legality detection on the encrypted data packet, and when the detection result is illegal, record the digest information of the encrypted data packet and discard the encrypted data packet;

[0019] A decryption module, configured to decrypt the encrypted data packet using the security code to obtain the transmission data when the detection result is legal.

[0020] An embodiment of the present invention further provides a data transmission device, which is used to reduce the data transmission development cost, improve the efficiency of data transmission, encryption and decryption in emergency location services, and ensure the security of data transmission. This device is applied to the second service, and the device includes:

[0021] A security code processing module, configured to generate a security code and send the security code to the first service;

[0022] An encryption module, configured to encrypt the transmission data using the security code to obtain an encrypted data packet;

[0023] A data sending module, configured to send an encrypted data packet to a first service, so that the first service: receive the encrypted data packet in a boundary area, perform a legality check on the encrypted data packet, and when the check result is legal, decrypt the encrypted data packet by using a security code to obtain transmission data.

[0024] An embodiment of the present invention further provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the above data transmission method is implemented.

[0025] An embodiment of the present invention further provides a computer-readable storage medium, where the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the above data transmission method is implemented.

[0026] An embodiment of the present invention further provides a computer program product, where the computer program product includes a computer program, and when the computer program is executed by a processor, the above data transmission method is implemented.

[0027] In an embodiment of the present invention, the first service receives a security code sent by the second service; receives an encrypted data packet sent by the second service in the boundary area of the first service; the encrypted data packet is obtained by the second service encrypting transmission data by using the security code; performs a legality check on the encrypted data packet, and when the check result is illegal, records the summary information of the encrypted data packet and discards the encrypted data packet; when the check result is legal, decrypts the encrypted data packet by using the security code to obtain transmission data. In the embodiment of the present invention, data is transmitted from the second service to the first service. The second service first generates a security code. The first service obtains the security code from the second service in the initialization stage. Then the second service encrypts the transmission data by using the security code. The first service receives the encrypted data packet in the boundary area and performs a legality check on the encrypted data packet. After the legality check is legal, decryption is performed, which ensures the security of data transmission. At the same time, the data encryption and decryption process is simple, reducing the data transmission development cost and improving the efficiency of data transmission, encryption, and decryption in emergency location services.

[0028] In an embodiment of the present invention, a second service generates a security code and sends the security code to a first service; encrypts transmission data by using the security code to obtain an encrypted data packet; and sends the encrypted data packet to the first service, so that the first service: receives the encrypted data packet in a boundary area, performs a legality check on the encrypted data packet, and when the check result is legal, decrypts the encrypted data packet by using the security code to obtain the transmission data. In the embodiment of the present invention, data is transmitted from the second service to the first service. A security code is generated in an initialization stage, and the security code is provided to the first service according to a security code acquisition request of the first service. After that, the second service encrypts the transmission data by using the security code and sends the encrypted data packet to the first service for the first service to decrypt the encrypted data packet, ensuring the security of data transmission. At the same time, the data encryption and decryption process is simple, reducing the development cost of data transmission and improving the efficiency of data transmission, encryption and decryption in emergency location services. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts. In the drawings:

[0030] Figure 1 is a schematic flowchart of a data transmission method applied to a first service in an embodiment of the present invention;

[0031] Figure 2 is a schematic flowchart of a data transmission method applied to a second service in an embodiment of the present invention;

[0032] Figure 3 is a schematic diagram of a data transmission device applied to a first service in an embodiment of the present invention;

[0033] Figure 4 is a schematic diagram of a data transmission device applied to a second service in an embodiment of the present invention;

[0034] Figure 5 is a schematic diagram of a computer device in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0035] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer and more understandable, the following further describes the embodiments of the present invention in detail with reference to the drawings. Herein, the illustrative embodiments of the present invention and their descriptions are used to explain the present invention, but not to limit the present invention.

[0036] The applicant has found that in emergency location service applications, such as during the management platform's management and transmission of user data, data loss may occur, affecting the information security of users. In existing data transmission technical solutions, data encryption is too complex, the timeliness and efficiency of data decryption are low, which may affect rescue operations, and the development cost is high, unable to meet the actual needs of emergency location services. Therefore, the applicant has proposed a data transmission method.

[0037] It should be noted that in the technical solution of this application, the acquisition, storage, use, processing, etc. of data all comply with the relevant provisions of national laws and regulations.

[0038] Figure 1 It is a schematic flowchart of the data transmission method applied to the first service in an embodiment of the present invention. As Figure 1 shown, the method includes:

[0039] Step 101: Send a security code acquisition request to the second service;

[0040] Step 102: Receive the security code sent by the second service;

[0041] Step 103: Receive the encrypted data packet sent by the second service in the boundary area of the first service; the encrypted data packet is obtained by the second service encrypting the transmission data using the security code;

[0042] Step 104: Perform a legality detection on the encrypted data packet. When the detection result is illegal, record the digest information of the encrypted data packet and discard the encrypted data packet;

[0043] Step 105: When the detection result is legal, decrypt the encrypted data packet using the security code to obtain the transmission data.

[0044] From Figure 1 the shown process, it can be seen that in the embodiment of the present invention, the second service transmits data to the first service. The second service first generates a security code. The first service obtains the security code from the second service during the initialization phase. Then, the second service encrypts the transmission data using the security code. The first service receives the encrypted data packet in the boundary area and performs a legality detection on the encrypted data packet. After the legality detection is legal, decryption is performed, ensuring the security of data transmission. At the same time, the data encryption and decryption process is simple, reducing the data transmission development cost and improving the efficiency of data transmission, encryption, and decryption in emergency location services.

[0045] The following will explain in detail the data transmission method applied to the first service in the embodiment of the present invention.

[0046] When the second service transfers data to the first service, in the initialization stage, the first service obtains a security code from the second service. Specifically, it first sends a security code acquisition request to the second service and then receives the security code sent by the second service. After that, it receives the encrypted data packet sent by the second service during implementation. Among them, the security code is the unique identifier in the entire system of the transferred data, and the received security code can be stored in the first service in the form of key-value pairs. The encrypted data packet is obtained by the second service encrypting the transferred data using the security code.

[0047] In addition, to ensure the security of other data of the first service, the first service receives and temporarily stores the encrypted data packet sent by the second service in the boundary area.

[0048] During the temporary storage process, the encrypted data packet is subjected to a legality check. If the check result is legal, the transferred data is transferred to the interior of the first service for processing. If the check result is illegal, the summary information of the encrypted data packet is recorded and the encrypted data packet is discarded for subsequent auditing and early warning processing. Among them, the summary information may include, but is not limited to, the source routing information of the encrypted data packet, the length information of the encrypted data packet, the reception time information of the encrypted data packet, whether the internal data of the encrypted data packet contains meaningless characters, etc.

[0049] In one embodiment, to improve the efficiency of data transfer, encryption, and decryption, the legality check of the encrypted data packet may include:

[0050] Check the length information of the encrypted data packet. When the length information of the encrypted data packet is less than the preset threshold, it is determined that the legality check result of the encrypted data packet is illegal.

[0051] For example, it is set that the length of the encrypted data packet must be greater than 64 bytes, otherwise it is illegal data, that is, the legality check result of the encrypted data packet is illegal.

[0052] For the data packet with a legal legality check result, decryption processing is performed inside the first service. During implementation, the encrypted data packet is decrypted using the security code sent by the second service to obtain the transferred data.

[0053] In one embodiment, the encrypted data packet is obtained by the second service encrypting the transferred data using the national secret symmetric encryption and decryption SM4 algorithm with the security code;

[0054] Decrypting the encrypted data packet using the security code to obtain the transferred data may include:

[0055] Using the SM4 algorithm, decrypt the encrypted data packet with the security code to obtain the transferred data.

[0056] In this example, the SM4 algorithm is adopted, which can ensure the security of data transmission while reducing the data transmission cost and improving the efficiency of data transmission, encryption, and decryption in emergency location services.

[0057] In one embodiment, decrypting the encrypted data packet with the security code to obtain the transmission data may include:

[0058] Decrypt the encrypted data packet with the security code. If the encrypted data packet cannot be decrypted, the encrypted data packet is illegal data. Record the digest information of the encrypted data packet and discard the encrypted data packet. If the encrypted data can be decrypted, it is legal data. For example, if the internal data of the encrypted data packet contains empty or other meaningless characters, such as data with the pattern FFFFF / DDDDD, it is determined that such an encrypted data packet is illegal. Record the digest information of the encrypted data packet and discard the encrypted data packet. This can facilitate subsequent auditing and early warning processing.

[0059] In one embodiment, after obtaining the transmission data, it may further include:

[0060] Statistically analyze the digest information of the undecryptable encrypted data packets by different time periods and display it to the user in the form of a trend curve and / or a heat map.

[0061] During implementation, an audit processor can be set up inside the first service to audit the stored encrypted data packets, including statistics on the routing source of the encrypted data packets, the size of the encrypted data packets, the frequency of illegal encrypted data packets, the proportion of illegal encrypted data packets, etc., for subsequent operation and maintenance processing.

[0062] 1) Draw the frequency data of illegal encrypted data packets per hour, per day, and per month into a trend curve to determine whether the system has maliciously or deliberately consumed server resources or wasted server resources.

[0063] 2) Group and statistically analyze the routing IP sources of the encrypted data packets to determine approximately which regions the illegal encrypted data packets come from and display them as a heat map on the map.

[0064] In one embodiment, to improve the security of data during transmission, the second service updates the security code regularly. The first service will regularly initiate routing and send a security code acquisition request to the second service through the application programming interface (API) at regular intervals; then receive the updated security code sent by the second service through the API. Correspondingly, after the first service passes the legality detection, it decrypts the encrypted data packet with the updated security code to obtain the transmission data.

[0065] During implementation, the security code can be a Universally Unique Identifier (UUID), which is automatically generated by the machine at regular intervals. After each new security code is generated, the second service waits for the first service to obtain the latest security code and then uses the latest security code. If the first service has not obtained the latest security code from the second service through the API, the second service does not use the latest security code and continues to use the previous security code for encryption.

[0066] When the first service obtains the latest security code, the second service can mark the currently used security code, that is, the latest security code, and use the marked latest security code for encryption during encryption. The first service uses the latest security code for decryption.

[0067] Figure 2 It is a schematic flowchart of the data transmission method applied to the second service in the embodiment of the present invention. As Figure 2 shown, the method includes:

[0068] Step 201: Generate a security code and provide the security code to the first service according to the security code acquisition request of the first service;

[0069] Step 202: Encrypt the transmission data using the security code to obtain an encrypted data packet;

[0070] Step 203: Send the encrypted data packet to the first service so that the first service: receives the encrypted data packet in the boundary area, performs a legality check on the encrypted data packet, and when the check result is legal, decrypts the encrypted data packet using the security code to obtain the transmission data.

[0071] From Figure 2 As can be seen from the above process, in the embodiment of the present invention, the second service transmits data to the first service. The security code is generated in the initialization stage, and the security code is provided to the first service according to the security code acquisition request of the first service. After that, the second service encrypts the transmission data using the security code and sends the encrypted data packet to the first service for the first service to decrypt the encrypted data packet, ensuring the security of data transmission. At the same time, the data encryption and decryption process is simple, reducing the development cost of data transmission and improving the efficiency of data transmission, encryption, and decryption in emergency location services.

[0072] The data transmission method applied to the second service in the embodiment of the present invention will be explained in detail below.

[0073] When the second service transfers data to the first service, in the initialization stage, the second service generates a security code. The first service requests the security code from the second service, and the second service provides the security code to the first service according to the security code acquisition request of the first service. The second service encrypts the transferred data using the security code to obtain an encrypted data packet, and sends the encrypted data packet to the first service, so that the first service: receives the encrypted data packet in the boundary area, performs a legality check on the encrypted data packet, and when the check result is legal, decrypts the encrypted data packet using the security code to obtain the transferred data. Among them, the security code is the unique identifier in the entire system of the transferred data.

[0074] In one embodiment, in order to improve the security of data during transmission, the second service updates the security code regularly and provides the updated security code to the first service according to the security code acquisition request of the first service. During implementation, the first service will regularly trigger the routing and send a security code acquisition request to the second service through the API; then receive the updated security code sent by the second service through the API. Correspondingly, the second service will encrypt the transferred data using the updated security code to obtain an encrypted data packet.

[0075] During implementation, the security code can be a UUID, which is automatically generated by the machine at regular intervals. After each new security code is generated, wait for the first service to obtain the latest security code, and then the second service uses the latest security code. If the first service has not obtained the latest security code from the second service through the API, the second service does not use the latest security code either, and always uses the previous security code for encryption.

[0076] In one embodiment, encrypting the transferred data using the updated security code to obtain an encrypted data packet may include:

[0077] Use the SM4 algorithm to encrypt the transferred data using the updated security code to obtain an encrypted data packet. Correspondingly, the first service also uses the SM4 algorithm to decrypt the encrypted data packet using the security code.

[0078] In this example, using the SM4 algorithm can ensure the security of data transmission while reducing the data transmission cost and improving the efficiency of data transmission and encryption / decryption in emergency location services.

[0079] In summary, the embodiments of the present invention are applied between different services in an emergency location service system. When transmitting data through the network, while ensuring data security as efficiently as possible, the transmitted data is encrypted, and the transmitted data can be traced and audited, fully ensuring the security of data transmission. At the same time, the data encryption / decryption process is simple, reducing the data transmission development cost and improving the efficiency of data transmission and encryption / decryption in emergency location services.

[0080] An embodiment of the present invention also provides a data transmission device as described in the following embodiments. Since the principle of this device for solving problems is similar to that of the data transmission method, the implementation of this device can refer to the implementation of the data transmission method, and the repeated parts will not be elaborated.

[0081] Figure 3 It is a schematic diagram of a data transmission device applied to the first service in an embodiment of the present invention. As Figure 3 shown, the device includes:

[0082] A security code receiving module 301, configured to send a security code acquisition request to the second service; receive the security code sent by the second service;

[0083] An encrypted data packet receiving module 302, configured to receive the encrypted data packet sent by the second service in the boundary area of the first service; the encrypted data packet is obtained by the second service encrypting the transmission data using the security code;

[0084] A legality detection module 303, configured to perform a legality detection on the encrypted data packet, and when the detection result is illegal, record the digest information of the encrypted data packet and discard the encrypted data packet;

[0085] A decryption module 304, configured to decrypt the encrypted data packet using the security code to obtain the transmission data when the detection result is legal.

[0086] In one embodiment, the security code receiving module 301 is specifically configured to:

[0087] Send a security code acquisition request to the second service regularly through the API;

[0088] Receive the updated security code sent by the second service regularly through the API;

[0089] The decryption module 304 is specifically configured to:

[0090] When the detection result is legal, decrypt the encrypted data packet using the updated security code to obtain the transmission data.

[0091] In one embodiment, the digest information includes one or any combination of the following:

[0092] The source routing information of the encrypted data packet, the length information of the encrypted data packet, the reception time information of the encrypted data packet, whether the internal data of the encrypted data packet contains meaningless characters.

[0093] In one embodiment, the legality detection module 303 is specifically configured to:

[0094] Detect the length information of the encrypted data packet, and when the length information of the encrypted data packet is less than the preset threshold, determine that the legality detection result of the encrypted data packet is illegal.

[0095] In one embodiment, the preset threshold is 64.

[0096] In one embodiment, the encrypted data packet is obtained by the second service using the SM4 algorithm to encrypt the transmission data with a security code.

[0097] The decryption module 304 is specifically configured to:

[0098] Use the SM4 algorithm to decrypt the encrypted data packet with the security code to obtain the transmission data.

[0099] In one embodiment, the decryption module 304 is specifically configured to:

[0100] Decrypt the encrypted data packet with the security code. If the encrypted data packet cannot be decrypted, record the digest information of the encrypted data packet and discard the encrypted data packet.

[0101] In one embodiment, the apparatus further includes:

[0102] A statistical analysis module, configured to, after the decryption module 304 obtains the transmission data, statistically analyze the digest information of the undecryptable encrypted data packets in different time periods and display it to the user in the form of a trend curve and / or a heat map.

[0103] Figure 4 The figure is a schematic diagram of a data transmission apparatus applied to the second service in an embodiment of the present invention. As Figure 4 shown, the apparatus includes:

[0104] A security code processing module 401, configured to generate a security code and provide the security code to the first service according to a security code acquisition request of the first service.

[0105] An encryption module 402, configured to encrypt the transmission data with the security code to obtain an encrypted data packet.

[0106] A data sending module 403, configured to send the encrypted data packet to the first service, so that the first service: receives the encrypted data packet in the boundary area, performs a legality detection on the encrypted data packet, and when the detection result is legal, decrypts the encrypted data packet with the security code to obtain the transmission data.

[0107] In one embodiment, the security code processing module 401 is specifically configured to:

[0108] Regularly update the security code and provide the updated security code to the first service according to a security code acquisition request of the first service.

[0109] The encryption module 402 is specifically configured to:

[0110] Encrypt the transmission data using the updated security code to obtain an encrypted data packet.

[0111] In one embodiment, the encryption module 402 is specifically configured to:

[0112] Use the SM4 algorithm to encrypt the transmission data using the updated security code to obtain an encrypted data packet.

[0113] Figure 5 Schematic diagram of the computer device in the embodiment of the present invention, as Figure 5 shown, the embodiment of the present invention also provides a computer device 500, including a processor 501, a memory 502, and a computer program 503 stored on the memory 502 and executable on the processor 501. When the processor 501 executes the computer program 503, the above data transmission method is implemented.

[0114] The embodiment of the present invention also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the above data transmission method is implemented.

[0115] The embodiment of the present invention also provides a computer program product. The computer program product includes a computer program, and when the computer program is executed by a processor, the above data transmission method is implemented.

[0116] In the embodiment of the present invention, the first service receives the security code sent by the second service; receives the encrypted data packet sent by the second service in the boundary area of the first service; the encrypted data packet is obtained by the second service encrypting the transmission data using the security code; performs a legality check on the encrypted data packet. When the check result is illegal, records the summary information of the encrypted data packet and discards the encrypted data packet; when the check result is legal, decrypts the encrypted data packet using the security code to obtain the transmission data. In the embodiment of the present invention, the second service transmits data to the first service. The second service first generates a security code. The first service obtains the security code from the second service during the initialization phase. Then the second service encrypts the transmission data using the security code. The first service receives the encrypted data packet in the boundary area and performs a legality check on the encrypted data packet. After the legality check is legal, decryption is performed, which ensures the security of data transmission. At the same time, the data encryption and decryption process is simple, reducing the data transmission development cost and improving the efficiency of data transmission, encryption, and decryption in emergency location services.

[0117] In an embodiment of the present invention, a second service generates a security code and sends the security code to a first service; encrypts transmission data by using the security code to obtain an encrypted data packet; and sends the encrypted data packet to the first service, so that the first service: receives the encrypted data packet in a boundary area, performs a legality check on the encrypted data packet, and when the check result is legal, decrypts the encrypted data packet by using the security code to obtain the transmission data. In the embodiment of the present invention, data is transmitted from the second service to the first service. A security code is generated in an initialization phase, and the security code is provided to the first service according to a security code acquisition request of the first service. After that, the second service encrypts the transmission data by using the security code and sends the encrypted data packet to the first service for the first service to decrypt the encrypted data packet, ensuring the security of data transmission. At the same time, the data encryption and decryption process is simple, reducing the data transmission development cost and improving the efficiency of data transmission, encryption, and decryption in emergency location services.

[0118] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0119] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, as well as the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the specified functions in Figure 1 one or more of the processes Figure 1 or multiple processes and / or blocks

[0120] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device implements the specified functions in Figure 1 one or more of the processes Figure 1 or multiple processes and / or blocks

[0121] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus, so that a series of operation steps are performed on the computer or other programmable apparatus to produce a computer-implemented process, and thus the instructions executed on the computer or other programmable apparatus provide steps for implementing the functions specified in one process or a plurality of processes and / or blocks Figure 1 one process or a plurality of processes and / or blocks Figure 1 steps for implementing the functions specified in one block or a plurality of blocks.

[0122] The specific embodiments described above further elaborate on the objectives, technical solutions, and beneficial effects of the present invention. It should be understood that the above description is only for the specific embodiments of the present invention and is not intended to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included within the protection scope of the present invention.

Claims

1. A data transmission method, characterized in that, Applied to the first service, including: Sending a security code acquisition request to the second service; Receiving the security code sent by the second service; Receiving the encrypted data packet sent by the second service in the boundary area of the first service; the encrypted data packet is obtained by the second service encrypting the transmission data using the security code; Performing a legality detection on the encrypted data packet, and when the detection result is illegal, recording the digest information of the encrypted data packet and discarding the encrypted data packet; When the detection result is legal, decrypting the encrypted data packet using the security code to obtain the transmission data.

2. The method according to claim 1, characterized in that Sending a security code acquisition request to the second service, including: Regularly sending a security code acquisition request to the second service through the application programming interface (API); Receiving the security code sent by the second service, including: Regularly receiving the updated security code sent by the second service through the API; When the detection result is legal, decrypting the encrypted data packet using the security code to obtain the transmission data, including: When the detection result is legal, decrypting the encrypted data packet using the updated security code to obtain the transmission data.

3. The method according to claim 1, wherein The digest information includes one or any combination of the following: The source routing information of the encrypted data packet, the length information of the encrypted data packet, the reception time information of the encrypted data packet, whether the internal data of the encrypted data packet contains meaningless characters.

4. The method according to claim 1, characterized in that, Performing a legality detection on the encrypted data packet, including: Detecting the length information of the encrypted data packet, and when the length information of the encrypted data packet is less than the preset threshold, determining that the legality detection result of the encrypted data packet is illegal.

5. The method according to claim 4, characterized in that, The preset threshold is 64.

6. The method according to claim 1, wherein The encrypted data packet is obtained by the second service encrypting the transmission data using the Guomi symmetric encryption and decryption SM4 algorithm with the security code; Decrypting the encrypted data packet using the security code to obtain the transmission data, including: Using the SM4 algorithm to decrypt the encrypted data packet using the security code to obtain the transmission data.

7. The method according to claim 1, characterized in that Decrypting the encrypted data packet using the security code to obtain the transmission data, including: Decrypting the encrypted data packet using the security code, and if the encrypted data packet cannot be decrypted, recording the digest information of the encrypted data packet and discarding the encrypted data packet.

8. The method according to claim 7, wherein After obtaining the transmission data, it further includes: Statistically analyzing the digest information of the undecryptable encrypted data packets in different time periods and presenting it to the user in the form of a trend curve and / or a heat map.

9. A data transmission method, characterized in that, Applied to the second service, including: Generating a security code and providing the security code to the first service according to the security code acquisition request of the first service; Encrypting the transmission data using the security code to obtain an encrypted data packet; Sending the encrypted data packet to the first service so that the first service: receives the encrypted data packet in the boundary area, performs a legality detection on the encrypted data packet, and when the detection result is legal, decrypts the encrypted data packet using the security code to obtain the transmission data.

10. The method according to claim 9, characterized in that Generating a security code and providing the security code to the first service according to the security code acquisition request of the first service, including: Regularly updating the security code and providing the updated security code to the first service according to the security code acquisition request of the first service; Encrypting the transmission data using the security code to obtain an encrypted data packet, including: Encrypting the transmission data using the updated security code to obtain an encrypted data packet.

11. The method according to claim 10, wherein Encrypt the transmission data using the updated security code to obtain an encrypted data packet, including: Use the SM4 algorithm to encrypt the transmission data using the updated security code to obtain an encrypted data packet.

12. A data transmission device, characterized in that, Applied to the first service, including: A security code receiving module, configured to send a security code acquisition request to the second service; receive the security code sent by the second service; An encrypted data packet receiving module, configured to receive the encrypted data packet sent by the second service in the boundary area of the first service; the encrypted data packet is obtained by the second service encrypting the transmission data using the security code; A legality detection module, configured to perform a legality detection on the encrypted data packet, and when the detection result is illegal, record the digest information of the encrypted data packet and discard the encrypted data packet; A decryption module, configured to, when the detection result is legal, decrypt the encrypted data packet using the security code to obtain the transmission data.

13. The device according to claim 12, characterized in that, Specifically, the security code receiving module is used for: Regularly send a security code acquisition request to the second service through the API; Regularly receive the updated security code sent by the second service through the API; Specifically, the decryption module is used for: When the detection result is legal, decrypt the encrypted data packet using the updated security code to obtain the transmission data.

14. The device according to claim 12, characterized in that, The digest information includes one or any combination of the following: The source routing information of the encrypted data packet, the length information of the encrypted data packet, the reception time information of the encrypted data packet, whether the internal data of the encrypted data packet contains meaningless characters.

15. The device according to claim 12, characterized in that Specifically, the legality detection module is used for: Detect the length information of the encrypted data packet, and when the length information of the encrypted data packet is less than a preset threshold, determine that the legality detection result of the encrypted data packet is illegal.

16. The device according to claim 15, characterized in that, The preset threshold is 64.

17. The device according to claim 12, characterized in that, The encrypted data packet is obtained by the second service encrypting the transmission data using the SM4 algorithm and the security code; Specifically, the decryption module is used for: Use the SM4 algorithm to decrypt the encrypted data packet using the security code to obtain the transmission data.

18. The device according to claim 12, characterized in that, Specifically, the decryption module is used for: Decrypt the encrypted data packet using the security code. If the encrypted data packet cannot be decrypted, record the digest information of the encrypted data packet and discard the encrypted data packet.

19. The device according to claim 18, characterized in that, It further includes: A statistical analysis module, configured to, after the decryption module obtains the transmission data, statistically analyze the digest information of the undecryptable encrypted data packets in different time periods and display it to the user in the form of a trend curve and / or a heat map.

20. A data transmission device, characterized in that, Applied to the second service, including: A security code processing module, configured to generate a security code and provide the security code to the first service according to the security code acquisition request of the first service; An encryption module, configured to encrypt the transmission data using the security code to obtain an encrypted data packet; A data sending module, configured to send the encrypted data packet to the first service, so that the first service: receive the encrypted data packet in the boundary area, perform a legality detection on the encrypted data packet, and when the detection result is legal, decrypt the encrypted data packet using the security code to obtain the transmission data.

21. The device according to claim 20, characterized in that Specifically, the security code processing module is used for: Regularly update the security code and provide the updated security code to the first service according to the security code acquisition request of the first service; Specifically, the encryption module is used for: Encrypt the transmission data using the updated security code to obtain an encrypted data packet.

22. The device according to claim 21, characterized in that, Specifically, the encryption module is used for: Using the SM4 algorithm, encrypt the transmitted data with the updated security code to obtain an encrypted data packet.

23. A computer device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the method according to any one of claims 1 to 11.

24. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the method according to any one of claims 1 to 11.

25. A computer program product, characterized in that, The computer program product includes a computer program, and when the computer program is executed by a processor, it implements the method according to any one of claims 1 to 11.