Domestic instant messaging security framework adaptive to'swan mongolian 'operating system
By designing an instant messaging security framework that is adapted to the "Hongmeng" operating system, the existing framework cannot adapt and has weak security has been solved, the full process security mechanism is realized, and it is adapted to the domestic ecosystem. It provides functions such as information encryption and decryption, identity authentication and equipment control to ensure the security and privatization of communication.
Patent Information
- Application Number
- CN202510534981.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-27
- Publication Date
- 2025-07-11
AI Technical Summary
The existing instant messaging framework has not been fully adapted to the new generation of "Hongmeng" operating system, and its security is weak and cannot meet the needs of mobile collaborative office scenarios with high security requirements.
A domestic instant messaging security framework that is adapted to the "Hongmeng" operating system is designed, including communication interaction modules, information encryption and decryption modules, signaling encryption and decryption modules, identity authentication modules, equipment control modules, login control modules and connection control modules. Through component packaging and modular design, information encryption and decryption, identity authentication, device management and connection auditing functions are realized to ensure the security and controllability of the communication process.
The full-process security mechanism on the "Hongmeng" operating system is realized, and mechanisms such as signaling and information encryption, networked identity authentication, equipment control, and communication control are provided, ensuring the security and privatized deployment of communications, adapting to the domestic ecosystem, supporting privatized deployment, and ensuring the purity and security of the communication network.
Smart Images

Figure CN120301668A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a domestic instant messaging security framework adapted to the "Hongmeng" operating system, specifically to a domestic instant messaging security framework adapted to the "Hongmeng" operating system. Background Art
[0002] The information technology application innovation industry, also known as the Xinchuang industry, encompasses the security and controllability of the entire industrial chain from basic software and hardware at the bottom layer of IT to application software at the upper layer.
[0003] The industries involved in the Xinchuang industry include IT infrastructure: CPU chips, servers, storage, switches, routers, various clouds, and related service contents; basic software: databases, operating systems, middleware; application software: OA, ERP, office software, government applications; information security: perimeter security products, endpoint security products, etc. Currently, the achievements of domesticating desktop operating systems mainly include operating systems such as Kirin and Tongxin, which have gradually become mature and stable. However, the domestication of mobile operating systems is still in the stage of research and commercial preparation.
[0004] Among them, the new generation of the "Hongmeng" (Harmony OS NEXT) operating system is a domestic operating system independently developed by Huawei and was released on August 4, 2023. This system is the first major version of Hongmeng to abandon codes such as the Linux kernel and the Android Open Source Project (AOSP). This system only supports applications with the Hongmeng kernel and the Hongmeng system and is no longer compatible with Android applications. It is reported that in 2012, Huawei began planning to develop its own operating system. On August 9, 2019, Huawei's Harmony OS 1.0 was officially released. In the following years, the Hongmeng system was successively updated with several major versions such as Harmony OS 2.0, Harmony OS 3.0, and Harmony OS 4.0. Since the second half of 2023, Huawei's Hongmeng system has started to focus on the software ecosystem and pay attention to expanding native Hongmeng applications. On August 4, 2023, Huawei launched the Harmony OS NEXT Developer Preview. On January 18, 2024, the Harmony OS NEXT Star River Edition was officially opened for application to developers.
[0005] The implementation of the domestic "Hongmeng" operating system is the first step in promoting the domestication of mobile operating systems. The development of software and applications adapted to the domestic "Hongmeng" operating system helps to strengthen the ecological environment and promotion application foundation of the domestic mobile operating system.
[0006] At present, mobile collaborative office work is booming, and instant messaging software is an important part of the mobile collaborative office ecosystem. In units with high security requirements, the exclusivity of communication data, the security of the communication process, and the rigor of communication management all drive users to pursue the security of application systems while seeking private deployment and domestic adaptation. Therefore, building a domestic-adapted, simple-to-use, secure and controllable, exclusive instant messaging framework helps to ensure that government agencies and enterprises and institutions improve their office efficiency and promote the further development of mobile office work.
[0007] Traditional instant messaging frameworks are adapted to operating systems such as WINDOWS, LINUX, and ANDROID. So far, there is no instant messaging framework that is fully adapted to the new generation of "HarmonyOS" operating system. The functions of traditional instant messaging frameworks are concentrated on information interaction, providing convenience for information interaction, but they are relatively weak in the overall security system. This framework helps government agencies to achieve instant messaging and synchronous office work around mobile office technology, aiming to meet the usage requirements of users for communication software in different business scenarios. It can be adapted to the new generation of "HarmonyOS" operating system and can be deployed in the domestic server software and hardware environment. This framework has achieved a breakthrough in adapting to the "HarmonyOS" operating system, and through the combined use of information encryption and decryption modules, signaling encryption and decryption modules, identity authentication modules, device control modules, login control modules, communication control modules, and communication audit modules, different levels of security requirements can be achieved according to user needs. Summary of the Invention
[0008] To solve related problems, the present invention provides a domestic instant messaging security framework adapted to the "HarmonyOS" operating system.
[0009] The present invention is realized through the following technical solutions: A domestic instant messaging security framework adapted to the "HarmonyOS" operating system is composed of a communication interaction module (1), an information encryption and decryption module (2), a signaling encryption and decryption module (3), an identity authentication module (4), a device control module (5), a login control module (6), a communication control module (7), and a communication audit module (8). Each module can work independently or in combination and cooperation, and can fully realize the security of instant messaging communication devices and communication security adapted to the new generation of the "HarmonyOS" operating system. Among them, the login control module (6) needs to be used in combination with the identity authentication module (4) and the device control module (5), and the communication control module (7) is the basis of the communication audit module (8) and supports private deployment. It is characterized in that: the aforementioned communication interaction module (1) uses the "HarmonyOS" software development environment (IDE), targets the IM SDK component, and performs IMHAR development and adaptation transformation, realizing that the front-end transformed by "HarmonyOS" can quickly perform instant information interaction through the IM HAR component; the aforementioned information encryption and decryption module (2) uses a component encapsulation method to encrypt and decrypt the information of instant messaging through an encryption interface and a decryption interface, strengthening the security of instant messaging software. The information encryption and decryption module supports and integrates various national cryptography algorithms; the aforementioned signaling encryption and decryption module (3) uses a component encapsulation method and combines methods such as mixed coding, encryption and decryption algorithms, and one-time passwords to encrypt and confuse both parties of the communication and the communication method during the handshake of instant messaging, ensuring communication security and information interaction method switching in an insecure network environment; the aforementioned identity authentication module (4) verifies the data such as the identity and identity authentication input by the user based on the authentication information of the terminal application user stored on the server side, ensuring that only authorized users can log in and join the communication network for communication; the aforementioned device control module (5) is based on the C / S architecture, stores device information on the server side, and can monitor the status of devices intended to log in to the communication network, ensuring that the use of relevant devices is in a controllable state, preventing information leakage problems caused by device loss, and at the same time ensuring that only authorized devices can join the communication network; the aforementioned login control module (6) is based on the device control module (5) and the identity authentication module (4), and can jointly inspect the devices and users intended to log in to the communication network, ensuring that only authorized users using the user's device can log in and use the communication network; the aforementioned communication control module (7) uses a one-time authorization mechanism to authorize the communication interaction of users and prevent users from sending information to another user without authorization; the aforementioned communication audit module (8) audits the communication of users based on communication logs to ensure that the information sent after authorization complies with the authorization.
[0010] The aforementioned communication interaction module (1) is characterized in that: the use of the "HarmonyOS" software development environment (IDE) refers to the use of the one-stop integrated development environment (IDE) DevEco Device Tool provided by Huawei specifically for software developers participating in the adaptation of the new generation of "HarmonyOS NEXT" mobile operating system; the development and adaptation transformation of IM HAR by benchmarking the IM SDK component means adapting the original IM SDK adapted to the Android side, generating a HAR package, and enabling it to run on the new generation of "HarmonyOS" operating system; the necessity of the aforementioned transformation is that the new generation of "HarmonyOS" operating system is no longer compatible with the Android operating system, that is, software originally running on Android cannot run on the domestic "HarmonyOS" mobile operating system without undergoing adaptation transformation on the "HarmonyOS" side; the aforementioned communication interaction module consists of an IM HAR client, an IM HAR server, and an IM HAR management end. Among them, the IM HAR client is responsible for signaling and information interaction, the IM HAR server is responsible for information management, and the IM HAR management end is responsible for the management of basic information such as instant messaging personnel and organizations.
[0011] The aforementioned information encryption and decryption module (2) is characterized in that: in the form of component encapsulation, through the encryption interface and the decryption interface, the encryption and decryption of instant messaging information are realized. The information encryption and decryption module supports and integrates various national cryptography algorithms, which means encapsulating various national cryptography algorithms and integrating them into the aforementioned IM HAR client (9) in the form of components or microservices. Before information is sent, the encryption algorithm is called to encrypt the information to be sent. When information is received, the decryption algorithm is called to decrypt the received information, so as to achieve the confidentiality of information during the flow on the network.
[0012] The aforementioned signaling encryption and decryption module (3) is characterized in that: in the form of component encapsulation, a combination of scrambling, encryption and decryption algorithms, one-time passwords, etc. are used to encrypt and confuse the two parties in communication and the communication method, etc. when an instant messaging handshake is initiated. It means adding a scrambling code first, and then encrypting the signaling through a one-time encryption method. After the receiver receives the signaling, it is solved according to the agreed one-time decryption method, and the signaling is restored by removing the scrambling code, so as to ensure that after a network attacker obtains the signaling through means such as sniffing, it cannot be decrypted. Even if it is decrypted, it only affects the current communication. The signaling encryption and decryption module (3) is also encapsulated in the IM HAR client (9).
[0013] The aforementioned identity authentication module (4) is characterized in that: the verification of data such as the identity and identity verification input by the user based on the authentication information of the terminal application user stored on the server means that data such as the user's password and biometric code are collected in advance at the application end and uploaded to the server for storage. When the user performs identity authentication at the application end, the password and biometric code data input during authentication are compared with the password and biometric code stored on the server. If they are consistent, the identity verification passes, and the user is authorized to use the relevant modules of the application based on the relevant configurations of the server. If they are inconsistent, the user is not allowed to log in and use the application.
[0014] The aforementioned device management and control module (5) is characterized in that: device information is stored on the server, and the status of the device to be logged in to the communication network can be supervised. This means that the unique identifier of the device is generated / collected / obtained at the application end and uploaded to the server for storage and custody. The unique identifier does not change with the uninstallation of the application. When the device is lost or in other situations, the server can disable the relevant device. After the device is disabled, when the application end uses the device for identity verification, a prompt that the device is disabled is returned, thereby preventing unauthorized personnel from using the relevant device to log in to the network for social attacks.
[0015] The aforementioned login management and control module (6) is characterized in that: the joint inspection of the device and the user to be logged in to the communication network means that the user authentication information and user device information are pre-stored on the server. When the user logs in and uses the application, the user needs to verify the identity and the device in sequence. Only when both verifications pass can the user log in and use the application. The core is "one person, one device".
[0016] The aforementioned communication management and control module (7) is characterized in that: by default, users cannot send or receive messages / files. Each time they send or receive messages / files, they need to apply for the sending and receiving permissions, and they can send and receive messages only when they obtain permission. The communication management and control can achieve control in various dimensions such as sequentially, time period, and object. It should be noted that the communication management and control module is usually only used in scenarios with a relatively high classification level and is often used together with the communication audit module (8) to achieve "apply before use, audit after use".
[0017] The aforementioned communication audit module (8) is characterized in that: it audits the communication parties, communication time, and communication content of the authorized sending and receiving of messages / files to ensure that the relevant content complies with the application. It is often used together with the communication management and control module (7) in scenarios with a relatively high classification level to achieve "apply before use, audit after use".
[0018] Compared with the traditional instant messaging framework, the beneficial effects of the present invention are: It is adapted to the domestic "HarmonyOS" mobile operating system and is adapted to the fully domestic mobile terminal; A full - process security mechanism for the communication process is provided, including signaling and information encryption mechanisms, networked identity authentication mechanisms, device control mechanisms, login control mechanisms, communication control mechanisms, and communication audit mechanisms, realizing the overall security control of personnel, devices, applications, and communications; It is fully adapted to the domestic ecological environment and supports private deployment, that is, it supports the privacy of instant messaging tool data, encryption method privacy, key privacy, and channel privacy, thus ensuring the purity and security of the communication network. Description of the Drawings
[0019] Figure 1 Process description for the specific implementation of the communication interaction module of the domestic instant messaging security framework adapted to the "HarmonyOS" operating system Figure 2 Process description for the specific implementation of the information encryption and decryption module of the domestic instant messaging security framework adapted to the "HarmonyOS" operating system Figure 3 Process description for the specific implementation of the signaling encryption and decryption module of the domestic instant messaging security framework adapted to the "HarmonyOS" operating system Figure 4 Process description for the specific implementation of the identity authentication module of the domestic instant messaging security framework adapted to the "HarmonyOS" operating system Figure 5 Process description for the specific implementation of the device control module of the domestic instant messaging security framework adapted to the "HarmonyOS" operating system Figure 6 Process description for the specific implementation of the login control module of the domestic instant messaging security framework adapted to the "HarmonyOS" operating system Figure 7 Process description for the specific implementation of the communication control module of the domestic instant messaging security framework adapted to the "HarmonyOS" operating system Figure 8 Process description for the specific implementation of the communication audit module of the domestic instant messaging security framework adapted to the "HarmonyOS" operating system Figure 9 Explanation that the module combination of the domestic instant messaging security framework adapted to the "HarmonyOS" operating system can work independently or in combination and cooperation. Specific Embodiment
[0020] Next, the specific embodiments of the present invention will be clearly and detailedly described in conjunction with the drawings of the present invention. The described embodiments are only a part of the embodiments of the present invention.
[0021] The technical solution of the present invention to solve the above technical problems is: A domestic instant messaging security framework adapted to the "HarmonyOS" operating system, which is composed of a communication interaction module, an information encryption and decryption module, a signaling encryption and decryption module, an identity authentication module, a device management and control module, a login management and control module, a communication management and control module, and a communication audit module. Each module can work independently or in combination and cooperation, and can fully realize the security of instant messaging communication devices and communication security adapted to the new generation of "HarmonyOS" operating system. Among them, the login management and control module needs to be used in combination with the identity authentication module and the device management and control module, and the communication management and control module is the basis of the communication audit module.
[0022] (1) Communication interaction module The communication interaction module is the core component of this application. It is responsible for processing data transmission and communication between the APP and the server or other devices. This module is based on the MQTT communication protocol and network protocol, and integrates the SDK on the basis of the HarmonyOS syntax; in terms of security, it supports SSL / TLS encryption, and undergoes multiple encoding and transcoding before transmission to ensure the security and data integrity of the data transmission process.
[0023] In terms of the starting point of adapting to the HarmonyOS system, the integration difficulty is relatively high; in terms of the requirement of supporting multiple data formats, the implementation of the module is also relatively complex, and it is difficult to develop and maintain; in high-concurrency scenarios, the communication interaction module may become a performance bottleneck, especially when dealing with a large amount of data transmission. In order to ensure security and real-time performance, it may increase the consumption of network bandwidth and server resources. Although based on standard protocols, there may still be compatibility problems in actual applications, especially in cross-platform or cross-device situations.
[0024] This communication interaction module mainly realizes SDK integration based on the MQTT communication protocol, and enhances the allocation of capabilities such as connection management, topic subscription, multi-type data transmission, and error handling and reconnection on its extension module. The specific steps include: 1. Realize the synchronous migration of native APIs from the Android side to the HarmonyOS side, covering code migration from JavaScript to ArkTs and custom optimization of data classes; 2. The front and back ends jointly adapt to multiple open-source protocols to meet communication requirements from the aspects of compatibility, instantaneity, security, and scalability; 3. Obtain messages from the server by subscribing to topics, and then decode the messages to realize data storage and UI rendering; multiple communication environments can be created through configuration; 4. Bidirectionally subscribe to message processing between the application and the communication interaction module, and control the communication connection and disconnection of the client between each other, and efficiently and instantaneously realize application exit and login.
[0025] The communication interaction module integrating the SDK has high stability and strong processing capabilities in handling the judgment of connection status, as well as in message compression, encryption, message sending and receiving judgment, and data transmission security for message sending and receiving. Moreover, the separated design has advantages in subsequent requirement customization and expansion.
[0026] (2)Information Encryption and Decryption Module Existing encryption and decryption mechanisms mainly rely on traditional symmetric encryption algorithms such as AES. This mechanism has advantages in encryption speed and decryption efficiency, but its security highly depends on the management of keys. Once the key is leaked, all information encrypted with this key will face the risk of being decrypted. In addition, when facing increasingly complex network attacks, the protection ability of traditional symmetric encryption algorithms appears relatively weak. Especially when facing brute-force cracking and man-in-the-middle attacks, the communication security of users cannot be fully guaranteed.
[0027] The information encryption and decryption module in this application is integrated and encapsulated based on the AES symmetric encryption algorithm and the RSA asymmetric encryption algorithm, combined with the security framework of the HarmonyOS system. Before and after data transmission, the module also adopts an additional hash verification mechanism to provide double protection for the security and integrity of the data. Although the encryption algorithm itself is universal, compatibility issues still need to be considered in specific applications, especially when interacting with other systems or services.
[0028] The core of the information encryption and decryption module lies in the implementation of efficient encryption algorithm integration and flexible policy management. The specific steps include: 1. Implement the adaptation of the encryption algorithm library from a general platform to the HarmonyOS platform, including the code migration from JavaScript to ArkTs and the optimization and adjustment of algorithm parameters; 2. Initialize the encryption context through the system security interface, create a key pair and store it securely to lay a foundation for subsequent encryption operations, and implement the security mechanisms for key generation, distribution, storage, and update. Ensure the security and availability of the key during its life cycle. 3. Encrypt sensitive data to ensure that it cannot be stolen or tampered with during storage or transmission; 4. Implement the automated management of the decryption process to ensure that the original information can be correctly and efficiently restored when the data is used, and at the same time monitor the exceptions during the decryption process and respond to security warnings in a timely manner.
[0029] This system equipped with an information encryption and decryption module demonstrates excellent stability and powerful processing capabilities in data protection. Whether in scenarios with high concurrency and large data volumes, the information encryption and decryption module can adopt efficient algorithms and hardware acceleration technologies to improve the overall performance of the system. Or through a reasonably designed key management mechanism, the information encryption and decryption module can reduce the complexity and risks of key management. In addition, the modular design adopted by the module makes subsequent security policy adjustments and function expansions more flexible and convenient.
[0030] (3) Signaling Encryption and Decryption Module The signaling encryption and decryption module is a key security component of this communication system. It focuses on ensuring the confidentiality, integrity, and authenticity of signaling data during transmission. This module is deeply integrated based on advanced encryption algorithms (such as ECC elliptic curve encryption) and signaling protocols (such as SIP protocol extensions), combined with the security mechanism of the HarmonyOS system. Before and after signaling transmission, the module also incorporates digital signature and message authentication code technologies, providing multiple guarantees for the security of signaling.
[0031] In the integrated environment of the HarmonyOS system, due to differences in system architecture and APIs, the implementation and optimization of signaling encryption and decryption algorithms face certain challenges. At the same time, to meet the security requirements in different communication scenarios, the module needs to support multiple encryption modes and key negotiation mechanisms, which increases the complexity of development and the workload of maintenance. In high-concurrency communication scenarios, the signaling encryption and decryption module may become a performance bottleneck, especially when processing a large amount of signaling data. To maintain efficient security protection, more computing resources and memory may be consumed. Although the encryption algorithms and signaling protocols themselves are general-purpose, compatibility issues still need to be considered in specific applications, especially when interacting with other communication systems or services.
[0032] The core of the signaling encryption and decryption module lies in the implementation of efficient encryption algorithm integration and flexible signaling processing strategies. The specific steps include: 1. Implement the migration and optimization of the encryption algorithm library from a general platform to the HarmonyOS platform, including code conversion from C language to ArkTs and fine-tuning of algorithm parameters; 2. The module designs a unified signaling encryption and decryption interface, shielding the complexity of underlying encryption algorithms and key management, enabling upper-layer applications to achieve cross-platform and cross-protocol communication security without caring about specific encryption details; 3. The module supports dynamic key updates and distribution, ensuring that during communication, even if the encryption algorithm is cracked, attackers cannot continuously obtain valid keys, thus greatly enhancing the security of communication; 4. The module adopts a modular design, supporting the rapid integration and deployment of new encryption algorithms and key management mechanisms, enabling the system to flexibly respond to new challenges in future communication security.
[0033] The introduction of this signaling encryption and decryption module has brought significant security and performance improvements to the communication system. On the one hand, through intelligent algorithm adaptation and unified interface design, the module effectively reduces the adaptation cost of cross-platform and cross-protocol communication, and improves the flexibility and scalability of the system. On the other hand, dynamic key updates and modular design enable the system to maintain a high level of security and stability and effectively resist various network attacks.
[0034] More importantly, the module supports multiple encryption modes, such as asymmetric encryption mode based on public key encryption, fast encryption mode based on symmetric encryption, etc. Users can flexibly choose the most suitable encryption mode according to specific application scenarios and security requirements to achieve dual protection of communication content and signaling. This innovative design not only improves the security of the communication system, but also provides users with a more convenient and efficient use experience.
[0035] (4) Identity authentication module The identity authentication module is a core component of the information security system. It is responsible for verifying the true identity of the user or device and ensuring that only authorized entities can access system resources. At the beginning of its design, this module was prepared for the subsequent integration of multiple identity authentication technologies, such as password verification, biometric recognition (such as fingerprint recognition, facial recognition), and digital certificate authentication, and is deeply integrated with the security framework of the Hongmeng system to provide users with a convenient and secure identity authentication experience.
[0036] In the integrated environment of Hongmeng system, the development of identity authentication module faces certain challenges. The current password login and its verification rules are only preliminary. Due to the particularity of system architecture and API, the authentication technology needs to be adapted and optimized to ensure its efficient operation. At the same time, in order to meet the needs of different user groups, the module needs to support multiple authentication methods and flexible authentication strategies, which increases the complexity of development and the workload of maintenance. In addition, in high-concurrency access scenarios, the performance of the identity authentication module may become a bottleneck of the system, and optimization measures need to be taken to improve the authentication speed and accuracy.
[0037] The implementation process of the identity authentication module involves several key links, including: 1. Technology selection and integration: Select appropriate identity authentication technology based on system requirements and security standards, and integrate it into the Hongmeng system. This includes docking with the system security interface, configuration of algorithm parameters, and customization of the authentication process; 2. User information management: Establish a user information database to store user identity information and authentication data (such as password hash values, biometric templates, etc.). At the same time, implement encrypted storage and access control of user information to ensure data security; 3. Identification process implementation: Implement the process of user authentication according to the selected identification technology. This includes steps such as receiving the identity information entered by the user, invoking the corresponding identification algorithm for verification, and returning the identification result; 4. Security enhancement: Implement additional security measures in the identification process, such as multi-factor authentication, brute-force attack prevention mechanism, and abnormal behavior detection, etc., to improve the overall security of the system.
[0038] This system equipped with an identity identification module performs excellently in identity security management. The multiple identification technologies adopted by the module provide users with flexible and secure identity authentication methods, while ensuring the accuracy and efficiency of the identification process. In addition, the module also has a powerful abnormal behavior detection ability and a brute-force attack prevention mechanism, effectively improving the security and stability of the system. Through continuous optimization and upgrade, the identity identification module can continuously adapt to new security threats and user needs, providing continuous and reliable identity security protection for the system.
[0039] (5) Device control module This module manages the login and usage of users on different devices to ensure the security of data transmission and the privacy of user information. The existing device control module ensures that users can switch between different devices while guaranteeing the security during data transmission by adopting end-to-end encryption and multi-platform login support. Due to the differences in hardware and software configurations of different devices, the device management module needs to adapt to the compatibility requirements of various devices, which may also lead to limited functions or degraded performance on certain devices. When monitoring the device status, the device management module needs to obtain key data such as the connection information and usage status of the device in real time. The existing methods rely on the device to actively report data or perform remote queries through network connections. It is vulnerable to network latency and interruptions, and may also result in inaccurate or lost data due to device failures or malicious attacks.
[0040] Specific implementation steps of the module: 1. Device information acquisition: Obtain the device information of the local machine by calling the APIs provided by the HarmonyOS, including device model, serial number, operating system version, etc.; 2. Device registration: Submit the obtained device information to the server for registration, and the server will assign a unique identifier to each device; 3. Device permission grouping: Divide the devices into different permission groups according to the type and usage of the devices. Each permission group will correspond to different access permissions and operation permissions; 4. Device upgrade and update: Administrators can update the version through the service system to push new software versions or patches to specific devices to improve the performance and security of the devices.
[0041] The APIs provided by the HarmonyOS, as a bridge connecting devices and managing systems, greatly simplify the process of obtaining device information, avoid the cumbersome traditional manual information input, and ensure device management. On this basis, administrators can further manage the permission grouping of different devices, set appropriate access and operation permissions for different types of devices according to actual needs, and achieve efficient and secure management. The application upgrade and update strategy ensures that users can easily obtain the latest software versions and security patches through the centralized management of different device permissions, thus maintaining the device performance and security in the best state. This strategy not only eliminates compatibility issues caused by inconsistent device versions but also saves the cumbersome steps of manually updating each device, significantly saving time and effort.
[0042] (6) Login Control Module This module manages user logins. Although the existing login module has certain advantages in terms of user experience and convenience, such as quickly responding to user login requests and providing basic account management functions, it has obvious deficiencies in terms of security and management. Its main deficiencies lie in the weakness in security, insufficient recording and maintenance of user login status, difficulty in effectively tracking and monitoring, lax session management, lack of an accurate user status tracking mechanism, and no setting of login timeout. Users can remain logged in even if they do not operate for a long time, increasing potential security threats.
[0043] Specific implementation steps of related modules: 1. Implement a user authentication mechanism through username, password, and verification code, encrypt and store the user password using an encryption algorithm, and perform real-time verification when the user enters login information; 2. Implement the recording and maintenance of login status, including information such as login time, login location, and login device; 3. Adopt session management technology to assign a unique session identifier to each logged-in user for tracking the user's login status and behavior; 4. Implement a login timeout mechanism to automatically log out the user's login status when the user uses the application for a period of time and require the user to re-enter login information; 5. Implement a login failure handling mechanism to limit the number of login attempts and lock abnormal accounts.
[0044] The login control module integrates multiple advantages and effectively improves the security of the system and the efficiency of user management. Through the composite identity authentication mechanism, combined with the encryption algorithm to store user passwords, the high security of the login process is ensured. At the same time, the module records and maintains the user's login status information in detail, including time, location and device details, providing a solid foundation for security audits. Each user is assigned a unique session identifier to achieve accurate tracking of user behavior. The introduced login timeout and failure processing mechanism not only automatically logs out idle users to prevent information leakage, but also effectively resists security risks such as brute force cracking by limiting the number of login attempts and locking abnormal accounts.
[0045] (7) Communication control module The communication control module is a key component in the communication system. It is responsible for monitoring and managing the establishment, maintenance and termination of communication connections to ensure the smoothness and security of the communication process. The module integrates functions such as intelligent routing selection, flow control, connection status monitoring, and abnormal behavior detection, and is closely integrated with the communication framework of the Hongmeng system to provide users with stable and efficient communication services.
[0046] In the integrated environment of the Hongmeng system, the development of the communication control module faces certain technical challenges. Due to the particularity of the system architecture and communication protocols, the control strategy needs to be fine-tuned and adapted to ensure that it can run efficiently. At the same time, in order to meet the needs of different communication scenarios, the module needs to support multiple communication protocols and flexible connection management strategies, which increases the complexity of development and the workload of maintenance. In addition, in high-concurrency communication scenarios, the performance of the communication control module may become a bottleneck of the system, and optimization measures need to be taken to improve communication efficiency and stability.
[0047] The implementation process of the communication control module involves several key links, including: 1. Protocol adaptation and integration: According to system requirements and communication standards, select the appropriate communication protocol and integrate it into the Hongmeng system. This includes the implementation of the protocol stack, parameter configuration, and customization of the communication process; 2. Intelligent routing selection: Implement intelligent routing selection algorithms based on factors such as network conditions, user preferences, and communication needs to ensure the stability and efficiency of communication connections; 3. Flow control and congestion management: According to the bandwidth, delay and packet loss rate of the communication link, dynamic flow control and congestion management mechanisms are implemented to optimize communication performance and avoid network congestion; 4. Connection status monitoring and anomaly detection: Real-time monitoring of the status of communication connections, including connection establishment, data transmission, and connection termination. At the same time, an abnormal behavior detection algorithm is implemented to promptly discover and handle abnormal situations in the communication process to ensure the security of communication.
[0048] This system equipped with a communication control module demonstrates excellent performance and flexibility in communication management. The intelligent routing selection and traffic control strategies adopted by the module effectively enhance the stability and efficiency of communication connections. At the same time, the module also has powerful connection status monitoring and abnormal behavior detection capabilities, which can promptly discover and handle potential problems during the communication process, ensuring the security and reliability of communication. Through continuous optimization and upgrade, the communication control module can continuously adapt to new communication requirements and security threats, providing users with higher-quality and more secure communication services.
[0049] (8) Communication Audit Module The communication audit module is a core component in the communication management system. It focuses on comprehensively auditing and analyzing the historical records, behavior patterns, and compliance of communication connections. This module integrates functions such as data analysis, behavior pattern recognition, and compliance inspection, and is deeply integrated with the communication management framework of the HarmonyOS, aiming to provide users with transparent and traceable communication audit services.
[0050] In the integrated environment of the HarmonyOS, the development of the communication audit module faces a series of technical challenges. Due to the particularity of the system architecture and communication logs, the audit module needs to efficiently process and analyze a large amount of communication data to ensure the accuracy and timeliness of audit results. At the same time, to meet the compliance requirements of different industries, the module needs to support flexible audit rule configuration and report generation functions, which increases the complexity and flexibility requirements of development. In addition, conducting audits while protecting user privacy is also an important issue to consider during the development process.
[0051] The implementation process of the communication audit module covers multiple key aspects, which are as follows: 1. Data collection and preprocessing: Implement the interface docking with the communication management framework of the HarmonyOS, collect communication connection data in real time, and perform preprocessing tasks such as data cleaning and format conversion to provide a reliable data basis for subsequent audit analysis; 2. Behavior pattern recognition: Use machine learning algorithms to deeply analyze communication data to identify users' communication behavior patterns, such as communication frequency and time period preferences, providing a basis for abnormal behavior detection; 3. Compliance inspection: According to the preset audit rules and industry standards, conduct compliance inspections on communication connections, including sensitive word detection of communication content and blacklist screening of communication objects, to ensure the compliance of communication activities; 4. Audit report generation: Automatically generate detailed audit reports based on audit results, including audit time, audit object, audit results, and recommended measures, for easy viewing and management by users.
[0052] The system equipped with the communication audit module demonstrates powerful audit capabilities and compliance guarantee in communication management. The module adopts advanced data analysis technologies and behavior pattern recognition algorithms, which can accurately identify anomalies and violations in communication behaviors, providing users with timely warnings and reports. At the same time, the module also supports flexible audit rule configuration and report generation functions to meet the compliance requirements of different industries. Through continuous optimization and upgrading, the communication audit module can continuously adapt to new communication technologies and compliance standards, providing users with more comprehensive and efficient communication audit services. LOONGARCH64. CPUs of each architecture are different kernel modules. Common domestic operating systems, including Kylin and Tongxin, have carried out kernel adaptability transformations on their respective identity recognition and verification modules for different kernel modules, resulting in a geometric increase in the identity recognition and verification modules of the information and communication technology innovation (ICT) with changes in CPU architecture, operating system, and operating system version, and they are incompatible with each other.
[0053] Based on the similarities and differences in CPU architecture and version of the domestic operating system, the identity recognition and verification module of the framework of the present invention extracts common modules and separates different modules. The specific steps include: Based on the standard LINUX, the PAM module is transformed to achieve the portability transformation from WINDOWS to LINUX based on the personal identification number (PIN); Based on the operating system version and CPU architecture, the adaptability transformation of the personal identification number verification is carried out to achieve the adaptability transformation from the standard LINUX to domestic operating systems, including Tongxin UOS and Kylin operating system; Based on the same series of operating systems, the compatibility transformation is carried out to achieve the compatibility transformation from the new version to the old version of the Tongxin series / Kylin series, and a single package is compatible with one series of operating systems; Based on the modular development concept, encapsulation is carried out to achieve the framework and modular transformation.
[0054] Through the innovation of this module, the login verification content of the ICT system is upgraded from the single-layer verification method of the username and password combination to the double-layer verification method of the username and password combination + UKEY / PIN code. Users can choose: Multi-layer verification code verification method: that is, on the premise of inserting the UKEY, the verification is completed by combining the input of the user password and PIN code; Single PIN code verification method: that is, on the premise of inserting the UKEY, the PIN code is input to complete the verification; Single password verification method: that is, on the premise of inserting the UKEY, the password is input to complete the verification. Generally, this verification method is not recommended for identity verification.
[0055] Through the innovation of this module, identity verification cannot be passed without a UKEY. When an unauthorized user attempts to log in remotely under non-contact conditions (network / remote), since the PIN code cannot be inserted, the verification fails, thus preventing the user from logging in to the IT-created terminal / server remotely. In addition, it also prevents unauthorized users without a UKEY from attempting to log in to the IT-created terminal / server under contact conditions.
Claims
1. A domestic instant messaging security framework adapted to the "HarmonyOS" operating system, which is composed of a communication interaction module (1), an information encryption and decryption module (2), a signaling encryption and decryption module (3), an identity authentication module (4), a device control module (5), a login control module (6), a communication control module (7), and a communication audit module (8). Each module can work independently or cooperate in combination, and can fully implement the security of instant messaging communication devices and communication security adapted to the new generation of "HarmonyOS" operating system. Among them, the login control module (6) needs to be used in combination with the identity authentication module (4) and the device control module (5), and the communication control module (7) is the basis of the communication audit module (8). This framework supports private deployment, and is characterized in that: The aforementioned communication interaction module (1) uses the "HarmonyOS" software development environment (IDE), targets the IM SDK component, and conducts IMHAR development and adaptation transformation, enabling the front-end after "HarmonyOS" transformation to quickly perform instant information interaction through the IM HAR component; The aforementioned information encryption and decryption module (2) uses component encapsulation to encrypt and decrypt the information of instant messaging through encryption interfaces and decryption interfaces, strengthening the security of instant messaging software. The information encryption and decryption module supports and integrates various national cryptography algorithms; The aforementioned signaling encryption and decryption module (3) uses component encapsulation and combines methods such as mixed coding, encryption and decryption algorithms, and one-time passwords to encrypt and confuse both parties of communication and communication methods during the handshake of instant messaging, ensuring communication security and information interaction method switching in an insecure network environment; The aforementioned identity authentication module (4) verifies the identity, identity verification and other data input by the user based on the authentication information of the terminal application user stored on the server side, ensuring that only authorized users can log in and join the communication network for communication; The aforementioned device control module (5) is based on the C / S architecture, stores device information on the server side, can monitor the status of devices intending to log in to the communication network, ensure that the use of relevant devices is under control, prevent information leakage caused by device loss, and at the same time ensure that only authorized devices can join the communication network; The aforementioned login control module (6) is based on the device control module (5) and the identity authentication module (4), and can jointly inspect the devices and users intending to log in to the communication network, ensuring that only authorized users using the user's device can log in and use the communication network; The aforementioned communication control module (7) uses a one-time authorization mechanism to authorize the communication interaction of users and prevent users from sending information to another user without authorization; The aforementioned communication audit module (8) audits the communication of users based on communication logs to ensure that the information sent after authorization complies with the authorization.
2. The communication interaction module (1) according to claim 1, characterized in that: The use of the "Hongmeng" software development environment (IDE) refers to the one-stop integrated development environment (IDE) DevEco Device Tool provided by Huawei specifically for software developers participating in the adaptation of the new generation of the "Hongmeng" (Harmony OS NEXT) mobile operating system; The IM HAR development and adaptation transformation against the IM SDK component refers to the adaptation transformation of the original IM SDK adapted to the android side to generate a HAR package and enable it to run on the new generation of the "Hongmeng" operating system; The necessity of the above transformation is that the new generation of the "Hongmeng" operating system is no longer compatible with the android operating system. That is, software that originally ran on android cannot run on the domestic mobile operating system of "Hongmeng" without undergoing adaptation transformation on the "Hongmeng" side; The aforementioned communication interaction module consists of an IM HAR client, an IM HAR server, and an IM HAR management end. Among them, the IM HAR client is responsible for signaling and information interaction, the IM HAR server is responsible for information management, and the IM HAR management end is responsible for the management of basic information such as instant messaging personnel and organizations.
3. The information encryption and decryption module (2) as described in claim 1, characterized in that: The information encryption and decryption of instant messaging is achieved in a component encapsulation manner through an encryption interface and a decryption interface. The information encryption and decryption module supports and integrates various national cryptographic algorithms, which means that various national cryptographic algorithms are encapsulated and integrated into the aforementioned IM HAR client (9) in the form of components or microservices. Before information is sent, an encryption algorithm is called to encrypt the information to be sent. When information is received, a decryption algorithm is called to decrypt the received information, thereby achieving the confidentiality of information during the flow on the network.
4. The signaling encryption and decryption module (3) as described in claim 1, characterized in that: The component encapsulation method combines the use of scrambling codes, encryption and decryption algorithms, one-time passwords, etc. When the handshake for instant messaging is initiated, the communication parties and communication methods are encrypted and confused, which means that a scrambling code is first added, and then the signaling is encrypted through a one-time encryption method. After the receiving party receives the signaling, it is solved according to the agreed one-time decryption method, and the signaling is restored by removing the scrambling code, so as to ensure that after a network attacker obtains the signaling through means such as sniffing, it cannot be decrypted. Even if it is decrypted, it only affects the current communication. The signaling encryption and decryption module (3) is also encapsulated in the IM HAR client (9).
5. The identity authentication module (4) as described in claim 1, characterized in that: The verification of data such as the identity and identity authentication input by the user based on the authentication information of the terminal application user stored on the server side means that the data such as the user's password and biometric code are collected in advance on the application side and uploaded to the server side for storage. When the user conducts identity authentication on the application side, the password and biometric code data input during the authentication are compared with the password and biometric code stored on the server side. If they are consistent, the identity authentication passes, and the user is authorized to use the relevant modules of the application based on the relevant configurations of the server side. If they are inconsistent, the user is not allowed to log in and use the application.
6. The device management and control module (5) according to claim 1, wherein: The server side stores device information and can monitor the status of devices attempting to log in to the communication network. This means that the unique identifier of the device is generated / collected / collected on the application side first and uploaded to the server side for storage and custody. The unique identifier does not change with the uninstallation of the application. When the device is lost or otherwise, the server side can disable the relevant device. After the device is disabled, when the application side uses the device for identity authentication, a prompt that the device is disabled is returned, thereby preventing unauthorized personnel from using the relevant device to log in to the network for social attacks.
7. The login management and control module (6) according to claim 1, wherein: The joint inspection of the device and the user attempting to log in to the communication network means that the server side pre-stores the user authentication information and the user device information. When the user logs in and uses the application, the user needs to verify the identity and the device in sequence. Only when both verifications pass can the user log in and use the application. The core is "one person, one device".
8. The communication management and control module (7) according to claim 1, wherein: By default, users cannot send or receive messages / files. Each time before sending or receiving messages / files, they need to apply for the sending and receiving permissions and can only send and receive messages when the permission is obtained. The communication management and control can achieve control in various dimensions such as sequentially, by time period, and by object. It should be noted that the communication management and control module is usually only used in scenarios with a relatively high security level and is often used together with the communication audit module (8) to achieve "apply before use, audit after use".
9. The communication audit module (8) according to claim 1, wherein: Audit the communication parties, communication time, and communication content of the authorized sending and receiving of messages / files to ensure that the relevant content complies with the application. It is often used together with the communication management and control module (7) in scenarios with a relatively high security level to achieve "apply before use, audit after use".