Method and device for realizing data cross-domain security acquisition and transmission based on national cryptographic algorithm, processor and computer readable storage medium thereof

Through SM4-SR algorithm and collaborative authentication technology, S boxes are dynamically generated, reversible matrix transformation and multi-dimensional collaborative authentication are introduced, and end-to-end transmission tunnel is built, which solves the security problems in cross-domain acquisition and transmission of data, and realizes data security and transmission reliability.

CN120342740APending Publication Date: 2025-07-18THE THIRD RES INST OF MIN OF PUBLIC SECURITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510620144.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-14
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

The prior art has the risk of data being stolen and tampered with during the data cross-domain acquisition and transmission. The authenticity of the data source is difficult to verify, and it is difficult to establish trust between different security domains, which affects the security acquisition and utilization of data.

Method used

The data acquisition encryption mechanism based on the SM4-SR domestic cryptographic algorithm and the end-to-end secure transmission mechanism separated from the key are adopted. By dynamically generating S boxes, introducing reversible random matrix transformation layers and multi-dimensional dynamic collaborative authentication, an end-to-end transmission tunnel is built to ensure the secure data transmission.

Benefits of technology

It effectively solves the security problems in the cross-domain data collection process, ensures the encryption security and transmission security of data, adapts to complex network environments, and realizes the secure collection and transmission of cross-domain data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342740A_ABST
    Figure CN120342740A_ABST
Patent Text Reader

Abstract

The invention relates to a method for realizing data cross-domain security acquisition and transmission based on a national cryptographic algorithm, which comprises the following steps of: performing symmetric encryption on acquired data based on an acquired data encryption mechanism of an SM4-SR domestic cryptographic algorithm, and protecting the acquired data; and realizing cross-domain directional end-to-end acquisition data secure transmission based on an acquisition data end-to-end secure transmission mechanism of collaborative authentication and key isolation. By the adoption of the method and device for achieving data cross-domain safe collection and transmission based on the national cryptographic algorithm, the processor and the computer readable storage medium of the processor, through an encryption mechanism and a transmission mechanism based on the improved SM4 algorithm, the safety problems that data are stolen and tampered in the existing data cross-domain collection process can be effectively solved; the method has remarkable technical effects in the aspects of data encryption security, transmission security, guarantee of data cross-domain acquisition security, adaptation to complex network environments and the like, and has relatively high practical value and popularization and application prospects.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data security, and particularly to the field of information security. Specifically, it refers to a method, device, processor and computer-readable storage medium for realizing cross-domain secure data acquisition and transmission based on national cryptographic algorithms. Background Art

[0002] With the rapid development of information technology, the cross-domain flow of data between different fields and systems has become increasingly frequent. During the process of cross-domain data acquisition and transmission, traditional plaintext data acquisition and transmission technologies face risks such as being stolen and tampered with, it is difficult to verify the authenticity of the data source, and it is difficult to establish trust between different security domains. It is difficult to effectively guarantee the confidentiality and integrity of data, seriously affecting the secure acquisition and effective utilization of data. How to achieve cross-domain secure data acquisition and transmission and ensure data authenticity and integrity has become a key problem to be solved urgently in the current data processing process. Summary of the Invention

[0003] The purpose of the present invention is to overcome the above-mentioned disadvantages of the prior art, and provide a method, device, processor and computer-readable storage medium for realizing cross-domain secure data acquisition and transmission based on national cryptographic algorithms, which have good security, good confidentiality and a relatively wide range of applications.

[0004] In order to achieve the above purpose, the method, device, processor and computer-readable storage medium for realizing cross-domain secure data acquisition and transmission based on national cryptographic algorithms of the present invention are as follows:

[0005] The method for realizing cross-domain secure data acquisition and transmission based on national cryptographic algorithms is mainly characterized in that the method includes the following steps:

[0006] (1) Based on the acquisition data encryption mechanism of the SM4-SR domestic cryptographic algorithm, symmetrically encrypt the acquisition data to protect the acquisition data;

[0007] (2) Based on the end-to-end secure transmission mechanism of acquisition data with collaborative authentication and key isolation, realize cross-domain directional end-to-end secure transmission of acquisition data.

[0008] Preferably, the step (1) specifically includes the following steps:

[0009] (1.1) Dynamically generate an S-box through the main key derivation parameter, and use a different S-box for encryption each time acquisition data is collected;

[0010] (1.2) Introduce a reversible random matrix transformation layer, realize key confusion by transforming the round function, store the inverse matrix, and increase the device fingerprint.

[0011] Preferably, the step (1.1) specifically includes the following steps:

[0012] (1.1.1) Initialize the parameters of the master key MK, counter CTR, and seed value Seed;

[0013] (1.1.2) Dynamically construct the S-box based on the initialized parameters through the master key derivation parameters. After processing every N acquisition data blocks, increment the value of the counter by one, and encrypt the acquisition data header with the initial value of CTR carried;

[0014] (1.1.3) When the counter is updated each time, reconstruct a new S-box so that different S-boxes are used for encrypting every N acquisition data blocks.

[0015] Preferably, step (1.2) specifically includes the following steps:

[0016] (1.2.1) Add a reversible random matrix transformation layer, insert a reversible matrix transformation before the round function, and generate a reversible matrix M according to the current round number i and the master key according to the matrix generation rule i ;

[0017] (1.2.2) Store the inverse matrix

[0018] (1.2.3) Add the device fingerprint generated based on the SM3 digest algorithm to the acquisition data ciphertext header.

[0019] Preferably, step (2) specifically includes the following steps:

[0020] (2.1) Implement multi-dimensional dynamic collaborative authentication;

[0021] (2.2) Construct an end-to-end transmission tunnel.

[0022] Preferably, step (2.1) specifically includes the following steps:

[0023] (2.1.1) Generate a device fingerprint using the hardware device characteristics of the acquired data, fragment the master key, and store it separately at the device transmission sender node, transmission receiver node, and management end;

[0024] (2.1.2) The sender node sends an authentication request, carrying the device fingerprint digest, current geographical location, and timestamp signature;

[0025] (2.1.3) The receiver node performs verification and calculates the weight;

[0026] (2.1.4) After the verification passes, reconstruct the fragmented keys into the master key.

[0027] Preferably, step (2.2) specifically includes the following steps:

[0028] (2.2.1) Use the SM4-SR algorithm to construct an outer tunnel through the device fingerprint and timestamp;

[0029] (2.2.2) Use the recombined master key and random number to generate a dynamic session key to construct an inner tunnel;

[0030] (2.2.3) Send the collected data according to the data packet structure.

[0031] The device for realizing cross-domain secure data acquisition and transmission based on the national cryptographic algorithm is mainly characterized in that the device includes:

[0032] A processor configured to execute computer-executable instructions;

[0033] A memory storing one or more computer-executable instructions, and when the computer-executable instructions are executed by the processor, each step of the above-mentioned method for realizing cross-domain secure data acquisition and transmission based on the national cryptographic algorithm is realized.

[0034] The processor for realizing cross-domain secure data acquisition and transmission based on the national cryptographic algorithm is mainly characterized in that the processor is configured to execute computer-executable instructions, and when the computer-executable instructions are executed by the processor, each step of the above-mentioned method for realizing cross-domain secure data acquisition and transmission based on the national cryptographic algorithm is realized.

[0035] The computer-readable storage medium is mainly characterized in that a computer program is stored thereon, and the computer program can be executed by a processor to realize each step of the above-mentioned method for realizing cross-domain secure data acquisition and transmission based on the national cryptographic algorithm.

[0036] By adopting the method, device, processor and computer-readable storage medium for realizing cross-domain secure data acquisition and transmission based on the national cryptographic algorithm of the present invention, through the encryption mechanism and transmission mechanism based on the improved SM4 algorithm, it can effectively solve the security problems such as data being stolen and tampered with in the existing cross-domain data acquisition process, and has remarkable technical effects in terms of data encryption security, transmission security, ensuring cross-domain data acquisition security and adapting to complex network environments. It can be widely applied to fields such as finance, government affairs, and medical care, and has high practical value and promotion application prospects. Description of the Drawings

[0037] Figure 1 For the method of the present invention for realizing cross-domain secure data acquisition and transmission based on the national cryptographic algorithm.

[0038] Figure 2 It is a schematic diagram of the acquisition data encryption mechanism based on the SM4-SR domestic cryptographic algorithm for the method of the present invention for realizing cross-domain secure data acquisition and transmission based on the national cryptographic algorithm.

[0039] Figure 3 Schematic diagram of the end-to-end secure transmission mechanism for collected data based on collaborative authentication and key sharding isolation in the method for realizing cross-domain secure data collection and transmission based on national cryptography algorithm of the present invention.

[0040] Figure 4 Schematic diagram of the cross-domain secure data collection process based on national cryptography algorithm in the method for realizing cross-domain secure data collection and transmission based on national cryptography algorithm of the present invention. Detailed implementation manners

[0041] In order to more clearly describe the technical content of the present invention, the following will be further described in conjunction with specific embodiments.

[0042] The method for realizing cross-domain secure data collection and transmission based on national cryptography algorithm of the present invention includes the following steps:

[0043] (1) The collected data encryption mechanism based on the SM4-SR domestic cryptographic algorithm symmetrically encrypts the collected data to protect the collected data;

[0044] (2) The end-to-end secure transmission mechanism for collected data based on collaborative authentication and key isolation realizes cross-domain directional end-to-end secure transmission of collected data.

[0045] As a preferred implementation manner of the present invention, the step (1) specifically includes the following steps:

[0046] (1.1) Dynamically generate an S-box through the master key derivation parameter, and use a different S-box for encryption each time the data is collected;

[0047] (1.2) Introduce a reversible random matrix transformation layer, realize key confusion by transforming the round function, store the inverse matrix, and increase the device fingerprint.

[0048] As a preferred implementation manner of the present invention, the step (1.1) specifically includes the following steps:

[0049] (1.1.1) Initialize the parameters of the master key MK, counter CTR, and seed value Seed;

[0050] (1.1.2) Dynamically construct an S-box through the master key derivation parameter based on the initialized parameters. After processing N collected data blocks, the value of the counter is incremented by one, and the initial value of CTR is carried in the encrypted data header;

[0051] (1.1.3) Each time the counter is updated, a new S-box is re-constructed so that a different S-box is used for encryption every N collected data blocks.

[0052] As a preferred implementation manner of the present invention, the step (1.2) specifically includes the following steps:

[0053] (1.2.1) Add a reversible random matrix transformation layer, insert a reversible matrix transformation before the round function, and generate a reversible matrix M according to the current round number i and the master key according to the matrix generation rule i ;

[0054] (1.2.2) Store the inverse matrix

[0055] (1.2.3) Add a device fingerprint generated based on the SM3 digest algorithm to the header of the collected data ciphertext.

[0056] As a preferred embodiment of the present invention, the step (2) specifically includes the following steps:

[0057] (2.1) Implement multi-dimensional dynamic collaborative authentication;

[0058] (2.2) Build an end-to-end transmission tunnel.

[0059] As a preferred embodiment of the present invention, the step (2.1) specifically includes the following steps:

[0060] (2.1.1) Generate a device fingerprint using the hardware device characteristics of the collected data, fragment the master key, and store it separately at the device transmission sender node, transmission receiver node, and management end;

[0061] (2.1.2) The sender node sends an authentication request, carrying the device fingerprint digest, current geographical location, and timestamp signature;

[0062] (2.1.3) The receiver node performs verification and calculates the weight;

[0063] (2.1.4) After the verification passes, the fragmented keys are recombined to restore the master key.

[0064] As a preferred embodiment of the present invention, the step (2.2) specifically includes the following steps:

[0065] (2.2.1) Use the SM4-SR algorithm to build an outer tunnel through the device fingerprint and timestamp;

[0066] (2.2.2) Use the recombined master key and random number to generate a dynamic session key to build an inner tunnel;

[0067] (2.2.3) Send the collected data according to the data packet structure.

[0068] The device for realizing cross-domain secure data acquisition and transmission based on the national cryptographic algorithm of the present invention, wherein the device includes:

[0069] A processor configured to execute computer-executable instructions;

[0070] A memory stores one or more computer-executable instructions. When the computer-executable instructions are executed by the processor, each step of the above method for realizing cross-domain secure data acquisition and transmission based on national cryptographic algorithms is implemented.

[0071] The processor of the present invention for realizing cross-domain secure data acquisition and transmission based on national cryptographic algorithms, wherein the processor is configured to execute computer-executable instructions. When the computer-executable instructions are executed by the processor, each step of the above method for realizing cross-domain secure data acquisition and transmission based on national cryptographic algorithms is implemented.

[0072] The computer-readable storage medium of the present invention stores a computer program thereon. The computer program can be executed by a processor to implement each step of the above method for realizing cross-domain secure data acquisition and transmission based on national cryptographic algorithms.

[0073] In the specific implementation manner of the present invention, it relates to the field of data processing and information security, especially a cross-domain secure data acquisition and transmission method based on national cryptographic algorithms. It combines encrypted acquisition and collaborative authentication. By constructing a cross-domain secure transmission mechanism based on national cryptographic algorithms, a secure transmission channel is established between different security domains for encrypted acquisition data transmission, ensuring the secure and reliable acquisition and transmission of data between different security domains, and serving data security processing and risk prevention.

[0074] The cross-domain secure data acquisition method based on national cryptographic algorithms has a precondition of establishing a unique unified key management center in the data flow system as the management end, specifically including: one is the acquisition data encryption mechanism based on the SM4-SR domestic cryptographic algorithm, which performs symmetric encryption on the acquisition data to achieve the confidentiality protection of the acquisition data; the other is the end-to-end secure transmission mechanism of the acquisition data based on collaborative authentication and key isolation, which realizes the cross-domain directional end-to-end secure transmission of the acquisition data, as Figure 1 shown.

[0075] The acquisition data encryption mechanism based on the SM4-SR domestic cryptographic algorithm includes the dynamic parameterized S-box generation mechanism and the key confusion based on the transformation of the round function, as Figure 2 shown.

[0076] The dynamic parameterized S-box generation mechanism refers to dynamically generating an S-box through the main key-derived parameters, so that different S-boxes can be used for the encryption of each acquisition data.

[0077] The key confusion method based on the transformation of the round function refers to introducing a reversible random matrix transformation layer, realizing key confusion by transforming the round function, storing the inverse matrix, and adding device fingerprints for subsequent decryption of the acquisition data and collaborative verification.

[0078] The described end-to-end secure transmission mechanism for acquisition data based on collaborative authentication and key sharding isolation includes the described multi-dimensional dynamic collaborative authentication method and the end-to-end transmission tunnel construction method, as Figure 3 shown.

[0079] The described multi-dimensional dynamic collaborative authentication method generates a device fingerprint using the hardware device characteristics of the data to be acquired, shards the master key and stores it separately at three locations: the transmission sender node (device local security area), the transmission receiver node, and the management end. Before transmission, the sender initiates authentication, and the receiver verifies it. After successful verification, the key shards are recombined to restore the master key, which is used for the establishment of the subsequent transmission channel.

[0080] The described end-to-end tunnel construction method first uses the above-mentioned SM4-SR algorithm to construct an outer tunnel through the device fingerprint and timestamp, and then uses the recombined master key and random number to generate a dynamic session key to construct an inner tunnel. Through the constructed transmission channel, end-to-end encrypted transmission of acquisition data is achieved.

[0081] In a specific embodiment, the dynamic parameterized S-box generation mechanism first initializes parameters such as the master key MK, counter CTR, and seed value Seed, and dynamically constructs an S-box based on the initialized parameters through the master key-derived parameters. After processing N (N = 64) data blocks (acquisition data blocks), CTR += 1, and the initial value of CTR is carried in the encrypted acquisition data header; each time CTR is updated, a new S-box is correspondingly reconstructed, so that different S-boxes are used for encrypting every 64 acquisition data blocks.

[0082] The dynamic parameterized S-box generation method is as follows:

[0083] (1) Initialize parameters

[0084] 1) Input: master key MK (128bit), counter CTR (32bit).

[0085] 2) Generate the seed value: Seed = SM3(MK||CTR).

[0086] (2) S-box construction algorithm

[0087]

[0088] (3) Update mechanism

[0089] 1) After processing N data blocks, CTR += 1 (N = 64);

[0090] 2) The encrypted data header carries the initial value of CTR.

[0091] In a specific embodiment, the key confusion method based on the transformation of the round function is to add a reversible random matrix transformation layer, insert a reversible matrix transformation before the round function, and generate a reversible matrix M according to the current round number i and the master key according to the matrix generation rule. i , to achieve key confusion and increase key security; to correctly decrypt the collected data block, the inverse matrix is stored at the same time. For decryption, and attach the device fingerprint generated based on the SM3 digest algorithm to the header of the collected data ciphertext.

[0092] The key confusion method based on the transformation of the round function is as follows:

[0093] (1) Add a reversible random matrix layer

[0094] Insert a reversible matrix transformation before the round function: where M i is a randomly generated reversible matrix, V i is a random vector, X is the input intermediate state, and X′ is the transformed state.

[0095] (2) Matrix generation rule

[0096] Generate according to the current round number i and the master key:

[0097] key_material = SM4_KeyExpand(MK)[i * 8:(i + 1) * 8]

[0098] M i = generate_invertible_matrix(SM3(key_material))

[0099] (3) Store the inverse matrix

[0100] In a specific embodiment, the multi-dimensional dynamic collaborative authentication method is to generate a device fingerprint using device features such as the hardware MAC address and CPU serial number of the collected data, and use the Shamir secret sharing algorithm to decompose the master key K into n shards (n ≥ 5), and store the sharded master keys in the transmission sender node (device local security area), transmission receiver node, and management end respectively. When authenticating before transmission, the sender node initiates authentication carrying information such as the device fingerprint digest, current geographical location, and timestamp signature. The receiver node verifies the device fingerprint digest, timestamp signature (SM2 signature), and the rationality of the geographical location. After verification, the key shards are recombined to restore the master key.

[0101] The multi-dimensional dynamic collaborative authentication method is as follows:

[0102] (1) Device fingerprint generation

[0103]

[0104] (2) Initialization of Key Sharding

[0105] Use the Shamir secret sharing algorithm to decompose the master key MK into n shards (n≥5),

[0106] The sharding formula is f(x) = a0 + a1x + a2x 2 mod p, where a0 = MK and p is a large prime number;

[0107] The sharding storage strategy is as follows (taking 5 shards as an example):

[0108] 1) Store 2 shards in the local security area of the device (hardware-level secure storage)

[0109] 2) Store 2 shards in the transmission end node

[0110] 3) Store 1 shard in the unified key management center (HSM hardware encryption)

[0111] (3) Cooperative Authentication

[0112] 1) The sending device sends an authentication request, carrying the device fingerprint digest, current geographical location, and timestamp signature;

[0113] a. Real-time information collection to be carried:

[0114] ● Obtain the geographical location through triangulation (accuracy < 50 meters)

[0115] ● Synchronize the timestamp with the atomic clock (error < 1ms)

[0116] b. Generate a signature package

[0117] 2) The receiving end verifies

[0118] A [Receive request] --> B {Timestamp verification}

[0119] B --> |Within ±5s| C [Device fingerprint comparison]

[0120] C --> D [Geographical location analysis]

[0121] D --> E [Signature validity verification]

[0122] E --> F [Shard integrity check]

[0123] 3) Dynamic weight decision model

[0124] Verification factor weight assignment:

[0125] ● Degree of device fingerprint matching: 40%

[0126] ● Geographical location rationality: 30%

[0127] ● Timestamp validity: 30%

[0128] Pass the certification when the comprehensive score ≥ 85%

[0129] 3) Reorganization of the master key

[0130] a. Sharding collection mechanism

[0131] ● Two shards in the local SE area

[0132] ● One shard from the nearest transmission node

[0133] ● One shard from the management terminal

[0134] b. Lagrange interpolation recovery

[0135]

[0136] In a specific embodiment, the end-to-end tunnel construction method constructs an outer tunnel through the device fingerprint and timestamp, and then constructs an inner tunnel by using the reorganized master key and random number to generate a dynamic session key, so as to realize the encrypted transmission of end-to-end collected data.

[0137] The end-to-end tunnel construction method is as follows:

[0138] (1) Outer tunnel

[0139] SM4-SR encryption,

[0140] (2) Inner tunnel

[0141] Dynamic session key encryption,

[0142] (3) Packet structure

[0143] [Outer layer Header][Inner layer Header][Ciphertext][Dynamic MAC][Time window signature].

[0144] The structure in the technical solution of the present invention includes a unique unified key management center in the data flow system and two clients that need to collect and transmit data. Among them, the key management center serves as the management terminal for key generation and distribution, and the two clients are used for data collection and receiving data. The function finally realized by the present invention is the secure collection and transmission of cross-domain end-to-end data.

[0145] The technical solution of the present invention realizes cross-domain secure data acquisition and transmission based on the national cryptographic algorithm, effectively solving the security problems such as data theft and tampering existing in the existing cross-domain data acquisition process. The main purpose is to use cryptographic technology to protect the security of cross-domain data interaction.

[0146] The core design of the technical solution of the present invention is to implement the encryption of the acquired data based on the improved algorithm SM4_SR of SM4, and then realize the collaborative authentication in combination with technologies such as key sharding.

[0147] The technical solution of the present invention innovatively proposes the improved algorithm SM4-SR of SM4; innovatively proposes a multi-dimensional collaborative authentication method, and combines the two for the acquisition and transmission of cross-domain data.

[0148] For the specific implementation solution of this embodiment, reference may be made to the relevant descriptions in the above embodiments, which will not be elaborated here.

[0149] It can be understood that the same or similar parts in the above embodiments can be referred to each other, and the content not detailed in some embodiments can be referred to the same or similar content in other embodiments.

[0150] It should be noted that in the description of the present invention, the terms "first", "second", etc. are only used for descriptive purposes and cannot be understood as indicating or implying relative importance. In addition, in the description of the present invention, unless otherwise specified, the meaning of "plurality" refers to at least two.

[0151] Any process or method description shown in the flowchart or described in other ways herein can be understood as representing a module, segment, or part of code including one or more executable instructions for implementing a specific logical function or process. The scope of the preferred embodiments of the present invention includes additional implementations, where the functions may be executed in a substantially simultaneous manner or in a reverse order according to the functions involved, rather than in the order shown or discussed, which should be understood by those skilled in the technical field to which the embodiments of the present invention belong.

[0152] It should be understood that each part of the present invention can be implemented by hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution device. For example, if implemented by hardware, as in another embodiment, any one or a combination of the following well-known technologies in the art can be used: discrete logic circuits with logic gate circuits for implementing logical functions on data signals, application-specific integrated circuits with appropriate combinational logic gate circuits, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.

[0153] Those of ordinary skill in the art can understand that all or part of the steps carried out in implementing the above-described method embodiments can be completed by instructing relevant hardware through a program, and the corresponding program can be stored in a computer-readable storage medium. When the program is executed, it includes one or a combination of the steps of the method embodiments.

[0154] In addition, in each of the embodiments of the present invention, the functional units can be integrated into a processing module, or each unit can exist physically alone, or two or more units can be integrated into one module. The above-mentioned integrated module can be implemented in the form of hardware or in the form of a software functional module. When the integrated module is implemented in the form of a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium.

[0155] The above-mentioned storage medium can be a read-only memory, a magnetic disk, an optical disc, etc.

[0156] In the description of this specification, the descriptions with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples", etc. mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic descriptions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples.

[0157] By adopting the method, device, processor, and computer-readable storage medium for realizing cross-domain secure data acquisition and transmission based on the national cryptographic algorithm of the present invention, through the encryption mechanism and transmission mechanism based on the improved SM4 algorithm, it can effectively solve the security problems such as data being stolen and tampered with in the existing cross-domain data acquisition process, and has significant technical effects in terms of data encryption security, transmission security, ensuring cross-domain data acquisition security, and adapting to complex network environments. It can be widely applied to fields such as finance, government affairs, and healthcare, and has high practical value and application and promotion prospects.

[0158] In this specification, the present invention has been described with reference to its specific embodiments. However, it is obvious that various modifications and transformations can still be made without departing from the spirit and scope of the present invention. Therefore, the specification and the drawings should be regarded as illustrative rather than restrictive.

Claims

1. A method for realizing cross - domain secure data acquisition and transmission based on national cryptographic algorithms, characterized in that The method described above includes the following steps: (1) Based on the data acquisition encryption mechanism of the domestic SM4-SR cryptographic algorithm, symmetrically encrypt the acquired data to protect the acquired data; (2) Based on the end-to-end secure transmission mechanism of collaborative authentication and key isolation for the acquired data, achieve cross-domain directional end-to-end secure transmission of the acquired data.

2. The method for realizing cross-domain secure data acquisition and transmission based on the national cryptographic algorithm according to claim 1, characterized in that The specific steps of step (1) include the following steps: (1.1) Dynamically generate the S-box through the master key derivation parameter, and use a different S-box for encryption each time data is acquired; (1.2) Introduce a reversible random matrix transformation layer, realize key confusion by transforming the round function, store the inverse matrix, and increase the device fingerprint.

3. The method for realizing cross-domain secure data acquisition and transmission based on the national cryptographic algorithm according to claim 2, characterized in that, The specific steps of step (1.1) include the following steps: (1.1.1) Initialize the parameters of the master key MK, counter CTR, and seed value Seed; (1.1.2) Dynamically construct the S-box through the master key derivation parameter based on the initialized parameters. After processing N acquired data blocks, increment the value of the counter by one, and encrypt the acquired data header to carry the initial value of CTR; (1.1.3) Each time the counter is updated, reconstruct a new S-box so that a different S-box is used for encrypting every N acquired data blocks.

4. The method for realizing cross-domain secure data acquisition and transmission based on the national cryptographic algorithm according to claim 2, wherein The specific steps of step (1.2) include the following steps: (1.2.1) Add a reversible random matrix transformation layer, insert a reversible matrix transformation before the round function, and generate a reversible matrix M according to the current round number i and the master key according to the matrix generation rule i ; (1.2.2) Store the inverse matrix (1.2.3) Add the device fingerprint generated based on the SM3 digest algorithm to the head of the acquired data ciphertext.

5. The method for realizing cross-domain secure data acquisition and transmission based on the national cryptographic algorithm according to claim 1, characterized in that, The specific steps of step (2) include the following steps: (2.1) Implement multi-dimensional dynamic collaborative authentication; (2.2) Build an end-to-end transmission tunnel.

6. The method for realizing cross-domain secure data acquisition and transmission based on the national cryptographic algorithm according to claim 5, wherein The specific steps of step (2.1) include the following steps: (2.1.1) Generate the device fingerprint using the hardware device characteristics of the acquired data, fragment the master key, and store it separately at the device transmission sender node, transmission receiver node, and management end; (2.1.2) The sender node sends an authentication request, carrying the device fingerprint digest, current geographical location, and timestamp signature; (2.1.3) The receiver node performs verification and calculates the weight; (2.1.4) After the verification passes, reconstruct the fragmented keys into the master key.

7. The method for realizing cross-domain secure data acquisition and transmission based on the national cryptographic algorithm according to claim 5, wherein The specific steps of step (2.2) include the following steps: (2.2.1) Use the SM4-SR algorithm to build an outer tunnel through the device fingerprint and timestamp; (2.2.2) Use the reconstructed master key and random number to generate a dynamic session key to build an inner tunnel; (2.2.3) Send the acquired data according to the data packet structure.

8. A device for realizing cross-domain secure data acquisition and transmission based on national cryptography algorithms, characterized in that, The device described above includes: A processor configured to execute computer-executable instructions; A memory storing one or more computer-executable instructions, and when the computer-executable instructions are executed by the processor, each step of the method for realizing cross-domain secure acquisition and transmission of data based on the national cryptographic algorithm described in any one of claims 1 to 7 is realized.

9. A processor for realizing cross-domain secure data acquisition and transmission based on national cryptographic algorithms, characterized in that, The processor is configured to execute computer-executable instructions, and when the computer-executable instructions are executed by the processor, each step of the method for realizing cross-domain secure acquisition and transmission of data based on the national cryptographic algorithm described in any one of claims 1 to 7 is realized.

10. A computer-readable storage medium, characterized in that, A computer program is stored thereon, and the computer program can be executed by a processor to implement each step of the method for realizing cross-domain secure data acquisition and transmission based on the national cryptographic algorithm described in any one of claims 1 to 7.