Internet-based communication key generation method

By setting up a key pool, generation pool, decryption pool, and splitting pool in the packaging chain between the Internet platform and the access port, and combining the encryption and decryption of the key server, the security threats to data transmission in remote work are solved, achieving double-encrypted transmission and improving the security of data transmission.

CN120825282BActive Publication Date: 2026-05-19SHANGHAI LEILONG INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SHANGHAI LEILONG INFORMATION TECH CO LTD
Filing Date
2025-07-30
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

In remote work mode, when enterprise data is accessed on public or personal networks, it faces security threats such as hacker attacks and data breaches, and existing technologies are insufficient to effectively guarantee data transmission security.

Method used

By setting up a packaging chain between the internet platform and the access port, including a key pool, generation pool, decryption pool, and splitting pool, and using a key server for encryption and decryption, combined with folding and splitting rules, double-encrypted data transmission is achieved.

Benefits of technology

It improves the security of data transmission, prevents data leakage, and provides further protection even if the key is cracked, thus enhancing the security of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120825282B_ABST
    Figure CN120825282B_ABST
Patent Text Reader

Abstract

The application discloses a communication key generation method based on the Internet, and relates to the technical field of communication. A packaging chain is arranged between an Internet platform and an access port, wherein the packaging chain comprises a first packaging pool, a second packaging pool and a transmission channel; the access port is used to access the Internet platform to obtain access information, the access information is packaged by the second packaging pool to generate a key information package; the key information package is transmitted to the first packaging pool through the transmission channel, and the access information is obtained by decrypting the key information package through the first packaging pool and provided to the access port. The key information package is generated by encryption through the key issued by the key server, data can be better encrypted, the access information is split and folded, and double encryption transmission is performed in cooperation with the key, so that the transmission safety of data is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of communication technology, and more specifically to a method for generating communication keys based on the Internet. Background Technology

[0002] With the rapid development of information technology, the internet has deeply integrated into all aspects of society, changing people's lifestyles and work habits. In today's society, business operating models are also constantly evolving, with more and more companies adopting remote work models to improve work efficiency, reduce costs, and adapt to different work scenarios and employee needs.

[0003] Remote working allows employees to connect to internal company resources via the internet from different geographical locations, enabling them to work anytime, anywhere. However, this work model also brings a series of security challenges. When employees access sensitive company information using public or personal networks, the data is vulnerable to security threats such as hacking and network eavesdropping, posing a risk of leakage to the company's core data and confidential information. Summary of the Invention

[0004] The purpose of this invention is to provide an Internet-based communication key generation method to address the shortcomings of the prior art.

[0005] To achieve the above objectives, the present invention provides the following technical solution: a method for generating communication keys based on the Internet, comprising the following steps:

[0006] A packaging chain is set up between the Internet platform and the access port, wherein the packaging chain includes a first packaging pool, a second packaging pool, and a transmission channel;

[0007] Access information is obtained by accessing the Internet platform through the access port, and the access information is packaged into a key information packet through the second packaging pool.

[0008] The key information packet is transmitted to the first packaging pool through the transmission channel. The first packaging pool decrypts the key information packet to obtain access information and provides it to the access port.

[0009] In a preferred embodiment, the step of establishing a wrapper chain between the Internet platform and the access port includes:

[0010] A second packaging pool is configured for the corresponding Internet platform, which includes a key pool and a generation pool;

[0011] Configure the first packaging pool for the corresponding access port, where the first packaging pool includes a decryption pool and a splitting pool;

[0012] The decryption pool and the key pool are connected via a transmission channel; the generation pool is connected to the Internet platform, and the splitting pool is connected to the access port.

[0013] A key server is set up for each decryption pool and key pool. The key server is connected to the decryption pool and key pool respectively through a secure channel.

[0014] In a preferred embodiment, configuring a second packaging pool on the corresponding internet platform includes the following steps:

[0015] Folded plates and multiple breakpoints are set in the generation pool, wherein the folded plates are composed of multiple single carriers connected together;

[0016] Multiple folding rules are defined for each folding section, and these rules are then sorted. Each folding rule includes a folding form and the folding order corresponding to that form.

[0017] In a preferred embodiment, configuring the first packaging pool for the corresponding access port includes the following steps:

[0018] Configure data modules within the split pool;

[0019] Multiple splitting rules are set in the splitting pool. The number of splitting rules is the same as the number of folding rules. Each splitting rule includes a splitting form and the splitting order corresponding to the splitting form. The multiple splitting rules are sorted. The sorting of the multiple folding rules and the multiple splitting rules are in a one-to-one correspondence. The corresponding folding rules are the opposite of the splitting rules.

[0020] In a preferred embodiment, the steps of accessing the Internet platform through an access port to obtain access information, and packaging the access information into a key information packet through a second packaging pool, include:

[0021] Access data to the internet platform through the access port, and obtain access information through the internet platform;

[0022] Access information is transmitted to the generation pool via the Internet platform to obtain folded data, and the folded data is transmitted to the key pool for encryption to generate key information packets.

[0023] In a preferred embodiment, the steps of transmitting access information to a generation pool via an internet platform to obtain folded data, and transmitting the folded data to a key pool for encryption to generate a key information packet, include:

[0024] The access information is transmitted to the generation pool, the access information is divided into multiple individual data, the folded plate is copied to obtain the assimilation plate, and the individual data is stored in the individual carrier of the assimilation plate in sequence.

[0025] The folding rules are retrieved in sequence. The assimilation plate containing the individual data is folded according to the folding rules. The multiple intersections of the folded assimilation plate are matched with the corresponding breakpoints. The adjacent individual carriers corresponding to the intersections are disconnected and reconnected through the breakpoints. The breakpoints corresponding to the multiple intersections of the folded assimilation plate are connected for communication. The folding order corresponding to the folding form of the intersection in the folding rules is recorded through the breakpoints to obtain the folded data.

[0026] The retrieved and used folding rules will be invalidated;

[0027] The folded data is transmitted to the key pool and encrypted using the key issued by the key server to generate a key information packet.

[0028] In a preferred embodiment, the steps of transmitting the key information packet to a first packaging pool via a transmission channel, decrypting the key information packet in the first packaging pool to obtain access information, and providing it to the access port include:

[0029] The key information packet is transmitted to the decryption pool through the transmission channel. The key information packet is decrypted using the key issued by the key server to obtain the decrypted data.

[0030] The decrypted data is transmitted to the split pool to obtain access information for reconnection and expansion;

[0031] Provide access information to the access port.

[0032] In a preferred embodiment, the step of transmitting the decrypted data to the split pool to obtain reconnected and expanded access information includes:

[0033] After the decrypted data is in the splitting pool, the splitting rules are retrieved in sequence. The splitting order in the splitting rules is used to disconnect the breakpoint from the individual carriers on both sides in turn. Before disconnection, the splitting order is confirmed by communicating between the breakpoint and other breakpoints in the decrypted data in turn according to the splitting order of the breakpoint.

[0034] If the splitting order is incorrect, the breakpoint will be disconnected from the individual carriers on both sides, and the individual carriers on both sides will be unable to connect. The decrypted data will be destroyed by other breakpoints in the decrypted data.

[0035] If the splitting order is correct, the breakpoints are disconnected from the individual carriers on both sides, and the individual carriers on both sides are reconnected and expanded until all breakpoints in the decrypted data are disconnected, resulting in multiple reconnected and expanded individual carriers. The individual data in the multiple individual carriers are combined in order to obtain access information, and the retrieved splitting rules are invalidated.

[0036] The technical effects and advantages provided by the present invention in the above technical solution are as follows:

[0037] This invention uses a key issued by a key server to generate a key information packet, which can better encrypt data, split and fold access information, and, together with the key, perform double encryption transmission to ensure data transmission security and prevent data leakage. Even if the data is decrypted by the key, the data folding provides further protection, greatly improving the security of data transmission. Attached Figure Description

[0038] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this invention. For those skilled in the art, other drawings can be obtained based on these drawings.

[0039] Figure 1 This is a flowchart of the method of the present invention. Detailed Implementation

[0040] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0041] Example 1, please refer to Figure 1 As shown in this embodiment, a communication key generation method based on the Internet includes the following steps:

[0042] S1. Set up a packaging chain between the Internet platform and the access port, wherein the packaging chain includes a first packaging pool, a second packaging pool, and a transmission channel;

[0043] S2. Access the Internet platform through the access port to obtain access information, and package the access information through the second packaging pool to generate a key information packet;

[0044] S3. Transmit the key information packet to the first packaging pool through the transmission channel, and decrypt the key information packet through the first packaging pool to obtain access information and provide it to the access port.

[0045] In one embodiment, step S1 of setting up the wrapper chain between the Internet platform and the access port includes:

[0046] S11. Configure a second packaging pool for the corresponding Internet platform, wherein the second packaging pool includes a key pool and a generation pool;

[0047] S12. Configure the first packaging pool for the corresponding access port, wherein the first packaging pool includes a decryption pool and a splitting pool;

[0048] S13. The decryption pool and the key pool are connected via a transmission channel; the generation pool is connected to the Internet platform, and the splitting pool is connected to the access port.

[0049] S14. Set up key servers for the corresponding decryption pool and key pool. The key servers are connected to the decryption pool and key pool respectively through secure channels.

[0050] In one embodiment, step S11 of configuring the second packaging pool on the corresponding Internet platform includes:

[0051] S111. Folded plates and multiple breakpoints are set in the generation pool, wherein the folded plates are composed of multiple single carriers connected together.

[0052] S112. Formulate multiple folding rules for the corresponding folding plates, and sort the multiple folding rules. The folding rules include the folding form and the folding order corresponding to the folding form.

[0053] In one embodiment, step S12 of configuring the first packaging pool for the corresponding access port includes:

[0054] S121. Set up data modules in the split pool;

[0055] S122. Set multiple splitting rules in the splitting pool. The number of splitting rules is the same as the number of folding rules. Each splitting rule includes a splitting form and the splitting order corresponding to the splitting form. Sort the multiple splitting rules. The sorting of the multiple folding rules and the multiple splitting rules are in one-to-one correspondence. The corresponding folding rules are the opposite of the splitting rules.

[0056] As described in steps S11-S14 above, the internet platform and the access port are connected via a packaging chain, and the decryption pool and the key pool are connected via a transmission channel. The generation pool is connected to the internet platform, and the splitting pool is connected to the access port. The internet platform provides the access port access data, which is used for encrypted transmission. For example, in a remote work scenario, employees access internal corporate resources such as file servers and email systems via the internet. The symmetric key generation method can be used to encrypt data transmitted between employees and the corporate server, preventing data from being stolen by external attackers. The access data is encrypted through the key pool. The encryption process involves the key server generating the symmetric key K, which is then sent to the sender (internet platform) and receiver (access port) through a secure channel. This secure channel can be protected using encryption technology. This secure channel is an encrypted transmission channel set up using conventional methods, such as using an asymmetric encryption algorithm to encrypt the symmetric key during transmission. After receiving the key, the sending and receiving ends use their respective private keys to decrypt it, obtaining a symmetric key K, which is used for subsequent encrypted transmission of information. In the Internet platform, before encrypting the data, the access data is first input into the generation pool. The generation pool folds and encrypts the access data, and then it is encrypted and transmitted. After that, it is transmitted to the decryption pool of the access port to decrypt the access data, and then it is transmitted to the splitting pool to unfold the folded access data, obtaining the complete access data and providing it to the access port.

[0057] In one embodiment, step S2, which involves accessing the internet platform through an access port to obtain access information and then packaging the access information into a key information packet using a second packaging pool, includes:

[0058] S21. Access data to the Internet platform through the access port and obtain access information through the Internet platform;

[0059] S22. The access information is transmitted to the generation pool via the Internet platform to obtain folded data, and the folded data is transmitted to the key pool for encryption to generate key information packets;

[0060] In one embodiment, step S22, which involves transmitting access information to a generation pool via an internet platform to obtain folded data, and transmitting the folded data to a key pool for encryption to generate a key information packet, includes:

[0061] S221. The access information is transmitted to the generation pool, the access information is divided into multiple individual data, the folded plate is copied to obtain the assimilation plate, and the individual data is stored in the individual carrier of the assimilation plate in sequence.

[0062] S222. Retrieve the folding rules in sequence, fold the assimilation plate containing the individual data according to the folding rules, match the multiple intersections of the folded assimilation plate with the corresponding breakpoints, disconnect the adjacent individual carriers corresponding to the intersections and reconnect them through the breakpoints, establish communication connections between the breakpoints corresponding to the multiple intersections of the folded assimilation plate, and record the folding order corresponding to the folding form in the folding rules through the breakpoints (folding is to change the network position of the individual carriers carrying the individual data, and fold the chain-connected individual carriers by changing the network position to obtain the folded individual carrier. The folding form represents the network position relationship between the multiple individual carriers of the folded plate. Similarly, the subsequent splitting form is the opposite of the folding form, with the aim of obtaining the chain-folded plate), and obtain the folded data;

[0063] S223. Invalidate the retrieved and used folding rules;

[0064] S224. Transmit the folded data to the key pool and encrypt it using the key issued by the key server to generate a key information packet;

[0065] As described in steps S21 and S22 above, data is accessed through the access port to obtain access information from the internet platform. To encrypt the data, the access information needs to be transmitted to a generation pool (a cloud server) via the internet platform. Data operations are performed on the cloud server, which contains folded modules. Each folded module is composed of multiple interconnected virtual machines (VMs). Adjacent VMs are linked together in a chain-like manner. Each VM is used to store VM data, which is obtained by dividing the access information according to a preset data size. The subsequent data units, treated as individual data units, are stored sequentially in the individual carriers of the assimilation module according to the division order. The assimilation module is a replicated folded module, identical to the folded module. The folded module serves as a template and is not transmitted. Then, the folding rules are retrieved sequentially (the folding rules correspond to the splitting rules, and the order is the same; the folding rule is used for folding). When the splitting pool in the first packaging pool receives the decrypted data, it can split it using the splitting rule corresponding to the folding rule. The splitting rule is the opposite of the folding rule; for example, the folding rule is folding form one plus folding form two. Following the above order and folding form, the folded data is obtained. The splitting rule is to split folding form two first, then split folding form one, and so on (the reverse operation). Based on the folding rule, the assimilation block storing the individual data is folded (the multiple individual carriers within the assimilation block are also virtual machines). The multiple intersections of the folded assimilation block are matched with corresponding breakpoints. The adjacent individual carriers corresponding to the intersections are disconnected and reconnected through the breakpoints. This represents the location of the folded individual carrier, which is connected by inserting a breakpoint. This allows for breakpoint-based splitting in subsequent operations. Breakpoints are also where the virtual machine can record folding rules and connect adjacent individual carriers. Communication connections are established between the breakpoints corresponding to the multiple intersections of the folded assimilation block, enabling communication between multiple breakpoints regarding folding. Rule communication is used for collaborative judgment in the subsequent splitting process. By recording the folding order corresponding to the intersection point in the folding rule through breakpoints, folded data is obtained. The retrieved folding rule is invalidated, which ensures that the next retrieved folding rule corresponds to the subsequent splitting rule. The folded data is transmitted to the key pool and encrypted with the key issued by the key server to generate a key information packet. This enables better encryption of the data. The access information is split and folded, and with the key, double encryption is performed for transmission to ensure data transmission security and prevent data leakage. Even if the key is used to decrypt the data, the data folding provides further protection, greatly improving the security of data transmission.

[0066] In one embodiment, step S3, which involves transmitting the key information packet to a first packaging pool via a transmission channel, decrypting the key information packet in the first packaging pool to obtain access information, and providing it to the access port, includes:

[0067] S31. Transmit the key information packet to the decryption pool through the transmission channel, and decrypt the key information packet using the key issued by the key server to obtain the decrypted data;

[0068] S32. Transmit the decrypted data to the split pool to obtain the access information for reconnection and expansion;

[0069] S33. Provide access information to the access port;

[0070] In one embodiment, step S32, which involves transmitting the decrypted data to a split pool to obtain reconnected and expanded access information, includes:

[0071] S321. After the decrypted data is in the splitting pool, the splitting rules are retrieved in sequence. The splitting order in the splitting rules is used to disconnect the breakpoint from the individual carriers on both sides in turn. Before disconnection, the splitting order is confirmed by communicating between the breakpoint and other breakpoints in the decrypted data in turn according to the splitting order of the breakpoint.

[0072] S322. If the splitting order is incorrect, the breakpoint will be disconnected from the individual carriers on both sides, and the individual carriers on both sides will be unable to connect. The decrypted data will be destroyed by other breakpoints in the decrypted data.

[0073] S323. If the splitting order is correct, the breakpoint is disconnected from the individual carriers on both sides, and the individual carriers on both sides are reconnected and expanded until all breakpoints in the decrypted data are disconnected, resulting in multiple reconnected and expanded individual carriers. The individual data in the multiple individual carriers are combined in order to obtain access information, and the retrieved splitting rules are invalidated.

[0074] As described in steps S31-S33 above, after obtaining the key information packet, the key information packet is transmitted to the decryption pool through the transmission channel. In the decryption pool, the key information packet is decrypted using the key issued by the key server to obtain the decrypted data. Then, the decrypted data is transmitted to the splitting pool, and the splitting rules are retrieved in sequence. These splitting rules are the opposite of the folding rules of the decrypted data. The breakpoints are disconnected from the individual carriers on both sides according to the splitting order in the splitting rules. For example, the folding rule is fold form one plus fold form two. Folded data is obtained according to the above order and folding forms. Fold form two is split first, and then fold form one is split. Before disconnecting at each step in the sequence, the breakpoints are communicated with other breakpoints in the decrypted data to confirm the splitting order. For example, when splitting fold form two first, its corresponding breakpoint needs to coordinate with other breakpoints to determine if the splitting order is correct. If the splitting order is incorrect, the breakpoints and the individual carriers on both sides are disconnected. If the data carrier breaks down and the individual carriers on both sides cannot connect, it indicates an incorrect splitting order. This means the data was accessed by a port without the correct splitting order (an unauthorized access port). The decrypted data is then destroyed through other breakpoints within the decrypted data. Since breakpoints are connected to adjacent individual carriers, and multiple individual carriers are continuously connected, multiple individual carriers can receive the breakpoint's signal. All data in each individual carrier self-destructs to prevent unauthorized access. In this situation, the first packaging pool corresponding to the access port may not have received the data, while the folding rules in the second packaging pool of the internet platform have already been used in sequence. The internet platform will prompt the access port to destroy the corresponding splitting rules in the first packaging pool, even if the splitting rules in the first packaging pool have not been retrieved or used. The purpose is to maintain the correspondence between the splitting rules in the splitting pool and the folding rules in the generation pool, thus obtaining the internet platform's data transmission security index: specifically...

[0075] ,in, This is a security index for data transmission on internet platforms. This specifies the number of times the splitting rules in the first packaging pool will be destroyed when the internet platform prompts the access port. This refers to the number of access ports for which internet platforms have issued warnings about the destruction of splitting rules. As a constant greater than zero, the higher the security index of data transmission on an internet platform, the more severe the impact from the network, indicating a significant risk of external network interference, which can be understood by management personnel.

[0076] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A method for generating communication keys based on the Internet, characterized in that, Includes the following steps: A packaging chain is established between the internet platform and the access port, wherein the packaging chain includes a first packaging pool, a second packaging pool, and a transmission channel, and the steps include: A second packaging pool is configured for the corresponding Internet platform, which includes a key pool and a generation pool; The steps for configuring a second packaging pool on the corresponding internet platform include: Folded plates and multiple breakpoints are set in the generation pool, wherein the folded plates are composed of multiple single carriers connected together; Multiple folding rules are defined for each folding panel, and these rules are then sorted. Each folding rule includes a folding form and the folding order corresponding to that form. Configure the first packaging pool for the corresponding access port, where the first packaging pool includes a decryption pool and a splitting pool; The steps for configuring the first packaging pool on the corresponding access port include: Configure data modules within the split pool; Multiple splitting rules are set in the splitting pool. The number of splitting rules is the same as the number of folding rules. Each splitting rule includes a splitting form and the splitting order corresponding to the splitting form. The multiple splitting rules are sorted. The sorting of the multiple folding rules and the multiple splitting rules are in a one-to-one correspondence. The corresponding folding rules are the opposite of the splitting rules. The decryption pool and the key pool are connected via a transmission channel; the generation pool is connected to the Internet platform, and the splitting pool is connected to the access port. A key server is set up for each decryption pool and key pool. The key server is connected to the decryption pool and key pool respectively through a secure channel. Access to the internet platform via the access port to obtain access information, and then packaging the access information into a key information packet through a second packaging pool, the steps of which include: Access data to the internet platform through the access port, and obtain access information through the internet platform; The steps include: transmitting access information to a generation pool via an internet platform to obtain folded data; transmitting the folded data to a key pool for encryption to generate a key information packet; and transmitting the folded data to a key pool. The access information is transmitted to the generation pool, the access information is divided into multiple individual data, the folded plate is copied to obtain the assimilation plate, and the individual data is stored in the individual carrier of the assimilation plate in sequence. The folding rules are retrieved in sequence. The assimilation plate containing the individual data is folded according to the folding rules. The multiple intersections of the folded assimilation plate are matched with the corresponding breakpoints. The adjacent individual carriers corresponding to the intersections are disconnected and reconnected through the breakpoints. The breakpoints corresponding to the multiple intersections of the folded assimilation plate are connected for communication. The folding order corresponding to the folding form of the intersection in the folding rules is recorded through the breakpoints to obtain the folded data. The retrieved and used folding rules will be invalidated; The folded data is transmitted to the key pool and encrypted using the key issued by the key server to generate a key information packet; The key information packet is transmitted to the first packaging pool through the transmission channel. The first packaging pool decrypts the key information packet to obtain access information and provides it to the access port.

2. The method for generating communication keys based on the Internet according to claim 1, characterized in that: The steps of transmitting the key information packet to the first packaging pool via the transmission channel, decrypting the key information packet in the first packaging pool to obtain access information, and providing it to the access port include: The key information packet is transmitted to the decryption pool through the transmission channel. The key information packet is decrypted using the key issued by the key server to obtain the decrypted data. The decrypted data is transmitted to the split pool to obtain access information for reconnection and expansion; Provide access information to the access port.

3. The method for generating communication keys based on the Internet according to claim 2, characterized in that: The steps of transmitting the decrypted data to the split pool to obtain reconnected and expanded access information include: After the decrypted data is in the splitting pool, the splitting rules are retrieved in sequence. The splitting order in the splitting rules is used to disconnect the breakpoint from the individual carriers on both sides in turn. Before disconnection, the splitting order is confirmed by communicating between the breakpoint and other breakpoints in the decrypted data in turn according to the splitting order of the breakpoint. If the splitting order is incorrect, the breakpoint will be disconnected from the individual carriers on both sides, and the individual carriers on both sides will be unable to connect. The decrypted data will be destroyed by other breakpoints in the decrypted data. If the splitting order is correct, the breakpoints are disconnected from the individual carriers on both sides, and the individual carriers on both sides are reconnected and expanded until all breakpoints in the decrypted data are disconnected, resulting in multiple reconnected and expanded individual carriers. The individual data in the multiple individual carriers are combined in order to obtain access information, and the retrieved splitting rules are invalidated.