Multi-receiver data asset verification transmission method and system based on national secret algorithm
By generating and signing value certificates using national cryptographic algorithms, and encrypting data using national cryptographic algorithms SM4 and SM2, the problem of identity verification in multi-receiver data transmission is solved, achieving data transmission security and value controllability.
Patent Information
- Application Number
- CN202511595144.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-03
- Publication Date
- 2026-01-13
AI Technical Summary
In multi-receiver data transmission scenarios, existing technologies struggle to accurately verify the legitimacy of each recipient's identity, potentially allowing unauthorized nodes to acquire data. This makes it impossible to ensure that only legitimate recipients can decrypt and use the data, posing a data security risk.
The data asset value is assessed and encrypted using the national cryptographic algorithm, a value certificate is generated and signed, the data is encrypted using the national cryptographic SM4 algorithm, the data encryption key is encrypted using the national cryptographic SM2 public key of each receiving edge node, the key ciphertext is generated, and the security and legality of data transmission are ensured through multi-level verification.
It achieves security and value controllability in the transmission of data assets to multiple recipients, ensuring that only legitimate recipients can decrypt and use the data, thereby improving the security and verification efficiency of data transmission.
Smart Images

Figure CN121333736A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of information security technology, and in particular to a method and system for verifying and transmitting multi-receiver data assets based on national cryptographic algorithms. Background Technology
[0002] In data asset transmission scenarios, secure data sharing among multiple recipients has critical requirements for identity verification and transmission security, directly impacting the confidentiality and compliant use of data assets. Existing technologies mostly employ conventional encryption or single-identity verification methods to ensure transmission, playing a certain role in closed or single-recipient scenarios. However, with the increasing demand for multi-recipient data interaction, existing technologies have revealed limitations. They struggle to accurately verify the identity of each recipient, making it easy for unauthorized nodes to obtain data. They also fail to ensure that only legitimate recipients can decrypt and use the data, resulting in security vulnerabilities in data asset transmission and failing to meet the needs of secure data verification and transmission in multi-recipient scenarios. Summary of the Invention
[0003] This application provides a method and system for verifying and transmitting multi-receiver data assets based on national cryptographic algorithms, which solves the technical problems of data being easily tampered with and stripped in traditional data asset transmission, and the difficulty for recipients to trust the claimed value.
[0004] The first aspect of this application provides a multi-receiver data asset verification and transmission method based on Chinese cryptographic algorithms. The method includes: assessing the value of the original data asset in the cloud; simultaneously calculating the hash value using the Chinese cryptographic SM3 algorithm to generate a value certificate, which includes a data hash value, a value assessment index, and a usage strategy; encrypting the original data asset using the Chinese cryptographic SM4 algorithm and a data encryption key to obtain ciphertext; encrypting the data encryption key using the Chinese cryptographic SM2 public key of each receiving edge node to obtain key ciphertext corresponding to each edge node; signing the value certificate using the SM2 private key in the cloud to generate a digital signature; sending a transmission data packet composed of the data ciphertext, the key ciphertext corresponding to each edge node, the value certificate, and the digital signature to each receiving edge node; and performing multi-level verification upon receiving the transmission data packet.
[0005] A second aspect of this application provides a multi-receiver data asset verification and transmission system based on Chinese cryptographic algorithms. The system includes: a value certificate generation module, used to assess the value of the original data asset in the cloud, simultaneously using the Chinese cryptographic SM3 algorithm to calculate a hash value, generating a value certificate containing a data hash value, value assessment indicators, and usage strategies; a key ciphertext acquisition module, used to encrypt the original data asset using the Chinese cryptographic SM4 algorithm and a data encryption key to obtain data ciphertext, and then encrypt the data encryption key using the Chinese cryptographic SM2 public key of each receiving edge node to obtain key ciphertext corresponding to each edge node; a digital signature generation module, used to sign the value certificate in the cloud using an SM2 private key to generate a digital signature; a transmission data packet acquisition module, used to send a transmission data packet composed of the data ciphertext, the key ciphertext corresponding to each edge node, the value certificate, and the digital signature to each receiving edge node; and a multi-level verification execution module, used by each receiving edge node to perform multi-level verification after receiving the transmission data packet.
[0006] One or more technical solutions provided in this application have at least the following technical effects or advantages: This application achieves secure and accurate verification and transmission of data assets from multiple recipients by conducting value assessments on the original data assets in the cloud and generating value certificates using the national cryptographic SM3 algorithm. It then uses the national cryptographic SM4 algorithm to encrypt the original data, employs the national cryptographic SM2 public key of each receiving edge node to encrypt the data key, and finally assembles and transmits the data packet after signing with the cloud's SM2 private key. Each receiving edge node decrypts and verifies the data through multi-level verification, and combines a private PKI system to ensure legitimate identity. Furthermore, it optimizes the key encryption strategy for multi-receiver scenarios, thereby achieving secure and accurate verification and transmission of data assets from multiple recipients. This results in secure transmission, controllable value, and efficient verification in the transmission of data assets from multiple recipients. Attached Figure Description
[0007] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0008] Figure 1 This is a flowchart illustrating the multi-receiver data asset verification and transmission method based on national cryptographic algorithms provided in this application embodiment.
[0009] Figure 2 This is a schematic diagram of the structure of a multi-receiver data asset verification and transmission system based on national cryptographic algorithms provided in this application embodiment.
[0010] Explanation of reference numerals in the attached diagram: 1. Value certificate generation module; 2. Key ciphertext acquisition module; 3. Digital signature generation module; 4. Transmission data packet acquisition module; 5. Multi-level verification execution module. Detailed Implementation
[0011] This application provides a method and system for verifying and transmitting multi-receiver data assets based on national cryptographic algorithms, which solves the technical problems of data being easily tampered with and stripped in traditional data asset transmission, and the difficulty for recipients to trust the claimed value.
[0012] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.
[0013] It should be noted that the terms "first," "second," etc., in the specification and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or server that includes a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or modules not explicitly listed or inherent to such processes, methods, products, or devices.
[0014] Example 1, as Figure 1 As shown, a multi-receiver data asset verification and transmission method based on national cryptographic algorithms is provided, wherein the method includes: Step A100: Evaluate the value of the original data assets in the cloud, and simultaneously use the national cryptographic SM3 algorithm to calculate the hash value and generate a value certificate, which includes the data hash value, value evaluation indicators and usage strategy.
[0015] In this embodiment of the application, the SM3 algorithm is a cryptographic hash algorithm that is suitable for digital signature and verification, message authentication code generation and verification, and random number generation.
[0016] Specifically, first, in response to the encrypted transmission command, the original data asset is located by the data asset identifier. Then, its national cryptographic SM3 hash value is calculated. The metadata registry is queried to obtain the bound value attribute metadata in order to extract value assessment indicators and usage strategies. Finally, it is encapsulated into a structured data object to generate a value certificate. The steps A110-A140 are described in detail.
[0017] Step A200: Use the national cryptographic SM4 algorithm and data encryption key to encrypt the original data asset to obtain data ciphertext, and use the national cryptographic SM2 public key of each receiving edge node to encrypt the data encryption key to obtain the key ciphertext corresponding to each edge node.
[0018] In this embodiment, the SM4 algorithm is a block symmetric cipher algorithm suitable for the needs of using block ciphers in cryptographic applications.
[0019] Optionally, a data encryption key conforming to the national cryptographic standard SM4 is first generated. The cloud starts a secure random number generator conforming to the national cryptographic standard to generate a 128-bit random number. This random number must meet the national cryptographic standard's requirements for the randomness of symmetric encryption keys, ensuring that the key has no fixed pattern and is difficult to predict or crack. After generation, the cloud will use this 128-bit random number as the data encryption key and immediately store it in its own secure storage area. Its storage mechanism is consistent with that of sensitive information such as the cloud's SM2 private key, ensuring that the key is not illegally accessed or leaked. Ultimately, this forms the core key used to call the national cryptographic standard SM4 algorithm to encrypt the original data assets. This key must meet the national cryptographic standard's specifications for the randomness and security of symmetric encryption keys and serve as the core key for encrypting the original data assets.
[0020] Subsequently, the national standard SM4 algorithm is invoked, using the generated data encryption key as the core, and employing an encryption mode conforming to national standard specifications to perform a full encryption operation on the located original data assets. Regardless of the size of the original data assets, complete encryption is achieved through the national standard SM4 algorithm, ultimately generating the corresponding ciphertext. This ciphertext possesses strong confidentiality and can only be decrypted using the corresponding data encryption key generated in this instance, ensuring that the original data assets will not be illegally stolen or read during transmission.
[0021] Furthermore, when using the national cryptographic SM4 algorithm to fully encrypt the original data assets, the cloud first divides the original data assets into several data blocks according to the 128-bit (16-byte) standard required by the national cryptographic SM4 algorithm. If the last block is less than 128 bits long, it is padded according to the national cryptographic standard to meet the block length requirement. Then, using the generated data encryption key that conforms to the national cryptographic standard as the symmetric key, and a compliant initialization vector, such as a 128-bit random initialization vector in CBC mode (Cryptographic Block Chaining mode), 32 rounds of fixed round function operations are performed on each 128-bit data block, including nonlinear transformation, linear transformation, and round key addition. After all data blocks have been iteratively encrypted, all encrypted blocks are concatenated in the original block order to finally generate the complete ciphertext corresponding to the original data assets. This ciphertext can only be restored to the original data assets by using the same data encryption key and the national cryptographic SM4 decryption process.
[0022] Next, after generating the encrypted data, the SM2 public key of each receiving edge node is obtained. According to the design of the private public key PKI system, the specific details are explained in step A521. Before deployment, each receiving edge node has completed the binding of its unique identifier and SM2 public / private key pair, and registered with a private root certificate authority to obtain an edge digital certificate. Its SM2 public key is encapsulated in the corresponding edge digital certificate, and these edge digital certificates are uniformly stored in the cloud. Therefore, the cloud will extract the unique SM2 public key of each receiving edge node from its stored edge digital certificates. Each extracted SM2 public key uniquely corresponds to a specific receiving edge node, ensuring accurate matching between the public key and the receiving node.
[0023] Next, for each extracted SM2 public key of the receiving edge node, an encryption operation is performed on the data encryption key. The SM2 algorithm is invoked, using the data encryption key as the encryption object and the SM2 public key of a single receiving edge node as the encryption key, performing asymmetric encryption. This operation is repeated for all receiving edge nodes; that is, each receiving edge node's SM2 public key corresponds to an independent encryption of the data encryption key, ultimately generating a unique key ciphertext for each receiving edge node. Due to the asymmetric nature of the SM2 algorithm, each key ciphertext can only be decrypted using the SM2 private key securely stored by its corresponding receiving edge node; other nodes cannot decrypt non-corresponding key ciphertexts using their own private keys.
[0024] By generating compliant data encryption keys and encrypting the original data assets using the national cryptographic SM4 algorithm to obtain ciphertext, extracting the national cryptographic SM2 public keys of each receiving edge node from the edge digital certificate stored in the cloud, and then using the SM2 public keys of each node to encrypt the data encryption keys to obtain the corresponding key ciphertext, the confidentiality of the original data asset transmission is ensured, while ensuring that only designated receiving edge nodes can decrypt and obtain the data encryption keys.
[0025] Step A300: The cloud uses the SM2 private key to sign the value certificate and generate a digital signature.
[0026] In this embodiment of the application, the SM2 private key is an integer greater than or equal to 1 and less than n-1, where n is the order of the SM2 algorithm.
[0027] In one embodiment of this application, after the aforementioned steps of completing the value assessment and hash value calculation of the original data asset using the national cryptographic SM3 algorithm in the cloud, it is first confirmed that a value certificate has been generated. This value certificate is a structured data object containing data hash value, value assessment indicators, and usage strategies. This is the core target object for subsequent signature operations, ensuring that the signature content covers all key contents of data integrity basis, value information, and usage rules.
[0028] Next, the cloud will retrieve its own securely stored SM2 private key. This SM2 private key is the private portion of a proprietary asymmetric key pair generated by the private root certificate authority during the cloud's registration with the private root certificate authority during the deployment phase. It is always stored in a trusted and secure area within the cloud, such as a hardware security module or encrypted storage partition, and can only be accessed by authorized signature operations to prevent unauthorized access or theft. Simultaneously, the cloud will initialize the signature module for the national cryptographic algorithm SM2, ensuring that the algorithm environment complies with the national cryptographic standards for the signature process, providing a compliant technical environment for subsequent signature operations.
[0029] Subsequently, the cloud inputs the complete value certificate into the national cryptographic SM2 algorithm signature module and performs the operation according to the national cryptographic SM2 signature process: First, the national cryptographic SM3 hash calculation is performed on the binary data of the value certificate to obtain a 256-bit hash value that uniquely corresponds to the content of the value certificate. This step can compress the data volume of the value certificate and fix the data characteristics. Then, the signature module calls the cloud's SM2 private key and combines it with a randomly generated elliptic curve random number that conforms to the national cryptographic standard to perform a signature operation on the 256-bit hash value, generating a digital signature containing two components r and s. Here, r is obtained by random number and elliptic curve operation, and s is calculated by the SM2 private key, random number, and hash value. The two components together constitute a complete digital signature, and the length of the signature result conforms to the national cryptographic SM2 algorithm's signature format requirements.
[0030] Finally, after the digital signature is generated, the cloud performs a validity self-check. This is done by simulating the subsequent verification logic of edge nodes, specifically by using the cloud's SM2 public key to verify the digital signature and the value credential. This confirms the digital signature passes the validity check and prevents subsequent edge node verification failures due to computational errors. For example, during the self-check, the cloud uses its own SM2 public key to recalculate the SM3 hash value of the value credential, and then performs an SM2 signature verification operation using the r and s components of the digital signature. If the verification result shows validity, the digital signature is confirmed to have been successfully generated and can be used for assembling subsequent data packets.
[0031] By retrieving a dedicated SM2 private key from the cloud and combining it with the national cryptographic SM2 algorithm to perform a signature operation and self-check on the value certificate containing complete key information, the system achieves the effects of ensuring that the value certificate is not tampered with during transmission, proving that the value certificate originates from a legitimate cloud, and providing a basis for receiving edge nodes to verify the authenticity of the value certificate.
[0032] Step A400: The cloud sends the encrypted data, the encrypted key corresponding to each edge node, the value certificate and the digital signature together to form a transmission data packet to each receiving edge node.
[0033] Specifically, after completing the initial encryption and signing operations, the cloud first confirms that the four core components of the transmission data packet obtained in the aforementioned steps are ready. The data ciphertext is generated by fully encrypting the original data asset by calling the national cryptographic SM4 algorithm and the data encryption key, which can prevent the original data from being illegally read during transmission. The key ciphertext corresponding to each edge node is obtained by performing asymmetric encryption on the data encryption key using its own national cryptographic SM2 public key for each receiving edge node, ensuring that only the corresponding edge node can decrypt and obtain the data encryption key.
[0034] A certificate of value is a structured data object formed by the cloud after assessing the value of the original data asset and simultaneously calculating the data hash value using the national cryptographic SM3 algorithm. It contains the basis for data integrity verification and usage constraints. A digital signature is generated by the cloud using its own securely stored SM2 private key to sign the certificate of value, which is used to prove the authenticity and immutability of the certificate of value.
[0035] Subsequently, the cloud integrates and assembles the encrypted data, the key ciphertext corresponding to each edge node, the value certificate, and the digital signature according to the preset structured data format, such as the binary data packet format that conforms to industry transmission standards or the extensible JSON format, to ensure that each edge node can quickly locate its own key ciphertext after receiving the data packet.
[0036] Finally, after the above steps assemble the data packet, the cloud sends the complete data packet to each receiving edge node through a stable cloud-edge communication link, such as the TCP / IP protocol based on industrial Ethernet or the MQTT lightweight communication protocol suitable for edge devices, thereby realizing the directional transmission of data from the cloud to multiple edge nodes.
[0037] By integrating the encrypted data, exclusive key information, value proof, and signature verification information required for data transmission into a unified transmission data packet and distributing it to each receiving edge node, the security, integrity, and verifiability of data asset transmission in multi-receiver scenarios are ensured.
[0038] Step A500: After receiving the transmitted data packet, each receiving edge node performs multi-level verification.
[0039] Specifically, after each receiving edge node receives the transmitted data packet, it sequentially performs multi-level verification by using the SM2 public key in the cloud to verify the validity of the digital signature, locating and decrypting the corresponding key ciphertext to obtain the data encryption key, using the key to decrypt the data ciphertext to obtain the original data, and calculating the SM3 hash value of the original data and comparing it with the hash value in the value certificate. The specific steps are explained in detail in A510-A540.
[0040] Furthermore, step A100 in the method provided in this application embodiment includes: A110: In response to an encrypted transmission command, locate the original data asset to be transmitted based on the data asset identifier in the encrypted transmission command.
[0041] A120: Calculate the national cryptographic SM3 hash value of the original data asset, and use it as the data hash value.
[0042] A130: Query the metadata registry to obtain predefined value attribute metadata bound to the data asset identifier, and extract value assessment indicators and usage strategies.
[0043] A140: Construct a structured data object, encapsulate the data hash value, the value assessment index, and the usage strategy within the data object, and generate the value certificate.
[0044] In this embodiment of the application, the data asset identifier is identification information carried in the encrypted transmission instruction.
[0045] Specifically, upon receiving an encrypted transmission command, the first step is to respond to the encrypted transmission command and locate the original data asset. A data asset identifier is used as the unique index for the data asset. This identifier is typically a globally unique code, such as a UUID format or a business-defined code. By parsing this data asset identifier carried in the encrypted transmission command, the original data asset to be transmitted is accurately matched and located in the data storage cluster, which is the cloud-side storage medium for storing the original data asset to be transmitted.
[0046] Next, the SM3 hash value of the original data asset is calculated. The SM3 cryptographic hash algorithm conforms to the standard GB / T32905-2016 "Information Security Technology - Cryptographic Hash Algorithms," possessing collision resistance and anti-image properties, and can convert input data of arbitrary length into a 256-bit fixed-length hash value. The SM3 algorithm is then used to perform a full calculation on the located original data asset, generating a 256-bit data hash value. This hash value will serve as the core basis for subsequent verification of data integrity.
[0047] Furthermore, when using the national cryptographic SM3 algorithm to perform full calculation on the located original data assets, the original data assets are first completely input into the algorithm, regardless of their size, and then preprocessed and padded to ensure that the total data length is a multiple of 512 bits. The padded content includes the original data length information to preserve data integrity characteristics. The padded complete data is then divided into several data groups in 512-bit units. Starting from the algorithm's preset 256-bit initial hash value, iterative compression operations are performed on each 512-bit data group. This involves generating 48 32-bit extended words through message expansion, and updating the hash value using the FF and GG functions in the compression function, as well as shift, XOR, and other logical operations. After all data groups have completed iterative compression, the final output 256-bit fixed-length result is the national cryptographic SM3 data hash value of the original data asset. Due to the algorithm's anti-collision and uniqueness, this hash value can accurately correspond to the content characteristics of the original data asset, becoming the core basis for subsequent edge nodes to verify whether the data has been tampered with during transmission and to ensure data integrity.
[0048] Subsequently, the metadata registry is queried and value assessment indicators and usage strategies are extracted. The metadata registry is a centralized management system that specifically stores descriptive information of data assets. The metadata in the registry is bound to the data asset identifier in a one-to-one correspondence and includes information such as the value attributes and usage rules of the data asset.
[0049] Specifically, the process begins by acquiring each original data asset to be included in the management system, along with its corresponding unique data asset identifier. Simultaneously, the metadata for this data asset is compiled, including descriptive information such as value attributes and usage rules. Next, the generated unique data asset identifier and the compiled metadata are entered into the metadata registry. Then, through the built-in association mapping mechanism in the metadata registry, the data asset identifier is configured to be specifically bound to the corresponding metadata, ensuring that one data asset identifier is associated with only one set of metadata, and one set of metadata is bound to only one data asset identifier. After the binding configuration is complete, the metadata registry stores and archives this one-to-one correspondence. If the metadata content is updated or the data asset identifier needs adjustment, the unique correspondence between the two will be maintained through system synchronization to ensure the accuracy of the association.
[0050] Next, using the identified data asset identifier as the query condition, access the metadata registry to obtain the predefined value attribute metadata bound to it, and extract the value assessment indicators and usage strategies from it, as detailed in step A131.
[0051] Finally, the steps of constructing a structured data object and generating a value certificate are performed. Structured data objects typically use standardized formats such as JSON and XML to ensure data parsing and compatibility. A structured data object conforming to a preset format is created, and the data hash value, value assessment indicators, and usage strategies obtained in the previous steps are encapsulated as the core fields of the object, ultimately generating a value certificate.
[0052] Through the above-mentioned sequential steps, combined with data asset management and cryptographic technology, a value certificate containing data integrity evidence, value information and usage rules is accurately generated, providing a standardized and practical core data carrier for integrity verification, value control and permission verification in subsequent multi-recipient data asset transmission.
[0053] Furthermore, step A130 in the method provided in this application embodiment includes: A131: The value certificate includes at least one of the following usage strategies: data usage validity period, data usage frequency limit, description of permitted uses of data, and data distribution restriction clauses; the value assessment indicators include at least one of the following: data quality score, data scarcity level, and data valuation information.
[0054] Optionally, firstly, the usage strategy is a set of rules that constrain the use of data assets, including at least one of the following: data usage validity period, data usage limit, description of permitted uses of data, and data distribution restriction clauses. Specifically, the data usage validity period clarifies the time frame within which the data can be legally used; the data usage limit specifies the maximum number of times the data can be decrypted and accessed, for example, no more than 10 times; the description of permitted uses of data defines the scenarios in which the data can be applied, such as using it only for internal business analysis and not for external commercial promotion; and the data distribution restriction clauses clarify whether the recipient is allowed to further distribute the data to other nodes, such as prohibiting forwarding to unauthorized edge nodes.
[0055] The acquisition of usage strategies relies on a metadata registry. When the cloud responds to the encrypted transmission command and locates the original data asset to be transmitted, it accesses the metadata registry using the data asset identifier of the original data asset as the sole query condition. Through the binding relationship between the data asset identifier and the predefined value attribute metadata in the metadata registry, the pre-configured usage strategy content corresponding to the data asset is extracted, ensuring that the acquired usage strategy accurately matches the target data asset without mismatch or omission.
[0056] Furthermore, the core function of the usage policy is to achieve compliant use control of data assets: after receiving the data packet, the edge node first parses the usage policy in the value certificate before performing the decryption operation, and verifies whether its current attributes (such as the number of times it has been used) or context (such as the current time and planned purpose) meet the rule requirements. For example, if the current time exceeds the validity period of the data use, or the number of times it has been used reaches the limit, the edge node will terminate the decryption process; only if it fully complies with the usage policy can the data continue to be decrypted, thereby avoiding the over-use, excessive access, unauthorized use or illegal distribution of data assets, and ensuring the controllability of the data asset use process.
[0057] Next, the value assessment indicators are a set of information that quantifies and describes the value characteristics of data assets, including at least one of the following: data quality score, data scarcity level, and data valuation information. The data quality score is a quantitative evaluation of the accuracy, completeness, timeliness, and consistency of the data, and can use a 100-point system. The data scarcity level reflects the degree of scarcity of the data asset among similar data, and examples can be categorized as: A (average), AA (scarce), AAA (extremely scarce), etc. The data valuation information is the assessment result of the economic or application value of the data asset, such as a monetary valuation of 50,000 yuan or an application value level of core business support.
[0058] The acquisition path of value assessment indicators is consistent with the above-mentioned usage strategy, both relying on the metadata registry. While locating the original data asset and calculating its national cryptographic SM3 hash value, the cloud will query the metadata registry through the data asset identifier, extract the pre-set value assessment indicator content from the predefined value attribute metadata bound to the identifier, and ensure that each data asset can correspond to exclusive value description information, providing a basis for subsequent value management.
[0059] Furthermore, the core role of value assessment indicators is to support the value-based management and differentiated control of data assets: the cloud can prioritize data assets based on value assessment indicators. For example, data assets with high data quality scores, high scarcity levels, and high valuations will be given priority in security resource allocation and enhanced verification processes during transmission. Edge nodes can also use value assessment indicators to clarify the importance of data assets, adopt stricter storage protection and usage record measures for high-value data assets, and optimize the usage efficiency of low-value data assets. Ultimately, this achieves refined value control of data assets and avoids the loss of value of high-value data due to improper management.
[0060] Furthermore, step A200 in the method provided in this application embodiment includes: A210: Identify the number of receivers based on the number of each receiving edge node. When the number of receivers exceeds the preset receiving threshold, issue an encryption command.
[0061] A220: In response to the encryption command, the cloud, based on the national cryptographic SM2 algorithm and broadcast encryption technology, uses a preset set of receiving edge node identities to perform an encryption operation on the data encryption key, generating a unified broadcast encrypted ciphertext.
[0062] A230: Each receiving edge node uses its own SM2 private key to decrypt the broadcast encrypted ciphertext. If the identity of each receiving edge node is within the preset receiving edge node identity set, the decryption is successful.
[0063] Specifically, when the number of receivers is extremely large, it may become a performance bottleneck, requiring all receivers to be encrypted at once. Specifically, after generating the encrypted data in the aforementioned steps, the cloud first identifies the number of receiving edge nodes and compares it with a preset receiving threshold. This threshold can be preset based on system performance, for example, set to 10 receiving edge nodes. When the number of receiving edge nodes does not exceed the preset receiving threshold, for example, when there are 8 receiving edge nodes, the cloud extracts the SM2 public key of each receiving edge node from its stored edge digital certificates. These edge digital certificates are obtained by the receiving edge nodes through registration with a private root certificate authority before deployment and are bound to the node's unique identity identifier.
[0064] Subsequently, the cloud invokes the national cryptographic SM2 algorithm, using the national cryptographic SM2 public key of each receiving edge node as the encryption key, and performs asymmetric encryption operation on the 128-bit data encryption key respectively. Finally, eight corresponding key ciphertexts are generated for the eight receiving edge nodes. Each key ciphertext can only be decrypted by the national cryptographic SM2 private key securely stored by its corresponding receiving edge node, ensuring the security of the targeted transmission of the data encryption key.
[0065] When the number of receiving edge nodes exceeds a preset receiving threshold, for example, if there are 20 edge nodes, the cloud will trigger an encryption command based on the number of identified receivers. In response to this command, the cloud will invoke the national cryptographic algorithm SM2 and combine it with broadcast encryption technology to first determine a preset set of receiving edge node identities. This set contains the unique identity information of the 20 edge nodes that need to receive data, and is pre-associated with the national cryptographic algorithm SM2 public-private key pair of each node.
[0066] Subsequently, the cloud uses this identity set as a basis to perform a single encryption operation on the 128-bit data encryption key, eliminating the need for separate encryption for each node, and ultimately generating a unified broadcast encrypted ciphertext. The generation of this broadcast encrypted ciphertext requires only one SM2 encryption operation, significantly reducing the number of encryption operations and lowering the cloud's performance consumption compared to the previous example which required encrypting 20 nodes separately.
[0067] Specifically: The cloud invokes the national cryptographic algorithm SM2 and integrates the core logic of broadcast encryption technology. First, based on the public key characteristics of all nodes within the preset set of receiving edge node identities using the national cryptographic algorithm SM2, it generates unified broadcast encryption parameters adapted to the national cryptographic algorithm SM2. These parameters integrate the authentication information of authorized nodes, eliminating the need to generate parameters separately for each node. Next, based on the generated unified broadcast encryption parameters, the cloud uses the 128-bit data encryption key as the encryption object and performs a complete encryption operation according to the standard encryption process of the national cryptographic algorithm SM2, including data preprocessing, round function operation, and nonlinear transformation. The entire process only requires one national cryptographic SM2 encryption operation, without needing to initiate encryption separately for each receiving edge node. Finally, this operation outputs a unified broadcast encrypted ciphertext. This ciphertext can only be decrypted by receiving edge nodes whose identities are within the preset set of receiving edge node identities using their own securely stored national cryptographic SM2 private key. Nodes whose identities are not within the set cannot obtain the data encryption key by decrypting with their private key.
[0068] Finally, after each receiving edge node receives the transmission data packet, which contains information such as encrypted data, encrypted keys, or broadcast encrypted data, it first performs a decryption operation using its own securely stored SM2 private key: if the data packet contains proprietary encrypted keys, the node directly decrypts it using its private key to obtain the data encryption key; if it contains unified broadcast encrypted data, when the node decrypts it using its private key, the system automatically verifies whether the node's identity is within the preset set of receiving edge node identities. If the identity matches, decryption is successful and the data encryption key is obtained. After obtaining the data encryption key, each receiving edge node then calls the SM4 algorithm to decrypt the encrypted data using the data encryption key, ultimately obtaining the original data asset, ensuring that only authorized nodes can complete the entire data decryption process.
[0069] By generating a data encryption key that conforms to the national cryptographic standard and combining it with the national cryptographic SM4 algorithm to obtain the data ciphertext, and then encrypting the data encryption key separately using the national cryptographic SM2 algorithm or by combining it with broadcast encryption technology according to the number of recipients, the data encryption key is encrypted once. This achieves the effect of ensuring the security of data asset transmission to multiple recipients, solving the encryption performance bottleneck when the number of recipients is extremely large, and improving the efficiency of data asset verification and transmission.
[0070] Furthermore, step A400 in the method provided in this application embodiment includes: A410: Before sending the data packets, the cloud requests each receiving edge node to provide an edge digital certificate.
[0071] A420: The cloud verifies the validity of the edge digital certificates of each receiving edge node, including verifying whether the edge digital certificate was issued by the private root certificate authority and is not on the certificate revocation list.
[0072] A430: After successful verification, the cloud uses the SM2 public key of each receiving edge node to encrypt the data encryption key.
[0073] In this embodiment of the application, the private root certificate authority is the core institution of the private public key PKI system. It is responsible for generating public and private key pairs, issuing digital certificates, and verifying the validity of certificates for entities within a specific scope, such as the cloud and receiving edge nodes.
[0074] Specifically, after the cloud completes the encryption of the original data assets to obtain the ciphertext, generates a value certificate and digital signature, it does not directly send out the transmission data packet. Instead, it first sends a request for edge digital certificates to all receiving edge nodes. For example, if data needs to be transmitted to 20 receiving edge nodes, the cloud will send a certificate request instruction to each of these 20 nodes. The instruction will carry the cloud's own identity identifier, which comes from the cloud digital certificate issued by the private root certificate authority. This is to allow the receiving edge nodes to verify the legitimacy of the request initiator and prevent unauthorized entities from obtaining the edge digital certificate.
[0075] Subsequently, each receiving edge node receives a certificate request from the cloud. Using the cloud digital certificate pre-installed in its own trusted storage area, it extracts the national cryptographic SM2 public key from the cloud, verifies the validity of the cloud identity identifier in the request instruction, and confirms that the request comes from a legitimate cloud. Then, it retrieves the edge digital certificate obtained from the private root certificate authority during the deployment phase from its own secure storage area. This certificate contains the node's unique identity identifier, the national cryptographic SM2 public key, and the issuance information of the private root certificate authority. The edge digital certificate is then fed back to the cloud to ensure that the certificate obtained by the cloud is accurately associated with the corresponding node.
[0076] Next, after the cloud receives the edge digital certificate from each receiving edge node, it initiates the certificate validity verification process: The first step is to verify whether the issuing authority of the edge digital certificate is the preset private root certificate authority. By comparing the information in the issuer field of the certificate with the unique identifier of the private root certificate authority, such as the authority name and certificate serial number, it is determined whether the certificate is issued by a legitimate authority.
[0077] The second step involves querying the pre-obtained certificate revocation list. This list records all edge digital certificates revoked by the private root certificate authority for reasons such as expiration, key leakage, or node shutdown. If a certificate of an edge node is on this list, it is deemed invalid. For example, if one of the 20 nodes has a certificate issued by a node other than the private root certificate authority, and another node's certificate is on the revocation list, then the certificate verification for these two nodes will fail. The cloud will exclude these two nodes and only perform subsequent operations on the remaining 18 successfully verified nodes.
[0078] Finally, for receiving edge nodes whose edge digital certificates have been verified, the cloud extracts the corresponding national cryptographic SM2 public key from their edge digital certificates. These public keys are bound to the unique identity of the node to ensure the accuracy of the public key ownership. Subsequently, the cloud calls the national cryptographic SM2 algorithm and uses the national cryptographic SM2 public key of each verified node as the encryption key to perform asymmetric encryption operations on the previously generated data encryption key used to decrypt the data ciphertext. This generates a unique key ciphertext for each verified node. Nodes that fail verification will not obtain the corresponding key ciphertext and cannot participate in subsequent data decryption.
[0079] By requesting and verifying the validity of the edge digital certificate of the receiving edge node before sending out the transmission data packet, the cloud uses its national cryptographic SM2 public key to encrypt the data encryption key only for the verified node. This achieves the effect of filtering out legally authorized receiving edge nodes, preventing illegal nodes from obtaining the key ciphertext, and further strengthening the security defense of multi-receiver data asset transmission.
[0080] Furthermore, step A500 in the method provided in this application embodiment includes: A510: Verify the validity of the digital signature using the SM2 public key in the cloud.
[0081] A520: After successful verification, locate the key ciphertext corresponding to the SM2 private key of each receiving edge node from the transmitted data packet and decrypt it. If the decryption is successful, obtain the data encryption key.
[0082] A530: Use the data encryption key to decrypt the ciphertext of the data to obtain the decrypted original data.
[0083] A540: Calculate the SM3 hash value of the decrypted original data and compare it with the data hash value declared in the value certificate to verify the data integrity and consistency with the value certificate.
[0084] Specifically, after receiving the transmission data packet, each receiving edge node first initiates the digital signature verification process. Since each receiving edge node has extracted and stored the cloud's SM2 public key from the pre-installed cloud digital certificate during the deployment phase, the node will now use this public key to verify the validity of the digital signature in the transmission data packet according to the national cryptographic SM2 algorithm's signature verification specifications. The digital signature is generated by the cloud using its own SM2 private key to sign the value certificate. The verification process needs to confirm whether the signature was legitimately issued by the cloud and whether the value certificate has been tampered with during transmission. Assuming there are 8 receiving edge nodes, 7 nodes will verify the validity of the digital signature using the cloud's SM2 public key, and 1 node will fail verification due to a mismatch between the signature and public key. The node that fails verification will directly terminate subsequent verification operations, and only the 7 nodes that pass verification will proceed to the next step.
[0085] Next, after the digital signature verification is successful, each receiving edge node will select the corresponding key ciphertext from the transmitted data packet. The transmitted data packet contains multiple key ciphertexts, each generated by encryption using the corresponding receiving edge node's national cryptographic standard SM2 public key. Each receiving edge node's national cryptographic standard SM2 private key is securely stored by itself and its deployment phase is bound to the node's unique identity identifier. In the example above, among the seven verified nodes, each node will locate its unique key ciphertext based on its own identity identifier, and then use its securely stored national cryptographic standard SM2 private key to decrypt the key ciphertext. If decryption is successful, the node can obtain the data encryption key used to decrypt the data ciphertext; if decryption fails, such as when the key ciphertext and private key do not match, the data encryption key cannot be obtained, and the subsequent process terminates.
[0086] After obtaining the data encryption key, each receiving edge node invokes the Chinese national cryptographic standard SM4 algorithm, using the encryption key as the decryption key, to decrypt the ciphertext in the transmitted data packet. The ciphertext is generated by the cloud using the SM4 algorithm to encrypt the original data asset. For example, if a node receives a data packet containing 3GB of ciphertext, the node can obtain the decrypted original data identical to the original data asset in the cloud by using the encryption key and following the SM4 decryption process. If the encryption key is incorrect or the ciphertext is corrupted, decryption will fail, the node will not obtain valid original data, and the process will terminate.
[0087] Finally, each receiving edge node performs an integrity check on the decrypted original data. The node invokes the national cryptographic algorithm SM3 to calculate the hash value of the decrypted original data. Regardless of the original data size, a fixed-length 256-bit hash value is generated. Then, a pre-declared data hash value is extracted from the value certificate of the transmitted data packet. This hash value is the national cryptographic algorithm SM3 hash value calculated by the cloud for the original data asset. The two are compared. If the two hash values match perfectly, it means that the decrypted original data has not been tampered with during transmission and completely matches the data asset described in the value certificate; if they do not match, the data integrity is deemed compromised, and the node will refuse to use the data.
[0088] By receiving edge nodes sequentially performing a multi-level verification process—including digital signature verification, key ciphertext decryption to obtain the data encryption key, data ciphertext decryption to obtain the original data, and comparison of the original data hash value with the value certificate hash value—the system achieves the following effects: ensuring that only legitimate nodes can obtain valid data, verifying the legality of the data source and the integrity of the transmission, and guaranteeing the accurate matching of data assets and value certificates.
[0089] Furthermore, step A520 in the method provided in this application embodiment includes: A521: Parse the usage strategy in the value certificate, verify whether its current attributes or context environment comply with the usage strategy, and if so, continue to perform the decryption operation.
[0090] In one embodiment, after completing the digital signature validity verification, each receiving edge node does not directly locate the key ciphertext corresponding to its own SM2 private key from the transmitted data packet. Instead, it first extracts the value certificate from the transmitted data packet. The value certificate is a structured data object generated in the cloud in the aforementioned steps, which includes data hash value, value assessment index and usage strategy.
[0091] Next, the receiving edge node will proactively acquire its current attributes and context, which are the core basis for verifying compliance with the usage policy. Specifically, the node will read its own system's current time to verify whether it is within the data usage validity period; query the historical usage records of the data asset stored locally to count the number of uses and determine whether the limit has been exceeded; confirm the planned purpose of the received data, such as for monitoring and analyzing the operational status of devices in a certain area; and also verify whether its own network environment, device identity, and other contextual information comply with the potential environmental constraints in the usage policy, such as some usage policies that may restrict usage to nodes in specific network segments.
[0092] Subsequently, the receiving edge nodes initiate a verification process, comparing the extracted usage policy with their current attributes and context. If the usage policy includes a data usage validity period, the node will determine if the current time is within the validity period; if it includes a usage limit, it will confirm if the number of uses has been less than the limit; if it includes a description of permitted uses, it will check if the planned use matches the permitted use; if it includes distribution restrictions, it will verify whether it has any risk of unauthorized distribution. For example, suppose 15 receiving edge nodes perform this verification simultaneously. If 2 nodes' current time has exceeded the data usage validity period, 3 nodes have reached the usage limit, and 1 node's planned use does not meet the permitted range, these 6 nodes will terminate the subsequent decryption operation due to failing the verification; the remaining 9 nodes will meet all verification requirements of the usage policy and will be granted permission to continue the subsequent operation.
[0093] Finally, receiving edge nodes that pass verification will continue with the subsequent process, locating the ciphertext corresponding to their own SM2 private key from the transmitted data packets, and preparing to decrypt it to obtain the data encryption key. Nodes that fail verification will directly refuse to locate and decrypt the ciphertext and will not obtain the data encryption key, thus being unable to decrypt the data. This pre-verification step screens node access permissions and compliance early in the data decryption process, avoiding the risk of non-compliant nodes attempting to decrypt data after obtaining the key.
[0094] By receiving edge nodes' steps of parsing the usage strategy in the value certificate before decrypting the key ciphertext, and verifying whether their current attributes and context are compliant, the system achieves the effect of screening compliant nodes in the data decryption process, preventing data assets from being used beyond their expiration date, excessively accessed, or used for unauthorized purposes, and further strengthening the control over the use of data assets.
[0095] Furthermore, step A520 in the method provided in this application embodiment includes: A522: The SM2 public key in the cloud and the SM2 public keys of each receiving edge node are generated, distributed, and managed through a private public key PKI system, specifically including: Before deployment, each receiving edge node binds its unique identifier to an SM2 public-private key pair generated by a private root certificate authority (CCA) and registers with the CCA. The CCA then issues edge digital certificates for each receiving edge node. Each receiving edge node securely stores its own SM2 private key, while the edge digital certificates are delivered to the cloud for storage. The cloud registers with the CCA, which issues cloud digital certificates. The cloud's SM2 private key is securely stored in the cloud, while the cloud digital certificates are distributed and pre-installed in the trusted storage area of each receiving edge node.
[0096] In this embodiment of the application, the private public key PKI system refers to the public key infrastructure that generates, distributes and manages public and private key pairs and digital certificates of entities within a specific scope (such as cloud and edge nodes) by a private root certificate authority, and is used for entity identity authentication and encryption operations within that scope.
[0097] Optionally, during the deployment phase of the receiving edge nodes, assuming there are 20 receiving edge nodes that need to connect to the system, each receiving edge node has a unique identity, such as the first edge receiving node to the twentieth edge receiving node. First, the private root certificate authority generates a separate SM2 public-private key pair for each receiving edge node according to the national cryptographic standard. This public-private key pair has the randomness and anti-cracking properties required by the national cryptographic standard.
[0098] Subsequently, each receiving edge node associates its unique identifier with its corresponding SM2 public / private key pair to ensure accurate correspondence between node identity and key. After binding, each receiving edge node submits a registration request to the private root certificate authority, which includes the bound identifier and SM2 public key information. The private root certificate authority verifies the legality of the registration information, such as verifying the uniqueness of the identifier. If the verification is successful, it issues a unique edge digital certificate to each receiving edge node. This certificate encapsulates the node's unique identifier, SM2 public key, and the issuing identifier of the private root certificate authority, serving as proof of the node's identity and the legitimacy of its SM2 public key.
[0099] Subsequently, after obtaining the edge digital certificate issued by the private root certificate authority, each receiving edge node stores its corresponding SM2 private key in a local secure storage module, such as a hardware security chip or encrypted storage partition. This module only allows authorized decryption operations within the node to access the SM2 private key, effectively preventing unauthorized theft or tampering. Simultaneously, each receiving edge node delivers the generated edge digital certificate to the cloud via an encrypted communication link. The cloud stores these edge digital certificates uniformly in a dedicated encrypted certificate database and creates an index for each certificate that is associated with the node's unique identity, facilitating rapid location and retrieval of the corresponding node's SM2 public key.
[0100] Next, after collecting edge digital certificates from all receiving edge nodes, the cloud initiates its interaction process with the private root certificate authority. Specifically, the cloud submits a registration application to the private root certificate authority, which includes the cloud's system identity information, such as "Multi-receiver data transmission cloud-001". After verifying the legitimacy and compliance of the cloud's identity, the private root certificate authority generates an SM2 public-private key pair conforming to Chinese cryptographic standards for the cloud, and issues a cloud digital certificate based on this key pair and the cloud's identity information. The cloud stores its SM2 private key in a trusted and secure storage area, such as a dedicated confidential partition on the cloud's encryption server, and uses it only for subsequent signing operations on value credentials.
[0101] Finally, the cloud uses a secure distribution protocol to push the issued cloud digital certificates in batches to all receiving edge nodes. After receiving the certificates, each receiving edge node pre-installs the cloud digital certificates in its own trusted storage area, such as the node's trusted flash memory partition, to ensure that the cloud's SM2 public key can be directly extracted when verifying digital signatures later.
[0102] By receiving edge nodes and the cloud respectively registering with the private root certificate authority to obtain digital certificates, securely storing their own SM2 private keys and interactively storing / pre-setting the other party's certificates, the system achieves the effect of securely generating, orderly distributing and standardizing the management of SM2 public keys between the cloud and each receiving edge node based on the private public key PKI system, providing a legitimate and secure key foundation for subsequent data encryption key encryption and digital signature verification.
[0103] Furthermore, step A522 in the method provided in this application embodiment includes: A522-1: The cloud obtains the edge digital certificates of each edge node and extracts the national cryptographic SM2 public key of each receiving edge node from the certificate, which is used to encrypt the data encryption key.
[0104] A522-2: Each receiving edge node extracts the SM2 public key from the pre-set cloud digital certificate to verify the validity of the digital signature.
[0105] In this embodiment, the edge digital certificate is obtained by the receiving edge node from the private root certificate authority before deployment. It contains the node's unique identity identifier and the Chinese national cryptographic standard SM2 public key, serving as a credential to prove the node's identity and the legitimacy of the public key. The cloud digital certificate is issued by the private root certificate authority to the cloud, containing the cloud's identity information and the cloud's SM2 public key, serving as a credential to prove the cloud's identity and the legitimacy of the public key.
[0106] In one embodiment, the cloud first extracts the SM2 public key of each receiving edge node from the edge digital certificates of each receiving edge node stored in its own storage. The public key is the public key of the SM2 asymmetric encryption algorithm, which only has encryption function and needs to be used in conjunction with the SM2 private key of the corresponding node to decrypt the data. These extracted public keys will be used for subsequent encryption operations on the data encryption key to ensure that each receiving edge node can only decrypt the exclusive key ciphertext with its own securely stored SM2 private key.
[0107] At the same time, each receiving edge node extracts the cloud's SM2 public key from the cloud digital certificate pre-installed in its own trusted storage area. This public key will be used to verify the validity of the digital signature in the transmitted data packet. The digital signature is a unique identifier generated by the cloud using its own SM2 private key for the value certificate. By verifying the signature through the cloud's SM2 public key, it can be confirmed that the value certificate comes from a legitimate cloud and has not been tampered with during transmission.
[0108] By extracting the national cryptographic SM2 public key from the edge digital certificate in the cloud for use as an encryption key for encrypting data, and extracting the cloud SM2 public key from the cloud digital certificate for use as a verification digital signature, the system achieves the effect of ensuring the security of the targeted transmission of data encryption keys and the legitimacy of the source of digital signatures, and provides key key and signature verification support for the verification and transmission of data assets by multiple recipients.
[0109] In summary, the multi-receiver data asset verification and transmission method based on national cryptographic algorithms provided in this application has the following technical effects: This application assesses the value of original data assets in the cloud and simultaneously calculates hash values using the national cryptographic SM3 algorithm to generate value certificates. It then encrypts the original data assets using the national cryptographic SM4 algorithm and a data encryption key to obtain ciphertext. Next, it uses the national cryptographic SM2 public key of each receiving edge node to encrypt the data encryption key, obtaining corresponding key ciphertext. Subsequently, the cloud uses the SM2 private key to sign the value certificate, generating a digital signature. The data ciphertext, key ciphertext, value certificate, and digital signature are combined into a transmission data packet and sent to each receiving edge node. Each receiving edge node performs multi-level verification upon receipt, thereby achieving secure verification and transmission of data assets from multiple recipients. This makes the security, integrity, and verifiability of data asset transmission in multi-recipient scenarios more accurate and reliable, achieving the technical effects of secure transmission, controllable value, and efficient verification in multi-recipient data asset transmission.
[0110] Example 2, as Figure 2 As shown, based on the same inventive concept as Embodiment 1 above, this application provides a multi-receiver data asset verification and transmission system based on national cryptographic algorithms, the system comprising: Value certificate generation module 1 is used to evaluate the value of the original data assets in the cloud, and simultaneously use the national cryptographic SM3 algorithm to calculate the hash value to generate a value certificate, which includes the data hash value, value evaluation index and usage strategy.
[0111] The key ciphertext acquisition module 2 is used to call the national cryptographic SM4 algorithm and the data encryption key to encrypt the original data asset to obtain data ciphertext, and use the national cryptographic SM2 public key of each receiving edge node to encrypt the data encryption key to obtain the key ciphertext corresponding to each edge node.
[0112] Digital signature generation module 3 is used to sign the value certificate using the SM2 private key in the cloud to generate a digital signature.
[0113] The data packet acquisition module 4 is used to send the data packet, which is composed of the encrypted data, the key encrypted text corresponding to each edge node, the value certificate and the digital signature, to each receiving edge node.
[0114] The multi-level verification execution module 5 is used by each receiving edge node to perform multi-level verification after receiving the transmitted data packet.
[0115] Furthermore, the multi-level verification execution module 5 is used to perform the following steps: The validity of the digital signature is verified using the SM2 public key in the cloud. After successful verification, the ciphertext corresponding to the SM2 private key of each receiving edge node is located in the transmitted data packet and decrypted. If decryption is successful, the data encryption key is obtained. The ciphertext is decrypted using the data encryption key to obtain the decrypted original data. The SM3 hash value of the decrypted original data is calculated and compared with the data hash value declared in the value certificate to verify the data integrity and consistency with the value certificate.
[0116] Furthermore, the multi-level verification execution module 5 is used to perform the following steps: The SM2 public key in the cloud and the SM2 public keys of each receiving edge node are generated, distributed, and managed through a private public key PKI system, specifically including: Before deployment, each receiving edge node binds its unique identifier to an SM2 public-private key pair generated by a private root certificate authority (CCA) and registers with the CCA. The CCA then issues edge digital certificates for each receiving edge node. Each receiving edge node securely stores its own SM2 private key, while the edge digital certificates are delivered to the cloud for storage. The cloud registers with the CCA, which issues cloud digital certificates. The cloud's SM2 private key is securely stored in the cloud, while the cloud digital certificates are distributed and pre-installed in the trusted storage area of each receiving edge node.
[0117] Furthermore, the multi-level verification execution module 5 is used to perform the following steps: The cloud obtains the edge digital certificates of each edge node and extracts the national cryptographic SM2 public key of each receiving edge node from the certificates, which is used to encrypt the data encryption key; each receiving edge node extracts the cloud's SM2 public key from the preset cloud digital certificate, which is used to verify the validity of the digital signature.
[0118] Furthermore, the data packet acquisition module 4 is used to perform the following steps: Before sending the data packets, the cloud first requests each receiving edge node to provide an edge digital certificate. The cloud verifies the validity of the edge digital certificate of each receiving edge node, including verifying whether the edge digital certificate was issued by the private root certificate authority and is not on the certificate revocation list. After the verification is successful, the cloud uses the SM2 public key of each receiving edge node to encrypt the data encryption key.
[0119] Furthermore, the value certificate generation module 1 is used to perform the following steps: In response to the encrypted transmission command, the original data asset to be transmitted is located according to the data asset identifier in the encrypted transmission command; the SM3 hash value of the original data asset is calculated as the data hash value; the metadata registry is queried to obtain the predefined value attribute metadata bound to the data asset identifier, and the value assessment indicators and usage strategies are extracted; a structured data object is constructed, and the data hash value, the value assessment indicators and the usage strategies are encapsulated in the data object to generate the value certificate.
[0120] Furthermore, the value certificate generation module 1 is used to perform the following steps: The value certificate includes at least one of the following usage strategies: data usage validity period, data usage limit, description of permitted uses of data, and data distribution restriction clauses; the value assessment indicators include at least one of the following: data quality score, data scarcity level, and data valuation information.
[0121] Furthermore, the multi-level verification execution module 5 is used to perform the following steps: The usage strategy in the value certificate is parsed, and the user's current attributes or context are verified to meet the requirements of the usage strategy. If they do, the decryption operation is continued.
[0122] Furthermore, the key ciphertext acquisition module 2 is used to perform the following steps: The number of receivers is identified based on the number of each receiving edge node. When the number of receivers exceeds a preset receiving threshold, an encryption command is issued. In response to the encryption command, the cloud uses the national cryptographic SM2 algorithm and broadcast encryption technology, and a preset set of receiving edge node identities, to perform an encryption operation on the data encryption key, generating a unified broadcast encrypted ciphertext. Each receiving edge node uses its own SM2 private key to decrypt the broadcast encrypted ciphertext. If the identity of each receiving edge node is within the preset set of receiving edge node identities, the decryption is successful.
[0123] The multi-receiver data asset verification and transmission system based on national cryptographic algorithms provided in this invention can execute the multi-receiver data asset verification and transmission method based on national cryptographic algorithms provided in any embodiment of this invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0124] Although this application makes various references to certain modules in the system according to the embodiments of this application, any number of different modules can be used and run on user terminals and / or servers. The various units and modules included are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be achieved; in addition, the specific names of each functional unit are only for easy distinction between each other and are not used to limit the scope of protection of this invention.
[0125] The specific embodiments described above do not constitute a limitation on the scope of protection of this application. Those skilled in the art should understand that various modifications, combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this application should be included within the scope of protection of this application. In some cases, the actions or steps described in this application can be performed in a different order than that shown in the embodiments and still achieve the desired results. Furthermore, the processes depicted in the accompanying drawings do not necessarily require a specific or sequential order to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
Claims
1. A multi-receiver data asset verification and transmission method based on national cryptographic algorithms, characterized in that, include: The raw data assets are valued in the cloud, and the hash value is calculated using the national cryptographic SM3 algorithm to generate a value certificate, which includes the data hash value, value assessment indicators and usage strategies. The original data asset is encrypted by calling the national cryptographic SM4 algorithm and the data encryption key to obtain the data ciphertext. The data encryption key is then encrypted using the national cryptographic SM2 public key of each receiving edge node to obtain the key ciphertext corresponding to each edge node. The value certificate is signed using the SM2 private key in the cloud to generate a digital signature; The cloud will combine the encrypted data, the encrypted key corresponding to each edge node, the value certificate, and the digital signature into a transmission data packet and send it to each receiving edge node. After receiving the transmitted data packet, each receiving edge node performs multi-level verification.
2. The multi-receiver data asset verification and transmission method based on national cryptographic algorithms as described in claim 1, characterized in that, After receiving the transmitted data packet, each receiving edge node performs multi-level verification, including: Verify the validity of the digital signature using the SM2 public key in the cloud; After successful verification, the key ciphertext corresponding to the SM2 private key of each receiving edge node is located from the transmitted data packet and decrypted. If the decryption is successful, the data encryption key is obtained. The encrypted data is decrypted using the data encryption key to obtain the decrypted original data. Calculate the SM3 hash value of the decrypted original data and compare it with the data hash value declared in the value certificate to verify the data integrity and consistency with the value certificate.
3. The multi-receiver data asset verification and transmission method based on national cryptographic algorithms as described in claim 2, characterized in that, The SM2 public key in the cloud and the SM2 public keys of each receiving edge node are generated, distributed, and managed through a private public key PKI system, specifically including: Before deployment, each receiving edge node binds its unique identifier to an SM2 public-private key pair generated by a private root certificate authority and registers with the private root certificate authority, which then issues each edge digital certificate to the receiving edge node. Each receiving edge node securely stores its own SM2 private key, while each edge digital certificate is delivered to the cloud for storage. The cloud registers with the private root certificate authority, which then issues a cloud digital certificate. The SM2 private key in the cloud is securely stored in the cloud, while the cloud digital certificate is distributed and pre-installed in the trusted storage area of each receiving edge node.
4. The multi-receiver data asset verification and transmission method based on national cryptographic algorithms as described in claim 3, characterized in that, The cloud obtains the edge digital certificates of each edge node and extracts the national cryptographic SM2 public key of each receiving edge node from the certificates, which is used to encrypt the data encryption key; Each receiving edge node extracts the cloud's SM2 public key from a pre-set cloud digital certificate to verify the validity of the digital signature.
5. The multi-receiver data asset verification and transmission method based on national cryptographic algorithms as described in claim 4, characterized in that, Before sending the data packets, the cloud first requests each receiving edge node to provide an edge digital certificate; The cloud verifies the validity of the edge digital certificates of each receiving edge node, including verifying whether the edge digital certificate was issued by the private root certificate authority and is not on the certificate revocation list; After successful verification, the cloud uses the SM2 public key of each receiving edge node to encrypt the data encryption key.
6. The multi-receiver data asset verification and transmission method based on national cryptographic algorithms as described in claim 1, characterized in that, The raw data assets are valued in the cloud, and the hash value is calculated simultaneously using the national cryptographic algorithm SM3 to generate a value certificate, which includes the data hash value, value assessment indicators, and usage strategies, including: In response to the encrypted transmission command, the original data asset to be transmitted is located according to the data asset identifier in the encrypted transmission command; Calculate the SM3 hash value of the original data asset as the data hash value; Query the metadata registry to obtain predefined value attribute metadata bound to the data asset identifier, and extract value assessment indicators and usage strategies; A structured data object is constructed, in which the data hash value, the value assessment index, and the usage strategy are encapsulated to generate the value certificate.
7. The multi-receiver data asset verification and transmission method based on national cryptographic algorithms as described in claim 6, characterized in that, The value certificate includes at least one of the following usage strategies: data usage validity period, data usage limit, description of permitted uses of data, and data distribution restriction clauses; the value assessment indicators include at least one of the following: data quality score, data scarcity level, and data valuation information.
8. The multi-receiver data asset verification and transmission method based on national cryptographic algorithms as described in claim 1, characterized in that, Before locating and decrypting the ciphertext corresponding to the SM2 private key of each receiving edge node from the transmitted data packet, the process further includes: The usage strategy in the value certificate is parsed, and the user's current attributes or context are verified to meet the requirements of the usage strategy. If they do, the decryption operation is continued.
9. The multi-receiver data asset verification and transmission method based on national cryptographic algorithms as described in claim 1, characterized in that, After encrypting the original data asset using the national cryptographic SM4 algorithm and data encryption key to obtain the ciphertext, the process further includes: The number of receivers is identified based on the number of each receiving edge node. When the number of receivers exceeds the preset receiving threshold, an encryption command is issued. In response to the encryption command, the cloud, based on the national cryptographic SM2 algorithm and broadcast encryption technology, uses a preset set of receiving edge node identities to perform an encryption operation on the data encryption key, generating a unified broadcast encrypted ciphertext; Each receiving edge node uses its own SM2 private key to decrypt the broadcast encrypted ciphertext. If the identity of each receiving edge node is within the preset receiving edge node identity set, the decryption is successful.
10. A multi-receiver data asset verification and transmission system based on national cryptographic algorithms, characterized in that, The system is used to implement the multi-receiver data asset verification and transmission method based on national cryptographic algorithms as described in any one of claims 1-9, the system comprising: The value certificate generation module is used to evaluate the value of raw data assets in the cloud, and simultaneously use the national cryptographic SM3 algorithm to calculate hash values and generate value certificates, which include data hash values, value evaluation indicators and usage strategies. The key ciphertext acquisition module is used to call the national cryptographic SM4 algorithm and the data encryption key to encrypt the original data asset to obtain the data ciphertext, and use the national cryptographic SM2 public key of each receiving edge node to encrypt the data encryption key to obtain the key ciphertext corresponding to each edge node. The digital signature generation module is used to sign the value certificate using the SM2 private key in the cloud to generate a digital signature; The data packet acquisition module is used to send the data packet, the key ciphertext corresponding to each edge node, the value certificate and the digital signature together in the cloud to each receiving edge node. The multi-level verification execution module is used to perform multi-level verification after each receiving edge node receives the transmitted data packet.
Citation Information
Cited By
Electronic bill mutual identification verification system and method based on data sharing
CN121526589A