Chip-based transmission encryption and decryption method, system, device, medium and product
Patent Information
- Application Number
- CN202511772512.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-28
- Publication Date
- 2026-09-29
- Estimated Expiration
- 2045-11-28
AI Technical Summary
然而,在实际的工作中,各单位在日常办公中很多的敏感性数据的传输与使用均没有采用配套的安全防护,存在严重的安全隐患问题,极易导致数据泄露
本申请提供了一种基于芯片技术的传输加、解密方法、系统、介质,通过步骤在身份认证通过后,所述第一芯片级安全套件根据预置的密钥更新方案与设备管理平台进行密钥同步以获取经所述设备管理平台认证后的第一密钥,解决了传统密钥容易被破解,通过设备管理平台,实现了对成千上万终端设备的统一密钥策略下发、身份权限管理和安全审计,提高了密钥的安全性和灵活性。通过利用加密芯片的SM4加密引擎和所述第一密钥对所述明文进行加密生成文件密文;利用所述第一芯片设备上的加密芯片的SM2加密引擎和所述公钥对所述第一密钥进行加密以生成密钥密文。通过加密芯片和对密钥进行策略化生命周期管理,有效防止了基于软件的数据窃取和密钥泄露,满足了高等级的数据保密要求。
Smart Images

Figure CN121486062B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of secure data transmission, and in particular to a method, system, device, medium, or product for transmitting encryption and decryption based on chip technology. Background Technology
[0002] With the development of technologies such as big data, artificial intelligence, cloud computing, and blockchain, the speed and scale of data generation, collection, storage, and utilization are constantly expanding, and the value of data is becoming increasingly prominent. However, in actual work, many organizations do not employ corresponding security protections for the transmission and use of sensitive data in their daily office work, posing serious security risks and making data leaks highly likely.
[0003] Software-based encryption is vulnerable to monitoring and tampering because it lacks a relatively isolated and secure environment, making it susceptible to computer viruses and thus not highly secure. Furthermore, traditional encryption methods cannot adapt to scenarios with surging encryption demands. For example, when large numbers of files need to be encrypted and transmitted, manually transferring sensitive data and files is costly, and timeliness and efficiency cannot be guaranteed. Summary of the Invention
[0004] The purpose of this application is to provide a chip-based encryption and decryption method, system, and medium for data transmission, which can ensure the security of file transmission, reduce or eliminate the cost of manually transferring sensitive data and files, and improve work efficiency and timeliness.
[0005] To achieve the above objectives, this application provides the following solution: Firstly, this application provides a transmission encryption method based on chip technology, the transmission encryption method based on chip technology comprising: Obtain access information from the sender that initiates the first chip-level security suite on the first chip device, and perform identity authentication to confirm the sender's user identity and the legitimacy of the first chip device; After successful identity authentication, the first chip-level security suite synchronizes its keys with the device management platform according to a preset key update scheme to obtain the first key authenticated by the device management platform. The first chip-level security suite obtains a list of one or more receiving devices determined by the sender's user permissions from the device management platform, the list containing the public keys of the receiving devices; Obtain plaintext and the receiving device, and use the SM4 encryption engine of the encryption chip on the first chip device and the first key to encrypt the plaintext to generate ciphertext. The first key is encrypted using the SM2 encryption engine and the public key to generate key ciphertext; The encrypted file and the encrypted key are sent to the receiving device via a communication channel for decryption.
[0006] Optionally, the key update scheme is one of the following: Permanent key scheme: The first chip-level security suite synchronizes a long-term valid key from the device management platform; Periodic key scheme: The first chip-level security suite determines whether the current time is within the key validity period. If so, it uses the local key; otherwise, it synchronizes and updates the key from the device management platform. Dynamic key scheme: The first chip-level security suite synchronously generates a new key in real time from the device management platform each time an operation is performed.
[0007] Optionally, the authentication steps include: Verify user IDs to deny unauthorized access; Verify the mapping relationship between the user ID and the first chip device ID; Based on the user identity associated with the mapping relationship, the corresponding security policy is enforced on the first chip device.
[0008] Secondly, this application provides a transmission decryption method based on chip technology, including: Obtain the ciphertext of the file and the ciphertext of the key as described above using a communication channel; Obtain access information from the recipient to launch the second chip-level security suite on the second chip device, and perform identity authentication to confirm the identity of the recipient user and the legitimacy of the second chip device; After successful identity authentication, the second chip-level security suite synchronizes its keys with the device management platform according to a preset key update scheme to obtain the private key authenticated by the device management platform. The first key is obtained by decrypting the ciphertext of the key using the private key and the SM2 encryption engine of the encryption chip on the second chip device; The ciphertext of the file is decrypted using the SM4 encryption engine of the encryption chip on the second chip device and the first key to obtain the plaintext.
[0009] In some embodiments, the key update scheme is one of the following: Permanent key scheme: The second chip-level security suite synchronizes long-term valid keys from the device management platform; Periodic key scheme: The second chip-level security suite determines whether the current time is within the key validity period. If so, it uses the local key; otherwise, it synchronizes and updates the key from the device management platform. Dynamic key scheme: The second chip-level security suite synchronizes a new key generated in real time from the device management platform each time an operation is performed.
[0010] Optional, the authentication steps include: Verify user IDs to deny unauthorized access; Verify the mapping relationship between the user ID and the second chip device ID; Based on the user identity associated with the mapping relationship, the corresponding security policy is enforced on the second chip device.
[0011] Thirdly, this application provides a data security transmission system, including: The identity authentication module is used to authenticate the identity of users and chip devices; The key management module is used to interact with the remote device management platform according to the preset key update scheme to complete the synchronization of user keys and generate the first key and / or private key; An encryption module is used to encrypt the first key with the receiver's public key to generate key ciphertext and to encrypt plaintext with the first key and the SM4 encryption engine on the chip device to generate file ciphertext. The decryption module is used to decrypt the ciphertext of the key using the recipient's private key and extract the first key, and then use the first key and the SM4 encryption engine to decrypt the ciphertext of the file and extract the plaintext.
[0012] Fourthly, this application provides a computer device, including: a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the chip-based transmission encryption method of any of the above embodiments, and / or the steps of the chip-based decryption method of any of the above embodiments.
[0013] Fifthly, this application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the chip-based transmission encryption method as described in any of the above embodiments, and / or the chip-based decryption method as described in any of the above embodiments.
[0014] Sixthly, this application provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the chip-based transmission encryption method of any of the above embodiments, and / or the steps of the chip-based decryption method of any of the above embodiments.
[0015] According to the specific embodiments provided in this application, the following technical effects are disclosed: This application provides a chip-based encryption and decryption method, system, and medium. After successful authentication, the first chip-level security suite synchronizes its keys with the device management platform according to a pre-set key update scheme to obtain a first key authenticated by the device management platform. This solves the problem of traditional keys being easily cracked. Through the device management platform, unified key policy distribution, identity and access management, and security auditing are achieved for thousands of terminal devices, improving key security and flexibility. The plaintext is encrypted using the SM4 encryption engine of the encryption chip and the first key to generate ciphertext; the first key is then encrypted using the SM2 encryption engine of the encryption chip on the first chip device and the public key to generate key ciphertext. Through encryption chip and policy-based lifecycle management of keys, software-based data theft and key leakage are effectively prevented, meeting high-level data confidentiality requirements. Attached Figure Description
[0016] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0017] Figure 1 This is a flowchart of a chip-based transmission encryption method according to an embodiment of this application; Figure 2 A schematic diagram illustrating the process of generating ciphertext for a chip-based transmission encryption method according to an embodiment of this application; Figure 3 A schematic diagram illustrating the process of generating key ciphertext in a chip-based transmission encryption method according to an embodiment of this application; Figure 4 A schematic flowchart illustrating a chip-based transmission decryption method according to another embodiment of this application; Figure 5 A schematic diagram illustrating the process of decrypting the first key using a chip-based transmission decryption method, provided in another embodiment of this application; Figure 6 This is a schematic diagram illustrating the process of decrypting plaintext using a chip-based transmission decryption method, as provided in another embodiment of this application. Detailed Implementation
[0018] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0019] To make the above-mentioned objectives, features and advantages of this application more apparent and understandable, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0020] The purpose of this application is to provide a chip-based encryption and decryption method, system, and medium for data transmission, which can ensure the security of file transmission, reduce or eliminate the cost of manually transferring sensitive data and files, and improve work efficiency and timeliness.
[0021] To achieve the above objectives, this application provides the following solution: In one exemplary embodiment, please refer to Figure 1 This application provides a chip-based transmission encryption method. The method includes: obtaining access information from the sender that initiates a first chip-level security suite on a first chip device, and performing identity authentication to confirm the sender's user identity and the legitimacy of the first chip device. After successful authentication, the first chip-level security suite synchronizes keys with the device management platform according to a preset key update scheme to obtain a first key authenticated by the device management platform. The first chip-level security suite obtains a list of one or more receiver devices determined by the sender's user permissions from the device management platform. This list contains the public keys of the receiver devices. Specifically, the sender user sends a request to the device management platform. Upon receiving the request, the device management platform collects the registered, legitimate receiver device IDs within the current user's permission scope. This allows the user to select the receiver, so the device management platform can distribute the public key of the selected receiver to the receiving user. Please refer to [link to relevant documentation]. Figure 2 The process involves obtaining the plaintext and the receiving device, then using the SM4 encryption engine of the encryption chip and the first key to encrypt the plaintext and generate the ciphertext file. Please refer to [link to relevant documentation]. Figure 3 The first key is encrypted using the SM2 encryption engine and public key of the encryption chip on the first chip device to generate key ciphertext. The ciphertext file and the key ciphertext are then sent to the receiving device via a communication channel for decryption. It should be noted that the communication channel can be a self-built local area network or any third-party communication software. It should also be noted that the encryption chip is a chip with a built-in SM4 encryption engine, including both encryption and decryption functions.
[0022] It should be noted that, in the step of obtaining the access information of the sender activating the first chip-level security suite on the first chip device, the first chip-level security suite can be understood as software matching the first chip device, and the first chip device is a computer device comprising an encryption chip, including computers, tablets, mobile phones, processors and other devices. The receiver device is the second chip device described below.
[0023] In this embodiment, a closed-loop security system that closely combines centralized management with strong terminal security is constructed. The device management platform is responsible for centralized control and distribution of policies, identities, relationships and keys, while the encryption chip is responsible for final execution and operation, which systematically solves a series of complex problems in organization (toB / toG) scenarios, such as how to implement flexible identity authorization, auditable device management, high-strength data confidentiality and convenient cross-user secure communication. Simple hybrid encryption or hardware encryption cannot solve the flexibility problem of identity and device management. For chip-level encryption technology, the encryption process is completed by the chip itself, does not depend on the environment such as processors and operating systems, and truly realizes cross-platform encryption.
[0024] It can be understood that the present application implements identity security by establishing a mapping relationship between users and devices, implements operation security by using an encryption chip to encrypt data, implements key security by synchronizing keys through the device management platform and implementing strategic life cycle management for keys, and implements algorithm security by combining SM2 and SM4. The combination of four layers of security: identity security, operation security, key security and algorithm security effectively prevents software-based data theft and key leakage, and meets high-level data confidentiality requirements. In addition, all operations are bound to specific users and specific devices, and once a security incident occurs, it can be located quickly and accurately. The participation of the encryption chip ensures the non-repudiation of encryption operations, enhances the traceability of problems, and further reduces the risk of information leakage caused by personnel.
[0025] Optionally, the key update scheme is one of the following schemes; permanent key scheme: the first chip-level security suite synchronizes long-term effective keys from the device management platform; periodic key scheme: the first chip-level security suite judges whether the current time is within the key validity period, uses the local key if yes, otherwise synchronizes the updated key from the device management platform; dynamic key scheme: the first chip-level security suite synchronizes real-time generated new keys from the device management platform every time an operation is performed.
[0026] Understandably, when users and devices are in high-security areas, the platform can provide permanent keys for user convenience. When users and devices are in areas with lower security levels, periodic keys can be provided, such as when the device is within a designated area and operated by a regular employee. When there is a certain risk of data leakage for a user or device, a temporary key can be provided, such as when the device is outside a designated area and there is a risk of loss, for example, when an employee takes the device on a business trip. These three key policies enable unified key policy distribution, identity and access management, and security auditing for thousands of terminal devices, improving the flexibility of device management.
[0027] Optionally, the authentication steps include: verifying the user ID to deny unauthorized user access; verifying the mapping relationship between the user ID and the first chip device ID; and enforcing the corresponding security policy on the first chip device based on the user identity associated with the mapping relationship.
[0028] Understandably, the mapping relationships are stored on the device management platform and verified by the platform. These mapping relationships are associated with certain security policies, specifically: for example, if the accessed device is a risky tablet, unauthorized users will be unable to print, install software, or access the workspace, etc.
[0029] Secondly, please refer to Figure 4 This application provides a chip-based transmission decryption method, including: obtaining the encrypted file and key provided in the first aspect embodiment through a communication channel; obtaining access information of the recipient launching a chip-level security suite on a second chip device and performing identity authentication to confirm the identity of the recipient user and the legitimacy of the second chip device; after successful authentication, the second chip-level security suite synchronizes keys with the device management platform according to a preset key update scheme to obtain the private key authenticated by the device management platform. Please refer to... Figure 5 The first key is obtained by decrypting the ciphertext using the private key and the SM2 encryption engine of the encryption chip on the second chip device. See also... Figure 6 The ciphertext of the file is decrypted using the SM4 encryption engine of the encryption chip on the second chip device and the first key to obtain the plaintext. It should be noted that the encryption chip is a chip with a built-in SM4 encryption engine, including both encryption and decryption functions. The first chip-level security suite and the second chip-level security suite can be software with the same functionality.
[0030] It should be noted that in the step of obtaining access information of the sender starting the second chip-level security suite on the second chip device, the second chip-level security suite can be understood as software that is compatible with the second chip device. The second chip device is a computer device containing an encryption chip, including computers, tablets, mobile phones, processors, and other devices.
[0031] Similarly, in this embodiment, a closed-loop security system tightly integrating centralized management and strong terminal security is constructed. The device management platform is responsible for the centralized control and distribution of policies, identities, relationships, and keys, while the encryption chip is responsible for the final execution and computation. This systematically solves a series of complex problems in organizational (toB / toG) scenarios, such as how to achieve flexible identity authorization, auditable device management, high-strength data confidentiality, and convenient cross-user secure communication. Simple hybrid encryption / decryption or hardware encryption / decryption cannot solve the flexibility issues of identity and device management. Chip-level encryption / decryption technology completes the encryption and decryption process entirely through the chip itself, without relying on processors, operating systems, or other environments, truly achieving cross-platform encryption / decryption.
[0032] Understandably, this application achieves identity security by establishing a mapping relationship between users and devices, operational security by using encryption chips to encrypt and decrypt data, key security by synchronizing keys through a device management platform and implementing policy-based lifecycle management of keys, and algorithm security by combining SM2 and SM4. This four-fold security approach—identity security, operational security, key security, and algorithm security—effectively prevents software-based data theft and key leakage, meeting high-level data confidentiality requirements. Furthermore, all operations are bound to specific users and devices, allowing for rapid and accurate location of incidents. The involvement of encryption chips ensures the non-repudiation of encryption and decryption operations, enhances traceability, and further reduces the risk of leaks caused by human error.
[0033] In some embodiments, the key update scheme is one of the following: permanent key scheme: the second chip-level security suite synchronizes a long-term valid key from the device management platform; periodic key scheme: the second chip-level security suite determines whether the current time is within the key validity period, and if so, uses the local key; otherwise, it synchronizes the updated key from the device management platform; dynamic key scheme: the second chip-level security suite synchronizes a new key generated in real time from the device management platform each time an operation is performed.
[0034] Understandably, when users and devices are in high-security areas, the platform can provide permanent keys for user convenience. When users and devices are in areas with lower security levels, periodic keys can be provided, such as when the device is within a designated area and operated by a regular employee. When there is a certain risk of data leakage for a user or device, a temporary key can be provided, such as when the device is outside a designated area and there is a risk of loss, for example, when an employee takes the device on a business trip. These three key policies enable unified key policy distribution, identity and access management, and security auditing for thousands of terminal devices, improving the flexibility of device management.
[0035] Optionally, the authentication steps include: verifying the user ID to deny unauthorized user access; verifying the mapping relationship between the user ID and the second chip device ID; and enforcing the corresponding security policy on the second chip device based on the user identity associated with the mapping relationship.
[0036] Understandably, the mapping relationships are stored on the device management platform and verified by the platform. These mapping relationships are associated with certain security policies, specifically: for example, if the accessed device is a risky tablet, unauthorized users will be unable to print, install software, or access the workspace, etc.
[0037] Thirdly, this application provides a data security transmission system, including: an identity authentication module for authenticating the user and the chip device; a key management module for interacting with a remote device management platform according to a preset key update scheme to synchronize the user key and generate a first key and / or a private key; an encryption module for encrypting the first key with the receiver's public key to generate key ciphertext and encrypting plaintext with the first key and the SM4 encryption engine on the chip device to generate file ciphertext; and a decryption module for decrypting the key ciphertext with the receiver's private key and extracting the first key, and then decrypting the file ciphertext with the first key and the SM4 encryption engine and extracting the plaintext.
[0038] Similarly, in this embodiment, a closed-loop security system tightly integrating centralized management and strong terminal security is constructed. The device management platform is responsible for the centralized control and distribution of policies, identities, relationships, and keys, while the encryption chip is responsible for the final execution and computation. This systematically solves a series of complex problems in organizational (toB / toG) scenarios, such as how to achieve flexible identity authorization, auditable device management, high-strength data confidentiality, and convenient cross-user secure communication. Simple hybrid encryption / decryption or hardware encryption / decryption cannot solve the flexibility issues of identity and device management. Chip-level encryption / decryption technology completes the encryption and decryption process entirely through the chip itself, without relying on processors, operating systems, or other environments, truly achieving cross-platform encryption / decryption.
[0039] Fourthly, this application provides a computer device, including: a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the chip-based transmission encryption method of any of the above embodiments, and / or the steps of the chip-based decryption method of any of the above embodiments.
[0040] Fifthly, this application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the chip-based transmission encryption method as described in any of the above embodiments, and / or the chip-based decryption method as described in any of the above embodiments.
[0041] Sixthly, this application provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the chip-based transmission encryption method of any of the above embodiments, and / or the chip-based decryption method of any of the above embodiments.
[0042] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of the relevant data must comply with relevant regulations.
[0043] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments described above. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM).
[0044] The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.
[0045] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0046] This document uses specific examples to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the methods and core ideas of this application. Furthermore, those skilled in the art will recognize that, based on the ideas of this application, there will be changes in the specific implementation methods and application scope. Therefore, the content of this specification should not be construed as a limitation of this application.
Claims
1. A transmission encryption method based on chip technology, characterized in that, The chip-based transmission encryption method includes: Obtain access information from the sender that initiates the first chip-level security suite on the first chip device, and perform identity authentication to confirm the sender's user identity and the legitimacy of the first chip device; After successful identity authentication, the first chip-level security suite synchronizes its keys with the device management platform according to a preset key update scheme to obtain the first key authenticated by the device management platform; wherein, the identity authentication steps include: Verify the user ID to deny unauthorized access; verify the mapping relationship between the user ID and the first chip device ID; enforce the corresponding security policy on the first chip device based on the user identity associated with the mapping relationship; The first chip-level security suite obtains a list of one or more receiving devices determined by the sender's user permissions from the device management platform, the list containing the public keys of the receiving devices; Obtain plaintext and the receiving device, and use the SM4 encryption engine of the encryption chip on the first chip device and the first key to encrypt the plaintext to generate ciphertext. The first key is encrypted using the SM2 encryption engine and the public key to generate key ciphertext; The encrypted file and the encrypted key are sent to the receiving device via a communication channel for decryption.
2. The transmission encryption method based on chip technology according to claim 1, characterized in that, The key update scheme is one of the following: Permanent key scheme: The first chip-level security suite synchronizes a long-term valid key from the device management platform; Periodic key scheme: The first chip-level security suite determines whether the current time is within the key validity period. If so, it uses the local key; otherwise, it synchronizes and updates the key from the device management platform. Dynamic key scheme: The first chip-level security suite synchronously generates a new key in real time from the device management platform each time an operation is performed.
3. A transmission decryption method based on chip technology, characterized in that, include: Obtain the ciphertext of the file and the ciphertext of the key as described in any one of claims 1 or 2 using a communication channel; Obtain access information from the recipient to launch the second chip-level security suite on the second chip device, and perform identity authentication to confirm the recipient's user identity and the legitimacy of the second chip device; wherein the identity authentication steps include: Verify the user ID to deny unauthorized access; verify the mapping relationship between the user ID and the second chip device ID; enforce the corresponding security policy on the second chip device based on the user identity associated with the mapping relationship; After successful identity authentication, the second chip-level security suite synchronizes its keys with the device management platform according to a preset key update scheme to obtain the private key authenticated by the device management platform. The first key is obtained by decrypting the ciphertext of the key using the private key and the SM2 encryption engine of the encryption chip on the second chip device; The ciphertext of the file is decrypted using the SM4 encryption engine of the encryption chip on the second chip device and the first key to obtain the plaintext.
4. The chip-based transmission decryption method according to claim 3, characterized in that, The key update scheme is one of the following: Permanent key scheme: The second chip-level security suite synchronizes long-term valid keys from the device management platform; Periodic key scheme: The second chip-level security suite determines whether the current time is within the key validity period. If so, it uses the local key; otherwise, it synchronizes and updates the key from the device management platform. Dynamic key scheme: The second chip-level security suite synchronizes a new key generated in real time from the device management platform each time an operation is performed.
5. A data security transmission system, characterized in that, include: The identity authentication module is used to authenticate the identity of users and chip devices; Specifically, it is used to verify user IDs to deny unauthorized access, verify the mapping relationship between user IDs and chip device IDs, and enforce the corresponding security policies on the chip device based on the user identity associated with the mapping relationship. The key management module is used to interact with the remote device management platform according to the preset key update scheme to complete the synchronization of user keys and generate the first key and / or private key; An encryption module is used to encrypt the first key with the receiver's public key to generate key ciphertext and to encrypt plaintext with the first key and the SM4 encryption engine on the chip device to generate file ciphertext. The decryption module is used to decrypt the ciphertext of the key using the recipient's private key and extract the first key, and then use the first key and the SM4 encryption engine to decrypt the ciphertext of the file and extract the plaintext.
6. A computer device, comprising: A memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that the processor executes the computer program to implement the steps of the chip-based transmission encryption method according to any one of claims 1-2, and / or the steps of the chip-based decryption method according to any one of claims 3-4.
7. A computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by a processor, the computer program implements the steps of the chip-based transmission encryption method as described in any one of claims 1-2, and / or the steps of the chip-based decryption method as described in any one of claims 3-4.
8. A computer program product, comprising a computer program, characterized in that, When executed by a processor, the computer program implements the steps of the chip-based transmission encryption method as described in any one of claims 1-2, and / or the chip-based decryption method as described in any one of claims 3-4.
Citation Information
Patent Citations
Chip encryption method, multi-chip system and electronic equipment
CN114817948A
Forward and backward secure audio and video communication system and communication method based on dynamic key updating
CN120434028A