Data communication method and device, computer equipment, storage medium and program product

By sending broadcast information to candidate connection terminals and performing key verification in wireless communication, the vulnerability of wireless communication devices to attacks is solved, more reliable security verification and encrypted data transmission are achieved, and the security of communication connections is improved.

CN122002278APending Publication Date: 2026-05-08SHENZHEN CHENBEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SHENZHEN CHENBEI TECH CO LTD
Filing Date
2025-11-07
Publication Date
2026-05-08

AI Technical Summary

Technical Problem

Wireless communication devices are vulnerable to malicious attacks and lack data security.

Method used

By sending broadcast information to candidate connection terminals, a communication connection is established with the target terminal based on the response information of the candidate connection devices. Security verification is performed using the first key generated by the communication device and the second key sent by the target terminal. If the security verification passes, encrypted data transmission is performed.

Benefits of technology

The security of the communication connection is improved by using the key generated by both parties for security verification, making the verification result more reliable, and encrypting the data during transmission, which further enhances the security of the communication connection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122002278A_ABST
    Figure CN122002278A_ABST
Patent Text Reader

Abstract

The invention relates to a data communication method and device, computer equipment, a storage medium and a program product. The method comprises the following steps: sending broadcast information to a candidate connection terminal, and establishing communication connection with a target terminal according to response information of candidate connection equipment; performing security verification on the target terminal according to a first key generated by the communication device and a received second key sent by the target terminal; and under the condition that the security verification is passed, performing encrypted data transmission with the target terminal through the communication connection. Before the communication device and the target terminal are paired, security verification is carried out on the target terminal, the security of communication connection is improved, security verification is carried out through the first secret key and the second secret key generated by the two parties interacting, the verification result is more reliable, in addition, data are encrypted during data transmission, and the data transmission efficiency is improved. And the security of communication connection is further improved.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application claims priority to Chinese Patent Application No. 202411587799.9, filed on November 7, 2024, entitled “Data Communication Method, Apparatus, Computer Equipment, Storage Medium and Program Product”, the entire contents of which are incorporated herein by reference. Technical Field

[0002] This application relates to the field of communication technology, and in particular to a data communication method, apparatus, computer equipment, storage medium, and program product. Background Technology

[0003] Wireless communication is a communication method that utilizes the properties of electromagnetic waves propagating in free space to exchange information. Examples include Bluetooth, WiFi, Zigbee, LoRa, 4G, and NB-IoT. Due to the increasingly widespread application of wireless communication, data security has become a key performance indicator for electronic devices.

[0004] Traditional communication methods make devices vulnerable to malicious attacks, such as data eavesdropping and replay attacks, and injection attacks. Therefore, improving the security of wireless communication has become an urgent problem to be solved. Summary of the Invention

[0005] Therefore, it is necessary to provide a data communication method, apparatus, computer equipment, storage medium, and program product that can improve the security of wireless communication in response to the above-mentioned technical problems.

[0006] In a first aspect, this application provides a data communication method, including: Broadcast information is sent to candidate connection terminals, and a communication connection is established with the target terminal based on the response information of the candidate connection devices; The target terminal is subjected to security verification based on the first key generated by the communication device and the second key received from the target terminal. If the security verification passes, encrypted data transmission is performed with the target terminal via the communication connection.

[0007] In one embodiment, the encrypted data transmission with the target terminal via the communication connection includes: The encrypted data transmission with the target terminal via the communication connection includes: The data to be transmitted is processed according to a preset data encryption algorithm and a preset data format to obtain first encrypted data, and the first encrypted data is sent to the target terminal. Alternatively, the target terminal may receive second encrypted data sent by the target terminal; the second encrypted data is obtained by the target terminal processing the data to be transmitted according to a preset data encryption algorithm and a preset data format.

[0008] In one embodiment, the step of performing security verification on the target terminal according to preset key generation rules and preset encryption rules includes: The step of performing security verification on the target terminal based on the first key generated by the communication device and the second key received from the target terminal includes: A first key is generated according to the preset key generation rule, and a second key sent by the target terminal is received; the second key is generated by the target terminal according to the preset key generation rule. The first target key is determined based on the first key, the second key, and the key generation rule; The target terminal is subjected to security verification based on the first target key and the second target key.

[0009] In one embodiment, the security verification of the target terminal based on the first target key and the second target key includes: Determine whether the first target key and the second target key are the same; If they are the same, the security verification of the target terminal is determined to be successful; if they are different, the security verification of the target terminal is determined to be unsuccessful.

[0010] In one embodiment, determining the first target key based on the first key, the second key, and the key generation rule includes: According to the key generation rules, the first key and the second key are subjected to modulo-digital processing to obtain public key information; The public key information is combined with the preset private key information to obtain the first target key.

[0011] In one embodiment, the method further includes: The first target key is sent to the target terminal so that the target terminal can perform security verification on the communication device based on the first target key and the second target key.

[0012] In one embodiment, the broadcast information includes a key version number, and establishing a communication connection with the target terminal based on the response information of the candidate connection device includes: When the key version number is the same as the preset version number of the target terminal, receive the response information sent by the target terminal; The target terminal is determined based on the response information, and a communication connection is established with the target terminal.

[0013] Secondly, this application also provides a data communication device, comprising: The broadcast module is used to send broadcast information to candidate connection terminals and establish a communication connection with the target terminal based on the response information of the candidate connection devices; The verification module is used to perform security verification on the target terminal based on the first key generated by the communication device and the second key received from the target terminal. The transmission module is used to transmit encrypted data with the target terminal through the communication connection if the security verification passes.

[0014] Thirdly, this application also provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to perform the following steps: Broadcast information is sent to candidate connection terminals, and a communication connection is established with the target terminal based on the response information of the candidate connection devices; The target terminal is subjected to security verification based on the first key generated by the communication device and the second key received from the target terminal. If the security verification passes, encrypted data transmission is performed with the target terminal via the communication connection.

[0015] Fourthly, this application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, performs the following steps: Broadcast information is sent to candidate connection terminals, and a communication connection is established with the target terminal based on the response information of the candidate connection devices; The target terminal is subjected to security verification based on the first key generated by the communication device and the second key received from the target terminal. If the security verification passes, encrypted data transmission is performed with the target terminal via the communication connection.

[0016] Fifthly, this application also provides a computer program product, including a computer program that, when executed by a processor, performs the following steps: Broadcast information is sent to candidate connection terminals, and a communication connection is established with the target terminal based on the response information of the candidate connection devices; The target terminal is subjected to security verification based on the first key generated by the communication device and the second key received from the target terminal. If the security verification passes, encrypted data transmission is performed with the target terminal via the communication connection.

[0017] The aforementioned data communication method, apparatus, computer equipment, storage medium, and program product send broadcast information to candidate connection terminals and establish a communication connection with the target terminal based on the response information from the candidate connection devices. They perform security verification on the target terminal using a first key generated by the communication device and a second key received from the target terminal. If the security verification passes, encrypted data is transmitted with the target terminal through the communication connection. Performing security verification on the target terminal before pairing the communication device with it enhances the security of the communication connection. Furthermore, using the first and second keys generated by both parties makes the verification result more reliable. In addition, encrypting the data during transmission further improves the security of the communication connection. Attached Figure Description

[0018] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the drawings used in the description of the embodiments of this application or related technologies will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0019] Figure 1 This is a diagram illustrating the application environment of a data communication method in one embodiment. Figure 2 This is a flowchart illustrating a data communication method in one embodiment; Figure 3 This is a flowchart illustrating a data communication method in another embodiment; Figure 4 This is a flowchart illustrating a data communication method in another embodiment; Figure 5 This is a flowchart illustrating a data communication method in another embodiment; Figure 6 This is a flowchart illustrating a data communication method in another embodiment; Figure 7 This is a flowchart illustrating a data communication method in another embodiment; Figure 8 This is a flowchart illustrating a data communication method in another embodiment; Figure 9 This is a flowchart illustrating a data communication method in another embodiment; Figure 10 This is a structural block diagram of a data communication device in one embodiment; Figure 11This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation

[0020] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0021] The data communication method provided in this application embodiment can be applied to, for example... Figure 1 In the application environment shown, communication device 102 communicates with candidate connection device 103, which includes target terminal 104. Communication device 102 sends broadcast information to candidate connection device 103, and further establishes a communication connection with target terminal 104. Upon successful security verification, communication device 102 and target terminal 104 perform encrypted data transmission. Communication device 102 can be, but is not limited to, various personal computers, laptops, smartphones, tablets, IoT devices, and portable wearable devices. IoT devices can be smart speakers, smart TVs, smart air conditioners, smart in-vehicle devices, projection devices, etc. Portable wearable devices can be smartwatches, smart bracelets, head-mounted devices, etc. Head-mounted devices can be virtual reality (VR) devices, augmented reality (AR) devices, smart glasses, etc. Candidate connection device 103 can be, but is not limited to, various personal computers, laptops, smartphones, tablets, IoT devices, and portable wearable devices. IoT devices can be smart speakers, smart TVs, smart air conditioners, smart in-vehicle devices, projection devices, etc. Portable wearable devices can include smartwatches, smart bracelets, and head-mounted devices. Head-mounted devices can include virtual reality (VR) devices, augmented reality (AR) devices, and smart glasses.

[0022] In one embodiment, such as Figure 2 As shown, a data communication method is provided, which is applied to... Figure 1 Taking communication equipment as an example, the explanation includes: S201, broadcast information is sent to candidate connection terminals, and a communication connection is established with the target terminal based on the response information of the candidate connection devices.

[0023] The response information indicates whether the candidate connection device can establish a communication connection with the communication device. The communication connection can include any of the following communication methods: Bluetooth, WiFi, Zigbee, LoRa, 4G, and NB-IoT.

[0024] In this embodiment, the communication device sends broadcast information to multiple candidate connection devices. The broadcast information may include the connection request of the communication device. Each candidate connection device generates response information based on the connection request and sends it to the communication device. The communication device filters the candidate connection devices based on the response information to obtain a target terminal that matches the connection request, thereby establishing a communication connection with the target terminal. Optionally, the communication device may send a connection establishment request to the target terminal and establish a communication connection with the target terminal after receiving a response message from the target terminal.

[0025] Optionally, if the connection request of the communication device matches the locally stored information, the candidate connection device sends a response message to the communication device; or, the candidate connection device generates a response message based on the connection request of the communication device and the locally stored information, and sends it to the communication device.

[0026] S202, perform security verification on the target terminal based on the first key generated by the communication device and the second key sent by the target terminal.

[0027] The communication device generates a first key according to preset rules and sends the first key to the target terminal; the target terminal generates a second key according to preset rules and sends the second key to the communication device. Further, the communication device performs security verification on the target terminal based on the first key and the second key, and the target terminal performs security verification on the communication device based on the first key and the second key.

[0028] Optionally, the communication device can determine whether the first key and the second key are the same. If they are the same, the security verification of the target terminal is deemed to have passed; if they are different, the security verification of the target terminal is deemed to have failed.

[0029] S203: If the security verification passes, encrypted data is transmitted with the target terminal via a communication connection.

[0030] In this embodiment, after the security verification is passed, the communication device and the target terminal complete pairing and can exchange data. The communication device encrypts the data to be transmitted, obtaining encrypted data, and sends the encrypted data to the target terminal through the communication connection established with the target device. The target terminal can decrypt the encrypted data according to the decryption method corresponding to the communication device.

[0031] In the aforementioned data communication method, broadcast information is sent to candidate connection terminals, and a communication connection is established with the target terminal based on the response information from the candidate connection devices. The target terminal is then subjected to security verification based on a first key generated by the communication device and a second key received from the target terminal. If the security verification passes, encrypted data is transmitted with the target terminal through the communication connection. Performing security verification on the target terminal before pairing enhances the security of the communication connection. Furthermore, using the first and second keys generated by both parties makes the verification result more reliable. Additionally, encrypting the data during transmission further enhances the security of the communication connection.

[0032] In one embodiment, an implementation of the above S203 is provided, such as... Figure 3 As shown, the aforementioned "encrypted data transmission with the target terminal via a communication connection" includes: S301, the data to be transmitted is processed according to the preset data encryption algorithm and preset data format to obtain the first encrypted data, and the first encrypted data is sent to the target terminal.

[0033] The preset data encryption algorithm includes any encryption algorithm such as symmetric encryption algorithm or asymmetric encryption algorithm; the preset data format includes the data arrangement order, data composition structure, etc.

[0034] In this embodiment, the data to be transmitted and related data are obtained. The data to be transmitted is encrypted using a preset encryption algorithm to obtain initial encrypted data. The initial encrypted data and related data are then combined according to a preset data format to obtain encrypted data. For example, the related data may include a packet header, sequence number, checksum, opcode, and encryption version number. The initial encrypted data includes privacy-sensitive data converted by the encryption algorithm to obtain a new encoding. Further, if two consecutive packets of data received by the target terminal have the same sequence number, they are determined to be illegal data and discarded. When the encrypted data is legal data, it is decrypted according to the encryption version number.

[0035] S302, Receive the second encrypted data sent by the target terminal; the second encrypted data is obtained by the target terminal processing the data to be transmitted according to the preset data encryption algorithm and preset data format.

[0036] In this embodiment of the application, the communication device terminates the encrypted data sent by the target terminal, parses the encrypted data, removes data such as packet header, sequence number, check code, operation code, and encryption version number from the encrypted data to obtain initial encrypted data, and further decrypts the initial encrypted data according to a preset encryption algorithm to obtain decrypted data.

[0037] Optionally, the communication device may pre-store an algorithm library and the correspondence between each encryption algorithm and the header information, so that the encryption algorithm corresponding to the target terminal can be determined from the preset algorithm library according to the header information and the correspondence, and then the encrypted data can be decrypted according to the encryption algorithm.

[0038] In the above-mentioned embodiments, the target terminal can encrypt the data to obtain encrypted data, and then send the encrypted data to the communication device. After determining that the encrypted data is valid, the encrypted data is parsed, thereby improving the security of data transmission; the communication device can encrypt the data to obtain encrypted data, and then send the encrypted data to the target terminal. After determining that the encrypted data is valid, the encrypted data is parsed, thereby improving the security of data transmission.

[0039] In one embodiment, one implementation of S202 above is provided, such as... Figure 4 As shown, the aforementioned "performing security verification on the target terminal based on the first key generated by the communication device and the second key received from the target terminal" includes: S401, Generate a first key according to a preset key generation rule, and receive a second key sent by the target terminal; the second key is generated by the target terminal according to the preset key generation rule.

[0040] In this embodiment, the communication device generates a first key according to a preset key generation rule and sends the first key to the target terminal; the target terminal generates a second key according to the preset key generation rule and sends the second key to the communication device. It should be noted that the key generation rules of the communication device and the target terminal are the same.

[0041] S402, determine the first target key based on the first key, the second key, and the key generation rules.

[0042] In this embodiment, the first key and the second key are processed according to a preset key generation rule to obtain the first target key. Optionally, features can be extracted from the first key and the second key separately according to the key generation rule, and the common features of the first key and the second key can be used as the first target key; or, the first key and the second key can be combined according to the key format in the key generation rule to obtain the first target key.

[0043] S403, perform security verification on the target terminal based on the first target key and the second target key.

[0044] In this embodiment of the application, the method by which the target terminal generates the second target key is the same as the method by which the communication device generates the first target key. After receiving the second target key, the communication device parses the first target key and the second target key, and obtains the security verification result of the target terminal by performing consistency judgment or other processing on the first target key and the second target key.

[0045] Optionally, the first target key may include first public key information and first private key information, and the second target key may include second public key information and second private key information. The second target information is parsed according to a preset generation rule to obtain the second public key information. Further, the communication device determines whether the first public key information and the second public key information are consistent. If they are consistent, the security verification of the target terminal passes; if they are inconsistent, the security verification of the target terminal fails.

[0046] Optionally, S202 further includes: sending a first target key to a target terminal so that the target terminal performs security verification on the communication device based on the first target key and the second target key.

[0047] Optionally, in this embodiment, the target terminal generates a second target key and receives a first target key sent by the communication device, parses the first target key and the second target key, and obtains the security verification result of the communication device by performing a consistency judgment or other processing on the first target key and the second target key.

[0048] In the above-described embodiments, the communication device determines a first target key based on a first key, a second key, and a key generation rule, and the target terminal determines a second target key based on the first key, the second key, and the key generation rule. This allows for verification of the communication device and the target terminal based on the first and second target keys, thereby improving the accuracy of the verification.

[0049] In one embodiment, one implementation of S403 described above is provided, such as... Figure 5 As shown, the above-mentioned "determining the first target key based on the first key, the second key, and the key generation rules" includes: S501, determine whether the first target key and the second target key are the same. If they are the same, proceed to step S502. If they are not the same, proceed to step S503.

[0050] S502, confirming that the security verification of the target terminal has passed.

[0051] S503 indicates that the security verification of the target terminal failed.

[0052] In this embodiment of the application, it is determined whether the first target key and the second target key are the same. If they are the same, it indicates that the generation rules for encrypted communication between the target terminal and the communication device are the same, and the data in the target terminal has not been tampered with, and the security verification of the target terminal is determined to be successful. If they are different, it indicates that the generation rules for encrypted communication between the target terminal and the communication device are different, and / or the data in the target terminal has been tampered with, and the security verification of the target terminal is determined to be unsuccessful.

[0053] In the above application embodiments, the consistency judgment of the first target key and the second target key is performed, and the security verification of the target terminal is determined based on the consistency judgment result. This method is simple, less prone to errors, and improves the accuracy of the security verification result.

[0054] In one embodiment, one implementation of the above-described S402 is provided, such as... Figure 6 As shown, the above-mentioned "determining the first target key based on the first key, the second key, and the key generation rules" includes: S601, according to the key generation rules, perform modulo-digital processing on the first key and the second key to obtain public key information.

[0055] In this embodiment of the application, the first key and the second key can be processed by data cleaning, data filtering and other processes. Furthermore, the first key and the second key are processed according to the key generation rules to convert the first key and the second key in numerical format into public key information in string format.

[0056] Optionally, the key generation rules may include a trained analog-to-digital (ADC) processing model. The first key and the second key are input into the ADC processing model, and the ADC processing model outputs the public key information.

[0057] S602, combine the public key information with the preset private key information to obtain the first target key.

[0058] In this embodiment, the communication device pre-stores private key information, and combines the public key information and private key information in a preset order to form a first target key. Optionally, the target terminal pre-stores private key information, and combines the public key information and private key information in a preset order to form a second target key.

[0059] In this embodiment of the application, the first target key and the second target key are generated by the first key and the second key, which improves the accuracy and security of the first target key and the second target key, and further improves the accuracy of security verification using the first target key and the second target key.

[0060] In one embodiment, an implementation of S201 above is provided, wherein the broadcast information includes a key version number, such as... Figure 7As shown, the above-mentioned "establishing a communication connection with the target terminal based on the response information of the candidate connection device" includes: S701: When the key version number is the same as the preset version number of the target terminal, receive the response information sent by the target terminal.

[0061] Each key version number corresponds one-to-one with a preset key generation rule. For example, key version number 1 corresponds to key generation rule A, key version number 2 corresponds to key generation rule B, and key version number 3 corresponds to key generation rule C. The corresponding information may include a pairing message.

[0062] In this embodiment of the application, after receiving the broadcast information, the candidate connection device determines whether it is consistent with the local key version number based on the key version number in the broadcast information. If they are consistent, the candidate connection device generates response information and sends it to the communication device.

[0063] S702 determines the target terminal based on the response information and establishes a communication connection with the target terminal.

[0064] In this embodiment of the application, if the communication device receives multiple response messages, it determines all the candidate connection devices corresponding to the multiple response messages as target terminals and establishes a communication connection with each target terminal respectively; if the communication device receives a single response message, it determines the candidate connection device corresponding to the response message as the target terminal and establishes a communication connection with the target terminal.

[0065] In the above application embodiments, the target terminal is determined according to the key version number in the broadcast information, ensuring that the key generation rule of the target terminal matches the key generation rule of the communication device, avoiding the failure of security verification of the target terminal due to different key generation rules, improving the accuracy of security verification, and increasing the success rate of establishing a communication connection.

[0066] In one embodiment, such as Figure 8 As shown, the above data communication method includes: In IoT smart devices, Bluetooth communication is a crucial communication method for interaction between mobile terminals such as smartphones and Bluetooth devices; therefore, data security is becoming a key performance indicator for smart hardware devices. Common attack methods in Bluetooth communication devices include data eavesdropping and replay attacks, injection attacks, etc.; therefore, during the data desensitization process, it is essential to implement a technology to enhance the security of encryption devices to improve data security.

[0067] Each time a connection is established, the Bluetooth device (the aforementioned communication device) and the APP (the terminal device, the aforementioned target terminal) dynamically negotiate and update the key. Once the key and verification are complete, the data between the two parties is encrypted and decrypted using that key; otherwise, the connection is closed. This achieves the effect of fast encryption algorithm speed, suitable for scenarios with high real-time requirements; and it also requires little space and can be used by MCUs with limited resources.

[0068] Broadcast phase: Set the key version number in a specific byte. The version number is described by document enumeration. Different key version numbers represent specific ways of generating the key.

[0069] Connection phase: The APP uses the broadcast code (including the actual MAC address) to initially filter devices that match the key version number for connection.

[0070] Key negotiation: After the connection is established, the APP selects the corresponding key generation rule according to the key version and sends the key1 (the first key mentioned above) generated under the rule to the device. After receiving key1, the device parses out the key KEY (the public key information mentioned above) under the rule (algorithm processing). At the same time, it generates key2 (the second key mentioned above) under the same rule and returns it to the APP. The APP parses out the same key KEY. The key exchange is completed.

[0071] Key authentication: The app generates a sessionKey under the encryption rules, encrypts it with the default IV (the aforementioned preset private key) and KEY, and transmits it to the device. Upon receiving the sessionKey, the device parses it from the default IV and KEY combination, and then encrypts specific content (such as a MAC string) using the sessionKey + KEY under the encryption rules, generating response data and returning it to the app. If the app interprets the specific content using the sessionKey + KEY and performs a comparison and verification (e.g., if the MAC matches the actual MAC), the connection is successful; otherwise, the connection is terminated.

[0072] Encrypted data communication: The data consists of plaintext and ciphertext. The plaintext includes a header, sequence number, checksum, opcode, and encryption version number. The ciphertext is generated by converting privacy-sensitive data using an encryption algorithm. The sender controls the sequence number, and the receiver performs a preliminary judgment on the sequence number: if two consecutive data packets have the same sequence number, they are considered invalid and discarded; otherwise, the ciphertext is decrypted according to the encryption version number.

[0073] In one embodiment, a complete data communication method is provided, such as Figure 9 As shown, the method includes: S1, the communication device sends a broadcast message to the candidate connection terminal, and receives the response message sent by the target terminal when the key version number is the same as the preset version number of the target terminal.

[0074] S2, the communication device determines the target terminal based on the response information and establishes a communication connection with the target terminal.

[0075] S3, the communication device generates a first key according to a preset key generation rule and receives a second key sent by the target terminal; the second key is generated by the target terminal according to the preset key generation rule.

[0076] S4, the communication device sends the first target key to the target terminal so that the target terminal can perform security verification on the communication device based on the first target key and the second target key.

[0077] S5, the communication device performs modulo-digital processing on the first key and the second key according to the key generation rules to obtain the public key information.

[0078] S6, the communication device combines the public key information with the preset private key information to obtain the first target key.

[0079] S7, the communication device determines whether the first target key and the second target key are the same.

[0080] S8. If they are the same, the communication device determines that the security verification of the target terminal has passed; if they are different, the communication device determines that the security verification of the target terminal has failed.

[0081] S9, the communication device processes the data to be transmitted according to the preset data encryption algorithm and preset data format to obtain the first encrypted data, and sends the first encrypted data to the target terminal.

[0082] S10, or, the communication device receives the second encrypted data sent by the target terminal; the second encrypted data is obtained by the target terminal processing the data to be transmitted according to a preset data encryption algorithm and a preset data format.

[0083] In the aforementioned data communication method, broadcast information is sent to candidate connection terminals, and a communication connection is established with the target terminal based on the response information from the candidate connection devices. The target terminal is then subjected to security verification based on a first key generated by the communication device and a second key received from the target terminal. If the security verification passes, encrypted data is transmitted with the target terminal through the communication connection. Performing security verification on the target terminal before pairing enhances the security of the communication connection. Furthermore, using the first and second keys generated by both parties makes the verification result more reliable. Additionally, encrypting the data during transmission further enhances the security of the communication connection.

[0084] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.

[0085] Based on the same inventive concept, this application also provides a data communication apparatus for implementing the data communication method described above. The solution provided by this apparatus is similar to the implementation scheme described in the above method; therefore, the specific limitations in one or more data communication apparatus embodiments provided below can be found in the limitations of the data communication method described above, and will not be repeated here.

[0086] In one embodiment, such as Figure 10 As shown, a data communication device is provided, including: a broadcast module 10, a verification module 11, and a transmission module 12, wherein: The broadcast module 10 is used to send broadcast information to candidate connection terminals and establish a communication connection with the target terminal based on the response information of the candidate connection devices; The verification module 11 is used to perform security verification on the target terminal based on the first key generated by the communication device and the second key sent by the target terminal. The transmission module 12 is used to transmit encrypted data with the target terminal via a communication connection after the security verification is passed.

[0087] In one embodiment, the transmission module 12 includes: a first transmitting unit and a first receiving unit, wherein: The first sending unit is used to process the data to be transmitted according to a preset data encryption algorithm and a preset data format to obtain the first encrypted data, and send the first encrypted data to the target terminal.

[0088] The first receiving unit is used to receive the second encrypted data sent by the target terminal; the second encrypted data is obtained by the target terminal processing the data to be transmitted according to a preset data encryption algorithm and a preset data format.

[0089] In one embodiment, the verification module 11 includes: a generation unit, a determination unit, and a verification unit, wherein: The generation unit is used to generate a first key according to a preset key generation rule and receive a second key sent by the target terminal; the second key is generated by the target terminal according to the preset key generation rule.

[0090] The determining unit is used to determine the first target key based on the first key, the second key, and the key generation rules.

[0091] The verification unit is used to perform security verification on the target terminal based on the first target key and the second target key.

[0092] In one embodiment, the verification unit is specifically used to determine whether the first target key and the second target key are the same; if they are the same, the security verification of the target terminal is determined to be successful; if they are different, the security verification of the target terminal is determined to be unsuccessful.

[0093] In one embodiment, the determining unit is specifically used to perform modulo-digital processing on the first key and the second key according to the key generation rules to obtain public key information; and to combine the public key information with preset private key information to obtain the first target key.

[0094] In one embodiment, the transmission module 12 further includes a second sending unit, configured to send a first target key to a target terminal, so that the target terminal performs security verification on the communication device based on the first target key and the second target key.

[0095] In one embodiment, the broadcast module 10 includes: a second receiving unit and an establishing unit, wherein: The second receiving unit is used to receive response information sent by the target terminal when the key version number is the same as the preset version number of the target terminal.

[0096] The establishment unit is used to determine the target terminal based on the response information and establish a communication connection with the target terminal.

[0097] Each module in the aforementioned data communication device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the memory of a computer device as software, so that the processor can call and execute the operations corresponding to each module.

[0098] In one embodiment, a computer device is provided, which may be a terminal, and its internal structure diagram may be as follows: Figure 11As shown, the computer device includes a processor, memory, input / output interfaces, a communication interface, a display unit, and an input device. The processor, memory, and input / output interfaces are connected via a system bus, and the communication interface, display unit, and input device are also connected to the system bus via the input / output interfaces. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The input / output interfaces are used for exchanging information between the processor and external devices. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, mobile cellular networks, Near Field Communication (NFC), or other technologies. When the computer program is executed by the processor, it implements a data communication method. The display unit is used to form a visually visible image and can be a display screen, a projection device, or a virtual reality imaging device. The display screen can be an LCD screen or an e-ink screen. The input device of the computer device can be a touch layer covering the display screen, or buttons, trackballs, or touchpads set on the casing of the computer device, or external keyboards, touchpads, or mice, etc.

[0099] Those skilled in the art will understand that Figure 11 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0100] In one embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to perform the following steps: It sends broadcast information to candidate connection terminals and establishes a communication connection with the target terminal based on the response information of the candidate connection devices; The target terminal is security verified based on the first key generated by the communication device and the second key sent by the target terminal. Once the security verification is successful, encrypted data is transmitted to the target terminal via a communication connection.

[0101] In one embodiment, the processor, when executing a computer program, also performs the following steps: The data to be transmitted is processed according to a preset data encryption algorithm and a preset data format to obtain the first encrypted data, and the first encrypted data is sent to the target terminal. Alternatively, it may receive second encrypted data sent by the target terminal; the second encrypted data is obtained by the target terminal processing the data to be transmitted according to a preset data encryption algorithm and a preset data format.

[0102] In one embodiment, the processor, when executing a computer program, also performs the following steps: A first key is generated according to a preset key generation rule, and a second key sent by the target terminal is received; the second key is generated by the target terminal according to the preset key generation rule. The first target key is determined based on the first key, the second key, and the key generation rules; The target terminal is security verified based on the first target key and the second target key.

[0103] In one embodiment, the processor, when executing a computer program, also performs the following steps: Determine whether the first target key and the second target key are the same; If they are the same, the security verification of the target terminal is confirmed to have passed; if they are different, the security verification of the target terminal is confirmed to have failed.

[0104] In one embodiment, the processor, when executing a computer program, also performs the following steps: According to the key generation rules, the first key and the second key are modulo-processed to obtain the public key information; The public key information is combined with the preset private key information to obtain the first target key.

[0105] In one embodiment, the processor, when executing a computer program, also performs the following steps: The first target key is sent to the target terminal so that the target terminal can perform security verification on the communication device based on the first target key and the second target key.

[0106] In one embodiment, the processor, when executing a computer program, also performs the following steps: When the key version number is the same as the preset version number of the target terminal, receive the response information sent by the target terminal; The target terminal is identified based on the response information, and a communication connection is established with the target terminal.

[0107] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, the computer program performing the following steps when executed by a processor: It sends broadcast information to candidate connection terminals and establishes a communication connection with the target terminal based on the response information of the candidate connection devices; The target terminal is security verified based on the first key generated by the communication device and the second key sent by the target terminal. Once the security verification is successful, encrypted data is transmitted to the target terminal via a communication connection.

[0108] In one embodiment, when the computer program is executed by a processor, it also performs the following steps: The data to be transmitted is processed according to a preset data encryption algorithm and a preset data format to obtain the first encrypted data, and the first encrypted data is sent to the target terminal. Alternatively, it may receive second encrypted data sent by the target terminal; the second encrypted data is obtained by the target terminal processing the data to be transmitted according to a preset data encryption algorithm and a preset data format.

[0109] In one embodiment, when the computer program is executed by a processor, it also performs the following steps: A first key is generated according to a preset key generation rule, and a second key sent by the target terminal is received; the second key is generated by the target terminal according to the preset key generation rule. The first target key is determined based on the first key, the second key, and the key generation rules; The target terminal is security verified based on the first target key and the second target key.

[0110] In one embodiment, when the computer program is executed by a processor, it also performs the following steps: Determine whether the first target key and the second target key are the same; If they are the same, the security verification of the target terminal is confirmed to have passed; if they are different, the security verification of the target terminal is confirmed to have failed.

[0111] In one embodiment, when the computer program is executed by a processor, it also performs the following steps: According to the key generation rules, the first key and the second key are modulo-processed to obtain the public key information; The public key information is combined with the preset private key information to obtain the first target key.

[0112] In one embodiment, when the computer program is executed by a processor, it also performs the following steps: The first target key is sent to the target terminal so that the target terminal can perform security verification on the communication device based on the first target key and the second target key.

[0113] In one embodiment, when the computer program is executed by a processor, it also performs the following steps: When the key version number is the same as the preset version number of the target terminal, receive the response information sent by the target terminal; The target terminal is identified based on the response information, and a communication connection is established with the target terminal.

[0114] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, performs the following steps: It sends broadcast information to candidate connection terminals and establishes a communication connection with the target terminal based on the response information of the candidate connection devices; The target terminal is security verified based on the first key generated by the communication device and the second key sent by the target terminal. Once the security verification is successful, encrypted data is transmitted to the target terminal via a communication connection.

[0115] In one embodiment, when the computer program is executed by a processor, it also performs the following steps: The data to be transmitted is processed according to a preset data encryption algorithm and a preset data format to obtain the first encrypted data, and the first encrypted data is sent to the target terminal. Alternatively, it may receive second encrypted data sent by the target terminal; the second encrypted data is obtained by the target terminal processing the data to be transmitted according to a preset data encryption algorithm and a preset data format.

[0116] In one embodiment, when the computer program is executed by a processor, it also performs the following steps: A first key is generated according to a preset key generation rule, and a second key sent by the target terminal is received; the second key is generated by the target terminal according to the preset key generation rule. The first target key is determined based on the first key, the second key, and the key generation rules; The target terminal is security verified based on the first target key and the second target key.

[0117] In one embodiment, when the computer program is executed by a processor, it also performs the following steps: Determine whether the first target key and the second target key are the same; If they are the same, the security verification of the target terminal is confirmed to have passed; if they are different, the security verification of the target terminal is confirmed to have failed.

[0118] In one embodiment, when the computer program is executed by a processor, it also performs the following steps: According to the key generation rules, the first key and the second key are modulo-processed to obtain the public key information; The public key information is combined with the preset private key information to obtain the first target key.

[0119] In one embodiment, when the computer program is executed by a processor, it also performs the following steps: The first target key is sent to the target terminal so that the target terminal can perform security verification on the communication device based on the first target key and the second target key.

[0120] In one embodiment, when the computer program is executed by a processor, it also performs the following steps: When the key version number is the same as the preset version number of the target terminal, receive the response information sent by the target terminal; The target terminal is identified based on the response information, and a communication connection is established with the target terminal.

[0121] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, artificial intelligence (AI) processors, etc., and are not limited to these.

[0122] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.

[0123] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.

Claims

1. A data communication method, characterized in that, The method is applied to a communication device, and the method includes: Broadcast information is sent to candidate connection terminals, and a communication connection is established with the target terminal based on the response information of the candidate connection devices; The target terminal is subjected to security verification based on the first key generated by the communication device and the second key received from the target terminal. If the security verification passes, encrypted data transmission is performed with the target terminal via the communication connection.

2. The method according to claim 1, characterized in that, The encrypted data transmission with the target terminal via the communication connection includes: The data to be transmitted is processed according to a preset data encryption algorithm and a preset data format to obtain first encrypted data, and the first encrypted data is sent to the target terminal. Alternatively, the target terminal may receive second encrypted data sent by the target terminal; the second encrypted data is obtained by the target terminal processing the data to be transmitted according to a preset data encryption algorithm and a preset data format.

3. The method according to claim 1, characterized in that, The step of performing security verification on the target terminal based on the first key generated by the communication device and the second key received from the target terminal includes: A first key is generated according to a preset key generation rule, and a second key sent by the target terminal is received; the second key is generated by the target terminal according to the preset key generation rule. The public key information is determined based on the first key, the second key, and the preset key generation rule; Based on the public key information, preset private key information, and preset encryption rules, the system interacts with the target terminal and performs security verification on the target terminal based on the interaction information.

4. The method according to any one of claims 1-3, characterized in that, The broadcast information includes a key version number. Establishing a communication connection with the target terminal based on the response information of the candidate connection device includes: When the key version number is the same as the preset version number of the target terminal, receive the response information sent by the target terminal; The target terminal is determined based on the response information, and a communication connection is established with the target terminal.

5. A data communication device, characterized in that, The device includes: The broadcast module is used to send broadcast information to candidate connection terminals and establish a communication connection with the target terminal based on the response information of the candidate connection devices; The verification module is used to perform security verification on the target terminal based on the first key generated by the communication device and the second key received from the target terminal. The transmission module is used to transmit encrypted data with the target terminal through the communication connection if the security verification passes.

6. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 4.

7. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 4.

8. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 4.