Security module, secure communication system and method, storage medium, and program product
By designing a security module including communication modules and security chips in the terminal device, and using multiple encryption methods for data transmission, the problem of data transmission security within the terminal device is solved, and secure data transmission between the terminal device and the external server is realized.
Patent Information
- Application Number
- PCT/CN2024/113795
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-29
- Filing Date
- 2024-08-21
- Publication Date
- 2025-06-05
AI Technical Summary
The existing communication technology lacks an effective security mechanism in terminal devices, resulting in a risk of leakage when data is transmitted between modules, and it is impossible to fully guarantee the data security of the communication system.
A security module is designed, including a communication module and a security chip, and data transmission is transmitted using multiple encryption methods. The communication module performs encrypted data transmission based on the first encryption protocol and other modules in the terminal, and the security chip performs encrypted data transmission with an external server based on the security chip encryption protocol.
The security of data transmission between the terminal device and the external server is realized, while avoiding the risk of data being leaked during transmission between internal modules of the terminal device, ensuring the data security of the communication system.
Smart Images

Figure CN2024113795_05062025_PF_FP_ABST
Abstract
Description
Security module, security communication system and method, storage medium and program product
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This disclosure is based on and claims the priority of Chinese patent application with application number 202311620399.9 and application date November 29, 2023. The entire content of this Chinese patent application is incorporated herein by reference into this disclosure. Technical Field
[0003] The present disclosure belongs to the field of communication technology, and in particular relates to a security module, a secure communication system and method, a storage medium, and a program product. Background Art
[0004] With the rapid development of terminal communication and IoT technologies, the volume of communication between devices has increased significantly, placing higher demands on communication security. Current communication technologies mostly deploy security services to ensure secure communications between different terminal devices and between terminal devices and servers. However, due to the lack of corresponding security mechanisms within each terminal device, there is a risk of data leakage when transmitting between modules within the terminal device, making it impossible to fully guarantee the data security of the communication system.
[0005] Summary of the Invention
[0006] The embodiments of the present disclosure provide a security module, a secure communication system and method, a storage medium, and a program product, which can realize secure communication under multiple encryption methods. While ensuring the security of data transmission between terminal devices and external servers, it also avoids the risk of data leakage during transmission between various modules within the terminal device.
[0007] In a first aspect, an embodiment of the present disclosure provides a security module, which includes a communication module and a security chip; the communication module is used to encrypt or decrypt data based on a first encryption protocol, wherein the first encryption protocol is a data transmission encryption protocol within the terminal where the security module is located; the security chip is used to encrypt or decrypt data based on a security chip encryption protocol, wherein the security chip encryption protocol is a data transmission encryption protocol between the terminal where the security module is located and an external device.
[0008] In the second aspect, an embodiment of the present disclosure provides a secure communication system, which includes the security module provided in the first aspect above, as well as a main controller and a server; the security module and the main controller are deployed on the same terminal; encrypted data transmission is performed between the security module and the main controller based on a first encryption protocol; encrypted data transmission is performed between the security module and the server based on a security chip encryption protocol; and data transmission is performed between the main controller and the server based on a second encryption protocol.
[0009] In a third aspect, an embodiment of the present disclosure provides a secure communication method, which applies the secure communication system provided in the second aspect above, and includes: the main controller encrypts data based on the first encryption protocol to obtain first encrypted data; the main controller sends the first encrypted data to the communication module in the security module; and the communication module receives the first encrypted data and decrypts the first encrypted data based on the first encryption protocol.
[0010] In a fourth aspect, an embodiment of the present disclosure provides a computer storage medium having instructions stored thereon, which, when executed by a processor, implement the method described in the third aspect above.
[0011] In a fourth aspect, an embodiment of the present disclosure provides a computer program product comprising instructions, which, when executed by a processor, causes the processor to execute the method as described in the third aspect above.
[0012] The disclosed embodiments provide a security module, secure communication system, and method. The security module includes a communication module and a security chip. Within a terminal device, the communication module performs encrypted data transmission with other modules within the terminal based on a first encryption protocol. During external communication, the security chip performs encrypted data transmission with external servers and other devices based on the security chip encryption protocol. In this solution, by applying the security encryption function of the security chip and custom encryption algorithms between modules within the terminal, secure communication using multiple encryption methods is achieved. This ensures the security of data transmission between the terminal and the external server while also avoiding the risk of data leakage during transmission between modules within the terminal device. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] In order to more clearly illustrate the technical solutions of the embodiments of the present disclosure, the following briefly introduces the drawings required for use in the embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0014] FIG1 is a schematic diagram of a secure communication system provided by an embodiment of the present disclosure.
[0015] FIG2 is a schematic diagram of data interaction between a main controller and a security module provided in an embodiment of the present disclosure.
[0016] FIG3 is a schematic diagram of data interaction between a security module and a server provided in an embodiment of the present disclosure.
[0017] FIG4 is a schematic diagram of data interaction between a main controller and a server provided by an embodiment of the present disclosure.
[0018] FIG5 is another schematic diagram of data interaction between a main controller and a server provided by an embodiment of the present disclosure.
[0019] FIG6 is a flowchart of upgrading a first encryption protocol provided by an embodiment of the present disclosure.
[0020] FIG7 is a flowchart of an upgraded second encryption protocol provided by an embodiment of the present disclosure.
[0021] FIG8 is a schematic structural diagram of a computer device provided by an embodiment of the present disclosure. DETAILED DESCRIPTION
[0022] The features and exemplary embodiments of various aspects of the present disclosure will be described in detail below. In order to make the purposes, technical solutions and advantages of the present disclosure clearer, the present disclosure will be further described in detail below in conjunction with the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain the present disclosure, rather than to limit the present disclosure. For those skilled in the art, the present disclosure can be implemented without the need for some of these specific details. The following description of the embodiments is merely to provide a better understanding of the present disclosure by illustrating examples of the present disclosure.
[0023] It should be noted that, in this document, terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises", "comprising" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article or device. In the absence of further limitations, the elements defined by the sentence "comprising..." do not exclude the presence of other identical elements in the process, method, article or device comprising the elements.
[0024] In order to solve the problems of the prior art, the embodiments of the present disclosure provide a security module, a security communication system and a method. The following is a detailed description with reference to the accompanying drawings. Figure 1 is a schematic diagram of a security communication system provided by an embodiment of the present disclosure. As shown in Figure 1, the security communication system includes a security module 101, a main controller 102 and a server 103. In one embodiment, the security module 101 and the main controller 102 are deployed in the same terminal 104, that is, the security module and the main controller are different hardware modules inside the same terminal. The terminal 104 can be a smart phone, a tablet computer, a portable computer, a desktop computer, etc., and the embodiments of the present disclosure are not limited to this.
[0025] In one embodiment, the security module 101 belongs to the communication unit of the terminal 104. Exemplarily, the security module 101 is consistent with the traditional communication module in appearance, and is a communication module with security encryption capabilities and network communication capabilities, used to realize communication between the terminal 104 and the server 103. In one embodiment, the security module 101 includes a communication module 1011 and a security chip 1012, and data can be exchanged between the communication module 1011 and the security chip 1012. Exemplarily, the communication module 1011 and the security chip 1012 can be connected through a physical interface, which can be a serial port, I2C, SPI or other interface, which is not limited in the embodiment of the present disclosure. Optionally, a security software development kit (SDK) compatible with the security chip 1012 can be integrated on the communication module 1011, and calling the API interface provided by the security SDK can drive the security chip 1012 to provide secure communication services.
[0026] In one embodiment, the main controller 102 is a control unit of a terminal device. The main controller 102 can exchange data with the server 103 through the security module 101. In one embodiment, the main controller 102 is a control unit of the terminal 104 and can be used to receive control instructions sent by the security module 101, complete the operation indicated by the control instruction, and respond to the operation result. In one embodiment, the main controller 102 can be implemented as a microcontroller (MCU), but this embodiment of the present disclosure is not limited to this.
[0027] In one embodiment, server 103 is deployed in the cloud. Server 103 can be a single server, multiple servers, a cloud computing platform, or the like. The present disclosure does not limit the device type of server 103. Server 103 can connect to terminal 104 via a wireless network or a wired network to enable communication and control of terminal 104. In one embodiment, server 103 can provide remote upgrade services to communication module 1011 and main controller 1012 in security module 101. Communication module 1011 and main controller 1012 in security module 101 support remote upgrade capabilities.
[0028] In one embodiment, the server 103 includes an IoT security access platform 1031 and an IoT application platform 1032. For example, the IoT security access platform 1031 can communicate with the terminal 104 and perform operations such as encryption, decryption, and data signing on transmitted data. The IoT application platform 1032 can provide functions such as device access, data collection, data processing, and application management.
[0029] The following describes in detail the communication process between the various hardware components within the terminal in the above-mentioned secure communication system, in conjunction with the accompanying drawings. In an embodiment of the present disclosure, encrypted data transmission can be performed between the security module and the main controller based on a first encryption protocol. The first encryption protocol is a data transmission encryption protocol within the terminal where the security module is located. For example, in an embodiment of the present disclosure, the first encryption protocol can be a custom encryption protocol between the security module and the main controller, and both the main controller and the communication module within the security module can perform data encryption or decryption based on the first encryption protocol. Figure 2 is a schematic diagram of data interaction between the main controller and the security module provided in an embodiment of the present disclosure. As shown in Figure (a) of Figure 2, in one embodiment, the main controller can encrypt data based on the first encryption protocol to obtain first encrypted data, and then send the first encrypted data to the communication module within the security module. That is, step 201 is executed to send data encrypted based on the first encryption protocol. After receiving the first encrypted data, the communication module decrypts the first encrypted data based on the first encryption protocol to obtain the original data sent by the main controller. In this scenario, only the communication module in the security module is called, and the main controller and the communication module respectively provide data encryption or decryption functions. There is no need to call the security chip, and encrypted data can be directly transmitted between the main controller and the communication module in the security module. In one embodiment, the communication module can also execute step 202 to send data encrypted based on the first encryption protocol to the main controller, and the main controller decrypts the received data based on the first encryption protocol. It should be noted that in the embodiment of the present disclosure, the execution order of steps 201 and 202 is not limited. In the embodiment of the present disclosure, the data transmission between the main controller and the security module is encrypted by the first encryption protocol, which can avoid the leakage of internal terminal data.
[0030] In an embodiment of the present disclosure, unencrypted plaintext data can also be transmitted between the various modules in the terminal. As shown in Figure (b) in Figure 2, in one embodiment, unencrypted plaintext data can be transmitted between the main controller and the security module. For example, the main controller can execute step 203 to send unencrypted plaintext data to the communication module, and the communication module can execute step 204 to send unencrypted plaintext data to the main controller. In an embodiment of the present disclosure, the execution order of steps 203 and 204 is not limited. In this scenario, it is only necessary to call the communication module in the security module, and there is no need for a security chip to encrypt data. Unencrypted plaintext data is directly transmitted between the main controller and the communication module in the security module.
[0031] In one embodiment, the data sent by the main controller to the security module may carry at least one of a first data recipient identifier and a first encryption identifier. The first data recipient identifier indicates the data receiving device. For example, the first data recipient identifier may be the identifier of the security module or the identifier of a server. After receiving the data sent by the main controller, the security module may determine, based on the first data recipient identifier, whether the received data should be processed by the security module or forwarded to the server. In one embodiment, this determination process may be performed by the communication module within the security module. The first encryption identifier indicates whether the data is encrypted using a first encryption protocol. Based on the first encryption identifier, the security module may determine whether the received data needs to be decrypted using the first encryption protocol. For example, in an embodiment of the present disclosure, after receiving the first encrypted data, the communication module, in response to the first encrypted data carrying the first encryption identifier, performs a step of decrypting the first encrypted data using the first encryption protocol. The data sent by the main controller may also carry other information, which is not limited in the present embodiment. In one embodiment, the information carried in the data sent by the main controller may be unencrypted plaintext data or data encrypted using the first encryption protocol, which is not limited in the present embodiment.
[0032] The communication process between the various devices in the above-mentioned secure communication system is described in detail below with reference to the accompanying drawings. In the embodiment of the present disclosure, encrypted data transmission can be performed between the security module and the server based on the security chip encryption protocol. Among them, the security chip encryption protocol is a data transmission encryption protocol between the terminal where the security module is located and the external device. Exemplarily, the security chip encryption protocol can be provided by an IoT security manufacturer and integrated into the security chip and the IoT security access platform. The security chip in the security module and the IoT security access platform in the server can both perform data encryption or data decryption based on the security chip encryption protocol. That is, the data encryption and data decryption functions are provided by the security chip on the terminal side, and the data encryption and data decryption functions are provided by the IoT security access platform on the server side. In one embodiment, since the security chip encryption protocol, devices and services are all provided by the IoT security manufacturer, other users cannot modify their contents. After the secure communication system is running, the security chip encryption protocol does not support changes.
[0033] Figure 3 is a schematic diagram of data interaction between a security module and a server provided by an embodiment of the present disclosure. As shown in Figure 3, in one embodiment, encrypted data transmission between the security module and the server can be performed based on a security chip encryption protocol. Exemplarily, the communication module within the security module can execute step 301 to call the API of the internally integrated security SDK and send the encrypted data to the security chip. The security chip executes step 302 to encrypt the data based on the security chip encryption protocol and send the encrypted data to the communication module. The communication module executes step 303 to send the encrypted data to the IoT security access platform within the server. The IoT security access platform executes step 304 to decrypt the data based on the security chip encryption protocol and send the decrypted data to the IoT application platform. The process of the server sending encrypted data to the security module is similar. Exemplarily, the IoT application platform within the server executes step 305 to send the encrypted data to the IoT security access platform. The IoT security access platform executes step 306 to encrypt the data based on the security chip encryption protocol and send the encrypted data to the communication module within the security module. The communication module executes step 307 and sends the encrypted data to the security chip. The security chip executes step 308 and decrypts the data based on the security chip encryption protocol and sends the decrypted data back to the communication module. In the disclosed embodiments, by applying the security chip encryption protocol, the security of data transmission between the security module in the terminal and the server can be improved.
[0034] In an embodiment of the present disclosure, the main controller can perform encrypted data transmission with the server through the security module. In one embodiment, the main controller can send unencrypted plaintext data to the security module, which encrypts the data based on the security chip encryption protocol and forwards it to the server. Figure 4 is a schematic diagram of data interaction between the main controller and the server provided in an embodiment of the present disclosure. As shown in Figure 4, the main controller executes step 401 to send unencrypted plaintext data to the communication module in the security module. The communication module executes step 402 to call the API interface of the internally integrated security SDK and forward the data sent by the main controller to the security chip. The security chip executes step 403 to encrypt the data based on the security chip encryption protocol and sends the encrypted data back to the communication module. The communication module executes step 404 to send the encrypted data to the IoT security access platform in the server. The IoT security access platform executes step 405 to decrypt the data based on the security chip encryption protocol to obtain the plaintext data sent by the main controller and sends the decrypted plaintext data to the IoT application platform. The process of the server sending data to the main controller is similar. Exemplarily, the Internet of Things application platform executes step 406 to send the unencrypted plaintext data to the Internet of Things security access platform. The Internet of Things security access platform executes step 407 to apply the security chip encryption protocol to encrypt the data, and sends the encrypted data to the communication module in the security module. The communication module executes step 408 to forward the received encrypted data to the security chip. The security chip executes step 409 to decrypt the data based on the security chip encryption protocol, and sends the decrypted data back to the communication module. The communication module then forwards the decrypted data to the main controller. In the embodiment of the present disclosure, during the communication between the main controller and the server, forwarding and data encryption are performed by the security module to ensure the security of communication between devices.
[0035] In one embodiment, encrypted data transmission can be performed between the main controller and the server based on a second encryption protocol. This means that data that is confidential to the security module can be transmitted between the main controller and the server. The second encryption protocol is a custom encryption protocol between the main controller and the IoT application platform, and both the main controller and the IoT application platform can encrypt or decrypt data based on the second encryption protocol. Figure 5 is another schematic diagram of data interaction between the main controller and the server provided by an embodiment of the present disclosure. As shown in Figure 5, the main controller executes step 501 to encrypt data based on the second encryption protocol, obtaining second encrypted data, and then sends the second encrypted data to the communication module within the security module. The communication module executes step 502 to call the API interface of the internally integrated security SDK and send the data to be encrypted, namely the second encrypted data. The security chip executes step 503 to receive the second encrypted data forwarded by the communication module and encrypts the second encrypted data based on the security chip's encryption protocol to obtain third encrypted data. After receiving the third encrypted data sent by the security chip, the communication module executes step 504 to forward the third encrypted data to the server. The server receives the third encrypted data and decrypts it based on the security chip protocol and the second encryption protocol. In one embodiment, the IoT secure access platform in the server receives the third encrypted data, executes step 505 to decrypt the third encrypted data based on the security chip encryption protocol to obtain the second encrypted data, and forwards the decrypted second encrypted data to the IoT application platform. The IoT application platform executes step 506 to receive the second encrypted data and decrypts it based on the second encryption protocol to obtain the original data sent by the main controller. The server transmits the encrypted data to the main controller in a similar manner. Exemplarily, the IoT application platform executes step 507 to encrypt the plaintext data to be transmitted based on the second encryption protocol to obtain encrypted intermediate data, and then executes step 508 to transmit the intermediate data to the IoT secure access platform. The IoT secure access platform executes step 509 to encrypt the intermediate data based on the security chip encryption protocol, and then executes step 510 to transmit the encrypted data to the communication module. The communication module forwards the data to the security chip for decryption. The security chip executes step 511 to decrypt the received data based on the security chip encryption protocol, obtaining intermediate data, and then sends this intermediate data back to the communication module. The communication module executes step 512 to forward the decrypted data, i.e., forward the intermediate data to the main controller. The main controller executes step 513 to decrypt the data based on the second encryption protocol, obtaining the original plaintext data sent by the IoT application platform.
[0036] In the disclosed embodiments, by applying this second encryption protocol, data transmitted between the main controller and the server remains confidential to other modules in the terminal, ensuring that data transmitted between the main controller and the IoT application platform cannot be parsed or intercepted by an intermediate transmission device. For example, the intermediate transmission device may be a security module, an IoT security access platform, or the like.
[0037] In one embodiment, the communication between the security module and the main controller may be implemented through AT (Attention) instructions or through user-defined protocols and channels, which is not limited in the embodiments of the present disclosure.
[0038] In one embodiment, the data sent by the server to the security module may carry at least one of a second data recipient identifier and a second encryption identifier. The second data recipient identifier is used to identify the data receiving device. For example, the second data recipient identifier may be the identifier of the security module or the identifier of the main controller. After receiving the data sent by the server, the security module may determine, based on the second data recipient identifier, whether the received data should be processed by the security module or forwarded to the main controller. Optionally, this determination process may be performed by the communication module within the security module. The second encryption identifier indicates whether the data is encrypted using the second encryption protocol. The main controller may determine, based on the second encryption identifier, whether the received data needs to be decrypted using the second encryption protocol. For example, in the embodiment of the present disclosure, after receiving the intermediate data forwarded by the communication module, the main controller may decrypt the intermediate data using the second encryption protocol in response to the intermediate data carrying the second encryption identifier. If the intermediate data does not carry the second encryption identifier, the main controller may treat the intermediate data as the original plaintext data sent by the server. Of course, the data sent by the server may also carry other information, which is not limited in the embodiment of the present disclosure. In one embodiment, the information carried by the data sent by the server may be data encrypted using the second encryption protocol or the security chip encryption protocol, which is not limited in this embodiment of the present disclosure.
[0039] In one embodiment, the first encryption protocol and the second encryption protocol can be set by the developer. Exemplarily, the first encryption protocol and the second encryption protocol can both be implemented in the form of "algorithm" + "key", the first encryption protocol is deployed in the software run by the communication module and the software run by the main controller, and the second encryption protocol is deployed in the software run by the main controller and on the Internet of Things application platform. In one embodiment, the first encryption protocol supports changes, for example, the software firmware related to the first encryption protocol in the main controller and the security module can be upgraded respectively by remote upgrade OTA (Over-the-Air Technology). In one embodiment, the second encryption protocol supports changes, for example, the software firmware related to the second encryption protocol on the Internet of Things application platform can be upgraded. The software firmware related to the second encryption protocol in the main controller is upgraded by remote upgrade OTA.
[0040] The upgrade process of the above-mentioned first security protocol and second security protocol is described in detail below with reference to the accompanying drawings. In one embodiment, the communication module and the main controller can be used to upgrade the running software of the first encryption protocol. Figure 6 is a flow chart of upgrading the first encryption protocol provided by an embodiment of the present disclosure. As shown in Figure 6, first, a developer can create a first software firmware upgrade package that supports the upgraded first encryption protocol to run on the main controller, and a second software firmware upgrade package that supports the upgraded first encryption protocol to run on the communication module, and add the first software firmware upgrade package and the second software firmware upgrade package to the Internet of Things application platform in the server, that is, the process of executing step 601. Then, the running software of the first encryption protocol in the main controller is upgraded. Exemplarily, the process can be implemented as follows: the server executes step 602 to send a first upgrade instruction to the security module, and then forwards the first upgrade instruction to the main controller through the security module, and the first upgrade instruction carries the first software firmware upgrade package. After receiving the first upgrade instruction from the server, the main controller executes step 603 to upgrade the operating software of the first encryption protocol in the main controller based on the first upgrade instruction. Specifically, the main controller can complete the upgrade of the first encryption protocol by burning the first software firmware upgrade package. After completing the upgrade of the first encryption protocol, the main controller sends the upgraded version number of the first encryption protocol and the main controller identifier to the IoT application platform in the server. The IoT application platform executes step 604 to receive and verify the correctness of the upgraded version number of the first encryption protocol and the main controller identifier. If the upgraded version number of the first encryption protocol and the main controller identifier are correct, the upgrade is successful. If the upgraded version number of the first encryption protocol and the main controller identifier are incorrect, the upgrade fails. In response to the upgrade failure, the server reissues the first upgrade instruction to the main controller, re-executing step 602. In response to the upgrade success, the subsequent steps of upgrading the operating software of the first encryption protocol in the communication module are continued. Finally, the operating software of the first encryption protocol in the communication module is upgraded. Exemplarily, the process can be implemented as follows: the server executes step 605 to send a second upgrade instruction to the communication module in the security module, and the second upgrade instruction carries the second software firmware upgrade package. After receiving the second upgrade instruction sent by the server, the communication module executes step 606 to upgrade the running software of the first encryption protocol in the communication module based on the second upgrade instruction, that is, the communication module can complete the upgrade of the first encryption protocol by burning the second software firmware upgrade package. After the communication module completes the upgrade of the first encryption protocol, it sends the version number and main controller identifier of the upgraded first encryption protocol to the Internet of Things application platform in the server. The Internet of Things application platform executes step 607 to receive and detect the correctness of the version number and main controller identifier of the upgraded first encryption protocol.If the version number and main controller identifier of the upgraded first encryption protocol are correct, the upgrade is successful. If the version number and main controller identifier of the upgraded first encryption protocol are incorrect, the upgrade fails. In response to the upgrade failure, the server re-issues the second upgrade instruction to the communication module, that is, re-executes the above step 605. In response to the upgrade success, it is determined that the upgrade of the first encryption protocol is completed. In the embodiment of the present disclosure, by upgrading the first encryption protocol, the data encryption effect is ensured, and the security of data transmission between various modules inside the terminal device is further improved.
[0041] Figure 7 is a flowchart of an upgrade process for a second encryption protocol provided by an embodiment of the present disclosure. As shown in Figure 7, developers can first integrate and deploy the upgraded second encryption protocol on the server's IoT application platform, executing step 701 to complete the upgrade of the server's running software for the second encryption protocol. After deployment, the IoT application platform supports data encryption and decryption based on the upgraded second encryption protocol. Developers can also create a third software and firmware upgrade package that supports the upgraded second encryption protocol on the main controller and add it to the server's IoT application platform, executing step 702. The running software for the second encryption protocol in the main controller is then upgraded. Exemplarily, this process can be implemented as follows: the server executes step 703 to send a third upgrade instruction to the security module, which then forwards the third upgrade instruction to the main controller, carrying the third software and firmware upgrade package. After receiving the third upgrade instruction from the server, the main controller executes step 704 to upgrade the running software for the second encryption protocol in the main controller based on the third upgrade instruction. Specifically, the main controller can complete the upgrade of the second encryption protocol by burning the third software and firmware upgrade package. The main controller sends the version number of the upgraded second encryption protocol and the main controller identifier to the Internet of Things application platform in the server. The Internet of Things application platform executes step 705 to receive and detect the correctness of the version number of the upgraded second encryption protocol and the main controller identifier. If the version number of the upgraded second encryption protocol and the main controller identifier are correct, the upgrade is successful. If the version number of the upgraded second encryption protocol and the main controller identifier are incorrect, the upgrade fails. In response to the upgrade failure, the server re-issues the third upgrade instruction to the main controller, that is, re-executes step 703. In response to the upgrade success, it is determined that the upgrade of the second encryption protocol is complete. In the embodiment of the present disclosure, by upgrading the second encryption protocol, the data encryption effect is ensured, and the security of data transmission between the main controller and the server is further improved.
[0042] In one embodiment, the version number of the first encryption protocol and the version number of the second encryption protocol can be used to manage the software version. The version numbers before and after the upgrade are different, which can be used to determine whether the running software of the encryption protocol has been successfully upgraded. The above-mentioned communication module identifier and main controller identifier can be used for device management. The identifier can be the IMEI (International Mobile Equipment Identity) number, SN (serial number), hardware version number, etc. of the device. In the embodiment of the present disclosure, there is no limitation on the transmission method of the above-mentioned software and firmware upgrade package. For example, the second encryption protocol and the security chip encryption protocol can be applied for encryption and then transmitted, or only the security chip encryption protocol can be applied for encryption and then transmitted.
[0043] The security module in the disclosed embodiment includes a communication module and a security chip. Within the terminal device, the communication module performs encrypted data transmission with other modules within the terminal based on a first encryption protocol. During external communication, the security chip performs encrypted data transmission with external servers and other devices based on the security chip encryption protocol. In this solution, by applying the security chip's security encryption function and custom encryption algorithms between the modules within the terminal, secure communication using multiple encryption methods is achieved. This not only ensures the security of data transmission between the terminal and external servers, but also avoids the risk of data leakage during transmission between modules within the terminal device.
[0044] All of the above optional technical solutions can be combined in any way to form optional embodiments of the present application, and will not be described in detail here.
[0045] Figure 8 is a schematic diagram of the hardware structure of a computer device provided in an embodiment of the present disclosure. In the embodiment of the present disclosure, the above-mentioned terminal and server can both be regarded as a computer device.
[0046] The computer device may include a processor 801 and a memory 802 storing computer program instructions.
[0047] Specifically, the processor 801 may include a central processing unit (CPU) or an application specific integrated circuit (ASIC), or may be configured to implement one or more integrated circuits of the embodiments of the present disclosure.
[0048] Memory 802 may include a large capacity memory for data or instructions. By way of example and not limitation, memory 802 may include a hard disk drive (HDD), a floppy disk drive, a flash memory, an optical disk, a magneto-optical disk, a magnetic tape, or a Universal Serial Bus (USB) drive, or a combination of two or more of these. In one example, memory 802 may include removable or non-removable (or fixed) media, or memory 802 may be a non-volatile solid-state memory. Memory 802 may be internal or external to the computing device.
[0049] In one example, the memory 802 may include read-only memory (ROM), random access memory (RAM), magnetic disk storage media devices, optical storage media devices, flash memory devices, electrical, optical, or other physical / tangible memory storage devices. Thus, generally, the memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the method according to an aspect of the present disclosure.
[0050] The processor 801 implements the secure communication method shown in FIG. 2 to FIG. 7 by reading and executing computer program instructions stored in the memory 802 .
[0051] In one example, the computer device may further include a communication interface 803 and a bus 804. As shown in Figure 8, the processor 801, the memory 802, and the communication interface 803 are connected via the bus 804 and communicate with each other.
[0052] The communication interface 803 is mainly used to implement communication between various modules, devices, units and / or equipment in the embodiments of the present disclosure.
[0053] Bus 804 includes hardware, software or both, and couples the components of the online data traffic metering device to each other. For example, and not limitation, the bus may include an Accelerated Graphics Port (AGP) or other graphics bus, an Extended Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), a Hyper Transport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an InfiniBand interconnect, a Low Pin Count (LPC) bus, a memory bus, a Micro Channel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local (VLB) bus or other suitable buses or a combination of two or more of these. Where appropriate, bus 304 may include one or more buses. Although the present disclosure describes and illustrates a specific bus, the present disclosure contemplates any suitable bus or interconnect.
[0054] In addition, in conjunction with the secure communication methods in the above embodiments, embodiments of the present disclosure may provide a computer storage medium for implementation. The computer storage medium stores computer program instructions; when executed by a processor, the computer program instructions implement any of the secure communication methods in the above embodiments. Exemplarily, the computer storage medium may be a non-transitory computer-readable storage medium.
[0055] It should be understood that the present disclosure is not limited to the specific configurations and processes described above and illustrated in the figures. For the sake of brevity, a detailed description of known methods is omitted here. In the above embodiments, several specific steps are described and illustrated as examples. However, the method process of the present disclosure is not limited to the specific steps described and illustrated. Those skilled in the art can make various changes, modifications, and additions, or change the order of the steps after understanding the spirit of the present disclosure.
[0056] The functional blocks (modules) shown in the above-described block diagram can be implemented as hardware, software, firmware or a combination thereof. When implemented in hardware, it can be, for example, an electronic circuit, an application-specific integrated circuit (ASIC), appropriate firmware, a plug-in, a function card, etc. When implemented in software, the components / elements of the present disclosure are programs or code segments used to perform the required tasks. The program or code segment can be stored in a machine-readable medium, or transmitted on a transmission medium or a communication link via a data signal carried in a carrier wave. "Machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, read-only memories (ROMs), flash memories, erasable read-only memories (EROMs), floppy disks, compact disc read-only memories (CD-ROMs), optical discs, hard disks, optical fiber media, radio frequency (RF) links, etc. The code segments can be downloaded via computer networks such as the Internet, intranets, etc.
[0057] It should also be noted that the exemplary embodiments described in this disclosure describe methods or systems based on a series of steps or devices. However, this disclosure is not limited to the order of the steps described above. In other words, the steps may be performed in the order described in the embodiments, or in a different order, or several steps may be performed simultaneously.
[0058] Aspects of the present disclosure have been described above with reference to the flowcharts and / or block diagrams of the methods, devices (systems) and computer program products according to the embodiments of the present disclosure. It should be understood that each box in the flowchart and / or block diagram and the combination of each box in the flowchart and / or block diagram can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer or other programmable data processing device to produce a machine so that these instructions executed by the processor of the computer or other programmable data processing device enable the implementation of the function / action specified in one or more boxes of the flowchart and / or block diagram. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor or a field programmable logic circuit. It is also understood that each box in the block diagram and / or flowchart and the combination of the boxes in the block diagram and / or flowchart can also be implemented by dedicated hardware that performs the specified function or action, or can be implemented by a combination of dedicated hardware and computer instructions.
[0059] The above description is only a specific embodiment of the present disclosure. Those skilled in the art will clearly understand that for the convenience and brevity of description, the specific working processes of the systems, modules and units described above can refer to the corresponding processes in the aforementioned method embodiments, and will not be repeated here. It should be understood that the scope of protection of the present disclosure is not limited to this. Any person skilled in the art can easily think of various equivalent modifications or replacements within the technical scope disclosed in the present disclosure, and these modifications or replacements should be included in the scope of protection of the present disclosure.
Claims
1. A security module, comprising a communication module and a security chip; The communication module is used to perform data encryption or data decryption based on a first encryption protocol, wherein the first encryption protocol is a data transmission encryption protocol inside the terminal where the security module is located; The security chip is used to perform data encryption or data decryption based on a security chip encryption protocol, wherein the security chip encryption protocol is a data transmission encryption protocol between the terminal where the security module is located and an external device.
2. The security module according to claim 1, wherein: The communication module is also used to upgrade the operating software of the first encryption protocol.
3. A secure communication system, comprising the security module according to claim 1 or 2, a main controller, and a server; The security module and the main controller are deployed in the same terminal; The security module and the main controller perform encrypted data transmission based on a first encryption protocol; The security module and the server perform encrypted data transmission based on the security chip encryption protocol; The main controller and the server perform data transmission based on a second encryption protocol.
4. The secure communication system according to claim 3, wherein: The main controller is used for performing data encryption based on the first encryption protocol to obtain first encrypted data, and sending the first encrypted data to the communication module in the security module; The communication module is used to receive the first encrypted data and decrypt the first encrypted data based on the first encryption protocol.
5. The secure communication system according to claim 3, wherein: The main controller is used for performing data encryption based on the second encryption protocol to obtain second encrypted data, and forwarding the second encrypted data to the communication module in the security module; The security chip is used to receive the second encrypted data, and encrypt the second encrypted data based on the security chip encryption protocol to obtain third encrypted data; The communication module is used to receive the third encrypted data sent by the security chip, and forward the third encrypted data to the server; The server is used to receive the third encrypted data and decrypt the third encrypted data based on the security chip protocol and the second encryption protocol.
6. The secure communication system according to claim 5, wherein: The server includes an IoT security access platform and an IoT application platform; The IoT security access platform is configured to receive the third encrypted data, decrypt the third encrypted data based on the security chip encryption protocol to obtain the second encrypted data, and forward the second encrypted data to the IoT application platform; The Internet of Things application platform is used to receive the second encrypted data and decrypt the second encrypted data based on the second encryption protocol.
7. The secure communication system according to claim 3, wherein: The main controller is further used to receive a first upgrade instruction sent by the server, and upgrade the running software of the first encryption protocol in the main controller based on the first upgrade instruction; The communication module is also used to receive a second upgrade instruction sent by the server, and upgrade the running software of the first encryption protocol in the communication module based on the second upgrade instruction.
8. The secure communication system according to claim 3, wherein: The main controller is also used to receive a third upgrade instruction sent by the server, and to upgrade the running software of the second encryption protocol in the main controller based on the third upgrade instruction.
9. A secure communication method, the method being applied to the secure communication system according to any one of claims 3 to 8, the method comprising: The main controller encrypts data based on the first encryption protocol to obtain first encrypted data; The main controller sends the first encrypted data to the communication module in the security module; as well as The communication module receives the first encrypted data and decrypts the first encrypted data based on the first encryption protocol.
10. The method according to claim 9, wherein: Before the main controller encrypts data based on the first encryption protocol to obtain first encrypted data, the method further includes: The main controller encrypts data based on the second encryption protocol to obtain second encrypted data, and sends the second encrypted data to the communication module in the security module; The security chip receives the second encrypted data, and encrypts the second encrypted data based on the security chip encryption protocol to obtain third encrypted data; The communication module receives the third encrypted data, and forwards the third encrypted data to the server; and The server receives the third encrypted data, and decrypts the third encrypted data based on the security chip protocol and the second encryption protocol.
11. The method according to claim 10, wherein: The server includes an Internet of Things security access platform and an Internet of Things application platform, the server receives the third encrypted data, and decrypts the third encrypted data based on the security chip protocol and the second encryption protocol, including: The IoT security access platform receives the third encrypted data, decrypts the third encrypted data based on the security chip encryption protocol to obtain the second encrypted data, and forwards the second encrypted data to the IoT application platform; The second encrypted data is received by the Internet of Things application platform, and the second encrypted data is decrypted based on the second encryption protocol.
12. The method according to claim 9, wherein: Before the main controller encrypts data based on the first encryption protocol to obtain first encrypted data, the method further includes: The main controller receives a first upgrade instruction sent by the server, and upgrades the running software of the first encryption protocol in the main controller based on the first upgrade instruction; and The communication module receives a second upgrade instruction sent by the server, and upgrades the running software of the first encryption protocol in the communication module based on the second upgrade instruction.
13. The method according to claim 12, wherein: After the main controller receives the first upgrade instruction sent by the server and upgrades the running software of the first encryption protocol in the main controller based on the first upgrade instruction, the method further includes: The main controller sends the upgrade result of the running software of the first encryption protocol to the server; In response to the upgrade being successful, the server sends the second upgrade instruction to the communication module; and In response to an upgrade failure, the server resends the first upgrade instruction to the main controller.
14. The method according to claim 10, wherein: The main controller encrypts data based on the second encryption protocol to obtain second encrypted data, and before sending the second encrypted data to the communication module in the security module, the method further includes: The main controller receives the third upgrade instruction sent by the server, and upgrades the running software of the second encryption protocol in the main controller based on the third upgrade instruction.
15. A computer storage medium having instructions stored thereon, wherein when the instructions are executed by a processor, the method according to any one of claims 9 to 14 is implemented.
16. A computer program product comprising instructions, wherein when the instructions are executed by a processor, the processor is caused to perform the method according to any one of claims 9 to 14.
Citation Information
Patent Citations
Security camera device encryption method and security camera device
CN107277320A
Security communication module, security communication system and method and readable storage medium
CN111683367A
In-device data transmission method, and method and device for realizing in-device data transmission
CN112887263A
Method of using touch screen device for system encryption and protection
US20160196437A1