Method and apparatus for transmitting data, device, medium, and product

By using both post-quantum encryption and non-post-quantum encryption algorithms to double-encrypt data during data transmission, the problem that traditional encryption algorithms cannot resist quantum computer attacks is solved, achieving higher data transmission security and reliability.

WO2025252073A1PCT designated stage Publication Date: 2025-12-11GIESECKE & DEVRIENT (CHINA) TECHNOLOGIES CO LTD +1
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/098808
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-06-05
Filing Date
2025-06-03
Publication Date
2025-12-11

AI Technical Summary

Technical Problem

Traditional encryption algorithms cannot withstand attacks from quantum computers, leading to a decline in data transmission security.

Method used

Data is double-encrypted using both post-quantum encryption and non-post-quantum encryption algorithms, and then decrypted at the receiving end using the corresponding decryption algorithm to ensure the security of data transmission.

Benefits of technology

It effectively resists attacks from quantum computers, improves the security and reliability of data transmission, and prevents unpredictable failures or compatibility issues.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025098808_11122025_PF_FP_ABST
    Figure CN2025098808_11122025_PF_FP_ABST
Patent Text Reader

Abstract

The present application belongs to the technical field of communications, and discloses a method and apparatus for transmitting data, a device, a medium, and a product. In the embodiments of the present application, a post-quantum encryption algorithm and a non-post-quantum encryption algorithm are used to encrypt a received first service packet to obtain a second service packet, and the second service packet is sent to a receiver by means of a specified channel, so as to enable the receiver to use a post-quantum decryption algorithm corresponding to the post-quantum encryption algorithm and a non-post-quantum decryption algorithm corresponding to the non-post-quantum encryption algorithm to decrypt the second service packet to obtain the first service packet. That is, in the embodiments of the present application, on the basis of the post-quantum encryption algorithm, the non-post-quantum encryption algorithm is further used for reinforcement, so that attacks by a quantum computer can be effectively resisted, thereby improving the security of data transmission.
Need to check novelty before this filing date? Find Prior Art

Description

Data transmission method, device, equipment, medium and product TECHNICAL FIELD

[0001] The present application belongs to the technical field of communication, and particularly relates to a data transmission method, device, equipment, medium and product. BACKGROUND

[0002] In data transmission, in order to improve the security of data transmission, symmetric encryption algorithm, asymmetric encryption algorithm and the like are usually used to encrypt the transmitted data. However, with the development of technology, the traditional encryption algorithm is no longer secure. SUMMARY

[0003] The purpose of the embodiments of the present application is to provide a data transmission method, device, equipment, medium and product, which can guarantee the security of data transmission.

[0004] In order to solve the above technical problems, the present application is implemented as follows:

[0005] In a first aspect, the embodiments of the present application provide a data transmission method, comprising:

[0006] receiving a first service packet;

[0007] encrypting the first service packet by using a post-quantum encryption algorithm and a non-post-quantum encryption algorithm to obtain a second service packet;

[0008] sending the second service packet to a receiving party through a specified channel, so that the receiving party decrypts the second service packet by using a post-quantum decryption algorithm corresponding to the post-quantum encryption algorithm and a non-post-quantum decryption algorithm corresponding to the non-post-quantum encryption algorithm, to obtain the first service packet.

[0009] In a second aspect, the embodiments of the present application provide a data transmission device, comprising:

[0010] a receiving module configured to receive a first service packet;

[0011] an encryption module configured to encrypt the first service packet by using a post-quantum encryption algorithm and a non-post-quantum encryption algorithm to obtain a second service packet;

[0012] a sending module configured to send the second service packet to a receiving party through a specified channel, so that the receiving party decrypts the second service packet by using a post-quantum decryption algorithm corresponding to the post-quantum encryption algorithm and a non-post-quantum decryption algorithm corresponding to the non-post-quantum encryption algorithm, to obtain the first service packet.

[0013] In a third aspect, the embodiments of the present application provide an electronic device, comprising a processor and a memory storing computer program instructions; the processor reads and executes the computer program instructions to implement the method of the first aspect.

[0014] In a fourth aspect, an embodiment of the present application provides a readable storage medium, and the readable storage medium stores a program or instructions, and the program or instructions are executed by a processor to implement the method in the first aspect.

[0015] In a fifth aspect, an embodiment of the present application provides a computer program product, and the computer program product comprises a computer program, and the computer program is executed by a processor to implement the method in the first aspect.

[0016] The embodiment of the present application encrypts the received first service packet by using the post-quantum encryption algorithm and the non-post-quantum encryption algorithm, obtains a second service packet, and sends the second service packet to a receiving party through a designated channel, so that the receiving party decrypts the second service packet by using the post-quantum decryption algorithm corresponding to the post-quantum encryption algorithm and the non-post-quantum decryption algorithm corresponding to the non-post-quantum encryption algorithm, and obtains the first service packet. That is, the embodiment of the present application further uses the post-quantum encryption algorithm to reinforce on the basis of the post-quantum encryption algorithm, which can effectively resist attacks of quantum computers and improve the security of data transmission. BRIEF DESCRIPTION OF DRAWINGS

[0017] FIG. 1 is a flowchart of a data transmission method according to an embodiment of the present application;

[0018] FIG. 2 is a flowchart of another data transmission method according to an embodiment of the present application;

[0019] FIG. 3 is a flowchart of another data transmission method according to an embodiment of the present application;

[0020] FIG. 4 is a structural schematic diagram of a data transmission device according to an embodiment of the present application;

[0021] FIG. 5 is a hardware structural schematic diagram of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION

[0022] The features and exemplary embodiments of various aspects of the present application will be described in detail below, in order to make the purposes, technical solutions and advantages of the present application more clear and apparent, the present application will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain the present application, but not to limit the present application. For those skilled in the art, the present application can be implemented without some of these specific details. The following description of the embodiments is only to provide a better understanding of the present application by showing examples of the present application.

[0023] It should be noted that, in the present document, relational terms such as first and second and the like can be used solely to distinguish one entity or action from another entity or action without necessarily requiring or implying any actual such relationship or order between such entities or actions. Moreover, the terms "comprises", "comprising", or any other variation thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but can include other elements not expressly listed or inherent to such process, method, article, or apparatus. An element proceeded by "comprises... a" does not, without more constraints, exclude the presence of additional identical elements in the process, method, article, or apparatus that comprises the element.

[0024] With the development of quantum computers, traditional encryption algorithms such as symmetric encryption algorithms and asymmetric encryption algorithms are no longer secure. In order to resist attacks by quantum computers and ensure the security of data transmission, the embodiments of the present application provide a data transmission method, device, equipment, medium and product. The data transmission method, device, equipment, medium and product provided by the embodiments of the present application will be described below through specific embodiments.

[0025] FIG. 1 is a flowchart of a data transmission method provided by the embodiments of the present application. The data transmission method can be applied to a sender, which can be an electronic device such as a mobile phone, a computer, a tablet, etc. that sends a service message.

[0026] As shown in FIG. 1, the data transmission method can include the following steps:

[0027] S110, receiving a first service message.

[0028] S120, encrypting the first service message using a post-quantum encryption algorithm and a non-post-quantum encryption algorithm to obtain a second service message.

[0029] S130, sending the second service message to a receiver through a designated channel, so that the receiver decrypts the second service message using a post-quantum decryption algorithm corresponding to the post-quantum encryption algorithm and a non-post-quantum decryption algorithm corresponding to the non-post-quantum encryption algorithm to obtain the first service message.

[0030] The embodiment of the application uses a post-quantum encryption algorithm and a non-post-quantum encryption algorithm to encrypt the received first service message to obtain a second service message, and sends the second service message to the receiving party through a designated channel, so that the receiving party uses a post-quantum decryption algorithm corresponding to the post-quantum encryption algorithm and a non-post-quantum decryption algorithm corresponding to the non-post-quantum encryption algorithm to decrypt the second service message to obtain the first service message. That is, the embodiment of the application further uses the post-quantum encryption algorithm to reinforce on the basis of the post-quantum encryption algorithm, which can effectively resist attacks by quantum computers and improve the security of data transmission.

[0031] The above steps are described in detail as follows:

[0032] In S110, the first service message is a service message received by the sending party and needs to be sent to the receiving party. Exemplarily, the first service message can be a message for accessing a certain webpage, or other messages, and the embodiment of the application does not limit the specific content of the message. The receiving party can be an electronic device such as a mobile phone, a computer, or a server.

[0033] In S120, in order to ensure the security of the first service message, the first service message needs to be encrypted before being sent to the receiving party. Considering the development of quantum computers, in order to effectively resist attacks by quantum computers, the embodiment of the application can use a post-quantum encryption algorithm and a non-post-quantum encryption algorithm to double-encrypt the first service message, thereby improving the security of the first service message.

[0034] The non-post-quantum encryption algorithm can include, but is not limited to, a public key encryption, a digital signature, a public key encryption followed by a digital signature, a digital signature followed by a public key encryption, and the like.

[0035] The post-quantum encryption algorithm is a kind of cryptographic algorithm that can resist attacks by quantum computers on existing cryptographic algorithms such as non-post-quantum encryption algorithms.

[0036] When the first service message is encrypted using the post-quantum encryption algorithm and the non-post-quantum encryption algorithm, exemplarily, the first service message can be first encrypted using the post-quantum encryption algorithm, and then further encrypted using the non-post-quantum encryption algorithm on the result obtained by the post-quantum encryption algorithm. Alternatively, the first service message can be first encrypted using the non-post-quantum encryption algorithm, and then further encrypted using the post-quantum encryption algorithm on the result obtained by the non-post-quantum encryption algorithm. The specific selection can be made according to actual needs. For example, for the same service message, the above processes can be used for encryption respectively, and the appropriate encryption process can be selected according to the encryption time.

[0037] The second service message is the final service message obtained by encryption using the post-quantum encryption algorithm and the non-post-quantum encryption algorithm, that is, the service message sent to the receiving party.

[0038] In S130, after the sender obtains the second service message, the sender can send the second service message to the receiver through a specified channel. After receiving the second service message, the receiver can use the post-quantum decryption algorithm corresponding to the post-quantum encryption algorithm and the non-post-quantum decryption algorithm corresponding to the non-post-quantum encryption algorithm to decrypt the second service message to obtain the original message, i.e., the first service message.

[0039] Taking the case that the sender first encrypts by using the post-quantum encryption algorithm and then encrypts by using the non-post-quantum encryption algorithm as an example, after receiving the second service message, the receiver first decrypts by using the non-post-quantum decryption algorithm corresponding to the non-post-quantum encryption algorithm, and then further decrypts by using the post-quantum decryption algorithm corresponding to the post-quantum encryption algorithm.

[0040] Taking the case that the sender first encrypts by using the non-post-quantum encryption algorithm and then encrypts by using the post-quantum encryption algorithm as an example, after receiving the second service message, the receiver first decrypts by using the post-quantum decryption algorithm corresponding to the post-quantum encryption algorithm, and then further decrypts by using the non-post-quantum decryption algorithm corresponding to the non-post-quantum encryption algorithm.

[0041] The post-quantum encryption algorithm includes the post-quantum public key of the receiver and the post-quantum private key of the sender. Taking the case that the non-post-quantum encryption algorithm includes a public key encryption algorithm and / or a digital signature algorithm as an example, as shown in FIG. 2, the data transmission method can include the following steps:

[0042] S210, receiving a first service message.

[0043] S220, encrypting the first service message by using a post-quantum public key and digitally signing the encrypted first service message by using a post-quantum private key to obtain a first signed message.

[0044] S230, encrypting the first signed message by using a public key encryption algorithm and / or a digital signature algorithm to obtain a second service message.

[0045] S240, sending the second service message to the receiver through a specified channel, so that the receiver uses a post-quantum decryption algorithm corresponding to a post-quantum encryption algorithm and a non-post-quantum decryption algorithm corresponding to a non-post-quantum encryption algorithm to decrypt the second service message to obtain the first service message.

[0046] The processes of S210 and S240 can be referred to the above embodiments, which will not be described herein for brevity.

[0047] The post-quantum public key is sent by the receiver to the sender and is used by the sender to encrypt the first service message. The post-quantum private key is sent by the sender to the receiver and is used by the receiver to decrypt the encrypted message. Therefore, before S210, the data transmission method can further include the following steps:

[0048] receiving the post-quantum public key sent by the sender, and sending the post-quantum public key of the sender to the receiver.

[0049] That is, before application, the sender and the receiver can first perform post-quantum key exchange to provide a basis for subsequent encryption and decryption. For example, the sender can send a post-quantum public key to the receiver, and the receiver can send a post-quantum private key to the sender.

[0050] Before application, the post-quantum key exchange of the embodiments of the present application makes it possible to encrypt the service message using a post-quantum encryption algorithm, effectively resists attacks by quantum computers, and ensures the security of data transmission.

[0051] When encrypting the first service message using the post-quantum encryption algorithm, the first service message can be first encrypted using the post-quantum public key of the receiver, and then digitally signed using the post-quantum private key of the sender to obtain a first signed message. On this basis, the first signed message can be further encrypted using a public key encryption algorithm and / or a digital signature algorithm to obtain a second service message.

[0052] For example, the first signed message can be further encrypted using a public key encryption algorithm to obtain a second service message.

[0053] For example, the first signed message can also be further digitally signed using a digital signature algorithm to obtain a second service message.

[0054] For example, the first signed message can also be first encrypted using a public key encryption algorithm, and then digitally signed using a digital signature algorithm on the encrypted first signed message to obtain a second service message.

[0055] For example, the first signed message can also be first digitally signed using a digital signature algorithm, and then encrypted using a public key encryption algorithm on the secondly signed first signed message to obtain a second service message.

[0056] The embodiments of the present application introduce a post-quantum encryption module without changing the structure of the original encryption system, so that the post-quantum encryption module can adapt to the original encryption system, prevent unpredictable failures or compatibility problems, achieve secure encryption of the first service message, and ensure the security of data transmission.

[0057] Considering that the ciphertext or signature output by the post-quantum encryption algorithm can be relatively long and exceed the length requirement of the input message of the non-post-quantum encryption algorithm, in order to ensure the reliability of data transmission, after S220, the data transmission method can further include the following steps:

[0058] determining whether the length of the first signature message is greater than a first reference length, the first reference length being a maximum message length of a single message allowed by the public key encryption algorithm and / or the digital signature algorithm;

[0059] splitting the first signature message to obtain at least two first split messages when it is determined that the length of the first signature message is greater than the first reference length, each of the first split messages having a length less than or equal to the first reference length;

[0060] encrypting the first signature message by using the public key encryption algorithm and / or the digital signature algorithm to obtain a second service message, comprising:

[0061] encrypting each of the first split messages by using the public key encryption algorithm and / or the digital signature algorithm to obtain a second service message corresponding to each of the first split messages.

[0062] Exemplarily, when the non-post-quantum encryption algorithm only contains the public key encryption algorithm or the digital signature algorithm, the first reference length can be a maximum length of a single message input by the public key encryption algorithm or the digital signature algorithm. When the non-post-quantum encryption algorithm contains the public key encryption algorithm and the digital signature algorithm, the first reference length can be a minimum value of a maximum length of a single message input by the public key encryption algorithm and a maximum length of a single message input by the digital signature algorithm. In this way, it can be ensured that the length of the message input by each encryption algorithm does not exceed the maximum length allowed thereby.

[0063] In actual application, the first reference length can change with the business, for example, different business types can correspond to different first reference lengths. The correspondence between the business type and the first reference length can be stored in advance. In subsequent use, the first reference length corresponding to the first service message can be obtained by searching the correspondence table according to the business type to which the first service message belongs.

[0064] Exemplarily, when the length of the first signature message is greater than the first reference length, the first signature message can be split to obtain at least two first split messages, wherein the length of each of the first split messages is less than the first reference length. For each of the first split messages, the public key encryption algorithm and / or the digital signature algorithm can be used for encryption to obtain a second service message corresponding to each of the first split messages. The specific encryption process can be referred to the above embodiments, which will not be described in detail here.

[0065] Exemplarily, in order to enable the receiver to accurately obtain the complete first service message, the sender can set a corresponding identifier for each first split message after splitting the first signature message, to identify the order of the first split message in the first signature message. The identifier of each first split message can be stored through an additional data structure, which can be sent to the receiver together with the second service message later. Based on the data structure, the receiver can combine and restore the decrypted message to obtain the first service message.

[0066] The sender can send each second service message at the same time, or send them in sequence.

[0067] After obtaining the first signature message by using the post-quantum encryption algorithm, the embodiment of the present application can further judge the length of the first signature message, and split the first signature message when its length is greater than the maximum length of a single message allowed by the non-post-quantum encryption algorithm, so that each first split message after splitting is less than the maximum length, and is coupled with the non-post-quantum encryption algorithm, thereby ensuring the reliability of data transmission.

[0068] In some embodiments, as shown in FIG. 3, the data transmission method can include the following steps:

[0069] S310, receiving a first service message.

[0070] S320, encrypting the first service message by using a public key encryption algorithm and / or a digital signature algorithm to obtain a first encrypted message.

[0071] S330, encrypting the first encrypted service message by using a post-quantum public key, and digitally signing the encrypted first encrypted message by using a post-quantum private key to obtain a second service message.

[0072] S340, sending the second service message to a receiver through a designated channel, so that the receiver decrypts the second service message by using a post-quantum decryption algorithm corresponding to the post-quantum encryption algorithm and a non-post-quantum decryption algorithm corresponding to the non-post-quantum encryption algorithm, to obtain the first service message.

[0073] When encrypting the first service message, the embodiment of the present application first encrypts the first service message by using a public key encryption algorithm and / or a digital signature algorithm, and then further encrypts by using a post-quantum encryption algorithm. The specific encryption process is similar to the process of first encrypting by using a post-quantum encryption algorithm, and then further encrypting by using a public key encryption algorithm and / or a digital signature algorithm. For brevity, details are not repeated here.

[0074] The embodiment of the application introduces a post-quantum encryption module without changing the structure of the original encryption system, so that the post-quantum encryption module can adapt to the original encryption system, prevent unpredictable failures or compatibility problems, realize the secure encryption of the first service message, and ensure the security of data transmission.

[0075] It can be understood that the channel also has requirements on the length of the transmitted data, and the maximum length allowed by the same channel for different types of service messages can be different. In order to ensure reliable transmission of data, the S130 can include the following steps:

[0076] In the case that the length of the second service message is greater than the second reference length, the second service message is split to obtain at least two second split messages, and the second reference length is the maximum message length of a single message allowed to be input by the specified channel;

[0077] Each second split message is sent to the receiver through the specified channel.

[0078] Exemplarily, the correspondence between different types of service messages and the maximum message length of a single message can be stored in advance, and in subsequent application, the corresponding relationship table can be searched according to the type of the service message to determine the maximum message length of a single corresponding service message allowed to be input by the channel. Here, the channel can be a physical channel or a virtual channel.

[0079] Exemplarily, if the length of the second service message is greater than the maximum message length of a single message allowed by the channel, the sender splits the second service message to obtain at least two second split messages, so that the length of each second split message is less than the maximum message length of a single message allowed by the channel. Then each second split message is sent to the receiver through the channel simultaneously or sequentially.

[0080] Before the embodiment of the application sends the second service message to the receiver, the length of the second service message is judged. If the length of the second service message is greater than the maximum length of a single message allowed by the channel, the second service message is split so that each second split message after splitting is less than the maximum length and is coupled with the service type corresponding to the channel, thereby ensuring the reliability of data transmission.

[0081] The decryption process of the receiver corresponds to the encryption process of the sender, and the decryption process of the embodiment of the application will not be described in detail.

[0082] The embodiment of the present application adds a post-quantum encryption module on the basis of keeping the original password system structure unchanged, so that the post-quantum encryption module adapts to the original password system, the degree of modification is reduced, and the occurrence of unpredictable failures or compatibility problems can be prevented, the attack of the quantum computer can be effectively resisted, the security of data transmission is improved, the problem of large transmission data is effectively solved, and the reliability and stability of data transmission are ensured.

[0083] Based on the same inventive concept, the embodiment of the present application also provides a data transmission device, as shown in FIG. 4, the data transmission device 400 can include:

[0084] The receiving module 401 is configured to receive a first service packet.

[0085] The encryption module 402 is configured to encrypt the first service packet by using a post-quantum encryption algorithm and a non-post-quantum encryption algorithm to obtain a second service packet.

[0086] The sending module 403 is configured to send the second service packet to a receiving party through a designated channel, so that the receiving party decrypts the second service packet by using a post-quantum decryption algorithm corresponding to the post-quantum encryption algorithm and a non-post-quantum decryption algorithm corresponding to the non-post-quantum encryption algorithm to obtain the first service packet.

[0087] The encryption module 402 is configured to encrypt the first service packet by using a post-quantum encryption algorithm and a non-post-quantum encryption algorithm to obtain a second service packet.

[0088] In some embodiments, the post-quantum encryption algorithm includes a post-quantum public key of the receiving party and a post-quantum private key of the sending party; and the non-post-quantum encryption algorithm includes a public key encryption algorithm and / or a digital signature algorithm.

[0089] The encryption module 402 is specifically configured to:

[0090] encrypt the first service packet by using the post-quantum public key, and digitally sign the encrypted first service packet by using the post-quantum private key to obtain a first signature packet;

[0091] encrypt the first signature packet by using the public key encryption algorithm and / or the digital signature algorithm to obtain the second service packet.

[0092] In some embodiments, the data transmission apparatus 400 can further include:

[0093] a judgment module, configured to, after the encryption module 402 performs digital signature on the encrypted first service packet by using the post-quantum private key to obtain a first signature packet, judge whether the length of the first signature packet is greater than a first reference length, the first reference length being a maximum packet length of a single packet allowed by the public key encryption algorithm and / or the digital signature algorithm;

[0094] a splitting module, configured to, in a case where it is determined that the length of the first signature packet is greater than the first reference length, split the first signature packet to obtain at least two first split packets, the length of each first split packet being less than or equal to the first reference length;

[0095] the encryption module 402, specifically configured to:

[0096] perform encryption on each first split packet by using the public key encryption algorithm and / or the digital signature algorithm to obtain a second service packet corresponding to each first split packet.

[0097] In some embodiments, the post-quantum encryption algorithm includes a post-quantum public key of a receiving party and a post-quantum private key of a sending party; and the non-post-quantum encryption algorithm includes the public key encryption algorithm and / or the digital signature algorithm.

[0098] the encryption module 402, specifically configured to:

[0099] perform encryption on the first service packet by using the public key encryption algorithm and / or the digital signature algorithm to obtain a first encrypted packet;

[0100] encrypt the first encrypted service packet by using the post-quantum public key, and perform digital signature on the encrypted first encrypted packet by using the post-quantum private key to obtain a second service packet.

[0101] In some embodiments, the splitting module is further configured to, in a case where the length of the second service packet is greater than a second reference length, split the second service packet to obtain at least two second split packets, the second reference length being a maximum packet length of a single packet allowed to be input by a specified channel;

[0102] the sending module 403, specifically configured to:

[0103] send each second split packet to the receiving party through the specified channel.

[0104] In some embodiments, the receiving module 401 is further configured to receive the post-quantum public key sent by the sending party;

[0105] the sending module 403 is further configured to send the post-quantum public key of the sending party to the receiving party.

[0106] The embodiment of the present application adds a post-quantum encryption module on the basis of keeping the original password system structure unchanged, so that the post-quantum encryption module adapts to the original password system, the degree of modification is reduced, and the occurrence of unpredictable failures or compatibility problems can be prevented, the attack of the quantum computer can be effectively resisted, the security of data transmission is improved, the problem of large transmission data is effectively solved, and the reliability and stability of data transmission are ensured.

[0107] Each module in the device shown in FIG. 4 has the function of implementing each step in FIGS. 1-3 and can achieve the corresponding technical effects. For brevity of description, no further description is given here.

[0108] Based on the same inventive concept, the embodiment of the present application also provides an electronic device. FIG. 5 is a hardware structure schematic diagram of an electronic device provided by an embodiment of the present application.

[0109] As shown in FIG. 5, the electronic device 500 can include a processor 501 and a memory 502 storing computer program instructions.

[0110] Specifically, the processor 501 can include a central processing unit (CPU), or an application specific integrated circuit (ASIC), or can be configured to implement one or more integrated circuits of the embodiments of the present application.

[0111] The memory 502 can include a mass storage for data or instructions. By way of example and not limitation, the memory 502 can include a hard disk drive (HDD), a floppy disk drive, a flash memory, an optical disk, a magneto-optical disk, a magnetic tape, or a universal serial bus (USB) drive or a combination of two or more of these. In one example, the memory 502 can include a removable or non-removable (or fixed) medium, or the memory 502 is a non-volatile solid state memory. The memory 502 can be internal or external to the integrated gateway disaster recovery device.

[0112] In one example, the memory 502 can be a read only memory (ROM). In one example, the ROM can be a mask programmed ROM, a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), an electrically alterable ROM (EAROM), or a flash memory, or a combination of two or more of these.

[0113] The memory 502 can include read-only memory (ROM), random access memory (RAM), magnetic disk storage media devices, optical storage media devices, flash memory devices, electrical, optical, or other physical / tangible memory storage devices. Thus, generally, the memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software that, when executed (e.g., by one or more processors), is operable to perform the operations described with reference to the methods according to the present application.

[0114] The processor 501 implements the methods / step in the embodiments shown in FIGS. 1-3 by reading and executing computer program instructions stored in the memory 502, and achieves the corresponding technical effects that the examples shown in FIGS. 1-3 achieve their methods / step, which are not described herein for brevity.

[0115] In one example, the electronic device 500 can further include a communication interface 503 and a bus 504. As shown in FIG. 5, the processor 501, the memory 502, and the communication interface 503 are connected through the bus 504 and complete communication therebetween.

[0116] The communication interface 503 is mainly used to realize the communication between the modules, devices, units and / or equipment in the embodiments of the present application.

[0117] The bus 504 includes hardware, software, or both, for coupling components of the electronic device 500 to each other in a known manner. By way of example and not limitation, the bus 504 can include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), a Hyper Transport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an InfiniBand interconnect, a Low Pin Count (LPC) bus, a memory bus, a Micro Channel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association local (VLB) bus, or other suitable bus or combination of two or more of these. Where appropriate, the bus 504 can include one or more buses. Although particular buses are described and shown in the embodiments of the present application, the present application contemplates any suitable bus or interconnect.

[0118] The electronic device can perform the data transmission method in the embodiments of the present application after receiving the first service packet, so as to realize the data transmission method described in combination with FIG. 1 to FIG. 3, and the data transmission apparatus shown in FIG. 4.

[0119] In addition, in combination with the data transmission method in the above embodiments, the embodiments of the present application can provide a readable storage medium for implementation. The readable storage medium stores programs or instructions, which, when executed by a processor, implement any one of the data transmission methods in the above embodiments and achieve the same technical effects. To avoid repetition, details are not described herein.

[0120] In addition, in combination with the data transmission method in the above embodiments, the embodiments of the present application further provide a computer program product, which includes a computer program. When the computer program is executed by a processor, any one of the data transmission methods in the above embodiments is implemented, and the same technical effects are achieved. To avoid repetition, details are not described herein.

[0121] It should be noted that the present application is not limited to the specific configurations and processes described above and shown in the drawings. For the sake of brevity, detailed descriptions of well-known methods are omitted herein. In the above embodiments, several specific steps are described and shown as examples. However, the method processes of the present application are not limited to the specific steps described and shown. Those skilled in the art can make various changes, modifications and additions, or change the order of the steps, after understanding the spirit of the present application.

[0122] The functional blocks shown in the above structural block diagrams can be implemented as hardware, software, firmware or a combination thereof. When implemented in hardware, it can be, for example, an electronic circuit, an application specific integrated circuit (ASIC), appropriate firmware, a plug-in, a functional card, etc. When implemented in software, the elements of the present application are program or code segments used to perform the required tasks. The program or code segments can be stored in a machine-readable medium or transmitted through a data signal carried in a carrier wave over a transmission medium or communication link. The "machine-readable medium" can include any medium capable of storing or transmitting information. Examples of the machine-readable medium include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical disks, hard disks, optical fiber media, radio frequency (RF) links, etc. The code segments can be downloaded via a computer network such as the Internet, an intranet, etc.

[0123] It should also be noted that the example embodiments mentioned in the present application describe some methods or systems based on a series of steps or devices. However, the present application is not limited to the order of the above steps, that is, the steps can be performed in the order mentioned in the embodiments, or in an order different from the embodiments, or several steps can be performed simultaneously.

[0124] The above mainly describes the aspects of the present application with reference to the flowcharts and / or block diagrams of the methods, devices (systems) and computer program products according to the embodiments of the present application. It should be understood that each block in the flowcharts and / or block diagrams, and the combination of the blocks in the flowcharts and / or block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus, to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing apparatus enable the implementation of the functions / actions specified in one or more blocks of the flowcharts and / or block diagrams. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field programmable logic circuit. It should also be understood that each block in the block diagrams and / or flowcharts, and the combination of the blocks in the block diagrams and / or flowcharts, can also be implemented by special hardware that performs the specified functions or actions, or can be implemented by a combination of special hardware and computer instructions.

[0125] The above is only a specific implementation of the present application, and those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described systems, modules and units can refer to the corresponding processes in the foregoing method embodiments, which will not be described here. It should be understood that the protection scope of the present application is not limited thereto, and any person skilled in the art can easily think of various equivalent modifications or replacements within the technical range disclosed in the present application, and these modifications or replacements should be covered within the protection scope of the present application.

Claims

1. A data transmission method, characterized by, The method comprises: receiving a first service message; encrypting the first service message by using a post-quantum encryption algorithm and a non-post-quantum encryption algorithm to obtain a second service message; sending the second service message to a receiver through a specified channel, so that the receiver decrypts the second service message by using a post-quantum decryption algorithm corresponding to the post-quantum encryption algorithm and a non-post-quantum decryption algorithm corresponding to the non-post-quantum encryption algorithm, to obtain the first service message.

2. The method of claim 1, wherein, The post-quantum encryption algorithm comprises a post-quantum public key of the receiver and a post-quantum private key of a sender; and the non-post-quantum encryption algorithm comprises a public key encryption algorithm and / or a digital signature algorithm. The method of encrypting the first service message by using the post-quantum encryption algorithm and the non-post-quantum encryption algorithm to obtain the second service message comprises: encrypting the first service message by using the post-quantum public key, and digitally signing the encrypted first service message by using the post-quantum private key to obtain a first signature message; encrypting the first signature message by using the public key encryption algorithm and / or the digital signature algorithm to obtain the second service message.

3. The method of claim 2, wherein, After the step of digitally signing the encrypted first service message by using the post-quantum private key to obtain the first signature message, the method further comprises: determining whether the length of the first signature message is greater than a first reference length, the first reference length being a maximum message length of a single message allowed by the public key encryption algorithm and / or the digital signature algorithm; in a case where it is determined that the length of the first signature message is greater than the first reference length, splitting the first signature message to obtain at least two first split messages, each of the first split messages having a length less than or equal to the first reference length; The method of encrypting the first signature message by using the public key encryption algorithm and / or the digital signature algorithm to obtain the second service message comprises: encrypting each of the first split messages by using the public key encryption algorithm and / or the digital signature algorithm to obtain a second service message corresponding to each of the first split messages.

4. The method of claim 1, wherein, The post-quantum encryption algorithm comprises a post-quantum public key of the receiver and a post-quantum private key of a sender; and the non-post-quantum encryption algorithm comprises a public key encryption algorithm and / or a digital signature algorithm. The method of encrypting the first service message by using the post-quantum encryption algorithm and the non-post-quantum encryption algorithm to obtain the second service message comprises: encrypting the first service message by using the public key encryption algorithm and / or the digital signature algorithm to obtain a first encrypted message; encrypting the first encrypted service message by using the post-quantum public key, and digitally signing the encrypted first encrypted message by using the post-quantum private key to obtain the second service message.

5. The method according to any one of claims 1 to 4, characterized in that, The method of sending the second service message to the receiver through the specified channel comprises: in a case where the length of the second service message is greater than a second reference length, splitting the second service message to obtain at least two second split messages, the second reference length being a maximum message length of a single message allowed to be input by the specified channel; The second split message is sent to the receiving party through the designated channel.

6. The method according to any one of claims 1 to 4, characterized in that, Before receiving the first service message, the method further comprises: Receiving the post-quantum public key sent by the sender, and sending the post-quantum public key of the sender to the receiving party.

7. A data transmission apparatus, characterized by comprising: Comprise: A receiving module for receiving a first service message; An encryption module for encrypting the first service message using a post-quantum encryption algorithm and a non-post-quantum encryption algorithm to obtain a second service message; A sending module for sending the second service message to a receiving party through a designated channel, so that the receiving party uses a post-quantum decryption algorithm corresponding to the post-quantum encryption algorithm and a non-post-quantum decryption algorithm corresponding to the non-post-quantum encryption algorithm to decrypt the second service message to obtain the first service message.

8. An electronic device, comprising: Comprise: a processor, and a memory storing computer program instructions; the processor reads and executes the computer program instructions to realize the method of any one of claims 1-6.

9. A readable storage medium, characterized by, The program or instruction stored on the readable storage medium is executed by the processor to realize the method of any one of claims 1-6.

10. A computer program product, characterised in that, Comprise a computer program, which is executed by the processor to realize the method of any one of claims 1-6.

Citation Information

Patent Citations

  • Post-quantum security enhancement digital envelope method, device and system

    CN112118098A

  • Certificate-based security using post-quantum cryptography

    CN116491098A

  • Signature encryption method, system and equipment

    CN118101213A

  • Data transmission method, device, equipment, medium and product

    CN118677657A

  • Method and system for creating a quantum secured encryption key

    US20220321333A1