Data processing method and apparatus, electronic device, and storage medium
Patent Information
- Application Number
- PCT/CN2026/084833
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-03-26
- Filing Date
- 2026-03-20
- Publication Date
- 2026-10-01
Smart Images

Figure CN2026084833_01102026_PF_FP_ABST
Abstract
Description
Data processing methods, apparatus, electronic devices and storage media
[0001] Cross-reference to related applications
[0002] This application claims priority to Chinese Patent Application No. 202510367985.X, filed on March 26, 2025, the entire contents of which are incorporated herein by reference. Technical Field
[0003] This application belongs to the field of communication technology, and specifically relates to a data processing method, apparatus, electronic device and storage medium. Background Technology
[0004] With the continuous development of electronic devices, making voice calls using electronic devices has become increasingly common. Currently, users can make voice calls using electronic devices such as mobile phones through carrier networks.
[0005] During a call, issues such as unclear voice quality and dropped calls may occur due to poor signal quality. Therefore, when both parties' electronic devices are simultaneously connected to a data network, they can establish a data link through a server. The sending device can then encrypt the voice data using the encryption key from the key pair allocated by the server, and then transmit the encrypted voice data redundantly via the data link. Upon receiving the encrypted voice data, the receiving device can decrypt it using the decryption key from the key pair allocated by the server, thus enabling the voice call between the two parties.
[0006] However, since the server stores the decryption key, if the server is attacked or the decryption key is intercepted by an attacker during its transmission, the attacker may obtain the decryption key and use it to decrypt the encrypted voice data, thereby obtaining the user's voice data and causing voice data leakage. Summary of the Invention
[0007] The purpose of this application is to provide a data processing method, apparatus, electronic device, and storage medium that can improve the security of voice data during a call.
[0008] In a first aspect, embodiments of this application provide a data processing method, executed by a first electronic device, the method comprising:
[0009] During a voice call with the second electronic device, the first electronic device receives first encrypted data forwarded by the server through the first link. The first encrypted data is generated by the second electronic device encrypting the voice data with the first key. The first link is a data link established by the first electronic device and the second electronic device through the server.
[0010] The first electronic device obtains voice data based on the second key and the first encrypted data in the first electronic device;
[0011] Wherein, the second key is generated by the first electronic device; or, the second key is generated by the second electronic device; in the case where the second key is generated by the second electronic device, the second key is sent by the second electronic device to the first electronic device through the second link, and the second link is a communication link between the first electronic device and the second electronic device.
[0012] Secondly, embodiments of this application provide a data processing method, executed by a second electronic device, the method comprising:
[0013] During a voice call with the first electronic device, the second electronic device sends the identification information of the first electronic device to the server;
[0014] The second electronic device receives a first key sent by the server based on the identification information of the first electronic device and a first association relationship, wherein the first association relationship is the association relationship between the identification information of the first electronic device and the first key;
[0015] The second electronic device uses the first key to encrypt the voice data, generating the first encrypted data;
[0016] The second electronic device sends the first encrypted data to the server through the first link, which is a data link established between the first electronic device and the second electronic device through the server.
[0017] Thirdly, embodiments of this application provide a data processing method, executed by a second electronic device, the method comprising:
[0018] During a voice call with the first electronic device, the second electronic device sends the identification information of the first electronic device to the server;
[0019] The second electronic device receives a third key sent by the server based on the identification information of the first electronic device and a second association relationship. The second association relationship is the association relationship between the identification information of the first electronic device and the third key.
[0020] The second electronic device uses a third key to encrypt the first key, generating second encrypted data;
[0021] The second electronic device transmits the second encrypted data to the first electronic device through the second link, which is a communication link between the first and second electronic devices.
[0022] Fourthly, embodiments of this application provide a data processing apparatus, the apparatus comprising:
[0023] The transceiver module is used to receive first encrypted data forwarded by the server through the first link during a voice call with the second electronic device. The first encrypted data is generated by the second electronic device encrypting the voice data with the first key. The first link is a data link established by the first electronic device and the second electronic device through the server.
[0024] The processing module is used to obtain voice data based on the second key in the first electronic device and the first encrypted data received by the transceiver module;
[0025] Wherein, the second key is generated by the first electronic device; or, the second key is generated by the second electronic device; in the case where the second key is generated by the second electronic device, the second key is sent by the second electronic device to the first electronic device through the second link, and the second link is a communication link between the first electronic device and the second electronic device.
[0026] Fifthly, embodiments of this application provide a data processing apparatus, the apparatus comprising:
[0027] The sending module is used to send the identification information of the first electronic device to the server during a voice call with the first electronic device;
[0028] The receiving module is used to receive the first key sent by the server based on the identification information of the first electronic device and the first association relationship sent by the sending module, wherein the first association relationship is the association relationship between the identification information of the first electronic device and the first key;
[0029] The processing module is used to encrypt the voice data using the first key received by the receiving module, and generate the first encrypted data;
[0030] The sending module is also used to send the first encrypted data generated by the processing module to the server through the first link, whereby the first electronic device and the second electronic device establish a data link through the server.
[0031] Sixthly, embodiments of this application provide a data processing apparatus, the apparatus comprising:
[0032] The sending module is used to send the identification information of the first electronic device to the server during a voice call with the first electronic device;
[0033] The receiving module is used to receive the third key sent by the server based on the identification information of the first electronic device and the second association relationship sent by the sending module. The second association relationship is the association relationship between the identification information of the first electronic device and the third key.
[0034] The processing module is used to encrypt the first key with the third key to generate the second encrypted data;
[0035] The sending module is also used to transmit the second encrypted data generated by the processing module to the first electronic device via the second link, which is a communication link between the first electronic device and the second electronic device.
[0036] In a seventh aspect, embodiments of this application provide an electronic device including a processor and a memory, the memory storing a program or instructions executable on the processor, the program or instructions, when executed by the processor, implementing the steps of the data processing method as described in the first aspect, or the steps of the data processing method as described in the second aspect, or the steps of the data processing method as described in the second aspect.
[0037] Eighthly, embodiments of this application provide a readable storage medium storing a program or instructions that, when executed by a processor, implement the steps of the data processing method as described in the first aspect, or the steps of the data processing method as described in the second aspect, or the steps of the data processing method as described in the second aspect.
[0038] Ninthly, embodiments of this application provide a chip, the chip including a processor and a communication interface, the communication interface being coupled to the processor, the processor being used to run a program or instructions to implement the steps of the data processing method as described in the first aspect, or the steps of the data processing method as described in the second aspect, or the steps of the data processing method as described in the second aspect.
[0039] In a tenth aspect, embodiments of this application provide a computer program product stored in a storage medium, which is executed by at least one processor to implement the data processing method as described in the first aspect, or the data processing method as described in the second aspect, or the data processing method as described in the second aspect.
[0040] In this embodiment, during a voice call with a second electronic device, the first electronic device receives first encrypted data forwarded by the server through a first link. This first encrypted data is generated by the second electronic device encrypting voice data using a first key. The first link is a data link established between the first and second electronic devices through the server. The first electronic device obtains voice data based on a second key and the first encrypted data. The second key is generated by the first electronic device; or, the second key is generated by the second electronic device. If the second key is generated by the second electronic device, it is sent to the first electronic device via a second link, which is the communication link between the first and second electronic devices. Thus, since the second key is generated by the first electronic device, or sent to the first electronic device via the second link, even if the server is attacked, the attacker cannot obtain the second key, nor can they decrypt the first encrypted data to obtain the voice data based on the second key, thereby improving the security of voice data during the voice call. Attached Figure Description
[0041] Figure 1 is a flowchart illustrating a data processing method provided in some embodiments of this application;
[0042] Figure 2 is a flowchart illustrating a data processing method provided in some embodiments of this application;
[0043] Figure 3 is a flowchart illustrating a data processing method provided in some embodiments of this application;
[0044] Figure 4 is a flowchart illustrating a data processing method provided in some embodiments of this application;
[0045] Figure 5 is a flowchart illustrating a data processing method provided in some embodiments of this application;
[0046] Figure 6 is a flowchart illustrating a data processing method provided in some embodiments of this application;
[0047] Figure 7 is a flowchart illustrating a data processing method provided in some embodiments of this application;
[0048] Figure 8 is a flowchart illustrating a data processing method provided in some embodiments of this application;
[0049] Figure 9 is a flowchart illustrating a data processing method provided in some embodiments of this application;
[0050] Figure 10 is a schematic diagram of a data processing method provided in some embodiments of this application;
[0051] Figure 11 is a flowchart illustrating a data processing method provided in some embodiments of this application;
[0052] Figure 12 is a schematic diagram of a data processing method provided in some embodiments of this application;
[0053] Figure 13 is a flowchart illustrating a data processing method provided in some embodiments of this application;
[0054] Figure 14 is a schematic diagram of a data processing method provided in some embodiments of this application;
[0055] Figure 15 is a schematic diagram of the structure of a data processing apparatus provided in some embodiments of this application;
[0056] Figure 16 is a schematic diagram of the structure of a data processing apparatus provided in some embodiments of this application;
[0057] Figure 17 is a schematic diagram of the structure of a data processing apparatus provided in some embodiments of this application;
[0058] Figure 18 is a schematic diagram of the structure of an electronic device provided in some embodiments of this application;
[0059] Figure 19 is a schematic diagram of the hardware structure of an electronic device provided in some embodiments of this application. Detailed Implementation
[0060] The technical solutions of the embodiments of this application will be clearly described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application are within the scope of protection of this application.
[0061] The terms "first," "second," etc., used in the specification and claims of this application are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such use of data can be interchanged where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first," "second," etc., are generally of the same class and the number of objects is not limited; for example, a first object can be one or more. Furthermore, in the specification and claims, "and / or" indicates at least one of the connected objects, and the character " / " generally indicates that the preceding and following objects are in an "or" relationship.
[0062] The terms "at least one," "at least one of," etc., used in the specification and claims of this application refer to any one, any two, or a combination of two or more of the included items. For example, at least one of a, b, and c can mean: "a," "b," "c," "a and b," "a and c," "b and c," and "a, b, and c," where a, b, and c can be single or multiple. Similarly, "at least two" refers to two or more items, and its meaning is similar to that of "at least one."
[0063] Key: A tool used to encrypt and decrypt data. Based on whether the encryption and decryption keys used by a cryptographic algorithm are the same, and whether the decryption process can be derived from the encryption process, keys can be divided into symmetric keys and asymmetric keys.
[0064] Identifiers: are text, symbols, images, etc. used to indicate information. They can be displayed in the form of controls or other containers, including but not limited to text identifiers, symbol identifiers, and image identifiers.
[0065] The data processing method, apparatus, electronic device, and storage medium provided in this application will be described in detail below with reference to the accompanying drawings and through specific embodiments and application scenarios.
[0066] The data processing method provided in this application can be applied to voice call scenarios. For example, in scenario 1, where two users are making a phone call, the voice data of both parties needs to be encrypted during transmission to improve the security of their voice data. In scenario 2, where two users are making a voice call through an instant messaging program, the voice data of both parties needs to be encrypted during transmission to improve the security of their voice data. In scenario 3, where two users are making a video call through an instant messaging program, the voice data of both parties needs to be encrypted during transmission to improve the security of their voice data.
[0067] The data processing method provided in this application can be executed by a data processing device. Exemplarily, the data processing device can be an electronic device, or a functional component or entity within that electronic device. The following will use an electronic device as an example to illustrate the data processing device provided in this application.
[0068] Figure 1 is a flowchart illustrating the data processing method provided in an embodiment of this application. As shown in Figure 1, the data processing method provided in an embodiment of this application may include the following steps 101 and 102.
[0069] Step 101: During a voice call with the second electronic device, the first electronic device receives the first encrypted data forwarded by the server through the first link.
[0070] In some embodiments of this application, the first encrypted data is generated by the second electronic device encrypting the voice data using the first key, and the first link is a data link established between the first electronic device and the second electronic device through the server.
[0071] For example, in a scenario where user A and user B are making a phone call, user A's phone can forward the first encrypted data through the data link established by user A's phone and user B's phone via the server.
[0072] For example, in a scenario where user A and user B are having a voice call through an instant messaging program, user A's electronic device can forward the first encrypted data through the data link established by user A's electronic device and user B's electronic device via the server.
[0073] For example, in a scenario where user A and user B are having a video call through an instant messaging program, user B's electronic device can forward the first encrypted data through the data link established by user A's electronic device and user B's electronic device via the server.
[0074] In some embodiments of this application, the aforementioned voice data may be voice data generated by the first electronic device after extracting audio features from the user's spoken voice recorded by a microphone and encoding the speech spectrum.
[0075] For example, in a scenario where user A and user B are making a phone call, if user A says "hello", then the above voice data can be voice data generated by extracting audio features and encoding the speech spectrum of user A's voice "hello" recorded by the microphone on user A's phone.
[0076] For example, in a scenario where user A and user B are having a voice call through an instant messaging program, if user A says "How are you lately?", then the aforementioned voice data can be voice data generated by encoding the audio features and speech spectrum of the user's voice "How are you lately?" recorded by the microphone on user A's electronic device.
[0077] For example, in a scenario where user A and user B are having a video call through an instant messaging program, and user B says "goodbye," the aforementioned voice data can be voice data generated by user B's electronic device after performing audio feature and speech spectrum encoding on the user's voice "goodbye" recorded by the microphone.
[0078] In some embodiments of this application, the first key mentioned above is an encryption key.
[0079] In some embodiments of this application, the first key may include information such as the first key type, the first algorithm identifier, the first key data, the first key purpose, the first key length, and the first validity period. The specific details can be determined according to actual needs, and this embodiment does not impose specific limitations here.
[0080] In some embodiments of this application, the first key type can be a symmetric key or a public key in an asymmetric key.
[0081] In some embodiments of this application, when the first key type is a symmetric key, the first algorithm identifier can be the algorithm identifier of a symmetric encryption algorithm, such as the algorithm identifier of the Advanced Encryption Standard (AES) algorithm or the algorithm identifier of the Data Encryption Standard (DES) algorithm.
[0082] In some embodiments of this application, when the first key type is a symmetric key, the first algorithm identifier can be the algorithm identifier of an asymmetric encryption algorithm, such as the algorithm identifier of the asymmetric encryption algorithm RSA or the algorithm identifier of Elliptic Curve Cryptography (ECC).
[0083] In some embodiments of this application, when the first key type is a symmetric key, the first key data can be the key value of the symmetric key.
[0084] In some embodiments of this application, when the first key type is a public key in an asymmetric key, the first key data can be the modulus of the asymmetric key and the exponent of the public key in the asymmetric key.
[0085] In some embodiments of this application, the modulus of the aforementioned asymmetric key can be the product of two prime numbers.
[0086] For example, the modulus of the aforementioned asymmetric key can be the product of 5 and 7, which is 35.
[0087] For example, the modulus of the aforementioned asymmetric key can be the product of 3 and 11, which is 33.
[0088] In some embodiments of this application, the exponent of the public key in the asymmetric key can be a small integer that is coprime to the modulus of the aforementioned asymmetric key.
[0089] For example, if the modulus of the asymmetric key is 35, then the exponent of the public key in the asymmetric key can be 34.
[0090] For example, if the modulus of the asymmetric key is 33, then the exponent of the public key in the asymmetric key can be 37.
[0091] In some embodiments of this application, the first key is used to indicate that the first encryption key is used to encrypt data.
[0092] In some embodiments of this application, when the first key type is a symmetric key, the first key length can be the key length of a symmetric key. For example, the first key length can be the key length 256 of an AES-256 key.
[0093] In some embodiments of this application, when the first key type is a public key in an asymmetric key, the first key length can be the key length of the public key. For example, the first key length can be the key length of the private key in an RSA key, which is 2048 or 4096.
[0094] For example, the first key may include the public key in the first key type symmetric key, the key value of the AES algorithm, the algorithm identifier of the AES algorithm, the key length of 256, the purpose of the key to encrypt data, and the key validity period of 36 hours.
[0095] For example, the first key may include the public key in the first key type asymmetric key, the modulus of the asymmetric key is 35, the exponent of the public key in the asymmetric key is 34, the algorithm identifier of the RSA algorithm, the key length is 2048, the key is used to encrypt data, and the key validity period is 24 hours.
[0096] In some embodiments of this application, the aforementioned first validity period is used to indicate the validity period of the aforementioned first key. After the aforementioned first validity period expires, the electronic device that generated the aforementioned first key needs to update the aforementioned first key.
[0097] In some embodiments of this application, the first electronic device and the second electronic device can be terminals of two users who need to make a voice call, and the two users can use the first electronic device and the second electronic device to make a voice call.
[0098] In some embodiments of this application, the server may be a backend server for the first application. When the first application is running simultaneously on both the first electronic device and the second electronic device, the first electronic device may receive the first encrypted data forwarded by the backend server via the first data link.
[0099] In some embodiments of this application, the first encrypted data may be encrypted voice data obtained by encrypting the voice data using the first key.
[0100] For example, the first encrypted data mentioned above can be encrypted voice data generated after encrypting the voice data using the key value of the symmetric key and the AES algorithm mentioned above.
[0101] For example, the first encrypted data mentioned above can be encrypted voice data generated after encrypting the voice data using the modulus, exponent, and ECC algorithm of the asymmetric key mentioned above.
[0102] In some embodiments of this application, the first application mentioned above may include, but is not limited to, any of the following: navigation applications, social networking applications, shopping applications, video applications, photo album applications, music applications, etc. The specific application can be determined based on actual usage needs, and this application embodiment does not impose any limitations.
[0103] Step 102: The first electronic device obtains voice data based on the second key and the first encrypted data in the first electronic device.
[0104] In some embodiments of this application, the second key is generated by the first electronic device; or, the second key is generated by the second electronic device.
[0105] In some embodiments of this application, when the second key is generated by the second electronic device, the second key is sent by the second electronic device to the first electronic device through a second link, and the second link is a communication link between the first electronic device and the second electronic device.
[0106] In some embodiments of this application, when the first key and the second key are symmetric keys, or when the first key and the second key are respectively the public key and private key of a key pair, the second key is the decryption key, and the first electronic device can use the second key to decrypt the first encrypted data to obtain the voice data.
[0107] In some embodiments of this application, the second key may include information such as the second key type, second algorithm identifier, second key data, second key purpose, second key length, and second validity period. The specific details can be determined according to actual needs, and this embodiment does not impose specific limitations here.
[0108] In some embodiments of this application, when the first key and the second key are symmetric keys, the key information contained in the second key, excluding the purpose of the second key, is similar to the key information contained in the first key, excluding the purpose of the first key. To avoid overlap, this embodiment will not repeat the details here.
[0109] In some embodiments of this application, the second key type described above can be a symmetric key or an asymmetric key.
[0110] In some embodiments of this application, when the second key type is a public key in an asymmetric key, the second key data can be the modulus and exponent of the asymmetric key.
[0111] In some embodiments of this application, the modulus of the aforementioned asymmetric key can be the product of two prime numbers.
[0112] For example, the modulus of the aforementioned asymmetric key can be the product of 5 and 7, which is 35.
[0113] For example, the modulus of the aforementioned asymmetric key can be the product of 3 and 11, which is 33.
[0114] In some embodiments of this application, when the second key type is a public key in an asymmetric key, the exponent of the asymmetric key can be a small integer coprime to the modulus of the asymmetric key.
[0115] For example, in the case where the second key type is a public key in an asymmetric key, the exponent of the asymmetric key can be 34.
[0116] For example, in the case where the second key type is a public key in an asymmetric key, the exponent of the asymmetric key can be 37.
[0117] In some embodiments of this application, when the second key type is a private key in an asymmetric key, the second key data can be the modulus of the asymmetric key or the exponent of the private key in the asymmetric key.
[0118] In some embodiments of this application, the private key index in the aforementioned asymmetric key can be calculated from the public key index and the modulus of the aforementioned asymmetric key through specific mathematical operations.
[0119] For example, if the modulus of the asymmetric key is 35, and the exponent of the public key in the asymmetric key is 34, then the exponent of the private key in the asymmetric key can be the sum of the modulus 35 of the asymmetric key and the exponent 34 of the public key in the asymmetric key, which is 69.
[0120] For example, if the modulus of the asymmetric key is 33, and the exponent of the public key in the asymmetric key is 37, then the exponent of the private key in the asymmetric key can be the product of the modulus of the asymmetric key (35) and the exponent of the public key (34), which is 1190.
[0121] In some embodiments of this application, when the second key type is a public key in an asymmetric key, the purpose of the second key can be used to instruct the second encryption key to be used to encrypt data.
[0122] In some embodiments of this application, when the second key type is a public key in an asymmetric key, the purpose of the second key can be used to instruct the second encryption key to decrypt data.
[0123] In some embodiments of this application, when the second key type is a symmetric key, the second key length can be the key length of a symmetric key. For example, the second key length can be the key length 256 of an AES-256 key.
[0124] In some embodiments of this application, when the second key type is an asymmetric key, the second key length can be the key length of an asymmetric key. For example, the second key length can be the key length of an RSA key, 2048 or 4096.
[0125] For example, the second key mentioned above may include the public key in the second key type symmetric key, the key value of the AES algorithm, the algorithm identifier of the AES algorithm, the key length of 256, the purpose of the key to encrypt data, and the key validity period of 36 hours.
[0126] For example, the second key mentioned above may include the public key in the second key type asymmetric key, the modulus of the asymmetric key is 35, the exponent of the public key in the asymmetric key is 34, the algorithm identifier of the RSA algorithm, the key length is 2048, the key is used to encrypt data, and the key validity period is 24 hours.
[0127] For example, the second key may include the private key in the second key type asymmetric key, the modulus of the asymmetric key is 35, the exponent of the private key in the asymmetric key is 69, the algorithm identifier of the RSA algorithm, the key length is 2048, the key purpose is decryption data, and the key validity period is 24 hours.
[0128] In the data processing method provided in this application embodiment, during a voice call with a second electronic device, the first electronic device receives first encrypted data forwarded by the server through a first link. The first encrypted data is generated by the second electronic device encrypting voice data using a first key. The first link is a data link established between the first and second electronic devices through the server. The first electronic device obtains voice data based on a second key and the first encrypted data. The second key is generated by the first electronic device; or, the second key is generated by the second electronic device. If the second key is generated by the second electronic device, it is sent to the first electronic device by the second electronic device through a second link, which is the call link between the first and second electronic devices. Thus, since the second key is generated by the first electronic device, or sent to the first electronic device by the second electronic device through a second link, even if the server is attacked, the attacker cannot obtain the second key, nor can they decrypt the first encrypted data to obtain the voice data based on the second key, thereby improving the security of voice data during the voice call. Furthermore, using the solution of this application, there is no need for the server to transmit the second key to the first electronic device, thus effectively avoiding the problem of the server being hijacked by an attacker during the transmission of the second key to the first electronic device, further improving the security of voice data during the voice call.
[0129] In some embodiments of this application, where the first key and the second key are generated by the second electronic device, as shown in FIG1 and FIG2, prior to step 101, the data processing method provided in this application embodiment may further include the following steps 103a and 103b:
[0130] Step 103a: The first electronic device receives the second key sent by the second electronic device through the second link.
[0131] In some embodiments of this application, the first electronic device can receive the second key sent by the second electronic device through the second link when the first electronic device and the second electronic device establish a call connection.
[0132] In some embodiments of this application, the second link described above can be a telephone link such as Voice over Long-Term Evolution (VoLTE), Voice over New Radio (VoNR), or Voice over Wi-Fi (VoWiFi).
[0133] Step 103b: The first electronic device stores the second key in the key storage area of the first electronic device.
[0134] In some embodiments of this application, the key storage area may be a protected area of the first electronic device or a built-in hardware area of the first electronic device to prevent the second key from being tampered with or illegally read.
[0135] In some embodiments of this application, the first electronic device can receive the identification information of the second electronic device at the same time as receiving the second key sent by the second electronic device through the second link, and store the identification information of the second electronic device and the second key in a storage unit of the key storage area.
[0136] In some embodiments of this application, the identification information of the second electronic device can be the device identifier of the second electronic device, such as the Temporary Mobile Subscriber Identity (TMSI) or International Mobile Equipment Identity (IMEI) of the second electronic device. The specific identifier can be determined according to actual needs, and no specific limitation is made here in this embodiment.
[0137] In this way, the first electronic device receives the second key sent by the second electronic device through the second link, and the first electronic device stores the second key in the key storage area of the first electronic device. The server does not need to transmit the second key to the first electronic device, which can effectively avoid the problem of the second key being intercepted by attackers during the transmission of the second key from the server to the second electronic device, thereby improving the security of voice data during voice calls.
[0138] In some embodiments of this application, the first key and the second key are symmetric keys or asymmetric keys; when the first key and the second key are asymmetric keys, the first key and the second key are respectively the public key and the private key of the asymmetric key; referring to Figure 2, as shown in Figure 3, the above step 102 can be implemented by the following step 102a:
[0139] Step 102a: The first electronic device uses the second key stored in the first electronic device to decrypt the first encrypted data to obtain voice data.
[0140] In some embodiments of this application, while receiving the first encrypted data forwarded by the server through the first link, the first electronic device can also receive the identification information of the second electronic device forwarded by the server through the first link. Based on the identification information of the second electronic device, the first electronic device determines the first storage unit in the key storage area where the identification information of the second electronic device and the second key are located. The second key is then obtained from the first storage unit, and the first encrypted data is decrypted using the second key to obtain the voice data.
[0141] It should be noted that after the first electronic device obtains the above-mentioned voice data, it can perform voice spectrum decoding and vocoder encoding on the above-mentioned voice data to recover the user's voice from the above-mentioned voice data, and then play the user's voice through a speaker.
[0142] In this way, the electronic device can directly use the second key stored in the first electronic device to decrypt the first encrypted data and obtain the voice data. The first electronic device can also use the second key to decrypt the first encrypted data without the server transmitting the second key to the first electronic device. This effectively avoids the problem of the second key being intercepted by attackers during the transmission of the second key from the server to the second electronic device, thereby improving the security of voice data during voice calls.
[0143] In some embodiments of this application, where the first key and the second key are generated by the first electronic device, the data processing method provided in this application may further include the following steps 104a and 104b before step 101, and step 102 may be implemented through step 102b:
[0144] Step 104a: The first electronic device generates the first key pair.
[0145] In some embodiments of this application, the first key pair may include the first key and the second key, wherein the first key and the second key are a public key and a private key, respectively.
[0146] In some embodiments of this application, the first key pair can be an asymmetric key, and the first key and the second key are respectively the public key and the private key in the asymmetric key.
[0147] In some embodiments of this application, the first electronic device may generate the first key pair based on the first identification information and the first key generation algorithm.
[0148] In some embodiments of this application, the first identification information mentioned above includes at least one of the following:
[0149] The identification information of the second electronic device, the identification information of the first electronic device, the identification information agreed upon in advance by the first and second electronic devices for call marking, the identification information temporarily assigned by the server to both the first and second electronic devices, and the identification information of the first user, wherein the first user includes at least one of the users of the first electronic device and the users of the second electronic device.
[0150] In some embodiments of this application, the identification information of the first electronic device can be the device identifier of the first electronic device, such as the TMSI or IMEI of the first electronic device. The specific identification information can be determined according to actual needs, and no specific limitation is made here.
[0151] For example, the TMSI of the first electronic device can be 0x1A2B3C4D, and the IMEI of the first electronic device can be 490154203237518.
[0152] For example, the TMSI of the first electronic device can be 0x1D2C3B4A, and the IMEI of the first electronic device can be 370154163236827.
[0153] Step 104b: The first electronic device sends its identification information and first key to the server through the second link, so that the server establishes a first association between the identification information and the first key of the first electronic device.
[0154] In some embodiments of this application, after the first electronic device generates the first key pair, it can store the first key pair in the key storage area and then send the identification information of the first electronic device and the first key to the server through the second link.
[0155] In some embodiments of this application, after receiving the identification information of the first electronic device and the first key, the server can establish a first association relationship between the identification information of the first electronic device and the first key.
[0156] Step 102b: The first electronic device uses the second key to decrypt the first encrypted data to obtain voice data.
[0157] In some embodiments of this application, after receiving the first encrypted data forwarded by the server through the first link, the first electronic device can obtain the second key from the key storage area, and then use the second key to decrypt the first encrypted data to obtain the voice data.
[0158] In this way, after the first electronic device generates the first key pair, it only needs to send the identification information of the first electronic device and the public key in the first key pair to the server through the second link. Therefore, even if an attacker attacks the server, they cannot obtain the private key in the asymmetric key, nor can they decrypt the first encrypted data to obtain the voice data, thereby improving the security of voice data during voice calls.
[0159] In some embodiments of this application, where the first key is generated by the second electronic device and the second key is generated by the first electronic device, the data processing method provided in this application embodiment may further include the following step 105 before step 101, and step 102 may be implemented by the following steps 102c1 and 102c2:
[0160] Step 105: The first electronic device receives the second encrypted data sent by the second electronic device through the second link.
[0161] In some embodiments of this application, the second encrypted data is generated by the second electronic device encrypting the first key with a third key, and the third key and the second key are respectively the public key and private key in the second key pair pre-stored by the first electronic device.
[0162] In some embodiments of this application, the second key pair may be an asymmetric key pair, and the third key and the second key are respectively the public key and private key of the asymmetric key pair.
[0163] In some embodiments of this application, where the third key and the second key are respectively the public key and the private key in the second key pair, the third key can be an encryption key and the second key can be a decryption key.
[0164] In some embodiments of this application, the third key may include information such as the third key type, third algorithm identifier, third key data, third key purpose, third key length, and third validity period. The specific details can be determined according to actual needs, and this embodiment does not impose specific limitations here.
[0165] In some embodiments of this application, where the third key and the second key are respectively the public key and the private key in the second key pair, the third key type can be the private key in an asymmetric key.
[0166] In some embodiments of this application, where the third key and the second key are respectively the public key and the private key in the second key pair, the third key data can be the modulus, exponent, and other parameters of the asymmetric key.
[0167] In some embodiments of this application, where the third key and the second key are respectively the public key and the private key in the second key pair, the purpose of the third key is to instruct the third encryption key to be used to decrypt data.
[0168] In some embodiments of this application, when the third key and the second key are respectively the public key and the private key in the second key pair, the length of the second key can be the key length of the private key. For example, the length of the second key can be the key length of the private key in the RSA key, which is 2048 or 4096.
[0169] In some embodiments of this application, where the third key and the second key are respectively the public key and the private key in the second key pair, the second key type can be the public key in an asymmetric key.
[0170] In some embodiments of this application, where the third key and the second key are respectively the public key and the private key in the second key pair, the second key data can be the modulus and exponent of an asymmetric key.
[0171] In some embodiments of this application, where the third key and the second key are respectively the public key and the private key in the second key pair, the purpose of the second key is to instruct the second encryption key to be used to encrypt data.
[0172] In some embodiments of this application, where the third key and the second key are respectively the public key and the private key in the second key pair, the purpose of the third key is to instruct the third encryption key to be used to decrypt data.
[0173] In some embodiments of this application, when the third key and the second key are respectively the public key and private key of the second key pair, and when the second key type is the public key in an asymmetric key, the length of the second key can be the key length of the public key. For example, the length of the second key can be the key length of the public key in an RSA key, which is 2048 or 4096.
[0174] In some embodiments of this application, when the third key and the second key are respectively the public key and the private key in the second key pair, the third algorithm identifier can be the algorithm identifier of an asymmetric encryption algorithm, such as the algorithm identifier of the RSA algorithm or the algorithm identifier of the ECC algorithm.
[0175] For example, the aforementioned third key may include the public key in the third key type symmetric key, the key value of the symmetric key, the algorithm identifier of the AES algorithm, the key length of 256, the key purpose of decryption data, and the key validity period of 36 hours.
[0176] For example, the aforementioned third key may include the public key in the third key type asymmetric key, the modulus of the asymmetric key is 35, the exponent of the public key in the asymmetric key is 34, the algorithm identifier of the RSA algorithm, the key length is 2048, the key is used to encrypt data, and the key validity period is 24 hours.
[0177] In some embodiments of this application, the second encrypted data may be encrypted data obtained by the second electronic device encrypting the first key using the third key.
[0178] For example, when the key type of the third key is a private key in an asymmetric key, the third key data is the modulus, exponent and other parameters of the asymmetric key, and the asymmetric encryption algorithm indicated by the third encryption algorithm is the ECC algorithm, the second encrypted data can be encrypted data generated by encrypting the first key using the modulus, exponent and other parameters of the asymmetric key and the ECC algorithm.
[0179] For example, when the key type of the third key is a private key in an asymmetric key, the third key data is the modulus, exponent and other parameters of the asymmetric key, and the asymmetric encryption algorithm indicated by the third encryption algorithm is the RSA algorithm, the second encrypted data can be encrypted data generated by encrypting the first key using the modulus, exponent and other parameters of the asymmetric key and the RSA algorithm.
[0180] Step 102c1: The first electronic device uses the second key to decrypt the second encrypted data to obtain the first key.
[0181] In some embodiments of this application, the first electronic device may use the asymmetric encryption algorithm indicated by the second algorithm identifier and the modulus, exponent and other parameters of the asymmetric key in the second key data to decrypt the first key.
[0182] Step 102c2: The first electronic device uses the first key to decrypt the first encrypted data to obtain voice data.
[0183] In some embodiments of this application, the first key is a symmetric key, and the first encrypted data is generated using a symmetric encryption algorithm pre-agreed upon by the first key, the first electronic device, and the second electronic device.
[0184] In some embodiments of this application, when the key type of the first key is a symmetric key, the first key can be used to encrypt data or to decrypt data; that is, the first key can be an encryption key or a decryption key.
[0185] In some embodiments of this application, when the first key is a symmetric key, the electronic device can use the key value of the first key and the symmetric encryption algorithm indicated by the algorithm identifier to decrypt the first encrypted data to obtain voice data. Thus, the first electronic device receives the second encrypted data sent by the second electronic device through the second link, thereby preventing the first key from being intercepted by an attacker during the transmission of the second encrypted data from the server to the first electronic device, which could lead to leakage of the first key. This effectively prevents voice data leakage caused by an attacker using the first key to decrypt the first encrypted data, thereby improving the security of voice data during voice calls.
[0186] In some embodiments of this application, prior to step 101 above, the data processing method provided in this application may further include the following steps 106a and 106b:
[0187] Step 106a: The first electronic device generates a second key pair.
[0188] In some embodiments of this application, the second key pair includes the second key and the third key, wherein the second key and the third key are a private key and a public key, respectively.
[0189] In some embodiments of this application, the first electronic device can generate the second key pair based on the first identification information and the first key generation algorithm. For an explanation of the first identification information, please refer to the relevant description in step 104a above. This embodiment will not repeat it here.
[0190] Step 106b: The first electronic device sends its identification information and third key to the server through the second link, so that the server establishes a second association between the identification information and the third key of the first electronic device.
[0191] In some embodiments of this application, after the first electronic device generates the second key pair, it can store the second key pair in the key storage area and then send the identification information of the first electronic device and the third key to the server through the second link.
[0192] In some embodiments of this application, after receiving the identification information of the first electronic device and the third key, the server can establish a second association relationship between the identification information of the first electronic device and the third key.
[0193] In this way, after the first electronic device generates the second key pair, it only needs to send the identification information of the first electronic device and the public key in the second key pair to the server through the second link. Therefore, even if an attacker attacks the server, they cannot obtain the private key in the asymmetric key, nor can they decrypt the first encrypted data to obtain the voice data, thereby improving the security of voice data during voice calls.
[0194] In some embodiments of this application, during the voice call between the first electronic device and the second electronic device, the data processing method provided in this application may further include the following step 107:
[0195] Step 107: The first electronic device receives voice data sent by the second electronic device through the second link.
[0196] In some embodiments of this application, when the second key is generated by the second electronic device, the first electronic device can simultaneously receive the voice data and the second key sent by the second electronic device through the second link. The first electronic device can also receive the voice data from the second electronic device through the second link after receiving the second key from the second electronic device, or it can receive the voice data from the second electronic device through the second link before receiving the second key from the second electronic device. This embodiment does not impose specific limitations here.
[0197] In this way, the first electronic device receives voice data from the second electronic device through the second link, which enables the voice data received from the second electronic device through the second link to be mutually redundant with the voice data corresponding to the first encrypted data, thereby increasing the success rate of voice data transmission, thus avoiding call drops and improving call quality.
[0198] Figure 4 is a flowchart illustrating the data processing method provided in the embodiments of this application. As shown in Figure 4, the data processing method provided in the embodiments of this application may include the following steps 201 to 204.
[0199] Step 201: During a voice call with the first electronic device, the second electronic device sends the identification information of the first electronic device to the server.
[0200] In some embodiments of this application, the identification information of the first electronic device is used to instruct the server to obtain the first key, which is either the public key of the asymmetric key generated by the first electronic device or a symmetric key.
[0201] In some embodiments of this application, the second electronic device can send the identification information of the first electronic device to the server via the first link.
[0202] Step 202: The second electronic device receives the first key sent by the server based on the identification information and the first association relationship of the first electronic device.
[0203] In some embodiments of this application, the first association relationship is the association relationship between the identification information of the first electronic device and the first key.
[0204] In some embodiments of this application, after receiving the identification information of the first electronic device, the server can obtain the first key based on the identification information of the first electronic device and the first association relationship, and then return the first key to the second electronic device.
[0205] In some embodiments of this application, the second electronic device may receive the second key returned by the server via the first link.
[0206] Step 203: The second electronic device uses the first key to encrypt the voice data and generate the first encrypted data.
[0207] In some embodiments of this application, when the first key is a symmetric key, the second electronic device can use the key value of the symmetric key in the first key data and the symmetric encryption algorithm indicated by the first algorithm identifier to encrypt the voice data and generate the first encrypted data.
[0208] In some embodiments of this application, when the first key is the public key in the asymmetric key, the second electronic device can use the modulus and exponent of the asymmetric key in the first key data and the asymmetric encryption algorithm indicated by the first algorithm identifier to encrypt the voice data and generate the first encrypted data.
[0209] Step 204: The second electronic device sends the first encrypted data to the server through the first link.
[0210] In some embodiments of this application, the first link is a data link established by the first electronic device and the second electronic device through the server.
[0211] In some embodiments of this application, while the second electronic device sends the first encrypted data to the server via the first link, it can also send the identification information of the first electronic device to the server via the first link, so that the server forwards the first encrypted data to the first electronic device via the first link based on the identification information of the first electronic device.
[0212] In the data processing method provided in this application embodiment, during a voice call between a second electronic device and a first electronic device, the second electronic device sends its identification information to the server; the second electronic device receives a first key sent by the server based on the identification information and a first association relationship of the first electronic device; and the second electronic device sends first encrypted data to the server through a first link. Thus, using the scheme of this application, the server only needs to send the encryption key to the second electronic device. Therefore, even if an attacker attacks the server, they cannot obtain the decryption key, nor can they decrypt the first encrypted data to obtain the voice data, thereby improving the security of voice data during a voice call.
[0213] In some embodiments of this application, after step 201 described above, the data processing method provided in this application may further include step 205, and step 203 described above may be implemented through step 203a:
[0214] Step 205: The second electronic device receives the server's verification information sent by the server based on the identification information of the first electronic device.
[0215] In some embodiments of this application, the second electronic device can receive the verification information returned by the server based on the identification information of the first electronic device through the first link.
[0216] In some embodiments of this application, the verification information may be the digital signature of the server.
[0217] It should be noted that step 205 can be executed after step 202 or simultaneously with step 202. This embodiment does not impose any specific restrictions here.
[0218] Step 203a: If the second electronic device passes the server security verification based on the verification information, the second electronic device uses the first key to encrypt the first data and generate the first encrypted data.
[0219] In some embodiments of this application, the second electronic device can perform server security verification based on the aforementioned verification information to determine whether the server has been illegally attacked. If it is confirmed that the server has not been illegally attacked, i.e., the server security verification has been passed, the second electronic device can use the aforementioned first key to encrypt the aforementioned first data, generating first encrypted data.
[0220] Thus, the second electronic device receives the server's verification information returned by the server based on the identification information of the first electronic device. When the second electronic device performs security verification on the server based on the verification information, the second electronic device uses the first key to encrypt the first data and generate the first encrypted data. This allows the first electronic device to encrypt the first data using the first key when it is determined that the server has not been attacked by an attacker, thereby improving the security of the encrypted data.
[0221] Figure 5 is a flowchart illustrating the data processing method provided in the embodiments of this application. As shown in Figure 5, the data processing method provided in the embodiments of this application may include the following steps 301 to 304.
[0222] Step 301: During a voice call with the first electronic device, the second electronic device sends the identification information of the first electronic device to the server.
[0223] In some embodiments of this application, the identification information of the first electronic device is used to instruct the server to obtain a third key, which is the public key in the asymmetric key generated by the first electronic device.
[0224] In some embodiments of this application, the second electronic device can send the identification information of the first electronic device to the server via the first link.
[0225] Step 302: The second electronic device receives the third key sent by the server based on the identification information and the second association relationship of the first electronic device.
[0226] In some embodiments of this application, the aforementioned second association relationship is the association relationship between the identification information of the first electronic device and the third key.
[0227] In some embodiments of this application, after receiving the identification information of the first electronic device, the server can obtain the third key based on the identification information of the first electronic device and the second association relationship, and then return the third key to the second electronic device.
[0228] In some embodiments of this application, the second electronic device may receive the third key sent by the server via the first link.
[0229] Step 303: The second electronic device uses the third key to encrypt the first key, generating the second encrypted data.
[0230] In some embodiments of this application, the first key may be a symmetric key, and the second electronic device may use the modulus and exponent of the asymmetric key in the third key data and the asymmetric encryption algorithm indicated by the third algorithm identifier to encrypt the first key and generate the second encrypted data.
[0231] Step 304: The second electronic device transmits the second encrypted data to the first electronic device through the second link.
[0232] In some embodiments of this application, the second link is a communication link between the first electronic device and the second electronic device.
[0233] In some embodiments of this application, while the second electronic device transmits the second encrypted data to the first electronic device via the second link, it can also transmit voice data to the first electronic device via the second link.
[0234] In some embodiments of this application, the second electronic device may add the second encrypted data to a Real-time Transport Protocol (RTP) data packet used to transmit the voice data, and then transmit the RTP data packet to the first electronic device through the second link to transmit the second encrypted data and the voice data to the first electronic device.
[0235] In some embodiments of this application, the second electronic device may also add the second encrypted data to a Real-time Transport Control Protocol (RTCP) data packet for transmitting control information, and transmit the RTCP data packet and the RTP data packet to the first electronic device via the second link, so as to transmit the second encrypted data and the voice data to the first electronic device.
[0236] In some embodiments of this application, the second electronic device adds the second encrypted data to the reserved field of the RTCP data packet.
[0237] In some embodiments of this application, the RTCP data packets described above include channel information, voice encoding information, etc.
[0238] In the data processing method provided in this application embodiment, during a voice call between a second electronic device and a first electronic device, the second electronic device sends its identification information to the server; the second electronic device receives a third key sent by the server based on the identification information and a second association relationship of the first electronic device; the second electronic device uses the third key to encrypt the first key, generating second encrypted data; the second electronic device transmits the second encrypted data to the first electronic device through a second link. Thus, using the scheme of this application, the server only needs to send the encryption key to the second electronic device. Therefore, even if an attacker attacks the server, they cannot obtain the decryption key, nor can they decrypt the second encrypted data to obtain the first key. Consequently, they cannot use the first key data to decrypt the first encrypted data to obtain the voice data, thereby improving the security of voice data during the voice call.
[0239] The data processing method provided in this application embodiment will be further described below with reference to Figure 6. As shown in Figure 6, the data processing method provided in this application embodiment may include the following steps:
[0240] Step 401: The first electronic device generates the first key pair.
[0241] In some embodiments of this application, the first key pair includes the first key and the second key, wherein the first key and the second key are a public key and a private key, respectively.
[0242] It should be noted that the implementation process of step 401 above can refer to step 104a above, and will not be repeated here in this embodiment.
[0243] Step 402: The first electronic device sends its identification information and first key to the server via the second link.
[0244] Step 403: The server establishes a first association between the identification information of the first electronic device and the first key.
[0245] It should be noted that the implementation process of steps 402 and 403 above can refer to step 104b above, and will not be repeated here in this embodiment.
[0246] Step 404: During a voice call with the first electronic device, the second electronic device sends the identification information of the first electronic device to the server.
[0247] Step 405: The server sends the first key to the second electronic device based on the identification information and the first association relationship of the first electronic device.
[0248] It should be noted that the implementation process of steps 404 and 405 above can refer to step 201 above, and will not be repeated here in this embodiment.
[0249] Step 406: The second electronic device receives the first key returned by the server based on the identification information and the first association relationship of the first electronic device, as well as the server's verification information.
[0250] It should be noted that the implementation process of step 406 can refer to steps 202 and 205 above, and will not be repeated here in this embodiment.
[0251] Step 407: If the second electronic device passes the server security verification based on the verification information, the second electronic device uses the first key to encrypt the voice data and generate the first encrypted data.
[0252] It should be noted that the implementation process of step 407 above can refer to step 203a above, and will not be repeated here in this embodiment.
[0253] Step 408: The second electronic device sends the first encrypted data to the server through the first link.
[0254] In some embodiments of this application, the first link is a data link established by the first electronic device and the second electronic device through the server.
[0255] It should be noted that the implementation process of step 408 can refer to step 204 above, and will not be repeated here in this embodiment.
[0256] Step 409: During the voice call between the first electronic device and the second electronic device, the server forwards the first encrypted data to the first electronic device through the first link.
[0257] Step 410: The first electronic device receives the first encrypted data forwarded by the server through the first link.
[0258] It should be noted that the implementation process of steps 409 and 410 above can refer to step 101 above, and will not be repeated here in this embodiment.
[0259] Step 411: The first electronic device uses the second key to decrypt the first encrypted data to obtain voice data.
[0260] It should be noted that the implementation process of step 411 above can refer to step 102b above, and will not be repeated here in this embodiment.
[0261] In the data processing method provided in this application embodiment, after the first electronic device generates a first key pair, it only needs to send the public key of the first key pair to the server. The second electronic device obtains the public key from the server, encrypts the voice data, and forwards the encrypted voice data to the first electronic device through the server. Then, the first electronic device uses the private key of the first key pair to decrypt the encrypted voice data to obtain the voice data. Thus, on the one hand, during the transmission of voice data, only the public key and the encrypted voice data are transmitted through the server. Therefore, even if the server is intercepted by an attacker during the transmission of the public key and encrypted voice data, the attacker cannot obtain the decryption key, let alone decrypt the encrypted voice data to obtain the voice data, thereby improving the security of voice data during voice calls. On the other hand, the server only stores the public key. Even if an attacker attacks the server, they cannot obtain the decryption key, let alone decrypt the encrypted voice data to obtain the voice data, thereby improving the security of voice data during voice calls.
[0262] The data processing method provided in this application embodiment will be further described below with reference to Figure 7. As shown in Figure 7, the data processing method provided in this application embodiment may include the following steps:
[0263] Step 501: The first electronic device generates the second key pair.
[0264] In some embodiments of this application, the second key pair includes the second key and the third key, wherein the second key and the third key are a private key and a public key, respectively.
[0265] It should be noted that the implementation process of step 501 above can refer to step 106a above, and will not be repeated here in this embodiment.
[0266] Step 502: The first electronic device sends its identification information and third key to the server via the second link.
[0267] Step 503: The server establishes a second association between the identification information of the first electronic device and the third key.
[0268] It should be noted that the implementation process of steps 502 and 503 above can refer to step 106b above, and will not be repeated here in this embodiment.
[0269] Step 504: During a voice call with the first electronic device, the second electronic device sends the identification information of the first electronic device to the server.
[0270] Step 505: The server sends a third key to the second electronic device based on the identification information of the first electronic device and the second association relationship.
[0271] It should be noted that the implementation process of steps 504 and 505 above can refer to step 301 above, and will not be repeated here in this embodiment.
[0272] Step 506: The second electronic device receives the third key sent by the server based on the identification information and second association of the first electronic device, as well as the server's verification information.
[0273] It should be noted that the implementation process of step 504 above can refer to step 302 above, and will not be repeated here in this embodiment.
[0274] Step 507: After verifying the server security based on the verification information, the second electronic device uses the third key to encrypt the first key and generate the second encrypted data.
[0275] It should be noted that the implementation process of step 507 can refer to step 303 above, and will not be repeated here in this embodiment.
[0276] Step 508: The second electronic device transmits the second encrypted data to the first electronic device through the second link.
[0277] It should be noted that the implementation process of step 506 can refer to step 304 above, and will not be repeated here in this embodiment.
[0278] Step 509: The first electronic device receives the second encrypted data sent by the second electronic device through the second link.
[0279] It should be noted that the implementation process of step 507 can refer to step 105 above, and will not be repeated here in this embodiment.
[0280] Step 510: The first electronic device uses the second key to decrypt the second encrypted data and obtain the first key.
[0281] It should be noted that the implementation process of step 510 above can refer to step 102c1 above, and will not be repeated here in this embodiment.
[0282] Step 511: During the voice call between the first electronic device and the second electronic device, the second electronic device uses the first key to encrypt the voice data to obtain the first encrypted data.
[0283] Step 512: The second electronic device sends the first encrypted data to the server through the first link.
[0284] It should be noted that the implementation process of step 512 above can refer to step 204 above, and will not be repeated here in this embodiment.
[0285] Step 513: During the voice call between the first electronic device and the second electronic device, the server forwards the first encrypted data to the first electronic device through the first link.
[0286] Step 514: The first electronic device receives the first encrypted data forwarded by the server through the first link.
[0287] It should be noted that the implementation process of steps 513 and 514 above can refer to step 101 above, and will not be repeated here in this embodiment.
[0288] Step 515: The first electronic device uses the first key to decrypt the first encrypted data to obtain voice data.
[0289] It should be noted that the implementation process of step 515 above can refer to step 102c2 above, and will not be repeated here in this embodiment.
[0290] In the data processing method provided in this application embodiment, after the first electronic device generates the second key pair, it only needs to send the public key from the first key pair to the server. The second electronic device obtains the public key from the server, encrypts the first key, and forwards the encrypted data to the first electronic device through the server. Then, the first electronic device uses the private key from the second key pair to decrypt the encrypted data to obtain the first key. Therefore, when receiving voice data encrypted with the first key, it uses the first key to encrypt the voice data to obtain the voice data. Thus, on the one hand, during the transmission of voice data, only the public key and encrypted data are transmitted through the server. Therefore, even if the server is intercepted by an attacker during the transmission of the public key and encrypted data, the attacker cannot obtain the decryption key, nor can they decrypt the encrypted data to obtain the first key, and thus cannot use the first key to decrypt the encrypted voice data to obtain the voice data, thereby improving the security of voice data during voice calls. On the other hand, the server only stores the public key. Even if an attacker attacks the server, they cannot obtain the decryption key, nor can they decrypt the encrypted data to obtain the first key, and thus cannot use the first key to decrypt the encrypted voice data to obtain the voice data, thereby improving the security of voice data during voice calls.
[0291] The data processing method provided in this application embodiment will be further described below with reference to Figure 8. As shown in Figure 8, the data processing method provided in this application embodiment may include the following steps:
[0292] Step 601: The second electronic device generates the first key pair.
[0293] In some embodiments of this application, the first key pair includes the first key and the second key, wherein the first key and the second key are a public key and a private key, respectively.
[0294] It should be noted that the implementation process of step 601 is similar to that of step 104. To avoid repetition, this embodiment will not repeat the details here.
[0295] Step 602: The second electronic device sends the second key to the first electronic device via the second link.
[0296] Step 603: During the voice call between the first electronic device and the second electronic device, the first electronic device receives the second key sent by the second electronic device through the second link.
[0297] It should be noted that the implementation process of step 603 is similar to that of step 103a. To avoid repetition, this embodiment will not repeat the details here.
[0298] Step 604: The first electronic device stores the second key in the key storage area of the first electronic device.
[0299] It should be noted that the implementation process of step 604 is similar to that of step 103b. To avoid repetition, this embodiment will not repeat the details here.
[0300] Step 605: The first electronic device receives the first encrypted data forwarded by the server through the first link.
[0301] In some embodiments of this application, the first encrypted data is generated by the second electronic device encrypting the voice data using the first key.
[0302] It should be noted that the implementation process of step 605 is similar to that of step 101. To avoid repetition, this embodiment will not repeat the details here.
[0303] Step 606: The first electronic device uses the second key stored in the first electronic device to decrypt the first encrypted data to obtain voice data.
[0304] It should be noted that the implementation process of step 606 is similar to that of step 102a. To avoid repetition, this embodiment will not repeat the details here.
[0305] In the data processing method provided in this application embodiment, after the second electronic device generates the first key pair, it directly sends the second key to the first electronic device via the second link. Upon receiving the second key, the first electronic device stores it in a key storage area. Then, upon receiving the first encrypted data forwarded by the server via the first link, it uses the second key to decrypt the first encrypted data, thus obtaining the voice data. In this way, even if the server is attacked, the attacker cannot obtain the second key, nor can they decrypt the first encrypted data using the second key to obtain the voice data, thereby improving the security of voice data during voice calls. Furthermore, using the solution of this application, there is no need for the server to transmit the second key to the first electronic device, thus effectively avoiding the problem of the server intercepting the second key during transmission, further improving the security of voice data during voice calls.
[0306] The following describes the data processing method provided in the embodiments of this application in detail, taking scenarios 1 to 4 as examples and using electronic devices as terminals.
[0307] Scenario 1: A scenario where the terminal has a built-in private key. For example, as shown in Figure 9, in Scenario 1, the data processing method provided in this application embodiment may include steps 701 to 704.
[0308] Step 701: The data receiver's terminal stores an asymmetric key pair.
[0309] For example, the terminal of the data receiver can be the first electronic device described above.
[0310] For example, the data sender's terminal generates an asymmetric encryption key pair, including a public key and a private key.
[0311] For example, the key pair for the asymmetric encryption can be the first key pair mentioned above.
[0312] For example, the public key can be the first key in the first key pair described above, and the private key can be the second key in the first key pair described above.
[0313] For example, before the data sender's terminal leaves the factory, the private key is written into the protected area of the data sender's terminal or the built-in hardware key storage area to prevent it from being tampered with or read illegally; at the same time, the data sender stores the terminal's corresponding public key combination on the manufacturer's server.
[0314] For example, the manufacturer's server can be the aforementioned server.
[0315] For example, the aforementioned identification information may be the Embedded Multi Media Card Identification (EMMCID) or the International Mobile Equipment Identity (IMEI) of the terminal.
[0316] Step 702: The data sender's terminal obtains the public key of the data sender's terminal from the server.
[0317] For example, the terminal of the data sender can be the second electronic device described above.
[0318] For example, when all terminals of the data sender are running the first application, the aforementioned server can be the backend server of the first application. The terminals of the data sender can establish a data link through the backend server of the first application, and the terminals of the data sender can obtain the public key of the data sender's terminal from the server through the data link.
[0319] For example, the terminal of the data receiver and the terminal of the data sender can establish a data link through the server, and request the public key of the data sender's terminal from the server through the data link; the server sends the public key of the data sender's terminal and the server's verification information to the terminal of the data receiver. After receiving the public key, the terminal of the data receiver uses the verification information to verify it to ensure that the public key is not tampered with.
[0320] Step 703: The data sender's terminal encrypts the voice data using a public key, generates the first encrypted data, and sends it.
[0321] For example, the data sender's terminal can use an asymmetric encryption algorithm, with the server providing the data receiver's terminal's public key, to encrypt the voice data, and then send the generated first encrypted data to the server via a data link, or directly to the data receiver's terminal.
[0322] Step 704: The terminal of the data receiver receives the first encrypted data and uses the private key from the stored asymmetric encryption key pair to decrypt the first encrypted data to obtain the voice data.
[0323] For example, referring to Figure 10, the two terminals in a voice call are user A's terminal and user B's terminal. When user A is the voice initiator and user B is the voice receiver, user A's terminal is the data sender's terminal, and user B's terminal is the data receiver's terminal. When user B is the voice initiator and user A is the voice receiver, user B's terminal is the data sender's terminal, and user A's terminal is the data receiver's terminal. Therefore, user A's terminal and user B's terminal can generate and store their respective asymmetric key pairs, and then send the public key from their respective asymmetric key pairs to the server.
[0324] For example, after the server stores the public keys of the asymmetric key pairs of user A's terminal and user B's terminal, if user A's terminal needs to transmit user A's voice data to user B's terminal, user A's terminal can send a request to the server to obtain user B's terminal's public key. Upon receiving the request from user A's terminal, the server can send user B's terminal's public key and the server's verification information to user A's terminal. After receiving user B's terminal's public key and the server's verification information, user A's terminal can verify the information to ensure that user B's terminal's public key has not been tampered with. Then, it uses user B's terminal's public key to encrypt the symmetric encryption key generated by user A's terminal, obtaining second encrypted data, and forwards the second encrypted data to the server, which then forwards it to user B's terminal, or the server directly sends the second encrypted data to user B's terminal. Upon receiving the second encrypted data, user B's terminal can decrypt the second encrypted data using the private key from the asymmetric key pair to obtain the symmetric encryption key. Furthermore, after user B's terminal receives user A's voice data encrypted with a symmetric encryption key by user A's terminal, it can encrypt user A's voice data with a symmetric encryption key to obtain user A's encrypted voice data.
[0325] In the data processing method provided in this application embodiment, the private key is always stored in the terminal of the data receiver. Therefore, even if an attacker attacks the server or hijacks the communication data between the server and the terminal of the data receiver, the attacker will not be able to obtain the private key, nor will the attacker be able to use the private key to decrypt the corresponding voice data, thereby improving the security of voice data during voice calls.
[0326] Scenario 2: A scenario where a symmetric key is protected using a terminal-embedded private key. For example, as shown in Figure 11, in Scenario 2, the data processing method provided in this application embodiment may include steps 801 to 806.
[0327] Step 801: The data receiver's terminal stores an asymmetric key pair.
[0328] For example, the aforementioned asymmetric key pair is the aforementioned second key pair.
[0329] Step 802: The data sender's terminal obtains the public key of the data sender's terminal from the server.
[0330] It should be noted that the public key of the data sender's terminal is the aforementioned third key.
[0331] It should be noted that the implementation process of steps 801 and 802 is similar to that of steps 701 and 702. To avoid repetition, this embodiment will not describe them again here.
[0332] Step 803: The data sender's terminal uses the public key to encrypt the symmetric encryption key generated by the data sender's terminal, generates the second encrypted data, and sends it.
[0333] For example, the key for symmetric encryption can be the first key mentioned above.
[0334] For example, the data sender's terminal can use an asymmetric encryption algorithm, and the server provides the data receiver's terminal's public key to encrypt the symmetric encryption key. Then, the generated second encrypted data is sent to the server via a data link, or directly to the data receiver's terminal.
[0335] Step 804: The terminal of the data receiver receives the second encrypted data and uses the private key from the stored asymmetric encryption key pair to decrypt the second encrypted data to obtain the symmetric encryption key.
[0336] Step 805: The data sender's terminal encrypts the voice data using a symmetric encryption key, generates the first encrypted data, and sends it.
[0337] Step 806: The data receiver's terminal decrypts the first encrypted data using a symmetric encryption key to obtain the voice data.
[0338] For example, referring to Figure 12, the two terminals in a voice call are user A's terminal and user B's terminal. When user A is the voice initiator and user B is the voice receiver, user A's terminal is the data sender's terminal, and user B's terminal is the data receiver's terminal. When user B is the voice initiator and user A is the voice receiver, user B's terminal is the data sender's terminal, and user A's terminal is the data receiver's terminal. Therefore, user A's terminal and user B's terminal can generate and store their respective asymmetric key pairs, and then send the public key from their respective asymmetric key pairs to the server.
[0339] For example, after the server stores the public keys of the asymmetric key pairs of user A's terminal and user B's terminal, if user A's terminal needs to transmit user A's voice data to user B's terminal, user A's terminal can send a request to the server to obtain user B's terminal's public key. After receiving user A's terminal's request, the server can send user B's terminal's public key and the server's verification information to user A's terminal. After receiving user B's terminal's public key and the server's verification information, user A's terminal can use the verification information to verify that user B's terminal's public key has not been tampered with, then use user B's terminal's public key to encrypt user A's voice data, and forward the encrypted voice data to the server, which then forwards it to user B's terminal, or the server can directly send the encrypted voice data to user B's terminal.
[0340] For example, after the server stores the public keys of the asymmetric key pairs of user A's terminal and user B's terminal, if user B's terminal needs to transmit user B's voice data to user A's terminal, user B's terminal can send a request to the server to obtain user A's terminal's public key. After receiving user B's terminal's request, the server can send user A's terminal's public key and the server's verification information to user B's terminal. After receiving user A's terminal's public key and the server's verification information, user B's terminal can use the verification information to verify that user A's terminal's public key has not been tampered with, then use user A's terminal's public key to encrypt user B's voice data, and forward the encrypted voice data to the server, which then forwards it to user A's terminal, or the server can directly send the encrypted voice data to user A's terminal.
[0341] In the data processing method provided in this application embodiment, the private key is always stored in the terminal of the data receiver. Therefore, even if an attacker attacks the server or hijacks the communication data between the server and the terminal of the data receiver, the attacker will not be able to obtain the private key, nor will the attacker be able to use the private key to decrypt the symmetric encryption key, nor will the attacker be able to use the symmetric encryption key to decrypt the corresponding voice data, thereby improving the security of voice data during voice calls.
[0342] Scenario 3: Using a three-way channel to transmit keys
[0343] For example, as shown in FIG13, in scenario 3, the data processing method provided in this application embodiment may include the following steps 901 to 904.
[0344] Step 901: Both parties in the call select a third-party channel on their terminals.
[0345] For example, the aforementioned third-party channel can be a third link, which can be a data link established by the terminals of both parties in the call through the backend server of the second application. The second application and the first application are different applications.
[0346] For example, the terminals of both parties in the call can verbally negotiate a temporary checksum using the backend server of the second application, for example, by forwarding the digital checksum information through a third link, directly as the public key in the symmetric key or asymmetric key, or as the basic information for generating the key.
[0347] For example, the third channel mentioned above can be the second link mentioned above, such as a VoLTE, VoNR, VoWiFi, or other telephone link.
[0348] For example, after the terminals of both parties establish a call connection, they use the redundant bits of the control signaling of the telephone link such as VoLTE, VoNR, and VoWiFi to transmit key information, such as the redundant fields of the signaling that can be transmitted to the other end in RTP packets, Session Initialization Protocol (SIP) packets, or RTCP packets.
[0349] It should be noted that in traditional VoLTE, VoNR, and VoWiFi, after a call is established, two types of data packets are exchanged with the base station: one is the RTP data packet for transmitting voice data, which is a protocol format that encapsulates audio such as AMR; the other is the RTCP data packet for transmitting control information, which contains negotiation information such as channel information and voice coding. On the one hand, key information can be put into the RTP data packet and transmitted to the other end, but the original voice data will be corrupted, and the caller may perceive abnormal sound quality; on the other hand, key information can be put into the reserved field of the RTCP data packet for transmission.
[0350] Step 902: The data receiver's terminal uses a third-party channel to transmit the key.
[0351] For example, the data receiving terminal can transmit the public key of its asymmetric encryption key pair, or the negotiated key of symmetric encryption, to the other end through the aforementioned three-party channel.
[0352] It should be noted that the matter of the third-party channel transmission key can be negotiated in advance by both parties in the call, and the calling or called party can generate the key and then send it to the other party for verification before use.
[0353] Step 903: The data sender's terminal encrypts the voice data using the key transmitted through a third-party channel, generates the first encrypted data, and forwards it to the data receiver's terminal through the server.
[0354] Step 904: The terminal of the data receiver receives the first encrypted data, and decrypts the first encrypted data using the private key in the asymmetric encryption key pair or the negotiated key in the symmetric encryption key pair to obtain the voice data.
[0355] For example, referring to Figure 14, the two terminals in a voice call are user A's terminal and user B's terminal. When user A is the voice initiator and user B is the voice receiver, user A's terminal is the data sender's terminal, and user B's terminal is the data receiver's terminal. When user B is the voice initiator and user A is the voice receiver, user B's terminal is the data sender's terminal, and user A's terminal is the data receiver's terminal. Therefore, user A's terminal and user B's terminal can generate and store their respective asymmetric key pairs, and then send the public key from their respective asymmetric key pairs to each other through a third-party channel.
[0356] For example, if user A's terminal needs to transmit user A's voice data to user B's terminal, after user A's terminal receives user B's terminal's public key through the third channel, it can use user B's terminal's public key to encrypt user A's voice data and forward the encrypted voice data to the server, which then forwards it to user B's terminal.
[0357] For example, if user B's terminal needs to transmit user B's voice data to user A's terminal, after user B's terminal receives user A's terminal's public key through the third channel, it can use user A's terminal's public key to encrypt user B's voice data and forward the encrypted voice data to the server, which will then forward it to user A's terminal.
[0358] In the data processing method provided in this embodiment, the third channel transmits the key and forwards the encrypted voice data through the server. This allows the key and data to be transmitted through different channels, thereby improving the security of the voice data.
[0359] Scenario 4: Generating a key using the first identifier information and a timestamp.
[0360] For example, in scenario 4, either party in a voice call can use the first identifier information and timestamp, and the two parties in the voice call can generate the same symmetric encryption key using a key generation algorithm agreed upon by both parties. The two parties in the voice call can then use the symmetric key generated by the key generation algorithm agreed upon by both parties in the voice call to encrypt and decrypt the voice data.
[0361] It should be noted that the interpretation of the first identification information can refer to the relevant description in step 104a above, and will not be repeated here in this embodiment.
[0362] It should be noted that the solution in Scenario 4 is applicable when a third-party channel cannot be established. When a third-party channel cannot be established, the key or key verification information cannot be transmitted to the other end; the voice data can be encrypted and decrypted using a symmetric key generated by a key generation algorithm agreed upon by both parties in the voice call.
[0363] In the data processing method provided in this application embodiment, when a third-party channel cannot be established, the voice data is encrypted and decrypted using a symmetric key generated by a key generation algorithm agreed upon by both parties in the voice call. Thus, the voice data can be encrypted and decrypted without transmitting the key through a third-party channel, thereby improving the transmission efficiency of the voice data.
[0364] It should be noted that each of the above method embodiments, or various possible implementations of each method embodiment, can be executed individually or in combination of any two or more. The specific implementation can be determined according to actual usage requirements, and this application embodiment does not impose any restrictions on this.
[0365] The data processing method provided in this application can be executed by a data processing device. This application uses an example of a data processing device executing the data processing method to illustrate the data processing device provided in this application.
[0366] Figure 15 is a schematic diagram of the structure of the data processing device provided in the embodiment of this application. The data processing device 1500 includes a transceiver module 1501 and a processing module 1502.
[0367] The transceiver module 1501 is used to receive first encrypted data forwarded by the server through the first link during a voice call with the second electronic device. The first encrypted data is generated by the second electronic device encrypting voice data with a first key. The first link is a data link established between the first electronic device and the second electronic device through the server.
[0368] Processing module 1502 is used to obtain the voice data based on the second key in the first electronic device and the first encrypted data received by the transceiver module;
[0369] Wherein, the second key is generated by the first electronic device; or, the second key is generated by the second electronic device; in the case where the second key is generated by the second electronic device, the second key is sent by the second electronic device to the first electronic device through the second link, and the second link is a communication link between the first electronic device and the second electronic device.
[0370] In some embodiments of this application, when the first key and the second key are generated by the second electronic device, the transceiver module 1501 is further configured to receive the second key sent by the second electronic device through the second link before receiving the first encrypted data forwarded by the server through the first link;
[0371] The processing module 1502 is further configured to store the second key in the key storage area of the first electronic device.
[0372] In some embodiments of this application, the first key and the second key are symmetric keys or asymmetric keys; when the first key and the second key are asymmetric keys, the first key and the second key are respectively the public key and the private key of the asymmetric key;
[0373] The processing module 1502 is specifically used for:
[0374] The first encrypted data is decrypted using the second key stored in the first electronic device to obtain voice data.
[0375] In some embodiments of this application, when the first key and the second key are generated by the first electronic device, the processing module 1502 is further configured to generate a first key pair before receiving the first encrypted data forwarded by the server through the first link. The first key pair includes the first key and the second key, wherein the first key and the second key are a public key and a private key, respectively.
[0376] The transceiver module 1501 is further configured to send the identification information of the first electronic device and the first key to the server through the second link, so that the server establishes a first association relationship between the identification information of the first electronic device and the first key.
[0377] The processing module 1502 is specifically used for:
[0378] The first encrypted data is decrypted using the second key to obtain the voice data.
[0379] In some embodiments of this application, where the first key is generated by the second electronic device and the second key is generated by the first electronic device, the transceiver module 1501 is further configured to receive second encrypted data sent by the second electronic device through the second link before receiving the first encrypted data forwarded by the receiving server through the first link. The second encrypted data is generated by the second electronic device encrypting the first key with a third key, and the third key and the second key are respectively the public key and private key in the second key pair pre-stored by the first electronic device.
[0380] The processing module 152 is specifically used for:
[0381] The second key is used to decrypt the second encrypted data to obtain the first key;
[0382] Using the first key, the first encrypted data is decrypted to obtain the voice data.
[0383] In some embodiments of this application, the processing module 1502 is further configured to generate a second key pair before receiving the first encrypted data forwarded by the server through the first link. The second key pair includes a second key and a third key, wherein the second key and the third key are a private key and a public key, respectively.
[0384] The transceiver module 1501 is further configured to send the identification information of the first electronic device and the third key to the server through the second link, so that the server establishes a second association relationship between the identification information of the first electronic device and the third key.
[0385] In some embodiments of this application, during a voice call between the first electronic device and the second electronic device, the transceiver module 1501 is further configured to:
[0386] The voice data is received via the second link from the second electronic device.
[0387] In the data processing apparatus provided in this application embodiment, during a voice call with a second electronic device, the device receives first encrypted data forwarded by a server through a first link. This first encrypted data is generated by the second electronic device encrypting voice data using a first key. The first link is a data link established between the first and second electronic devices through the server. The first electronic device obtains voice data based on a second key and the first encrypted data. The second key is generated by the first electronic device; or, if the second key is generated by the second electronic device, it is sent to the first electronic device via a second link, which is the call link between the first and second electronic devices. Thus, since the second key is generated by the first electronic device, or sent to the first electronic device via the second link, even if the server is attacked, the attacker cannot obtain the second key, nor can they decrypt the first encrypted data to obtain the voice data based on the second key, thereby improving the security of voice data during the voice call. Thus, since the second key is generated by the first electronic device, or sent to the first electronic device via the second link, even if the server is attacked, the attacker cannot obtain the second key, nor can they decrypt the first encrypted data to obtain the voice data based on the second key, thereby improving the security of voice data during voice calls.
[0388] Figure 16 is a schematic diagram of a data processing device provided in an embodiment of this application. The data processing device 1600 includes: a sending module 1601, a receiving module 1602, and a processing module 1603.
[0389] The sending module 1601 is used to send the identification information of the first electronic device to the server during a voice call with the first electronic device.
[0390] The receiving module 1602 is used to receive a first key sent by the server based on the identification information of the first electronic device and a first association relationship sent by the sending module, wherein the first association relationship is the association relationship between the identification information of the first electronic device and the first key.
[0391] Processing module 1603 is used to encrypt voice data using the first key received by the receiving module to generate first encrypted data;
[0392] The sending module 1601 is further configured to send the first encrypted data generated by the processing module to the server via a first link, wherein the first link is a data link established by the first electronic device and the second electronic device through the server.
[0393] In some embodiments of this application, the receiving module 1602 is further configured to receive, after sending the identification information of the first electronic device to the server, the server's verification information based on the identification information of the first electronic device;
[0394] The processing module 1603 is specifically used for:
[0395] If the security verification of the server is passed based on the verification information, the first data is encrypted using the first key to generate the first encrypted data.
[0396] In the data processing apparatus provided in this application embodiment, during a voice call with a first electronic device, the server sends the identification information of the first electronic device; receives a first key sent by the server based on the identification information and a first association relationship of the first electronic device; and sends first encrypted data to the server through a first link. Thus, using the scheme of this application, the server only needs to send the encryption key to the second electronic device. Therefore, even if an attacker attacks the server, they cannot obtain the decryption key, nor can they decrypt the first encrypted data to obtain the voice data, thereby improving the security of voice data during voice calls.
[0397] Figure 17 is a schematic diagram of the structure of a data processing device 1700 provided in an embodiment of this application. The data processing device 1700 includes a sending module 1701, a receiving module 1702, and a processing module 1703.
[0398] The sending module 1701 is used to send the identification information of the first electronic device to the server during a voice call with the first electronic device.
[0399] The receiving module 1702 is used to receive a third key sent by the server based on the identification information and second association relationship of the first electronic device sent by the sending module, wherein the second association relationship is the association relationship between the identification information of the first electronic device and the third key.
[0400] Processing module 1703 is used to encrypt the first key using the third key to generate second encrypted data;
[0401] The sending module 1701 is further configured to transmit the second encrypted data generated by the processing module to the first electronic device via a second link, wherein the second link is a communication link between the first electronic device and the second electronic device.
[0402] In the data processing apparatus provided in this application embodiment, during a voice call with a first electronic device, the system sends identification information of the first electronic device to a server; receives a third key sent by the server based on the identification information and a second association relationship of the first electronic device; the second electronic device uses the third key to encrypt the first key, generating second encrypted data; and transmits the second encrypted data to the first electronic device via a second link. Thus, using the scheme of this application, the server only needs to send the encryption key to the second electronic device. Therefore, even if an attacker attacks the server, they cannot obtain the decryption key, nor can they decrypt the second encrypted data to obtain the first key. Consequently, they cannot use the first key data to decrypt the first encrypted data to obtain the voice data, thereby improving the security of voice data during voice calls.
[0403] The data processing device in this application embodiment can be an electronic device or a component within an electronic device, such as an integrated circuit or a chip. The electronic device can be a terminal or other devices besides a terminal. For example, the electronic device can be a mobile phone, tablet computer, laptop computer, PDA, in-vehicle electronic device, mobile internet device, augmented reality / virtual reality device, robot, wearable device, super mobile personal computer, netbook, or personal digital assistant, etc. It can also be a server, network attached storage (NAS), personal computer (PC), television set (TV), ATM, or self-service machine, etc. This application embodiment does not specifically limit the specific device.
[0404] The data processing device in this application embodiment can be a device with an operating system. The operating system can be Android, iOS, or other possible operating systems; this application embodiment does not specifically limit the specific operating system.
[0405] The data processing apparatus provided in this application embodiment can implement the various processes implemented in the various embodiments of the above data processing method. To avoid repetition, it will not be described again here.
[0406] Optionally, as shown in FIG18, this application embodiment also provides an electronic device 1800, including a processor 1801 and a memory 1802. The memory 1802 stores a program or instructions that can be executed on the processor 1801. When the program or instructions are executed by the processor 1801, they implement the various steps of the above-described data processing method embodiment and can achieve the same technical effect. To avoid repetition, they will not be described again here.
[0407] It should be noted that the electronic devices in the embodiments of this application include the mobile electronic devices and non-mobile electronic devices described above.
[0408] Figure 19 is a schematic diagram of the hardware structure of an electronic device that implements an embodiment of this application.
[0409] The electronic device 1900 includes, but is not limited to, components such as: radio frequency unit 1901, network module 1902, audio output unit 1903, input unit 1904, sensor 1905, display unit 1906, user input unit 1907, interface unit 1908, memory 1909, and processor 1910.
[0410] Those skilled in the art will understand that the electronic device 1900 may also include a power supply (such as a battery) for powering various components. The power supply may be logically connected to the processor 1910 through a power management system, thereby enabling functions such as charging, discharging, and power consumption management through the power management system. The electronic device structure shown in Figure 19 does not constitute a limitation on the electronic device. The electronic device may include more or fewer components than shown, or combine certain components, or have different component arrangements, which will not be elaborated here.
[0411] The radio frequency unit 1901 is used to receive first encrypted data forwarded by the server through the first link during a voice call with the second electronic device. The first encrypted data is generated by the second electronic device encrypting voice data with a first key. The first link is a data link established between the first electronic device and the second electronic device through the server.
[0412] Processor 1910 is configured to obtain the voice data based on a second key in the first electronic device and the first encrypted data received by the transceiver module;
[0413] Wherein, the second key is generated by the first electronic device; or, the second key is generated by the second electronic device; in the case where the second key is generated by the second electronic device, the second key is sent by the second electronic device to the first electronic device through the second link, and the second link is a communication link between the first electronic device and the second electronic device.
[0414] In some embodiments of this application, when the first key and the second key are generated by the second electronic device, the radio frequency unit 1901 is further configured to receive the second key sent by the second electronic device through the second link before receiving the first encrypted data forwarded by the receiving server through the first link;
[0415] The processor 1910 is also configured to store the second key in the key storage area of the first electronic device.
[0416] In some embodiments of this application, the first key and the second key are symmetric keys or asymmetric keys; when the first key and the second key are asymmetric keys, the first key and the second key are respectively the public key and the private key of the asymmetric key;
[0417] Processor 1910, specifically used for:
[0418] The first encrypted data is decrypted using the second key stored in the first electronic device to obtain voice data.
[0419] In some embodiments of this application, when the first key and the second key are generated by the first electronic device, the processor 1910 is further configured to generate a first key pair before receiving the first encrypted data forwarded by the server through the first link. The first key pair includes the first key and the second key, wherein the first key and the second key are a public key and a private key, respectively.
[0420] The radio frequency unit 1901 is also used to send the identification information of the first electronic device and the first key to the server through the second link, so that the server establishes a first association relationship between the identification information of the first electronic device and the first key;
[0421] Processor 1910, specifically used for:
[0422] The first encrypted data is decrypted using the second key to obtain the voice data.
[0423] In some embodiments of this application, where the first key is generated by the second electronic device and the second key is generated by the first electronic device, the transceiver module 1501 is further configured to receive second encrypted data sent by the second electronic device through the second link before receiving the first encrypted data forwarded by the receiving server through the first link. The second encrypted data is generated by the second electronic device encrypting the first key with a third key, and the third key and the second key are respectively the public key and private key in the second key pair pre-stored by the first electronic device.
[0424] Processor 1910, specifically used for:
[0425] The second key is used to decrypt the second encrypted data to obtain the first key;
[0426] Using the first key, the first encrypted data is decrypted to obtain the voice data.
[0427] In some embodiments of this application, the processor 1910 is further configured to generate a second key pair before receiving first encrypted data forwarded by the server through the first link, the second key pair including a second key and the third key, the second key and the third key being a private key and a public key, respectively;
[0428] The radio frequency unit 1901 is also used to send the identification information of the first electronic device and the third key to the server through the second link, so that the server can establish a second association relationship between the identification information of the first electronic device and the third key.
[0429] In some embodiments of this application, during a voice call between the first electronic device and the second electronic device, the radio frequency unit 1901 is further configured to:
[0430] The voice data is received via the second link from the second electronic device.
[0431] In the data processing apparatus provided in this application embodiment, during a voice call with a second electronic device, the device receives first encrypted data forwarded by a server through a first link. This first encrypted data is generated by the second electronic device encrypting voice data using a first key. The first link is a data link established between the first and second electronic devices through the server. The first electronic device obtains voice data based on a second key and the first encrypted data. The second key is generated by the first electronic device; or, if the second key is generated by the second electronic device, it is sent to the first electronic device via a second link, which is the call link between the first and second electronic devices. Thus, since the second key is generated by the first electronic device, or sent to the first electronic device via the second link, even if the server is attacked, the attacker cannot obtain the second key, nor can they decrypt the first encrypted data to obtain the voice data based on the second key, thereby improving the security of voice data during the voice call.
[0432] In some embodiments of this application, the radio frequency unit 1901 is used to send the identification information of the first electronic device to the server during a voice call with the first electronic device;
[0433] The server receives a first key based on the identification information of the first electronic device and a first association relationship sent by the sending module, wherein the first association relationship is the association relationship between the identification information of the first electronic device and the first key.
[0434] The processor 1910 is used to encrypt voice data using the first key received by the receiving module to generate first encrypted data;
[0435] The radio frequency unit 1901 is also used to send the first encrypted data generated by the processing module to the server via a first link, wherein the first link is a data link established by the first electronic device and the second electronic device through the server.
[0436] In some embodiments of this application, the radio frequency unit 1901 is further configured to receive, after sending the identification information of the first electronic device to the server, the server's verification information based on the identification information of the first electronic device.
[0437] Processor 1910, specifically used for:
[0438] If the security verification of the server is passed based on the verification information, the first data is encrypted using the first key to generate the first encrypted data.
[0439] In the electronic device provided in this application embodiment, during a voice call with the first electronic device, the server sends the identification information of the first electronic device; receives the first key sent by the server based on the identification information and the first association relationship of the first electronic device; and sends the first encrypted data to the server through the first link. Thus, using the solution of this application, the server only needs to send the encryption key to the second electronic device. Therefore, even if an attacker attacks the server, they cannot obtain the decryption key, nor can they decrypt the first encrypted data to obtain the voice data, thereby improving the security of voice data during voice calls.
[0440] In some embodiments of this application, the radio frequency unit 1901 is used to send the identification information of the first electronic device to the server during a voice call with the first electronic device;
[0441] The server receives a third key based on the identification information and second association relationship of the first electronic device sent by the sending module, wherein the second association relationship is the association relationship between the identification information of the first electronic device and the third key.
[0442] Processor 1910 is configured to encrypt the first key using the third key to generate second encrypted data;
[0443] The radio frequency unit 1901 is also used to transmit the second encrypted data generated by the processing module to the first electronic device via a second link, wherein the second link is a communication link between the first electronic device and the second electronic device.
[0444] In the electronic device provided in this application embodiment, during a voice call with a first electronic device, the server sends the identification information of the first electronic device; receives a third key sent by the server based on the identification information and a second association relationship of the first electronic device; the second electronic device uses the third key to encrypt the first key to generate second encrypted data; and transmits the second encrypted data to the first electronic device through a second link. Thus, using the scheme of this application, the server only needs to send the encryption key to the second electronic device. Therefore, even if an attacker attacks the server, they cannot obtain the decryption key, nor can they decrypt the second encrypted data to obtain the first key, and consequently cannot use the first key data to decrypt the first encrypted data to obtain the voice data, thereby improving the security of voice data during voice calls.
[0445] It should be understood that, in this embodiment, the input unit 1904 may include a graphics processing unit (GPU) 19041 and a microphone 19042. The GPU 19041 processes image data of still images or videos obtained by an image capture device (such as a camera) in video capture mode or image capture mode. The display unit 1906 may include a display panel 19061, which may be configured in the form of a liquid crystal display, an organic light-emitting diode, or the like. The user input unit 1907 includes at least one of a touch panel 19071 and other input devices 19072. The touch panel 19071 is also called a touch screen. The touch panel 19071 may include a touch detection device and a touch controller. Other input devices 19072 may include, but are not limited to, a physical keyboard, function keys (such as volume control buttons, power buttons, etc.), a trackball, a mouse, and a joystick, which will not be described in detail here.
[0446] The memory 1909 can be used to store software programs and various data. The memory 1909 may primarily include a first storage area for storing programs or instructions and a second storage area for storing data. The first storage area may store the operating system, application programs or instructions required for at least one function (such as sound playback, image playback, etc.). Furthermore, the memory 1909 may include volatile memory or non-volatile memory, or both. The non-volatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory can be random access memory (RAM), static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct memory bus RAM (DRRAM). The memory 1909 in the embodiments of this application includes, but is not limited to, these and any other suitable types of memory.
[0447] Processor 1910 may include one or more processing units; optionally, processor 1910 integrates an application processor and a modem processor, wherein the application processor mainly handles operations involving the operating system, user interface, and applications, and the modem processor mainly handles wireless communication signals, such as a baseband processor. It is understood that the aforementioned modem processor may also not be integrated into processor 1910.
[0448] This application also provides a readable storage medium storing a program or instructions. When the program or instructions are executed by a processor, they implement the various processes of the above-described data processing method embodiments and achieve the same technical effects. To avoid repetition, they will not be described again here.
[0449] The processor is the processor in the electronic device described in the above embodiments. The readable storage medium includes computer-readable storage media, such as computer read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk.
[0450] This application embodiment also provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor. The processor is used to run programs or instructions to implement the various processes of the above data processing method embodiments and can achieve the same technical effect. To avoid repetition, it will not be described again here.
[0451] It should be understood that the chip mentioned in the embodiments of this application may also be referred to as a system-on-a-chip, system chip, chip system, or system-on-a-chip, etc.
[0452] This application provides a computer program product, which is stored in a storage medium and executed by at least one processor to implement the various processes of the data processing method embodiments described above, and can achieve the same technical effect. To avoid repetition, it will not be described again here.
[0453] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element. Furthermore, it should be noted that the scope of the methods and apparatuses in the embodiments of this application is not limited to performing functions in the order shown or discussed, but may also include performing functions substantially simultaneously or in the reverse order, depending on the functions involved. For example, the described methods may be performed in a different order than described, and various steps may be added, omitted, or combined. Additionally, features described with reference to certain examples may be combined in other examples.
[0454] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a computer software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods described in the various embodiments of this application.
[0455] The embodiments of this application have been described above with reference to the accompanying drawings. However, this application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of this application without departing from the spirit and scope of the claims, and all of these forms are within the protection scope of this application.
Claims
1. A data processing method, executed by a first electronic device, the method comprising: During a voice call with the second electronic device, the first electronic device receives first encrypted data forwarded by the server through the first link. The first encrypted data is generated by the second electronic device encrypting the voice data using a first key. The first link is a data link established between the first electronic device and the second electronic device through the server. The first electronic device obtains the voice data based on the second key and the first encrypted data in the first electronic device; Wherein, the second key is generated by the first electronic device, or the second key is generated by the second electronic device; In the case where the second key is generated by the second electronic device, the second key is sent from the second electronic device to the first electronic device via the second link, and the second link is the communication link between the first electronic device and the second electronic device.
2. The method according to claim 1, wherein, If the first key and the second key are generated by the second electronic device, before the first electronic device receives the first encrypted data forwarded by the server through the first link, the method further includes: The first electronic device receives the second key sent by the second electronic device through the second link; The first electronic device stores the second key in the key storage area of the first electronic device.
3. The method according to claim 2, wherein, The first key and the second key are either symmetric keys or asymmetric keys; when the first key and the second key are asymmetric keys, the first key and the second key are respectively the public key and the private key of the asymmetric key; The first electronic device obtains the voice data based on the second key and the first encrypted data, including: The first electronic device uses the second key stored in the first electronic device to decrypt the first encrypted data to obtain voice data.
4. The method according to claim 1, wherein, If the first key and the second key are generated by the first electronic device, before the first electronic device receives the first encrypted data forwarded by the server through the first link, the method further includes: A first electronic device generates a first key pair, the first key pair including a first key and a second key, the first key and the second key being a public key and a private key, respectively; The first electronic device sends its identification information and the first key to the server via the second link, so that the server establishes a first association between the identification information and the first key of the first electronic device. The first electronic device obtains voice data based on the second key and the first encrypted data, including: The first electronic device uses the second key to decrypt the first encrypted data to obtain voice data.
5. The method according to claim 1, wherein, If the first key is generated by the second electronic device, and the second key is also generated by the first electronic device, before the first electronic device receives the first encrypted data forwarded by the server through the first link, the method further includes: The first electronic device receives the second encrypted data sent by the second electronic device through the second link. The second encrypted data is generated by the second electronic device encrypting the first key with a third key. The third key and the second key are respectively the public key and private key in the second key pair pre-stored by the first electronic device. The first electronic device obtains the voice data based on the second key and the first encrypted data, including: The first electronic device uses the second key to decrypt the second encrypted data to obtain the first key; The first electronic device uses the first key to decrypt the first encrypted data and obtain voice data.
6. The method according to claim 5, wherein, Before the first electronic device receives the first encrypted data forwarded by the server through the first link, the method further includes: The first electronic device generates a second key pair, the second key pair including a second key and the third key, the second key and the third key being a private key and a public key, respectively; The first electronic device sends its identification information and the third key to the server via the second link, so that the server establishes a second association between the identification information and the third key.
7. The method according to any one of claims 1 to 6, wherein, During a voice call between the first electronic device and the second electronic device, the method further includes: The first electronic device receives the voice data sent by the second electronic device through the second link.
8. A data processing method, performed by a second electronic device, the method comprising: During a voice call with the first electronic device, the second electronic device sends the identification information of the first electronic device to the server; The second electronic device receives a first key sent by the server based on the identification information of the first electronic device and a first association relationship, wherein the first association relationship is the association relationship between the identification information of the first electronic device and the first key; The second electronic device uses the first key to encrypt the voice data and generate the first encrypted data; The second electronic device sends the first encrypted data to the server through the first link, whereby the first electronic device and the second electronic device establish a data link through the server.
9. The method according to claim 8, wherein, After the second electronic device sends the identification information of the first electronic device to the server, the method further includes: The second electronic device receives the server's verification information sent by the server based on the identification information of the first electronic device; The second electronic device uses the first key to encrypt the voice data, generating first encrypted data, including: If the second electronic device passes the security verification of the server based on the verification information, the second electronic device uses the first key to encrypt the first data and generate the first encrypted data.
10. A data processing method, performed by a second electronic device, the method comprising: During a voice call with the first electronic device, the second electronic device sends the identification information of the first electronic device to the server; The second electronic device receives a third key sent by the server based on the identification information of the first electronic device and a second association relationship, wherein the second association relationship is the association relationship between the identification information of the first electronic device and the third key; The second electronic device uses the third key to encrypt the first key, generating second encrypted data; The second electronic device transmits the second encrypted data to the first electronic device via a second link, whereby the second link is a communication link between the first electronic device and the second electronic device.
11. A data processing apparatus, the apparatus comprising: The transceiver module is used to receive first encrypted data forwarded by the server through the first link during a voice call with the second electronic device. The first encrypted data is generated by the second electronic device encrypting voice data with a first key. The first link is a data link established between the first electronic device and the second electronic device through the server. The processing module is used to obtain the voice data based on the second key in the first electronic device and the first encrypted data received by the transceiver module; Wherein, the second key is generated by the first electronic device; or, the second key is generated by the second electronic device; In the case where the second key is generated by the second electronic device, the second key is sent from the second electronic device to the first electronic device via the second link, and the second link is the communication link between the first electronic device and the second electronic device.
12. The apparatus according to claim 11, wherein, If the first key and the second key are generated by the second electronic device, the transceiver module is further configured to receive the second key sent by the second electronic device through the second link before receiving the first encrypted data forwarded by the server through the first link; The processing module is further configured to store the second key in the key storage area of the first electronic device.
13. The apparatus according to claim 12, wherein, The first key and the second key are either symmetric keys or asymmetric keys; when the first key and the second key are asymmetric keys, the first key and the second key are respectively the public key and the private key of the asymmetric key; The processing module is specifically used for: The first encrypted data is decrypted using the second key stored in the first electronic device to obtain voice data.
14. The apparatus according to claim 11, wherein, If the first key and the second key are generated by the first electronic device, the processing module is further configured to generate a first key pair before receiving the first encrypted data forwarded by the server through the first link. The first key pair includes the first key and the second key, wherein the first key and the second key are a public key and a private key, respectively. The transceiver module is further configured to send the identification information of the first electronic device and the first key to the server through the second link, so that the server establishes a first association relationship between the identification information of the first electronic device and the first key; The processing module is specifically used for: The first encrypted data is decrypted using the second key to obtain the voice data.
15. The apparatus according to claim 11, wherein, If the first key is generated by the second electronic device and the second key is generated by the first electronic device, the transceiver module is further configured to receive the second encrypted data sent by the second electronic device through the second link before receiving the first encrypted data forwarded by the receiving server through the first link. The second encrypted data is generated by the second electronic device encrypting the first key with a third key. The third key and the second key are respectively the public key and private key in the second key pair pre-stored by the first electronic device. The processing module is specifically used for: The second key is used to decrypt the second encrypted data to obtain the first key; Using the first key, the first encrypted data is decrypted to obtain the voice data.
16. The apparatus according to claim 15, wherein, The processing module is further configured to generate a second key pair before receiving the first encrypted data forwarded by the server through the first link. The second key pair includes a second key and a third key, wherein the second key and the third key are a private key and a public key, respectively. The transceiver module is further configured to send the identification information of the first electronic device and the third key to the server via the second link, so that the server establishes a second association relationship between the identification information of the first electronic device and the third key.
17. The apparatus according to any one of claims 11 to 16, wherein, During a voice call between the first electronic device and the second electronic device, the transceiver module is further configured to: The voice data is received via the second link from the second electronic device.
18. A data processing apparatus, the apparatus comprising: The sending module is used to send the identification information of the first electronic device to the server during a voice call with the first electronic device; The receiving module is used to receive a first key sent by the server based on the identification information of the first electronic device and a first association relationship sent by the sending module, wherein the first association relationship is the association relationship between the identification information of the first electronic device and the first key. The processing module is used to encrypt the voice data using the first key received by the receiving module to generate first encrypted data; The sending module is further configured to send the first encrypted data generated by the processing module to the server via a first link, wherein the first link is a data link established by the first electronic device and the second electronic device through the server.
19. The apparatus according to claim 18, wherein, The receiving module is further configured to receive, after sending the identification information of the first electronic device to the server, the server's verification information sent by the server based on the identification information of the first electronic device; The processing module is specifically used for: If the verification information passes the security verification of the server, the first data is encrypted using the first key to generate the first encrypted data.
20. A data processing apparatus, the apparatus comprising: The sending module is used to send the identification information of the first electronic device to the server during a voice call with the first electronic device; The receiving module is used to receive a third key sent by the server based on the identification information and second association relationship of the first electronic device sent by the sending module, wherein the second association relationship is the association relationship between the identification information of the first electronic device and the third key. The processing module is used to encrypt the first key using the third key to generate second encrypted data; The sending module is further configured to transmit the second encrypted data generated by the processing module to the first electronic device via a second link, wherein the second link is a communication link between the first electronic device and the second electronic device.
21. An electronic device comprising a processor and a memory, the memory storing a program or instructions executable on the processor, the program or instructions, when executed by the processor, implementing the steps of the data processing method as claimed in any one of claims 1 to 7.
22. An electronic device comprising a processor and a memory, the memory storing a program or instructions executable on the processor, the program or instructions, when executed by the processor, implementing the steps of the data processing method as claimed in claim 8 or 9.
23. An electronic device comprising a processor and a memory, the memory storing a program or instructions executable on the processor, the program or instructions, when executed by the processor, implementing the steps of the data processing method of claim 10.