Method, apparatus and system for transmitting data
Abstract
FIELD: information security. SUBSTANCE: invention relates to information security. Method comprises: forming a pair of asymmetric keys comprising a first public key and a first private key, sending a request for data carrying the first public key to a server; receiving the encrypted text and the second public key sent by the server, wherein the second public key is the public key in the asymmetric key pair received by the server, the pair of asymmetric keys received by the server further comprises a second private key, and the encrypted text is information obtained by encrypting the initial parameter to generate an autonomous payment code using the common key; common key is a key formed based on the second private key and the first public key using a predetermined key matching algorithm; and generating a shared key based on the first private key and the second public key using the key negotiation algorithm and using a shared key to decrypt the encrypted text to obtain an initial parameter. EFFECT: ensuring data security during the entire transmission process, as well as high efficiency of encryption and decryption. 14 cl, 9 dwg

Term
11.1 yearsleft in the term
Expires 18 October 2037.
- Priority and filed
- Granted
- Today
- Expires
14 claims: 8 independent, 6 dependent
- 1Способ передачи данных, при этом способ применим в клиенте и содержит этапы, на которых:формируют пару асимметричных ключей, содержащую первый открытый ключ и первый закрытый ключ, и отправляют запрос данных, переносящий первый открытый ключ, на сервер;принимают зашифрованный текст и второй открытый ключ, отправленные сервером, причем второй открытый ключ является открытым ключом в паре асимметричных ключей, полученной сервером, пара асимметричных ключей, полученная сервером, дополнительно содержит второй закрытый ключ, и зашифрованный текст является информацией, полученной путем шифрования начального параметра для формирования кода автономного платежа с использованием общего ключа;общий ключ является ключом, сформированным на основе второго закрытого ключа и первого открытого ключа с использованием предварительно заданного алгоритма согласования ключей;формируют общий ключ на основе первого закрытого ключа и второго открытого ключа с использованием алгоритма согласования ключей и используют общий ключ для дешифрования зашифрованного текста для получения начального параметра;при этом общий ключ, сформированный на основе второго закрытого ключа и первого открытого ключа с использованием предварительно заданного алгоритма согласования ключей, идентичен общему ключу, сформированному на основе первого закрытого ключа и второго открытого ключа с использованием алгоритма согласования ключей.
- 2Способ по п. 1, при этом отправка запроса данных, переносящего первый открытый ключ, на сервер содержит этапы, на которых:используют закрытый ключ в сертификате клиента для подписания первого открытого ключа для получения первой информации подписи, при этом сертификат клиента представляет собой сертификат, выданный уполномоченным учреждением клиенту;отправляют запрос данных, переносящий первый открытый ключ и первую информацию подписи, на сервер, так что сервер использует открытый ключ в сертификате клиента и первый открытый ключ для проверки первой информации подписи, и отправляют зашифрованный текст и второй открытый ключ клиенту, если проверка прошла успешно.
- 3Способ по п. 1 или 2, при этом клиент расположен в носимом устройстве.
- 4Способ по п. 3, при этом носимое устройство содержит умный браслет.
- 5Способ передачи данных, при этом способ применим на сервере и содержит этапы, на которых:принимают запрос данных, переносящий первый открытый ключ и отправленный клиентом, при этом запрос данных предназначен для запроса серверу возвращать начальный параметр для формирования кода автономного платежа, причем первый открытый ключ является открытым ключом в паре асимметричных ключей, сформированной клиентом, и пара асимметричных ключей, сформированная клиентом, дополнительно содержит первый закрытый ключ;получают пару асимметричных ключей, содержащую второй открытый ключ и второй закрытый ключ, и формируют общий ключ на основе второго закрытого ключа и первого открытого ключа с использованием предварительно заданного алгоритма согласования ключей;используют общий ключ для шифрования начального параметра, которому соответствует запрос данных, и отправляют зашифрованный текст, полученный в результате шифрования, и второй открытый ключ клиенту, так что клиент формирует общий ключ на основе первого закрытого ключа и второго открытого ключа, используя алгоритм согласования ключей, и использует общий ключ для дешифрования зашифрованного текста, чтобы получать начальный параметр;при этом общий ключ, сформированный на основе второго закрытого ключа и первого открытого ключа с использованием предварительно заданного алгоритма согласования ключей, идентичен общему ключу, сформированному на основе первого закрытого ключа и второго открытого ключа с использованием алгоритма согласования ключей.
- 6Способ по п. 5, при этом способ дополнительно содержит этапы, на которых:используют закрытый ключ в сертификате сервера для подписи второго открытого ключа для получения второй информации подписи, при этом сертификат сервера является сертификатом, выданным уполномоченным учреждением серверу;при отправке зашифрованного текста, полученного в результате шифрования, и второго открытого ключа клиенту, также отправляют клиенту вторую информацию подписи, так что клиент проверяет вторую информацию подписи на основе открытого ключа в сертификате сервера и второго открытого ключа и дешифрует зашифрованный текст, если проверка прошла успешно.
- 7Способ передачи данных, при этом способ содержит этапы, на которых:терминал запросчика данных формирует пару асимметричных ключей, содержащую первый открытый ключ и первый закрытый ключ, и отправляет запрос данных, переносящий первый открытый ключ, в терминал поставщика данных;терминал поставщика данных получает пару асимметричных ключей, содержащую второй открытый ключ и второй закрытый ключ, и формирует общий ключ на основе второго закрытого ключа и первого открытого ключа с использованием предварительно заданного алгоритма согласования ключей;терминал поставщика данных использует общий ключ для шифрования целевых данных, которым соответствует запрос данных, и отправляет зашифрованный текст, полученный в результате шифрования, и второй открытый ключ в терминал запросчика данных;терминал запросчика данных формирует общий ключ на основе первого закрытого ключа и второго открытого ключа с использованием алгоритма согласования ключей и использует общий ключ для дешифрования зашифрованного текста для получения целевых данных;при этом общий ключ, сформированный на основе второго закрытого ключа и первого открытого ключа с использованием предварительно заданного алгоритма согласования ключей, идентичен общему ключу, сформированному на основе первого закрытого ключа и второго открытого ключа с использованием алгоритма согласования ключей.
- 8Способ по п. 7, при этом отправка запроса данных, переносящего первый открытый ключ, в терминал поставщика данных содержит этапы, на которых:терминал запросчика данных использует закрытый ключ в сертификате запросчика, чтобы подписать первый открытый ключ для получения первой информации подписи, причем сертификат запросчика представляет собой сертификат, выданный уполномоченным учреждением терминалу запросчика данных;терминал запросчика данных отправляет запрос данных, переносящий первый открытый ключ и первую информацию подписи, в терминал поставщика данных;способ дополнительно содержит: терминал поставщика данных проверяет первую информацию подписи на основе открытого ключа в сертификате запросчика и первого открытого ключа, и терминал поставщика данных отправляет зашифрованный текст и второй открытый ключ в терминал запросчика данных, если проверка является успешной.
- 9Способ по п. 7, при этом способ дополнительно содержит этапы, на которых:терминал поставщика данных использует закрытый ключ в сертификате поставщика, чтобы подписать второй открытый ключ для получения второй информации подписи, причем сертификат поставщика является сертификатом, выданным уполномоченным учреждением для терминала поставщика данных;когда терминал поставщика данных отправляет зашифрованный текст, полученный в результате шифрования, и второй открытый ключ в терминал запросчика данных, терминал поставщика данных дополнительно отправляет вторую информацию подписи в терминал запросчика данных;терминал запросчика данных проверяет вторую информацию подписи на основе открытого ключа в сертификате поставщика и второго открытого ключа, а терминал запросчика данных дешифрует зашифрованный текст, если проверка прошла успешно.
- 10Устройство передачи данных, при этом устройство содержит:модуль формирования ключей для формирования пары асимметричных ключей, содержащей первый открытый ключ и первый закрытый ключ;модуль отправки запроса для отправки запроса данных, переносящего первый открытый ключ, на сервер;модуль приема информации для приема зашифрованного текста и второго открытого ключа, отправленных сервером, причем второй открытый ключ является открытым ключом в паре асимметричных ключей, полученной сервером, пара асимметричных ключей, полученная сервером, дополнительно содержит второй закрытый ключ, и зашифрованный текст является информацией, полученной путем шифрования начального параметра для формирования кода автономного платежа с использованием общего ключа;общий ключ является ключом, сформированным на основе второго закрытого ключа и первого открытого ключа с использованием предварительно заданного алгоритма согласования ключей;модуль формирования общего ключа для формирования общего ключа на основе первого закрытого ключа и второго открытого ключа с использованием алгоритма согласования ключей;модуль дешифрования информации для использования общего ключа для дешифрования зашифрованного текста для получения начального параметра;при этом общий ключ, сформированный на основе второго закрытого ключа и первого открытого ключа с использованием предварительно заданного алгоритма согласования ключей, идентичен общему ключу, сформированному на основе первого закрытого ключа и второго открытого ключа с использованием алгоритма согласования ключей.
- 11Устройство передачи данных, при этом устройство содержит:модуль приема запроса для приема запроса данных, переносящего первый открытый ключ и отправленного клиентом, при этом запрос данных предназначен для запроса серверу возвращать начальный параметр для формирования кода автономного платежа, причем первый открытый ключ является открытым ключом в паре асимметричных ключей, сформированной клиентом, и пара асимметричных ключей, сформированная клиентом, дополнительно содержит первый закрытый ключ;модуль получения ключа для получения пары асимметричных ключей, содержащей второй открытый ключ и второй закрытый ключ;модуль формирования общего ключа для формирования общего ключа на основе второго закрытого ключа и первого открытого ключа с использованием предварительно заданного алгоритма согласования ключей;модуль шифрования информации для использования общего ключа для шифрования начального параметра, которому соответствует запрос данных;модуль отправки информации для отправки зашифрованного текста, полученного в результате шифрования, и второго открытого ключа клиенту, так что клиент формирует общий ключ на основе первого закрытого ключа и второго открытого ключа с использованием алгоритма согласования ключей и использует общий ключ, чтобы дешифровать зашифрованный текст, чтобы получать начальный параметр;при этом общий ключ, сформированный на основе второго закрытого ключа и первого открытого ключа с использованием предварительно заданного алгоритма согласования ключей, идентичен общему ключу, сформированному на основе первого закрытого ключа и второго открытого ключа с использованием алгоритма согласования ключей.
- 12Система передачи данных, при этом система содержит устройство запросчика данных и устройство поставщика данных;устройство запросчика данных формирует пару асимметричных ключей, содержащую первый открытый ключ и первый закрытый ключ, и отправляет запрос данных, переносящий первый открытый ключ, в устройство поставщика данных;устройство поставщика данных получает пару асимметричных ключей, содержащую второй открытый ключ и второй закрытый ключ, и формирует общий ключ на основе второго закрытого ключа и первого открытого ключа с использованием предварительно заданного алгоритма согласования ключей;устройство поставщика данных использует общий ключ для шифрования целевых данных, которым соответствует запрос данных, и отправляет зашифрованный текст, полученный в результате шифрования, и второй открытый ключ в устройство запросчика данных;устройство запросчика данных формирует общий ключ на основе первого закрытого ключа и второго открытого ключа с использованием алгоритма согласования ключей и использует общий ключ для дешифрования зашифрованного текста для получения целевых данных;при этом общий ключ, сформированный на основе второго закрытого ключа и первого открытого ключа с использованием предварительно заданного алгоритма согласования ключей, идентичен общему ключу, сформированному на основе первого закрытого ключа и второго открытого ключа с использованием алгоритма согласования ключей.
- 13Способ передачи данных, при этом способ содержит этапы, на которых:терминал запросчика данных формирует первый симметричный ключ и отправляет запрос данных, переносящий первый симметричный ключ, в терминал поставщика данных;терминал поставщика данных получает второй симметричный ключ и формирует общий ключ на основе первого симметричного ключа и второго симметричного ключа с использованием предварительно заданного алгоритма согласования ключей, причем второй симметричный ключ отличается от первого симметричного ключа;терминал поставщика данных использует общий ключ для шифрования целевых данных, которым соответствует запрос данных, и отправляет зашифрованный текст, полученный в результате шифрования, и второй симметричный ключ в терминал запросчика данных;и терминал запросчика данных формирует общий ключ на основе первого симметричного ключа и второго симметричного ключа с использованием алгоритма согласования ключей и использует общий ключ для дешифрования зашифрованного текста для получения целевых данных.
- 14Система передачи данных, при этом система содержит устройство запросчика данных и устройство поставщика данных;устройство запросчика данных формирует первый симметричный ключ и отправляет запрос данных, переносящий первый симметричный ключ, в устройство поставщика данных;устройство поставщика данных получает второй симметричный ключ и формирует общий ключ на основе первого симметричного ключа и второго симметричного ключа с использованием предварительно заданного алгоритма согласования ключей, причем второй симметричный ключ отличается от первого симметричного ключа;устройство поставщика данных использует общий ключ для шифрования целевых данных, которым соответствует запрос данных, и отправляет зашифрованный текст, полученный в результате шифрования, и второй симметричный ключ в устройство запросчика данных;устройство запросчика данных формирует общий ключ на основе первого симметричного ключа и второго симметричного ключа с использованием алгоритма согласования ключей и использует общий ключ для дешифрования зашифрованного текста для получения целевых данных.
Independent claims14
236 paragraphs in 3 sections, as filed
FIELD OF THE INVENTION
2The present application relates to the field of network communication technology, in particular to a method, device and data transmission system.
3State of the art
4Currently, people are increasingly focusing on data security, especially data security during transmission. Taking autonomous payments as an example, the server device can send a strategy for generating payment codes to the client device, and the client device saves the strategy. When a user needs to use a payment code, the client device can use a strategy to generate a payment code. The seller scans the payment code with a scanning device. The scanning device transmits the information obtained as a result of the scan to the server device for verification. After the information is verified, the money is deducted. You can see that in the process, when the server device transmits the strategy to the client device, it is necessary to ensure the security of the channel between the client device and the server device. If the strategy issued by the server device is intercepted by a third-party hacker, the user of the client device will suffer serious losses.
5In the prior art, an identical key can be pre-installed on all client devices and server devices. The server device can use the key to encrypt the transmitted information and transmit the encrypted text to the client device. The client device uses the key to decrypt the ciphertext. However, since all client devices and server devices share the same key, if a client device or server device key leaks, all client devices and server devices will be subject to a security risk.
6In another prior art, a client device can generate a pair of asymmetric keys, store a private key, and upload the public key to the server device. The server device uses the public key to encrypt the information to be transmitted, and transmits the encrypted text to the client device. The client device uses the private key to decrypt the ciphertext. Since the asymmetric key algorithm uses a different random number during each calculation, a different pair of asymmetric keys is generated during each calculation. Consequently, the pairs of asymmetric keys generated by different clients are also different, which allows avoiding security risks for all client devices and server devices as a result of a leak of the key of the client device or server device. Meanwhile, since the encrypted text can only be decrypted using the private key, which corresponds to the public key pair, even if the public key was intercepted during the transmission of the public key, the encrypted text still cannot be decrypted through the public key, which ensures information security. However, the asymmetric key must use a complex encryption algorithm for encryption and a complex decryption algorithm for decryption, so encryption and decryption take a lot of time.
SUMMARY OF THE INVENTION
8This application provides a method, device and data transmission system for solving information security problems and long-term encryption and decryption in modern technologies.
9In accordance with a first aspect of an embodiment of the present application, there is provided a data transmission method, the method being applicable to a client, and comprises:
10generating a pair of asymmetric keys containing the first public key and the first private key, and sending a data request transferring the first public key to the server;
11receiving encrypted text and a second public key sent by the server, the second public key being the public key in the asymmetric key pair received by the server, the asymmetric key pair received by the server further comprises a second private key, and the encrypted text is information obtained by encrypting the initial parameter to generate an offline payment code using a shared key; the shared key is a key generated on the basis of the second private key and the first public key using a predefined key matching algorithm;
12generating a shared key based on the first private key and the second public key using the key matching algorithm and using the shared key to decrypt the encrypted text to obtain the initial parameter;
13Here, the shared key generated from the second private key and the first public key using a predefined key matching algorithm is identical to the shared key based on the first private key and the second public key generated using the key matching algorithm.
14According to a second aspect of an embodiment of the present application, there is provided a data transmission method, the method being applicable on a server and comprising:
15receiving a data request transferring the first public key and sent by the client, the data request is intended to request the server to return the initial parameter for generating an offline payment code, the first public key being the public key in the pair of asymmetric keys generated by the client and the pair of asymmetric keys generated by the client, further comprises a first private key;
16obtaining a pair of asymmetric keys containing a second public key and a second private key, and generating a shared key based on the second private key and the first public key using a predefined key matching algorithm;
17using a public key to encrypt the initial parameter to which the data request corresponds, and sending the encrypted text obtained as a result of the encryption and the second public key to the client, so that the client generates a common key based on the first private key and second public key using a key matching algorithm, and uses a shared key to decrypt the ciphertext to get the initial parameter.
18Here, the shared key generated from the second private key and the first public key using a predefined key matching algorithm is identical to the shared key generated from the first private key and the second public key using the key matching algorithm.
19According to a third aspect of an embodiment of the present application, there is provided a data transmission method that comprises:
20the data interrogator terminal generates a pair of asymmetric keys containing the first public key and the first private key, and sends a data request transferring the first public key to the data provider terminal;
21the data provider terminal receives a pair of asymmetric keys containing a second public key and a second private key, and generates a common key based on the second private key and the first public key using a predefined key matching algorithm;
22the data provider terminal uses a shared key to encrypt the target data to which the data request corresponds, and sends the encrypted text resulting from the encryption and the second public key to the data requestor terminal;
23the data interrogator terminal generates a common key based on the first private key and the second public key using the key matching algorithm and uses the common key to decrypt the encrypted text to obtain the target data;
24Here, the shared key generated from the second private key and the first public key using a predefined key matching algorithm is identical to the shared key generated from the first private key and the second public key using the key matching algorithm.
25According to a fourth aspect of an embodiment of the present application, there is provided a data transmission device, which comprises:
26a key generation module for generating a pair of asymmetric keys comprising a first public key and a first private key;
27a request sending module for sending a data request transferring the first public key to the server;
28an information receiving module for receiving ciphertext and a second public key sent by the server, the second public key being the public key in the pair of asymmetric keys received by the server, the pair of asymmetric keys received by the server further comprises a second private key, and the encrypted text is information received by encrypting the initial parameter to generate an offline payment code using a shared key; the shared key is a key generated on the basis of the second private key and the first public key using a predefined key matching algorithm;
29a shared key generation module for generating a shared key based on a first private key and a second public key using a key matching algorithm; and
30information decryption module for using a common key to decrypt the ciphertext to obtain the initial parameter.
31Here, the shared key generated from the second private key and the first public key using a predefined key matching algorithm is identical to the shared key generated from the first private key and the second public key using the key matching algorithm.
32In accordance with a fifth aspect of an embodiment of the present application, there is provided a data transmission device that comprises:
33a request receiving module for receiving a data request transferring the first public key and sent by the client, the data request is intended to request the server to return the initial parameter for generating an offline payment code, the first public key being the public key in the pair of asymmetric keys generated by the client, and the pair asymmetric keys generated by the client further comprises a first private key;
34a key obtaining module for obtaining a pair of asymmetric keys comprising a second public key and a second private key;
35a shared key generation module for generating a shared key based on the second private key and the first public key using a predefined key matching algorithm;
36an information encryption module for using a common key to encrypt the initial parameter to which the data request corresponds;
37an information sending module for sending the encrypted text obtained as a result of the encryption and the second public key to the client, so that the client generates a common key based on the first private key and the second public key using the key matching algorithm and uses the shared key to decrypt the encrypted text so that get the initial parameter;
38Here, the shared key generated from the second private key and the first public key using a predefined key matching algorithm is identical to the shared key generated from the first private key and the second public key using the key matching algorithm.
39According to a sixth aspect of an embodiment of the present application, there is provided a data communication system that comprises a data interrogator device and a data provider device;
40The data interrogator device generates a pair of asymmetric keys containing the first public key and the first private key, and sends a data request transferring the first public key to the data provider device;
41The data provider device receives an asymmetric key pair containing a second public key and a second private key, and generates a shared key based on the second private key and the first public key using a predefined key matching algorithm;
42The data provider device uses a shared key to encrypt the target data to which the data request corresponds, and sends the encrypted text resulting from the encryption and the second public key to the data requestor device;
43The data interrogator device generates a shared key based on the first private key and second public key using the key matching algorithm and uses the shared key to decrypt the encrypted text to obtain the target data;
44Here, the shared key generated from the second private key and the first public key using a predefined key matching algorithm is identical to the shared key generated from the first private key and the second public key using the key matching algorithm.
45According to a seventh aspect of an embodiment of the present application, there is provided a data transmission method that comprises:
46the data interrogator terminal generates a first symmetric key and sends a data request carrying the first symmetric key to the data provider terminal;
47the data provider terminal receives a second symmetric key and generates a common key based on the first symmetric key and the second symmetric key using a predefined key matching algorithm, the second symmetric key being different from the first symmetric key;
48the data provider terminal uses a shared key to encrypt the target data to which the data request corresponds, and sends the encrypted text resulting from the encryption and the second symmetric key to the data requestor terminal;
49the data interrogator terminal generates a common key based on the first symmetric key and the second symmetric key using the key matching algorithm and uses the common key to decrypt the encrypted text to obtain the target data.
50According to an eighth aspect of an embodiment of the present application, a data communication system is provided and comprises: a data interrogator device and a data provider device;
51the data interrogator device generates a first symmetric key and sends a data request transferring the first symmetric key to the data provider device;
52the data provider device receives a second symmetric key and generates a common key based on the first symmetric key and the second symmetric key using a predefined key matching algorithm, the second symmetric key being different from the first symmetric key;
53the data provider device uses a common key to encrypt the target data to which the data request corresponds, and sends the encrypted text obtained as a result of the encryption and the second symmetric key to the data requestor device;
54the data interrogator device generates a common key based on the first symmetric key and the second symmetric key using the key matching algorithm and uses the common key to decrypt the encrypted text to obtain the target data.
55During the application of the method, device and data transmission system provided for in the embodiments of the present application, a pair of asymmetric keys containing a first public key and a first private key can be generated through a data interrogator terminal, and a data request carrying the first public key is sent to a data provider terminal, a pair of asymmetric keys containing a second public key and a second private key is obtained through the data provider terminal, the shared key is generated based on the second private key and the first public key using a predefined key matching algorithm, then the shared key is used to encrypt the target data to which the data request corresponds, and finally, the encrypted text obtained from the encryption and the second public key are transmitted to the data interrogator terminal, and the data interrogator terminal generates a common key based on the first private key and the second public key using the same key matching algorithm. Since the shared key generated from the second private key and the first public key using the predefined key matching algorithm is identical to the shared key generated from the first private key and the second public key using the key matching algorithm, the data provider terminal can use the shared key to encryption, and the data interrogator terminal may use a common key for decryption. Since the key to encrypt the target data and the key to decrypt the target data are identical, symmetric encryption and decryption algorithms can be used to encrypt and decrypt the data. Since the symmetric encryption algorithm usually performs encryption using tools such as a shift cipher, while the asymmetric encryption algorithm performs encryption in ways such as finding large primes, you can see that the encryption process of the symmetric encryption algorithm is simpler than the encryption process of the asymmetric algorithm encryption. Therefore, this embodiment may not allow the disadvantage of a long encryption and decryption time resulting from complex asymmetric encryption and decryption algorithms, and increase the efficiency of encryption and decryption. In addition, since the full key is not disclosed during the entire transfer process, it does not make sense even if the public key is cracked by a hacker, which ensures data security throughout the entire transfer process.
56During the application of the method, device and data transmission system provided for in the embodiments of the present application, the first symmetric key can be received through the data interrogator terminal, the data request transferring the first symmetric key is sent to the data provider terminal, the second symmetric key is obtained through the supplier terminal data the shared key is generated on the basis of the first symmetric key and the second symmetric key using a predefined key matching algorithm, the shared key is used to encrypt the target data to which the data request corresponds and, finally, the encrypted text obtained from the encryption and the second symmetric key are transmitted to the terminal data interrogator and the data interrogator terminal uses the same key matching algorithm to generate a common key based on the first symmetric key and the second symmetric key. Since the data provider terminal and the data interrogator terminal use the same key matching algorithm, the common key generated by the data provider terminal and the common key generated by the data interrogator terminal can be used to decrypt the encrypted text through the generated common key, thereby obtaining target data. You can see that, since the shared key is different from the first symmetric key and the second symmetric key, even if the hacker stole the symmetric key, the hacker will not know which key matching algorithm the current application used, so the hacker cannot decrypt the encrypted text, thereby ensuring security data throughout the transfer process. In addition, since the encryption key of the target data and the decryption key of the target data are identical, symmetric key encryption and decryption algorithms are used to encrypt and decrypt the data in order to avoid long encryption and decryption times resulting from complex asymmetric encryption and decryption algorithms, thereby improving the efficiency of encryption and decryption.
57It should be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and cannot limit the present application.
58Brief Description of the Drawings
59The accompanying drawings are here included in the description and form part of it, show the implementation options corresponding to this application, and are used together with the description to explain the principles of this application.
60FIG. 1A is a schematic diagram of an application data transfer scenario provided by an exemplary embodiment of the present application.
61FIG. 1B is a flowchart of an embodiment of a data communication method provided by the present application.
62FIG. 2 is a flowchart of another embodiment of a data transmission method provided by the present application.
63FIG. 3 is a flowchart of another embodiment of a data transmission method provided by the present application.
64FIG. 4 is a block diagram of an embodiment of a data communication system provided by this application.
65FIG. 5 is a block diagram of an embodiment of a data communication device provided by this application.
66FIG. 6 is a block diagram of another embodiment of a data communication device provided by this application.
67FIG. 7 is a flowchart of another embodiment of a data transmission method provided by the present application.
68FIG. 8 is a block diagram of another embodiment of a data communication system provided by this application.
DETAILED DESCRIPTION OF THE INVENTION
70Here, exemplary embodiments will be described in detail with examples shown in the accompanying drawings. When the description below includes the accompanying drawings, unless otherwise indicated, the same position in the various accompanying drawings denotes the same or similar element. The implementation methods described in the following exemplary embodiments do not represent all implementation methods consistent with this application. Conversely, they are only examples of the device and method, described in detail in the attached claims and consistent with some aspects of the present application.
71The terms used in this application are intended only to describe exemplary embodiments and are not intended to limit the present application. The singular forms “one,” “this,” and “this,” as used in this application and in the appended claims, are also intended to encompass the plural forms unless their meanings are clearly indicated in context. It should also be understood that the term "and / or" used in the text refers to any or all possible combinations containing one or many related listed elements.
72It should be understood that although terms such as the first, second, and third may be used in this application to describe various types of information, information should not be limited to these terms. These terms are intended only to differentiate information of one type. For example, without departing from the scope of this application, the first information may also be referred to as second information, and similarly, the second information may also be referred to as first information. Depending on the context, the term “if” as used here may be interpreted as “during ...”, “when ...” or “in response to a definition”.
73People are increasingly focusing on data security, especially data security during transmission. As shown in FIG. 1A, FIG. 1A is a schematic diagram of an application data transfer scenario provided by an exemplary embodiment of the present application. In this concept, data can be transferred between various client devices and server devices. For example, the client device sends a data request to the server device, and the server device returns the corresponding target data in accordance with the data request. During the transfer process, hackers can intercept target data that is transmitted, resulting in loss for users.
74To ensure data security during transmission, the same key can be pre-installed on all client devices and server devices. The server device can use the key to encrypt the transmitted information and transmit the encrypted text to the client device. The client device uses the key to decrypt the ciphertext. However, since all client devices and server devices share the same key, if a client device or server device key leaks, all client devices and server devices will be subject to a security risk. To avoid this circumstance, in another prior art, the client device can generate a pair of asymmetric keys, store the private key and load the public key into the server device. The server device uses the public key to encrypt the information to be transmitted, and transmits the encrypted text to the client device. The client device uses the private key to decrypt the ciphertext. Since the asymmetric key algorithm uses a different random number during each calculation, a different pair of asymmetric keys is generated during each calculation. Consequently, the pairs of asymmetric keys generated by different clients are also different, which allows avoiding security risks for all client devices and server devices as a result of a leak of the key of the client device or server device. Meanwhile, since the encrypted text can only be decrypted using the private key, which corresponds to the public key pair, even if the public key was intercepted during the transmission of the public key, the encrypted text still cannot be decrypted through the public key, which ensures information security. However, the asymmetric key must use a complex encryption algorithm for encryption and a complex decryption algorithm for decryption, so encryption and decryption take a lot of time.
75In order to avoid the problems of information security in modern technologies and the time-consuming encryption and decryption problems, the present application provides a method for transmitting data, as shown in FIG. 1B. FIG. 1B is a flowchart of an embodiment of a data communication method provided by the present application. This method may include the following steps 101-108:
76At step 101, the data interrogator terminal generates a pair of asymmetric keys containing the first public key and the first private key.
77At step 102, the data interrogator terminal sends a data request carrying the first public key to the data provider terminal.
78At step 103, the data provider terminal receives a pair of asymmetric keys containing a second public key and a second private key.
79At 104, the data provider terminal generates a shared key based on the second private key and the first public key using a predefined key matching algorithm.
80At step 105, the data provider terminal uses a shared key to encrypt the target data to which the data request corresponds.
81At step 106, the data provider terminal sends the encrypted text obtained from the encryption and the second public key to the data interrogator terminal.
82At step 107, the data interrogator terminal generates a shared key based on the first private key and second public key using a key matching algorithm.
83At step 108, the data interrogator terminal uses a shared key to decrypt the ciphertext to obtain the target data.
84Here, the data interrogator terminal is a data requesting terminal, and the data provider terminal is a data providing terminal. In one example, the data requestor terminal may be a client, the data provider terminal may be a server, and the client requests the server to return the target data. Taking as an example the target data, which is the initial parameter for generating the offline payment code, the data request can be a request for the activation of an offline payment, the data requester terminal is a client, and the data provider terminal is a server. The client sends a request to activate an offline payment to the server, and the server returns the initial parameter to the client in accordance with the request. In another example, the server may also request data from the client, and thus, the data interrogator terminal may be a server, and the data provider terminal may be a client. There are no restrictions.
85From the above embodiment, it can be seen that a pair of asymmetric keys containing a first public key and a first private key can be generated through a data interrogator terminal, wherein a data request carrying a first public key is sent to a data provider terminal, an asymmetric key pair containing a second public a key and a second private key, obtained through the terminal of the data provider, the shared key is generated based on the second private key and the first public key using a predefined key matching algorithm, then the shared key is used to encrypt the target data to which the data request corresponds, and finally, the encrypted text obtained from the encryption and the second public key are transmitted to the data interrogator terminal, and the data interrogator terminal generates a common key based on the first private key and the second public key using the same key matching algorithm. Since the shared key generated from the second private key and the first public key using the predefined key matching algorithm is identical to the shared key generated from the first private key and the second public key using the key matching algorithm, the data provider terminal can use the shared key to encryption, and the data interrogator terminal may use a common key for decryption. Since the key to encrypt the target data and the key to decrypt the target data are identical, symmetric encryption and decryption algorithms can be used to encrypt and decrypt the data. Since the symmetric encryption algorithm usually performs encryption using tools such as a shift cipher, while the asymmetric encryption algorithm performs encryption in a way such as finding large primes, you can see that the encryption process of the symmetric encryption algorithm is simpler than the encryption process of the asymmetric algorithm encryption. Therefore, this embodiment may not allow the disadvantage of a long encryption and decryption time resulting from complex asymmetric encryption and decryption algorithms, and increase the efficiency of encryption and decryption. Since a different random number is used each time, a different pair of asymmetric keys is generated each time. Consequently, the pairs of asymmetric keys generated by different clients are also different, which allows avoiding security risks for all client devices and server devices as a result of a leak of the key of the client device or server device. In addition, since the full key is not disclosed during the entire transfer process, it does not make sense even if the public key is cracked by a hacker, which ensures data security throughout the entire transfer process.
86There is no specific time limit for generating a pair of asymmetric keys containing the first public key and the first private key. For example, a pair of asymmetric keys may be generated before each transmission of a data request. As another example, an asymmetric key pair can be generated at a time other than the time immediately before sending the data request, for example, when other conditions are met, so that a previously generated asymmetric key pair can be received when the data request is to be sent. For example, a pair of asymmetric keys can be formed at set intervals, and each newly formed pair of asymmetric keys replaces a previously generated pair of asymmetric keys.
87In the example, the first public key and the first private key may be a pair of asymmetric keys generated using the key generation algorithm. Before sending a data request, the data interrogator terminal uses a key generation algorithm each time to generate a pair of asymmetric keys containing the first public key and the first private key. Since the pair of asymmetric keys generated by the asymmetric key algorithm is different each time under normal conditions, this may prevent the leakage of the key pair stored in a fixed manner, as a result of which all subsequent information encrypted using the key pair will be insecure.
88After the data interrogator terminal receives the first public key and the first private key, the data interrogator terminal can send a data request carrying the first public key to the data provider terminal. Here, the data request is a request for target data.
89In one example, the data requestor terminal may directly include the first public key in the data request, thereby increasing the speed of sending the data request.
90In another example, sending a data request carrying the first public key to a data provider terminal contains:
91the data interrogator terminal uses the private key in the interrogator certificate to sign the first public key to obtain the first signature information. Interrogator certificate is a certificate issued by an authorized institution to a data interrogator terminal.
92The data requestor terminal sends a data request transferring the first public key and the first signature information to the data provider terminal.
93The method further comprises the following steps: the data provider terminal verifies the first signature information based on the public key in the interrogator certificate and the first public key. If the verification is successful, the data provider terminal will send the encrypted text and the second public key to the data interrogator terminal.
94Here, an authorized institution usually refers to an institution that is authorized and can issue certificates. The certificate issued by the authorized institution for the data interrogator terminal contains at least a private key and a public key. In other words, the requester certificate contains a private key and a public key.
95As one way of signing, the data interrogator terminal may use a hash algorithm to perform hashing operations with the first public key to obtain the first brief description of the information, use the private key in the requestor's certificate to encrypt the first brief description of the information to obtain the first signature information, then generate a data request carrying the first public key and the first signature information based on the first signature information, and send a data request to the terminal of the data provider.
96After the data provider terminal receives the data request, the data provider terminal can verify the first signature information based on the public key in the interrogator certificate and the first public key. If the verification is successful, the encrypted text and the second public key will be sent to the terminal of the data provider.
97Here, the data provider terminal can receive the public key in the interrogator certificate in the following way: the data interrogator terminal transmits it to the data provider terminal in advance, or the data interrogator terminal sends it to the data provider terminal when sending the data request.
98As one of the verification methods, the data provider terminal may use a hash algorithm to perform hashing operations on the first public key received in order to obtain a second brief description of the information, use the public key in the requestor's certificate to decrypt the first signature information, in order to receive the first brief description of the information, and check whether the first brief description of the information corresponds to the second brief description of the information. If they match, it means that the check was successful. The terminal of the data provider can perform the operation of sending the ciphertext and the second public key to the terminal of the data interrogator only after a successful verification.
99From the above embodiment, it can be seen that signing the first public key and successfully validating the first signature information can ensure that the first public key is not tampered with, and at the same time, the interrogator certificate ensures that the data interrogator terminal is a secure terminal authenticated by an authorized institution, thereby ensuring the security of the common key negotiation process.
100After the data provider terminal receives the data request, the data provider terminal may receive a pair of asymmetric keys containing a second public key and a second private key. Here, the second public key and the second private key may be a pair of keys generated using a key generation algorithm. You can see that the pair of asymmetric keys containing the first public key and the first private key, and the pair of asymmetric keys containing the second public key and the second private key are formed by the identical key generation algorithm. Since the key generation algorithm uses a different random number during each calculation, the pairs of asymmetric keys generated during the calculation at different times will almost always be different. Therefore, the pair of asymmetric keys generated by the data interrogator terminal is different from the pair of asymmetric keys generated by the data provider terminal under normal circumstances.
101There is no specific time limit for generating a pair of asymmetric keys containing a second public key and a second private key. For example, a pair of asymmetric keys may be generated each time a data request is received. As another example, a pair of asymmetric keys may not be generated when a data request is received, but when other conditions are satisfied, so that a previously generated pair of asymmetric keys can be obtained when a data request is received. For example, a pair of asymmetric keys can be formed at set intervals, and each newly formed pair of asymmetric keys replaces a previously generated pair of asymmetric keys.
102For example, when a data request is received, the data provider terminal uses a key generation algorithm each time to generate a pair of asymmetric keys containing a second public key and a second private key. Since the pair of asymmetric keys generated by the asymmetric key algorithm is different each time under normal conditions, this may prevent the leakage of the key pair stored in a fixed manner, as a result of which all subsequent information encrypted using the key pair will be insecure.
103After the data provider terminal receives a pair of asymmetric keys containing the second public key and the second private key, the data provider terminal can generate a common key based on the second private key and the first public key using a predefined key matching algorithm. Subsequently, the data interrogator terminal will generate a shared key based on the first private key and the second public key using a key matching algorithm.
104A key matching algorithm, also known as a key exchange algorithm, may be, for example, an ECDH algorithm. Here ECDH is a DH (Diffie-Hellman) key exchange algorithm based on ECC (elliptic curve cryptosystems). Thus, both parties can agree to receive a common key without transmitting any secret information.
105In this embodiment, the shared key generated from the second private key and the first public key using a predefined key matching algorithm is identical to the shared key generated from the first private key and the second public key using the key matching algorithm. As one implementation method, the key matching algorithms used by the data provider terminal and the data interrogator terminal are identical, the key generation algorithms used by the data provider terminal and the data interrogator terminal are also identical, and the key matching algorithm and the key generation algorithm satisfy the following condition: for any two pairs of asymmetric keys generated using the key generation algorithm, when the public key of either of the two pairs of asymmetric keys and the private key of the other pair of asymmetric keys are selected, the matching results obtained using the key matching algorithm are identical.
106You can see that since the first public key is usually not equal to the second public key, and the first private key is usually not equal to the second private key, it is impossible to derive the first private key from the first public key or to derive the second private key from the second public key, and the public key, matched from the first private key and the second public key, identical to the shared key matched from the second private key and the first public key, the full key is not disclosed at any time during the entire transfer process, and data security is ensured throughout the transfer process. In addition, since the encryption key of the target data and the decryption key of the target data are identical, the symmetric key encryption and decryption algorithms are used to encrypt and decrypt the data in order to prevent a long encryption and decryption time resulting from complex asymmetric encryption and decryption algorithms. best improving the efficiency of encryption and decryption.
107After the data provider terminal generates a shared key, the data provider terminal can use the shared key to encrypt the target data that the data request corresponds to and send the encrypted text resulting from the encryption and the second public key to the data requestor terminal.
108In one example, a data provider terminal may directly send a second public key to a data requestor terminal to increase sending efficiency.
109In another example, the method further comprises:
110the data provider terminal uses the private key in the provider certificate to sign the second public key in order to receive the second signature information. A vendor certificate is a certificate issued by an authorized institution for a data provider terminal.
111When the data provider terminal sends the encrypted text obtained from the encryption and the second public key to the data interrogator terminal, the data provider terminal further sends the second signature information to the data interrogator terminal.
112The data requester terminal verifies the second signature information based on the public key in the provider certificate and the second public key. If the verification is successful, the data interrogator terminal will decrypt the encrypted text.
113Here, an authorized institution may be an institution that can issue certificates. The certificate issued by the authorized institution to the data provider terminal contains at least a private key and a public key. In other words, the vendor certificate contains a private key and a public key.
114As one signing method, the data provider terminal may use a hash algorithm to perform hashing operations on the second public key to obtain a third brief description of the information, use the private key in the provider's certificate to encrypt the third brief description of the information to obtain the second signature information, and then send the encrypted text, the second public key and the second signature information to the data requestor terminal.
115The data requester terminal verifies the second signature information based on the public key in the provider certificate and the second public key. If the verification is successful, the data interrogator terminal will decrypt the encrypted text.
116Here, the data interrogator terminal can receive the public key in the provider certificate in the following way: the data provider terminal transmits it to the data interrogator terminal in advance, or the data provider terminal sends it to the data interrogator terminal when sending encrypted text and the second public key.
117As one of the verification methods, the data interrogator terminal can use the hashing algorithm to perform hashing operations on the received second public key to obtain the fourth brief description of the information, use the public key in the supplier’s certificate to decrypt the second signature information to obtain the third brief description of the information and verify that whether a third summary of information is a fourth summary of information. If they match, it means that the check was successful. The data requestor terminal can perform the operation of decrypting the ciphertext only after successful verification.
118From the above embodiment, it can be seen that signing the second public key and successfully validating the second signature information can ensure that the second public key is not tampered with, and at the same time, the vendor certificate ensures that the data provider terminal is a secure terminal authenticated by an authorized institution, thereby ensuring the security of the common key negotiation process.
119As shown in FIG. 2, FIG. 2 is a flowchart of another embodiment of a data transmission method provided by the present application. An embodiment employs a data transmission method for transmitting an initial parameter. The method is applicable in the client and may contain the following steps 201-203:
120At step 201, a pair of asymmetric keys is generated containing the first public key and the first private key, and a data request is sent, transferring the first public key, to the server.
121Here, there is no need to set a specific time limit for the formation of a pair of asymmetric keys containing the first public key and the first private key. For example, a pair of asymmetric keys may be generated before each transmission of a data request. As another example, a pair of asymmetric keys can be generated not at the moment immediately before sending a data request, but when other conditions are met, so that a previously generated pair of asymmetric keys can be obtained when sending a data request. For example, a pair of asymmetric keys can be formed at set intervals, and each newly formed pair of asymmetric keys replaces a previously generated pair of asymmetric keys.
122For example, the first public key and the first private key may be a pair of asymmetric keys generated using a key generation algorithm. Before sending a data request, the client uses the key generation algorithm each time to generate a pair of asymmetric keys containing the first public key and the first private key. Since the pair of asymmetric keys generated by the asymmetric key algorithm is different each time under normal conditions, this may prevent the leakage of the key pair stored in a fixed manner, as a result of which all subsequent information encrypted using the key pair will be insecure.
123After receiving the first public key and the first private key, a data request carrying the first public key can be sent to the server. Here, the data request is intended to request from the server the return of the initial parameter for generating the offline payment code.
124In one example, the first public key can be directly transmitted in the data request, thereby increasing the speed of sending the data request.
125In another example, sending a data request that transfers the first public key to the server contains:
126use of the private key in the client certificate for signing the first public key to obtain the first signature information, while the client certificate is a certificate issued by an authorized institution to the client;
127sending a data request transferring the first public key and the first signature information to the server, so that the server uses the public key in the client certificate and the first public key to verify the first signature information, and sending the encrypted text and the second public key to the client if the verification was successful.
128Here, an authorized institution may be an institution that can issue certificates. A certificate issued by an authorized institution to a client contains at least a private key and a public key. In other words, the client certificate contains a private key and a public key. The server can receive the public key in the client certificate in the following way: the client sends it to the server in advance or the client sends it to the server during the sending of the data request.
129The present embodiment may use the private key in the client certificate to sign the first public key. For example, a client can use a hash algorithm to perform hash operations with the first public key to obtain the first brief description of the information, use the private key in the client’s certificate to encrypt the first brief description of the information, to receive the first signature information, and then send a data request transferring first public key and first signature information in the data provider terminal.
130From the above embodiment, it can be seen that signing the first public key facilitates the server to verify the first signature information, successful verification can ensure that the first public key is not tampered with, and at the same time, the client certificate ensures that the client is a secure terminal authenticated by an authorized institution, thereby ensuring the security of the common key negotiation process.
131At step 202, the encrypted text and the second public key sent by the server are received, the second public key being the public key in the pair of asymmetric keys received by the server, the pair of asymmetric keys received by the server further comprises a second private key, and the encrypted text is information received by encrypting the initial parameter to generate an offline payment code using a shared key; the shared key is a key generated from the second private key and the first public key using a predefined key matching algorithm. At step 203, a shared key is generated based on the first private key and the second public key using the key matching algorithm, and the shared key is used to decrypt the ciphertext and obtain the initial parameter.
132Here, a key matching algorithm, also known as a key exchange algorithm, may be, for example, an ECDH algorithm in which ECDH is a DH (Diffie-Hellman) key exchange algorithm based on ECC (elliptic curve cryptosystems). Therefore, both parties can agree on a common key without transmitting any secret information.
133In this embodiment, the shared key generated from the second private key and the first public key using a predefined key matching algorithm is identical to the shared key generated from the first private key and the second public key using the key matching algorithm. As one implementation method, the key matching algorithms used by the data provider terminal and the data interrogator terminal are identical, the key generation algorithms used by the data provider terminal and the data interrogator terminal are also identical, and the key matching algorithm and the key generation algorithm satisfy the following condition : for any two pairs of asymmetric keys generated using the key generation algorithm, when the public key of either of the two pairs of asymmetric keys and the private key of the other pair of asymmetric keys are selected, the matching results obtained using the key matching algorithm are identical.
134You can see that since the first public key is usually not equal to the second public key, and the first private key is usually not equal to the second private key, it is impossible to derive the first private key from the first public key or to derive the second private key from the second public key, and the public key, matched from the first private key and the second public key, identical to the shared key matched from the second private key and the first public key, the full key is not disclosed at any time during the entire transfer process, and data security is ensured throughout the transfer process. In addition, since the key for encrypting the initial parameter and the key for decrypting the initial parameter are identical, the encryption and decryption algorithms with a symmetric key are used to encrypt and decrypt the initial parameter in order to prevent long encryption and decryption arising due to complex asymmetric encryption algorithms and decryption, which increases the efficiency of encryption and decryption.
135In an optional implementation method, the client may reside in an electronic device, in particular in a wearable device. Since the wearable device often has configurations corresponding to relatively low performance, when this solution is used in a wearable device, symmetric encryption and decryption algorithms are not very resource intensive. Ensuring transmission security, this solution significantly improves productivity and improves the efficiency of the entire transmission process. In addition, the wearable device may include a smart bracelet. The implementation of this option with a smart bracelet can not only guarantee the safety of the transmission of the initial parameter, but also ensure the efficiency of the entire transfer process.
136For example, the method in the embodiment can be performed through a secure element (SE), which allows you to generate an asymmetric key, generate a common key and decrypt the encrypted text that must be executed in SE. In addition, the initial parameter can also be stored in SE. Since the SE has an anti-hack function, the SE can provide an initial parameter with a very high level of security.
137In addition, the initial parameter can be stored in SE, and at the same time, the access rights for SE can be set, with control of the formation of the payment code by fingerprint recognition, heart rate recognition, face recognition or other verification methods, thereby providing a complete payment code with a very high level of security.
138As shown in FIG. 3, FIG. 3 is a flowchart of another embodiment of a data transmission method provided by the present application. An embodiment uses a data transmission method for transmitting an initial parameter. When the method is used on the server, it may comprise the following steps 301-303:
139At step 301, a data request is received that transfers the first public key and sent by the client, the data request is intended to request the server to return the initial parameter for generating the offline payment code, the first public key is the public key in the pair of asymmetric keys generated by the client, and a pair of asymmetric keys, generated by the client further comprises a first private key.
140Here, when the data request is accepted, if the data request contains only the first public key, step 302 can be performed directly; if the data request contains the first public key and the first signature information, the first signature information is checked based on the public key in the client certificate and the first public key, and step 302 is performed only after successful verification.
141The server can receive the public key in the client certificate in the following way: the client sends it to the server in advance or the client sends it to the server during the sending of the data request.
142As one of the verification methods, the server can use the hashing algorithm to perform hashing operations with the first public key received in order to receive a second brief description of the information, use the public key in the client certificate to decrypt the first signature information, to receive the first brief description of the information and verify whether the first brief description of the information corresponds to the second brief description of the information. If they match, it means that the check was successful. Subsequently, the server will return the encrypted text and the second key to the client.
143At step 302, a pair of asymmetric keys is obtained containing the second public key and the second private key, and a common key is generated based on the second private key and the first public key using a predefined key matching algorithm.
144At step 303, a shared key is used to encrypt the initial parameter to which the data request corresponds, and the encrypted text resulting from the encryption and the second public key are sent to the client, so that the client generates a shared key based on the first private key and second public key using the algorithm key negotiation, and uses a common key to decrypt the ciphertext and get the initial parameter.
145There is no need to set specific time limits for the formation of a pair of asymmetric keys containing a second public key and a second private key. For example, a pair of asymmetric keys may be generated each time a data request is received. As another example, a pair of asymmetric keys may not be generated at the moment when a data request is received, but when other conditions are satisfied, so that a previously generated pair of asymmetric keys can be obtained when a data request is received. For example, a pair of asymmetric keys can be formed at set intervals, and each newly formed pair of asymmetric keys replaces a previously generated pair of asymmetric keys.
146For example, the second public key and the second private key may be a key pair generated using a key generation algorithm. For example, when a data request is received, the server uses a key generation algorithm each time to generate a pair of asymmetric keys containing a second public key and a second private key. Since the pair of asymmetric keys generated by the asymmetric key algorithm is different each time under normal conditions, this may prevent the leakage of the key pair stored in a fixed manner, as a result of which all subsequent information encrypted using the key pair will be insecure.
147Here, a pair of asymmetric keys containing a first public key and a first private key, and a pair of asymmetric keys containing a second public key and a second private key are generated by the identical key generation algorithm. Since the key generation algorithm uses a different random number during each calculation, the pairs of asymmetric keys generated during the calculation at different times may look different. Therefore, the pair of asymmetric keys generated by the client is different from the pair of asymmetric keys generated by the server under normal conditions.
148After the server receives the second public key and the second private key, the server can generate a shared key based on the second private key and the first public key using a predefined key matching algorithm.
149A key matching algorithm, also known as a key exchange algorithm, may be, for example, an ECDH algorithm in which ECDH is a DH (Diffie-Hellman) key exchange algorithm based on ECC (elliptic curve cryptosystems). Therefore, both parties can agree on a common key without transmitting any secret information.
150In this embodiment, the shared key generated from the second private key and the first public key using a predefined key matching algorithm is identical to the shared key generated from the first private key and the second public key using the key matching algorithm. As one implementation method, the key matching algorithms used by the data provider terminal and the data interrogator terminal are identical, the key generation algorithms used by the data provider terminal and the data interrogator terminal are also identical, and the key matching algorithm and the key generation algorithm satisfy the following condition: for any two pairs of asymmetric keys generated using the key generation algorithm, when the public key of either of the two pairs of asymmetric keys and the private key of the other pair of asymmetric keys are selected, the matching results obtained using the key matching algorithm are identical.
151P donkey as the server receives the common key, the server may use a shared key to encrypt the initial setting, which corresponds to the data request, and send encrypted text resulting from encryption and a second public key of the client. The initial parameter is the initial parameter for generating the offline payment code. After the server receives the data request, the server can receive the initial parameter in accordance with the data request. The initial parameters that customers correspond to may be the same or different, depending on actual requirements.
152As for sending the second public key, in one example, the second public key can be directly sent to the client to increase the sending speed.
153In another example, the method further comprises:
154using the private key in the server certificate to sign the second public key to obtain the second signature information. A server certificate is a certificate issued by an authorized institution to a server.
155When sending the encrypted text resulting from the encryption and the second public key to the client, the second signature information is also sent to the client, so that the client checks the second signature information based on the public key in the server certificate and the second public key. If the check is successful, the client decrypts the encrypted text.
156Here, an authorized institution may be an institution that can issue certificates. The certificate issued by an authorized institution to the server contains at least a private key and a public key. In other words, the server certificate contains a private key and a public key. The client can receive the public key in the server certificate in the following way: the server sends it to the client in advance or the server sends it to the client when sending encrypted text and the second public key.
157As one signature method, the server can use the hash algorithm to perform hashing operations on the second public key to obtain a third brief description of the information, use the private key in the server certificate to encrypt the third brief description of the information, to receive the second signature information, and then send the encrypted text, a second public key and second signature information to the client.
158The client can verify the second signature information based on the public key in the server certificate and the second public key. If successful, the client decrypts the encrypted text.
159As one of the verification methods, the client can use the hash algorithm to perform hashing operations on the second public key to obtain the fourth brief description of the information, use the public key in the server certificate to decrypt the second signature information to obtain the third brief description of the information and check whether the third short description of information to the fourth brief description of information. If they match, it means that the check was successful. The client can perform the operation of decrypting the ciphertext only after successful verification.
160From the above embodiment, it can be seen that signing the second public key and successfully validating the second signature information can ensure that the second public key is not tampered with, and at the same time, the server certificate ensures that the server is a secure party authenticated by an authorized institution, thereby ensuring security of the common key negotiation process.
161According to an embodiment of the data transmission method provided by this application, this application further provides embodiments of a data transmission device and a data transmission system.
162Turning to FIG. 4. This is a block diagram of an embodiment of a data communication system provided by this application:
163The system 40 comprises a data interrogator device 41 and a data provider device 42.
164The data interrogator device 41 generates an asymmetric key pair containing the first public key and the first private key, and sends a data request transferring the first public key to the data provider device 42.
165The data provider device 42 receives an asymmetric key pair containing a second public key and a second private key, and generates a shared key based on the second private key and the first public key using a predefined key matching algorithm.
166The data provider device 42 uses a shared key to encrypt the target data to which the data request corresponds, and sends the encrypted text resulting from the encryption and the second public key to the data interrogator device 41.
167The data interrogator device 41 generates a shared key based on the first private key and the second public key using a key matching algorithm and uses the shared key to decrypt the encrypted text to obtain the target data.
168Here, the shared key generated from the second private key and the first public key using a predefined key matching algorithm is identical to the shared key generated from the first private key and the second public key using the key matching algorithm.
169In an optional implementation method, the data interrogator device 41 uses the private key in the interrogator certificate to sign the first public key to receive the first signature information, and sends a data request transferring the first public key and first signature information to the data provider device 42. An interrogator certificate is a certificate issued by an authorized institution for a data interrogator device.
170Before the data provider device 42 returns the encrypted text and the second public key to the data interrogator device 41, the data provider device 42 verifies the first signature information based on the public key in the interrogator certificate and the first public key and determines that the verification is successful.
171In an optional implementation method, the data provider device 42 uses the private key in the provider certificate to sign the second public key in order to receive the second signature information. When the encrypted text resulting from the encryption and the second public key are sent to the data interrogator device 41, the data provider device 42 also sends the second signature information to the data interrogator device 41; a vendor certificate is a certificate issued by an authorized agency for a data provider device 42.
172Before the data interrogator device 41 decrypts the encrypted text, the data interrogator device 41 verifies the second signature information based on the public key in the supplier’s certificate and the second public key and determines that the verification was successful.
173Turning to FIG. 5. This is a block diagram of an embodiment of a data communication device provided by this application:
174The device comprises: a key generation module 51, a request sending module 52, an information receiving module 53, a shared key generation module 54, and information decryption module 55.
175The key generation module 51 is for generating a pair of asymmetric keys comprising a first public key and a first private key.
176The request sending unit 52 is for sending a data request transferring the first public key to the server.
177The information receiving module 53 is designed to receive the encrypted text and the second public key sent by the server, the second public key being the public key in the pair of asymmetric keys received by the server, the pair of asymmetric keys received by the server further comprises a second private key, and the encrypted text is information obtained by encrypting the initial parameter to generate an offline payment code using a shared key; the shared key is a key generated based on the second private key and the first public key using a predefined key matching algorithm.
178The shared key generation module 54 is designed to generate a shared key based on the first private key and the second public key using a key matching algorithm.
179The information decryption module 55 is intended to use a common key to decrypt the encrypted text and obtain the initial parameter.
180Here, the shared key generated from the second private key and the first public key using a predefined key matching algorithm is identical to the shared key generated from the first private key and the second public key using the key matching algorithm.
181In an optional implementation method, the request sending module 52 is intended to:
182using the private key in the client certificate for signing the first public key to obtain the first signature information, while the client certificate is a certificate issued by an authorized institution to the client;
183sending a data request transferring the first public key and the first signature information to the server, so that the server uses the public key in the client certificate and the first public key to verify the first signature information, and send the encrypted text and the second public key to the client if the verification was successful.
184Turning to FIG. 6. This is a block diagram of another embodiment of a data communication device provided by this application.
185The device comprises: a request receiving module 61, a key receiving module 62, a shared key generating module 63, an information encryption module 64, and an information sending module 65.
186Here, the request receiving module 61 is designed to receive a data request transferring the first public key and sent by the client, while the data request is intended to request the server to return the initial parameter for generating the offline payment code, the first public key being the public key in the pair of asymmetric keys generated by the client, and the pair of asymmetric keys generated by the client further comprises a first private key.
187The key obtaining module 62 is intended to receive a pair of asymmetric keys comprising a second public key and a second private key.
188The shared key generation module 63 is designed to generate a shared key based on the second private key and the first public key using a predefined key matching algorithm.
189The information encryption module 64 is intended to use a common key to encrypt the initial parameter to which the data request corresponds.
190The information sending module 65 is designed to send the client the encrypted text obtained as a result of the encryption and the second public key, so that the client generates a shared key based on the first private key and the second public key using the key matching algorithm and uses the shared key to decrypt the encrypted text, to get the initial parameter.
191Here, the shared key generated from the second private key and the first public key using a predefined key matching algorithm is identical to the shared key generated from the first private key and the second public key using the key matching algorithm.
192In an optional implementation method, the device 60 further comprises (not shown in FIG. 6):
193a signature module for using the private key in the server certificate to sign the second public key to obtain the second signature information, the server certificate being a certificate issued by an authorized institution to the server.
194The information sending module 65 is additionally used to send the second signature information to the client when sending the encrypted text resulting from the encryption and the second public key to the client, so that the client verifies the second signature information based on the public key in the server certificate and the second public key. After successful verification, the client decrypts the encrypted text.
195Based on this, the present application further provides a wearable device. The wearable device contains an SE chip, which is intended for:
196forming a pair of asymmetric keys containing the first public key and the first private key, and sending a data request transferring the first public key to the server;
197receiving the encrypted text and the second public key sent by the server, the second public key being the public key in the asymmetric key pair received by the server, the asymmetric key pair received by the server further comprises a second private key, and the encrypted text is information obtained by encrypting the initial parameter to generate an offline payment code using a shared key; the shared key is a key generated on the basis of the second private key and the first public key using a predefined key matching algorithm;
198generating a shared key based on the first private key and the second public key using the key matching algorithm and using the shared key to decrypt the encrypted text and obtain the initial parameter.
199Here, the shared key generated from the second private key and the first public key using a predefined key matching algorithm is identical to the shared key generated from the first private key and the second public key using the key matching algorithm.
200From the above embodiment, it can be seen that by configuring the SE in the wearable device, the formation of a pair of asymmetric keys, the generation of a common key, storage of target data, and decryption of encrypted text are performed in SE. In addition, since the SE has a hacking prevention function, the SE can provide the target data with a very high level of security.
201In order to avoid problems of information security and long-term encryption and decryption in modern technologies, the present application additionally provides an alternative method of data transfer, as shown in Fig. 7. FIG. 7 is a flowchart of another embodiment of a data transmission method provided by the present application. The method may comprise the following steps 701-708:
202At step 701, the data interrogator terminal generates a first symmetric key.
203At 702, the data interrogator terminal sends a data request carrying the first symmetric key to the data provider terminal.
204At 703, the data provider terminal receives a second symmetric key that is different from the first symmetric key.
205At 704, the data provider terminal generates a common key based on the first symmetric key and the second symmetric key using a predefined key matching algorithm.
206At 705, the data provider terminal uses a shared key to encrypt the target data to which the data request corresponds.
207At 706, the data provider terminal sends the encrypted text obtained from the encryption and the second symmetric key to the data requestor terminal.
208At 707, the data interrogator terminal generates a common key based on the first symmetric key and the second symmetric key using a key matching algorithm.
209At 708, the data interrogator terminal uses a shared key to decrypt the ciphertext to obtain the target data.
210From the above embodiment, it can be seen that the first symmetric key can be received through the data interrogator terminal, the data request carrying the first symmetric key is sent to the data provider terminal, the second symmetric key is obtained through the data provider terminal, the common key is generated based on the first symmetric key and a second symmetric key using a predefined key matching algorithm, then the shared key is used to encrypt the target data to which the data request corresponds, and finally, the ciphertext obtained from the encryption and the second symmetric key are transmitted to the data interrogator terminal, and the data interrogator terminal uses the same key matching algorithm to generate a common key based on the first symmetric key and the second symmetric key. Since the data provider terminal and the data interrogator terminal use the same key matching algorithm, the common key generated by the data provider terminal and the common key generated by the data interrogator terminal can be used to decrypt the encrypted text through the generated common key, thereby obtaining target data. It can be seen that since the asymmetric key algorithm uses a different random number during each calculation, a different pair of asymmetric keys is generated during each calculation. Therefore, the asymmetric key pairs generated by different clients are also different, which avoids the security risk for all client devices and server devices as a result of a key leak in the client device or server device. Meanwhile, since the shared key is different from the first symmetric key and the second symmetric key, even if the hacker stole the symmetric key, the hacker will not know which key matching algorithm the present application used, so the hacker cannot decrypt the encrypted text, thereby ensuring data security on throughout the transfer process. In addition, since the encryption key of the target data and the decryption key of the target data are identical, symmetric key encryption and decryption algorithms are used to encrypt and decrypt the data in order to avoid long encryption and decryption times resulting from complex asymmetric encryption and decryption algorithms, thereby improving the efficiency of encryption and decryption.
211Here, the key generation algorithm generating the first symmetric key and the key generation algorithm forming the second symmetric key may be the same or different. No specific restrictions have been established. Since the symmetric key generated by the key generation algorithm is different each time, the second symmetric key is different from the first symmetric key.
212After the data interrogator terminal receives the first symmetric key, it can generate a data request carrying the first symmetric key based on the first symmetric key. Here, a data request is used to request target data. After the data request is generated, it can be sent to the terminal of the data provider.
213In one example, a data requestor terminal may use a data request to directly transfer the first symmetric key, thereby increasing the speed of sending a data request.
214In another example, sending a data request that transfers the first symmetric key to the terminal of the data provider contains:
215the data interrogator terminal uses the private key in the interrogator certificate to sign the first symmetric key to obtain the first signature information. Interrogator certificate is a certificate issued by an authorized institution to a data interrogator terminal.
216The data requestor terminal sends a data request transferring the first symmetric key and the first signature information to the data provider terminal.
217Here, an authorized institution may be an institution that can issue certificates. The certificate issued by the authorized institution for the data interrogator terminal contains at least a private key and a public key.
218After the data provider terminal receives the data request, the data provider terminal can verify the first signature information based on the public key in the interrogator certificate and the first symmetric key. After successful verification, the data provider terminal should perform the operation of returning the ciphertext and the second symmetric key to the data interrogator terminal.
219From the above embodiment, it can be seen that signing the first symmetric key and successfully validating the first signature information can ensure that the first symmetric key is not tampered with, and at the same time, the interrogator certificate ensures that the data interrogator terminal is a secure terminal authenticated by an authorized institution, thereby ensuring the security of the common key negotiation process.
220After the data provider terminal receives the data request, the data provider terminal may receive a second symmetric key. After the data provider terminal receives the second symmetric key, the data provider terminal can generate a common key based on the first symmetric key and the second symmetric key using a predefined key matching algorithm.
221Here, the key matching algorithm, also known as the key exchange algorithm, can be, for example, the ECDH algorithm, while ECDH is a DH (Diffie-Hellman) key exchange algorithm based on ECC (elliptic curve cryptosystems). Therefore, both parties can agree on a common key without transmitting classified information.
222The data provider terminal may use a common key to encrypt the target data to which the data request corresponds, and send the encrypted text resulting from the encryption and a second symmetric key to the data requestor terminal.
223In one example, a data provider terminal may directly send a second symmetric key to a data requestor terminal to increase sending efficiency.
224In another example, the data provider terminal uses the private key in the provider certificate to sign the second symmetric key in order to receive the second signature information. A vendor certificate is a certificate issued by an authorized institution for a data provider terminal.
225When the data provider terminal sends the encrypted text obtained from the encryption and the second symmetric key to the data interrogator terminal, the data provider terminal further sends the second signature information to the data interrogator terminal.
226Here, an authorized institution may be an institution that can issue certificates. The certificate issued by the authorized institution to the data provider terminal contains at least a private key and a public key. In other words, the vendor certificate contains a private key and a public key.
227The data requester terminal verifies the second signature information based on the public key in the provider certificate and the second symmetric key. After the verification completes successfully, the data interrogator terminal performs the step of decrypting the ciphertext.
228From the above embodiment, it can be seen that signing the second symmetric key and successfully validating the second signature information can ensure that the second symmetric key is not tampered with, and at the same time, the provider certificate ensures that the data provider terminal is a secure terminal authenticated by an authorized institution, thereby ensuring the security of the common key negotiation process.
229According to an embodiment of the data transmission method provided by this application, this application further provides an embodiment of a data transmission system.
230Turning to FIG. 8. This is a block diagram of another embodiment of a data communication system provided by this application:
231System 80 comprises a data interrogator device 81 and a data provider device 82.
232The data interrogator device 81 generates a first symmetric key and sends a data request carrying the first symmetric key to the data provider device 82.
233The data provider device 82 obtains a second symmetric key and generates a common key based on the first symmetric key and the second symmetric key using a predefined key matching algorithm, the second symmetric key being different from the first symmetric key.
234The data provider device 82 uses a common key to encrypt the target data to which the data request corresponds, and sends the encrypted text resulting from the encryption and a second symmetric key to the data interrogator device 81.
235The data interrogator device 81 generates a common key based on the first symmetric key and the second symmetric key using the key matching algorithm and uses the common key to decrypt the encrypted text to obtain the target data.
236The processes for achieving the functions and effects of each module in the aforementioned device are described in detail in the processes for achieving the corresponding steps in the aforementioned method, so no unnecessary details will be repeated.
237An embodiment of the device basically corresponds to an embodiment of the method, therefore, for the corresponding parts of the device, please refer to the corresponding parts of the embodiment of the method. The embodiment of the device described above is only exemplary, its blocks described as separate components may or may not be physically separated, and the components displayed as blocks may or may not be physical units, that is, they may be located in one place or distributed over many network units. Some or all of the modules can be selected in accordance with the actual need to achieve the objectives of the solution of this application. Specialists in the art can understand and implement this without creative effort.
238After considering the description and practice of the invention claimed herein, those skilled in the art can easily think of other embodiments of the present application. This application is intended to cover any modification, use, or adaptive change of this application. These modifications, applications, or adaptive changes follow the general principle of this application and include generally applicable general knowledge or traditional technical means in the field of technology that are not covered by this application. The description and embodiments are exemplary only. The actual scope and nature of this application are set forth in the following claims.
239It should be understood that the present application is not limited to the exact structure described above and shown in the accompanying drawings, and various modifications and changes can be made without going beyond its scope. The scope of this application is limited by the attached claims.
Contents3
8 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| WO02086830A1 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| CN103400267A | Cites | China | Search report |
| CN105337737B | Cites | China | Search report |
| CN1400819A | Cites | China | Search report |
| RU2230438C2 | Cites | Russian Federation | Search report |
| US6941457B1 | Cites | United States of America | Search report |
| WO2002086830A1 | Cites | World Intellectual Property Organization (WIPO) | – |
30 members in 16 offices
Members30
| Document | Office | Kind | |
|---|---|---|---|
| CN107040369A | China | A | |
| ZA201902947A0 | South Africa | A0 | |
| TW201817193A | Taiwan Province of China | A | |
| CA3041664A1 | Canada | A1 | |
| WO2018077086A1 | World Intellectual Property Organization (WIPO) | A1 | |
| TWI641258B | Taiwan Province of China | B | |
| AU2017352361A1 | Australia | A1 | |
| SG11201903671WA | Singapore | A | |
| KR20190073472A | Republic of Korea | A | |
| BR112019008371A2 | Brazil | A2 | |
| MX2019004948A | Mexico | A | |
| US2019253249A1 | United States of America | A1 | |
| EP3534565A1 | European Patent Office (EPO) | A1 | |
| EP3534565A4 | European Patent Office (EPO) | A4 | |
| JP2019533384A | Japan | A | |
| PH12019500938A1 | Philippines | A1 | |
| AU2019101594A4 | Australia | A4 | |
| CN107040369B | China | B | |
| RU2715163C1This record | Russian Federation | C1 | |
| CN111585749A | China | A | |
| ZA201902947B | South Africa | B | |
| EP3534565B1 | European Patent Office (EPO) | B1 | |
| KR20200127264A | Republic of Korea | A | |
| AU2017352361B2 | Australia | B2 | |
| CA3041664C | Canada | C | |
| JP2021083076A | Japan | A | |
| ES2837039T3 | Spain | T3 | |
| JP7119040B2 | Japan | B2 | |
| CN111585749B | China | B | |
| MX379285B | Mexico | B |
2 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Official registration of the transfer of exclusive rightPC41 | PC41 | |
| Official registration of the transfer of exclusive rightPC41 | PC41 |
Numbers
- Publication
- 2715163
- Application
- 2019116027
Titles2
- Russian
- СПОСОБ, УСТРОЙСТВО И СИСТЕМА ПЕРЕДАЧИ ДАННЫХ
- English
- METHOD, APPARATUS AND SYSTEM FOR TRANSMITTING DATA
Classification
- CPC, 18
- H04L9/0838
- G06Q20/085
- H04L9/3073
- H04L9/085
- H04L9/0825
- H04L63/0428
- H04L9/0841
- H04L9/0861
- G06Q20/401
- G06Q2220/00
- G06Q20/20
- G06Q20/382
- G06Q20/327
- G06Q20/204
- G06Q20/3829
- G06Q20/4097
- H04L9/14
- G06Q20/40
- IPC, 1
- H04L9 08