Data transmission method, apparatus and system
Abstract
The present invention provides a data transmission method, device and system. The method includes: generating an asymmetric key pair including a first public key and a first private key, and sending a data request carrying the first public key to a server ; Receive the ciphertext and the second public key sent by the server, where the second public key is the public key in the asymmetric key pair obtained by the server, and the asymmetric key pair obtained by the server It also includes a second private key. The ciphertext is information obtained by using a shared key to encrypt the seed parameters used to generate the offline payment code; the shared key is based on the second private key and the first public key. The key is a key generated using a preset key agreement algorithm; according to the first private key and the second public key, the key agreement algorithm is used to generate a common key, and the shared secret is used The key decrypts the ciphertext to obtain the seed parameter. The invention not only guarantees the safety of the data in the entire transmission process, but also improves the efficiency of encryption and decryption.

Term
No projected expiry on record.
- Priority and filed
- Granted
- Today
14 claims: 14 independent, 0 dependent
- 1一種資料傳輸方法,所述方法應用於用戶端中,包括: 生成包括第一公鑰和第一私鑰的非對稱密鑰對,向伺務端發送攜帶有所述第一公鑰的資料請求; 接收所述伺務端發送的密文和第二公鑰,所述第二公鑰是伺務端獲取的非對稱密鑰對中的公鑰,該伺務端獲取的非對稱密鑰對中還包括第二私鑰,所述密文是利用共用密鑰將用於生成離線付款碼的種子參數加密後的資訊;該共用密鑰是根據所述第二私鑰和所述第一公鑰,採用預設的密鑰協商演算法生成的密鑰; 根據所述第一私鑰和所述第二公鑰,採用所述密鑰協商演算法生成共用密鑰,並利用所述共用密鑰對所述密文進行解密,得到所述種子參數; 其中,根據所述第二私鑰和所述第一公鑰採用預設的密鑰協商演算法生成的共用密鑰、與根據所述第一私鑰和所述第二公鑰採用所述密鑰協商演算法生成的共用密鑰相同。
- 2根據申請專利範圍第1項所述的方法,其中,所述向伺務端發送攜帶有所述第一公鑰的資料請求,包括: 利用用戶端證書中的私鑰對所述第一公鑰進行簽名,獲得第一簽名資訊,所述用戶端證書是指定機構頒發給所述用戶端的證書; 向伺務端發送攜帶有所述第一公鑰和所述第一簽名資訊的資料請求,以便所述伺務端利用所述用戶端證書中的公鑰和所述第一公鑰對所述第一簽名資訊進行驗簽,驗簽通過後向所述用戶端發送所述密文和所述第二公鑰。
- 3根據申請專利範圍第1或2項所述的方法,其中,所述用戶端位於可穿戴設備。
- 4根據申請專利範圍第3項所述的方法,其中,所述可穿戴設備包括智慧手環。
- 5一種資料傳輸方法,所述方法應用於伺務端中,包括: 接收用戶端發送的攜帶有第一公鑰的資料請求,所述資料請求用於請求伺務端返回用於生成離線付款碼的種子參數,所述第一公鑰是所述用戶端生成的非對稱密鑰對中的公鑰,該用戶端生成的非對稱密鑰對中還包括第一私鑰; 獲取包括第二公鑰和第二私鑰的非對稱密鑰對,並根據所述第二私鑰和所述第一公鑰,採用預設的密鑰協商演算法生成共用密鑰; 利用所述共用密鑰加密所述資料請求對應的種子參數,並將加密得到的密文和所述第二公鑰發送至所述用戶端,以便所述用戶端根據所述第一私鑰和所述第二公鑰,採用所述密鑰協商演算法生成共用密鑰,並利用所述共用密鑰對所述密文進行解密,得到所述種子參數; 其中,根據所述第二私鑰和所述第一公鑰採用預設的密鑰協商演算法生成的共用密鑰、與根據所述第一私鑰和所述第二公鑰採用所述密鑰協商演算法生成的共用密鑰相同。
- 6根據申請專利範圍第5項所述的方法,其中,所述方法還包括: 利用伺務端證書中的私鑰對所述第二公鑰進行簽名,獲得第二簽名資訊,所述伺務端證書是指定機構頒發給所述伺務端的證書; 將加密得到的密文和所述第二公鑰發送至所述用戶端時,還將所述第二簽名資訊發送至所述用戶端,以便所述用戶端根據所述伺務端證書中的公鑰和所述第二公鑰,對所述第二簽名資訊進行驗簽,驗簽通過後,所述用戶端對所述密文進行解密。
- 7一種資料傳輸方法,所述方法包括: 資料請求端生成包括第一公鑰和第一私鑰的非對稱密鑰對,向資料提供端發送攜帶有所述第一公鑰的資料請求; 所述資料提供端獲取包括第二公鑰和第二私鑰的非對稱密鑰對,並根據所述第二私鑰和所述第一公鑰,採用預設的密鑰協商演算法生成共用密鑰; 所述資料提供端利用所述共用密鑰加密所述資料請求對應的目標資料,並將加密得到的密文和所述第二公鑰發送至所述資料請求端; 所述資料請求端根據所述第一私鑰和所述第二公鑰,採用所述密鑰協商演算法生成共用密鑰,並利用所述共用密鑰對所述密文進行解密,得到所述目標資料; 其中,根據所述第二私鑰和所述第一公鑰採用預設的密鑰協商演算法生成的共用密鑰、與根據所述第一私鑰和所述第二公鑰採用所述密鑰協商演算法生成的共用密鑰相同。
- 8根據申請專利範圍第7項所述的方法,其中,所述向資料提供端發送攜帶有所述第一公鑰的資料請求,包括: 所述資料請求端利用請求端證書中的私鑰對所述第一公鑰進行簽名,獲得第一簽名資訊,所述請求端證書是指定機構頒發給所述資料請求端的證書; 所述資料請求端將攜帶有所述第一公鑰和所述第一簽名資訊的資料請求發送至資料提供端; 所述方法還包括:所述資料提供端根據所述請求端證書中的公鑰和所述第一公鑰,對所述第一簽名資訊進行驗簽,驗簽通過後所述資料提供端向所述資料請求端發送所述密文和所述第二公鑰。
- 9根據申請專利範圍第7項所述的方法,其中,所述方法還包括: 所述資料提供端利用提供端證書中的私鑰對所述第二公鑰進行簽名,獲得第二簽名資訊,所述提供端證書是指定機構頒發給所述資料提供端的證書; 所述資料提供端將加密得到的密文和所述第二公鑰發送至所述資料請求端時,還將所述第二簽名資訊發送至所述資料請求端; 所述資料請求端根據所述提供端證書中的公鑰和所述第二公鑰,對所述第二簽名資訊進行驗簽,驗簽通過後,所述資料請求端對所述密文進行解密。
- 10一種資料傳輸裝置,所述裝置包括: 密鑰生成模組,用於生成包括第一公鑰和第一私鑰的非對稱密鑰對; 請求發送模組,用於向伺務端發送攜帶有所述第一公鑰的資料請求; 資訊接收模組,用於接收所述伺務端發送的密文和第二公鑰,所述第二公鑰是伺務端獲取的非對稱密鑰對中的公鑰,該伺務端獲取的非對稱密鑰對中還包括第二私鑰,所述密文是利用共用密鑰將用於生成離線付款碼的種子參數加密後的資訊;該共用密鑰是根據所述第二私鑰和所述第一公鑰,採用預設的密鑰協商演算法生成的密鑰; 共用密鑰生成模組,用於根據所述第一私鑰和所述第二公鑰,採用所述密鑰協商演算法生成共用密鑰; 資訊解密模組,用於利用所述共用密鑰對所述密文進行解密,得到所述種子參數; 其中,根據所述第二私鑰和所述第一公鑰採用預設的密鑰協商演算法生成的共用密鑰、與根據所述第一私鑰和所述第二公鑰採用所述密鑰協商演算法生成的共用密鑰相同。
- 11一種資料傳輸裝置,所述裝置包括: 請求接收模組,用於接收用戶端發送的攜帶有第一公鑰的資料請求,所述資料請求用於請求伺務端返回用於生成離線付款碼的種子參數,所述第一公鑰是所述用戶端生成的非對稱密鑰對中的公鑰,該用戶端生成的非對稱密鑰對中還包括第一私鑰; 密鑰獲取模組,用於獲取包括第二公鑰和第二私鑰的非對稱密鑰對; 共用密鑰生成模組,用於根據所述第二私鑰和所述第一公鑰,採用預設的密鑰協商演算法生成共用密鑰; 資訊加密模組,用於利用所述共用密鑰加密所述資料請求對應的種子參數; 資訊發送模組,用於將加密得到的密文和所述第二公鑰發送至所述用戶端,以便所述用戶端根據所述第一私鑰和所述第二公鑰,採用所述密鑰協商演算法生成共用密鑰,並利用所述共用密鑰對所述密文進行解密,得到所述種子參數; 其中,根據所述第二私鑰和所述第一公鑰採用預設的密鑰協商演算法生成的共用密鑰、與根據所述第一私鑰和所述第二公鑰採用所述密鑰協商演算法生成的共用密鑰相同。
- 12一種資料傳輸系統,所述系統包括資料請求端裝置和資料提供端裝置; 所述資料請求端裝置生成包括第一公鑰和第一私鑰的非對稱密鑰對,向資料提供端裝置發送攜帶有所述第一公鑰的資料請求; 所述資料提供端裝置獲取包括第二公鑰和第二私鑰的非對稱密鑰對,並根據所述第二私鑰和所述第一公鑰,採用預設的密鑰協商演算法生成共用密鑰; 所述資料提供端裝置利用所述共用密鑰加密所述資料請求對應的目標資料,並將加密得到的密文和所述第二公鑰發送至所述資料請求端裝置; 所述資料請求端裝置根據所述第一私鑰和所述第二公鑰,採用所述密鑰協商演算法生成共用密鑰,並利用所述共用密鑰對所述密文進行解密,得到所述目標資料; 其中,根據所述第二私鑰和所述第一公鑰採用預設的密鑰協商演算法生成的共用密鑰、與根據所述第一私鑰和所述第二公鑰採用所述密鑰協商演算法生成的共用密鑰相同。
- 13一種資料傳輸方法,所述方法包括: 資料請求端生成第一對稱密鑰,向資料提供端發送攜帶有所述第一對稱密鑰的資料請求; 所述資料提供端獲取第二對稱密鑰,並根據所述第一對稱密鑰和所述第二對稱密鑰,採用預設的密鑰協商演算法生成共用密鑰,所述第二對稱密鑰與所述第一對稱密鑰不同; 所述資料提供端利用所述共用密鑰加密所述資料請求對應的目標資料,並將加密得到的密文和所述第二對稱密鑰發送至所述資料請求端; 所述資料請求端根據所述第一對稱密鑰和所述第二對稱密鑰,採用所述密鑰協商演算法生成共用密鑰,並利用所述共用密鑰對所述密文進行解密,得到所述目標資料。
- 14一種資料傳輸系統,所述系統包括資料請求端裝置和資料提供端裝置; 所述資料請求端裝置生成第一對稱密鑰,向資料提供端裝置發送攜帶有所述第一對稱密鑰的資料請求; 所述資料提供端裝置獲取第二對稱密鑰,並根據所述第一對稱密鑰和所述第二對稱密鑰,採用預設的密鑰協商演算法生成共用密鑰,所述第二對稱密鑰與所述第一對稱密鑰不同; 所述資料提供端裝置利用所述共用密鑰加密所述資料請求對應的目標資料,並將加密得到的密文和所述第二對稱密鑰發送至所述資料請求端裝置; 所述資料請求端裝置根據所述第一對稱密鑰和所述第二對稱密鑰,採用所述密鑰協商演算法生成共用密鑰,並利用所述共用密鑰對所述密文進行解密,得到所述目標資料。
Independent claims14
9 paragraphs, as filed
Data transmission method, device and system
The present invention relates to the field of network communication technology, in particular to data transmission methods, devices and systems.
Nowadays, people pay more and more attention to the security of data, especially the security of data during transmission. Taking offline payment as an example, the server device can send a policy for generating a payment code to the client device, and the client device stores the policy. When the user needs to use the payment code, the client device can use the strategy to generate the payment code. The merchant scans the payment code by the scanning device, and the scanning device transmits the scanned information to the server device for verification. After verification, the payment will be deducted. . It can be seen that in the process of transmitting policies from the server device to the client device, it is necessary to ensure the security of the channel between the client device and the server device. If the policy issued by the server device is intercepted by a third-party hacker, It will cause serious losses to the user of the client device. In a related technology, the same key can be preset in all client devices and server devices respectively, and the server device can use the key to encrypt the information to be transmitted and transmit the cipher text to the client device , The client device uses the key to decrypt the ciphertext. However, since all client devices and server devices share the same key, if a key of a client device or server device is leaked, all client devices and server devices will have security risks. In another related technology, the client device can generate a pair of asymmetric keys, save the private key, and upload the public key to the server device. The server device uses the public key to encrypt the information that needs to be transmitted, and The ciphertext is transmitted to the client device, and the client device uses the private key to decrypt the ciphertext. Since the asymmetric key algorithm uses a different random number for each calculation, the asymmetric key pair generated by each calculation is different, so the asymmetric key pair generated by different users is also different, which avoids the problem of a certain user The leak of the key of the device or the server device causes the security risk of all client devices and server devices. At the same time, because only the private key corresponding to the public key can decrypt the cipher text, even when the public key is transmitted The public key is intercepted, and the ciphertext cannot be decrypted by the public key, which ensures the security of the information. However, because the asymmetric key needs to be encrypted with a complex encryption algorithm, it is decrypted by a complex decryption algorithm. Decryption takes a long time.
The present invention provides a data transmission method, device and system to solve the problem of information security in the prior art and the problem that encryption and decryption takes a long time. According to a first aspect of the embodiments of the present invention, a data transmission method is provided. The method is applied to a user end and includes: generating an asymmetric key pair including a first public key and a first private key, and sending it to the server end Sending a data request carrying the first public key; receiving a ciphertext and a second public key sent by the server, where the second public key is the public key in the asymmetric key pair obtained by the server , The asymmetric key pair obtained by the server also includes a second private key, and the ciphertext is information obtained by using a shared key to encrypt the seed parameters used to generate the offline payment code; the shared key is based on The second private key and the first public key are keys generated by using a preset key agreement algorithm; according to the first private key and the second public key, the key agreement algorithm is used Method to generate a shared key, and use the shared key to decrypt the ciphertext to obtain the seed parameters; wherein, according to the second private key and the first public key, a preset key agreement is adopted The shared key generated by the algorithm is the same as the shared key generated by using the key agreement algorithm according to the first private key and the second public key. According to a second aspect of the embodiments of the present invention, there is provided a data transmission method, which is applied to a server, and includes: Receiving a data request carrying a first public key sent by the client, the data request is used to request the server to return the seed parameters used to generate the offline payment code, and the first public key is a non-transmission generated by the client The public key in the symmetric key pair, the asymmetric key pair generated by the user terminal further includes the first private key; the asymmetric key pair including the second public key and the second private key is obtained, and the asymmetric key pair is obtained according to the first private key. The second private key and the first public key are used to generate a shared key using a preset key agreement algorithm; the shared key is used to encrypt the seed parameters corresponding to the data request, and the encrypted ciphertext and all keys are encrypted. The second public key is sent to the user end, so that the user end uses the key agreement algorithm to generate a common key according to the first private key and the second public key, and uses the common key The key decrypts the ciphertext to obtain the seed parameter; wherein, according to the second private key and the first public key, the shared key generated by the preset key agreement algorithm is the same as The first private key and the second public key use the same shared key generated by the key agreement algorithm. According to a third aspect of the embodiments of the present invention, there is provided a data transmission method, the method comprising: a data requesting end generates an asymmetric key pair including a first public key and a first private key, and sending to the data providing end the asymmetric key pair The data request of the first public key; The data provider obtains an asymmetric key pair including a second public key and a second private key, and uses a preset key agreement algorithm to generate a shared key according to the second private key and the first public key. The key; the data provider encrypts the target data corresponding to the data request by using the shared key, and sends the encrypted ciphertext and the second public key to the data requesting side; the data request The end uses the key agreement algorithm to generate a shared key according to the first private key and the second public key, and uses the shared key to decrypt the ciphertext to obtain the target data; Wherein, according to the second private key and the first public key, the shared key generated by using a preset key agreement algorithm is different from using the secret key according to the first private key and the second public key. The shared key generated by the key agreement algorithm is the same. According to a fourth aspect of the embodiments of the present invention, there is provided a data transmission device, the device comprising: a key generation module for generating an asymmetric key pair including a first public key and a first private key; requesting to send A module for sending a data request carrying the first public key to the server; The information receiving module is used to receive the ciphertext and the second public key sent by the server, where the second public key is the public key in the asymmetric key pair obtained by the server, and the server obtains The asymmetric key pair also includes a second private key, and the ciphertext is information obtained by using a shared key to encrypt the seed parameters used to generate the offline payment code; the shared key is based on the second private key And the first public key, a key generated by using a preset key agreement algorithm; a shared key generation module for using the secret key according to the first private key and the second public key The key agreement algorithm generates a shared key; the information decryption module is used to decrypt the ciphertext using the shared key to obtain the seed parameters; wherein, according to the second private key and the first The public key generated by using a preset key agreement algorithm is the same as the common key generated by using the key agreement algorithm according to the first private key and the second public key. According to a fifth aspect of the embodiments of the present invention, there is provided a data transmission device, the device comprising: a request receiving module for receiving a data request carrying a first public key sent by a user terminal, the data request being used for Request the server to return the seed parameter used to generate the offline payment code. The first public key is the public key in the asymmetric key pair generated by the user side, and the asymmetric key pair generated by the user side returns Includes a first private key; a key acquisition module for obtaining an asymmetric key pair including a second public key and a second private key; The shared key generation module is used to generate a shared key according to the second private key and the first public key using a preset key agreement algorithm; the information encryption module is used to use the shared key Key to encrypt the seed parameters corresponding to the data request; an information sending module for sending the encrypted ciphertext and the second public key to the client, so that the client can use the first private key And the second public key, use the key agreement algorithm to generate a shared key, and use the shared key to decrypt the ciphertext to obtain the seed parameter; wherein, according to the second private key The shared key and the first public key are generated by using a preset key agreement algorithm, and the shared key is generated by using the key agreement algorithm according to the first private key and the second public key. The keys are the same. According to a sixth aspect of the embodiments of the present invention, a data transmission system is provided, the system includes a data requesting end device and a data providing end device; the data requesting end device generates a non-transmission system including a first public key and a first private key. A symmetric key pair sends a data request carrying the first public key to a data provider device; the data provider device obtains an asymmetric key pair including a second public key and a second private key, and performs a The second private key and the first public key are used to generate a common key using a preset key agreement algorithm; The data provider device uses the shared key to encrypt the target data corresponding to the data request, and sends the encrypted ciphertext and the second public key to the data requester device; the data requester The device uses the key agreement algorithm to generate a shared key according to the first private key and the second public key, and uses the shared key to decrypt the ciphertext to obtain the target data; Wherein, according to the second private key and the first public key, the shared key generated by using a preset key agreement algorithm is different from using the secret key according to the first private key and the second public key. The shared key generated by the key agreement algorithm is the same. According to a seventh aspect of the embodiments of the present invention, there is provided a data transmission method, the method comprising: a data requesting end generates a first symmetric key, and sending a data request carrying the first symmetric key to the data providing end; The data provider obtains the second symmetric key, and uses a preset key agreement algorithm to generate a shared key according to the first symmetric key and the second symmetric key. The second symmetric key is The key is different from the first symmetric key; the data provider uses the shared key to encrypt the target data corresponding to the data request, and sends the encrypted ciphertext and the second symmetric key to all The data requesting end; The material requesting end uses the key agreement algorithm to generate a shared key according to the first symmetric key and the second symmetric key, and uses the shared key to decrypt the ciphertext, Obtain the target data. According to an eighth aspect of the embodiments of the present invention, a data transmission system is provided, the system includes a data requesting end device and a data providing end device; the data requesting end device generates a first symmetric key and sends it to the data providing end device A material request carrying the first symmetric key; the material providing end device obtains a second symmetric key, and uses a preset key according to the first symmetric key and the second symmetric key A negotiated algorithm generates a shared key, the second symmetric key is different from the first symmetric key; the data provider device uses the shared key to encrypt the target data corresponding to the data request, and encrypts The obtained ciphertext and the second symmetric key are sent to the material requesting end device; the material requesting end device adopts the key agreement according to the first symmetric key and the second symmetric key An algorithm generates a common key, and uses the common key to decrypt the ciphertext to obtain the target data. When applying the data transmission method, device, and system of the embodiments of the present invention, the data requesting terminal can generate an asymmetric key pair including the first public key and the first private key, and send the data provider carrying the first public key to the data provider. For data request, the data provider obtains an asymmetric key pair including the second public key and the second private key, and uses the preset key agreement algorithm to generate the shared secret based on the second private key and the first public key. Then use the shared key to encrypt the data to request the corresponding target data, and finally transmit the encrypted ciphertext and the second public key to the data requesting end. The data requesting end uses the same first private key and second public key. The key agreement algorithm generates a shared key, because the shared key generated by the preset key agreement algorithm based on the second private key and the first public key is different from the use of the key based on the first private key and the second public key. The common key generated by the negotiation algorithm is the same, so the data provider can use the common key for encryption, and the data requester can use the common key for decryption. Since the keys for encrypting the target data and decrypting the target data are the same, a symmetric encryption and decryption algorithm can be used to encrypt and decrypt the data. Since symmetric encryption algorithms are often encrypted by means of shifting, and asymmetric encryption algorithms are encrypted by searching for large prime numbers, it can be seen that the encryption process of symmetric encryption algorithms is better than that of asymmetric encryption algorithms. It is simple, so this embodiment can avoid the defect of long encryption and decryption time caused by complex asymmetric encryption and decryption algorithms, and improve the efficiency of encryption and decryption. And because the complete key is not exposed during the entire transmission process, even if the hacker hijacks the public key, it is meaningless, thus ensuring the security of the data during the entire transmission process. When applying the data transmission method, device, and system of the embodiments of the present invention, the first symmetric key can be obtained by the data requesting end, and the data request carrying the first symmetric key can be sent to the data providing end. Obtain the second symmetric key, and use the preset key agreement algorithm to generate a shared key according to the first symmetric key and the second symmetric key, and use the shared key to encrypt the data to request the corresponding target data, and finally The encrypted ciphertext and the second symmetric key are transmitted to the data requesting end. The data requesting end uses the same key agreement algorithm to generate a common key according to the first symmetric key and the second symmetric key. The key agreement algorithm of the data requester and the data requester are the same. Therefore, the shared key generated by the data provider and the data requester are the same. The data requester can decrypt the ciphertext by using the generated shared key to obtain the target data. It can be seen that, since the shared key is different from the first symmetric key and the second symmetric key, even if the hacker hijacks the symmetric key, they dont know which key agreement algorithm is used in the present invention, so the secret cannot be verified. The text is decrypted to ensure the security of the data during the entire transmission process. In addition, since the shared key of the encrypted target data and the decrypted target data is the same, the symmetric key encryption and decryption algorithm is used to encrypt and decrypt the data to avoid the long encryption and decryption time caused by complex asymmetric encryption and decryption algorithms, thereby increasing The efficiency of encryption and decryption. It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present invention.
Here will be detailed finely to the exemplary embodiments described, examples of which are shown in the accompanying drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings indicate the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all implementation manners consistent with the present invention. On the contrary, they are only examples of devices and methods consistent with some aspects of the present invention as detailed in the scope of the appended application. The terms used in the present invention are only for the purpose of describing specific embodiments, and are not intended to limit the present invention. The singular forms of "a", "said" and "the" used in the scope of the present invention and the appended applications also intend to include plural forms, unless the context clearly indicates other meanings. It should also be understood that the term "and/or" as used herein refers to and includes any or all possible combinations of one or more related listed items. It should be understood that although the terms first, second, third, etc. may be used in the present invention to describe various information, the information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of the present invention, the first information can also be referred to as second information, and similarly, the second information can also be referred to as first information. Depending on the context, the word "if" as used herein can be interpreted as "when" or "when" or "in response to certainty". People pay more and more attention to the security of data, especially the security of data in the transmission process. As shown in FIG. 1A, FIG. 1A is a schematic diagram of an application scenario of data transmission according to an exemplary embodiment of the present invention. In the schematic diagram, data transmission can be performed between different client devices and server devices. For example, the client device sends a data request to the server device, and the server device returns corresponding target data according to the data request. During the transmission process, hackers may intercept the target data in transmission, thereby causing losses to the user. In order to ensure the security of the data in the transmission process, the same key can be preset in all client devices and server devices. The server device can use the key to encrypt the information to be transmitted and encrypt the secret The text is transmitted to the client device, and the client device uses the key to decrypt the ciphertext. However, since all client devices and server devices share the same key, if a key of a client device or server device is leaked, all client devices and server devices will have security risks. In order to avoid this situation, in another related technology, the client device can generate a pair of asymmetric keys, save the private key, and upload the public key to the server device. The server device will need to transmit using the public key. Encrypt the information and transmit the cipher text to the client device, and the client device uses the private key to decrypt the cipher text. Since the asymmetric key algorithm uses a different random number for each calculation, the asymmetric key pair generated by each calculation is different, so the asymmetric key pair generated by different users is also different, which avoids the problem of a certain user The leak of the key of the device or the server device causes the security risk of all client devices and server devices. At the same time, because only the private key corresponding to the public key can decrypt the cipher text, even when the public key is transmitted The public key is intercepted, and the ciphertext cannot be decrypted by the public key, which ensures the security of the information. However, because the asymmetric key needs to be encrypted with a complex encryption algorithm, it is decrypted by a complex decryption algorithm. Decryption takes a long time. In order to avoid the problem of information security in the prior art and the problem of time-consuming encryption and decryption, the present invention provides a data transmission method, as shown in FIG. 1B. FIG. 1B is a flowchart of an embodiment of the data transmission method of the present invention. It may include the following steps 101 to 108: In step 101, the material requesting end generates an asymmetric key pair including the first public key and the first private key. In step 102, the data requesting end sends a data request carrying the first public key to the data providing end. In step 103, the data provider obtains an asymmetric key pair including the second public key and the second private key. In step 104, the data provider uses a preset key agreement algorithm to generate a common key according to the second private key and the first public key. In step 105, the data provider uses the shared key to encrypt the target data corresponding to the data request. In step 106, the data provider sends the encrypted ciphertext and the second public key to the data requester. In step 107, the material requesting end uses the key agreement algorithm to generate a common key according to the first private key and the second public key. In step 108, the data requester uses the shared key to decrypt the ciphertext to obtain the target data. Among them, the data requesting end is the end requesting data, and the data providing end is the end providing data. In an example, the data requesting end may be a client, the data providing end may be a server, and the client requests the server to return target data. Taking the target data as the seed parameter used to generate the offline payment code as an example, the data request can be a request for opening an offline payment, the data requesting end is the user end, and the data providing end is the server end. The client sends a request to enable offline payment to the server, and the server returns seed parameters to the client according to the request. In another example, the server can also request data from the client, and the data requester can be the server, and the data provider can be the client, which is not limited. It can be seen from the above embodiment that the data requesting terminal can generate an asymmetric key pair including the first public key and the first private key, and send the data request carrying the first public key to the data provider. Obtain an asymmetric key pair including the second public key and the second private key, and use the preset key agreement algorithm to generate a shared key according to the second private key and the first public key, and then use the shared key to encrypt The target data corresponding to the data request, and finally the encrypted ciphertext and the second public key are transmitted to the data requesting end. The data requesting end uses the same key agreement algorithm to generate a shared secret based on the first private key and the second public key. Key, because the shared key generated by using the preset key agreement algorithm according to the second private key and the first public key, and the shared key generated by using the key agreement algorithm according to the first private key and the second public key The same, so the data provider can use the shared key for encryption, and the data requester can use the shared key for decryption. Since the keys for encrypting the target data and decrypting the target data are the same, a symmetric encryption and decryption algorithm can be used to encrypt and decrypt the data. Since symmetric encryption algorithms are often encrypted by means of shifting, and asymmetric encryption algorithms are encrypted by searching for large prime numbers, it can be seen that the encryption process of symmetric encryption algorithms is better than that of asymmetric encryption algorithms. It is simple, so this embodiment can avoid the defect of long encryption and decryption time caused by complex asymmetric encryption and decryption algorithms, and improve the efficiency of encryption and decryption. Also, because a different random number is used each time, the asymmetric key pair generated each time is different, so that the asymmetric key pair generated by different users is also different, which avoids the problem of a certain user equipment or server equipment. Leakage of keys causes security risks for all client devices and server devices. At the same time, since the complete key is not exposed during the entire transmission process, even if a hacker hijacks the public key, it does not make sense to ensure that the data is available. Security throughout the transmission process. Wherein, the generation time of the asymmetric key pair including the first public key and the first private key may not be specifically limited. For example, an asymmetric key pair can be generated each time before sending a material request. For another example, the asymmetric key pair may not be generated before the material request is sent, but generated when other conditions are met, so that the generated asymmetric key pair can be obtained when the material request is to be sent. For example, a pair of asymmetric key pairs may be generated every set time interval, and each newly generated asymmetric key pair replaces the last generated asymmetric key pair. In an example, the first public key and the first private key may be an asymmetric key pair generated by a key generation algorithm. Before sending the data request, the data requester uses the key generation algorithm to generate an asymmetric key pair that includes the first public key and the first private key each time. Because the asymmetric key algorithm generates the asymmetric key each time It is not the same in general, it can avoid the problem of insecurity of all subsequent information encrypted by the key pair due to the leakage of the permanently stored key pair. After the data requesting end obtains the first public key and the first private key, the data request carrying the first public key can be sent to the data providing end. Among them, the data request is a request for requesting target data. In one example, the data requester can directly carry the first public key in the data request, thereby increasing the speed of sending the data request. In another example, the sending the data request carrying the first public key to the data provider includes: the data requesting side signs the first public key by using the private key in the certificate of the requesting side, The first signature information is obtained, and the requester certificate is a certificate issued to the data requester by a designated authority. The data requesting end sends a data request carrying the first public key and the first signature information to the data providing end. The method further includes: the data provider verifies the first signature information according to the public key in the requester certificate and the first public key, and after the verification is passed, the data provider sends The data requesting end sends the ciphertext and the second public key. Among them, the designated organization is generally a more authoritative organization that can issue certificates. The certificate issued by the designated authority to the data requester includes at least the private key and the public key, that is, the requester certificate includes the private key and the public key. As one of the signature methods, the data requester can use the hash algorithm to hash the first public key to obtain the first information digest, and use the private key in the requester certificate to encrypt the first information digest to obtain the first signature Then, according to the first signature information, a data request carrying the first public key and the first signature information is generated, and the data request is sent to the data provider. After the data provider receives the data request, the data provider can verify the first signature information based on the public key in the certificate of the requester and the first public key, and provide the data to the data after the verification is passed. The terminal sends the ciphertext and the second public key. The method for the data provider to obtain the public key in the certificate of the requester may be that the data requester pre-broadcasts it to the data provider, or the data requester sends it to the data provider when sending the data request. As one of the signature verification methods, the data provider can use the hash algorithm to hash the received first public key to obtain the second information digest, and use the public key in the requesters certificate to decrypt the first signature information. Obtain the first information summary and verify whether the first information summary and the second information summary are consistent. If they are the same, it means the verification is passed. Only the data provider can execute the process of sending the ciphertext and the second public key to the data requesting end. operate. It can be seen from the above embodiment that by signing the first public key and verifying the first signature information, when the verification is passed, it can be ensured that the first public key has not been tampered with, and the data is ensured by the request-side certificate. The requesting end is the secure end certified by an authority, so as to ensure the security of the negotiation process of the shared key. After receiving the data request, the data provider can obtain an asymmetric key pair including the second public key and the second private key. Wherein, the second public key and the second private key may be a key pair generated by the key generation algorithm. It can be seen that the asymmetric key pair formed by the first public key and the first private key, and the first The asymmetric key pair composed of the second public key and the second private key is generated by the same key generation algorithm. Since the key generation algorithm uses a different random number for each calculation, the asymmetric key pair generated by each calculation is almost different, so the asymmetric key pair generated by the data requester and the asymmetric key generated by the data provider It is different in general. The generation time of the asymmetric key pair including the second public key and the second private key may not be specifically limited. For example, an asymmetric key pair can be generated every time a material request is received. For another example, the asymmetric key pair may not be generated when the material request is received, but when other conditions are met, so that the generated asymmetric key pair can be obtained when the material request is received. For example, a pair of asymmetric key pairs may be generated every set time interval, and each newly generated asymmetric key pair replaces the last generated asymmetric key pair. In one example, when a data request is received, the data provider uses the key generation algorithm to generate an asymmetric key pair including the second public key and the second private key each time. Generally, the generated asymmetric key pairs are not the same, which can avoid the problem of insecure information encrypted by the key pairs due to the leakage of the permanently stored key pairs. After the data provider obtains the asymmetric key pair including the second public key and the second private key, it can use a preset key agreement algorithm to generate a shared secret based on the second private key and the first public key. key. The subsequent data requester will use the key agreement algorithm to generate a shared key according to the first private key and the second public key. The key agreement algorithm can also be called a key exchange algorithm, for example, it can be an ECDH algorithm. Among them, ECDH is a DH (Diffie-Hellman) key exchange algorithm based on ECC (Elliptic Curve Cryptosystems). So that the two parties can negotiate a common key without sharing any secrets. In this embodiment, the shared key generated by the preset key agreement algorithm according to the second private key and the first public key is different from the common key generated according to the first private key and the second public key. The shared keys generated by the key agreement algorithm are the same. As one of the implementation methods, the key agreement algorithm adopted by the data provider and the data requester is the same, and the key generation algorithm adopted by the data provider and the data requester are also the same, and the key agreement algorithm is the same as the The key generation algorithm satisfies: For any two asymmetric key pairs generated by the key generation algorithm, select the public key in any asymmetric key pair and the public key in the other asymmetric key pair. For the private key, the negotiation result obtained by using the key negotiation algorithm is the same. It can be seen that since the first public key is often not equal to the second public key, and the first private key is often not equal to the second private key, the first private key cannot be derived from the first public key, and the second public key cannot be derived from the second public key. The private key, at the same time, the shared key negotiated between the first private key and the second public key is the same as the shared key negotiated between the second private key and the first public key, so that the entire key is not exposed during the entire transmission process. Ensure the security of the data during the entire transmission process. At the same time, since the encryption and decryption target data have the same key, the symmetric encryption and decryption algorithm is used to encrypt and decrypt the data to avoid the long encryption and decryption time caused by complex asymmetric encryption and decryption algorithms, thereby improving the encryption and decryption performance. efficiency. After the data provider generates a common key, the data provider can use the common key to encrypt the target data corresponding to the data request, and send the encrypted ciphertext and the second public key to the data request end. In an example, the data provider can directly send the second public key to the data requester to improve the sending efficiency. In another example, the method further includes: The data provider uses the private key in the provider certificate to sign the second public key to obtain second signature information, and the provider certificate is a certificate issued to the data provider by a designated authority. When the data provider sends the encrypted ciphertext and the second public key to the data requester, it also sends the second signature information to the data requester. The data requester verifies the second signature information according to the public key in the provider certificate and the second public key. After the verification is passed, the data requester verifies the ciphertext Decrypted. Among them, the designated organization may be an organization that can issue certificates. The certificate issued by the designated authority to the data provider includes at least the private key and the public key, that is, the certificate of the provider includes the private key and the public key. As one of the signature methods, the data provider can use the hash algorithm to hash the second public key to obtain the third information digest, and use the private key in the provider certificate to encrypt the third information digest to obtain the second signature Information, and then send the ciphertext, the second public key, and the second signature information to the data requester. The data requester verifies the second signature information according to the public key in the provider certificate and the second public key. After the verification is passed, the data requester verifies the ciphertext Decrypted. The method for the data requesting end to obtain the public key in the provider certificate may be that the data provider pre-broadcasts to the data requesting end, or the data provider sends the ciphertext and the second public key to the data requesting end when sending the ciphertext and the second public key. As one of the signature verification methods, the data requester can use the hash algorithm to hash the received second public key to obtain the fourth information summary, and use the public key in the provider certificate to decrypt the second signature information. Obtain the third information summary and verify whether the third information summary and the fourth information summary are consistent. If they are consistent, it means that the signature verification is passed. Only when the signature verification is passed, the data requesting end performs the operation of decrypting the ciphertext. It can be seen from the above embodiment that by signing the second public key and verifying the second signature information, when the verification is passed, it can be ensured that the second public key has not been tampered with, and the data is ensured by the provider certificate. The provider is the secure end certified by an authority, so as to ensure the security of the negotiation process of the shared key. As shown in FIG. 2, FIG. 2 is a flowchart of another embodiment of the data transmission method of the present invention. This embodiment applies the data transmission method to the transmission seed parameter. The method is applied to the user terminal and may include the following steps: 201 Go to step 203: In step 201, an asymmetric key pair including a first public key and a first private key is generated, and a data request carrying the first public key is sent to the server. Wherein, the generation time of the asymmetric key pair including the first public key and the first private key may not be specifically limited. For example, an asymmetric key pair can be generated each time before sending a material request. For another example, the asymmetric key pair may not be generated before the material request is sent, but generated when other conditions are met, so that the generated asymmetric key pair can be obtained when the material request is to be sent. For example, a pair of asymmetric key pairs may be generated every set time interval, and each newly generated asymmetric key pair replaces the last generated asymmetric key pair. In an example, the first public key and the first private key may be an asymmetric key pair generated by a key generation algorithm. Before sending the material request, the user side uses the key generation algorithm to generate an asymmetric key pair that includes the first public key and the first private key each time. Because the asymmetric key algorithm generates an asymmetric key pair each time Under normal circumstances, they are not the same, it can avoid the problem of insecurity of all subsequent information encrypted by the key pair due to the leakage of the permanently stored key pair. After obtaining the first public key and the first private key, the data request carrying the first public key can be sent to the server. Wherein, the data request is used to request the server to return the seed parameters used to generate the offline payment code. In an example, the first public key can be directly carried in the data request, thereby increasing the speed of sending the data request. In another example, the sending the data request carrying the first public key to the server includes: signing the first public key with the private key in the client certificate to obtain the first signature information , The client certificate is a certificate issued to the client by a designated organization. Send a data request carrying the first public key and the first signature information to the server, so that the server uses the public key in the client certificate and the first public key to pair the The first signature information is verified, and the ciphertext and the second public key are sent to the client after the verification is passed. Among them, the designated organization may be an organization that can issue certificates. The certificate issued by the designated authority to the client includes at least the private key and the public key, that is, the certificate of the client includes the private key and the public key. Regarding the manner in which the server obtains the public key in the client certificate, the client may pre-broadcast it to the server, or the client may send it to the server when sending a data request. In this embodiment, the private key in the client certificate may be used to sign the first public key. For example, the client may use a hash algorithm to hash the first public key to obtain the first information summary, and use the client certificate in Encrypt the first information digest with the private key to obtain the first signature information, and then send the data request carrying the first public key and the first signature information to the data provider. It can be seen from the above embodiment that by signing the first public key, the server can verify the first signature information. When the verification is passed, it can be ensured that the first public key has not been tampered with. The certificate ensures that the user end is a secure end certified by an authority, thereby ensuring the security of the negotiation process of the shared key. In step 202, the ciphertext and the second public key sent by the server are received, and the second public key is the public key in the asymmetric key pair obtained by the server, and the non-symmetric key pair obtained by the server is The symmetric key pair also includes a second private key. The ciphertext is information obtained by using a shared key to encrypt the seed parameters used to generate the offline payment code; the shared key is based on the second private key and the The first public key is a key generated by using a preset key agreement algorithm. In step 203, according to the first private key and the second public key, the key agreement algorithm is used to generate a shared key, and the shared key is used to decrypt the ciphertext to obtain the The seed parameters. Among them, the key agreement algorithm can also be called a key exchange algorithm, for example, it can be an ECDH algorithm. Among them, ECDH is a DH (Diffie-Hellman) key exchange algorithm based on ECC (Elliptic Curve Cryptosystems). So that the two parties can negotiate a common key without sharing any secrets. In this embodiment, the shared key generated by the preset key agreement algorithm according to the second private key and the first public key is different from the common key generated according to the first private key and the second public key. The shared keys generated by the key agreement algorithm are the same. As one of the implementations, the key agreement algorithm adopted by the client and the server is the same, and the key generation algorithm adopted by the client and the server are also the same, and the key agreement algorithm is the same as the key agreement algorithm. The generation algorithm satisfies: for any two asymmetric key pairs generated by the key generation algorithm, select the public key in any asymmetric key pair and the private key in the other asymmetric key pair , The negotiation results obtained by using the key agreement algorithm are the same. It can be seen that because the first public key is often not equal to the second public key, and the first private key is often not equal to the second private key. The first private key cannot be derived from the first public key, and the second public key cannot be derived from the second public key. The private key, at the same time, the shared key negotiated between the first private key and the second public key is the same as the shared key negotiated between the second private key and the first public key, so that the entire key is not exposed during the entire transmission process. Ensure the security of the seed parameters during the entire transmission process. In addition, since the encryption seed parameter and the decryption seed parameter have the same key, the symmetric encryption and decryption algorithm is used to encrypt and decrypt the seed parameters to avoid the long encryption and decryption time caused by complex asymmetric encryption and decryption algorithms, thereby improving encryption and decryption. s efficiency. In an optional implementation manner, the user terminal may be located in an electronic device, especially a wearable device. Due to the low configuration of the wearable device itself, the symmetric encryption and decryption algorithm does not need to consume too much resources when the solution is applied to the wearable device. While ensuring transmission security, it greatly improves performance and speeds up the efficiency of the entire transmission process. Further, the wearable device may include a smart bracelet. The implementation of this embodiment by the smart bracelet can not only ensure the transmission security of the seed parameters, but also ensure the efficiency of the entire transmission process. In one example, the method of this embodiment can be executed by a secure element (SE), so that the generation of asymmetric keys, the generation of a shared key, and the decryption of ciphertexts are all performed in the secure element. Further Yes, the seed parameters can also be stored in the secure element. Because the secure element has the function of preventing cracking, the seed parameters can reach a very high level of security. Further, the seed parameters can be stored in the secure element, and at the same time, the access authority of the secure element can be set, and the generation of the payment code can be controlled by verification methods such as fingerprint recognition, pulse recognition, and face recognition, so that the entire payment code can reach Very high security level. As shown in FIG. 3, FIG. 3 is a flowchart of another embodiment of the data transmission method of the present invention. This embodiment applies the data transmission method to the transmission seed parameter, and the method is applied to the server end, which may include the following steps 301 to step 303: In step 301, a data request carrying a first public key sent by the client is received, and the data request is used to request the server to return the seed parameters used to generate the offline payment code. The public key is the public key in the asymmetric key pair generated by the user end, and the asymmetric key pair generated by the user end also includes the first private key. Among them, when receiving the data request, if the data request only carries the first public key, step 302 can be directly executed; if the data request carries the first public key and the first signature information, it will be based on the public key and the first public key in the client certificate. The first public key verifies the first signature information, and step 302 is executed after the verification is passed. The manner in which the server obtains the public key in the client certificate may be pre-broadcasted by the client to the server, or the client may send it to the server when sending a data request. As one of the signature verification methods, the server can use the hash algorithm to hash the received first public key to obtain the second information digest, and use the public key in the client certificate to decrypt the first signature information. Obtain the first information digest and verify whether the first information digest and the second information digest are consistent. If they are the same, it means that the verification is passed. Only after the verification is passed, the server will return the ciphertext and the second key to the client. . In step 302, an asymmetric key pair including a second public key and a second private key is obtained, and a preset key agreement algorithm is used to generate a shared key according to the second private key and the first public key. Key. In step 303, the shared key is used to encrypt the seed parameters corresponding to the data request, and the encrypted ciphertext and the second public key are sent to the client, so that the client can follow the The first private key and the second public key use the key agreement algorithm to generate a shared key, and use the shared key to decrypt the ciphertext to obtain the seed parameter. Wherein, the generation time of the asymmetric key pair including the second public key and the second private key may not be specifically limited. For example, an asymmetric key pair can be generated every time a material request is received. For another example, the asymmetric key pair may not be generated when the material request is received, but when other conditions are met, so that the generated asymmetric key pair can be obtained when the material request is received. For example, a pair of asymmetric key pairs may be generated every set time interval, and each newly generated asymmetric key pair replaces the last generated asymmetric key pair. In an example, the second public key and the second private key may be a key pair generated by using the key generation algorithm. For example, when receiving a data request, the server uses the key generation algorithm to generate an asymmetric key pair that includes the second public key and the second private key each time. Symmetric key pairs are generally different, which can avoid the problem of insecure information encrypted with key pairs due to leaks of fixedly stored key pairs. Wherein, the asymmetric key pair formed by the first public key and the first private key and the asymmetric key pair formed by the second public key and the second private key are generated by the same key generation algorithm. Since the key generation algorithm uses different random numbers for each calculation, the asymmetric key pair generated by each calculation is almost different, so the asymmetric key pair generated by the user side and the asymmetric key pair generated by the server side are almost different. Generally different. After obtaining the second public key and the second private key, the server may use a preset key agreement algorithm to generate a shared key according to the second private key and the first public key. The key agreement algorithm may be called a key exchange algorithm, for example, it may be an ECDH algorithm. Among them, ECDH is a DH (Diffie-Hellman) key exchange algorithm based on ECC (Elliptic Curve Cryptosystems). So that the two parties can negotiate a common key without sharing any secrets. In this embodiment, the shared key generated by the preset key agreement algorithm according to the second private key and the first public key is different from the common key generated according to the first private key and the second public key. The shared keys generated by the key agreement algorithm are the same. As one of the implementations, the key agreement algorithm adopted by the client and the server is the same, and the key generation algorithm adopted by the client and the server are also the same, and the key agreement algorithm is the same as the key agreement algorithm. The generation algorithm satisfies: for any two asymmetric key pairs generated by the key generation algorithm, select the public key in any asymmetric key pair and the private key in the other asymmetric key pair , The negotiation results obtained by using the key agreement algorithm are the same. After obtaining the shared key, the server can use the shared key to encrypt the seed parameters corresponding to the data request, and send the encrypted ciphertext and the second public key to the client. Among them, the seed parameter is the seed parameter used to generate the offline payment code. After receiving the data request, the server can obtain the seed parameters according to the data request. The seed parameters corresponding to each user terminal can be the same or different, and the specific parameters are determined according to requirements. Regarding the sending of the second public key, in one example, the second public key can be directly sent to the user end to improve the sending efficiency. In another example, the method further includes: signing the second public key with a private key in the server certificate to obtain second signature information, and the server certificate is issued by a designated authority to the The server's certificate. When sending the encrypted ciphertext and the second public key to the client, the second signature information is also sent to the client, so that the client can follow the information in the server certificate The public key and the second public key verify the second signature information, and after the verification is passed, the client decrypts the ciphertext. Among them, the designated organization may be an organization that can issue certificates. The certificate issued by the designated authority to the server includes at least the private key and the public key, that is, the server certificate includes the private key and the public key. Regarding the manner in which the client obtains the public key in the server certificate, the server may pre-broadcast to the client, or the server may send the ciphertext and the second public key to the client when sending the ciphertext and the second public key. As one of the signature methods, the server can use the hash algorithm to hash the second public key to obtain the third information digest, and use the private key in the server certificate to encrypt the third information digest to obtain the second Signing information, and then sending the ciphertext, the second public key, and the second signature information to the client. The client terminal may verify the second signature information according to the public key in the server certificate and the second public key. After the verification is passed, the client terminal decrypts the ciphertext. As one of the signature verification methods, the client can use the hash algorithm to hash the received second public key to obtain the fourth information summary, and use the public key in the server certificate to decrypt the second signature information. Obtain the third information summary and verify whether the third information summary and the fourth information summary are consistent. If they are consistent, it means that the signature verification is passed. Only when the signature verification is passed, the client performs the operation of decrypting the ciphertext. It can be seen from the above embodiment that by signing the second public key and verifying the second signature information, when the verification is passed, it can be ensured that the second public key has not been tampered with, and the server certificate is used to ensure The data server is a secure end certified by an authority, so as to ensure the security of the negotiation process of the shared key. Corresponding to the embodiments of the data transmission method of the present invention, the present invention also provides embodiments of a data transmission device and a data transmission system. Refer to FIG. 4, which is a block diagram of an embodiment of the data transmission system of the present invention: The system 40 includes a data requesting end device 41 and a data providing end device 42. The material requesting end device 41 generates an asymmetric key pair including a first public key and a first private key, and sends a material request carrying the first public key to the material providing end device 42. The data provider device 42 obtains an asymmetric key pair including a second public key and a second private key, and uses a preset key agreement algorithm according to the second private key and the first public key Generate a common key. The data provider device 42 uses the shared key to encrypt the target data corresponding to the data request, and sends the encrypted ciphertext and the second public key to the data requester device 41. The data requesting end device 41 uses the key agreement algorithm to generate a common key according to the first private key and the second public key, and uses the common key to decrypt the ciphertext, Obtain the target data. Wherein, according to the second private key and the first public key, the shared key generated by using a preset key agreement algorithm is different from using the secret key according to the first private key and the second public key. The shared key generated by the key agreement algorithm is the same. In an optional implementation manner, the data requesting end device 41 uses the private key in the requesting end certificate to sign the first public key to obtain first signature information, and will carry the first public key The data request with the first signature information is sent to the data provider device 42, and the requester certificate is a certificate issued to the data requester by a designated authority. Before the data provider device 42 returns the ciphertext and the second public key to the data requester device 41, the first signature information is performed according to the public key in the requester certificate and the first public key. Check the signature and confirm that the signature is passed. In an optional implementation manner, the data provider device 42 uses the private key in the provider certificate to sign the second public key to obtain the second signature information, and then encrypts the encrypted cipher text and the When the second public key is sent to the data requesting device 41, the second signature information is also sent to the data requesting device 41; the provider certificate is a certificate issued to the data provider by a designated authority . Before decrypting the ciphertext, the data requesting end device 41 verifies the second signature information according to the public key in the provider certificate and the second public key, and determines that the verification is passed. Referring to FIG. 5, it is a block diagram of an embodiment of the data transmission device of the present invention: The device includes: a key generation module 51, a request sending module 52, an information receiving module 53, a shared key generation module 54 and information Decryption module 55. The key generation module 51 is used to generate an asymmetric key pair including the first public key and the first private key. The request sending module 52 is configured to send a data request carrying the first public key to the server. The information receiving module 53 is configured to receive the ciphertext and the second public key sent by the server, and the second public key is the public key in the asymmetric key pair obtained by the server. The obtained asymmetric key pair also includes a second private key. The ciphertext is information obtained by using a shared key to encrypt the seed parameters used to generate the offline payment code; the shared key is based on the second private key. The key and the first public key are keys generated by using a preset key agreement algorithm. The shared key generation module 54 is configured to generate a shared key by using the key agreement algorithm according to the first private key and the second public key. The information decryption module 55 is used to decrypt the ciphertext using the shared key to obtain the seed parameter. Wherein, according to the second private key and the first public key, the shared key generated by using a preset key agreement algorithm is different from using the secret key according to the first private key and the second public key. The shared key generated by the key agreement algorithm is the same. In an optional implementation manner, the request sending module 52 is specifically configured to: use the private key in the client certificate to sign the first public key to obtain first signature information, and the client certificate is The certificate issued by the designated authority to the client. Send a data request carrying the first public key and the first signature information to the server, so that the server uses the public key in the client certificate and the first public key to pair the first The signature information is verified, and the ciphertext and the second public key are sent to the client after the verification is passed. Refer to FIG. 6, which is a block diagram of another embodiment of the data transmission device of the present invention: The device includes: a request receiving module 61, a key acquisition module 62, a shared key generation module 63, an information encryption module 64, and Information sending module 65. Wherein, the request receiving module 61 is configured to receive a data request carrying the first public key sent by the client, and the data request is used to request the server to return the seed parameters used to generate the offline payment code. The public key is the public key in the asymmetric key pair generated by the user end, and the asymmetric key pair generated by the user end further includes the first private key. The key acquisition module 62 is used to acquire an asymmetric key pair including the second public key and the second private key. The shared key generation module 63 is configured to generate a shared key using a preset key agreement algorithm according to the second private key and the first public key. The information encryption module 64 is configured to use the shared key to encrypt the seed parameters corresponding to the data request. The information sending module 65 is used to send the encrypted ciphertext and the second public key to the user end, so that the user end uses all the information according to the first private key and the second public key. The key agreement algorithm generates a common key, and uses the common key to decrypt the ciphertext to obtain the seed parameter. Wherein, according to the second private key and the first public key, the shared key generated by using a preset key agreement algorithm is different from using the secret key according to the first private key and the second public key. The shared key generated by the key agreement algorithm is the same. In an optional implementation manner, the device 60 further includes (not shown in FIG. 6): a signature module for signing the second public key by using the private key in the server certificate to obtain the second public key Signature information, the server certificate is a certificate issued to the server by a designated authority. The information sending module 65 is also used to send the encrypted ciphertext and the second public key to the client, and also send the second signature information to the client so that the The client verifies the second signature information according to the public key in the server certificate and the second public key. After the verification is passed, the client decrypts the ciphertext. Based on this, the present invention also provides a wearable device that includes a secure element (SE) chip, and the secure element chip is used to: generate an asymmetric key including a first public key and a first private key Yes, send a data request carrying the first public key to the server. Receive the ciphertext and the second public key sent by the server, where the second public key is the public key in the asymmetric key pair obtained by the server, and the asymmetric key pair obtained by the server It also includes a second private key, and the ciphertext is information obtained by using a shared key to encrypt the seed parameters used to generate the offline payment code; the shared key is based on the second private key and the first public key , The key generated by the preset key agreement algorithm. According to the first private key and the second public key, the key agreement algorithm is used to generate a common key, and the common key is used to decrypt the ciphertext to obtain the seed parameter. Wherein, according to the second private key and the first public key, the shared key generated by using a preset key agreement algorithm is different from using the secret key according to the first private key and the second public key. The shared key generated by the key agreement algorithm is the same. It can be seen from the above embodiment that by configuring the SE in the wearable device, the generation of asymmetric key pairs, the generation of a shared key, the storage of target data, and the decryption of ciphertexts can be performed in the SE, and since the SE has Anti-cracking protection allows the target data to reach a very high level of security. In order to avoid the problem of information security in the prior art and the problem of time-consuming encryption and decryption, the present invention also provides another data transmission method, as shown in FIG. 7, which is a flowchart of another embodiment of the data transmission method of the present invention The method may include the following steps 701 to 708: In step 701, the data requester generates a first symmetric key. In step 702, the material requesting terminal sends a material request carrying the first symmetric key to the material providing terminal. In step 703, the data provider obtains a second symmetric key, and the second symmetric key is different from the first symmetric key. In step 704, the data provider uses a preset key agreement algorithm to generate a common key according to the first symmetric key and the second symmetric key. In step 705, the data provider uses the shared key to encrypt the target data corresponding to the data request. In step 706, the data provider sends the encrypted ciphertext and the second symmetric key to the data requester. In step 707, the material requester uses the key agreement algorithm to generate a common key according to the first symmetric key and the second symmetric key. In step 708, the data requester uses the shared key to decrypt the ciphertext to obtain the target data. It can be seen from the above embodiment that the first symmetric key can be obtained by the data requester, and the data request carrying the first symmetric key can be sent to the data provider, and the second symmetric key can be obtained by the data provider, and According to the first symmetric key and the second symmetric key, a preset key agreement algorithm is used to generate a shared key, and the shared key is used to encrypt data to request the corresponding target data, and finally the encrypted ciphertext and the first The second symmetric key is transmitted to the data requesting side, and the data requesting side uses the same key agreement algorithm to generate a common key according to the first symmetric key and the second symmetric key. Due to the key agreement between the data provider and the data requester The algorithm is the same, so the shared key generated by the data provider and the data requester is the same, and the data requester can decrypt the ciphertext with the generated shared key to obtain the target data. It can be seen that because the symmetric key algorithm uses a different random number for each calculation, the symmetric key pair generated by each calculation is different, and the symmetric key pair generated by different users is also different, which avoids the problem of a certain user equipment Or the secret key of the server-side device is leaked, causing all user-side devices and server-side devices to have security risks. At the same time, because the shared key is different from the first symmetric key and the second symmetric key, even The hacker hijacks the symmetric key and does not know which key agreement algorithm is used in the present invention, so the ciphertext cannot be decrypted, thereby ensuring the security of the data during the entire transmission process. In addition, since the shared key of the encrypted target data and the decrypted target data is the same, the symmetric key encryption and decryption algorithm is used to encrypt and decrypt the data to avoid the long encryption and decryption time caused by complex asymmetric encryption and decryption algorithms, thereby increasing The efficiency of encryption and decryption. Wherein, the key generation algorithm for generating the first symmetric key and the key generation algorithm for generating the second symmetric key may be the same or different, and the details are not limited. Since the symmetric key generated by the key generation algorithm is different each time, the second symmetric key is different from the first symmetric key. After obtaining the first symmetric key at the material requesting end, a material request carrying the first symmetric key can be generated according to the first symmetric key. Among them, the data request is a request for requesting target data. After the data request is generated, the data request can be sent to the data provider. In an example, the data requester can directly carry the first symmetric key by using the data request, thereby increasing the speed of generating the data request. In another example, the sending the data request carrying the first symmetric key to the data provider includes: The data requesting end uses the private key in the requesting end certificate to sign the first symmetric key to obtain first signature information, and the requesting end certificate is a certificate issued to the data requesting end by a designated authority. The terminal sends the data request carrying the first symmetric key and the first signature information to the data provider. Among them, the designated organization may be an organization that can issue certificates. The certificate issued by the designated authority to the data requester includes at least the private key and the public key. After the data provider receives the data request, the data provider can verify the first signature information based on the public key in the requester certificate and the first symmetric key. The data providing side performs the operation of returning the ciphertext and the second symmetric key to the data requesting side. It can be seen from the above embodiment that by signing the first symmetric key and verifying the first signature information, when the verification is passed, it can be ensured that the first symmetric key has not been tampered with, and at the same time, by the requester certificate Ensure that the data requesting end is the safe end certified by the authority, so as to ensure the security of the negotiation process of the shared key. The data provider can obtain the second symmetric key after receiving the data request. After obtaining the second symmetric key, the data provider may use a preset key agreement algorithm to generate a common key according to the first symmetric key and the second symmetric key. Among them, the key agreement algorithm can also be called a key exchange algorithm, for example, it can be an ECDH algorithm. Among them, ECDH is a DH (Diffie-Hellman) key exchange algorithm based on ECC (Elliptic Curve Cryptosystems). So that the two parties can negotiate a common key without sharing any secrets. The data provider may use the shared key to encrypt the target data corresponding to the data request, and send the encrypted ciphertext and the second symmetric key to the data requester. In an example, the data provider can directly send the second symmetric key to the data requester to improve the sending efficiency. In another example, the data provider uses the private key in the provider certificate to sign the second symmetric key to obtain second signature information, and the provider certificate is issued to the data provider by a designated authority. End certificate. When the data provider sends the encrypted ciphertext and the second symmetric key to the data requester, it also sends the second signature information to the data requester. Among them, the designated organization may be an organization that can issue certificates. The certificate issued by the designated authority to the data provider includes at least the private key and the public key, that is, the certificate of the provider includes the private key and the public key. The data requester verifies the second signature information according to the public key in the provider certificate and the second symmetric key. After the verification is passed, the data requester executes the ciphertext verification Steps of decryption. It can be seen from the above embodiment that by signing the second symmetric key and verifying the second signature information, when the verification is passed, it can be ensured that the second symmetric key has not been tampered with, and at the same time, by providing the certificate Ensure that the data provider is the secure end certified by an authority, so as to ensure the security of the negotiation process of the shared key. Corresponding to the embodiment of the data transmission method of the present invention, the present invention also provides an embodiment of the data transmission system. Refer to FIG. 8, which is a block diagram of another embodiment of the data transmission system of the present invention: The system 80 includes a data requesting end device 81 and a data providing end device 82. The material requesting end device 81 generates a first symmetric key, and sends a material request carrying the first symmetric key to the material providing end device 82. The material providing end device 82 obtains a second symmetric key, and uses a preset key agreement algorithm to generate a common key according to the first symmetric key and the second symmetric key. The symmetric key is different from the first symmetric key. The data provider device 82 uses the shared key to encrypt the target data corresponding to the data request, and sends the encrypted ciphertext and the second symmetric key to the data requester device 81. The material requesting end device 81 uses the key agreement algorithm to generate a common key according to the first symmetric key and the second symmetric key, and uses the common key to perform processing on the ciphertext Decrypt to obtain the target data. For the implementation process of the functions and roles of each module in the above-mentioned device, please refer to the implementation process of the corresponding steps in the above-mentioned method for details, which will not be repeated here. For the device embodiment, since it basically corresponds to the method embodiment, the relevant part can refer to the part of the description of the method embodiment. The device embodiments described above are merely illustrative. The modules described as separate components may or may not be physically separate, and the components displayed as modules may or may not be physical modules. It can be located in one place, or it can be distributed to multiple network modules. Some or all of the modules can be selected according to actual needs to achieve the objectives of the solution of the present invention. Those of ordinary skill in the art can understand and implement it without making progressive labor. Those skilled in the art will easily think of other embodiments of the present invention after considering the specification and practicing the invention applied here. The present invention is intended to cover any variations, uses, or adaptive changes of the present invention. These variations, uses, or adaptive changes follow the general principles of the present invention and include common knowledge or common knowledge in the technical field that the present invention has not applied for. Conventional technical means. The description and the embodiments are only regarded as examples, and the true scope and spirit of the present invention are pointed out by the following patent application scope. It should be understood that the present invention is not limited to the precise structure described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present invention is only limited by the scope of the attached patent application.
<p>101~108Step</p><p>201~203Step</p><p>301~303Step</p><p>40System</p><p>41Data request side device</p><p>42Data provider device</p><p>51Key Generation Module</p><p>52Request sending module</p><p>53Information receiving module</p><p>54Shared key generation module</p><p>55Information Decryption Module</p><p>61Request receiving module</p><p>62Key Acquisition Module</p><p>63Shared key generation module</p><p>64Information Encryption Module</p><p>65Information sending module</p><p>701~708Step</p><p>80System</p><p>81Data request side device</p><p>82Data provider device</p>
The drawings herein are incorporated into the specification and constitute a part of the specification, show embodiments consistent with the present invention, and together with the specification are used to explain the principle of the present invention. FIG. 1A is a schematic diagram of an application scenario of data transmission according to an exemplary embodiment of the present invention. FIG. 1B is a flowchart of an embodiment of the data transmission method of the present invention. FIG. 2 is a flowchart of another embodiment of the data transmission method of the present invention. FIG. 3 is a flowchart of another embodiment of the data transmission method of the present invention. Fig. 4 is a block diagram of an embodiment of the data transmission system of the present invention. Fig. 5 is a block diagram of an embodiment of the data transmission device of the present invention. FIG. 6 is a block diagram of another embodiment of the data transmission device of the present invention. FIG. 7 is a flowchart of another embodiment of the data transmission method of the present invention. Fig. 8 is a block diagram of another embodiment of the data transmission system of the present invention.
<bio-deposit></bio-deposit>
<sequence-list-text></sequence-list-text>
9 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| WO02086830A1 | Cites | World Intellectual Property Organization (WIPO) | Examiner |
| CN1400819A | Cites | China | Examiner |
| EP2285040A1 | Cites | European Patent Office (EPO) | Examiner |
| US6941457B1 | Cites | United States of America | Examiner |
| WO2002086830A1 | Cites | World Intellectual Property Organization (WIPO) | – |
30 members in 16 offices
Members30
| Document | Office | Kind | |
|---|---|---|---|
| CN107040369A | China | A | |
| ZA201902947A0 | South Africa | A0 | |
| TW201817193A | Taiwan Province of China | A | |
| CA3041664A1 | Canada | A1 | |
| WO2018077086A1 | World Intellectual Property Organization (WIPO) | A1 | |
| TWI641258BThis record | Taiwan Province of China | B | |
| AU2017352361A1 | Australia | A1 | |
| SG11201903671WA | Singapore | A | |
| KR20190073472A | Republic of Korea | A | |
| BR112019008371A2 | Brazil | A2 | |
| MX2019004948A | Mexico | A | |
| US2019253249A1 | United States of America | A1 | |
| EP3534565A1 | European Patent Office (EPO) | A1 | |
| EP3534565A4 | European Patent Office (EPO) | A4 | |
| JP2019533384A | Japan | A | |
| PH12019500938A1 | Philippines | A1 | |
| AU2019101594A4 | Australia | A4 | |
| CN107040369B | China | B | |
| RU2715163C1 | Russian Federation | C1 | |
| CN111585749A | China | A | |
| ZA201902947B | South Africa | B | |
| EP3534565B1 | European Patent Office (EPO) | B1 | |
| KR20200127264A | Republic of Korea | A | |
| AU2017352361B2 | Australia | B2 | |
| CA3041664C | Canada | C | |
| JP2021083076A | Japan | A | |
| ES2837039T3 | Spain | T3 | |
| JP7119040B2 | Japan | B2 | |
| CN111585749B | China | B | |
| MX379285B | Mexico | B |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Annulment or lapse of patent due to non-payment of feesLapsedMM4A | MM4A |
Numbers
- Publication
- I641258
- Application
- 106131351
Titles2
- Chinese
- 資料傳輸方法、裝置及系統
- English
- Data transmission method, device and system
Classification
- CPC, 18
- H04L9/0838
- G06Q20/085
- H04L9/3073
- H04L9/085
- H04L63/0428
- H04L9/0825
- H04L9/0861
- G06Q20/401
- G06Q2220/00
- G06Q20/20
- G06Q20/382
- G06Q20/327
- G06Q20/204
- G06Q20/3829
- G06Q20/4097
- H04L9/0841
- H04L9/14
- G06Q20/40
- IPC, 2
- H04L9 14
- G06Q20 38