WO2018113708A1 - 一种邮件发送、查看、查看控制方法及其设备 - Google Patents

一种邮件发送、查看、查看控制方法及其设备 Download PDF

Info

Publication number
WO2018113708A1
WO2018113708A1 PCT/CN2017/117564 CN2017117564W WO2018113708A1 WO 2018113708 A1 WO2018113708 A1 WO 2018113708A1 CN 2017117564 W CN2017117564 W CN 2017117564W WO 2018113708 A1 WO2018113708 A1 WO 2018113708A1
Authority
WO
WIPO (PCT)
Prior art keywords
mail
time
key
encrypted
sent
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2017/117564
Other languages
English (en)
French (fr)
Inventor
曾溪泉
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Beijing Qihoo Technology Co Ltd
Original Assignee
Beijing Qihoo Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Beijing Qihoo Technology Co Ltd filed Critical Beijing Qihoo Technology Co Ltd
Publication of WO2018113708A1 publication Critical patent/WO2018113708A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L51/00User-to-user messaging in packet-switching networks, transmitted according to store-and-forward or real-time protocols, e.g. e-mail
    • H04L51/42Mailbox-related aspects, e.g. synchronisation of mailboxes
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/04Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
    • H04L63/0428Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/06Network architectures or network communication protocols for network security for supporting key management in a packet data network
    • H04L63/068Network architectures or network communication protocols for network security for supporting key management in a packet data network using time-dependent keys, e.g. periodically changing keys

Definitions

  • the present invention relates to the field of communications technologies, and in particular, to a mail sending, viewing, viewing control method and device thereof.
  • E-mail ElectronicMail, Email
  • ElectronicMail is a common office communication tool for people's daily work. Technicians frequently use office computers, personal computers, mobile phones, etc. in the course of their work. Electronic products send and receive e-mail, so the information security of e-mail becomes especially important. However, in the current use of e-mail, it is usually set up a complex mailbox account password to secure the mail.
  • this way of sending and receiving mail through the password of the mailbox account only realizes the encryption of the mail communication, and can not realize the whole process of encrypting the content of the email.
  • the method of encrypting the content of the email is also used in the market, and the encryption method adopted is adopted. It is encrypted with a certificate and a public key. Knowing the private key corresponding to the public key can decrypt the content of the email and browse it, whether it is encrypting the email communication through the password of the email account or encrypting the content of the email through the certificate and the public key.
  • encrypted mail is not time-sensitive and easy to crack.
  • the present invention provides a mail sending, viewing, viewing control method and apparatus thereof that overcome the above problems or at least partially solve the above problems.
  • the specific technical solutions are:
  • An embodiment of the present application provides a mail sending method, where the method includes:
  • the present invention also provides a mail viewing method, which is applied to a mail receiving end, and the method includes:
  • the feedback information is generated by the server according to the request time of the key request and the time key sent by the sending end, when the request time exceeds the
  • the feedback information is information indicating that the encrypted mail is invalid, and the feedback information is the time key when the request time is within a time range corresponding to the time key.
  • the present invention also provides a mail viewing control method, which is applied to a server, and the method includes:
  • the time key is refused to be distributed to the mail receiving end, so that the mail receiving end cannot decrypt and view the encrypted mail;
  • the time key is issued to the mail receiving end, so that the mail receiving end decrypts and views the encrypted mail according to the time key.
  • the invention also provides a mail sending end, comprising:
  • An obtaining unit a time key for obtaining a mail to be sent, wherein the time key is used to limit a time limit during which the mail to be sent can be viewed;
  • An encryption unit configured to encrypt the to-be-sent email according to the time key to generate an encrypted email
  • the first sending unit is configured to send the encrypted mail to the recipient, send the time key to the server, and control, by the server, whether the recipient can view the encrypted mail according to the time key.
  • the invention also provides a mail receiving end, comprising:
  • a first receiving unit configured to receive an encrypted mail that is encrypted according to a time key, where the time key is used to limit a time limit during which the encrypted mail can be viewed;
  • a response requesting unit configured to generate and send a key request to the server in response to the viewing operation of viewing the encrypted mail, the key requesting to acquire the time key of the encrypted mail;
  • a second receiving unit configured to receive feedback information that is sent by the server to the key request, where the feedback information is generated by the server according to the request time of the key request and the time key sent by the sending end,
  • the feedback information is information indicating that the encrypted mail is invalid when the request time exceeds a time range corresponding to the time key, and the feedback is when the request time is within a time range corresponding to the time key.
  • the information is the time key;
  • the parsing response unit is configured to parse the feedback information, and respond to the viewing operation according to the parsing result.
  • the invention also provides a mail server, comprising:
  • a third receiving unit configured to receive a key request for obtaining an encrypted mail time key sent by the mail receiving end;
  • a verification unit configured to compare a request time of the mail receiving end requesting the time key with a time range corresponding to the time key;
  • a second sending unit configured to refuse to issue the time key to the mail receiving end if the request time exceeds the time range, so that the mail receiving end cannot decrypt and view the encrypted mail;
  • the time key is issued to the mail receiving end, so that the mail receiving end decrypts and views the encrypted mail according to the time key.
  • the present invention also provides a computer program comprising computer readable code that, when executed on a computing device, causes the computing device to perform a mailing method according to the above, or to perform a mail viewing as described above The method, or the mail viewing control method as described above.
  • the invention also provides a computer readable medium storing a computer program as described above.
  • the encryption method of the present invention uses the time key to encrypt the mail to be sent, and the time key is used to limit the time limit for the mail to be sent to be viewed, that is, after the time limit, the mail will be Can not be viewed again, to ensure the timeliness of the mail; at the same time, the time key used to encrypt the mail is sent to the server, and the server manages the issuance of the key, thereby controlling whether the encrypted mail can be viewed, ensuring the mail
  • the high security of the information during transmission and use and the timeliness of the mail solve the technical problem that the encrypted mail in the prior art is not time-sensitive and easy to crack.
  • FIG. 1 is a flow chart showing a mail sending method according to an embodiment of the present invention
  • FIG. 2 is a flow chart showing a mail viewing method according to an embodiment of the present invention.
  • FIG. 3 is a flowchart of a mail viewing control method according to an embodiment of the present invention.
  • FIG. 4 is a schematic diagram of a mail sending end according to an embodiment of the present invention.
  • FIG. 5 is a schematic diagram of a mail receiving end according to an embodiment of the present invention.
  • FIG. 6 shows a schematic diagram of a mail server according to an embodiment of the present invention
  • Figure 5 shows schematically a block diagram of a computing device for performing the method according to the invention
  • Fig. 6 schematically shows a storage unit for holding or carrying program code implementing the method according to the invention.
  • the embodiments of the present invention provide a mail sending, viewing, and viewing control method and a device thereof, which are used to solve the technical problem that the encrypted mail in the prior art is not time-sensitive and easy to crack.
  • a method for sending a mail includes the following steps:
  • S11 Obtain a time key of the to-be-sent mail, where the time key is used to limit a time limit during which the to-be-sent mail can be viewed;
  • S12 Encrypt the to-be-sent email according to the time key to generate an encrypted email.
  • S13 Send the encrypted mail to the recipient, send the time key to the server, and control, by the server, whether the recipient can view the encrypted mail according to the time key.
  • the foregoing mail sending method provided by the present application can be applied to the use of IMAP (Internet Mail Access Protocol)/POP3 (Post Office Protocol 3), the third post office protocol. Versions) / SMTP (Simple Mail Transfer Protocol) / ESMTP (Extended SMTP) to send and receive e-mail to the mail client, and the mail client can be used to build various mail servers. You need to complete the configuration according to the relevant mail server address. For example, if a mail client wants to use the SINA mail server, you can configure the receiving mail server address (POP3) as: pop.sina.com.cn or: pop3.sina. Com.cn, the mail server address (SMTP) is: smtp.sina.com.cn, which can be used. This method is widely used and easy to operate.
  • Step S11 Obtain a time key of the mail to be sent, where the time key is used to limit the time limit in which the to-be-sent mail can be viewed.
  • S111 Obtain an expiration time of the to-be-sent mail, where the expiration time is an expiration time after the sending of the mail;
  • Step S111 Obtain an expiration time of the to-be-sent mail, and the expiration time may be generated in the following manner:
  • the first way the expiration time is set by the sender.
  • the specific method is as follows: the sender of the mail sets the entry of the input invalidation time instruction before the sender sends the new mail. For example, the sender can manually enter or manually select the expiration time through the portal, such as manual entry or selection.
  • the time is “2016-8-1 11:30”, that is, the mail expiration time is “2016-8-1 11:30”.
  • the specific method is that the expiration time is automatically generated by the sending time of the mail sending end plus a fixed period.
  • the time for sending the mail is “2016-8-1 11:30”, and the fixed period is 30. Day, then the expiration time is "2016-8-31 11:30".
  • the fixed period setting is a function integration at the time of development of the mail system.
  • the present invention is not limited.
  • Step S112 Obtain a time key according to the expiration time.
  • the specific time key may be a time public key ID calculated by using an identification cryptographic algorithm, and at least the following two methods are:
  • the first method the original mail data can be encrypted by using a symmetric encryption method.
  • the principle of the symmetric encryption algorithm is that the data sender and the plaintext (original data) and the encryption key are processed together by the encryption algorithm to make it complicated.
  • the encrypted ciphertext is sent out.
  • the receiving party wants to interpret the original data, it needs to decrypt the ciphertext by using the encrypted used key and the inverse algorithm of the same encryption algorithm, so that it can be restored to a readable plaintext.
  • the symmetric encryption algorithm there is only one key used, and both parties send and receive the key to encrypt and decrypt the data.
  • the advantage of the symmetric encryption algorithm is the high speed of encryption and decryption and the difficulty of using long keys. .
  • the second method the time key can also be obtained by an asymmetric encryption algorithm.
  • the asymmetric encryption algorithm requires two keys: a public key (publickey) and a private key (privatekey).
  • the public key and the private key are a pair. If the data is encrypted with the public key, only the corresponding private key can be used for decryption; if the data is encrypted with the private key, only the corresponding public key can be used. Decrypt.
  • the characteristic of the asymmetric cryptosystem is that the encryption and decryption speed is slower than the symmetric encryption, but the encryption algorithm has complex strength and high security.
  • Step S12 Encrypt the to-be-sent email according to the time key to generate an encrypted email.
  • Step S12 may be implemented by using a method 1: encrypting the to-be-sent mail by using the time key to generate the encrypted mail;
  • the original mail data may be encrypted by using a symmetric encryption method, and the specific encrypted content is as follows:
  • EncrpytBySym email data ciphertext
  • fx_encryptBySym ori (mail content), ID (time key)
  • ori is all content of EML (including mail header, mail body)
  • EncrpytBySym is encryption
  • the obtained mail data ciphertext, the encryption strength used for encryption is AES256.
  • Step S12 may also be implemented by using method 2: generating a session key, and encrypting the to-be-sent mail by using the combination of the time key and the session key to generate the encrypted mail;
  • the algorithm that generates the session key generates a session key. Then, the session key is used to encrypt the mail to be sent, and the mail data ciphertext in the encrypted mail is generated, and the specific method is:
  • the session key is encrypted by using the time key to generate a session key ciphertext in the encrypted mail;
  • the specific method may be:
  • Session key ciphertext id1_encryptdata fx_encryptByIBC (SessionPassword, ID (time key)), this encryption algorithm uses sm9 encryption algorithm, the encryption strength is RSA3072.
  • the encrypted mail may be an encapsulated package generated by the mail data ciphertext and the session key ciphertext before being sent; the mail data ciphertext and the session key ciphertext are encapsulated in a P7 format,
  • the specific encapsulation format of the XXX mail system is as follows:
  • Encryption type XXXsmail
  • Encryption algorithm id-ibc-enc-kem-sok-esbdh
  • Encoding type dem-dem3, hmacSHA
  • Decryptable time stamp yyyymmddhhnnsszzz
  • step S13 may be performed: sending the encrypted mail to the recipient, sending the time key to the server, and controlling, by the server, whether the recipient can view the location according to the time key.
  • Encrypted mail A method of controlling whether the server can view the encrypted mail according to the time key according to the time key will be described in detail later.
  • a mail viewing method provided by an embodiment of the present application is applied to a mail receiving end, and the method includes:
  • S21 Receive an encrypted email that is encrypted according to a time key, where the time key is used to limit a time period during which the encrypted email can be viewed;
  • S22 Respond to the viewing operation of viewing the encrypted mail, generate and send a key request to the server, where the key request is used to obtain the time key of the encrypted mail;
  • S23 Receive feedback information that the server responds to the key request, where the feedback information is generated by the server according to the request time of the key request and the time key sent by the sending end, when the request time is When the time range corresponding to the time key is exceeded, the feedback information is information indicating that the encrypted mail is invalid, and the feedback information is the time when the request time is within a time range corresponding to the time key.
  • the responding to the viewing operation according to the parsing result includes:
  • step S241 is performed: in response to the viewing operation, prompting the user that the encrypted mail has expired and cannot be viewed;
  • step S242 is performed: in response to the viewing operation, decrypting the encrypted mail according to the time key, obtaining mail data and displaying;
  • step S242 the decrypting the encrypted mail according to the time key may be performed in two ways:
  • Method 1 decrypting the encrypted mail by using the time key to obtain mail data
  • Or method 2 parsing the encapsulated packet of the encrypted mail to obtain a session key ciphertext in the encrypted mail; decrypting the session key ciphertext with the time key to obtain a session key; using the session secret The key decrypts the mail data ciphertext in the encrypted mail to obtain the mail data.
  • S21 Receive an encrypted email that is encrypted according to a time key, where the time key is used to limit a time period during which the encrypted email can be viewed;
  • the time key can be the time public key ID calculated by the identification cryptographic algorithm, and there are at least two methods:
  • the first method the original mail data can be encrypted by using a symmetric encryption method.
  • the principle of the symmetric encryption algorithm is that the data sender and the plaintext (original data) and the encryption key are processed together by the encryption algorithm to make it complicated.
  • the encrypted ciphertext is sent out.
  • the receiving party wants to interpret the original data, it needs to decrypt the ciphertext by using the encrypted used key and the inverse algorithm of the same encryption algorithm, so that it can be restored to a readable plaintext.
  • the symmetric encryption algorithm there is only one key used, and both parties send and receive the key to encrypt and decrypt the data.
  • the advantage of the symmetric encryption algorithm is the high speed of encryption and decryption and the difficulty of using long keys. .
  • the second method the time key can also be obtained by an asymmetric encryption algorithm.
  • the asymmetric encryption algorithm requires two keys: a public key (publickey) and a private key (privatekey).
  • the public key and the private key are a pair. If the data is encrypted with the public key, only the corresponding private key can be used for decryption; if the data is encrypted with the private key, only the corresponding public key can be used. Decrypt.
  • the characteristic of the asymmetric cryptosystem is that the encryption and decryption speed is slower than the symmetric encryption, but the encryption algorithm has complex strength and high security.
  • S22 Respond to the viewing operation of viewing the encrypted mail, generate and send a key request to the server, where the key request is used to obtain the time key of the encrypted mail;
  • the mail receiving end sends a key request to the server to obtain a time key, where the time key is issued by the server by verifying whether the time for applying the time key by the mail receiving end is within a time range corresponding to the time key.
  • the server is generally a CA server; the so-called CA, which is a digital certificate authentication center (CertficateAuthority, CA), is a key link in the security of the entire online electronic transaction. It is primarily responsible for generating, distributing, and managing the identity authentication digital certificates required by all entities involved in online transactions.
  • S23 Receive feedback information that the server responds to the key request, where the feedback information is generated by the server according to the request time of the key request and the time key sent by the sending end, when the request time is When the time range corresponding to the time key is exceeded, the feedback information is information indicating that the encrypted mail is invalid, and the feedback information is the time when the request time is within a time range corresponding to the time key. Key.
  • an example is as follows:
  • the request time for the mail receiving end to send a key request to the server is 2016-8-20 10:10:10, and the time key corresponding to the time key sent by the mail sending end is 2016-8-10 10:10:10, then the request is made.
  • the time exceeds the time range corresponding to the time key, and the feedback information sent by the server to the mail receiving end is invalid for the encrypted mail, and the time key corresponding to the time key sent by the mail sending end is 2016-8-30 10:10:10, then the request is The time is within the time range corresponding to the time key, and the feedback information sent by the server to the mail receiving end is the time key.
  • the responding to the viewing operation according to the parsing result includes:
  • step S241 the mail receiving end responds to the viewing operation, prompting the user that the encrypted mail has expired and cannot be viewed;
  • step S242 the mail receiving end responds to the viewing operation, decrypts the encrypted mail according to the time key, obtains mail data and displays it;
  • step S242 the decrypting the encrypted mail according to the time key may be performed in two ways:
  • Method 1 decrypting the encrypted mail by using the time key to obtain mail data
  • Or method 2 parsing the encapsulated packet of the encrypted mail to obtain a session key ciphertext in the encrypted mail; decrypting the session key ciphertext with the time key to obtain a session key; using the session secret Key decrypting the mail data ciphertext in the encrypted mail to obtain mail data;
  • the mail receiving end parses the session key ciphertext with the time key to obtain the session key.
  • the session key SessionPassword is "1234567890”
  • the package package here is the P7 format package data generated in the foregoing mail sending method, and the specific package data is as follows:
  • Encryption algorithm id-ibc-enc-kem-sok-esbdh
  • Encoding type dem-dem3, hmacSHA
  • Decryptable time stamp yyyymmddhhnnsszzz
  • the session key ciphertext id1_encryptdata and the expiration time yyyymmddhhnnsszzz can be obtained therefrom.
  • a mail viewing control method applied to a server including:
  • S31 Receive a key request for obtaining an encrypted mail time key sent by the mail receiving end;
  • executing S322 issuing the time key to the mail receiving end, so that the mail receiving end decrypts and views the encrypted mail according to the time key.
  • step S32 correspond to step S23.
  • step S321 and step S322 correspond to S241 and S242, respectively.
  • the encrypted transmission, the decryption reception, and the viewing control of the mail are performed by the aforementioned method, and the mail system includes the aforementioned mail transmitting end, mail receiving end, and server.
  • the mail sending end includes:
  • the obtaining unit 21 a time key for obtaining a mail to be sent, where the time key is used to limit a time limit during which the mail to be sent can be viewed;
  • the encryption unit 22 is configured to encrypt the to-be-sent mail according to the time key to generate an encrypted mail.
  • a first sending unit 23 configured to send the encrypted mail to a recipient, send the time key to a server, and control, by the server, whether the recipient can view the encrypted mail according to the time key .
  • the obtaining unit 21 includes:
  • the time acquisition subunit is configured to obtain an expiration time of the to-be-sent mail, where the expiration time is an expiration time after the mail is sent;
  • the time acquisition subunit is configured to obtain the expiration time by adding a sending time of the to-be-sent mail to a fixed period.
  • the encryption unit 22 includes:
  • a first encryption subunit configured to encrypt the to-be-sent mail by using the time key to generate the encrypted mail
  • the second encryption subunit is configured to generate a session key, and the to-be-sent mail is encrypted by using the combination of the time key and the session key to generate the encrypted mail.
  • the second encryption subunit is configured to:
  • the session key is encrypted with the time key to generate a session key ciphertext in the encrypted mail.
  • the mail receiving end includes:
  • the first receiving unit 31 is configured to receive an encrypted mail that is encrypted according to a time key, where the time key is used to limit a time limit during which the encrypted mail can be viewed;
  • the response requesting unit 32 is configured to generate and send a key request to the server in response to the viewing operation of viewing the encrypted mail, where the key request is used to acquire the time key of the encrypted mail;
  • the second receiving unit 33 is configured to receive feedback information that is sent by the server to the key request, where the feedback information is generated by the server according to the request time of the key request and the time key sent by the sending end. And when the request time exceeds a time range corresponding to the time key, the feedback information is information indicating that the encrypted mail is invalid, and when the request time is within a time range corresponding to the time key, The feedback information is the time key;
  • the parsing response unit 34 is configured to parse the feedback information, and respond to the viewing operation according to the parsing result.
  • parsing response unit 34 is configured to:
  • the parsing response unit 34 includes:
  • a first parsing response subunit configured to decrypt the encrypted mail with the time key to obtain mail data
  • a second parsing response subunit configured to parse the encapsulated packet of the encrypted mail to obtain a session key ciphertext in the encrypted mail; decrypt the session key ciphertext with the time key, to obtain a session key; Decrypting the mail data ciphertext in the encrypted mail with the session key to obtain mail data.
  • the mail server includes:
  • the third receiving unit 41 is configured to receive a key request for acquiring an encrypted mail time key sent by the mail receiving end;
  • the verification unit 42 is configured to compare the request time of the mail receiving end requesting the time key with a time range corresponding to the time key;
  • the second sending unit 43 is configured to: when the request time exceeds the time range, refuse to issue the time key to the mail receiving end, so that the mail receiving end cannot decrypt and view the encrypted mail; When the time key is issued to the mail receiving end without exceeding the time range, the mail receiving end decrypts and views the encrypted mail according to the time key.
  • the encryption method of the present invention uses the time key to encrypt the mail to be sent, and the time key is used to limit the time limit for the mail to be sent to be viewed, that is, after the time limit, the mail will be Can not be viewed again, to ensure the timeliness of the mail; at the same time, the time key used to encrypt the mail is sent to the server, and the server manages the issuance of the key, thereby controlling whether the encrypted mail can be viewed, ensuring the mail
  • the high security of the information during transmission and use and the timeliness of the mail solve the technical problem that the encrypted mail in the prior art is not time-sensitive and easy to crack.
  • modules in the devices of the embodiments can be adaptively changed and placed in one or more devices different from the embodiment.
  • the modules or units or components of the embodiments may be combined into one module or unit or component, and further they may be divided into a plurality of sub-modules or sub-units or sub-components.
  • any combination of the features disclosed in the specification, including the accompanying claims, the abstract and the drawings, and any methods so disclosed, or All processes or units of the device are combined.
  • Each feature disclosed in this specification (including the accompanying claims, the abstract and the drawings) may be replaced by alternative features that provide the same, equivalent or similar purpose.
  • the various component embodiments of the present invention may be implemented in hardware, or in a software module running on one or more processors, or in a combination thereof.
  • a microprocessor or digital signal processor may be used in practice to implement some or all of the components of the mail sender, mail receiver, and mail server in accordance with embodiments of the present invention. Or all features.
  • the invention can also be implemented as a device or device program (e.g., a computer program and a computer program product) for performing some or all of the methods described herein.
  • Such a program implementing the invention may be stored on a computer readable medium or may be in the form of one or more signals. Such signals may be downloaded from an Internet website server, provided on a carrier signal, or provided in any other form.
  • Figure 7 shows a block diagram of a computing device for performing the method in accordance with the present invention.
  • the computing device conventionally includes a processor 710 and a computer program product or computer readable medium in the form of a memory 720.
  • Memory 720 can be an electronic memory such as a flash memory, EEPROM (Electrically Erasable Programmable Read Only Memory), EPROM, hard disk, or ROM.
  • Memory 720 has a storage space 730 that stores program code 731 for performing any of the method steps described above.
  • storage space 730 for program code may include various program code 731 for implementing various steps in the above methods, respectively.
  • the program code can be read from or written to one or more computer program products.
  • These computer program products include program code carriers such as hard disks, compact disks (CDs), memory cards or floppy disks.
  • Such computer program products are typically portable or fixed storage units such as those described in FIG.
  • the storage unit may have storage segments, storage spaces, and the like that are similarly arranged to memory 720 in the computing device of FIG.
  • the program code can be compressed, for example, in an appropriate form.
  • the storage unit stores computer readable program code 731' for performing the steps of the method according to the present invention, ie program code readable by a processor such as 710, when the program code is run by the computing device, resulting in The computing device performs the various steps in the methods described above.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Information Transfer Between Computers (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

本发明公开了一种邮件发送、查看、查看控制方法及其设备。该方法包括:获得待发送邮件的时间密钥,所述时间密钥用于限制所述待发送邮件可被查看的时间期限;根据所述时间密钥,对所述待发送邮件进行加密生成加密邮件;发送所述加密邮件至收件方,发送所述时间密钥至服务器并通过所述服务器根据所述时间密钥控制所述收件方是否可查看所述加密邮件。本发明为邮件提供了过期失效的保障,使邮件的安全性、时效性更高,加密范围更广。

Description

一种邮件发送、查看、查看控制方法及其设备 技术领域
本发明涉及通信技术领域,尤其涉及一种邮件发送、查看、查看控制方法及其设备。
背景技术
随着科技的发展,电子邮件的应用范围越来越广,电子邮件(ElectronicMail,Email)是人们日常工作常用的办公通信工具,技术人员在工作过程中会频繁利用办公电脑、个人电脑、手机等电子产品收发电子邮件,因此,电子邮件的信息安全就变得尤其重要,然而在目前邮件的使用过程中,通常是设置复杂的邮箱帐户密码以求邮件的安全。
事实上,这种通过邮箱账户密码来收发邮件的方式只实现了邮件通讯加密,并不能实现电子邮件内容的全程加密,目前,市场上也有使用对电子邮件内容进行加密的方法,采取的加密方法是用证书和公钥来加密,知晓公钥对应的私钥才能解密该邮件内容并浏览,无论是通过邮箱账户密码来对邮件通讯进行加密还是通过证书和公钥来对邮件内容进行加密,不足之处在于:加密邮件不具有时效性,易于破解。
发明内容
鉴于上述问题,本发明提出了一种克服上述问题或者至少部分地解决上述问题的邮件发送、查看、查看控制方法及其设备,具体技术方案是:
本申请实施例提供一种邮件发送方法,所述方法包括:
获得待发送邮件的时间密钥,所述时间密钥用于限制所述待发送邮件可被查看的时间期限;
根据所述时间密钥,对所述待发送邮件进行加密生成加密邮件;
发送所述加密邮件至收件方,发送所述时间密钥至服务器并通过所述服务器根据所述时间密钥控制所述收件方是否可查看所述加密邮件。
本发明还提供一种邮件查看方法,应用于邮件接收端,所述方法包括:
接收根据时间密钥进行加密的加密邮件,所述时间密钥用于限制所述加密邮件可被查看的时间期限;
响应查看所述加密邮件的查看操作,生成并发送密钥请求至服务器,所述密钥 请求用于获取所述加密邮件的所述时间密钥;
接收所述服务器响应所述密钥请求的反馈信息,所述反馈信息由所述服务器根据所述密钥请求的请求时间和发送端发送的所述时间密钥生成,当所述请求时间超出所述时间密钥对应的时间范围时所述反馈信息为表征所述加密邮件无效的信息,当所述请求时间在所述时间密钥对应的时间范围内时所述反馈信息为所述时间密钥;
解析所述反馈信息,根据解析结果响应所述查看操作。
本发明还提供一种邮件查看控制方法,应用于服务器,所述方法包括:
接收邮件接收端发送的获取加密邮件时间密钥的密钥请求;
将所述邮件接收端请求所述时间密钥的请求时间与所述时间密钥对应的时间范围进行比较;
如果所述请求时间超出所述时间范围,拒绝向邮件接收端发放所述时间密钥,使得邮件接收端无法对加密邮件进行解密及查看;
如果所述请求时间未超出所述时间范围,向邮件接收端发放所述时间密钥,使得邮件接收端根据所述时间密钥对加密邮件进行解密并查看。
本发明还提供一种邮件发送端,包括:
获取单元:用于获得待发送邮件的时间密钥,所述时间密钥用于限制待发送邮件可被查看的时间期限;
加密单元:用于根据所述时间密钥,对所述待发送邮件进行加密生成加密邮件;
第一发送单元:用于发送所述加密邮件至收件方,发送所述时间密钥至服务器并通过所述服务器根据所述时间密钥控制所述收件方是否可查看所述加密邮件。
本发明还提供一种邮件接收端,包括:
第一接收单元:用于接收根据时间密钥进行加密的加密邮件,所述时间密钥用于限制所述加密邮件可被查看的时间期限;
响应请求单元:用于响应查看所述加密邮件的查看操作,生成并发送密钥请求至服务器,所述密钥请求用于获取所述加密邮件的所述时间密钥;
第二接收单元:用于接收所述服务器响应所述密钥请求的反馈信息,所述反馈信息由所述服务器根据所述密钥请求的请求时间和发送端发送的所述时间密钥生成,当所述请求时间超出所述时间密钥对应的时间范围时所述反馈信息为表征所述加密邮件无效的信息,当所述请求时间在所述时间密钥对应的时间范围内时所述反馈信息为所述时间密钥;
解析响应单元:用于解析所述反馈信息,根据解析结果响应所述查看操作。
本发明还提供一种邮件服务器,包括:
第三接收单元:用于接收邮件接收端发送的获取加密邮件时间密钥的密钥请求;
验证单元:用于将所述邮件接收端请求所述时间密钥的请求时间与所述时间密钥对应的时间范围进行比较;
第二发送单元:用于如果所述请求时间超出所述时间范围,拒绝向邮件接收端发放所述时间密钥,使得邮件接收端无法对加密邮件进行解密及查看;
如果所述请求时间未超出所述时间范围,向邮件接收端发放所述时间密钥,使得邮件接收端根据所述时间密钥对加密邮件进行解密并查看。
本发明还提供一种计算机程序,包括计算机可读代码,当所述计算机可读代码在计算设备上运行时,导致所述计算设备执行根据如上述的邮件发送方法,或者执行如上述的邮件查看方法,或者执行如上述的邮件查看控制方法。
本发明还提供一种计算机可读介质,其中存储了如上所述的计算机程序。
本申请实施例中提供的技术方案,至少具有如下技术效果或优点:
与传统的加密方法相比,本发明的加密方法在于利用时间密钥对待发送邮件进行加密,该时间密钥用于限制待发送邮件可被查看的时间期限,即过了该时间期限,邮件将不能再被查看,保证了邮件的时效性;同时,用于加密邮件的时间密钥是发送至服务器,由服务器来管理密钥的发放,以此来控制加密邮件能否被查看,确保了邮件传输以及使用过程中信息的高度安全性和邮件的时效性,解决了现有技术中加密邮件不具有时效性、易于破解的技术问题。
上述说明仅是本发明技术方案的概述,为了能够更清楚了解本发明的技术手段,而可依照说明书的内容予以实施,并且为了让本发明的上述和其它目的、特征和优点能够更明显易懂,以下特举本发明的具体实施方式。
附图说明
通过阅读下文优选实施方式的详细描述,各种其他的优点和益处对于本领域普通技术人员将变得清楚明了。附图仅用于示出优选实施方式的目的,而并不认为是对本发明的限制。而且在整个附图中,用相同的参考符号表示相同的部件。在附图中:
图1示出了根据本发明一个实施例的一种邮件发送方法流程图;
图2示出了根据本发明一个实施例的一种邮件查看方法流程图;
图3示出了根据本发明一个实施例的一种邮件查看控制方法流程图;
图4示出了根据本发明一个实施例的一种邮件发送端的示意图;
图5示出了根据本发明一个实施例的一种邮件接收端的示意图;
图6示出了根据本发明一个实施例的一种邮件服务器的示意图;
图5示意性地示出了用于执行根据本发明的方法的计算设备的框图;以及
图6示意性地示出了用于保持或者携带实现根据本发明的方法的程序代码的存储单元。
具体实施例
下面将参照附图更详细地描述本公开的示例性实施例。虽然附图中显示了本公开的示例性实施例,然而应当理解,可以以各种形式实现本公开而不应被这里阐述的实施例所限制。相反,提供这些实施例是为了能够更透彻地理解本公开,并且能够将本公开的范围完整的传达给本领域的技术人员。
本发明实施例提供一种邮件发送、查看、查看控制方法及其设备,用以解决现有技术中加密邮件不具有时效性、易于破解的技术问题。
请参考图1,本申请实施例提供的一种邮件发送的方法,该方法包括以下步骤:
S11:获得待发送邮件的时间密钥,所述时间密钥用于限制所述待发送邮件可被查看的时间期限;
S12:根据所述时间密钥,对所述待发送邮件进行加密生成加密邮件;
S13:发送所述加密邮件至收件方,发送所述时间密钥至服务器并通过所述服务器根据所述时间密钥控制所述收件方是否可查看所述加密邮件。
需要说明的是,在具体实施过程中,本申请提供的上述邮件发送方法可应用于使用IMAP(Internet Mail Access Protocol,交互式邮件存取协议)/POP3(Post Office Protocol 3,邮局协议的第3个版本)/SMTP(Simple Mail Transfer Protocol,简单邮件传输协议)/ESMTP(Extended SMTP,扩展SMTP)等协议收发电子邮件的邮件客户端,且该邮件客户端可以搭建各种邮件服务器来使用,只需按照相关邮件服务器地址完成配置即可,举例来说明,如某邮件客户端要使用SINA邮件服务器,可配置接收邮件服务器地址(POP3)为:pop.sina.com.cn或:pop3.sina.com.cn,发送邮件服务器地址(SMTP)为:smtp.sina.com.cn,即可使用,该方法应用广泛,操作方便。
下面,结合图1详细介绍本邮件发送方法的具体实现步骤:
步骤S11,获得待发送邮件的时间密钥,所述时间密钥用于限制所述待发送邮件 可被查看的时间期限。
具体包括:
S111:获得待发送邮件的失效时间,所述失效时间为所述邮件发送后过期失效的时间;
S112:根据所述失效时间得到时间密钥;
其中步骤S111,获得待发送邮件的失效时间,所述失效时间的生成可以采用以下方式:
第一种方式:失效时间由发件人设定。
具体方法为:邮件发送端为发件人在编辑新邮件发送前,设定有输入失效时间指令的入口,比如,发件人可以通过这个入口手动录入或者手动选择失效时间,比如手动录入或选择的时间为“2016-8-1 11:30”,即邮件的失效时间为“2016-8-1 11:30”。
第二种方式:失效时间由发送端系统自动生成。
具体方法为,所述失效时间是由邮件发送端的发送邮件的时间加上一个固定的期限自动生成,比如说,发送邮件的时间为“2016-8-1 11:30”,固定的期限为30天,那么所述失效时间为“2016-8-31 11:30”。所述固定期限的设定为邮件系统开发时的功能集成。关于失效时间的生成方式,本发明不做限制。
步骤S112:根据所述失效时间得到时间密钥。
具体的时间密钥可以为利用标识密码算法计算得到的时间公钥ID,至少有以下两种方法:
第一种方法:可以使用对称加密的方法对原始邮件数据加密,对称加密算法的原理是:数据发信方将明文(原始数据)和加密密钥一起经过加密算法处理后,使其变成复杂的加密密文发送出去。收信方收到密文后,若想解读原始数据,则需要使用加密用过的密钥及相同加密算法的逆算法对密文进行解密,才能使其恢复成可读明文。在对称加密算法中,使用的密钥只有一个,发收信双方都使用这个密钥对数据进行加密和解密,对称加密算法的优点在于加解密的高速度和使用长密钥时的难破解性。
第二种方法:时间密钥还可以用非对称加密算法得到,非对称加密算法需要两个密钥:公开密钥(publickey)和私有密钥(privatekey)。公开密钥与私有密钥是一对,如果用公开密钥对数据进行加密,只有用对应的私有密钥才能解密;如果用私有密钥对数据进行加密,那么只有用对应的公开密钥才能解密。非对称密码体制的特点在于:加密解密速度较对称加密慢,但加密算法强度复杂、安全性高。
步骤S12,根据所述时间密钥,对所述待发送邮件进行加密生成加密邮件;
步骤S12具体的可以采用方法一实现:用所述时间密钥对所述待发送邮件进行加密生成所述加密邮件;
具体在本实施例中,此处可以采用对称加密的方法对原始邮件数据加密,具体加密内容如下:
EncrpytBySym(邮件数据密文)=fx_encryptBySym(ori(邮件内容),ID(时间密钥)),ori为EML的所有内容(包含邮件头、邮件体),采用的是二进制数据格式,EncrpytBySym即为加密获得的邮件数据密文,加密使用的加密强度为AES256。
步骤S12也可以采用方法二实现:生成会话密钥,用所述时间密钥和所述会话密钥的组合对所述待发送邮件进行加密生成所述加密邮件;
具体在本实施例中,举例说明,生成会话密钥的算法为根据随机数生成一段会话密钥,如SessionPassword=fx_randomSession(“1234567890”),SessionPassword=会话密钥,1234567890即为一个随机数,通过生成会话密钥的算法即生成一段会话密钥。然后,用所述会话密钥对待发送邮件进行加密,生成所述加密邮件中的邮件数据密文,具体方法是:
EncrpytBySym(邮件数据密文)=fx_encryptBySym(ori(邮件内容),SessionPassword,ID),EncrpytBySym即为用所述时间密钥和所述会话密钥的组合对所述待发送邮件进行加密生成的邮件数据密文。
接下来,用所述时间密钥对所述会话密钥进行加密,生成所述加密邮件中的会话密钥密文;具体方法可以是:
会话密钥密文id1_encryptdata=fx_encryptByIBC(SessionPassword(会话密钥),ID(时间密钥)),此加密算法采用sm9加密算法,加密强度是RSA3072。
进一步的,其中的加密邮件具体可以是在发送前将由所述邮件数据密文和会话密钥密文进行封装后生成的封装包;对邮件数据密文和会话密钥密文进行P7格式封装,结合本实施例,具体封装为XXX邮件系统格式如下:
P7Data=SEQUENCE{
加密类型=XXXsmail
加密算法=id-ibc-enc-kem-sok-esbdh
摘要类型=aes256
编码类型=dem-dem3,hmacSHA
可解密时间信息={
可解密时间标识=yyyymmddhhnnsszzz
域=360jiamiyou_olym
版本=1
会话密钥密文(id1_encryptdata)
}
数据密文(EncryptBySym)
}
上述工作完成后,就可以进行步骤S13:发送所述加密邮件至收件方,发送所述时间密钥至服务器并通过所述服务器根据所述时间密钥控制所述收件方是否可查看所述加密邮件。关于服务器如何根据所述时间密钥控制所述收件方是否可查看所述加密邮件的方法将在后面内容作详细描述。
请参考图2:本申请实施例提供的一种邮件查看方法,应用于邮件接收端,所述方法包括:
S21:接收根据时间密钥进行加密的加密邮件,所述时间密钥用于限制所述加密邮件可被查看的时间期限;
S22:响应查看所述加密邮件的查看操作,生成并发送密钥请求至服务器,所述密钥请求用于获取所述加密邮件的所述时间密钥;
S23:接收所述服务器响应所述密钥请求的反馈信息,所述反馈信息由所述服务器根据所述密钥请求的请求时间和发送端发送的所述时间密钥生成,当所述请求时间超出所述时间密钥对应的时间范围时所述反馈信息为表征所述加密邮件无效的信息,当所述请求时间在所述时间密钥对应的时间范围内时所述反馈信息为所述时间密钥;
S24:解析所述反馈信息,根据解析结果响应所述查看操作;
所述根据解析结果响应所述查看操作,包括:
当解析结果为所述加密邮件无效时,执行步骤S241:响应所述查看操作,提示用户所述加密邮件已过期无法被查看;
当解析结果为所述时间密钥时,执行步骤S242:响应所述查看操作,根据所述时间密钥解密所述加密邮件,获得邮件数据并显示;
在执行步骤S242中,所述根据所述时间密钥解密所述加密邮件,可以采用两种办法:
方法一:用所述时间密钥解密所述加密邮件,得到邮件数据;
或者方法二:解析所述加密邮件的封装包得到所述加密邮件中的会话密钥密文;用所述时间密钥解密所述会话密钥密文,得到会话密钥;用所述会话密钥解密所述加密邮件中的邮件数据密文,得到邮件数据。
下面,结合图2详细介绍本申请实施例中邮件查看方法的具体实现步骤:
S21:接收根据时间密钥进行加密的加密邮件,所述时间密钥用于限制所述加密邮件可被查看的时间期限;
时间密钥可以为利用标识密码算法计算得到的时间公钥ID,至少有以下两种方法:
第一种方法:可以使用对称加密的方法对原始邮件数据加密,对称加密算法的原理是:数据发信方将明文(原始数据)和加密密钥一起经过加密算法处理后,使其变成复杂的加密密文发送出去。收信方收到密文后,若想解读原始数据,则需要使用加密用过的密钥及相同加密算法的逆算法对密文进行解密,才能使其恢复成可读明文。在对称加密算法中,使用的密钥只有一个,发收信双方都使用这个密钥对数据进行加密和解密,对称加密算法的优点在于加解密的高速度和使用长密钥时的难破解性。
第二种方法:时间密钥还可以用非对称加密算法得到,非对称加密算法需要两个密钥:公开密钥(publickey)和私有密钥(privatekey)。公开密钥与私有密钥是一对,如果用公开密钥对数据进行加密,只有用对应的私有密钥才能解密;如果用私有密钥对数据进行加密,那么只有用对应的公开密钥才能解密。非对称密码体制的特点在于:加密解密速度较对称加密慢,但加密算法强度复杂、安全性高。
S22:响应查看所述加密邮件的查看操作,生成并发送密钥请求至服务器,所述密钥请求用于获取所述加密邮件的所述时间密钥;
所述邮件接收端向服务器发送密钥请求获得时间密钥,所述时间密钥是服务器通过验证所述邮件接收端申请时间密钥的时间是否在时间密钥对应的时间范围内来发放的,此处服务器一般为CA服务器;所谓CA,即为数字证书认证中心(CertficateAuthority,CA),是整个网上电子交易安全的关键环节。它主要负责产生、分配并管理所有参与网上交易的实体所需的身份认证数字证书。
S23:接收所述服务器响应所述密钥请求的反馈信息,所述反馈信息由所述服务器根据所述密钥请求的请求时间和发送端发送的所述时间密钥生成,当所述请求时间超出所述时间密钥对应的时间范围时所述反馈信息为表征所述加密邮件无效的信息,当所述请求时间在所述时间密钥对应的时间范围内时所述反馈信息为所述时间 密钥。
具体在本实施例中,举例说明:
邮件接收端向服务器发送密钥请求的请求时间是2016-8-20 10:10:10,而邮件发送端发送的时间密钥对应的时间是2016-8-10 10:10:10,则请求时间超出所述时间密钥对应的时间范围,服务器给邮件接收端的反馈信息即为加密邮件无效,邮件发送端发送的时间密钥对应的时间是2016-8-30 10:10:10,则请求时间在所述时间密钥对应的时间范围内,此时服务器给邮件接收端的反馈信息为时间密钥。
S24:解析所述反馈信息,根据解析结果响应所述查看操作;
所述根据解析结果响应所述查看操作,包括:
当解析结果为所述加密邮件无效时,执行步骤S241:邮件接收端响应所述查看操作,提示用户所述加密邮件已过期无法被查看;
当解析结果为所述时间密钥时,执行步骤S242:邮件接收端响应所述查看操作,根据所述时间密钥解密所述加密邮件,获得邮件数据并显示;
在执行步骤S242中,所述根据所述时间密钥解密所述加密邮件,可以采用两种办法:
方法一:用所述时间密钥解密所述加密邮件,得到邮件数据;
或者方法二:解析所述加密邮件的封装包得到所述加密邮件中的会话密钥密文;用所述时间密钥解密所述会话密钥密文,得到会话密钥;用所述会话密钥解密所述加密邮件中的邮件数据密文,得到邮件数据;
具体的,邮件接收端在得到时间密钥后,会用所述时间密钥解析所述会话密钥密文,得到所述会话密钥。在本实施例中,通过解析会话密钥密文(id1_encryptdata),得到会话密钥SessionPassword为“1234567890”,然后通过会话密钥SessionPassword来解析邮件数据密文,如在加密时,EncrpytBySym(邮件数据密文)=fx_encryptBySym(ori(邮件内容),SessionPassword(会话密钥)),解密后,最后得到邮件数据ORI。
此处的封装包如前述邮件发送方法中所述的生成的P7格式封装数据,具体封装数据如下:
P7Data=SEQUENCE{
加密类型=360smail
加密算法=id-ibc-enc-kem-sok-esbdh
摘要类型=aes256
编码类型=dem-dem3,hmacSHA
可解密时间信息={
可解密时间标识=yyyymmddhhnnsszzz
域=360jiamiyou_olym
版本=1
会话密钥密文(id1_encryptdata)
}
数据密文(EncryptBySym)
}。
通过对P7格式封装包解析,可从中得到会话密钥密文id1_encryptdata和失效时间yyyymmddhhnnsszzz。
请参考图3:一种邮件查看控制方法,应用于服务器,方法包括:
S31:接收邮件接收端发送的获取加密邮件时间密钥的密钥请求;
S32:将所述邮件接收端请求所述时间密钥的请求时间与所述时间密钥对应的时间范围进行比较;
如果所述请求时间超出所述时间范围,执行S321:拒绝向邮件接收端发放所述时间密钥,使得邮件接收端无法对加密邮件进行解密及查看;
如果所述请求时间未超出所述时间范围,执行S322:向邮件接收端发放所述时间密钥,使得邮件接收端根据所述时间密钥对加密邮件进行解密并查看。
步骤S32的具体原理和操作方法与步骤S23相对应。
步骤S321和步骤S322的具体原理和操作方法分别与S241和S242相对应。
作为对应于上述加密方法的邮件系统,采用前述的方法进行邮件的加密发送、解密接收和查看控制,该邮件系统包括前述的邮件发送端、邮件接收端和服务器。
其中,邮件发送端,如图4所示,包括:
获取单元21:用于获得待发送邮件的时间密钥,所述时间密钥用于限制待发送邮件可被查看的时间期限;
加密单元22:用于根据所述时间密钥,对所述待发送邮件进行加密生成加密邮件;
第一发送单元23:用于发送所述加密邮件至收件方,发送所述时间密钥至服务器并通过所述服务器根据所述时间密钥控制所述收件方是否可查看所述加密邮件。
获取单元21,包括:
时间获取子单元,一种可选实施例,时间获取子单元用于获得待发送邮件的失效时间,所述失效时间为所述邮件发送后过期失效的时间;
另一种可选实施例,所述时间获取子单元,用于获得将所述待发送邮件的发送时间加上固定期限生成所述失效时间。
密钥获取子单元,用于根据所述失效时间得到时间密钥。加密单元22,包括:
第一加密子单元,用于用所述时间密钥对所述待发送邮件进行加密生成所述加密邮件;或者
第二加密子单元;
一种可选实施例,第二加密子单元用于生成会话密钥,用所述时间密钥和所述会话密钥的组合对所述待发送邮件进行加密生成所述加密邮件.
另一种可选实施例,第二加密子单元,用于:
用所述会话密钥对待发送邮件进行加密,生成所述加密邮件中的邮件数据密文;
用所述时间密钥对所述会话密钥进行加密,生成所述加密邮件中的会话密钥密文。
邮件接收端,如图5所示,包括:
第一接收单元31:用于接收根据时间密钥进行加密的加密邮件,所述时间密钥用于限制所述加密邮件可被查看的时间期限;
响应请求单元32:用于响应查看所述加密邮件的查看操作,生成并发送密钥请求至服务器,所述密钥请求用于获取所述加密邮件的所述时间密钥;
第二接收单元33:用于接收所述服务器响应所述密钥请求的反馈信息,所述反馈信息由所述服务器根据所述密钥请求的请求时间和发送端发送的所述时间密钥生成,当所述请求时间超出所述时间密钥对应的时间范围时所述反馈信息为表征所述加密邮件无效的信息,当所述请求时间在所述时间密钥对应的时间范围内时所述反馈信息为所述时间密钥;
解析响应单元34:用于解析所述反馈信息,根据解析结果响应所述查看操作。
具体的,解析响应单元34,用于:
当解析结果为所述加密邮件无效时,响应所述查看操作,提示用户所述加密邮件已过期无法被查看;
当解析结果为所述时间密钥时,响应所述查看操作,根据所述时间密钥解密所述加密邮件,获得邮件数据并显示;
所述解析响应单元34,包括:
第一解析响应子单元,用于用所述时间密钥解密所述加密邮件,得到邮件数据;或者
第二解析响应子单元,用于解析所述加密邮件的封装包得到所述加密邮件中的会话密钥密文;用所述时间密钥解密所述会话密钥密文,得到会话密钥;用所述会话密钥解密所述加密邮件中的邮件数据密文,得到邮件数据。
邮件服务器,如图6所示,包括:
第三接收单元41:用于接收邮件接收端发送的获取加密邮件时间密钥的密钥请求;
验证单元42:用于将所述邮件接收端请求所述时间密钥的请求时间与所述时间密钥对应的时间范围进行比较;
第二发送单元43:用于在所述请求时间超出所述时间范围时,拒绝向邮件接收端发放所述时间密钥,使得邮件接收端无法对加密邮件进行解密及查看;在所述请求时间未超出所述时间范围,向邮件接收端发放所述时间密钥时,使得邮件接收端根据所述时间密钥对加密邮件进行解密并查看。
与传统的加密方法相比,本发明的加密方法在于利用时间密钥对待发送邮件进行加密,该时间密钥用于限制待发送邮件可被查看的时间期限,即过了该时间期限,邮件将不能再被查看,保证了邮件的时效性;同时,用于加密邮件的时间密钥是发送至服务器,由服务器来管理密钥的发放,以此来控制加密邮件能否被查看,确保了邮件传输以及使用过程中信息的高度安全性和邮件的时效性,解决了现有技术中加密邮件不具有时效性、易于破解的技术问题。
在此提供的算法和显示不与任何特定计算机、虚拟系统或者其它设备固有相关。各种通用系统也可以与基于在此的示教一起使用。根据上面的描述,构造这类系统所要求的结构是显而易见的。此外,本发明也不针对任何特定编程语言。应当明白,可以利用各种编程语言实现在此描述的本发明的内容,并且上面对特定语言所做的描述是为了披露本发明的最佳实施方式。
在此处所提供的说明书中,说明了大量具体细节。然而,能够理解,本发明的实施例可以在没有这些具体细节的情况下实践。在一些实例中,并未详细示出公知的方法、结构和技术,以便不模糊对本说明书的理解。
类似地,应当理解,为了精简本公开并帮助理解各个发明方面中的一个或多个,在上面对本发明的示例性实施例的描述中,本发明的各个特征有时被一起分组到单个实施例、图、或者对其的描述中。然而,并不应将该公开的方法解释成反映如下 意图:即所要求保护的本发明要求比在每个权利要求中所明确记载的特征更多的特征。更确切地说,如下面的权利要求书所反映的那样,发明方面在于少于前面公开的单个实施例的所有特征。因此,遵循具体实施方式的权利要求书由此明确地并入该具体实施方式,其中每个权利要求本身都作为本发明的单独实施例。
本领域那些技术人员可以理解,可以对实施例中的设备中的模块进行自适应性地改变并且把它们设置在与该实施例不同的一个或多个设备中。可以把实施例中的模块或单元或组件组合成一个模块或单元或组件,以及此外可以把它们分成多个子模块或子单元或子组件。除了这样的特征和/或过程或者单元中的至少一些是相互排斥之外,可以采用任何组合对本说明书(包括伴随的权利要求、摘要和附图)中公开的所有特征以及如此公开的任何方法或者设备的所有过程或单元进行组合。除非另外明确陈述,本说明书(包括伴随的权利要求、摘要和附图)中公开的每个特征可以由提供相同、等同或相似目的的替代特征来代替。
此外,本领域的技术人员能够理解,尽管在此所述的一些实施例包括其它实施例中所包括的某些特征而不是其它特征,但是不同实施例的特征的组合意味着处于本发明的范围之内并且形成不同的实施例。例如,在下面的权利要求书中,所要求保护的实施例的任意之一都可以以任意的组合方式来使用。
本发明的各个部件实施例可以以硬件实现,或者以在一个或者多个处理器上运行的软件模块实现,或者以它们的组合实现。本领域的技术人员应当理解,可以在实践中使用微处理器或者数字信号处理器(DSP)来实现根据本发明实施例的邮件发送端、邮件接收端和邮件服务器中的一些或者全部部件的一些或者全部功能。本发明还可以实现为用于执行这里所描述的方法的一部分或者全部的设备或者装置程序(例如,计算机程序和计算机程序产品)。这样的实现本发明的程序可以存储在计算机可读介质上,或者可以具有一个或者多个信号的形式。这样的信号可以从因特网网站服务器上下载得到,或者在载体信号上提供,或者以任何其他形式提供。
例如,图7示出了用于执行根据本发明的方法的计算设备的框图。该计算设备传统上包括处理器710和以存储器720形式的计算机程序产品或者计算机可读介质。存储器720可以是诸如闪存、EEPROM(电可擦除可编程只读存储器)、EPROM、硬盘或者ROM之类的电子存储器。存储器720具有存储用于执行上述方法中的任何方法步骤的程序代码731的存储空间730。例如,用于程序代码的存储空间730可以包括分别用于实现上面的方法中的各种步骤的各个程序代码731。这些程序代码可以从一个或者多个计算机程序产品中读出或者写入到这一个或者多个计算机程序产品 中。这些计算机程序产品包括诸如硬盘,紧致盘(CD)、存储卡或者软盘之类的程序代码载体。这样的计算机程序产品通常为例如图8所述的便携式或者固定存储单元。该存储单元可以具有与图7的计算设备中的存储器720类似布置的存储段、存储空间等。程序代码可以例如以适当形式进行压缩。通常,存储单元存储有用于执行根据本发明的方法步骤的计算机可读程序代码731’,即可以由诸如710之类的处理器读取的程序代码,当这些程序代码由计算设备运行时,导致该计算设备执行上面所描述的方法中的各个步骤。
本文中所称的“一个实施例”、“实施例”或者“一个或者多个实施例”意味着,结合实施例描述的特定特征、结构或者特性包括在本发明的至少一个实施例中。此外,请注意,这里“在一个实施例中”的词语例子不一定全指同一个实施例。
应该注意的是上述实施例对本发明进行说明而不是对本发明进行限制,并且本领域技术人员在不脱离所附权利要求的范围的情况下可设计出替换实施例。在权利要求中,不应将位于括号之间的任何参考符号构造成对权利要求的限制。单词“包含”不排除存在未列在权利要求中的元件或步骤。位于元件之前的单词“一”或“一个”不排除存在多个这样的元件。本发明可以借助于包括有若干不同元件的硬件以及借助于适当编程的计算机来实现。在列举了若干装置的单元权利要求中,这些装置中的若干个可以是通过同一个硬件项来具体体现。单词第一、第二、以及第三等的使用不表示任何顺序。可将这些单词解释为名称。
此外,还应当注意,本说明书中使用的语言主要是为了可读性和教导的目的而选择的,而不是为了解释或者限定本发明的主题而选择的。因此,在不偏离所附权利要求书的范围和精神的情况下,对于本技术领域的普通技术人员来说许多修改和变更都是显而易见的。对于本发明的范围,对本发明所做的公开是说明性的,而非限制性的,本发明的范围由所附权利要求书限定。

Claims (26)

  1. 一种邮件发送方法,包括:
    获得待发送邮件的时间密钥,所述时间密钥用于限制所述待发送邮件可被查看的时间期限;
    根据所述时间密钥,对所述待发送邮件进行加密生成加密邮件;
    发送所述加密邮件至收件方,发送所述时间密钥至服务器并通过所述服务器根据所述时间密钥控制所述收件方是否可查看所述加密邮件。
  2. 如权利要求1所述的方法,其特征在于,所述获得待发送邮件的时间密钥,包括:
    获得待发送邮件的失效时间,所述失效时间为所述邮件发送后过期失效的时间;
    根据所述失效时间得到时间密钥。
  3. 如权利要求1所述的方法,其特征在于,所述根据所述时间密钥,对所述待发送邮件进行加密生成加密邮件,具体方法包括:
    用所述时间密钥对所述待发送邮件进行加密生成所述加密邮件;或者
    生成会话密钥,用所述时间密钥和所述会话密钥的组合对所述待发送邮件进行加密生成所述加密邮件。
  4. 如权利要求3所述的方法,其特征在于,所述用所述时间密钥和所述会话密钥的组合对所述待发送邮件进行加密,包括:
    用所述会话密钥对待发送邮件进行加密,生成所述加密邮件中的邮件数据密文;
    用所述时间密钥对所述会话密钥进行加密,生成所述加密邮件中的会话密钥密文。
  5. 如权利要求4所述的方法,其特征在于,所述加密邮件具体是:在发送前将由所述邮件数据密文和会话密钥密文进行封装后生成的封装包。
  6. 如权利要求1~5任一所述的方法,其特征在于,所述时间密钥为利用标识密码算法计算得到的时间公钥。
  7. 如权利要求2所述的方法,其特征在于,所述获得待发送邮件的失效时间,包括:
    将所述待发送邮件的发送时间加上固定期限生成所述失效时间。
  8. 一种邮件查看方法,应用于邮件接收端,包括:
    接收根据时间密钥进行加密的加密邮件,所述时间密钥用于限制所述加密邮件可被查看的时间期限;
    响应查看所述加密邮件的查看操作,生成并发送密钥请求至服务器,所述密钥请求用于获取所述加密邮件的所述时间密钥;
    接收所述服务器响应所述密钥请求的反馈信息,所述反馈信息由所述服务器根据所述密钥请求的请求时间和发送端发送的所述时间密钥生成,当所述请求时间超出所述时间密钥对应的时间范围时所述反馈信息为表征所述加密邮件无效的信息,当所述请求时间在所述时间密钥对应的时间范围内时所述反馈信息为所述时间密钥;
    解析所述反馈信息,根据解析结果响应所述查看操作。
  9. 如权利要求8所述的方法,其特征在于,所述加密邮件为:
    用所述时间密钥加密生成的邮件;或者
    用所述时间密钥和所述会话密钥的组合进行加密生成的邮件。
  10. 如权利要求8或权利要求9所述的方法,其特征在于,所述根据解析结果响应所述查看操作,包括:
    当解析结果为所述加密邮件无效时,响应所述查看操作,提示用户所述加密邮件已过期无法被查看;
    当解析结果为所述时间密钥时,响应所述查看操作,根据所述时间密钥解密所述加密邮件,获得邮件数据并显示。
  11. 如权利要求10所述的方法,其特征在于,所述根据所述时间密钥解密所述加密邮件,包括:
    用所述时间密钥解密所述加密邮件,得到邮件数据;或者
    解析所述加密邮件的封装包得到所述加密邮件中的会话密钥密文;用所述时间密钥解密所述会话密钥密文,得到会话密钥;用所述会话密钥解密所述加密邮件中的邮件数据密文,得到邮件数据。
  12. 一种邮件查看控制方法,应用于服务器,包括:
    接收邮件接收端发送的获取加密邮件时间密钥的密钥请求;
    将所述邮件接收端请求所述时间密钥的请求时间与所述时间密钥对应的时间范围进行比较;
    如果所述请求时间超出所述时间范围,拒绝向邮件接收端发放所述时间密钥,使得邮件接收端无法对加密邮件进行解密及查看;
    如果所述请求时间未超出所述时间范围,向邮件接收端发放所述时间密钥,使得邮件接收端根据所述时间密钥对加密邮件进行解密并查看。
  13. 一种邮件发送端,包括:
    获取单元:用于获得待发送邮件的时间密钥,所述时间密钥用于限制待发送邮件可被查看的时间期限;
    加密单元:用于根据所述时间密钥,对所述待发送邮件进行加密生成加密邮件;
    第一发送单元:用于发送所述加密邮件至收件方,发送所述时间密钥至服务器并通过所述服务器根据所述时间密钥控制所述收件方是否可查看所述加密邮件。
  14. 如权利要求13所述邮件发送端,其特征在于:所述获取单元,包括:
    时间获取子单元,用于获得待发送邮件的失效时间,所述失效时间为所述邮件发送后过期失效的时间;
    密钥获取子单元,用于根据所述失效时间得到时间密钥。
  15. 如权利要求13所述的邮件发送端,其特征在于,所述加密单元,包括:
    第一加密子单元,用于用所述时间密钥对所述待发送邮件进行加密生成所述加密邮件;或者
    第二加密子单元,用于生成会话密钥,用所述时间密钥和所述会话密钥的组合对所述待发送邮件进行加密生成所述加密邮件。
  16. 如权利要求15所述的邮件发送端,其特征在于,所述第二加密子单元,用于:
    用所述会话密钥对待发送邮件进行加密,生成所述加密邮件中的邮件数据密文;
    用所述时间密钥对所述会话密钥进行加密,生成所述加密邮件中的会话密钥密文。
  17. 如权利要求16所述的邮件发送端,其特征在于,所述加密邮件具体是:在发送前将由所述邮件数据密文和会话密钥密文进行封装后生成的封装 包。
  18. 如权利要求13~17任一所述的邮件发送端,其特征在于,所述时间密钥为利用标识密码算法计算得到的时间公钥。
  19. 如权利要求14所述的邮件发送端,其特征在于,所述时间获取子单元,用于:
    将所述待发送邮件的发送时间加上固定期限生成所述失效时间。
  20. 一种邮件接收端,包括:
    第一接收单元:用于接收根据时间密钥进行加密的加密邮件,所述时间密钥用于限制所述加密邮件可被查看的时间期限;
    响应请求单元:用于响应查看所述加密邮件的查看操作,生成并发送密钥请求至服务器,所述密钥请求用于获取所述加密邮件的所述时间密钥;
    第二接收单元:用于接收所述服务器响应所述密钥请求的反馈信息,所述反馈信息由所述服务器根据所述密钥请求的请求时间和发送端发送的所述时间密钥生成,当所述请求时间超出所述时间密钥对应的时间范围时所述反馈信息为表征所述加密邮件无效的信息,当所述请求时间在所述时间密钥对应的时间范围内时所述反馈信息为所述时间密钥;
    解析响应单元:用于解析所述反馈信息,根据解析结果响应所述查看操作。
  21. 如权利要求20所述的邮件接收端,其特征在于,所述加密邮件为:
    用所述时间密钥加密生成的邮件;或者
    用所述时间密钥和所述会话密钥的组合进行加密生成的邮件。
  22. 如权利要求20或权利要求21所述的邮件接收端,其特征在于,解析响应单元,用于:
    当解析结果为所述加密邮件无效时,响应所述查看操作,提示用户所述加密邮件已过期无法被查看;
    当解析结果为所述时间密钥时,响应所述查看操作,根据所述时间密钥解密所述加密邮件,获得邮件数据并显示。
  23. 如权利要求22所述的邮件接收端,其特征在于,所述解析响应单元,包括:
    第一解析响应子单元,用于用所述时间密钥解密所述加密邮件,得到邮 件数据;或者
    第二解析响应子单元,用于解析所述加密邮件的封装包得到所述加密邮件中的会话密钥密文;用所述时间密钥解密所述会话密钥密文,得到会话密钥;用所述会话密钥解密所述加密邮件中的邮件数据密文,得到邮件数据。
  24. 一种邮件服务器,包括:
    第三接收单元:用于接收邮件接收端发送的获取加密邮件时间密钥的密钥请求;
    验证单元:用于将所述邮件接收端请求所述时间密钥的请求时间与所述时间密钥对应的时间范围进行比较;
    第二发送单元:用于在所述请求时间超出所述时间范围时,拒绝向邮件接收端发放所述时间密钥,使得邮件接收端无法对加密邮件进行解密及查看;在所述请求时间未超出所述时间范围时,向邮件接收端发放所述时间密钥,使得邮件接收端根据所述时间密钥对加密邮件进行解密并查看。
  25. 一种计算机程序,包括计算机可读代码,当所述计算机可读代码在计算设备上运行时,导致所述计算设备执行根据权利要求1-7中的任一个所述的邮件发送方法,或者,执行根据权利要求8-11中的任一个所述的邮件查看方法,或者,执行根据权利要求12所述的邮件查看控制方法。
  26. 一种计算机可读介质,其中存储了如权利要求25所述的计算机程序。
PCT/CN2017/117564 2016-12-21 2017-12-20 一种邮件发送、查看、查看控制方法及其设备 Ceased WO2018113708A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201611190140.5A CN106603388B (zh) 2016-12-21 2016-12-21 一种邮件发送、查看、查看控制方法及其设备
CN201611190140.5 2016-12-21

Publications (1)

Publication Number Publication Date
WO2018113708A1 true WO2018113708A1 (zh) 2018-06-28

Family

ID=58602233

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2017/117564 Ceased WO2018113708A1 (zh) 2016-12-21 2017-12-20 一种邮件发送、查看、查看控制方法及其设备

Country Status (2)

Country Link
CN (1) CN106603388B (zh)
WO (1) WO2018113708A1 (zh)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
TWI678904B (zh) * 2018-08-27 2019-12-01 宏碁股份有限公司 電子郵件檢查方法與電子郵件檢查系統
CN114650181A (zh) * 2022-03-31 2022-06-21 西安电子科技大学 电子邮件加解密方法、系统、设备及计算机可读存储介质
CN119071062A (zh) * 2024-08-27 2024-12-03 湖南大学 一种电子邮件传输安全加密方法及系统

Families Citing this family (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106603388B (zh) * 2016-12-21 2020-04-21 北京奇虎科技有限公司 一种邮件发送、查看、查看控制方法及其设备
CN108833083A (zh) * 2018-06-27 2018-11-16 扬州天佑网络科技有限公司 一种基于时间与空间信件内容传输方法
CN116192466A (zh) * 2023-01-04 2023-05-30 深圳市中达为科技有限公司 信件处理方法、装置、电子设备及存储介质

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101677300A (zh) * 2008-09-18 2010-03-24 国际商业机器公司 用于电子邮件消息传递的方法和电子邮件系统
CN102195989A (zh) * 2011-06-15 2011-09-21 中国电信股份有限公司 电子邮件的处理方法和系统
US20140013103A1 (en) * 2012-07-03 2014-01-09 Futurewei Technologies, Inc. Low-Latency Secure Segment Encryption and Authentication Interface
CN104660589A (zh) * 2015-01-20 2015-05-27 中兴通讯股份有限公司 一种对信息进行加密控制、解析信息的方法、系统和终端
CN106453069A (zh) * 2016-12-21 2017-02-22 北京奇虎科技有限公司 一种即时通信消息发送、查看、查看控制方法及其设备
CN106603388A (zh) * 2016-12-21 2017-04-26 北京奇虎科技有限公司 一种邮件发送、查看、查看控制方法及其设备

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP4200965B2 (ja) * 2004-11-22 2008-12-24 村田機械株式会社 暗号メールサーバとそのプログラム
JP4595728B2 (ja) * 2005-07-26 2010-12-08 富士ゼロックス株式会社 電子メール送信装置、プログラム、インターネットファックス送信装置、スキャン画像開示装置及び送信装置
CN104468478A (zh) * 2013-09-17 2015-03-25 上海俊悦光纤网络科技有限公司 一种邮件加密方法

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101677300A (zh) * 2008-09-18 2010-03-24 国际商业机器公司 用于电子邮件消息传递的方法和电子邮件系统
CN102195989A (zh) * 2011-06-15 2011-09-21 中国电信股份有限公司 电子邮件的处理方法和系统
US20140013103A1 (en) * 2012-07-03 2014-01-09 Futurewei Technologies, Inc. Low-Latency Secure Segment Encryption and Authentication Interface
CN104660589A (zh) * 2015-01-20 2015-05-27 中兴通讯股份有限公司 一种对信息进行加密控制、解析信息的方法、系统和终端
CN106453069A (zh) * 2016-12-21 2017-02-22 北京奇虎科技有限公司 一种即时通信消息发送、查看、查看控制方法及其设备
CN106603388A (zh) * 2016-12-21 2017-04-26 北京奇虎科技有限公司 一种邮件发送、查看、查看控制方法及其设备

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
TWI678904B (zh) * 2018-08-27 2019-12-01 宏碁股份有限公司 電子郵件檢查方法與電子郵件檢查系統
CN114650181A (zh) * 2022-03-31 2022-06-21 西安电子科技大学 电子邮件加解密方法、系统、设备及计算机可读存储介质
CN119071062A (zh) * 2024-08-27 2024-12-03 湖南大学 一种电子邮件传输安全加密方法及系统

Also Published As

Publication number Publication date
CN106603388B (zh) 2020-04-21
CN106603388A (zh) 2017-04-26

Similar Documents

Publication Publication Date Title
US12137083B2 (en) Differential client-side encryption of information originating from a client
US20240419766A1 (en) Secure Messaging Service with Digital Rights Management Using Blockchain Technology
CN106603388B (zh) 一种邮件发送、查看、查看控制方法及其设备
CN114650181B (zh) 电子邮件加解密方法、系统、设备及计算机可读存储介质
CN102055685B (zh) 网页邮件信息加密的方法
WO2015180689A1 (zh) 验证信息的获取方法及装置
CN107210915A (zh) 相互认证
CN104283680A (zh) 一种数据传输的方法、客户端、服务器及其系统
CN107408187A (zh) 通过认证令牌的改进安全
CN107342966A (zh) 权限凭证发放方法和装置
CN101841785A (zh) 通过手机短信加密传送信息的方法和系统
CN106453069B (zh) 一种即时通信消息发送、查看、查看控制方法及其设备
WO2018113756A1 (zh) 一种即时通信发送方法、控制方法、发送端及接收端
US20240250807A1 (en) Noncustodial techniques for granular encryption and decryption
CN102510431B (zh) 远程资源获取方法、系统、设备及用户终端
CN103929722A (zh) 一种短信加密方法和系统
HK1078708B (zh) 认证及检验sms通信的方法
HK1078708A1 (zh) 认证及检验sms通信的方法
JP2003318888A (ja) リマインダサービス方法

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 17883191

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 17883191

Country of ref document: EP

Kind code of ref document: A1