WO2020107486A1 - 一种数据传输方法、设备、终端、服务器及存储介质 - Google Patents

一种数据传输方法、设备、终端、服务器及存储介质 Download PDF

Info

Publication number
WO2020107486A1
WO2020107486A1 PCT/CN2018/118784 CN2018118784W WO2020107486A1 WO 2020107486 A1 WO2020107486 A1 WO 2020107486A1 CN 2018118784 W CN2018118784 W CN 2018118784W WO 2020107486 A1 WO2020107486 A1 WO 2020107486A1
Authority
WO
WIPO (PCT)
Prior art keywords
terminal
data
communication connection
authentication information
service
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2018/118784
Other languages
English (en)
French (fr)
Inventor
郑德恩
马超
周贤
耿超
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
SZ DJI Technology Co Ltd
Original Assignee
SZ DJI Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by SZ DJI Technology Co Ltd filed Critical SZ DJI Technology Co Ltd
Priority to PCT/CN2018/118784 priority Critical patent/WO2020107486A1/zh
Priority to CN201880038851.1A priority patent/CN110785977A/zh
Publication of WO2020107486A1 publication Critical patent/WO2020107486A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/04Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
    • H04L63/0428Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/14Session management
    • H04L67/141Setup of application sessions

Definitions

  • the invention relates to the technical field of control, and in particular to a data transmission method, device, terminal, server and storage medium based on a public communication network.
  • Embodiments of the present invention provide a data transmission method, device, terminal, server, and storage medium based on a public communication network, which implements encryption control of data transmission in a public wireless communication network, and improves data transmission in a public wireless communication network
  • the security is beneficial to the long-distance communication between the first terminal and the second terminal.
  • an embodiment of the present invention provides a data transmission method based on a public communication network, which is applied to service equipment.
  • the method includes:
  • the encrypted data when the first terminal is a control device and the second terminal is a mobile platform, the encrypted data includes control data of the mobile device by the control device; or, when the first terminal is When the mobile platform and the second terminal are the control device, the encrypted data includes working data collected by the mobile platform.
  • an embodiment of the present invention provides another data transmission method based on a public communication network, which is applied to a first terminal, and the method includes:
  • the encrypted data when the first terminal is a control device and the second terminal is a mobile platform, the encrypted data includes control data of the mobile device by the control device; or, when the first terminal is When the mobile platform and the second terminal are the control device, the encrypted data includes working data collected by the mobile platform.
  • an embodiment of the present invention provides another data transmission method based on a public communication network, which is applied to a network server.
  • the method includes:
  • the encrypted data when the first terminal is a control device and the second terminal is a mobile platform, the encrypted data includes control data of the control device on the mobile platform; or, when the first terminal is a When the mobile platform is used and the second terminal is the control device, the encrypted data includes work data collected by the mobile platform.
  • an embodiment of the present invention provides a data transmission device based on a public communication network, which is applied to a business device.
  • the device includes: a processor and a memory;
  • the memory is used to store program instructions
  • the processor executes the program instructions stored in the memory. When the program instructions are executed, the processor is used to perform the following steps:
  • the encrypted data when the first terminal is a control device and the second terminal is a mobile platform, the encrypted data includes control data of the mobile device by the control device; or, when the first terminal is When the mobile platform and the second terminal are the control device, the encrypted data includes working data collected by the mobile platform.
  • an embodiment of the present invention provides another data transmission device based on a public communication network, which is applied to a first terminal, and the device includes: a processor and a memory;
  • the memory is used to store program instructions
  • the processor executes the program instructions stored in the memory. When the program instructions are executed, the processor is used to perform the following steps:
  • the encrypted data when the first terminal is a control device and the second terminal is a mobile platform, the encrypted data includes control data of the mobile device by the control device; or, when the first terminal is When the mobile platform and the second terminal are the control device, the encrypted data includes working data collected by the mobile platform.
  • an embodiment of the present invention provides yet another data transmission device based on a public communication network, which is applied to a network server, and the device includes: a processor and a memory;
  • the memory is used to store program instructions
  • the processor executes the program instructions stored in the memory. When the program instructions are executed, the processor is used to perform the following steps:
  • the encrypted data when the first terminal is a control device and the second terminal is a mobile platform, the encrypted data includes control data of the control device on the mobile platform; or, when the first terminal is a When the mobile platform is used and the second terminal is the control device, the encrypted data includes work data collected by the mobile platform.
  • an embodiment of the present invention provides a service device, including: a processor and a memory;
  • the memory is used to store program instructions
  • the processor executes the program instructions stored in the memory. When the program instructions are executed, the processor is used to perform the following steps:
  • the encrypted data when the first terminal is a control device and the second terminal is a mobile platform, the encrypted data includes control data of the mobile device by the control device; or, when the first terminal is When the mobile platform and the second terminal are the control device, the encrypted data includes working data collected by the mobile platform.
  • an embodiment of the present invention provides a terminal, including: a processor and a memory;
  • the memory is used to store program instructions
  • the processor executes the program instructions stored in the memory. When the program instructions are executed, the processor is used to perform the following steps:
  • the encrypted data when the first terminal is a control device and the second terminal is a mobile platform, the encrypted data includes control data of the control device on the mobile platform; or, when the first terminal is the When the mobile platform is the control device, the encrypted data includes work data collected by the mobile platform.
  • an embodiment of the present invention provides a network server, including: a processor and a memory;
  • the memory is used to store program instructions
  • the processor executes the program instructions stored in the memory. When the program instructions are executed, the processor is used to perform the following steps:
  • the encrypted data when the first terminal is a control device and the second terminal is a mobile platform, the encrypted data includes control data of the control device on the mobile platform; or, when the first terminal is a When the mobile platform is used and the second terminal is the control device, the encrypted data includes work data collected by the mobile platform.
  • an embodiment of the present invention provides a computer-readable storage medium that stores a computer program, and when the computer program is executed by a processor, implements the first aspect, the second aspect, or the third aspect as described above Aspect of the data transmission method.
  • a data transmission device based on a public communication network may establish a first communication connection channel with a first terminal, receive encrypted data sent by the first terminal through the first communication connection channel, and convert the The encrypted data is sent to the second terminal, so that the second terminal can decrypt the encrypted data to obtain the original data.
  • the encryption control of the data transmission in the public wireless communication network is realized, the security of the data transmission in the public wireless communication network is improved, and the long distance communication between the first terminal and the second terminal is also facilitated .
  • FIG. 1 is a schematic flowchart of interaction of a data transmission method based on a public communication network provided by an embodiment of the present invention
  • 2a is a schematic diagram of establishing a communication connection according to an embodiment of the present invention.
  • 2b is another schematic diagram of establishing a communication connection provided by an embodiment of the present invention.
  • FIG. 3 is a schematic flowchart of a data transmission method based on a public communication network provided by an embodiment of the present invention
  • FIG. 4 is a schematic flowchart of another data transmission method based on a public communication network provided by an embodiment of the present invention.
  • FIG. 5 is a schematic flowchart of another data transmission method based on a public communication network provided by an embodiment of the present invention.
  • FIG. 6 is a schematic structural diagram of a data transmission device based on a public communication network according to an embodiment of the present invention.
  • FIG. 7 is a schematic structural diagram of another data transmission device based on a public communication network according to an embodiment of the present invention.
  • FIG. 8 is a schematic structural diagram of yet another data transmission device based on a public communication network provided by an embodiment of the present invention.
  • the data transmission method based on the public communication network may be executed by a data transmission system.
  • the data transmission system includes a service device, a first terminal, a second terminal, and a network server.
  • the first terminal may establish a first communication connection channel with the second terminal through the service device.
  • the first communication connection channel may be the first terminal and the The TCP channel established by the service device through a transmission control protocol (Transmission Control Protocol, TCP); in some embodiments, the first communication connection channel may be a user datagram protocol (User Datagram) between the first terminal and the service device Protocol, UDP) established UDP channel.
  • TCP Transmission Control Protocol
  • UDP User Datagram
  • the first terminal may perform two-way communication with service equipment through the first communication connection channel.
  • the second terminal and the service device may also establish a TCP channel through TCP or a UDP channel through UDP, so that the second terminal can perform a two-way communication connection with the service device for Two-way communication.
  • the first terminal and the second terminal establish communication connections with the service equipment, respectively, and then realize the first communication connection between each other via the service equipment.
  • the first terminal may establish a second communication connection channel with the second terminal through the network server.
  • the second communication connection channel may be the first terminal through a hypertext transmission security protocol ( Hypertext Transfer Protocol (Secure, HTTPS) establishes an HTTPS channel to realize a two-way communication connection between the first terminal and the network server, or a two-way communication connection between the second terminal and the network server.
  • HTTPS Hypertext Transfer Protocol
  • the first terminal and the second terminal respectively establish a communication connection with the network server, and then realize the second communication connection between each other via the network server.
  • the public communication network may include a public wireless communication network
  • the service device may be provided in a server for data transmission in a mobile communication network such as 4G or 5G (or the service device may be provided in a service such as 4G or 5G Service server for data transmission in mobile communication networks, etc.
  • the service server can be set up in a public cloud or a private cloud), of course, it is not limited to the above 4G or 5G mobile communication networks, as long as it is a public wireless communication network Yes;
  • the first terminal may be set on a control device including a display device (such as a user interface) (such as a remote control device of a second terminal, a mobile terminal (such as a mobile phone, a tablet, etc.)) ,
  • the second terminal may be set on a mobile platform (such as a drone, unmanned boat, unmanned car, robot, etc.); in some embodiments, the first terminal may be set on a mobile platform, so The second terminal may be provided on a control device including a
  • the data transmission method based on the public communication network proposed in the embodiments of the present invention can be applied to the field of drones.
  • the UAV field generally uses the private security link of the UAV (such as a private image transmission remote control link, where the UAV often has only one communication link, namely WIFI or a private image transmission remote control link).
  • Data transmission (such as image transmission or remote control data transmission) is relatively safe.
  • wireless ad hoc networks can be used to achieve relatively long-distance data transmission.
  • the small network coverage of wireless ad hoc networks and the obstruction of objects and buildings in flight can cause wireless self-organization.
  • the network fails. Due to the special nature of UAV flight, it is necessary to keep the aircraft controllable at all times, so in industry applications, public wireless communication networks can be used as communication backup links.
  • mobile communication networks such as 4G/5G operate on the public network, and the data between the drone and the remote control terminal is easily hijacked by third parties, resulting in flight missions that are vulnerable to hacker attacks. Therefore, how to protect flight safety in the public wireless communication network is a very important point for the UAV in the image transmission control of mobile communication networks such as 4G/5G.
  • data transmission at a long distance can be performed to ensure the security of data transmission.
  • the public wireless communication network is used as a mobile communication network for example.
  • the mobile communication network may include a fourth-generation mobile communication network (the 4th Generation mobile communication technology (4G) or a fifth-generation mobile communication network (Fifth-Generation, 5G).
  • 4G the 4th Generation mobile communication technology
  • 5G the fifth-generation mobile communication network
  • the drone when combining a 4G or 5G mobile communication network with the private security link of the drone for data transmission, the drone (such as the first terminal) can communicate with the control device (such as the second terminal) Distance to frequency. After the unmanned aerial vehicle and the control device perform close-range frequency comparison, the unmanned aerial vehicle and the control device can synchronize a preset type of data set (such as a triplet).
  • the preset type of data set is the synchronization random number and/or the verification code after the frequency of the drone and the control device are synchronized through a private security link Generated; in some embodiments, the synchronous random number includes the random number generated by the drone and/or the random number generated by the control device.
  • the drone may send login authentication information to a network server, where the login authentication information carries a request to obtain service authentication information.
  • the network server may verify the login authentication information, and send the service authentication information to the drone after the verification is successful.
  • the drone can send business authentication information to the business device, so that a TCP channel or a UDP channel is established between the business device and the drone.
  • the UAV can calculate the data key according to the generated random number, and obtain the service key through encryption operation according to the root key and the preset type of data set.
  • the UAV can encrypt the data key according to the business key to obtain the encryption key, and send the encryption key to the control device synchronously through the network server.
  • the UAV can encrypt the original data to be transmitted according to the data key to obtain encrypted data, and send the encrypted data to the business device through the TCP channel or UDP channel, so that the business device can forward the encrypted data to the control device. In this way, the safe transmission of data between the control device and the drone can be achieved.
  • the remote control device decrypts the encrypted data according to the synchronized encryption key to obtain the original data corresponding to the encrypted data
  • the encryption key is obtained by encrypting the data key with the service key
  • the The service key is calculated based on the root key and a preset type of data group, and the preset type of data group is further synchronized to the first terminal and the second terminal through a private secure link (the root key Is fixed), so, synchronizing preset data groups through a private security link can ensure the security of the service key, and the data key is encrypted twice, which further improves the security of the data.
  • this way of combining the private safety link of the drone with the remote control device and the public wireless communication network not only realizes the encryption control of the data transmission in the public wireless communication network, but also improves the data transmission in the public wireless communication network.
  • the security is also conducive to long-distance communication between UAV and remote control equipment, especially for the application of UAV.
  • FIG. 1 is a schematic flowchart of an interaction of a data transmission method based on a public communication network according to an embodiment of the present invention.
  • the interaction method may be applied to a data transmission system, in which the data transmission system is specifically explained As mentioned earlier.
  • the method in the embodiment of the present invention includes the following steps.
  • the first terminal sends login authentication information to a network server, where the login authentication information carries a request for acquiring service authentication information.
  • the first terminal may send login authentication information to the network server, where the login authentication information carries an acquisition request for service authentication information.
  • the first terminal may send login authentication information to the network server through a private secure link to prevent the login authentication information from being hijacked by other devices.
  • the first terminal may be a control device or a mobile platform.
  • the service authentication information may be a service token such as a service token
  • the login authentication information may be a login authentication token such as a login token.
  • the login authentication information may be obtained from the user center server through the third terminal, and sent to one of the first terminal and the second terminal, and the first terminal and the second terminal Use a private secure link to synchronize to another; in some embodiments, the third terminal may be a control device, or the third terminal may be a device that establishes a communication connection with the control device.
  • the login authentication information is to send the identity authentication information to the user center server through a third terminal, so that the user center server can verify the identity authentication information.
  • the user server center sends the login authentication information to the third terminal.
  • the identity authentication information may include account information and password
  • the account information and password are obtained through the user interface of the third terminal
  • the third terminal is A device that establishes a communication connection with the user center server.
  • the user center server may store relevant information about the mobile platform and the control device corresponding to the mobile platform, so that the account information and password sent by the third terminal can be authenticated.
  • the user center server may be independent of the network server, or the network server may include the user center server, that is, the network server may implement the function of the user center server or the function of sending service authentication information to the first terminal and the second terminal.
  • the first terminal is an unmanned aerial vehicle
  • the second terminal is a control device
  • the user interface is set on the control device
  • the user can enter account information and password through the user interface of the control device
  • the control device can send the login authentication information synchronously Give the drone as the first terminal so that the drone can send the login authentication information to the network server to obtain the business authentication information.
  • S102 The network server verifies the login authentication information, and sends service authentication information to the first terminal after the verification is successful.
  • the network server may verify the login authentication information, and if the verification is successful, a second communication connection channel with the first terminal may be established And send the service authentication information to the first terminal through the second communication connection channel.
  • the network server may verify the login authentication information, and if the verification is successful, the first terminal may be allowed to log in to the network server , The network server may send the service authentication information requested by the first terminal to the first terminal.
  • S103 The first terminal sends the service authentication information to the service device.
  • the first terminal may send the service authentication information to the service device.
  • S104 The service device establishes a first communication connection channel with the first terminal.
  • the service device may establish a first communication connection channel with the first terminal according to the service authentication information.
  • the first communication connection channel includes a transmission control protocol TCP channel or a user datagram protocol UDP channel.
  • FIG. 2a is a schematic diagram of establishing a communication connection according to an embodiment of the present invention.
  • the first terminal 21 may establish a second communication connection channel such as an HTTPS channel by verifying the device certificate of the network server 22, and send login authentication information to the network server through the second communication connection channel.
  • the login authentication information carries a request for obtaining service authentication information.
  • the network server 22 may verify the login authentication information. If the verification is successful, it may respond to the service authentication information acquisition request and send the service authentication information to the first terminal twenty one.
  • the first terminal 21 may send the service authentication information to the service device 23, and the service device 23 may establish a first communication connection channel, such as a TCP channel or a UDP channel, with the first terminal 21 according to the service authentication information.
  • the first terminal may be a drone or a control device.
  • FIG. 2b is used as an example for illustration, and FIG. 2b is another schematic diagram of establishing a communication connection according to an embodiment of the present invention.
  • the second terminal 24 may establish a second communication connection channel such as an HTTPS channel by verifying the device certificate of the network server 22, and send login authentication information to the network server through the second communication connection channel.
  • the login authentication information carries a request for obtaining service authentication information.
  • the network server 22 may verify the login authentication information. If the verification is successful, it may respond to the request for obtaining the service authentication information and send the service authentication information to the second terminal twenty four.
  • the second terminal 24 may send the service authentication information to the service device 23, and the service device 23 may establish a first communication connection channel, such as a TCP channel or a UDP channel, with the second terminal 24 according to the service authentication information.
  • the second terminal may be a drone or a control device.
  • both the first terminal 21 and the second terminal 24 can establish a second communication connection channel with the network server 22, and both can establish the first communication connection channel with the service device 23 through the network server 22.
  • S105 The first terminal calculates the data key according to the generated random number.
  • the first terminal may calculate the data key according to the generated random number.
  • S106 The first terminal obtains the service key through an encryption operation according to the root key and the data group of the preset type.
  • the first terminal may obtain the service key through an encryption operation according to the root key and the data group of the preset type.
  • the root key is preset in the first terminal and the second terminal, and the root key of the first terminal is the same as the root key of the second terminal.
  • the first terminal is a drone and the second terminal is a control device
  • the drone and the control device need to burn the private key, which is the root key, issued by the certificate center before leaving the factory. .
  • the preset type of data set is the first terminal and the second terminal after frequency comparison, according to the synchronization random number and/or verification after synchronization processing through the private secure link Code generated; in some embodiments, the synchronous random number includes a random number generated by the first terminal and/or a random number generated by the second terminal.
  • the method of synchronizing the synchronization random number and/or the verification code between the first terminal and the second terminal through the private secure link enables the first terminal and the second terminal to have the same preset type of data Group, and the third party cannot obtain the preset type data group to ensure the security of the preset type data group.
  • S107 The first terminal encrypts the data key according to the service password to obtain an encryption key.
  • the first terminal may encrypt the data key according to the service key to obtain an encryption key.
  • the service key is calculated based on a root key and a preset type of data group, the root key is preset and unchanged, and the preset type of data group is the first
  • the terminal and the second terminal are generated according to the synchronization random number and/or verification code after the synchronization process through the private secure link after the frequency is compared, and the data key is calculated by the first terminal according to the generated random number , Where the random number and synchronous random number will only change when the first terminal restarts, therefore, the encryption key is unchanged before the first terminal restarts, and the encryption key only needs to be generated once That's it.
  • the first terminal may use a symmetric encryption algorithm, an asymmetric encryption algorithm, or a hash algorithm to encrypt the data key.
  • the embodiment of the present invention does not specifically limit the algorithm for encrypting the data key. .
  • S108 The first terminal sends the encryption key to the network server.
  • the first terminal may send the encryption key to the network server.
  • the first terminal may send an encryption key to the network server through a second communication connection channel, so that the second terminal can obtain the encryption key from the network server.
  • the second communication connection channel includes an HTTPS channel.
  • the first terminal may also send the encryption key to the service device through the first communication connection channel, so that the service device can send the encryption key to the first device through the first communication connection channel Second terminal.
  • the encryption key may be preferably sent to the network server, so that the encryption key and the encrypted data described below can be transmitted from two different transmission paths to the first
  • the second terminal is beneficial to prevent the leakage of encrypted data caused by the simultaneous interception of the encryption key and the encrypted data by a third party, and further improves the security of data transmission between the first terminal and the second terminal.
  • the second communication connection channel is established between the first terminal and the network server by verifying the device certificates of both parties; in some embodiments, the second communication connection The channel is established by the first terminal by checking the device certificate of the network server.
  • the device certificate includes a network server certificate and/or a terminal device certificate, the network server certificate is set on the network server, and the terminal device certificate is set on the first terminal. For example, assuming that the first terminal is a drone and the second terminal is a control device, the drone and the control device need to burn a device certificate issued by a certificate center before leaving the factory.
  • the data key may not be encrypted by using the service key.
  • the data key or the encryption key after encrypting the data key may not be performed at the first terminal or the second terminal via the network server or service device Forwarding, but can be transmitted via a private safety link when the first terminal and the second terminal are in close frequency.
  • S109 The second terminal obtains the encryption key from the network server.
  • the second terminal may obtain the encryption key from the network server. Specifically, as long as the first terminal has a signal of a mobile communication network such as 4G, 5G, etc., it may actively go to the network server to request for the encryption key until the encryption key is obtained.
  • a mobile communication network such as 4G, 5G, etc.
  • S110 The first terminal encrypts the original data to be transmitted according to the data key to obtain encrypted data.
  • the first terminal may encrypt the original data to be transmitted according to the data key to obtain encrypted data.
  • the first terminal may use a symmetric encryption algorithm, an asymmetric encryption algorithm, or a hash algorithm to encrypt the original data to be transmitted.
  • the embodiment of the present invention does not specifically limit the algorithm for encrypting the original data.
  • the encrypted data when the first terminal is a control device and the second terminal is a mobile platform, the encrypted data includes control data of the control device on the mobile platform; or, when the When the first terminal is the mobile platform and the second terminal is the control device, the encrypted data includes work data collected by the mobile platform.
  • the control data may be data such as joystick data, zoom data, flight parameter setting data, etc. that can control the drone to perform corresponding operations
  • the work data may include image data, video data, and power
  • the data and location data may also include other data collected by the mobile platform, which is not specifically limited in this embodiment of the present invention.
  • the original data to be transmitted is the control device's control data for the drone.
  • Rod data For another example, assuming that the first terminal is a drone and the second terminal is a control device of the drone, the original data to be transmitted is work data collected by the drone, such as image data.
  • S111 The first terminal sends the encrypted data to the service device.
  • the first terminal may send the encrypted data to the service device through the first communication connection channel.
  • the first terminal is a drone and the encrypted data is encrypted image data
  • the drone can send the encrypted image data to a business device through a TCP channel or a UDP channel.
  • S112 The service device sends the encrypted data to the second terminal.
  • the service device may send the encrypted data to the second terminal through the first communication connection channel.
  • the drone can send the obtained encrypted image data to the control device through a TCP channel or a UDP channel.
  • S113 The second terminal decrypts the encrypted data according to the encryption key to obtain original data.
  • the second terminal may decrypt the encrypted data according to the encryption key to obtain the original data.
  • the second terminal may decrypt the encrypted data according to the encryption key to obtain a data key, and decrypt the encrypted data according to the data key to obtain the first The original data transmitted by the terminal to the second terminal.
  • the first terminal is a drone and the second terminal is a control device.
  • the control device may decrypt the encrypted image data according to the encryption key to obtain the data key, and Decrypt the encrypted image data according to the data key to obtain the image data transmitted by the drone to the control.
  • the first terminal may send login authentication information to the network server, so that the network server verifies the identity authentication information carried in the login authentication information, and sends the first terminal to the first terminal after the verification is successful Business certification information.
  • the first terminal may send the service authentication information to the service device, so that the service device establishes a first communication connection channel with the first terminal.
  • the first terminal may encrypt the original data to be transmitted to obtain encrypted data, and send the encrypted data to the service device through the first communication connection channel, so that the service device sends the encrypted data to the second terminal. In this way, the secure transmission of data between the first terminal and the second terminal can be achieved.
  • the second terminal decrypts the encrypted data according to the synchronized encryption key to obtain the original data
  • the encryption key is obtained by encrypting the data key with the service key, and the service key Calculated according to the root key and a preset type of data group
  • the preset type of data group is further synchronized to the first terminal and the second terminal through a private secure link (the root key is fixed ), in this way, synchronizing preset data groups through a private secure link can ensure the security of the service key, and perform secondary encryption on the data key to further improve data security.
  • this way of combining the private security link of the first terminal with the second terminal and the public wireless communication network not only realizes the encryption control of the data transmission in the public wireless communication network, but also improves the data in the public wireless communication network.
  • the security of transmission is also conducive to long-distance communication between the first terminal and the second terminal, and is particularly beneficial to the application of drones.
  • FIG. 3 is a schematic flowchart of a data transmission method based on a public communication network according to an embodiment of the present invention.
  • the method may be performed by a data transmission device based on a public communication network, where the data transmission device Can be set on business equipment.
  • the detailed description of the detailed implementation process of the data transmission method for service equipment in the embodiments of the present invention is as follows.
  • S301 Establish a first communication connection channel with the first terminal.
  • the data transmission device may establish a first communication connection channel with the first terminal.
  • the first communication connection channel may be a TCP channel or a UDP channel.
  • the data transmission device may receive service authentication information sent by the first terminal, and establish A first communication connection channel between terminals.
  • the service authentication information is obtained by the first terminal from the network server through the second communication connection channel and login authentication information.
  • the second communication connection channel may include an HTTPS channel, and the HTTPS adds a TLS protocol on the basis of the HTTP protocol, the purpose of which is to ensure that data is transmitted on a mobile communication network such as 4G or 5G Security.
  • the login authentication information may be a login token, that is, a login token.
  • the service authentication information may be a business token, that is, a service token.
  • the second communication connection channel may be established between the first terminal and the network server by verifying the device certificates of both parties; in some embodiments, the second communication The connection channel may be established by the first terminal by checking the device certificate of the network server.
  • the device certificate includes a network server certificate and/or a terminal device certificate, the network server certificate is set on the network server, and the terminal device certificate is set on the first terminal.
  • the login authentication information carries the service authentication information acquisition request; wherein the service authentication information acquisition request is used to instruct the network server to verify the login authentication information, and After successful verification, send service authentication information to the first terminal.
  • the drone can verify the device certificate of the network server, and the network server The device certificate of the aircraft is verified to establish an HTTPS channel between the drone and the network server.
  • the drone can send login authentication information to the web server through the HTTPS channel, and the web server verifies the login authentication information according to the login authentication information, and sends business authentication information to the drone after the verification is successful .
  • the drone can send business authentication information to the business device, so that the business device can establish a TCP channel or a UDP channel with the drone according to the business authentication information, so that the drone can pass the TCP channel Or UDP channel to transmit data to business equipment.
  • the first terminal may be a drone and the second terminal may be a control device; or the first terminal may be a control device and the second terminal may be a drone.
  • the control device includes a user interface, and the user interface includes an application APP.
  • the user can input account information and a password on the AAP through the user interface, and the control device can obtain the APP from the APP.
  • the account information and password are sent to the user center server to enable the user center server to verify the account information and password. If the verification is successful, the user center server returns login authentication information to the control device.
  • the control device may The login authentication information is synchronously sent to the drone through a private security link.
  • the control device may send the login authentication information to the network server through the HTTPS channel to verify the login authentication information. If the network server successfully verifies the login authentication information, the network server may send service authentication information to the control device, and the control device may synchronize the service authentication information to the drone.
  • the above-mentioned application APP can also be set on a device other than the control device, such as a mobile terminal (such as a mobile phone, a tablet computer, etc.) communicatively connected to the control device, and the user can enter account information on the AAP through the user interface And password, the mobile terminal may send the account information and password obtained on the APP to the user center server, so that the user center server verifies the account information and password. If the verification is successful, the user The central server returns login authentication information to the mobile terminal, and the mobile terminal may send the login authentication information to the control device, and then the control device synchronously sends it to the drone through a private security link.
  • a mobile terminal such as a mobile phone, a tablet computer, etc.
  • S302 Receive the encrypted data sent by the first terminal through the first communication connection channel, and send the encrypted data to the second terminal.
  • the data transmission device may receive the encrypted data sent by the first terminal through the first communication connection channel, and send the encrypted data to the second terminal.
  • the encrypted data when the first terminal is a control device and the second terminal is a mobile platform, the encrypted data includes control data of the control device on the mobile platform; or, when the When the first terminal is the mobile platform and the second terminal is the control device, the encrypted data includes work data collected by the mobile platform.
  • the encrypted data is obtained by encrypting the original data to be transmitted according to the data key by the first terminal; in some embodiments, the data key is generated by the first terminal according to Calculated by the random number.
  • the original data is control data of the control device on the mobile platform; or, when the first terminal is When the mobile platform and the second terminal are control devices, the original data is working data collected by the mobile platform.
  • the data transmission device may also receive the encryption key sent by the first terminal through the first communication connection channel, and send the encryption key to the second terminal, so that The second terminal decrypts the encrypted data according to the encryption key.
  • the encryption key is obtained by the first terminal encrypting the data key.
  • the encryption key is the first terminal encrypting the data according to a service password
  • the key is encrypted.
  • the service key is obtained by the first terminal through an encryption operation according to a root key and a data group of a preset type.
  • the root key is preset in the first terminal and the second terminal, wherein the root key of the first terminal and the root key of the second terminal the same.
  • the preset type of data set is the first terminal and the second terminal after frequency comparison, according to the synchronization random number and/or verification after synchronization processing through the private secure link Code generation; wherein, the synchronous random number includes the random number generated by the first terminal and/or the random number generated by the second terminal.
  • the first terminal is a drone
  • the second terminal is a control device
  • the original data to be transmitted is image data collected by the drone
  • the first terminal can generate random numbers according to The data key is calculated
  • the image data collected by the drone is encrypted according to the data key to obtain encrypted data.
  • the drone can encrypt the data key according to the service password to obtain an encryption key, and send the encryption key to the control device through the network server.
  • the drone may send the encrypted data to a business device through a TCP channel or a UDP channel, so that the business device sends the encrypted data to a control device, so that the control device can control Decrypt the encrypted data to obtain a data key, and decrypt the encrypted data according to the data key to obtain image data.
  • the data transmission device may establish a first communication connection channel with the first terminal, and receive encrypted data sent by the first terminal through the first communication connection channel, and convert the encrypted data Send to the second terminal. In this way, the secure transmission of data between the first terminal and the second terminal can be achieved.
  • the second terminal decrypts the encrypted data according to the synchronized encryption key to obtain the original data
  • the encryption key is obtained by encrypting the data key with the service key, and the service key Calculated according to the root key and a preset type of data group
  • the preset type of data group is further synchronized to the first terminal and the second terminal through a private secure link (the root key is fixed ), in this way, synchronizing preset data groups through a private secure link can ensure the security of the service key, and perform secondary encryption on the data key to further improve data security.
  • this way of combining the private security link of the first terminal with the second terminal and the public wireless communication network not only realizes the encryption control of the data transmission in the public wireless communication network, but also improves the data in the public wireless communication network.
  • the security of transmission is also conducive to long-distance communication between the first terminal and the second terminal, and is particularly beneficial to the application of drones.
  • FIG. 4 is a schematic flowchart of another method for data transmission based on a public communication network according to an embodiment of the present invention.
  • the method may be performed by a data transmission device based on a public communication network.
  • the device may be set on the first terminal.
  • the detailed description of the detailed implementation process of the data transmission method for the first terminal according to the embodiment of the present invention is as follows.
  • S401 Establish a first communication connection channel with a service device.
  • the data transmission device may establish a first communication connection channel with the service device.
  • the explanation of the first communication connection channel is as described above, and will not be repeated here.
  • the data transmission when the data transmission is set up to establish a first communication connection channel with a service device, it may send service authentication information to the service device, and establish a connection with the first terminal according to the service authentication information The first communication connection channel.
  • the service authentication information is obtained from the network server through the second communication connection channel and the login authentication information.
  • the explanation of the first communication connection channel is as described above, the explanation of the second communication connection channel is as described above, and the explanation of the device certificate is as described above, and is not repeated here Repeat.
  • the login authentication information carries the service authentication information acquisition request; wherein the service authentication information acquisition request is used to instruct the network server to verify the login authentication information, and After successful verification, send service authentication information to the first terminal.
  • the service authentication information acquisition request is used to instruct the network server to verify the login authentication information, and After successful verification, send service authentication information to the first terminal.
  • S402 Send encrypted data to the service device through the first communication connection channel, so that the service device sends the encrypted data to a second terminal.
  • the data transmission device may send encrypted data to the service device through the first communication connection channel, so that the service device sends the encrypted data to the second terminal.
  • the encrypted data when the first terminal is a control device and the second terminal is a mobile platform, the encrypted data includes control data of the control device on the mobile platform; or, when the When the first terminal is the mobile platform and the second terminal is the control device, the encrypted data includes work data collected by the mobile platform.
  • the interpretation of the encrypted data is as described above, and the interpretation of the data key is as described above, and will not be repeated here.
  • the data transmission device may send an encryption key to the network server through the second communication connection channel, so that the second terminal obtains the encryption key according to the encryption key obtained from the network server Decrypt the encrypted data; or, send the encryption key to the service device through the first communication connection channel, so that the second terminal controls the exchange according to the encryption key obtained from the service device Decrypt the encrypted data; wherein, the encryption key is obtained by the first terminal encrypting the data key according to a service password.
  • the service key is obtained by the first terminal through an encryption operation according to a root key and a data group of a preset type. Wherein, the explanation of the root key is as described above, and the explanation of the preset type data group is as described above, and will not be repeated here.
  • the control device may calculate based on the generated random number Obtain a data key, and encrypt the control data according to the data key to obtain encrypted data.
  • the control device may encrypt the data key according to the service password to obtain an encryption key, and send the encryption key to the drone through the network server.
  • the control device may send the encrypted data to the business device through a TCP channel or a UDP channel, so that the business device sends the encrypted data to the drone, so that the drone can pair according to the encryption key Decrypt the encrypted data to obtain a data key, and decrypt the encrypted data according to the data key to obtain the control data, so that the drone can perform the drone according to the control data control.
  • the data transmission device may establish a first communication connection channel with the service device, and send encrypted data to the service device through the first communication connection channel, so that the service device uses the The encrypted data is sent to the second terminal. In this way, the secure transmission of data between the first terminal and the second terminal can be achieved.
  • the second terminal decrypts the encrypted data according to the synchronized encryption key to obtain the original data
  • the encryption key is obtained by encrypting the data key with the service key, and the service key Calculated according to the root key and a preset type of data group
  • the preset type of data group is further synchronized to the first terminal and the second terminal through a private secure link (the root key is fixed ), in this way, synchronizing preset data groups through a private secure link can ensure the security of the service key, and perform secondary encryption on the data key to further improve data security.
  • this way of combining the private security link of the first terminal with the second terminal and the public wireless communication network not only realizes the encryption control of the data transmission in the public wireless communication network, but also improves the data in the public wireless communication network.
  • the security of transmission is also conducive to long-distance communication between the first terminal and the second terminal, and is particularly beneficial to the application of drones.
  • FIG. 5 is a schematic flowchart of yet another data transmission method based on a public communication network according to an embodiment of the present invention.
  • the method may be executed by a data transmission device based on a public communication network, where the data transmission
  • the device can be set on a web server.
  • the detailed description of the detailed implementation process of the data transmission method for the network server according to the embodiment of the present invention is as follows.
  • S501 Establish a second communication connection channel with the first terminal.
  • the data transmission device may establish a second communication connection channel with the first terminal.
  • the second communication connection channel is established between the first terminal and the network server by verifying the device certificates of both parties; or, the second communication connection channel is the first A terminal is established by verifying the device certificate of the network server. The explanation of the device certificate is as described above, and will not be repeated here.
  • the second communication channel includes an HTTPS channel.
  • S502 Receive an encryption key sent by the first terminal through the second communication connection channel, so that the second terminal sends the first terminal to the first terminal according to the encryption key obtained from the network server The encrypted data of the second terminal is decrypted.
  • the data transmission device may receive the encryption key sent by the first terminal through the second communication connection channel, so that the second terminal uses the encryption key obtained from the network server to The encrypted data sent by the first terminal to the second terminal is decrypted.
  • the encrypted data when the first terminal is a control device and the second terminal is a mobile platform, the encrypted data includes control data for the mobile platform by the control device; or, when the When the first terminal is the mobile platform and the second terminal is the control device, the encrypted data includes work data collected by the mobile platform.
  • the encryption key is obtained by the first terminal encrypting the data key, and the encrypted data is obtained by the first terminal encrypting the original data to be transmitted according to the data key ;
  • the encryption key is obtained by the first terminal encrypting the data key according to the service password.
  • the service key is obtained by the first terminal through an encryption operation according to a root key and a data group of a preset type.
  • the data key is calculated by the first terminal according to the generated random number.
  • the data transmission device may also receive login authentication information sent by the first terminal through the second communication connection channel, and convert the The service authentication information corresponding to the login authentication information is given to the first terminal, so that the first terminal establishes a first communication connection channel with the service device according to the service authentication information.
  • the encrypted data is sent by the first terminal to the service device through the first communication connection channel, and sent by the service device to the second terminal.
  • the first communication connection channel includes a transmission control protocol TCP channel or a user datagram protocol UDP channel.
  • the login authentication information carries the service authentication information acquisition request; wherein the service authentication information acquisition request is used to instruct the network server to verify the login authentication information, and After successful verification, send service authentication information to the first terminal.
  • the service authentication information acquisition request is used to instruct the network server to verify the login authentication information, and After successful verification, send service authentication information to the first terminal.
  • the data transmission device may establish a second communication connection channel with the first terminal, and receive the encryption key sent by the first terminal through the second communication connection channel. In this way, the secure transmission of data between the first terminal and the second terminal can be achieved.
  • the second terminal decrypts the encrypted data according to the synchronized encryption key to obtain the original data
  • the encryption key is obtained by encrypting the data key with the service key, and the service key Calculated according to the root key and a preset type of data group
  • the preset type of data group is further synchronized to the first terminal and the second terminal through a private secure link (the root key is fixed ), in this way, synchronizing preset data groups through a private secure link can ensure the security of the service key, and perform secondary encryption on the data key to further improve data security.
  • this way of combining the private security link of the first terminal with the second terminal and the public wireless communication network not only realizes the encryption control of the data transmission in the public wireless communication network, but also improves the data in the public wireless communication network.
  • the security of transmission is also conducive to long-distance communication between the first terminal and the second terminal, and is particularly beneficial to the application of drones.
  • FIG. 6 is a schematic structural diagram of a data transmission device based on a public communication network according to an embodiment of the present invention.
  • the data transmission device includes: a memory 601, a processor 602, and a data interface 603.
  • the memory 601 may include a volatile memory (volatile memory); the memory 601 may also include a non-volatile memory (non-volatile memory); the memory 601 may also include a combination of the foregoing types of memories.
  • the processor 602 may be a central processing unit (central processing unit, CPU).
  • the processor 602 may further include a hardware data transmission device.
  • the hardware data transmission device may be an application-specific integrated circuit (ASIC), a programmable logic device (PLD) or a combination thereof.
  • ASIC application-specific integrated circuit
  • PLD programmable logic device
  • it may be a complex programmable logic device (complex programmable logic device, CPLD), field programmable logic gate array (field-programmable gate array, FPGA), or any combination thereof.
  • the memory 601 is used to store program instructions.
  • the processor 602 may call the program instructions stored in the memory 601 to perform the following steps:
  • the encrypted data when the first terminal is a control device and the second terminal is a mobile platform, the encrypted data includes control data of the mobile device by the control device; or, when the first terminal is When the mobile platform and the second terminal are the control device, the encrypted data includes working data collected by the mobile platform.
  • the processor 602 when the processor 602 establishes a first communication connection channel with the first terminal, it is specifically used to:
  • the second communication connection channel is established between the first terminal and the network server by checking the device certificates of both parties; or,
  • the second communication connection channel is established by the first terminal by checking the device certificate of the network server.
  • the device certificate includes a network server certificate and/or a terminal device certificate, the network server certificate is set on the network server, and the terminal device certificate is set on the first terminal.
  • the second communication connection channel includes a hypertext transmission security protocol HTTPS channel.
  • the login authentication information carries the request for obtaining the business authentication information
  • the acquisition request of the service authentication information is used to instruct the network server to verify the login authentication information, and send the service authentication information to the first terminal after the verification is successful.
  • the login authentication information is obtained by the third terminal through the user center server, and sent by the third terminal to the control device, and synchronously sent by the control device to the mobile platform through a private secure link of;
  • the third terminal is the control device, or the third terminal is a device that establishes a communication connection with the control device; the third terminal establishes a communication connection with the user center server, and the user
  • the central server is independent of the network server, or the network server includes the user central server.
  • the first communication connection channel includes a transmission control protocol TCP channel or a user datagram protocol UDP channel.
  • the encrypted data is obtained by encrypting the original data to be transmitted according to the data key by the first terminal;
  • the original data is control data of the control device on the mobile platform; or, when the first terminal is When the mobile platform and the second terminal are control devices, the original data is working data collected by the mobile platform.
  • the data key is calculated by the first terminal according to the generated random number.
  • processor 602 is also used to:
  • the encryption key is obtained by the first terminal encrypting the data key.
  • the encryption key is obtained by the first terminal encrypting the data key according to a service password.
  • the service key is obtained by the first terminal through an encryption operation according to a root key and a data group of a preset type.
  • the root key is preset in the first terminal and the second terminal, and the root key of the first terminal is the same as the root key of the second terminal.
  • the data group of the preset type is generated by the first terminal and the second terminal according to a synchronization random number and/or a verification code after synchronization processing through a private security link;
  • the synchronous random number includes a random number generated by the first terminal and/or a random number generated by the second terminal.
  • the data transmission device may establish a first communication connection channel with the first terminal, and receive encrypted data sent by the first terminal through the first communication connection channel, and the The encrypted data is sent to the second terminal. In this way, the secure transmission of data between the first terminal and the second terminal can be achieved.
  • the second terminal decrypts the encrypted data according to the synchronized encryption key to obtain the original data
  • the encryption key is obtained by encrypting the data key with the service key, and the service key Calculated according to the root key and a preset type of data group
  • the preset type of data group is further synchronized to the first terminal and the second terminal through a private secure link (the root key is fixed ), in this way, synchronizing preset data groups through a private secure link can ensure the security of the service key, and perform secondary encryption on the data key to further improve data security.
  • this way of combining the private security link of the first terminal with the second terminal and the public wireless communication network not only realizes the encryption control of the data transmission in the public wireless communication network, but also improves the data in the public wireless communication network.
  • the security of transmission is also conducive to long-distance communication between the first terminal and the second terminal, and is particularly beneficial to the application of drones.
  • FIG. 7 is a schematic structural diagram of another data transmission device based on a public communication network according to an embodiment of the present invention.
  • the data transmission device includes: a memory 701, a processor 702, and a data interface 703.
  • the memory 701 may include a volatile memory (volatile memory); the memory 701 may also include a non-volatile memory (non-volatile memory); the memory 701 may also include a combination of the foregoing types of memories.
  • the processor 702 may be a central processing unit (central processing unit, CPU).
  • the processor 702 may further include a hardware data transmission device.
  • the hardware data transmission device may be an application-specific integrated circuit (ASIC), a programmable logic device (PLD) or a combination thereof.
  • ASIC application-specific integrated circuit
  • PLD programmable logic device
  • FPGA field-programmable gate array
  • the memory 701 is used to store program instructions.
  • the processor 702 may call the program instructions stored in the memory 701 to perform the following steps:
  • the encrypted data when the first terminal is a control device and the second terminal is a mobile platform, the encrypted data includes control data of the mobile device by the control device; or, when the first terminal is When the mobile platform and the second terminal are the control device, the encrypted data includes working data collected by the mobile platform.
  • processor 702 establishes the first communication connection channel with the service device, it is specifically used to:
  • the second communication connection channel is established between the first terminal and the network server by checking the device certificates of both parties; or,
  • the second communication connection channel is established by the first terminal by checking the device certificate of the network server.
  • the device certificate includes a network server certificate and/or a terminal device certificate, the network server certificate is set on the network server, and the terminal device certificate is set on the first terminal.
  • the second communication connection channel includes an HTTPS channel.
  • the login authentication information carries the request for obtaining the business authentication information
  • the acquisition request of the service authentication information is used to instruct the network server to verify the login authentication information, and send the service authentication information to the first terminal after the verification is successful.
  • the login authentication information is obtained by the third terminal through the user center server, and sent by the third terminal to the control device, and synchronously sent by the control device to the mobile platform through a private secure link of;
  • the third terminal is the control device, or the third terminal is a device that establishes a communication connection with the control device; the third terminal establishes a communication connection with the user center server, and the user
  • the central server is independent of the network server, or the network server includes the user central server.
  • the first communication connection channel includes a transmission control protocol TCP channel or a user datagram protocol UDP channel.
  • the encrypted data is obtained by encrypting the original data to be transmitted according to the data key by the first terminal;
  • the original data is control data of the control device on the mobile platform; or, when the first terminal is When the mobile platform and the second terminal are control devices, the original data is working data collected by the mobile platform.
  • the data key is calculated by the first terminal according to the generated random number.
  • processor 702 is also used to:
  • the encryption key is obtained by the first terminal encrypting the data key.
  • the encryption key is obtained by the first terminal encrypting the data key according to a service password.
  • the service key is obtained by the first terminal through an encryption operation according to a root key and a data group of a preset type.
  • the root key is preset in the first terminal and the second terminal, and the root key of the first terminal is the same as the root key of the second terminal.
  • the data group of the preset type is generated by the first terminal and the second terminal according to a synchronization random number and/or a verification code after synchronization processing through a private security link;
  • the synchronous random number includes a random number generated by the first terminal and/or a random number generated by the second terminal.
  • the data transmission device may establish a first communication connection channel with the service device, and send encrypted data to the service device through the first communication connection channel, so that the service device uses the The encrypted data is sent to the second terminal. In this way, the secure transmission of data between the first terminal and the second terminal can be achieved.
  • the second terminal decrypts the encrypted data according to the synchronized encryption key to obtain the original data
  • the encryption key is obtained by encrypting the data key with the service key, and the service key Calculated according to the root key and a preset type of data group
  • the preset type of data group is further synchronized to the first terminal and the second terminal through a private secure link (the root key is fixed ), in this way, synchronizing preset data groups through a private secure link can ensure the security of the service key, and perform secondary encryption on the data key to further improve data security.
  • this way of combining the private security link of the first terminal with the second terminal and the public wireless communication network not only realizes the encryption control of the data transmission in the public wireless communication network, but also improves the data in the public wireless communication network.
  • the security of transmission is also conducive to long-distance communication between the first terminal and the second terminal, and is particularly beneficial to the application of drones.
  • FIG. 8 is a schematic structural diagram of yet another data transmission device based on a public communication network according to an embodiment of the present invention.
  • the data transmission device includes: a memory 801, a processor 802, and a data interface 803.
  • the memory 801 may include a volatile memory (volatile memory); the memory 801 may also include a non-volatile memory (non-volatile memory); the memory 801 may also include a combination of the foregoing types of memories.
  • the processor 802 may be a central processing unit (central processing unit, CPU).
  • the processor 802 may further include a hardware data transmission device.
  • the hardware data transmission device may be an application-specific integrated circuit (ASIC), a programmable logic device (PLD) or a combination thereof.
  • ASIC application-specific integrated circuit
  • PLD programmable logic device
  • FPGA field programmable logic gate array
  • the memory 801 is used to store program instructions.
  • the processor 802 may call the program instructions stored in the memory 801 to perform the following steps:
  • the encrypted data when the first terminal is a control device and the second terminal is a mobile platform, the encrypted data includes control data of the control device on the mobile platform; or, when the first terminal is a When the mobile platform is used and the second terminal is the control device, the encrypted data includes work data collected by the mobile platform.
  • the second communication connection channel is established between the first terminal and the network server by checking the device certificates of both parties; or,
  • the second communication connection channel is established by the first terminal by checking the device certificate of the network server.
  • the device certificate includes a network server certificate and/or a terminal device certificate, the network server certificate is set on the network server, and the terminal device certificate is set on the first terminal.
  • the second communication connection channel includes an HTTPS channel.
  • the encryption key is obtained by the first terminal encrypting a data key
  • the encrypted data is obtained by the first terminal encrypting the original data to be transmitted according to the data key
  • the original data is control data of the control device on the mobile platform; or, when the first terminal is When the mobile platform and the second terminal are control devices, the original data is working data collected by the mobile platform.
  • the encryption key is obtained by the first terminal encrypting the data key according to the service password.
  • the service key is obtained by the first terminal through an encryption operation according to a root key and a data group of a preset type.
  • the root key is preset in the first terminal and the second terminal, and the root key of the first terminal is the same as the root key of the second terminal.
  • the data group of the preset type is generated by the first terminal and the second terminal according to a synchronization random number and/or a verification code after synchronization processing through a private security link;
  • the synchronous random number includes a random number generated by the first terminal and/or a random number generated by the second terminal.
  • the data key is calculated by the first terminal according to the generated random number.
  • the processor 802 establishes a second communication connection channel with the first terminal, it is also used to:
  • the encrypted data is sent by the first terminal to the service device through the first communication connection channel, and is sent by the service device to the second terminal.
  • the login authentication information carries the request for obtaining the business authentication information
  • the acquisition request of the service authentication information is used to instruct the network server to verify the login authentication information, and send the service authentication information to the first terminal after the verification is successful.
  • the login authentication information is obtained by the third terminal through the user center server, and sent by the third terminal to the control device, and synchronously sent by the control device to the mobile platform through a private secure link of;
  • the third terminal is the control device, or the third terminal is a device that establishes a communication connection with the control device; the third terminal establishes a communication connection with the user center server, and the user
  • the central server is independent of the network server, or the network server includes the user central server.
  • the first communication connection channel includes a transmission control protocol TCP channel or a user datagram protocol UDP channel.
  • the data transmission device may establish a second communication connection channel with the first terminal and receive the encryption key sent by the first terminal through the second communication connection channel, so that the second terminal
  • the encryption key obtained by the network server decrypts the encrypted data sent from the first terminal to the second terminal to obtain original data.
  • An embodiment of the present invention provides a service device, including: a processor and a memory; the memory is used to store program instructions; the processor executes the program instructions stored in the memory, and when the program instructions are executed, The processor is used to perform the following steps:
  • the encrypted data when the first terminal is a control device and the second terminal is a mobile platform, the encrypted data includes control data of the mobile device by the control device; or, when the first terminal is When the mobile platform and the second terminal are the control device, the encrypted data includes working data collected by the mobile platform.
  • the processor establishes the first communication connection channel with the first terminal, it is specifically used to:
  • the second communication connection channel is established between the first terminal and the network server by checking the device certificates of both parties; or,
  • the second communication connection channel is established by the first terminal by checking the device certificate of the network server.
  • the device certificate includes a network server certificate and/or a terminal device certificate, the network server certificate is set on the network server, and the terminal device certificate is set on the first terminal.
  • the second communication connection channel includes a hypertext transmission security protocol HTTPS channel.
  • the login authentication information carries the request for obtaining the business authentication information
  • the acquisition request of the service authentication information is used to instruct the network server to verify the login authentication information, and send the service authentication information to the first terminal after the verification is successful.
  • the login authentication information is obtained by the third terminal through the user center server, and sent by the third terminal to the control device, and synchronously sent by the control device to the mobile platform through a private secure link of;
  • the third terminal is the control device, or the third terminal is a device that establishes a communication connection with the control device; the third terminal establishes a communication connection with the user center server, and the user
  • the central server is independent of the network server, or the network server includes the user central server.
  • the first communication connection channel includes a transmission control protocol TCP channel or a user datagram protocol UDP channel.
  • the encrypted data is obtained by encrypting the original data to be transmitted according to the data key by the first terminal;
  • the original data is control data of the control device on the mobile platform; or, when the first terminal is When the mobile platform and the second terminal are control devices, the original data is working data collected by the mobile platform.
  • the data key is calculated by the first terminal according to the generated random number.
  • processor is also used to:
  • the encryption key is obtained by the first terminal encrypting the data key.
  • the encryption key is obtained by the first terminal encrypting the data key according to a service password.
  • the service key is obtained by the first terminal through an encryption operation according to a root key and a data group of a preset type.
  • the root key is preset in the first terminal and the second terminal, and the root key of the first terminal is the same as the root key of the second terminal.
  • the data group of the preset type is generated by the first terminal and the second terminal according to a synchronization random number and/or a verification code after synchronization processing through a private security link;
  • the synchronous random number includes a random number generated by the first terminal and/or a random number generated by the second terminal.
  • the service device may establish a first communication connection channel with the first terminal, and receive encrypted data sent by the first terminal through the first communication connection channel, and send the encrypted data To the second terminal, so that the second terminal can decrypt the encrypted data to obtain the original data.
  • An embodiment of the present invention provides a terminal, including: a processor and a memory; the memory is used to store program instructions; the processor executes the program instructions stored in the memory, when the program instructions are executed, the The processor is used to perform the following steps:
  • the encrypted data when the first terminal is a control device and the second terminal is a mobile platform, the encrypted data includes control data of the control device on the mobile platform; or, when the first terminal is the When the mobile platform is the control device, the encrypted data includes work data collected by the mobile platform.
  • the processor establishes the first communication connection channel with the service device, it is specifically used to:
  • the second communication connection channel is established between the first terminal and the network server by checking the device certificates of both parties; or,
  • the second communication connection channel is established by the first terminal by checking the device certificate of the network server.
  • the device certificate includes a network server certificate and/or a terminal device certificate, the network server certificate is set on the network server, and the terminal device certificate is set on the first terminal.
  • the second communication connection channel includes an HTTPS channel.
  • the login authentication information carries the request for obtaining the business authentication information
  • the acquisition request of the service authentication information is used to instruct the network server to verify the login authentication information, and send the service authentication information to the first terminal after the verification is successful.
  • the login authentication information is obtained by the third terminal through the user center server, and sent by the third terminal to the control device, and synchronously sent by the control device to the mobile platform through a private secure link of;
  • the third terminal is the control device, or the third terminal is a device that establishes a communication connection with the control device; the third terminal establishes a communication connection with the user center server, and the user
  • the central server is independent of the network server, or the network server includes the user central server.
  • the first communication connection channel includes a transmission control protocol TCP channel or a user datagram protocol UDP channel.
  • the encrypted data is obtained by encrypting the original data to be transmitted according to the data key by the first terminal;
  • the original data is control data of the control device on the mobile platform; or, when the first terminal is When the mobile platform and the second terminal are control devices, the original data is working data collected by the mobile platform.
  • the data key is calculated by the first terminal according to the generated random number.
  • processor is also used to:
  • the encryption key is obtained by the first terminal encrypting the data key.
  • the encryption key is obtained by the first terminal encrypting the data key according to a service password.
  • the service key is obtained by the first terminal through an encryption operation according to a root key and a data group of a preset type.
  • the root key is preset in the first terminal and the second terminal, and the root key of the first terminal is the same as the root key of the second terminal.
  • the data group of the preset type is generated by the first terminal and the second terminal according to a synchronization random number and/or a verification code after synchronization processing through a private security link;
  • the synchronous random number includes a random number generated by the first terminal and/or a random number generated by the second terminal.
  • the first terminal may establish a first communication connection channel with the service device, and send encrypted data to the service device through the first communication connection channel, so that the service device uses the
  • the encrypted data is sent to the second terminal, so that the second terminal can decrypt the encrypted data according to the synchronized encryption key to obtain the original data.
  • An embodiment of the present invention provides a network server, including: a processor and a memory; the memory is used to store program instructions; the processor executes the program instructions stored in the memory, and when the program instructions are executed, The processor is used to perform the following steps:
  • the encrypted data when the first terminal is a control device and the second terminal is a mobile platform, the encrypted data includes control data of the control device on the mobile platform; or, when the first terminal is a When the mobile platform is used and the second terminal is the control device, the encrypted data includes work data collected by the mobile platform.
  • the second communication connection channel is established between the first terminal and the network server by checking the device certificates of both parties; or,
  • the second communication connection channel is established by the first terminal by checking the device certificate of the network server.
  • the device certificate includes a network server certificate and/or a terminal device certificate
  • the network server certificate is set on the network server
  • the terminal device certificate is set on the first terminal
  • the second communication connection channel includes an HTTPS channel.
  • the encryption key is obtained by the first terminal encrypting a data key
  • the encrypted data is obtained by the first terminal encrypting the original data to be transmitted according to the data key
  • the original data is control data of the control device on the mobile platform; or, when the first terminal is When the mobile platform and the second terminal are control devices, the original data is working data collected by the mobile platform.
  • the encryption key is obtained by the first terminal encrypting the data key according to the service password.
  • the service key is obtained by the first terminal through an encryption operation according to a root key and a data group of a preset type.
  • the root key is preset in the first terminal and the second terminal, and the root key of the first terminal is the same as the root key of the second terminal.
  • the data group of the preset type is generated by the first terminal and the second terminal according to a synchronization random number and/or a verification code after synchronization processing through a private security link;
  • the synchronous random number includes a random number generated by the first terminal and/or a random number generated by the second terminal.
  • the data key is calculated by the first terminal according to the generated random number.
  • the processor establishes the second communication connection channel with the first terminal, it is also used to:
  • the encrypted data is sent by the first terminal to the service device through the first communication connection channel, and is sent by the service device to the second terminal.
  • the login authentication information carries the request for obtaining the business authentication information
  • the acquisition request of the service authentication information is used to instruct the network server to verify the login authentication information, and send the service authentication information to the first terminal after the verification is successful.
  • the login authentication information is obtained by the third terminal through the user center server, and sent by the third terminal to the control device, and synchronously sent by the control device to the mobile platform through a private secure link of;
  • the third terminal is the control device, or the third terminal is a device that establishes a communication connection with the control device; the third terminal establishes a communication connection with the user center server, and the user
  • the central server is independent of the network server, or the network server includes the user central server.
  • the first communication connection channel includes a transmission control protocol TCP channel or a user datagram protocol UDP channel.
  • the network server may establish a second communication connection channel with the first terminal and receive the encryption key sent by the first terminal through the second communication connection channel, so that the second terminal
  • the encryption key obtained by the network server decrypts the encrypted data sent from the first terminal to the second terminal to obtain original data.
  • a computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the data transmission method described in the embodiment of the present invention is implemented. The method will not be repeated here.
  • the computer-readable storage medium may be an internal storage unit of the device according to any one of the foregoing embodiments, such as a hard disk or a memory of the device.
  • the computer-readable storage medium may also be an external storage device of the device, for example, a plug-in hard disk equipped on the device, a smart memory card (Smart Media Card, SMC), and a secure digital (SD) card , Flash card (Flash Card), etc.
  • the computer-readable storage medium may also include both an internal storage unit of the device and an external storage device.
  • the computer-readable storage medium is used to store the computer program and other programs and data required by the device.
  • the computer-readable storage medium may also be used to temporarily store data that has been or will be output.
  • the storage medium may be a magnetic disk, an optical disk, a read-only memory (Read-Only Memory, ROM) or a random access memory (Random Access Memory, RAM), etc.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Telephonic Communication Services (AREA)

Abstract

本发明实施例提供了一种基于公共通信网络的数据传输方法、设备、终端、服务器及存储介质,其中,该方法包括:建立与第一终端之间的第一通信连接通道;接收所述第一终端通过所述第一通信连接通道发送的加密数据,并将所述加密数据发送给第二终端;其中,当所述第一终端为控制设备、且所述第二终端为移动平台时,所述加密数据包括所述控制设备对所述移动平台的控制数据;或,当所述第一终端为所述移动平台、且所述第二终端为所述控制设备时,所述加密数据包括所述移动平台采集的工作数据。通过这种方式,实现了对公共无线通信网络中的数据传输进行加密控制,提高了公共无线通信网络中数据传输的安全性,有利于第一终端和第二终端之间的远距离通信。

Description

一种数据传输方法、设备、终端、服务器及存储介质 技术领域
本发明涉及控制技术领域,尤其涉及一种基于公共通信网络的数据传输方法、设备、终端、服务器及存储介质。
背景技术
随着移动通信网络的发展,移动通信网络中数据传输的安全性问题越来越多,尤其是随着无人机技术领域的发展,通过无人机的私有安全链路进行数据传输很难实现远距离的数据传输,因此在无人机的行业应用中可以借助公用无线通信网络作为通信备份链路。
目前为止,在无人机领域中,对在移动通信网络中的数据传输的安全性问题越来越受重视,但还没有一套针对无人机系统的成熟的网络安全方案。因此,如何更好地确保移动通信网络中数据传输的安全性成为研究的重点。
发明内容
本发明实施例提供了一种基于公共通信网络的数据传输方法、设备、终端、服务器及存储介质,实现了对公共无线通信网络中的数据传输进行加密控制,提高了公共无线通信网络中数据传输的安全性,有利于第一终端和第二终端之间的远距离通信。
第一方面,本发明实施例提供了一种基于公共通信网络的数据传输方法,应用于业务设备,所述方法包括:
建立与第一终端之间的第一通信连接通道;
接收所述第一终端通过所述第一通信连接通道发送的加密数据,并将所述加密数据发送给第二终端;
其中,当所述第一终端为控制设备、且所述第二终端为移动平台时,所述加密数据包括所述控制设备对所述移动平台的控制数据;或,当所述第一终端为所述移动平台、且所述第二终端为所述控制设备时,所述加密数据包括所述移动平台采集的工作数据。
第二方面,本发明实施例提供了另一种基于公共通信网络的数据传输方 法,应用于第一终端,所述方法包括:
建立与业务设备之间的第一通信连接通道;
通过所述第一通信连接通道向所述业务设备发送加密数据,以使得所述业务设备将所述加密数据发送至第二终端;
其中,当所述第一终端为控制设备、且所述第二终端为移动平台时,所述加密数据包括所述控制设备对所述移动平台的控制数据;或,当所述第一终端为所述移动平台、且所述第二终端为所述控制设备时,所述加密数据包括所述移动平台采集的工作数据。
第三方面,本发明实施例提供了又一种基于公共通信网络的数据传输方法,应用于网络服务器,所述方法包括:
建立与第一终端的第二通信连接通道;
接收所述第一终端通过所述第二通信连接通道发送的加密密钥,以使得第二终端根据从所述网络服务器获取的所述加密密钥对所述第一终端发送至所述第二终端的加密数据进行解密;
其中,当所述第一终端为控制设备、所述第二终端为移动平台时,所述加密数据包括所述控制设备对所述移动平台的控制数据;或,当所述第一终端为所述移动平台、且所述第二终端为所述控制设备时,所述加密数据包括所述移动平台采集的工作数据。
第四方面,本发明实施例提供了一种基于公共通信网络的数据传输设备,应用于业务设备,所述设备包括:处理器和存储器;
所述存储器,用于存储程序指令;
所述处理器,执行所述存储器存储的程序指令,当程序指令被执行时,所述处理器用于执行如下步骤:
建立与第一终端之间的第一通信连接通道;
接收所述第一终端通过所述第一通信连接通道发送的加密数据,并将所述加密数据发送给第二终端;
其中,当所述第一终端为控制设备、且所述第二终端为移动平台时,所述加密数据包括所述控制设备对所述移动平台的控制数据;或,当所述第一终端为所述移动平台、且所述第二终端为所述控制设备时,所述加密数据包括所述移动平台采集的工作数据。
第五方面,本发明实施例提供了另一种基于公共通信网络的数据传输设备,应用于第一终端,所述设备包括:处理器和存储器;
所述存储器,用于存储程序指令;
所述处理器,执行所述存储器存储的程序指令,当程序指令被执行时,所述处理器用于执行如下步骤:
建立与业务设备之间的第一通信连接通道;
通过所述第一通信连接通道向业务设备发送加密数据,以使得所述业务设备将所述加密数据发送至第二终端;
其中,当所述第一终端为控制设备、且所述第二终端为移动平台时,所述加密数据包括所述控制设备对所述移动平台的控制数据;或,当所述第一终端为所述移动平台、且所述第二终端为所述控制设备时,所述加密数据包括所述移动平台采集的工作数据。
第六方面,本发明实施例提供了又一种基于公共通信网络的数据传输设备,应用于网络服务器,所述设备包括:处理器和存储器;
所述存储器,用于存储程序指令;
所述处理器,执行所述存储器存储的程序指令,当程序指令被执行时,所述处理器用于执行如下步骤:
建立与第一终端的第二通信连接通道;
接收所述第一终端通过所述第二通信连接通道发送的加密密钥,以使得第二终端根据从所述网络服务器获取的所述加密密钥对所述第一终端发送至所述第二终端的加密数据进行解密;
其中,当所述第一终端为控制设备、所述第二终端为移动平台时,所述加密数据包括所述控制设备对所述移动平台的控制数据;或,当所述第一终端为所述移动平台、且所述第二终端为所述控制设备时,所述加密数据包括所述移动平台采集的工作数据。
第七方面,本发明实施例提供了一种业务设备,包括:处理器和存储器;
所述存储器,用于存储程序指令;
所述处理器,执行所述存储器存储的程序指令,当程序指令被执行时,所述处理器用于执行如下步骤:
建立与第一终端之间的第一通信连接通道;
接收所述第一终端通过所述第一通信连接通道发送的加密数据,并将所述加密数据发送给第二终端;
其中,当所述第一终端为控制设备、且所述第二终端为移动平台时,所述加密数据包括所述控制设备对所述移动平台的控制数据;或,当所述第一终端为所述移动平台、且所述第二终端为所述控制设备时,所述加密数据包括所述移动平台采集的工作数据。
第八方面,本发明实施例提供了一种终端,包括:处理器和存储器;
所述存储器,用于存储程序指令;
所述处理器,执行所述存储器存储的程序指令,当程序指令被执行时,所述处理器用于执行如下步骤:
建立与业务设备之间的第一通信连接通道;
通过所述第一通信连接通道向所述业务设备发送加密数据,以使得所述业务设备将所述加密数据发送至第二终端;
其中,当第一终端为控制设备、且所述第二终端为移动平台时,所述加密数据包括所述控制设备对所述移动平台的控制数据;或,当所述第一终端为所述移动平台、且所述第二终端为所述控制设备时,所述加密数据包括所述移动平台采集的工作数据。
第九方面,本发明实施例提供了一种网络服务器,包括:处理器和存储器;
所述存储器,用于存储程序指令;
所述处理器,执行所述存储器存储的程序指令,当程序指令被执行时,所述处理器用于执行如下步骤:
建立与第一终端的第二通信连接通道;
接收所述第一终端通过所述第二通信连接通道发送的加密密钥,以使得第二终端根据从所述网络服务器获取的所述加密密钥对所述第一终端发送至所述第二终端的加密数据进行解密;
其中,当所述第一终端为控制设备、所述第二终端为移动平台时,所述加密数据包括所述控制设备对所述移动平台的控制数据;或,当所述第一终端为所述移动平台、且所述第二终端为所述控制设备时,所述加密数据包括所述移动平台采集的工作数据。
第十方面,本发明实施例提供了一种计算机可读存储介质,该计算机可读 存储介质存储有计算机程序,该计算机程序被处理器执行时实现如上述第一方面、第二方面或第三方面所述的数据传输方法。
本发明实施例中,基于公共通信网络的数据传输设备可以建立与第一终端之间的第一通信连接通道,接收第一终端通过所述第一通信连接通道发送的加密数据,并将所述加密数据发送给第二终端,以使第二终端可以对所述加密数据进行解密,得到原始数据。通过这种实施方式,实现了对公共无线通信网络中的数据传输进行加密控制,提高了公共无线通信网络中数据传输的安全性,也有利于第一终端和第二终端之间的远距离通信。
附图说明
为了更清楚地说明本发明实施例或现有技术中的技术方案,下面将对实施例中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本发明的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图获得其他的附图。
图1是本发明实施例提供的一种基于公共通信网络的数据传输方法交互的流程示意图;
图2a是本发明实施例提供的一种建立通信连接的示意图;
图2b是本发明实施例提供的另一种建立通信连接的示意图;
图3是本发明实施例提供的一种基于公共通信网络的数据传输方法的流程示意图;
图4是本发明实施例提供的另一种基于公共通信网络的数据传输方法的流程示意图;
图5是本发明实施例提供的又一种基于公共通信网络的数据传输方法的流程示意图;
图6是本发明实施例提供的一种基于公共通信网络的数据传输设备的结构示意图;
图7是本发明实施例提供的另一种基于公共通信网络的数据传输设备的结构示意图;
图8是本发明实施例提供的又一种基于公共通信网络的数据传输设备的结构示意图。
具体实施方式
下面将结合本发明实施例中的附图,对本发明实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例仅仅是本发明一部分实施例,而不是全部的实施例。基于本发明中的实施例,本领域普通技术人员在没有作出创造性劳动前提下所获得的所有其他实施例,都属于本发明保护的范围。
下面结合附图,对本发明的一些实施方式作详细说明。在不冲突的情况下,下述的实施例及实施例中的特征可以相互组合。
本发明实施例中提供的基于公共通信网络的数据传输方法可以由一种数据传输系统执行,所述数据传输系统包括业务设备、第一终端、第二终端、网络服务器。在一些实施例中,所述第一终端可以通过所述业务设备与第二终端建立第一通信连接通道,在某些实施例中,所述第一通信连接通道可以是第一终端与所述业务设备通过传输控制协议(Transmission Control Protocol,TCP)建立的TCP通道;在某些实施例中,所述第一通信连接通道可以是第一终端与所述业务设备通过用户数据报协议(User Datagram Protocol,UDP)建立的UDP通道。所述第一终端可以通过所述第一通信连接通道与业务设备进行双向通信。在一些实施例中,所述第二终端与所述业务设备也可以通过TCP建立TCP通道或通过UDP建立UDP通道,以使所述第二终端可以和所述业务设备进行双向通信连接,以进行双向通信。如此,第一终端与第二终端分别与业务设备建立通信连接,进而经由业务设备实现彼此之间的第一通信连接。
所述第一终端可以通过所述网络服务器与所述第二终端建立第二通信连接通道,在某些实施例中,所述第二通信连接通道可以是第一终端通过超文本传输安全协议(Hypertext Transfer Protocol Secure,HTTPS)建立的HTTPS通道,以实现所述第一终端与网络服务器之间的双向通信连接,或实现所述第二终端与网络服务器之间的双向通信连接。如此,第一终端与第二终端分别与网络服务器建立通信连接,进而经由网络服务器实现彼此之间的第二通信连接。在某些实施例中,公共通信网络可以包括公共无线通信网络,所述业务设备可以设置在诸如4G或5G等移动通信网络中用于数据传输的服务器(或者,业务设备即在诸如4G或5G等移动通信网络中用于数据传输的业务服务器,该业务服务器可以设于公有云或私有云中)上,当然,也并不限于上述4G或5G 等移动通信网络,只要是公用无线通信网络即可;在某些实施例中,所述第一终端可以设置在包括显示设备(如用户界面)的控制设备(如第二终端的远程遥控设备、移动终端(如手机、平板电脑等))上,所述第二终端可以设置在移动平台(如无人机、无人船、无人汽车、机器人等)上;在某些实施例中,所述第一终端可以设置在移动平台上,所述第二终端可以设置在包括显示设备的控制设备上。可以理解,对于控制设备而言,若在以下的应用场景中可以不通过显示设备进行相关操作,则控制设备也可以不包括显示设备。下面以应用于无人机的数据传输方法进行示意性说明。
本发明实施例提出的基于公共通信网络的数据传输方法可以应用于无人机领域。其中,无人机领域,一般采用无人机的私有安全链路(如私有图传遥控链路,其中,无人机往往只有一种通信链路,即WIFI或私有图传遥控链路)进行数据传输(如图像传输或遥控数据传输)较为安全。但由于私有安全链路控制的距离较近,当控制距离较远时,私有安全链路无法进行数据传输。在无人机行业应用中,可以利用无线自组网的方式实现相对较远距离的数据传输,但无线自组网的网络覆盖范围小以及在飞行中的物体、建筑物遮挡,会导致无线自组网失效。而由于无人机飞行的特殊性,需要时刻保持飞机可控,因此在行业应用中可以借助于公共无线通信网络作为通信备份链路。一般来说,4G/5G等移动通信网络运行在公网,无人机与遥控端之间的数据容易被第三方劫持,导致飞行任务容易遭到黑客攻击。因此,如何在公共无线通信网络中保护飞行安全是无人机在诸如4G/5G等移动通信网络的图传控制中非常重要的一点。本发明实施例中,通过公用无线通信网络对待传输的数据进行加密后,进行远距离的数据传输,可以确保数据传输的安全性。
在本发明实施例中,以公用无线通信网络为移动通信网络为例进行说明。其中,所述移动通信网络可以包括第四代移动通信网络(the 4th Generation mobile communication technology,4G)或第五代移动通信网络(Fifth-Generation,5G)。
在一个实施例中,在结合4G或5G等移动通信网络和无人机的私有安全链路进行数据传输时,无人机(如第一终端)可以和控制设备(如第二终端)进行近距离对频。在无人机和所述控制设备进行近距离对频之后,所述无人机可以和控制设备同步预设类型的数据组(如三元组)。在某些实施例中,所述 预设类型的数据组是所述无人机和所述控制设备在对频之后,根据通过私有安全链路进行同步处理后的同步随机数和/或验证码生成的;在某些实施例中,所述同步随机数包括所述无人机生成的随机数和/或控制设备生成的随机数。
在一个实施例中,所述无人机可以向网络服务器发送登录认证信息,所述登录认证信息携带了业务认证信息的获取请求。所述网络服务器可以对所述登录认证信息进行验证,并在验证成功之后将业务认证信息发送给所述无人机。无人机可以向业务设备发送业务认证信息,以使所述业务设备与所述无人机之间建立TCP通道或UDP通道。无人机可以根据生成的随机数计算得到数据密钥,并根据根密钥和预设类型的数据组经过加密运算得到业务密钥。无人机可以根据业务密钥对数据密钥进行加密得到加密密钥,并将加密密钥通过网络服务器同步发送给控制设备。无人机可以根据数据密钥对待传输的原始数据进行加密得到加密数据,并通过TCP通道或UDP通道将加密数据发送给业务设备,以使业务设备可以将加密数据转发给控制设备。如此,可以实现控制设备与无人机之间的数据的安全传输。而在遥控设备根据同步的加密密钥对所述加密数据进行解密,得到加密数据对应的原始数据时,由于,所述加密密钥是业务密钥对数据密钥进行加密得到的,且所述业务密钥根据根密钥和预设类型的数据组计算得到的,所述预设类型的数据组则是进一步通过私有安全链路同步至第一终端和第二终端的(所述根密钥是固定的),如此,通过私有安全链路同步预设类型的数据组可以确保业务密钥的安全性,对所述数据密钥进行二次加密,进一步提高了数据的安全性。因此,通过这种结合无人机与遥控设备的私有安全链路以及公用无线通信网络的方式,不仅实现了对公共无线通信网络中的数据传输进行加密控制,提高了公共无线通信网络中数据传输的安全性,也有利于无人机和遥控设备之间的远距离通信,尤其有利于无人机的应用。
下面结合附图对本发明实施例提供的基于公共通信网络的数据传输方法的实施例进行示意性说明。
请参见图1,图1是本发明实施例提供的一种基于公共通信网络的数据传输方法交互的流程示意图,所述交互方法可以应用于数据传输系统,其中,所述数据传输系统的具体解释如前所述。具体地,本发明实施例的所述方法包括如下步骤。
S101:第一终端向网络服务器发送登录认证信息,所述登录认证信息携带了业务认证信息的获取请求。
本发明实施例中,第一终端可以向网络服务器发送登录认证信息,所述登录认证信息携带了业务认证信息的获取请求。在一个实施例中,所述第一终端可以通过私有安全链路向网络服务器发送登录认证信息,以防止所述登录认证信息被其他设备劫持。在某些实施例中,所述第一终端可以为控制设备或移动平台。
在某些实施例中,所述业务认证信息可以为业务令牌如业务token,所述登录认证信息可以为登录认证令牌如登录token。在某些实施例中,所述登录认证信息可以通过第三终端从用户中心服务器中获取,并发送给第一终端和第二终端中的一个,并由第一终端和第二终端中的一个利用私有安全链路同步给另一个;在某些实施例中,所述第三终端可以是控制设备,或者,所述第三终端可以是与控制设备建立通信连接的设备。在某些实施例中,所述登录认证信息是通过第三终端将身份认证信息发送给用户中心服务器,以使所述用户中心服务器可以对所述身份认证信息进行验证,如果验证成功,则所述用户服务器中心向第三终端发送所述登录认证信息。在某些实施例中,所述身份认证信息可以包括账户信息和密码,所述账户信息和密码是通过第三终端的用户界面获取到的,在某些实施例中,所述第三终端为与所述用户中心服务器建立通信连接的设备。
其中,可以理解,用户中心服务器中可以存储有关于移动平台以及移动平台对应的控制设备的相关信息,从而可以实现对第三终端发送的账户信息和密码进行认证。用户中心服务器可以独立于网络服务器,也可以是网络服务器包括用户中心服务器,即网络服务器可以实现用户中心服务器的功能,也能实现给第一终端、第二终端发送业务认证信息的功能。
例如,假设所述第一终端是无人机,第二终端是控制设备,所述用户界面设置在所述控制设备上,则用户可以通过所述控制设备的用户界面输入账户信息和密码,以使所述控制设备将所述账户信息和密码发送给用户中心服务器进行验证,如果用户中心服务器验证成功,则可以向控制设备发送登录认证信息,所述控制设备可以将所述登录认证信息同步发送给作为第一终端的无人机,以使无人机可以将登录认证信息发送给网络服务器,以获取业务认证信息。
S102:网络服务器对所述登录认证信息进行验证,并在验证成功之后发送业务认证信息给所述第一终端。
本发明实施例中,网络服务器在接收到第一终端发送的登录认证信息之后,可以对所述登录认证信息进行验证,如果验证成功,则可以建立与所述第一终端的第二通信连接通道,并通过第二通信连接通道将业务认证信息发送给所述第一终端。
在一个实施例中,所述网络服务器在接收到第一终端发送的登录认证信息之后,可以对所述登录认证信息进行验证,如果验证成功,则可以允许所述第一终端登录所述网络服务器,所述网络服务器可以将所述第一终端请求获取的业务认证信息发送给所述第一终端。
S103:第一终端向业务设备发送所述业务认证信息。
本发明实施例中,第一终端可以向业务设备发送所述业务认证信息。
S104:业务设备建立与第一终端之间的第一通信连接通道。
本发明实施例中,业务设备可以根据所述业务认证信息建立与第一终端之间的第一通信连接通道。在某些实施例中,所述第一通信连接通道包括传输控制协议TCP通道或用户数据报协议UDP通道。
具体可以图2a为例进行说明,图2a是本发明实施例提供的一种建立通信连接的示意图。如图2a所示,第一终端21可以通过验证网络服务器22的设备证书来建立第二通信连接通道如HTTPS通道,并通过所述第二通信连接通道向所述网络服务器发送给登录认证信息。在某些实施例中,所述登录认证信息中携带了业务认证信息的获取请求。所述网络服务器22在接收到所述登录认证信息之后,可以对所述登录认证信息进行验证,如果验证成功,则可以响应所述业务认证信息的获取请求,将业务认证信息发送给第一终端21。第一终端21可以将所述业务认证信息发送给业务设备23,所述业务设备23可以根据所述业务认证信息建立与第一终端21之间的第一通信连接通道如TCP通道或UDP通道。在某些实施例中,所述第一终端可以为无人机或者控制设备。
同理,又以图2b为例进行说明,图2b是本发明实施例提供的另一种建立通信连接的示意图。如图2b所示,第二终端24可以通过验证网络服务器22的设备证书来建立第二通信连接通道如HTTPS通道,并通过所述第二通信连接通道向所述网络服务器发送给登录认证信息。在某些实施例中,所述登录认 证信息中携带了业务认证信息的获取请求。所述网络服务器22在接收到所述登录认证信息之后,可以对所述登录认证信息进行验证,如果验证成功,则可以响应所述业务认证信息的获取请求,将业务认证信息发送给第二终端24。第二终端24可以将所述业务认证信息发送给业务设备23,所述业务设备23可以根据所述业务认证信息建立与第二终端24之间的第一通信连接通道如TCP通道或UDP通道。在某些实施例中,所述第二终端可以为无人机或者控制设备。
如此,第一终端21、第二终端24均可以与网络服务器22建立第二通信连接通道,且均可以通过网络服务器22与业务设备23建立第一通信连接通道。
S105:第一终端根据生成的随机数计算得到数据密钥。
本发明实施例中,第一终端可以根据生成的随机数计算得到数据密钥。
S106:第一终端根据根密钥和预设类型的数据组经过加密运算得到业务密钥。
本发明实施例中,第一终端可以根据根密钥和预设类型的数据组经过加密运算得到业务密钥。
在某些实施例中,所述根密钥是所述第一终端和所述第二终端中预先设置的,所述第一终端的根密钥与所述第二终端的根密钥相同。例如,假设所述第一终端为无人机,所述第二终端为控制设备,则所述无人机和控制设备在出厂之前,需要烧录经过证书中心签发过的私钥即根密钥。
在某些实施例中,所述预设类型的数据组是所述第一终端和所述第二终端在对频之后,根据通过私有安全链路进行同步处理后的同步随机数和/或验证码生成的;在某些实施例中,所述同步随机数包括所述第一终端生成的随机数和/或所述第二终端生成的随机数。本发明实施例通过私有安全链路在第一终端和第二终端之间对同步随机数和/或验证码进行同步处理的方式,使得第一终端和第二终端拥有相同的预设类型的数据组,且第三方无法获取该预设类型的数据组,确保所述预设类型数据组的安全性。
S107:第一终端根据业务密码对所述数据密钥进行加密得到加密密钥。
本发明实施例中,第一终端可以根据业务密钥对所述数据密钥进行加密得到加密密钥。
在某些实施例中,所述业务密钥是根据根密钥和预设类型的数据组计算得 到,所述根密钥是预设不变的,所述预设类型的数据组是第一终端和所述第二终端在对频之后,根据通过私有安全链路进行同步处理后的同步随机数和/或验证码生成的,所述数据密钥是第一终端根据生成的随机数计算得到的,其中,所述随机数和同步随机数在第一终端重启时才会发生变化,因此,所述加密密钥在第一终端重启之前是不变的,所述加密密钥只需要生成一次即可。
在某些实施例中,第一终端可以采用对称加密算法、非对称加密算法或Hash算法对所述数据密钥进行加密,本发明实施例对所述数据密钥进行加密的算法不做具体限定。
S108:第一终端将所述加密密钥发送给网络服务器。
本发明实施例中,第一终端可以将所述加密密钥发送给网络服务器。在一些实施例中,所述第一终端可以通过第二通信连接通道向所述网络服务器发送加密密钥,以便第二终端可以从所述网络服务器中获取所述加密密钥。在某些实施例中,所述第二通信连接通道包括HTTPS通道。
在一个实施例中,所述第一终端还可以通过第一通信连接通道向业务设备发送加密密钥,以便所述业务设备可以通过第一通信连接通道将所述加密密钥发送给所述第二终端。
可以理解,在上述两种加密密钥的传输方式中,可以优选将加密密钥发送至网络服务器,如此,可以将加密密钥以及下述说明的加密数据从两个不同的传输路径传输至第二终端,有利于防止加密密钥和加密数据被第三方同时截取而造成的加密数据的泄露,进一步提高了第一终端和第二终端之间的数据传输的安全性。
在某些实施例中,所述第二通信连接通道是所述第一终端和所述网络服务器之间通过校验双方的设备证书建立的;在某些实施例中,所述第二通信连接通道是所述第一终端通过校验所述网络服务器的设备证书建立的。在某些实施例中,所述设备证书包括网络服务器证书和/或终端设备证书,所述网络服务器证书设置于网络服务器上,所述终端设备证书设置于所述第一终端上。例如,假设所述第一终端为无人机,所述第二终端为控制设备,则所述无人机和控制设备在出厂之前,需要烧录经过证书中心签发过的设备证书。
可以理解,数据密钥也可以不利用业务密钥进行加密,相应的,数据密钥或对数据密钥加密后的加密密钥可以不经由网络服务器或业务设备在第一终 端或第二终端进行转发,而是可以在第一终端与第二终端在近距离对频时经由私有安全链路传输。
S109:第二终端从网络服务器中获取所述加密密钥。
本发明实施例中,第二终端可以从网络服务器中获取所述加密密钥。具体的,只要第一终端具有诸如4G、5G等移动通信网络的信号,则可以主动去网络服务器请求获取加密密钥,直至获取到加密密钥为止。
S110:第一终端根据数据密钥对待传输的原始数据进行加密得到加密数据。
本发明实施例中,第一终端可以根据数据密钥对待传输的原始数据进行加密得到加密数据。在某些实施例中,第一终端可以采用对称加密算法、非对称加密算法或Hash算法对待传输的原始数据进行加密,本发明实施例对原始数据进行加密的算法不做具体限定。
在某些实施例中,当所述第一终端为控制设备、且所述第二终端为移动平台时,所述加密数据包括所述控制设备对所述移动平台的控制数据;或,当所述第一终端为所述移动平台、且所述第二终端为所述控制设备时,所述加密数据包括所述移动平台采集的工作数据。在某些实施例中,控制数据可以为诸如摇杆数据、变焦数据、飞行参数的设定数据等能控制无人机执行相应操作的数据,所述工作数据可以包括图像数据、视频数据、电量数据、位置数据,也可以包括所述移动平台采集到的其他数据,本发明实施例不做具体限定。
例如,假设所述第一终端为无人机的控制设备,所述第二终端为无人机,则所述待传输的原始数据为所述控制设备对所述无人机的控制数据如摇杆数据。又例如,假设所述第一终端为无人机,所述第二终端为无人机的控制设备,则所述待传输的原始数据为无人机采集的工作数据如图像数据。
S111:第一终端将所述加密数据发送给业务设备。
本发明实施例中,第一终端可以通过第一通信连接通道将所述加密数据发送给业务设备。例如,假设所述第一终端为无人机,所述加密数据为加密图像数据,则所述无人机可以通过TCP通道或UDP通道将所述加密图像数据发送给业务设备。
S112:业务设备将所述加密数据发送给第二终端。
本发明实施例中,业务设备可以通过第一通信连接通道将所述加密数据发 送给第二终端。例如,所述无人机可以将获取到的加密图像数据通过TCP通道或UDP通道发送给控制设备。
S113:第二终端根据所述加密密钥对所述加密数据进行解密,得到原始数据。
本发明实施例中,第二终端可以根据所述加密密钥对所述加密数据进行解密,得到原始数据。在一个实施例中,所述第二终端可以根据所述加密密钥对所述加密数据进行解密,得到数据密钥,并根据所述数据密钥对所述加密数据进行解密得到所述第一终端传输给所述第二终端的原始数据。
例如,假设第一终端为无人机,第二终端为控制设备,如果所述原始数据为图像数据,则所述控制设备可以根据加密密钥对加密图像数据进行解密,得到数据密钥,并根据所述数据密钥对所述加密图像数据进行解密,得到所述无人机传输给所述控制的图像数据。
可以理解,在图1所示实施例中的部分步骤之间可以其它时序,例如,步骤S108与步骤S111可以同步执行,也可以是步骤S111在步骤S108之前执行,具体可以根据需要进行设定,图1并不对步骤之间的时序造成限定。
本发明实施例中,第一终端可以向网络服务器发送登录认证信息,以使网络服务器对所述登录认证信息中携带的身份认证信息进行验证,并在验证成功之后,向所述第一终端发送业务认证信息。所述第一终端可以将所述业务认证信息发送给业务设备,以使业务设备建立与第一终端之间的第一通信连接通道。第一终端可以对待传输的原始数据进行加密得到加密数据,并通过所述第一通信连接通道将加密数据发送给业务设备,以使业务设备将所述加密数据发送给第二终端。如此,可以实现第一终端与第二终端的数据的安全传输。而在第二终端根据同步的加密密钥对所述加密数据进行解密,得到原始数据时,由于,所述加密密钥是业务密钥对数据密钥进行加密得到的,且所述业务密钥根据根密钥和预设类型的数据组计算得到的,所述预设类型的数据组则是进一步通过私有安全链路同步至第一终端和第二终端的(所述根密钥是固定的),如此,通过私有安全链路同步预设类型的数据组可以确保业务密钥的安全性,对所述数据密钥进行二次加密,进一步提高了数据的安全性。因此,通过这种结合第一终端与第二终端的私有安全链路以及公用无线通信网络的方式,不仅实现了对公共无线通信网络中的数据传输进行加密控制,提高了公共无线通信网 络中数据传输的安全性,也有利于第一终端和第二终端之间的远距离通信,尤其有利于无人机的应用。
请参见图3,图3是本发明实施例提供的一种基于公共通信网络的数据传输方法的流程示意图,所述方法可以由基于公共通信网络的数据传输设备执行,其中,所述数据传输设备可以设置在业务设备上。本发明实施例对应用于业务设备的数据传输方法的详细实施过程的示意性说明如下。
S301:建立与第一终端之间的第一通信连接通道。
本发明实施例中,所述数据传输设备可以建立与第一终端之间的第一通信连接通道。在某些实施例中,所述第一通信连接通道可以为TCP通道或UDP通道。
在一个实施例中,所述数据传输设备在建立与第一终端之间的第一通信连接通道时,可以接收第一终端发送的业务认证信息,并根据所述业务认证信息建立与所述第一终端之间的第一通信连接通道。在某些实施例中,所述业务认证信息是所述第一终端通过第二通信连接通道和登录认证信息从网络服务器中获取到的。在某些实施例中,所述第二通信连接通道可以包括HTTPS通道,所述HTTPS在HTTP协议的基础上加入了TLS协议,其目的是保证数据在在诸如4G或5G等移动通信网络上传输的安全性。在某些实施例中,所述登录认证信息可以为登录令牌即登录token,在某些实施例中,所述业务认证信息可以业务令牌即业务token。
在某些实施例中,所述第二通信连接通道可以是所述第一终端和所述网络服务器之间通过校验双方的设备证书建立的;在某些实施例中,所述第二通信连接通道可以是所述第一终端通过校验所述网络服务器的设备证书建立的。在某些实施例中,所述设备证书包括网络服务器证书和/或终端设备证书,所述网络服务器证书设置于网络服务器上,所述终端设备证书设置于所述第一终端上。
在某些实施例中,所述登录认证信息携带了所述业务认证信息的获取请求;其中,所述业务认证信息的获取请求用于指示所述网络服务器对所述登录认证信息进行验证,并在验证成功之后发送业务认证信息给所述第一终端。
例如,假设所述第一终端为无人机,所述第二终端为控制设备,则所述无 人机可以通过对网络服务器的设备证书进行校验,以及所述网络服务器对所述无人机的设备证书进行校验,以建立所述无人机与网络服务器之间的HTTPS通道。所述无人机可以通过所述HTTPS通道将登录认证信息发送给网络服务器,网络服务器根据所述登录认证信息对所述登录认证信息进行验证,并在验证成功之后向无人机发送业务认证信息。所述无人机可以将业务认证信息发送给业务设备,以使业务设备可以根据所述业务认证信息建立与无人机之间的TCP通道或UDP通道,以便无人机可以通过所述TCP通道或UDP通道向业务设备传输数据。
在一个实施例中,所述第一终端可以为无人机,所述第二终端可以为控制设备;或所述第一终端可以为控制设备,所述第二终端可以为无人机。所述控制设备上包括用户界面,所述用户界面上包括应用程序APP,用户可以通过所述用户界面在所AAP上输入账户信息和密码,所述控制设备可以将所述APP上获取到所述账户信息和密码发送给用户中心服务器,以使用户中心服务器对所述账户信息和密码进行验证,如果验证成功,则所述用户中心服务器向所述控制设备返回登录认证信息,所述控制设备可以通过私有安全链路将所述登录认证信息同步发送给无人机。同时,控制设备可以通过HTTPS通道将所述登录认证信息发送给网络服务器,以使所述登录认证信息进行验证。如果所述网络服务器对所述登录认证信息验证成功,则所述网络服务器可以向所述控制设备发送业务认证信息,所述控制设备可以将所述业务认证信息同步至无人机中。
可以理解,上述应用程序APP也可以设置在控制设备以外的设备上,如与控制设备通信连接的移动终端(如手机、平板电脑等),用户可以通过所述用户界面在所AAP上输入账户信息和密码,所述移动终端可以将所述APP上获取到所述账户信息和密码发送给用户中心服务器,以使用户中心服务器对所述账户信息和密码进行验证,如果验证成功,则所述用户中心服务器向所述移动终端返回登录认证信息,所述移动终端可以将登录认证信息发送给控制设备,再由控制设备通过私有安全链路同步发送给无人机。
S302:接收所述第一终端通过所述第一通信连接通道发送的加密数据,并将所述加密数据发送给第二终端。
本发明实施例中,所述数据传输设备可以接收所述第一终端通过所述第一 通信连接通道发送的加密数据,并将所述加密数据发送给第二终端。
在某些实施例中,当所述第一终端为控制设备、且所述第二终端为移动平台时,所述加密数据包括所述控制设备对所述移动平台的控制数据;或,当所述第一终端为所述移动平台、且所述第二终端为所述控制设备时,所述加密数据包括所述移动平台采集的工作数据。
在一个实施例中,所述加密数据是所述第一终端根据数据密钥对待传输的原始数据进行加密得到的;在某些实施例中,所述数据密钥是所述第一终端根据生成的随机数计算得到的。其中,当所述第一终端为控制设备、且所述第二终端为移动平台时,所述原始数据为所述控制设备对所述移动平台的控制数据;或,当所述第一终端为移动平台、且所述第二终端为控制设备时,所述原始数据为所述移动平台采集的工作数据。
在一个实施例中,所述数据传输设备还可以接收所述第一终端通过所述第一通信连接通道发送的加密密钥,并将所述加密密钥发送给所述第二终端,以使得所述第二终端根据所述加密密钥对所述加密数据进行解密。
在某些实施例中,所述加密密钥是所述第一终端对所述数据密钥进行加密得到的,具体地,所述加密密钥是所述第一终端根据业务密码对所述数据密钥进行加密得到的。在某些实施例中,所述业务密钥是所述第一终端根据根密钥和预设类型的数据组经过加密运算得到的。在某些实施例中,所述根密钥是所述第一终端和所述第二终端中预先设置的,其中,所述第一终端的根密钥与所述第二终端的根密钥相同。在某些实施例中,所述预设类型的数据组是所述第一终端和所述第二终端在对频之后,根据通过私有安全链路进行同步处理后的同步随机数和/或验证码生成的;其中,所述同步随机数包括所述第一终端生成的随机数和/或所述第二终端生成的随机数。
例如,假设所述第一终端为无人机,所述第二终端为控制设备,所述待传输的原始数据为所述无人机采集的图像数据,则第一终端可以根据生成的随机数计算得到数据密钥,并根据所述数据密钥对所述无人机采集到的图像数据进行加密,得到加密数据。所述无人机可以根据业务密码对所述数据密钥进行加密得到加密密钥,并将所述加密密钥通过网络服务器发送给控制设备。所述无人机可以通过TCP通道或UDP通道将所述加密数据发送给业务设备,以使所述业务设备将所述加密数据发送给控制设备,以便所述控制设备可以根据加密 密钥对所述加密数据进行解密,得到数据密钥,并根据所述数据密钥对所述加密数据进行解密得到图像数据。
本发明实施例中,数据传输设备可以建立与第一终端之间的第一通信连接通道,并接收所述第一终端通过所述第一通信连接通道发送的加密数据,以及将所述加密数据发送给第二终端。如此,可以实现第一终端与第二终端之间的数据的安全传输。而在第二终端根据同步的加密密钥对所述加密数据进行解密,得到原始数据时,由于,所述加密密钥是业务密钥对数据密钥进行加密得到的,且所述业务密钥根据根密钥和预设类型的数据组计算得到的,所述预设类型的数据组则是进一步通过私有安全链路同步至第一终端和第二终端的(所述根密钥是固定的),如此,通过私有安全链路同步预设类型的数据组可以确保业务密钥的安全性,对所述数据密钥进行二次加密,进一步提高了数据的安全性。因此,通过这种结合第一终端与第二终端的私有安全链路以及公用无线通信网络的方式,不仅实现了对公共无线通信网络中的数据传输进行加密控制,提高了公共无线通信网络中数据传输的安全性,也有利于第一终端和第二终端之间的远距离通信,尤其有利于无人机的应用。
请参见图4,图4是本发明实施例提供的另一种基于公共通信网络的数据传输方法的流程示意图,所述方法可以由基于公共通信网络的数据传输设备执行,其中,所述数据传输设备可以设置在第一终端上。本发明实施例对应用于第一终端的数据传输方法的详细实施过程的示意性说明如下。
S401:建立与业务设备之间的第一通信连接通道。
本发明实施例中,所述数据传输设备可以建立与业务设备之间的第一通信连接通道。其中,所述第一通信连接通道的解释如前所述,此处不再赘述。
在一个实施例中,所述数据传输设在建立与业务设备之间的第一通信连接通道时,可以向业务设备发送业务认证信息,并根据所述业务认证信息建立与所述第一终端之间的第一通信连接通道。在某些实施例中,所述业务认证信息是通过第二通信连接通道和登录认证信息从网络服务器中获取到的。在某些实施例中,所述第一通信连接通道的解释如前所述,所述第二通信连接通道的解释如前所述,所述设备证书的解释如前所述,此处不再赘述。
在某些实施例中,所述登录认证信息携带了所述业务认证信息的获取请 求;其中,所述业务认证信息的获取请求用于指示所述网络服务器对所述登录认证信息进行验证,并在验证成功之后发送业务认证信息给所述第一终端。具体实施例如前所述,此处不再赘述。
S402:通过所述第一通信连接通道向所述业务设备发送加密数据,以使得所述业务设备将所述加密数据发送至第二终端。
本发明实施例中,所述数据传输设备可以通过所述第一通信连接通道向所述业务设备发送加密数据,以使得所述业务设备将所述加密数据发送至第二终端。在某些实施例中,当所述第一终端为控制设备、且所述第二终端为移动平台时,所述加密数据包括所述控制设备对所述移动平台的控制数据;或,当所述第一终端为所述移动平台、且所述第二终端为所述控制设备时,所述加密数据包括所述移动平台采集的工作数据。其中,所述加密数据的解释如前所述,所述数据密钥的解释如前所述,此处均不再复述。
在一个实施例中,所述数据传输设备可以通过所述第二通信连接通道向所述网络服务器发送加密密钥,以使得所述第二终端根据从所述网络服务器获取的所述加密密钥对所述加密数据进行解密;或者,通过所述第一通信连接通道向所述业务设备发送加密密钥,以使得所述第二终端根据从所述业务设备获取的所述加密密钥对所述加密数据进行解密;其中,所述加密密钥是所述第一终端根据业务密码对所述数据密钥进行加密得到的。在某些实施例中,所述业务密钥是所述第一终端根据根密钥和预设类型的数据组经过加密运算得到的。其中,所述根密钥的解释如前所述,所述预设类型的数据组的解释如前所述,此处均不再复述。
例如,假设所述第一终端为控制设备,所述第二终端为无人机,所述待传输的原始数据为对所述无人机的控制数据,则控制设备可以根据生成的随机数计算得到数据密钥,并根据所述数据密钥对所述控制数据进行加密,得到加密数据。所述控制设备可以根据业务密码对所述数据密钥进行加密得到加密密钥,并将所述加密密钥通过网络服务器发送给无人机。所述控制设备可以通过TCP通道或UDP通道将所述加密数据发送给业务设备,以使所述业务设备将所述加密数据发送给无人机,以便所述无人机可以根据加密密钥对所述加密数据进行解密,得到数据密钥,并根据所述数据密钥对所述加密数据进行解密得到所述控制数据,从而使所述无人机可以根据所述控制数据对无人机进行控 制。
本发明实施例中,数据传输设备可以建立与业务设备之间的第一通信连接通道,并通过所述第一通信连接通道向所述业务设备发送加密数据,以使得所述业务设备将所述加密数据发送至第二终端。如此,可以实现第一终端与第二终端之间的数据的安全传输。而在第二终端根据同步的加密密钥对所述加密数据进行解密,得到原始数据时,由于,所述加密密钥是业务密钥对数据密钥进行加密得到的,且所述业务密钥根据根密钥和预设类型的数据组计算得到的,所述预设类型的数据组则是进一步通过私有安全链路同步至第一终端和第二终端的(所述根密钥是固定的),如此,通过私有安全链路同步预设类型的数据组可以确保业务密钥的安全性,对所述数据密钥进行二次加密,进一步提高了数据的安全性。因此,通过这种结合第一终端与第二终端的私有安全链路以及公用无线通信网络的方式,不仅实现了对公共无线通信网络中的数据传输进行加密控制,提高了公共无线通信网络中数据传输的安全性,也有利于第一终端和第二终端之间的远距离通信,尤其有利于无人机的应用。
请参见图5,图5是本发明实施例提供的又一种基于公共通信网络的数据传输方法的流程示意图,所述方法可以由基于公共通信网络的数据传输设备执行,其中,所述数据传输设备可以设置在网络服务器上。本发明实施例对应用于网络服务器的数据传输方法的详细实施过程的示意性说明如下。
S501:建立与第一终端的第二通信连接通道。
本发明实施例中,数据传输设备可以建立与第一终端的第二通信连接通道。在某些实施例中,所述第二通信连接通道是所述第一终端和所述网络服务器之间通过校验双方的设备证书建立的;或,所述第二通信连接通道是所述第一终端通过校验所述网络服务器的设备证书建立的。其中,所述设备证书的解释如前所述,此处不再赘述。在某些实施例中,所述第二通信通道包括HTTPS通道。
S502:接收所述第一终端通过所述第二通信连接通道发送的加密密钥,以使得第二终端根据从所述网络服务器获取的所述加密密钥对所述第一终端发送至所述第二终端的加密数据进行解密。
本发明实施例中,数据传输设备可以接收所述第一终端通过所述第二通信 连接通道发送的加密密钥,以使得第二终端根据从所述网络服务器获取的所述加密密钥对所述第一终端发送至所述第二终端的加密数据进行解密。
在某些实施例中,当所述第一终端为控制设备、所述第二终端为移动平台时,所述加密数据包括所述控制设备对所述移动平台的控制数据;或,当所述第一终端为所述移动平台、且所述第二终端为所述控制设备时,所述加密数据包括所述移动平台采集的工作数据。
在一个实施例中,所述加密密钥是所述第一终端对数据密钥加密得到的,所述加密数据是所述第一终端根据所述数据密钥对待传输的原始数据进行加密得到的;其中,当所述第一终端为控制设备、且所述第二终端为移动平台时,所述原始数据为所述控制设备对所述移动平台的控制数据;或,当所述第一终端为移动平台、且所述第二终端为控制设备时,所述原始数据为所述移动平台采集的工作数据。在某些实施例中,所述加密密钥是所述第一终端根据业务密码对数据密钥进行加密得到的。在某些实施例中,所述业务密钥是所述第一终端根据根密钥和预设类型的数据组经过加密运算得到的。在某些实施例中,所述数据密钥是第一终端根据生成的随机数计算得到的。其中,所述根密钥的解释和所述预设类型的数据组的解释如前所述,此处不再赘述。
在一个实施例中,所述数据传输设备在建立与第一终端的第二通信连接通道之后,还可以接收所述第一终端通过所述第二通信连接通道发送的登录认证信息,将所述登录认证信息对应的业务认证信息给所述第一终端,以使得所述第一终端根据所述业务认证信息建立与业务设备之间的第一通信连接通道。在某些实施例中,所述加密数据为所述第一终端通过所述第一通信连接通道发送至所述业务设备,并由所述业务设备发送至所述第二终端。在某些实施例中,所述第一通信连接通道包括传输控制协议TCP通道或用户数据报协议UDP通道。
在某些实施例中,所述登录认证信息携带了所述业务认证信息的获取请求;其中,所述业务认证信息的获取请求用于指示所述网络服务器对所述登录认证信息进行验证,并在验证成功之后发送业务认证信息给所述第一终端。具体实施例如前所述,此处不再赘述。
本发明实施例中,数据传输设备可以建立与第一终端的第二通信连接通道,并接收所述第一终端通过所述第二通信连接通道发送的加密密钥。如此, 可以实现第一终端与第二终端之间的数据的安全传输。而在第二终端根据同步的加密密钥对所述加密数据进行解密,得到原始数据时,由于,所述加密密钥是业务密钥对数据密钥进行加密得到的,且所述业务密钥根据根密钥和预设类型的数据组计算得到的,所述预设类型的数据组则是进一步通过私有安全链路同步至第一终端和第二终端的(所述根密钥是固定的),如此,通过私有安全链路同步预设类型的数据组可以确保业务密钥的安全性,对所述数据密钥进行二次加密,进一步提高了数据的安全性。因此,通过这种结合第一终端与第二终端的私有安全链路以及公用无线通信网络的方式,不仅实现了对公共无线通信网络中的数据传输进行加密控制,提高了公共无线通信网络中数据传输的安全性,也有利于第一终端和第二终端之间的远距离通信,尤其有利于无人机的应用。
请参见图6,图6是本发明实施例提供的一种基于公共通信网络的数据传输设备的结构示意图。具体的,所述数据传输设备包括:存储器601、处理器602以及数据接口603。
所述存储器601可以包括易失性存储器(volatile memory);存储器601也可以包括非易失性存储器(non-volatile memory);存储器601还可以包括上述种类的存储器的组合。所述处理器602可以是中央处理器(central processing unit,CPU)。所述处理器602还可以进一步包括硬件数据传输设备。上述硬件数据传输设备可以是专用集成电路(application-specific integrated circuit,ASIC),可编程逻辑器件(programmable logic device,PLD)或其组合。具体例如可以是复杂可编程逻辑器件(complex programmable logic device,CPLD),现场可编程逻辑门阵列(field-programmable gate array,FPGA)或其任意组合。
进一步地,所述存储器601用于存储程序指令,当程序指令被执行时所述处理器602可以调用存储器601中存储的程序指令,用于执行如下步骤:
建立与第一终端之间的第一通信连接通道;
接收所述第一终端通过所述第一通信连接通道发送的加密数据,并将所述加密数据发送给第二终端;
其中,当所述第一终端为控制设备、且所述第二终端为移动平台时,所述加密数据包括所述控制设备对所述移动平台的控制数据;或,当所述第一终端为所述移动平台、且所述第二终端为所述控制设备时,所述加密数据包括所述 移动平台采集的工作数据。
进一步地,所述处理器602建立与第一终端之间的第一通信连接通道时,具体用于:
接收第一终端发送的业务认证信息,所述业务认证信息是所述第一终端通过第二通信连接通道和登录认证信息从网络服务器中获取到的;
根据所述业务认证信息建立与所述第一终端之间的第一通信连接通道。
进一步地,所述第二通信连接通道是所述第一终端和所述网络服务器之间通过校验双方的设备证书建立的;或,
所述第二通信连接通道是所述第一终端通过校验所述网络服务器的设备证书建立的。
进一步地,所述设备证书包括网络服务器证书和/或终端设备证书,所述网络服务器证书设置于网络服务器上,所述终端设备证书设置于所述第一终端上。
进一步地,所述第二通信连接通道包括超文本传输安全协议HTTPS通道。
进一步地,所述登录认证信息携带了所述业务认证信息的获取请求;
其中,所述业务认证信息的获取请求用于指示所述网络服务器对所述登录认证信息进行验证,并在验证成功之后发送业务认证信息给所述第一终端。
进一步地,所述登录认证信息是第三终端通过用户中心服务器获取,并由所述第三终端发送给所述控制设备,以及由所述控制设备通过私有安全链路同步发送给所述移动平台的;
其中,所述第三终端是所述控制设备,或者,所述第三终端是与所述控制设备建立通信连接的设备;所述第三终端与所述用户中心服务器建立通信连接,所述用户中心服务器独立于所述网络服务器,或者,所述网络服务器包括所述用户中心服务器。
进一步地,所述第一通信连接通道包括传输控制协议TCP通道或用户数据报协议UDP通道。
进一步地,所述加密数据是所述第一终端根据数据密钥对待传输的原始数据进行加密得到的;
其中,当所述第一终端为控制设备、且所述第二终端为移动平台时,所述原始数据为所述控制设备对所述移动平台的控制数据;或,当所述第一终端为 移动平台、且所述第二终端为控制设备时,所述原始数据为所述移动平台采集的工作数据。
进一步地,所述数据密钥是所述第一终端根据生成的随机数计算得到的。
进一步地,所述处理器602还用于:
接收所述第一终端通过所述第一通信连接通道发送的加密密钥,并将所述加密密钥发送给所述第二终端,以使得所述第二终端根据所述加密密钥对所述加密数据进行解密;
所述加密密钥是所述第一终端对所述数据密钥进行加密得到的。
进一步地,所述加密密钥是所述第一终端根据业务密码对所述数据密钥进行加密得到的。
进一步地,所述业务密钥是所述第一终端根据根密钥和预设类型的数据组经过加密运算得到的。
进一步地,所述根密钥是所述第一终端和所述第二终端中预先设置的,所述第一终端的根密钥与所述第二终端的根密钥相同。
进一步地,所述预设类型的数据组是所述第一终端和所述第二终端在对频之后,根据通过私有安全链路进行同步处理后的同步随机数和/或验证码生成的;
所述同步随机数包括所述第一终端生成的随机数和/或所述第二终端生成的随机数。
本发明实施例中,所述数据传输设备可以建立与第一终端之间的第一通信连接通道,并接收所述第一终端通过所述第一通信连接通道发送的加密数据,以及将所述加密数据发送给第二终端。如此,可以实现第一终端与第二终端之间的数据的安全传输。而在第二终端根据同步的加密密钥对所述加密数据进行解密,得到原始数据时,由于,所述加密密钥是业务密钥对数据密钥进行加密得到的,且所述业务密钥根据根密钥和预设类型的数据组计算得到的,所述预设类型的数据组则是进一步通过私有安全链路同步至第一终端和第二终端的(所述根密钥是固定的),如此,通过私有安全链路同步预设类型的数据组可以确保业务密钥的安全性,对所述数据密钥进行二次加密,进一步提高了数据的安全性。因此,通过这种结合第一终端与第二终端的私有安全链路以及公用无线通信网络的方式,不仅实现了对公共无线通信网络中的数据传输进行加密 控制,提高了公共无线通信网络中数据传输的安全性,也有利于第一终端和第二终端之间的远距离通信,尤其有利于无人机的应用。
请参见图7,图7是本发明实施例提供的另一种基于公共通信网络的数据传输设备的结构示意图。具体的,所述数据传输设备包括:存储器701、处理器702以及数据接口703。
所述存储器701可以包括易失性存储器(volatile memory);存储器701也可以包括非易失性存储器(non-volatile memory);存储器701还可以包括上述种类的存储器的组合。所述处理器702可以是中央处理器(central processing unit,CPU)。所述处理器702还可以进一步包括硬件数据传输设备。上述硬件数据传输设备可以是专用集成电路(application-specific integrated circuit,ASIC),可编程逻辑器件(programmable logic device,PLD)或其组合。具体例如可以是复杂可编程逻辑器件(complex programmable logic device,CPLD),现场可编程逻辑门阵列(field-programmable gate array,FPGA)或其任意组合。
进一步地,所述存储器701用于存储程序指令,当程序指令被执行时所述处理器702可以调用存储器701中存储的程序指令,用于执行如下步骤:
建立与业务设备之间的第一通信连接通道;
通过所述第一通信连接通道向业务设备发送加密数据,以使得所述业务设备将所述加密数据发送至第二终端;
其中,当所述第一终端为控制设备、且所述第二终端为移动平台时,所述加密数据包括所述控制设备对所述移动平台的控制数据;或,当所述第一终端为所述移动平台、且所述第二终端为所述控制设备时,所述加密数据包括所述移动平台采集的工作数据。
进一步地,所述处理器702建立与业务设备之间的第一通信连接通道时,具体用于:
向业务设备发送业务认证信息,所述业务认证信息是通过第二通信连接通道和登录认证信息从网络服务器中获取到的;
根据所述业务认证信息建立与所述第一终端之间的第一通信连接通道。
进一步地,所述第二通信连接通道是所述第一终端和所述网络服务器之间通过校验双方的设备证书建立的;或,
所述第二通信连接通道是所述第一终端通过校验所述网络服务器的设备证书建立的。
进一步地,所述设备证书包括网络服务器证书和/或终端设备证书,所述网络服务器证书设置于网络服务器上,所述终端设备证书设置于所述第一终端上。
进一步地,所述第二通信连接通道包括HTTPS通道。
进一步地,所述登录认证信息携带了所述业务认证信息的获取请求;
其中,所述业务认证信息的获取请求用于指示所述网络服务器对所述登录认证信息进行验证,并在验证成功之后发送业务认证信息给所述第一终端。
进一步地,所述登录认证信息是第三终端通过用户中心服务器获取,并由所述第三终端发送给所述控制设备,以及由所述控制设备通过私有安全链路同步发送给所述移动平台的;
其中,所述第三终端是所述控制设备,或者,所述第三终端是与所述控制设备建立通信连接的设备;所述第三终端与所述用户中心服务器建立通信连接,所述用户中心服务器独立于所述网络服务器,或者,所述网络服务器包括所述用户中心服务器。
进一步地,所述第一通信连接通道包括传输控制协议TCP通道或用户数据报协议UDP通道。
进一步地,所述加密数据是所述第一终端根据数据密钥对待传输的原始数据进行加密得到的;
其中,当所述第一终端为控制设备、且所述第二终端为移动平台时,所述原始数据为所述控制设备对所述移动平台的控制数据;或,当所述第一终端为移动平台、且所述第二终端为控制设备时,所述原始数据为所述移动平台采集的工作数据。
进一步地,所述数据密钥是所述第一终端根据生成的随机数计算得到的。
进一步地,所述处理器702还用于:
通过所述第二通信连接通道向所述网络服务器发送加密密钥,以使得所述第二终端根据从所述网络服务器获取的所述加密密钥对所述加密数据进行解密;或者,
通过所述第一通信连接通道向所述业务设备发送加密密钥,以使得所述第 二终端根据从所述业务设备获取的所述加密密钥对所述加密数据进行解密;
其中,所述加密密钥是所述第一终端对所述数据密钥进行加密得到的。
进一步地,所述加密密钥是所述第一终端根据业务密码对所述数据密钥进行加密得到的。
进一步地,所述业务密钥是所述第一终端根据根密钥和预设类型的数据组经过加密运算得到的。
进一步地,所述根密钥是所述第一终端和所述第二终端中预先设置的,所述第一终端的根密钥与所述第二终端的根密钥相同。
进一步地,所述预设类型的数据组是所述第一终端和所述第二终端在对频之后,根据通过私有安全链路进行同步处理后的同步随机数和/或验证码生成的;
所述同步随机数包括所述第一终端生成的随机数和/或所述第二终端生成的随机数。
本发明实施例中,数据传输设备可以建立与业务设备之间的第一通信连接通道,并通过所述第一通信连接通道向所述业务设备发送加密数据,以使得所述业务设备将所述加密数据发送至第二终端。如此,可以实现第一终端与第二终端的数据的安全传输。而在第二终端根据同步的加密密钥对所述加密数据进行解密,得到原始数据时,由于,所述加密密钥是业务密钥对数据密钥进行加密得到的,且所述业务密钥根据根密钥和预设类型的数据组计算得到的,所述预设类型的数据组则是进一步通过私有安全链路同步至第一终端和第二终端的(所述根密钥是固定的),如此,通过私有安全链路同步预设类型的数据组可以确保业务密钥的安全性,对所述数据密钥进行二次加密,进一步提高了数据的安全性。因此,通过这种结合第一终端与第二终端的私有安全链路以及公用无线通信网络的方式,不仅实现了对公共无线通信网络中的数据传输进行加密控制,提高了公共无线通信网络中数据传输的安全性,也有利于第一终端和第二终端之间的远距离通信,尤其有利于无人机的应用。
请参见图8,图8是本发明实施例提供的又一种基于公共通信网络的数据传输设备的结构示意图。具体的,所述数据传输设备包括:存储器801、处理器802以及数据接口803。
所述存储器801可以包括易失性存储器(volatile memory);存储器801也可以包括非易失性存储器(non-volatile memory);存储器801还可以包括上述种类的存储器的组合。所述处理器802可以是中央处理器(central processing unit,CPU)。所述处理器802还可以进一步包括硬件数据传输设备。上述硬件数据传输设备可以是专用集成电路(application-specific integrated circuit,ASIC),可编程逻辑器件(programmable logic device,PLD)或其组合。具体例如可以是复杂可编程逻辑器件(complex programmable logic device,CPLD),现场可编程逻辑门阵列(field-programmable gate array,FPGA)或其任意组合。
进一步地,所述存储器801用于存储程序指令,当程序指令被执行时所述处理器802可以调用存储器801中存储的程序指令,用于执行如下步骤:
建立与第一终端的第二通信连接通道;
接收所述第一终端通过所述第二通信连接通道发送的加密密钥,以使得第二终端根据从所述网络服务器获取的所述加密密钥对所述第一终端发送至所述第二终端的加密数据进行解密;
其中,当所述第一终端为控制设备、所述第二终端为移动平台时,所述加密数据包括所述控制设备对所述移动平台的控制数据;或,当所述第一终端为所述移动平台、且所述第二终端为所述控制设备时,所述加密数据包括所述移动平台采集的工作数据。
进一步地,所述第二通信连接通道是所述第一终端和所述网络服务器之间通过校验双方的设备证书建立的;或,
所述第二通信连接通道是所述第一终端通过校验所述网络服务器的设备证书建立的。
进一步地,所述设备证书包括网络服务器证书和/或终端设备证书,所述网络服务器证书设置于所述网络服务器上,所述终端设备证书设置于所述第一终端上。
进一步地,所述第二通信连接通道包括HTTPS通道。
进一步地,所述加密密钥是所述第一终端对数据密钥加密得到的,所述加密数据是所述第一终端根据所述数据密钥对待传输的原始数据进行加密得到的;
其中,当所述第一终端为控制设备、且所述第二终端为移动平台时,所述 原始数据为所述控制设备对所述移动平台的控制数据;或,当所述第一终端为移动平台、且所述第二终端为控制设备时,所述原始数据为所述移动平台采集的工作数据。
进一步地,所述加密密钥是所述第一终端根据业务密码对数据密钥进行加密得到的。
进一步地,所述业务密钥是所述第一终端根据根密钥和预设类型的数据组经过加密运算得到的。
进一步地,所述根密钥是所述第一终端和所述第二终端中预先设置的,所述第一终端的根密钥与所述第二终端的根密钥相同。
进一步地,所述预设类型的数据组是所述第一终端和所述第二终端在对频之后,根据通过私有安全链路进行同步处理后的同步随机数和/或验证码生成的;
所述同步随机数包括所述第一终端生成的随机数和/或所述第二终端生成的随机数。
进一步地,所述数据密钥是所述第一终端根据生成的随机数计算得到的。
进一步地,所述处理器802建立与第一终端的第二通信连接通道之后,还用于:
接收所述第一终端通过所述第二通信连接通道发送的登录认证信息;
将所述登录认证信息对应的业务认证信息给所述第一终端,以使得所述第一终端根据所述业务认证信息建立与业务设备之间的第一通信连接通道;
所述加密数据为所述第一终端通过所述第一通信连接通道发送至所述业务设备,并由所述业务设备发送至所述第二终端。
进一步地,所述登录认证信息携带了所述业务认证信息的获取请求;
其中,所述业务认证信息的获取请求用于指示所述网络服务器对所述登录认证信息进行验证,并在验证成功之后发送业务认证信息给所述第一终端。
进一步地,所述登录认证信息是第三终端通过用户中心服务器获取,并由所述第三终端发送给所述控制设备,以及由所述控制设备通过私有安全链路同步发送给所述移动平台的;
其中,所述第三终端是所述控制设备,或者,所述第三终端是与所述控制设备建立通信连接的设备;所述第三终端与所述用户中心服务器建立通信连 接,所述用户中心服务器独立于所述网络服务器,或者,所述网络服务器包括所述用户中心服务器。
进一步地,所述第一通信连接通道包括传输控制协议TCP通道或用户数据报协议UDP通道。
本发明实施例中,数据传输设备可以建立与第一终端的第二通信连接通道,并接收所述第一终端通过所述第二通信连接通道发送的加密密钥,以使得第二终端根据从所述网络服务器获取的所述加密密钥对所述第一终端发送至所述第二终端的加密数据进行解密,得到原始数据。通过这种实施方式,实现了对网络中的数据传输进行加密控制,提高网络中数据传输的安全性。
本发明实施例中提供了一种业务设备,包括:处理器和存储器;所述存储器,用于存储程序指令;所述处理器,执行所述存储器存储的程序指令,当程序指令被执行时,所述处理器用于执行如下步骤:
建立与第一终端之间的第一通信连接通道;
接收所述第一终端通过所述第一通信连接通道发送的加密数据,并将所述加密数据发送给第二终端;
其中,当所述第一终端为控制设备、且所述第二终端为移动平台时,所述加密数据包括所述控制设备对所述移动平台的控制数据;或,当所述第一终端为所述移动平台、且所述第二终端为所述控制设备时,所述加密数据包括所述移动平台采集的工作数据。
进一步地,所述处理器建立与第一终端之间的第一通信连接通道时,具体用于:
接收第一终端发送的业务认证信息,所述业务认证信息是所述第一终端通过第二通信连接通道和登录认证信息从网络服务器中获取到的;
根据所述业务认证信息建立与所述第一终端之间的第一通信连接通道。
进一步地,所述第二通信连接通道是所述第一终端和所述网络服务器之间通过校验双方的设备证书建立的;或,
所述第二通信连接通道是所述第一终端通过校验所述网络服务器的设备证书建立的。
进一步地,所述设备证书包括网络服务器证书和/或终端设备证书,所述 网络服务器证书设置于网络服务器上,所述终端设备证书设置于所述第一终端上。
进一步地,所述第二通信连接通道包括超文本传输安全协议HTTPS通道。
进一步地,所述登录认证信息携带了所述业务认证信息的获取请求;
其中,所述业务认证信息的获取请求用于指示所述网络服务器对所述登录认证信息进行验证,并在验证成功之后发送业务认证信息给所述第一终端。
进一步地,所述登录认证信息是第三终端通过用户中心服务器获取,并由所述第三终端发送给所述控制设备,以及由所述控制设备通过私有安全链路同步发送给所述移动平台的;
其中,所述第三终端是所述控制设备,或者,所述第三终端是与所述控制设备建立通信连接的设备;所述第三终端与所述用户中心服务器建立通信连接,所述用户中心服务器独立于所述网络服务器,或者,所述网络服务器包括所述用户中心服务器。
进一步地,所述第一通信连接通道包括传输控制协议TCP通道或用户数据报协议UDP通道。
进一步地,所述加密数据是所述第一终端根据数据密钥对待传输的原始数据进行加密得到的;
其中,当所述第一终端为控制设备、且所述第二终端为移动平台时,所述原始数据为所述控制设备对所述移动平台的控制数据;或,当所述第一终端为移动平台、且所述第二终端为控制设备时,所述原始数据为所述移动平台采集的工作数据。
进一步地,所述数据密钥是所述第一终端根据生成的随机数计算得到的。
进一步地,所述处理器还用于:
接收所述第一终端通过所述第一通信连接通道发送的加密密钥,并将所述加密密钥发送给所述第二终端,以使得所述第二终端根据所述加密密钥对所述加密数据进行解密;
所述加密密钥是所述第一终端对所述数据密钥进行加密得到的。
进一步地,所述加密密钥是所述第一终端根据业务密码对所述数据密钥进行加密得到的。
进一步地,所述业务密钥是所述第一终端根据根密钥和预设类型的数据组 经过加密运算得到的。
进一步地,所述根密钥是所述第一终端和所述第二终端中预先设置的,所述第一终端的根密钥与所述第二终端的根密钥相同。
进一步地,所述预设类型的数据组是所述第一终端和所述第二终端在对频之后,根据通过私有安全链路进行同步处理后的同步随机数和/或验证码生成的;
所述同步随机数包括所述第一终端生成的随机数和/或所述第二终端生成的随机数。
本发明实施例中,业务设备可以建立与第一终端之间的第一通信连接通道,并接收所述第一终端通过所述第一通信连接通道发送的加密数据,以及将所述加密数据发送给第二终端,以使第二终端可以对所述加密数据进行解密得到原始数据。通过这种结合第一终端与第二终端的私有安全链路以及公用无线通信网络的方式,实现了对公共无线通信网络中的数据传输进行加密控制,提高了公共无线通信网络中数据传输的安全性,也有利于第一终端和第二终端之间的远距离通信,尤其是在无人机行业应用中
本发明实施例中提供了一种终端,包括:处理器和存储器;所述存储器,用于存储程序指令;所述处理器,执行所述存储器存储的程序指令,当程序指令被执行时,所述处理器用于执行如下步骤:
建立与业务设备之间的第一通信连接通道;
通过所述第一通信连接通道向所述业务设备发送加密数据,以使得所述业务设备将所述加密数据发送至第二终端;
其中,当第一终端为控制设备、且所述第二终端为移动平台时,所述加密数据包括所述控制设备对所述移动平台的控制数据;或,当所述第一终端为所述移动平台、且所述第二终端为所述控制设备时,所述加密数据包括所述移动平台采集的工作数据。
进一步地,所述处理器建立与业务设备之间的第一通信连接通道时,具体用于:
向业务设备发送业务认证信息,所述业务认证信息是通过第二通信连接通道和登录认证信息从网络服务器中获取到的;
根据所述业务认证信息建立与所述第一终端之间的第一通信连接通道。
进一步地,所述第二通信连接通道是所述第一终端和所述网络服务器之间通过校验双方的设备证书建立的;或,
所述第二通信连接通道是所述第一终端通过校验所述网络服务器的设备证书建立的。
进一步地,所述设备证书包括网络服务器证书和/或终端设备证书,所述网络服务器证书设置于网络服务器上,所述终端设备证书设置于所述第一终端上。
进一步地,所述第二通信连接通道包括HTTPS通道。
进一步地,所述登录认证信息携带了所述业务认证信息的获取请求;
其中,所述业务认证信息的获取请求用于指示所述网络服务器对所述登录认证信息进行验证,并在验证成功之后发送业务认证信息给所述第一终端。
进一步地,所述登录认证信息是第三终端通过用户中心服务器获取,并由所述第三终端发送给所述控制设备,以及由所述控制设备通过私有安全链路同步发送给所述移动平台的;
其中,所述第三终端是所述控制设备,或者,所述第三终端是与所述控制设备建立通信连接的设备;所述第三终端与所述用户中心服务器建立通信连接,所述用户中心服务器独立于所述网络服务器,或者,所述网络服务器包括所述用户中心服务器。
进一步地,所述第一通信连接通道包括传输控制协议TCP通道或用户数据报协议UDP通道。
进一步地,所述加密数据是所述第一终端根据数据密钥对待传输的原始数据进行加密得到的;
其中,当所述第一终端为控制设备、且所述第二终端为移动平台时,所述原始数据为所述控制设备对所述移动平台的控制数据;或,当所述第一终端为移动平台、且所述第二终端为控制设备时,所述原始数据为所述移动平台采集的工作数据。
进一步地,所述数据密钥是所述第一终端根据生成的随机数计算得到的。
进一步地,所述处理器还用于:
通过所述第二通信连接通道向所述网络服务器发送加密密钥,以使得所述第二终端根据从所述网络服务器获取的所述加密密钥对所述加密数据进行解 密;或者,
通过所述第一通信连接通道向所述业务设备发送加密密钥,以使得所述第二终端根据从所述业务设备获取的所述加密密钥对所述加密数据进行解密;
其中,所述加密密钥是所述第一终端对所述数据密钥进行加密得到的。
进一步地,所述加密密钥是所述第一终端根据业务密码对所述数据密钥进行加密得到的。
进一步地,所述业务密钥是所述第一终端根据根密钥和预设类型的数据组经过加密运算得到的。
进一步地,所述根密钥是所述第一终端和所述第二终端中预先设置的,所述第一终端的根密钥与所述第二终端的根密钥相同。
进一步地,所述预设类型的数据组是所述第一终端和所述第二终端在对频之后,根据通过私有安全链路进行同步处理后的同步随机数和/或验证码生成的;
所述同步随机数包括所述第一终端生成的随机数和/或所述第二终端生成的随机数。
本发明实施例中,第一终端可以建立与业务设备之间的第一通信连接通道,并通过所述第一通信连接通道向所述业务设备发送加密数据,以使得所述业务设备将所述加密数据发送至第二终端,从而使第二终端可以根据同步的加密密钥对所述加密数据进行解密,得到原始数据。通过这种结合第一终端与第二终端的私有安全链路以及公用无线通信网络的方式,实现了对公共无线通信网络中的数据传输进行加密控制,提高了公共无线通信网络中数据传输的安全性,也有利于第一终端和第二终端之间的远距离通信,尤其是在无人机行业应用中。
本发明实施例中提供了一种网络服务器,包括:处理器和存储器;所述存储器,用于存储程序指令;所述处理器,执行所述存储器存储的程序指令,当程序指令被执行时,所述处理器用于执行如下步骤:
建立与第一终端的第二通信连接通道;
接收所述第一终端通过所述第二通信连接通道发送的加密密钥,以使得第二终端根据从所述网络服务器获取的所述加密密钥对所述第一终端发送至所 述第二终端的加密数据进行解密;
其中,当所述第一终端为控制设备、所述第二终端为移动平台时,所述加密数据包括所述控制设备对所述移动平台的控制数据;或,当所述第一终端为所述移动平台、且所述第二终端为所述控制设备时,所述加密数据包括所述移动平台采集的工作数据。
进一步地,所述第二通信连接通道是所述第一终端和所述网络服务器之间通过校验双方的设备证书建立的;或,
所述第二通信连接通道是所述第一终端通过校验所述网络服务器的设备证书建立的。
进一步地,所述设备证书包括网络服务器证书和/或终端设备证书,所述网络服务器证书设置于所述网络服务器上,所述终端设备证书设置于所述第一终端上
进一步地,所述第二通信连接通道包括HTTPS通道。
进一步地,所述加密密钥是所述第一终端对数据密钥加密得到的,所述加密数据是所述第一终端根据所述数据密钥对待传输的原始数据进行加密得到的;
其中,当所述第一终端为控制设备、且所述第二终端为移动平台时,所述原始数据为所述控制设备对所述移动平台的控制数据;或,当所述第一终端为移动平台、且所述第二终端为控制设备时,所述原始数据为所述移动平台采集的工作数据。
进一步地,所述加密密钥是所述第一终端根据业务密码对数据密钥进行加密得到的。
进一步地,所述业务密钥是所述第一终端根据根密钥和预设类型的数据组经过加密运算得到的。
进一步地,所述根密钥是所述第一终端和所述第二终端中预先设置的,所述第一终端的根密钥与所述第二终端的根密钥相同。
进一步地,所述预设类型的数据组是所述第一终端和所述第二终端在对频之后,根据通过私有安全链路进行同步处理后的同步随机数和/或验证码生成的;
所述同步随机数包括所述第一终端生成的随机数和/或所述第二终端生成 的随机数。
进一步地,所述数据密钥是所述第一终端根据生成的随机数计算得到的。
进一步地,所述处理器建立与第一终端的第二通信连接通道之后,还用于:
接收所述第一终端通过所述第二通信连接通道发送的登录认证信息;
将所述登录认证信息对应的业务认证信息给所述第一终端,以使得所述第一终端根据所述业务认证信息建立与业务设备之间的第一通信连接通道;
所述加密数据为所述第一终端通过所述第一通信连接通道发送至所述业务设备,并由所述业务设备发送至所述第二终端。
进一步地,所述登录认证信息携带了所述业务认证信息的获取请求;
其中,所述业务认证信息的获取请求用于指示所述网络服务器对所述登录认证信息进行验证,并在验证成功之后发送业务认证信息给所述第一终端。
进一步地,所述登录认证信息是第三终端通过用户中心服务器获取,并由所述第三终端发送给所述控制设备,以及由所述控制设备通过私有安全链路同步发送给所述移动平台的;
其中,所述第三终端是所述控制设备,或者,所述第三终端是与所述控制设备建立通信连接的设备;所述第三终端与所述用户中心服务器建立通信连接,所述用户中心服务器独立于所述网络服务器,或者,所述网络服务器包括所述用户中心服务器。
进一步地,所述第一通信连接通道包括传输控制协议TCP通道或用户数据报协议UDP通道。
本发明实施例中,网络服务器可以建立与第一终端的第二通信连接通道,并接收所述第一终端通过所述第二通信连接通道发送的加密密钥,以使得第二终端根据从所述网络服务器获取的所述加密密钥对所述第一终端发送至所述第二终端的加密数据进行解密,得到原始数据。通过这种结合第一终端与第二终端的私有安全链路以及公用无线通信网络的方式,实现了对公共无线通信网络中的数据传输进行加密控制,提高了公共无线通信网络中数据传输的安全性,也有利于第一终端和第二终端之间的远距离通信,尤其是在无人机行业应用中。
在本发明的实施例中还提供了一种计算机可读存储介质,所述计算机可读存储介质存储有计算机程序,所述计算机程序被处理器执行时实现本发明实施 例中描述的数据传输方法方式,在此不再赘述。
所述计算机可读存储介质可以是前述任一项实施例所述的设备的内部存储单元,例如设备的硬盘或内存。所述计算机可读存储介质也可以是所述设备的外部存储设备,例如所述设备上配备的插接式硬盘,智能存储卡(Smart Media Card,SMC),安全数字(Secure Digital,SD)卡,闪存卡(Flash Card)等。进一步地,所述计算机可读存储介质还可以既包括所述设备的内部存储单元也包括外部存储设备。所述计算机可读存储介质用于存储所述计算机程序以及所述设备所需的其他程序和数据。所述计算机可读存储介质还可以用于暂时地存储已经输出或者将要输出的数据。
本领域普通技术人员可以理解实现上述实施例方法中的全部或部分流程,是可以通过计算机程序来指令相关的硬件来完成,所述的程序可存储于一计算机可读取存储介质中,该程序在执行时,可包括如上述各方法的实施例的流程。其中,所述的存储介质可为磁碟、光盘、只读存储记忆体(Read-Only Memory,ROM)或随机存储记忆体(Random Access Memory,RAM)等。
以上所揭露的仅为本发明部分实施例而已,当然不能以此来限定本发明之权利范围,因此依本发明权利要求所作的等同变化,仍属本发明所涵盖的范围。

Claims (133)

  1. 一种基于公共通信网络的数据传输方法,其特征在于,应用于业务设备,所述方法包括:
    建立与第一终端之间的第一通信连接通道;
    接收所述第一终端通过所述第一通信连接通道发送的加密数据,并将所述加密数据发送给第二终端;
    其中,当所述第一终端为控制设备、且所述第二终端为移动平台时,所述加密数据包括所述控制设备对所述移动平台的控制数据;或,当所述第一终端为所述移动平台、且所述第二终端为所述控制设备时,所述加密数据包括所述移动平台采集的工作数据。
  2. 根据权利要求1所述的方法,其特征在于,所述建立与第一终端之间的第一通信连接通道,包括:
    接收第一终端发送的业务认证信息,所述业务认证信息是所述第一终端通过第二通信连接通道和登录认证信息从网络服务器中获取到的;
    根据所述业务认证信息建立与所述第一终端之间的第一通信连接通道。
  3. 根据权利要求2所述的方法,其特征在于,
    所述第二通信连接通道是所述第一终端和所述网络服务器之间通过校验双方的设备证书建立的;或,
    所述第二通信连接通道是所述第一终端通过校验所述网络服务器的设备证书建立的。
  4. 根据权利要求3所述的方法,其特征在于,所述设备证书包括网络服务器证书和/或终端设备证书,所述网络服务器证书设置于网络服务器上,所述终端设备证书设置于所述第一终端上。
  5. 根据权利要求2所述的方法,其特征在于,所述第二通信连接通道包括超文本传输安全协议HTTPS通道。
  6. 根据权利要求2所述的方法,其特征在于,
    所述登录认证信息携带了所述业务认证信息的获取请求;
    其中,所述业务认证信息的获取请求用于指示所述网络服务器对所述登录认证信息进行验证,并在验证成功之后发送所述业务认证信息给所述第一终端。
  7. 根据权利要求6所述的方法,其特征在于,
    所述登录认证信息是第三终端通过用户中心服务器获取,并由所述第三终端发送给所述控制设备,以及由所述控制设备通过私有安全链路同步发送给所述移动平台的;
    其中,所述第三终端是所述控制设备,或者,所述第三终端是与所述控制设备建立通信连接的设备;所述第三终端与所述用户中心服务器建立通信连接,所述用户中心服务器独立于所述网络服务器,或者,所述网络服务器包括所述用户中心服务器。
  8. 根据权利要求1所述的方法,其特征在于,所述第一通信连接通道包括传输控制协议TCP通道或用户数据报协议UDP通道。
  9. 根据权利要求1所述的方法,其特征在于,
    所述加密数据是所述第一终端根据数据密钥对待传输的原始数据进行加密得到的;
    其中,当所述第一终端为控制设备、且所述第二终端为移动平台时,所述原始数据为所述控制设备对所述移动平台的控制数据;或,当所述第一终端为移动平台、且所述第二终端为控制设备时,所述原始数据为所述移动平台采集的工作数据。
  10. 根据权利要求9所述的方法,其特征在于,所述数据密钥是所述第一终端根据生成的随机数计算得到的。
  11. 根据权利要求9所述的方法,其特征在于,所述方法还包括:
    接收所述第一终端通过所述第一通信连接通道发送的加密密钥,并将所述加密密钥发送给所述第二终端,以使得所述第二终端根据所述加密密钥对所述加密数据进行解密;
    所述加密密钥是所述第一终端对所述数据密钥进行加密得到的。
  12. 根据权利要求11所述的方法,其特征在于,
    所述加密密钥是所述第一终端根据业务密码对所述数据密钥进行加密得到的。
  13. 根据权利要求12所述的方法,其特征在于,
    所述业务密钥是所述第一终端根据根密钥和预设类型的数据组经过加密运算得到的。
  14. 根据权利要求13所述的方法,其特征在于,
    所述根密钥是所述第一终端和所述第二终端中预先设置的,所述第一终端的根密钥与所述第二终端的根密钥相同。
  15. 根据权利要求13所述的方法,其特征在于,
    所述预设类型的数据组是所述第一终端和所述第二终端在对频之后,根据通过私有安全链路进行同步处理后的同步随机数和/或验证码生成的;
    所述同步随机数包括所述第一终端生成的随机数和/或所述第二终端生成的随机数。
  16. 一种基于公共通信网络的数据传输方法,其特征在于,应用于第一终端,所述方法包括:
    建立与业务设备之间的第一通信连接通道;
    通过所述第一通信连接通道向所述业务设备发送加密数据,以使得所述业务设备将所述加密数据发送至第二终端;
    其中,当所述第一终端为控制设备、且所述第二终端为移动平台时,所述 加密数据包括所述控制设备对所述移动平台的控制数据;或,当所述第一终端为所述移动平台、且所述第二终端为所述控制设备时,所述加密数据包括所述移动平台采集的工作数据。
  17. 根据权利要求16所述的方法,其特征在于,所述建立与业务设备之间的第一通信连接通道,包括:
    向业务设备发送业务认证信息,所述业务认证信息是通过第二通信连接通道和登录认证信息从网络服务器中获取到的;
    根据所述业务认证信息建立与所述第一终端之间的第一通信连接通道。
  18. 根据权利要求17所述的方法,其特征在于,
    所述第二通信连接通道是所述第一终端和所述网络服务器之间通过校验双方的设备证书建立的;或,
    所述第二通信连接通道是所述第一终端通过校验所述网络服务器的设备证书建立的。
  19. 根据权利要求18所述的方法,其特征在于,所述设备证书包括网络服务器证书和/或终端设备证书,所述网络服务器证书设置于网络服务器上,所述终端设备证书设置于所述第一终端上。
  20. 根据权利要求17所述的方法,其特征在于,所述第二通信连接通道包括HTTPS通道。
  21. 根据权利要求17所述的方法,其特征在于,
    所述登录认证信息携带了所述业务认证信息的获取请求;
    其中,所述业务认证信息的获取请求用于指示所述网络服务器对所述登录认证信息进行验证,并在验证成功之后发送所述业务认证信息给所述第一终端。
  22. 根据权利要求21所述的方法,其特征在于,
    所述登录认证信息是第三终端通过用户中心服务器获取,并由所述第三终端发送给所述控制设备,以及由所述控制设备通过私有安全链路同步发送给所述移动平台的;
    其中,所述第三终端是所述控制设备,或者,所述第三终端是与所述控制设备建立通信连接的设备;所述第三终端与所述用户中心服务器建立通信连接,所述用户中心服务器独立于所述网络服务器,或者,所述网络服务器包括所述用户中心服务器。
  23. 根据权利要求16所述的方法,其特征在于,所述第一通信连接通道包括传输控制协议TCP通道或用户数据报协议UDP通道。
  24. 根据权利要求16所述的方法,其特征在于,
    所述加密数据是所述第一终端根据数据密钥对待传输的原始数据进行加密得到的;
    其中,当所述第一终端为控制设备、且所述第二终端为移动平台时,所述原始数据为所述控制设备对所述移动平台的控制数据;或,当所述第一终端为移动平台、且所述第二终端为控制设备时,所述原始数据为所述移动平台采集的工作数据。
  25. 根据权利要求24所述的方法,其特征在于,所述数据密钥是所述第一终端根据生成的随机数计算得到的。
  26. 根据权利要求17所述的方法,其特征在于,所述方法还包括:
    通过所述第二通信连接通道向所述网络服务器发送加密密钥,以使得所述第二终端根据从所述网络服务器获取的所述加密密钥对所述加密数据进行解密;或者,
    通过所述第一通信连接通道向所述业务设备发送加密密钥,以使得所述第二终端根据从所述业务设备获取的所述加密密钥对所述加密数据进行解密;
    其中,所述加密密钥是所述第一终端对所述数据密钥进行加密得到的。
  27. 根据权利要求26所述的方法,其特征在于,
    所述加密密钥是所述第一终端根据业务密码对所述数据密钥进行加密得到的。
  28. 根据权利要求27所述的方法,其特征在于,
    所述业务密钥是所述第一终端根据根密钥和预设类型的数据组经过加密运算得到的。
  29. 根据权利要求28所述的方法,其特征在于,
    所述根密钥是所述第一终端和所述第二终端中预先设置的,所述第一终端的根密钥与所述第二终端的根密钥相同。
  30. 根据权利要求28所述的方法,其特征在于,
    所述预设类型的数据组是所述第一终端和所述第二终端在对频之后,根据通过私有安全链路进行同步处理后的同步随机数和/或验证码生成的;
    所述同步随机数包括所述第一终端生成的随机数和/或所述第二终端生成的随机数。
  31. 一种基于公共通信网络的数据传输方法,其特征在于,应用于网络服务器,所述方法包括:
    建立与第一终端的第二通信连接通道;
    接收所述第一终端通过所述第二通信连接通道发送的加密密钥,以使得第二终端根据从所述网络服务器获取的所述加密密钥对所述第一终端发送至所述第二终端的加密数据进行解密;
    其中,当所述第一终端为控制设备、所述第二终端为移动平台时,所述加密数据包括所述控制设备对所述移动平台的控制数据;或,当所述第一终端为所述移动平台、且所述第二终端为所述控制设备时,所述加密数据包括所述移动平台采集的工作数据。
  32. 根据权利要求31所述的方法,其特征在于,
    所述第二通信连接通道是所述第一终端和所述网络服务器之间通过校验双方的设备证书建立的;或,
    所述第二通信连接通道是所述第一终端通过校验所述网络服务器的设备证书建立的。
  33. 根据权利要求32所述的方法,其特征在于,所述设备证书包括网络服务器证书和/或终端设备证书,所述网络服务器证书设置于所述网络服务器上,所述终端设备证书设置于所述第一终端上。
  34. 根据权利要求32所述的方法,其特征在于,所述第二通信连接通道包括HTTPS通道。
  35. 根据权利要求31所述的方法,其特征在于,
    所述加密密钥是所述第一终端对数据密钥加密得到的,所述加密数据是所述第一终端根据所述数据密钥对待传输的原始数据进行加密得到的;
    其中,当所述第一终端为控制设备、且所述第二终端为移动平台时,所述原始数据为所述控制设备对所述移动平台的控制数据;或,当所述第一终端为移动平台、且所述第二终端为控制设备时,所述原始数据为所述移动平台采集的工作数据。
  36. 根据权利要求35所述的方法,其特征在于,
    所述加密密钥是所述第一终端根据业务密码对数据密钥进行加密得到的。
  37. 根据权利要求36所述的方法,其特征在于,
    所述业务密钥是所述第一终端根据根密钥和预设类型的数据组经过加密运算得到的。
  38. 根据权利要求37所述的方法,其特征在于,
    所述根密钥是所述第一终端和所述第二终端中预先设置的,所述第一终端的根密钥与所述第二终端的根密钥相同。
  39. 根据权利要求37所述的方法,其特征在于,
    所述预设类型的数据组是所述第一终端和所述第二终端在对频之后,根据通过私有安全链路进行同步处理后的同步随机数和/或验证码生成的;
    所述同步随机数包括所述第一终端生成的随机数和/或所述第二终端生成的随机数。
  40. 根据权利要求35所述的方法,其特征在于,所述数据密钥是所述第一终端根据生成的随机数计算得到的。
  41. 根据权利要求31所述的方法,其特征在于,所述建立与第一终端的第二通信连接通道之后,还包括:
    接收所述第一终端通过所述第二通信连接通道发送的登录认证信息;
    将所述登录认证信息对应的业务认证信息给所述第一终端,以使得所述第一终端根据所述业务认证信息建立与业务设备之间的第一通信连接通道;
    所述加密数据为所述第一终端通过所述第一通信连接通道发送至所述业务设备,并由所述业务设备发送至所述第二终端。
  42. 根据权利要求41所述的方法,其特征在于,
    所述登录认证信息携带了所述业务认证信息的获取请求;
    其中,所述业务认证信息的获取请求用于指示所述网络服务器对所述登录认证信息进行验证,并在验证成功之后发送所述业务认证信息给所述第一终端。
  43. 根据权利要求42所述的方法,其特征在于,
    所述登录认证信息是第三终端通过用户中心服务器获取,并由所述第三终端发送给所述控制设备,以及由所述控制设备通过私有安全链路同步发送给所述移动平台的;
    其中,所述第三终端是所述控制设备,或者,所述第三终端是与所述控制设备建立通信连接的设备;所述第三终端与所述用户中心服务器建立通信连 接,所述用户中心服务器独立于所述网络服务器,或者,所述网络服务器包括所述用户中心服务器。
  44. 根据权利要求41所述的方法,其特征在于,所述第一通信连接通道包括传输控制协议TCP通道或用户数据报协议UDP通道。
  45. 一种基于公共通信网络的数据传输设备,其特征在于,应用于业务设备,所述设备包括:处理器和存储器;
    所述存储器,用于存储程序指令;
    所述处理器,执行所述存储器存储的程序指令,当程序指令被执行时,所述处理器用于执行如下步骤:
    建立与第一终端之间的第一通信连接通道;
    接收所述第一终端通过所述第一通信连接通道发送的加密数据,并将所述加密数据发送给第二终端;
    其中,当所述第一终端为控制设备、且所述第二终端为移动平台时,所述加密数据包括所述控制设备对所述移动平台的控制数据;或,当所述第一终端为所述移动平台、且所述第二终端为所述控制设备时,所述加密数据包括所述移动平台采集的工作数据。
  46. 根据权利要求45所述的设备,其特征在于,所述处理器建立与第一终端之间的第一通信连接通道时,具体用于:
    接收第一终端发送的业务认证信息,所述业务认证信息是所述第一终端通过第二通信连接通道和登录认证信息从网络服务器中获取到的;
    根据所述业务认证信息建立与所述第一终端之间的第一通信连接通道。
  47. 根据权利要求46所述的设备,其特征在于,
    所述第二通信连接通道是所述第一终端和所述网络服务器之间通过校验双方的设备证书建立的;或,
    所述第二通信连接通道是所述第一终端通过校验所述网络服务器的设备证书建立的。
  48. 根据权利要求47所述的设备,其特征在于,所述设备证书包括网络服务器证书和/或终端设备证书,所述网络服务器证书设置于网络服务器上,所述终端设备证书设置于所述第一终端上。
  49. 根据权利要求46所述的设备,其特征在于,所述第二通信连接通道包括超文本传输安全协议HTTPS通道。
  50. 根据权利要求46所述的设备,其特征在于,
    所述登录认证信息携带了所述业务认证信息的获取请求;
    其中,所述业务认证信息的获取请求用于指示所述网络服务器对所述登录认证信息进行验证,并在验证成功之后发送所述业务认证信息给所述第一终端。
  51. 根据权利要求50所述的设备,其特征在于,
    所述登录认证信息是第三终端通过用户中心服务器获取,并由所述第三终端发送给所述控制设备,以及由所述控制设备通过私有安全链路同步发送给所述移动平台的;
    其中,所述第三终端是所述控制设备,或者,所述第三终端是与所述控制设备建立通信连接的设备;所述第三终端与所述用户中心服务器建立通信连接,所述用户中心服务器独立于所述网络服务器,或者,所述网络服务器包括所述用户中心服务器。
  52. 根据权利要求45所述的设备,其特征在于,所述第一通信连接通道包括传输控制协议TCP通道或用户数据报协议UDP通道。
  53. 根据权利要求45所述的设备,其特征在于,
    所述加密数据是所述第一终端根据数据密钥对待传输的原始数据进行加密得到的;
    其中,当所述第一终端为控制设备、且所述第二终端为移动平台时,所述 原始数据为所述控制设备对所述移动平台的控制数据;或,当所述第一终端为移动平台、且所述第二终端为控制设备时,所述原始数据为所述移动平台采集的工作数据。
  54. 根据权利要求53所述的设备,其特征在于,所述数据密钥是所述第一终端根据生成的随机数计算得到的。
  55. 根据权利要求53所述的设备,其特征在于,所述处理器还用于:
    接收所述第一终端通过所述第一通信连接通道发送的加密密钥,并将所述加密密钥发送给所述第二终端,以使得所述第二终端根据所述加密密钥对所述加密数据进行解密;
    所述加密密钥是所述第一终端对所述数据密钥进行加密得到的。
  56. 根据权利要求55所述的设备,其特征在于,
    所述加密密钥是所述第一终端根据业务密码对所述数据密钥进行加密得到的。
  57. 根据权利要求56所述的设备,其特征在于,
    所述业务密钥是所述第一终端根据根密钥和预设类型的数据组经过加密运算得到的。
  58. 根据权利要求57所述的设备,其特征在于,
    所述根密钥是所述第一终端和所述第二终端中预先设置的,所述第一终端的根密钥与所述第二终端的根密钥相同。
  59. 根据权利要求57所述的设备,其特征在于,
    所述预设类型的数据组是所述第一终端和所述第二终端在对频之后,根据通过私有安全链路进行同步处理后的同步随机数和/或验证码生成的;
    所述同步随机数包括所述第一终端生成的随机数和/或所述第二终端生成的随机数。
  60. 一种基于公共通信网络的数据传输设备,其特征在于,应用于第一终端,所述设备包括:处理器和存储器;
    所述存储器,用于存储程序指令;
    所述处理器,执行所述存储器存储的程序指令,当程序指令被执行时,所述处理器用于执行如下步骤:
    建立与业务设备之间的第一通信连接通道;
    通过所述第一通信连接通道向业务设备发送加密数据,以使得所述业务设备将所述加密数据发送至第二终端;
    其中,当所述第一终端为控制设备、且所述第二终端为移动平台时,所述加密数据包括所述控制设备对所述移动平台的控制数据;或,当所述第一终端为所述移动平台、且所述第二终端为所述控制设备时,所述加密数据包括所述移动平台采集的工作数据。
  61. 根据权利要求60所述的设备,其特征在于,所述处理器建立与业务设备之间的第一通信连接通道时,具体用于:
    向业务设备发送业务认证信息,所述业务认证信息是通过第二通信连接通道和登录认证信息从网络服务器中获取到的;
    根据所述业务认证信息建立与所述第一终端之间的第一通信连接通道。
  62. 根据权利要求61所述的设备,其特征在于,
    所述第二通信连接通道是所述第一终端和所述网络服务器之间通过校验双方的设备证书建立的;或,
    所述第二通信连接通道是所述第一终端通过校验所述网络服务器的设备证书建立的。
  63. 根据权利要求62所述的设备,其特征在于,所述设备证书包括网络服务器证书和/或终端设备证书,所述网络服务器证书设置于网络服务器上,所述终端设备证书设置于所述第一终端上。
  64. 根据权利要求61所述的设备,其特征在于,所述第二通信连接通道包括HTTPS通道。
  65. 根据权利要求61所述的设备,其特征在于,
    所述登录认证信息携带了所述业务认证信息的获取请求;
    其中,所述业务认证信息的获取请求用于指示所述网络服务器对所述登录认证信息进行验证,并在验证成功之后发送所述业务认证信息给所述第一终端。
  66. 根据权利要求65所述的设备,其特征在于,
    所述登录认证信息是第三终端通过用户中心服务器获取,并由所述第三终端发送给所述控制设备,以及由所述控制设备通过私有安全链路同步发送给所述移动平台的;
    其中,所述第三终端是所述控制设备,或者,所述第三终端是与所述控制设备建立通信连接的设备;所述第三终端与所述用户中心服务器建立通信连接,所述用户中心服务器独立于所述网络服务器,或者,所述网络服务器包括所述用户中心服务器。
  67. 根据权利要求60所述的设备,其特征在于,所述第一通信连接通道包括传输控制协议TCP通道或用户数据报协议UDP通道。
  68. 根据权利要求60所述的设备,其特征在于,
    所述加密数据是所述第一终端根据数据密钥对待传输的原始数据进行加密得到的;
    其中,当所述第一终端为控制设备、且所述第二终端为移动平台时,所述原始数据为所述控制设备对所述移动平台的控制数据;或,当所述第一终端为移动平台、且所述第二终端为控制设备时,所述原始数据为所述移动平台采集的工作数据。
  69. 根据权利要求68所述的设备,其特征在于,所述数据密钥是所述第 一终端根据生成的随机数计算得到的。
  70. 根据权利要求61所述的设备,其特征在于,所述处理器还用于:
    通过所述第二通信连接通道向所述网络服务器发送加密密钥,以使得所述第二终端根据从所述网络服务器获取的所述加密密钥对所述加密数据进行解密;或者,
    通过所述第一通信连接通道向所述业务设备发送加密密钥,以使得所述第二终端根据从所述业务设备获取的所述加密密钥对所述加密数据进行解密;
    其中,所述加密密钥是所述第一终端对所述数据密钥进行加密得到的。
  71. 根据权利要求70所述的设备,其特征在于,
    所述加密密钥是所述第一终端根据业务密码对所述数据密钥进行加密得到的。
  72. 根据权利要求71所述的设备,其特征在于,
    所述业务密钥是所述第一终端根据根密钥和预设类型的数据组经过加密运算得到的。
  73. 根据权利要求72所述的设备,其特征在于,
    所述根密钥是所述第一终端和所述第二终端中预先设置的,所述第一终端的根密钥与所述第二终端的根密钥相同。
  74. 根据权利要求72所述的设备,其特征在于,
    所述预设类型的数据组是所述第一终端和所述第二终端在对频之后,根据通过私有安全链路进行同步处理后的同步随机数和/或验证码生成的;
    所述同步随机数包括所述第一终端生成的随机数和/或所述第二终端生成的随机数。
  75. 一种基于公共通信网络的数据传输设备,其特征在于,应用于网络服务器,所述设备包括:处理器和存储器;
    所述存储器,用于存储程序指令;
    所述处理器,执行所述存储器存储的程序指令,当程序指令被执行时,所述处理器用于执行如下步骤:
    建立与第一终端的第二通信连接通道;
    接收所述第一终端通过所述第二通信连接通道发送的加密密钥,以使得第二终端根据从所述网络服务器获取的所述加密密钥对所述第一终端发送至所述第二终端的加密数据进行解密;
    其中,当所述第一终端为控制设备、所述第二终端为移动平台时,所述加密数据包括所述控制设备对所述移动平台的控制数据;或,当所述第一终端为所述移动平台、且所述第二终端为所述控制设备时,所述加密数据包括所述移动平台采集的工作数据。
  76. 根据权利要求75所述的设备,其特征在于,
    所述第二通信连接通道是所述第一终端和所述网络服务器之间通过校验双方的设备证书建立的;或,
    所述第二通信连接通道是所述第一终端通过校验所述网络服务器的设备证书建立的。
  77. 根据权利要求76所述的设备,其特征在于,所述设备证书包括网络服务器证书和/或终端设备证书,所述网络服务器证书设置于所述网络服务器上,所述终端设备证书设置于所述第一终端上。
  78. 根据权利要求76所述的设备,其特征在于,所述第二通信连接通道包括HTTPS通道。
  79. 根据权利要求75所述的设备,其特征在于,
    所述加密密钥是所述第一终端对数据密钥加密得到的,所述加密数据是所述第一终端根据所述数据密钥对待传输的原始数据进行加密得到的;
    其中,当所述第一终端为控制设备、且所述第二终端为移动平台时,所述原始数据为所述控制设备对所述移动平台的控制数据;或,当所述第一终端为 移动平台、且所述第二终端为控制设备时,所述原始数据为所述移动平台采集的工作数据。
  80. 根据权利要求79所述的设备,其特征在于,
    所述加密密钥是所述第一终端根据业务密码对数据密钥进行加密得到的。
  81. 根据权利要求80所述的设备,其特征在于,
    所述业务密钥是所述第一终端根据根密钥和预设类型的数据组经过加密运算得到的。
  82. 根据权利要求81所述的设备,其特征在于,
    所述根密钥是所述第一终端和所述第二终端中预先设置的,所述第一终端的根密钥与所述第二终端的根密钥相同。
  83. 根据权利要求81所述的设备,其特征在于,
    所述预设类型的数据组是所述第一终端和所述第二终端在对频之后,根据通过私有安全链路进行同步处理后的同步随机数和/或验证码生成的;
    所述同步随机数包括所述第一终端生成的随机数和/或所述第二终端生成的随机数。
  84. 根据权利要求79所述的设备,其特征在于,所述数据密钥是所述第一终端根据生成的随机数计算得到的。
  85. 根据权利要求75所述的设备,其特征在于,所述处理器建立与第一终端的第二通信连接通道之后,还用于:
    接收所述第一终端通过所述第二通信连接通道发送的登录认证信息;
    将所述登录认证信息对应的业务认证信息给所述第一终端,以使得所述第一终端根据所述业务认证信息建立与业务设备之间的第一通信连接通道;
    所述加密数据为所述第一终端通过所述第一通信连接通道发送至所述业务设备,并由所述业务设备发送至所述第二终端。
  86. 根据权利要求85所述的设备,其特征在于,
    所述登录认证信息携带了所述业务认证信息的获取请求;
    其中,所述业务认证信息的获取请求用于指示所述网络服务器对所述登录认证信息进行验证,并在验证成功之后发送所述业务认证信息给所述第一终端。
  87. 根据权利要求86所述的设备,其特征在于,
    所述登录认证信息是第三终端通过用户中心服务器获取,并由所述第三终端发送给所述控制设备,以及由所述控制设备通过私有安全链路同步发送给所述移动平台的;
    其中,所述第三终端是所述控制设备,或者,所述第三终端是与所述控制设备建立通信连接的设备;所述第三终端与所述用户中心服务器建立通信连接,所述用户中心服务器独立于所述网络服务器,或者,所述网络服务器包括所述用户中心服务器。
  88. 根据权利要求85所述的设备,其特征在于,所述第一通信连接通道包括传输控制协议TCP通道或用户数据报协议UDP通道。
  89. 一种业务设备,其特征在于,包括:处理器和存储器;
    所述存储器,用于存储程序指令;
    所述处理器,执行所述存储器存储的程序指令,当程序指令被执行时,所述处理器用于执行如下步骤:
    建立与第一终端之间的第一通信连接通道;
    接收所述第一终端通过所述第一通信连接通道发送的加密数据,并将所述加密数据发送给第二终端;
    其中,当所述第一终端为控制设备、且所述第二终端为移动平台时,所述加密数据包括所述控制设备对所述移动平台的控制数据;或,当所述第一终端为所述移动平台、且所述第二终端为所述控制设备时,所述加密数据包括所述移动平台采集的工作数据。
  90. 根据权利要求89所述的业务设备,其特征在于,所述处理器建立与第一终端之间的第一通信连接通道时,具体用于:
    接收第一终端发送的业务认证信息,所述业务认证信息是所述第一终端通过第二通信连接通道和登录认证信息从网络服务器中获取到的;
    根据所述业务认证信息建立与所述第一终端之间的第一通信连接通道。
  91. 根据权利要求90所述的业务设备,其特征在于,
    所述第二通信连接通道是所述第一终端和所述网络服务器之间通过校验双方的设备证书建立的;或,
    所述第二通信连接通道是所述第一终端通过校验所述网络服务器的设备证书建立的。
  92. 根据权利要求91所述的业务设备,其特征在于,所述设备证书包括网络服务器证书和/或终端设备证书,所述网络服务器证书设置于网络服务器上,所述终端设备证书设置于所述第一终端上。
  93. 根据权利要求90所述的业务设备,其特征在于,所述第二通信连接通道包括超文本传输安全协议HTTPS通道。
  94. 根据权利要求90所述的业务设备,其特征在于,
    所述登录认证信息携带了所述业务认证信息的获取请求;
    其中,所述业务认证信息的获取请求用于指示所述网络服务器对所述登录认证信息进行验证,并在验证成功之后发送所述业务认证信息给所述第一终端。
  95. 根据权利要求94所述的业务设备,其特征在于,
    所述登录认证信息是第三终端通过用户中心服务器获取,并由所述第三终端发送给所述控制设备,以及由所述控制设备通过私有安全链路同步发送给所述移动平台的;
    其中,所述第三终端是所述控制设备,或者,所述第三终端是与所述控制设备建立通信连接的设备;所述第三终端与所述用户中心服务器建立通信连接,所述用户中心服务器独立于所述网络服务器,或者,所述网络服务器包括所述用户中心服务器。
  96. 根据权利要求89所述的业务设备,其特征在于,所述第一通信连接通道包括传输控制协议TCP通道或用户数据报协议UDP通道。
  97. 根据权利要求89所述的业务设备,其特征在于,
    所述加密数据是所述第一终端根据数据密钥对待传输的原始数据进行加密得到的;
    其中,当所述第一终端为控制设备、且所述第二终端为移动平台时,所述原始数据为所述控制设备对所述移动平台的控制数据;或,当所述第一终端为移动平台、且所述第二终端为控制设备时,所述原始数据为所述移动平台采集的工作数据。
  98. 根据权利要求97所述的业务设备,其特征在于,所述数据密钥是所述第一终端根据生成的随机数计算得到的。
  99. 根据权利要求97所述的业务设备,其特征在于,所述处理器还用于:
    接收所述第一终端通过所述第一通信连接通道发送的加密密钥,并将所述加密密钥发送给所述第二终端,以使得所述第二终端根据所述加密密钥对所述加密数据进行解密;
    所述加密密钥是所述第一终端对所述数据密钥进行加密得到的。
  100. 根据权利要求99所述的业务设备,其特征在于,
    所述加密密钥是所述第一终端根据业务密码对所述数据密钥进行加密得到的。
  101. 根据权利要求100所述的业务设备,其特征在于,
    所述业务密钥是所述第一终端根据根密钥和预设类型的数据组经过加密运算得到的。
  102. 根据权利要求101所述的业务设备,其特征在于,
    所述根密钥是所述第一终端和所述第二终端中预先设置的,所述第一终端的根密钥与所述第二终端的根密钥相同。
  103. 根据权利要求101所述的业务设备,其特征在于,
    所述预设类型的数据组是所述第一终端和所述第二终端在对频之后,根据通过私有安全链路进行同步处理后的同步随机数和/或验证码生成的;
    所述同步随机数包括所述第一终端生成的随机数和/或所述第二终端生成的随机数。
  104. 一种终端,其特征在于,包括:处理器和存储器;
    所述存储器,用于存储程序指令;
    所述处理器,执行所述存储器存储的程序指令,当程序指令被执行时,所述处理器用于执行如下步骤:
    建立与业务设备之间的第一通信连接通道;
    通过所述第一通信连接通道向所述业务设备发送加密数据,以使得所述业务设备将所述加密数据发送至第二终端;
    其中,当第一终端为控制设备、且所述第二终端为移动平台时,所述加密数据包括所述控制设备对所述移动平台的控制数据;或,当所述第一终端为所述移动平台、且所述第二终端为所述控制设备时,所述加密数据包括所述移动平台采集的工作数据。
  105. 根据权利要求104所述的终端,其特征在于,所述处理器建立与业务设备之间的第一通信连接通道时,具体用于:
    向业务设备发送业务认证信息,所述业务认证信息是通过第二通信连接通道和登录认证信息从网络服务器中获取到的;
    根据所述业务认证信息建立与所述第一终端之间的第一通信连接通道。
  106. 根据权利要求105所述的终端,其特征在于,
    所述第二通信连接通道是所述第一终端和所述网络服务器之间通过校验双方的设备证书建立的;或,
    所述第二通信连接通道是所述第一终端通过校验所述网络服务器的设备证书建立的。
  107. 根据权利要求106所述的终端,其特征在于,所述设备证书包括网络服务器证书和/或终端设备证书,所述网络服务器证书设置于网络服务器上,所述终端设备证书设置于所述第一终端上。
  108. 根据权利要求105所述的终端,其特征在于,所述第二通信连接通道包括HTTPS通道。
  109. 根据权利要求105所述的终端,其特征在于,
    所述登录认证信息携带了所述业务认证信息的获取请求;
    其中,所述业务认证信息的获取请求用于指示所述网络服务器对所述登录认证信息进行验证,并在验证成功之后发送所述业务认证信息给所述第一终端。
  110. 根据权利要求109所述的终端,其特征在于,
    所述登录认证信息是第三终端通过用户中心服务器获取,并由所述第三终端发送给所述控制设备,以及由所述控制设备通过私有安全链路同步发送给所述移动平台的;
    其中,所述第三终端是所述控制设备,或者,所述第三终端是与所述控制设备建立通信连接的设备;所述第三终端与所述用户中心服务器建立通信连接,所述用户中心服务器独立于所述网络服务器,或者,所述网络服务器包括所述用户中心服务器。
  111. 根据权利要求104所述的终端,其特征在于,所述第一通信连接通 道包括传输控制协议TCP通道或用户数据报协议UDP通道。
  112. 根据权利要求104所述的终端,其特征在于,
    所述加密数据是所述第一终端根据数据密钥对待传输的原始数据进行加密得到的;
    其中,当所述第一终端为控制设备、且所述第二终端为移动平台时,所述原始数据为所述控制设备对所述移动平台的控制数据;或,当所述第一终端为移动平台、且所述第二终端为控制设备时,所述原始数据为所述移动平台采集的工作数据。
  113. 根据权利要求112所述的终端,其特征在于,所述数据密钥是所述第一终端根据生成的随机数计算得到的。
  114. 根据权利要求105所述的终端,其特征在于,所述处理器还用于:
    通过所述第二通信连接通道向所述网络服务器发送加密密钥,以使得所述第二终端根据从所述网络服务器获取的所述加密密钥对所述加密数据进行解密;或者,
    通过所述第一通信连接通道向所述业务设备发送加密密钥,以使得所述第二终端根据从所述业务设备获取的所述加密密钥对所述加密数据进行解密;
    其中,所述加密密钥是所述第一终端对所述数据密钥进行加密得到的。
  115. 根据权利要求114所述的终端,其特征在于,
    所述加密密钥是所述第一终端根据业务密码对所述数据密钥进行加密得到的。
  116. 根据权利要求115所述的终端,其特征在于,
    所述业务密钥是所述第一终端根据根密钥和预设类型的数据组经过加密运算得到的。
  117. 根据权利要求116所述的终端,其特征在于,
    所述根密钥是所述第一终端和所述第二终端中预先设置的,所述第一终端的根密钥与所述第二终端的根密钥相同。
  118. 根据权利要求116所述的终端,其特征在于,
    所述预设类型的数据组是所述第一终端和所述第二终端在对频之后,根据通过私有安全链路进行同步处理后的同步随机数和/或验证码生成的;
    所述同步随机数包括所述第一终端生成的随机数和/或所述第二终端生成的随机数。
  119. 一种网络服务器,其特征在于,包括:处理器和存储器;
    所述存储器,用于存储程序指令;
    所述处理器,执行所述存储器存储的程序指令,当程序指令被执行时,所述处理器用于执行如下步骤:
    建立与第一终端的第二通信连接通道;
    接收所述第一终端通过所述第二通信连接通道发送的加密密钥,以使得第二终端根据从所述网络服务器获取的所述加密密钥对所述第一终端发送至所述第二终端的加密数据进行解密;
    其中,当所述第一终端为控制设备、所述第二终端为移动平台时,所述加密数据包括所述控制设备对所述移动平台的控制数据;或,当所述第一终端为所述移动平台、且所述第二终端为所述控制设备时,所述加密数据包括所述移动平台采集的工作数据。
  120. 根据权利要求119所述的服务器,其特征在于,
    所述第二通信连接通道是所述第一终端和所述网络服务器之间通过校验双方的设备证书建立的;或,
    所述第二通信连接通道是所述第一终端通过校验所述网络服务器的设备证书建立的。
  121. 根据权利要求120所述的服务器,其特征在于,所述设备证书包括网络服务器证书和/或终端设备证书,所述网络服务器证书设置于所述网络服 务器上,所述终端设备证书设置于所述第一终端上。
  122. 根据权利要求120所述的服务器,其特征在于,所述第二通信连接通道包括HTTPS通道。
  123. 根据权利要求119所述的服务器,其特征在于,
    所述加密密钥是所述第一终端对数据密钥加密得到的,所述加密数据是所述第一终端根据所述数据密钥对待传输的原始数据进行加密得到的;
    其中,当所述第一终端为控制设备、且所述第二终端为移动平台时,所述原始数据为所述控制设备对所述移动平台的控制数据;或,当所述第一终端为移动平台、且所述第二终端为控制设备时,所述原始数据为所述移动平台采集的工作数据。
  124. 根据权利要求123所述的服务器,其特征在于,
    所述加密密钥是所述第一终端根据业务密码对数据密钥进行加密得到的。
  125. 根据权利要求124所述的服务器,其特征在于,
    所述业务密钥是所述第一终端根据根密钥和预设类型的数据组经过加密运算得到的。
  126. 根据权利要求125所述的服务器,其特征在于,
    所述根密钥是所述第一终端和所述第二终端中预先设置的,所述第一终端的根密钥与所述第二终端的根密钥相同。
  127. 根据权利要求125所述的服务器,其特征在于,
    所述预设类型的数据组是所述第一终端和所述第二终端在对频之后,根据通过私有安全链路进行同步处理后的同步随机数和/或验证码生成的;
    所述同步随机数包括所述第一终端生成的随机数和/或所述第二终端生成的随机数。
  128. 根据权利要求123所述的服务器,其特征在于,所述数据密钥是所述第一终端根据生成的随机数计算得到的。
  129. 根据权利要求119所述的服务器,其特征在于,所述处理器建立与第一终端的第二通信连接通道之后,还用于:
    接收所述第一终端通过所述第二通信连接通道发送的登录认证信息;
    将所述登录认证信息对应的业务认证信息给所述第一终端,以使得所述第一终端根据所述业务认证信息建立与业务设备之间的第一通信连接通道;
    所述加密数据为所述第一终端通过所述第一通信连接通道发送至所述业务设备,并由所述业务设备发送至所述第二终端。
  130. 根据权利要求129所述的服务器,其特征在于,
    所述登录认证信息携带了所述业务认证信息的获取请求;
    其中,所述业务认证信息的获取请求用于指示所述网络服务器对所述登录认证信息进行验证,并在验证成功之后发送所述业务认证信息给所述第一终端。
  131. 根据权利要求130所述的服务器,其特征在于,
    所述登录认证信息是第三终端通过用户中心服务器获取,并由所述第三终端发送给所述控制设备,以及由所述控制设备通过私有安全链路同步发送给所述移动平台的;
    其中,所述第三终端是所述控制设备,或者,所述第三终端是与所述控制设备建立通信连接的设备;所述第三终端与所述用户中心服务器建立通信连接,所述用户中心服务器独立于所述网络服务器,或者,所述网络服务器包括所述用户中心服务器。
  132. 根据权利要求129所述的服务器,其特征在于,所述第一通信连接通道包括传输控制协议TCP通道或用户数据报协议UDP通道。
  133. 一种计算机可读存储介质,所述计算机可读存储介质存储有计算机 程序,其特征在于,所述计算机程序被处理器执行时实现如权利要求1至44任一项所述方法。
PCT/CN2018/118784 2018-11-30 2018-11-30 一种数据传输方法、设备、终端、服务器及存储介质 Ceased WO2020107486A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
PCT/CN2018/118784 WO2020107486A1 (zh) 2018-11-30 2018-11-30 一种数据传输方法、设备、终端、服务器及存储介质
CN201880038851.1A CN110785977A (zh) 2018-11-30 2018-11-30 一种数据传输方法、设备、终端、服务器及存储介质

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2018/118784 WO2020107486A1 (zh) 2018-11-30 2018-11-30 一种数据传输方法、设备、终端、服务器及存储介质

Publications (1)

Publication Number Publication Date
WO2020107486A1 true WO2020107486A1 (zh) 2020-06-04

Family

ID=69383055

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2018/118784 Ceased WO2020107486A1 (zh) 2018-11-30 2018-11-30 一种数据传输方法、设备、终端、服务器及存储介质

Country Status (2)

Country Link
CN (1) CN110785977A (zh)
WO (1) WO2020107486A1 (zh)

Families Citing this family (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113545022A (zh) * 2020-05-27 2021-10-22 深圳市大疆创新科技有限公司 数据处理、加密、解密方法、设备和存储介质
CN111786987B (zh) * 2020-06-29 2023-04-25 杭州海康机器人股份有限公司 一种任务下发方法、装置、系统及设备
WO2022060288A2 (zh) * 2020-09-15 2022-03-24 华为技术有限公司 一种无人机与遥控器的安全通信方法以及相关装置
CN113507437A (zh) * 2021-06-03 2021-10-15 中联国智科技管理(北京)有限公司 一种基于5g的会议通信方法及装置
CN115119199B (zh) * 2022-08-30 2022-12-02 国网湖北省电力有限公司技术培训中心 基于星链无人机组的信息传递方法及设备
CN116032577A (zh) * 2022-12-19 2023-04-28 北京成鑫盈通科技有限公司 实现终端设备端到端的数据安全传输系统、传输方法、介质及终端

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106713491A (zh) * 2017-01-20 2017-05-24 亿航智能设备(广州)有限公司 一种基于云端的飞行数据管理方法及装置
US20170270314A1 (en) * 2016-03-21 2017-09-21 Acronis International Gmbh System and method for data backup using unmanned aerial vehicle (uav)
CN207070091U (zh) * 2017-06-29 2018-03-02 杨卓 一种基于无线网络的无人机安全控制系统

Family Cites Families (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
ITTO20110681A1 (it) * 2011-07-27 2013-01-28 Csp Innovazione Nelle Ict Scarl Metodo per consentire missioni di veicoli aerei senza pilota, in particolare in spazi aerei non segregati
CN104486343B (zh) * 2014-12-18 2018-06-19 广东粤铁科技有限公司 一种双因子双向认证的方法及系统
WO2017096599A1 (zh) * 2015-12-10 2017-06-15 深圳市大疆创新科技有限公司 安全通信系统、方法及装置
CN106716973A (zh) * 2016-11-22 2017-05-24 深圳市大疆创新科技有限公司 无人飞行器的控制方法及地面控制端
CN109302428A (zh) * 2016-12-27 2019-02-01 深圳市大疆创新科技有限公司 无人机的控制方法和设备
CN106686013A (zh) * 2017-03-10 2017-05-17 湖北天专科技有限公司 一种无人飞行器身份识别装置、识别系统及其识别方法
CN108780603A (zh) * 2017-11-30 2018-11-09 深圳市大疆创新科技有限公司 一种无人机系统及其通信方法、遥控装置
CN108886667B (zh) * 2017-12-15 2021-04-27 深圳市大疆创新科技有限公司 无线通信方法、设备及系统

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20170270314A1 (en) * 2016-03-21 2017-09-21 Acronis International Gmbh System and method for data backup using unmanned aerial vehicle (uav)
CN106713491A (zh) * 2017-01-20 2017-05-24 亿航智能设备(广州)有限公司 一种基于云端的飞行数据管理方法及装置
CN207070091U (zh) * 2017-06-29 2018-03-02 杨卓 一种基于无线网络的无人机安全控制系统

Also Published As

Publication number Publication date
CN110785977A (zh) 2020-02-11

Similar Documents

Publication Publication Date Title
US11303616B2 (en) System and method for a multi system trust chain
US10237241B2 (en) Transport layer security latency mitigation
CN113596828B (zh) 端对端服务层认证
EP3982590B1 (en) Security authentication method, configuration method, and related device
US9398049B2 (en) Method and device for securely transmitting data
CN110785977A (zh) 一种数据传输方法、设备、终端、服务器及存储介质
CN110999223A (zh) 安全加密的心跳协议
KR101762013B1 (ko) Two factor 통신 채널을 활용한 사물기기의 등록 및 비밀키 설정 방법
US20160080940A1 (en) Method, Apparatus, and System for Configuring Wireless Device
CN109905348B (zh) 端到端认证及密钥协商方法、装置及系统
CN109995719A (zh) 一种无人机认证方法、系统、无人机监管平台和第一设备
CN103391292A (zh) 针对移动应用的安全登录方法、系统和装置
EP3811583B1 (en) Secure systems and methods for resolving audio device identity using remote application
CN115885496B (zh) 一种通信方法及相关装置
CN105227309B (zh) 用于物联网终端与云端通讯的加密方法
WO2020133085A1 (zh) 信息传输方法、存储介质、信息传输系统及无人飞行器
US20250220434A1 (en) Secure sniffing of wireless connections with forward secrecy
WO2017091987A1 (zh) 一种终端间的安全交互方法及装置
CN111357305B (zh) 可移动平台的通信方法、设备、系统及存储介质
CN111132143B (zh) 一体化多媒体智能设备安全保护系统及方法
CN115567195A (zh) 安全通信方法、客户端、服务器、终端和网络侧设备
CN105391693A (zh) 一种智能终端授权的方法及装置
JP7677568B2 (ja) 鍵取得方法及び関連する装置
CN116619390B (zh) 一种基于视觉图像的机械臂控制方法及装置
WO2016176902A1 (zh) 一种终端认证方法、管理终端及申请终端

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 18941663

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 18941663

Country of ref document: EP

Kind code of ref document: A1