Background technology
Be standing breath now, and the e world that every industry development is advanced fast, because information flow is quick, people to the demand of information with exchange more and more big, therefore, the Internet (Internet) just is widely used in all trades and professions, and a kind of device for mobile communication (as: mobile phone) is widely used especially, and become already many people live the custom in an indispensable part.
Generally speaking, when this device for mobile communication carries out the transmitting-receiving of Email (E-mail) on the internet at present, basically all be to carry out in the mode of plaintext (encryption), thus, will being easy to be subjected to intentionally, personage (hacker) intercepts and captures from this network and intercepts.Aforementioned said phenomenon for the individual, is the secret worry that a kind of privacy is revealed not only, for enterprise, also is a kind of great safe secret worry undoubtedly simultaneously, therefore, and the particular importance that will seem of strick precaution in this respect.
Because the design of each device for mobile communication and manufacturer do not encrypt at the transmitting-receiving of Email now, do not had the inclination personage's intercepting and capturing and intercepting to guarantee this Email.Therefore, this problem is the design and the manufacturer of these device for mobile communication in fact, needs to be resolved hurrily and improved important topic.
So, if can design a kind of E-mail enciphered implementation method,, do not had the inclination the personage from this network, to intercept or steal to make the user when sending and receiving e-mail, believe that this will the person of opinion that the person of being to use finds pleasure in.
Embodiment
The present invention is a kind of E-mail enciphered implementation method; this method is provided with a safe Connection Service device 11 respectively in a mail server 10; and in a device for mobile communication 12 (as: mobile phone), the address that can use this mail server 10 is set; allow the user utilize this device for mobile communication 12 to select transmitting-receiving one Email; and after logining a Internet; this device for mobile communication 12 can be connected with this mail server 10 according to this address; after the success to be connected; restart this safe Connection Service device 11; make this safe Connection Service device 11 can be at the address of its address and this this mail server 10; carry out the process of an identity authentication and an interchange key; thereby set up one by the virtual secure passage of this device for mobile communication 12 to this mail server 10; Chuan Shu mail data can be after seeing through specific secret key encryption in regular turn; can carry out transfer of data via this virtual secure passage; so; this device for mobile communication 12 can see through the mail treatment module 123 in it; carry out the normal transmitting-receiving of mail; and protect important information in this Email, do not had the inclination the personage arbitrarily to see through this network and intercept or steal.
In framework of the present invention, see also shown in Figure 1, include this mail server 10 respectively, be respectively equipped with a network in it and connect module 101, in order to usefulness, a virtual connection module 102 that is connected with this Internet, in order to set up and to safeguard usefulness, a mail treatment module 103 that is connected with this device for mobile communication 12 safety to each other, in order to realize the usefulness of mail treatment; This safe Connection Service device 11, in order to the setting of special disposal escape way and the usefulness that is connected, can use same server 10 with this mail server 10, and, then can use the built-in safe connection processing module (not shown) of win2000 to realize, but the present invention is when reality is implemented if use a form (windows) operating system, be not limited thereto, if other operating system also has corresponding software not add to give unnecessary details at this for realizing.
Moreover, this device for mobile communication 12, be in order to support data dial, the usefulness of sending and receiving e-mail, be respectively equipped with a dial-up connection module 121 in it, be connected in order to set up, a virtual connection module 122 with the non-safety of this Internet 13, be in order to foundation and maintenance and this mail server 10 to each other the full usefulness that is connected, mail treatment module 123, in order to usefulness, a mail of realizing mail transmission/reception module 124 is set, in order to the relevant information of setting and this mail server 10; This Internet 13 is in order to realize the usefulness of this mail server 10 and this device for mobile communication 12 the Internet to each other.
In the present invention, see also shown in Figure 2, it is the secret key encryption framework of this mail data, because when Network Transmission, be with the unit of transfer of package (Frame) as data, so, data information for arbitrary Email all needs to handle the back transmission through enfeoffment, after all packages have been grabbed, form complete Email, have the header structure of internet communication agreement (Internet Protocol) in the fixed position of this Email respectively, be called for short IP agreement 21, it is actual packet via this Internet exchange, one security accord encrypts 22, be packet, and mail agreement data 23, according to this internet communication formed mail data of reaching an agreement on via formed escape way agreement after encrypting, in a certain position of these information contents, promptly can obtain its data content value respectively.
With next the present invention when utilizing this device for mobile communication 12 to select to send and receive e-mail, the implementation method that this is E-mail enciphered:
Aspect this device for mobile communication 12, control processing according to the following step, see also shown in Figure 3:
(301) at first, start this dial-up connection module 121, set up non-safe dial-up connection with this Internet 13;
(302) see through this virtual connection module 122, be connected with this mail server 10 virtual secure passage to each other according to this address, and judge whether successful connection, if not successful connection, then return step (301), if successful connection promptly continues next step (303);
(303), carry out the operation of the normal transmitting-receiving of mail, and realize the data of secret key encryption/deciphering mail transmission/reception via this mail treatment module 123;
(304) judge whether this mail transmission/reception finishes,, then return step (303), if transmitting-receiving finishes promptly to continue next step (305) if transmitting-receiving does not finish;
(305) then, by this safe this virtual secure passage of Connection Service device 11 removals, finish the processing of controlling aspect this device for mobile communication 12 simultaneously.
Aspect this mail server 10, then control processing according to the following step, see also shown in Figure 4:
(401) at first, this network connects the non-safe dial-up connection request that module 101 receives this device for mobile communication 12;
(402), carry out being connected with the non-to each other safety of this device for mobile communication 12 via this virtual connection module 102;
(403) after the success to be connected, start this safe Connection Service device 11, make this safe Connection Service device 11 can be at the address of its address and this mail server 10, carry out the judgement of authentication and interchange key, if authentication is incorrect, then return step (401),, promptly continue next step (404) if authentication is correct;
(404) set up by the virtual secure passage of this device for mobile communication 12 to this mail server 10;
(405) see through mail treatment module 103, carry out the operation of the normal transmitting-receiving of mail, and realize the data of secret key encryption/deciphering mail transmission/reception;
(406) judge whether this mail transmission/reception finishes,, then return step (405),, promptly continue next step (407) if transmitting-receiving finishes if transmitting-receiving does not finish;
(407) then, by this safe this virtual secure passage of Connection Service device 11 removals, finish the processing of controlling aspect this mail server 10 simultaneously.
So, this Email is in the virtual secure passage by above-mentioned foundation, reception of carrying out and transmission, even if data information quilt intentionally personage also will present the mess code that a pile can't be discerned through this network interception, and then can reach the important information of guaranteeing in this Email, not by the purpose of arbitrarily intercepting or stealing.
The above only is a best specific embodiment of the present invention, but feature of the present invention is not limited thereto, and anyly is familiar with present technique field person in field of the present invention, can think easily and variation or modification, all should be encompassed in the following claim of the present invention.