A personal data service data export method, device and storage medium

Through the use of chain interface verification and software development kits, the low security problem of data export solutions in existing technologies is solved, and encryption, watermarking and password protection of data files are achieved, ensuring that data can only be read once, meeting the compliance requirements of data protection laws.

CN118764203BActive Publication Date: 2025-10-14NUBIA TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410782393.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-17
Publication Date
2025-10-14
Estimated Expiration
2044-06-17

AI Technical Summary

Technical Problem

The data export solution for personal data services in the existing technology has low security. Data can be exported after a single interface call. The export interface allows the business system to freely input SQL query statements. The asynchronous method is prone to data leakage, and Excel spreadsheets storing plain text are vulnerable to attacks.

Method used

It uses a chain interface verification method, sends data field groups and query conditions in batches, generates encrypted data keys and file hash salts, verifies the download address through a secure hash algorithm, uses a software development kit to convert it into a readable table file, and downloads it all at once within a preset time, adding watermark and password protection.

Benefits of technology

Improves the security of data export solutions, prevents data leakage, meets compliance requirements of data protection laws, and ensures that data files can only be read once.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118764203B_ABST
    Figure CN118764203B_ABST
Patent Text Reader

Abstract

The application discloses a personal data service data export method, device and computer readable storage medium, wherein the method comprises the following steps: sending an application for exporting data and a public key to a personal data service party, and receiving a data key and a file hash salt sent by the service party; obtaining a download address file compressed and encrypted by the service party; calculating the download address file and the file hash salt according to a preset secure hash algorithm, and sending a calculated hash value to the service party to receive a file password returned by the service party; decrypting the download address file according to the file password, and performing one-time data download according to the decrypted download address within a preset time to obtain an unreadable data file; and combining account information and converting the data file into a readable table file through a preset software development kit. The application realizes a personal data service data export scheme with higher security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of mobile communications, and in particular to a method and device for exporting personal data service data, and a computer-readable storage medium. Background Art

[0002] To comply with national personal data protection laws and overseas regulations like the GDPR, internet companies are developing their own personal data services, essentially unifying all personal data within these services. Currently, business systems using these services often require a feature for batch exporting data in certain business scenarios. Most companies use the personal data service's API to directly export data into Excel spreadsheets.

[0003] The problems with the above solution are:

[0004] 1. The solution has low security, and the data can be output to an Excel spreadsheet after a single interface call;

[0005] 2. The export interface generally allows the business system to freely input SQL and other query statements, which is prone to third-party attacks;

[0006] 3. Export is usually done asynchronously, and the service provides an Excel spreadsheet download address. Once the address is leaked, data leakage may occur.

[0007] 4. Excel spreadsheets are generally stored in plain text, which can easily lead to data leakage when forwarded to others.

[0008] Therefore, a new solution needs to be implemented to solve the above-mentioned problem of low security. Summary of the Invention

[0009] In order to solve the above technical defects in the prior art, the present invention proposes a method for exporting personal data service data, which is applied to a data access party. The method includes:

[0010] Sending a request for exporting data and a public key to a personal data service provider, and receiving a data key and a file hash salt encrypted using the public key from the personal data service provider;

[0011] When it is found that the data export action of the personal service provider has been completed, the data key decrypted by the private key is sent to the personal data service provider to obtain the download address file of the exported data compressed and encrypted by the personal data service provider;

[0012] Calculate the download address file and the file hash salt according to a preset secure hash algorithm, and send the calculated hash value to the personal data service provider to receive the file password sent by the personal data service provider after verifying the hash value;

[0013] Decrypt the download address file according to the file password, and perform a one-time data download according to the decrypted download address within a preset time to obtain an unreadable data file;

[0014] Log in to the software development kit provided by the personal data service provider according to the preset account information, and convert the data file into a readable table file through the software development kit.

[0015] Optionally, the sending of the data export request to the personal data service provider includes:

[0016] The field groups of the data to be exported and the corresponding business system query conditions are sent to the personal data service provider in batches through the first interface provided by the personal data service provider, so that the personal data service provider combines the field groups and the query conditions to obtain a query statement.

[0017] Optionally, the converting the data file into a readable table file by the software development kit further comprises:

[0018] Adding and embedding watermark information corresponding to the account information into the table file through the software development kit;

[0019] Furthermore, an independent opening password and editing authority are set for the table file through the software development kit.

[0020] The present invention also proposes a method for exporting personal data service data, which is applied to a personal data service provider. The method comprises:

[0021] Receive the field groups of the data to be exported and the corresponding business system query conditions sent in batches by the data access party, and combine the field groups and the query conditions to obtain a query statement;

[0022] When the query statement passes the legality check, the data key and file hash salt obtained by encrypting the public key provided by the data access party are sent to the data access party, and the data is read in pages according to the query statement;

[0023] After the reading is completed, the data key decrypted by the data access party using the private key is received, and after the data key is verified, the compressed and encrypted download address file is sent to the data access party;

[0024] Receiving a hash value calculated by the data access party using the file hash salt and the download address file, and when the received hash value is consistent with the local hash value, sending a file password corresponding to the download address file to the data access party;

[0025] A preset software development kit is provided to the data access party, so that the data access party decrypts the download address file according to the file password, performs a one-time data download according to the decrypted download address within a preset time, and after obtaining an unreadable data file, logs in to the software development kit according to preset account information, and converts the data file into a readable table file through the software development kit.

[0026] Optionally, the receiving of the field groups of the data to be exported and the corresponding query conditions of the business system sent in batches by the data access party further includes:

[0027] The field groups and the query conditions sent by the data access party are received in batches through a preset first interface.

[0028] Optionally, the paging reading of data according to the query statement further includes:

[0029] After reading each page of data, the data of the page is written into an unreadable data file;

[0030] Furthermore, a query instruction sent by the data access party is received through a preset second interface to determine whether the data export action has been completed.

[0031] Optionally, the sending of the file password corresponding to the download address file to the data access party further includes:

[0032] Sending the file password to the data access party through a preset third interface;

[0033] After the file password is sent, the download address file is deleted.

[0034] Optionally, after the file password is sent, deleting the download address file further includes:

[0035] Monitor data downloading actions within a preset time period;

[0036] When the downloading action is not detected within the time period, or when the downloading action is detected for the second time within the time period, the data file is deleted.

[0037] The present invention also proposes a personal data service data export device, which includes a memory, a processor, and a computer program stored on the memory and runnable on the processor. When the computer program is executed by the processor, the steps of the personal data service data export method as described in any one of the above items are implemented.

[0038] The present invention also proposes a computer-readable storage medium, which stores a personal data service data export program. When the personal data service data export program is executed by a processor, it implements the steps of the personal data service data export method as described in any one of the above items.

[0039] The personal data service data export method, device, and computer-readable storage medium of the present invention include sending a data export application and a public key to a personal data service provider, and receiving a data key and a file hash salt encrypted using the public key from the personal data service provider; upon querying that the data export action of the personal data service provider has been completed, sending the data key decrypted using the private key to the personal data service provider to obtain a download address file of the exported data compressed and encrypted by the personal data service provider; calculating the download address file and the file hash salt using a preset secure hash algorithm, and sending the calculated hash value to the personal data service provider to receive a file password sent by the personal data service provider after verifying the hash value; decrypting the download address file using the file password, and performing a one-time data download according to the decrypted download address within a preset time to obtain an unreadable data file; logging into a software development kit provided by the personal data service provider using preset account information, and converting the data file into a readable table file using the software development kit. The present invention implements a more secure personal data service data export solution. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] The present invention will be further described below with reference to the accompanying drawings and embodiments, in which:

[0041] Figure 1 This is a hardware structure diagram of a mobile terminal according to the present invention;

[0042] Figure 2 is a first flow chart of the method for exporting personal data service data of the present invention;

[0043] Figure 3 This is a second flow chart of the method for exporting personal data service data according to the present invention. DETAILED DESCRIPTION

[0044] It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.

[0045] In the subsequent description, suffixes such as "module," "component," or "unit" used to represent elements are only used to facilitate the description of the present invention and have no specific meaning. Therefore, "module," "component," or "unit" can be used interchangeably.

[0046] The terminal can be implemented in various forms. For example, the terminal described in the present invention may include mobile terminals such as mobile phones, tablet computers, laptop computers, PDAs, portable media players (PMPs), navigation devices, wearable devices, smart bracelets, pedometers, etc., as well as fixed terminals such as digital TVs and desktop computers.

[0047] The following description will be made by taking a mobile terminal as an example. It will be understood by those skilled in the art that, in addition to components specifically used for mobile purposes, the configuration according to the embodiments of the present invention can also be applied to fixed type terminals.

[0048] See also Figure 1 , which is a schematic diagram of the hardware structure of a mobile terminal for implementing various embodiments of the present invention. The mobile terminal 100 may include: an RF (Radio Frequency) unit 101, a WiFi module 102, an audio output unit 103, an A / V (audio / video) input unit 104, a sensor 105, a display unit 106, a user input unit 107, an interface unit 108, a memory 109, a processor 110, and a power supply 111. Those skilled in the art will understand that Figure 1 The structure of the mobile terminal shown in the figure does not constitute a limitation to the mobile terminal. The mobile terminal may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.

[0049] The following combination Figure 1 A detailed introduction to the various components of the mobile terminal:

[0050] The RF unit 101 can be used to send and receive information or receive signals during calls. Specifically, it receives downlink information from the base station and transmits it to the processor 110 for processing. It also transmits uplink data to the base station. Typically, the RF unit 101 includes, but is not limited to, an antenna, at least one amplifier, a transceiver, a coupler, a low-noise amplifier, a duplexer, and more. Furthermore, the RF unit 101 can communicate with the network and other devices via wireless communication. The above-mentioned wireless communications may use any communication standard or protocol, including but not limited to GSM (Global System of Mobile communication), GPRS (General Packet Radio Service), CDMA2000 (Code Division Multiple Access 2000), WCDMA (Wideband Code Division Multiple Access), TD-SCDMA (Time Division-Synchronous Code Division Multiple Access), FDD-LTE (Frequency Division Duplexing-Long Term Evolution) and TDD-LTE (Time Division Duplexing-Long Term Evolution), etc.

[0051] WiFi is a short-range wireless transmission technology. Mobile terminals can help users send and receive emails, browse web pages, and access streaming media through the WiFi module 102. It provides users with wireless broadband Internet access. Figure 1 The WiFi module 102 is shown, but it is understandable that it is not an essential component of the mobile terminal and can be omitted as needed without changing the essence of the invention.

[0052] The audio output unit 103 can convert audio data received by the RF unit 101 or the WiFi module 102 or stored in the memory 109 into an audio signal and output it as sound when the mobile terminal 100 is in a call signal reception mode, a talk mode, a recording mode, a voice recognition mode, a broadcast reception mode, or the like. Furthermore, the audio output unit 103 can also provide audio output related to a specific function performed by the mobile terminal 100 (e.g., a call signal reception sound, a message reception sound, etc.). The audio output unit 103 may include a speaker, a buzzer, or the like.

[0053] The A / V input unit 104 is used to receive audio or video signals. The A / V input unit 104 may include a graphics processing unit (GPU) 1041 and a microphone 1042. The GPU 1041 processes image data of still images or videos captured by an image capture device (e.g., a camera) in video capture mode or image capture mode. The processed image frames may be displayed on the display unit 106. The image frames processed by the GPU 1041 may be stored in the memory 109 (or other storage medium) or transmitted via the RF unit 101 or the WiFi module 102. The microphone 1042 may receive sound (audio data) in operating modes such as a phone call mode, a recording mode, and a voice recognition mode, and may process such sound into audio data. In the phone call mode, the processed audio (voice) data may be converted into a format that can be transmitted to a mobile communication base station via the RF unit 101. The microphone 1042 may implement various types of noise cancellation (or suppression) algorithms to eliminate (or suppress) noise or interference generated during the reception and transmission of audio signals.

[0054] The mobile terminal 100 also includes at least one sensor 105, such as a light sensor, a motion sensor, and other sensors. Specifically, the light sensor includes an ambient light sensor and a proximity sensor, wherein the ambient light sensor can adjust the brightness of the display panel 1061 according to the brightness of the ambient light, and the proximity sensor can turn off the display panel 1061 and / or the backlight when the mobile terminal 100 is moved to the ear. As a type of motion sensor, the accelerometer sensor can detect the magnitude of acceleration in all directions (generally three axes), and can detect the magnitude and direction of gravity when stationary. It can be used for applications that identify the posture of the mobile phone (such as horizontal and vertical screen switching, related games, magnetometer posture calibration), vibration recognition related functions (such as pedometer, tapping), etc.; as for other sensors that can be configured in the mobile phone, such as fingerprint sensors, pressure sensors, iris sensors, molecular sensors, gyroscopes, barometers, hygrometers, thermometers, infrared sensors, etc., they will not be described here.

[0055] The display unit 106 is used to display information input by the user or information provided to the user. The display unit 106 may include a display panel 1061, which may be configured in the form of a liquid crystal display (LCD), an organic light-emitting diode (OLED), or the like.

[0056] The user input unit 107 can be used to receive input numerals or character information, and to generate key signal inputs related to user settings of the mobile terminal and control of functions. Specifically, the user input unit 107 can include a touch panel 1071 and other input devices 1072. The touch panel 1071, also called a touch screen, can collect a touch operation of a user on or proximate thereto (such as an operation of the user using a finger, a stylus, or any suitable object or accessory on or proximate to the touch panel 1071), and drive a corresponding connection device according to a pre-set program. The touch panel 1071 can include two parts, a touch detecting device and a touch controller. The touch detecting device detects a user's touch position and detects a signal resulting from a touch operation, and transmits the signal to the touch controller. The touch controller receives touch information from the touch detecting device, converts it into touch coordinates, and transmits the touch coordinates to the processor 110, and can receive commands from the processor 110 and execute them. In addition, the touch panel 1071 can be implemented in various types such as a resistive type, a capacitive type, an infrared type, and a surface acoustic wave type. In addition to the touch panel 1071, the user input unit 107 can include other input devices 1072. Specifically, the other input devices 1072 can include one or more of, but are not limited to, a physical keyboard, function keys (such as a volume control button, a switch button, etc.), a trackball, a mouse, a joystick, etc.

[0057] Further, the touch panel 1071 can cover the display panel 1061, and when the touch panel 1071 detects a touch operation on or proximate thereto, it transmits the same to the processor 110 to determine the type of the touch event, and then the processor 110 provides a corresponding visual output on the display panel 1061 according to the type of the touch event. Although in the above description, the touch panel 1071 and the display panel 1061 are implemented as two separate components to achieve the input and output functions of the mobile terminal, in some embodiments, the touch panel 1071 and the display panel 1061 can be integrated to achieve the input and output functions of the mobile terminal, without being limited thereto. Figure 1

[0058] The interface unit 108 serves as an interface through which at least one external device can be connected with the mobile terminal 100. For example, the external device can include a wired or wireless headset port, an external power (or battery charger) port, a wired or wireless data port, a memory card port, a port for connecting a device having an identification module, an audio input / output (I / O) port, a video I / O port, an earphone port, etc. The interface unit 108 can be used to receive input (e.g., data information, power, etc.) from an external device and to transmit the received input to one or more elements within the mobile terminal 100, or can be used to transmit data between the mobile terminal 100 and the external device. ​

[0059] The memory 109 can be used to store software programs and various data. The memory 109 can mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system, application programs required by at least one function (such as a sound playing function, an image playing function, etc.), and the like; and the data storage area can store data created according to the use of the mobile phone (such as audio data, a phone book, etc.), and the like. In addition, the memory 109 can include a high-speed random access memory, and can also include a non-volatile memory, such as at least one magnetic disk storage device, a flash memory device, or other volatile solid-state memory device.

[0060] The processor 110 is the control center of the mobile terminal, connects all parts of the mobile terminal through various interfaces and lines, executes various functions of the mobile terminal and processes data by running or executing software programs and / or modules stored in the memory 109 and calling data stored in the memory 109, and thus monitors the mobile terminal as a whole. The processor 110 can include one or more processing units; preferably, the processor 110 can integrate an application processor and a modem processor, wherein the application processor mainly processes an operating system, a user interface, and application programs, and the like, and the modem processor mainly processes wireless communication. It can be understood that the above-mentioned modem processor can also not be integrated into the processor 110.

[0061] The mobile terminal 100 can also include a power supply 111 (such as a battery) for supplying power to various components; preferably, the power supply 111 can be logically connected to the processor 110 through a power management system, so as to realize the functions of managing charging, discharging, and power consumption management, and the like through the power management system.

[0062] Although Figure 1 The mobile terminal 100 can also include a Bluetooth module and the like, which are not shown here.

[0063] Based on the above mobile terminal hardware structure, various embodiments of the method of the present application are proposed.

[0064] Figure 2 This is the first flowchart of the personal data service data export method of the present application. The embodiment proposes a personal data service data export method, which is applied to a data access party, and the method includes the following steps:

[0065] S1, sending an application for exporting data and a public key to a personal data service party, and receiving a data key and a file hash salt encrypted according to the public key and sent by the personal data service party;

[0066] S2. When it is found that the data export action of the personal service provider has been completed, the data key decrypted by the private key is sent to the personal data service provider to obtain the download address file of the exported data compressed and encrypted by the personal data service provider;

[0067] S3. Calculate the download address file and the file hash salt using a preset secure hash algorithm, and send the calculated hash value to the personal data service provider, so as to receive the file password sent by the personal data service provider after verifying the hash value.

[0068] S4. Decrypt the download address file according to the file password, and perform a one-time data download according to the decrypted download address within a preset time to obtain an unreadable data file;

[0069] S5. Log in to the software development kit provided by the personal data service provider according to the preset account information, and convert the data file into a readable table file through the software development kit.

[0070] In this embodiment, the application for exporting data is sent to the personal data service provider, including: sending field groups of the data to be exported and query conditions of the corresponding business system to the personal data service provider in batches through a first interface provided by the personal data service provider, so that the personal data service provider combines the field groups and the query conditions to obtain a query statement.

[0071] In this embodiment, converting the data file into a readable table file through the software development kit further includes: adding and embedding watermark information corresponding to the account information into the table file through the software development kit; and setting an independent opening password and editing permission for the table file through the software development kit.

[0072] In this embodiment, the export interface minimizes the number of query statements allowed by the business system. The export interface parameters have been modified to prevent direct query entry by the business system. Instead, the query statement is split into two parts: the field group to be exported by the business system and the query conditions. Upon receiving the interface request, the personal data service combines the field group and query conditions to generate the SQL statement for the query. If the business system specifies a specific amount of data to be exported, the query is executed based on that amount. If not, the export is limited to the most recent period of data, as required by data protection laws.

[0073] In this embodiment, a chained interface verification method is used, with multiple interface calls completing the export function. To further improve security, the personal data service replaces the original single interface call in the export solution with three interface calls, completing the complete export function through chained interface verification. Specifically, the data access party calls the interface to request data export. After verifying the parameter validity, the personal data service generates a data key and file hash salt encrypted with the data access party's public key. Furthermore, the personal data service reads data in pages according to the assembled SQL statements, writing the data to a file after each page is read. Furthermore, the data access party periodically calls the personal data service's second interface to check whether the export action is complete. In this second interface, the data key, decrypted with the private key, must be passed in to obtain the download address of the exported file.

[0074] In this embodiment, the download address of the exported file implements a one-time available mechanism. After the data access party obtains the download address of the file, since the file is compressed and encrypted and cannot be used, it is necessary to call the third interface of the personal data service at this time. The parameter passed in is the hash value of SHA256 (a secure hash algorithm) after adding the hash salt in the second interface to the file content to indicate that it has indeed downloaded the file. Furthermore, after comparing the hash values ​​and finding that they are consistent, the third interface returns the password of the file. Furthermore, after the third interface completes the action of returning the password of the file, it immediately deletes the download address of the file, that is, the download address of the file is only guaranteed to be available once. Furthermore, if the file has not been downloaded within the specified time, the file will also be automatically deleted by the service.

[0075] In this embodiment, a watermark of the user's identification is automatically added to the exported file. Among them, for the data access party, after decrypting the file, it will be found that the file is still unavailable and is not in Excel format. At this time, the data access party needs to use the SDK (Software Development Kit) of the personal data service to generate a readable Excel file based on the current login account information obtained by the service side. Furthermore, when generating Excel, the SDK automatically adds a watermark of the user's account information to the entire document, and the watermark is embedded in the Excel document and cannot be removed. Furthermore, the exported file automatically adds a password and does not allow copying and modification of the content. Specifically, the SDK will modify the document information of Excel, add a password when it is opened, and does not allow copying and modification of the content.

[0076] As can be seen, this embodiment uses a chained interface verification method and modifies the interface parameter structure to implement the export function, enhancing its security. A watermark is also added to the generated Excel file to enhance the security of the exported file. Furthermore, since the download file address is guaranteed to be usable only once and a strong security verification mechanism is in place, the entire export function is guaranteed to be free of security vulnerabilities, effectively meeting the requirements of data protection laws and providing strong support for corporate compliance efforts.

[0077] The beneficial effects of this embodiment are as follows: by sending a data export application and a public key to a personal data service provider, and receiving a data key and a file hash salt encrypted according to the public key from the personal data service provider; when it is queried that the data export action of the personal data service provider has been completed, sending the data key decrypted by the private key to the personal data service provider to obtain a download address file of the exported data compressed and encrypted by the personal data service provider; calculating the download address file and the file hash salt according to a preset secure hash algorithm, and sending the calculated hash value to the personal data service provider to receive a file password sent by the personal data service provider after verifying the hash value; decrypting the download address file according to the file password, and performing a one-time data download according to the decrypted download address within a preset time to obtain an unreadable data file; logging into a software development kit provided by the personal data service provider according to preset account information, and converting the data file into a readable table file through the software development kit. A more secure personal data service data export solution is achieved.

[0078] Figure 3 This is the second flow chart of the method for exporting personal data service data of the present invention. The present invention also proposes a method for exporting personal data service data, which is applied to a personal data service provider, and the method includes:

[0079] S10, receiving the field groups of the data to be exported and the corresponding business system query conditions sent in batches by the data access party, and combining the field groups and the query conditions to obtain a query statement;

[0080] S20. When the query statement passes the validity check, the data key and file hash salt encrypted using the public key provided by the data access party are sent to the data access party, and data is read in pages according to the query statement.

[0081] S30: After the reading is completed, the data key decrypted by the data access party using the private key is received, and after the data key is verified, the compressed and encrypted download address file is sent to the data access party;

[0082] S40: receiving a hash value calculated by the data access party using the file hash salt and the download address file, and when the received hash value is consistent with the local hash value, sending the file password corresponding to the download address file to the data access party;

[0083] S50. A preset software development kit is provided to the data access party, so that the data access party decrypts the download address file according to the file password, performs a one-time data download according to the decrypted download address within a preset time, and after obtaining an unreadable data file, logs in to the software development kit according to preset account information, and converts the data file into a readable table file through the software development kit.

[0084] In this embodiment, the receiving of the field groups of the data to be exported and the query conditions of the corresponding business system sent in batches by the data access party further includes: receiving the field groups and the query conditions sent by the data access party in batches through a preset first interface.

[0085] In this embodiment, the paging reading of data according to the query statement further includes: writing the data of one page into an unreadable data file after each page of data is read; and receiving a query instruction sent by the data access party through a preset second interface to determine whether the data export action has been completed.

[0086] In this embodiment, sending the file password corresponding to the download address file to the data access party further includes: sending the file password to the data access party through a preset third interface; after the file password is sent, deleting the download address file.

[0087] In this embodiment, deleting the download address file after the file password is sent further includes: monitoring the data download action within a preset time period; deleting the data file when the download action is not detected within the time period, or when the download action is detected for the second time within the time period.

[0088] In this embodiment, the export interface minimizes the number of query statements allowed by the business system. The export interface parameters have been modified to prevent direct query entry by the business system. Instead, the query statement is split into two parts: the field group to be exported by the business system and the query conditions. Upon receiving the interface request, the personal data service combines the field group and query conditions to generate the SQL statement for the query. If the business system specifies a specific amount of data to be exported, the query is executed based on that amount. If not, the export is limited to the most recent period of data, as required by data protection laws.

[0089] In this embodiment, a chained interface verification method is used, with multiple interface calls completing the export function. To further improve security, the personal data service replaces the original single interface call in the export solution with three interface calls, completing the complete export function through chained interface verification. Specifically, the data access party calls the interface to request data export. After verifying the parameter validity, the personal data service generates a data key and file hash salt encrypted with the data access party's public key. Furthermore, the personal data service reads data in pages according to the assembled SQL statements, writing the data to a file after each page is read. Furthermore, the data access party periodically calls the personal data service's second interface to check whether the export action is complete. In this second interface, the data key, decrypted with the private key, must be passed in to obtain the download address of the exported file.

[0090] In this embodiment, the download address of the exported file implements a one-time available mechanism. After the data access party obtains the download address of the file, since the file is compressed and encrypted and cannot be used, it is necessary to call the third interface of the personal data service at this time. The parameter passed in is the hash value of SHA256 (a secure hash algorithm) after adding the hash salt in the second interface to the file content to indicate that it has indeed downloaded the file. Furthermore, after comparing the hash values ​​and finding that they are consistent, the third interface returns the password of the file. Furthermore, after the third interface completes the action of returning the password of the file, it immediately deletes the download address of the file, that is, the download address of the file is only guaranteed to be available once. Furthermore, if the file has not been downloaded within the specified time, the file will also be automatically deleted by the service.

[0091] In this embodiment, a watermark of the user's identification is automatically added to the exported file. Among them, for the data access party, after decrypting the file, it will be found that the file is still unavailable and is not in Excel format. At this time, the data access party needs to use the SDK (Software Development Kit) of the personal data service to generate a readable Excel file based on the current login account information obtained by the service side. Furthermore, when generating Excel, the SDK automatically adds a watermark of the user's account information to the entire document, and the watermark is embedded in the Excel document and cannot be removed. Furthermore, the exported file automatically adds a password and does not allow copying and modification of the content. Specifically, the SDK will modify the document information of Excel, add a password when it is opened, and does not allow copying and modification of the content.

[0092] As can be seen, this embodiment uses a chained interface verification method and modifies the interface parameter structure to implement the export function, enhancing its security. A watermark is also added to the generated Excel file to enhance the security of the exported file. Furthermore, since the download file address is guaranteed to be usable only once and a strong security verification mechanism is in place, the entire export function is guaranteed to be free of security vulnerabilities, effectively meeting the requirements of data protection laws and providing strong support for corporate compliance efforts.

[0093] The beneficial effect of this embodiment is that, by receiving the field group of the data to be exported and the query conditions of the corresponding business system sent in batches by the data access party, and combining the field group and the query conditions, a query statement is obtained; when the legitimacy check of the query statement is passed, the data key and file hash salt obtained by encrypting with the public key provided by the data access party are sent to the data access party, and the data is read in pages according to the query statement; when the reading is completed, the data key decrypted by the private key of the data access party is received, and when the data key is verified, the compressed and encrypted download address file is sent to the data access party. Receive a hash value calculated by the data access party using the file hash salt and the download address file, and when the received hash value is consistent with the local hash value, send the file password corresponding to the download address file to the data access party; provide the data access party with a preset software development kit, so that the data access party can decrypt the download address file according to the file password, and perform a one-time data download according to the decrypted download address within a preset time. After obtaining the unreadable data file, the data access party logs in to the software development kit according to the preset account information, and converts the data file into a readable table file through the software development kit. A more secure personal data service data export solution is achieved.

[0094] Based on the above embodiments, the application further proposes a personal data service data export device, comprising a memory, a processor and a computer program stored on the memory and executable on the processor, the computer program being executed by the processor to implement the steps of the personal data service data export method according to any one of the above.

[0095] It should be noted that the above device embodiments and method embodiments belong to the same concept, and the specific implementation process is detailed in the method embodiments, and the technical features in the method embodiments are all applicable to the device embodiments, which will not be described here.

[0096] Based on the above embodiments, the application further proposes a computer readable storage medium, the computer readable storage medium storing a personal data service data export program, the personal data service data export program being executed by a processor to implement the steps of the personal data service data export method according to any one of the above.

[0097] It should be noted that the above medium embodiments and method embodiments belong to the same concept, and the specific implementation process is detailed in the method embodiments, and the technical features in the method embodiments are all applicable to the medium embodiments, which will not be described here.

[0098] It should be noted that in this document, the term "comprising" or "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such a process, method, article or device. Without more limitations, the element defined by the statement "comprising a" does not exclude the presence of additional identical elements in the process, method, article or device including the element.

[0099] The above embodiment numbers of the application are only for description, and do not represent the advantages and disadvantages of the embodiments.

[0100] Through the description of the above embodiments, those skilled in the art can clearly understand that the above embodiment methods can be realized by software plus a general hardware platform, of course, they can also be realized by hardware, but in many cases the former is a better embodiment. Based on such understanding, the technical solutions of the application can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes a plurality of instructions for making a terminal (which can be a mobile phone, computer, server, air conditioner or network device) execute the methods described in the embodiments of the application.

[0101] The embodiments of the present invention are described above in conjunction with the accompanying drawings, but the present invention is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of the present invention, ordinary technicians in this field can also make many forms without departing from the scope of protection of the present invention and the claims, all of which are protected by the present invention.

Claims

1. A method for exporting personal data service data, applied to a data access party, characterized in that: The method comprises: Sending a request for exporting data and a public key to a personal data service provider, and receiving a data key and a file hash salt encrypted using the public key from the personal data service provider; When it is found that the data export action of the personal data service provider has been completed, the data key decrypted by the private key is sent to the personal data service provider to obtain the download address file of the exported data compressed and encrypted by the personal data service provider; Calculate the download address file and the file hash salt according to a preset secure hash algorithm, and send the calculated hash value to the personal data service provider to receive the file password sent by the personal data service provider after verifying the hash value; Decrypt the download address file according to the file password, and perform a one-time data download according to the decrypted download address within a preset time to obtain an unreadable data file; Log in to the software development kit provided by the personal data service provider according to the preset account information, and convert the data file into a readable table file through the software development kit.

2. The method for exporting personal data service data according to claim 1, characterized in that: The application for exporting data to the personal data service provider includes: The field groups of the data to be exported and the corresponding business system query conditions are sent to the personal data service provider in batches through the first interface provided by the personal data service provider, so that the personal data service provider combines the field groups and the query conditions to obtain a query statement.

3. The method for exporting personal data service data according to claim 1, characterized in that: The step of converting the data file into a readable table file by the software development kit further comprises: Adding and embedding watermark information corresponding to the account information into the table file through the software development kit; Furthermore, an independent opening password and editing authority are set for the table file through the software development kit.

4. A method for exporting personal data service data, applied to a personal data service provider, characterized in that: The method comprises: Receive the field groups of the data to be exported and the corresponding business system query conditions sent in batches by the data access party, and combine the field groups and the query conditions to obtain a query statement; When the query statement passes the legality check, the data key and file hash salt obtained by encrypting the public key provided by the data access party are sent to the data access party, and the data is read in pages according to the query statement; After the reading is completed, the data key decrypted by the data access party using the private key is received, and after the data key is verified, the compressed and encrypted download address file is sent to the data access party; Receiving a hash value calculated by the data access party using the file hash salt and the download address file, and when the received hash value is consistent with the local hash value, sending a file password corresponding to the download address file to the data access party; A preset software development kit is provided to the data access party, so that the data access party decrypts the download address file according to the file password, performs a one-time data download according to the decrypted download address within a preset time, and after obtaining an unreadable data file, logs in to the software development kit according to preset account information, and converts the data file into a readable table file through the software development kit.

5. The method for exporting personal data service data according to claim 4, characterized in that: The receiving of the field groups of the data to be exported and the corresponding query conditions of the business system sent in batches by the data access party further includes: The field groups and the query conditions sent by the data access party are received in batches through a preset first interface.

6. The method for exporting personal data service data according to claim 4, characterized in that: The paging reading of data according to the query statement further includes: After reading each page of data, the data of the page is written into an unreadable data file; Furthermore, a query instruction sent by the data access party is received through a preset second interface to determine whether the data export action has been completed.

7. The method for exporting personal data service data according to claim 4, characterized in that: The sending of the file password corresponding to the download address file to the data access party further includes: Sending the file password to the data access party through a preset third interface; After the file password is sent, the download address file is deleted.

8. The method for exporting personal data service data according to claim 7, characterized in that: After the file password is sent, deleting the download address file further includes: Monitor data downloading actions within a preset time period; When the downloading action is not detected within the time period, or when the downloading action is detected for the second time within the time period, the data file is deleted.

9. A personal data service data export device, characterized in that: The device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the computer program is executed by the processor, the steps of the personal data service data export method according to any one of claims 1 to 8 are implemented.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a personal data service data export program, which, when executed by a processor, implements the steps of the personal data service data export method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Offline package verification method and device, equipment and storage medium

    CN114218534A

  • Encrypted data fuzzy query method and device and electronic equipment

    CN117539927A