Information sending method, device, electronic device and computer readable medium

By performing permission control, data isolation and encryption processing on business log data, digital summary information is generated, and users are accessed and verified, security and credibility issues are solved during the information sending process, and the security and credibility of information access are improved.

CN118779911BActive Publication Date: 2025-08-15PARK DO CREDIT CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202410871117.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-01
Publication Date
2025-08-15
Estimated Expiration
2044-07-01

AI Technical Summary

Technical Problem

In the prior art, there are problems such as missing information, modification, leakage and low security of business log data during information transmission, resulting in poor security and credibility of information access.

Method used

By performing permission control, data isolation and encryption processing on business log data, digital summary information is generated and access verification is performed on users, ensuring the integrity and security of the information during transmission.

Benefits of technology

It improves the security and credibility of information access, reduces the possibility of information missing and tampering, and enhances the user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118779911B_ABST
    Figure CN118779911B_ABST
Patent Text Reader

Abstract

The embodiments of the present disclosure disclose an information sending method, device, electronic device and computer-readable medium. A specific implementation of the method includes: obtaining business log data, wherein the business log data is the business log data corresponding to the log storage server in the application information; performing permission control on the log storage server corresponding to the business log data to obtain a server permission control result; in response to determining that the server permission control result indicates that the server permission control is successful, performing permission control on the database corresponding to the business log data to obtain a database permission control result; in response to determining that the verification result indicates that the verification is passed, sending digital summary information to the user's corresponding device end for the user to perform a call operation. This implementation improves the security of information access and improves the credibility of access information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present disclosure relate to the field of computer technology, and more particularly to an information sending method, device, electronic device, and computer-readable medium. Background Art

[0002] With the rapid development of the information age, the application of information transmission is becoming increasingly widespread. Sending processed information to users generally requires verification. Information transmission is a technology that delivers information to users and can improve the security of information access. Furthermore, secure verification of user permissions when accessing digital summary information can also improve information access security. Furthermore, generating summary information for log data can also enhance data security. Currently, information transmission typically involves manual control and verification of information access rights before sending the processed information to the user.

[0003] However, when the above method is adopted, the following technical problems often occur:

[0004] First, manual control and verification of information can result in information loss, making access to it less secure. Information can be modified during transmission, leading to insufficient integrity and poor reliability.

[0005] Second, since the user's access rights are not securely verified, information leakage may occur when the user calls the digital summary information, and information call errors may also occur due to incorrect access rights, resulting in low security of information access.

[0006] Third, because the business log data is not protected, it may be tampered with or deleted, resulting in low security of the business log data. When verifying the business log data, verification errors may occur, resulting in low data security.

[0007] The above information disclosed in this Background section is only for enhancement of understanding of the background of the inventive concept and therefore it may contain information that does not form the prior art that is already known in this country to a person of ordinary skill in the art. Summary of the Invention

[0008] The content of this disclosure is used to briefly introduce concepts that will be described in detail in the detailed description section below. The content of this disclosure is not intended to identify key features or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.

[0009] Some embodiments of the present disclosure propose information sending methods, devices, electronic devices, and computer-readable media to solve one or more of the technical problems mentioned in the above background technology section.

[0010] In a first aspect, some embodiments of the present disclosure provide an information sending method, the method comprising: obtaining business log data, wherein the business log data is the business log data corresponding to the log storage server in the application information; performing permission control on the log storage server corresponding to the business log data to obtain a server permission control result; in response to determining that the server permission control result indicates that the server permission control is successful, performing permission control on the database corresponding to the business log data to obtain a database permission control result; in response to determining that the database permission control result indicates that the database permission control is successful, performing data isolation on the business log data to obtain isolated business log data, wherein the location partition of the isolated business log data and the business log data in the log storage server in the application information is different; performing encryption processing on the isolated business log data to obtain encrypted business log data; generating digital summary information based on the encrypted business log data; in response to determining that a user accesses the digital summary information, performing access information verification on the user information corresponding to the user to obtain a verification result; in response to determining that the verification result indicates that the verification is passed, sending the digital summary information to the device corresponding to the user for the user to perform a call operation.

[0011] In a second aspect, some embodiments of the present disclosure provide an information sending device, the device comprising: an acquisition unit, configured to acquire business log data, wherein the business log data is the business log data corresponding to the log storage server in the application information; a first permission control unit, configured to perform permission control on the log storage server corresponding to the business log data, and obtain a server permission control result; a second permission control unit, configured to perform permission control on the database corresponding to the business log data in response to determining that the server permission control result indicates that the server permission control is successful, and obtain a database permission control result; a data isolation unit, configured to perform permission control on the business log data in response to determining that the database permission control result indicates that the database permission control is successful. Perform data isolation to obtain isolated business log data, wherein the above-mentioned isolated business log data and the above-mentioned business log data are in a different location partition of the log storage server in the above-mentioned application information; an encryption processing unit is configured to perform encryption processing on the above-mentioned isolated business log data to obtain encrypted business log data; a generation unit is configured to generate digital summary information based on the above-mentioned encrypted business log data; a verification unit is configured to, in response to determining that the user accesses the above-mentioned digital summary information, perform access information verification on the user information corresponding to the above-mentioned user to obtain a verification result; a sending unit is configured to, in response to determining that the above-mentioned verification result indicates that the verification is passed, send the above-mentioned digital summary information to the device corresponding to the above-mentioned user for the above-mentioned user to perform a call operation.

[0012] In a third aspect, some embodiments of the present disclosure provide an electronic device comprising: one or more processors; a storage device on which one or more programs are stored, and when the one or more programs are executed by one or more processors, the one or more processors implement the method described in any implementation of the first aspect above.

[0013] In a fourth aspect, some embodiments of the present disclosure provide a computer-readable medium having a computer program stored thereon, wherein when the program is executed by a processor, the method described in any implementation of the first aspect is implemented.

[0014] The above-described embodiments of the present disclosure have the following beneficial effects: Through the information transmission methods of some embodiments of the present disclosure, the security of information access and the reliability of accessed information are improved. Specifically, the low security of information access and the low reliability of accessed information are caused by: manual control and verification of information may result in information loss, resulting in low security of information access. Because information may be modified during transmission, this may lead to insufficient information integrity and low reliability of accessed information. Based on this, the information transmission methods of some embodiments of the present disclosure first obtain business log data, where the business log data corresponds to the log storage server in the application information. This allows the acquisition of business log data to facilitate subsequent processing. Then, permission control is performed on the log storage server corresponding to the business log data to obtain a server permission control result. This reduces the possibility of information loss and improves the security of information access. Subsequently, in response to determining that the server permission control result indicates that the server permission control is successful, permission control is performed on the database corresponding to the business log data to obtain a database permission control result. This reduces the possibility of information loss and improves the security of information access. Then, in response to determining that the database permission control result indicates successful database permission control, the business log data is isolated to obtain isolated business log data. The isolated business log data and the business log data are located in a different location partition on the log storage server in the application information. Data isolation reduces the likelihood of information modification during transmission, thereby improving information integrity and enhancing the credibility of access information. The isolated business log data is then encrypted to obtain encrypted business log data. This improves the security of the isolated business log data. Next, digital summary information is generated based on the encrypted business log data. This improves the credibility of the information corresponding to the encrypted business log data. Furthermore, in response to determining that the user has accessed the digital summary information, access information verification is performed on the user information corresponding to the user to obtain a verification result. This improves the credibility of the access information. In response to determining that the verification result indicates successful verification, the digital summary information is sent to the device corresponding to the user for the user to access. This improves the user experience. Therefore, the security of information access is improved and the credibility of access information is enhanced. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] The above and other features, advantages, and aspects of the various embodiments of the present disclosure will become more apparent with reference to the following detailed description in conjunction with the accompanying drawings. Throughout the drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic and that components and elements are not necessarily drawn to scale.

[0016] Figure 1 is a flow chart of some embodiments of the information sending method according to the present disclosure;

[0017] Figure 2 is a schematic structural diagram of some embodiments of the information sending device according to the present disclosure;

[0018] Figure 3 It is a structural diagram of an electronic device suitable for implementing some embodiments of the present disclosure. DETAILED DESCRIPTION

[0019] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as being limited to the embodiments described herein. On the contrary, these embodiments are provided to provide a more thorough and complete understanding of the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are for illustrative purposes only and are not intended to limit the scope of protection of the present disclosure.

[0020] It should also be noted that, for ease of description, only the parts related to the invention are shown in the drawings. In the absence of conflict, the embodiments and features in the embodiments of the present disclosure may be combined with each other.

[0021] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.

[0022] It should be noted that the modifications of "one" and "multiple" mentioned in the present disclosure are illustrative rather than restrictive, and those skilled in the art should understand that unless otherwise clearly indicated in the context, they should be understood as "one or more".

[0023] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only used for illustrative purposes and are not used to limit the scope of these messages or information.

[0024] The present disclosure will be described in detail below with reference to the accompanying drawings and in conjunction with embodiments.

[0025] Figure 1 This is a process 100 of some embodiments of the information sending method of the present disclosure. The information sending method includes the following steps:

[0026] Step 101: Obtain business log data.

[0027] In some embodiments, the execution subject of the information sending method (for example, a computing device) can obtain business log data through a wired connection or a wireless connection, wherein the above-mentioned business log data is the business log data corresponding to the log storage server in the application information.

[0028] Here, the business log data may refer to the log data recorded during the execution of the log storage server in the application information. The application information may refer to software application (App) information. The log storage server may refer to a server for storing log data.

[0029] It should be noted that the above-mentioned wireless connection methods may include but are not limited to 3G / 4G connection, WiFi connection, Bluetooth connection, WiMAX connection, Zigbee connection, UWB (ultra wideband) connection, and other wireless connection methods currently known or to be developed in the future.

[0030] Step 102: Perform authority control on the log storage server corresponding to the business log data to obtain a server authority control result.

[0031] In some embodiments, the execution entity may perform authority control on the log storage server corresponding to the business log data to obtain a server authority control result.

[0032] Here, the above server authority control result can represent server authority control success or server authority control failure.

[0033] As an example, the execution subject may determine the read and write permissions of the log storage server corresponding to the business log data to obtain server read and write permission information, and then modify the server read and write permission information to obtain a modified permission result as the server permission control result.

[0034] Optionally, the execution entity may perform permission control on the log storage server corresponding to the business log data through the following steps to obtain a server permission control result:

[0035] The first step is to determine the read and write permission information corresponding to the above log storage server.

[0036] Here, the above-mentioned read and write permission information may refer to permission information for performing read operations and write operations on the log storage server.

[0037] The second step is to perform permission verification on the above read and write permission information to obtain the permission verification result.

[0038] Here, the above permission verification result can represent permission verification passed or permission verification failed.

[0039] As an example, the execution entity may perform permission verification on the read and write permission information through OpenID Connect to obtain a permission verification result.

[0040] In the third step, in response to determining that the above-mentioned permission verification result indicates that the verification is passed, read and write permission control is performed on the above-mentioned log storage server to obtain a server permission control result, wherein the above-mentioned server permission control result indicates the result after the read and write permission control corresponding to the server is successful.

[0041] As an example, the execution subject may determine the read and write permissions of the log storage server to obtain determined server read and write permission information, and then modify the determined server read and write permission information to obtain a modified server permission result as the server permission control result.

[0042] Step 103 : In response to determining that the server authority control result indicates that the server authority control is successful, authority control is performed on the database corresponding to the business log data to obtain a database authority control result.

[0043] In some embodiments, in response to determining that the server authority control result indicates that the server authority control is successful, the execution entity may perform authority control on the database corresponding to the business log data to obtain a database authority control result.

[0044] Here, the database authority control result can represent the success of the database authority control and the failure of the database authority control. The above authority control can refer to access authority control.

[0045] Optionally, the execution entity may perform permission control on the database corresponding to the business log data through the following steps to obtain a database permission control result:

[0046] The first step is to verify the access rights of the database corresponding to the above business log data and obtain the access rights verification result.

[0047] Here, the access permission verification result may represent whether the access permission verification is passed or not.

[0048] As an example, the execution entity may first determine the access rights of the database corresponding to the business log data, and then verify the access rights to obtain an access rights verification result.

[0049] In the second step, in response to determining that the access permission verification result indicates that the access permission verification is passed, the user's access permission is verified to obtain a user access permission verification result.

[0050] In the third step, in response to determining that the user access authority verification result indicates that the user access authority verification is passed, the user is matched with the user authority stored in the database corresponding to the business log data to obtain a matching result.

[0051] Here, the above matching results can represent consistent matching and inconsistent matching.

[0052] As an example, the execution entity may compare the user with the user rights stored in the database corresponding to the business log data, and obtain a comparison result as a matching result. The correlation comparison may refer to comparing user information with user rights.

[0053] In the fourth step, in response to determining that the above matching result indicates a matching inconsistency, the access permission of the database corresponding to the above business log data is isolated, and the database permission result after isolation is obtained as the database permission control result.

[0054] As an example, the execution entity may isolate the access rights of the database corresponding to the business log data, and obtain the isolated database permission result as the database permission control result. The isolation may refer to isolation from other access rights.

[0055] In the fifth step, in response to determining that the above matching result indicates a consistent match, the access permission of the database corresponding to the above business log data is encrypted to obtain the encrypted database permission result as the database permission control result.

[0056] As an example, the execution entity may use an AES (Advanced Encryption Standard) encryption algorithm to encrypt the access rights of the database corresponding to the business log data, and obtain an encrypted database permission result as a database permission control result.

[0057] Step 104 : In response to determining that the database authority control result indicates that the database authority control is successful, data isolation is performed on the business log data to obtain isolated business log data.

[0058] In some embodiments, the above-mentioned execution entity may, in response to determining that the above-mentioned database permission control result indicates that the database permission control is successful, perform data isolation on the above-mentioned business log data to obtain isolated business log data, wherein the above-mentioned isolated business log data and the above-mentioned business log data have a different location partition in the log storage server in the above-mentioned application information.

[0059] As an example, the execution entity may perform location partition transformation on the business log data to obtain transformed business log data, and then encrypt the transformed business log data to obtain encrypted business log data as isolated business log data.

[0060] Step 105: encrypt the isolated business log data to obtain encrypted business log data.

[0061] In some embodiments, the execution entity may encrypt the isolated business log data to obtain encrypted business log data.

[0062] As an example, the execution entity may encrypt the isolated business log data using an Advanced Encryption Standard (AES) encryption algorithm to obtain encrypted business log data.

[0063] Optionally, the execution entity may encrypt the isolated business log data through the following steps to obtain encrypted business log data:

[0064] The first step is to clean the above-mentioned isolated business log data to obtain the cleaned log data.

[0065] Here, the above-mentioned data-cleaned log data may refer to the data-cleaned log data obtained by removing duplicate log data from the above-mentioned isolated business log data.

[0066] The second step is to divide the log data after the data cleaning into blocks to obtain at least one log data block information.

[0067] As an example, the execution entity may divide the cleaned log data into preset blocks to obtain at least one divided log data block information as at least one log data block information. The preset blocks may be 10 blocks.

[0068] In the third step, a key is generated for each log data block information in the at least one log data block information to generate log data block key information and obtain a log data block key information set.

[0069] The fourth step is to perform user access information detection on the above-mentioned log data block key information set to obtain a user behavior detection result set, wherein the user behavior detection results in the above-mentioned user behavior detection result set represent normal user behavior detection results and abnormal user behavior detection results.

[0070] As an example, the execution entity may detect the user access information corresponding to the log data block key information set to obtain a user behavior detection result set.

[0071] In the fifth step, in response to determining that the user behavior detection results in the above-mentioned user behavior detection result set represent the abnormal user behavior detection results, the log data block key information set corresponding to the abnormal user behavior detection is filtered to obtain a filtered log data block key information set, wherein the above-mentioned filtered log data block key information set is the filtered log data block key information set after the user behavior detection results corresponding to the abnormal user behavior detection results are removed from the above-mentioned user behavior detection result set.

[0072] In step 6, in response to determining that the user has accessed the isolated business log data, the filtered log data block key information set is decrypted to obtain a decrypted log data block key information set.

[0073] As an example, the execution entity may decrypt the filtered log data block key information set through Burp Suite to obtain a decrypted log data block key information set.

[0074] In the seventh step, in response to determining that the user has ended accessing the above-mentioned isolated business log data, the above-mentioned decrypted log data block key information set is encrypted to obtain encrypted business log data.

[0075] As an example, the execution entity may encrypt the decrypted log data block key information set using an AES (Advanced Encryption Standard) encryption algorithm to obtain encrypted business log data.

[0076] Step 106: Generate digital summary information based on the encrypted business log data.

[0077] In some embodiments, the execution entity may generate digital summary information based on the encrypted business log data.

[0078] Here, the digital summary information may refer to information with a fixed length corresponding to the encrypted service log data, and the fixed length may refer to 128 bits.

[0079] As an example, the execution entity may first use a hash function to divide the encrypted business log data into a preset length to obtain the divided log data information. Then, the divided log data information may be encrypted using an AES (Advanced Encryption Standard) encryption algorithm to obtain the encrypted log data information. Finally, the encrypted log data information may be digitally signed to obtain the signed log data information as digital summary information. The preset length may refer to a pre-set length. For example, the preset length may refer to 128 bits.

[0080] Optionally, the execution entity may generate digital summary information based on the encrypted business log data through the following steps:

[0081] The first step is to extract key information from the encrypted business log data to obtain the extracted key information.

[0082] Here, the key information may include but is not limited to at least one of the following: timestamp information, operation type information, and user identity information.

[0083] As an example, the execution subject may perform data preprocessing on the encrypted business log data to obtain processed log data, and then determine key information on the processed log data to obtain key information as extracted key information.

[0084] The second step is to perform format conversion on the extracted key information to obtain format-converted key information.

[0085] As an example, the execution subject may perform format conversion on the extracted key information by binary conversion to obtain format-converted key information. The format-converted key information may refer to key information converted into a binary format.

[0086] The third step is to divide the key information after the above format conversion into block information of the same byte length to obtain a block information set.

[0087] Here, the block information with the same byte length may refer to block information with a byte length of 8 bits. For example, the key information after the format conversion may be 1011001100110011, and the block information with the same byte length may refer to: "Block 1: 10110011, Block 2: 00110011".

[0088] As an example, the execution entity may divide the format-converted key information according to a preset byte length to obtain a divided key information set as a block information set. Here, the preset byte length may refer to a pre-set byte length. For example, the preset byte length may refer to 8 bits.

[0089] The fourth step is to generate a hash value for each block information in the block information set to generate a block information hash value and obtain a block information hash value set.

[0090] Here, the block information hash value in the block information hash value set may refer to H1 = "Hello, World!" The block information hash value set may include but is not limited to at least one of the following: H1, H2, H3.

[0091] As an example, the execution entity may generate a hash value for each block information in the block information set using SHA-256 to generate a block information hash value and obtain a block information hash value set.

[0092] The fifth step is to perform hash value concatenation on each block information hash value in the block information hash value set to obtain a character string corresponding to the concatenated first hash values.

[0093] Here, the character string corresponding to the concatenation of the first hash values may be H4=H1H2H3.

[0094] As an example, the execution entity may concatenate hash values corresponding to the respective block information hash values in the block information hash value set to obtain a string corresponding to the concatenated first hash values as the string corresponding to the concatenated first hash values.

[0095] Step 6: Generate a hash value for the string corresponding to the concatenated first hash value to obtain a hash value corresponding to the first string.

[0096] As an example, the execution entity may use SHA-256 to generate a hash value for the string corresponding to the concatenation of the first hash value to obtain a hash value corresponding to the first string.

[0097] In the seventh step, the hash value corresponding to the first character string is hashed together with each block information hash value in the block information hash value set to obtain a character string corresponding to the second hash value concatenation.

[0098] Here, the character string corresponding to the concatenation of the second hash values may be H5=H1H2H3H4.

[0099] As an example, the execution entity may concatenate the hash value corresponding to the first string with the hash values corresponding to the block information hash values in the block information hash value set to obtain a string corresponding to the concatenated second hash value as the string corresponding to the second hash value connection.

[0100] In the eighth step, a hash value is generated for the character string corresponding to the concatenated second hash value to obtain a hash value corresponding to the second character string.

[0101] As an example, the execution entity may use SHA-256 to generate a hash value for the string corresponding to the concatenated second hash value to obtain a hash value corresponding to the second string.

[0102] In step 9, in response to determining that the hash value length corresponding to the hash value corresponding to the second character string is greater than or equal to the preset hash value length, additional data is added to the hash value corresponding to the second character string to obtain a character string after the additional data is added.

[0103] Here, the preset hash value length may refer to a length corresponding to a preset hash value. For example, the preset hash value length may refer to 128 bits. The additional data may refer to timestamp data.

[0104] As an example, the execution entity may add the timestamp data corresponding to the hash value corresponding to the second character string to obtain an added character string, and use the added character string as the additional data.

[0105] In the tenth step, a hash value is generated for the string after the additional data is added, and a hash value corresponding to the third string is obtained.

[0106] As an example, the execution entity may use SHA-256 to generate a hash value for the string after the additional data is added, to obtain a hash value corresponding to the third string.

[0107] In the eleventh step, digitally sign the hash value corresponding to the third character string to obtain the signed hash value.

[0108] As an example, the execution entity may use digital signature technology to digitally sign the hash value corresponding to the third character string to obtain a signed hash value.

[0109] In the twelfth step, the above-mentioned signed hash value is concatenated with the above-mentioned character string after the additional data is added to obtain the concatenated information as the digital summary information.

[0110] The relevant content in the above-mentioned first to twelfth steps serves as an inventive point of the present disclosure, which solves the third technical problem mentioned in the background technology: "Since the business log data is not securely protected, the business log data may be tampered with or deleted, resulting in low security of the business log data. When the business log data is verified, verification errors may occur, resulting in low data security." The factors that lead to low data security are often as follows: Since the business log data is not securely protected, the business log data may be tampered with or deleted, resulting in low security of the business log data. When the business log data is verified, verification errors may occur, resulting in low data security. If the above factors are solved, the effect of improving data security can be achieved. In order to achieve this effect, encrypting the business data can improve security. Generating a hash value for the extracted key information can ensure that the data has not been tampered with during transmission. Digitally signing the hash value can improve the credibility of the data, thereby improving the security of the data.

[0111] Step 107 : In response to determining that the user has accessed the digital summary information, access information verification is performed on the user information corresponding to the user to obtain a verification result.

[0112] In some embodiments, the execution entity may, in response to determining that the user has accessed the digital summary information, perform access information verification on the user information corresponding to the user to obtain a verification result.

[0113] Here, the access information may include but is not limited to at least one of the following: visitor identity information, access time information, and access result information. The verification result may indicate whether the verification is passed or not.

[0114] As an example, the execution entity may verify the access information corresponding to the user information of the user and obtain a verification result.

[0115] Optionally, the execution entity may perform access information verification on the user information corresponding to the user through the following steps to obtain a verification result:

[0116] The first step is to verify the access time information of the user information corresponding to the above user and obtain the access time verification result.

[0117] As an example, the execution entity may verify the access time information corresponding to the user information of the user to obtain an access time verification result, which may indicate whether the access time verification is normal or abnormal.

[0118] In the second step, in response to determining that the access time verification result indicates that the access time verification is normal, the access identity information of the user corresponding to the user information is verified to obtain the access identity information verification result.

[0119] As an example, the execution entity may verify the access identity information corresponding to the user information of the user to obtain a verification result of the access identity information. The verification result of the access identity information may indicate whether the access identity information verification is normal or abnormal.

[0120] In the third step, in response to determining that the access identity information verification result indicates that the access identity information verification is successful, the access result information is verified on the user information corresponding to the user, and a verification result of the access result information is obtained as the verification result.

[0121] As an example, the execution entity may verify the access result information corresponding to the user information of the user to obtain a verification result of the access result information. The verification result of the access result information may indicate whether the access result information verification is normal or abnormal.

[0122] Step 108 : In response to determining that the verification result indicates that the verification is successful, the digital summary information is sent to the device corresponding to the user for the user to perform a call operation.

[0123] In some embodiments, the execution entity may, in response to determining that the verification result indicates that the verification is passed, send the digital summary information to the device corresponding to the user for the user to perform a call operation.

[0124] Here, the above-mentioned user corresponding device end may refer to the user's corresponding mobile phone end.

[0125] Optionally, after the above “step 108”, the above method further includes:

[0126] The first step is to obtain user identification information in response to determining that the user calls the digital summary information.

[0127] Here, the user identification information may refer to the user's identification information. For example, the user identification information may include but is not limited to at least one of the following: user name information, user geographic location information, and user email address information.

[0128] The second step is to compare the above user identification information with the user authority database to obtain a comparison result.

[0129] Here, the user rights database may refer to a database that stores user rights. For example, the user rights database may include but is not limited to at least one of the following: user name information, user role information.

[0130] As an example, the execution entity may compare the user identification information with the corresponding user information in the user rights database to obtain a comparison result, which may indicate consistency or inconsistency.

[0131] In a third step, in response to determining that the comparison result indicates a consistency, access token information and access key pair information are generated according to the user identification information.

[0132] Here, the access token information may refer to token information used for identity authentication. For example, the access token information may include, but is not limited to, at least one of the following: token value information, token type information, and user identification information. The access key pair information may refer to the public and private key information used for encryption, decryption, and authentication during the access process.

[0133] As an example, the execution entity may authenticate the user identification information to obtain an authentication result. Then, in response to determining that the authentication result indicates successful authentication, access token information is created. Next, a validity period is set for the access token information to obtain valid token information. Next, a random number generator is used to create key pair information. Next, the key pair information and the valid token information are stored and encrypted to obtain encrypted key pair information as the access key pair information.

[0134] The fourth step is to authenticate the user corresponding to the above user identification information and obtain a verification result.

[0135] In step 5, in response to determining that the verification result indicates that the verification is passed, the access token information and the access key pair information are encrypted to obtain encrypted access token information and encrypted access key pair information.

[0136] As an example, the execution entity may utilize an AES (Advanced Encryption Standard) encryption algorithm to encrypt the access token information and the access key pair information to obtain encrypted access token information and encrypted access key pair information.

[0137] Step 6: encrypt the digital summary information to obtain encrypted digital summary information.

[0138] As an example, the execution entity may encrypt the digital summary information using an AES (Advanced Encryption Standard) encryption algorithm to obtain encrypted digital summary information.

[0139] In the seventh step, zero-knowledge verification is performed on the access right corresponding to the encrypted digital summary information to obtain a result of access right verification, wherein the result of access right verification can represent whether the access right is passed or not.

[0140] Here, the above-mentioned zero-knowledge verification may refer to zero-knowledge proof.

[0141] In the eighth step, in response to determining that the access permission certification result indicates that the access permission is granted, context information access control is performed on the encrypted digital summary information to obtain context information access controlled information.

[0142] As an example, the execution subject may determine the context information of the encrypted digital summary information to obtain the context information, and then perform access control on the access information corresponding to the context information to obtain context information access-controlled information.

[0143] In the ninth step, fine-grained access control is performed on the above context information after access control to obtain the controlled digital summary information.

[0144] In the tenth step, the controlled digital summary information is quantum encrypted according to the encrypted access token information and the encrypted access key pair information to obtain the encrypted digital summary information.

[0145] The relevant content of steps 1-10 described above, as an inventive feature of this disclosure, addresses the second technical problem mentioned in the background art: "The lack of security verification of user access rights may result in information leakage when the user accesses the digital summary information, or information access errors may occur due to incorrect access rights, resulting in low information access security." Factors that contribute to low information access security are often as follows: The lack of security verification of user access rights may result in information leakage when the user accesses the digital summary information, or information access errors may occur due to incorrect access rights, resulting in low information access security. If these factors are resolved, the security of information access can be improved. To achieve this, in step 1, in response to determining that the user has accessed the digital summary information, user identification information is obtained. In step 2, the user identification information is compared with a user rights database to obtain a comparison result. In step 3, in response to determining that the comparison result indicates a match, an access token and an access key pair are generated based on the user identification information. In step 4, the user corresponding to the user identification information is authenticated to obtain a verification result. Step 5: In response to determining that the verification result indicates verification is successful, the access token information and the access key pair information are encrypted to obtain encrypted access token information and encrypted access key pair information. Step 6: The digital summary information is encrypted to obtain encrypted digital summary information. Step 7: Zero-knowledge verification is performed on the access permission corresponding to the encrypted digital summary information to obtain an access permission verification result, wherein the access permission verification result can indicate whether the access permission is approved or not. Step 8: In response to determining that the access permission verification result indicates access permission is approved, contextual information access control is performed on the encrypted digital summary information to obtain contextual information access control information. Step 9: Fine-grained access control is performed on the contextual information access control information to obtain controlled digital summary information. Step 10: Quantum encryption is performed on the controlled digital summary information based on the encrypted access token information and the encrypted access key pair information to obtain encrypted digital summary information. This improves the security of information access.

[0146] The above-described embodiments of the present disclosure have the following beneficial effects: Through the information transmission methods of some embodiments of the present disclosure, the security of information access and the reliability of accessed information are improved. Specifically, the low security of information access and the low reliability of accessed information are caused by: manual control and verification of information may result in information loss, resulting in low security of information access. Because information may be modified during transmission, this may lead to insufficient information integrity and low reliability of accessed information. Based on this, the information transmission methods of some embodiments of the present disclosure first obtain business log data, where the business log data corresponds to the log storage server in the application information. This allows the acquisition of business log data to facilitate subsequent processing. Then, permission control is performed on the log storage server corresponding to the business log data to obtain a server permission control result. This reduces the possibility of information loss and improves the security of information access. Subsequently, in response to determining that the server permission control result indicates that the server permission control is successful, permission control is performed on the database corresponding to the business log data to obtain a database permission control result. This reduces the possibility of information loss and improves the security of information access. Then, in response to determining that the database permission control result indicates successful database permission control, the business log data is isolated to obtain isolated business log data. The isolated business log data and the business log data are located in a different location partition on the log storage server in the application information. Data isolation reduces the likelihood of information modification during transmission, thereby improving information integrity and enhancing the credibility of access information. The isolated business log data is then encrypted to obtain encrypted business log data. This improves the security of the isolated business log data. Next, digital summary information is generated based on the encrypted business log data. This improves the credibility of the information corresponding to the encrypted business log data. Furthermore, in response to determining that the user has accessed the digital summary information, access information verification is performed on the user information corresponding to the user to obtain a verification result. This improves the credibility of the access information. In response to determining that the verification result indicates successful verification, the digital summary information is sent to the device corresponding to the user for the user to access. This improves the user experience. Therefore, the security of information access is improved and the credibility of access information is enhanced.

[0147] Further references Figure 2 As an implementation of the methods shown in the above figures, the present disclosure provides some embodiments of a method for sending information. These device embodiments are similar to Figure 1 Corresponding to the method embodiments shown, the device can be specifically applied to various electronic devices.

[0148] like Figure 2 As shown, the information sending device 200 of some embodiments includes: an acquisition unit 201, a first permission control unit 202, a second permission control unit 203, a data isolation unit 204, an encryption processing unit 205, a generation unit 206, a verification unit 207 and a sending unit 208. The acquisition unit 201 is configured to acquire business log data, wherein the business log data is the business log data corresponding to the log storage server in the application information; the first permission control unit 202 is configured to perform permission control on the log storage server corresponding to the business log data and obtain a server permission control result; the second permission control unit 203 is configured to perform permission control on the database corresponding to the business log data in response to determining that the server permission control result indicates that the server permission control is successful and obtain a database permission control result; the data isolation unit 204 is configured to perform data isolation on the business log data in response to determining that the database permission control result indicates that the database permission control is successful. Obtain the isolated business log data, wherein the above-mentioned isolated business log data and the above-mentioned business log data have different location partitions in the log storage server in the above-mentioned application information; the encryption processing unit 205 is configured to encrypt the above-mentioned isolated business log data to obtain the encrypted business log data; the generation unit 206 is configured to generate digital summary information based on the above-mentioned encrypted business log data; the verification unit 207 is configured to verify the access information of the above-mentioned user in response to determining that the user accesses the above-mentioned digital summary information, and obtain a verified result; the sending unit 208 is configured to send the above-mentioned digital summary information to the user in response to determining that the above-mentioned verification result indicates that the verification is passed, so that the above-mentioned user can perform a calling operation.

[0149] It is understood that the units described in the device 200 are similar to those described in the reference Figure 1 Therefore, the operations, features and beneficial effects described above for the method are also applicable to the device 200 and the units included therein, and will not be repeated here.

[0150] Reference below Figure 3 , which shows a structural diagram of an electronic device (such as a computing device) 300 suitable for implementing some embodiments of the present disclosure. Figure 3 The electronic device shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present disclosure.

[0151] like Figure 3As shown, the electronic device 300 may include a processing device (e.g., a central processing unit, a graphics processing unit, etc.) 301, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 302 or a program loaded from a storage device 308 into a random access memory (RAM) 304. Various programs and data required for the operation of the electronic device 300 are also stored in the RAM 303. The processing device 301, the ROM 302, and the RAM 304 are connected to each other via a bus 304. An input / output (I / O) interface 305 is also connected to the bus 304.

[0152] Typically, the following devices may be connected to the I / O interface 305: an input device 306 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 307 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 308 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 309. The communication device 309 may allow the electronic device 300 to communicate with other devices wirelessly or by wire to exchange data. Figure 3 The electronic device 300 is shown with various devices, but it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed instead. Figure 3 Each block shown in the figure may represent one device, or may represent multiple devices as needed.

[0153] In particular, according to some embodiments of the present disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, some embodiments of the present disclosure include a computer program product comprising a computer program carried on a computer-readable medium, the computer program comprising program code for executing the method shown in the flowchart. In some such embodiments, the computer program can be downloaded and installed from a network via the communication device 309, or installed from the storage device 308, or installed from the ROM 302. When the computer program is executed by the processing device 301, the functions defined in the methods of some embodiments of the present disclosure are performed.

[0154] It should be noted that the computer-readable medium described in some embodiments of the present disclosure may be a computer-readable signal medium or a computer-readable storage medium or any combination of the two. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or device, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In some embodiments of the present disclosure, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, device, or device. In some embodiments of the present disclosure, the computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transfer a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium may be transmitted using any suitable medium, including but not limited to wires, optical cables, RF (radio frequency), etc., or any suitable combination thereof.

[0155] In some embodiments, the client and server can communicate using any currently known or future developed network protocol, such as HTTP (Hypertext Transfer Protocol), and can be interconnected with any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network ("LAN"), a wide area network ("WAN"), an internet (e.g., the Internet), and a peer-to-peer network (e.g., an ad hoc peer-to-peer network), as well as any currently known or future developed network.

[0156] The computer-readable medium may be included in the electronic device, or may exist independently without being incorporated into the electronic device. The computer-readable medium carries one or more programs. When the one or more programs are executed by the electronic device, the electronic device: obtains business log data, wherein the business log data is business log data corresponding to the log storage server in the application information; performs permission control on the log storage server corresponding to the business log data to obtain a server permission control result; in response to determining that the server permission control result indicates that the server permission control is successful, performs permission control on the database corresponding to the business log data to obtain a database permission control result; in response to determining that the database permission control result indicates that the database permission control is successful, performs data isolation on the business log data to obtain isolated business log data, wherein the location partition of the isolated business log data and the location partition of the log storage server in the application information are different; encrypts the isolated business log data to obtain encrypted business log data; generates digital summary information based on the encrypted business log data; in response to determining that a user accesses the digital summary information, performs access information verification on the user information corresponding to the user to obtain a verification result; in response to determining that the verification result indicates that the verification is successful, sends the digital summary information to the device corresponding to the user for the user to call and operate.

[0157] Computer program code for performing the operations of some embodiments of the present disclosure may be written in one or more programming languages, or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).

[0158] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the module, program segment, or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than the order marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of the boxes in the block diagram and / or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0159] The units described in some embodiments of the present disclosure may be implemented by software or by hardware. The described units may also be provided in a processor. For example, they may be described as follows: a processor comprising: an acquisition unit, a first permission control unit, a second permission control unit, a data isolation unit, an encryption processing unit, a generation unit, a verification unit, and a sending unit. The names of these units do not, in some cases, constitute a limitation on the units themselves. For example, the acquisition unit may also be described as a "unit for acquiring business log data."

[0160] The functions described above herein may be performed, at least in part, by one or more hardware logic components. For example, and without limitation, exemplary types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chip (SOCs), complex programmable logic devices (CPLDs), and the like.

[0161] The above description is only an illustration of some preferred embodiments of the present disclosure and the technical principles used therein. Those skilled in the art should understand that the scope of the invention involved in the embodiments of the present disclosure is not limited to the technical solutions formed by the specific combination of the above technical features, but should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above inventive concept. For example, the above features are replaced with (but not limited to) technical features with similar functions disclosed in the embodiments of the present disclosure by each other to form a technical solution.

Claims

1. A method for sending information, comprising: Obtaining business log data, wherein the business log data is business log data corresponding to the log storage server in the application information; Performing authority control on the log storage server corresponding to the business log data to obtain a server authority control result; In response to determining that the server authority control result indicates that the server authority control is successful, performing authority control on the database corresponding to the business log data to obtain a database authority control result; In response to determining that the database authority control result indicates that the database authority control is successful, performing data isolation on the business log data to obtain isolated business log data, wherein the isolated business log data and the business log data have a different location partition in the log storage server in the application information; Encrypting the isolated business log data to obtain encrypted business log data, wherein encrypting the isolated business log data to obtain encrypted business log data includes: cleaning the isolated business log data to obtain cleaned log data; The cleaned log data is divided into blocks to obtain at least one log data block information; Performing key generation on each log data block information in the at least one log data block information to generate log data block key information, and obtaining a log data block key information set; Performing user access information detection on the log data block key information set to obtain a user behavior detection result set, wherein the user behavior detection results in the user behavior detection result set represent normal user behavior detection results and abnormal user behavior detection results; In response to determining that the user behavior detection result in the user behavior detection result set represents an abnormal user behavior detection result, filtering the log data block key information set corresponding to the abnormal user behavior detection result to obtain a filtered log data block key information set, wherein the filtered log data block key information set is the filtered log data block key information set after removing the user behavior detection result corresponding to the abnormal user behavior detection result from the user behavior detection result set; In response to determining that the user accesses the isolated business log data, decrypting the filtered log data block key information set to obtain a decrypted log data block key information set; In response to determining that the user has ended accessing the isolated business log data, encrypting the decrypted log data block key information set to obtain encrypted business log data; Generating digital summary information based on the encrypted business log data, wherein the digital summary information is information having a fixed length corresponding to the encrypted business log data, wherein generating digital summary information based on the encrypted business log data includes: Extracting key information from the encrypted business log data to obtain extracted key information; Performing format conversion on the extracted key information to obtain format-converted key information; Dividing the format-converted key information into block information of the same byte length to obtain a block information set; Performing hash value generation on each block information in the block information set to generate a block information hash value, thereby obtaining a block information hash value set; Performing hash value concatenation on each block information hash value in the block information hash value set to obtain a character string corresponding to the concatenated first hash values; Generate a hash value for the string corresponding to the concatenation of the first hash values to obtain a hash value corresponding to the first string; Performing hash value concatenation on the hash value corresponding to the first character string and each block information hash value in the block information hash value set to obtain a character string corresponding to the concatenated second hash value; Generate a hash value for the string corresponding to the concatenation of the second hash values to obtain a hash value corresponding to the second string; In response to determining that the hash value length corresponding to the hash value corresponding to the second character string is greater than or equal to a preset hash value length, adding additional data to the hash value corresponding to the second character string to obtain a character string after the additional data is added; Generate a hash value for the character string after the additional data is added to obtain a hash value corresponding to the third character string; Digitally signing the hash value corresponding to the third character string to obtain a signed hash value; Concatenate the signed hash value with the string after the additional data is added to obtain concatenated information as digital summary information; In response to determining that the user accesses the digital summary information, performing access information verification on the user information corresponding to the user to obtain a verification result; In response to determining that the verification result indicates that the verification is passed, sending the digital summary information to the device corresponding to the user for the user to perform a call operation; In response to determining that the user calls the digital summary information, obtaining user identification information; Comparing the user identification information with the user authority database to obtain a comparison result; In response to determining that the comparison result indicates a consistent comparison, generating access token information and access key pair information based on the user identification information; authenticating the user corresponding to the user identification information to obtain a verification result; In response to determining that the verification result indicates that the verification is passed, encrypting the access token information and the access key pair information to obtain encrypted access token information and encrypted access key pair information; encrypting the digital summary information to obtain encrypted digital summary information; Performing zero-knowledge verification on the access right corresponding to the encrypted digital summary information to obtain an access right verification result, wherein the access right verification result can indicate whether the access right is approved or not; In response to determining that the access permission certification result indicates that the access permission is granted, performing context information access control on the encrypted digital summary information to obtain context information access control information; Performing fine-grained access control on the context information after access control to obtain digital summary information after control; The controlled digital summary information is quantum encrypted according to the encrypted access token information and the encrypted access key pair information to obtain encrypted digital summary information.

2. The method according to claim 1, wherein The performing authority control on the log storage server corresponding to the business log data to obtain a server authority control result includes: Determine the read and write permission information corresponding to the log storage server; Performing permission verification on the read and write permission information to obtain a permission verification result; In response to determining that the permission verification result indicates that the verification is passed, read and write permission control is performed on the log storage server to obtain a server permission control result, wherein the server permission control result indicates a result after the read and write permission control of the server is successful.

3. The method according to claim 1, wherein In response to determining that the server authority control result indicates that the server authority control is successful, performing authority control on the database corresponding to the business log data to obtain a database authority control result includes: Performing access permission verification on the database corresponding to the business log data to obtain an access permission verification result; In response to determining that the access permission verification result indicates that the access permission verification is passed, verifying the user's access permission to obtain a user access permission verification result; In response to determining that the user access permission verification result indicates that the user access permission verification is passed, matching the user with the user permissions stored in the database corresponding to the business log data to obtain a matching result; In response to determining that the matching result indicates a matching inconsistency, isolating the access rights of the database corresponding to the business log data, and obtaining a database permission result after isolation as a database permission control result; In response to determining that the matching result indicates a consistent match, the access permission of the database corresponding to the business log data is encrypted to obtain an encrypted database permission result as a database permission control result.

4. The method according to claim 1, wherein In response to determining that the user accesses the digital summary information, performing access information verification on the user information corresponding to the user to obtain a verification result includes: Performing access time information verification on the user information corresponding to the user to obtain a result after access time verification; In response to determining that the access time verification result indicates that the access time verification is normal, performing access identity information verification on the user information corresponding to the user to obtain an access identity information verification result; In response to determining that the access identity information post-verification result indicates that the access identity information verification is successful, access result information verification is performed on the user information corresponding to the user to obtain an access result information post-verification result as a post-verification result.

5. An information sending device, comprising: an acquiring unit configured to acquire business log data, wherein the business log data is business log data corresponding to the log storage server in the application information; A first authority control unit is configured to perform authority control on the log storage server corresponding to the business log data and obtain a server authority control result; a second authority control unit configured to, in response to determining that the server authority control result indicates that the server authority control is successful, perform authority control on the database corresponding to the business log data to obtain a database authority control result; a data isolation unit configured to, in response to determining that the database authority control result indicates that the database authority control is successful, isolate the business log data to obtain isolated business log data, wherein the isolated business log data and the business log data have a different location partition in the log storage server in the application information; The encryption processing unit is configured to perform encryption processing on the isolated business log data to obtain encrypted business log data, wherein the encryption processing on the isolated business log data to obtain encrypted business log data includes: performing data cleaning on the isolated business log data to obtain data-cleaned log data; performing block processing on the data-cleaned log data to obtain at least one log data block information; performing key generation on each log data block information in the at least one log data block information to generate log data block key information to obtain a log data block key information set; performing user access information detection on the log data block key information set to obtain a user behavior detection result set, wherein the user behavior detection result in the user behavior detection result set represents a normal result of the user behavior detection and a normal result of the user behavior detection. Abnormal result; in response to determining that the user behavior detection result in the user behavior detection result set represents an abnormal user behavior detection result, filtering the log data block key information set corresponding to the abnormal user behavior detection result to obtain a filtered log data block key information set, wherein the filtered log data block key information set is the filtered log data block key information set after removing the user behavior detection result corresponding to the abnormal user behavior detection result from the user behavior detection result set; in response to determining that the user accesses the isolated business log data, decrypting the filtered log data block key information set to obtain a decrypted log data block key information set; in response to determining that the user accesses the isolated business log data, encrypting the decrypted log data block key information set to obtain encrypted business log data; The generating unit is configured to generate digital summary information according to the encrypted business log data, wherein the digital summary information is information with a fixed length corresponding to the encrypted business log data, wherein the generating of digital summary information according to the encrypted business log data comprises: extracting key information from the encrypted business log data to obtain extracted key information; performing format conversion on the extracted key information to obtain format-converted key information; dividing the format-converted key information into block information of the same byte length to obtain a block information set; performing hash value generation on each block information in the block information set to generate a block information hash value to obtain a block information hash value set; performing hash value connection on each block information hash value in the block information hash value set to obtain a character string corresponding to the first hash value connection; performing hash value connection on the character string corresponding to the first hash value connection Generate a hash value to obtain a hash value corresponding to a first string; perform hash value concatenation on the hash value corresponding to the first string and each block information hash value in the block information hash value set to obtain a string corresponding to the concatenation of the second hash value; generate a hash value on the string corresponding to the concatenation of the second hash value to obtain a hash value corresponding to the second string; in response to determining that a hash value length corresponding to the hash value corresponding to the second string is greater than or equal to a preset hash value length, add additional data to the hash value corresponding to the second string to obtain a string after the additional data is added; generate a hash value on the string after the additional data is added to obtain a hash value corresponding to a third string; digitally sign the hash value corresponding to the third string to obtain a signed hash value; and concatenate the signed hash value with the string after the additional data is added to obtain concatenated information as digital summary information; A verification unit configured to, in response to determining that a user accesses the digital summary information, perform access information verification on the user information corresponding to the user and obtain a verification result; The sending unit is configured to, in response to determining that the verification result indicates that the verification is passed, send the digital summary information to the device corresponding to the user for the user to call the operation; in response to determining that the user calls the digital summary information, obtain user identification information; compare the user identification information with the user authority database to obtain a comparison result; in response to determining that the comparison result indicates that the comparison is consistent, generate access token information and access key pair information based on the user identification information; authenticate the user corresponding to the user identification information to obtain a verification result; in response to determining that the verification result indicates that the verification is passed, encrypt the access token information and the access key pair information to obtain encrypted access token information and encrypted access key pair information information; encrypting the digital summary information to obtain encrypted digital summary information; performing zero-knowledge verification on the access permission corresponding to the encrypted digital summary information to obtain an access permission verification result, wherein the access permission verification result can represent access permission approval and access permission rejection; in response to determining that the access permission verification result represents access permission approval, performing context information access control on the encrypted digital summary information to obtain context information access control information; performing fine-grained access control on the context information access control information to obtain controlled digital summary information; performing quantum encryption on the controlled digital summary information according to the encrypted access token information and the encrypted access key pair information to obtain encrypted digital summary information.

6. An electronic device comprising: one or more processors; a storage device having one or more programs stored thereon; When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 4.

7. A computer-readable medium having a computer program stored thereon, wherein: When the program is executed by a processor, the method according to any one of claims 1 to 4 is implemented.

Citation Information

Patent Citations

  • Log reading method, device, computer equipment and storage medium

    CN111897786A