Log processing method and device, computer equipment and storage medium
The log data is encrypted and signed through dynamic key generation and target encryption algorithms, which solves the problem of insufficient data protection in traditional log systems and realizes the security and integrity of log data.
Patent Information
- Application Number
- CN202510655550.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-20
- Publication Date
- 2025-08-29
AI Technical Summary
Traditional logging systems have insufficient encryption methods in data protection, and log data is easily tampered with or leaked, affecting system security and business continuity.
Dynamic key generation strategy, target symmetric encryption algorithm and digital signature algorithm are used to encrypt and sign log data to ensure data confidentiality and integrity.
It improves the security and accuracy of log data during transmission and storage, prevents data tampering and leakage, and ensures the stable operation of the system.
Smart Images

Figure CN120567459A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of artificial intelligence technology and can be applied to the field of financial technology, and in particular to log processing methods, devices, computer equipment and storage media. Background Art
[0002] In today's digital age, information technology has been deeply integrated into all industries and has become a core force driving efficient business operations. Log files play a vital role in the operation of various information systems. They record in detail key information such as the system's operating status, user operations, and the time and entities involved in various events. They are an indispensable basis for system maintenance, troubleshooting, and security audits. For example, in financial business systems, log files record detailed information such as the time, amount, parties involved, and transaction type of each transaction. This information is crucial for subsequent business verification. Business verification is a key step in ensuring the accuracy and compliance of capital flows in financial operations. By comparing transaction records in log files with actual capital flows, potential discrepancies and errors can be promptly identified and corrected, ensuring the normal operation of financial operations.
[0003] However, traditional logging systems suffer from significant data protection deficiencies. For one thing, they lack effective encryption, and log data often exists in plaintext during storage and transmission, making it an easy target for cyber attackers. Once an attacker breaches the system's security, they can easily obtain sensitive information from log files, such as user login credentials and transaction records. They can then conduct malicious operations, such as tampering with transaction data and stealing user funds, resulting in significant financial losses for financial institutions and users.
[0004] On the other hand, traditional log systems also have serious deficiencies in data integrity verification. Due to the lack of reliable verification mechanisms, log data is extremely vulnerable to malicious tampering or accidental corruption during storage and transmission. Attackers can modify key information in log files without being detected, concealing their illegal activities and making subsequent audits and investigations difficult to uncover the truth. Furthermore, log data corruption can lead to the loss of important business information, impacting system operation and business continuity.
[0005] Therefore, it is particularly urgent and necessary to develop a system that can comprehensively protect the security of log data, so as to ensure the authenticity and reliability of log data and provide strong guarantees for the safe and stable operation of various information systems. Summary of the Invention
[0006] The purpose of the embodiments of the present application is to provide a log processing method, apparatus, computer equipment and storage medium to solve the technical problem of low security in the processing of existing log data.
[0007] In a first aspect, a log processing method is provided, comprising:
[0008] Obtain log data generated based on user consultation requests;
[0009] Formatting the log data to obtain corresponding first log data;
[0010] Obtaining user identification data of the user, and performing key generation processing on the user identification data based on a preset dynamic key generation strategy to obtain a corresponding encryption key;
[0011] Acquire the data size of the first log data, and generate a target encryption block size corresponding to a target symmetric encryption algorithm based on the data size;
[0012] Encrypting the first log data using a specified encryption mode of the target symmetric encryption algorithm based on the encryption key and the target encryption block size to obtain corresponding second log data;
[0013] Digitally signing the second log data based on a preset target digital signature algorithm to obtain a corresponding target digital signature; wherein the key length of the target digital signature algorithm is generated based on a preset security performance requirement;
[0014] The second log data and the target digital signature are stored.
[0015] In a second aspect, a log processing device is provided, comprising:
[0016] A first acquisition module is used to acquire log data generated based on the user's consultation request;
[0017] a collating module, configured to format the log data to obtain corresponding first log data;
[0018] A first generation module is configured to obtain user identification data of the user and perform key generation processing on the user identification data based on a preset dynamic key generation strategy to obtain a corresponding encryption key;
[0019] a second generating module, configured to obtain a data size of the first log data and generate a target encryption block size corresponding to a target symmetric encryption algorithm based on the data size;
[0020] an encryption module, configured to encrypt the first log data using a specified encryption mode of the target symmetric encryption algorithm based on the encryption key and the target encryption block size to obtain corresponding second log data;
[0021] a signature module, configured to digitally sign the second log data based on a preset target digital signature algorithm to obtain a corresponding target digital signature; wherein the key length of the target digital signature algorithm is generated based on a preset security performance requirement;
[0022] The first storage module is used to store and process the second log data and the target digital signature.
[0023] In a third aspect, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the above-mentioned log processing method when executing the computer program.
[0024] In a fourth aspect, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the above-mentioned log processing method are implemented.
[0025] In the scheme implemented by the above-mentioned log processing method, device, computer equipment and storage medium, log data generated based on the user's consultation request is first obtained; then the log data is formatted to obtain corresponding first log data; then the user identification data of the user is obtained, and the user identification data is key-generated based on a preset dynamic key generation strategy to obtain a corresponding encryption key; subsequently, the data scale of the first log data is obtained, and a target encryption block size corresponding to the target symmetric encryption algorithm is generated based on the data scale; further, based on the encryption key and the target encryption block size, the first log data is encrypted using the specified encryption mode of the target symmetric encryption algorithm to obtain corresponding second log data; and the second log data is digitally signed based on the preset target digital signature algorithm to obtain the corresponding target digital signature; wherein the key length of the target digital signature algorithm is generated based on preset security performance requirements; finally, the second log data and the target digital signature are stored and processed. This application obtains log data generated based on the user's consultation request, formats the log data to obtain the first log data, then performs key generation processing on the user identification data based on the use of a dynamic key generation strategy to obtain an encryption key, and generates a target encryption block size corresponding to the target symmetric encryption algorithm based on the data scale of the first log data, and then uses the specified encryption mode of the target symmetric encryption algorithm based on the encryption key and the target encryption block size to encrypt the first log data to obtain the corresponding second log data, and further digitally signs the second log data based on the use of the target digital signature algorithm to obtain the target digital signature, and finally stores the second log data and the target digital signature. After the above processing flow, this application combines the dual encryption mechanism of the optimized target symmetric encryption algorithm and the target digital signature algorithm for log processing, effectively improving the efficiency and accuracy of log processing, and ensuring the confidentiality, integrity and source reliability of the log data during transmission and storage. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] In order to more clearly illustrate the solutions in this application, a brief introduction will be given below to the drawings required for use in the description of the embodiments of this application. Obviously, the drawings described below are some embodiments of this application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0027] Figure 1 is an exemplary system architecture diagram to which the present application may be applied;
[0028] Figure 2 is a flow chart of an embodiment of a log processing method according to the present application;
[0029] Figure 3 is a structural diagram of an embodiment of a log processing device according to the present application;
[0030] Figure 4 It is a structural diagram of an embodiment of a computer device according to the present application. DETAILED DESCRIPTION
[0031] Unless otherwise defined, all technical and scientific terms used herein have the same meanings as commonly understood by those skilled in the art to which this application belongs. The terms used in the specification of the application are for the purpose of describing specific embodiments only and are not intended to limit this application. The terms "including" and "having" and any variations thereof in the specification and claims of this application and the above-mentioned drawings are intended to cover non-exclusive inclusions. The terms "first", "second", etc. in the specification and claims of this application or the above-mentioned drawings are used to distinguish different objects, not to describe a specific order.
[0032] References herein to "embodiments" mean that a particular feature, structure, or characteristic described in connection with the embodiments may be included in at least one embodiment of the present application. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor does it constitute an independent or alternative embodiment that is mutually exclusive of other embodiments. It is understood, both explicitly and implicitly, by those skilled in the art that the embodiments described herein may be combined with other embodiments.
[0033] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings.
[0034] like Figure 1 As shown, system architecture 100 may include a terminal device 101, a network 102, and a server 103. Terminal device 101 may be a laptop computer 1011, a tablet computer 1012, or a mobile phone 1013. Network 102 is a medium for providing a communication link between terminal device 101 and server 103. Network 102 may include various connection types, such as wired or wireless communication links or fiber optic cables.
[0035] The user can use the terminal device 101 to interact with the server 103 via the network 102 to receive or send messages, etc. Various communication client applications can be installed on the terminal device 101, such as web browser applications, shopping applications, search applications, instant messaging tools, email clients, social platform software, etc.
[0036] The terminal device 101 can be various electronic devices with a display screen and supporting web browsing. In addition to the laptop computer 1011, tablet computer 1012 or mobile phone 1013, the terminal device 101 can also be an e-book reader, an MP3 player (Moving Picture Experts Group Audio Layer III), an MP4 (Moving Picture Experts Group Audio Layer IV) player, a laptop computer and a desktop computer, etc.
[0037] The server 103 may be a server that provides various services, such as a background server that provides support for web pages displayed on the terminal device 101 .
[0038] It should be noted that the log processing method provided in the embodiment of the present application is generally executed by a server / terminal device, and accordingly, the log processing device is generally set in the server / terminal device.
[0039] It should be understood that Figure 1 The number of terminal devices, networks and servers in the embodiment is merely illustrative. Any number of terminal devices, networks and servers may be provided as required.
[0040] Continue to refer Figure 2 , shows a flow chart of an embodiment of the log processing method according to the present application. According to different requirements, the order of the steps in the flow chart can be changed, and some steps can be omitted. The log processing method provided by the embodiment of the present application can be applied to any scenario that requires log processing, and the log processing method can be applied to products in these scenarios, for example, log processing in the financial and insurance fields. The log processing method includes the following steps:
[0041] Step S201: Obtain log data generated based on the user's consultation request.
[0042] In this embodiment, the electronic device on which the log processing method is running (eg Figure 1The server / terminal device shown in the figure can obtain log data generated based on the user's consultation request through a wired or wireless connection. It should be noted that the wireless connection method may include but is not limited to 3G / 4G / 5G connection, WiFi connection, Bluetooth connection, WiMAX connection, Zigbee connection, UWB (Ultra Wide Band) connection, and other wireless connection methods currently known or developed in the future. The execution entity of this application is specifically a log processing system, which can be simply referred to as the system. After receiving a user's consultation request, the system authenticates and processes the consultation request and automatically records log data. The log data may include at least basic customer information (such as name, contact information), request time, consultation content, and processing results. This application can be applied to insurance consultation business scenarios in the financial sector. For example, the consultation request may be for a consultation on critical illness insurance coverage, including: Customer Ms. Li submits a consultation through the front-end system: "I would like to know the coverage of critical illness insurance. What specific diseases are included?" The corresponding log data may include: Customer Name: Ms. Li. Contact Information: 13912345678. Request time: October 5, 202, 14:30. Question: What diseases are covered by critical illness insurance? Result: A list of 30 major diseases covered by critical illness insurance (such as cancer, heart disease, stroke, etc.) has been provided.
[0043] Alternatively, the above inquiry request could be about the auto insurance claims process, such as: Customer Mr. Wang submits a query: "My car was in an accident. How do I file a claim? What documents do I need?" The corresponding log data may include: Customer Name: Mr. Wang. Contact: 13898765432. Request Time: October 6, 2023, 10:15 AM. Inquiry Question: Auto insurance claims process and required documents. Outcome: Claims process instructions (reporting → damage assessment → document submission → review → payment) and document list (accident photos, driver's license, insurance policy, etc.) have been provided.
[0044] Furthermore, the above-mentioned consultation request may be for life insurance premium calculation, such as: Customer Mr. Zhang asks, "I'm 35 years old and would like to purchase a term life insurance policy with a coverage of 1 million yuan. What is the approximate annual premium?" The corresponding log data may include: Customer Name: Mr. Zhang. Contact Information: 13787654321. Request Time: October 7, 2023, 4:45 PM. Question: Premium estimate for a 35-year-old male purchasing a term life insurance policy with a coverage of 1 million yuan. Result: Provided premium estimate (e.g., 30-year payment period, annual premium of approximately 2,000 yuan) and explanation of factors influencing the premium rate (age, health status, coverage period, etc.).
[0045] Step S202: format the log data to obtain corresponding first log data.
[0046] In this embodiment, the above-mentioned formatting refers to arranging the log data into a structured format, such as JSON or XML, so as to obtain corresponding first log data for subsequent encryption and signature processing.
[0047] Step S203: Acquire user identification data of the user, and perform key generation processing on the user identification data based on a preset dynamic key generation strategy to obtain a corresponding encryption key.
[0048] In this embodiment, the user identification data may refer to a user ID, such as a user name. The specific implementation process of performing key generation processing on the user identification data based on the preset dynamic key generation strategy to obtain the corresponding encryption key will be further described in detail in subsequent specific embodiments of this application and will not be elaborated on here.
[0049] Step S204: Acquire the data size of the first log data, and generate a target encryption block size corresponding to a target symmetric encryption algorithm based on the data size.
[0050] In this embodiment, the data size refers to the memory size occupied by the first log data. This memory size can be compared with a preset memory threshold. If the memory size of the first log data is greater than or equal to the threshold, the first log data is considered a large data block; if the memory size of the first log data is less than the threshold, the first log data is considered a small data block. Furthermore, the encryption block size is dynamically adjusted based on the data size of the log data. Specifically, for small data blocks, using a smaller encryption block size (e.g., 128 bits) can reduce encryption operation overhead and increase encryption speed; for large data blocks, using a larger encryption block size (e.g., 256 bits) can reduce the number of encryption operations and optimize encryption performance. Thus, by encrypting data using a target encryption block size that matches the data size of the first log data, encryption performance can be optimized and processing efficiency can be improved. The value of the memory threshold is not specifically limited and can be set based on actual business needs. The aforementioned symmetric encryption algorithm can specifically be the AES algorithm. The AES algorithm is a symmetric key encryption algorithm with advantages such as fast encryption speed and high security, making it the preferred algorithm for protecting data confidentiality. AES encryption ensures that sensitive information is not leaked during transmission and storage.
[0051] Step S205 : Based on the encryption key and the target encryption block size, the first log data is encrypted using a specified encryption mode of the target symmetric encryption algorithm to obtain corresponding second log data.
[0052] In this embodiment, the specific implementation process of encrypting the first log data based on the encryption key and the target encryption block size using the specified encryption mode of the target symmetric encryption algorithm to obtain the corresponding second log data will be further described in detail in subsequent specific embodiments of this application and will not be elaborated on here.
[0053] Step S206 , digitally signing the second log data based on a preset target digital signature algorithm to obtain a corresponding target digital signature; wherein the key length of the target digital signature algorithm is generated based on a preset security performance requirement.
[0054] In this embodiment, the target digital signature algorithm may specifically employ the DSA algorithm. The DSA algorithm, based on the discrete logarithm problem, is highly secure and unforgeable, and is an important means of ensuring data integrity and source reliability. Through the DSA digital signature, the recipient can verify the integrity and source of the data, ensuring its authenticity and credibility. Digitally signing the second log data using the target digital signature algorithm can be used to ensure the integrity of the log data, verify its source, and prevent tampering or forgery of the log data.
[0055] Step S207: storing the second log data and the target digital signature.
[0056] In this embodiment, the specific implementation process of storing and processing the second log data and the target digital signature will be further described in detail in subsequent specific embodiments of this application and will not be elaborated on here.
[0057] This application first obtains log data generated based on the user's consultation request; then formats the log data to obtain corresponding first log data; then obtains the user identification data of the user, and performs key generation processing on the user identification data based on a preset dynamic key generation strategy to obtain a corresponding encryption key; subsequently obtains the data scale of the first log data, and generates a target encryption block size corresponding to the target symmetric encryption algorithm based on the data scale; further based on the encryption key and the target encryption block size, uses the specified encryption mode of the target symmetric encryption algorithm to encrypt the first log data to obtain corresponding second log data; and digitally signs the second log data based on a preset target digital signature algorithm to obtain a corresponding target digital signature; wherein the key length of the target digital signature algorithm is generated based on a preset security performance requirement; finally, the second log data and the target digital signature are stored and processed. This application obtains log data generated based on the user's consultation request, formats the log data to obtain the first log data, then performs key generation processing on the user identification data based on the use of a dynamic key generation strategy to obtain an encryption key, and generates a target encryption block size corresponding to the target symmetric encryption algorithm based on the data scale of the first log data, and then uses the specified encryption mode of the target symmetric encryption algorithm based on the encryption key and the target encryption block size to encrypt the first log data to obtain the corresponding second log data, and further digitally signs the second log data based on the use of the target digital signature algorithm to obtain the target digital signature, and finally stores the second log data and the target digital signature. After the above processing flow, this application combines the dual encryption mechanism of the optimized target symmetric encryption algorithm and the target digital signature algorithm for log processing, effectively improving the security and accuracy of log processing, and ensuring the confidentiality, integrity and source reliability of the log data during transmission and storage.
[0058] In some optional implementations, step S203 includes the following steps:
[0059] Obtain a timestamp corresponding to the log data.
[0060] In this embodiment, the timestamp refers to the generation time of the log data.
[0061] The user identification data and the timestamp are concatenated to obtain corresponding concatenated data.
[0062] In this embodiment, the user identification data refers to a user ID. The user identification data and the timestamp can be combined in a predetermined order to produce the corresponding spliced data. The predetermined order can be timestamp-user identification data. For example, the timestamp "20231005140000" and the user ID "lisi" can be combined to form "20231005140000li si."
[0063] A hash operation is performed on the spliced data based on a preset target hash algorithm to obtain a corresponding hash operation result.
[0064] In this embodiment, the target hash algorithm is not specifically limited and can be determined according to actual business needs. For example, the SHA-256 algorithm can be used. The concatenated data can be hashed according to the selected target hash algorithm to generate a unique hash result.
[0065] The hash operation result is used as the encryption key.
[0066] In this embodiment, by using a dynamic key generation strategy to generate encryption keys, it can be ensured that the keys for each encryption operation are different. Even if a key is leaked, it will not affect the security of other data.
[0067] The present application obtains the timestamp corresponding to the log data; then concatenates the user identification data and the timestamp to obtain the corresponding concatenated data; then performs a hash operation on the concatenated data based on a preset target hash algorithm to obtain the corresponding hash operation result; and subsequently uses the hash operation result as the encryption key. The present application obtains the timestamp corresponding to the log data, concatenates the user identification data and the timestamp to obtain the concatenated data, and then performs a hash operation on the concatenated data based on the use of a target hash algorithm, thereby intelligently and accurately generating the corresponding encryption key, ensuring the uniqueness and security of the generated encryption key.
[0068] In some optional implementations of this embodiment, step S205 includes the following steps:
[0069] Obtain encryption authentication conditions corresponding to the log data.
[0070] In this embodiment, the encryption authentication condition refers to the encryption speed requirement and authentication requirement of the log data.
[0071] The encryption authentication condition is analyzed to determine a specified encryption mode corresponding to the target symmetric encryption algorithm.
[0072] In this embodiment, for log data that requires high encryption speed and authentication, GCM mode is used as the designated encryption mode for encryption to ensure the confidentiality and integrity of the log data during transmission. For log data that requires high encryption speed but low authentication requirements, CBC mode is used as the designated encryption mode for encryption to improve the encryption efficiency of the log data.
[0073] Call the preset encryption environment.
[0074] In this embodiment, the encryption environment may specifically use memory.
[0075] In the encryption environment, the first log data is encrypted using a specified encryption mode of the target symmetric encryption algorithm based on the encryption key and the target encryption block size to obtain the second log data.
[0076] In this embodiment, by encrypting the first log data in the above-described encryption environment using a specified encryption mode of a target symmetric encryption algorithm based on a determined encryption key and target encryption block size, the most appropriate encryption mode can be selected according to different application scenarios, thereby improving the encryption efficiency and security of the log data. Furthermore, by performing data encryption processing in memory, the efficiency of data encryption can be further improved. Furthermore, by adaptively adjusting the encryption block size based on the data size of the log data and subsequently performing auxiliary encryption on the log data using the target encryption block size, encryption performance can be effectively optimized.
[0077] This application obtains the encryption authentication conditions corresponding to the log data; then analyzes the encryption authentication conditions to determine the specified encryption mode corresponding to the target symmetric encryption algorithm; then calls a preset encryption environment; subsequently, in the encryption environment, based on the encryption key and the target encryption block size, uses the specified encryption mode of the target symmetric encryption algorithm to encrypt the first log data to obtain the second log data. This application obtains the encryption authentication conditions corresponding to the log data, then analyzes the encryption authentication conditions to determine the specified encryption mode corresponding to the target symmetric encryption algorithm, and then, in the called encryption environment, uses the specified encryption mode of the target symmetric encryption algorithm to encrypt the first log data based on the encryption key and the target encryption block size, which can effectively improve the encryption efficiency and security of the log data and ensure the accuracy of the obtained second log data.
[0078] In some optional implementations, step S207 includes the following steps:
[0079] The second log data and the target digital signature are combined to obtain a corresponding data packet.
[0080] In this embodiment, the second log data and the target digital signature can be combined in a specified order to obtain a corresponding data packet, which is convenient for management and query. There is no specific limitation on the selection of the specified order, and it can be determined according to actual business needs.
[0081] Call pre-built distributed storage media.
[0082] In this embodiment, the distributed storage medium is a pre-built storage device with scalability, which can support the storage and management of a large amount of log data, and can dynamically expand the storage capacity according to the growth of data volume.
[0083] The data packet is stored in the distributed storage medium.
[0084] In this embodiment, the storage location corresponding to the log data can be pre-determined in the distributed storage medium, and then the data packet can be stored in the storage location.
[0085] Access control processing is performed on the distributed storage medium that has completed the storage processing.
[0086] In this embodiment, the distributed storage medium may be encrypted by using access control, data encryption, and other technologies to ensure the security of the log data. For example, the distributed storage medium may be encrypted using disk encryption technology to prevent data leakage.
[0087] The present application obtains a corresponding data packet by performing data combination processing on the second log data and the target digital signature; then calls a pre-built distributed storage medium; then stores the data packet in the distributed storage medium; and subsequently performs access control processing on the distributed storage medium that has completed the storage processing. The present application obtains a corresponding data packet by performing data combination processing on the second log data and the target digital signature; then stores the data packet in the distributed storage medium; and then intelligently performs access control processing on the distributed storage medium that has completed the storage processing, thereby effectively ensuring the storage security of the log data and preventing the leakage of the log data.
[0088] In some optional implementations, after step S203, the electronic device may further perform the following steps:
[0089] Obtain the pre-stored master key from the preset hardware module.
[0090] In this embodiment, the aforementioned hardware module is a pre-built, secure hardware module used to ensure the security of the master key. This is achieved by dividing the key into multiple levels, including a master key and subkeys. The master key is used to encrypt the subkeys, which are then used for actual data encryption. The master key is stored in the secure hardware module, while subkeys are dynamically generated and encrypted when needed. This reduces the complexity of key management while improving key security. The generation of the master key is not specifically defined and can be performed based on actual encryption requirements.
[0091] The encryption key is encrypted based on the master key to obtain an encrypted subkey.
[0092] In this embodiment, the encryption key may be encrypted using the obtained master key to obtain an encrypted encryption key, ie, the subkey.
[0093] Get the preset target storage policy.
[0094] In this embodiment, there is no specific limitation on the selection of the above-mentioned target storage strategy, which can be determined according to actual storage needs. For example, any one of the strategies such as local database storage, disk storage, network disk storage, and blockchain storage can be adopted.
[0095] The subkey is stored based on the target storage policy.
[0096] In this embodiment, the storage processing of the above subkeys can be performed according to the selected target storage policy to improve the security of key management and reduce the risk of key leakage.
[0097] This application obtains a pre-stored master key from a preset hardware module; then encrypts the encryption key based on the master key to obtain an encrypted subkey; then obtains a preset target storage policy; and subsequently stores the subkey based on the target storage policy. This application obtains a pre-stored master key based on the use of a hardware module; then encrypts the encryption key based on the use of the master key to obtain an encrypted subkey; and subsequently stores the subkey based on the use of the target storage policy, thereby effectively reducing the complexity of key management while improving key security.
[0098] In some optional implementations of this embodiment, before step S206, the electronic device may further perform the following steps:
[0099] Obtain an application scenario for the log data, and determine corresponding security performance requirements based on the application scenario.
[0100] In this embodiment, the application scenarios of the log data include system application scenarios with security and performance requirements. The application scenarios can be analyzed to determine matching security and performance requirements. Application scenarios include scenarios with high security requirements and low performance requirements, or scenarios with low security requirements and high performance requirements. Corresponding security and performance requirements include scenarios with high security requirements and low performance requirements, or scenarios with low security requirements and high performance requirements.
[0101] Call the preset data mapping table.
[0102] In this embodiment, the data mapping table is a pre-built data table that stores key length data corresponding to security performance requirements. Specifically, for requirements with higher security requirements, a longer key length (e.g., 2048 bits) is selected as the key length data. For requirements with higher performance requirements, a shorter key length (e.g., 1024 bits) is selected as the key length data while ensuring a certain level of security.
[0103] The data mapping table is queried based on the security performance requirement to obtain a specified key length that matches the security performance requirement from the data mapping table.
[0104] In this embodiment, the specified security performance requirement that matches the above security performance requirement can be found from the above data mapping table, and then the key length data corresponding to the specified security performance requirement can be extracted from the data mapping table and used as the above specified key length.
[0105] The specified key length is used as the key length of the target digital signature algorithm.
[0106] This application obtains the application scenario of the log data and determines the corresponding security performance requirements based on the application scenario; then calls a preset data mapping table; then queries the data mapping table based on the security performance requirements to obtain a specified key length that matches the security performance requirements from the data mapping table; and subsequently uses the specified key length as the key length of the target digital signature algorithm. This application obtains the application scenario of the log data and determines the corresponding security performance requirements based on the application scenario, and then queries the called data mapping table based on the use of the security performance requirements, so that the key length of the target digital signature algorithm can be accurately determined based on the security performance requirements of the log data in an efficient and intelligent manner, effectively ensuring the accuracy and adaptability of the obtained key length.
[0107] In some optional implementations of this embodiment, after step S207, the electronic device may further perform the following steps:
[0108] Determine whether a user-triggered audit request for the log data is received.
[0109] In this embodiment, the audit request is a request triggered when a user needs to query or audit log data.
[0110] If so, obtain the designated public key of the target digital signature algorithm corresponding to the log data from a preset target cache.
[0111] In this embodiment, when an audit request for log data is detected, the specified public key of the target digital signature algorithm corresponding to the above log data is automatically obtained from the preset target cache. Among them, the signature verification optimization of the target digital signature algorithm is realized based on the above target cache. Specifically, the public key operation result of the target digital signature algorithm is pre-stored based on the target cache. When the digital signature corresponding to the same public key is verified again, the cached result can be directly used to increase the speed of signature verification. There is no specific limitation on the selection of the above target cache, and it can be determined according to actual business needs. For example, a redis database or memory can be used.
[0112] The digital signature of the second log data is verified based on the designated public key.
[0113] In this embodiment, the digital signature of the second log data can be directly verified using the cached designated public key to verify the validity of the target digital signature. The validity verification process includes checking the integrity and source reliability of the target digital signature to ensure that the log data has not been tampered with, and obtaining a corresponding verification result. The verification result may include whether the digital signature verification passed or failed.
[0114] If the digital signature verification passes, the second log data is decrypted based on the decryption key of the target symmetric encryption algorithm to obtain the decrypted original log data.
[0115] In this embodiment, if the digital signature verification passes, the decryption key corresponding to the target symmetric encryption algorithm is obtained, and the decryption key is used to decrypt the encrypted second log data to restore the original information, thereby obtaining the decrypted original log data. The decryption key is a subkey that can be obtained by decrypting the master key.
[0116] The original log data is returned to the user.
[0117] In this embodiment, the above-mentioned raw log data is returned to the user for analysis and use, such as for auditing, statistics or customer service improvement, thereby facilitating real-time monitoring, post-analysis and compliance checks by the user, thereby helping the insurance company to promptly identify potential security issues and take corresponding measures.
[0118] The present application determines whether a user-triggered audit request for the log data is received; if so, the specified public key of the target digital signature algorithm corresponding to the log data is obtained from the preset target cache; then the digital signature of the second log data is verified based on the specified public key; if the digital signature verification passes, the second log data is decrypted based on the decryption key of the target symmetric encryption algorithm to obtain the decrypted original log data; and the original log data is subsequently returned to the user. When the present application receives a user-triggered audit request for the log data, it will automatically and intelligently obtain the specified public key of the target digital signature algorithm corresponding to the log data from the preset target cache, and perform digital signature verification on the second log data based on the specified public key. Only when the digital signature verification passes, the second log data will be decrypted based on the decryption key of the target symmetric encryption algorithm, and the decrypted original log data will be returned to the user, effectively improving the processing standardization and security of the audit request for the log data. In addition, by returning the original log data to the user for analysis and use, the user experience can be effectively improved.
[0119] In some optional implementations, the user information obtained is obtained with the user's consent and complies with relevant laws and policies.
[0120] In addition, any software tools or components not provided by our company that appear in the embodiments of this application are merely examples and do not represent actual use.
[0121] In addition, this application provides comprehensive security protection for log data in the insurance consulting service system through innovative encryption and verification strategies, as well as efficient log processing processes. In the increasingly complex network environment and the growing demand for insurance consulting services, this insurance consulting service system log security protection solution based on DSA digital signatures and AES encryption will become one of the key technologies to ensure data security. By adopting a dual encryption mechanism, the present invention not only meets the needs of data confidentiality, but also ensures the integrity and source reliability of the data, providing a strong security guarantee for the digital transformation of the insurance industry.
[0122] Specifically, this application provides comprehensive security protection: By combining DSA digital signatures with AES encryption technology, this application provides comprehensive security protection for log data in the insurance consulting service system, including confidentiality, integrity, and source authenticity. This dual encryption mechanism ensures the security of data during transmission and storage.
[0123] Wide Applicability: This application is applicable to various insurance consulting service scenarios, such as online, telephone, and face-to-face consultations, meeting the needs of different insurance companies and customers. Regardless of the consultation method, this application can provide effective security protection for log data.
[0124] Efficient log processing: By automating the encryption, signing, storage, and management processes, this application improves the efficiency and accuracy of log processing and reduces the risk of manual intervention and errors. This enables insurance companies to manage and utilize log data more efficiently.
[0125] Scalable auditing capabilities: The system includes an audit function that records all encryption, decryption, and signature verification operations, facilitating real-time monitoring, post-analysis, and compliance checks. This helps insurance companies promptly identify potential security issues and take appropriate action.
[0126] It should be understood that the size of the serial numbers of the steps in the above embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0127] It should be emphasized that in order to further ensure the privacy and security of the above-mentioned second log data, the above-mentioned second log data can also be stored in a node of a blockchain.
[0128] The blockchain referred to in this application refers to a new application model for computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanisms, and encryption algorithms. Blockchain is essentially a decentralized database, a series of data blocks generated using cryptographic methods. Each data block contains information about a batch of network transactions, which is used to verify the validity of the information (to prevent counterfeiting) and generate the next block. Blockchain can include the blockchain underlying platform, the platform product service layer, and the application service layer.
[0129] The embodiments of the present application can acquire and process relevant data based on artificial intelligence technology. Artificial Intelligence (AI) is the theory, method, technology, and application system that uses digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use knowledge to achieve optimal results.
[0130] Fundamental AI technologies generally include sensors, dedicated AI chips, cloud computing, distributed storage, big data processing, operating / interaction systems, and mechatronics. AI software technologies primarily encompass computer vision, robotics, biometrics, speech processing, natural language processing, and machine learning / deep learning.
[0131] Those skilled in the art will appreciate that all or part of the processes in the above-described method embodiments can be implemented by instructing related hardware via computer-readable instructions. The computer-readable instructions can be stored in a computer-readable storage medium, and when the program is executed, it can include the processes in the above-described method embodiments. The aforementioned storage medium can be a non-volatile storage medium such as a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM).
[0132] It should be understood that although the steps in the flowcharts of the accompanying drawings are shown in sequence as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some of the steps in the flowcharts of the accompanying drawings may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily executed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be executed in turn or alternately with other steps or at least a portion of the sub-steps or stages of other steps.
[0133] Further references Figure 3 , as a response to the above Figure 2 The present application provides an embodiment of a log processing device. Figure 2 Corresponding to the method embodiment shown, the device can be specifically applied to various electronic devices.
[0134] like Figure 3 As shown, the log processing device 300 of this embodiment includes: a first acquisition module 301, a sorting module 302, a first generation module 303, a second generation module 304, an encryption module 305, a signature module 306 and a first storage module 307.
[0135] The first acquisition module 301 is used to acquire log data generated based on the user's consultation request;
[0136] The arranging module 302 is used to format the log data to obtain corresponding first log data;
[0137] The first generation module 303 is configured to obtain user identification data of the user and perform key generation processing on the user identification data based on a preset dynamic key generation strategy to obtain a corresponding encryption key;
[0138] A second generating module 304 is configured to obtain a data size of the first log data and generate a target encryption block size corresponding to a target symmetric encryption algorithm based on the data size;
[0139] An encryption module 305 is configured to encrypt the first log data using a specified encryption mode of the target symmetric encryption algorithm based on the encryption key and the target encryption block size to obtain corresponding second log data;
[0140] The signing module 306 is configured to digitally sign the second log data based on a preset target digital signature algorithm to obtain a corresponding target digital signature; wherein the key length of the target digital signature algorithm is generated based on a preset security performance requirement;
[0141] The first storage module 307 is configured to store the second log data and the target digital signature.
[0142] In this embodiment, the operations performed by the above modules or units correspond one-to-one to the steps of the log processing method in the aforementioned embodiment, and are not described in detail here.
[0143] In some optional implementations of this embodiment, the first generating module 303 includes:
[0144] A first acquisition submodule is used to obtain a timestamp corresponding to the log data;
[0145] a splicing submodule, configured to perform splicing processing on the user identification data and the timestamp to obtain corresponding spliced data;
[0146] An operation submodule, configured to perform a hash operation on the spliced data based on a preset target hash algorithm to obtain a corresponding hash operation result;
[0147] A determination submodule is configured to use the hash operation result as the encryption key.
[0148] In this embodiment, the operations performed by the above modules or units correspond one-to-one to the steps of the log processing method in the aforementioned embodiment, and are not described in detail here.
[0149] In some optional implementations of this embodiment, the encryption module 305 includes:
[0150] A second acquisition submodule is used to obtain encryption authentication conditions corresponding to the log data;
[0151] An analysis submodule, configured to analyze the encryption authentication condition to determine a specified encryption mode corresponding to the target symmetric encryption algorithm;
[0152] The first calling submodule is used to call the preset encryption environment;
[0153] The encryption submodule is used to encrypt the first log data in the encryption environment based on the encryption key and the target encryption block size using a specified encryption mode of the target symmetric encryption algorithm to obtain the second log data.
[0154] In this embodiment, the operations performed by the above modules or units correspond one-to-one to the steps of the log processing method in the aforementioned embodiment, and are not described in detail here.
[0155] In some optional implementations of this embodiment, the first storage module 307 includes:
[0156] a combining submodule, configured to perform data combining processing on the second log data and the target digital signature to obtain a corresponding data packet;
[0157] The second calling submodule is used to call the pre-built distributed storage medium;
[0158] A storage submodule, configured to store the data packet in the distributed storage medium;
[0159] The control submodule is used to perform access control processing on the distributed storage medium that completes the storage processing.
[0160] In this embodiment, the operations performed by the above modules or units correspond one-to-one to the steps of the log processing method in the aforementioned embodiment, and are not described in detail here.
[0161] In some optional implementations of this embodiment, the log processing device further includes:
[0162] A second acquisition module is used to obtain a pre-stored master key from a preset hardware module;
[0163] A first processing module, configured to encrypt the encryption key based on the master key to obtain an encrypted subkey;
[0164] A third acquisition module is used to obtain a preset target storage policy;
[0165] The second storage module is configured to perform storage processing on the subkey based on the target storage policy.
[0166] In this embodiment, the operations performed by the above modules or units correspond one-to-one to the steps of the log processing method in the aforementioned embodiment, and are not described in detail here.
[0167] In some optional implementations of this embodiment, the log processing device further includes:
[0168] A first determination module is configured to obtain an application scenario of the log data and determine a corresponding security performance requirement based on the application scenario;
[0169] A calling module is used to call a preset data mapping table;
[0170] a query module, configured to query the data mapping table based on the security performance requirement, so as to obtain a specified key length matching the security performance requirement from the data mapping table;
[0171] The second determining module is configured to use the specified key length as the key length of the target digital signature algorithm.
[0172] In this embodiment, the operations performed by the above modules or units correspond one-to-one to the steps of the log processing method in the aforementioned embodiment, and are not described in detail here.
[0173] In some optional implementations of this embodiment, the log processing device further includes:
[0174] A judgment module, configured to judge whether an audit request for the log data triggered by a user has been received;
[0175] A fourth obtaining module is configured to obtain, if yes, a designated public key of the target digital signature algorithm corresponding to the log data from a preset target cache;
[0176] a verification module, configured to perform digital signature verification on the second log data based on the specified public key;
[0177] A second processing module is configured to decrypt the second log data based on the decryption key of the target symmetric encryption algorithm to obtain decrypted original log data if the digital signature verification passes;
[0178] The returning module is used to return the original log data to the user.
[0179] In this embodiment, the operations performed by the above modules or units correspond one-to-one to the steps of the log processing method in the aforementioned embodiment, and are not described in detail here.
[0180] To solve the above technical problems, the present application also provides a computer device. Figure 4 , Figure 4 This is a basic structural block diagram of the computer device in this embodiment.
[0181] The computer device 4 includes a memory 41, a processor 42, and a network interface 43 that are interconnected through a system bus. It should be noted that the figure only shows a computer device 4 having components 41-43, but it should be understood that it is not required to implement all the components shown, and more or fewer components can be implemented instead. Among them, those skilled in the art can understand that the computer device here is a device that can automatically perform numerical calculations and / or information processing according to pre-set or stored instructions, and its hardware includes but is not limited to microprocessors, application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), digital signal processors (DSPs), embedded devices, etc.
[0182] The computer device may be a desktop computer, notebook computer, PDA, cloud server, etc. The computer device may interact with the user via a keyboard, mouse, remote control, touchpad, or voice control device.
[0183] The memory 41 includes at least one type of readable storage medium, including flash memory, hard disk, multimedia card, card-type memory (e.g., SD or DX memory), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, magnetic disk, optical disk, etc. In some embodiments, the memory 41 can be an internal storage unit of the computer device 4, such as the hard disk or memory of the computer device 4. In other embodiments, the memory 41 can also be an external storage device of the computer device 4, such as a plug-in hard disk equipped on the computer device 4, a smart memory card (SMC), a secure digital (SD) card, a flash card, etc. Of course, the memory 41 can also include both the internal storage unit of the computer device 4 and its external storage device. In this embodiment, the memory 41 is generally used to store the operating system and various application software installed on the computer device 4, such as computer-readable instructions of the log processing method. In addition, the memory 41 can also be used to temporarily store various types of data that have been output or are to be output.
[0184] In some embodiments, the processor 42 may be a central processing unit (CPU), a controller, a microcontroller, a microprocessor, or other data processing chip. The processor 42 is generally used to control the overall operation of the computer device 4. In this embodiment, the processor 42 is used to execute computer-readable instructions stored in the memory 41 or process data, such as computer-readable instructions for executing the log processing method.
[0185] The network interface 43 may include a wireless network interface or a wired network interface. The network interface 43 is generally used to establish a communication connection between the computer device 4 and other electronic devices.
[0186] Compared with the prior art, the embodiments of the present application have the following beneficial effects:
[0187] In an embodiment of the present application, the present application obtains log data generated based on a user's consultation request, formats the log data to obtain first log data, then performs key generation processing on the user identification data based on the use of a dynamic key generation strategy to obtain an encryption key, and generates a target encryption block size corresponding to the target symmetric encryption algorithm based on the data scale of the first log data, and then, based on the encryption key and the target encryption block size, uses the specified encryption mode of the target symmetric encryption algorithm to encrypt the first log data to obtain the corresponding second log data, and further digitally signs the second log data based on the use of the target digital signature algorithm to obtain the target digital signature, and finally stores the second log data and the target digital signature. After the above processing flow, the present application combines the optimized target symmetric encryption algorithm and the target digital signature algorithm for log processing, effectively improving the efficiency and accuracy of log processing, and ensuring the confidentiality, integrity and source reliability of the log data during transmission and storage.
[0188] The present application also provides another embodiment, namely, providing a computer-readable storage medium, wherein the computer-readable storage medium stores computer-readable instructions, and the computer-readable instructions can be executed by at least one processor to enable the at least one processor to perform the steps of the log processing method as described above.
[0189] Compared with the prior art, the embodiments of the present application have the following beneficial effects:
[0190] In an embodiment of the present application, the present application obtains log data generated based on a user's consultation request, formats the log data to obtain first log data, then performs key generation processing on the user identification data based on the use of a dynamic key generation strategy to obtain an encryption key, and generates a target encryption block size corresponding to the target symmetric encryption algorithm based on the data scale of the first log data, and then, based on the encryption key and the target encryption block size, uses the specified encryption mode of the target symmetric encryption algorithm to encrypt the first log data to obtain the corresponding second log data, and further digitally signs the second log data based on the use of the target digital signature algorithm to obtain the target digital signature, and finally stores the second log data and the target digital signature. After the above processing flow, the present application combines the optimized target symmetric encryption algorithm and the target digital signature algorithm for log processing, effectively improving the efficiency and accuracy of log processing, and ensuring the confidentiality, integrity and source reliability of the log data during transmission and storage.
[0191] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a number of instructions for enabling a terminal device (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in each embodiment of the present application.
[0192] Obviously, the embodiments described above are only some of the embodiments of the present application, rather than all of the embodiments. The preferred embodiments of the present application are given in the accompanying drawings, but they do not limit the patent scope of the present application. The present application can be implemented in many different forms. On the contrary, the purpose of providing these embodiments is to make the understanding of the disclosure of the present application more thorough and comprehensive. Although the present application has been described in detail with reference to the aforementioned embodiments, for those skilled in the art, it is still possible to modify the technical solutions described in the aforementioned specific embodiments, or to make equivalent replacements for some of the technical features therein. Any equivalent structure made using the contents of the present application specification and the accompanying drawings, directly or indirectly used in other related technical fields, is also within the scope of patent protection of the present application.
Claims
1. A log processing method, characterized in that: The steps include: Obtain log data generated based on user consultation requests; Formatting the log data to obtain corresponding first log data; Obtaining user identification data of the user, and performing key generation processing on the user identification data based on a preset dynamic key generation strategy to obtain a corresponding encryption key; Acquire the data size of the first log data, and generate a target encryption block size corresponding to a target symmetric encryption algorithm based on the data size; Encrypting the first log data using a specified encryption mode of the target symmetric encryption algorithm based on the encryption key and the target encryption block size to obtain corresponding second log data; Digitally signing the second log data based on a preset target digital signature algorithm to obtain a corresponding target digital signature; wherein the key length of the target digital signature algorithm is generated based on a preset security performance requirement; The second log data and the target digital signature are stored.
2. The log processing method according to claim 1, characterized in that: The step of performing key generation processing on the user identification data based on a preset dynamic key generation strategy to obtain a corresponding encryption key specifically includes: Obtaining a timestamp corresponding to the log data; performing splicing processing on the user identification data and the timestamp to obtain corresponding spliced data; Performing a hash operation on the spliced data based on a preset target hash algorithm to obtain a corresponding hash operation result; The hash operation result is used as the encryption key.
3. The log processing method according to claim 1, wherein: The step of encrypting the first log data using a specified encryption mode of the target symmetric encryption algorithm based on the encryption key and the target encryption block size to obtain corresponding second log data specifically includes: Obtaining encryption authentication conditions corresponding to the log data; Analyzing the encryption authentication condition to determine a specified encryption mode corresponding to the target symmetric encryption algorithm; Call the preset encryption environment; In the encryption environment, the first log data is encrypted using a specified encryption mode of the target symmetric encryption algorithm based on the encryption key and the target encryption block size to obtain the second log data.
4. The log processing method according to claim 1, wherein: The step of storing and processing the second log data and the target digital signature specifically includes: Performing data combination processing on the second log data and the target digital signature to obtain a corresponding data packet; Call pre-built distributed storage media; Storing the data packet in the distributed storage medium; Access control processing is performed on the distributed storage medium that has completed the storage processing.
5. The log processing method according to claim 1, wherein: After the steps of obtaining the user identification data of the user and performing key generation processing on the user identification data based on a preset dynamic key generation strategy to obtain a corresponding encryption key, the method further includes: Obtaining a pre-stored master key from a preset hardware module; Encrypting the encryption key based on the master key to obtain an encrypted subkey; Get the preset target storage policy; The subkey is stored based on the target storage policy.
6. The log processing method according to claim 1, wherein: Before the step of digitally signing the second log data based on a preset target digital signature algorithm to obtain a corresponding target digital signature, the method further includes: Obtaining an application scenario for the log data, and determining corresponding security performance requirements based on the application scenario; Call the preset data mapping table; querying the data mapping table based on the security performance requirement to obtain a specified key length matching the security performance requirement from the data mapping table; The specified key length is used as the key length of the target digital signature algorithm.
7. The log processing method according to claim 1, wherein: After the step of storing the second log data and the target digital signature, the method further includes: Determining whether a user-triggered audit request for the log data is received; If so, obtaining a designated public key of the target digital signature algorithm corresponding to the log data from a preset target cache; Performing digital signature verification on the second log data based on the specified public key; If the digital signature verification passes, decrypting the second log data based on the decryption key of the target symmetric encryption algorithm to obtain the decrypted original log data; The original log data is returned to the user.
8. A log processing device, characterized in that: include: A first acquisition module is used to acquire log data generated based on the user's consultation request; a collating module, configured to format the log data to obtain corresponding first log data; A first generation module is configured to obtain user identification data of the user and perform key generation processing on the user identification data based on a preset dynamic key generation strategy to obtain a corresponding encryption key; a second generating module, configured to obtain a data size of the first log data and generate a target encryption block size corresponding to a target symmetric encryption algorithm based on the data size; an encryption module, configured to encrypt the first log data using a specified encryption mode of the target symmetric encryption algorithm based on the encryption key and the target encryption block size to obtain corresponding second log data; a signature module, configured to digitally sign the second log data based on a preset target digital signature algorithm to obtain a corresponding target digital signature; wherein the key length of the target digital signature algorithm is generated based on a preset security performance requirement; The first storage module is used to store and process the second log data and the target digital signature.
9. A computer device, characterized in that: The method comprises a memory and a processor, wherein the memory stores computer-readable instructions, and the processor implements the steps of the log processing method according to any one of claims 1 to 7 when executing the computer-readable instructions.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-readable instructions, which, when executed by a processor, implement the steps of the log processing method according to any one of claims 1 to 7.