Encryption Method, Device, Computer Equipment and Storage Medium for Sensitive Information
By annotating and identifying sensitive information and combining three-part strings to encrypt, the problem of sensitive information being easily cracked in the prior art is solved, and data security and privacy are improved, ensuring data integrity and program readability.
Patent Information
- Application Number
- CN202011232009.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-11-06
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2040-11-06
AI Technical Summary
The encryption methods of sensitive information in the prior art are easily cracked, resulting in high risk of data leakage and cannot effectively ensure the security and privacy of data.
By annotating and identifying sensitive fields, combining three-part strings generated from Cyberark managed password, Git repository and random algorithm, they are combined according to the specified rules and encrypted, using the Guose algorithm for encryption, and monitoring and locking encrypted data in real time to prevent tampering.
It improves the security of sensitive information, eliminates the opportunity for development, operation and maintenance and DBA personnel to view sensitive data, ensures data integrity and user privacy, and improves the readability and maintenance convenience of the program.
Smart Images

Figure CN112329063B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of information encryption, and particularly to an encryption method, device, computer device and storage medium for sensitive information. Background Art
[0002] Most current enterprise online systems generally involve important sensitive data, such as salaries, bonuses, budgets, personnel information, etc. When developing projects related to enterprise systems, these sensitive data are usually stored in a mysql database in plain text, and at this time, all personnel related to this project can view it, resulting in relatively poor data confidentiality. Once these data are leaked, it may bring great negative impacts to the company or individuals. In the prior art, although these data are also encrypted, it is usually a relatively simple encryption method, and the password is easily cracked, and the problem of leakage cannot be fundamentally solved. Summary of the Invention
[0003] The main object of the present invention is to provide an encryption method, device, computer device and storage medium for sensitive information, aiming to solve the technical problem that passwords in the prior art are easily cracked.
[0004] Based on the above invention object, the present invention proposes an encryption method for sensitive information, including:
[0005] Obtain specified data;
[0006] Select sensitive fields to be encrypted from the specified data, and annotate and identify the sensitive fields to obtain identified data with identification;
[0007] According to the identification of the identified data, intercept a first string of a preset length from a preset managed password, obtain a second string from a preset Git repository, and randomly generate a third string through a random algorithm;
[0008] Combine the first string, the second string, and the third string according to a specified rule to obtain an encryption password;
[0009] Encrypt the identified data and the encryption password through a preset encryption algorithm to obtain encrypted data with the sensitive fields encrypted.
[0010] Further, before the step of intercepting a first string of a preset length from a preset managed password, it includes:
[0011] Generate a string through a preset random algorithm, and set the string as the managed password of Cyberark;
[0012] Register a virtual user in Cyberark and associate the virtual user with the first string of a preset length in the managed password; and,
[0013] The step of intercepting the first string of a preset length from the preset managed password includes:
[0014] Obtain a virtual user and intercept the first string associated with the virtual user from the managed password.
[0015] Further, before the step of obtaining the second string from the preset Git repository, it includes:
[0016] Store a preset random string in the Git repository;
[0017] Judge whether the encrypted password has been leaked;
[0018] If so, receive modification information through the user interface of the Git repository;
[0019] Modify the random string according to the modification information to obtain the second string.
[0020] Further, the step of annotating and marking the sensitive field to obtain the marked identification data includes:
[0021] Package the sensitive field to obtain an entity object of the sensitive field;
[0022] Add the already packaged annotation mark in front of the position where the entity object is located to obtain the marked identification data.
[0023] Further, the step of combining the first string, the second string, and the third string according to a specified rule to obtain the encrypted password includes:
[0024] Randomly shuffle the characters in the first string, the second string, and the third string respectively;
[0025] Randomly intersperse the characters in the shuffled first string, second string, and third string with each other and combine them into a whole string to obtain the encrypted password.
[0026] Further, after the step of encrypting the identification data and the encrypted password through a preset encryption algorithm to obtain the encrypted data with the sensitive field encrypted, it includes:
[0027] When it is monitored that a first data passes through a preset AOP program exit, judge whether the first data carries encrypted information;
[0028] If so, intercept the first data, and perform reverse decryption on the first data according to the encryption algorithm to obtain the specified data without encryption of the sensitive field.
[0029] Further, after the step of encrypting the identification data and the encryption password through a preset encryption algorithm to obtain encrypted data with the sensitive field encrypted, it includes:
[0030] Monitor the encrypted data in real time, and determine whether the encryption password has been tampered with;
[0031] If so, lock the encrypted data so that the encrypted data cannot be decrypted.
[0032] The present invention also provides an encryption device for sensitive information, including:
[0033] A data acquisition unit for acquiring specified data;
[0034] A selection field unit for selecting sensitive fields to be encrypted from the specified data, and annotating and identifying the sensitive fields to obtain identified identification data;
[0035] A character acquisition unit for intercepting a first string of a preset length from a preset escrow password according to the identification of the identification data, acquiring a second string from a preset Git repository, and randomly generating a third string through a random algorithm;
[0036] A combined password unit for combining the first string, the second string, and the third string according to a specified rule to obtain an encryption password;
[0037] An encrypted data unit for encrypting the identification data and the encryption password through a preset encryption algorithm to obtain encrypted data with the sensitive field encrypted.
[0038] Further, it further includes:
[0039] A repository storage unit for storing a preset random string in the Git repository;
[0040] A password judgment unit for judging whether the encryption password has been leaked;
[0041] A modification information unit for receiving modification information through the user interface of the Git repository when it is determined that the encryption password has been leaked;
[0042] A character modification unit for modifying the random string according to the modification information to obtain the second string.
[0043] Further, it further includes:
[0044] A judgment information unit, configured to judge whether the first data carries encrypted information when it is detected that the first data passes through a preset AOP program exit;
[0045] A decryption data unit, configured to determine that the first data carries encrypted information, intercept the first data, and perform reverse decryption on the first data according to the encryption algorithm to obtain the specified data without encryption of the sensitive field.
[0046] The present invention further provides a computer device, including a memory and a processor, where the memory stores a computer program, and when the processor executes the computer program, the steps of the above-mentioned encryption method for sensitive information are implemented.
[0047] The present invention further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the above-mentioned encryption method for sensitive information are implemented.
[0048] The beneficial effects of the present invention are as follows: By annotating and identifying sensitive information, then obtaining three parts of the password in three different ways, and then combining these three parts to obtain the password for encrypting sensitive information. After obtaining the password of the sensitive information according to the annotation identifier, the sensitive information is encrypted according to the password, which can ensure the security of data, eliminate the opportunity for any party of development, operation and maintenance, and DBA to view sensitive data, and effectively ensure the integrity of data and user privacy; moreover, by annotating and identifying data and encrypting according to the corresponding password, for R & D personnel, personnel in different environments can view and operate according to the encrypted information, which improves the readability of the program and makes the program easier to maintain. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] Figure 1 It is a schematic diagram of the steps of the encryption method for sensitive information in an embodiment of the present invention;
[0050] Figure 2 It is a schematic block diagram of the structure of the encryption device for sensitive information in an embodiment of the present invention;
[0051] Figure 3 It is a schematic block diagram of the structure of a computer device in an embodiment of the present invention.
[0052] The implementation, functional features and advantages of the object of the present invention will be further described with reference to the embodiments and the accompanying drawings. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0053] It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0054] Refer to Figure 1, the encryption method for sensitive information in this embodiment includes:
[0055] Step S1: Obtain specified data;
[0056] Step S2: Select sensitive fields that need to be encrypted from the specified data, and perform annotation marking on the sensitive fields to obtain marked identification data;
[0057] Step S3: According to the identification of the identification data, intercept a first string of a preset length from a preset managed password, obtain a second string from a preset Git repository, and randomly generate a third string through a random algorithm;
[0058] Step S4: Combine the first string, the second string, and the third string according to a specified rule to obtain an encryption password;
[0059] Step S5: Encrypt the identification data and the encryption password through a preset encryption algorithm to obtain encrypted data with the sensitive fields encrypted.
[0060] As described in the above steps S1 - S2, the above specified data can be the profile data of personnel in an enterprise, and these profile data can include information such as ID cards, phone numbers, salaries, bonuses, etc., or can be the salary, bonus, budget, etc. data of the enterprise. The specified data is stored in a preset database and needs to be directly obtained, or can be crawled from the Internet.
[0061] In this embodiment, sensitive fields that need to be encrypted are selected from the specified data. The above sensitive fields can be fields such as ID card numbers and phone numbers in the above profile data that record relatively important information, and then these sensitive fields are annotated and marked to obtain marked specified data, which is named the above identification data for easy distinction. Specifically, the above step S2 includes:
[0062] Step S21: Package the sensitive fields to obtain an entity object of the sensitive fields;
[0063] Step S22: Add the already packaged annotation mark to the front of the position where the entity object is located to obtain the marked identification data.
[0064] After identifying the sensitive fields, the sensitive fields are first encapsulated to obtain entity objects of the sensitive fields, that is, the sensitive fields are encapsulated into entity objects, and the preset annotation identifiers are encapsulated. Then, the encapsulated annotation identifiers are added in front of the positions where the sensitive fields encapsulated into entity objects are located. In this embodiment, it is implemented through a preset AOP (Aspect Oriented Programming) program. Through the setting of the AOP program, objects with annotation identifiers are made to pass through the entry of the AOP program, and then these objects are intercepted uniformly. That is, when the data passes through the entry, the identification data with the annotation identifier is intercepted for encryption.
[0065] As described in the above steps S3 - S4, to improve the security of the password, the above - mentioned encrypted password consists of three parts. The first part is the first string with a preset length intercepted from a preset managed password. The above - mentioned managed password is the password managed by Cyberark. Here, neither the length of the intercepted string nor the interception position is limited. A random string can be intercepted from the managed password to obtain the above - mentioned first string. The second part is the second string obtained from a preset Git repository. Since the random strings generated in different environments are different, for example, the strings generated in the development environment, test environment, and production environment are all different, and the strings generated in different environments can be stored in the Git repository, the strings retrieved from the Git repository in different environments are different. The third part is the third string randomly generated by a random algorithm, or a string can be generated by a random algorithm and then a part of it is intercepted. The above - mentioned first string, second string, and third string are combined according to a specified rule. For example, they are combined in a specified order. The second string is connected after the first string, and the third string is connected after the second string to obtain the above - mentioned encrypted password. Or, according to the business scenario, the combination method can be controlled, and a part of the string can be inserted into another part of the string. In this embodiment, each part of the string carries encryption and decryption information, and this encryption and decryption information corresponds to the above - mentioned annotation identifier. Therefore, the above - mentioned three parts of the string can be obtained based on the above - mentioned identifier, and the combination will only be performed when the encryption and decryption information of the three parts of the string matches.
[0066] In another embodiment, the above - mentioned encrypted password can also consist of two parts, that is, it can be composed of any two of the above - mentioned first string, second string, and third string. The combination method is not limited and can be directly connected for combination or combined by character interspersion.
[0067] As described in step S5 above, the above-mentioned designated data with identifiers is encrypted with the above-mentioned encryption password through a preset encryption algorithm to obtain designated data with sensitive fields encrypted. For the convenience of distinction, the designated data here is named encrypted data. The above encryption algorithm can adopt the national encryption algorithm, such as asymmetric algorithm, hash algorithm, etc. Since the encryption algorithm is a relatively mature existing technology, the encryption process will not be elaborated here.
[0068] The encryption method for sensitive information provided by this proposal annotates and identifies the data, and encrypts it according to the corresponding password. Moreover, due to different environments and different personnel, the generated and intercepted strings are different. Therefore, it can not only ensure the absolute security of the password, but also enable personnel in different environments to view and operate, which is very convenient.
[0069] In one embodiment, for step S3 above, before the step of intercepting the first string of a preset length from the preset managed password, it includes:
[0070] Step S01: Generate a string through a preset random algorithm, and set the string as the managed password of Cyberark;
[0071] Step S02: Register a virtual user in Cyberark, and associate the virtual user with the first string of the preset length in the managed password;
[0072] The step of intercepting the first string of a preset length from the preset managed password includes:
[0073] Step S30: Obtain the virtual user, and intercept the first string associated with the virtual user from the managed password according to the virtual user.
[0074] In this embodiment, before intercepting the first string in the managed password, a string is first generated through a random algorithm, and this string is set as the managed password of Cyberark, that is, this string is hosted as the managed password in Cyberark. The above Cyberark platform is a platform for hosting accounts. In this embodiment, a virtual user is applied for registration from this Cyberark platform, and the virtual user is associated with the part that needs to be used as the password, that is, associated with the first string of the preset length in the managed password, forming a mapping relationship. Subsequently, the corresponding first string can be obtained through the user name. That is, when generating the encryption password, first obtain the virtual user. In different environments, such as the development environment, the test environment, and the production environment, the corresponding virtual users are different, and their corresponding first strings are also different. When sensitive information needs to be encrypted, the first string associated with the virtual user can be intercepted from the managed password through the virtual user.
[0075] In one embodiment, before the step of obtaining the second string from the preset Git repository in the above step S3, the following steps are included:
[0076] Step S31: Store the preset random string in the Git repository;
[0077] Step S32: Determine whether the encrypted password has been leaked;
[0078] Step S33: If so, receive modification information through the user interface of the Git repository;
[0079] Step S34: Modify the random string according to the modification information to obtain the second string.
[0080] In this embodiment, the above random string can be generated by a preset rule or by a random algorithm. The above Git repository has a corresponding user interface, and the information in the Git repository can be modified through the user interface. Specifically, first store the random string in the Git repository. When the above encrypted password has not been generated, directly take out the above random string from the Git repository, which is defaulted to the above second string. When the encrypted password already exists, first determine whether the encrypted password has been leaked. For example, obtain the abnormal information of the specified data. At this time, the abnormal information can be expressed as the specified data being frequently viewed or viewed by a strange account, or the specified data being tampered with. Since each viewing has a record, the specified data can be determined whether it is abnormal by obtaining the record. In addition, the specified data abnormal information determined by the user can be automatically input. When the above abnormal information is obtained and it can be determined that the encrypted password has been leaked, the encrypted password can be directly modified by the user. Specifically, the modification information input by the user can be directly received through the user interface of the Git repository. The modification information can be a modification character instruction or a modified string. Then modify the above random string according to the above modification information, so that the existing random string changes, and a new string is obtained, that is, the above second string is obtained, so that the encrypted password changes, which is flexible while ensuring the security of the data.
[0081] In one embodiment, the above step S4 includes:
[0082] Step S41: Shuffle the characters in the first string, the second string, and the third string respectively;
[0083] Step S42: Randomly intersperse the characters in the shuffled first string, second string, and third string and merge them into a whole string to obtain the encrypted password.
[0084] In this embodiment, the first string, the second string, and the third string are combined according to a specified rule. To improve the security of the encrypted password, the characters in the first string, the second string, and the third string are randomly shuffled, that is, the character order in the three strings is shuffled. For example, "abcde" is shuffled into "bdaec", etc., to obtain the shuffled first string, second string, and third string. Then, the characters of these three strings are randomly interspersed with each other. For example, after shuffling, the first string is "bdaec", and the second string after shuffling is "25fhj", etc. When interspersing the characters of the three strings, the first character or the second character of the second string can be inserted between the first character and the second character of the first string, etc. This embodiment does not limit the order of the characters in the first string, the second string, and the third string and the interspersing order. After interspersing, they are combined to obtain the above-mentioned encrypted password.
[0085] In one embodiment, after the above step S5, it includes:
[0086] Step S6: When it is monitored that the first data passes through the preset AOP program exit, determine whether the first data carries encrypted information;
[0087] Step S7: If so, intercept the first data, and perform reverse decryption on the first data according to the encryption algorithm to obtain the specified data without encryption of the sensitive field.
[0088] In this embodiment, after the specified data is encrypted, the AOP program exit is continuously monitored to determine whether the first data passing through the AOP program exit carries encrypted information. The above-mentioned encrypted information is the same as the encrypted information carried by the above string. When it is determined that the first data passing through the AOP program exit has encrypted information, the encrypted first data can be intercepted and decrypted according to the above encryption algorithm. Of course, this decryption process is the reverse process of the above encryption process, which will not be elaborated here. The data obtained after decryption is the above-mentioned specified data.
[0089] In another embodiment, after the above step S5, it includes:
[0090] Step S6: Monitor the encrypted data in real time and determine whether the encrypted password has been tampered with;
[0091] Step S7: If so, lock the encrypted data so that the encrypted data cannot be decrypted.
[0092] In this embodiment, for the password protection policy of the above-mentioned specified data, real-time monitoring is carried out throughout the process to prevent the password from being tampered with. As described in steps S6 - S7, the above-mentioned encrypted data is monitored in real time. If the password of the encrypted data is tampered with, the encrypted data is locked so that it cannot be decrypted. Further, continuous monitoring can be carried out during use. When it is found that the password is tampered with, the above-mentioned specified data is locked so that it cannot be encrypted or decrypted, and a warning is issued to further ensure the security of the data.
[0093] Referring to Figure 2 , in this embodiment, an encryption device for sensitive information is provided. This device corresponds to the above-mentioned encryption method for sensitive information. The device includes:
[0094] A data acquisition unit 1 for acquiring specified data;
[0095] A selected field unit 2 for selecting sensitive fields to be encrypted from the specified data, and annotating and identifying the sensitive fields to obtain marked data with identification;
[0096] A character acquisition unit 3 for intercepting a first string of a preset length from a preset escrow password according to the identification of the marked data, obtaining a second string from a preset Git repository, and randomly generating a third string through a random algorithm;
[0097] A combined password unit 4 for combining the first string, the second string, and the third string according to a specified rule to obtain an encrypted password;
[0098] An encrypted data unit 5 for encrypting the marked data and the encrypted password through a preset encryption algorithm to obtain encrypted data with the sensitive fields encrypted.
[0099] As described in the above data acquisition unit 1 and selected field unit 2, the above-mentioned specified data can be the profile data of personnel in an enterprise, and these profile data can include information such as ID cards, phone numbers, salaries, and bonuses, or can be data such as the salary, bonus, and budget of the enterprise. The specified data is stored in a preset database and needs to be directly acquired, or can be crawled from the Internet.
[0100] In this embodiment, sensitive fields to be encrypted are selected from the specified data. The above-mentioned sensitive fields can be fields such as ID card numbers and phone numbers in the above-mentioned profile data that record relatively important information. Then, these sensitive fields are annotated and identified to obtain marked specified data, which is named the above-mentioned marked data here for easy distinction. Specifically, the above-mentioned selected field unit 2 includes:
[0101] An encapsulated object sub-unit for encapsulating the sensitive fields to obtain entity objects of the sensitive fields;
[0102] Add identification subunit: used to add the already encapsulated annotation identification in front of the position where the entity object is located to obtain the identified identification data with the identification.
[0103] After finding the sensitive fields, first encapsulate the sensitive fields to obtain the entity object of the sensitive fields, that is, encapsulate the sensitive fields into an entity object and encapsulate the preset annotation identification. Then add the already encapsulated annotation identification in front of the position where the sensitive fields encapsulated into the entity object are located. In this embodiment, it is implemented through a preset AOP (Aspect Oriented Programming) program. Through the AOP program setting, let the objects with annotation identification pass through the entrance of the AOP program, and then intercept these objects uniformly. That is, when the data passes through the entrance, intercept the identification data with the already carried annotation identification for encryption.
[0104] As described in the above-mentioned character acquisition unit 3 and combined password unit 4, in order to improve the security of the password, the above-mentioned encrypted password is composed of three parts. The first part is the first string with a preset length intercepted from the preset escrow password. The above-mentioned escrow password is the password escrowed by Cyberark. Here, neither the length of the intercepted string nor the interception position is limited. A random string can be intercepted from the escrow password to obtain the above-mentioned first string. The second part is the second string obtained from the preset Git repository. Since the random strings generated in different environments are different. For example, the strings generated in the development environment, test environment, and production environment are all different, and the strings generated in different environments can be stored in the Git repository. Therefore, the strings taken out from the Git repository in different environments are different. The third part is the third string randomly generated by a random algorithm, or a string can be generated by a random algorithm and then a part of it is intercepted. The above-mentioned first string, second string, and third string are combined according to a specified rule. For example, they are combined in a specified order. The second string is connected after the first string, and the third string is connected after the second string to obtain the above-mentioned encrypted password. Or the combination method can be controlled according to the business scenario, and a part of the string is inserted into another part of the string. In this embodiment, each part of the string carries encryption and decryption information, and this encryption and decryption information corresponds to the above-mentioned annotation identification. Therefore, the above-mentioned three parts of the string can be obtained based on the above-mentioned identification, and the combination will only be performed when the encryption and decryption information of the three parts of the string matches.
[0105] In another embodiment, the above-mentioned encrypted password can also be composed of two parts, that is, it can be composed of any two of the above-mentioned first string, second string, and third string. The combination method is not limited, and it can be directly connected and combined, or combined by character interspersion.
[0106] As described in the above-mentioned encrypted data unit 5, the above-mentioned identified specified data and the above-mentioned encryption password are encrypted through a preset encryption algorithm to obtain the specified data with sensitive fields encrypted. For the sake of distinction, the specified data here is named encrypted data. The above-mentioned encryption algorithm can adopt the national encryption algorithm, such as asymmetric algorithm, hash algorithm, etc. Since the encryption algorithm is a relatively mature existing technology, the encryption process will not be elaborated here.
[0107] The encryption method of sensitive information provided by this proposal annotates and identifies the data, and encrypts it according to the corresponding password. Since different environments and different personnel generate and intercept different strings, it can not only ensure the absolute security of the password, but also enable personnel in different environments to view and operate, which is very convenient.
[0108] In one embodiment, the above-mentioned encryption device for sensitive information includes:
[0109] A managed password unit, which is used to generate a string through a preset random algorithm and set the string as the managed password of Cyberark;
[0110] A registered user unit, which is used to register a virtual user in Cyberark and associate the virtual user with the first string of a preset length in the managed password;
[0111] The obtained character unit 3 includes:
[0112] A user obtaining unit, which is used to obtain a virtual user and intercept the first string associated with the virtual user from the managed password according to the virtual user.
[0113] In this embodiment, before intercepting the first string in the managed password, a string is first generated through a random algorithm and set as the managed password of Cyberark, that is, this string is used as the managed password and hosted to Cyberark. The above-mentioned Cyberark platform is a platform for hosting accounts. In this embodiment, a virtual user is applied for registration from this Cyberark platform and the virtual user is associated with the part that needs to be used as the password, that is, associated with the first string of a preset length in the managed password to form a mapping relationship. Subsequently, the corresponding first string can be obtained through the user name. That is, when generating the encryption password, the virtual user is first obtained. In different environments, such as the development environment, the test environment, and the production environment, the corresponding virtual users are different, and the corresponding first strings are also different. When sensitive information needs to be encrypted, the first string associated with the virtual user can be intercepted from the managed password through the virtual user.
[0114] In one embodiment, the encryption device for sensitive information includes:
[0115] A storage unit for storing a preset random string into the Git repository;
[0116] A password judgment unit for judging whether the encrypted password has been leaked;
[0117] A modification information unit for receiving modification information through the user interface of the Git repository when it is determined that the encrypted password has been leaked;
[0118] A character modification unit for modifying the random string according to the modification information to obtain the second string.
[0119] In this embodiment, the above-mentioned random string can be generated by a preset rule or by a random algorithm. The above-mentioned Git repository has a corresponding user interface, and the information in the Git repository can be modified through the user interface. Specifically, first store the random string into the Git repository. When the above-mentioned encrypted password has not been generated, directly take out the above-mentioned random string from the Git repository, which is defaulted to the above-mentioned second string. When the encrypted password already exists, first judge whether the encrypted password has been leaked. For example, obtain the abnormal information of the specified data. At this time, the abnormal information can be expressed as the specified data being frequently viewed or viewed by a strange account, or the specified data being tampered with. Since each view has a record, it is possible to determine whether the specified data is abnormal by obtaining the record. In addition, the abnormal information of the specified data determined by the user can be automatically input. When the above-mentioned abnormal information is obtained and it can be determined that the encrypted password has been leaked, the encrypted password can be directly modified by the user. Specifically, the modification information input by the user can be directly received through the user interface of the Git repository. The modification information can be a character modification instruction or a modified string. Then, modify the above-mentioned random string according to the above-mentioned modification information to change the previously existing random string and obtain a new string, that is, obtain the above-mentioned second string, so that the encrypted password changes, which is flexible while ensuring the security of the data.
[0120] In one embodiment, the above-mentioned combined password unit 4 includes:
[0121] A character scrambling unit for scrambling the characters in the first string, the second string, and the third string respectively;
[0122] A character merging unit for randomly interspersing the characters in the scrambled first string, second string, and third string and merging them into a whole string to obtain the encrypted password.
[0123] In this embodiment, the first string, the second string, and the third string are combined according to a specified rule. To improve the security of the encrypted password, the characters in the first string, the second string, and the third string are randomly shuffled, that is, the character order in the three strings is shuffled. For example, "abcde" is shuffled into "bdaec", etc., to obtain the shuffled first string, second string, and third string. Then, the characters of these three strings are randomly interspersed with each other. For example, after shuffling, the first string is "bdaec", and the second string after shuffling is "25fhj", etc. When interspersing the characters of the three strings, the first character or the second character of the second string can be inserted between the first character and the second character of the first string, etc. This embodiment does not limit the order of the characters in the first string, the second string, and the third string and the interspersing order. After interspersing, they are combined to obtain the above-mentioned encrypted password.
[0124] In one embodiment, the above-mentioned encryption device for sensitive information includes:
[0125] A judgment information unit, configured to judge whether the first data carries encrypted information when it is detected that the first data passes through a preset AOP program exit;
[0126] A decryption data unit, configured to determine that the first data carries encrypted information, intercept the first data, and perform reverse decryption on the first data according to the encryption algorithm to obtain the specified data without encryption of the sensitive field.
[0127] In this embodiment, after the specified data is encrypted, the AOP program exit is continuously monitored to determine whether the first data passing through the AOP program exit carries encrypted information. The above-mentioned encrypted information is the same as the encrypted information carried by the above-mentioned string. When it is determined that the first data passing through the AOP program exit has encrypted information, the encrypted first data can be intercepted and decrypted according to the above-mentioned encryption algorithm. Of course, this decryption process is the reverse process of the above-mentioned encryption process, which will not be elaborated here. The data obtained after decryption is the above-mentioned specified data.
[0128] In another embodiment, the above-mentioned encryption data unit 5 includes:
[0129] A real-time monitoring unit, configured to monitor the encrypted data in real time and judge whether the encrypted password is tampered with;
[0130] A locked data unit, configured to lock the encrypted data when it is determined that the encrypted password is tampered with, so that the encrypted data cannot be decrypted.
[0131] In this embodiment, for the password protection policy of the above-mentioned specified data, real-time monitoring is carried out throughout the process to prevent the password from being tampered with. As described above, the encrypted data is monitored in real time. If the password of the encrypted data is tampered with, the encrypted data is locked so that it cannot be decrypted. Further, continuous monitoring can be carried out during the use process. When it is found that the password is tampered with, the above-mentioned specified data is locked so that it cannot be encrypted or decrypted, and a warning is issued to further ensure the security of the data.
[0132] Referring to Figure 3 , in an embodiment of the present invention, a computer device is further provided. The computer device may be a server, and its internal structure may be as Figure 3 shown. The computer device includes a processor, a memory, a network interface, and a database connected through a system bus. Among them, the processor of the computer design is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store all the data required for encrypting the above-mentioned sensitive information. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it realizes an encryption method for sensitive information.
[0133] The steps for the above-mentioned processor to execute the encryption method for sensitive information: obtain specified data; select sensitive fields that need to be encrypted from the specified data, and annotate and identify the sensitive fields to obtain marked identification data; according to the identification of the identification data, intercept a first string of a preset length from a preset managed password, obtain a second string from a preset Git repository, and randomly generate a third string through a random algorithm; combine the first string, the second string, and the third string according to a specified rule to obtain an encryption password; encrypt the identification data and the encryption password through a preset encryption algorithm to obtain encrypted data with the sensitive fields encrypted.
[0134] In one embodiment, before the step of intercepting a first string of a preset length from a preset managed password, it includes: generating a string through a preset random algorithm, setting the string as the managed password of Cyberark; registering a virtual user in Cyberark, and associating the virtual user with the first string of the preset length in the managed password; and the step of intercepting a first string of a preset length from a preset managed password includes: obtaining the virtual user, and intercepting the first string associated with the virtual user from the managed password according to the virtual user.
[0135] In one embodiment, before the step of obtaining the second string from the preset Git repository, the following steps are included: storing a preset random string in the Git repository; determining whether the encrypted password has been leaked; if so, receiving modification information through the user interface of the Git repository; and modifying the random string according to the modification information to obtain the second string.
[0136] In one embodiment, the step of annotating and marking the sensitive field to obtain the marked identification data includes: encapsulating the sensitive field to obtain an entity object of the sensitive field; and adding the already encapsulated annotation mark in front of the position where the entity object is located to obtain the marked identification data.
[0137] In one embodiment, the step of combining the first string, the second string, and the third string according to a specified rule to obtain the encrypted password includes: scrambling the characters in the first string, the second string, and the third string respectively; and randomly interspersing the characters in the scrambled first string, second string, and third string and merging them into a whole string to obtain the encrypted password.
[0138] In one embodiment, after the step of encrypting the identification data and the encrypted password through a preset encryption algorithm to obtain the encrypted data with the sensitive field encrypted, the following steps are included: when it is monitored that a first data passes through a preset AOP program exit, determining whether the first data carries encrypted information; if so, intercepting the first data and performing reverse decryption on the first data according to the encryption algorithm to obtain the specified data without encryption of the sensitive field.
[0139] In one embodiment, after the step of encrypting the identification data and the encrypted password through a preset encryption algorithm to obtain the encrypted data with the sensitive field encrypted, the following steps are included: monitoring the encrypted data in real time and determining whether the encrypted password has been tampered with; if so, locking the encrypted data so that the encrypted data cannot be decrypted.
[0140] Those skilled in the art can understand that Figure 3 the structure shown is only a block diagram of some structures related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied.
[0141] An embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, a method for encrypting sensitive information is implemented, specifically: obtaining specified data; selecting sensitive fields that need to be encrypted from the specified data, and annotating and marking the sensitive fields to obtain marked identification data; according to the identification of the identification data, intercepting a first string of a preset length from a preset managed password, obtaining a second string from a preset Git repository, and randomly generating a third string through a random algorithm; combining the first string, the second string, and the third string according to a specified rule to obtain an encryption password; encrypting the identification data and the encryption password through a preset encryption algorithm to obtain encrypted data with the sensitive fields encrypted.
[0142] Before the step of intercepting the first string of a preset length from the preset managed password in the above computer-readable storage medium, it includes: generating a string through a preset random algorithm, and setting the string as the managed password of Cyberark; registering a virtual user in Cyberark, and associating the virtual user with the first string of the preset length in the managed password; and the step of intercepting the first string of a preset length from the preset managed password includes: obtaining the virtual user, and intercepting the first string associated with the virtual user from the managed password according to the virtual user.
[0143] In one embodiment, before the step of obtaining the second string from the preset Git repository in the above, it includes: storing a preset random string in the Git repository; judging whether the encryption password has been leaked; if so, receiving modification information through the user interface of the Git repository; and modifying the random string according to the modification information to obtain the second string.
[0144] In one embodiment, the step of annotating and marking the sensitive fields to obtain marked identification data includes: encapsulating the sensitive fields to obtain an entity object of the sensitive fields; adding the already encapsulated annotation mark in front of the position where the entity object is located to obtain the marked identification data.
[0145] In one embodiment, the step of combining the first string, the second string, and the third string according to a specified rule to obtain an encryption password includes: respectively scrambling the characters in the first string, the second string, and the third string; randomly interspersing the characters in the scrambled first string, second string, and third string, and merging them into a whole string to obtain the encryption password.
[0146] In one embodiment, after the step of encrypting the identification data and the encryption password through a preset encryption algorithm to obtain encrypted data with the sensitive field encrypted, the following steps are included:
[0147] When it is monitored that first data passes through a preset AOP program exit, determine whether the first data carries encryption information; if so, intercept the first data, and perform reverse decryption on the first data according to the encryption algorithm to obtain the specified data without encryption of the sensitive field.
[0148] In one embodiment, after the step of encrypting the identification data and the encryption password through a preset encryption algorithm to obtain encrypted data with the sensitive field encrypted, the following steps are included:
[0149] Monitor the encrypted data in real time, and determine whether the encryption password has been tampered with; if so, lock the encrypted data so that the encrypted data cannot be decrypted.
[0150] Those of ordinary skill in the art can understand that all or part of the processes in the above embodiment methods can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the above method embodiments. Among them, any reference to a memory, storage, database, or other medium provided in this application can include non-volatile and / or volatile memories. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or an external cache. By way of illustration and not limitation, there are various forms of RAM, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (SSRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.
[0151] It should be noted that in this text, the term "including", "comprising" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, apparatus, article or method comprising a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, apparatus, article or method. Without further limitation, an element defined by the phrase "comprising an..." does not exclude the presence of additional identical elements in the process, apparatus, article or method comprising such element.
[0152] The above are only the preferred embodiments of the present invention, and do not limit the patent scope of the present invention accordingly. Any equivalent structure or equivalent process transformation made by using the contents of the specification and drawings of the present invention, or directly or indirectly applied in other related technical fields, shall be similarly included in the patent protection scope of the present invention.
Claims
1. A method for encrypting sensitive information, characterized in that, Including: Obtain specified data; Select sensitive fields that need to be encrypted from the specified data, and annotate and identify the sensitive fields to obtain marked identification data; According to the identification of the identification data, intercept a first string of a preset length from a preset managed password, obtain a second string from a preset Git repository, and randomly generate a third string through a random algorithm; Combine the first string, the second string, and the third string according to specified rules to obtain an encryption password; Encrypt the identification data and the encryption password through a preset encryption algorithm to obtain encrypted data with the sensitive fields encrypted; Before the step of intercepting a first string of a preset length from a preset managed password, including: Generate a string through a preset random algorithm, and set the string as the managed password of Cyberark; Register a virtual user in Cyberark, and associate the virtual user with the first string of a preset length in the managed password; and The step of intercepting a first string of a preset length from a preset managed password includes: Obtain a virtual user, and intercept a first string associated with the virtual user from the managed password according to the virtual user; The step of annotating and identifying the sensitive fields to obtain marked identification data includes: Encapsulate the sensitive fields to obtain an entity object of the sensitive fields; Add the already encapsulated annotation identification in front of the position where the entity object is located to obtain the marked identification data.
2. The encryption method for sensitive information according to claim 1, characterized in that, Before the step of obtaining a second string from a preset Git repository, including: Store a preset random string in the Git repository; Judge whether the encryption password has been leaked; If so, receive modification information through the user interface of the Git repository; Modify the random string according to the modification information to obtain the second string.
3. The encryption method for sensitive information according to claim 1, wherein The step of combining the first string, the second string, and the third string according to specified rules to obtain an encryption password includes: Randomly shuffle the characters in the first string, the second string, and the third string respectively; Randomly intersperse the characters in the shuffled first string, second string, and third string and merge them into a whole string to obtain the encryption password.
4. The encryption method for sensitive information according to claim 1, wherein After the step of encrypting the identification data and the encryption password through a preset encryption algorithm to obtain encrypted data with the sensitive fields encrypted, including: When it is monitored that a first data passes through a preset AOP program exit, judge whether the first data carries encryption information; If so, intercept the first data, and perform reverse decryption on the first data according to the encryption algorithm to obtain the specified data without encryption of the sensitive fields.
5. The encryption method for sensitive information according to claim 1, wherein After the step of encrypting the identification data and the encryption password through a preset encryption algorithm to obtain encrypted data with the sensitive fields encrypted, including: Real-time monitor the encrypted data, and judge whether the encryption password has been tampered with; If so, lock the encrypted data so that the encrypted data cannot be decrypted.
6. An encryption device for sensitive information, characterized in that, The encryption device is applied to execute the encryption method of the sensitive information according to any one of claims 1-5: A data unit acquisition unit, configured to acquire specified data; A selected field unit, configured to select sensitive fields to be encrypted from the specified data, and annotate and identify the sensitive fields to obtain identified data with identification; A character acquisition unit, configured to intercept a first string of a preset length from a preset managed password, acquire a second string from a preset Git repository, and randomly generate a third string through a random algorithm according to the identification of the identified data; A combined password unit, configured to combine the first string, the second string, and the third string according to a specified rule to obtain an encryption password; An encrypted data unit, configured to encrypt the identified data and the encryption password through a preset encryption algorithm to obtain encrypted data with the sensitive fields encrypted.
7. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, the steps of the encryption method of the sensitive information according to any one of claims 1 to 5 are implemented.
8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, the steps of the encryption method of the sensitive information according to any one of claims 1 to 5 are implemented.
Citation Information
Patent Citations
Sensitive word encryption method and device based on hive data warehouse and storage medium
CN110990848A
Securely Transferring User Information Between Applications
US20180212771A1