Data interaction method and device, computer device, and storage medium
By encrypting and storing data from the business request end and implementing contactless interaction, the problems of data leakage and contact infection are solved, achieving efficient and secure data interaction.
Patent Information
- Application Number
- CN202110349369.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-03-31
- Publication Date
- 2025-12-23
- Estimated Expiration
- 2041-03-31
AI Technical Summary
In business scenarios, users manually entering data through contactless devices are easily spied on or recorded, leading to a high risk of information leakage, increased time consumption, impact on user experience, and the risk of contact infection.
By receiving target request data from the business request end, encrypting and storing it to generate encrypted encoded data, and providing it to the business execution end through contactless means, data security and convenience are ensured.
It improved the efficiency of data entry, avoided the risk of data leakage and contact infection, and enhanced the user experience.
Smart Images

Figure CN112948869B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] Embodiments of the present application relate to the technical field of computer technology, and particularly relate to a data interaction method and device, a computer device, and a storage medium. BACKGROUND
[0002] In many business scenarios, a user needs to manually enter information data required for handling a business on a device at a business execution end through a touch screen, a keyboard, or other contact devices. For example, when handling a transfer account business in a bank, the user needs to manually enter data such as a transfer account amount, a payee account number, and a transfer account password. However, the operation in such a data entry process is easy to be snooped by a passerby or illegally detected and recorded through a contact device, thereby causing information data to be leaked and a high security risk. Meanwhile, the manual entry method needs the user to perform the operation after arriving at a business handling site, thereby increasing a business handling time and being extremely low in efficiency, and seriously affecting user experience; and a large number of users use the same contact device to enter data, which easily causes indirect contact between users and increases a contact infection risk. SUMMARY
[0003] Embodiments of the present application provide a data interaction method and device, a computer device, and a storage medium, to improve the efficiency of data entry in a business scenario, avoid data leakage risk and contact infection risk caused by a user directly contacting a common device to enter data, improve the security and convenience of a data interaction process, and greatly optimize user experience.
[0004] In a first aspect, embodiments of the present application provide a data interaction method applied to a security processing device, including:
[0005] receiving target request data sent by a business request end;
[0006] performing encrypted storage processing on the target request data, and generating encrypted code data according to an encrypted storage processing result;
[0007] feeding back the encrypted code data to the business request end, so that the business request end provides the target request data to a business execution end through the encrypted code data.
[0008] In a second aspect, embodiments of the present application provide a data interaction method applied to a security processing device, including:
[0009] receiving to-be-decoded data sent by a business execution end; wherein the to-be-decoded data is generated by the business execution end according to encrypted code data provided by a business request end;
[0010] performing decoding analysis processing on the to-be-decoded data, and obtaining target storage data matched with the to-be-decoded data according to a decoding analysis processing result.
[0011] In a case where it is determined that the to-be-decoded data is valid according to the target storage data, target request data matched with the to-be-decoded data is acquired, and the target request data is fed back to the service execution end.
[0012] In a third aspect, an embodiment of the present application further provides a data interaction device configured in a security processing device, comprising:
[0013] A request data receiving module is configured to receive target request data sent by a service request end;
[0014] An encoded data generating module is configured to perform encryption storage processing on the target request data, and generate encrypted encoded data according to an encryption storage processing result;
[0015] An encoded data feeding back module is configured to feed back the encrypted encoded data to the service request end, so that the service request end provides the target request data to a service execution end through the encrypted encoded data.
[0016] In a fourth aspect, an embodiment of the present application further provides a data interaction device configured in a security processing device, comprising:
[0017] A to-be-decoded data receiving module is configured to receive to-be-decoded data sent by a service execution end; wherein the to-be-decoded data is generated by the service execution end according to encrypted encoded data provided by a service request end;
[0018] A storage data acquiring module is configured to perform decoding analysis processing on the to-be-decoded data, and acquire target storage data matched with the to-be-decoded data according to a decoding analysis processing result;
[0019] A request data feeding back module is configured to acquire target request data matched with the to-be-decoded data in a case where it is determined that the to-be-decoded data is valid according to the target storage data, and feed back the target request data to the service execution end.
[0020] In a fifth aspect, an embodiment of the present application further provides a computer device, comprising:
[0021] One or more processors;
[0022] A storage device configured to store one or more programs;
[0023] When the one or more programs are executed by the one or more processors, the one or more processors implement the data interaction method provided by any embodiment of the present application.
[0024] In a sixth aspect, an embodiment of the present application further provides a computer storage medium, which stores a computer program, and the computer program is executed by a processor to implement the data interaction method provided by any of the embodiments of the present application.
[0025] The embodiment of the present application receives the target request data input by the user in advance and sent by the service request end, and encrypts and stores the target request data, feeds back the encrypted code data corresponding to the target request data to the service request end according to the encryption and storage result of the target request data, so that the service request end can safely and quickly provide the target request data to the service execution end through the encrypted code data, improves the efficiency of data input in the service scenario, avoids the data leakage risk and contact infection risk caused by the user directly contacting and using the shared equipment to input data, improves the security and convenience of the data interaction process, and greatly optimizes the user experience. BRIEF DESCRIPTION OF DRAWINGS
[0026] Figure 1 A flowchart of a data interaction method provided for the first embodiment of the present application.
[0027] Figure 2 A flowchart of a data interaction method provided for the second embodiment of the present application.
[0028] Figure 3 A flowchart of a data interaction method provided for the third embodiment of the present application.
[0029] Figure 4 A flowchart of a data interaction method provided for the fourth embodiment of the present application.
[0030] Figure 5 A structural schematic diagram of a data interaction system provided for the fourth embodiment of the present application.
[0031] Figure 6 A structural schematic diagram of a data interaction device provided for the fifth embodiment of the present application.
[0032] Figure 7 A structural schematic diagram of a data interaction device provided for the sixth embodiment of the present application.
[0033] Figure 8 A structural schematic diagram of a computer device provided for the seventh embodiment of the present application. DETAILED DESCRIPTION
[0034] The present application will be further described below in conjunction with the drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the present application, but not to limit the present application.
[0035] It is also noted that the drawings may not be to scale as some components can be presented with exaggerated or minimized proportions to illustrate details of the exemplary embodiments. Also, the exemplary embodiments will be discussed in more detail with reference to the drawings. Before any exemplary embodiments are explained in detail, it is to be understood that the exemplary embodiments can be variously described as a process, a method, an apparatus, a system, a function, a procedure, a subroutine, a subroutine, a subroutine, etc. Although the process is described in a sequential order, some of the operations can be performed in parallel, concurrently or simultaneously, in some embodiments. In addition, the order of the operations can be re-arranged. The process can be terminated when its operations are completed, but can also have additional steps not included in the figure. The process can correspond to a method, a function, a procedure, a subroutine, etc.
[0036] Embodiment One
[0037] Figure 1 A flowchart of a data interaction method provided for the first embodiment of the present application, the embodiment can be applicable to the case where the user provides data to the business execution end by pre-entering data in the business request end. The method can be executed by the data interaction device provided by the embodiment of the present application, which can be realized by software and / or hardware, and can be generally integrated in a computer device, such as a security processing device. Correspondingly, as shown in Figure 1 the method includes the following operations:
[0038] S110, receiving target request data sent by the business request end.
[0039] The business request end can be a client used by the user, which can receive data entered by the user and can communicate with the security processing device. The security processing device can be a device for realizing data processing and storage, which is a middleware between the business request end and the business execution end, and is used to process the target request data sent by the business request end and send it to the business execution end. The target request data can be data entered by the user in the business request end, and can include but not limited to data necessary for handling business.
[0040] Correspondingly, the user can enter the business request end through the terminal device used, for example, can enter the pre-installed mobile banking client through the mobile phone, and enter the target request data in the business request end. After receiving the target request data entered by the user, the business request end can send it to the security processing device. The security processing device can receive the target request data sent by the business request end.
[0041] Optionally, the business request end can send target request data to the security processing device through a preset network communication device. The network communication device can use xml (Extensible Markup Language) to realize data interface based on http (Hyper Text Transfer Protocol). After receiving the target request data sent by the business request end, the network communication device can parse the target request data according to the predetermined xml tag name and send it to the security processing device.
[0042] S120, the target request data is encrypted and stored, and encrypted code data is generated according to the encrypted storage processing result.
[0043] The encrypted storage processing can be an operation of securely processing and storing the target request data. The encrypted storage processing result can include data describing the target request data after the encrypted storage processing, for example, it can include storage address data of the target request data after the security processing, and the target request data can be obtained according to the encrypted storage processing result. The encrypted code data can be data generated by encoding the encrypted storage processing result in a preset manner, wherein the encrypted storage processing result is stored, and the interaction can be realized through a non-contact way.
[0044] Correspondingly, the security processing device can perform encrypted storage processing on the target request data after receiving it. The specific way of encrypted storage processing can be determined according to the security policy preset by the user, and the specific content of the encrypted storage processing result can correspond to the specific way of encrypted storage processing. For example, the encrypted storage processing can include encrypting the target request data according to a preset encryption algorithm, storing the encrypted target request data in a database, and the encrypted storage processing result can be the storage address data of the target request data and the inverse algorithm matching the encryption algorithm used.
[0045] Further, the encrypted code data is generated according to the encrypted storage processing result, and the encrypted storage processing result can be stored in the encrypted code data. The encrypted code data can be realized through a non-contact way, for example, the encrypted code data can be image data, which can be displayed by one end and scanned or photographed by the other end to obtain the image data; for example, the encrypted code data can also be audio data, which can be played by one end and received by the other end to obtain the audio data.
[0046] S130, the encrypted code data is fed back to the business request end, so that the business request end provides the target request data to the business execution end through the encrypted code data.
[0047] The business execution end can be a client end that needs to obtain the target request data and handle a business according to the target request data.
[0048] Accordingly, after the encrypted coded data is fed back to the business request end, the user can display or play the encrypted coded data through the business request end, and provide the encrypted coded data to the business execution end through a non-contact approach, so that the business execution end can obtain the encrypted storage processing result in the encrypted coded data, and further obtain the target request data according to the encrypted storage processing result.
[0049] Optionally, the encrypted coded data can be encoded through a base64 encoding mode, and the generated encoded value is encapsulated in an xml data message and sent to the business request end, so that the business request end receives the decrypted coded data and provides the decrypted coded data to the business execution end.
[0050] The embodiment of the application provides a data interaction method, by receiving the target request data sent by the business request end and pre-recorded by the user, and encrypting and storing the target request data, feeding back the encrypted coded data corresponding to the target request data to the business request end according to the encrypted and stored result of the target request data, so that the business request end can safely and quickly provide the target request data to the business execution end through the encrypted coded data, improve the efficiency of data entry in a business scenario, avoid the data leakage risk and contact infection risk caused by the user directly contacting and using a shared device to enter data, improve the security and convenience of the data interaction process, and greatly optimize the user experience.
[0051] Embodiment two
[0052] Figure 2 A flowchart of a data interaction method provided by the embodiment two of the application is shown. The embodiment of the application is based on the above-mentioned embodiment and is embodied in the embodiment of the application. In the embodiment of the application, a specific optional implementation mode of encrypting and storing the target request data and generating encrypted coded data according to the encrypted and stored result is given.
[0053] As shown in the figure, the method of the embodiment of the application specifically includes: Figure 2
[0054] S210, receiving target request data sent by a business request end.
[0055] S220, encrypting and storing the target request data, and generating encrypted coded data according to the encrypted and stored result.
[0056] In an optional embodiment of the application, S220 can specifically include:
[0057] S221, generating identification character data matched with the target request data.
[0058] The identification character data can be a string generated according to a preset algorithm and can uniquely identify the target request data matched therewith.
[0059] Correspondingly, the identification character data can be generated after receiving the target request data, and the generated identification character data is different each time. The generated identification character data can match the target request data and can uniquely identify the target request data.
[0060] Optionally, a UUID (Universally Unique Identifier) mode can be used to generate a string of random characters as the identification character data.
[0061] S222, store the target request data and the identification character data corresponding thereto in a business database.
[0062] The business database can be a database for storing the target request data and the identification character data matched therewith, and can be pre-set in the security processing device.
[0063] Correspondingly, the target request data and the identification character data matched therewith are stored in the business database, and the target request data uniquely identified by the identification character data can be queried in the business database according to the identification character data.
[0064] S223, encode the identification character data to generate encrypted code data.
[0065] The encoding can be a preset encoding of the identification character data to generate the encrypted code data.
[0066] Correspondingly, the identification character data is stored in the encrypted code data by encoding the identification character data to generate the encrypted code data. After decoding the encrypted code data, the identification character data stored therein can be obtained, and the target request data matched therewith can be further queried in the business database according to the identification character data, so as to realize the interaction of the target request data.
[0067] The above embodiment generates the identification character data matched with the target request data in the process of encrypting and storing the target request data, encodes the identification character data to generate the encrypted code data as the content of data interaction, and even if the encrypted code data is illegally obtained and decoded in the process of data interaction, the obtained content is only the identification character data, which cannot access the business database to obtain the target request data, thereby effectively protecting the target request data and improving the security of data interaction.
[0068] In an optional embodiment of the present application, the target request data can include business information data and encoding parameter data; the encrypted encoding data can be two-dimensional code picture data storing the identification character data; the encoding processing of the identification character data to generate the encrypted encoding data can include: encoding processing of the identification character data according to the encoding parameter data to generate the two-dimensional code picture data.
[0069] The business information data can be data necessary for business processing, for example, can include business operation instructions and user account information, etc. The encoding parameter data can be data for parameter setting of the two-dimensional code picture data, for example, can include technical parameter data such as width, height, pattern color and background color of the two-dimensional code. The two-dimensional code picture data can be a two-dimensional barcode with readability, using black and white rectangular patterns to store binary data, and the data stored therein can be obtained after scanning.
[0070] Correspondingly, the business information data can be entered by the user through the business request end. For example, in the scenario of processing bank transfer business, the business information data can include business instruction data corresponding to the transfer request initiated by the user in the mobile bank client, and also include data such as customer number, customer account number, customer mobile phone number, customer certificate number, transfer amount, payee account number, payee opening bank and user transfer password, etc. related to the business input by the user in the form provided by the mobile bank client. The encoding parameter data can be set by the user through the business request end, or can be automatically set according to the device parameters of the business request end, for example, the user can set the pattern color and background color of the two-dimensional code in the mobile bank client, and automatically set the width and height of the two-dimensional code according to the width and height of the display screen of the mobile phone used by the user.
[0071] Further, when encoding processing of the identification character data is performed, two-dimensional code picture data with a certain format can be generated according to the encoding parameter data. Optionally, the ZXing open source image processing library can be used to encode process the identification character data according to the encoding parameter data to generate the two-dimensional code picture data.
[0072] The above embodiment stores the identification character data in the two-dimensional code picture data, so that the two-dimensional code picture data can be displayed by the business request end and scanned by the business execution end provided by the business request end, and the data can be safely and quickly interacted through a non-contact approach.
[0073] S230, feedback the encrypted encoding data to the business request end, so that the business request end provides the target request data to the business execution end through the encrypted encoding data.
[0074] In an optional embodiment of the present application, the method can further comprise: generating new identification character data matched with the target request data when receiving the re-encryption request sent by the service request end; in the service database, canceling the corresponding storage relationship between the target request data and the original identification character data, and storing the target request data and the new identification character data correspondingly; encoding the new identification character data to generate new encrypted code data, and feeding back the new encrypted code data to the service request end.
[0075] The re-encryption request can be generated by the service request end when detecting illegal acquisition operation on the encrypted code data. The illegal acquisition operation can include any operation that may cause the encrypted code data to be sent to other terminals.
[0076] Correspondingly, when the service request end detects the illegal acquisition operation on the encrypted code data, the re-encryption request can be immediately sent to the security processing device. After receiving the re-encryption request, the security processing device generates new identification character data, and the new identification character data can replace the original identification character data and be stored in the service database correspondingly with the target request data as the unique identification matched with the target request data. The original identification character data can be deleted, or the data content corresponding to the original identification character data can be modified to be empty. Then, after the original encrypted code data is illegally acquired, the original identification character data cannot be used to query the target request data in the service database.
[0077] Further, the new identification character data can be stored in the new encrypted code data through encoding processing, and the new encrypted code data is fed back to the service request end. After the service request end provides the new encrypted code data to the service execution end, the service execution end can acquire the new identification character data stored in the new encrypted code data, so as to query the corresponding target request data.
[0078] Optionally, in the case that the encrypted code data is two-dimensional code picture data storing the identification character data, the illegal acquisition operation on the encrypted code data can include a screenshot operation on the two-dimensional code picture data. When the service request end detects the screenshot operation on the two-dimensional code picture data, the re-encryption request is immediately sent to make the security processing device generate new identification character data and generate new two-dimensional code picture data corresponding to the two-dimensional code generation service.
[0079] The above implementation method enables the updating of the identifier character data corresponding to the target request data and the generation of new encrypted encoded data when there is a risk of leakage of encrypted encoded data. This replaces the encrypted encoded data and corresponding identifier character data with the newly generated encrypted encoded data and corresponding identifier character data, which can promptly invalidate the illegally obtained encrypted encoded data, avoid the leakage of target request data caused by the illegal acquisition of encrypted encoded data, and further improve the security of target request data.
[0080] In an optional embodiment of the present invention, after storing the target request data and the identifier character data in the business database, the method may further include: obtaining the generation time data of the identifier character data; and storing the generation time data and the identifier character data in the business database.
[0081] The generation time data can be the time when the identifier character data was generated, and its accuracy can be preset according to the business type, which is not limited here.
[0082] Correspondingly, the generation time data can be recorded at the moment the identifier character data is generated, or it can be obtained based on the generation time information contained in the identifier character data. For example, if the identifier character data is a random string generated in the UUID format, and the first part of it is determined by the generation time, then the generation time data of the identifier character data can be determined based on this part.
[0083] Furthermore, the generation time data and the identifier character data can be stored in the business database. Therefore, when the business execution end obtains the identifier character data through the encrypted encoded data, it can query the corresponding target request data and generation time data in the business database. The generation time of the identifier character data can then be determined based on the generation time data. For identifier character data with an excessively large interval between the generation time and the current time, it can be determined that there is a risk of leakage. Optionally, the identifier character data matching the target request data and the corresponding encrypted encoded data can be regenerated, and the new encrypted encoded data can be fed back to the business request end, replacing the original encrypted encoded data provided to the business execution end.
[0084] The above implementation method records the generation time of the identifier character data and judges the security of the identifier character data based on the generation time, thereby invalidating the identifier character data that is at risk of leakage and further improving the security of the target request data.
[0085] The embodiment of the present application provides a data interaction method, target request data pre-input by a user is received and sent by a service request end, and the target request data is encrypted and stored, encryption code data corresponding to the target request data is fed back to the service request end according to an encryption and storage result of the target request data, so that the service request end can safely and quickly provide the target request data to a service execution end through the encryption code data, the efficiency of data input in a service scenario is improved, data leakage risk and contact infection risk caused by direct contact of the user with a shared device for data input are avoided, the safety and convenience of a data interaction process are improved, and user experience is greatly optimized; further, in the process of encrypting and storing the target request data, identification character data matched with the target request data is generated, and encryption code data generated after encoding processing of the identification character data is used as data interaction content, so that, in the data interaction process, even if the encryption code data is illegally acquired and decoded, the obtained content is only the identification character data, the target request data cannot be accessed to obtain the target request data, the target request data is effectively protected, and the data interaction safety is further improved.
[0086] Embodiment three
[0087] Figure 3 A flowchart of a data interaction method provided by the embodiment three of the present application, the embodiment can be applied to the case that a user provides data to a service execution end by pre-inputting the data on a service request end, the method can be executed by the data interaction device provided by the embodiment of the present application, the device can be realized in the form of software and / or hardware, and is generally integrated in a computer device, for example, a security processing device. Correspondingly, as shown in the figure, Figure 3 the method comprises the following operations.
[0088] S310, receiving to-be-decoded data sent by a service execution end.
[0089] The to-be-decoded data is generated by the service execution end according to encryption code data provided by a service request end. The to-be-decoded data stores an encryption storage processing result stored in the encryption code data.
[0090] Correspondingly, after receiving the target request data sent by the service request end, the security processing device can perform encryption storage processing on the target request data, generate encryption coding data according to the encryption storage processing result, and feed back the encryption coding data to the service request end, that is, the encryption coding data stores the encryption storage processing result of the target request data. After receiving the encryption coding data fed back by the security processing device, the service request end can provide the encryption coding data to the service execution end. The service execution end can generate to-be-decoded data according to the encryption coding data, so that the encryption storage processing result stored in the encryption coding data can be obtained through the to-be-decoded data. For example, the encryption coding data can be image data, the image contains the stored data, the service request end can display the image data to show the service execution end, and the service execution end can scan or photograph the image data to generate to-be-decoded data.
[0091] Optionally, the service execution end can send the to-be-decoded data to the security processing device through a preset network communication device. After receiving the to-be-decoded data sent by the service execution end, the network communication device can perform base64 encoding on the to-be-decoded data, encapsulate the encoding value in an xml message, and send the xml message to the security processing device.
[0092] S320, decoding analysis processing is performed on the to-be-decoded data, and target storage data matching the to-be-decoded data is obtained according to a decoding analysis processing result.
[0093] The decoding analysis processing can be an operation of obtaining the data stored in the to-be-decoded data. The decoding analysis processing result can be the data stored in the to-be-decoded data, that is, the encryption storage processing result stored in the encryption coding data. The target storage data can be any pre-stored data obtained according to the decoding analysis processing result, and can include the target request data or be empty.
[0094] Correspondingly, the specific manner of decoding analysis processing on the to-be-decoded data can correspond to the encoding manner of generating the encryption coding data. After obtaining the decoding analysis processing result, that is, the encryption storage processing result stored in the encryption coding data, including but not limited to the storage position of the target request data after corresponding encryption storage processing, the data stored in the storage position is obtained, that is, the target storage data.
[0095] It should be noted that the encrypted coded data provided by the business request end to the business execution end may be invalid, that is, the data stored in the encrypted coded data does not include the encrypted storage processing result of the target request data, or cannot correctly describe the target request data after the encrypted storage processing, for example, the encrypted coded data is not fed back by the security processing device, or is set to be invalid due to the detection of the security processing device. At this time, the to-be-decoded data obtained according to the invalid encrypted coded data is also invalid. Correspondingly, the target storage data obtained according to the decoding analysis processing result of the invalid to-be-decoded data does not include the target request data, or cannot obtain any data according to the decoding analysis processing result of the invalid to-be-decoded data, and the target storage data can be empty.
[0096] S330, in the case that the to-be-decoded data is determined to be valid according to the target storage data, obtaining target request data matched with the to-be-decoded data, and feeding back the target request data to the business execution end.
[0097] Correspondingly, if the target request data is included in the target storage data, it can be determined that the to-be-decoded data is valid. Further, the target request data can be obtained and fed back to the business execution end, so that the business execution end performs the corresponding operation according to the target request data.
[0098] The embodiment of the application provides a data interaction method, by receiving the to-be-decoded data generated by the business execution end according to the encrypted coded data, and analyzing the to-be-decoded data to obtain the data stored therein, obtaining the target request data and feeding back the target request data in the case that the to-be-decoded data is determined to be valid according to the data, so that the business execution end can obtain the target request data through the encrypted coded data provided by the business request end, improve the efficiency of data entry in the business scene, avoid the data leakage risk and contact infection risk caused by the user directly contacting and using the shared equipment to enter data, improve the security and convenience of the data interaction process, and greatly optimize the user experience.
[0099] Embodiment four
[0100] Figure 4 A flowchart of a data interaction method provided by the fourth embodiment of the application. The above-mentioned embodiments are used as the basis for the embodiment of the application, and in the embodiment of the application, a specific optional implementation manner of decoding and analyzing the to-be-decoded data and obtaining the target storage data matched with the to-be-decoded data according to the decoding analysis processing result is given.
[0101] As shown in Figure 4 , the method of the embodiment of the application specifically includes:
[0102] S410, receiving the to-be-decoded data sent by the business execution end.
[0103] In an optional embodiment of the present application, the encrypted coded data is two-dimensional code picture data; and the to-be-decoded data is obtained by the service execution end performing a photographing process on the encrypted coded data.
[0104] The photographing process can be a scanning or photographing operation, and can generate picture data identical to the display content of the encrypted coded data.
[0105] Correspondingly, if the encrypted coded data is two-dimensional code picture data, the service request end can display and show the two-dimensional code picture data to the service execution end, so that the service execution end performs a photographing process on the two-dimensional code picture data to generate the to-be-decoded data. Therefore, the to-be-decoded data can be two-dimensional code picture data identical to the encrypted coded data, and the two-dimensional code picture data and the encrypted coded data store the same data.
[0106] S420, decoding and analyzing the to-be-decoded data, and obtaining target storage data matched with the to-be-decoded data according to a decoding and analyzing result.
[0107] In an optional embodiment of the present application, S420 can specifically include:
[0108] S421, decoding and analyzing the to-be-decoded data to obtain identification character data in the to-be-decoded data.
[0109] Correspondingly, after the security processing device receives the target request data sent by the service request end, the security processing device can generate identification character data matched with the target request data, store the target request data and the identification character data in the business database correspondingly, and generate encrypted coded data according to the identification character data, that is, store the identification character data in the encrypted coded data. The to-be-decoded data generated by the service execution end according to the encrypted coded data provided by the service request end also stores the identification character data. Therefore, the identification character data can be obtained after the to-be-decoded data is decoded and analyzed.
[0110] Optionally, when the encrypted coded data is two-dimensional code picture data generated by using a ZXing open-source image processing library for coding, the to-be-decoded data is two-dimensional code picture data identical to the encrypted coded data. Therefore, the ZXing open-source image processing library can also be used to decode and analyze the to-be-decoded data to obtain the identification character data stored in the to-be-decoded data.
[0111] S422, querying target storage data stored correspondingly with the identification character data in the business database.
[0112] Correspondingly, the data stored correspondingly with the identification character data in the business database is the target storage data.
[0113] In an optional embodiment of the present application, after the decoding analysis processing of the to-be-decoded data is performed and the target storage data matching the to-be-decoded data is obtained according to the decoding analysis processing result, the method further comprises: determining that the to-be-decoded data is invalid if the target request data is not included in the target storage data.
[0114] Correspondingly, if the target request data is not included in the target storage data, it can be determined that the identification character data does not exist in the business database or is not stored in correspondence with any target request data in the business database, which indicates that the to-be-decoded data is invalid.
[0115] In an optional embodiment of the present application, after the decoding analysis processing of the to-be-decoded data is performed and the target storage data matching the to-be-decoded data is obtained according to the decoding analysis processing result, the method further comprises: obtaining the generation time data of the target storage data if the target request data is included in the target storage data; obtaining the time difference value data between the generation time data and the current time data; determining that the to-be-decoded data is invalid if the time difference value data is greater than the preset time difference threshold data; and determining that the to-be-decoded data is valid if the time difference value data is not greater than the preset time difference threshold data.
[0116] The current time data can be the time at the current moment, and the accuracy thereof can be the same as that of the generation time data. The time difference value data can be the time length obtained by subtracting the generation time data from the current time data. The preset time difference threshold data can be the maximum time length during which the identification character data can remain valid.
[0117] Correspondingly, if the target request data is included in the target storage data, it can be determined that the identification character data matches the target request data, i.e., the identification character data and the encrypted coded data provided by the business request end are obtained in the encrypted storage processing of the target request data.
[0118] Further, the generation time data of the target storage data can be obtained to determine the generation time of the identification character data. If the time difference value data between the generation time data and the current time data is greater than the preset time difference threshold data, it indicates that the generation time of the identification character data is too far from the current time, and the identification character data has a leakage risk. Therefore, it is determined that the corresponding to-be-decoded data is invalid, so as to ensure that the target request data cannot be obtained by the business execution end according to the to-be-decoded data, i.e., the business cannot be handled for the business request end providing invalid encrypted coded data. If the time difference value data between the generation time data and the current time data is not greater than the preset time difference threshold data, it is determined that the identification character data is newly generated, and it is determined that the corresponding to-be-decoded data is valid.
[0119] S430, judging whether the to-be-decoded data is valid according to the target storage data, if yes, S440 can be executed, otherwise, S450 can be executed.
[0120] S440, obtaining target request data matched with the to-be-decoded data, and feeding back the target request data to the service execution end.
[0121] S450, feeding back abnormal notification data to the service execution end.
[0122] The abnormal notification data can be data indicating that the to-be-decoded data is invalid.
[0123] Correspondingly, if the to-be-decoded data is invalid, the service execution end can be informed that the to-be-decoded data is invalid by feeding back the abnormal notification data to the service execution end, so as to remind the user to reacquire the encrypted coded data and generate the to-be-decoded data.
[0124] Exemplarily, the embodiment of the present application also provides a data interaction system. Figure 5 The structure diagram of the data interaction system provided by the embodiment of the present application is shown in FIG. 1. Figure 5 As shown in the figure, the system is applied in a bank business scenario. The mobile bank client can be used as a service request end. The bank client can input his / her account number, password and other necessary information on the mobile bank client installed on the personal mobile phone, initiate a service handling request, and send target request data to the outside. The network communication device receives the target request data sent by the mobile bank client, sends it to the security processing device and calls the two-dimensional code picture generation service. The security processing device stores the target request data sent by the user and the corresponding generated identification character data in the service database, and generates two-dimensional code picture data storing the identification character data based on the two-dimensional code picture generation service, and feeds back to the mobile bank client. When the bank client arrives at the bank to handle the business within the specified time, the two-dimensional code picture data is displayed to the service execution end device of the bank counter through the mobile phone. The service execution end device scans the two-dimensional code picture data to obtain the same two-dimensional code picture as the to-be-decoded data, and sends it to the outside. The to-be-decoded data is sent to the security processing device again through the network communication device, and the two-dimensional code picture analysis service is called. The security processing device obtains the identification character data stored in the to-be-decoded data based on the two-dimensional code picture analysis service, so as to query the identification character data in the service database, and feed back the target request data to the service execution end device under the condition that the identification character data is valid. The service execution end device of the bank counter can fill in the target request data into the corresponding form to complete the input of the data required for business handling.
[0125] The embodiment of the present application provides a data interaction method, through receiving to be decoded data generated according to encrypted coded data sent by a service execution end, and analyzing the to be decoded data to obtain data stored therein, obtaining target request data and feeding back under the condition that the data is valid, so that the service execution end can obtain the target request data through the encrypted coded data provided by a service request end, improves the efficiency of data entry in a service scenario, avoids the data leakage risk and the contact infection risk caused by that a user directly contacts and uses a shared device to enter data, improves the security and convenience of the data interaction process, and greatly optimizes the user experience.
[0126] Embodiment five
[0127] Figure 6 The structure diagram of a data interaction device provided by the embodiment five of the present application is shown as Figure 6 The device comprises a request data receiving module 510, an encoded data generating module 520 and an encoded data feedback module 530.
[0128] The request data receiving module 510 is used for receiving target request data sent by a service request end.
[0129] The encoded data generating module 520 is used for performing encrypted storage processing on the target request data, and generating encrypted coded data according to the encrypted storage processing result.
[0130] The encoded data feedback module 530 is used for feeding back the encrypted coded data to the service request end, so that the service request end provides the target request data to a service execution end through the encrypted coded data.
[0131] In an optional embodiment of the present application, the encoded data generating module 520 can be specifically used for generating identification character data matched with the target request data, storing the target request data and the identification character data in a service database, and performing encoding processing on the identification character data to generate encrypted coded data.
[0132] In an optional implementation of the embodiment of the application, the device can further comprise: a re-encryption module, configured to generate new identification character data matched with the target request data when a re-encryption request sent by the service request end is received; wherein the re-encryption request is generated by the service request end when illegal acquisition operation on the encrypted coded data is detected; a re-storage module, configured to release the corresponding storage relationship between the target request data and the original identification character data in the service database, and to store the target request data and the new identification character data correspondingly; and a re-feedback module, configured to encode the new identification character data to generate new encrypted coded data, and to feed back the new encrypted coded data to the service request end.
[0133] In an optional implementation of the embodiment of the application, the coded data generation module 520 can further be configured to: acquire generation time data of the identification character data; and store the generation time data and the identification character data correspondingly in the service database.
[0134] In an optional implementation of the embodiment of the application, the target request data can comprise service information data and coded parameter data; the encrypted coded data can be two-dimensional code picture data in which the identification character data is stored; and the coded data generation module 520 can be configured to: encode the identification character data according to the coded parameter data to generate the two-dimensional code picture data.
[0135] The data interaction device described above can execute the data interaction method provided by any embodiment of the application, and has the corresponding functional modules and beneficial effects of executing the data interaction method.
[0136] The embodiment of the application provides a data interaction device, which receives target request data pre-recorded by a user and sent by a service request end, and encrypts and stores the target request data, feeds back encrypted coded data corresponding to the target request data to the service request end according to the encryption and storage result of the target request data, so that the service request end can safely and quickly provide the target request data to a service execution end through the encrypted coded data, improves the efficiency of data recording in a service scenario, avoids data leakage risk and contact infection risk caused by direct contact of the user with a shared device for recording data, improves the security and convenience of the data interaction process, and greatly optimizes the user experience.
[0137] Embodiment six
[0138] Figure 7 A structural schematic diagram of a data interaction device provided by the embodiment six of the application is shown in Figure 7As shown, the device comprises: a to-be-decoded data receiving module 610, a storage data obtaining module 620 and a request data feedback module 630.
[0139] The to-be-decoded data receiving module 610 is configured to receive to-be-decoded data sent by a service execution end; wherein the to-be-decoded data is generated by the service execution end according to encrypted and coded data provided by a service request end.
[0140] The storage data obtaining module 620 is configured to decode, analyze and process the to-be-decoded data, and obtain target storage data matched with the to-be-decoded data according to a decoding analysis processing result.
[0141] The request data feedback module 630 is configured to, in a case where it is determined that the to-be-decoded data is valid according to the target storage data, obtain target request data matched with the to-be-decoded data, and feed back the target request data to the service execution end.
[0142] In an optional implementation of the embodiment of the application, the storage data obtaining module 620 can be specifically configured to: decode, analyze and process the to-be-decoded data to obtain identification character data in the to-be-decoded data; and query target storage data corresponding to the identification character data in a service database.
[0143] In an optional implementation of the embodiment of the application, the device can further comprise a data invalidity determining module configured to, in a case where it is determined that the target storage data does not include target request data, determine that the to-be-decoded data is invalid.
[0144] In an optional implementation of the embodiment of the application, the device can further comprise a data validity determining module configured to, in a case where it is determined that the target storage data includes target request data, obtain generation time data of the target storage data; obtain a time difference value data between the generation time data and current time data; in a case where it is determined that the time difference value data is greater than preset time difference threshold data, determine that the to-be-decoded data is invalid; and in a case where it is determined that the time difference value data is not greater than the preset time difference threshold data, determine that the to-be-decoded data is valid.
[0145] In an optional implementation of the embodiment of the application, the device can further comprise an abnormality notification feedback module configured to, in a case where it is determined that the to-be-decoded data is invalid according to the target storage data, feed back abnormality notification data to the service execution end.
[0146] In an optional implementation of the embodiment of the application, the encrypted and coded data is two-dimensional code picture data; and the to-be-decoded data is obtained by the service execution end performing photographing processing on the encrypted and coded data.
[0147] The data interaction device can execute the data interaction method provided by any embodiment of the application, has the function module and beneficial effect corresponding to the execution of the data interaction method.
[0148] The data interaction device provided by the embodiment of the application receives the to-be-decoded data generated according to the encrypted coded data sent by the service execution end, and analyzes the to-be-decoded data to obtain the data stored therein, acquires the target request data and feeds back the target request data according to the data under the condition that the to-be-decoded data is valid, so that the service execution end can acquire the target request data through the encrypted coded data provided by the service request end, improves the efficiency of data entry in the service scenario, avoids the data leakage risk and contact infection risk caused by the direct contact of the user with the shared equipment for data entry, improves the security and convenience of the data interaction process, and greatly optimizes the user experience.
[0149] Embodiment seven
[0150] Figure 8 A structural schematic diagram of a computer device provided by the embodiment seven of the application is shown. Figure 8 A block diagram of an exemplary computer device 12 suitable to implement embodiments of the present application is shown. Figure 8 The computer device 12 shown is merely an example and should not impose any limitation on the function and use range of the embodiment of the application.
[0151] As shown in Figure 8 The computer device 12 is shown in the form of a general-purpose computing device. The components of the computer device 12 can include but are not limited to one or more processors 16, a memory 28, and a bus 18 connecting different system components including the memory 28 and the processor 16.
[0152] The bus 18 represents one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, a graphics acceleration port, a processor or a local bus using any of a variety of bus structures. For example, these architectures include but are not limited to an industry standard architecture (ISA) bus, a micro channel architecture (MAC) bus, an enhanced ISA bus, a video electronics standards association (VESA) local bus, and a peripheral component interconnect (PCI) bus.
[0153] The computer device 12 typically includes a variety of computer system readable media. These media can be any available media that can be accessed by the computer device 12, including volatile and non-volatile media, removable and non-removable media.
[0154] Memory 28 can include computer system readable media in the form of volatile memory, such as random access memory (RAM) 30 and / or cache memory 32. Computer device 12 can further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, storage system 34 can be provided for reading from and writing to a non-removable, non-volatile magnetic media (not shown and typically called a "hard drive"). Figure 8 Although not shown, computer device 12 can employ other, different, or Figure 8 additional components, such as one or more additional data storage devices (removable and / or non-removable, volatile and / or non-volatile). Computer device 12 can also be connected to a network (e.g., a LAN, a WAN, a LAN and / or a WAN included in an intranet, the Internet, etc.) via network adapter 20, which is one type of I / O adapter (as is conventional) to which computer device 12 can be connected. Network adapter 20 can also interface to one or more interfaces 22 that connect to one or more types of networks and / or communication lines, not just a single network or communication line. For example, in some embodiments, computer device 12 can have more than one network adapter 20 to interface to one or more type of networks or communication lines. For example, computer device 12 can be
[0155] Program / utility 40, having a set (at least one) of program modules 42, can be stored in, for example, memory 28 by way of example, and not limitation, as well as an operating system, one or more application programs, other program modules, and program data, and can include an implementation of a network environment, each or a combination thereof. Generally, program modules 42 include routines, programs, components, or the like, that perform particular
[0156] Computer device 12 can also communicate with one or more external devices 14 such as a keyboard or a pointing device, as well as other devices not shown, such as a display 24, which can be internal or external to computer device 12. Device 12 can also communicate with one or more devices that enable a user to interact with computer device 12; and / or one or more devices that enable computer device 12 to communicate with one or more other computing devices. Such communication can be via input / output (I / O) interface(s) 22. Similarly, such communication can be via network adapter 20, which can be an external device in communication with, for example, a modem, a network, or a local portion of a network, such as a LAN. Network adapter 20 can also be a component of computer device 12, and can be any device configured to allow computer device 12 to communicate with one or more remote devices. Network adapter 20 can include, by way of example, a wireless network adapter, a telephone modem, a cable modem, a DSL modem, a Tl, T2, T3, or T4, modem, or user datagram protocol (UDP) module, as examples. Figure 8 It will be appreciated that, although not shown, other hardware and / or software elements can be utilized in conjunction with computer device 12, such as microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data archival storage systems, etc.
[0157] The processor 16 performs various function applications and data processing by running programs stored in the memory 28, and implements the data interaction method provided by the embodiment of the application: receiving target request data sent by a service request end; performing encryption storage processing on the target request data, and generating encryption coding data according to the encryption storage processing result; feeding back the encryption coding data to the service request end, so that the service request end provides the target request data to a service execution end through the encryption coding data.
[0158] Or, receiving to-be-decoded data sent by a service execution end; wherein the to-be-decoded data is generated by the service execution end according to encryption coding data provided by a service request end; performing decoding analysis processing on the to-be-decoded data, and obtaining target storage data matched with the to-be-decoded data according to the decoding analysis processing result; in the case that it is determined that the to-be-decoded data is valid according to the target storage data, obtaining target request data matched with the to-be-decoded data, and feeding back the target request data to the service execution end.
[0159] Embodiment eight
[0160] The embodiment eight of the application provides a computer readable storage medium, and a computer program is stored on the computer readable storage medium. The program is executed by a processor to implement the data interaction method provided by the embodiment of the application: receiving target request data sent by a service request end; performing encryption storage processing on the target request data, and generating encryption coding data according to the encryption storage processing result; feeding back the encryption coding data to the service request end, so that the service request end provides the target request data to a service execution end through the encryption coding data.
[0161] Or, receiving to-be-decoded data sent by a service execution end; wherein the to-be-decoded data is generated by the service execution end according to encryption coding data provided by a service request end; performing decoding analysis processing on the to-be-decoded data, and obtaining target storage data matched with the to-be-decoded data according to the decoding analysis processing result; in the case that it is determined that the to-be-decoded data is valid according to the target storage data, obtaining target request data matched with the to-be-decoded data, and feeding back the target request data to the service execution end.
[0162] Any combination of one or more computer readable medium can be utilized. The computer readable medium can be a computer readable signal medium or a computer readable storage medium. A computer readable storage medium can be, for example, but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples (a non-exhaustive list) of the computer readable storage medium include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing. In the context of this document, a computer readable storage medium can be any tangible medium that can contain, or store a program for use by or in connection with an instruction execution system, apparatus, or device.
[0163] A computer readable signal medium can include a propagated data signal with computer readable program code embodied therein, for example, in baseband or as part of a carrier wave. Such a propagated signal can take any of a variety of forms, including, but not limited to, electro-magnetic, optical, or any suitable combination thereof. A computer readable signal medium can be any computer readable medium that is not a computer readable storage medium and that can communicate, propagate, or transport a program for use by or in connection with an instruction execution system, apparatus, or device.
[0164] Program code embodied on a computer readable medium can be transmitted using any appropriate medium, including but not limited to wireless, wireline, optical fiber cable, RF, etc., or any suitable combination of the foregoing.
[0165] Computer program code for carrying out operations of the present application can be written in any combination of one or more programming languages, including an object oriented programming language such as Java, Smalltalk, C++ or the like and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider). These implementations can provide for a great deal of flexibility, portability, and adaptability.
[0166] Note that the above merely describes preferred embodiments of the present application and the principles of the technology applied. Those skilled in the art will understand that the present application is not limited to the specific embodiments described herein, and that various obvious changes, modifications and substitutions can be made without departing from the scope of the present application. Therefore, although the present application has been described in detail through the above embodiments, the present application is not limited to the above embodiments, and can include more other equivalent embodiments without departing from the concept of the present application, and the scope of the present application is determined by the scope of the claims.
Claims
1. A data interaction method, characterized in that, The application is applied to a security processing device, comprising: receiving target request data sent by a service request end; encrypting and storing the target request data, and generating encrypted code data according to the result of the encryption and storage processing; feeding back the encrypted code data to the service request end, so that the service request end provides the target request data to a service execution end through the encrypted code data; receiving to-be-decoded data sent by the service execution end; wherein the to-be-decoded data is generated by the service execution end according to the encrypted code data provided by the service request end; decoding and analyzing the to-be-decoded data, and obtaining target storage data matched with the to-be-decoded data according to the result of the decoding and analyzing processing; if it is determined that the to-be-decoded data is valid according to the target storage data, obtaining target request data matched with the to-be-decoded data, and feeding back the target request data to the service execution end; wherein the encryption and storage processing of the target request data comprises: encrypting the target request data by using a preset encryption algorithm, and storing the target request data after the encryption processing into a database; wherein the result of the encryption and storage processing comprises storage address data of the target request data and a reverse algorithm matched with the encryption algorithm.
2. The method of claim 1, wherein, The encryption and storage processing of the target request data, and the generation of encrypted code data according to the result of the encryption and storage processing, comprise: generating identification character data matched with the target request data; storing the target request data and the identification character data in a service database correspondingly; encoding the identification character data to generate encrypted code data.
3. The method of claim 2, wherein, Further comprising: when receiving a re-encryption request sent by the service request end, generating new identification character data matched with the target request data; wherein the re-encryption request is generated by the service request end when detecting an illegal acquisition operation of the encrypted code data; in the service database, canceling the corresponding storage relationship between the target request data and the original identification character data, and storing the target request data and the new identification character data correspondingly; encoding the new identification character data to generate new encrypted code data, and feeding back the new encrypted code data to the service request end.
4. The method of claim 2, wherein, After storing the target request data and the identification character data in the service database correspondingly, further comprising: obtaining generation time data of the identification character data; storing the generation time data and the identification character data in the service database correspondingly.
5. The method according to any of claims 2-4, characterized by, The target request data comprises service information data and encoding parameter data; The encrypted code data is two-dimensional code picture data in which the identification character data is stored; The encoding processing of the identification character data to generate encrypted code data comprises: encoding the identification character data according to the encoding parameter data to generate the two-dimensional code picture data.
6. The method of claim 1, wherein, The decoding and analyzing processing of the to-be-decoded data, and the obtaining of target storage data matched with the to-be-decoded data according to the result of the decoding and analyzing processing, comprise: Decoding and analyzing the to-be-decoded data to obtain identification character data in the to-be-decoded data; Querying target storage data corresponding to the identification character data in the service database.
7. The method of claim 1, wherein, After decoding and analyzing the to-be-decoded data and obtaining target storage data matching the to-be-decoded data according to a decoding and analyzing result, the method further includes: In a case where it is determined that the target storage data does not include target request data, determining that the to-be-decoded data is invalid.
8. The method of claim 7, wherein, After decoding and analyzing the to-be-decoded data and obtaining target storage data matching the to-be-decoded data according to a decoding and analyzing result, the method further includes: In a case where it is determined that the target storage data includes target request data, obtaining generation time data of the target storage data; Obtaining time difference value data between the generation time data and current time data; In a case where it is determined that the time difference value data is greater than preset time difference threshold data, determining that the to-be-decoded data is invalid; In a case where it is determined that the time difference value data is not greater than preset time difference threshold data, determining that the to-be-decoded data is valid.
9. The method of claim 1, wherein, After decoding and analyzing the to-be-decoded data and obtaining target storage data matching the to-be-decoded data according to a decoding and analyzing result, the method further includes: In a case where it is determined that the to-be-decoded data is invalid according to the target storage data, feeding back exception notification data to the service execution end.
10. The method according to any of claims 1 to 9, characterized in that, The encrypted and encoded data is two-dimensional code picture data; The to-be-decoded data is obtained by photographing the encrypted and encoded data by the service execution end.
11. A data interaction device, characterized by The security processing apparatus includes: A request data receiving module configured to receive target request data sent by a service request end; An encoded data generating module configured to perform encrypted storage processing on the target request data, and generate encrypted and encoded data according to an encrypted storage processing result; An encoded data feeding back module configured to feed back the encrypted and encoded data to the service request end, so that the service request end provides the target request data to a service execution end through the encrypted and encoded data; A to-be-decoded data receiving module configured to receive to-be-decoded data sent by a service execution end, wherein the to-be-decoded data is generated by the service execution end according to encrypted and encoded data provided by the service request end; A storage data obtaining module configured to decode and analyze the to-be-decoded data, and obtain target storage data matching the to-be-decoded data according to a decoding and analyzing result; A request data feeding back module configured to, in a case where it is determined that the to-be-decoded data is valid according to the target storage data, obtain target request data matching the to-be-decoded data, and feed back the target request data to the service execution end. The encoded data generating module is specifically configured to: Encrypt the target request data by using a preset encryption algorithm, and store the encrypted target request data in a database. The encrypted storage processing result includes storage address data of the target request data and a reverse algorithm matching an encryption algorithm used by the target request data.
12. A computer device, comprising: The computer device includes: One or more processors; a storage device for storing one or more programs; when the one or more programs are executed by the one or more processors, the one or more processors implementing the data interaction method according to any one of claims 1-10.
13. A computer storage medium having stored thereon a computer program, characterized in that The program is executed by the processor to implement the data interaction method according to any one of claims 1-10.
Citation Information
Patent Citations
Information encryption method and device, computer equipment and storage medium
CN110011958A
Transaction data protection method and device, electronic equipment and medium
CN112202794A