Information security interaction method and device

By using the "two-handshake" method and the use of information query request credentials in the information security interaction method, the problem of inability to control the scope of customer personal information and difficult to trace information access in the prior art is solved, and the security verification and legality management of customer personal information is realized, and online information security is ensured.

CN113704580BActive Publication Date: 2025-05-16INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202110993425.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-08-27
Publication Date
2025-05-16
Estimated Expiration
2041-08-27

AI Technical Summary

Technical Problem

The existing technology cannot clearly define the scope of use of customer personal information, nor can it traceability management of the access and acquisition of customer personal information, resulting in the difficulty of defining the responsibilities of both parties to the information interaction when the customer's personal information is leaked or used without recognition.

Method used

Through an information security interaction method, the "two-handshake" method is used to provide information query services to the query requester, and generate information query request vouchers to safely verify the legitimacy of the query requester, and traceable management of the information query request to control the scope of use of customer personal information.

Benefits of technology

It realizes the security verification and legality management of customer personal information, ensures the security of online customer personal information, and effectively prevents the leakage of customer personal information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113704580B_ABST
    Figure CN113704580B_ABST
Patent Text Reader

Abstract

The present application provides an information security interaction method and device, which relates to the field of information security and can also be used in the financial field, including: performing an initial information query according to a first information query request sent by a query requester, and generating an information query request number; sending the information query request number to the query requester, so that the query requester generates an information query request certificate according to the information query request number; performing a secondary information query according to a second information query request sent by the query requester and the information query request certificate, and sending the secondary information query result to the query requester. The present application can perform a secure information query according to the information query request and the information query request certificate sent by the query requester.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of information security and can be used in the financial field, specifically to an information security interaction method and device. Background Art

[0002] In the era of widespread Internet application, the continuous application of new technologies has promoted the operation and development of the national economy and society. With the continuous innovation of financial technology and the rapid popularization of online banking services, more and more government departments, enterprises and institutions have launched their own online financial products, providing their customers with convenient online financial services.

[0003] As the main body of online financial services, banks may have a large number of information interactions with various government departments, enterprises and institutions. There are many business scenarios involving the interaction of customer personal information. During the interaction process, once the customer's personal information is hijacked and the customer's privacy is leaked, it will not only cause serious losses to the customer's funds, but also may affect the bank's reputation and image. Therefore, when providing, obtaining and using customer personal information, banks must assume the responsibility of protecting the security of customer personal information.

[0004] In the existing technology, banks mainly use basic information security measures such as dedicated line access, data desensitization, data encryption and digital signatures to interact with various government departments, enterprises and institutions to reduce the risk of leakage of customer personal information. However, relying on the existing information security protection means, it is impossible to clearly limit the scope of use of customer personal information, nor is it possible to trace the access and acquisition of customer personal information. Once the customer's personal information is leaked or the customer does not agree that his personal information is being used, it is difficult to define the responsibilities of both parties in the information exchange. Summary of the invention

[0005] In response to the problems in the prior art, the present application provides an information security interaction method and device, which can perform security information query based on the information query request and information query request credentials sent by the query requester.

[0006] In order to solve the above technical problems, this application provides the following technical solutions:

[0007] In a first aspect, the present application provides an information security interaction method, comprising:

[0008] Performing an initial information query according to the first information query request sent by the query requester, and generating an information query request number;

[0009] Sending the information query request number to the query request party, so that the query request party generates an information query request voucher according to the information query request number;

[0010] A secondary information query is performed according to the second information query request sent by the query requester and the information query request credential, and the secondary information query result is sent to the query requester.

[0011] Further, the first information query request includes an information query condition and a first query request server address, and the initial information query is performed according to the first information query request sent by the query requester, and an information query request number is generated, including:

[0012] Generate the information query request number according to the information query condition and the first query request server address;

[0013] Performing an initial information query according to the information query conditions and generating an initial information query result;

[0014] The information query request number is associated with the initial information query result and saved.

[0015] Furthermore, before performing a secondary information query according to the second information query request sent by the query requester and the information query request credential, the method further includes:

[0016] Determine whether the second information query request and the information query request credential meet a preset information query request condition.

[0017] Furthermore, the second information query request includes a query expiration time, a second query request server address, and the information query condition, and determining whether the second information query request and the information query request credential meet the preset information query request condition includes:

[0018] Determine whether the current system time exceeds the query expiration time;

[0019] If not, determining whether the second query request server address is consistent with the first query request server address;

[0020] If so, determining whether the information query condition exceeds a preset legal range of the information query condition;

[0021] If not, determine whether the information query request certificate is legal.

[0022] Furthermore, the second information query request includes the information query request number, and the performing of a secondary information query according to the second information query request sent by the query requester and the information query request credential, and sending the secondary information query result to the query requester, includes:

[0023] Searching the initial information query result according to the information query request number;

[0024] The initial information query result is sent to the query requester as the secondary information query result.

[0025] Furthermore, the second information query request includes the information query request number, and the performing of a secondary information query according to the second information query request sent by the query requester and the information query request credential, and sending the secondary information query result to the query requester, includes:

[0026] Searching the initial information query result according to the information query request number;

[0027] Performing a secondary information query based on the initial information query result to obtain the secondary information query result;

[0028] The secondary information query result is sent to the query requester.

[0029] In a second aspect, the present application provides an information security interaction device, comprising:

[0030] A request number generating unit, used to perform an initial information query according to a first information query request sent by a query requester, and generate an information query request number;

[0031] A request credential generating unit, configured to send the information query request number to the query request party, so that the query request party generates an information query request credential according to the information query request number;

[0032] The information query unit is used to perform a secondary information query according to the second information query request sent by the query requester and the information query request credential, and send the secondary information query result to the query requester.

[0033] Furthermore, the first information query request includes an information query condition and a first query request server address, and the request number generating unit includes:

[0034] A request number generating module, used to generate the information query request number according to the information query condition and the first query request server address;

[0035] A primary information query result generating module, used for performing a primary information query according to the information query condition and generating a primary information query result;

[0036] The association module is used to associate the information query request number with the initial information query result and save it.

[0037] Furthermore, the information security interaction device further includes:

[0038] The query request condition judgment unit is used to determine whether the second information query request and the information query request credential meet a preset information query request condition.

[0039] Furthermore, the second information query request includes a query expiration time, a second query request server address and the information query condition, and the information query unit includes:

[0040] An expiration time determination module, used to determine whether the current system time exceeds the query expiration time;

[0041] An address determination module, used to determine whether the second query request server address is consistent with the first query request server address;

[0042] A query condition legality determination module, used to determine whether the information query condition exceeds a preset information query condition legality range;

[0043] The request credential legitimacy determination module is used to determine whether the information query request credential is legal.

[0044] Furthermore, the second information query request includes the information query request number, and the information query unit includes:

[0045] A search module, used for searching the initial information query result according to the information query request number;

[0046] A sending module is used to send the initial information query result as the secondary information query result to the query requester.

[0047] Furthermore, the second information query request includes the information query request number, and the information query unit includes:

[0048] A search module, used for searching the initial information query result according to the information query request number;

[0049] A query module, used to perform a secondary information query based on the initial information query result to obtain the secondary information query result;

[0050] A sending module is used to send the initial information query result as the secondary information query result to the query requester.

[0051] In a third aspect, the present application provides an electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the information security interaction method when executing the program.

[0052] In a fourth aspect, the present application provides a computer-readable storage medium having a computer program stored thereon, which implements the steps of the information security interaction method when executed by a processor.

[0053] In response to the problems in the prior art, the information security interaction method and device provided by the present application can provide information query services to the query requester in a "two-way handshake" manner. By generating an information query request credential during the information query process, the legitimacy of the information query request made by the query requester can be securely verified. At the same time, the legitimacy of the information query request can be traceably managed, and the scope of use of customer personal information can be controlled at the level of interaction between the two parties, thereby ensuring the security of online customer personal information and effectively preventing the leakage of customer personal information. BRIEF DESCRIPTION OF THE DRAWINGS

[0054] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0055] Figure 1 This is a flowchart of the information security interaction method in an embodiment of the present application;

[0056] Figure 2 A flowchart for generating an information query request number in an embodiment of the present application;

[0057] Figure 3 This is a flowchart for determining information query request conditions in an embodiment of the present application;

[0058] Figure 4 This is one of the flow charts for performing secondary information query in an embodiment of the present application;

[0059] Figure 5 This is the second flow chart of performing secondary information query in the embodiment of the present application;

[0060] Figure 6 This is a structural diagram of the information security interaction device in the embodiment of the present application;

[0061] Figure 7 This is a structural diagram of a request number generating unit in an embodiment of the present application;

[0062] Figure 8 This is a structural diagram of the information query unit in the embodiment of the present application;

[0063] Fig. 9 This is one of the structural diagrams of the information query unit in the embodiment of the present application;

[0064] Fig.10 This is the second structural diagram of the information query unit in the embodiment of the present application;

[0065] Fig.11 A schematic diagram of the structure of an electronic device in an embodiment of the present application;

[0066] Fig.12 This is one of the business process diagrams in the embodiment of the present application;

[0067] Fig.13 This is the second schematic diagram of the business process in the embodiment of the present application. DETAILED DESCRIPTION

[0068] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0069] The information security interaction method provided in this application can be used in the business scenario of customer personal information interaction. The business scenario includes at least two participants, one is the information query requester, and the other is the information query service provider. Among them, the more typical query requester can be a government agency, a financial center, and a third-party financial service provider platform, and the information query service provider can be a bank and other financial institutions, but this application is not limited to this.

[0070] The provider of customer personal information shall assume the responsibility of protecting the security of customer personal information when obtaining, providing and using customer personal information. Although basic information security measures such as dedicated line access, data desensitization, data encryption and digital signatures have been adopted in the prior art to ensure the security of customer personal information, it is impossible to clearly define the scope of use of customer personal information, nor is it possible to manage the use of customer personal information in a traceable manner. When a customer disagrees with the scope of use of his or her personal information, or does not acknowledge that he or she has authorized the provider of the customer's personal information to use his or her personal information or provide his or her personal information to others, it is difficult to define the responsibilities of both parties to the information interaction. To this end, the present application provides an information security interaction method.

[0071] It should be noted that the information security interaction method and device provided in the present application can be used in the financial field, and can also be used in any field other than the financial field. The application field of the information security interaction method and device provided in the present application is not limited.

[0072] In one embodiment, see Figure 1In order to perform secure information query based on the information query request and information query request credential sent by the query requester, the information security interaction method provided by this application includes:

[0073] S101: performing an initial information query according to a first information query request sent by a query requester, and generating an information query request number;

[0074] It is understandable that when the query requester needs to obtain the customer personal information stored in the information query service provider, it can initiate an information query request to the information query service provider. For security reasons, this application proposes a customer personal information security interaction method based on query authorization. Among them, the information query requester and the information query service provider can safely complete the interaction of customer personal information through a "two-way handshake". During the interaction process, traditional encryption technology and digital signature technology can be used to pre-process customer personal information to ensure the integrity and security of the customer personal information itself.

[0075] It should be noted that in the first handshake of the "two-way handshake", the query requester needs to send a first information query request to the provider of the information query service, so that the provider of the information query service can perform an initial information query based on the first information query request and generate an information query request number. The so-called first information query request includes at least: information query conditions and the first query request server address, but this application is not limited to this. Among them, the information query conditions may include but are not limited to the customer's name, customer ID number, and the time period selected for the query. In one embodiment, the information query request number can be a combination of the time when the request occurred and the customer's ID number, such as 202108011107, but this application is not limited to this. The information query request number is only for identifying this information query request.

[0076] In one embodiment, the information query request number can be generated by a snowflake algorithm, using the time when the request occurs, the customer's ID number, and an auto-increment sequence taken from the database as input parameters to generate a globally unique information query request number through the snowflake algorithm.

[0077] The first query request server address can be used to compare with the second query request server address sent by the query requester during the second handshake to confirm that the "two handshakes" come from the same query requester, thereby further ensuring the security of information interaction.

[0078] That is to say, step S101 can be understood as the process of the first handshake between the two parties. In this process, the provider of the information query service can complete the initial information query and generate a unique information query request number for the first information query request corresponding to it, so that this number can be used as the basis for mutual recognition between the two parties in the future. Among them, the initial information query result is not sent to the query requester for the time being, but is stored on the provider side of the information query service until the second handshake is successful, and then the information query result is sent to the query requester to complete the security information exchange.

[0079] It should be noted that the initial information query result can be either the final information query result required by the query requester or the SQL query statement corresponding to the final information query result. In some cases, the final information query result has a large amount of data and is a detailed result. If the detailed result is stored during the initial information query, it will consume a large amount of storage space. In this case, you can choose to save only the SQL query statement corresponding to the final information query result as the initial information query result.

[0080] S102: Sending the information query request number to the query requesting party, so that the query requesting party generates an information query request voucher according to the information query request number;

[0081] It can be understood that, according to the above, the information query request number is a specific number generated by the provider of the information query service for this information query. After the provider of the information query service sends the information query request number to the query requester, the query requester can use this number as the basis for identity authentication in the subsequent information interaction process. Specifically, the information query request certificate is generated according to the information query request number. The significance of the information query request certificate is that with the information query request certificate, the provider of the information query service can obtain the identity information of the query requester; not only that, the information query request certificate can also contain the digital signature information of the customer that the query requester wants to query. The personal digital signature information indicates that the query requester and its customer agree that the query requester conducts this information query service, and agrees that the provider of the information query service will provide the query requester with its customer personal information; retaining the information query request certificate can provide a legal basis for any subsequent disputes over the leakage of customer personal information.

[0082] The information query request voucher can adopt the format agreed upon in advance by the two parties to the information interaction. For example, the information query request voucher can include an authorization code, an authorization letter, and an authorization picture, among which the information query request number is also indispensable. The validity of the authorization can also be determined based on the above information. During the interaction process, the information query request voucher can be provided by the query requester, and its validity can be determined by the provider of the information query service. Thereby, the interaction of customer personal information can be managed in a traceable manner, and the scope of use of customer personal information can be limited to strictly control the purpose and object of customer personal information. In one embodiment, the information query request number and the authorization code can be used to generate a QR code according to certain rules as a generated information query request voucher.

[0083] For example, by inputting the information query request number and the authorization code into the public class CreateQRCode for generating a QR code, a QR code can be generated according to the binary digital encoding rules.

[0084] S103: Perform a secondary information query according to the second information query request and the information query request credential sent by the query requester, and send the secondary information query result to the query requester.

[0085] It is understandable that this step reflects the second handshake process of the method described in this application. After the two parties to the information exchange complete the first handshake, the provider of the information query service can perform a second information query based on the second information query request and information query request credential sent by the query requester, and send the second information query result to the query requester.

[0086] The second information query request at least includes the information query request number, the query expiration time, the second query request server address and the information query condition. The information query request number is the unique number of this information query, and the initial information query result stored in the information query service provider that has been pre-queried in step S101 can be found with this number. After finding it, the information query service provider can send the initial information query result as the secondary information query result to the query requester to complete the security information interaction process.

[0087] From the above description, it can be seen that the information security interaction method provided by the present application can provide information query services to the query requester in a "two-way handshake" manner. By generating an information query request credential during the information query process, the legitimacy of the information query request made by the query requester can be securely verified. At the same time, the legitimacy of the information query request can be traceably managed, and the scope of use of customer personal information can be controlled at the level of interaction between the two parties, thereby ensuring the security of online customer personal information and effectively preventing the leakage of customer personal information.

[0088] In order to more clearly describe the characteristics and advantages of the method described in this application, the following will take the government platform initiating an inquiry into the details of personal wage payments to the bank (provider of information inquiry services) as an example to further explain the implementation process of the method described in this application. In this business scenario, the bank, as the provider of information inquiry services, will provide secure information inquiry services to the government platform as the inquiry requester.

[0089] In one embodiment, see Figure 2 The first information query request includes an information query condition and a first query request server address, performs an initial information query according to the first information query request sent by the query requester, and generates an information query request number, including:

[0090] S201: Generate an information query request number according to the information query condition and the first query request server address;

[0091] S202: Performing an initial information query according to the information query conditions and generating an initial information query result;

[0092] S203: Associate the information query request number with the initial information query result and save them.

[0093] It can be understood that step S201 to step S203 embody the first handshake process in the method described in this application, and the specific process is as follows (can be combined with Fig.12 ):

[0094] ① The government platform initiates the first query request to the bank through a dedicated line and sends the information query conditions. In the scenario of querying the details of salary payment, the query conditions can be: customer name, customer ID number, and query selected time period, etc. At the same time, the government platform also needs to send the server IP address (acquireIp) used to obtain the final information query results;

[0095] ② After receiving the first query request, the bank can generate a unique number (applyId) corresponding to the first query request, that is, the information query request number, and generate a database query SQL statement (querySql) for the customer's wage payment details according to the information query conditions; for example, the information query request number is a combination of the customer's ID number and the first query request server IP address number; the SQL statement pseudo code for querying the wage payment details data can be expressed as: select account number, account name, salary entry date, entry time, entry amount, summary from bank wage payment details table where customer ID number = ID number uploaded by the query party and account name = customer name uploaded by the query party and entry time between start date and end date; this application is not limited to this;

[0096] ③The bank stores the information query request number (applyId), the server IP address (acquireIp) sent by the government platform, the application receipt time, the query expiration time, the database query sql statement (querySql) and other information in the backend customer information query application form. Among them, the query expiration time can be agreed upon in advance by the interacting parties. In this scenario, because in related businesses, the government platform may conduct multiple inquiries on individual salary payment details in a short period of time, the bank and the government platform agree that 30 minutes after receiving the query request, the query request will be invalid;

[0097] ④The bank returns the information query request number (applyId) to the government platform;

[0098] ⑤ The government platform receives the information query request number (applyId) returned by the bank and registers the number. At this point, the two parties in information exchange have completed the first handshake process.

[0099] In one embodiment, the intermediate data generated in the above process can be stored in a "Customer Information Query Application Form" (which can be used as the initial information query result), for example:

[0100]

[0101]

[0102] The subsequent second handshake process can read the "Customer Information Inquiry Application Form" to obtain the necessary information.

[0103] From the above description, it can be seen that the information security interaction method provided by the present application can perform an initial information query based on the first information query request sent by the query requester and generate an information query request number.

[0104] In one embodiment, performing a secondary information query according to the second information query request sent by the query requester and the information query request credential includes:

[0105] Determine whether the second information query request and the information query request credential meet a preset information query request condition.

[0106] It is understandable that before performing the secondary information query, it is necessary to determine whether the second information query request and the information query request credential meet the preset information query request conditions, that is, to perform a legality judgment; if the legality judgment passes, the information query service provider can perform the secondary information query. For details of the specific process, please refer to the description of steps S301 to S304.

[0107] It can be seen from the above description that the information security interaction method provided by the present application can perform a secondary information query based on the second information query request sent by the query requester and the information query request credential.

[0108] In one embodiment, see Figure 3 The second information query request includes a query expiration time, a second query request server address, and the information query condition, and the determining whether the second information query request and the information query request credential meet the preset information query request condition includes:

[0109] S301: Determine whether the query expiration time exceeds the current system time;

[0110] S302: If not, determine whether the second query request server address is consistent with the first query request server address;

[0111] S303: If yes, determine whether the information query condition exceeds a preset legal range of the information query condition;

[0112] S304: If not, determine whether the information query request certificate is legal.

[0113] It can be understood that steps S301 to S304 reflect the second handshake process in the method described in this application. The specific process is as follows (can be combined with Fig.13 ):

[0114] ① After the government platform submits an inquiry request for the customer's personal wage payment information with the first information inquiry request, it is necessary to generate an information inquiry request certificate in accordance with the information inquiry request certificate format agreed upon by the two parties and keep it on file. This certificate can indicate that the customer knows and agrees that his or her personal information will be provided to the inquiry requesting party for a certain purpose. In this scenario: the inquiry certificate is an authorization letter from the individual (customer) authorizing the government platform to inquire about the details of personal wage payment, which needs to be signed by the customer himself or herself;

[0115] ② The government platform (query requester) initiates a query result acquisition request to the bank (query service provider), which is also the second information query request; uploads the query request number (applyId), the information query request credential (authCode) of the query, and the authorization time. The information query request credential can be a BASE64 encoded image, an accessible image URL address, or a string type authorization code. In this scenario, the information query request credential is the URL address of the image of the personal salary payment details query authorization letter;

[0116] ③ The bank (query service provider) receives the request from the government platform (query requester) and obtains the query request number (applyId). According to the query request number, it obtains the information acquisition server IP address (acquireIp), query failure time (failTime), and database query SQL statement (querySql) from the customer information query application form;

[0117] ④ The bank (query service provider) compares the current system time with the query failure time (failTime). If the system time is later than the failure time, the government platform query failure result is returned, and the query failure result and reason (query has timed out) are registered in the customer information query application form, and the second request interaction process is completed;

[0118] ⑤ If the query is not invalid, the bank (query service provider) continues to obtain the visitor's IP. To avoid the invalidation of the Request.getRemoteAddr() method after the access passes through reverse proxy software such as nginx, the following method can be used to obtain the visitor's IP address: first obtain X-Real-IP from the Header. If it does not exist, use "," to split the first IP from X-Forwarded-For. If it still does not exist, call Request.getRemoteAddr() to obtain the IP.

[0119] ⑥ The bank (query service provider) compares the obtained visitor IP with the information acquisition server IP address (acquireIp) obtained in the table to see if they are consistent. If they are inconsistent, the query failure result is returned, and the query failure result and reason (query IP does not match) are recorded in the customer information query application form, and the secondary request interaction process is completed;

[0120] ⑦ If the two IPs are consistent, the bank (query service provider) will register the information query request credential (authCode) sent by the government platform (query requester) in the customer information query application form, and obtain the query authorization credential generated by the query requester based on the credential information. Verify the validity of the authorization credential according to the rules agreed upon by the two parties. In this scenario, the bank can register the URL address of the personal salary payment details query authorization letter image sent by the government platform in the customer information query application form, access the URL address to obtain the authorization letter image, obtain the authorization content and customer signature content through OCR recognition technology, compare the authorization content with the authorization template, and compare the customer signature content with the customer name. If the two are successfully compared, the authorization credential is considered valid.

[0121] ⑧ If the bank (query service provider) determines that the authorization certificate is invalid, it will return the query failure result to the government platform (query requester) and register the query failure result and reason (invalid authorization certificate) in the customer information query application form, and the second request interaction process is completed.

[0122] From the above description, it can be seen that the information security interaction method provided in the present application can determine whether the second information query request and the information query request credential meet the preset information query request conditions.

[0123] In one embodiment, see Figure 4 , the second information query request includes the information query request number, performing a secondary information query according to the second information query request sent by the query requester and the information query request credential, and sending the secondary information query result to the query requester, including:

[0124] S401: searching the initial information query result according to the information query request number;

[0125] S402: Send the initial information query result as the secondary information query result to the query requesting party.

[0126] It is understandable that if the bank (query service provider) determines that the authorization certificate is valid, it will execute the database query SQL statement (querySql) registered in the table to obtain the salary details of the individual within the specified time period based on the name and ID number, and return the query details to the government platform (query requester) as the secondary information query result. Register the successful query result in the customer information query application form. At this point, the query requester has completed the query result acquisition, and the secondary request interaction process is completed.

[0127] From the above description, it can be seen that the information security interaction method provided by the present application can perform a secondary information query based on the second information query request sent by the query requester and the information query request credential, and send the secondary information query result to the query requester.

[0128] In one embodiment, see Figure 5 , the second information query request includes the information query request number, performing a secondary information query according to the second information query request sent by the query requester and the information query request credential, and sending the secondary information query result to the query requester, including:

[0129] S501: searching the initial information query result according to the information query request number;

[0130] S502: Perform a secondary information query based on the initial information query result to obtain the secondary information query result;

[0131] S503: Send the secondary information query result to the query requester.

[0132] It is understandable that steps S501 to S503 are another implementation method corresponding to steps S401 to S402. In the implementation method of steps S501 to S503, the initial information query result is not the final information query result, but only the SQL statement corresponding to the final information query result, for example:

[0133] Select

[0134] DEPZONE / / Agency area code

[0135] ,SEQNO / / Batch number

[0136] ,SENDATE / / Send date

[0137] ,STATUS / / Processing flag

[0138] ,ACCNO / / Account

[0139] ,IDENTITYID / / ID number

[0140] ,BUSIDATE / / Account entry date

[0141] ,AMOUNT / / Amount deposited

[0142] ,ACCNAME / / Account name

[0143] ,CINO / / Customer Number

[0144] ,MSGSUMMARY / / Summary

[0145] ,MSGSUMMARYF

[0146] FROM BDPVIEWX.DCM_BAS_PFHRSAGH_S

[0147] WHERE

[0148] IDENTITYID = 'Customer ID number sent by the query party' and

[0149] ACCNAME = 'Customer name sent by the querying party' and

[0150] BUSIDATE between 'Start query date' and 'End query date'

[0151] In this implementation mode, if the bank (query service provider) determines that the authorization certificate is valid, it executes the database query SQL statement (querySql) registered in the table to obtain the salary details of the individual within the specified time period based on the name and ID number, which is the initial information query result, and returns the query details to the government platform (query requester) as the secondary information query result. Register the successful query result in the customer information query application form. At this point, the query requester has completed the query result acquisition, and the secondary request interaction process is completed.

[0152] From the above description, it can be seen that the information security interaction method provided by the present application can perform a secondary information query based on the second information query request sent by the query requester and the information query request credential, and send the secondary information query result to the query requester.

[0153] Based on the same inventive concept, the embodiments of the present application also provide an information security interaction device, which can be used to implement the method described in the above embodiments, as described in the following embodiments. Since the principle of solving the problem by the information security interaction device is similar to that of the information security interaction method, the implementation of the information security interaction device can refer to the implementation of the method based on software performance benchmark determination, and the repeated parts will not be repeated. As used below, the term "unit" or "module" can be a combination of software and / or hardware that implements a predetermined function. Although the system described in the following embodiments is preferably implemented in software, the implementation of hardware, or a combination of software and hardware, is also possible and conceived.

[0154] In one embodiment, see Figure 6 In order to perform a secure information query based on an information query request and an information query request credential sent by a query requester, the present application provides an information security interaction device, including:

[0155] A request number generating unit 501, configured to perform an initial information query according to a first information query request sent by a query requester, and generate an information query request number;

[0156] A request credential generating unit 502, configured to send the information query request number to the query requester, so that the query requester generates an information query request credential according to the information query request number;

[0157] The information query unit 503 is used to perform a secondary information query according to the second information query request sent by the query requester and the information query request credential, and send the secondary information query result to the query requester.

[0158] In one embodiment, see Figure 7The first information query request includes an information query condition and a first query request server address, and the request number generating unit 501 includes:

[0159] A request number generating module 601, configured to generate the information query request number according to the information query condition and the first query request server address;

[0160] The initial information query result generating module 602 is used to perform the initial information query according to the information query condition and generate the initial information query result;

[0161] The association module 603 is used to associate the information query request number with the initial information query result and save them.

[0162] In one embodiment, the information security interaction device further includes:

[0163] The query request condition judgment unit is used to determine whether the second information query request and the information query request credential meet a preset information query request condition.

[0164] In one embodiment, see Figure 8 The second information query request includes a query expiration time, a second query request server address and the information query condition, and the information query unit 503 includes:

[0165] The expiration time determination module 701 is used to determine whether the current system time exceeds the query expiration time;

[0166] An address determination module 702, configured to determine whether the second query request server address is consistent with the first query request server address;

[0167] The query condition legality determination module 703 is used to determine whether the information query condition exceeds the preset information query condition legality range;

[0168] The request credential legitimacy determination module 704 is used to determine whether the information query request credential is legal.

[0169] In one embodiment, see Fig. 9 The second information query request includes the information query request number, and the information query unit 503 includes:

[0170] Search module 801, used to search the initial information query result according to the information query request number;

[0171] The sending module 802 is used to send the initial information query result as the secondary information query result to the query requester.

[0172] In one embodiment, see Fig.10 The second information query request includes the information query request number, and the information query unit 503 includes:

[0173] Search module 901, used to search the initial information query result according to the information query request number;

[0174] A query module 902 is used to perform a secondary information query based on the initial information query result to obtain the secondary information query result;

[0175] The sending module 903 is used to send the initial information query result as the secondary information query result to the query requesting party.

[0176] From a hardware perspective, in order to be able to perform a secure information query based on the information query request and the information query request credential sent by the query requester, the present application provides an embodiment of an electronic device for implementing all or part of the content in the information security interaction method, and the electronic device specifically includes the following content:

[0177] Processor, memory, communication interface and bus; wherein the processor, memory and communication interface communicate with each other through the bus; the communication interface is used to realize information transmission between the information security interaction device and related devices such as core business systems, user terminals and related databases; the logic controller can be a desktop computer, a tablet computer and a mobile terminal, etc., but the present embodiment is not limited thereto. In the present embodiment, the logic controller can be implemented with reference to the embodiment of the information security interaction method and the embodiment of the information security interaction device in the embodiment, and the contents thereof are incorporated herein, and the repeated parts are not repeated.

[0178] It is understandable that the user terminal may include a smart phone, a tablet electronic device, a network set-top box, a portable computer, a desktop computer, a personal digital assistant (PDA), a vehicle-mounted device, a smart wearable device, etc. Among them, the smart wearable device may include smart glasses, a smart watch, a smart bracelet, etc.

[0179] In practical applications, part of the information security interaction method can be executed on the electronic device side as described above, or all operations can be completed in the client device. The specific selection can be based on the processing capability of the client device and the limitations of the user's usage scenario. This application does not limit this. If all operations are completed in the client device, the client device may also include a processor.

[0180] The client device may have a communication module (i.e., a communication unit) that can communicate with a remote server to achieve data transmission with the server. The server may include a server on the task scheduling center side, and other implementation scenarios may also include a server on an intermediate platform, such as a server on a third-party server platform that has a communication link with the task scheduling center server. The server may include a single computer device, or a server cluster consisting of multiple servers, or a server structure of a distributed device.

[0181] Fig.11 FIG. 9 is a schematic block diagram of the system structure of the electronic device 9600 according to an embodiment of the present application. Fig.11 As shown, the electronic device 9600 may include a central processor 9100 and a memory 9140; the memory 9140 is coupled to the central processor 9100. It is worth noting that Fig.11 is exemplary; other types of structures may also be used to supplement or replace this structure to implement telecommunication functions or other functions.

[0182] In one embodiment, the information security interaction method function may be integrated into the central processing unit 9100. The central processing unit 9100 may be configured to perform the following control:

[0183] S101: performing an initial information query according to a first information query request sent by a query requester, and generating an information query request number;

[0184] S102: Sending the information query request number to the query requesting party, so that the query requesting party generates an information query request voucher according to the information query request number;

[0185] S103: Perform a secondary information query according to the second information query request and the information query request credential sent by the query requester, and send the secondary information query result to the query requester.

[0186] From the above description, it can be seen that the information security interaction method provided by the present application can provide information query services to the query requester in a "two-way handshake" manner. By generating an information query request credential during the information query process, the legitimacy of the information query request made by the query requester can be securely verified. At the same time, the legitimacy of the information query request can be traceably managed, and the scope of use of customer personal information can be controlled at the level of interaction between the two parties, thereby ensuring the security of online customer personal information and effectively preventing the leakage of customer personal information.

[0187] In another embodiment, the information security interaction device can be configured separately from the central processor 9100. For example, the data composite transmission device information security interaction device can be configured as a chip connected to the central processor 9100, and the function of the information security interaction method can be realized through the control of the central processor.

[0188] like Fig.11 As shown, the electronic device 9600 may also include: a communication module 9110, an input unit 9120, an audio processor 9130, a display 9160, and a power supply 9170. It is worth noting that the electronic device 9600 does not necessarily have to include Fig.11 In addition, the electronic device 9600 may also include Fig.11 For components not shown, reference may be made to the prior art.

[0189] like Fig.11 As shown, the central processing unit 9100 is sometimes also referred to as a controller or an operation control, and may include a microprocessor or other processor device and / or logic device. The central processing unit 9100 receives input and controls the operation of various components of the electronic device 9600.

[0190] The memory 9140 may be, for example, one or more of a cache, a flash memory, a hard drive, a removable medium, a volatile memory, a non-volatile memory or other suitable devices. The above-mentioned information related to the failure may be stored, and a program for executing the relevant information may also be stored. The CPU 9100 may execute the program stored in the memory 9140 to implement information storage or processing, etc.

[0191] The input unit 9120 provides input to the central processing unit 9100. The input unit 9120 is, for example, a key or a touch input device. The power supply 9170 is used to provide power to the electronic device 9600. The display 9160 is used to display display objects such as images and texts. The display may be, for example, an LCD display, but is not limited thereto.

[0192] The memory 9140 may be a solid-state memory, such as a read-only memory (ROM), a random access memory (RAM), a SIM card, etc. It may also be a memory that saves information even when the power is off, can be selectively erased, and is provided with more data, examples of which are sometimes referred to as EPROMs, etc. The memory 9140 may also be some other type of device. The memory 9140 includes a buffer memory 9141 (sometimes referred to as a buffer). The memory 9140 may include an application / function storage unit 9142, which is used to store application programs and function programs or processes for executing the operation of the electronic device 9600 through the central processor 9100.

[0193] The memory 9140 may also include a data storage unit 9143 for storing data, such as contacts, digital data, pictures, sounds, and / or any other data used by the electronic device. The driver storage unit 9144 of the memory 9140 may include various drivers for communication functions of the electronic device and / or for executing other functions of the electronic device (such as messaging applications, address book applications, etc.).

[0194] The communication module 9110 is a transmitter / receiver that sends and receives signals via the antenna 9111. The communication module (transmitter / receiver) 9110 is coupled to the central processor 9100 to provide input signals and receive output signals, which may be the same as the case of a conventional mobile communication terminal.

[0195] Based on different communication technologies, multiple communication modules 9110 may be provided in the same electronic device, such as a cellular network module, a Bluetooth module and / or a wireless LAN module. The communication module (transmitter / receiver) 9110 is also coupled to a speaker 9131 and a microphone 9132 via an audio processor 9130 to provide an audio output via the speaker 9131 and receive an audio input from the microphone 9132, thereby realizing a common telecommunication function. The audio processor 9130 may include any suitable buffer, decoder, amplifier, etc. In addition, the audio processor 9130 is also coupled to the central processor 9100, so that recording can be performed on the local machine through the microphone 9132, and the sound stored on the local machine can be played through the speaker 9131.

[0196] The embodiments of the present application also provide a computer-readable storage medium capable of implementing all the steps of the information security interaction method in the above embodiments, where the execution subject is a server or a client. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, all the steps of the information security interaction method in the above embodiments are implemented by the execution subject being a server or a client. For example, when the processor executes the computer program, the following steps are implemented:

[0197] S101: performing an initial information query according to a first information query request sent by a query requester, and generating an information query request number;

[0198] S102: Sending the information query request number to the query requesting party, so that the query requesting party generates an information query request voucher according to the information query request number;

[0199] S103: Perform a secondary information query according to the second information query request and the information query request credential sent by the query requester, and send the secondary information query result to the query requester.

[0200] From the above description, it can be seen that the information security interaction method provided by the present application can provide information query services to the query requester in a "two-way handshake" manner. By generating an information query request credential during the information query process, the legitimacy of the information query request made by the query requester can be securely verified. At the same time, the legitimacy of the information query request can be traceably managed, and the scope of use of customer personal information can be controlled at the level of interaction between the two parties, thereby ensuring the security of online customer personal information and effectively preventing the leakage of customer personal information.

[0201] It will be appreciated by those skilled in the art that embodiments of the present invention may be provided as methods, devices, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0202] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (apparatus), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0203] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0204] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0205] The present invention uses specific embodiments to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core idea. At the same time, for those skilled in the art, according to the idea of ​​the present invention, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present invention.

Claims

1. An information security interaction method, characterized in that: include: Performing an initial information query according to the first information query request sent by the query requester, and generating an information query request number; Sending the information query request number to the query request party, so that the query request party generates an information query request voucher according to the information query request number; Performing a secondary information query according to the second information query request sent by the query requester and the information query request credential, and sending the secondary information query result to the query requester; The query requester and the service provider exchange customer personal information through two handshakes. The initial information query result is stored on the service provider side until the second handshake succeeds, and then the information query result is sent to the query requester to complete the secure information exchange. Wherein, the first information query request includes information query conditions and a first query request server address, and the performing of the initial information query according to the first information query request sent by the query requester and generating an information query request number includes: generating the information query request number according to the information query conditions and the first query request server address; performing the initial information query according to the information query conditions and generating the initial information query result; associating the information query request number with the initial information query result and saving them; Among them, the second information query request includes the information query request number, and the secondary information query is performed according to the second information query request sent by the query request party and the information query request credential, and the secondary information query result is sent to the query request party, including: searching for the initial information query result according to the information query request number; and sending the initial information query result as the secondary information query result to the query request party.

2. The information security interaction method according to claim 1, characterized in that: Before performing a secondary information query according to the second information query request sent by the query requester and the information query request credential, the method further includes: Determine whether the second information query request and the information query request credential meet a preset information query request condition.

3. The information security interaction method according to claim 2, characterized in that: The second information query request includes a query expiration time, a second query request server address, and the information query condition, and determining whether the second information query request and the information query request credential meet the preset information query request condition includes: Determine whether the current system time exceeds the query expiration time; If not, determining whether the second query request server address is consistent with the first query request server address; If so, determining whether the information query condition exceeds a preset legal range of the information query condition; If not, determine whether the information query request certificate is legal.

4. The information security interaction method according to claim 1, characterized in that: The second information query request includes the information query request number, and performing a secondary information query according to the second information query request sent by the query requester and the information query request credential, and sending the secondary information query result to the query requester, comprises: Searching the initial information query result according to the information query request number; Performing a secondary information query based on the initial information query result to obtain the secondary information query result; The secondary information query result is sent to the query requester.

5. An information security interaction device, characterized in that: include: A request number generating unit, used to perform an initial information query according to a first information query request sent by a query requester, and generate an information query request number; A request credential generating unit, configured to send the information query request number to the query request party, so that the query request party generates an information query request credential according to the information query request number; An information query unit, configured to perform a secondary information query according to the second information query request sent by the query requester and the information query request credential, and send the secondary information query result to the query requester; The query requester and the service provider exchange customer personal information through two handshakes. The initial information query result is stored on the service provider side until the second handshake succeeds, and then the information query result is sent to the query requester to complete the secure information exchange. Wherein, the first information query request includes an information query condition and a first query request server address, and the request number generating unit includes: a request number generating module, used to generate the information query request number according to the information query condition and the first query request server address; a primary information query result generating module, used to perform a primary information query according to the information query condition and generate a primary information query result; an association module, used to associate the information query request number with the primary information query result and save them; Among them, the second information query request includes the information query request number, and the information query unit includes: a search module, used to search the initial information query result according to the information query request number; a sending module, used to send the initial information query result as the secondary information query result to the query request party.

6. The information security interaction device according to claim 5, characterized in that: Also includes: The query request condition judgment unit is used to determine whether the second information query request and the information query request credential meet a preset information query request condition.

7. The information security interaction device according to claim 6, characterized in that: The second information query request includes a query expiration time, a second query request server address and the information query condition, and the information query unit includes: An expiration time determination module, used to determine whether the current system time exceeds the query expiration time; An address determination module, used to determine whether the second query request server address is consistent with the first query request server address; A query condition legality determination module, used to determine whether the information query condition exceeds a preset information query condition legality range; The request credential legitimacy determination module is used to determine whether the information query request credential is legal.

8. The information security interaction device according to claim 5, characterized in that: The second information query request includes the information query request number, and the information query unit includes: A search module, used for searching the initial information query result according to the information query request number; A query module, used to perform a secondary information query based on the initial information query result to obtain the secondary information query result; A sending module is used to send the initial information query result as the secondary information query result to the query requester.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the steps of the information security interaction method described in any one of claims 1 to 4 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the information security interaction method described in any one of claims 1 to 4 are implemented.

Citation Information

Patent Citations

  • Authorization verification management method and system based on customer privacy protection

    CN112632493A