A method and apparatus for protecting data
The proposed solution generates key and lock strings for cache keys using elliptic curve cryptography to secure cache data by validating client access, addressing the inadequacies of existing protection mechanisms and preventing unauthorized access and data leaks.
Patent Information
- Application Number
- CN202010752399.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-07-30
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2040-07-30
AI Technical Summary
The lack of effective protection measures for cache primary keys in the prior art leads to anyone who can view or operate the cached data, which poses the risk of data leakage and misoperation.
Generate the keychain and lock string corresponding to the cache primary key, encrypt it through the elliptic curve encryption algorithm, and store the lock string in the lock table. The client uses the keychain to sign and sends the signature information to the server for verification.
Effectively protect cached data, prevent leakage and misoperation, and enhance the security of cached data.
Smart Images

Figure CN113761564B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular, to a method and device for protecting data. Background Art
[0002] Currently, the development of projects is inseparable from the use of cache services, such as redis, memcachae, etc. In the use of caches, it is often the case that multiple projects share a single or a cluster of cache servers. This can lead to different applications being able to obtain the cache primary keys (keys) of other applications, easily causing damage or viewing data corresponding to cache keys that do not belong to the current project. Moreover, without effective protection measures for cache keys, data corresponding to certain core cache keys can be known and spread by too many people, resulting in leakage problems.
[0003] To solve the security problems of caches, the commonly used method currently mainly relies on the user names and passwords provided by the cache service.
[0004] In the process of implementing the present invention, the inventors found that there are at least the following problems in the prior art:
[0005] There are no effective protection measures for cache keys, resulting in that as long as one can log in to the cache server, anyone can view or operate the data, and the risk of data leakage is very high, still causing accidents of unauthorized access or misoperation. Summary of the Invention
[0006] In view of this, embodiments of the present invention provide a method and device for protecting data to solve the technical problem of having no effective protection measures for cache primary keys.
[0007] To achieve the above object, according to one aspect of the embodiments of the present invention, there is provided a method for protecting data, which is applied to a server and includes:
[0008] Receiving a primary key application request or a primary key registration request sent by a client, and generating a key-value pair data structure;
[0009] Generating a key chain and a lock chain corresponding to the primary key in the key-value pair data structure;
[0010] Storing the lock chain in a lock table, where the lock table is used to store each primary key and its corresponding lock chain;
[0011] Sending the primary key and its corresponding key chain to the client.
[0012] Optionally, generating a key chain and a lock chain corresponding to the primary key in the key-value pair data structure includes:
[0013] Randomly generating a plurality of random numbers as the key chain corresponding to the primary key in the key-value pair data structure;
[0014] Generate a lock string corresponding to the primary key according to the key chain and using the elliptic curve encryption algorithm.
[0015] Optionally, generating a key string and a lock string corresponding to the primary key in the key-value pair data structure includes:
[0016] Randomly generate a number of random digits as the key corresponding to the primary key in the key-value pair data structure;
[0017] Generate a lock corresponding to the primary key according to the key and using the elliptic curve encryption algorithm;
[0018] Encode the key and the lock respectively using base encoding to obtain the key string and the lock string corresponding to the primary key.
[0019] Optionally, after sending the primary key and its corresponding key string to the client, it further includes:
[0020] Listen on the non-command processing port to receive a data operation request sent by the client; wherein, the data operation request carries the primary key and signature information obtained by signing the primary key with the key string;
[0021] Obtain the corresponding lock string from the lock table according to the primary key, and use the lock string and the elliptic curve digital signature algorithm to verify the signature information;
[0022] Return a response result according to the verification result.
[0023] Optionally, obtaining the corresponding lock string from the lock table according to the primary key, and using the lock string and the elliptic curve digital signature algorithm to verify the signature information includes:
[0024] Obtain the corresponding lock string from the lock table according to the primary key, perform base decoding on the lock string to obtain the lock corresponding to the primary key;
[0025] Use the lock and the elliptic curve digital signature algorithm to verify the signature information.
[0026] Optionally, returning a response result according to the verification result includes:
[0027] If the verification is successful, redirect the data operation request to the command processing port to process the data operation request and return an operation result to the client;
[0028] If the verification fails, return a message of unauthorized access to the client.
[0029] In addition, according to another aspect of the embodiments of the present invention, a method for protecting data is provided, which is applied to a client and includes:
[0030] Obtain a primary key and its corresponding keychain, and sign the primary key with the keychain to obtain signature information;
[0031] Send a data operation request to the non-command processing port of the server, where the data operation request carries the primary key and the signature information;
[0032] Receive the response result returned by the server.
[0033] Optionally, signing the primary key with the keychain to obtain signature information includes:
[0034] Perform base decoding on the keychain to obtain the key corresponding to the primary key;
[0035] Sign the primary key with the key to obtain signature information.
[0036] In addition, according to another aspect of the embodiments of the present invention, a device for protecting data is provided, which is set on the server and includes:
[0037] A first generation module, configured to receive a primary key application request or a primary key registration request sent by a client, and generate a key-value pair data structure;
[0038] A second generation module, configured to generate a keychain and a lock string corresponding to the primary key in the key-value pair data structure;
[0039] A storage module, configured to store the lock string in a lock table, where the lock table is used to store each primary key and its corresponding lock string;
[0040] A first sending module, configured to send the primary key and its corresponding keychain to the client.
[0041] Optionally, the second generation module is further configured to:
[0042] Randomly generate several random numbers as the keychain corresponding to the primary key in the key-value pair data structure;
[0043] According to the keychain, and using the elliptic curve encryption algorithm, generate the lock string corresponding to the primary key.
[0044] Optionally, the second generation module is further configured to:
[0045] Randomly generate several random numbers as the key corresponding to the primary key in the key-value pair data structure;
[0046] According to the key, and using the elliptic curve encryption algorithm, generate the lock corresponding to the primary key.
[0047] Encode the key and the lock respectively using base encoding, so as to obtain the key string and the lock string corresponding to the primary key.
[0048] Optionally, it further includes a processing module for:
[0049] After sending the primary key and its corresponding key string to the client, listen on the non-command processing port to receive the data operation request sent by the client; wherein, the data operation request carries the primary key and the signature information obtained by signing the primary key with the key string.
[0050] Obtain the corresponding lock string from the lock table according to the primary key, and use the lock string and the elliptic curve digital signature algorithm to verify the signature information.
[0051] Return a response result according to the verification result.
[0052] Optionally, the processing module is further used for:
[0053] Obtain the corresponding lock string from the lock table according to the primary key, perform base decoding on the lock string to obtain the lock corresponding to the primary key.
[0054] Use the lock and the elliptic curve digital signature algorithm to verify the signature information.
[0055] Optionally, the processing module is further used for:
[0056] If the verification is successful, redirect the data operation request to the command processing port to process the data operation request and return an operation result to the client.
[0057] If the verification fails, return a message of unauthorized access to the client.
[0058] In addition, according to another aspect of the embodiments of the present invention, a device for protecting data is provided, which is set on the client and includes:
[0059] A signature module for obtaining a primary key and its corresponding key string, and signing the primary key with the key string to obtain signature information.
[0060] A second sending module for sending a data operation request to the non-command processing port of the server, and the data operation request carries the primary key and the signature information.
[0061] A receiving module for receiving the response result returned by the server.
[0062] Optionally, the signature module is further used for:
[0063] Perform base decoding on the key chain to obtain the key corresponding to the primary key;
[0064] Use the key to sign the primary key to obtain signature information.
[0065] According to another aspect of the embodiments of the present invention, an electronic device is further provided, including:
[0066] One or more processors;
[0067] A storage device for storing one or more programs,
[0068] When the one or more programs are executed by the one or more processors, the one or more processors implement the method described in any of the above embodiments.
[0069] According to another aspect of the embodiments of the present invention, a computer-readable medium is further provided, on which a computer program is stored, and when the program is executed by a processor, the method described in any of the above embodiments is implemented.
[0070] One of the embodiments of the above invention has the following advantages or beneficial effects: Because the technical means of generating a key chain and a lock chain corresponding to the primary key, storing the lock chain in the lock table, and sending the primary key and its corresponding key chain to the client are adopted, the technical problem that there is no effective protection measure for the cached primary key in the prior art is overcome. The embodiments of the present invention generate a key chain and a lock chain corresponding to the primary key, and use the key chain and the lock chain to verify whether the client has the permission to operate or access the cached data, thereby strengthening the security of the cached data. Therefore, the embodiments of the present invention can effectively protect the cached data and prevent leakage and misoperation.
[0071] The further effects of the above non-conventional optional methods will be described in conjunction with specific embodiments below. BRIEF DESCRIPTION OF THE DRAWINGS
[0072] The drawings are used to better understand the present invention and do not constitute an improper limitation of the present invention. Among them:
[0073] Figure 1 is a schematic diagram of the main process of a method for protecting data according to an embodiment of the present invention;
[0074] Figure 2 is a schematic diagram of the main process of a method for protecting data according to a reference embodiment of the present invention;
[0075] Figure 3 is a schematic diagram of the main process of a method for protecting data according to another reference embodiment of the present invention;
[0076] Figure 4It is a schematic diagram of the main process of a method for protecting data according to another embodiment of the present invention;
[0077] Figure 5 It is a schematic diagram of the main modules of a device for protecting data according to an embodiment of the present invention;
[0078] Figure 6 It is a schematic diagram of the main modules of a device for protecting data according to another embodiment of the present invention;
[0079] Figure 7 It is an exemplary system architecture diagram to which the embodiments of the present invention can be applied;
[0080] Figure 8 It is a schematic diagram of the structure of a computer system of a terminal device or a server suitable for implementing the embodiments of the present invention. Detailed implementation manners
[0081] The following describes exemplary embodiments of the present invention with reference to the accompanying drawings. Various details of the embodiments of the present invention are included to facilitate understanding, and they should be considered merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present invention. Similarly, for the sake of clarity and conciseness, descriptions of well-known functions and structures are omitted below.
[0082] Figure 1 It is a schematic diagram of the main process of a method for protecting data according to an embodiment of the present invention. As an embodiment of the present invention, as Figure 1 shown, the method for protecting data is applied to a server side and may include:
[0083] Step 101, receiving a primary key application request or a primary key registration request sent by a client and generating a key-value pair data structure.
[0084] The server side (such as a cache server) needs to store user data through a key. When the server side receives a primary key application request carrying user data sent by the client, it first parses it to obtain the user data, then assigns a primary key to the user data, thereby generating a key-value (key-value) data structure, and finally saves the key-value data structure.
[0085] After the server receives the primary key registration request carrying the custom primary key sent by the client, it first parses it to obtain the user-defined primary key, and then determines whether the primary key conflicts with the existing primary keys. If there is no conflict, it returns a registration success message to the client; if there is a conflict, it returns a registration failure message to the client. After the primary key registration is successful, the client sends a data storage request carrying the primary key and the corresponding user data to the server, and the server stores the primary key and the corresponding user data in a key-value manner.
[0086] Step 102: Generate a key string and a lock string corresponding to the primary key in the key-value pair data structure.
[0087] After the server generates the key-value pair data structure, it generates a key string and a lock string corresponding to the key in the key-value pair data structure. In an embodiment of the present invention, a randomly generated random number can be used as the key string, and then an encryption algorithm is used to generate the corresponding lock string.
[0088] Optionally, step 102 may include: randomly generating a random number of several bits as the key string corresponding to the primary key in the key-value pair data structure; according to the key string, and using the elliptic curve encryption algorithm (ECC algorithm), generating the lock string corresponding to the primary key. For example, a 256-bit (bit) random number or a 512-bit random number can be randomly generated as the key string corresponding to the key; then according to the key string, the parameters of the curve of the ECC algorithm (i.e., the Secp256k1 parameters) are used to generate the lock string corresponding to the key, which can effectively protect the security of the data.
[0089] Optionally, step 102 may include: randomly generating a random number of several bits as the key corresponding to the primary key in the key-value pair data structure; according to the key, and using the elliptic curve encryption algorithm, generating the lock corresponding to the primary key; respectively encoding the key and the lock using base encoding to obtain the key string and the lock string corresponding to the primary key. In this embodiment, the key and the lock corresponding to the key are respectively base-encoded to generate a key string and a lock string that are convenient for identification and storage. Optionally, base58 can be used to encode the key and the lock respectively to improve the readability of the key and the lock; or, base64 can also be used to encode the key and the lock respectively, and the embodiments of the present invention do not limit this.
[0090] Step 103: Store the lock string in a lock table, and the lock table is used to store each primary key and its corresponding lock string.
[0091] After generating the key string and lock string corresponding to the key, the server stores the lock string in the lock table. The server will generate a lock table to store the lock string corresponding to each key. As described in step 102, the stored lock string can be an encoded string after base encoding, or a lock without base encoding.
[0092] Step 104, send the primary key and its corresponding key string to the client.
[0093] When the server returns the operation result to the client, it will return the key and its corresponding key string to the client.
[0094] Optionally, after step 104, it further includes: listening on a non-command processing port to receive a data operation request sent by the client; wherein, the data operation request carries the primary key and signature information obtained by signing the primary key with the key string; obtaining the corresponding lock string from the lock table according to the primary key, and using the lock string and the Elliptic Curve Digital Signature Algorithm (ECDSA algorithm) to verify the signature information; returning a response result according to the verification result. When the client accesses the key next time, it also needs to carry the signature information of the key to access the cached data. Specifically, the client uses the key string and the ECDSA algorithm to sign the key to obtain the signature information of the key. After the server parses the key and its corresponding signature information from the data operation request, it obtains the lock string corresponding to the key from the lock table, then uses the lock string and the ECDSA algorithm to verify the signature information, and finally returns a response result to the client according to the verification result.
[0095] According to the various embodiments described above, it can be seen that the embodiments of the present invention solve the technical problem in the prior art that there is no effective protection measure for the cached primary key by means of generating a key string and a lock string corresponding to the primary key, storing the lock string in the lock table, and sending the primary key and its corresponding key string to the client. The embodiments of the present invention generate a corresponding key string and lock string for the primary key, and use the key string and the lock string to verify whether the client has the permission to operate or access the cached data, thereby enhancing the security of the cached data. Therefore, the embodiments of the present invention can effectively protect the cached data and prevent leakage and misoperation.
[0096] Figure 2 It is a schematic diagram of the main process of a method for protecting data according to a reference embodiment of the present invention. As another embodiment of the present invention, as Figure 2 shown, the method for protecting data is applied to the server and may include:
[0097] Step 201, receive a primary key application request or a primary key registration request sent by the client, and generate a key-value pair data structure.
[0098] Step 202: Randomly generate several random numbers as the key corresponding to the primary key in the key-value pair data structure.
[0099] Step 203: Generate the lock corresponding to the primary key according to the key and using the elliptic curve encryption algorithm.
[0100] Step 204: Encode the key and the lock respectively using base encoding to obtain the key string and the lock string corresponding to the primary key.
[0101] Step 205: Store the lock string in the lock table, which is used to store each primary key and its corresponding lock string.
[0102] Step 206: Send the primary key and its corresponding key string to the client.
[0103] In addition, the specific implementation content of the method for protecting data in a referenceable embodiment of the present invention has been described in detail in the above-mentioned method for protecting data, so the repeated content will not be described herein.
[0104] Figure 3 It is a schematic diagram of the main process of the method for protecting data according to another referenceable embodiment of the present invention. As another embodiment of the present invention, as Figure 3 shown, the method for protecting data is applied to the server side and may include:
[0105] Step 301: Receive a primary key application request or a primary key registration request sent by the client and generate a key-value pair data structure.
[0106] Step 302: Generate the key string and the lock string corresponding to the primary key in the key-value pair data structure.
[0107] Step 303: Store the lock string in the lock table, which is used to store each primary key and its corresponding lock string.
[0108] Step 304: Send the primary key and its corresponding key string to the client.
[0109] Step 305: Listen on the non-command processing port to receive the data operation request sent by the client. Wherein, the data operation request carries the primary key and the signature information obtained by signing the primary key using the key string.
[0110] The non-command processing port needs to be specified in advance. The server listens on the specified port (i.e., the non-command processing port) to receive the data operation request (i.e., the communication protocol message) sent by the client, and then parses it to obtain the key and its corresponding signature information. It should be noted that the signature information is obtained by the client using the keychain and signing the key using the ECDSA algorithm.
[0111] Step 306: Obtain the corresponding lock string from the lock table according to the primary key, and perform base decoding on the lock string to obtain the lock corresponding to the primary key.
[0112] After parsing to obtain the key and its corresponding signature information, obtain the lock string corresponding to the key from the lock table, and then perform base decoding on the lock string (such as base58 or base64, and which decoding method to use is determined by the encoding method), so as to obtain the lock corresponding to the key.
[0113] Step 307: Use the lock and adopt the elliptic curve digital signature algorithm to verify the signature information.
[0114] Step 308: Verify whether it is successful; if so, execute step 308; if not, execute step 309.
[0115] Step 309: Redirect the data operation request to the command processing port to process the data operation request and return the operation result to the client.
[0116] If the signature verification is successful, it means that the key and the lock match, and data acquisition can be performed. Therefore, the server redirects the data operation request (i.e., the communication protocol message) to the command processing port (this is the port where the cache server actually processes the request) to process the data operation request. After the processing is completed, the operation result is returned to the client.
[0117] Step 310: Return a message of unauthorized access to the client.
[0118] If the signature verification fails, it means that the key and the lock do not match, and the client is not authorized to access the cached data. Then, a message of unauthorized access is returned to the client.
[0119] The embodiment of the present invention adopts port listening and redirection technologies, without any intrusion into the cache server side, and performs data protection processing before actually processing the request, effectively protecting the security of the cached data.
[0120] In addition, the specific implementation content of the method for protecting data in another referenceable embodiment of the present invention has been described in detail in the above-mentioned method for protecting data, so the repeated content will not be described here.
[0121] Figure 4 It is a schematic diagram of the main process of a method for protecting data according to another embodiment of the present invention. As another embodiment of the present invention, as Figure 4 shown, the method for protecting data is applied to a client and may include:
[0122] Step 401, obtain a primary key and its corresponding keychain, and sign the primary key with the keychain to obtain signature information.
[0123] When a user issues an instruction to obtain or modify a certain cache key, the client obtains the key and its corresponding keychain, and signs the primary key with the keychain to obtain signature information. For example, the ECDSA algorithm can be used for signing.
[0124] Optionally, signing the primary key with the keychain to obtain signature information includes: performing base decoding on the keychain to obtain the key corresponding to the primary key; signing the primary key with the key to obtain signature information. After the client obtains the corresponding keychain according to the key, it performs base decoding on the keychain (such as base58 or base64, and which decryption method to use is determined by the encoding method), so as to obtain the key corresponding to the key, and then uses the key and the ECDSA algorithm to sign the key, thereby obtaining signature information.
[0125] Step 402, send a data operation request to the non-command processing port of the server, and the data operation request carries the primary key and the signature information.
[0126] After the client obtains the signature information, it prefabricates the key and its corresponding signature information into a communication protocol message as a data operation request, and then sends the data operation request to the non-command processing port (designated port) of the server.
[0127] Step 403, receive the response result returned by the server.
[0128] The server listens on the non-command processing port to receive the data operation request sent by the client, parses to obtain the key and its corresponding signature information; then verifies the signature information, and processes the data operation request according to the verification result of the signature information. If the verification is successful, the data operation request is redirected to the command processing port to process the data operation request and return an operation result to the client; if the verification fails, a message of unauthorized access is returned to the client.
[0129] The client is used to control the data acquisition operation of the cache key. When communicating with the server, it uses the keychain of the cache key to sign the key, prefabricates it into the communication protocol message, and then sends the key and its corresponding signature information to the non-command processing port of the server.
[0130] In addition, the specific implementation content of the method for protecting data in another embodiment of the present invention has been described in detail in the above-mentioned method for protecting data, so the repeated content will not be described here.
[0131] Figure 5 It is a schematic diagram of the main modules of the device for protecting data according to an embodiment of the present invention, as Figure 5 shown, the device 500 for protecting data is provided on the server side, and includes a first generation module 501, a second generation module 502, a storage module 503, and a first sending module 504; wherein, the first generation module 501 is used to receive the primary key application request or primary key registration request sent by the client and generate a key-value pair data structure; the second generation module 502 is used to generate a keychain and a lock string corresponding to the primary key in the key-value pair data structure; the storage module 503 is used to store the lock string into the lock table, and the lock table is used to store each primary key and its corresponding lock string; the first sending module 504 is used to send the primary key and its corresponding keychain to the client.
[0132] Optionally, the second generation module 502 is further used for:
[0133] Randomly generate several random numbers as the keychain corresponding to the primary key in the key-value pair data structure;
[0134] According to the keychain, and using the elliptic curve encryption algorithm, generate the lock string corresponding to the primary key.
[0135] Optionally, the second generation module 502 is further used for:
[0136] Randomly generate several random numbers as the key corresponding to the primary key in the key-value pair data structure;
[0137] According to the key, and using the elliptic curve encryption algorithm, generate the lock corresponding to the primary key.
[0138] Use base encoding to encode the key and the lock respectively, so as to obtain the keychain and the lock string corresponding to the primary key.
[0139] Optionally, it further includes a processing module, which is used for:
[0140] After sending the primary key and its corresponding key string to the client, listen on the non-command processing port to receive a data operation request sent by the client; wherein, the data operation request carries the primary key and the signature information obtained by signing the primary key with the key string.
[0141] Obtain the corresponding lock string from the lock table according to the primary key, and use the lock string and the elliptic curve digital signature algorithm to verify the signature information.
[0142] Return a response result according to the verification result.
[0143] Optionally, the processing module is further configured to:
[0144] Obtain the corresponding lock string from the lock table according to the primary key, perform base decoding on the lock string to obtain the lock corresponding to the primary key.
[0145] Use the lock and the elliptic curve digital signature algorithm to verify the signature information.
[0146] Optionally, the processing module is further configured to:
[0147] If the verification is successful, redirect the data operation request to the command processing port to process the data operation request and return an operation result to the client.
[0148] If the verification fails, return a message of unauthorized access to the client.
[0149] According to the various embodiments described above, it can be seen that the embodiments of the present invention solve the technical problem in the prior art that there is no effective protection measure for cached primary keys by generating a key string and a lock string corresponding to the primary key, storing the lock string in the lock table, and sending the primary key and its corresponding key string to the client. The embodiments of the present invention generate a key string and a lock string corresponding to the primary key, and use the key string and the lock string to verify whether the client has the permission to operate or access the cached data, thereby enhancing the security of the cached data. Therefore, the embodiments of the present invention can effectively protect the cached data and prevent leakage and misoperation.
[0150] It should be noted that the specific implementation content of the apparatus for protecting data in the present invention has been described in detail in the above-described method for protecting data, so the repeated content will not be described herein.
[0151] Figure 6 is a schematic diagram of the main modules of the apparatus for protecting data according to another embodiment of the present invention, as Figure 6As shown, the device 600 for protecting data is provided on the client side and includes a signature module 601, a second sending module 602, and a receiving module 603. Among them, the signature module 601 is used to obtain the primary key and its corresponding keychain, sign the primary key using the keychain to obtain signature information. The second sending module 602 is used to send a data operation request to the non-command processing port of the server, and the data operation request carries the primary key and the signature information. The receiving module 603 is used to receive the response result returned by the server.
[0152] Optionally, the signature module 601 is further used for:
[0153] Perform base decoding on the keychain to obtain the key corresponding to the primary key;
[0154] Sign the primary key using the key to obtain signature information.
[0155] It should be noted that the specific implementation content of the device for protecting data in the present invention has been described in detail in the above-mentioned method for protecting data, so the repeated content will not be described here again.
[0156] Figure 7 An exemplary system architecture 700 is shown that can apply the method for protecting data or the device for protecting data according to the embodiments of the present invention.
[0157] As Figure 7 shown, the system architecture 700 may include terminal devices 701, 702, 703, a network 704, and a server 705. The network 704 is used to provide a medium for communication links between the terminal devices 701, 702, 703 and the server 705. The network 704 may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.
[0158] Users can use the terminal devices 701, 702, 703 to interact with the server 705 through the network 704 to receive or send messages, etc. Various communication client applications may be installed on the terminal devices 701, 702, 703, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (only for example).
[0159] The terminal devices 701, 702, 703 may be various electronic devices with a display screen and supporting web browsing, including but not limited to smart phones, tablet computers, laptop portable computers, and desktop computers, etc.
[0160] The server 705 can be a server that provides various services. For example, it can be a back-end management server (only an example) that supports shopping websites browsed by users using the terminal devices 701, 702, and 703. The back-end management server can analyze and process data such as item information query requests received, and feedback the processing results (such as target push information, item information - only examples) to the terminal devices.
[0161] It should be noted that the method for protecting data provided in the embodiments of the present invention is generally executed by the server 705. Correspondingly, the device for protecting data is generally arranged in the server 705. The method for protecting data provided in the embodiments of the present invention can also be executed by the terminal devices 701, 702, and 703. Correspondingly, the device for protecting data can be arranged in the terminal devices 701, 702, and 703.
[0162] It should be understood that Figure 7 the numbers of terminal devices, networks, and servers in
[0163] are merely illustrative. According to the implementation requirements, there can be any number of terminal devices, networks, and servers. Figure 8 The following refers to Figure 8 which shows a schematic structural diagram of a computer system 800 of a terminal device suitable for implementing the embodiments of the present invention.
[0164] As Figure 8 shown, the computer system 800 includes a central processing unit (CPU) 801, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 802 or the program loaded from the storage section 808 into the random access memory (RAM) 803. In the RAM 803, various programs and data required for the operation of the system 800 are also stored. The CPU 801, ROM 802, and RAM 803 are connected to each other through a bus 804. The input / output (I / O) interface 805 is also connected to the bus 804.
[0165] The following components are connected to the I / O interface 805: an input section 806 including a keyboard, a mouse, etc.; an output section 807 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc. as well as a speaker, etc.; a storage section 808 including a hard disk, etc.; and a communication section 809 including a network interface card such as a LAN card, a modem, etc. The communication section 809 performs communication processing via a network such as the Internet. A drive 810 is also connected to the I / O interface 805 as needed. A removable medium 811 such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc. is mounted on the drive 810 as needed so that a computer program read therefrom is installed into the storage section 808 as needed.
[0166] Specifically, according to the embodiments disclosed by the present invention, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments disclosed by the present invention include a computer program which includes a computer program carried on a computer-readable medium, and the computer program contains program codes for performing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 809, and / or installed from the removable medium 811. When the computer program is executed by a central processing unit (CPU) 801, the above functions defined in the system of the present invention are executed.
[0167] It should be noted that the computer-readable medium shown in the present invention can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present invention, the computer-readable storage medium can be any tangible medium that contains or stores a program, which can be used by or in conjunction with an instruction execution system, apparatus, or device. In the present invention, the computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted by any appropriate medium, including but not limited to: wireless, wire, optical cable, RF, etc., or any suitable combination of the above.
[0168] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer programs according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram can represent a module, a program segment, or a part of code, and the above module, program segment, or part of code contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, and the combination of blocks in the block diagram or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0169] The modules involved in the embodiments of the present invention can be implemented in software or in hardware. The described modules can also be provided in a processor. For example, it can be described as: a processor includes a first generation module, a second generation module, a storage module, and a first sending module. In some cases, the names of these modules do not constitute a limitation on the module itself.
[0170] The modules involved in the embodiments of the present invention can be implemented in software or in hardware. The described modules can also be provided in a processor. For example, it can be described as: a processor includes a signature module, a second sending module, and a receiving module. In some cases, the names of these modules do not constitute a limitation on the module itself.
[0171] As another aspect, the present invention further provides a computer-readable medium. The computer-readable medium can be included in the device described in the above embodiments; or it can exist independently and not be assembled into the device. The above computer-readable medium carries one or more programs. When the above one or more programs are executed by the device, the device implements the following method: receiving a primary key application request or a primary key registration request sent by a client, and generating a key-value pair data structure; generating a keychain and a lock string corresponding to the primary key in the key-value pair data structure; storing the lock string into a lock table, where the lock table is used to store each primary key and its corresponding lock string; and sending the primary key and its corresponding keychain to the client.
[0172] As another aspect, the present invention further provides a computer-readable medium. The computer-readable medium can be included in the device described in the above embodiments; or it can exist independently and not be assembled into the device. The above computer-readable medium carries one or more programs. When the above one or more programs are executed by the device, the device implements the following method: obtaining a primary key and its corresponding keychain, signing the primary key with the keychain to obtain signature information; sending a data operation request to a non-command processing port of a server, where the data operation request carries the primary key and the signature information; and receiving a response result returned by the server.
[0173] According to the technical solution of the embodiments of the present invention, by using the technical means of generating a keychain and a lock string corresponding to a primary key, storing the lock string into a lock table, and sending the primary key and its corresponding keychain to a client, the technical problem in the prior art that there is no effective protection measure for cached primary keys is overcome. The embodiments of the present invention generate a keychain and a lock string corresponding to a primary key, and use the keychain and the lock string to verify whether the client has the permission to operate or access cached data, thereby enhancing the security of the cached data. Therefore, the embodiments of the present invention can effectively protect the cached data and prevent leakage and misoperation.
[0174] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations and substitutions can occur depending on design requirements and other factors. Any modifications, equivalent substitutions and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A method for protecting data, applied to a server, characterized in that including: Receiving a primary key application request or a primary key registration request sent by a client, and generating a key-value pair data structure; Generating a keychain and a lock string corresponding to the primary key in the key-value pair data structure, where the primary key is assigned by the server or defined by the user; Storing the lock string into a lock table, where the lock table is used to store each primary key and its corresponding lock string; Sending the primary key and its corresponding keychain to the client; Listening on a non-command processing port to receive a data operation request sent by the client; wherein, the data operation request carries the primary key and signature information obtained by signing the primary key with the keychain; Obtaining the corresponding lock string from the lock table according to the primary key, and using the lock string and the elliptic curve digital signature algorithm to verify the signature information; Returning a response result according to the verification result.
2. The method according to claim 1, characterized in that, Generating a keychain and a lock string corresponding to the primary key in the key-value pair data structure includes: Randomly generating a plurality of random numbers as the keychain corresponding to the primary key in the key-value pair data structure; Generating the lock string corresponding to the primary key according to the keychain and using the elliptic curve encryption algorithm.
3. The method according to claim 1, characterized in that, Generating a keychain and a lock string corresponding to the primary key in the key-value pair data structure includes: Randomly generating a plurality of random numbers as the key corresponding to the primary key in the key-value pair data structure; Generating the lock corresponding to the primary key according to the key and using the elliptic curve encryption algorithm. Encoding the key and the lock respectively using base encoding to obtain the keychain and the lock string corresponding to the primary key.
4. The method according to claim 1, wherein Obtaining the corresponding lock string from the lock table according to the primary key, and using the lock string and the elliptic curve digital signature algorithm to verify the signature information includes: Obtaining the corresponding lock string from the lock table according to the primary key, performing base decoding on the lock string to obtain the lock corresponding to the primary key; Using the lock and the elliptic curve digital signature algorithm to verify the signature information.
5. The method according to claim 1, characterized in that, Returning a response result according to the verification result includes: If the verification is successful, redirecting the data operation request to a command processing port to process the data operation request and returning an operation result to the client; If the verification fails, returning a message of unauthorized access to the client.
6. A device for protecting data, which is arranged on the server side, is characterized in that, including: A first generation module, configured to receive a primary key application request or a primary key registration request sent by a client, and generate a key-value pair data structure; A second generation module, configured to generate a keychain and a lock string corresponding to the primary key in the key-value pair data structure, where the primary key is assigned by the server or defined by the user; A storage module, configured to store the lock string into a lock table, where the lock table is used to store each primary key and its corresponding lock string; A first sending module, configured to send the primary key and its corresponding keychain to the client; A processing module, configured to monitor a non-command processing port to receive a data operation request sent by the client; wherein, the data operation request carries the primary key and signature information obtained by signing the primary key with the keychain; obtain a corresponding lock string from the lock table according to the primary key, and use the lock string and the elliptic curve digital signature algorithm to verify the signature information; return a response result according to the verification result.
7. An electronic device, characterized in that, Comprising: One or more processors; A storage device for storing one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1-5.
8. A computer-readable medium having a computer program stored thereon, characterized in that, The program, when executed by the processor, implements the method according to any one of claims 1-5.
Citation Information
Patent Citations
Blockchain-based database system and method of using same
CN107292181A
Digital signature verification method, system and device and computer readable storage medium
CN109728914A
Block chain data indexing method and device, computer equipment and storage medium
CN110704428A