Privacy Data Protection Method, Device, Equipment and Storage Medium for Low-Code Platform
By creating a unique user key and intercepting data processing process on a low-code platform for encryption, decryption and desensitization, the problem of low privacy data protection in the existing technology is solved, and higher data security and privacy protection effects are achieved.
Patent Information
- Application Number
- CN202210855627.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-20
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2042-07-20
AI Technical Summary
Existing low-code platforms have low security when protecting privacy data, and unified keys are prone to being cracked and data leakage.
By creating a key dataset with the same length as the user list and matching the keys with the user name one by one, ensuring that each user's unique key is used for data encryption and decryption. Intercept the data returned by the user, filter the privacy data that complies with the protection rules for encryption, replace the original data, and desensitize the data during decryption.
It improves the security of user data, reduces the risk of data leakage, ensures the opacity of user data in the storage process, and improves the protection effect of privacy data.
Smart Images

Figure CN115146315B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of artificial intelligence technology, and particularly to a method, device, equipment and storage medium for protecting privacy data of a low-code platform. Background Art
[0002] With the advent of the digital age, people have uploaded their privacy data on more and more platforms. For example, in order to place an order on a food delivery platform, users need to upload their address information and contact information, which further increases the risk of leakage of users' privacy data. In order to protect the privacy security of users, the platform needs to perform encryption and decryption operations on the privacy data for privacy data protection.
[0003] Most of the existing privacy data protection technologies for low-code platforms are data encryption and decryption based on a unified key, and then privacy data is protected. For example, privacy data protection based on a substitution encryption and decryption algorithm. In practical applications, once the unified key is cracked, a large amount of data will be leaked, which may lead to low security when protecting privacy data. Summary of the Invention
[0004] The present invention provides a method, device, equipment and storage medium for protecting privacy data of a low-code platform, and its main purpose is to solve the problem of low security when protecting privacy data.
[0005] To achieve the above object, a method for protecting privacy data of a low-code platform provided by the present invention includes:
[0006] Obtain a user list, create a key data set with the same length as the length of the user list, and match the keys in the key data set with the user names in the user list one by one;
[0007] Select a user name from the user list one by one as the target user name, send a data entry request to the target user terminal corresponding to the target user name, and intercept the return data of the target user terminal to the data entry request;
[0008] Screen out the privacy data that meets the preset protection rules from the return data, encrypt the privacy data into user ciphertext according to the key corresponding to the target user name, replace the privacy data in the return data with the user ciphertext to obtain user data, and store the user data in a preset database;
[0009] When receiving a user data request corresponding to the target user name, query the user data from the database according to the user data request;
[0010] Intercept the user data, and decrypt the target user data according to the key corresponding to the target user name to obtain the returned data;
[0011] Perform data desensitization on the returned data, and display the desensitized returned data on a preset front-end page.
[0012] Optionally, the creating a key data set with the same length as the list length of the user list includes:
[0013] Create a string array with the same length as the list length;
[0014] Generate a random key through a preset encoding method;
[0015] Determine whether there is an array element in the string array that is the same as the key by traversing;
[0016] When there is an array element in the string array that is the same as the key, return to the step of generating a random key through the preset encoding method;
[0017] When there is no array element in the string array that is the same as the key, add the key as an array element to the string array in the order from front to back, and determine whether the last array element of the string array is a null value;
[0018] When the last array element of the string array is a null value, return to the step of generating a random key through the preset encoding method;
[0019] When the last array element of the string array is not a null value, use the string array as the key data set.
[0020] Optionally, the screening out privacy data that conforms to a preset protection rule from the returned data includes:
[0021] Obtain the digital protection rule in the protection rule, and screen out privacy numbers that conform to the digital protection rule from the returned data;
[0022] Obtain the text protection rule in the protection rule, and screen out privacy texts that conform to the text protection rule from the returned data;
[0023] Obtain the privacy data based on the privacy numbers and the privacy texts.
[0024] Optionally, the screening out privacy numbers that conform to the digital protection rule from the returned data includes:
[0025] Extract the protected digit length from the digital protection rule;
[0026] Extract a digit string from the returned data, and select a digit string with the same length as the digit length from the digit string as the privacy digit.
[0027] Optionally, screening out the privacy text that conforms to the text protection rule from the returned data according to the text protection rule includes:
[0028] Extract the privacy word library from the text protection rule;
[0029] Split the returned data after extracting the digit string into multiple user data sentences;
[0030] Split the user data sentences into user data words;
[0031] Calculate the sentence weight of each user data sentence according to the user data words and the privacy word library;
[0032] Use the user data sentences with the sentence weight greater than the preset threshold as the privacy text.
[0033] Optionally, encrypting the privacy data into user ciphertext according to the key corresponding to the target user name includes:
[0034] Generate the corresponding round key according to the key;
[0035] Perform a byte substitution operation on the privacy data through a preset substitution table;
[0036] Perform a row shift operation on the privacy data after byte substitution;
[0037] Perform a column confusion operation on the privacy data after row shift;
[0038] Perform an XOR operation on the privacy data after column confusion through the round key to obtain the user ciphertext.
[0039] Optionally, decrypting the target user data according to the key corresponding to the target user name to obtain the returned data includes:
[0040] Screen out the user ciphertext from the target user data;
[0041] Obtain the round key corresponding to the key, and perform an XOR operation on the user ciphertext using the round key;
[0042] Perform a reverse row shift operation on the user ciphertext after the XOR operation;
[0043] Perform an inverse byte substitution operation on the user ciphertext after reverse displacement using the replacement table to obtain the return data.
[0044] To solve the above problems, the present invention also provides a privacy data protection device for a low-code platform, the device includes:
[0045] A key creation module, configured to obtain a user list, create a key data set with the same length as the list length of the user list, and match the keys in the key data set with the user names in the user list one by one;
[0046] A data request module, configured to select a user name from the user list one by one as a target user name, send a data entry request to the target user terminal corresponding to the target user name, and intercept the return data of the target user terminal for the data entry request;
[0047] A data encryption module, configured to screen out privacy data that meets a preset protection rule from the return data, encrypt the privacy data into a user ciphertext according to the key corresponding to the target user name, replace the privacy data in the return data with the user ciphertext to obtain user data, and store the user data in a preset database;
[0048] A data decryption module, configured to query the user data from the database according to the user data request when receiving a user data request corresponding to the target user name; intercept the user data, and decrypt the target user data according to the key corresponding to the target user name to obtain the return data;
[0049] A data desensitization module, configured to perform data desensitization on the return data and display the desensitized return data on a preset front-end page.
[0050] To solve the above problems, the present invention also provides an electronic device, the electronic device includes:
[0051] At least one processor; and,
[0052] A memory communicatively connected to the at least one processor; wherein,
[0053] The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the privacy data protection method for the low-code platform described above.
[0054] In order to solve the above problems, the present invention also provides a storage medium, in which at least one computer program is stored. The at least one computer program is executed by a processor in an electronic device to implement the privacy data protection method of the low-code platform described above.
[0055] The embodiment of the present invention can ensure that each user has a unique private key for data encryption and decryption by creating a key data set with the same list length as the user list, and matching the keys in the key data set with the user names in the user list one by one, thereby further improving the security of user data; by intercepting the return data of the target user terminal in response to the data entry request, it can facilitate the subsequent encryption processing of the return data, reduce the risk of data leakage, and improve the security of user data; by using the key corresponding to the target user name to encrypt the privacy data into user ciphertext, the opacity of user data during the storage process is guaranteed, and the security of privacy data is improved. Therefore, the privacy data protection method, device, equipment and storage medium of the low-code platform proposed in the present invention can solve the problem of low security when protecting privacy data. BRIEF DESCRIPTION OF THE DRAWINGS
[0056] Figure 1 A flowchart of a privacy data protection method for a low-code platform provided by an embodiment of the present invention;
[0057] Figure 2 A schematic diagram of a process for screening private data provided by an embodiment of the present invention;
[0058] Figure 3 A schematic diagram of a process for decrypting target user data provided by an embodiment of the present invention;
[0059] Figure 4 A functional module diagram of a privacy data protection device of a low-code platform provided by an embodiment of the present invention;
[0060] Figure 5 A schematic diagram of the structure of an electronic device for implementing the privacy data protection method of the low-code platform provided in one embodiment of the present invention.
[0061] The realization of the purpose, functional features and advantages of the present invention will be further explained in conjunction with embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION
[0062] It should be understood that the specific embodiments described herein are only used to explain the present invention, and are not used to limit the present invention.
[0063] The user privacy information used in the solution of the present invention is obtained with the consent of the user and complies with the provisions of relevant laws and policies.
[0064] An embodiment of the present application provides a method for protecting privacy data of a low-code platform. The execution subject of the method for protecting privacy data of the low-code platform includes, but is not limited to, at least one of electronic devices such as a server, a terminal, etc. that can be configured to execute the method provided by the embodiment of the present application. In other words, the method for protecting privacy data of the low-code platform can be executed by software or hardware installed on a terminal device or a server device, and the software can be a blockchain platform. The server includes, but is not limited to: a single server, a server cluster, a cloud server, or a cloud server cluster, etc. The server can be an independent server or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, Content Delivery Network (CDN), and big data and artificial intelligence platforms.
[0065] Refer to Figure 1 As shown, it is a schematic flowchart of the method for protecting privacy data of a low-code platform provided by an embodiment of the present invention. In this embodiment, the method for protecting privacy data of the low-code platform includes:
[0066] S1. Obtain a user list, create a key data set with the same length as the list length of the user list, and match the keys in the key data set with the user names in the user list one by one;
[0067] In an embodiment of the present invention, the user list can be a list for storing user names stored in a database, a blockchain, and a company list.
[0068] In an embodiment of the present invention, the creating of the key data set with the same length as the list length of the user list includes: creating a string array with the same length as the list; generating a random key through a preset encoding method; determining whether there is an array element in the string array that is the same as the key by traversing; when there is an array element in the string array that is the same as the key, return to the step of generating a random key through the preset encoding method; when there is no array element in the string array that is the same as the key, add the key as an array element to the string array in the order from front to back, and determine whether the last array element of the string array is a null value; when the last array element of the string array is a null value, return to the step of generating a random key through the preset encoding method; when the last array element of the string array is not a null value, use the string array as the key data set.
[0069] Specifically, a string array with the same length as the list can be created through the Array function in Java.
[0070] Specifically, the encoding method can be the KeyGenerator.generateKey method in Java, and the KeyGenerator.generateKey method can generate a random key for an encryption specification such as AES.
[0071] Specifically, the keys in the key dataset can be matched one by one with the user names in the user list in a traversal manner.
[0072] In the embodiment of the present invention, by creating a key dataset with the same length as the user list and matching the keys in the key dataset with the user names in the user list one by one, it can be ensured that each user has a unique private key for data encryption and decryption of the user, which can further improve the data security of the user.
[0073] S2. Select a user name from the user list one by one as the target user name, send a data entry request to the target user terminal corresponding to the target user name, and intercept the return data of the target user terminal to the data entry request;
[0074] In the embodiment of the present invention, the data entry request refers to a request for notifying the user to enter data. For example, it notifies the user to submit a user rental settlement form.
[0075] Specifically, the return data can be form data containing user information, such as a rent settlement form, a signing contract, and an order invoice, etc.
[0076] In the embodiment of the present invention, the return data of the target user terminal to the data entry request can be intercepted through the AOP interception method of Spring.
[0077] In the embodiment of the present invention, by intercepting the return data of the target user terminal to the data entry request, it is convenient to perform encryption processing on the return data subsequently, and also reduces the risk of data leakage and improves the data security of the user.
[0078] S3. Screen out the private data that meets the preset protection rules from the return data, encrypt the private data into user ciphertext according to the key corresponding to the target user name, replace the private data in the return data with the user ciphertext to obtain user data, and store the user data in a preset database;
[0079] In an embodiment of the present invention, the protection rule refers to the conditional and regulatory constraints on the returned data, which may be the privacy protection rules of the law or the privacy protection rules of the industry. For example, data such as telephone numbers, ID card numbers, and detailed addresses in the returned data of the user are encrypted.
[0080] In an embodiment of the present invention, with reference to Figure 2 as shown, screening out privacy data that conforms to the preset protection rules from the returned data includes:
[0081] S21. Obtain the digital protection rule in the protection rule, and screen out privacy digits that conform to the digital protection rule from the returned data according to the digital protection rule;
[0082] S22. Obtain the text protection rule in the protection rule, and screen out privacy texts that conform to the digital protection rule from the returned data according to the digital protection rule;
[0083] S23. Obtain the privacy data according to the privacy digits and the privacy texts.
[0084] Specifically, screening out privacy digits that conform to the digital protection rule from the returned data according to the digital protection rule includes: extracting the protected digit length from the digital protection rule; extracting a digit string from the returned data, and selecting a digit string with the same length as the digit length from the digit string as the privacy digit.
[0085] Specifically, a digit string can be extracted from the returned data by using a regular expression, and a digit string with the same length as the digit length is selected from the digit string as the privacy digit.
[0086] Specifically, screening out privacy texts that conform to the digital protection rule from the returned data according to the digital protection rule includes: extracting a privacy word library from the text protection rule; splitting the returned data after extracting the digit string into multiple user data sentences; splitting the user data sentences into user data words; calculating the sentence weight of each user data sentence according to the user data words and the privacy word library; and using the user data sentences with the sentence weight greater than a preset threshold as privacy texts.
[0087] Specifically, the privacy word library refers to a word library composed of possible privacy words and the word weights corresponding to the privacy words. For example, the word weight of "street" is 5.
[0088] Specifically, regular expressions can be used to identify punctuation marks in the user data sentence, and then the returned data after extracting the numeric string can be split into multiple user data sentences.
[0089] Specifically, the user data sentence can be split into user data words by text segmentation tools such as JIEBA.
[0090] Specifically, calculating the sentence weight of each user data sentence according to the user data word and the privacy word library includes: accumulating the word weights of each user data word in the user data sentence, and dividing the accumulated value by the length of the user data sentence to obtain the sentence weight of the user data sentence.
[0091] Specifically, encrypting the privacy data into user ciphertext according to the key corresponding to the target username includes: generating a corresponding round key according to the key; performing a byte substitution operation on the privacy data through a preset substitution table; performing a row shift operation on the privacy data after byte substitution; performing a column confusion operation on the privacy data after row shift; performing an exclusive OR operation on the privacy data after column confusion through the round key to obtain the user ciphertext.
[0092] Specifically, a key scheduling algorithm can be used to generate a corresponding round key according to the key.
[0093] Specifically, the substitution table refers to an S-box (Substitution-box).
[0094] Specifically, performing a byte substitution operation on the privacy data through a preset substitution table means using the first four bytes of the privacy data as the row value, using the last four bytes of the privacy data as the column value, and retrieving the corresponding data in the substitution table using the row value and the column value for substitution.
[0095] In the embodiment of the present invention, by encrypting the privacy data into user ciphertext using the key corresponding to the target username, the opacity of user data during storage is ensured, and the security of privacy data is improved.
[0096] S4. When a user data request corresponding to the target username is received, query the user data from the database according to the user data request;
[0097] In the embodiment of the present invention, the user data request refers to a request for obtaining the user data. For example, a rental businessperson needs to obtain a user's rental settlement form from the system background to handle the rental business.
[0098] In an embodiment of the present invention, the user data can be queried from the database according to the user data request by a database query language such as SQL.
[0099] S5. Intercept the user data, and decrypt the target user data with the key corresponding to the target user name to obtain the returned data;
[0100] In an embodiment of the present invention, the method for intercepting the user data is the same as the method for intercepting the returned data of the data entry request by the target user end in step S2 above, and will not be elaborated here.
[0101] In an embodiment of the present invention, referring to Figure 3 As shown, decrypting the target user data with the key corresponding to the target user name to obtain the returned data includes:
[0102] S31. Screen out the user ciphertext from the target user data;
[0103] S32. Obtain the round key corresponding to the key, and perform an exclusive OR operation on the user ciphertext with the round key;
[0104] S33. Perform a reverse shift operation on the user ciphertext after the exclusive OR operation;
[0105] S34. Perform an inverse byte substitution operation on the ciphertext data after the reverse shift with the substitution table to obtain the returned data.
[0106] Specifically, the method for screening out the user ciphertext from the target user data is the same as the method for screening out the privacy data that conforms to the preset protection rules from the returned data in step S3 above, and will not be elaborated here.
[0107] Specifically, the reverse shift refers to a row shift in the opposite direction to the row shift direction in step S3 above.
[0108] Specifically, the method for performing an inverse byte substitution operation on the ciphertext data after the reverse shift with the substitution table to obtain the returned data is the reverse of the method for performing a byte substitution operation on the privacy data with the preset substitution table in step S3 above, and will not be elaborated here.
[0109] In an embodiment of the present invention, by intercepting the user data and decrypting the target user data with the key corresponding to the target user name, it is convenient for subsequent users to judge the target user data.
[0110] S6. Perform data desensitization on the returned data, and display the desensitized returned data on a preset front-end page.
[0111] In the embodiment of the present invention, the data desensitization of the returned data includes: screening out privacy data that conforms to a preset protection rule from the returned data; replacing the characters in the privacy data with special characters according to a preset data desensitization scheme.
[0112] Specifically, the method for screening out privacy data that conforms to a preset protection rule from the returned data is the same as the method in step S3 for screening out privacy data that conforms to a preset protection rule from the returned data.
[0113] Specifically, the data desensitization scheme, for example, replaces the middle four characters of the mobile phone number with asterisks.
[0114] Specifically, the characters in the privacy data can be replaced with special characters according to a preset data desensitization scheme through the regular expression of Java.
[0115] In the embodiment of the present invention, by performing data desensitization on the returned data and displaying the desensitized returned data on a preset front-end page, it can help users judge their own information, such as determining whether a mobile phone number belongs to themselves through the first three and the last four digits of the mobile phone number.
[0116] In the embodiment of the present invention, by creating a key data set with the same length as the list length of the user list and matching the keys in the key data set with the user names in the user list one by one, it can ensure that each user has a unique private key for data encryption and decryption of the user, which can further improve the data security of the user; by intercepting the returned data of the target user terminal for the data entry request, it is convenient to perform encryption processing on the returned data subsequently, and also reduces the risk of data leakage and improves the data security of the user. By encrypting the privacy data into user ciphertext using the key corresponding to the target user name, it ensures the opacity of the user data during the storage process and enhances the security of the privacy data. Therefore, the privacy data protection method of the low-code platform proposed by the present invention can solve the problem of low security when performing privacy data protection.
[0117] As Figure 4 shown, it is a functional module diagram of a privacy data protection device of a low-code platform provided by an embodiment of the present invention.
[0118] The privacy data protection device 100 of the low-code platform described in the present invention can be installed in an electronic device. According to the functions achieved, the privacy data protection device 100 of the low-code platform can include a key creation module 101, a data request module 102, a data encryption module 103, a data decryption module 104, and a data masking module 105. The modules described in the present invention can also be referred to as units, which refer to a series of computer program segments that can be executed by a device processor and can complete fixed functions, and are stored in the memory of the electronic device.
[0119] In this embodiment, the functions of each module / unit are as follows:
[0120] The key creation module 101 is used to obtain a user list, create a key data set with the same length as the list length of the user list, and match the keys in the key data set with the user names in the user list one by one;
[0121] The data request module 102 is used to select a user name from the user list one by one as the target user name, send a data entry request to the target user terminal corresponding to the target user name, and intercept the return data of the target user terminal to the data entry request;
[0122] The data encryption module 103 is used to screen out privacy data that meets the preset protection rules from the return data, encrypt the privacy data into user ciphertext according to the key corresponding to the target user name, replace the privacy data in the return data with the user ciphertext to obtain user data, and store the user data in a preset database;
[0123] The data decryption module 104 is used to query the user data from the database according to the user data request when receiving the user data request corresponding to the target user name; intercept the user data, and decrypt the target user data according to the key corresponding to the target user name to obtain the return data;
[0124] The data masking module 105 is used to perform data masking on the return data and display the masked return data on a preset front-end page.
[0125] Specifically, each module described in the privacy data protection device 100 of the low-code platform in the embodiment of the present invention uses the same technical means as the privacy data protection method of the low-code platform described above Figures 1 to 3 and can produce the same technical effects, which will not be elaborated here.
[0126] Such as Figure 5As shown, it is a schematic structural diagram of an electronic device for implementing a privacy data protection method of a low-code platform provided by an embodiment of the present invention.
[0127] The device 1 may include a processor 10, a memory 11, a communication bus 12, and a communication interface 13, and may also include a computer program stored in the memory 11 and operable on the processor 10, such as a privacy data protection program for a low-code platform.
[0128] Among them, the processor 10 may be composed of integrated circuits in some embodiments. For example, it may be composed of a single packaged integrated circuit, or may be composed of multiple packaged integrated circuits with the same or different functions, including a combination of one or more central processing units (CPUs), microprocessors, digital processing chips, graphics processors, and various control chips. The processor 10 is the control core (Control Unit) of the device, connecting various components of the entire device through various interfaces and lines, and by running or executing programs or modules stored in the memory 11 (such as executing a privacy data protection program for a low-code platform, etc.), and calling data stored in the memory 11, to perform various functions of the device and process data.
[0129] The memory 11 includes at least one type of readable storage medium, and the readable storage medium includes flash memory, mobile hard disks, multimedia cards, card-type memories (such as SD or DX memories, etc.), magnetic memories, magnetic disks, optical discs, etc. The memory 11 may be an internal storage unit of the device in some embodiments, such as the mobile hard disk of the device. The memory 11 may also be an external storage device of the device in other embodiments, such as a plug-in mobile hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the device. Further, the memory 11 may also include both an internal storage unit and an external storage device of the device. The memory 11 can be used not only to store application software installed on the device and various types of data, such as the code of a privacy data protection program for a low-code platform, etc., but also to temporarily store data that has been output or will be output.
[0130] The communication bus 12 can be a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, or the like. This bus can be divided into an address bus, a data bus, a control bus, etc. The bus is configured to enable connection communication between the memory 11 and at least one processor 10, etc.
[0131] The communication interface 13 is used for communication between the above-mentioned device and other devices, including a network interface and a user interface. Optionally, the network interface can include a wired interface and / or a wireless interface (such as a WI-FI interface, a Bluetooth interface, etc.), and is generally used to establish a communication connection between this device and other devices. The user interface can be a display, an input unit (such as a keyboard), and optionally, the user interface can also be a standard wired interface or a wireless interface. Optionally, in some embodiments, the display can be an LED display, a liquid crystal display, a touch liquid crystal display, and an OLED (Organic Light-Emitting Diode) toucher, etc. Among them, the display can also be appropriately referred to as a display screen or a display unit, and is used to display the information processed in the device and to display a visual user interface.
[0132] Only the device with components is shown in the figure. Those skilled in the art can understand that the structure shown in the figure does not constitute a limitation on the device, and it can include fewer or more components than shown in the figure, or combine certain components, or have different component arrangements.
[0133] For example, although not shown, the device may further include a power source (such as a battery) for powering each component. Preferably, the power source can be logically connected to the at least one processor 10 through a power management device, so as to implement functions such as charge management, discharge management, and power consumption management through the power management device. The power source can also include any components such as one or more DC or AC power sources, a recharge device, a power failure detection circuit, a power converter or an inverter, and a power status indicator. The device may also include a variety of sensors, a Bluetooth module, a Wi-Fi module, etc., which will not be elaborated here.
[0134] It should be understood that the above embodiments are only for illustration purposes and are not limited by this structure in the scope of the patent application.
[0135] The privacy data protection program of the low-code platform stored in the memory 11 in the device 1 is a combination of multiple instructions, and when running in the processor 10, it can achieve:
[0136] Obtain a user list, create a key data set with the same length as the list length of the user list, and match the keys in the key data set with the user names in the user list one by one;
[0137] Select a user name from the user list one by one as the target user name, send a data entry request to the target user terminal corresponding to the target user name, and intercept the return data of the target user terminal for the data entry request;
[0138] Screen out the private data that meets the preset protection rules from the return data, encrypt the private data into user ciphertext according to the key corresponding to the target user name, use the user ciphertext to replace the private data in the return data to obtain user data, and store the user data in a preset database;
[0139] When receiving a user data request corresponding to the target user name, query the user data from the database according to the user data request;
[0140] Intercept the user data, and decrypt the target user data according to the key corresponding to the target user name to obtain the return data;
[0141] Perform data desensitization on the return data, and display the desensitized return data on a preset front-end page.
[0142] Specifically, the specific implementation method of the processor 10 for the above instructions can refer to the description of the relevant steps in the corresponding embodiments of the attached drawings, which will not be elaborated here.
[0143] Further, if the module / unit integrated in the device 1 is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a storage medium. The storage medium can be volatile or non-volatile. For example, the storage medium may include: any entity or device capable of carrying the computer program code, a recording medium, a USB flash drive, a mobile hard disk, a magnetic disk, an optical disc, a computer memory, a read-only memory (ROM, Read-Only Memory).
[0144] The present invention also provides a storage medium, the readable storage medium stores a computer program, and when the computer program is executed by a processor of an electronic device, it can implement:
[0145] Obtain a user list, create a key data set with the same length as the list length of the user list, and match the keys in the key data set with the user names in the user list one by one;
[0146] Select a username from the user list one by one as the target username, send a data entry request to the target user terminal corresponding to the target username, and intercept the return data of the target user terminal to the data entry request;
[0147] Screen out the private data that meets the preset protection rules from the return data, encrypt the private data into user ciphertext according to the key corresponding to the target username, use the user ciphertext to replace the private data in the return data to obtain user data, and store the user data in a preset database;
[0148] When receiving a user data request corresponding to the target username, query the user data from the database according to the user data request;
[0149] Intercept the user data, and decrypt the target user data according to the key corresponding to the target username to obtain the return data;
[0150] Perform data desensitization on the return data, and display the desensitized return data on a preset front-end page.
[0151] In several embodiments provided by the present invention, it should be understood that the disclosed devices, apparatuses and methods can be implemented in other ways. For example, the device embodiments described above are only illustrative. For example, the division of the modules is only a logical function division, and there may be other division methods in actual implementation.
[0152] The modules described as separate components may or may not be physically separated. The components shown as modules may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0153] In addition, in each embodiment of the present invention, the various functional modules can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated unit can be implemented in the form of hardware, or in the form of hardware plus software functional modules.
[0154] For those skilled in the art, it is obvious that the present invention is not limited to the details of the above exemplary embodiments, and can be implemented in other specific forms without departing from the spirit or basic characteristics of the present invention.
[0155] Therefore, from any perspective, the embodiments should be regarded as exemplary and non-limiting. The scope of the present invention is defined by the appended claims rather than the above description. Thus, all changes falling within the meaning and scope of the equivalent elements of the claims are intended to be encompassed by the present invention. Any reference signs in the claims should not be construed as limiting the claims concerned.
[0156] The blockchain referred to in the present invention is a new application mode of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanism, and encryption algorithms. Blockchain, in essence, is a decentralized database, a series of data blocks generated by using cryptographic methods. Each data block contains information about a batch of network transactions, which is used to verify the validity of the information (anti-counterfeiting) and generate the next block. The blockchain can include the blockchain underlying platform, the platform product service layer, and the application service layer, etc.
[0157] The embodiments of this application can acquire and process relevant data based on artificial intelligence technology. Among them, Artificial Intelligence (AI) is to use digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, sense the environment, acquire knowledge, and use knowledge to obtain the best results in terms of theory, method, technology, and application systems.
[0158] In addition, obviously, the term "including" does not exclude other units or steps, and the singular does not exclude the plural. The multiple units or devices stated in the system claims can also be implemented by one unit or device through software or hardware. Words such as first, second, etc. are used to denote names and do not denote any specific order.
[0159] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not restrictive. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention.
Claims
1. A method for protecting privacy data of a low-code platform, characterized in that, The method includes: Obtain a user list, create a key data set with the same length as the list length of the user list, and match the keys in the key data set with the user names in the user list one by one; Select a user name from the user list one by one as the target user name, send a data entry request to the target user terminal corresponding to the target user name, and intercept the return data of the target user terminal for the data entry request; Screen out the private data that meets the preset protection rules from the return data, encrypt the private data into user ciphertext according to the key corresponding to the target user name, use the user ciphertext to replace the private data in the return data to obtain user data, and store the user data in a preset database; When receiving a user data request corresponding to the target user name, query the user data from the database according to the user data request; Intercept the user data, and decrypt the target user data according to the key corresponding to the target user name to obtain the return data; Perform data desensitization on the return data, and display the desensitized return data on a preset front-end page; Among them, the creation of the key data set with the same length as the list length of the user list includes: creating a string array with the same length as the list length; generating a random key through a preset encoding method; judging whether there is an array element in the string array that is the same as the key by traversing; when there is an array element in the string array that is the same as the key, return to the step of generating a random key through the preset encoding method; when there is no array element in the string array that is the same as the key, add the key as an array element to the string array in the order from front to back, and judge whether the last array element of the string array is a null value; when the last array element of the string array is a null value, return to the step of generating a random key through the preset encoding method; when the last array element of the string array is not a null value, use the string array as the key data set.
2. The method for protecting privacy data of a low-code platform according to claim 1, characterized in that, The screening of the private data that meets the preset protection rules from the return data includes: Obtain the digital protection rules in the protection rules, and screen out the private numbers that meet the digital protection rules from the return data according to the digital protection rules; Obtain the text protection rules in the protection rules, and screen out the private texts that meet the text protection rules from the return data according to the text protection rules; Obtain the private data according to the private numbers and the private texts.
3. The method for protecting privacy data of a low-code platform according to claim 2, characterized in that, The screening of the private numbers that meet the digital protection rules from the return data according to the digital protection rules includes: Extract the protected number length from the digital protection rules; Extract a digital string from the return data, and select a digital string with the same length as the number length from the digital string as the private number.
4. The method for protecting privacy data of a low-code platform according to claim 2, characterized in that, Screening out privacy texts that conform to the text protection rule from the returned data according to the text protection rule includes: Extracting a privacy word library from the text protection rule; Splitting the returned data after extracting the digital string into multiple user data sentences; Splitting the user data sentences into user data words; Calculating the sentence weight of each user data sentence according to the user data words and the privacy word library; Regarding the user data sentences with sentence weights greater than a preset threshold as privacy texts.
5. The method for protecting privacy data of a low-code platform according to claim 1, characterized in that, Encrypting the privacy data into user ciphertext according to the key corresponding to the target user name includes: Generating a corresponding round key according to the key; Performing a byte substitution operation on the privacy data through a preset substitution table; Performing a row shift operation on the privacy data after byte substitution; Performing a column confusion operation on the privacy data after row shift; Performing an exclusive OR operation on the privacy data after column confusion through the round key to obtain the user ciphertext.
6. The method for protecting privacy data of a low-code platform according to any one of claims 5, characterized in that, Decrypting the target user data according to the key corresponding to the target user name to obtain the returned data includes: Screening out the user ciphertext from the target user data; Obtaining the round key corresponding to the key and performing an exclusive OR operation on the user ciphertext using the round key; Performing a reverse row shift operation on the user ciphertext after the exclusive OR operation; Performing an inverse byte substitution operation on the user ciphertext after reverse row shift using the substitution table to obtain the returned data.
7. A privacy data protection device for a low-code platform, which is used to implement the privacy data protection method of the low-code platform described in any one of claims 1 to 6, characterized in that, The device includes: A key creation module, configured to obtain a user list, create a key data set with the same length as the list length of the user list, and match the keys in the key data set with the user names in the user list one by one; A data request module, configured to select a user name from the user list one by one as the target user name, send a data entry request to the target user terminal corresponding to the target user name, and intercept the returned data of the target user terminal for the data entry request; A data encryption module, configured to screen out privacy data that conforms to a preset protection rule from the returned data, encrypt the privacy data into user ciphertext according to the key corresponding to the target user name, replace the privacy data in the returned data with the user ciphertext to obtain user data, and store the user data in a preset database; A data decryption module, configured to query the user data from the database according to the user data request when receiving a user data request corresponding to the target user name; intercept the user data, and decrypt the target user data according to the key corresponding to the target user name to obtain the returned data; A data desensitization module, configured to desensitize the returned data and display the desensitized returned data on a preset front-end page.
8. An electronic device, characterized in that, The electronic device includes: At least one processor; and, A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and when the computer program is executed by the at least one processor, the at least one processor is enabled to execute the privacy data protection method of the low-code platform according to any one of claims 1 to 6.
9. A storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the privacy data protection method of the low-code platform according to any one of claims 1 to 6.
Citation Information
Patent Citations
Multi-purpose multi-dimensional, variable and multi-key e-mail and data encryption method
US20120284528A1
User privacy protection method and system
US20150341322A1