A data processing method, device, equipment and storage medium
By receiving and decrypting the encrypted business data sent by the government system in the secure access module and determining the target business services, the malicious calls and information leakage problems when the government system calls the business services, and achieving high security transmission of information.
Patent Information
- Application Number
- CN202210992919.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-18
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2042-08-18
AI Technical Summary
When the government system calls the interface of the business service, there are problems such that the business service is easily called maliciously and the interactive information is easily leaked.
By receiving the encrypted service data sent by the government system in the secure access module, decrypting and decapsulating, determining the target service service, and sending the unblocked service data to the target service service, ensuring the security of information.
Through encryption and packaging technology, third parties are avoided forcibly decrypting business data, improve information security, and prevent malicious attacks and information leakage.
Smart Images

Figure CN115357919B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular, to a data processing method, apparatus, device, and storage medium. Background Art
[0002] With the advancement of digital government affairs, different government affairs systems can expand their own functions by invoking different business services through interface calls.
[0003] Currently, in order to ensure the interaction security between government affairs systems and business services, as well as the requirements for commercial cryptography applications of the second-level information systems in the "Basic Requirements for Cryptography Applications in Information Systems", cryptographic technologies are used in the interaction between government affairs systems and business services to ensure the integrity and confidentiality of data during the communication process.
[0004] Generally, the interaction between government affairs systems and business services will adopt the OAuth2 method (an open security protocol) to provide open capability interfaces to a third-party access platform and call the interfaces through an authentication method. Among them, both request parameters and response parameters exist in plain text form, which are easily tampered with or stolen by a third party. In addition, many open capability interfaces contain personal privacy attributes, such as mobile phone numbers, account numbers, ID numbers, etc. At present, the data processing methods between interfaces are difficult to ensure information security. Summary of the Invention
[0005] The present invention provides a data processing method, apparatus, device, and storage medium to solve the problems that when a government affairs system calls the interface of a business service to expand its own functions, the business service is easily maliciously called and the interaction information is easily leaked.
[0006] According to one aspect of the present invention, a data processing method is provided. The method is applied to a secure access module, and the method includes:
[0007] Receiving encrypted service data sent by a government affairs system, where the encrypted service data includes encapsulated first service data and second service data, and the encapsulated first service data is service data of a specified data type encapsulated according to a set encapsulation rule;
[0008] Decrypting the encrypted service data to obtain the encapsulated first service data and the second service data;
[0009] Determining a target business service corresponding to the service data;
[0010] Unencapsulating the encapsulated first service data and determining first service data from the result of the unencapsulation;
[0011] Send the first service data and the second service data to the target service.
[0012] According to another aspect of the present invention, a data processing method is provided. The method is applied to a government affairs system and includes:
[0013] In response to a service request initiated by a user, obtain service data, where the service data includes first service data of a specified data type and second service data other than the first service data;
[0014] Encapsulate the first service data according to a set encapsulation rule;
[0015] Encrypt the encapsulated first service data and the second service data to obtain encrypted service data;
[0016] Call an interface provided by a preset secure access module to send the encrypted service data to the secure access module. The secure access module decrypts the encrypted service data to obtain the encapsulated first service data and the second service data, determines the target service corresponding to the service data, and unpacks the encapsulated first service data, determines the first service data from the unpacking result, and sends the first service data and the second service data to the target service.
[0017] According to another aspect of the present invention, a data processing device is provided. The device is applied to a secure access module and includes:
[0018] A receiving unit, configured to receive encrypted service data sent by a government affairs system. The encrypted service data includes encapsulated first service data and second service data, and the encapsulated first service data is service data of a specified data type encapsulated according to a set encapsulation rule;
[0019] A decryption unit, configured to decrypt the encrypted service data to obtain the encapsulated first service data and the second service data;
[0020] A target service determination unit, configured to determine the target service corresponding to the service data;
[0021] An unpacking unit, configured to unpack the encapsulated first service data and determine the first service data from the unpacking result;
[0022] A sending unit, configured to send the first service data and the second service data to the target service.
[0023] According to another aspect of the present invention, there is provided a data processing device, which is applied to a government affairs system. The device includes:
[0024] A response unit, configured to obtain service data in response to a service request initiated by a user. The service data includes first service data of a specified data type and second service data other than the first service data;
[0025] An encapsulation unit, configured to encapsulate the first service data according to a set encapsulation rule;
[0026] An encryption unit, configured to encrypt the encapsulated first service data and the second service data to obtain encrypted service data;
[0027] A calling unit, configured to call an interface provided by a preset secure access module to send the encrypted service data to the secure access module. The secure access module decrypts the encrypted service data to obtain the encapsulated first service data and the second service data, determines a target service corresponding to the service data, and further, unpacks the encapsulated first service data, determines the first service data from the unpacking result, and sends the first service data and the second service data to the target service.
[0028] According to another aspect of the present invention, there is provided an electronic device, which includes:
[0029] At least one processor; and
[0030] A memory communicatively connected to the at least one processor; wherein,
[0031] The memory stores a computer program executable by the at least one processor. When the computer program is executed by the at least one processor, the at least one processor is enabled to execute a data processing method according to any embodiment of the present invention.
[0032] According to another aspect of the present invention, there is provided a computer-readable storage medium storing computer instructions for enabling a processor to implement a data processing method according to any embodiment of the present invention when executed.
[0033] An embodiment of the present invention discloses a data processing method, which is applied to a secure access module. The method includes: receiving encrypted service data sent by a government affairs system, where the encrypted service data includes encapsulated first service data and second service data. The encapsulated first service data is service data of a specified data type encapsulated according to a set encapsulation rule. Decrypting the encrypted service data to obtain the encapsulated first service data and the second service data. Determining a target service corresponding to the service data. Unencapsulating the encapsulated first service data and determining the first service data from the result of the unencapsulation. By encrypting and encapsulating the first service data, it is possible to avoid the situation where the first service data will be presented in plain text after being forcibly decrypted by a third party, greatly improving the security of information. Finally, sending the first service data and the second service data to the target service to implement the invocation of the target service. The embodiment of the present invention can well hide the true information of the backend service, improve security, and avoid malicious attacks or replay of requests by a third party. Only one interface needs to be provided for the government affairs system, unifying the interface protocols of each service. Each service does not need any modification or adaptation.
[0034] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0036] Figure 1 is a flowchart of a data processing method according to Embodiment 1 of the present invention;
[0037] Figure 2 is a schematic diagram of an interface list according to Embodiment 1 of the present invention;
[0038] Figure 3 is a schematic diagram of a subscription relationship according to Embodiment 1 of the present invention;
[0039] Figure 4 is a flowchart of a data processing method according to Embodiment 2 of the present invention;
[0040] Figure 5 is a schematic structural diagram of a data processing device according to Embodiment 3 of the present invention;
[0041] Figure 6 It is a schematic structural diagram of a data processing device provided in Embodiment 4 of the present invention;
[0042] Figure 7 It is a schematic structural diagram of an electronic device for implementing a data processing method according to an embodiment of the present invention. Specific embodiments
[0043] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0044] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.
[0045] In the embodiments of the present application, the acquisition, storage, use, processing, etc. of data all comply with the relevant regulations of national laws and regulations.
[0046] Embodiment 1
[0047] Figure 1 A flowchart of a data processing method is provided for Embodiment 1 of the present invention, and this method is applied to a secure access module.
[0048] Currently, since the services processed by different government affairs systems are different, the number and types of service calls required are also large. The service interfaces provided by different service services are numerous and the service scopes are different, resulting in problems such as inability to uniformly define parameters and complex structures. A data processing method proposed in the embodiments of the present invention uses a secure access module as an interaction bridge between the government affairs system and the service service, which can unify various interface protocols and avoid confusion caused by non-uniform multiple interface protocols.
[0049] In addition, due to the current interface call method where parameters all appear in plain text, they are vulnerable to malicious requests, tampering, and theft. In the embodiments of the present invention, by encapsulating each parameter information, other irrelevant accounts cannot know through cracking what interfaces of business services the security access module can access, nor can they know the specific parameter information required by the specific business services, thereby ensuring the security of the interaction information.
[0050] The embodiments of the present invention propose a data processing method. By providing only one interface through the security access module, that is, providing one interface for each government affairs system, and then shielding the business-related attributes of each business service, it is possible to prevent attacks such as snooping, tampering, leakage of sensitive information, and forgery by a third party.
[0051] This method can be executed by a data processing device, and the data processing device can be implemented in the form of hardware and / or software.
[0052] As Figure 1 shown, the method includes the following steps:
[0053] S110, receive the encrypted service data sent by the government affairs system. The encrypted service data includes the encapsulated first service data and the second service data. The encapsulated first service data is service data encapsulated in a specified data type using a set encapsulation rule.
[0054] The government affairs system can obtain the interface document from the security access module in advance. Among them, the obtained interface document can be divided into two parts. One part is the interface protocol that is common for national cryptography and required to access the security access module. The interface protocol can include the interface address of the security access module. National cryptography refers to the domestic cryptographic algorithms recognized by the State Cryptography Administration. The other part of the interface document can be the business interface description corresponding to the business service shielded by the security access module.
[0055] When the government affairs system determines that it needs to call a specific business service, it can determine the first service data together with the business interface description and the information possessed by the government affairs system. The specified data type of the first service data can be a data type related to the business attributes of the business service and can enable a third party to guess how to call the business service. For example, the service data of the specified data type can be the request body corresponding to the business interface of the business service, that is, the parameter names of the input parameters, etc. Among them, the parameter names can be determined according to the business interface description, and the parameter values corresponding to the parameter names can be determined according to the specific situation of the government affairs system.
[0056] Exemplarily, assume that a government affairs system itself does not have the function of sending verification code text messages. When the government affairs system needs to send verification code text messages to users, it needs to call a business service through a secure access module to the platform interface for sending verification code text messages, so that the business service for sending verification code text messages can complete the request operation of the government affairs system. Then the specific application scenario can be that a user needs to perform an operation of logging in through a mobile phone number in a certain government affairs system. At this time, the government affairs system needs to verify the user based on the mobile phone number input by the user and the verification code input by the user. At this time, the government affairs system can use the mobile phone number input by the user as a parameter value, combine the content of the business attributes described in the corresponding business interface, such as the corresponding parameter name, etc., generate the first business data, and encapsulate the first business data to ensure security.
[0057] When encapsulating the first business data, it can be to map the first business data to the payload of a certain encapsulation protocol, and then fill in the protocol header of the corresponding protocol to form a data packet of the encapsulation protocol and complete rate adaptation. It can also be to pack the first business data and then encrypt the packed first business data. Specifically, it can be encrypted using the public key of the pre-stored secure access module. Specifically, SM2 encryption can be performed (SM2, a domestic cryptographic algorithm recognized by the State Cryptography Administration).
[0058] The second business data can be the business service number corresponding to the requested business service, the signature data indicating the identity of the government affairs system itself, etc. To ensure information security, compared with the encapsulated first business data, the second business data can be information that does not involve user privacy information and the business attributes of the business service.
[0059] In addition, after the government affairs system determines the encapsulated first business data and the second business data, it can encrypt the business data according to the encryption method preset by the secure access module to ensure the security and stable access of information when accessing the secure access module.
[0060] S120, decrypt the encrypted business data to obtain the encapsulated first business data and the second business data.
[0061] After receiving the encrypted business data sent by the government affairs system, the secure access module can decrypt the encrypted business data using the preset decryption method, and after decryption, the encapsulated first business data and the second business data can be obtained.
[0062] S130, determine the target business service corresponding to the business data.
[0063] The target business service that the government affairs system needs to call can be determined through the second business data.
[0064] Specifically, the interface information of all business services that the security access module can connect to can be configured. Exemplarily, an interface list can be pre-configured. Refer to Figure 2 a schematic diagram of an interface list in Figure 2 which, the business service number (such as Figure 2 "api_code" in Figure 2 ), the address of the business interface corresponding to the business service (such as Figure 2 "api_url" in Figure 2 ), the input parameter information of the business service (such as
[0065] "rep_body" in
[0066] In a specific implementation, the second business data can be the target business service number. After decrypting the business data, the target business service number can be obtained. According to the obtained target business service number, a search can be performed in the pre-configured interface list, and the business service corresponding to the business service number that is the same as the target business service label found is determined as the target business service.
[0067] Based on the system identifier and the target business service number, a search is performed in the database to determine whether there is a subscription relationship between the government affairs system and the target business service;
[0068] If an association between the system identifier and the target business service number is found in the database, it is determined that there is a subscription relationship, and the encapsulation of the first business data is continued to be unpacked, and the first business data is determined from the unpacked result.
[0069] The government affairs system needs to submit a subscription application to the security access module in advance to apply for subscribing to one or more business services that the security access module can provide access to. The security access module can review the government affairs systems applying for subscription, and after passing the review, the subscription relationship can be recorded in the pre-set database with an association. Refer to Figure 3 a schematic diagram of a subscription relationship in
[0070] Specifically, the system identifier can be the number of the government affairs system. Refer to Figure 3, you can search in the database based on the number of the government system and the target business service number. If you find a record of the number of the government system and the target business service number, it proves that the government system has subscribed to the target business service, and you can continue to perform the following steps. If no corresponding record is found, it proves that the government interface has not subscribed to the target business service in advance and does not have the authority to call the business service. You can return a prompt of access failure to the government system, or return a prompt that requires subscription in advance.
[0071] in addition, Figure 2 The interface list can also be information stored in a database.
[0072] In a specific implementation, after receiving the encrypted business data, the security access module can also perform interface authentication on the system identifier based on an established protocol, such as the oauth2 protocol, to confirm the accuracy of the system identifier, which can serve as the first barrier to block malicious access. If the system identifier is determined to have no access authority after interface authentication, there is no need to perform subsequent decryption steps.
[0073] S140, decapsulate the encapsulated first service data, and determine the first service data from the decapsulation result.
[0074] Based on the encapsulation rule for encapsulating the first business data, the encapsulated first business data is decapsulated. Exemplarily, if the encapsulation rule is to map the first business data to the payload of a certain encapsulation protocol, and then fill the header of the corresponding protocol to form a data packet of the encapsulation protocol, then decapsulation is the reverse process of encapsulation, disassembling the protocol packet, processing the information in the header, and taking out the first business data before encapsulation in the payload. In another specific implementation, if the encapsulation rule is to use the public key of a pre-existing security access module for encryption, the interface access module can use its own private key to decrypt the encapsulated first business data to obtain the first business data before encryption.
[0075] In one embodiment, the decapsulation result includes the obfuscated parameter names based on the obfuscation rules and the parameter values corresponding to the obfuscated parameter names. S140 includes the following steps:
[0076] S140-1, decapsulate the encapsulated first service data to obtain obfuscated parameter names and parameter values corresponding to the obfuscated parameter names;
[0077] S140-2, deobfuscating the obfuscated parameter name and determining the deobfuscated parameter name;
[0078] S140-3, using the parameter value corresponding to the obfuscated parameter name as the parameter value corresponding to the deobfuscated parameter name;
[0079] S140-4, determine the de-obfuscated parameter names and the parameter values corresponding to each de-obfuscated parameter name as the first service data.
[0080] In order to further mask business attributes related to business services, such as parameter information, etc., the secure access module can pre-obfuscate each parameter name of each business service according to certain obfuscation rules, and record the obtained obfuscated parameter names in the interface document provided to the government affairs system. For example, for Figure 2 the service interface numbered 100002 in, its input parameter name is "userid", and its Chinese description can be "user unique id". The secure access module can obfuscate "userid" according to the obfuscation rules. For example, after obfuscating "userid", "xPei" is obtained.
[0081] In the service interface description part of the interface document provided to the government affairs system, there can be a business attribute part. Under the business attribute, each parameter name can be described. At this time, the parameter name in it can be filled with "xPei" after obfuscating "userid", and the Chinese description is still filled with "user unique id". Then, when the government affairs system determines the second service data before encapsulation, referring to the obtained service interface description, "xPei" can be used at the position of the parameter name to indicate "user unique id".
[0082] After the secure access module de-encapsulates the encapsulated first service data, for the obtained obfuscated parameter names, de-obfuscation can be performed according to the obfuscation rules, and the de-obfuscated parameter names can be obtained. That is, after de-obfuscating "xPei", "userid" can be obtained.
[0083] After obfuscating the parameter names of the business attributes belonging to the business services, even if a third party intercepts the request message, they cannot know the plaintext content. In addition, because the business attribute fields are obfuscated, even after brute-forcing the request ciphertext, the third party cannot read or guess the meaning corresponding to the obfuscated parameter names. Exemplarily, if the unobfuscated parameter name "userid" is used, which is a relatively common attribute naming, it is easier for a third party to guess its actual meaning. The method adopted in the embodiments of the present invention can greatly simplify the data structure of the transmission message and is more identifiable.
[0084] Since the current technologies for obfuscating and de-obfuscating data are relatively mature, the specific obfuscation rules, obfuscation methods, and de-obfuscation methods are not limited here.
[0085] In one embodiment, the database is further used to respectively record the parameter names associated with each business service subscribed by each government affairs system, and the obfuscated parameter names generated after obfuscating the parameter names. S140-2 includes the following steps:
[0086] Determine the parameter names associated with the target business service in the database as candidate parameter names according to the system identifier and the target business service number, and use the obfuscated parameter names corresponding to the candidate parameter names as candidate obfuscated parameter names;
[0087] Compare the obfuscated parameter name with the candidate obfuscated parameter names, and use the candidate obfuscated parameter name that is the same as the obfuscated parameter name as the target obfuscated parameter name;
[0088] Use the parameter name corresponding to the target obfuscated parameter name as the de-obfuscated parameter name.
[0089] In order to solve problems such as malicious guessing or malicious replay caused by the same attribute naming of the parameters of the business service when different government affairs systems subscribe to the same business service, when the security access module issues the business interface description to different government affairs systems, the obfuscated parameter names obtained by the government affairs systems are different. That is, for the same parameter name of the same business service, multiple different obfuscated parameter names can be generated after obfuscation, and one of them is assigned to each government affairs system subscribing to the business service to ensure that when different government affairs systems call the same business service, the obfuscated parameter names they use are all different.
[0090] After the security access module assigns different obfuscated parameter names to each government affairs system subscribing to the corresponding business service, corresponding records can be made in the database. Refer to Figure 3 the second column and the fourth column in, where the government affairs system number in the second column is client001 and subscribes to the business service numbered 100002. In the request body (req_body) column, that is, the input parameter name, it is recorded that "xPei" is used as the obfuscated "userid". For the government affairs system number client002 in the fourth column, which also subscribes to the business service numbered 100002, in the request body (req_body) column, "EesQ" is used as the obfuscated "userid".
[0091] When de-obfuscating the obfuscated parameter name and determining the de-obfuscated parameter name, it can be directly searched in the database after obtaining the obfuscated parameter name. Exemplarily, refer to Figure 3 , when the system identifier is client001 and the target business service number is 100001, it can be located in the database Figure 3For the first column, at this time, the candidate parameter names are "mobile" and "content", and correspondingly, the candidate obfuscated parameter names are "xReY" and "JxqP". After obtaining the obfuscated parameter names from the first unpacked service data, the obfuscated parameter names can be compared one by one with the candidate obfuscated parameter names. When a candidate obfuscated parameter name that is the same as the obfuscated parameter name is found, it can be confirmed as the target obfuscated parameter name, and the parameter name corresponding to the target obfuscated parameter name is used as the de-obfuscated parameter name until all the obfuscated parameters in the first unpacked service data have their corresponding de-obfuscated parameter names determined. This way only requires pre-configuring the database and performing look-up and comparison on the data in the database, without the need to perform de-obfuscation operations every time, which can improve efficiency.
[0092] S150, send the first service data and the second service data to the target service.
[0093] After the secure access platform determines the first service data and the second service data, it can send the first service data and the second service data to the target service to implement the invocation of the service. Among them, before sending the first service data and the second service data, the address of the target service can be determined according to the target service number. Refer to Figure 2 , according to the target service number, "api_url" can be found, that is, the address of the service interface corresponding to the service.
[0094] In one embodiment, the method further includes the following steps:
[0095] Receive the service result returned by the target service;
[0096] Encrypt the service result;
[0097] Send the encrypted service result to the government affairs system.
[0098] After sending the first service data and the second service data to the target service, the target service can implement functions according to the received data. For example, if the target service is used to send verification code text messages, the target service can obtain information such as the phone number for receiving the verification code from the received first service data and the second service data, and send a verification code to this phone number, and the source of this phone number can be input by the user into the government affairs system.
[0099] The target business service needs to return a business result. For example, it returns the business result of whether the verification code has been successfully sent, so that the government affairs system can be informed and perform subsequent operations. The target business service directly returns the business result to the secure access module. The secure access module can encrypt the business result and send the encrypted business result to the government affairs system. Among them, in order to smoothly implement the encryption and decryption required when interacting with each government affairs system, the database can record each government affairs system and its corresponding private key and public key. The private key and public key of the government affairs system can come from the upload of each government affairs system.
[0100] An embodiment of the present invention discloses a data processing method, which is applied to a secure access module. The method includes: receiving encrypted service data sent by a government affairs system. The encrypted service data includes encapsulated first service data and second service data. The encapsulated first service data is service data encapsulated in a specified data type and using a set encapsulation rule. Decrypt the encrypted service data to obtain the encapsulated first service data and second service data. Determine the target business service corresponding to the service data. Unencapsulate the encapsulated first service data and determine the first service data from the result of the unencapsulation. By encrypting and encapsulating the first service data, it is possible to avoid the situation where the first service data will be displayed in plain text after being forcibly decrypted by a third party, greatly improving the security of information. Finally, send the first service data and the second service data to the target business service to implement the call of the target business service. The embodiment of the present invention can well hide the true information of the backend business service, improve security, and avoid malicious attacks or replay of requests by a third party. Only provide an interface to the government affairs system, unify the interface protocols of each business service, and no modification or adaptation is required for each business service.
[0101] Embodiment 2
[0102] Figure 4 It is a flowchart of a data processing method provided by Embodiment 2 of the present invention. The method is applied to a government affairs system, as Figure 4 shown. The method includes the following steps:
[0103] S410, in response to a service request initiated by a user, obtain service data. The service data includes first service data of a specified data type and second service data other than the first service data.
[0104] In response to a service request initiated by a user, the service to be invoked for the service request can be determined. For example, if the user enters a mobile phone number and initiates an operation to obtain a verification code, it can be determined that the service with the function of sending verification codes needs to be invoked at this time. After determining the service to be invoked, the service attributes of the service, such as parameter names, etc., can be determined from the interface document issued by the secure access module to determine the first service data. In addition, second service data is generated based on information such as the service number and signature data corresponding to the service.
[0105] S420, encapsulate the first service data using a set encapsulation rule;
[0106] After determining the first service data, the first service data can be encapsulated to ensure the confidentiality of the service attributes of the service. When specifically encapsulating, the public key of the secure access module obtained in advance can be used to encrypt the first service data.
[0107] S430, encrypt the encapsulated first service data and the second service data to obtain encrypted service data.
[0108] The encapsulated first service data and the second service data can be encrypted through a set encryption method. At the same time, the private key of itself can be used for signature to obtain signature data, so that the secure access module can better verify the identity of the government affairs system.
[0109] In addition, when determining the first service data according to the interface document, the information related to the service attributes of the service can be obfuscated information. For example, the parameter name can be an obfuscated parameter name. At this time, even if a third party forcibly decrypts the encrypted service data, it is difficult to obtain the information related to the service attributes of the service from the decrypted first service data.
[0110] S440, call the interface provided by a preset secure access module to send the encrypted service data to the secure access module. The secure access module decrypts the encrypted service data to obtain the encapsulated first service data and the second service data, determines the target service corresponding to the service data, and, de-encapsulates the encapsulated first service data, determines the first service data from the result of de-encapsulation, and sends the first service data and the second service data to the target service.
[0111] The interface document of the secure access module can be obtained in advance, and the interface address of the secure access module can be obtained from the interface document. The encrypted service data is sent to the secure access module, and the secure access module decrypts the encrypted service data and unpacks the encapsulated second service data. The obtained first service data and second service data are sent by the secure access module to the service, realizing the invocation of the service.
[0112] In one embodiment, the following steps are further included:
[0113] Receive the encrypted service result from the secure access module;
[0114] Decrypt the encrypted service result to obtain the service result, and display the service result to the user.
[0115] After receiving the encrypted service result, it can be decrypted and the decrypted service result can be displayed to the user. Exemplarily, when the user inputs the mobile phone number to initiate the operation of receiving the verification code, the returned service result can be that the verification code has been sent or the verification code sending fails, and the service result can be displayed to the user so that the user can know the current service processing situation.
[0116] An embodiment of the present invention discloses a data processing method, which is applied to a government affairs system and includes: in response to a service request initiated by a user, obtaining service data, where the service data includes first service data of a specified data type and second service data other than the first service data, encapsulating the first service data according to a set encapsulation rule; encrypting the encapsulated first service data and second service data to obtain encrypted service data; invoking an interface provided by a preset secure access module to send the encrypted service data to the secure access module, and the secure access module decrypts the encrypted service data to obtain the encapsulated first service data and second service data, determines a target service corresponding to the service data, and unpacks the encapsulated first service data, determines the first service data from the unpacking result, and sends the first service data and second service data to the target service. By means of encryption, encapsulation, etc., the service attributes of the service are shielded, preventing third parties from performing attack behaviors such as snooping, tampering, sensitive information leakage, forgery, etc., and ensuring the security of information.
[0117] Embodiment Three
[0118] Figure 5 FIG. 22 is a schematic structural diagram of a data processing device provided in Embodiment Three of the present invention. The device is applied to a secure access module and includes the following units:
[0119] A receiving unit 510, configured to receive the encrypted service data sent by the government affairs system, where the encrypted service data includes the encapsulated first service data and the second service data, and the encapsulated first service data is service data of a specified data type encapsulated according to a set encapsulation rule;
[0120] A decryption unit 520, configured to decrypt the encrypted service data to obtain the encapsulated first service data and the second service data;
[0121] A target service determination unit 530, configured to determine a target service corresponding to the service data;
[0122] A de-encapsulation unit 540, configured to de-encapsulate the encapsulated first service data and determine the first service data from the result of the de-encapsulation;
[0123] A sending unit 550, configured to send the first service data and the second service data to the target service.
[0124] In an embodiment, the encrypted service data is marked with the system identifier of the government affairs system, the second service data includes a target service number, and the secure access module has an associated pre-set database, where the database is used to record the subscription relationships between each government affairs system and each service; the apparatus further includes:
[0125] A judgment unit, configured to search in the database based on the system identifier and the target service number to judge whether there is a subscription relationship between the government affairs system and the target service;
[0126] An execution unit, configured to, when it is found in the database that the system identifier and the target service number are associated, determine that there is a subscription relationship, and then call the de-encapsulation unit 540.
[0127] In an embodiment, the result of the de-encapsulation includes parameter names obfuscated based on an obfuscation rule and parameter values corresponding to each of the obfuscated parameter names;
[0128] The de-encapsulation unit 540 includes the following sub-units:
[0129] A de-encapsulation sub-unit, configured to de-encapsulate the encapsulated first service data to obtain the obfuscated parameter names and the parameter values corresponding to each of the obfuscated parameter names;
[0130] An obfuscation reversal sub-unit, configured to reverse-obfuscate the obfuscated parameter names and determine the parameter names after the obfuscation reversal;
[0131] A parameter value determination subunit, configured to use the parameter value corresponding to the obfuscated parameter name as the parameter value corresponding to the de-obfuscated parameter name;
[0132] A first service data determination subunit, configured to determine the de-obfuscated parameter name and the parameter values corresponding to the de-obfuscated parameter names as the first service data.
[0133] In one embodiment, the database is further configured to record respectively the parameter names associated with each service subscribed by each government affairs system, and the obfuscated parameter names generated after obfuscating the parameter names;
[0134] The de-obfuscation subunit is specifically configured to:
[0135] According to the system identifier and the target service number, determine in the database the parameter names associated with the target service as candidate parameter names, and use the obfuscated parameter names corresponding to the candidate parameter names as candidate obfuscated parameter names;
[0136] Compare the obfuscated parameter name with the candidate obfuscated parameter names, and use the candidate obfuscated parameter name that is the same as the obfuscated parameter name as the target obfuscated parameter name;
[0137] Use the parameter name corresponding to the target obfuscated parameter name as the de-obfuscated parameter name.
[0138] In one embodiment, the apparatus further includes the following units:
[0139] A service result receiving unit, configured to receive the service result returned by the target service;
[0140] A service result encryption unit, configured to encrypt the service result;
[0141] A service result sending unit, configured to send the encrypted service result to the government affairs system.
[0142] The data processing apparatus provided by the embodiment of the present invention can implement the data processing method provided by the first embodiment of the present invention, and has corresponding functional modules and beneficial effects for executing the method.
[0143] Embodiment Four
[0144] Figure 6 FIG. is a schematic structural diagram of a data processing apparatus provided by the fourth embodiment of the present invention. The apparatus is applied to a government affairs system and includes:
[0145] A response unit 610, configured to obtain service data in response to a service request initiated by a user, where the service data includes first service data of a specified data type and second service data other than the first service data;
[0146] An encapsulation unit 620, configured to encapsulate the first service data according to a set encapsulation rule;
[0147] An encryption unit 630, configured to encrypt the encapsulated first service data and the second service data to obtain encrypted service data;
[0148] A calling unit 640, configured to call an interface provided by a preset secure access module to send the encrypted service data to the secure access module, where the secure access module decrypts the encrypted service data to obtain the encapsulated first service data and the second service data, determines a target service corresponding to the service data, and further, unpacks the encapsulated first service data, determines the first service data from the unpacking result, and sends the first service data and the second service data to the target service.
[0149] In one embodiment, the apparatus further includes the following units:
[0150] A service result receiving unit, configured to receive the encrypted service result from the secure access module;
[0151] A service result decryption unit, configured to decrypt the encrypted service result to obtain the service result;
[0152] A service result display unit, configured to display the service result to the user.
[0153] A data processing apparatus provided by an embodiment of the present invention can implement a data processing method provided by the second embodiment of the present invention, and has corresponding functional modules and beneficial effects for executing the method.
[0154] Embodiment Five
[0155] Figure 7The structural schematic diagram of the electronic device 10 that can be used to implement the embodiments of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0156] As Figure 7 shown, the electronic device 10 includes at least one processor 11 and a memory communicatively connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc. The memory stores a computer program executable by the at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0157] Multiple components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a disk, an optical disc, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.
[0158] The processor 11 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 11 include but are not limited to a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as a data processing method.
[0159] In some embodiments, a data processing method may be implemented as a computer program tangibly embodied in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed onto the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the data processing method described above may be performed. Alternatively, in other embodiments, the processor 11 may be configured to execute a data processing method by any other suitable means (e.g., by means of firmware).
[0160] The various embodiments of the systems and techniques described above in this document may be implemented in digital electronic circuitry, integrated circuit systems, field programmable gate arrays (FPGA), application specific integrated circuits (ASIC), application specific standard products (ASSP), systems on a chip (SOC), complex programmable logic devices (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include: implemented in one or more computer programs that may be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a special-purpose or general-purpose programmable processor that receives data and instructions from a storage system, at least one input device, and at least one output device, and transmits the data and instructions to the storage system, the at least one input device, and the at least one output device.
[0161] The computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus, such that the computer programs, when executed by the processor, cause the functions / operations specified in the flowchart and / or block diagram to be implemented. The computer programs may be executed entirely on the machine, partly on the machine, as a stand-alone software package partly on the machine and partly on a remote machine, or entirely on the remote machine or server.
[0162] In the context of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0163] To provide for interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can also be used to provide for interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0164] The systems and techniques described herein can be implemented in a computing system that includes backend components (such as, for example, a data server), or a computing system that includes middleware components (such as, for example, an application server), or a computing system that includes frontend components (such as, for example, a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (such as, for example, a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0165] A computing system may include a client and a server. The client and the server are generally far from each other and usually interact via a communication network. The relationship between the client and the server is created by computer programs running on respective computers and having a client-server relationship with each other. The server may be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system, and solves the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.
[0166] It should be understood that various forms of processes shown above can be used, steps can be reordered, added or deleted. For example, the steps described in the present invention can be executed in parallel, sequentially or in different orders, as long as the desired results of the technical solution of the present invention can be achieved, and no limitation is made herein.
[0167] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A data processing method, characterized in that, The method is applied to a security access module, and the method includes: Receiving encrypted service data sent by a government affairs system, where the encrypted service data includes encapsulated first service data and second service data, and the encapsulated first service data is service data of a specified data type encapsulated using a set encapsulation rule; Decrypting the encrypted service data to obtain the encapsulated first service data and the second service data; Determining a target service corresponding to the service data; Unencapsulating the encapsulated first service data and determining first service data from the result of the unencapsulation; Sending the first service data and the second service data to the target service; The encrypted service data is marked with the system identifier of the government affairs system, the second service data includes a target service number, and the security access module has an associated pre-set database, and the database is used to record the subscription relationships between each government affairs system and each service; After determining the corresponding target service, it further includes: Based on the system identifier and the target service number, searching in the database to determine whether there is a subscription relationship between the government affairs system and the target service; If the system identifier and the target service number are found to be associated in the database, it is determined that there is a subscription relationship, and continue to execute the step of unencapsulating the encapsulated first service data and determining first service data from the result of the unencapsulation.
2. The method according to claim 1, characterized in that The result of the unencapsulation includes parameter names obfuscated based on an obfuscation rule and parameter values corresponding to each of the obfuscated parameter names; The step of unencapsulating the encapsulated first service data and determining first service data from the result of the unencapsulation includes: Unencapsulating the encapsulated first service data to obtain the obfuscated parameter names and the parameter values corresponding to each of the obfuscated parameter names; De-obfuscating the obfuscated parameter names and determining the de-obfuscated parameter names; Taking the parameter values corresponding to the obfuscated parameter names as the parameter values corresponding to the de-obfuscated parameter names; Determining the de-obfuscated parameter names and the parameter values corresponding to each of the de-obfuscated parameter names as the first service data.
3. The method according to claim 2, wherein The database is further used to record respectively the parameter names associated with each service subscribed by each government affairs system and the obfuscated parameter names generated after obfuscating the parameter names; The step of de-obfuscating the obfuscated parameter names and determining the de-obfuscated parameter names includes: According to the system identifier and the target service number, determining in the database the parameter names associated with the target service as candidate parameter names, and taking the obfuscated parameter names corresponding to the candidate parameter names as candidate obfuscated parameter names; Comparing the obfuscated parameter names with the candidate obfuscated parameter names, and taking the candidate obfuscated parameter names that are the same as the obfuscated parameter names as target obfuscated parameter names; Taking the parameter names corresponding to the target obfuscated parameter names as the de-obfuscated parameter names.
4. The method according to any one of claims 1 to 3, characterized in that It further includes: Receive the service result returned by the target business service; Encrypt the service result; Send the encrypted service result to the government affairs system.
5. A data processing method, characterized in that, The method is applied to a government affairs system, and the method includes: In response to a service request initiated by a user, obtain service data, where the service data includes first service data of a specified data type and second service data other than the first service data; Encapsulate the first service data using a set encapsulation rule; Encrypt the encapsulated first service data and the second service data to obtain encrypted service data; The encrypted service data is marked with the system identifier of the government affairs system, and the second service data includes a target business service number. Call the interface provided by a preset secure access module to send the encrypted service data to the secure access module. The secure access module decrypts the encrypted service data to obtain the encapsulated first service data and the second service data, and determines the target business service corresponding to the service data. The secure access module has an associated preset database for recording the subscription relationships between each government affairs system and each business service. Based on the system identifier and the target business service number, search in the database to determine whether the government affairs system has a subscription relationship with the target business service. If the system identifier and the target business service number are found to be associated in the database, it is determined that there is a subscription relationship. Then, unencapsulate the encapsulated first service data, determine the first service data from the result of the unencapsulation, and send the first service data and the second service data to the target business service.
6. The method according to claim 5, wherein It further includes: Receive the encrypted service result from the secure access module; Decrypt the encrypted service result to obtain the service result, and display the service result to the user.
7. A data processing device, characterized in that, The device is applied to a secure access module, and the device includes: A receiving unit, configured to receive the encrypted service data sent by a government affairs system, where the encrypted service data includes the encapsulated first service data and the second service data, and the encapsulated first service data is service data of a specified data type encapsulated using a set encapsulation rule; A decryption unit, configured to decrypt the encrypted service data to obtain the encapsulated first service data and the second service data; A target business service determination unit, configured to determine the target business service corresponding to the service data; An unencapsulation unit, configured to unencapsulate the encapsulated first service data and determine the first service data from the result of the unencapsulation; A sending unit, configured to send the first service data and the second service data to the target business service; The encrypted service data is marked with the system identifier of the government affairs system. The second service data includes a target service number. The secure access module has an associated pre-set database, and the database is used to record the subscription relationships between each government affairs system and each service. After determining the corresponding target service, it further includes: Based on the system identifier and the target service number, search in the database to determine whether there is a subscription relationship between the government affairs system and the target service. If the system identifier and the target service number are found to be associated in the database, it is determined that there is a subscription relationship, and continue to perform the following operations: decompose the encapsulated first service data, and determine the first service data from the decompose result.
8. A data processing device, characterized in that, The device is applied to a government affairs system, and the device includes: A response unit, configured to respond to a service request initiated by a user and obtain service data, where the service data includes first service data of a specified data type and second service data other than the first service data. An encapsulation unit, configured to encapsulate the first service data using a set encapsulation rule. An encryption unit, configured to encrypt the encapsulated first service data and the second service data to obtain encrypted service data. The encrypted service data is marked with the system identifier of the government affairs system. The second service data includes a target service number. A call unit is configured to call an interface provided by a pre-set secure access module to send the encrypted service data to the secure access module. The secure access module decrypts the encrypted service data to obtain the encapsulated first service data and the second service data, and determines a target service corresponding to the service data. The secure access module has an associated pre-set database, and the database is used to record the subscription relationships between each government affairs system and each service. Based on the system identifier and the target service number, search in the database to determine whether there is a subscription relationship between the government affairs system and the target service. If the system identifier and the target service number are found to be associated in the database, it is determined that there is a subscription relationship, and further, decompose the encapsulated first service data, determine the first service data from the decompose result, and send the first service data and the second service data to the target service.
9. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor. When the computer program is executed by the at least one processor, the at least one processor is enabled to execute a data processing method according to any one of claims 1-4 and a data processing method according to any one of claims 5-6.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for causing a processor to implement a data processing method according to any one of claims 1-4 and a data processing method according to any one of claims 5-6 when executed.
Citation Information
Patent Citations
Data transmission method, device and system
CN102932349A
Business service security docking method and device, computer equipment and storage medium
CN114240347A