A method for encryption and decryption of identity signatures based on privacy protection

Verification and generation of authentication tokens through a third-party authentication system, combined with the data security processing service interface, the problem of insufficient data security after the integration of encryption and decryption tools in the software system is solved, and higher confidential data security is achieved.

CN115412255BActive Publication Date: 2025-06-27BEIJING YINFENG XINRONG TECH DEV
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210999982.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-19
Publication Date
2025-06-27
Estimated Expiration
2042-08-19

AI Technical Summary

Technical Problem

When the existing technology integrates encryption and decryption algorithm tools in software systems, data security can only be protected at the system data level. System developers can still view encrypted data by modifying the original permissions, resulting in the possibility of leaking confidential data.

Method used

The third-party authentication system authenticates the identity information of the logged-in user, obtains the authentication token, and calls the data security processing service interface based on the token. After verifying the token, the third-party authentication system cooperates with the software system to perform data security processing to ensure that the data is protected during the encryption and decryption process.

Benefits of technology

Even if system developers can illegally modify the permissions of the software system or crack the software system, they cannot obtain confidential data, which improves the security of identity signature encryption and decryption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115412255B_ABST
    Figure CN115412255B_ABST
Patent Text Reader

Abstract

The present disclosure relates to an identity signature encryption and decryption method based on privacy protection. The method includes: in response to a login operation, the software system authenticates the identity information of the logged-in user through a third-party authentication system and obtains an authentication token generated by the third-party authentication system; in response to a data processing request, the software system determines a data security processing service interface corresponding to the request type based on the request type of the data processing request; the software system uses the authentication token as a call parameter to call the data security processing service interface, so that after the third-party authentication system verifies the authentication token, it cooperates with the software system to perform data security processing. By separating the encryption and decryption services from the software system, the present disclosure ensures that even if system developers illegally modify the permissions of the software system or crack the software system, they cannot obtain confidential data, thereby improving the security of data processing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of information security, and in particular, to an identity signature encryption and decryption method based on privacy protection. Background Art

[0002] With the development of computer technology, the security of data in software systems has gradually attracted attention.

[0003] Currently, when a software system requires data encryption services, developers will integrate encryption and decryption algorithm tools in the software system and call the encryption and decryption algorithm tools when data encryption and decryption are needed to achieve data storage encryption.

[0004] However, integrating encryption and decryption algorithm tools in the system can only protect the security of data at the system data level. System developers can still view the encrypted data by modifying the original permissions, etc., and confidential data may still be leaked. Summary of the Invention

[0005] In order to solve the above technical problems or at least partially solve the above technical problems, the present disclosure provides an identity signature encryption and decryption method based on privacy protection to improve the security of confidential data.

[0006] In a first aspect, an embodiment of the present disclosure provides an identity signature encryption and decryption method based on privacy protection, including:

[0007] In response to a login operation, the software system authenticates the identity information of the logged-in user through a third-party authentication system and obtains an authentication token generated by the third-party authentication system;

[0008] In response to a data processing request, the software system determines a data security processing service interface corresponding to the request type based on the request type of the data processing request;

[0009] The software system uses the authentication token as a call parameter to call the data security processing service interface, so that after the third-party authentication system verifies the authentication token, it cooperates with the software system to perform data security processing.

[0010] In some embodiments, the data processing request is a new data request, and the data security processing service interface is a new interface;

[0011] Before the software system uses the authentication token as a call parameter to call the data security processing service interface, the method further includes: the software system generates a first key pair, the first key pair includes a first public key and a first private key; the software system encrypts the new data using the first public key to generate a first ciphertext;

[0012] The software system calls the data security processing service interface with the authentication token as a call parameter, including: the software system calls the new interface with the authentication token, the first ciphertext, and the first private key as call parameters.

[0013] In some embodiments, after the third-party authentication system verifies the authentication token, cooperating with the software system for data security processing includes:

[0014] After the third-party authentication system verifies the authentication token, it stores the first ciphertext and the first private key.

[0015] In some embodiments, the data processing request is an approval request, and the approval request carries the data information to be approved; the data security processing service interface is a modification interface;

[0016] The software system calls the data security processing service interface with the authentication token as a call parameter, including:

[0017] The software system calls the modification interface with the authentication token and the data information to be approved as call parameters.

[0018] In some embodiments, after the third-party authentication system verifies the authentication token, cooperating with the software system for data security processing includes:

[0019] After the third-party authentication system verifies the authentication token, it queries the corresponding first ciphertext and first private key based on the data information to be approved;

[0020] The third-party authentication system sends the queried first ciphertext and first private key to the software system;

[0021] The software system decrypts the received first ciphertext based on the received first private key and displays the decrypted data on the approval page.

[0022] In some embodiments, the data processing request is an archiving request, and the data security processing service interface is an archiving interface;

[0023] After the third-party authentication system verifies the authentication token, cooperating with the software system for data security processing includes:

[0024] The third-party authentication system queries and obtains the corresponding first ciphertext and first private key based on the archiving request;

[0025] The third-party authentication system decrypts the first ciphertext with the first private key and encrypts it again with the second public key in the second key pair to obtain a second ciphertext;

[0026] The third-party authentication system stores the second ciphertext.

[0027] In some embodiments, the data processing request is a contract management request, the contract management request includes contract information and the second private key in the second key pair, and the data security processing service interface is a query interface;

[0028] The software system calling the data security processing service interface with the authentication token as a call parameter includes: the software system calling the query interface with the authentication token and the contract information as call parameters.

[0029] In some embodiments, after the third-party authentication system verifies the authentication token, cooperating with the software system for data security processing includes:

[0030] The third-party authentication system queries the corresponding second ciphertext based on the contract information;

[0031] The third-party authentication system sends the second ciphertext to the software system;

[0032] The software system decrypts the second ciphertext using the second private key to obtain contract plaintext data;

[0033] The software system displays the contract plaintext data on a contract page.

[0034] In a second aspect, an embodiment of the present disclosure provides a privacy protection-based identity signature encryption and decryption device, including:

[0035] An acquisition module, configured to, in response to a login operation, the software system authenticates the identity information of a logged-in user through a third-party authentication system and obtains an authentication token generated by the third-party authentication system;

[0036] A determination module, configured to, in response to a data processing request, the software system determines a data security processing service interface corresponding to the request type based on the request type of the data processing request;

[0037] A processing module, configured to the software system calls the data security processing service interface with the authentication token as a call parameter, so that after the third-party authentication system verifies the authentication token, it cooperates with the software system for data security processing.

[0038] In a third aspect, an embodiment of the present disclosure provides an electronic device, including:

[0039] A memory;

[0040] A processor; and

[0041] A computer program;

[0042] Wherein, the computer program is stored in the memory and is configured to be executed by the processor to implement the method described in the first aspect.

[0043] In a fourth aspect, an embodiment of the present disclosure provides a computer-readable storage medium, on which a computer program is stored, and the computer program is executed by a processor to implement the method described in the first aspect.

[0044] In a fifth aspect, an embodiment of the present disclosure further provides a computer program product, which includes a computer program or instruction, and when the computer program or instruction is executed by a processor, it implements the above-mentioned identity signature encryption and decryption method based on privacy protection.

[0045] The data security method, device, equipment and computer-readable storage medium provided by the embodiments of the present disclosure separate the encryption and decryption service, that is, the third-party authentication system, from the software system. Even if a system developer can illegally modify the permissions of the software system or crack the software system, they cannot obtain confidential data, thereby improving the security of identity signature encryption and decryption. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] The accompanying drawings herein are incorporated into the specification and form a part of the specification, showing embodiments consistent with the present disclosure and used together with the specification to explain the principles of the present disclosure.

[0047] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure or the prior art, the following will briefly introduce the accompanying drawings required for use in the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0048] Figure 1 It is a flowchart of the identity signature encryption and decryption method based on privacy protection provided by an embodiment of the present disclosure;

[0049] Figure 2 It is a flowchart of the identity signature encryption and decryption method based on privacy protection provided by another embodiment of the present disclosure;

[0050] Figure 3 It is a flowchart of the identity signature encryption and decryption method based on privacy protection provided by another embodiment of the present disclosure;

[0051] Figure 4 It is a flowchart of the identity signature encryption and decryption method based on privacy protection provided by another embodiment of the present disclosure;

[0052] Figure 5 It is a flowchart of the identity signature encryption and decryption method based on privacy protection provided by another embodiment of the present disclosure;

[0053] Figure 6 Signaling diagram of the identity signature encryption and decryption method based on privacy protection provided by an embodiment of the present disclosure;

[0054] Figure 7 Signaling diagram of the identity signature encryption and decryption method based on privacy protection provided by an embodiment of the present disclosure;

[0055] Figure 8 Structural schematic diagram of the identity signature encryption and decryption device based on privacy protection provided by an embodiment of the present disclosure;

[0056] Figure 9 Structural schematic diagram of the electronic device provided by an embodiment of the present disclosure. Detailed implementation manners

[0057] In order to be able to more clearly understand the above-mentioned objects, features, and advantages of the present disclosure, the solutions of the present disclosure will be further described below. It should be noted that, without conflict, the embodiments of the present disclosure and the features in the embodiments may be combined with each other.

[0058] Many specific details are set forth in the following description in order to fully understand the present disclosure, but the present disclosure may also be implemented in other ways different from those described herein; obviously, the embodiments in the specification are only a part of the embodiments of the present disclosure, rather than all of the embodiments.

[0059] An embodiment of the present disclosure provides an identity signature encryption and decryption method based on privacy protection. The method will be introduced below in combination with specific embodiments.

[0060] Figure 1 Flowchart of the identity signature encryption and decryption method based on privacy protection provided by an embodiment of the present disclosure. The method is applied to a software system, and the specific steps are as follows:

[0061] S101. In response to a login operation, the software system authenticates the identity information of the logged-in user through a third-party authentication system and obtains an authentication token generated by the third-party authentication system.

[0062] In response to the user's login operation, such as when the user enters a username and password to log in to the system, the software system obtains the user's identity information and authenticates the user's identity information through a third-party authentication system. Among them, the third-party authentication system may be an encryption machine, and the third-party authentication system exists independently of the software system. After the third-party authentication system successfully authenticates the user's identity information, it generates an authentication token corresponding to the user's identity and sends the authentication token to the software system. Moreover, the authentication tokens of logged-in users with different identities are different.

[0063] S102. In response to a data processing request, the software system determines a data security processing service interface corresponding to the request type based on the request type of the data processing request.

[0064] After the software system receives an authentication token with successful authentication, it further obtains the data processing request of the user and determines the type of the data processing request, such as a new data request, an approval request, an archiving request, a contract management request, etc. According to the different request types of the data processing request, it determines the corresponding data security processing service interface, such as a new interface, a modification interface, an archiving interface, a query interface.

[0065] S103. The software system uses the authentication token as a call parameter to call the data security processing service interface, so that after the third-party authentication system verifies the authentication token, it cooperates with the software system to perform data security processing.

[0066] When the software system processes a data processing request, it uses the authentication token as a call parameter to call the data security processing service interface corresponding to the data processing request. After the third-party authentication system verifies the authentication token, it confirms that the user identity is legal and cooperates with the software system to process the data processing request. It should be noted that the authentication token has timeliness, that is, after obtaining an authentication token once, the user does not need to perform identity authentication again within a preset time, and the legal user identity can be proved through this authentication token to perform corresponding operations in the system. After the preset time has passed, it is necessary to re-perform identity authentication to obtain a new authentication token.

[0067] In the embodiment of the present disclosure, in response to a login operation, the software system authenticates the identity information of the logged-in user through a third-party authentication system and obtains an authentication token generated by the third-party authentication system; in response to a data processing request, the software system determines a data security processing service interface corresponding to the request type based on the request type of the data processing request; the software system uses the authentication token as a call parameter to call the data security processing service interface, so that after the third-party authentication system verifies the authentication token, it cooperates with the software system to perform data security processing, separating the encryption and decryption service, that is, the third-party authentication system and the software system. Even if a system developer can illegally modify the permissions of the software system or crack the software system, they cannot obtain confidential data, improving the security of identity signature encryption and decryption.

[0068] Figures 2 to 5 It is a schematic diagram of an identity signature encryption and decryption method based on privacy protection in different scenarios. Next, in combination with Figures 2 to 5 , the identity signature encryption and decryption method based on privacy protection provided by the present disclosure will be introduced. It can be understood that the identity signature encryption and decryption method based on privacy protection provided by the present disclosure can also be applied to other scenarios.

[0069] Figure 2 Flowchart of the identity signature encryption and decryption method based on privacy protection provided by embodiments of the present disclosure. This method can be applied to the scenario of new data. As Figure 2 shown, the specific steps included are as follows:

[0070] S201. In response to a login operation, the software system authenticates the identity information of the logged-in user through a third-party authentication system and obtains an authentication token generated by the third-party authentication system.

[0071] S202. In response to a new data request, determine that the data security processing service interface is a new interface.

[0072] The applicant for the new data request logs in to the software system. The software system authenticates the identity information of the logged-in user through a third-party authentication system and obtains an authentication token generated by the third-party authentication system to confirm that the applicant's identity is legal. The applicant enters the software system menu, performs corresponding operations, fills in relevant data, and submits a request for new data. The software system, in response to the new data request submitted by the applicant, confirms that the corresponding security processing service interface is a new interface.

[0073] S203. The software system generates a first key pair, where the first key pair includes a first public key and a first private key; the software system encrypts the new data using the first public key to generate a first ciphertext.

[0074] For the new data request submitted by the applicant, the software system generates a key pair, where the key pair includes a first public key and a first private key. The software system encrypts the new data filled in by the applicant using the first public key to generate a first ciphertext. It can be understood that for different new data requests, the software system randomly generates different key pairs.

[0075] S204. The software system uses the authentication token, the first ciphertext, and the first private key as call parameters to call the new interface.

[0076] The software system sends the authentication token, the first ciphertext encrypted by the first public key, and the first private key corresponding to the first public key to the third-party authentication system by calling the new interface.

[0077] S205. After verifying the authentication token, the third-party authentication system stores the first ciphertext and the first private key.

[0078] After receiving the authentication token, the first ciphertext encrypted by the first public key, and the first private key corresponding to the first public key sent by the software system, the third-party authentication system first verifies the authentication token. After successful verification, it saves the first ciphertext and the first private key in the corresponding first storage space in the third-party authentication system.

[0079] Figure 3 The flowchart of the identity signature encryption and decryption method based on privacy protection provided by another embodiment of the present disclosure can be applied to the data approval scenario. As Figure 3 shown, the specific steps included in this method are as follows:

[0080] S301. In response to a login operation, the software system authenticates the identity information of the logged-in user through a third-party authentication system and obtains the authentication token generated by the third-party authentication system.

[0081] S302. In response to an approval request, determine that the data security processing service interface is a modification interface.

[0082] When the approver logs in to the software system, the software system authenticates the identity information of the logged-in user through a third-party authentication system and obtains the authentication token generated by the third-party authentication system to confirm that the identity of the approver is legal. The approver opens the approval interface. In response to the approval request, the software system determines that the data security processing service interface is a modification interface. Among them, the approval request carries the data information to be approved.

[0083] S303. The software system uses the authentication token and the data information to be approved as call parameters to call the modification interface.

[0084] The software system sends the authentication token and the data information to be approved to the third-party authentication system by calling the modification interface.

[0085] S304. After the third-party authentication system verifies the authentication token, it queries the corresponding first ciphertext and first private key based on the data information to be approved.

[0086] After receiving the authentication token and the data information to be approved sent by the software system, the third-party authentication system first verifies the authentication token. After successful verification, it confirms that the identity of the approver is legal and searches for the corresponding first ciphertext and first private key in the first storage space of the third-party authentication system based on the data information to be approved.

[0087] S305. The third-party authentication system sends the queried first ciphertext and first private key to the software system.

[0088] S306. The software system decrypts the received first ciphertext based on the received first private key and displays the decrypted data on the approval page.

[0089] The software system receives the first private key and the first ciphertext sent by the third-party authentication system, decrypts the first ciphertext with the first private key, and displays the decrypted data on the approval page for the approver to view.

[0090] The approver edits the data on the approval page, submits the approval result after completion. The software system re-encrypts the approval result with the first public key to generate the approved first ciphertext, and sends the authentication token, the first secret key, and the approved first ciphertext to the third-party authentication system by calling the modification interface. After receiving the authentication token, the first secret key, and the approved first ciphertext sent by the software system, the third-party authentication system first verifies the authentication token. After successful verification, it saves the first secret key and the approved first ciphertext to the corresponding first storage space in the third-party authentication system.

[0091] The above disclosed implementation randomly generates a first key pair, including a first public key and a first private key, and stores the new data and the approval result in ciphertext form in the third-party authentication system with the first public key and the first private key, effectively isolating the system users and ensuring the security of the confidential data in the first storage space, and further improving the reliability of the identity signature encryption and decryption method based on privacy protection.

[0092] Based on the above embodiments, Figure 4 The flowchart of the identity signature encryption and decryption method based on privacy protection provided by another embodiment of the present disclosure, which can be applied to the contract filing scenario. As Figure 4 shown, the specific steps included in this method are as follows:

[0093] S401. In response to a login operation, the software system authenticates the identity information of the logged-in user through the third-party authentication system and obtains the authentication token generated by the third-party authentication system.

[0094] S402. In response to a filing request, determine that the data security processing service interface is the filing interface.

[0095] The archiver logs in to the software system. The software system authenticates the identity information of the logged-in user through the third-party authentication system and obtains the authentication token generated by the third-party authentication system to confirm that the identity of the archiver is legal. The archiver opens the filing interface. In response to the filing request, the software system determines that the data security processing service interface is the filing interface.

[0096] S403. The third-party authentication system queries and obtains the corresponding first ciphertext and first private key based on the filing request.

[0097] The software system sends the archiving request and the authentication token to the third-party authentication system through the archiving interface. The third-party authentication system verifies the authentication token. After successful verification, based on the received archiving request, it searches for the first ciphertext and the first private key corresponding to the archiving request in the first storage space.

[0098] S404. The third-party authentication system decrypts the first ciphertext using the first private key and encrypts it again using the second public key in the second key pair to obtain the second ciphertext.

[0099] Among them, the second key pair is preset by the highest-authority administrator and stored in the third-party authentication system. The second private key is only owned by the system's highest-authority administrator.

[0100] S405. The third-party authentication system stores the second ciphertext.

[0101] The third-party authentication system saves the second ciphertext generated after encryption with the second key to the corresponding first storage space in the third-party authentication system.

[0102] In addition, the third-party authentication system symmetrically encrypts the data obtained by decrypting the first ciphertext based on the Secure File Transfer Protocol (SFTP) password pre-configured and saved in the first storage space, and generates an SFTP encrypted file for storage in the second storage space of the third-party authentication system. Specifically, this second storage space is used to save file-type data, such as PDF contract files, for relevant personnel to download when needed.

[0103] Figure 5 This is the flowchart of the identity signature encryption and decryption method based on privacy protection provided by the embodiments of the present disclosure. This method can be applied to the contract management scenario. As Figure 5 shown, the specific steps included in this method are as follows:

[0104] S501. In response to the login operation, the software system authenticates the identity information of the logged-in user through the third-party authentication system and obtains the authentication token generated by the third-party authentication system.

[0105] S502. In response to the contract management request, it is determined that the data security processing service interface is the query interface.

[0106] Among them, the contract management request includes contract information and the second private key in the second key pair.

[0107] The highest-privilege administrator logs in to the software system. The software system authenticates the identity information of the logged-in user through a third-party authentication system and obtains the authentication token generated by the third-party authentication system to confirm the legal identity of the highest-privilege administrator. The highest-privilege administrator opens the menu in the software system, inputs the second private key, and initiates a contract management request. In response to the contract management request, the software system determines that the data security processing service interface is a query interface.

[0108] S503. The software system uses the authentication token and contract information as call parameters to call the query interface.

[0109] S504. The third-party authentication system queries the corresponding second ciphertext based on the contract information.

[0110] S505. The third-party authentication system sends the second ciphertext to the software system.

[0111] The software system sends the authentication token and contract information to the third-party authentication system through the query interface. After receiving the authentication token and contract information and passing the verification of the authentication token, the third-party authentication system queries the second ciphertext corresponding to the contract information in the first storage space of the third-party authentication system and sends it to the software system.

[0112] S506. The software system decrypts the second ciphertext using the second private key to obtain the contract plaintext data.

[0113] S507. The software system displays the contract plaintext data on the contract page.

[0114] The software system decrypts the second ciphertext using the second private key input by the highest-privilege administrator to obtain the contract plaintext data and displays the contract plaintext on the contract page.

[0115] In addition, if it is necessary to download the contract file, a user who holds the SFTP password (such as the highest-privilege administrator) initiates a download request through the software system after obtaining the authentication token through identity verification. The download request includes at least the SFTP password and the authentication token. After receiving the download request initiated by the user, the software system encrypts the SFTP password therein using the Message Digest Algorithm (MD5) and then sends the download request carrying the encrypted SFTP password to the third-party authentication system by calling the encryption material export interface. After verifying and passing the authentication token, the third-party authentication system decrypts the encrypted SFTP password based on MD5, obtains the corresponding SFTP encrypted file from the second storage space, decrypts it using the SFTP password, and sends the decrypted plaintext file to the software system for display to the user.

[0116] In the above - disclosed embodiments, by generating a second key pair, encrypting data using the first public key therein and then storing it, and only designated personnel have the second private key, not only the system users are isolated, but also the system developers and technical personnel are isolated, further improving the security of confidential data.

[0117] In addition, since the identity - signature encryption and decryption method based on privacy protection provided by the present disclosure provides encryption and decryption interface services in aspects such as data transmission, data storage, and file storage, and the interface services can be independently deployed, encrypted data and encrypted files can be stored separately, thus achieving isolation of comprehensive encrypted content in aspects such as storage space, code, and files, effectively ensuring that the encrypted content is not leaked.

[0118] In some embodiments, if it is necessary to update the second key pair, the highest - authority administrator logs in to the software system, obtains an authentication token through the identity authentication of the third - party authentication system, and then initiates a key update application in the software system to generate an updated second key pair and a second private key. The updated second key pair includes an updated second public key and an updated second private key. The second private key is sent to the highest - authority administrator by means of email, etc. The software system determines that the data security processing service interface is the key update interface based on the key update application, and sends the second private key and the updated second public key to the third - party authentication system by calling the key update interface. The third - party authentication system decrypts all the second ciphertexts according to the second private key, encrypts them again using the updated second public key and saves them, completing the update of the second key pair.

[0119] In some embodiments, if it is necessary to update the SFTP password, the highest - authority administrator logs in to the software system, obtains an authentication token through the identity authentication of the third - party authentication system, and then initiates a password update application in the software system to set a new SFTP password. The software system determines that the data security processing service interface is the password update interface based on the password update application, and sends the updated SFTP password to the third - party authentication system by calling the password update interface. The third - party authentication system decrypts all the SFTP - encrypted files according to the SFTP password, encrypts them again using the updated SFTP password and saves them, and at the same time modifies the SFTP password configured in the third - party authentication system to the updated SFTP password, completing the update of the SFTP password.

[0120] Figure 6 and Figure 7 are the signaling diagrams of the identity - signature encryption and decryption method based on privacy protection provided by the embodiments of the present disclosure. Specifically, Figure 6 and Figure 7 The methods shown are consistent with the implementation processes and principles of the above - mentioned method embodiments, and will not be elaborated here.

[0121] Figure 8 The structural schematic diagram of the identity signature encryption and decryption device based on privacy protection provided by the embodiments of the present disclosure. The identity signature encryption and decryption device based on privacy protection provided by the embodiments of the present disclosure can execute the processing flow provided by the embodiments of the identity signature encryption and decryption method based on privacy protection, such as Figure 8 As shown, the identity signature encryption and decryption device 800 based on privacy protection includes: an acquisition module 810, a determination module 820, and a processing module 830; wherein, the acquisition module 810 is configured to, in response to a login operation, the software system authenticates the identity information of the logged-in user through a third-party authentication system and acquires an authentication token generated by the third-party authentication system; the determination module 820 is configured to, in response to a data processing request, the software system determines a data security processing service interface corresponding to the request type based on the request type of the data processing request; the processing module 830 is configured to the software system uses the authentication token as a call parameter to call the data security processing service interface, so that after the third-party authentication system verifies the authentication token, it cooperates with the software system to perform data security processing.

[0122] In some embodiments, the data processing request is a new data request, the data security processing service interface is a new interface, and the determination module 820 is further configured to the software system generates a first key pair, the first key pair includes a first public key and a first private key; the software system encrypts the new data using the first public key to generate a first ciphertext; the processing module 830 is further configured to the software system uses the authentication token, the first ciphertext, and the first private key as call parameters to call the new interface.

[0123] In some embodiments, the processing module 830 is further configured to after the third-party authentication system verifies the authentication token, store the first ciphertext and the first private key.

[0124] In some embodiments, the data processing request is an approval request, and the data information to be approved is carried in the approval request; the data security processing service interface is a modification interface; the processing module 830 is further configured to the software system uses the authentication token and the data information to be approved as call parameters to call the modification interface.

[0125] In some embodiments, the processing module 830 is further configured to after the third-party authentication system verifies the authentication token, query the corresponding first ciphertext and first private key based on the data information to be approved; the third-party authentication system sends the queried first ciphertext and first private key to the software system; the software system decrypts the received first ciphertext based on the received first private key and displays the decrypted data on the approval page.

[0126] In some embodiments, the data processing request is an archiving request, and the data security processing service interface is an archiving interface; the processing module 830 is further configured to enable the third-party authentication system to query and obtain a corresponding first ciphertext and a first private key based on the archiving request; the third-party authentication system decrypts the first ciphertext using the first private key and encrypts it again using the second public key in the second key pair to obtain a second ciphertext; the third-party authentication system stores the second ciphertext.

[0127] In some embodiments, the data processing request is a contract management request, the contract management request includes contract information and the second private key in the second key pair, and the data security processing service interface is a query interface; the processing module 830 is further configured to enable the software system to use the authentication token and the contract information as call parameters to call the query interface.

[0128] In some implementations, the processing module 830 is further configured to enable the third-party authentication system to query a corresponding second ciphertext based on the contract information; the third-party authentication system sends the second ciphertext to the software system; the software system decrypts the second ciphertext using the second private key to obtain contract plaintext data; the software system displays the contract plaintext data on a contract page.

[0129] Figure 8 The privacy protection-based identity signature encryption and decryption device in the illustrated embodiments can be used to execute the technical solutions of the above method embodiments, and its implementation principle and technical effects are similar, which will not be elaborated here.

[0130] Figure 9 It is a schematic structural diagram of an electronic device provided by an embodiment of the present disclosure. The electronic device provided by the embodiment of the present disclosure can execute the processing flow provided by the privacy protection-based identity signature encryption and decryption method embodiment, as Figure 9 shown, the electronic device 90 includes: a memory 91, a processor 92, a computer program, and a communication interface 93; wherein, the computer program is stored in the memory 91 and is configured to be executed by the processor 92 to perform the privacy protection-based identity signature encryption and decryption method as described above.

[0131] The memory 91, as a non-transitory computer-readable storage medium, can be used to store software programs, computer-executable programs, and modules, such as program instructions / modules corresponding to the privacy protection-based identity signature encryption and decryption method of the application program in the embodiment of the present disclosure (for example, attached Figure 8The acquisition module 810, determination module 820, and processing module 830 shown). The processor 92 executes various functional applications and data processing of the server by running software programs, instructions, and modules stored in the memory 91, that is, implements the privacy protection-based identity signature encryption and decryption method of the above method embodiment.

[0132] The memory 91 may include a program storage area and a data storage area. Among them, the program storage area may store an operating system and application programs required for at least one function; the data storage area may store data created according to the use of the electronic device, etc. In addition, the memory 91 may include a high-speed random access memory, and may also include a non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state storage devices. In some embodiments, the memory 91 may optionally include a memory remotely provided with respect to the processor 92, and these remote memories may be connected to the terminal device through a network. Examples of the above network include but are not limited to the Internet, enterprise intranet, local area network, mobile communication network, and combinations thereof.

[0133] In addition, an embodiment of the present disclosure also provides a computer-readable storage medium, on which a computer program is stored, and the computer program is executed by a processor to implement the privacy protection-based identity signature encryption and decryption method described in the above embodiment.

[0134] In addition, an embodiment of the present disclosure also provides a computer program product, which includes a computer program or instruction, and when the computer program or instruction is executed by a processor, it implements the privacy protection-based identity signature encryption and decryption method as described above.

[0135] It should be noted that in this article, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variation thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article or device including the element.

[0136] The above are only specific embodiments of the present disclosure, enabling those skilled in the art to understand or implement the present disclosure. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present disclosure. Therefore, the present disclosure will not be limited to these embodiments described herein, but rather to the broadest scope consistent with the principles and novel features disclosed herein.

Claims

1. A method for encrypting and decrypting identity signatures based on privacy protection, characterized in that, Applied to a software system, the method includes: In response to a login operation, the software system authenticates the identity information of the logged-in user through a third-party authentication system and obtains an authentication token generated by the third-party authentication system; In response to a data processing request, the software system determines a data security processing service interface corresponding to the request type based on the request type of the data processing request; The software system calls the data security processing service interface with the authentication token as a call parameter, so that after the third-party authentication system verifies the authentication token, it cooperates with the software system to perform data security processing; Wherein, the data processing request is a new data request, and the data security processing service interface is a new interface; Before the software system calls the data security processing service interface with the authentication token as a call parameter, the method further includes: the software system generates a first key pair, which includes a first public key and a first private key; the software system encrypts the new data with the first public key to generate a first ciphertext; The software system calling the data security processing service interface with the authentication token as a call parameter includes: the software system calls the new interface with the authentication token, the first ciphertext, and the first private key as call parameters.

2. The method according to claim 1, characterized in that, After the third-party authentication system verifies the authentication token, cooperating with the software system to perform data security processing includes: After the third-party authentication system verifies the authentication token, it stores the first ciphertext and the first private key.

3. The method according to claim 2, wherein The data processing request is an approval request, and the approval request carries data information to be approved; The data security processing service interface is a modification interface; The software system calling the data security processing service interface with the authentication token as a call parameter includes: The software system calls the modification interface with the authentication token and the data information to be approved as call parameters.

4. The method according to claim 3, wherein After the third-party authentication system verifies the authentication token, cooperating with the software system to perform data security processing includes: After the third-party authentication system verifies the authentication token, it queries the corresponding first ciphertext and first private key based on the data information to be approved; The third-party authentication system sends the queried first ciphertext and first private key to the software system; The software system decrypts the received first ciphertext based on the received first private key and displays the decrypted data on the approval page.

5. The method according to claim 1, characterized in that, The data processing request is an archiving request, and the data security processing service interface is an archiving interface; After the third-party authentication system verifies the authentication token, cooperating with the software system to perform data security processing includes: The third-party authentication system queries and obtains the corresponding first ciphertext and first private key based on the archiving request; The third-party authentication system decrypts the first ciphertext with the first private key and encrypts it again with the second public key in the second key pair to obtain a second ciphertext; The third-party authentication system stores the second ciphertext.

6. The method according to claim 5, characterized in that, The data processing request is a contract management request, and the contract management request includes contract information and the second private key in the second key pair. The data security processing service interface is a query interface; The software system calling the data security processing service interface with the authentication token as a call parameter includes: the software system calling the query interface with the authentication token and the contract information as call parameters.

7. The method according to claim 6, wherein After the third-party authentication system verifies the authentication token, cooperating with the software system for data security processing includes: The third-party authentication system queries the corresponding second ciphertext based on the contract information; The third-party authentication system sends the second ciphertext to the software system; The software system decrypts the second ciphertext using the second private key to obtain contract plaintext data; The software system displays the contract plaintext data on the contract page.

8. An identity signature encryption and decryption device based on privacy protection, characterized in that, The device includes: An acquisition module, configured to, in response to a login operation, the software system authenticates the identity information of the logged-in user through a third-party authentication system and obtains an authentication token generated by the third-party authentication system; A determination module, configured to, in response to a data processing request, the software system determines a data security processing service interface corresponding to the request type based on the request type of the data processing request; A processing module, configured to the software system call the data security processing service interface with the authentication token as a call parameter, so that after the third-party authentication system verifies the authentication token, it cooperates with the software system for data security processing; Wherein, the data processing request is a new data request, the data security processing service interface is a new interface, the determination module is further configured for the software system to generate a first key pair, the first key pair includes a first public key and a first private key, and the software system encrypts the new data using the first public key to generate a first ciphertext; the processing module is further configured for the software system to call the new interface with the authentication token, the first ciphertext and the first private key as call parameters.

9. An electronic device, characterized in that, The electronic device includes: A memory; A processor; and A computer program; Wherein, the computer program is stored in the memory and is configured to be executed by the processor to implement the method according to any one of claims 1-7.

Citation Information

Patent Citations

  • Application authentication method and device and electronic equipment

    CN114745125A