Method and system for quickly dynamically encrypting and decrypting application program request data
The described method and system enhance data security and reduce response times by tracing data paths, encrypting personal data, and using neural networks to manage secure data transmission in application programs.
Patent Information
- Application Number
- CN202211068543.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-01
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2042-09-01
AI Technical Summary
The prior art is difficult to efficiently encrypt and decrypt personal data in applications, resulting in insufficient security and long response time, affecting the user experience.
The IAST tool is used to insert the target application to mark personal data-related requests through marking features, and dynamically encrypt and decrypt during storage and query. The data in the database is processed using encryption keys and decryption keys, and filtered in combination with neural network algorithms.
It realizes efficient encryption and decryption of personal data, improves the security and response speed of data dissemination, and improves user query experience.
Smart Images

Figure CN115455465B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of application program privacy data security protection, and in particular to a method and system for quickly and dynamically encrypting and decrypting application program request data. Background Art
[0002] With the gradual development of the network process, there are more and more application programs, and a lot of personal data is also constantly spread among application programs, which also prompts people to pay more attention to the protection of personal data. In this regard, more and more applications are now beginning to adopt various security reinforcement measures for personal data, including standardized storage, restricted dissemination, storage encryption, etc. However, for many application programs, it has become very difficult to find the previous developers to modify the relevant business logic under the continuous replacement and iteration of developers. In this way, due to the lack of understanding of the business logic of application programs and security knowledge, it is difficult to strengthen the security of application programs.
[0003] To solve this problem, the industry generally uses IAST technology to encrypt and store the request data related to the marked personal data at present. However, if the subsequent request queries and returns personal data to the page display, the data is still encrypted, thus affecting business use.
[0004] In addition, for some request encryption and decryption systems with decryption functions, after obtaining the returned data of the request, it is necessary to traverse each character in the returned data to determine whether the current returned data is encrypted data. In this way, when batch checking data, the request data is relatively complex and the character volume of the returned data is large. Therefore, the traversal takes a long time, which will seriously affect the response time of the request data. Summary of the Invention
[0005] The purpose of the present invention is to provide a method and system for quickly and dynamically encrypting and decrypting application program request data, which can encrypt the data stored by users in the application program database, automatically decrypt the encrypted data retrieved by users from the database, and effectively reduce the response time of the request data.
[0006] To achieve the above purpose, the invention discloses a method for quickly and dynamically encrypting and decrypting application program request data, which includes:
[0007] Using an IAST tool to instrument the target application program to track the propagation path of requests entering the application program;
[0008] Using a first marking feature to mark the request uri related to personal data in the application program, where the request uri represents the type of the request;
[0009] Determine whether there is a request URI with the first marking feature in the requests from the user entering the application. If so, mark the request data representing the request content in this request with the second marking feature;
[0010] Determine whether the parameter data of the data propagation function input to the current application carries the second marking feature. If so, mark the return data of this data propagation function with the third marking feature;
[0011] When the SQL statement executed by the current database function is an insert statement, encrypt and store the data with the third marking feature that is currently to be stored in the database using the encryption key. At the same time, record the storage address of the encrypted data in the database to obtain a feature record table;
[0012] When the SQL statement executed by the current database function is a query statement, obtain the return data of the current request and the storage address of this return data;
[0013] Query the feature record table to determine whether the storage address of the current return data is in the feature record table. If so, decrypt this return data using the decryption key.
[0014] Preferably, the request data with the second marking feature is also screened according to a preset rule. When the request data meets the preset rule, the second marking feature on this request data is removed.
[0015] Preferably, the request data with the second marking feature is also screened again through a learning algorithm based on a neural network.
[0016] The present invention also discloses a system for quickly and dynamically encrypting and decrypting application program request data, which includes:
[0017] An instrumentation module, which is used to instrument the target application program through the IAST tool to track the propagation path of the requests entering the application program;
[0018] A first marking module, which marks the request URIs related to personal data in the application program with the first marking feature, and the request URIs represent the types of requests;
[0019] A second marking module, which is used to mark the request data representing the request content in the request when the request URI in the request from the user carries the first marking feature;
[0020] A third marking module, which is used to mark the return data of the data propagation function with the third marking feature when the parameter data of the data propagation function of the current application program carries the second marking feature;
[0021] An encryption module, which is used to encrypt and store the data with the third marker feature to be stored in the database currently by using an encryption key when the SQL statement executed by the current database function is an insert statement;
[0022] A recording module, which is used to record the storage address of the encrypted data in the database to obtain a feature record table;
[0023] A query module, which is used to query whether there is a storage address corresponding to the return data requested currently in the feature record table when the SQL statement executed by the current database function is a query statement;
[0024] A decryption module, which is used to decrypt the return data requested currently by using a decryption key according to the return value of the query module when the SQL statement executed by the current database function is a query statement.
[0025] Preferably, it further includes a first screening module, and the first screening module is used to screen the request data with the second marker feature according to a preset rule.
[0026] Preferably, it further includes a second screening module, and the second screening module re-screens the request data with the second marker feature through a learning algorithm based on a neural network.
[0027] The present invention also discloses another system for dynamically encrypting and decrypting application program request data, which includes:
[0028] One or more processors;
[0029] A memory;
[0030] And one or more programs, wherein one or more programs are stored in the memory and are configured to be executed by the one or more processors, and the programs include instructions for executing the method for quickly dynamically encrypting and decrypting application program request data as described above.
[0031] The present invention also discloses a computer-readable storage medium, which includes a computer program, and the computer program can be executed by a processor to complete the method for quickly dynamically encrypting and decrypting application program request data as described above.
[0032] Compared with the prior art, the above technical solution of the present invention encrypts the personal privacy data marked by the user and stored in the database of the application program, and automatically decrypts the encrypted data when the user retrieves it from the database, thereby dynamically completing the encryption and decryption of the personal data in the request. Moreover, for the user, there is no perception of use during storage and query. Therefore, not only the security of the personal data during the transmission between application programs is improved, but also it is convenient for the user to query and use, effectively enhancing the use experience. In addition, for the returned data of the request, it is only necessary to query the feature record table to know whether the returned data is encrypted, thereby effectively reducing the response time of the returned data and enhancing the use experience. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] Figure 1 It is a flowchart of the method for dynamically encrypting and decrypting application program request data in an embodiment of the present invention.
[0034] Figure 2 It is a structural diagram of the system for dynamically encrypting and decrypting application program request data in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0035] To describe in detail the technical content, structural features, achieved objectives and effects of the present invention, the following is described in detail in conjunction with the embodiments and with reference to the drawings.
[0036] This embodiment discloses a method for dynamically encrypting and decrypting application program request data to encrypt and store the personal privacy data received by the application program and automatically decrypt and present it when the user queries, thereby ensuring the security of the personal data during the transmission between application programs and facilitating the query and use of the user. Specifically, as Figure 1 , the method includes the following steps:
[0037] S1: Use the IAST tool to instrument the target application program to track the propagation path of the requests entering the application program.
[0038] S2: Use the first marking feature to mark the request uris related to personal data in the application program. The request uri represents the type of the request, such as / user, / project, / app, / rule, where / user is the request uri related to personal data, then use the first marking feature to mark / user.
[0039] S3: Determine whether there is a request uri with the first marking feature in the requests from the user entering the application program. If so, enter S4; if not, directly skip.
[0040] S4: Mark the request data representing the request content in the request with the second marking feature. For example, by instrumenting the request parsing function, the request uri in the current request is obtained as / user, and the request data is {"email": "zhangsan@qq.com", "age": "33", "card": "342415667412092743", "time": "2022-07-03", "group": "test", "id": "1", "name": "zhangsan"}. Since the request uri " / user" has the first marking feature, the second marking feature is used to mark the request data.
[0041] S5: Determine whether the parameter data of the data propagation function of the current application has the second marking feature when input. If so, go to the following step S6; if not, skip directly. In addition, it should be noted that the process of the application handling requests (i.e., the request propagation process) is roughly divided into four stages, and the requests are processed by the key functions of these four stages. These four stages are the input stage, the propagation stage, the encryption / decryption stage, and the output stage. The data propagation function in this embodiment is the key function of the propagation stage of the application.
[0042] S6: Track the data propagation function and mark the return data of the data propagation function with the third marking feature.
[0043] S7: When the database function is called, determine whether the sql statement executed by the current database function is an insert statement or a query statement. If it is an insert statement, go to S8; if it is a query statement, go to S9.
[0044] S8: Analyze the SQL statement, extract information such as data tables, fields, field values, etc. The extraction format is such as {"tableName": "users", "fields": [{"name": "email", "value": "zhangsan@qq.com"}, {"name": "age", "value": "33"}, {"name": "card", "value": "342415667412092743"}, {"name": "time", "value": "2022-07-03"}, {"name": "group", "value": "test"}, {"name": "id", "value": "1"}, {"name": "name", "value": "zhangsan"}]}. Then, use the encryption key to encrypt and store the data with the third marker feature that is currently to be stored in the database. For example, encrypt "zhangsan@qq.com" to become "xxxxxx"; encrypt "33" to become "yyyyyy"; encrypt "342415667412092743" to become "zzzzzz"; encrypt "zhangsan" to become "tttttt". In addition, after completing the encryption of the request data, also record the storage address (including table name and field name) of the encrypted data in the database to obtain the feature record table.
[0045] S9: Use the IAST tool to obtain the return data of the current request and the storage address of this return data.
[0046] S10: Query the feature record table to determine whether the storage address of the current return data is in the feature record table. If so, enter S11; if not, directly display the return data.
[0047] S11: Use the decryption key to decrypt the return data, and then display the decrypted return data.
[0048] It should be noted that in the above embodiments, the first marker feature, the second marker feature, and the third marker feature can be the same marker, or different markers.
[0049] Further, in the above step S4, the request data with the second marking feature can also be screened according to a preset rule. When the request data meets the preset rule, the second marking feature on the request data is removed. Specifically, in this embodiment, the preset rule includes a blacklist and / or a whitelist, and preset field names or regular expressions are set in the blacklist and the whitelist to match the request data. For example, if there is a rule with a known field name "id" in the blacklist, then the data "id": "1" in step 4 can be marked and cleaned, that is, the second marking feature on it is removed and no longer tracked subsequently.
[0050] Furthermore, a learning algorithm based on a neural network can also be used to further screen the request data with the second marking feature to intelligently screen personal private data with high accuracy.
[0051] According to the method for dynamically encrypting and decrypting application program request data disclosed in the above embodiment, the personal privacy data marked in the database of the application program stored by the user is encrypted, and when the user retrieves it from the database, the data in the encrypted state is automatically decrypted, so as to dynamically complete the encryption and decryption of personal data in the request. Moreover, for the user, there is no perception of use during storage and query. Thus, not only the security of personal data transmission between application programs is improved, but also it is convenient for the user to query and use, effectively improving the use experience.
[0052] In addition, for the returned data of the request, it is only necessary to query the feature record table to know whether the returned data is encrypted, without traversing each character in the returned data, thus effectively reducing the response time of the returned data and improving the use experience.
[0053] Furthermore, after the request data enters the propagation stage, the form of the request data will change through the execution of the propagation function. Therefore, if the returned data of the propagation function is not marked, after finally parsing the request data to be stored from the sql statement, it is still necessary to judge whether the current data has a mark by traversing. Therefore, the IAST tool is used to track the propagation function of the application program and mark the returned data of the propagation function. For the following code executed by the request, the insertUserStringBuilder object and the sql object are marked with the third marking feature.
[0054]
[0055]
[0056]
[0057] As a result, the personal privacy data waiting to enter the database directly carries marked features, so that it is possible to know whether the data waiting to be stored currently is the data that needs to be encrypted and stored without performing a traversal query operation, thus avoiding the slowdown of the running speed of the application program due to the traversal query in the encryption process.
[0058] In another preferred embodiment of the present invention, as Figure 2 , a system for dynamically encrypting and decrypting application program request data is also disclosed, which includes a stubbing module 10, a first marking module 11, a second marking module 12, a third marking module 13, an encryption module 14, a recording module 15, a query module 16, and a decryption module 17.
[0059] The stubbing module 10 is used to stub the target application program through the IAST tool to track the propagation path of the requests entering the application program.
[0060] The first marking module 11 marks the request uri related to personal data in the application program with the first marking feature, and the request uri represents the type of the request.
[0061] The second marking module 12 is used to mark the request data representing the request content in the request when the request uri in the request from the user carries the first marking feature.
[0062] The third marking module 13 is used to mark the return data of the data propagation function with the third marking feature when the parameter data of the data propagation function of the current application program carries the second marking feature.
[0063] The encryption module 14 is used to encrypt and store the data with the third marking feature to be stored in the database currently with the encryption key when the sql statement executed by the current database function is an insert statement.
[0064] The recording module 15 is used to record the storage address of the encrypted data in the database to obtain a feature record table.
[0065] The query module 16 is used to query whether there is a storage address corresponding to the return data of the current request in the feature record table when the sql statement executed by the current database function is a query statement.
[0066] The decryption module 17 is used to decrypt the return data of the current request with the decryption key according to the return value of the query module 16 when the sql statement executed by the current database function is a query statement.
[0067] Furthermore, the above system further includes a first screening module 18 and a second screening module 19. The first screening module 18 is configured to screen the request data with the second marked feature according to a preset rule. The second screening module 19 further screens the request data with the second marked feature through a learning algorithm based on a neural network.
[0068] It should be noted that for the working principle and working mode of the system for dynamically encrypting and decrypting application program request data in this embodiment, please refer to the above method for dynamically encrypting and decrypting application program request data, which will not be elaborated here.
[0069] The present invention also discloses another system for dynamically encrypting and decrypting application program request data, which includes one or more processors, a memory, and one or more programs, where one or more programs are stored in the memory and configured to be executed by the one or more processors. The programs include instructions for executing the method for dynamically encrypting and decrypting application program request data as described above. The processor may adopt a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the functions required to be executed by the modules in the system for dynamically encrypting and decrypting application program request data in the embodiments of the present application, or to execute the method for dynamically encrypting and decrypting application program request data in the method embodiments of the present application.
[0070] The present invention also discloses a computer-readable storage medium, which includes a computer program that can be executed by a processor to complete the method for dynamically encrypting and decrypting application program request data as described above. The computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or a data center integrating one or more available media. The available medium may be a read-only memory (ROM), a random access memory (RAM), a magnetic medium, such as a floppy disk, a hard disk, a magnetic tape, a magnetic disk, or an optical medium, such as a digital versatile disc (DVD), or a semiconductor medium, such as a solid state disk (SSD), etc.
[0071] The embodiments of the present application also disclose a computer program product or a computer program. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. A processor of an electronic device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the electronic device executes the method for dynamically encrypting and decrypting application program request data described above.
[0072] The foregoing disclosure is only the preferred embodiment of the present invention, and of course cannot be used to limit the scope of rights of the present invention. Therefore, equivalent changes made according to the scope of the patent application of the present invention still fall within the scope covered by the present invention.
Claims
1. A method for quickly dynamically encrypting and decrypting application program request data, characterized in that, Including: Using an IAST tool to instrument the target application to trace the propagation path of requests entering the application; Using a first marking feature to mark the request URIs related to personal data in the application, where the request URIs represent the types of requests; Determining whether there is a request URI with the first marking feature in the requests from the user entering the application. If so, using a second marking feature to mark the request data representing the request content in the request; Determining whether the parameter data of the data propagation function of the current application carries the second marking feature. If so, using a third marking feature to mark the return data of the data propagation function; When the SQL statement executed by the current database function is an insert statement, using an encryption key to encrypt and store the data with the third marking feature to be currently stored in the database, and at the same time, recording the storage address of the encrypted data in the database to obtain a feature record table; When the SQL statement executed by the current database function is a query statement, obtaining the return data of the current request and the storage address of the return data; Querying the feature record table to determine whether the storage address of the current return data is in the feature record table. If so, decrypting the return data using a decryption key; 2. The method for quickly and dynamically encrypting and decrypting application program request data according to claim 1, wherein, Also screening the request data with the second marking feature according to a preset rule, and removing the second marking feature from the request data when the request data meets the preset rule; 3. The method for quickly and dynamically encrypting and decrypting application program request data according to claim 2, wherein Also performing secondary screening on the request data with the second marking feature through a learning algorithm based on a neural network; 4. A system for quickly dynamically encrypting and decrypting application program request data, characterized in that, Including: An instrumentation module for instrumenting the target application through an IAST tool to trace the propagation path of requests entering the application; A first marking module that uses a first marking feature to mark the request URIs related to personal data in the application, where the request URIs represent the types of requests; A second marking module for, when the request URI in the request from the user carries the first marking feature, using a second marking feature to mark the request data representing the request content in the request; A third marking module for, when the parameter data of the data propagation function of the current application carries the second marking feature, using a third marking feature to mark the return data of the data propagation function; An encryption module for, when the SQL statement executed by the current database function is an insert statement, using an encryption key to encrypt and store the data with the third marking feature to be currently stored in the database; A recording module for recording the storage address of the encrypted data in the database to obtain a feature record table; A query module for, when the SQL statement executed by the current database function is a query statement, querying whether there is a storage address corresponding to the return data of the current request in the feature record table; A decryption module for, when the SQL statement executed by the current database function is a query statement, decrypting the return data of the current request using a decryption key according to the return value of the query module; 5. The system for quickly and dynamically encrypting and decrypting application program request data according to claim 4, characterized in that, It further includes a first screening module, which is used to screen the request data with the second marked feature according to a preset rule.
6. The system for quickly and dynamically encrypting and decrypting application program request data according to claim 5, wherein, It further includes a second screening module, which re-screens the request data with the second marked feature through a learning algorithm based on a neural network.
7. A system for dynamically encrypting and decrypting application program request data, characterized in that, It includes: One or more processors; A memory; And one or more programs, wherein the one or more programs are stored in the memory and are configured to be executed by the one or more processors, and the programs include instructions for executing the method for quickly dynamically encrypting and decrypting application program request data as described in any one of claims 1 to 3.
8. A computer-readable storage medium, characterized in that, It includes a computer program, which can be executed by a processor to complete the method for quickly dynamically encrypting and decrypting application program request data as described in any one of claims 1 to 3.
Citation Information
Patent Citations
Method and system for dynamically detecting level unauthorized based on IAST test tool
CN110688659A
Web application test data flow tracking method and system
CN111046396A