Method and System for Dynamically Encrypting and Decrypting Application Request Data Based on IAST Tool
The IAST tool dynamically encrypts and decrypts personal data within application programs, addressing security challenges and enhancing user experience by eliminating traversal queries, thereby improving data transmission speed and security.
Patent Information
- Application Number
- CN202211070169.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-01
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2042-09-01
AI Technical Summary
After the developer replaces or iterates, it is difficult for existing applications to lack the understanding of business logic and security knowledge, which leads to difficulty in security reinforcement and affects business speed when querying encrypted stored personal data.
The IAST tool instrumentation application is adopted to mark personal data request uri and data propagation functions through marking features, encrypt and store data and decrypt query data, and use neural networks to perform intelligent screening to avoid traversing queries.
While safely disseminating personal data between applications, it improves query speed and user experience, and avoids slowing down the application's running speed due to the encryption process.
Smart Images

Figure CN115455467B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of application program privacy data security protection, and particularly to a method and system for dynamically encrypting and decrypting application program request data based on an IAST tool. Background Art
[0002] With the gradual development of the network process, there are more and more application programs, and a lot of personal data is also continuously transmitted among application programs, which also makes people pay more attention to the protection of personal data. In this regard, more and more applications now also start to carry out various security reinforcement measures for personal data, including standardized storage, restricted transmission, storage encryption, etc. However, for many application programs, it has become very difficult to find the previous developers to modify the relevant business logic under the continuous replacement and iteration of developers. In this way, due to the lack of understanding of the business logic of the application program and security knowledge, it is difficult to strengthen the security of the application program. To solve this problem, the industry generally uses IAST technology to encrypt and store the request data related to the marked personal data at present. However, when the subsequent request queries and returns personal data to the page display, it is still encrypted data, thus affecting business use. In addition, when encrypting and storing personal data, it is also necessary to judge whether the current data is marked personal data by means of traversal query, thus slowing down the speed of the application program. Summary of the Invention
[0003] The object of the present invention is to provide a method and system for dynamically encrypting and decrypting application program request data based on an IAST tool, which encrypts the data stored by a user in an application program database and automatically decrypts the encrypted data retrieved by the user from the database.
[0004] To achieve the above object, the present invention discloses a method for dynamically encrypting and decrypting application program request data based on an IAST tool, which includes:
[0005] Using the IAST tool to instrument the target application program to track the propagation path of requests entering the application program;
[0006] Using a first marking feature to mark the request uri related to personal data in the application program, where the request uri represents the type of the request;
[0007] Judging whether there is a request uri with the first marking feature in the request from the user entering the application program. If so, using a second marking feature to mark the request data representing the request content in the request;
[0008] Judging whether the parameter data input into the data propagation function of the current application program has the second marking feature. If so, using a third marking feature to mark the return data of the data propagation function;
[0009] When the SQL statement executed by the current database function is an insert statement, the data with the third marker feature to be stored in the database currently is encrypted using an encryption key and stored, and an encryption feature is added to the encrypted data.
[0010] When the SQL statement executed by the current database function is a query statement, traverse the return data of the current request to determine whether the return data has an encryption feature. If so, decrypt the return data using a decryption key.
[0011] Preferably, the request data with the second marker feature is also screened according to a preset rule. When the request data meets the preset rule, the second marker feature on the request data is removed.
[0012] Preferably, the request data with the second marker feature is also screened again through a learning algorithm based on a neural network.
[0013] The present invention also discloses a system for dynamically encrypting and decrypting application program request data based on an IAST tool, which includes:
[0014] An instrumentation module, which is used to instrument a target application program through an IAST tool to track the propagation path of requests entering the application program;
[0015] A first marking module, which marks the request uri related to personal data in the application program with a first marking feature, and the request uri represents the type of the request;
[0016] A second marking module, which is used to mark the request data representing the request content in the request when the request uri in the request from the user has the first marking feature;
[0017] A third marking module, which is used to mark the return data of the data propagation function with a third marking feature when the parameter data of the data propagation function of the current application program has the second marking feature;
[0018] An encryption module, which is used to encrypt and store the data with the third marking feature to be stored in the database currently using an encryption key when the SQL statement executed by the current database function is an insert statement;
[0019] A feature adding module, which is used to add an encryption feature to the encrypted data;
[0020] A traversing module, which is used to traverse the return data of the current request to determine whether the return data has an encryption feature when the SQL statement executed by the current database function is a query statement;
[0021] A decryption module, which is used to decrypt the returned data with the encryption feature of the current request by using a decryption key according to the return value of the traversal module when the SQL statement executed by the current database function is a query statement.
[0022] Preferably, it further includes a first screening module, which is used to screen the request data with the second marking feature according to a preset rule.
[0023] Preferably, it further includes a second screening module, which re-screens the request data with the second marking feature through a learning algorithm based on a neural network.
[0024] The present invention also discloses another system for dynamically encrypting and decrypting application program request data, which includes:
[0025] One or more processors;
[0026] A memory;
[0027] And one or more programs, wherein one or more programs are stored in the memory and are configured to be executed by the one or more processors, and the programs include instructions for executing the method for dynamically encrypting and decrypting application program request data as described above.
[0028] The present invention also discloses a computer-readable storage medium, which includes a computer program, and the computer program can be executed by a processor to complete the method for dynamically encrypting and decrypting application program request data as described above.
[0029] Compared with the prior art, the above technical solution of the present invention encrypts the data marked as personal privacy data stored by the user in the database of the application program, and automatically decrypts the data in the encrypted state when the user retrieves it from the database, so as to dynamically complete the encryption and decryption of personal data in the request. Moreover, for the user, there is no perception during storage and query. Thus, not only the security of personal data transmission between application programs is improved, but also it is convenient for the user to query and use, effectively improving the usage experience. In addition, since the propagation function of the application program is tracked by the IAST tool and the returned data of the propagation function is marked, the personal privacy data entering the database directly has a marking feature, so that it is possible to know whether the currently stored data is the data that needs to be encrypted and stored without performing a traversal query operation, thus avoiding the slowdown of the application program operation speed caused by the traversal query during the encryption process. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] Figure 1 It is a flowchart of the method for dynamically encrypting and decrypting application program request data in an embodiment of the present invention.
[0031] Figure 2 This is the system structure diagram for the dynamic encryption and decryption of application program request data in the embodiments of the present invention. Specific Embodiments
[0032] To describe in detail the technical content, structural features, achieved objectives and effects of the present invention, the following will be described in detail in conjunction with the embodiments and with reference to the drawings.
[0033] This embodiment discloses a method for dynamically encrypting and decrypting application program request data to encrypt and store the personal privacy data received by the application program and automatically decrypt and present it when the user queries, so as to ensure the security of personal data during transmission between application programs and facilitate the query and use by the user. Specifically, as Figure 1 , the method includes the following steps:
[0034] S1: Use the IAST tool to instrument the target application program to track the propagation path of requests entering the application program.
[0035] S2: Use the first marking feature to mark the request uri related to personal data in the application program. The request uri represents the type of request, such as / user, / project, / app, / rule, where / user is the request uri related to personal data, then use the first marking feature to mark / user.
[0036] S3: Determine whether there is a request uri with the first marking feature in the requests from the user entering the application program. If so, go to S4; if not, skip directly.
[0037] S4: Use the second marking feature to mark the request data representing the request content in the request. For example, by instrumenting the request parsing function, it is obtained that the request uri in the current request is / user, and the request data is {"email": "zhangsan@qq.com", "age": "33", "card": "342415667412092743", "time": "2022-07-03", "group": "test", "id": "1", "name": "zhangsan"}. Since the request uri " / user" has the first marking feature, use the second marking feature to mark the request data.
[0038] S5: Determine whether the parameter data of the data propagation function for the currently input application has the second marking feature. If so, proceed to the following step S6; if not, skip directly. Additionally, it should be noted that the process of the application handling requests (i.e., the request propagation process) is roughly divided into four stages, and the requests are processed through the key functions of these four stages. These four stages are the input stage, the propagation stage, the encryption / decryption stage, and the output stage. The data propagation function in this embodiment is the key function in the propagation stage of the application.
[0039] S6: Trace the data propagation function and mark the return data of the data propagation function with the third marking feature.
[0040] S7: When the database function is called, determine whether the SQL statement executed by the current database function is an insert statement or a query statement. If it is an insert statement, proceed to S8; if it is a query statement, proceed to S9.
[0041] S8: Parse the SQL statement, extract information such as data tables, fields, and field values. The extraction format is like {"tableName": "users", "fields": [{"name": "email", "value": "zhangsan@qq.com"}, {"name": "age", "value": "33"}, {"name": "card", "value": "342415667412092743"}, {"name": "time", "value": "2022-07-03"}, {"name": "group", "value": "test"}, {"name": "id", "value": "1"}, {"name": "name", "value": "zhangsan"}]}. Then, use the encryption key to encrypt and store the data with the third marker feature that is to be stored in the database currently, and add an encryption feature to the encrypted data. For example, encrypt "zhangsan@qq.com" to become "xxxxxx"; encrypt "33" to become "yyyyyy"; encrypt "342415667412092743" to become "zzzzzz"; encrypt "zhangsan" to become "tttttt". Additionally, since the encrypted data and the original data are essentially no different and are both strings, such as the original data being zhangsan and the encrypted data being U2FsdGVkX18GleBPIMp5McnqgMXIo2jybLJhoZQZ8qg, therefore, in order to enable the subsequent decryption program to quickly identify the data object that needs to be decrypted, add an encryption feature to the encrypted data, such as V_AES_00000, so that V_AES_00000_U2FsdGVkX18GleBPIMp5McnqgMXIo2jybLJhoZQZ8qg can be obtained.
[0042] S9: Obtain the return data of the current request through the IAST tool, traverse the return data to determine whether the return data has an encryption feature. If so, enter S10; if not, directly display the return data.
[0043] S10: Decrypt and display the return data using the decryption key.
[0044] It should be noted that in the above embodiments, the first marker feature, the second marker feature, and the third marker feature can be the same marker or different markers.
[0045] Further, in the above step S4, the request data with the second marking feature can also be screened according to a preset rule. When the request data meets the preset rule, the second marking feature on the request data is removed. Specifically, in this embodiment, the preset rule includes a blacklist and / or a whitelist, and preset field names or regular expressions are set in the blacklist and the whitelist to match the request data. For example, if there is a rule with a known field name "id" in the blacklist, then the data "id": "1" in step 4 can be marked and cleaned, that is, the second marking feature on it is removed and no longer tracked later.
[0046] Furthermore, a learning algorithm based on a neural network can be used to screen the request data with the second marking feature again to intelligently screen personal private data with high accuracy.
[0047] According to the method for dynamically encrypting and decrypting application program request data disclosed in the above embodiment, the personal privacy data marked in the database of the application program stored by the user is encrypted, and when the user retrieves it from the database, the data in the encrypted state is automatically decrypted, so as to dynamically complete the encryption and decryption of personal data in the request. Moreover, for the user, there is no perception of use during storage and query. Therefore, not only the security of personal data transmission between application programs is improved, but also it is convenient for the user to query and use, effectively improving the use experience.
[0048] In addition, after the request data enters the propagation stage, the form of the request data will change through the execution of the propagation function. Therefore, if the return data of the propagation function is not marked, after finally parsing the request data to be stored from the sql statement, it is also necessary to judge whether the current data has a mark by traversing. Therefore, the IAST tool is used to track the propagation function of the application program and mark the return data of the propagation function. The following is the code for request execution, and the insertUserStringBuilder object and the sql object are marked with the third marking feature.
[0049] try{
[0050] User user=JSON.toJsonString(request.getBody(),User.class); / / Request data for the request uri ( / user)
[0051] Class.forName("com.mysql.jdbc.Driver"); / / Load the driver
[0052] String url = "jdbc:mysql: / / localhost:3306 / test"; / / Define the connection string. test is the database name
[0053] Connection conn = DriverManager.getConnection(url, "root", "root"); / / Connect to the database
[0054] String baseSql = “insert into users(email,age,card,time,group,id,name)values”;
[0055] String insertUserStringBuilder = new StringBuilder(baseSql);
[0056] insertUserStringBuilder.append(“(“).append(user.getEmail()).append(“,”).append(user.getAge()).append(“,”).append(user.getCard()).append(“,”).append(user.getTime()).append(“,”).append(user.getGroup()).append(“,”).append(user.getId()).append(“,”).append(user.getName()).append(“)”); / / Data propagation function. Here, the insertUserStringBuilder object needs to be marked
[0057] String sql = insertStringBuilder.toString(); / / Data propagation function. Here, the sql object needs to be marked
[0058] PreparedStatement pstmt = conn.prepareStatement(sql); / / Get the prepared object
[0059] int res = pstmt.executeUpdate(); / / Execute the sql statement. The sql statement is insert into users(email,age,card,time,group,id,name)
[0060] values("zhangsan@qq.com", "33", "342415667412092743", "2022-07-03", "test", "1", "zhangsan"); Parse and replace here
[0061] if (res > 0) {
[0062] System.out.println("Data entry successful");
[0063] }
[0064] pstmt.close(); / / Close resources
[0065] conn.close(); / / Close resources
[0066] } catch (Exception e) {
[0067] e.printStackTrace();
[0068] }
[0069] Thus, the personal privacy data waiting to enter the database directly carries a marked feature, so that it is possible to know whether the data waiting to be stored currently is the data that needs to be encrypted and stored without performing a traversal query operation, thereby avoiding the slowdown of the running speed of the application program due to the traversal query in the encryption process.
[0070] In another preferred embodiment of the present invention, as Figure 2 , a system for dynamically encrypting and decrypting application program request data is also disclosed, which includes a stubbing module 10, a first marking module 11, a second marking module 12, a third marking module 13, an encryption module 14, a feature adding module 15, a traversal module 16, and a decryption module 17.
[0071] The stubbing module 10 is used to stub the target application program through the IAST tool to track the propagation path of the requests entering the application program.
[0072] The first marking module 11 marks the request uri related to personal data in the application program with a first marking feature, and the request uri represents the type of the request.
[0073] The second marking module 12 is used to mark the request data representing the request content in the request when the request uri in the request from the user carries the first marking feature.
[0074] A third marking module 13, configured to mark the return data of the data propagation function with a third marking feature when the parameter data of the data propagation function of the current application program has a second marking feature.
[0075] An encryption module 14, configured to encrypt and store the data with a third marking feature to be currently stored in the database with an encryption key when the SQL statement executed by the current database function is an insert statement.
[0076] A feature adding module 15, configured to add an encryption feature to the encrypted data.
[0077] A traversing module 16, configured to traverse the return data of the current request to determine whether the return data has an encryption feature when the SQL statement executed by the current database function is a query statement.
[0078] A decryption module 17, configured to decrypt the return data with an encryption feature of the current request with a decryption key according to the return value of the traversing module when the SQL statement executed by the current database function is a query statement.
[0079] Further, the above system further includes a first screening module 18 and a second screening module 19. The first screening module 18 is configured to screen the request data with a second marking feature according to a preset rule. The second screening module 19 performs a second screening on the request data with a second marking feature through a learning algorithm based on a neural network.
[0080] It should be noted that for the working principle and working mode of the system for dynamically encrypting and decrypting application program request data in this embodiment, please refer to the above method for dynamically encrypting and decrypting application program request data, which will not be elaborated here.
[0081] The present invention also discloses another system for dynamically encrypting and decrypting application program request data, which includes one or more processors, a memory, and one or more programs, wherein one or more programs are stored in the memory and are configured to be executed by the one or more processors. The programs include instructions for executing the method for dynamically encrypting and decrypting application program request data as described above. The processor may employ a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is configured to execute relevant programs to implement the functions required to be executed by the modules in the system for dynamically encrypting and decrypting application program request data in the embodiments of the present application, or to execute the method for dynamically encrypting and decrypting application program request data in the method embodiments of the present application.
[0082] The present invention also discloses a computer-readable storage medium, which includes a computer program that can be executed by a processor to complete the method for dynamically encrypting and decrypting application program request data as described above. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or a data center integrating one or more available media. The available medium can be a read-only memory (ROM), or a random access memory (RAM), or a magnetic medium, such as a floppy disk, a hard disk, a magnetic tape, a magnetic disk, or an optical medium, such as a digital versatile disc (DVD), or a semiconductor medium, such as a solid state disk (SSD), etc.
[0083] The embodiment of the present application also discloses a computer program product or a computer program. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. The processor of the electronic device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the electronic device executes the method for dynamically encrypting and decrypting application program request data as described above.
[0084] The above-disclosed are only the preferred embodiments of the present invention. Of course, the scope of the rights of the present invention cannot be limited thereby. Therefore, equivalent changes made according to the scope of the patent application of the present invention still fall within the scope covered by the present invention.
Claims
1. A method for dynamically encrypting and decrypting application program request data based on an IAST tool, characterized in that Including: Using the IAST tool to instrument the target application to track the propagation path of requests entering the application; Using the first marking feature to mark the request uri related to personal data in the application, where the request uri represents the type of request; Judging whether there is a request uri with the first marking feature in the requests from the user entering the application. If so, using the second marking feature to mark the request data representing the request content in the request; Judging whether the parameter data of the data propagation function input to the current application carries the second marking feature. If so, using the third marking feature to mark the return data of the data propagation function; When the sql statement executed by the current database function is an insert statement, using the encryption key to encrypt and store the data with the third marking feature to be stored in the database currently, and adding an encryption feature to the encrypted data; When the sql statement executed by the current database function is a query statement, traversing the return data of the current request to judge whether the return data carries the encryption feature. If so, using the decryption key to decrypt the return data; 2. The method for dynamically encrypting and decrypting application program request data based on the IAST tool according to claim 1, wherein Also screening the request data with the second marking feature according to a preset rule. When the request data meets the preset rule, removing the second marking feature from the request data; 3. The method for dynamically encrypting and decrypting application program request data based on the IAST tool according to claim 2, wherein, Also re-screening the request data with the second marking feature through a learning algorithm based on a neural network; 4. A system for dynamically encrypting and decrypting application request data based on an IAST tool, characterized in that, Including: An instrumentation module for instrumenting the target application through the IAST tool to track the propagation path of requests entering the application; A first marking module that uses the first marking feature to mark the request uri related to personal data in the application, where the request uri represents the type of request; A second marking module for using the second marking feature to mark the request data representing the request content in the request when the request uri in the request from the user carries the first marking feature; A third marking module for using the third marking feature to mark the return data of the data propagation function when the parameter data of the data propagation function of the current application carries the second marking feature; An encryption module for using the encryption key to encrypt and store the data with the third marking feature to be stored in the database currently when the sql statement executed by the current database function is an insert statement; A feature adding module for adding an encryption feature to the encrypted data; A traversing module for traversing the return data of the current request to judge whether the return data carries the encryption feature when the sql statement executed by the current database function is a query statement; A decryption module for decrypting the return data with the encryption feature of the current request using the decryption key according to the return value of the traversing module when the sql statement executed by the current database function is a query statement; 5. The system for dynamically encrypting and decrypting application program request data based on the IAST tool according to claim 4, wherein Also includes a first screening module for screening the request data with the second marking feature according to a preset rule.
6. The system for dynamically encrypting and decrypting application program request data based on the IAST tool according to claim 5, wherein Further included is a second screening module, which re-screens the request data with the second marked feature through a learning algorithm based on a neural network.
7. A system for dynamically encrypting and decrypting application program request data, characterized in that, Comprising: One or more processors; A memory; And one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the one or more processors, and the programs include instructions for executing the method for dynamically encrypting and decrypting application program request data as described in any one of claims 1 to 3.
8. A computer-readable storage medium, characterized in that, Including a computer program, which can be executed by a processor to complete the method for dynamically encrypting and decrypting application program request data as described in any one of claims 1 to 3.
Citation Information
Patent Citations
Method and system for dynamically detecting level unauthorized based on IAST test tool
CN110688659A
SQL injection vulnerability detection method and system based on active IAST
CN113158197A