A security algorithm switching method, device, apparatus and storage medium
By automatically judging and switching the proportion of security algorithms in the trading system, the problem of smooth switching from non-national cryptographic algorithms to national cryptographic algorithms is solved, reducing labor costs and improving the stability and availability of the system.
Patent Information
- Application Number
- CN202211138217.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-19
- Publication Date
- 2025-12-23
- Estimated Expiration
- 2042-09-19
AI Technical Summary
In existing trading systems, the security of non-national cryptographic algorithms is insufficient, and it is necessary to switch to national cryptographic algorithms. However, traditional methods require human intervention, which leads to high costs and affects the stability and availability of the trading system.
By acquiring transaction information from the current algorithm phase, determining whether preset conditions are met, and automatically switching to the next algorithm phase, the application ratio of national cryptographic algorithms is increased, human intervention is reduced, labor costs are lowered, and the system's robustness and intelligence are improved.
It enables a smooth switch to the national cryptographic algorithm without pausing the system, reducing manual costs and improving the availability and stability of the trading system. It is suitable for systems with high access frequency and large transaction volume.
Smart Images

Figure CN115456627B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] Embodiments of the present application relate to the technical field of cloud computing security services, and in particular to a security algorithm switching method, device, equipment and storage medium. BACKGROUND
[0002] With the development of social informatization and technologization, especially the development of mobile Internet in recent years, the transaction volume of mobile payment has rapidly increased, the pressure on the transaction system has become increasingly large, and the requirement for the security of the transaction system has become increasingly high. Therefore, the security algorithm for ensuring the security of the transaction message is crucial.
[0003] Most of the original transaction security algorithms use non-national cryptographic algorithms, such as international encryption algorithms. However, all transactions need to use national cryptographic algorithms due to security considerations. Therefore, the original security algorithm needs to be switched to a national cryptographic algorithm. SUMMARY
[0004] Embodiments of the present application provide a security algorithm switching method, device, equipment, system and storage medium to solve the problem of automatically switching the security algorithm of a transaction to a national cryptographic algorithm.
[0005] In a first aspect, embodiments of the present application provide a security algorithm switching method, which comprises:
[0006] obtaining target transaction information of a target transaction that applies a first security algorithm in a current algorithm proportion stage; wherein the first security algorithm comprises a national cryptographic algorithm;
[0007] determining whether the target transaction information satisfies a preset stage adjustment condition; wherein the preset stage adjustment condition is determined according to the current algorithm proportion stage;
[0008] if yes, switching from the current algorithm proportion stage to a next algorithm proportion stage; wherein the first security algorithm application proportion of the next algorithm proportion stage is greater than that of the current algorithm proportion stage.
[0009] In a second aspect, embodiments of the present application further provide a security algorithm switching device, which comprises:
[0010] an information obtaining module configured to obtain target transaction information of a target transaction that applies a first security algorithm in a current algorithm proportion stage; wherein the first security algorithm comprises a national cryptographic algorithm;
[0011] a condition satisfaction determining module configured to determine whether the target transaction information satisfies a preset stage adjustment condition; wherein the preset stage adjustment condition is determined according to the current algorithm proportion stage;
[0012] The first stage switching module is configured to switch from the current algorithm proportion stage to a next algorithm proportion stage if the condition meets the judgment of the condition meets the judgment module, wherein the first security algorithm application proportion of the next algorithm proportion stage is greater than that of the current algorithm proportion stage.
[0013] In a third aspect, an electronic device is provided, which includes a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the security algorithm switching method according to any of the embodiments of the present application when executing the program.
[0014] In a fourth aspect, a computer readable storage medium is provided, which stores a computer program, and the program is executable on a processor to implement the security algorithm switching method according to any of the embodiments of the present application.
[0015] In a fifth aspect, a computer program product is provided, which includes a computer program, and the computer program is executable on a processor to implement the security algorithm switching method according to any of the embodiments of the present application.
[0016] In the embodiments of the present application, target transaction information of a target transaction applying a first security algorithm in a current algorithm proportion stage is acquired, wherein the first security algorithm includes a national security algorithm; it is judged whether the target transaction information meets a preset stage adjustment condition; wherein the preset stage adjustment condition is determined according to the current algorithm proportion stage; if yes, the current algorithm proportion stage is switched to a next algorithm proportion stage in which the first security algorithm application proportion is greater than that of the current algorithm proportion stage. By switching between different algorithm proportion stages, the application proportion of the national security algorithm is increased, the problem of automatically switching the security algorithm of a transaction to the national security algorithm is solved, human intervention is reduced, the artificial cost is reduced, and the robustness and intelligence of the system are improved. Moreover, since the first security algorithm application proportion can be adjusted, the granularity of switching the transaction to the national security algorithm can be changed according to actual conditions, the influence on the transaction is reduced, the availability and stability of the transaction system are enhanced, and the method is suitable for a transaction system with high access frequency and large transaction volume. Moreover, the system does not need to be suspended for algorithm switching, the influence of algorithm switching on the transaction system is reduced, and the availability and stability of the transaction system are ensured. BRIEF DESCRIPTION OF DRAWINGS
[0017] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiments. It should be understood that the following drawings only show some of the embodiments of the present application, and therefore should not be considered as a limitation to the scope. For those skilled in the art, other related drawings can also be obtained without creative labor.
[0018] Figure 1 The flow of the security algorithm switching method provided for the embodiment of the present application Figure One ;
[0019] Figure 2 The flow of the security algorithm switching method provided for the embodiment of the present application Figure Two ;
[0020] Figure 3 The flow of the security algorithm switching method provided for the embodiment of the present application Figure Three ;
[0021] Figure 4 The flow of the security algorithm switching method provided for the embodiment of the present application Figure Four ;
[0022] Figure 5 The structural schematic diagram of a security algorithm switching device provided for the embodiment of the present application
[0023] Figure 6 The structural schematic diagram of an electronic device for implementing the embodiment of the present application DETAILED DESCRIPTION
[0024] The present application will be further described below in conjunction with the drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the present application, but not to limit the present application. In addition, it should be noted that, for the convenience of description, only the parts related to the present application are shown in the drawings, but not all the structures.
[0025] It should be noted that: similar labels and letters represent similar items in the following drawings, therefore, once an item is defined in one drawing, it does not need to be further defined and explained in the subsequent drawings. At the same time, in the description of the present application, the terms "first", "second", "target" and the like are only used to distinguish the description, and cannot be understood as indicating or implying relative importance. The acquisition, storage, use, processing and the like of data in the technical solution of the present application all comply with the relevant provisions of national laws and regulations.
[0026] The technical solution of the present application and how the technical solution of the present application solves the above technical problems will be described in detail below with specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments.
[0027] Figure 1 The flow of the security algorithm switching method provided for the embodiment of the present application Figure One . As shown in Figure 1 , the security algorithm switching method comprises:
[0028] In step 110, target transaction information of a target transaction applying the first security algorithm in the current algorithm proportion stage is acquired; the first security algorithm includes a national security algorithm.
[0029] The target transaction is a transaction applying the first security algorithm and requiring subsequent processing, which can be all transactions applying the first security algorithm, part of transactions of a specified type, part of transactions determined randomly, etc., which are not limited in the embodiment.
[0030] The current algorithm proportion stage is an algorithm proportion stage in which a related transaction is currently located, the related transaction is a transaction having an association with the security algorithm switching, such as a transaction currently performed in a certain transaction system. The proportions of the related transactions applying the first security algorithm are different in different algorithm proportion stages. For example, one percent of the related transactions apply the first security algorithm in the current algorithm proportion stage, and ninety-nine percent of the related transactions apply other security algorithms.
[0031] The target transaction information is information related to the security algorithm switching in the transaction information, such as time information of the target transaction, which is not limited in the embodiment. The first security algorithm includes a national security algorithm, the national security algorithm is a national security SM double certificate algorithm, including SM1, SM2, SM3, SM4, etc.
[0032] Optionally, the target transaction information of the target transaction applying the first security algorithm in the current algorithm proportion stage is acquired, including:
[0033] According to the preset transaction type and the transaction identifier of the target transaction, the target transaction information of the target transaction applying the first security algorithm in the current algorithm proportion stage is acquired.
[0034] The transaction identifier can be used to identify the transaction type corresponding to the target transaction, which can be a target transaction code of the target transaction, which is not limited in the embodiment.
[0035] The preset transaction type can be a currently concerned transaction type. According to the preset transaction type and the transaction identifier, the target transaction requiring attention is acquired, and the target transaction information of the target transaction applying the first security algorithm in the target transaction is acquired.
[0036] For example, the transaction type includes ABC, the preset transaction type is A, and according to the transaction identifier, the target transaction of the transaction type A is acquired, and the target transaction information of the target transaction applying the first security algorithm is acquired from the target transaction of the transaction type A. The target transaction of the transaction type A is in the current algorithm proportion stage.
[0037] Optionally, the algorithm proportion stages that the target transactions of different transaction types are in, and the specific parameters corresponding to the algorithm proportion stages can be different. For example, the target transactions of transaction type A can be in the first security algorithm application proportion of 0.01%, 1%, and 50% respectively; the target transactions of transaction type B can be in the first security algorithm application proportion of 0.02%, 2%, and 60% respectively; that is, at the same time, the target transactions of transaction type A can be in the first security algorithm application proportion of 0.01%, and the target transactions of transaction type B can be in the first security algorithm application proportion of 2%. According to different transaction types, the corresponding security algorithm switching process is performed, thereby improving the pertinence of the algorithm proportion stage switching.
[0038] By obtaining the target transaction information of the target transaction of the corresponding transaction type in the current algorithm proportion stage according to the preset transaction type and the transaction identifier of the target transaction, when the target transactions of multiple transaction types are in the current algorithm proportion stage, the algorithm proportion stage switching can be performed for the target transaction of the preset transaction type according to the target transaction information in the subsequent process, thereby improving the pertinence of the algorithm proportion stage switching.
[0039] In step 120, it is judged whether the target transaction information satisfies a preset stage adjustment condition; wherein the preset stage adjustment condition is determined according to the current algorithm proportion stage.
[0040] Whether the target transaction information satisfies the preset stage adjustment condition can be that the target transaction information is compared with the preset stage adjustment condition. For example, the preset stage adjustment condition can be that whether the target transaction information in the current algorithm proportion stage lasts for a preset time period, and the embodiment is not limited in this regard.
[0041] The preset stage adjustment condition is determined according to the current algorithm proportion stage. For example, if there are four algorithm proportion stages, and the current algorithm proportion stage is algorithm proportion stage three, the preset stage adjustment condition can correspond to algorithm proportion stage three. The preset stage adjustment conditions corresponding to different algorithm proportion stages can be similar, for example, both contain success rate judgment conditions; or can be different, for example, the preset stage adjustment condition corresponding to algorithm proportion stage three contains a time condition, and the preset stage adjustment condition corresponding to algorithm proportion stage four contains a success rate condition, and the embodiment is not limited in this regard.
[0042] If the target transaction information does not satisfy the preset stage adjustment condition, an error can be reported, or the target transaction information is reacquired and compared with the preset stage adjustment condition again, and the embodiment is not limited in this regard.
[0043] If yes, switching from the current algorithm proportion stage to the next algorithm proportion stage, wherein the first security algorithm application proportion of the next algorithm proportion stage is greater than that of the current algorithm proportion stage.
[0044] If the preset stage adjustment condition is met, the current algorithm proportion stage is switched to the next algorithm proportion stage, that is, the proportion of the first security algorithm applied to the related transaction is increased. For example, the first security algorithm application proportion corresponding to the current algorithm proportion stage is 0.01%, and the first security algorithm application proportion corresponding to the next algorithm proportion stage can be 1%.
[0045] Optionally, in the embodiment, the program version is unified, and no program version is added, thereby reducing the version management cost.
[0046] Optionally, the method further comprises:
[0047] In response to the stage switching request, the current algorithm proportion stage is switched to the target algorithm proportion stage.
[0048] The stage switching request can be a request issued by a person, and is used to switch the current algorithm proportion stage to the target algorithm proportion stage. The stage switching request can be issued when an emergency occurs, and the embodiment does not limit this. For example, the first security algorithm application proportion corresponding to the current algorithm proportion stage is 0.01%, if no stage switching request is received, the next algorithm proportion stage with the first security algorithm application proportion of 0.1% needs to be switched to after the preset stage adjustment condition is met; if the stage switching request is received, and the target algorithm proportion stage corresponding to the stage switching request is associated with the first security algorithm application proportion of 1%, the current algorithm proportion stage is directly switched to the target algorithm proportion stage.
[0049] At this time, it can be unnecessary to determine whether the target transaction information meets the preset stage adjustment condition, and it can be unnecessary to switch from the current algorithm proportion stage to the target algorithm proportion stage according to the original stage switching sequence, thereby improving the flexibility of algorithm proportion stage switching.
[0050] Optionally, before the current algorithm proportion stage is switched to the next algorithm proportion stage, the method further comprises:
[0051] Determining whether the current algorithm proportion stage is a full proportion stage.
[0052] If yes, the current algorithm proportion stage is maintained.
[0053] The full-ratio stage is a stage in which the application ratio of the first security algorithm is 100%, and if the current algorithm ratio stage is the full-ratio stage, the current algorithm ratio stage is maintained. Thus, by switching between different algorithm ratio stages, the related transaction can be gradually changed from completely applying other security algorithms to completely applying the first security algorithm, thereby achieving smooth transition of the security algorithm application of the transaction.
[0054] The embodiment of the present application obtains target transaction information of a target transaction applying the first security algorithm in the current algorithm ratio stage, wherein the first security algorithm includes a national security algorithm; determines whether the target transaction information satisfies a preset stage adjustment condition; wherein the preset stage adjustment condition is determined according to the current algorithm ratio stage; and if the preset stage adjustment condition is satisfied, switches from the current algorithm ratio stage to a next algorithm ratio stage in which the application ratio of the first security algorithm is greater than the current algorithm ratio stage.
[0055] By switching between different algorithm ratio stages to increase the application ratio of the national security algorithm, the problem of automatically switching the security algorithm of the transaction to the national security algorithm is solved, human intervention is reduced, the labor cost is reduced, and the robustness and intelligence of the system are improved. The preset stage adjustment condition is determined according to the current algorithm ratio stage, different stage switching times can be determined according to different algorithm ratio stages, the pertinence of the stage switching time determination is improved, and thus the effectiveness of the subsequent ratio stage switching is improved. In addition, because the application ratio of the first security algorithm can be adjusted, the granularity of switching the transaction to the national security algorithm can be changed according to actual conditions, the impact on the transaction is reduced, the availability and stability of the transaction system are enhanced, and the method is suitable for a transaction system with high access frequency and large transaction volume. In addition, the system does not need to be suspended for algorithm switching, the impact of algorithm switching on the transaction system is reduced, and the availability and stability of the transaction system are ensured.
[0056] Figure 2 The flow of the security algorithm switching method provided by the embodiment of the present application Figure Two As shown in FIG. 1, the security algorithm switching method includes the following steps: Figure 2
[0057] Step 210, obtaining a transaction success rate of a target transaction applying a first security algorithm in a preset time period in a current algorithm ratio stage; wherein the first security algorithm includes a national security algorithm.
[0058] The transaction success rate of the target transaction in the preset time period is the proportion of the successful target transactions to all target transactions in the preset time period, for example, in 24 hours, if the related transaction is 100 transactions, 10 of which apply the first security algorithm, i.e., 10 target transactions, and 9 of the 10 target transactions are successful and 1 target transaction fails, the transaction success rate is 90%.
[0059] The transaction success rate of the target transaction in the preset time period can be calculated at a specified time after completion of the target transaction, that is, without real-time calculation, thereby reducing the influence on the transaction system.
[0060] Optionally, the preset time period is determined according to the current algorithm proportion stage.
[0061] Different preset time periods can be set according to different algorithm proportion stages. If the application proportion of the first security algorithm associated with the algorithm proportion stage is higher, the corresponding preset time period is longer. This embodiment does not limit this.
[0062] The transaction success rate in the corresponding time period is counted according to different algorithm proportion stages. If the preset time periods corresponding to the algorithm proportion stages are consistent, if the application proportion of the first security algorithm corresponding to the algorithm proportion stage is low, and the preset time period is too short, the amount of data of the obtained transaction success rate may be insufficient; if the application proportion of the first security algorithm corresponding to the algorithm proportion stage is high, and the preset time period is too long, the amount of data of the obtained transaction success rate may be excessive, and the like. The transaction success rate is improved in pertinence, and the time is saved while sufficient transaction success rate is counted, thereby improving the efficiency of switching of the algorithm proportion stage.
[0063] Step 220, determining whether the transaction success rate meets a preset success rate condition.
[0064] The preset success rate condition is a judgment condition for the transaction success rate, for example, whether the transaction success rate is 100%, and the corresponding preset success rate conditions of different algorithm proportion stages can be different. This embodiment does not limit this.
[0065] Step 230, if the preset success rate condition is met, switching from the current algorithm proportion stage to the next algorithm proportion stage, wherein the application proportion of the first security algorithm of the next algorithm proportion stage is greater than that of the current algorithm proportion stage.
[0066] If the preset success rate condition is met, switching from the current algorithm proportion stage to the next algorithm proportion stage.
[0067] The embodiment obtains the transaction success rate of the target transaction in the preset time period in the current algorithm proportion stage in which the first security algorithm is applied. When the transaction success rate meets the preset success rate condition, it is determined to switch from the current algorithm proportion stage to the next algorithm proportion stage, thereby reducing the influence on the transaction, improving the effectiveness of switching of the algorithm proportion stage, and avoiding the problem that the application proportion of the first security algorithm is still expanded when the transaction fails due to the application of the first security algorithm, which may cause the number of failed transactions to increase.
[0068] Figure 3 The flow of the security algorithm switching method provided by the embodiment of the application Figure Three . AsFigure 3 As shown, the security algorithm switching method comprises the following steps:
[0069] Step 310, obtaining first candidate transaction information of a target transaction applying a first security algorithm in a current algorithm proportion phase, and storing the first candidate transaction information to a preset storage location; wherein the first security algorithm comprises a national secret algorithm.
[0070] The first candidate transaction information can be all information associated with a single target transaction, and the corresponding first candidate transaction information can be stored to the preset storage location after completion of the single target transaction.
[0071] Step 320, obtaining target transaction information according to second candidate transaction information in the preset storage location.
[0072] The second candidate transaction information is all transaction information stored in the preset storage location, and the target transaction information can be obtained according to the second candidate transaction information by screening the second candidate transaction information according to a preset screening condition.
[0073] Optionally, obtaining the target transaction information according to the second candidate transaction information in the preset storage location comprises:
[0074] Determining the target transaction information from the second candidate transaction information according to a preset screening condition; wherein the preset screening condition comprises at least one of a time screening condition and a transaction identifier screening condition.
[0075] The time screening condition is a screening condition related to time, which can be a limit condition of transaction completion time, and an example of determining the target transaction information from the second candidate transaction information according to the preset screening condition can be obtaining the transaction completion time of the target transaction from the second candidate transaction information. The transaction identifier screening condition is a screening condition related to the transaction identifier of the transaction, and an example of determining the target transaction information from the second candidate transaction information according to the preset screening condition can be obtaining the identifier information of the target transaction from the second candidate transaction information.
[0076] By determining the target transaction information from the second candidate transaction information according to the preset screening condition comprising at least one of the time screening condition and the transaction identifier screening condition, the pertinence of obtaining the target transaction information is improved, and the judgment efficiency is improved by avoiding comparing multiple transaction information irrelevant to the preset phase adjustment condition with the preset phase adjustment condition, thereby improving the efficiency of the overall algorithm proportion phase switching.
[0077] Step 330, determining whether the target transaction information satisfies a preset phase adjustment condition; wherein the preset phase adjustment condition is determined according to the current algorithm proportion phase.
[0078] According to the target transaction information obtained through the screening, it is determined whether the preset stage adjustment condition is met.
[0079] In step 340, if the condition is met, the current algorithm proportion stage is switched to the next algorithm proportion stage; wherein the first security algorithm application proportion of the next algorithm proportion stage is greater than that of the current algorithm proportion stage.
[0080] By obtaining the first candidate transaction information of the target transaction applying the first security algorithm in the current algorithm proportion stage, and storing the first candidate transaction information to a preset storage location, the second candidate transaction information in the preset storage location is uniformly processed, without the need for real-time processing of the first candidate transaction information, thereby preventing the normal transaction from being affected, and improving the usability and stability of the transaction system.
[0081] Figure 4 The security algorithm switching method provided by the embodiments of the present application Figure Four As shown in Figure 4 , the security algorithm switching method comprises the following steps:
[0082] In step 410, a random number is generated for the transaction to be processed.
[0083] The transaction to be processed is a transaction whose security algorithm is to be determined, which can be a transaction whose corresponding security algorithm is not determined, or a transaction whose corresponding security algorithm needs to be changed, and the embodiments of the present application do not limit this. The random number can be generated within a preset numerical range, for example, a number is randomly generated between 1-10000.
[0084] In step 420, it is determined whether the random number is within the numerical range associated with the current algorithm proportion stage.
[0085] It is determined whether the random number is within the numerical range associated with the current algorithm proportion stage. For example, the current algorithm proportion stage is a stage in which the application proportion of the first security algorithm is 1%, and the numerical range associated with the current algorithm proportion stage can be 1-100. If the random number is within 1-100, the random number is within the numerical range associated with the current algorithm proportion stage.
[0086] In step 430, if yes, the target security algorithm of the transaction to be processed is determined to be the first security algorithm from the candidate security algorithms; wherein the candidate security algorithms include the first security algorithm and the second security algorithm; and the second security algorithm includes an international algorithm.
[0087] If the random number is within the numerical range associated with the current algorithm proportion stage, the transaction to be processed can be pre-configured with multiple types of candidate security algorithms, and when the random number is within the numerical range associated with the current algorithm proportion stage, the first security algorithm is selected as the target security algorithm from the candidate security algorithms.
[0088] If the random number is out of the number range associated with the current algorithm proportion stage, a second security algorithm is selected from the candidate security algorithms as the target security algorithm. The target security algorithm is a security algorithm applied by the target transaction. The second security algorithm includes an international algorithm, which can be an international single certificate RSA algorithm. The embodiment is not limited in this regard.
[0089] Step 440, target transaction information of a target transaction applying a first security algorithm in the current algorithm proportion stage is acquired. The first security algorithm includes a national security algorithm.
[0090] Step 450, whether the target transaction information meets a preset stage adjustment condition is judged. The preset stage adjustment condition is determined according to the current algorithm proportion stage.
[0091] Step 460, if yes, the current algorithm proportion stage is switched to a next algorithm proportion stage. The first security algorithm application proportion of the next algorithm proportion stage is greater than that of the current algorithm proportion stage.
[0092] The type of the security algorithm applied by the transaction is determined by the random number. The randomness of the application of the first security algorithm is improved while ensuring the application proportion of the first security algorithm. Thus, the first security algorithm is not selected for the specified transaction, and the problem that the security algorithm switching cannot be found in time is avoided. The application proportion of the first security algorithm is increased, and more transactions fail. The effectiveness of the security algorithm switching is improved.
[0093] In order to make the person skilled in the art more clearly understand the scheme, the application further provides a specific implementation manner.
[0094] The security algorithm switching is realized by a proportion controller, a proportion algorithm calculator and a proactive adjustment module. The proportion controller is used to store the application proportion of the first security algorithm in the current algorithm proportion stage, and is also used to synchronize the data to the service when the algorithm proportion stage is switched. The proportion algorithm calculator is used to count the target transaction and acquire the transaction success rate in a preset time period. The proportion algorithm calculator is also used to judge whether the transaction success rate meets a preset success rate condition. If yes, the proportion controller is called to adjust the application proportion of the first security algorithm. The proactive adjustment module is used to switch the current algorithm proportion stage to a target algorithm proportion stage in response to a stage switching request. The application proportion of the first security algorithm in each algorithm proportion stage and the preset success rate condition can be preset and initialized before the security algorithm switching.
[0095] Figure 5A structural schematic diagram of a security algorithm switching device provided by an embodiment of the present application. The device can be implemented in hardware and / or software, and can execute a security algorithm switching method provided by any embodiment of the present application, and has the corresponding function modules and beneficial effects of the execution method. As shown in the figure, the device comprises: Figure 5
[0096] An information acquisition module 510 is configured to acquire target transaction information of a target transaction applying a first security algorithm in a current algorithm proportion stage; wherein the first security algorithm comprises a national secret algorithm;
[0097] A condition satisfaction judgment module 520 is configured to judge whether the target transaction information satisfies a preset stage adjustment condition; wherein the preset stage adjustment condition is determined according to the current algorithm proportion stage;
[0098] A first stage switching module 530 is configured to switch from the current algorithm proportion stage to a next algorithm proportion stage if the condition satisfaction judgment module judges that the condition is satisfied; wherein the first security algorithm application proportion of the next algorithm proportion stage is greater than that of the current algorithm proportion stage.
[0099] Optionally, the information acquisition module comprises:
[0100] A transaction success rate acquisition unit is configured to acquire a transaction success rate of the target transaction applying the first security algorithm in a preset time period in the current algorithm proportion stage;
[0101] Correspondingly, the condition satisfaction judgment module comprises:
[0102] A condition satisfaction judgment unit is configured to judge whether the transaction success rate satisfies a preset success rate condition.
[0103] Optionally, the preset time period is determined according to the current algorithm proportion stage.
[0104] Optionally, the information acquisition module comprises:
[0105] A first information acquisition unit is configured to acquire target transaction information of a target transaction applying the first security algorithm in the current algorithm proportion stage according to a preset transaction type and a transaction identifier of the target transaction.
[0106] Optionally, the device further comprises:
[0107] A random number generation module is configured to generate a random number for a to-be-processed transaction before the information acquisition module;
[0108] A random number judgment module is configured to judge whether the random number is within a number range associated with the current algorithm proportion stage;
[0109] a security algorithm determination module, configured to determine, if the random number judgment module judges yes, a target security algorithm of the to-be-processed transaction as the first security algorithm from candidate security algorithms; wherein the candidate security algorithms comprise the first security algorithm and a second security algorithm; and the second security algorithm comprises an international algorithm.
[0110] Optionally, the information acquisition module comprises:
[0111] an information storage unit, configured to acquire first candidate transaction information of the target transaction, and store the first candidate transaction information to a preset storage location;
[0112] a second information acquisition unit, configured to acquire the target transaction information according to second candidate transaction information in the preset storage location.
[0113] Optionally, the second information acquisition unit comprises:
[0114] an information determination sub-unit, configured to determine the target transaction information from the second candidate transaction information according to a preset screening condition; wherein the preset screening condition comprises at least one of a time screening condition and a transaction identification screening condition.
[0115] Optionally, the apparatus further comprises:
[0116] a second stage switching module, configured to switch the current algorithm proportion stage to a target algorithm proportion stage in response to a stage switching request.
[0117] Optionally, the apparatus further comprises:
[0118] a stage judgment module, configured to judge whether the current algorithm proportion stage is a full proportion stage before the first stage switching module;
[0119] a stage keeping module, configured to keep the current algorithm proportion stage if the stage judgment module judges yes.
[0120] Figure 6 A structural schematic diagram of an electronic device 10 that can be used to implement embodiments of the present application is shown. The electronic device is intended to represent various forms of digital computers, such as laptops, desktops, tablets, personal digital assistants, servers, blade servers, mainframes, and other appropriate computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular telephones, smart phones, wearable devices (e.g., headsets, glasses, watches, etc.), and other similar computing devices. The components shown here, their connections and relationships, and their functions, are meant to be examples only, and are not intended to limit the inventiveness described and / or claimed in this document.
[0121] like Figure 6 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 may also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0122] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0123] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as the security algorithm switching method.
[0124] In some embodiments, the security algorithm switching method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the security algorithm switching method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to perform the security algorithm switching method by any other suitable means (e.g., by means of firmware).
[0125] The various embodiments of the systems and techniques described above can be implemented in digital electronic circuitry, integrated circuitry, a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on a chip (SOC), a load programmable logic device (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include implementation in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be special or general purpose, coupled to receive data and instructions from, and to transmit data and instructions to, a distributed storage system, at least one input device, and at least one output device.
[0126] Computer programs used to implement the processes of the application can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus, such that the computer program, when executed, can cause instructions defined in the flow charts and / or block diagrams to be implemented. The computer program can be executed entirely on a machine, partially on a machine, partially on a machine as a standalone software package and partially on a remote machine or entirely on a remote machine or server.
[0127] In the context of the present application, a computer-readable storage medium can be a tangible medium that can contain or store computer programs for use by or in connection with an instruction execution system, apparatus, or device. Computer-readable storage media can include, but are not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium will include one or more lines of electrical connections, portable computer disks, hard disk drives, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or Flash memory), optical fibers, portable compact disc read-only memories (CD-ROMs), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0128] To provide for interaction with a user, the systems and techniques described here can be implemented on an electronic device having a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can be used to provide for interaction with a user as well; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form, including acoustic, speech, or tactile input.
[0129] The systems and techniques described here can be implemented in a computing system that includes a back end component (e.g., as a data server), or that includes a middleware component (e.g., an application server), or that includes a front end component (e.g., a user computer having a graphical user interface or a Web browser through which a user can interact with an implementation of the systems and techniques described here), or any combination of such back end, middleware, or front end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), blockchain network, and the Internet.
[0130] The computing system can include clients and servers. A client and server are generally remote from each other and typically interact through a communication network. The relationship of client and server arises by virtue of computer programs running on the respective computers and having a client-server relationship to each other. A server can be a cloud server, also known as cloud computing server or cloud host, which is a host product in the cloud computing service system, to solve the defects of large management difficulty and weak business scalability in traditional physical host and VPS service.
[0131] It should be understood that the various forms of flow shown above can be re-ordered, added to, or deleted from without departing from the scope of the present application. For example, the steps recited in the present application can be executed in parallel, in series, or in a different order, without departing from the desired results of the technical solutions of the present application, and this is not limited herein.
[0132] The embodiment of the present application further provides a computer program product, comprising a computer program which, when executed by a processor, implements the security algorithm switching method provided in any embodiment of the present application.
[0133] Computer program code for carrying out operations of the present application can be written in any combination of one or more programming languages, including an object oriented programming language such as Java, Smalltalk, C++ or the like and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider).
[0134] It is to be understood that the above description is merely a preferred embodiment of the application and the applied technical principles. Those skilled in the art will understand that the present application is not limited to the specific embodiments described herein, and that various obvious changes, modifications and substitutions can be made without departing from the scope of the present application. Therefore, although the present application has been described in detail through the above embodiments, the present application is not limited to the above embodiments, and can include more other equivalent embodiments without departing from the concept of the present application, and the scope of the present application is determined by the scope of the appended claims.
Claims
1. A security algorithm switching method, characterized by, The method comprises: obtaining target transaction information of a target transaction in a current algorithm proportion stage and applying a first security algorithm; wherein the first security algorithm comprises a national security algorithm; the current algorithm proportion stage is an algorithm proportion stage in which a related transaction currently is; the related transaction is a transaction currently being processed; the target transaction is obtained according to a preset transaction type and a transaction identifier; target transactions of different transaction types are in different algorithm proportion stages; determining whether the target transaction information satisfies a preset stage adjustment condition; wherein the preset stage adjustment condition is determined according to the current algorithm proportion stage; if yes, switching from the current algorithm proportion stage to a next algorithm proportion stage; wherein a first security algorithm application proportion of the next algorithm proportion stage is greater than that of the current algorithm proportion stage.
2. The method of claim 1, wherein, The method comprises: obtaining a transaction success rate of the target transaction in a preset time period and applying the first security algorithm in the current algorithm proportion stage; correspondingly, determining whether the target transaction information satisfies a preset stage adjustment condition comprises: determining whether the transaction success rate satisfies a preset success rate condition.
3. The method of claim 2, wherein, The preset time period is determined according to the current algorithm proportion stage.
4. The method of claim 1, wherein, The method comprises: obtaining target transaction information of a target transaction in a current algorithm proportion stage and applying a first security algorithm according to a preset transaction type and a transaction identifier of the target transaction.
5. The method of claim 1, wherein, Before obtaining the target transaction information of the target transaction in the current algorithm proportion stage and applying the first security algorithm, the method further comprises: generating a random number for a to-be-processed transaction; determining whether the random number is in a numerical range associated with the current algorithm proportion stage; if yes, determining, from candidate security algorithms, that a target security algorithm of the to-be-processed transaction is the first security algorithm; wherein the candidate security algorithms comprise the first security algorithm and a second security algorithm; the second security algorithm comprises an international algorithm.
6. The method according to any one of claims 1 to 5, characterized in that, The method comprises: obtaining first candidate transaction information of the target transaction and storing the first candidate transaction information in a preset storage location; obtaining the target transaction information according to second candidate transaction information in the preset storage location.
7. The method of claim 6, wherein, The method comprises: determining the target transaction information from the second candidate transaction information according to a preset screening condition; wherein the preset screening condition comprises at least one of a time screening condition and a transaction identifier screening condition.
8. The method according to any one of claims 1 to 5, characterized in that, The method further comprises: switching the current algorithm proportion stage to a target algorithm proportion stage in response to a stage switching request.
9. The method according to any one of claims 1 to 5, characterized in that, Before switching from the current algorithm proportion stage to a next algorithm proportion stage, the method further comprises: determining whether the current algorithm proportion stage is a full proportion stage; if yes, maintaining the current algorithm proportion stage.
10. A security algorithm switching apparatus characterized by comprising: The method comprises: The information acquisition module is configured to acquire target transaction information of a target transaction to which a first security algorithm is applied in a current algorithm proportion stage; the first security algorithm comprises a national security algorithm; the current algorithm proportion stage is an algorithm proportion stage in which a related transaction currently is; the related transaction is a transaction currently being processed; the target transaction is acquired according to a preset transaction type and a transaction identifier; target transactions of different transaction types are in different algorithm proportion stages; The condition satisfaction judgment module is configured to judge whether the target transaction information satisfies a preset stage adjustment condition; the preset stage adjustment condition is determined according to the current algorithm proportion stage; The first stage switching module is configured to switch from the current algorithm proportion stage to a next algorithm proportion stage if the condition satisfaction judgment module judges that the condition is satisfied; the first security algorithm applied in the next algorithm proportion stage has a proportion greater than that in the current algorithm proportion stage.
11. The apparatus of claim 10, wherein, The information acquisition module comprises: The transaction success rate acquisition unit is configured to acquire a transaction success rate of the target transaction to which the first security algorithm is applied in the current algorithm proportion stage within a preset time period; Correspondingly, the condition satisfaction judgment module comprises: The condition satisfaction judgment unit is configured to judge whether the transaction success rate satisfies a preset success rate condition.
12. The apparatus of claim 10, wherein, The device further comprises: The random number generation module is configured to generate a random number for a transaction to be processed before the information acquisition module; The random number judgment module is configured to judge whether the random number is in a numerical range associated with the current algorithm proportion stage; The security algorithm determination module is configured to determine, if the random number judgment module judges that the condition is satisfied, that a target security algorithm of the transaction to be processed is the first security algorithm from among candidate security algorithms; the candidate security algorithms comprise the first security algorithm and a second security algorithm; the second security algorithm comprises an international algorithm.
13. The apparatus of any of claims 10-12, wherein, The information acquisition module comprises: The information storage unit is configured to acquire first candidate transaction information of the target transaction and store the first candidate transaction information in a preset storage location; The second information acquisition unit is configured to acquire the target transaction information according to second candidate transaction information in the preset storage location.
14. An electronic device, comprising: The computer program is stored in the memory and executable in the processor, and when the processor executes the computer program, the security algorithm switching method according to any one of claims 1-9 is implemented.
15. A computer readable storage medium having stored thereon a computer program, characterized in that, The program is executed by the processor to implement the security algorithm switching method according to any one of claims 1-9.
16. A computer program product comprising a computer program, characterized in that, The computer program is executed by the processor to implement the security algorithm switching method according to any one of claims 1-9.
Citation Information
Patent Citations
Method, terminal and safety carrier for realizing cryptographic algorithm system adaptive switching
CN103780376A
Alliance chain cryptographic algorithm switching method and device and alliance chain system
CN114978553A