Method and related device for generating security components based on low-code development framework

By selecting security strategies for front-end controls and back-end interfaces in a low-code development framework and combining them with encryption/decryption algorithms to generate secure components, security vulnerabilities in low-code development tools are addressed, improving software code security and data transmission reliability.

CN115617323BActive Publication Date: 2026-05-12FIBRLINK NETWORKS
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
FIBRLINK NETWORKS
Filing Date
2022-08-23
Publication Date
2026-05-12

AI Technical Summary

Technical Problem

Existing low-code development tools have significant vulnerabilities in terms of security standards and security functions when generating code, and cannot meet the privacy and confidentiality needs of enterprises and individual users.

Method used

By selecting the associated security policy method for each front-end control and back-end interface, security components are generated from a predefined security parameter table, including legitimacy verification, injection prevention, penetration prevention, unauthorized access prevention, and tamper prevention, and data encryption and decryption are performed in combination with SM2, SM3, and SM4 algorithms.

Benefits of technology

It reduces the risk of information being eavesdropped on, stolen, and tampered with, improves the security standards and functions of software code, and ensures the security of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115617323B_ABST
    Figure CN115617323B_ABST
Patent Text Reader

Abstract

The application provides a security component generation method based on a low-code development framework and related equipment, which comprises the following steps: selecting at least one security policy method associated with each front-end control from a pre-defined front-end security parameter table according to different security protection requirements of different front-end controls; meanwhile, selecting at least one security policy method associated with each back-end interface from a pre-defined back-end security parameter table according to different security protection requirements of different back-end interfaces; and generating a security component according to all security policy methods associated with all front-end controls and back-end interfaces involved in the software code in response to determining that the low-code development framework generates the software code, so that the software code finally output by the low-code development framework contains the security component, the risk of information of a service object being monitored, stolen and tampered with is reduced, and the security specification and security function of the software code finally output by the low-code development framework are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of cybersecurity technology, and in particular to a method and related equipment for generating security components based on a low-code development framework. Background Technology

[0002] With the continuous improvement of informatization, enterprises are becoming increasingly reliant on information-related software products in their production processes, leading to a surge in demand for related software development. To improve coding efficiency and shorten project development cycles, low-code development tools have emerged on the market. These tools abstract and encapsulate much of the programming knowledge required for software development through low-code technology. When using low-code development tools, developers can quickly develop applications and generate software code by simply using graphical drag-and-drop and parameterized configuration. This effectively solves repetitive tasks in code development and improves work efficiency.

[0003] Existing low-code technologies focus only on the rapid generation of functional code for software, with little attention paid to code security. This results in significant vulnerabilities in the generated code regarding security standards and functions, posing a risk of information being eavesdropped on, stolen, and tampered with by users. Consequently, they fail to meet the privacy and confidentiality needs of businesses and individual users. Summary of the Invention

[0004] In view of this, the purpose of this application is to propose a method and related equipment for generating security components based on a low-code development framework, so as to solve or partially solve the above-mentioned technical problems.

[0005] To achieve the above objectives, this application provides a method for generating security components based on a low-code development framework, comprising:

[0006] Select at least one security policy method associated with each front-end control from a predefined front-end security parameter table;

[0007] Select at least one security policy method associated with each backend interface from a predefined backend security parameter table;

[0008] In response to determining that the low-code development framework generates software code, a security component is generated based on all security policy methods associated with all front-end controls and back-end interfaces involved in the software code.

[0009] Optionally, before selecting at least one security policy method associated with each front-end control from a predefined front-end security parameter table, the method includes:

[0010] Define the front-end security parameter table based on the aforementioned front-end controls and front-end security requirements;

[0011] Define the backend security parameter table based on the backend interface and backend security requirements;

[0012] The security parameters in the front-end security parameter table and the back-end security parameter table are configured, and the security parameters include the security policy method.

[0013] Optionally, the method for generating security components based on a low-code development framework also includes:

[0014] During the execution of the software code, the security component calls encryption and decryption algorithms from the low-code development platform's public component library to encrypt and decrypt the data interaction process between the front end and the back end.

[0015] Optionally, the encryption / decryption algorithms include: SM2 algorithm, SM3 algorithm, and SM4 algorithm.

[0016] Optionally, the security parameters in the front-end security parameter table include: control name, control type, security policy method, communication protocol, and control status.

[0017] Optionally, the security parameters in the backend security parameter table include: interface protocol, interface type, interface name, interface URL, field name, and security policy method.

[0018] Based on the same inventive concept, this application also provides a security component generation device based on a low-code development framework, comprising:

[0019] The front-end association module is configured to select at least one security policy method associated with each front-end control from a predefined front-end security parameter table;

[0020] The backend association module is configured to select at least one security policy method associated with each backend interface from a predefined backend security parameter table;

[0021] The component generation module is configured to: in response to determining that the low-code development framework generates software code, generate a security component based on all security policy methods associated with all front-end controls and back-end interfaces involved in the software code.

[0022] Optionally, the security component generation device based on the low-code development framework also includes:

[0023] The front-end definition module is configured to define the front-end security parameter table based on the front-end controls and front-end security requirements.

[0024] The backend definition module is configured to define the backend security parameter table based on the backend interface and backend security requirements.

[0025] The parameter configuration module is configured to configure security parameters in the front-end security parameter table and the back-end security parameter table, wherein the security parameters include the security policy method.

[0026] Based on the same inventive concept, this application also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable by the processor, wherein the processor implements the method described above when executing the computer program.

[0027] Based on the same inventive concept, this application also provides a non-transitory computer-readable storage medium that stores computer instructions for causing a computer to perform the method described above.

[0028] As can be seen from the above, the security component generation method and related equipment based on the low-code development framework provided in this application select at least one security policy method associated with each front-end control from a predefined front-end security parameter table, based on the different security protection requirements of different front-end controls; simultaneously, select at least one security policy method associated with each back-end interface from a predefined back-end security parameter table, based on the different security protection requirements of different back-end interfaces; in response to determining the software code generated by the low-code development framework, security components are generated based on all security policy methods associated with all front-end controls and back-end interfaces involved in the software code, so that the software code finally output by the low-code development framework contains security components, reducing the risk of service object information being eavesdropped, stolen, and tampered with, and improving the security standardization and security functions of the software code finally output by the low-code development framework. Attached Figure Description

[0029] To more clearly illustrate the technical solutions in this application or related technologies, the drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the drawings described below are only embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0030] Figure 1 This is a flowchart illustrating a method for generating security components based on a low-code development framework, as described in an embodiment of this application.

[0031] Figure 2 This is a flowchart illustrating the definition of a security parameter table and the method for configuring security parameters according to an embodiment of this application.

[0032] Figure 3 This is a structural diagram of a security component generation device based on a low-code development framework according to an embodiment of this application;

[0033] Figure 4 This is a structural diagram of a security component generation apparatus based on a low-code development framework according to another embodiment of this application;

[0034] Figure 5 This is a structural diagram of an electronic device according to an embodiment of this application. Detailed Implementation

[0035] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with specific embodiments and the accompanying drawings.

[0036] It should be noted that, unless otherwise defined, the technical or scientific terms used in the embodiments of this application should have the ordinary meaning understood by one of ordinary skill in the art to which this application pertains. The terms "first," "second," and similar terms used in the embodiments of this application do not indicate any order, quantity, or importance, but are merely used to distinguish different components. Terms such as "comprising" or "including" mean that the element or object preceding the word encompasses the elements or objects listed after the word and their equivalents, without excluding other elements or objects. Terms such as "connected" or "linked" are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. Terms such as "upper," "lower," "left," and "right" are only used to indicate relative positional relationships; when the absolute position of the described object changes, the relative positional relationship may also change accordingly.

[0037] As the background technology shows, existing low-code development tools focus on the implementation of software functions and hardly involve code security-related parts, resulting in obvious vulnerabilities in the code in terms of security standards and security functions, which need to be manually improved in the later stage.

[0038] To address the problems existing in related technologies, based on the different security protection requirements of different front-end controls, at least one security policy method is selected for each front-end control from a predefined front-end security parameter table; simultaneously, based on the different security protection requirements of different back-end interfaces, at least one security policy method is selected for each back-end interface from a predefined back-end security parameter table; in response to determining the software code generated by the low-code development framework, a security component is generated based on all security policy methods associated with all front-end controls and back-end interfaces involved in the software code, so that the final software code output by the low-code development framework contains security components, eliminating the need for manual post-processing, reducing the risk of information of service objects being eavesdropped, stolen, and tampered with, and improving the security standardization and security functions of the final software code output by the low-code development framework.

[0039] The embodiments of this application will be described in detail below with reference to the accompanying drawings.

[0040] This application provides a method for generating security components based on a low-code development framework, referencing... Figure 1 The method includes the following steps:

[0041] Step S100: Select at least one security policy method associated with each front-end control from the predefined front-end security parameter table;

[0042] When developers use low-code frameworks to build front-end pages, the front-end page contains multiple front-end controls. A control refers to a reusable, programmable component at the smallest granularity in program design. Common front-end controls include input boxes, buttons, radio buttons, and checkboxes. Different security strategies can be selected for different front-end controls based on their different functions. These security strategies include: validity verification, injection prevention, penetration prevention, unauthorized access prevention, integrity verification, and tamper prevention. For example, when the front-end control is an input box, and the user enters information into the input box, at least two security strategies should be selected: validity verification and injection prevention. Validity verification mainly checks the input entered into the input box. Data type and length are validated. When an input field requires a user to enter a mobile phone number, the validity of the input field is checked to ensure that the user's input is 11 digits long and consists entirely of numbers. If the user's input does not meet the conditions, the user is prompted to modify it, and the error is recorded in the system log to ensure effective security tracing after a problem occurs. Injection attacks execute user-input data as code. Malicious attacks often involve appending code to the data. Therefore, when the front-end control is an input field, a security strategy to prevent injection should be selected to check whether the user's input data has been appended with code, thus preventing injection attacks.

[0043] Step S200: Select at least one security policy method associated with each backend interface from the predefined backend security parameter table;

[0044] When developers use low-code frameworks to build backend menus and programs, for each backend interface, they need to select at least one security policy method from a predefined backend security parameter table. The backend interface provides a channel for the frontend to interact with the backend server for data requests. When a user triggers a certain action, the frontend sends a request and data to the backend. The request and data sent by the frontend enter the backend through the backend interface. For the request returned by the frontend, the backend interface can select security policy methods such as legality verification, anti-penetration, and anti-unauthorized access to verify the request returned by the frontend, and perform integrity verification and anti-tampering on the data returned by the frontend.

[0045] Step S300: In response to determining the low-code development framework to generate software code, generate security components based on all security policy methods associated with all front-end controls and back-end interfaces involved in the software code.

[0046] After developers use low-code development tools to complete the development of front-end pages, back-end menus, and programs through graphical drag-and-drop and parameterized configuration, they can output the functional code of the software through the code conversion function of the low-code development tool. Once the functional code of the software is detected, the generation of the software begins. All security policy methods associated with all front-end controls and back-end interfaces involved in the software code call the corresponding security code from the low-code development database and write it into the corresponding position in the generated software code. All the security code written into the software code together form a security component.

[0047] As an optional embodiment, refer to Figure 2 Before selecting at least one security policy method associated with each front-end control from a predefined front-end security parameter table, the method includes:

[0048] Step S60: Define the front-end security parameter table based on the front-end controls and front-end security requirements;

[0049] The information on front-end controls that may be used in the development of the front-end page is sorted out, categorized, and entered into the front-end security parameter table. At the same time, the corresponding security policy method names are determined for the front-end security requirements and added to the front-end security parameter table. There are multiple security policy methods, and each security policy method corresponds to a part of specific security code that has been pre-written. This part of the security code is stored in the low-code development database.

[0050] Step S70: Define the backend security parameter table based on the backend interface and backend security requirements;

[0051] Determine the backend interfaces needed to build the backend menu and program, consider the requests and data types accepted by the backend interfaces and their corresponding network attack methods, and determine the backend security parameter table.

[0052] Step S80: Configure the security parameters in the front-end security parameter table and the back-end security parameter table. The security parameters include the security policy method.

[0053] The security parameters in the front-end security parameter table include information such as the name, type, and status of front-end controls, as well as security policy methods. It's necessary to establish a link between the control information and security policy methods in the front-end security parameter table. For each front-end control, a corresponding security policy method should be configured. For example, security policy methods corresponding to potential network attacks on the front-end control should be configured. Developers can adjust these configurations based on their actual needs during development. The back-end security parameter table contains information such as the name and type of back-end interfaces, and corresponding security parameters should also be configured based on the types of network attacks the back-end interfaces may encounter.

[0054] As an optional embodiment, the security component generation method based on the low-code development framework provided in this application further includes: during software code runtime, using the security component to call encryption and decryption algorithms from the public component library of the low-code development platform to encrypt and decrypt the data interaction process between the front end and the back end.

[0055] After developers build applications through a low-code development platform and obtain software code with security components, during the user's use of the application (i.e., when the software code is running), the application's front-end and back-end will continuously interact. The security components can use corresponding security code calls based on security policies and methods to package and store the data in the low-code development platform's public component library. Encryption and decryption algorithms are used to encrypt the data transmitted between the front-end and back-end to ensure the security of data transmission.

[0056] As an optional embodiment, the encryption / decryption algorithms include: SM2 algorithm, SM3 algorithm, and SM4 algorithm.

[0057] The SM2, SM3, and SM4 algorithms are common domestic commercial cryptographic algorithms. The SM2 elliptic curve public key cryptography algorithm is an asymmetric algorithm that can be used to encrypt data transmitted between the front end and the back end. The SM3 hash algorithm is a cryptographic hash algorithm independently designed in my country. It is suitable for the generation and verification of digital signatures and authentication codes for verification messages in commercial cryptographic applications, as well as the generation of random numbers. It can be used for the integrity verification of data transmitted between the front end and the back end. The SM4 block cipher algorithm can be used to encrypt and decrypt passwords and important business data.

[0058] As an optional embodiment, the security parameters in the front-end security parameter table include: control name, control type, security policy method, communication protocol, and control status.

[0059] Control name, control type, and control state are all inherent attributes of the front-end control itself. Different front-end controls can be distinguished by their names, the control type determines the purpose of the front-end control, and the control state indicates the current state of the control. A communication protocol refers to the rules and agreements that two entities must follow to complete communication or services. The protocol defines the format used by data units, the information and meaning that information units should contain, the connection method, and the timing of information sending and receiving, thereby ensuring that data in the network is successfully transmitted to the designated location. Security policy methods refer to the methods used to protect front-end controls and related data, which correspond to specific security codes. Security codes can call encryption and decryption algorithms to protect data.

[0060] As an optional implementation, the security parameters in the backend security parameter table include: interface protocol, interface type, interface name, interface URL, field name, and security policy method.

[0061] Interface protocol, interface type, interface name, interface URL, field names, etc., are all attributes inherent to the backend interface itself. The interface protocol refers to the communication methods and requirements that interfaces that need to exchange information must follow. The interface type determines the function of the backend interface, and the interface name can distinguish different backend interfaces. The interface URL (Uniform Resource Locator) can be understood as the address book of interfaces. Through the interface URL, you can reach any interface to obtain the required data. Fields can be used to define the characteristics or behaviors contained in an object. Different fields can be distinguished by field names. The security policy methods in the backend security parameter table are the same as those in the frontend security parameter table. In actual application, the required security policy method can be selected from all security policy methods for security protection according to the needs.

[0062] It should be noted that the method in this embodiment can be executed by a single device, such as a computer or server. The method can also be applied in a distributed scenario, where multiple devices cooperate to complete the task. In such a distributed scenario, one of these devices may execute only one or more steps of the method in this embodiment, and the multiple devices will interact with each other to complete the method described.

[0063] It should be noted that the above description describes some embodiments of this application. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in a different order than that shown in the above embodiments and still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0064] Based on the same inventive concept, and corresponding to any of the above embodiments, this application also provides a security component generation device based on a low-code development framework.

[0065] refer to Figure 3 The security component generation device based on the low-code development framework includes:

[0066] The front-end association module 24 is configured to: select at least one security policy method associated with each front-end control from a predefined front-end security parameter table;

[0067] The backend association module 25 is configured to select at least one security policy method associated with each backend interface from a predefined backend security parameter table;

[0068] The component generation module 26 is configured to: generate a security component in response to determining that the low-code development framework generates software code, based on all security policy methods associated with all front-end controls and back-end interfaces involved in the software code.

[0069] As an optional embodiment, refer to Figure 4 The security component generation device based on the low-code development framework also includes:

[0070] Front-end definition module 21 is configured to: define the front-end security parameter table based on the front-end controls and front-end security requirements;

[0071] Backend definition module 22 is configured to: define the backend security parameter table based on the backend interface and backend security requirements;

[0072] The parameter configuration module 23 is configured to configure security parameters in the front-end security parameter table and the back-end security parameter table, wherein the security parameters include the security policy method.

[0073] The front-end association module 24 is configured to: select at least one security policy method associated with each front-end control from a predefined front-end security parameter table;

[0074] The backend association module 25 is configured to select at least one security policy method associated with each backend interface from a predefined backend security parameter table;

[0075] The component generation module 26 is configured to: generate a security component in response to determining that the low-code development framework generates software code, based on all security policy methods associated with all front-end controls and back-end interfaces involved in the software code.

[0076] For ease of description, the above devices are described in terms of function, divided into various modules. Of course, in implementing this application, the functions of each module can be implemented in one or more software and / or hardware.

[0077] The apparatus described above is used to implement the corresponding security component generation method based on the low-code development framework in any of the foregoing embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0078] Based on the same inventive concept, corresponding to the methods of any of the above embodiments, this application also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the security component generation method based on a low-code development framework as described in any of the above embodiments.

[0079] Figure 5 This embodiment illustrates a more specific hardware structure of an electronic device, which may include a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. The processor 1010, memory 1020, input / output interface 1030, and communication interface 1040 are interconnected internally via the bus 1050.

[0080] The processor 1010 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this specification.

[0081] The memory 1020 can be implemented in the form of ROM (Read Only Memory), RAM (Random Access Memory), static storage device, dynamic storage device, etc. The memory 1020 can store the operating system and other applications. When the technical solutions provided in the embodiments of this specification are implemented by software or firmware, the relevant program code is stored in the memory 1020 and is called and executed by the processor 1010.

[0082] The input / output interface 1030 is used to connect input / output modules to realize information input and output. Input / output modules can be configured as components within the device (not shown in the figure) or externally connected to the device to provide corresponding functions. Input devices may include keyboards, mice, touchscreens, microphones, various sensors, etc., while output devices may include displays, speakers, vibrators, indicator lights, etc.

[0083] The communication interface 1040 is used to connect a communication module (not shown in the figure) to enable communication between this device and other devices. The communication module can communicate via wired means (such as USB, Ethernet cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.).

[0084] Bus 1050 includes a pathway for transmitting information between various components of the device, such as processor 1010, memory 1020, input / output interface 1030, and communication interface 1040.

[0085] It should be noted that although the above-described device only shows the processor 1010, memory 1020, input / output interface 1030, communication interface 1040, and bus 1050, in specific implementations, the device may also include other components necessary for normal operation. Furthermore, those skilled in the art will understand that the above-described device may only include the components necessary for implementing the embodiments of this specification, and not necessarily all the components shown in the figures.

[0086] The electronic devices described above are used to implement the corresponding security component generation method based on the low-code development framework in any of the foregoing embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0087] Based on the same inventive concept, corresponding to the methods of any of the above embodiments, this application also provides a non-transitory computer-readable storage medium that stores computer instructions for causing the computer to execute the security component generation method based on the low-code development framework as described in any of the above embodiments.

[0088] The computer-readable medium of this embodiment includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transfer medium that can be used to store information accessible by a computing device.

[0089] The computer instructions stored in the storage medium of the above embodiments are used to cause the computer to execute the security component generation method based on the low-code development framework as described in any of the above embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0090] Those skilled in the art should understand that the discussion of any of the above embodiments is merely exemplary and is not intended to imply that the scope of this application (including the claims) is limited to these examples; within the framework of this application, the technical features of the above embodiments or different embodiments can also be combined, the steps can be implemented in any order, and there are many other variations of different aspects of the embodiments of this application as described above, which are not provided in the details for the sake of brevity.

[0091] Additionally, to simplify the description and discussion, and to avoid obscuring the embodiments of this application, the well-known power / ground connections to integrated circuit (IC) chips and other components may or may not be shown in the provided drawings. Furthermore, the apparatus may be shown in block diagram form to avoid obscuring the embodiments of this application, and this also takes into account the fact that the details of the implementation of these block diagram apparatuses are highly dependent on the platform on which the embodiments of this application will be implemented (i.e., these details should be fully understood by those skilled in the art). While specific details (e.g., circuits) have been set forth to describe exemplary embodiments of this application, it will be apparent to those skilled in the art that the embodiments of this application can be implemented without these specific details or with variations thereof. Therefore, these descriptions should be considered illustrative rather than restrictive.

[0092] Although this application has been described in conjunction with specific embodiments thereof, many substitutions, modifications, and variations of these embodiments will be apparent to those skilled in the art from the foregoing description. For example, other memory architectures (e.g., dynamic RAM (DRAM)) may be used with the embodiments discussed.

[0093] The embodiments of this application are intended to cover all such substitutions, modifications, and variations that fall within the broad scope of the appended claims. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the embodiments of this application should be included within the protection scope of this application.

Claims

1. A method for generating security components based on a low-code development framework, characterized in that, include: Select at least one security policy method associated with each front-end control from a predefined front-end security parameter table; Select at least one security policy method associated with each backend interface from a predefined backend security parameter table; In response to determining that the low-code development framework generates software code, a security component is generated based on all security policy methods associated with all front-end controls and back-end interfaces involved in the software code; all security policy methods associated with all front-end controls and back-end interfaces involved in the software code call the corresponding security code from the low-code development database and write it into the corresponding position in the generated software code; all the security code written into the software code together constitute the security component. Before selecting at least one security policy method associated with each front-end control from a predefined front-end security parameter table, the process includes: Define the front-end security parameter table based on the aforementioned front-end controls and front-end security requirements; Define the backend security parameter table based on the backend interface and backend security requirements; Configure the security parameters in the front-end security parameter table and the back-end security parameter table. The security parameters include the security policy methods. It is necessary to establish a connection between the control information in the front-end security parameter table and the security policy methods. For each front-end control, a corresponding security policy method should be configured. Security policy methods corresponding to network attacks that the front-end control may encounter should be configured. Corresponding security parameters should be configured according to the types of network attacks that the back-end interface may encounter.

2. The method for generating security components based on a low-code development framework according to claim 1, characterized in that, Also includes: During the execution of the software code, the security component calls encryption and decryption algorithms from the low-code development platform's public component library to encrypt and decrypt the data interaction process between the front end and the back end.

3. The method for generating security components based on a low-code development framework according to claim 2, characterized in that, The encryption and decryption algorithms include: SM2 algorithm, SM3 algorithm, and SM4 algorithm.

4. The method for generating security components based on a low-code development framework according to claim 1, characterized in that, The security parameters in the front-end security parameter table include: control name, control type, security policy method, communication protocol, and control status.

5. The method for generating security components based on a low-code development framework according to claim 1, characterized in that, The security parameters in the backend security parameter table include: interface protocol, interface type, interface name, interface URL, field name, and security policy method.

6. A security component generation device based on a low-code development framework, characterized in that, include: The front-end association module is configured to select at least one security policy method associated with each front-end control from a predefined front-end security parameter table; The backend association module is configured to select at least one security policy method associated with each backend interface from a predefined backend security parameter table; The component generation module is configured to: in response to determining that the low-code development framework generates software code, generate a security component based on all security policy methods associated with all front-end controls and back-end interfaces involved in the software code; all security policy methods associated with all front-end controls and back-end interfaces involved in the software code call the corresponding security code from the low-code development database and write it into the corresponding position in the generated software code; all the security code written into the software code together constitutes the security component. Also includes: The front-end definition module is configured to define the front-end security parameter table based on the front-end controls and front-end security requirements. The backend definition module is configured to define the backend security parameter table based on the backend interface and backend security requirements. The parameter configuration module is configured to: configure security parameters in the front-end security parameter table and the back-end security parameter table, wherein the security parameters include the security policy methods; establish a connection between the control information in the front-end security parameter table and the security policy methods; configure a corresponding security policy method for each front-end control; configure security policy methods corresponding to network attacks that the front-end control may encounter; and configure corresponding security parameters according to the types of network attacks that the back-end interface may encounter.

7. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the method as described in any one of claims 1 to 5.

8. A non-transitory computer-readable storage medium storing computer instructions, characterized in that, The computer instructions are used to cause the computer to perform the method according to any one of claims 1 to 5.