A data processing method, an encryption device proxy terminal, and a main encryption device.

CN115632865BActive Publication Date: 2026-08-14LIANLIAN YINTONG ELECTRONIC PAYMENT CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-25
Publication Date
2026-08-14

AI Technical Summary

Technical Problem

但是,现有技术的每个金融终端都要部署状态探测程序去获取系统的运行状态,使得系统高耦合度,对金融终端的性能造成一定影响

Benefits of technology

[0057] The encryption device agent writes the target encryption result sent by the master encryption device into the non-abnormal message queue and the abnormal message queue. By consuming the target encryption result from the non-abnormal message queue and the abnormal message queue of the encryption device, the agent maintains the data consistency between the master encryption device and the slave encryption device, and avoids the failure of data decryption request processing after the master encryption device and the slave encryption device switch, which would affect the normal operation of the overall business system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115632865B_ABST
    Figure CN115632865B_ABST
Patent Text Reader

Abstract

This invention discloses a data processing method, an encryption device proxy, and a master encryption device. The method includes: receiving a data encryption request; sending the data encryption request to a first master encryption device; receiving a first target encryption result obtained by encrypting data to be encrypted from the first master encryption device; if it is determined that the storage space of a preset non-abnormal message queue does not meet a first preset condition, retrieving a target message from the preset non-abnormal message queue, migrating the target message from the preset non-abnormal message queue to a preset abnormal message queue, and writing the first target encryption result into the migrated preset non-abnormal message queue; the first target encryption result in the migrated preset non-abnormal message queue and the target message in the preset abnormal message queue are used for consumption by a first slave encryption device. This invention can ensure data consistency between the master encryption device and the slave encryption device and can improve the user experience.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer technology, and in particular to a data processing method, an encryption device proxy terminal, and a main encryption device. Background Technology

[0002] Currently, financial institutions such as banks, UnionPay, and third-party payment platforms widely use encryption machines to encrypt users' sensitive information. For example, existing technology discloses an encryption system that includes a financial terminal, a master encryption machine, a slave encryption machine, a master router, a slave router, and a server. The financial terminal is communicatively connected to both the master and slave encryption machines, the master encryption machine is communicatively connected to the master router, the slave encryption machine is communicatively connected to the slave router, and the server is communicatively connected to both the master and slave routers.

[0003] The aforementioned existing encryption systems, by establishing a master and slave encryption machine directly communicating with the financial terminal, allow the financial terminal to maintain encrypted communication with the service through the slave encryption machine in the event of a master encryption machine failure, effectively ensuring the security of sensitive data. However, each financial terminal in the existing technology requires the deployment of a status probe program to obtain the system's operational status, resulting in high system coupling and impacting the performance of the financial terminal. Furthermore, when switching between master and slave encryption machines, the existing technology cannot fully guarantee data consistency between the two, potentially leading to failures in processing data decryption requests after the switch, thus affecting enterprises and users. Summary of the Invention

[0004] To address at least one of the aforementioned technical problems, this invention provides a data processing method, an encryption device proxy, and a main encryption device.

[0005] According to one aspect of the present invention, a data processing method is proposed, the method comprising:

[0006] Receive a data encryption request, wherein the data encryption request carries the data to be encrypted;

[0007] Send the data encryption request to the first master encryption device;

[0008] Receive the first target encryption result obtained by encrypting the data to be encrypted by the first main encryption device;

[0009] If it is determined that the storage space of the preset non-abnormal message queue does not meet the first preset condition, the target message is obtained from the preset non-abnormal message queue, the target message is migrated from the preset non-abnormal message queue to the preset abnormal message queue, and the first target encryption result is written into the preset non-abnormal message queue after the message migration; the first target encryption result in the preset non-abnormal message queue after the message migration and the target message in the preset abnormal message queue are used to be consumed by the first encryption device.

[0010] In some possible implementations, the method further includes:

[0011] If the first slave encryption device fails to consume the first target encryption result in the preset non-abnormal message queue, and it is determined that the storage space of the preset abnormal message queue meets the second preset condition, the first target encryption result is written into the preset abnormal message queue, and the first target encryption result in the preset abnormal message queue is used to be consumed by the first slave encryption device.

[0012] In some possible implementations, the method further includes:

[0013] If the first slave encryption device fails to consume the first target encryption result in the preset non-abnormal message queue and it is determined that the storage space of the preset abnormal message queue does not meet the second preset condition, the first target encryption result is written to the preset storage device, and the first target encryption result in the preset storage device is used to be consumed by the first slave encryption device.

[0014] In some possible implementations, the method further includes:

[0015] If it is determined that the storage space of the preset non-abnormal message queue does not meet the first preset condition and the storage space of the preset abnormal message queue does not meet the second preset condition, the target message is obtained from the preset non-abnormal message queue, the target message is migrated from the preset non-abnormal message queue to the preset storage device, and the first target encryption result is written into the preset non-abnormal message queue after the message migration; the first target encryption result in the preset non-abnormal message queue after the message migration is used to be consumed by the first slave encryption device, and the target message in the preset storage device is used to be consumed by the first slave encryption device.

[0016] In some possible implementations, the method further includes:

[0017] If the storage space of the preset non-abnormal message queue meets the first preset condition, the first target encryption result is written into the preset non-abnormal message queue; the first target encryption result in the preset non-abnormal message queue is used to be consumed by the first slave encryption device.

[0018] In some possible implementations, before sending the data encryption request to the first primary encryption device, the method includes:

[0019] Identify the service status of the first master encryption device. If the service status identification result indicates that the first master encryption device is in an abnormal state, send a service status identification request to the first master encryption device based on a first preset frequency.

[0020] Receive service status identification information sent by the first master encryption device in response to the service status identification request;

[0021] If the number of times the first master encryption device is in an abnormal state within a first preset time period, as indicated by the business status identification information, meets a preset number threshold, it is determined that the first master encryption device is in an abnormal consistent state, and the first master encryption device and the first slave encryption device are switched. The abnormal consistent state is when the first master encryption device is in an abnormal state within a third preset time period.

[0022] In some possible implementations, controlling the switching between the first master encryption device and the first slave encryption device includes:

[0023] Control the first slave encryption device to switch to the second master encryption device;

[0024] The service status of the first master encryption device is determined to be down, so that the first master encryption device generates an alarm log corresponding to the down status;

[0025] Receive the alarm log sent by the first main encryption device;

[0026] If the service status of the first master encryption device is determined to be non-abnormal, the first master encryption device is controlled to switch to the second slave encryption device; the non-abnormal status is obtained by updating the downtime status based on the alarm log.

[0027] In some possible implementations, after the control of switching between the first master encryption device and the first slave encryption device, the method includes:

[0028] A data encryption request is sent to the second master encryption device so that the second master encryption device can encrypt the data to be encrypted to obtain a second target encryption result;

[0029] The second target encryption result is written into the preset non-abnormal message queue, the preset abnormal message queue, and the preset storage device, so that the second slave encryption device sequentially consumes the second target encryption result from the preset non-abnormal message queue, the preset abnormal message queue, and the preset storage device.

[0030] In some possible implementations, identifying the service status of the first master encryption device includes:

[0031] The service status identification request is sent to the first main encryption device based on the second preset frequency;

[0032] If no response information is received from the first primary encryption device in response to the service status identification request within the second preset time period, the service status identification result of the first primary encryption device is determined to be an identification result indicating that the first primary encryption device is in an abnormal state.

[0033] If, within the second preset time period, a response information sent by the first master encryption device in response to the service status identification request is received, the response information is analyzed, and the service status identification result of the first master encryption device is determined based on the analysis result of the response information.

[0034] In some possible implementations, the method includes:

[0035] If the business status identification result indicates that the first main encryption device is in an abnormal state, and the business status identification information indicates that the number of times the first main encryption device is in an abnormal state within the first preset time period does not meet the preset number threshold, then it is determined that the first main encryption device is in an abnormal state where the performance does not meet the third preset condition, so that the first main encryption device encrypts the data to be encrypted to obtain the first target encryption result.

[0036] According to a second aspect of the present invention, another data processing method is proposed, the method comprising:

[0037] Receive a data encryption request sent by the encryption device agent, wherein the data encryption request carries the data to be encrypted;

[0038] The data to be encrypted is then encrypted to obtain the first target encryption result;

[0039] The first target encryption result is sent to the encryption device agent; so that the encryption device agent, when determining that the storage space of the preset non-abnormal message queue does not meet the first preset condition, obtains the target message from the preset non-abnormal message queue, and migrates the target message from the preset non-abnormal message queue to the preset abnormal message queue, and writes the first target encryption result into the preset non-abnormal message queue after message migration; the first target encryption result in the preset non-abnormal message queue after message migration and the target message in the preset abnormal message queue are used to be consumed by the first slave encryption device.

[0040] In some possible implementations, prior to receiving the data encryption request sent by the encryption device proxy, the method includes:

[0041] The encryption device agent receives a service status identification request sent at a first preset frequency when it identifies the service status of the first main encryption device and the service status identification result indicates that the first main encryption device is in an abnormal state.

[0042] In response to the service status identification request, the encryption device agent sends service status identification information to the encryption device agent so that the encryption device agent determines that the first master encryption device is in an abnormal state of abnormal consistency when the number of times the service status identification information indicates that the first master encryption device is in an abnormal state within a first preset time period meets a preset number threshold, and so that the encryption device agent controls the first master encryption device to switch with the first slave encryption device.

[0043] The abnormal consistency state refers to the first main encryption device being in an abnormal state within a third preset time period.

[0044] In some possible implementations, the encryption device proxy identifies the service status of the first master encryption device by including:

[0045] Receive the service status identification request sent by the encryption device agent at a second preset frequency;

[0046] If no response information in response to the service status identification request is sent to the encryption device agent within the second preset time period, the encryption device agent shall determine that the service status identification result of the first main encryption device is an identification result indicating that the first main encryption device is in an abnormal state.

[0047] If, during the second preset time period, a response message in response to the service status identification request is sent to the encryption device agent, the encryption device agent will analyze the response message and determine the service status identification result of the first main encryption device based on the analysis result of the response message.

[0048] According to a third aspect of the present invention, an encryption device proxy is provided, the encryption device proxy comprising:

[0049] The request receiving module is used to receive data encryption requests sent by the client, wherein the data encryption requests carry data to be encrypted;

[0050] The request sending module is used to send the data encryption request to the first main encryption device;

[0051] The data receiving module is used to receive the first target encryption result obtained by encrypting the data to be encrypted, sent by the first main encryption device;

[0052] The data storage module is configured to, when determining that the storage space of the preset non-abnormal message queue does not meet a first preset condition, retrieve a target message from the preset non-abnormal message queue, migrate the target message from the preset non-abnormal message queue to a preset abnormal message queue, and write the first target encryption result into the preset non-abnormal message queue after message migration; the first target encryption result in the preset non-abnormal message queue after message migration and the target message in the preset abnormal message queue are used to be consumed by the first encryption device.

[0053] According to a fourth aspect of the present invention, a master encryption device is provided, the master encryption device comprising:

[0054] The data encryption module is used to receive a data encryption request sent by the encryption device agent, wherein the data encryption request carries data to be encrypted; and to encrypt the data to be encrypted to obtain a first target encryption result.

[0055] A data sending module is configured to send the first target encryption result to the encryption device agent; so that the encryption device agent, when determining that the storage space of the preset non-abnormal message queue does not meet a first preset condition, retrieves the target message from the preset non-abnormal message queue; and so that the encryption device agent migrates the target message from the preset non-abnormal message queue to a preset abnormal message queue; and so that the encryption device agent writes the first target encryption result into the preset non-abnormal message queue after message migration; the first target encryption result in the preset non-abnormal message queue after message migration and the target message in the preset abnormal message queue are used to be consumed by the first slave encryption device.

[0056] Implementing this invention has the following beneficial effects:

[0057] The encryption device agent writes the target encryption result sent by the master encryption device into the non-abnormal message queue and the abnormal message queue. By consuming the target encryption result from the non-abnormal message queue and the abnormal message queue of the encryption device, the agent maintains the data consistency between the master encryption device and the slave encryption device, and avoids the failure of data decryption request processing after the master encryption device and the slave encryption device switch, which would affect the normal operation of the overall business system. Attached Figure Description

[0058] To more clearly illustrate the technical solutions of this application, the drawings used in the description of the embodiments or prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0059] Figure 1 This is a schematic diagram of the implementation environment of a data processing method provided in an embodiment of the present invention;

[0060] Figure 2 This is a flowchart illustrating a data processing method provided in an embodiment of the present invention;

[0061] Figure 3 This is a schematic diagram of the business status identification process provided in an embodiment of the present invention;

[0062] Figure 4 This is a flowchart illustrating another data processing method provided in an embodiment of the present invention. Figure 1 ;

[0063] Figure 5 This is a flowchart illustrating another data processing method provided in an embodiment of the present invention. Figure 2 ;

[0064] Figure 6 This is a schematic diagram of the structure of a data processing encryption device proxy terminal provided in an embodiment of the present invention;

[0065] Figure 7 This is a schematic diagram of the structure of a main encryption device for data processing provided in an embodiment of the present invention. Detailed Implementation

[0066] To enable those skilled in the art to better understand the technical solutions in this application, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0067] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or server that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or devices.

[0068] Various exemplary embodiments, features, and aspects of this disclosure will now be described in detail with reference to the accompanying drawings. The same reference numerals in the drawings denote elements that have the same or similar functions. Although various aspects of the embodiments are shown in the drawings, they are not necessarily drawn to scale unless specifically indicated otherwise.

[0069] The term “exemplary” as used herein means “serving as an example, embodiment, or illustration.” Any embodiment illustrated herein as “exemplary” is not necessarily to be construed as superior to or better than other embodiments.

[0070] In this document, the term "and / or" is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent three cases: A alone, A and B simultaneously, and B alone. Furthermore, the term "at least one" in this document means any combination of at least two of any one or more elements. For example, including at least one of A, B, and C can mean including any one or more elements selected from the set consisting of A, B, and C.

[0071] Furthermore, to better illustrate this disclosure, numerous specific details are set forth in the following detailed description. Those skilled in the art will understand that this disclosure can be practiced without certain specific details. In some instances, methods, means, components, and circuits well known to those skilled in the art have not been described in detail in order to highlight the main points of this disclosure.

[0072] Figure 1 This is a schematic diagram illustrating the implementation environment of a data processing method provided in an embodiment of the present invention. For example... Figure 1 As shown, this implementation environment includes at least a client, an encryption device proxy, a master encryption device, and a slave encryption device. The client and the encryption device proxy, the encryption device proxy and the master encryption device, and the encryption proxy and the slave encryption device can be directly or indirectly connected via wired or wireless communication, which is not limited herein. For example, the client can send a data encryption request to the encryption device proxy via wired or wireless communication, the encryption device proxy can send a data encryption request to the master encryption device via wired or wireless communication, and the master encryption device can return the data encryption result to the encryption device proxy via wired or wireless communication, etc.

[0073] It should be noted that, Figure 1 This is just one example.

[0074] Figure 2 This is a flowchart illustrating a data processing method provided in an embodiment of the present invention. This method can be used for... Figure 1 In the implementation environment described in the embodiments or flowcharts, the present invention provides the method operation steps as shown in the examples or flowcharts, but based on conventional or non-inventive labor, more or fewer operation steps may be included. The order of steps listed in the embodiments is merely one of many possible execution orders and does not represent the only possible execution order. Specifically, as shown in the examples... Figure 2 As shown, the method may include:

[0075] Step S101: The encryption device agent receives a data encryption request sent by the client, the data encryption request carrying the data to be encrypted;

[0076] Specifically, the client may include, but is not limited to, smartphones, tablets, laptops, desktop computers, smartwatches, smart home appliances, etc.; the data to be encrypted may include, but is not limited to, personal identification information, passwords, personal photos, etc.

[0077] Step S102: The encryption device agent sends a data encryption request to the first main encryption device agent;

[0078] In this embodiment of the invention, the client sends a data encryption request to the encryption device proxy. Upon receiving the data encryption request, the encryption device proxy forwards it to the first primary encryption device. The data encryption request also carries a first key identifier, which is used to generate a corresponding key for the data to be encrypted, thereby enabling the encryption of the data.

[0079] Step S103: The first master encryption device encrypts the data to be encrypted to obtain the first target encryption result;

[0080] In this embodiment of the invention, the first master encryption device generates a key based on the first key identifier and encrypts the data to be encrypted using an encryption algorithm to obtain the first target encryption result.

[0081] Step S104: The first master encryption device sends the encryption result of the first target to the encryption device agent.

[0082] In this embodiment of the invention, after processing the data encryption request, the first master encryption device sends the key, the first target encryption result, and the correspondence between the first key identifier and the key and the first target result to the encryption device agent.

[0083] Step S105: When the encryption device agent determines that the storage space of the preset non-abnormal message queue does not meet the first preset condition, it retrieves the target message from the preset non-abnormal message queue, migrates the target message from the preset non-abnormal message queue to the preset abnormal message queue, and writes the first target encryption result into the preset non-abnormal message queue after message migration; the first target encryption result in the preset non-abnormal message queue after message migration and the target message in the preset abnormal message queue are used to be consumed by the first slave encryption device.

[0084] In this embodiment of the invention, the storage space of the preset non-abnormal message queue does not meet the first preset condition, i.e., the storage space of the preset non-abnormal message queue is insufficient to write the next message. The encryption device agent needs to write the key, the first target encryption result, and the correspondence between the first key identifier and the key and the first target result into the preset non-abnormal message queue. However, if the storage space of the preset non-abnormal message queue is insufficient to continue writing messages, the encryption device agent will retrieve the target message from the preset non-abnormal message queue and migrate the target message from the preset non-abnormal message queue to the preset abnormal message queue. At this time, the storage space of the preset non-abnormal message queue is sufficient to continue storing messages, and the encryption device agent can write the key, the first target encryption result, and the correspondence between the first key identifier and the key and the first target result into the preset non-abnormal message queue. At this time, the key, the first target encryption result, and the correspondence between the first key identifier and the key and the first target result in the preset abnormal message queue, and the target message in the preset abnormal message queue, are waiting to be consumed by the first slave encryption device, so that the data of the first master encryption device and the first slave encryption device remain consistent.

[0085] In a specific embodiment, the target message may be a preset number of keys that have not yet been consumed by the first encryption device, a first target encryption result, and the correspondence between the first key identifier and the key and the first target result; the specific storage space of the preset non-abnormal message queue and the preset abnormal queue is determined according to the actual situation.

[0086] In an optional embodiment, if the first slave encryption device fails to consume the first target encryption result in the preset non-abnormal message queue and it is determined that the storage space of the preset abnormal message queue meets the second preset condition, the first target encryption result is written into the preset abnormal message queue, and the first target encryption result in the preset abnormal message queue is used to be consumed by the first slave encryption device.

[0087] In an optional embodiment, if the first slave encryption device fails to consume the first target encryption result in the preset non-abnormal message queue and it is determined that the storage space of the preset abnormal message queue does not meet the second preset condition, the first target encryption result is written to a preset storage device, and the first target encryption result in the preset storage device is used to be consumed by the first slave encryption device.

[0088] In this embodiment of the invention, the storage space of the preset abnormal message queue does not meet the second preset condition, i.e., the storage space of the preset abnormal message queue is insufficient to write the next message. If the first slave encryption device fails to consume the first target encryption result in the preset non-abnormal queue, the encryption device proxy determines whether the storage space of the preset abnormal message queue is sufficient to continue writing messages. If the storage space of the preset abnormal message queue is sufficient to continue writing messages, the encryption device proxy writes the unconsumed first target encryption result into the preset abnormal message queue to await re-consumption by the first slave encryption device. If the storage space of the preset abnormal message queue is insufficient, the encryption device proxy writes the unconsumed first target encryption result into the preset storage device to await consumption by the first slave encryption device, maintaining data consistency between the master encryption device and the slave encryption device.

[0089] In an optional embodiment, if it is determined that the storage space of the preset non-abnormal message queue does not meet a first preset condition and the storage space of the preset abnormal message queue does not meet a second preset condition, the target message is obtained from the preset non-abnormal message queue, the target message is migrated from the preset non-abnormal message queue to the preset storage device, and the first target encryption result is written into the preset non-abnormal message queue after the message migration; the first target encryption result in the preset non-abnormal message queue after the message migration is used to be consumed by the first slave encryption device, and the target message in the preset storage device is used to be consumed by the first slave encryption device.

[0090] In an optional embodiment, if it is determined that the storage space of the preset non-abnormal message queue meets the first preset condition, the first target encryption result is written into the preset non-abnormal message queue; the first target encryption result in the preset non-abnormal message queue is used to be consumed by the first encryption device.

[0091] In this embodiment of the invention, when the encryption device proxy writes the first target encryption result, if it determines that the storage space of both the preset non-abnormal message queue and the preset abnormal message queue is insufficient to continue writing the first target encryption result, the encryption device proxy writes the first target encryption result to the preset storage device for consumption by the first slave encryption device, thus maintaining data consistency between the master encryption device and the slave encryption device. If the storage space of the preset non-abnormal message queue is sufficient, the encryption device proxy directly writes the first target encryption result to the preset non-abnormal message queue for consumption by the first slave encryption device, maintaining data consistency between the master encryption device and the slave encryption device.

[0092] In an optional embodiment, Figure 3 This is a schematic diagram of the business status identification process, such as... Figure 3 As shown, before the first primary encryption device encrypts the data to be encrypted to obtain the first target encryption result, the process includes:

[0093] Step S1001: The encryption device agent sends a service status identification request to the first main encryption device based on the second preset frequency;

[0094] In this embodiment of the invention, the preset frequency is specifically set according to the fault tolerance of the data encryption business requirements of the first master encryption device. The encryption device agent sends a business status identification request to the first master encryption device based on the second preset frequency. The encryption device agent identifies the business status of the first master encryption device and determines whether the first master encryption device is in an abnormal state. If the first master encryption device is in an abnormal state, the encryption device agent can handle it in time to avoid affecting the processing of business requirements.

[0095] Step S1002: During the second preset time period, the first main encryption device does not send a response to the service status identification request to the encryption device agent.

[0096] In this embodiment of the invention, the preset time period is specifically set according to the fault tolerance requirements of the business needs of data encryption by the first main encryption device.

[0097] Step S1003: The encryption device agent determines that the business status identification result of the first main encryption device is an identification result indicating that the first main encryption device is in an abnormal state;

[0098] In this embodiment of the invention, if the first primary encryption device does not send a response to the service status identification request to the encryption device proxy during the second preset time period, the encryption device proxy will determine that the first primary encryption device is in an abnormal state.

[0099] In an optional embodiment, during a second preset time period, the first master encryption device sends a response message in response to the service status identification request to the encryption device agent. The encryption device agent analyzes the response message and determines the service status identification result of the first master encryption device based on the analysis result of the response message.

[0100] In this embodiment of the invention, within a second preset time period, the first master encryption device sends response information in response to the service status identification request to the encryption device agent. The encryption device agent determines the service status identification result of the first master encryption device by analyzing the response information.

[0101] Step S1004: The encryption device agent sends a service status identification request to the first main encryption device based on the first preset frequency;

[0102] In this embodiment of the invention, when the encryption device agent determines that the first main encryption device is in an abnormal state, it re-identifies the business status of the first main encryption device to further determine the business status of the first main encryption device.

[0103] Step S1005: The first master encryption device responds to the service status identification request;

[0104] Step S1006: The first master encryption device sends service status identification information to the encryption device agent.

[0105] Step S1007: If the number of times the business status identification information indicates that the first main encryption device is in an abnormal state within the first preset time period meets the preset number threshold, the encryption device agent determines that the first main encryption device is in an abnormal state of consistent abnormality.

[0106] In this embodiment of the invention, the preset number of times threshold is specifically set according to the fault tolerance requirements of the first main encryption device for data encryption.

[0107] In an optional embodiment, if the service status identification result indicates that the first main encryption device is in an abnormal state, and the number of times the service status identification information indicates that the first main encryption device is in an abnormal state within the first preset time period does not meet the preset number threshold, the encryption device agent determines that the first main encryption device is in an abnormal state where the performance does not meet the third preset condition, and the first main encryption device encrypts the data to be encrypted to obtain the first target encryption result.

[0108] In this embodiment of the invention, the abnormal state of the first master encryption device has two specific states: one is the abnormal consistency state, in which the first master encryption device is always in an abnormal state and cannot process data encryption requests; the other is the performance unstable state, in which the first master encryption device can process data encryption requests.

[0109] Step S1008: The encryption device agent determines that the service status of the first main encryption device is down.

[0110] Step S1009: The first main encryption device generates an alarm log corresponding to the downtime status;

[0111] Step S1010: The first master encryption device sends an alarm log to the encryption device agent.

[0112] In this embodiment of the invention, the encryption device agent determines that the service status of the first primary encryption device is down, causing the first primary encryption device to stop working. The first primary encryption device generates an alarm log corresponding to the downtime status and sends the alarm log to the encryption device agent so that the operation and maintenance personnel know that the first primary encryption device cannot continue to process data encryption requests, thereby repairing the first primary encryption device as soon as possible and enabling the first primary encryption device to work normally.

[0113] Step S1011: The encryption device agent controls the first slave encryption device to switch to the second master encryption device;

[0114] In this embodiment of the invention, since the first master encryption device is in an abnormal consistency state and cannot work properly, in order to avoid affecting the normal processing of data encryption requests, the encryption device proxy will switch the first slave encryption device, which can work properly, to the second master encryption device.

[0115] Step S1012: When the encryption device agent determines that the business status of the first master encryption device is not abnormal, it controls the first master encryption device to switch to the second slave encryption device.

[0116] In this embodiment of the invention, the service status of the first master encryption device is restored to a non-abnormal state by the operation and maintenance personnel. After the encryption device agent determines that the service status of the first master encryption device is a non-abnormal state, it controls the first master encryption device to switch to the second slave encryption device.

[0117] In an optional embodiment, the encryption device agent sends a data encryption request to the second master encryption device, and the second master encryption device encrypts the data to be encrypted to obtain the second target encryption result;

[0118] The encryption device agent writes the second target encryption result into a preset non-abnormal message queue, a preset abnormal message queue, and a preset storage device. The second slave encryption device sequentially consumes the second target encryption result from the non-abnormal message queue, the preset abnormal message queue, and the preset storage device.

[0119] In this embodiment of the invention, after the encryption device agent controls the first slave encryption device to switch to the second master encryption device, the second master encryption device continues to process data encryption requests and encrypts the data to be encrypted to obtain the target encryption result. The encryption device agent controls the first master encryption device to switch to the second slave encryption device, and the second slave encryption device consumes the target encryption result from the preset non-abnormal message queue, the preset abnormal message queue, and the preset storage device, thereby maintaining the data consistency between the second master encryption device and the second slave encryption device.

[0120] The following explanation uses a POS machine transaction as an example to illustrate the above steps:

[0121] The POS machine sends a data encryption request to the encryption device agent. The data encryption request includes the transaction message and the key identifier.

[0122] The encryption device proxy identifies the service status of the main encryption device:

[0123] The encryption device agent sends a Hyper Text Transfer Protocol HEAD (HTTP HEAD) request to the main encryption device every 2 seconds.

[0124] After receiving the HTTP HEAD request, the master encryption device responds.

[0125] If the encryption device agent does not receive a response within 3 seconds, the main encryption device is in an abnormal state.

[0126] At this time, the encryption device agent sends an HTTP HEAD request to the abnormal master encryption device every second. If the encryption device agent determines that the master encryption device is in an abnormal state 3 times within 40 seconds, the master encryption device is in an abnormal consistency state, the master encryption device is in a crash state, and an alarm log is sent to the encryption device agent; the encryption device is then switched to the master encryption device.

[0127] If the encryption device agent receives a response within 3 seconds, it analyzes the Hypertext Transfer Protocol (HTTP) status code and determines the status of the main encryption device based on the HTTP status code.

[0128] When the master encryption device processes a data encryption request in a non-abnormal state, it successfully processes the request and sends the encryption result to the encryption device agent. The agent writes the result to the non-abnormal message queue, awaiting consumption by the slave encryption device, thus maintaining data consistency between the master and slave encryption devices. If the non-abnormal message queue has insufficient storage space, the agent migrates some unconsumed encryption results from the queue to the abnormal message queue; if the abnormal message queue has insufficient storage space, the agent migrates some unconsumed results to the storage device. The encryption results in both the abnormal message queue and the storage device await consumption by the slave encryption device, maintaining data consistency between the master and slave encryption devices. If the slave encryption device fails to consume an encryption result from its message queue, the agent writes the failed result to the abnormal message queue; if the abnormal message queue has insufficient storage space, the agent writes the failed result to the storage device. The encryption results in both the abnormal message queue and the storage device await consumption by the slave encryption device, ensuring consistency between the master and slave encryption devices.

[0129] When the primary encryption device is down, the secondary encryption device switches to the primary encryption device to process data encryption requests. The encryption results in the non-abnormal message queue, abnormal message queue, and storage device are switched to the secondary encryption device for consumption by the primary encryption device that has recovered from the downtime to a non-abnormal state, thus maintaining consistency between the primary and secondary encryption devices.

[0130] The following explanation uses the encrypted device's proxy end as the executing entity to illustrate this data processing method:

[0131] Figure 4 The diagram shown is a flowchart of another data processing method provided by an embodiment of the present invention. Figure 1 ,like Figure 4 As shown, the method may include;

[0132] Step S201: Receive a data encryption request sent by the client, the data encryption request carrying the data to be encrypted;

[0133] Step S202: Send a data encryption request to the first master encryption device;

[0134] Step S203: Receive the first target encryption result obtained by encrypting the data to be encrypted from the first master encryption device;

[0135] Step S204: If it is determined that the storage space of the preset non-abnormal message queue does not meet the first preset condition, the target message is obtained from the preset non-abnormal message queue, the target message is migrated from the preset non-abnormal message queue to the preset abnormal message queue, and the first target encryption result is written into the preset non-abnormal message queue after the message migration; the first target encryption result in the preset non-abnormal message queue after the message migration and the target message in the preset abnormal message queue are used to be consumed by the first encryption device.

[0136] Specifically, if the first slave encryption device fails to consume the first target encryption result in the preset non-abnormal message queue and it is determined that the storage space of the preset abnormal message queue meets the second preset condition, the first target encryption result is written into the preset abnormal message queue, and the first target encryption result in the preset abnormal message queue is used to be consumed by the first slave encryption device.

[0137] Specifically, if the first slave encryption device fails to consume the first target encryption result in the preset non-abnormal message queue and it is determined that the storage space of the preset abnormal message queue does not meet the second preset condition, the first target encryption result is written to the preset storage device, and the first target encryption result in the preset storage device is used to be consumed by the first slave encryption device.

[0138] Specifically, when it is determined that the storage space of the preset non-abnormal message queue does not meet the first preset condition and the storage space of the preset abnormal message queue does not meet the second preset condition, the target message is obtained from the preset non-abnormal message queue, the target message is migrated from the preset non-abnormal message queue to the preset storage device, and the first target encryption result is written into the preset non-abnormal message queue after the message migration; the first target encryption result in the preset non-abnormal message queue after the message migration is used to be consumed by the first slave encryption device, and the target message in the preset storage device is used to be consumed by the first slave encryption device.

[0139] Specifically, when it is determined that the storage space of the preset non-abnormal message queue meets the first preset condition, the first target encryption result is written into the preset non-abnormal message queue; the first target encryption result in the preset non-abnormal message queue is used to be consumed by the first slave encryption device.

[0140] Specifically, the sequence preceding S202 may include:

[0141] Identify the service status of the first master encryption device. If the service status identification result indicates that the first master encryption device is in an abnormal state, send a service status identification request to the first master encryption device based on a first preset frequency.

[0142] Receive service status identification information sent by the first master encryption device in response to the service status identification request;

[0143] If the number of times the first master encryption device is in an abnormal state within a first preset time period, as indicated by the business status identification information, meets the preset number threshold, it is determined that the first master encryption device is in an abnormal consistent state, and the first master encryption device and the first slave encryption device are switched. The abnormal consistent state is when the first master encryption device is in an abnormal state within a third preset time period.

[0144] Specifically, if the business status identification result indicates that the first main encryption device is in an abnormal state, and the business status identification information indicates that the number of times the first main encryption device is in an abnormal state within the first preset time period does not meet the preset number threshold, then the first main encryption device is determined to be in an abnormal state where the performance does not meet the third preset condition, so that the first main encryption device can encrypt the data to be encrypted to obtain the first target encryption result.

[0145] Specifically, controlling the switching between the first master encryption device and the first slave encryption device includes:

[0146] Control the switching of the first primary encryption device to the second primary encryption device;

[0147] The service status of the first master encryption device is determined to be down, so that the first master encryption device generates an alarm log corresponding to the down status;

[0148] Receive alarm logs sent by the first master encryption device;

[0149] If the service status of the first master encryption device is determined to be non-abnormal, the first master encryption device is controlled to switch to the second slave encryption device; the non-abnormal status is obtained by updating the downtime status based on the alarm log.

[0150] Specifically, a data encryption request is sent to the second master encryption device so that the second master encryption device can encrypt the data to be encrypted to obtain the second target encryption result;

[0151] The second target encryption result is written into a preset non-abnormal message queue, a preset abnormal message queue, and a preset storage device, so that the second slave encryption device sequentially consumes the second target encryption result in the preset non-abnormal message queue, the preset abnormal message queue, and the preset storage device.

[0152] Specifically, identifying the service status of the first master encryption device includes:

[0153] A service status identification request is sent to the first main encryption device based on the second preset frequency;

[0154] If no response information is received from the first main encryption device in response to the service status identification request within the second preset time period, the service status identification result of the first main encryption device is determined to be an identification result indicating that the first main encryption device is in an abnormal state.

[0155] Within the second preset time period, upon receiving the response information sent by the first main encryption device in response to the service status identification request, the response information is analyzed, and the service status identification result of the first main encryption device is determined based on the analysis result of the response information.

[0156] The following explanation uses the main encryption device as the executing entity to describe this data processing method:

[0157] Figure 5 The diagram shown is a flowchart of another data processing method provided by an embodiment of the present invention. Figure 2 ,like Figure 5 As shown, the method may include:

[0158] Step S301: Receive a data encryption request sent by the encryption device agent, the data encryption request carrying the data to be encrypted;

[0159] Step S302: Encrypt the data to be encrypted to obtain the first target encryption result;

[0160] Step S303: Send the first target encryption result to the encryption device agent; so that the encryption device agent obtains the target message from the preset non-abnormal message queue when it determines that the storage space of the preset non-abnormal message queue does not meet the first preset condition, and so that the encryption device agent migrates the target message from the preset non-abnormal message queue to the preset abnormal message queue, and so that the encryption device agent writes the first target encryption result into the preset non-abnormal message queue after message migration; the first target encryption result in the preset non-abnormal message queue after message migration and the target message in the preset abnormal message queue are used to be consumed by the first slave encryption device.

[0161] Specifically, the sequence preceding S301 may include:

[0162] The encryption device agent receives a service status identification request sent at a first preset frequency when it identifies the service status of the first main encryption device and the service status identification result indicates that the first main encryption device is in an abnormal state.

[0163] In response to the service status identification request, service status identification information is sent to the encryption device agent terminal, so that the encryption device agent terminal determines that the first master encryption device is in an abnormal state of abnormal consistency when the number of times the service status identification information indicates that the first master encryption device is in an abnormal state within a first preset time period meets a preset number threshold, and so that the encryption device agent terminal controls the first master encryption device to switch with the first slave encryption device.

[0164] An abnormal consistency state is when the first main encryption device is in an abnormal state within a third preset time period.

[0165] Specifically, the encryption device proxy identifies the business status of the first primary encryption device by including:

[0166] Receive a service status identification request sent by the encryption device agent based on a second preset frequency;

[0167] If no response information in response to the service status identification request is sent to the encryption device agent within the second preset time period, the encryption device agent shall determine that the service status identification result of the first main encryption device is an identification result indicating that the first main encryption device is in an abnormal state.

[0168] If, during the second preset time period, a response message in response to the service status identification request is sent to the encryption device agent, the encryption device agent will analyze the response message and determine the service status identification result of the first main encryption device based on the analysis result of the response message.

[0169] like Figure 6 As shown, this embodiment of the invention also provides a data processing encryption device proxy, which may include:

[0170] Request receiving module 401: Used to receive data encryption requests sent by the client, the data encryption requests carrying data to be encrypted;

[0171] Request sending module 402: Used to send a data encryption request to the first main encryption device;

[0172] Data receiving module 403: used to receive the first target encryption result obtained by encrypting the data to be encrypted sent by the first main encryption device;

[0173] Data storage module 404: When it is determined that the storage space of the preset non-abnormal message queue does not meet the first preset condition, it retrieves the target message from the preset non-abnormal message queue, migrates the target message from the preset non-abnormal message queue to the preset abnormal message queue, and writes the first target encryption result into the preset non-abnormal message queue after message migration; the first target encryption result in the preset non-abnormal message queue after message migration and the target message in the preset abnormal message queue are used to be consumed by the first encryption device.

[0174] Specifically, the encryption device proxy may also include:

[0175] First message consumption failure handling module: When the first slave encryption device fails to consume the first target encryption result in the preset non-abnormal message queue and it is determined that the storage space of the preset abnormal message queue meets the second preset condition, the first target encryption result is written into the preset abnormal message queue, and the first target encryption result in the preset abnormal message queue is used to be consumed by the first slave encryption device.

[0176] Specifically, the encryption device proxy may also include:

[0177] The second message consumption failure handling module is used to write the first target encryption result into a preset storage device when the first slave encryption device fails to consume the first target encryption result in the preset non-abnormal message queue and it is determined that the storage space of the preset abnormal message queue does not meet the second preset condition. The first target encryption result in the preset storage device is used to be consumed by the first slave encryption device.

[0178] Specifically, the encryption device proxy may also include:

[0179] First data storage module: When it is determined that the storage space of the preset non-abnormal message queue does not meet the first preset condition and the storage space of the preset abnormal message queue does not meet the second preset condition, the module retrieves the target message from the preset non-abnormal message queue, migrates the target message from the preset non-abnormal message queue to the preset storage device, and writes the first target encryption result into the preset non-abnormal message queue after the message migration; the first target encryption result in the preset non-abnormal message queue after the message migration is used to be consumed by the first slave encryption device, and the target message in the preset storage device is used to be consumed by the first slave encryption device.

[0180] Specifically, the encryption device proxy may also include:

[0181] The second data storage module is used to write the first target encryption result into the preset non-abnormal message queue when the storage space of the preset non-abnormal message queue meets the first preset condition; the first target encryption result in the preset non-abnormal message queue is used to be consumed by the first slave encryption device.

[0182] Specifically, the following may be included before the request sending module 402:

[0183] First business status identification request sending module: used to identify the business status of the first main encryption device, and when the business status identification result indicates that the first main encryption device is in an abnormal state, send a business status identification request to the first main encryption device based on a first preset frequency.

[0184] Service status identification information receiving module: used to receive service status identification information sent by the first main encryption device in response to the service status identification request;

[0185] Encryption device switching module: When the number of times the first master encryption device is in an abnormal state within a first preset time period, as indicated by the business status identification information, meets a preset number threshold, the module determines that the first master encryption device is in an abnormal consistent state, and controls the switching between the first master encryption device and the first slave encryption device. The abnormal consistent state is when the first master encryption device is in an abnormal state within a third preset time period.

[0186] Specifically, the encryption device switching module may include:

[0187] First control module: used to control the switching of the first slave encryption device to the second master encryption device;

[0188] Alarm log receiving module: used to determine that the service status of the first master encryption device is down, so that the first master encryption device generates an alarm log corresponding to the down status; and to receive the alarm log sent by the first master encryption device;

[0189] The second control module is used to control the first master encryption device to switch to the second slave encryption device when the service status of the first master encryption device is determined to be non-abnormal. The non-abnormal status is obtained by updating the downtime status based on the alarm log.

[0190] Specifically, the encryption device can include the following after switching modules:

[0191] First request sending module: used to send a data encryption request to the second master encryption device, so that the second master encryption device can encrypt the data to be encrypted to obtain the second target encryption result;

[0192] The third data storage module is used to write the second target encryption result into a preset non-abnormal message queue, a preset abnormal message queue, and a preset storage device, so that the second slave encryption device can sequentially consume the second target encryption result in the preset non-abnormal message queue, the preset abnormal message queue, and the preset storage device.

[0193] Specifically, identifying the service status of the first master encryption device may include:

[0194] Second service status identification request sending module: used to send a service status identification request to the first main encryption device based on a second preset frequency;

[0195] The first business status identification result determination module is used to determine the business status identification result of the first main encryption device as an identification result indicating that the first main encryption device is in an abnormal state if no response information sent by the first main encryption device in response to the business status identification request is received within the second preset time period; and to analyze the response information and determine the business status identification result of the first main encryption device based on the response information analysis result if a response information sent by the first main encryption device in response to the business status identification request is received within the second preset time period.

[0196] Specifically, the module prior to request sending module 402 may also include:

[0197] Abnormal State Determination Module: When the business state identification result indicates that the first main encryption device is in an abnormal state, and the number of times the business state identification information indicates that the first main encryption device is in an abnormal state within a first preset time period does not meet the preset number threshold, the module determines that the first main encryption device is in an abnormal state where the performance does not meet the third preset condition, so that the first main encryption device can encrypt the data to be encrypted to obtain the first target encryption result.

[0198] like Figure 7 As shown, this embodiment of the invention also provides a main data processing encryption device, which may include:

[0199] Data encryption module 501: Used to receive data encryption requests sent by the encryption device agent, the data encryption requests carrying the data to be encrypted; and to encrypt the data to be encrypted to obtain the first target encryption result;

[0200] Data sending module 502: used to send a first target encryption result to the encryption device agent; so that the encryption device agent can obtain the target message from the preset non-abnormal message queue when it determines that the storage space of the preset non-abnormal message queue does not meet the first preset condition, and so that the encryption device agent can migrate the target message from the preset non-abnormal message queue to the preset abnormal message queue, and so that the encryption device agent can write the first target encryption result into the preset non-abnormal message queue after message migration; the first target encryption result in the preset non-abnormal message queue after message migration and the target message in the preset abnormal message queue are used to be consumed by the first slave encryption device.

[0201] Specifically, the data encryption module 501 may include:

[0202] First Business Status Identification Request Receiving Module: Used to receive a business status identification request sent by the encryption device agent based on a first preset frequency when the business status of the first main encryption device is identified and the business status identification result indicates that the first main encryption device is in an abnormal state.

[0203] The business status identification information sending module is used to respond to the business status identification request and send business status identification information to the encryption device agent. This allows the encryption device agent to determine that the first master encryption device is in an abnormal state of abnormal consistency when the number of times the business status identification information indicates that the first master encryption device is in an abnormal state within a first preset time period meets a preset threshold. The encryption device agent also controls the switching between the first master encryption device and the first slave encryption device. The abnormal consistency state is when the first master encryption device is in an abnormal state within a third preset time period.

[0204] Specifically, the encryption device proxy's identification of the business status of the first primary encryption device can include:

[0205] Second business status identification request receiving module: used to receive business status identification requests sent by the encryption device agent based on a second preset frequency;

[0206] The second business status identification result determination module is used to, in the case that no response information in response to the business status identification request is sent to the encryption device agent within a second preset time period, enable the encryption device agent to determine that the business status identification result of the first main encryption device is an identification result indicating that the first main encryption device is in an abnormal state; and in the case that a response information in response to the business status identification request is sent to the encryption device agent within the second preset time period, enable the encryption device agent to analyze the response information and determine the business status identification result of the first main encryption device based on the analysis result of the response information.

[0207] This invention also provides a data processing system, including: a client, an encryption device proxy, a first master encryption device, and a first slave encryption device;

[0208] The client is used to send data encryption requests to the encryption device agent.

[0209] The encryption device agent is used to receive data encryption requests sent by clients; to send data encryption requests to the first master encryption device; to receive the first target encryption result obtained by encrypting the data to be encrypted sent by the first master encryption device; and to retrieve the target message from the preset non-abnormal message queue when it is determined that the storage space of the preset non-abnormal message queue does not meet the first preset condition, migrate the target message from the preset non-abnormal message queue to the preset abnormal message queue, and write the first target encryption result into the preset non-abnormal message queue after message migration; the first target encryption result in the preset non-abnormal message queue after message migration and the target message in the preset abnormal message queue are used to be consumed by the first slave encryption device.

[0210] The first primary encryption device is configured to receive a data encryption request sent by an encryption device agent; encrypt the data to be encrypted to obtain a first target encryption result; and send the first target encryption result to the encryption device agent.

[0211] The first encryption device is used to sequentially consume the first target encryption result from the preset non-abnormal message queue, the preset abnormal message queue, and the preset storage device.

[0212] As can be seen from the above embodiments of the data processing method, encryption device proxy, and main encryption device provided by the present invention, the present invention improves the overall availability of the encryption service of the main encryption device by identifying the business status of the main encryption device through the encryption device proxy, and avoids the impact of the main encryption device's abnormality on the encryption service; by controlling the switching between the main encryption device and the slave encryption device through the encryption device proxy, the main encryption device in an abnormal consistency state is changed to a downtime state, and an alarm log is sent to the encryption device proxy, enabling maintenance personnel to resolve the problem in a timely manner, and the slave encryption device is switched back to the main encryption device to continue processing data encryption request business, avoiding the impact on the normal operation of the overall encryption service business; by the encryption device proxy writing the target encryption result into the non-abnormal message queue, abnormal message queue, and storage device according to the storage status of the non-abnormal message queue, abnormal message queue, and storage device, as well as the consumption of the target encryption result by the slave encryption device, the target encryption result is awaited to be consumed by the slave encryption device, thereby maintaining data consistency between the main encryption device and the slave encryption device, avoiding the failure of data decryption request processing when the slave encryption device switches to the main encryption device, thereby improving the user experience.

[0213] It should be noted that the various embodiments of the present invention have been described above. These descriptions are exemplary and not exhaustive, nor are they limited to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described embodiments. The terminology used herein is chosen to best explain the principles, practical applications, or technological improvements to the embodiments in the market, or to enable others skilled in the art to understand the embodiments disclosed herein.

Claims

1. A data processing method, characterized in that, The method, applied to an encryption device proxy, includes: The system receives a data encryption request sent by a client. The data encryption request carries data to be encrypted and a first key identifier, which is used to generate a corresponding key for the data to be encrypted. Identify the service status of the first master encryption device. If the service status identification result indicates that the first master encryption device is in an abnormal state, send a service status identification request to the first master encryption device based on a first preset frequency. Receive service status identification information sent by the first master encryption device in response to the service status identification request; If the number of times the first primary encryption device is in an abnormal state within a first preset time period, as indicated by the business status identification information, does not meet the preset number threshold, it is determined that the first primary encryption device is in an abnormal state where the performance does not meet the third preset condition, and the data encryption request is sent to the first primary encryption device. The preset number threshold is a fault tolerance setting based on the business requirements of the first primary encryption device for data encryption. Receive the first target encryption result obtained by encrypting the data to be encrypted by the first main encryption device; The first target encryption result is obtained by the first main encryption device encrypting the data to be encrypted based on the key and encryption algorithm; If it is determined that the storage space of the preset non-abnormal message queue does not meet the first preset condition, the target message is obtained from the preset non-abnormal message queue, the target message is migrated from the preset non-abnormal message queue to the preset abnormal message queue, and the key, the first target encryption result, and the correspondence between the first key identifier and the key and the first target encryption result are written into the preset non-abnormal message queue after the message migration. The key, the first target encryption result, the correspondence between the first key identifier and the key and the first target encryption result, and the target message in the preset abnormal message queue after message migration are used to be consumed by the first encryption device.

2. The data processing method according to claim 1, characterized in that, The method further includes: If the first slave encryption device fails to consume the first target encryption result in the preset non-abnormal message queue, and it is determined that the storage space of the preset abnormal message queue meets the second preset condition, the first target encryption result is written into the preset abnormal message queue, and the first target encryption result in the preset abnormal message queue is used to be consumed by the first slave encryption device.

3. The data processing method according to claim 2, characterized in that, The method further includes: If the first slave encryption device fails to consume the first target encryption result in the preset non-abnormal message queue and it is determined that the storage space of the preset abnormal message queue does not meet the second preset condition, the first target encryption result is written to the preset storage device, and the first target encryption result in the preset storage device is used to be consumed by the first slave encryption device.

4. The data processing method according to claim 1, characterized in that, The method further includes: If it is determined that the storage space of the preset non-abnormal message queue does not meet the first preset condition and the storage space of the preset abnormal message queue does not meet the second preset condition, the target message is obtained from the preset non-abnormal message queue, the target message is migrated from the preset non-abnormal message queue to the preset storage device, and the first target encryption result is written into the preset non-abnormal message queue after the message migration; the first target encryption result in the preset non-abnormal message queue after the message migration is used to be consumed by the first slave encryption device, and the target message in the preset storage device is used to be consumed by the first slave encryption device.

5. The data processing method according to claim 1, characterized in that, The method further includes: If the storage space of the preset non-abnormal message queue meets the first preset condition, the first target encryption result is written into the preset non-abnormal message queue; the first target encryption result in the preset non-abnormal message queue is used to be consumed by the first slave encryption device.

6. The data processing method according to claim 1, characterized in that, The method includes: If the number of times the first master encryption device is in an abnormal state within a first preset time period, as indicated by the business status identification information, meets the preset number threshold, it is determined that the first master encryption device is in an abnormal consistent state, and the first master encryption device and the first slave encryption device are switched. The abnormal consistent state is when the first master encryption device is in an abnormal state within a third preset time period.

7. The data processing method according to claim 6, characterized in that, The control of switching between the first master encryption device and the first slave encryption device includes: Control the first slave encryption device to switch to the second master encryption device; The service status of the first master encryption device is determined to be down, so that the first master encryption device generates an alarm log corresponding to the down status; Receive the alarm log sent by the first main encryption device; If the service status of the first master encryption device is determined to be non-abnormal, the first master encryption device is controlled to switch to the second slave encryption device; the non-abnormal status is obtained by updating the downtime status based on the alarm log.

8. The data processing method according to claim 7, characterized in that, After the method controls the switching between the first master encryption device and the first slave encryption device, the method includes: A data encryption request is sent to the second master encryption device so that the second master encryption device can encrypt the data to be encrypted to obtain a second target encryption result; The second target encryption result is written into the preset non-abnormal message queue, the preset abnormal message queue, and the preset storage device, so that the second slave encryption device sequentially consumes the second target encryption result from the preset non-abnormal message queue, the preset abnormal message queue, and the preset storage device.

9. The data processing method according to claim 6, characterized in that, The identification of the service status of the first master encryption device includes: The service status identification request is sent to the first main encryption device based on the second preset frequency; If no response information is received from the first primary encryption device in response to the service status identification request within the second preset time period, the service status identification result of the first primary encryption device is determined to be an identification result indicating that the first primary encryption device is in an abnormal state. If, within the second preset time period, a response information sent by the first master encryption device in response to the service status identification request is received, the response information is analyzed, and the service status identification result of the first master encryption device is determined based on the analysis result of the response information.

10. A data processing method, characterized in that, The method includes: The receiving encryption device agent sends a service status identification request based on a first preset frequency when it identifies the service status of the first main encryption device and the service status identification result indicates that the first main encryption device is in an abnormal state. In response to the service status identification request, service status identification information is sent to the encryption device agent, so that the encryption device agent sends a data encryption request when the number of times the service status identification information indicates that the first main encryption device is in an abnormal state within a first preset time period does not meet a preset number threshold. The encryption device agent receives a data encryption request, which carries data to be encrypted and a first key identifier. The first key identifier is used to generate a corresponding key for the data to be encrypted. The data to be encrypted is encrypted based on the key and encryption algorithm to obtain the first target encryption result; Send the first target encryption result to the encryption device agent; so that the encryption device agent obtains the target message from the preset non-abnormal message queue when it determines that the storage space of the preset non-abnormal message queue does not meet the first preset condition; so that the encryption device agent migrates the target message from the preset non-abnormal message queue to the preset abnormal message queue; and so that the encryption device agent writes the key, the first target encryption result, and the correspondence between the first key identifier and the key and the first target encryption result into the preset non-abnormal message queue after the message migration. The key, the first target encryption result, the correspondence between the first key identifier and the key, the first target encryption result, and the target message in the preset abnormal message queue after message migration are used to be consumed by the first encryption device.

11. The data processing method according to claim 10, characterized in that, The method includes: In response to the service status identification request, service status identification information is sent to the encryption device agent, so that if the number of times the service status identification information indicates that the first master encryption device is in an abnormal state within a first preset time period meets the preset number threshold, the encryption device agent determines that the first master encryption device is in an abnormal consistent state, and controls the first master encryption device to switch with the first slave encryption device; wherein, the abnormal consistent state is that the first master encryption device is in an abnormal state within a third preset time period.

12. The data processing method according to claim 11, characterized in that, The encryption device proxy terminal identifies the service status of the first master encryption device, including: Receive the service status identification request sent by the encryption device agent at a second preset frequency; If no response information in response to the service status identification request is sent to the encryption device agent within the second preset time period, the encryption device agent shall determine that the service status identification result of the first main encryption device is an identification result indicating that the first main encryption device is in an abnormal state. If, during the second preset time period, a response message in response to the service status identification request is sent to the encryption device agent, the encryption device agent will analyze the response message and determine the service status identification result of the first main encryption device based on the analysis result of the response message.

13. A proxy terminal for an encryption device, characterized in that, The encryption device proxy includes: The request receiving module is used to receive a data encryption request sent by the client. The data encryption request carries the data to be encrypted and a first key identifier. The first key identifier is used to generate a corresponding key for the data to be encrypted. The first service status identification request sending module is used to identify the service status of the first main encryption device. When the service status identification result indicates that the first main encryption device is in an abnormal state, the module sends a service status identification request to the first main encryption device based on a first preset frequency. A service status identification information receiving module is used to receive service status identification information sent by the first main encryption device in response to the service status identification request. An abnormal state determination module is used to determine that the first main encryption device is in an abnormal state where the performance does not meet a third preset condition when the number of times the service state identification information indicates that the first main encryption device is in an abnormal state within a first preset time period does not meet a preset number threshold. The request sending module is used to send the data encryption request to the first main encryption device, and the preset number of times threshold is a fault tolerance setting based on the business requirements of the first main encryption device for data encryption; The data receiving module is used to receive a first target encryption result obtained by encrypting the data to be encrypted by the first main encryption device; the first target encryption result is obtained by the first main encryption device encrypting the data to be encrypted based on the key and encryption algorithm; The data storage module is configured to, when determining that the storage space of the preset non-abnormal message queue does not meet a first preset condition, retrieve a target message from the preset non-abnormal message queue, migrate the target message from the preset non-abnormal message queue to a preset abnormal message queue, and write the key, the first target encryption result, and the correspondence between the first key identifier and the key and the first target encryption result into the preset non-abnormal message queue after message migration; the key, the first target encryption result, and the correspondence between the first key identifier and the key and the first target encryption result in the preset non-abnormal message queue after message migration, and the target message in the preset abnormal message queue, are used to be consumed by the first slave encryption device.

14. A master encryption device, characterized in that, The main encryption device includes: The first business status identification request receiving module is used to receive a business status identification request sent by the encryption device agent based on a first preset frequency when the business status of the first main encryption device is identified and the business status identification result indicates that the first main encryption device is in an abnormal state. The service status identification information sending module is used to respond to the service status identification request and send service status identification information to the encryption device agent terminal, so that the encryption device agent terminal sends a data encryption request when the number of times the service status identification information indicates that the first main encryption device is in an abnormal state within a first preset time period does not meet a preset number threshold. The data encryption module is used to receive the data encryption request sent by the encryption device agent, the data encryption request carrying data to be encrypted and a first key identifier, the first key identifier being used to generate a corresponding key for the data to be encrypted; and to encrypt the data to be encrypted based on the key and the encryption algorithm to obtain a first target encryption result; A data sending module is configured to send the first target encryption result to the encryption device agent; so that the encryption device agent, when determining that the storage space of the preset non-abnormal message queue does not meet the first preset condition, obtains the target message from the preset non-abnormal message queue; and so that the encryption device agent migrates the target message from the preset non-abnormal message queue to a preset abnormal message queue; and so that the encryption device agent writes the key, the first target encryption result, and the correspondence between the first key identifier and the key and the first target encryption result into the preset non-abnormal message queue after message migration; the key, the first target encryption result, and the correspondence between the first key identifier and the key and the first target encryption result in the preset non-abnormal message queue after message migration, and the target message in the preset abnormal message queue, are used to be consumed by the first slave encryption device.

Citation Information

Patent Citations

  • Message processing method, server cluster and message processing system

    CN106878473A

  • Message queue management method, management system and electronic equipment

    CN114265753A

  • Message processing and content based searching for message locations in an asynchronous network

    US20060056433A1