A full-process data security protection system

Through the full-process data security protection system, user data is encrypted locally, stored on the server, and displayed in sample encryption, which solves the security issues in the process of data transmission, storage and use, and realizes the full-process security protection of data.

CN115664830BActive Publication Date: 2025-09-12ZHEJIANG BIG DATA JOINT COMPUTING CENT CO LTD +1
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202211349773.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-31
Publication Date
2025-09-12
Estimated Expiration
2042-10-31

AI Technical Summary

Technical Problem

In existing technologies, the security of data during transmission to cloud storage and the security of data storage in the cloud cannot be effectively guaranteed, and third-party servers are also threatened when using data.

Method used

A full-process data security protection system is adopted. Data is encrypted on the target user's local end, and the server performs encrypted storage and sampling processing. The sampled data is displayed in encrypted form according to the security level encryption strategy to ensure the security of data during transmission, storage and use.

Benefits of technology

It achieves data security protection throughout the entire process of transmission, storage, and use, reduces network resource consumption, and improves data security and privacy protection during use.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115664830B_ABST
    Figure CN115664830B_ABST
Patent Text Reader

Abstract

The present invention provides a full-process data security protection system, which at least includes a server, wherein the server includes a processor and a memory storing a computer program. When the processor loads and executes the computer program, the server implements the following steps: obtaining user data uploaded by a target user, encrypting the user data according to an encryption algorithm to obtain encrypted data, when a third party uses the encrypted data, sampling from the encrypted data according to preset rules to obtain sampled data, based on the security level encryption strategy corresponding to different fields in the encrypted data, encrypting different fields in the sampled data according to their corresponding security level encryption strategy, and providing the encrypted sampled data to a third party for display. Therefore, the present invention protects the security of data during transmission, storage, use, etc.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data security, and in particular to a full-process data security protection system. Background Art

[0002] With the increasing use of big data and the rapid development of the internet, most files are stored as data on personal phones or computers. Existing technologies often upload data to the cloud for security reasons. However, once data is transferred to the cloud, its security during upload and storage cannot be guaranteed. Furthermore, the security of this data is threatened when it is used by third-party servers. Summary of the Invention

[0003] In view of the above technical problems, the technical solution adopted by the present invention is:

[0004] A full-process data security protection system includes at least a server, wherein the server includes a processor and a memory storing a computer program. When the processor loads and executes the computer program, the server implements the following steps:

[0005] S100, obtaining user data uploaded by a target user, wherein the user data is data encrypted by the target client's local terminal.

[0006] S200 , encrypting the user data according to a first preset encryption algorithm to obtain first user encrypted data, where the first user encrypted data is stored in an independent logical storage area corresponding to the target user on the server.

[0007] S300 : When a third party different from the target customer uses the first user encrypted data, sampling is performed from the first user encrypted data according to a preset rule to obtain first user sample data.

[0008] S400, based on the security level encryption strategy corresponding to different fields in the first user encrypted data, encrypt different fields in the first user sample data according to their corresponding security level encryption strategy, and provide the encrypted first user sample data to a third party for display.

[0009] The present invention has at least the following beneficial effects: the present invention obtains user data uploaded by the target user, wherein the user data is the original data encrypted according to the second preset encryption algorithm to obtain the user data, thereby ensuring the security of the original data; the user data is transmitted to the server in a point-to-point manner, thereby ensuring the security of the data during transmission; the user data is encrypted according to the first preset encryption algorithm to obtain first user encrypted data; the first user encrypted data is stored in the form of ciphertext in an independent logical storage area of ​​the server used for the target user, thereby ensuring the security of the data in storage; when a third party uses the first user encrypted data, a sample is taken from the first user encrypted data, the data is encrypted according to the security level encryption strategy, and then displayed to the third party; the third party runs the encrypted first user sampled data in the server memory of the present invention, and destroys the intermediate data after the operation ends, thereby ensuring the security of the data during use; in summary, the present invention protects the security of data throughout the entire process of transmission, storage, use, and destruction. BRIEF DESCRIPTION OF THE DRAWINGS

[0010] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0011] Figure 1 A flowchart of a full-process data security protection system executing a computer program provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0012] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without making any creative efforts shall fall within the scope of protection of the present invention.

[0013] The embodiment of the present invention proposes a full-process data security protection system, which includes at least a server, wherein the server includes a processor and a memory storing a computer program. When the processor loads and executes the computer program, Figure 1 As shown, the server implements the following steps:

[0014] S100, obtaining user data uploaded by a target user, wherein the user data is data encrypted by the target client's local terminal.

[0015] S200 , encrypting the user data according to a first preset encryption algorithm to obtain first user encrypted data, where the first user encrypted data is stored in an independent logical storage area corresponding to the target user on the server.

[0016] Furthermore, the first user encrypted data is stored in an independent logical storage area corresponding to the target user on the server, and the logical storage area is located on the server's hard disk. Because the data stored in the logical storage area is encrypted, the data on the hard disk cannot be accessed after the server's hard disk is removed, thereby ensuring the security of the user data stored on the hard disk.

[0017] S300 : When a third party different from the target customer uses the first user encrypted data, sampling is performed from the first user encrypted data according to a preset rule to obtain first user sample data.

[0018] Specifically, a sampling ratio A0 for sampling the first user encrypted data according to a preset rule is obtained.

[0019] Optionally, A0<0.001; preferably, A0=0.001.

[0020] In one embodiment of the present invention, the sampling according to a preset rule is random sampling.

[0021] In another embodiment of the present invention, the first user encrypted data is stored in a data strip format including a plurality of different fields, and sampling the first user encrypted data according to a preset rule to obtain the first user sampled data includes the following steps:

[0022] S301, obtaining a user encrypted data list C corresponding to s second users different from the target user used by the third party = {C1, C2, ..., C r ,…,C s}, C r It is the second user encrypted data corresponding to the r-th second user and is part of the first user encrypted data corresponding to the r-th second user. The fields included in the first user encrypted data corresponding to the r-th second user are the same as the fields included in the corresponding second user encrypted data. The value range of r is 1 to s.

[0023] S303, based on the user encrypted data list C, obtain the preset field I in C1, C2, ..., C r ,…,C s The total set of common field values ​​E = {E1, E2, ..., E t ,…,E T}, where E t The tth one is included in C1, C2, ..., Cr ,…,C s The field value of the preset field I in , the value range of t is 1 to T.

[0024] Among them, the preset field I can be customized as needed.

[0025] S305: Based on the preset field I and the field value E, obtain the first user data corresponding to the target user, which contains the preset field I values ​​E1, E2, ..., E t ,…,E T to obtain the first user sampling data.

[0026] Based on S301 to S305, the user encrypted data list C is obtained, and based on the preset field I, the entire common field value set of all second user encrypted data is obtained. According to the preset field I and the entire common field value set E, all pieces of data containing the value of the preset field I are obtained from the first user data corresponding to the target user to obtain the first user sampling data. In summary, the third party obtains the pieces of data corresponding to the common field value under the preset field to obtain the first user sampling data, thereby ensuring the subsequent normal use of the first user sampling data by the third party.

[0027] S400, based on the security level encryption strategy corresponding to different fields in the first user encrypted data, encrypt different fields in the first user sample data according to their corresponding security level encryption strategy, and provide the encrypted first user sample data to a third party for display.

[0028] From the above content, it can be seen that the method of the present invention obtains first user data by sampling from the first user encrypted data according to preset rules, and encrypts the sampled first user data and displays it to a third party. Compared with the method in the prior art of simultaneously transmitting the original data and the encrypted data corresponding to the original data specifically for display to the third party, it can reduce the amount of data transmission and reduce the consumption of network resources while ensuring data security.

[0029] Specifically, encrypting different fields in the first user sample data according to their corresponding security level encryption strategies includes the following steps:

[0030] S401, obtain the first user sample data field A = {A1, A2, ..., A i ,…,A m}, A i It refers to the i-th field of the first user sample data. The value range of i is 1 to m, and m refers to the number of fields in the first user sample data.

[0031] S402, to A i , according to the field-priority correspondence (A, B), get A i Corresponding priority B j , where B={B1,B2,…,B j ,…,B n}, B j It refers to the jth priority. The value range of j is 1 to n. n refers to the number of priorities. Different priorities correspond to different security level encryption strategies.

[0032] Specifically, those skilled in the art know that the security level encryption strategies corresponding to different priorities are determined according to the type of field and actual needs.

[0033] Specifically, in the field-priority correspondence (A, B), the higher the priority, the stricter the corresponding security level encryption policy. This means that the higher the priority level of a field, the more important the corresponding data, and the more stringent the security level encryption policy required. For example, fields that can indicate personal identity, such as mobile phone numbers and ID numbers, can be desensitized by truncating or hiding the field data value, generally using special characters (such as *) to replace the true value, making the field data value no longer useful.

[0034] In one embodiment of the present invention, the priorities are divided into four levels.

[0035] S403, according to B j The corresponding security level encryption strategy for A i The corresponding field data is encrypted.

[0036] Based on S401-S403, obtain the fields of the first user sampling data, and i , according to the field-priority correspondence (A, B), get A i Corresponding priority B j , according to B j The corresponding security level encryption strategy for A i The corresponding data is encrypted to prevent the first user sampling data from being obtained through data collision and other means during use. At the same time, the present invention encrypts the encrypted data, which greatly improves the security of the data when it is used.

[0037] Furthermore, the third party runs the encrypted first user sampling data in the server memory, and destroys the encrypted first user sampling data and intermediate data generated during the running after the running is completed.

[0038] Based on S100-S400, the user data uploaded by the target user is obtained, wherein the user data is the original data encrypted according to the second preset encryption algorithm to obtain the user data, thereby ensuring the security of the original data, the user data is transmitted to the server in a point-to-point manner, thereby ensuring the security of the data during transmission, the user data is encrypted according to the first preset encryption algorithm to obtain first user encrypted data, the first user encrypted data is stored in the form of ciphertext in an independent logical storage area of ​​the server used for the target user, thereby ensuring the security of the data in storage, when a third party uses the first user encrypted data, a sample is taken from the first user encrypted data, the data is encrypted according to the security level encryption strategy, and then displayed to the third party, the third party runs the encrypted first user sampled data in the server memory of the present invention, and destroys the intermediate data after the operation ends, thereby ensuring the security of the data during use, in summary, the present invention protects the security of data in the entire process of transmission, storage, use, and destruction.

[0039] The full-process data security protection system of the present invention further includes an SDK located at a local terminal of any target client, wherein the SDK performs the following steps:

[0040] S001: Encrypt the original data of the target customer corresponding to the SDK according to a second preset encryption algorithm to obtain the user data.

[0041] Specifically, those skilled in the art know that any method in the prior art that uses the target client's local terminal to encrypt and obtain user data falls within the scope of protection of the present invention, such as using the DES algorithm in symmetric encryption and the RSA algorithm in asymmetric encryption.

[0042] S002: Transmit the user data to the server in a point-to-point manner.

[0043] The present invention also includes, when the target client local terminal uses the first user encrypted data, displaying the decrypted first user encrypted data to the target client local terminal, wherein the target client local terminal accesses the first user encrypted data through the target network exit IP, and the target network exit IP is bound to the independent logical storage area corresponding to the target user.

[0044] Specifically, when the target client locally uses the first user encrypted data, the target user accesses the first user encrypted data through the target network exit IP, and the server decrypts the first user encrypted data so that the user can directly view the decrypted data. Therefore, the target user is unaware of the entire decryption process when accessing the second encrypted data, thereby improving the user experience.

[0045] Furthermore, those skilled in the art know that the decryption process is the inverse process of the encryption process. For example, when using the DES algorithm for symmetric encryption, the encryption process and the decryption process use the same key, and the calculation speed is fast. For example, when using the RSA algorithm for asymmetric encryption, the encryption process and the decryption process use different keys. When the encryption process uses the public key, the decryption process must use the private key. The public key and the private key are used in pairs, which is more secure and the public key and the private key are kept separately without the need to transmit the public key and the private key.

[0046] Although some specific embodiments of the present invention have been described in detail by way of example, it will be understood by those skilled in the art that the above examples are for illustration only and are not intended to limit the scope of the present invention. It will also be understood by those skilled in the art that various modifications may be made to the embodiments without departing from the scope and spirit of the present invention. The scope of the present invention is defined by the appended claims.

Claims

1. A full-process data security protection system, characterized in that: The system comprises at least a server, wherein the server comprises a processor and a memory storing a computer program, and when the processor loads and executes the computer program, the server implements the following steps: S100, obtaining user data uploaded by a target user, wherein the user data is data encrypted by the target client's local terminal; S200, encrypting the user data according to a first preset encryption algorithm to obtain first user encrypted data, wherein the first user encrypted data is stored in an independent logical storage area corresponding to the target user on the server; S300, when a third party different from the target customer uses the first user encrypted data, sampling is performed from the first user encrypted data according to a preset rule to obtain first user sample data; S400: Based on the security level encryption policies corresponding to the different fields in the first user encrypted data, encrypt the different fields in the first user sampled data according to the corresponding security level encryption policies, and provide the encrypted first user sampled data to a third party for display; The S300 also includes: S301, obtain a user encrypted data list C={C1, C2, ..., C r ,…,C s }, C r is the second user encrypted data corresponding to the r-th second user, and is part of the first user encrypted data corresponding to the r-th second user. The first user encrypted data corresponding to the r-th second user contains the same fields as the second user encrypted data corresponding to the r-th second user. The value of r ranges from 1 to s. S303, based on the user encrypted data list C, obtain the preset field I in C1, C2, ..., C r ,…,C s The total set of common field values ​​E={E1, E2, ..., E t ,…,E T }, where E t The tth one is included in C1, C2, ..., C r ,…,C s The field value of the preset field I in , the value range of t is 1 to T; S305: Based on the preset field I and the field value set E, obtain the first user data corresponding to the target user, which contains the preset field I values ​​E1, E2, ..., E t ,…,E T to obtain the first user sampling data.

2. The system according to claim 1, wherein: The system further includes an SDK located at a local terminal of any target client, wherein the SDK performs the following steps: S001, encrypting the original data of the target customer corresponding to the SDK according to a second preset encryption algorithm to obtain the user data; S002: Transmit the user data to the server in a point-to-point manner.

3. The system according to claim 2, characterized in that Encrypting different fields in the first user sample data according to their corresponding security level encryption strategies includes the following steps: S401, obtain the first user sampling data field A = {A1, A2, ..., A i ,…,A m }, A i refers to the i-th field of the first user sample data, where i ranges from 1 to m, and m refers to the number of fields in the first user sample data; S402, to A i , according to the field-priority correspondence (A, B), get A i Corresponding priority B j , where B={B1, B2,…, B j ,…,B n }, B j It refers to the jth priority, where the value of j ranges from 1 to n, and n refers to the number of priorities. Different priorities correspond to different security level encryption strategies. S403, according to B j The corresponding security level encryption strategy for A i The corresponding field data is encrypted.

4. The system according to claim 1, wherein: In S300, the sampling according to the preset rules is random sampling.

5. The system according to claim 1, wherein: When the target client's local terminal uses the first user encrypted data, the decrypted first user encrypted data is displayed to the target client, wherein the target client's local terminal accesses the first user encrypted data through the target network exit IP, and the target network exit IP is bound to the independent logical storage area corresponding to the target user.

6. The system according to claim 1, wherein: The third party runs the encrypted first user sampling data in the server memory, and destroys the encrypted first user sampling data and intermediate data generated during the running after the running is completed.

7. The system according to claim 1, wherein: The encryption processing in S400 refers to data desensitization.

8. The system according to claim 3, wherein: In the field-priority correspondence relationship (A, B), the higher the priority, the stricter the data desensitization policy corresponding to the priority.

9. The system according to claim 1, wherein: S300 also includes obtaining a sampling ratio A0 for sampling the first user's encrypted data according to a preset rule.

Citation Information

Patent Citations

  • Data access control method and data access control system

    CN103746798A

  • A data static desensitization system and method based on database sensitive discovery

    CN109271808A

  • Data transmission method and device, electronic equipment and storage medium

    CN113595982A