Data acquisition method and device, electronic device, storage medium

By splitting data into sub-units and using alternating file transfer ports with dynamic encryption, the method enhances network data security during transmission, preventing complete data exposure even if some ports are compromised.

CN116016551BActive Publication Date: 2025-07-15CHINA TELECOM CORP LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211684917.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-27
Publication Date
2025-07-15
Estimated Expiration
2042-12-27

AI Technical Summary

Technical Problem

In the prior art, data has the risk of snooping and intercepting during network transmission, resulting in the failure to effectively guarantee data security.

Method used

The target data is cut into multiple target sub-data and sent alternately through at least two sets of file sending ports. The terminal device merges and recovers the data, and performs dynamic encryption and dynamic authentication at the same time.

Benefits of technology

Improve the security of data during network transmission, avoid snooping and intercepting events, and enhance data integrity and privacy protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116016551B_ABST
    Figure CN116016551B_ABST
Patent Text Reader

Abstract

The present disclosure provides a data acquisition method and apparatus, an electronic device, and a storage medium, relating to the technical field of data security. The data acquisition method includes: obtaining a data acquisition request of a terminal device, where the data acquisition request includes a data identifier; matching target data based on the data identifier, and slicing the target data into a plurality of target sub-data; returning the plurality of target sub-data to the terminal device through at least two groups of file sending ports, so that the terminal device merges the received plurality of target sub-data to recover the target data. The technical solution of the embodiments of the present disclosure can improve the security of data transmission and avoid the risk of data leakage.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0002] With the development of Internet technology, the transmission of data through the network has been increasingly widely used, such as cloud storage, cloud applications, etc. Therefore, how to improve the security of data during network transmission has received more and more attention.

[0003] Currently, data is generally obtained by accessing a server, and device identity authentication is mostly used. Taking digital certificates as an example, the relevant device identity authentication can only manually send the digital certificate to the Certificate Authority (CA), and the CA center verifies the digital certificate. However, this solution can only implement the identity authentication of the terminal device accessing the server, and the data may still be snooped or intercepted during the transmission process, and the security of the data during the transmission process cannot be effectively guaranteed.

[0004] It should be noted that the information disclosed in the above background art is only used to enhance the understanding of the background of the present disclosure, and therefore may include information that does not constitute the prior art known to those of ordinary skill in the art. Summary of the Invention

[0005] The purpose of the embodiments of the present disclosure is to provide a data acquisition method, a data acquisition device, an electronic device, and a computer-readable storage medium, so as to at least to a certain extent improve the data security of data during network transmission and avoid the risk of data leakage.

[0006] Other features and advantages of the present disclosure will become apparent through the following detailed description, or will be partially learned through the practice of the present disclosure.

[0007] According to the first aspect of the embodiments of the present disclosure, a data acquisition method is provided, including:

[0008] Obtain a data acquisition request of a terminal device, where the data acquisition request includes a data identifier;

[0009] Match target data based on the data identifier, and cut the target data into multiple target sub-data;

[0010] Return the multiple target sub-data to the terminal device through at least two sets of file sending ports, so that the terminal device merges the multiple target sub-data received to restore the target data.

[0011] In some exemplary embodiments of the present disclosure, based on the foregoing solution, the at least two sets of file sending ports include a first file sending port and a second file sending port, and the returning the multiple target sub-data to the terminal device through at least two sets of file sending ports includes:

[0012] Divide the multiple target sub - data into first target sub - data and second target sub - data;

[0013] In response to an access request sent by the terminal device to the first file sending port, send the first target sub - data to the terminal device through the first file sending port; and

[0014] Proactively send the second target sub - data to the terminal device through the second file sending port;

[0015] Wherein, the first file sending port and the second file sending port alternately send the first target sub - data and the second target sub - data.

[0016] In some exemplary embodiments of the present disclosure, based on the foregoing solution, the method includes:

[0017] Determine a target port identifier in the set of port identifiers of the first file sending port;

[0018] Return the target port identifier to the terminal device so that the terminal device can obtain the first target sub - data by accessing the corresponding first file sending port according to the target port identifier;

[0019] Wherein, each of the target sub - data corresponds to each of the file sending ports one by one.

[0020] In some exemplary embodiments of the present disclosure, based on the foregoing solution, returning the target port identifier to the terminal device includes:

[0021] Send the target port identifier and the first target sub - data that needs to be sent at the previous moment to the terminal device so that the terminal device can obtain the first target sub - data that needs to be sent at the next moment by accessing the corresponding first file sending port according to the target port identifier.

[0022] In some exemplary embodiments of the present disclosure, based on the foregoing solution, the method further includes:

[0023] In response to the second file sending port receiving an access request, determine the access request as a malicious access request and stop sending the target sub - data.

[0024] In some exemplary embodiments of the present disclosure, based on the foregoing solution, the method further includes:

[0025] Perform dynamic encryption processing on the target sub - data;

[0026] The performing dynamic encryption processing on the target sub - data includes:

[0027] Randomly determine a target field in the current target sub - data, and delete the target field from the current target sub - data; and

[0028] Add the target field to the target sub - data to be sent at the next moment.

[0029] In some exemplary embodiments of the present disclosure, based on the foregoing solution, after obtaining a data acquisition request of a terminal device, the method further includes:

[0030] Send a dynamic authentication request to the terminal device, where the dynamic authentication request includes any one or a combination of a face recognition request, a fingerprint recognition request, a two - dimensional code verification request, and a dynamic code verification request;

[0031] Receive dynamic authentication response information, and determine a dynamic authentication result according to the dynamic authentication response information.

[0032] According to a second aspect of the embodiments of the present disclosure, there is provided a data acquisition device, including:

[0033] A data request module, configured to obtain a data acquisition request of a terminal device, where the data acquisition request includes a data identifier;

[0034] A data segmentation module, configured to match target data based on the data identifier, and cut the target data into multiple target sub - data;

[0035] A data distribution module, configured to return the multiple target sub - data to the terminal device through at least two groups of file sending ports, so that the terminal device merges the received multiple target sub - data to restore the target data.

[0036] According to a third aspect of the embodiments of the present disclosure, there is provided an electronic device, including: a processor; and a memory, where a computer - readable instruction is stored on the memory, and when the computer - readable instruction is executed by the processor, the data acquisition method described in any one of the above is implemented.

[0037] According to a fourth aspect of the embodiments of the present disclosure, there is provided a computer - readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the data acquisition method described in any one of the above is implemented.

[0038] The technical solutions provided by the embodiments of the present disclosure may include the following beneficial effects:

[0039] The data acquisition method in the exemplary embodiments of the present disclosure can acquire a data acquisition request of a terminal device, match target data according to a data identifier carried in the data acquisition request, cut the target data into multiple target sub-data, and then can return the multiple target sub-data to the terminal device through at least two groups of file sending ports, so that the terminal device merges the received multiple target sub-data to restore the target data. On the one hand, splitting the target data into multiple target sub-data for sending can avoid the risk of the entire target data being leaked due to snooping or interception events during network transmission, and improve the security of the target data. On the other hand, sending the multiple split target sub-data through at least two groups of file sending ports, in this way, when some file sending ports are leaked, it is also impossible to accurately trace all the file sending ports, ensuring that at least some of the target sub-data cannot be snooped or intercepted, further improving the security of the target data during network transmission.

[0040] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] The accompanying drawings herein are incorporated into the specification and constitute a part of the specification, showing embodiments consistent with the present disclosure, and are used together with the specification to explain the principles of the present disclosure. Obviously, the accompanying drawings in the following description are only some embodiments of the present disclosure, and those of ordinary skill in the art can also obtain other drawings based on these drawings without creative efforts. In the drawings:

[0042] Figure 1 Schematically shows a flowchart of a data acquisition method according to some embodiments of the present disclosure;

[0043] Figure 2 Schematically shows a flowchart of implementing target data transmission through at least two groups of file sending ports according to some embodiments of the present disclosure;

[0044] Figure 3 Schematically shows a schematic diagram of the principle of transmitting target data according to some embodiments of the present disclosure;

[0045] Figure 4 Schematically shows a schematic diagram of the composition of a data acquisition device according to some embodiments of the present disclosure;

[0046] Figure 5 Schematically shows a schematic diagram of the structure of a computer system of an electronic device according to some embodiments of the present disclosure;

[0047] Figure 6Schematically shows a schematic diagram of a computer-readable storage medium according to some embodiments of the present disclosure.

[0048] In the drawings, the same or corresponding reference numerals indicate the same or corresponding parts. Detailed implementation

[0049] Example embodiments will now be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this disclosure will be more thorough and complete, and will fully convey the concept of the example embodiments to those skilled in the art.

[0050] In addition, the described features, structures, or characteristics may be combined in any suitable manner in one or more embodiments. In the following description, numerous specific details are provided to give a thorough understanding of the embodiments of the present disclosure. However, those skilled in the art will realize that the technical solutions of the present disclosure can be practiced without one or more of the specific details, or other methods, components, devices, steps, etc. may be used. In other cases, well-known methods, devices, implementations, or operations are not shown or described in detail to avoid obscuring aspects of the present disclosure.

[0051] In addition, the drawings are only schematic diagrams and are not necessarily drawn to scale. The block diagrams shown in the drawings are merely functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities can be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.

[0052] In the present example embodiment, first, a data acquisition method is provided. The data acquisition method can be applied to a server. For example, when a terminal device is connected to the server through a network, a client application can be installed on the terminal device, and a server application can be installed on the server. Then, a communication link can be created according to the client application and the server application to realize the transmission of data materials. At this time, the server can use the data acquisition method provided in this embodiment to enhance the security of data during network transmission; of course, the data acquisition method can also be applied to the terminal device. When a first terminal device is connected to a second terminal device through a network, a client application can be installed on the first terminal device, and a server application can also be installed on the second terminal device. Then, a communication link can be created through the client application and the server application to realize the transmission of data materials on the second terminal device to the first terminal device. At this time, the second terminal device can use the data acquisition method provided in this embodiment to enhance the security of data during network transmission.

[0053] Taking the execution of this method by the server as an example, the data acquisition method provided in the present disclosure will be described below. Figure 1 A schematic flowchart of a data acquisition method according to some embodiments of the present disclosure is shown. Refer to Figure 1 As shown, the data acquisition method may include the following steps:

[0054] Step S110: Obtain a data acquisition request from a terminal device, where the data acquisition request includes a data identifier;

[0055] Step S120: Match target data based on the data identifier, and cut the target data into multiple target sub-data;

[0056] Step S130: Return the multiple target sub-data to the terminal device through at least two groups of file sending ports, so that the terminal device merges the received multiple target sub-data to restore the target data.

[0057] According to the data acquisition method in this exemplary embodiment, on the one hand, the target data is divided into multiple target sub-data for transmission, which can avoid the risk of the entire target data being leaked due to snooping or interception events during network transmission, and improve the security of the target data; on the other hand, the multiple divided target sub-data are sent through at least two groups of file sending ports. In this way, when some file sending ports are leaked, it is also impossible to accurately track all the file sending ports, ensuring that at least some of the target sub-data cannot be snooped or intercepted, further improving the security of the target data during network transmission.

[0058] Next, the data acquisition method in this exemplary embodiment will be further described.

[0059] In step S110, a data acquisition request from a terminal device is obtained, and the data acquisition request includes a data identifier.

[0060] In an exemplary embodiment of the present disclosure, the data acquisition request refers to a request instruction for a terminal device to initiate data acquisition from a server, and the data identifier refers to identification information for identifying the data to be requested by the terminal device. For example, the data identifier may be the cultural name characters or file name hash value of the data to be requested by the terminal device, or the unique encoding of the data to be requested by the terminal device in the corresponding storage database. This exemplary embodiment does not make special limitations on the unique identifier type of the data to be requested by the terminal device.

[0061] The interaction of request instructions and the transfer of data can be achieved through the data transmission channel established between the client application on the terminal device and the server application on the server, such as realizing the transfer of the data acquisition request of the terminal device.

[0062] In step S120, the target data is matched based on the data identifier, and the target data is cut into multiple target sub-data.

[0063] In an exemplary embodiment of the present disclosure, the target data refers to the data that the terminal device needs to request and obtain from the storage database of the server. For example, the target data can be a data file, a picture information, a recording information, etc. The type of the target data is not specially limited in this exemplary embodiment.

[0064] The target data can be the data stored in the corresponding storage database of the server, or the data stored in other terminal devices connected to the server. The source of the target data is not specially limited in this exemplary embodiment.

[0065] The target sub-data refers to multiple sub-data obtained by splitting the target data. For example, the target sub-data can be multiple segments of strings obtained by splitting the data file, and each segment of string can be represented as a target sub-data. Of course, the target sub-data can also be multiple sub-image blocks obtained by splitting the picture information, and each sub-image block can be represented as a target sub-data.

[0066] The target data can be split according to a pre-set splitting method. For example, the target data can be evenly split to obtain target sub-data with the same size and dimension, or the target data can be randomly split to obtain target sub-data with different sizes and dimensions. Of course, the relevant information of the surrounding target sub-data is stored in different target sub-data, so that after receiving all the target sub-data, the terminal device can accurately merge all the target sub-data to obtain the target data.

[0067] In step S130, the multiple target sub-data are returned to the terminal device through at least two groups of file sending ports, so that the terminal device merges the received multiple target sub-data to restore the target data.

[0068] In an exemplary embodiment of the present disclosure, the file sending port refers to the port created between the server and the terminal device for sending the target sub-data. For example, the file sending port can be a unidirectional port, or a bidirectional port. Of course, it can also be a mixed port of a unidirectional port and a bidirectional port. This exemplary embodiment does not make special limitations on this.

[0069] The file sending ports can be divided into at least two groups of file sending ports, and the target sub-data can be sent alternately through the at least two groups of file sending ports. For example, the file sending ports can be divided into active file sending ports and passive file sending ports. Specifically, after the terminal device sends a data acquisition request, the active file sending port can actively send the allocated target sub-data to the terminal device according to the instruction, without the terminal device requesting access to the active file sending port, which is equivalent to a one-way file sending port; for the passive file sending port, only when the terminal device obtains the port identifier from the received target sub-data and sends an access request to the passive file sending port through the port identifier, the passive file sending port will send the corresponding target sub-data to the terminal device, which is equivalent to a two-way file sending port. Of course, the file sending ports can also be randomly divided into multiple groups of file sending ports, and the data transmission methods of different groups of file sending ports can be defined as different types. This exemplary embodiment does not make any special limitations on the grouping method of the file sending ports.

[0070] Next, the technical content in steps S110 to S130 will be described in detail.

[0071] In an exemplary embodiment of the present disclosure, the at least two groups of file sending ports may include a first file sending port and a second file sending port. For example, the first file sending port may be a passive file sending port, and the second file sending port may be an active file sending port; of course, the first file sending port may be a file sending port with one data transmission method, and the second file sending port may be a file sending port with another data transmission method. It can be understood that the "first" and "second" in the "first file sending port" and "second file sending port" in this embodiment are only used to distinguish file sending ports with different data transmission methods, without any meaning of order or quantity, and should not cause any special limitations to this exemplary embodiment.

[0072] Optionally, taking the first file sending port as a passive file sending port and the second file sending port as an active file sending port as an example, it can be achieved through Figure 2 the steps in to return multiple target sub-data to the terminal device through at least two groups of file sending ports. Referring to Figure 2 as shown, it may specifically include:

[0073] Step S210, dividing the multiple target sub-data into first target sub-data and second target sub-data;

[0074] Step S220, in response to the access request sent by the terminal device to the first file sending port, sending the first target sub-data to the terminal device through the first file sending port; and

[0075] Step S230, actively send the second target sub-data to the terminal device through the second file sending port.

[0076] Among them, the first target sub-data refers to the target sub-data determined from the divided multiple target sub-data and sent through the first file sending port, and the second target sub-data refers to the target sub-data determined from the divided multiple target sub-data and sent through the second file sending port. It can be understood that the "first" and "second" in the "first target sub-data" and "second target sub-data" in this embodiment are only used to distinguish the target sub-data sent by different file sending ports after division, without any special meaning, and should not cause any special limitations to this example embodiment.

[0077] The first target sub-data can be sent to the terminal device by calling the corresponding first file sending port, that is, the passive file sending port, through the access request of the terminal device; the second target sub-data can be actively sent to the terminal device through the second file sending port, that is, the active file sending port.

[0078] Optionally, the first file sending port and the second file sending port can alternately send the first target sub-data and the second target sub-data. For example, after receiving the access request of the terminal device, call the corresponding first file sending port to send the first target sub-data (and send the port identifier of the next first file sending port at the same time), and then send the second target sub-data to the terminal device through the randomly selected second file sending port; at the next moment, the terminal device continues to send an access request to another first file sending port through the port identifier carried in the first target sub-data sent at the previous moment, and so on to alternately send the target sub-data until all the target sub-data is sent.

[0079] Optionally, each target sub-data corresponds to each file sending port one by one, that is, each file sending port only corresponds to one target sub-data each time.

[0080] Optionally, when the second file sending port receives any type of access request, for example, it can include but is not limited to the access request sent by the terminal device. At this time, the access request can be determined as a malicious access request, and the sending of the target sub-data is stopped.

[0081] Since the second file sending port is an active file sending port and is set to directly send the target sub-data to the terminal device, it does not need or will not receive any access requests. If any access request is received, it can prove that the access request is a request instruction sent by a device attempting to spy on or intercept the target sub-data. At this time, directly stop the sending of the target sub-data, effectively ensuring the security of the target data and avoiding the risk of leakage.

[0082] In this embodiment, by using the data transmission method of segmenting target data and uncertain dynamic file transmission channels, the server will prepare data and segment the data, and each segmented sub-data is sent to an independent file transmission port. The file transmission ports can be divided into two groups. The first group of file transmission ports sends sub-data after receiving the access request of the client, and the second group of file transmission ports actively sends sub-data to the client. The first group of file transmission ports and the second group of file transmission ports alternately send sub-data during use. Since in the process of sending sub-data, which channels are used is only decided when sending sub-data, potential snooping behavior can be avoided, because the second group of file transmission ports actively sends sub-data, so when it receives a connection request or an access request, it can easily discover the snooping behavior, thereby immediately preventing the continued transmission of data, effectively avoiding the risk of data being snooped or intercepted, and ensuring the security of data.

[0083] In an example embodiment of the present disclosure, a target port identifier can be determined in a port identifier set of a first file sending port; the target port identifier is returned to a terminal device so that the terminal device accesses the corresponding first file sending port according to the target port identifier to obtain the first target sub-data.

[0084] The first target sub-data can be sent to the first file sending port determined by the access request, and the target port identifier can be determined in the port identifier set of the first file sending port, so as to make an access request to the next first file sending port through the target port identifier to obtain the next first target sub-data.

[0085] Specifically, the target port identifier and the first target sub-data to be sent at the previous moment can be sent to the terminal device, so that the terminal device accesses the first file sending port corresponding to the target port identifier to obtain the first target sub-data to be sent at the next moment.

[0086] In this embodiment, the terminal device that initiates the data acquisition request itself only knows a part of the file sending port. Only after receiving the previous target sub-data can it know which file sending port the next target sub-data uses to send the target sub-data. That is, the use of the file sending port is random and not fixed, which increases the possibility of the file sending port being detected. Different target sub-data are sent through different file sending ports and are difficult to be intercepted. In addition, each target sub-data is only a sub-part of the data, and the entire target data cannot be reversely deduced from a target sub-data of the target data, which effectively ensures the security of the target data and reduces the risk of leakage.

[0087] In an exemplary embodiment of the present disclosure, dynamic encryption processing can be performed on target sub-data; specifically, the dynamic encryption processing of the target sub-data can be achieved through the following steps, including:

[0088] A target field can be randomly determined in the current target sub-data, and the target field can be deleted from the current target sub-data; and the target field can be added to the target sub-data sent at the next moment.

[0089] In this embodiment, for the target sub-data obtained by segmentation, confidentiality is achieved by adding dynamic encryption. Specifically, multiple fields are randomly selected from the first target sub-data for missing processing, and the content of these missing processes is located in the second target sub-data. The second target sub-data also has missing content, and so on. That is, only by obtaining each target sub-data in sequence can the complete target data requested be obtained. If the target sub-data is not obtained in sequence or the order of the obtained target sub-data is incorrect, the difficulty of reverse deciphering will increase sharply. When there are missing parts in the obtained target sub-data, it will also cause other target sub-data adjacent to the missing target sub-data to be undecipherable, effectively reducing the risk of the target data being intercepted or reverse deciphered, and further ensuring the security of the target data.

[0090] Optionally, for the cipher book used by the terminal device to merge the target sub-data, the cipher book used for each data transmission can be different. Because the generation of the cipher book is random, the encryption method in this application cannot be reverse-derived by analyzing the cipher book, further enhancing the security of the target data.

[0091] In an exemplary embodiment of the present disclosure, after obtaining the data acquisition request of the terminal device, the dynamic authentication of the terminal device can be achieved through the following steps, improving the security of the authentication of the terminal device and ensuring the security of the target data from the source:

[0092] A dynamic authentication request can be sent to the terminal device. Optionally, the dynamic authentication request can include any one or a combination of a face recognition request, a fingerprint recognition request, a QR code verification request, and a dynamic code verification request; receive the dynamic authentication response information, and determine the dynamic authentication result according to the dynamic authentication response information. Among them, the dynamic authentication response information refers to the authentication information input by the terminal device based on the dynamic authentication request sent by the server, such as face information, fingerprint information, etc. Specifically, the dynamic authentication result can be determined according to the dynamic authentication response information. For example, if the dynamic authentication result is passed or "True" or "1", a data channel can be established with the terminal device to achieve the transmission of the target data; if the dynamic authentication result is not passed or "False" or "0", the data channel established with the terminal device can be interrupted.

[0093] Figure 3 Schematically shown is a schematic diagram of the principle of transmitting target data according to some embodiments of the present disclosure.

[0094] Referring Figure 3 As shown, a server-side application can be installed on the server 310, and a client application can be installed on the terminal device 320, and a data transmission channel can be established between the server 310 and the terminal device 320 through the server-side application and the client application.

[0095] Specifically, the server 310 can respond to a data acquisition request sent by the terminal device 320 and initiate a dynamic authentication request, which can include but is not limited to a face recognition request, a fingerprint recognition request, a QR code verification request, and a dynamic code verification request; after the dynamic authentication result is passed, the server 310 can split the target data 330 associated with the data acquisition request into multiple target sub-data, obtaining a first target sub-data 340 and a second target sub-data 350, and each target sub-data is sent to a separate file sending port. The file sending ports are divided into two groups. For example, they can be divided into a first file sending port 360 and a second file sending port 370. The first file sending port 360 can be a passive file sending port or a bidirectional file sending port, and the second file sending port 370 can be an active file sending port or a unidirectional file sending port; the terminal device 320 can access the first file sending port 360 to obtain the corresponding first target sub-data 340, and the terminal device 320 can receive the second target sub-data 350 sent by the second file sending port 370; in this way, after the terminal device 320 receives all the target sub-data, it can merge the multiple target sub-data to obtain the target data 330, completing the secure transmission of the target data 330 from the server 310 to the terminal device 320.

[0096] Among them, the access of the terminal device 320 to the first file sending port 360 and the acceptance of the access of the second file sending port 370 can be set to alternate, but only communicate with one file sending port each time. Since different target sub-data are sent through different file sending channels, it is difficult to be intercepted, and each target sub-data is only a sub-part of the target data, and obtaining a single target sub-data alone has no meaning. For the target sub-data, a dynamic encryption method can be added for confidentiality. The specific method is to randomly select multiple fields from the first target sub-data for missing processing, and the content of these missing processing is located in the second target sub-data. The second target sub-data also has missing content, and so on. That is, only by obtaining each target sub-data in sequence can the final target data be obtained.

[0097] In summary, the data acquisition method provided in the exemplary embodiment of the present example can obtain a data acquisition request of a terminal device, match target data according to a data identifier carried in the data acquisition request, and cut the target data into multiple target sub-data. Furthermore, the multiple target sub-data can be returned to the terminal device through at least two sets of file sending ports, so that the terminal device can perform data merging on the received multiple target sub-data to restore the target data. On the one hand, dividing the target data into multiple target sub-data for sending can avoid the risk of the entire target data being leaked due to snooping or interception events during network transmission, and improve the security of the target data. On the other hand, sending the divided multiple target sub-data through at least two sets of file sending ports. In this way, when some file sending ports are leaked, it is impossible to accurately track all the file sending ports, ensuring that at least some of the target sub-data cannot be snooped or intercepted, and further improving the security of the target data during network transmission.

[0098] It should be noted that although the steps of the method in the present disclosure are described in a specific order in the drawings, this does not require or imply that these steps must be performed in this specific order, or that all the steps shown must be performed to achieve the desired result. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step for execution, and / or one step may be decomposed into multiple steps for execution, etc.

[0099] In addition, in the exemplary embodiment of the present example, a data acquisition device is also provided. Referring to Figure 4 As shown, the data acquisition device 400 includes: a data request module 410, a data splitting module 420, and a data distribution module 430. Among them:

[0100] The data request module 410 is used to obtain a data acquisition request of a terminal device, and the data acquisition request includes a data identifier;

[0101] The data splitting module 420 is used to match target data based on the data identifier and cut the target data into multiple target sub-data;

[0102] The data distribution module 430 is used to return the multiple target sub-data to the terminal device through at least two sets of file sending ports, so that the terminal device can perform data merging on the received multiple target sub-data to restore the target data.

[0103] In an exemplary embodiment of the present disclosure, based on the foregoing solution, at least two sets of file sending ports may include a first file sending port and a second file sending port. The data distribution module 430 may be used to:

[0104] Divide the multiple target sub-data into first target sub-data and second target sub-data;

[0105] In response to an access request sent by the terminal device to the first file sending port, send the first target sub-data to the terminal device through the first file sending port; and

[0106] Proactively send the second target sub-data to the terminal device through the second file sending port;

[0107] wherein, the first file sending port and the second file sending port alternately send the first target sub-data and the second target sub-data.

[0108] In an exemplary embodiment of the present disclosure, based on the foregoing solution, the data acquisition device 400 may include a port identifier sending unit, and the port identifier sending unit may be used to:

[0109] Determine a target port identifier in the port identifier set of the first file sending port;

[0110] Return the target port identifier to the terminal device, so that the terminal device accesses the corresponding first file sending port according to the target port identifier to obtain the first target sub-data;

[0111] wherein, each of the target sub-data corresponds to each of the file sending ports one by one.

[0112] In an exemplary embodiment of the present disclosure, based on the foregoing solution, the port identifier sending unit may be used to:

[0113] Send the target port identifier and the first target sub-data that needs to be sent at the previous moment to the terminal device, so that the terminal device accesses the corresponding first file sending port according to the target port identifier to obtain the first target sub-data that needs to be sent at the next moment.

[0114] In an exemplary embodiment of the present disclosure, based on the foregoing solution, the data acquisition device 400 may include a malicious request rejection unit, and the malicious request rejection unit may be used to:

[0115] In response to the second file sending port receiving an access request, determine the access request as a malicious access request and stop sending the target sub-data.

[0116] In an exemplary embodiment of the present disclosure, based on the foregoing solution, the data acquisition device 400 may include a data dynamic encryption unit, and the data dynamic encryption unit may be used to:

[0117] Perform dynamic encryption processing on the target sub-data;

[0118] Performing dynamic encryption processing on the target sub-data includes:

[0119] Randomly determining a target field in the current target sub-data, and deleting the target field from the current target sub-data; and

[0120] Adding the target field to the target sub-data to be sent at the next moment.

[0121] In an exemplary embodiment of the present disclosure, based on the foregoing solution, the data acquisition device 400 may include a dynamic authentication unit, and the dynamic authentication unit may be used for:

[0122] Sending a dynamic authentication request to the terminal device, where the dynamic authentication request includes any one or a combination of a face recognition request, a fingerprint recognition request, a QR code verification request, and a dynamic code verification request;

[0123] Receiving dynamic authentication response information, and determining a dynamic authentication result according to the dynamic authentication response information.

[0124] The specific details of each module of the data acquisition device above have been described in detail in the corresponding data acquisition method, so they will not be repeated here.

[0125] It should be noted that although several modules or units of the data acquisition device are mentioned in the above detailed description, this division is not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of the two or more modules or units described above may be embodied in one module or unit. Conversely, the features and functions of one module or unit described above may be further divided and embodied by multiple modules or units.

[0126] In addition, in an exemplary embodiment of the present disclosure, an electronic device capable of implementing the above data acquisition method is also provided.

[0127] Those skilled in the art can understand that various aspects of the present disclosure can be implemented as a system, a method, or a program product. Therefore, various aspects of the present disclosure can be specifically implemented in the following forms, namely: a complete hardware embodiment, a complete software embodiment (including firmware, microcode, etc.), or an embodiment combining hardware and software aspects, which can be collectively referred to as "circuit", "module", or "system" here.

[0128] Next, refer to Figure 5 to describe the electronic device 500 according to this embodiment of the present disclosure. Figure 5 The electronic device 500 shown is only an example and should not impose any limitations on the functions and usage scope of the embodiments of the present disclosure.

[0129] AsFigure 5 As shown, the electronic device 500 is presented in the form of a general-purpose computing device. The components of the electronic device 500 may include, but are not limited to: at least one of the above-mentioned processing units 510, at least one of the above-mentioned storage units 520, a bus 530 connecting different system components (including the storage unit 520 and the processing unit 510), and a display unit 540.

[0130] Among them, the storage unit stores program code, and the program code can be executed by the processing unit 510, so that the processing unit 510 executes the steps according to various exemplary embodiments of the present disclosure described in the "Exemplary Method" section of the present specification above. For example, the processing unit 510 can execute steps such as Figure 1 shown in step S110, obtaining a data acquisition request of the terminal device, where the data acquisition request includes a data identifier; step S120, matching target data based on the data identifier and cutting the target data into multiple target sub-data; step S130, returning the multiple target sub-data to the terminal device through at least two groups of file sending ports, so that the terminal device merges the received multiple target sub-data to restore the target data.

[0131] The storage unit 520 may include a readable medium in the form of a volatile storage unit, such as a random access storage unit (RAM) 521 and / or a cache storage unit 522, and may further include a read-only storage unit (ROM) 523.

[0132] The storage unit 520 may further include a program / utilities 524 having a set (at least one) of program modules 525. Such program modules 525 include, but are not limited to: an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include the implementation of a network environment.

[0133] The bus 530 may represent one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, a graphics acceleration port, a processing unit, or a local bus using any bus structure in a variety of bus structures.

[0134] The electronic device 500 can also communicate with one or more external devices 570 (such as a keyboard, a pointing device, a Bluetooth device, etc.), and can also communicate with one or more devices that enable a user to interact with the electronic device 500, and / or communicate with any device (such as a router, a modem, etc.) that enables the electronic device 500 to communicate with one or more other computing devices. Such communication can be carried out through the input / output (I / O) interface 550. Moreover, the electronic device 500 can also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through the network adapter 560. As shown in the figure, the network adapter 560 communicates with other modules of the electronic device 500 through the bus 530. It should be understood that, although not shown in the figure, other hardware and / or software modules can be used in combination with the electronic device 500, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.

[0135] Through the description of the above embodiments, those skilled in the art can easily understand that the exemplary embodiments described herein can be implemented by software, or can be implemented by the way of software in combination with necessary hardware. Therefore, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product, and the software product can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) to execute the method according to the embodiments of the present disclosure.

[0136] In an exemplary embodiment of the present disclosure, there is also provided a computer-readable storage medium, on which a program product capable of implementing the above method of the present specification is stored. In some possible embodiments, various aspects of the present disclosure can also be implemented in the form of a program product, which includes program code. When the program product runs on a terminal device, the program code is used to enable the terminal device to execute the steps according to various exemplary embodiments of the present disclosure described in the above "Exemplary Method" section of the present specification.

[0137] Reference Figure 6 As shown, a program product 600 for implementing the above data acquisition method according to an embodiment of the present disclosure is described. It can adopt a portable compact disc read-only memory (CD-ROM) and includes program code, and can run on a terminal device, such as a personal computer. However, the program product of the present disclosure is not limited thereto. In this document, the readable storage medium can be any tangible medium that contains or stores a program, and the program can be used by or in combination with an instruction execution system, apparatus, or device.

[0138] The program product may employ any combination of one or more readable media. The readable media may be a readable signal medium or a readable storage medium. A readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the foregoing. More specific examples (a non-exhaustive list) of the readable storage medium include: an electrical connection having one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0139] A computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, in which the readable program code is carried. Such a propagated data signal may take many forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the foregoing. The readable signal medium may also be any readable medium other than a readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device.

[0140] The program code contained on the readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wireline, optical fiber cable, RF, etc., or any suitable combination of the foregoing.

[0141] The program code for performing the operations of the present disclosure may be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, etc., and also including conventional procedural programming languages such as the "C" language or similar programming languages. The program code may execute entirely on the user's computing device, partly on the user's device, as a stand-alone software package, partly on the user's computing device and partly on a remote computing device, or entirely on the remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., through the Internet using an Internet service provider).

[0142] In addition, the above-mentioned drawings are only schematic illustrations of the processes included in the method according to the exemplary embodiments of the present disclosure, and are not for limiting purposes. It is easy to understand that the processes shown in the above-mentioned drawings do not indicate or limit the time sequence of these processes. Additionally, it is also easy to understand that these processes may be executed synchronously or asynchronously, for example, in multiple modules.

[0143] Through the description of the above embodiments, those skilled in the art can easily understand that the exemplary embodiments described herein can be implemented by software or by a combination of software and necessary hardware. Therefore, the technical solution according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, and includes several instructions to enable a computing device (such as a personal computer, a server, a touch terminal, or a network device, etc.) to execute the method according to the embodiments of the present disclosure.

[0144] After considering the specification and practicing the invention disclosed herein, those skilled in the art will readily conceive of other embodiments of the present disclosure. This application is intended to cover any variations, uses, or adaptations of the present disclosure, which follow the general principles of the present disclosure and include known common knowledge or conventional technical means in the technical field not disclosed in the present disclosure. The specification and embodiments are only regarded as exemplary, and the true scope and spirit of the present disclosure are pointed out by the claims.

[0145] It should be understood that the present disclosure is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present disclosure is only limited by the appended claims.

Claims

1. A data acquisition method, characterized in that, Including: Obtain a data acquisition request of a terminal device, where the data acquisition request includes a data identifier; Match target data based on the data identifier, and cut the target data into multiple target sub-data; Return the multiple target sub-data to the terminal device through at least two sets of file sending ports, so that the terminal device merges the multiple target sub-data received to restore the target data; Wherein, the at least two sets of file sending ports include a first file sending port and a second file sending port, the first file sending port is a passive file sending port, and the second file sending port is an active file sending port; the multiple target sub-data are divided into first target sub-data and second target sub-data; The returning the multiple target sub-data to the terminal device through at least two sets of file sending ports includes: In response to an access request sent by the terminal device to the first file sending port, send the first target sub-data to the terminal device through the first file sending port; and actively send the second target sub-data to the terminal device through the second file sending port; wherein, the first file sending port and the second file sending port alternately send the first target sub-data and the second target sub-data.

2. The data acquisition method according to claim 1, wherein The method includes: Determine a target port identifier in the set of port identifiers of the first file sending port; Return the target port identifier to the terminal device, so that the terminal device accesses the corresponding first file sending port according to the target port identifier to obtain the first target sub-data; Wherein, each of the target sub-data corresponds to each of the file sending ports one by one.

3. The data acquisition method according to claim 2, wherein The returning the target port identifier to the terminal device includes: Send the target port identifier and the first target sub-data that needs to be sent at the previous moment to the terminal device, so that the terminal device accesses the corresponding first file sending port according to the target port identifier to obtain the first target sub-data that needs to be sent at the next moment.

4. The data acquisition method according to claim 1, wherein The method further includes: In response to the second file sending port receiving an access request, determine the access request as a malicious access request and stop sending the target sub-data.

5. The data acquisition method according to claim 1, characterized in that, The method further includes: Perform dynamic encryption processing on the target sub-data; The performing dynamic encryption processing on the target sub-data includes: Randomly determine a target field in the current target sub-data, and delete the target field from the current target sub-data; and Add the target field to the target sub-data to be sent at the next moment.

6. The data acquisition method according to claim 1, wherein After obtaining the data acquisition request of the terminal device, the method further includes: Send a dynamic authentication request to the terminal device, where the dynamic authentication request includes any one or a combination of a face recognition request, a fingerprint recognition request, a QR code verification request, and a dynamic code verification request; Receive dynamic authentication response information, and determine a dynamic authentication result according to the dynamic authentication response information.

7. A data acquisition device, characterized in that, Including: A data request module, configured to obtain a data acquisition request of a terminal device, where the data acquisition request includes a data identifier; A data splitting module, configured to match target data based on the data identifier and split the target data into a plurality of target sub-data; A data distribution module, configured to return the plurality of target sub-data to the terminal device through at least two groups of file sending ports, so that the terminal device merges the received plurality of target sub-data to recover the target data; wherein, the at least two groups of file sending ports include a first file sending port and a second file sending port, the first file sending port is a passive file sending port, and the second file sending port is an active file sending port; the plurality of target sub-data are divided into first target sub-data and second target sub-data; The data distribution module is configured to, in response to an access request sent by the terminal device to the first file sending port, send the first target sub-data to the terminal device through the first file sending port; and actively send the second target sub-data to the terminal device through the second file sending port; wherein, the first file sending port and the second file sending port alternately send the first target sub-data and the second target sub-data.

8. An electronic device, characterized in that, Comprising: A processor; And A memory, on which computer-readable instructions are stored, and when the computer-readable instructions are executed by the processor, the data acquisition method according to any one of claims 1 to 6 is implemented.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, the data acquisition method according to any one of claims 1 to 6 is implemented.

Citation Information

Patent Citations

  • Data segment transmission method and system based on wireless protocol

    CN108551450A

  • File acquisition method and device, computer equipment and storage medium

    CN110941845A